Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with Rbot-AFW worm


  • This topic is locked This topic is locked
32 replies to this topic

#1 arsarcanum4

arsarcanum4

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:07:44 AM

Posted 16 May 2009 - 08:52 AM

DONT KNOW IF ITS RBOT-AFW but on a guide to post said to put something like this.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:42:37 PM, on 5/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DL32] DL32
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1231070202259
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 4667 bytes



ALSO: I used www.hijackthis.de for automated detection of "bad things" in the hijackthis log and it said :

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
= very nasty

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
= very nasty

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
= nasty

O4 - HKCU\..\Run: [DL32] DL32
=It seems that the name of this program is the same as the name of the file. In the most cases this is the result of trojans. To be sure, you should check this file.

^ my avg 8 always detects a trojan trying to connect, but its web shield blocks it automatically. don't know if it really removes it. (for the last thing)

Edited by arsarcanum4, 16 May 2009 - 11:58 AM.


BC AdBot (Login to Remove)

 


#2 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:06:44 AM

Posted 17 May 2009 - 08:22 AM

Hello! :thumbup2:
My name is Sam and I will be helping you.

In order to see what's going on with your computer I will ask for you to post various logs from the tools that we will use to resolve your issue. Please also share with me any information about how your computer is reacting and behaving each step of the way as we work through this process.


Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.




We need to create an OTListIt2 Report
  • Please download OTListIt2 from here
  • Save it to your desktop.
  • Double click on the icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Push the "Run Scan" button.
  • The scan should take just a few minutes.
  • Copy the log that opens up and paste it back here in your next reply.

Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#3 arsarcanum4

arsarcanum4
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:07:44 AM

Posted 17 May 2009 - 08:35 PM

I have downloaded the things on a second computer, and transferring it via USB since my internet on the other computer doesn't work. I have Mbam already installed from before and it found nothing. I'll post my results of the scans tommorow.


EDIT: i get bsod when i try to run mbam now that says the equal or less thing. i did another hijackthis scan and deleted R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171/ . My internet works now, but i think theres still something. I got spyware blaster + scanning my computer with all anti spyware + AVG to see if anything is left. If it pops up again, ill bump this post. Thanks Sam

Edited by arsarcanum4, 17 May 2009 - 09:22 PM.


#4 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:06:44 AM

Posted 18 May 2009 - 11:40 AM

ok
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#5 arsarcanum4

arsarcanum4
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:07:44 AM

Posted 18 May 2009 - 02:57 PM

The internet works now, but when I search something on Google, it says a fake message, it doesn't appear in MSN live search though. Here are the results of the scans

For the Extras. Txt (results):


OTListIt Extras logfile created on: 5/18/2009 3:52:59 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = E:\
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

445.48 Mb Total Physical Memory | 155.71 Mb Available Physical Memory | 34.95% Memory free
720.21 Mb Paging File | 476.61 Mb Available in Paging File | 66.18% Paging File free
Paging file location(s): C:\pagefile.sys 336 672 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 51.08 Gb Free Space | 91.40% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 953.58 Mb Total Space | 929.16 Mb Free Space | 97.44% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HUNAG-DELL
Current User Name: Peter Huang
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{10C69612-017B-45F5-B986-7D113D5A2EA3}" = MSN Toolbar
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"AVG8Uninstall" = AVG 8.5
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"DVD Decrypter" = DVD Decrypter (Remove Only)
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"LiveUpdate1.7" = LiveUpdate 1.7 (Symantec Corporation)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SpywareBlaster_is1" = SpywareBlaster 4.2
"Storm Codec 5" = Storm Codec
"Windows XP Service Pack" = Windows XP Service Pack 3
"ZHTIELangPack" = Chinese (Traditional) Language Support

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/4/2009 3:55:51 PM | Computer Name = HUNAG-DELL | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16827, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x00002476.

Error - 5/4/2009 5:54:31 PM | Computer Name = HUNAG-DELL | Source = MsiInstaller | ID = 1008
Description = The installation of C:\Program Files\Common Files\Wise Installation
Wizard\WISCDDCBBF1270346BC938BBCC81A1EEAAA_4_26_0_1002.MSI is not permitted due
to an error in software restriction policy processing. The object cannot be trusted.

Error - 5/7/2009 6:59:52 PM | Computer Name = HUNAG-DELL | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x021d18f5.

Error - 5/8/2009 9:53:19 PM | Computer Name = HUNAG-DELL | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x008918f5.

Error - 5/10/2009 2:16:01 PM | Computer Name = HUNAG-DELL | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x01d718f5.

Error - 5/15/2009 11:44:41 PM | Computer Name = HUNAG-DELL | Source = ACW_DE | ID = 2
Description = Application already running. Cannot create a file when that file
already exists.

Error - 5/17/2009 10:11:01 PM | Computer Name = HUNAG-DELL | Source = Application Hang | ID = 1002
Description = Hanging application OTListIt2.exe, version 2.0.15.8, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 5/17/2009 10:19:18 PM | Computer Name = HUNAG-DELL | Source = Application Hang | ID = 1002
Description = Hanging application OTListIt2.exe, version 2.0.15.8, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 5/18/2009 3:48:31 PM | Computer Name = HUNAG-DELL | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/18/2009 3:48:43 PM | Computer Name = HUNAG-DELL | Source = Application Hang | ID = 1002
Description = Hanging application OTListIt2.exe, version 2.0.15.8, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 5/7/2009 6:59:57 PM | Computer Name = HUNAG-DELL | Source = Service Control Manager | ID = 7034
Description = The Terminal Services service terminated unexpectedly. It has done
this 1 time(s).

Error - 5/8/2009 6:22:04 PM | Computer Name = HUNAG-DELL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 5/8/2009 6:23:13 PM | Computer Name = HUNAG-DELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AvgLdx86 AvgMfx86 Fips intelppm OMCI

Error - 5/8/2009 6:27:05 PM | Computer Name = HUNAG-DELL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 5/8/2009 9:53:24 PM | Computer Name = HUNAG-DELL | Source = Service Control Manager | ID = 7031
Description = The DCOM Server Process Launcher service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in 60000
milliseconds: Reboot the machine.

Error - 5/8/2009 9:53:24 PM | Computer Name = HUNAG-DELL | Source = Service Control Manager | ID = 7034
Description = The Terminal Services service terminated unexpectedly. It has done
this 1 time(s).

Error - 5/10/2009 2:21:03 PM | Computer Name = HUNAG-DELL | Source = Service Control Manager | ID = 7031
Description = The DCOM Server Process Launcher service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in 60000
milliseconds: Reboot the machine.

Error - 5/10/2009 2:21:03 PM | Computer Name = HUNAG-DELL | Source = Service Control Manager | ID = 7034
Description = The Terminal Services service terminated unexpectedly. It has done
this 1 time(s).

Error - 5/17/2009 10:13:29 PM | Computer Name = HUNAG-DELL | Source = System Error | ID = 1003
Description = Error code 100000d1, parameter1 e1739000, parameter2 00000002, parameter3
00000000, parameter4 f7124cf1.

Error - 5/17/2009 10:16:53 PM | Computer Name = HUNAG-DELL | Source = System Error | ID = 1003
Description = Error code 100000d1, parameter1 e1744000, parameter2 00000002, parameter3
00000000, parameter4 f7124cf1.


< End of report >















FOR THE OTLISTIT.TXT (results):
OTListIt logfile created on: 5/18/2009 3:52:59 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = E:\
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

445.48 Mb Total Physical Memory | 155.71 Mb Available Physical Memory | 34.95% Memory free
720.21 Mb Paging File | 476.61 Mb Available in Paging File | 66.18% Paging File free
Paging file location(s): C:\pagefile.sys 336 672 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 51.08 Gb Free Space | 91.40% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 953.58 Mb Total Space | 929.16 Mb Free Space | 97.44% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HUNAG-DELL
Current User Name: Peter Huang
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2008/04/13 20:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2005/12/19 10:08:42 | 00,018,944 | ---- | M] () -- C:\WINDOWS\System32\WLTRYSVC.EXE
PRC - [2005/12/19 10:08:40 | 01,200,128 | ---- | M] (Dell Inc.) -- C:\WINDOWS\System32\bcmwltry.exe
PRC - [2009/05/05 16:29:08 | 00,298,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2009/01/12 15:40:03 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2003/08/28 15:01:22 | 00,061,440 | ---- | M] () -- C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
PRC - [2009/05/05 16:29:09 | 00,908,568 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2009/05/05 16:29:08 | 00,833,304 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgam.exe
PRC - [2009/05/18 15:47:16 | 00,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/05/05 16:29:19 | 00,594,712 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2009/05/18 15:48:39 | 00,692,504 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2003/10/31 20:42:40 | 00,032,768 | ---- | M] (Cyberlink Corp.) -- C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
PRC - [2005/12/19 10:08:42 | 01,347,584 | ---- | M] (Dell Inc.) -- C:\WINDOWS\system32\WLTRAY.exe
PRC - [2009/01/12 15:40:03 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/05/05 16:29:12 | 01,947,928 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2009/01/05 10:41:28 | 00,162,744 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe
PRC - [2008/04/13 20:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
PRC - [2009/02/06 06:10:02 | 00,227,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\wmiprvse.exe
PRC - [2009/05/17 21:32:38 | 00,501,248 | ---- | M] (OldTimer Tools) -- E:\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2009/05/05 16:29:09 | 00,908,568 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe -- (avg8emc [Auto | Running])
SRV - [2009/05/05 16:29:08 | 00,298,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd [Auto | Running])
SRV - [2008/04/13 20:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2009/01/12 15:40:03 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2003/07/16 16:30:48 | 00,066,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ipxsap.dll -- (NwSapAgent [Auto | Running])
SRV - [2003/08/28 15:01:22 | 00,061,440 | ---- | M] () -- C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe -- (spkrmon [Auto | Running])
SRV - [2005/12/19 10:08:42 | 00,018,944 | ---- | M] () -- C:\WINDOWS\System32\WLTRYSVC.EXE -- (wltrysvc [Auto | Running])

========== Driver Services (SafeList) ==========

DRV - [2002/04/01 14:15:00 | 00,004,816 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\system32\drivers\aeaudio.sys -- (aeaudio [On_Demand | Running])
DRV - [2009/05/05 16:30:21 | 00,325,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgldx86.sys -- (AvgLdx86 [System | Running])
DRV - [2009/05/05 16:30:19 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys -- (AvgMfx86 [System | Running])
DRV - [2009/05/05 16:30:32 | 00,012,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgrkx86.sys -- (AvgRkx86 [Boot | Running])
DRV - [2009/05/05 16:30:31 | 00,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgtdix.sys -- (AvgTdiX [System | Running])
DRV - [2005/11/02 14:24:34 | 00,424,320 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\system32\DRIVERS\bcmwl5.sys -- (BCM43XX [On_Demand | Running])
DRV - [2008/04/13 14:56:06 | 00,088,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys -- (NwlnkIpx [Auto | Running])
DRV - [2003/07/16 16:40:08 | 00,063,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\nwlnknb.sys -- (NwlnkNb [Auto | Running])
DRV - [2003/07/16 16:40:09 | 00,055,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys -- (NwlnkSpx [Auto | Running])
DRV - [2001/08/22 09:42:58 | 00,013,632 | ---- | M] (Dell Computer Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS -- (OMCI [System | Running])
DRV - [2003/07/16 16:42:18 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2008/04/13 12:39:15 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2008/04/13 14:36:39 | 00,040,960 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\DRIVERS\sisagp.sys -- (sisagp [Boot | Running])
DRV - [2004/08/03 23:31:36 | 00,032,768 | ---- | M] (SiS Corporation) -- C:\WINDOWS\System32\DRIVERS\sisnic.sys -- (SISNIC [On_Demand | Running])
DRV - [2004/03/29 17:04:42 | 00,612,352 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\system32\drivers\smwdm.sys -- (smwdm [On_Demand | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default = AA 09 18 7A 56 CC 85 4A A6 7F 57 DA 71 9F 43 E6 [binary data]
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default = AA 09 18 7A 56 CC 85 4A A6 7F 57 DA 71 9F 43 E6 [binary data]
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Default = AA 09 18 7A 56 CC 85 4A A6 7F 57 DA 71 9F 43 E6 [binary data]
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Default = AA 09 18 7A 56 CC 85 4A A6 7F 57 DA 71 9F 43 E6 [binary data]
IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default = AA 09 18 7A 56 CC 85 4A A6 7F 57 DA 71 9F 43 E6 [binary data]
IE - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.live.com [binary data]
IE - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKU\S-1-5-21-1482476501-412668190-725345543-1004\S-1-5-21-1482476501-412668190-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-1482476501-412668190-725345543-1004\S-1-5-21-1482476501-412668190-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>



O1 HOSTS File: (736 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKU\S-1-5-21-1482476501-412668190-725345543-1004\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKU\S-1-5-21-1482476501-412668190-725345543-1004\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe (Dell Inc.)
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti ()
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKU\S-1-5-21-1482476501-412668190-725345543-1004..\Run: [DL32] DL32 File not found
O4 - HKU\S-1-5-21-1482476501-412668190-725345543-1004..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKU\S-1-5-21-1482476501-412668190-725345543-1004..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-1482476501-412668190-725345543-1004\..Trusted Domains: 25 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat...b?1231070202259 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_11)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/04 04:28:52 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * ()

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[6 C:\WINDOWS\*.tmp files]
[2009/05/18 15:44:32 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Peter Huang\My Documents\OTListIt2.exe
[2009/05/17 22:15:06 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/17 22:15:04 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/17 22:15:02 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/05/16 09:31:52 | 00,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009/05/15 23:44:36 | 00,000,000 | ---D | C] -- C:\233090cf05067e248173b8fc
[2009/05/15 23:43:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/05/15 23:43:34 | 00,118,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSSTDFMT.DLL
[2009/05/15 23:43:34 | 00,000,000 | ---D | C] -- C:\Program Files\SpywareBlaster
[2009/05/15 23:41:04 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\Peter Huang\My Documents\HijackThis.lnk
[2009/05/15 23:41:04 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/05/15 23:28:38 | 00,000,000 | ---D | C] -- C:\Program Files\ACW
[2009/05/07 16:36:36 | 00,000,000 | ---D | C] -- C:\Program Files\SwiftKit
[2009/05/07 07:50:15 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009/05/06 15:53:35 | 00,000,000 | -H-D | C] -- C:\$AVG8.VAULT$
[2009/05/05 16:37:45 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009/05/05 16:30:33 | 00,011,952 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/05/05 16:30:33 | 00,001,507 | ---- | C] () -- C:\Documents and Settings\Peter Huang\My Documents\AVG 8.5.lnk
[2009/05/05 16:30:32 | 00,012,552 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgrkx86.sys
[2009/05/05 16:30:31 | 00,108,552 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/05/05 16:30:21 | 00,325,896 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/05/05 16:30:19 | 00,027,784 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/05/05 16:29:41 | 36,177,980 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/05/05 16:29:41 | 36,119,516 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm.old
[2009/05/05 16:29:38 | 00,056,764 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/05/05 16:29:38 | 00,056,731 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg.old
[2009/05/05 16:29:35 | 00,434,673 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/05/05 16:29:30 | 06,061,540 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/05/05 16:29:30 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg
[2009/05/05 16:29:07 | 00,000,000 | ---D | C] -- C:\Program Files\AVG
[2009/05/05 16:29:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg8
[2009/05/04 17:58:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/05/04 17:58:06 | 00,000,780 | ---- | C] () -- C:\Documents and Settings\Peter Huang\My Documents\SUPERAntiSpyware Free Edition.lnk
[2009/05/04 17:58:04 | 00,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2009/05/04 17:58:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\SUPERAntiSpyware.com
[2009/05/04 17:25:04 | 06,325,280 | ---- | C] () -- C:\Documents and Settings\Peter Huang\My Documents\SUPERAntiSpyware.exe
[2009/05/04 16:18:07 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2009/05/04 16:14:05 | 00,000,000 | -H-D | C] -- C:\WINDOWS\msdownld.tmp
[2009/05/04 16:11:55 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/05/04 16:08:40 | 25,569,440 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Peter Huang\My Documents\Setup.exe
[2009/05/03 18:12:17 | 00,000,046 | ---- | C] () -- C:\WINDOWS\System32\p2hhr.bat
[2009/05/03 17:50:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\Help
[2009/05/03 17:46:16 | 00,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2009/05/03 15:01:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\U3
[2009/05/03 14:21:35 | 00,003,448 | ---- | C] () -- C:\WINDOWS\System32\lmppcsetup.exe
[2009/05/03 09:01:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\AVG8
[2009/05/03 09:01:11 | 00,839,240 | ---- | C] (AVG Technologies) -- C:\Documents and Settings\Peter Huang\My Documents\avg_avwt_stb_all_8_19.exe
[2009/05/03 08:53:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\uvdqjnqw
[2009/05/03 08:30:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\Mozilla
[2009/05/03 08:26:44 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\796525
[2009/05/03 08:26:36 | 00,000,434 | ---- | C] () -- C:\WINDOWS\tasks\At2.job
[2009/04/27 19:47:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\Malwarebytes
[2009/04/27 19:47:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/27 19:43:27 | 02,967,816 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Peter Huang\My Documents\mbam-setup.exe
[2009/04/27 18:59:30 | 00,000,434 | ---- | C] () -- C:\WINDOWS\tasks\At1.job
[2009/01/05 13:09:49 | 00,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2009/01/05 13:09:49 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2006/11/01 02:54:30 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2006/11/01 02:52:38 | 00,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2006/05/26 09:29:14 | 00,005,120 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2006/04/03 08:26:36 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2003/07/16 16:51:23 | 00,000,503 | ---- | C] () -- C:\WINDOWS\win.ini
[2003/07/16 16:47:28 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini
[2003/07/16 16:44:09 | 01,614,848 | ---- | C] () -- C:\WINDOWS\System32\sfcfiles.dll
[2003/05/15 02:39:50 | 00,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2002/05/15 00:58:38 | 00,122,880 | ---- | C] () -- C:\WINDOWS\System32\v2k2_dec.dll
[2002/03/29 16:12:28 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\NavLogon.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[6 C:\WINDOWS\*.tmp files]
[2009/05/18 15:51:30 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/05/18 15:51:27 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Peter Huang\Local Settings\desktop.ini
[2009/05/18 15:51:23 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/05/18 15:48:35 | 36,177,980 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/05/18 15:48:35 | 00,056,764 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/05/18 15:44:40 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Peter Huang\My Documents\OTListIt2.exe
[2009/05/17 22:07:39 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/05/16 09:31:52 | 00,000,118 | ---- | M] () -- C:\WINDOWS\System32\MRT.INI
[2009/05/15 23:41:04 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Peter Huang\My Documents\HijackThis.lnk
[2009/05/15 23:31:17 | 36,119,516 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm.old
[2009/05/15 23:31:17 | 00,056,731 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg.old
[2009/05/10 14:15:00 | 00,000,434 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2009/05/09 09:56:54 | 00,000,736 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/05/08 23:27:32 | 00,000,436 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2009/05/07 03:16:29 | 24,699,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/05/05 16:42:45 | 00,000,082 | -HS- | M] () -- C:\Documents and Settings\Peter Huang\My Documents\desktop.ini
[2009/05/05 16:30:33 | 00,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/05/05 16:30:33 | 00,001,507 | ---- | M] () -- C:\Documents and Settings\Peter Huang\My Documents\AVG 8.5.lnk
[2009/05/05 16:30:32 | 00,012,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgrkx86.sys
[2009/05/05 16:30:31 | 00,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/05/05 16:30:21 | 00,325,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/05/05 16:30:19 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/05/05 16:29:38 | 00,434,673 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/05/05 16:29:35 | 06,061,540 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/05/04 17:58:06 | 00,000,780 | ---- | M] () -- C:\Documents and Settings\Peter Huang\My Documents\SUPERAntiSpyware Free Edition.lnk
[2009/05/04 17:25:05 | 06,325,280 | ---- | M] () -- C:\Documents and Settings\Peter Huang\My Documents\SUPERAntiSpyware.exe
[2009/05/04 16:18:11 | 00,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/05/04 16:10:47 | 25,569,440 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Peter Huang\My Documents\Setup.exe
[2009/05/03 18:43:58 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.bak
[2009/05/03 18:12:17 | 00,000,046 | ---- | M] () -- C:\WINDOWS\System32\p2hhr.bat
[2009/05/03 18:05:40 | 00,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/05/03 14:21:35 | 00,003,448 | ---- | M] () -- C:\WINDOWS\System32\lmppcsetup.exe
[2009/05/03 09:01:24 | 00,839,240 | ---- | M] (AVG Technologies) -- C:\Documents and Settings\Peter Huang\My Documents\avg_avwt_stb_all_8_19.exe
[2009/05/03 08:26:37 | 00,000,434 | ---- | M] () -- C:\WINDOWS\tasks\At2.job
[2009/04/27 19:47:13 | 02,967,816 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Peter Huang\My Documents\mbam-setup.exe
< End of report >

Edited by arsarcanum4, 18 May 2009 - 02:59 PM.


#6 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:06:44 AM

Posted 18 May 2009 - 04:41 PM

Run OTListIt2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTLI
    O4 - HKU\S-1-5-21-1482476501-412668190-725345543-1004..\Run: [DL32] DL32 File not found
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
    O7 - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
    
    :Files
    C:\WINDOWS\tasks\At*.job
    
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log

================



Please update Malwarebytes and run a full scan.
  • Open Malwarebytes and select the Update tab.
  • Click on the Check for Updates button and allow the program to download the latest updates.
  • Once you have the latest updates, select the Scanner tab.
  • Select "Perform full scan" and click the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#7 arsarcanum4

arsarcanum4
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:07:44 AM

Posted 18 May 2009 - 07:49 PM

RESULTS OF THE THING YOU TOLD ME TO PASTE

========== OTLISTIT ==========
Registry value HKEY_USERS\S-1-5-21-1482476501-412668190-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Run\\DL32 not found.
Registry value HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully.
Registry value HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools not found.
Registry value HKEY_USERS\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully.
========== FILES ==========
C:\WINDOWS\tasks\At1.job moved successfully.
C:\WINDOWS\tasks\At2.job moved successfully.
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\Peter Huang\Local Settings\Temp\2022655310.exe scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Peter Huang\Local Settings\Temp\etilqs_h7QGKIlGBzo3qJobohvy scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\02d589d1-02c2-44b8-9013-59447b63b58e.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\13ac1fff-e612-49d1-b39e-153b54dc81ca.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\1ad722ac-ffa6-4e7f-8c26-4c6f72946442.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\2255425b-2190-45df-835e-e9a6002e2434.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\266fa7b2-a8f6-42f7-a946-c4fa7a000ff0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\3a357f21-2fd9-49df-a13c-f98601d77183.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\45e67799-2365-4d98-80fc-9e657f912832.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\4f924912-9a4a-4609-9869-6b33207b3419.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\6d510cd2-097d-4d0a-bc96-a45910138201.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\7274496c-931b-4d98-b580-e6d2278d1b67.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\87b985e4-ae0f-41f6-8717-8ee6d49e3197.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\93702e61-355f-4da1-8c51-9f511b106921.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\97203bf5-128a-46fa-b458-a501978696fc.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\a2356bea-385c-4685-b0d9-d6239f78b39a.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\a6b03d06-0bcd-431e-855d-dcb8cc85adb2.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\a9bd6ccb-dbd5-48ae-bb59-df1e5d5b1dd7.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\aed98663-cb87-4aad-918d-54bcfbc601eb.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\b191051f-5d2e-4cb0-bd9d-18c64d3868b6.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\b4d13f12-f432-4a89-97e8-f19328ea5572.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\c449eaa6-05e1-4414-be76-58ff94e7a961.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\d37d7f6f-edf8-42a0-b934-5b5163c3914c.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\d435b7f2-e83f-401b-a4b1-fd6f0b8f7034.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\e88a9127-1044-490a-8d22-75f6b0be1309.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ec53a9b3-6223-4442-ba48-ab8fa93966f8.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_b4.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.

OTListIt2 by OldTimer - Version 2.0.15.8 log created on 05182009_201758

Files moved on Reboot...
C:\Documents and Settings\Peter Huang\Local Settings\Temp\2022655310.exe moved successfully.
File C:\Documents and Settings\Peter Huang\Local Settings\Temp\etilqs_h7QGKIlGBzo3qJobohvy not found!
File C:\WINDOWS\temp\02d589d1-02c2-44b8-9013-59447b63b58e.tmp not found!
File C:\WINDOWS\temp\13ac1fff-e612-49d1-b39e-153b54dc81ca.tmp not found!
C:\WINDOWS\temp\1ad722ac-ffa6-4e7f-8c26-4c6f72946442.tmp moved successfully.
File C:\WINDOWS\temp\2255425b-2190-45df-835e-e9a6002e2434.tmp not found!
File C:\WINDOWS\temp\266fa7b2-a8f6-42f7-a946-c4fa7a000ff0.tmp not found!
C:\WINDOWS\temp\3a357f21-2fd9-49df-a13c-f98601d77183.tmp moved successfully.
C:\WINDOWS\temp\45e67799-2365-4d98-80fc-9e657f912832.tmp moved successfully.
C:\WINDOWS\temp\4f924912-9a4a-4609-9869-6b33207b3419.tmp moved successfully.
C:\WINDOWS\temp\6d510cd2-097d-4d0a-bc96-a45910138201.tmp moved successfully.
C:\WINDOWS\temp\7274496c-931b-4d98-b580-e6d2278d1b67.tmp moved successfully.
File C:\WINDOWS\temp\87b985e4-ae0f-41f6-8717-8ee6d49e3197.tmp not found!
File C:\WINDOWS\temp\93702e61-355f-4da1-8c51-9f511b106921.tmp not found!
File C:\WINDOWS\temp\97203bf5-128a-46fa-b458-a501978696fc.tmp not found!
C:\WINDOWS\temp\a2356bea-385c-4685-b0d9-d6239f78b39a.tmp moved successfully.
File C:\WINDOWS\temp\a6b03d06-0bcd-431e-855d-dcb8cc85adb2.tmp not found!
File C:\WINDOWS\temp\a9bd6ccb-dbd5-48ae-bb59-df1e5d5b1dd7.tmp not found!
File C:\WINDOWS\temp\aed98663-cb87-4aad-918d-54bcfbc601eb.tmp not found!
C:\WINDOWS\temp\b191051f-5d2e-4cb0-bd9d-18c64d3868b6.tmp moved successfully.
C:\WINDOWS\temp\b4d13f12-f432-4a89-97e8-f19328ea5572.tmp moved successfully.
C:\WINDOWS\temp\c449eaa6-05e1-4414-be76-58ff94e7a961.tmp moved successfully.
C:\WINDOWS\temp\d37d7f6f-edf8-42a0-b934-5b5163c3914c.tmp moved successfully.
C:\WINDOWS\temp\d435b7f2-e83f-401b-a4b1-fd6f0b8f7034.tmp moved successfully.
File C:\WINDOWS\temp\e88a9127-1044-490a-8d22-75f6b0be1309.tmp not found!
File C:\WINDOWS\temp\ec53a9b3-6223-4442-ba48-ab8fa93966f8.tmp not found!
File C:\WINDOWS\temp\Perflib_Perfdata_b4.dat not found!

Registry entries deleted on Reboot...


RESULTS OF OTLIST SCAN AFTER DELETION:

OTListIt logfile created on: 5/18/2009 8:37:20 PM - Run 2
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\Peter Huang\My Documents
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

445.48 Mb Total Physical Memory | 95.64 Mb Available Physical Memory | 21.47% Memory free
720.21 Mb Paging File | 447.93 Mb Available in Paging File | 62.19% Paging File free
Paging file location(s): C:\pagefile.sys 336 672 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 51.41 Gb Free Space | 92.00% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 953.58 Mb Total Space | 930.64 Mb Free Space | 97.59% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HUNAG-DELL
Current User Name: Peter Huang
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2008/04/13 20:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2005/12/19 10:08:42 | 00,018,944 | ---- | M] () -- C:\WINDOWS\System32\WLTRYSVC.EXE
PRC - [2005/12/19 10:08:40 | 01,200,128 | ---- | M] (Dell Inc.) -- C:\WINDOWS\System32\bcmwltry.exe
PRC - [2009/05/05 16:29:08 | 00,298,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2009/01/12 15:40:03 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2003/08/28 15:01:22 | 00,061,440 | ---- | M] () -- C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
PRC - [2009/05/05 16:29:09 | 00,908,568 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2009/05/05 16:29:08 | 00,833,304 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgam.exe
PRC - [2009/05/18 15:47:16 | 00,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/05/05 16:29:19 | 00,594,712 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2009/05/18 15:48:39 | 00,692,504 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2008/04/13 20:12:29 | 00,069,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe
PRC - [2003/10/31 20:42:40 | 00,032,768 | ---- | M] (Cyberlink Corp.) -- C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
PRC - [2005/12/19 10:08:42 | 01,347,584 | ---- | M] (Dell Inc.) -- C:\WINDOWS\system32\WLTRAY.exe
PRC - [2009/01/12 15:40:03 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/05/05 16:29:12 | 01,947,928 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2009/01/05 10:41:28 | 00,162,744 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe
PRC - [2008/04/13 20:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
PRC - [2009/04/24 00:38:11 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/05/18 15:44:40 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Peter Huang\My Documents\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2009/05/05 16:29:09 | 00,908,568 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe -- (avg8emc [Auto | Running])
SRV - [2009/05/05 16:29:08 | 00,298,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd [Auto | Running])
SRV - [2008/04/13 20:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2009/01/12 15:40:03 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2003/07/16 16:30:48 | 00,066,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ipxsap.dll -- (NwSapAgent [Auto | Running])
SRV - [2003/08/28 15:01:22 | 00,061,440 | ---- | M] () -- C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe -- (spkrmon [Auto | Running])
SRV - [2005/12/19 10:08:42 | 00,018,944 | ---- | M] () -- C:\WINDOWS\System32\WLTRYSVC.EXE -- (wltrysvc [Auto | Running])

========== Driver Services (SafeList) ==========

DRV - [2002/04/01 14:15:00 | 00,004,816 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\system32\drivers\aeaudio.sys -- (aeaudio [On_Demand | Running])
DRV - [2009/05/05 16:30:21 | 00,325,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgldx86.sys -- (AvgLdx86 [System | Running])
DRV - [2009/05/05 16:30:19 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys -- (AvgMfx86 [System | Running])
DRV - [2009/05/05 16:30:32 | 00,012,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgrkx86.sys -- (AvgRkx86 [Boot | Running])
DRV - [2009/05/05 16:30:31 | 00,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgtdix.sys -- (AvgTdiX [System | Running])
DRV - [2005/11/02 14:24:34 | 00,424,320 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\system32\DRIVERS\bcmwl5.sys -- (BCM43XX [On_Demand | Running])
DRV - [2008/04/13 14:56:06 | 00,088,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys -- (NwlnkIpx [Auto | Running])
DRV - [2003/07/16 16:40:08 | 00,063,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\nwlnknb.sys -- (NwlnkNb [Auto | Running])
DRV - [2003/07/16 16:40:09 | 00,055,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys -- (NwlnkSpx [Auto | Running])
DRV - [2001/08/22 09:42:58 | 00,013,632 | ---- | M] (Dell Computer Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS -- (OMCI [System | Running])
DRV - [2003/07/16 16:42:18 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2008/04/13 12:39:15 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2008/04/13 14:36:39 | 00,040,960 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\DRIVERS\sisagp.sys -- (sisagp [Boot | Running])
DRV - [2004/08/03 23:31:36 | 00,032,768 | ---- | M] (SiS Corporation) -- C:\WINDOWS\System32\DRIVERS\sisnic.sys -- (SISNIC [On_Demand | Running])
DRV - [2004/03/29 17:04:42 | 00,612,352 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\system32\drivers\smwdm.sys -- (smwdm [On_Demand | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default = AA 09 18 7A 56 CC 85 4A A6 7F 57 DA 71 9F 43 E6 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.live.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {3A54B7BD-02DD-4CE2-8826-CE254C105C9B}:1.0
FF - prefs.js..extensions.enabledItems: {C650F6EF-E788-4439-8D8A-AD35D38A1F13}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/18 20:13:40 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/05/18 20:12:27 | 00,000,000 | ---D | M]

[2009/05/18 20:13:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Peter Huang\Application Data\mozilla\Extensions
[2009/05/18 20:13:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Peter Huang\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/18 20:13:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Peter Huang\Application Data\mozilla\Firefox\Profiles\h5e7vnb0.default\extensions
[2009/05/18 20:12:28 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/05/18 20:21:01 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{3A54B7BD-02DD-4CE2-8826-CE254C105C9B}
[2009/05/18 20:12:28 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/05/18 20:24:03 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{C650F6EF-E788-4439-8D8A-AD35D38A1F13}
[2009/04/24 00:38:30 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/24 00:38:32 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/23 20:39:08 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/23 20:39:08 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/23 20:39:08 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/23 20:39:08 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/23 20:39:08 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/23 20:39:08 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/23 20:39:08 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (305362 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123haustiereundmehr.com
O1 - Hosts: 10538 more lines...
O2 - BHO: (C:\WINDOWS\system32\had732ufn8.dll) - {A6C7B2A1-00F3-42BD-F434-00AABA2C8953} - C:\WINDOWS\system32\had732ufn8.dll ()
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe (Dell Inc.)
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti ()
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [Diagnostic Manager] C:\DOCUME~1\PETERH~1\LOCALS~1\Temp\1150769394.exe File not found
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 55 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat...b?1231070202259 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_11)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
O22 - SharedTaskScheduler: {A6C7B2A1-00F3-42BD-F434-00AABA2C8953} - hasf8h3rfijfn98gf9iar - C:\WINDOWS\system32\had732ufn8.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/04 04:28:52 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/05/18 20:34:58 | 00,000,000 | R--D | M]

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[6 C:\WINDOWS\*.tmp files]
[2009/05/18 20:17:58 | 00,000,000 | ---D | C] -- C:\_OTListIt
[2009/05/18 20:13:46 | 00,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/05/18 20:12:31 | 00,001,602 | ---- | C] () -- C:\Documents and Settings\Peter Huang\My Documents\Mozilla Firefox.lnk
[2009/05/18 20:12:25 | 00,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2009/05/18 19:58:45 | 07,526,856 | ---- | C] (Mozilla) -- C:\Documents and Settings\Peter Huang\My Documents\Firefox Setup 3.0.10.exe
[2009/05/18 18:28:06 | 00,000,227 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009/05/18 16:58:52 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2009/05/18 16:58:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/05/18 16:22:16 | 00,037,376 | ---- | C] () -- C:\WINDOWS\System32\glsetup.exe
[2009/05/18 16:22:09 | 00,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\setup.exe
[2009/05/18 16:07:09 | 00,015,000 | ---- | C] () -- C:\WINDOWS\System32\had732ufn8.dll
[2009/05/18 16:07:07 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\ak1.exe
[2009/05/18 15:44:32 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Peter Huang\My Documents\OTListIt2.exe
[2009/05/17 22:15:06 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/17 22:15:04 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/17 22:15:02 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/05/16 09:31:52 | 00,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009/05/15 23:44:36 | 00,000,000 | ---D | C] -- C:\233090cf05067e248173b8fc
[2009/05/15 23:43:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/05/15 23:43:34 | 00,118,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSSTDFMT.DLL
[2009/05/15 23:43:34 | 00,000,000 | ---D | C] -- C:\Program Files\SpywareBlaster
[2009/05/15 23:41:04 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\Peter Huang\My Documents\HijackThis.lnk
[2009/05/15 23:41:04 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/05/15 23:28:38 | 00,000,000 | ---D | C] -- C:\Program Files\ACW
[2009/05/07 16:36:36 | 00,000,000 | ---D | C] -- C:\Program Files\SwiftKit
[2009/05/07 07:50:15 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009/05/06 15:53:35 | 00,000,000 | -H-D | C] -- C:\$AVG8.VAULT$
[2009/05/05 16:37:45 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009/05/05 16:30:33 | 00,011,952 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/05/05 16:30:33 | 00,001,507 | ---- | C] () -- C:\Documents and Settings\Peter Huang\My Documents\AVG 8.5.lnk
[2009/05/05 16:30:32 | 00,012,552 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgrkx86.sys
[2009/05/05 16:30:31 | 00,108,552 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/05/05 16:30:21 | 00,325,896 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/05/05 16:30:19 | 00,027,784 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/05/05 16:29:41 | 36,177,980 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/05/05 16:29:41 | 36,119,516 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm.old
[2009/05/05 16:29:38 | 00,056,764 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/05/05 16:29:38 | 00,056,731 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg.old
[2009/05/05 16:29:35 | 00,434,673 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/05/05 16:29:30 | 06,061,540 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/05/05 16:29:30 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg
[2009/05/05 16:29:07 | 00,000,000 | ---D | C] -- C:\Program Files\AVG
[2009/05/05 16:29:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg8
[2009/05/04 17:58:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/05/04 17:58:06 | 00,000,780 | ---- | C] () -- C:\Documents and Settings\Peter Huang\My Documents\SUPERAntiSpyware Free Edition.lnk
[2009/05/04 17:58:04 | 00,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2009/05/04 17:58:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\SUPERAntiSpyware.com
[2009/05/04 17:25:04 | 06,325,280 | ---- | C] () -- C:\Documents and Settings\Peter Huang\My Documents\SUPERAntiSpyware.exe
[2009/05/04 16:18:07 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2009/05/04 16:14:05 | 00,000,000 | -H-D | C] -- C:\WINDOWS\msdownld.tmp
[2009/05/04 16:11:55 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/05/03 18:12:17 | 00,000,046 | ---- | C] () -- C:\WINDOWS\System32\p2hhr.bat
[2009/05/03 17:50:24%

Edited by arsarcanum4, 18 May 2009 - 07:54 PM.


#8 arsarcanum4

arsarcanum4
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:07:44 AM

Posted 18 May 2009 - 08:00 PM

--used up max characters, continued below.

[2009/05/03 17:50:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\Help
[2009/05/03 17:46:16 | 00,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2009/05/03 15:01:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\U3
[2009/05/03 14:21:35 | 00,003,448 | ---- | C] () -- C:\WINDOWS\System32\lmppcsetup.exe
[2009/05/03 09:01:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\AVG8
[2009/05/03 09:01:11 | 00,839,240 | ---- | C] (AVG Technologies) -- C:\Documents and Settings\Peter Huang\My Documents\avg_avwt_stb_all_8_19.exe
[2009/05/03 08:53:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\uvdqjnqw
[2009/05/03 08:30:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\Mozilla
[2009/05/03 08:26:44 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\796525
[2009/04/27 19:47:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\Malwarebytes
[2009/04/27 19:47:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/27 19:43:27 | 02,967,816 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Peter Huang\My Documents\mbam-setup.exe
[2009/01/05 13:09:49 | 00,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2009/01/05 13:09:49 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2006/11/01 02:54:30 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2006/11/01 02:52:38 | 00,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2006/05/26 09:29:14 | 00,005,120 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2006/04/03 08:26:36 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2003/07/16 16:51:23 | 00,000,503 | ---- | C] () -- C:\WINDOWS\win.ini
[2003/07/16 16:47:28 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini
[2003/07/16 16:44:09 | 01,614,848 | ---- | C] () -- C:\WINDOWS\System32\sfcfiles.dll
[2003/05/15 02:39:50 | 00,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2002/05/15 00:58:38 | 00,122,880 | ---- | C] () -- C:\WINDOWS\System32\v2k2_dec.dll
[2002/03/29 16:12:28 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\NavLogon.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[6 C:\WINDOWS\*.tmp files]
[2009/05/18 20:32:39 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/05/18 20:32:37 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Peter Huang\Local Settings\desktop.ini
[2009/05/18 20:32:32 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/05/18 20:13:46 | 00,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat
[2009/05/18 20:12:31 | 00,001,602 | ---- | M] () -- C:\Documents and Settings\Peter Huang\My Documents\Mozilla Firefox.lnk
[2009/05/18 20:01:46 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/05/18 19:58:47 | 07,526,856 | ---- | M] (Mozilla) -- C:\Documents and Settings\Peter Huang\My Documents\Firefox Setup 3.0.10.exe
[2009/05/18 18:28:07 | 00,000,227 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2009/05/18 17:17:32 | 00,305,362 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/05/18 17:11:15 | 00,305,362 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090518-171732.backup
[2009/05/18 16:40:41 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090518-171115.backup
[2009/05/18 16:22:17 | 00,037,376 | ---- | M] () -- C:\WINDOWS\System32\glsetup.exe
[2009/05/18 16:07:24 | 00,000,046 | ---- | M] () -- C:\WINDOWS\System32\p2hhr.bat
[2009/05/18 16:07:09 | 00,015,000 | ---- | M] () -- C:\WINDOWS\System32\had732ufn8.dll
[2009/05/18 16:07:07 | 00,020,480 | ---- | M] () -- C:\WINDOWS\System32\ak1.exe
[2009/05/18 15:48:35 | 36,177,980 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/05/18 15:48:35 | 00,056,764 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/05/18 15:44:40 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Peter Huang\My Documents\OTListIt2.exe
[2009/05/16 09:31:52 | 00,000,118 | ---- | M] () -- C:\WINDOWS\System32\MRT.INI
[2009/05/15 23:41:04 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Peter Huang\My Documents\HijackThis.lnk
[2009/05/15 23:31:17 | 36,119,516 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm.old
[2009/05/15 23:31:17 | 00,056,731 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg.old
[2009/05/08 23:27:32 | 00,000,436 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2009/05/07 03:16:29 | 24,699,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/05/05 16:42:45 | 00,000,082 | -HS- | M] () -- C:\Documents and Settings\Peter Huang\My Documents\desktop.ini
[2009/05/05 16:30:33 | 00,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/05/05 16:30:33 | 00,001,507 | ---- | M] () -- C:\Documents and Settings\Peter Huang\My Documents\AVG 8.5.lnk
[2009/05/05 16:30:32 | 00,012,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgrkx86.sys
[2009/05/05 16:30:31 | 00,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/05/05 16:30:21 | 00,325,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/05/05 16:30:19 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/05/05 16:29:38 | 00,434,673 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/05/05 16:29:35 | 06,061,540 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/05/04 17:58:06 | 00,000,780 | ---- | M] () -- C:\Documents and Settings\Peter Huang\My Documents\SUPERAntiSpyware Free Edition.lnk
[2009/05/04 17:25:05 | 06,325,280 | ---- | M] () -- C:\Documents and Settings\Peter Huang\My Documents\SUPERAntiSpyware.exe
[2009/05/04 16:18:11 | 00,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/05/03 18:43:58 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.bak
[2009/05/03 18:05:40 | 00,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/05/03 14:21:35 | 00,003,448 | ---- | M] () -- C:\WINDOWS\System32\lmppcsetup.exe
[2009/05/03 09:01:24 | 00,839,240 | ---- | M] (AVG Technologies) -- C:\Documents and Settings\Peter Huang\My Documents\avg_avwt_stb_all_8_19.exe
[2009/04/27 19:47:13 | 02,967,816 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Peter Huang\My Documents\mbam-setup.exe

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >







I still can't use MBAM for some reason, I keep getting a BSOD. Also, I saw some processes that were the cause of the problem on HijackThis. I delete them, but they keep on coming back :/ .

#9 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:06:44 AM

Posted 19 May 2009 - 02:07 PM

Please stop making changes with Hijackthis on your own. It makes it all but impossible for me to see what's actually going on with your computer if I don't know what you are changing.


Run OTListIt2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTLI
    O2 - BHO: (C:\WINDOWS\system32\had732ufn8.dll) - {A6C7B2A1-00F3-42BD-F434-00AABA2C8953} - C:\WINDOWS\system32\had732ufn8.dll ()
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - Reg Error: Key error. File not found
    
    :Files
    C:\WINDOWS\System32\glsetup.exe
    C:\WINDOWS\System32\p2hhr.bat
    C:\WINDOWS\System32\had732ufn8.dll
    C:\WINDOWS\System32\ak1.exe
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log

Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#10 arsarcanum4

arsarcanum4
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:07:44 AM

Posted 19 May 2009 - 03:31 PM

========== OTLISTIT ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6C7B2A1-00F3-42BD-F434-00AABA2C8953}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6C7B2A1-00F3-42BD-F434-00AABA2C8953}\ not found.
File C:\WINDOWS\system32\had732ufn8.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}\ not found.
========== FILES ==========
C:\WINDOWS\System32\glsetup.exe moved successfully.
File\Folder C:\WINDOWS\System32\p2hhr.bat not found.
File\Folder C:\WINDOWS\System32\had732ufn8.dll not found.
C:\WINDOWS\System32\ak1.exe moved successfully.
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\Peter Huang\Local Settings\Temp\hsperfdata_Peter Huang\2204 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Peter Huang\Local Settings\Temp\hsperfdata_Peter Huang\3456 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Peter Huang\Local Settings\Temp\etilqs_x7egaVhCdpLdZ0ftGKtP scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\5070dc61-e2dd-4693-a6cc-abcc9951beea.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\5c1fe260-c372-40a0-a4b0-b4e2d9dbd3e2.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\9c64a0a0-379d-4cfb-ba1e-7a78f700848d.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_740.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
File delete failed. C:\Documents and Settings\Peter Huang\Application Data\Sun\Java\Deployment\cache\6.0\41\79708429-6e68ba32 scheduled to be deleted on reboot.
Java cache emptied.
Temp folders emptied.

OTListIt2 by OldTimer - Version 2.0.15.8 log created on 05192009_162457

Files moved on Reboot...
File C:\Documents and Settings\Peter Huang\Local Settings\Temp\hsperfdata_Peter Huang\2204 not found!
File C:\Documents and Settings\Peter Huang\Local Settings\Temp\hsperfdata_Peter Huang\3456 not found!
File C:\Documents and Settings\Peter Huang\Local Settings\Temp\etilqs_x7egaVhCdpLdZ0ftGKtP not found!
File C:\WINDOWS\temp\5070dc61-e2dd-4693-a6cc-abcc9951beea.tmp not found!
File C:\WINDOWS\temp\5c1fe260-c372-40a0-a4b0-b4e2d9dbd3e2.tmp not found!
File C:\WINDOWS\temp\9c64a0a0-379d-4cfb-ba1e-7a78f700848d.tmp not found!
File C:\WINDOWS\temp\Perflib_Perfdata_740.dat not found!
C:\Documents and Settings\Peter Huang\Application Data\Sun\Java\Deployment\cache\6.0\41\79708429-6e68ba32 moved successfully.

Registry entries deleted on Reboot...

#11 arsarcanum4

arsarcanum4
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:07:44 AM

Posted 19 May 2009 - 03:36 PM

THE NEW OTLISTIT2 SCAN AFTER REMOVAL

OTListIt logfile created on: 5/19/2009 4:32:09 PM - Run 4
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\Peter Huang\My Documents
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

445.48 Mb Total Physical Memory | 51.98 Mb Available Physical Memory | 11.67% Memory free
720.21 Mb Paging File | 361.72 Mb Available in Paging File | 50.22% Paging File free
Paging file location(s): C:\pagefile.sys 336 672 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 51.39 Gb Free Space | 91.96% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 953.58 Mb Total Space | 930.64 Mb Free Space | 97.59% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HUNAG-DELL
Current User Name: Peter Huang
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2008/04/13 20:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2005/12/19 10:08:42 | 00,018,944 | ---- | M] () -- C:\WINDOWS\System32\WLTRYSVC.EXE
PRC - [2005/12/19 10:08:40 | 01,200,128 | ---- | M] (Dell Inc.) -- C:\WINDOWS\System32\bcmwltry.exe
PRC - [2009/05/05 16:29:08 | 00,298,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2009/01/12 15:40:03 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2003/08/28 15:01:22 | 00,061,440 | ---- | M] () -- C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
PRC - [2009/05/05 16:29:09 | 00,908,568 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2009/05/05 16:29:08 | 00,833,304 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgam.exe
PRC - [2009/05/18 15:47:16 | 00,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/05/05 16:29:19 | 00,594,712 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2009/05/18 15:48:39 | 00,692,504 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2003/10/31 20:42:40 | 00,032,768 | ---- | M] (Cyberlink Corp.) -- C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
PRC - [2005/12/19 10:08:42 | 01,347,584 | ---- | M] (Dell Inc.) -- C:\WINDOWS\system32\WLTRAY.exe
PRC - [2009/01/12 15:40:03 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/05/05 16:29:12 | 01,947,928 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2009/01/05 10:41:28 | 00,162,744 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe
PRC - [2008/04/13 20:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
PRC - [2009/04/24 00:38:11 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/05/18 15:44:40 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Peter Huang\My Documents\OTListIt2.exe
PRC - [2009/01/12 15:40:01 | 00,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\java.exe

========== Win32 Services (SafeList) ==========

SRV - [2009/05/05 16:29:09 | 00,908,568 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe -- (avg8emc [Auto | Running])
SRV - [2009/05/05 16:29:08 | 00,298,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd [Auto | Running])
SRV - [2008/04/13 20:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2009/01/12 15:40:03 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2003/07/16 16:30:48 | 00,066,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ipxsap.dll -- (NwSapAgent [Auto | Running])
SRV - [2003/08/28 15:01:22 | 00,061,440 | ---- | M] () -- C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe -- (spkrmon [Auto | Running])
SRV - [2005/12/19 10:08:42 | 00,018,944 | ---- | M] () -- C:\WINDOWS\System32\WLTRYSVC.EXE -- (wltrysvc [Auto | Running])

========== Driver Services (SafeList) ==========

DRV - [2002/04/01 14:15:00 | 00,004,816 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\system32\drivers\aeaudio.sys -- (aeaudio [On_Demand | Running])
DRV - [2009/05/05 16:30:21 | 00,325,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgldx86.sys -- (AvgLdx86 [System | Running])
DRV - [2009/05/05 16:30:19 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys -- (AvgMfx86 [System | Running])
DRV - [2009/05/05 16:30:32 | 00,012,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgrkx86.sys -- (AvgRkx86 [Boot | Running])
DRV - [2009/05/05 16:30:31 | 00,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgtdix.sys -- (AvgTdiX [System | Running])
DRV - [2005/11/02 14:24:34 | 00,424,320 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\system32\DRIVERS\bcmwl5.sys -- (BCM43XX [On_Demand | Running])
DRV - [2008/04/13 14:56:06 | 00,088,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys -- (NwlnkIpx [Auto | Running])
DRV - [2003/07/16 16:40:08 | 00,063,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\nwlnknb.sys -- (NwlnkNb [Auto | Running])
DRV - [2003/07/16 16:40:09 | 00,055,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys -- (NwlnkSpx [Auto | Running])
DRV - [2001/08/22 09:42:58 | 00,013,632 | ---- | M] (Dell Computer Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS -- (OMCI [System | Running])
DRV - [2003/07/16 16:42:18 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2008/04/13 12:39:15 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2008/04/13 14:36:39 | 00,040,960 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\DRIVERS\sisagp.sys -- (sisagp [Boot | Running])
DRV - [2004/08/03 23:31:36 | 00,032,768 | ---- | M] (SiS Corporation) -- C:\WINDOWS\System32\DRIVERS\sisnic.sys -- (SISNIC [On_Demand | Running])
DRV - [2004/03/29 17:04:42 | 00,612,352 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\system32\drivers\smwdm.sys -- (smwdm [On_Demand | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default = AA 09 18 7A 56 CC 85 4A A6 7F 57 DA 71 9F 43 E6 [binary data]
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default = AA 09 18 7A 56 CC 85 4A A6 7F 57 DA 71 9F 43 E6 [binary data]
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Default = AA 09 18 7A 56 CC 85 4A A6 7F 57 DA 71 9F 43 E6 [binary data]
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Default = AA 09 18 7A 56 CC 85 4A A6 7F 57 DA 71 9F 43 E6 [binary data]
IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default = AA 09 18 7A 56 CC 85 4A A6 7F 57 DA 71 9F 43 E6 [binary data]
IE - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.live.com [binary data]
IE - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKU\S-1-5-21-1482476501-412668190-725345543-1004\S-1-5-21-1482476501-412668190-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {3A54B7BD-02DD-4CE2-8826-CE254C105C9B}:1.0
FF - prefs.js..extensions.enabledItems: {C650F6EF-E788-4439-8D8A-AD35D38A1F13}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/18 20:13:40 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/05/18 20:12:27 | 00,000,000 | ---D | M]

[2009/05/18 20:13:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Peter Huang\Application Data\mozilla\Extensions
[2009/05/18 20:13:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Peter Huang\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/18 20:13:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Peter Huang\Application Data\mozilla\Firefox\Profiles\h5e7vnb0.default\extensions
[2009/05/18 20:12:28 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/05/18 20:21:01 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{3A54B7BD-02DD-4CE2-8826-CE254C105C9B}
[2009/05/18 20:12:28 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/05/18 20:24:03 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{C650F6EF-E788-4439-8D8A-AD35D38A1F13}
[2009/04/24 00:38:30 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/24 00:38:32 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/23 20:39:08 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/23 20:39:08 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/23 20:39:08 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/23 20:39:08 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/23 20:39:08 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/23 20:39:08 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/23 20:39:08 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (305362 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123haustiereundmehr.com
O1 - Hosts: 10538 more lines...
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKU\S-1-5-21-1482476501-412668190-725345543-1004\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe (Dell Inc.)
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti ()
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKU\S-1-5-21-1482476501-412668190-725345543-1004..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKU\S-1-5-21-1482476501-412668190-725345543-1004..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1482476501-412668190-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 0
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\.DEFAULT\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-18\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-1482476501-412668190-725345543-1004\..Trusted Domains: 55 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_11)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/04 04:28:52 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/05/19 16:29:03 | 00,000,000 | R--D | M]

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[6 C:\WINDOWS\*.tmp files]
[2009/05/19 16:26:20 | 00,104,326 | ---- | C] () -- C:\WINDOWS\System32\vp_setup.exe
[2009/05/19 15:44:55 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- C:\Documents and Settings\Peter Huang\My Documents\spybotsd162.exe
[2009/05/18 20:17:58 | 00,000,000 | ---D | C] -- C:\_OTListIt
[2009/05/18 20:13:46 | 00,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/05/18 20:12:31 | 00,001,602 | ---- | C] () -- C:\Documents and Settings\Peter Huang\My Documents\Mozilla Firefox.lnk
[2009/05/18 20:12:25 | 00,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2009/05/18 19:58:45 | 07,526,856 | ---- | C] (Mozilla) -- C:\Documents and Settings\Peter Huang\My Documents\Firefox Setup 3.0.10.exe
[2009/05/18 18:28:06 | 00,000,227 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009/05/18 16:58:52 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2009/05/18 16:58:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/05/18 16:22:09 | 00,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\setup.exe
[2009/05/18 15:44:32 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Peter Huang\My Documents\OTListIt2.exe
[2009/05/17 22:15:06 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/17 22:15:04 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/17 22:15:02 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/05/16 09:31:52 | 00,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009/05/15 23:44:36 | 00,000,000 | ---D | C] -- C:\233090cf05067e248173b8fc
[2009/05/15 23:43:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/05/15 23:43:34 | 00,118,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSSTDFMT.DLL
[2009/05/15 23:43:34 | 00,000,000 | ---D | C] -- C:\Program Files\SpywareBlaster
[2009/05/15 23:41:04 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\Peter Huang\My Documents\HijackThis.lnk
[2009/05/15 23:41:04 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/05/15 23:28:38 | 00,000,000 | ---D | C] -- C:\Program Files\ACW
[2009/05/07 16:36:36 | 00,000,000 | ---D | C] -- C:\Program Files\SwiftKit
[2009/05/07 07:50:15 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009/05/06 15:53:35 | 00,000,000 | -H-D | C] -- C:\$AVG8.VAULT$
[2009/05/05 16:37:45 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009/05/05 16:30:33 | 00,011,952 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/05/05 16:30:33 | 00,001,507 | ---- | C] () -- C:\Documents and Settings\Peter Huang\My Documents\AVG 8.5.lnk
[2009/05/05 16:30:32 | 00,012,552 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgrkx86.sys
[2009/05/05 16:30:31 | 00,108,552 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/05/05 16:30:21 | 00,325,896 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/05/05 16:30:19 | 00,027,784 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/05/05 16:29:41 | 36,177,980 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/05/05 16:29:41 | 36,119,516 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm.old
[2009/05/05 16:29:38 | 00,056,764 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/05/05 16:29:38 | 00,056,731 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg.old
[2009/05/05 16:29:35 | 00,434,673 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/05/05 16:29:30 | 06,061,540 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/05/05 16:29:30 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg
[2009/05/05 16:29:07 | 00,000,000 | ---D | C] -- C:\Program Files\AVG
[2009/05/05 16:29:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg8
[2009/05/04 17:58:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/05/04 17:58:04 | 00,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2009/05/04 17:58:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\SUPERAntiSpyware.com
[2009/05/04 17:25:04 | 06,325,280 | ---- | C] () -- C:\Documents and Settings\Peter Huang\My Documents\SUPERAntiSpyware.exe
[2009/05/04 16:18:07 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2009/05/04 16:14:05 | 00,000,000 | -H-D | C] -- C:\WINDOWS\msdownld.tmp
[2009/05/04 16:11:55 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/05/03 17:50:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\Help
[2009/05/03 17:46:16 | 00,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2009/05/03 15:01:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\U3
[2009/05/03 14:21:35 | 00,003,448 | ---- | C] () -- C:\WINDOWS\System32\lmppcsetup.exe
[2009/05/03 09:01:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\AVG8
[2009/05/03 09:01:11 | 00,839,240 | ---- | C] (AVG Technologies) -- C:\Documents and Settings\Peter Huang\My Documents\avg_avwt_stb_all_8_19.exe
[2009/05/03 08:53:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\uvdqjnqw
[2009/05/03 08:30:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\Mozilla
[2009/05/03 08:26:44 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\796525
[2009/04/27 19:47:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Peter Huang\Application Data\Malwarebytes
[2009/04/27 19:47:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/27 19:43:27 | 02,967,816 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Peter Huang\My Documents\alpha.exe.exe
[2009/01/05 13:09:49 | 00,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2009/01/05 13:09:49 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2006/11/01 02:54:30 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2006/11/01 02:52:38 | 00,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2006/05/26 09:29:14 | 00,005,120 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2006/04/03 08:26:36 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2003/07/16 16:51:23 | 00,000,503 | ---- | C] () -- C:\WINDOWS\win.ini
[2003/07/16 16:47:28 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini
[2003/07/16 16:44:09 | 01,614,848 | ---- | C] () -- C:\WINDOWS\System32\sfcfiles.dll
[2003/05/15 02:39:50 | 00,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2002/05/15 00:58:38 | 00,122,880 | ---- | C] () -- C:\WINDOWS\System32\v2k2_dec.dll
[2002/03/29 16:12:28 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\NavLogon.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[6 C:\WINDOWS\*.tmp files]
[2009/05/19 16:28:15 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/05/19 16:28:13 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Peter Huang\Local Settings\desktop.ini
[2009/05/19 16:28:08 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/05/19 16:26:23 | 00,104,326 | ---- | M] () -- C:\WINDOWS\System32\vp_setup.exe
[2009/05/18 20:13:46 | 00,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat
[2009/05/18 20:12:31 | 00,001,602 | ---- | M] () -- C:\Documents and Settings\Peter Huang\My Documents\Mozilla Firefox.lnk
[2009/05/18 20:01:46 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/05/18 19:58:47 | 07,526,856 | ---- | M] (Mozilla) -- C:\Documents and Settings\Peter Huang\My Documents\Firefox Setup 3.0.10.exe
[2009/05/18 18:28:07 | 00,000,227 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2009/05/18 17:17:32 | 00,305,362 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/05/18 17:11:15 | 00,305,362 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090518-171732.backup
[2009/05/18 16:40:41 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090518-171115.backup
[2009/05/18 15:48:35 | 36,177,980 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/05/18 15:48:35 | 00,056,764 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/05/18 15:44:40 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Peter Huang\My Documents\OTListIt2.exe
[2009/05/16 09:31:52 | 00,000,118 | ---- | M] () -- C:\WINDOWS\System32\MRT.INI
[2009/05/15 23:41:04 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Peter Huang\My Documents\HijackThis.lnk
[2009/05/15 23:31:17 | 36,119,516 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm.old
[2009/05/15 23:31:17 | 00,056,731 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg.old
[2009/05/15 19:55:46 | 16,409,960 | ---- | M] (Safer Networking Limited ) -- C:\Documents and Settings\Peter Huang\My Documents\spybotsd162.exe
[2009/05/08 23:27:32 | 00,000,436 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2009/05/07 03:16:29 | 24,699,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/05/05 16:42:45 | 00,000,082 | -HS- | M] () -- C:\Documents and Settings\Peter Huang\My Documents\desktop.ini
[2009/05/05 16:30:33 | 00,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/05/05 16:30:33 | 00,001,507 | ---- | M] () -- C:\Documents and Settings\Peter Huang\My Documents\AVG 8.5.lnk
[2009/05/05 16:30:32 | 00,012,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgrkx86.sys
[2009/05/05 16:30:31 | 00,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/05/05 16:30:21 | 00,325,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/05/05 16:30:19 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/05/05 16:29:38 | 00,434,673 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/05/05 16:29:35 | 06,061,540 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/05/04 17:25:05 | 06,325,280 | ---- | M] () -- C:\Documents and Settings\Peter Huang\My Documents\SUPERAntiSpyware.exe
[2009/05/04 16:18:11 | 00,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/05/03 18:43:58 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.bak
[2009/05/03 18:05:40 | 00,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/05/03 14:21:35 | 00,003,448 | ---- | M] () -- C:\WINDOWS\System32\lmppcsetup.exe
[2009/05/03 09:01:24 | 00,839,240 | ---- | M] (AVG Technologies) -- C:\Documents and Settings\Peter Huang\My Documents\avg_avwt_stb_all_8_19.exe
[2009/04/27 19:47:13 | 02,967,816 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Peter Huang\My Documents\alpha.exe.exe

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >

#12 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:06:44 AM

Posted 19 May 2009 - 04:21 PM

Try running Malwarebytes again now.
If it still won't run, try Superantispyware next.


Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.

Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#13 arsarcanum4

arsarcanum4
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:07:44 AM

Posted 20 May 2009 - 04:29 PM

I ran Mbam in safe mode. It found 7 things infected, and removed them. There was no log that popped up though.

#14 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:06:44 AM

Posted 20 May 2009 - 06:49 PM

Logs are automatically saved so you just have to access it. Run Malwarebytes and select the Logs tab. You should see a list of logs. Open the most recent log and copy that text here.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#15 arsarcanum4

arsarcanum4
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:07:44 AM

Posted 21 May 2009 - 04:38 PM

Malwarebytes' Anti-Malware 1.36
Database version: 1945
Windows 5.1.2600 Service Pack 3

5/19/2009 4:08:59 PM
mbam-log-2009-05-19 (16-08-59).txt

Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 88862
Time elapsed: 14 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\diagnostic manager (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\p2hhr.bat (Malware.Trace) -> Quarantined and deleted successfully.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users