Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

SetDllDirectoryW could not be located in the dynamic link library


  • Please log in to reply

#1
tauman

tauman

    New Member

  • Member
  • Pip
  • 4 posts
Background, but not current problem:
Couldn't log into my Dell Dimensions 8200. Blue screen of death with message olethk32.dll was corrupt. Thought I'd be daring and attempted to replace that member with the same named member from the Installation disk that came with the PC. Went into Recovery console and was able to hardcopy from D:\i386\olethk32.dl_ to c:\windows\system32\olethk32.dll. Got past that error, but another blue screen of death appeared with a different message. Made a decision (whether it was smart or not is yet to be decided) that this could be a long road of fixing member after member so I decided to reload Windows XP OS from the installation disk. Was able to boot up, but with no SP2 or SP3 installed.

Current Problem:
Opened Internet Explorer and attempted a link and received error message, "The procedure entry point SetDllDirectoryW could not be located in the dynamic link library Kernel32.dll"

Started Googling the error message and thats how I found you guys. Too late? I hope not. Found the posting http://www.geekstogo...nd-t245506.html Sounded like the same error, so I went ahead with the recommendation of rshaffer and went to the 'Start Here' link to get rid of any Malware and Spyware Cleaning Guide' Downloaded the stated software and the results are below.

1. Temp File Cleaner - ran successfully as described
2. System Restore Point - attempted to run SysRestorePoint. Failed with error msg. "this application has failed to start because the application config. is incorrect. Reinstalling the application may fix the problem". Reinstalled successfully but failed to run with the same error msg. Decided to push forward with the idea that its my a$$ if I don't have a point to restore to.
3. ERUNT - ran successfully as described
4.1 MBAM - downloaded free copy, ran successfully as described (not a full scan). created 'mbam-log-2009-12-29.txt' (below)

*****begin mbam.txt *******begin mbam.txt******* begin mbam.txt *****************

Malwarebytes' Anti-Malware 1.42
Database version: 3289
Windows 5.1.2600
Internet Explorer 6.0.2600.0000

12/29/2009 7:47:09 PM
mbam-log-2009-12-29 (19-47-09).txt

Scan type: Quick Scan
Objects scanned: 109785
Time elapsed: 6 minute(s), 58 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 3
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{014da6c4-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{014da6c6-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\MyWay (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWay\myBar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWay\myBar\0.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Files Infected:
(No malicious items detected)

******** end mbam.txt*******end mbam.txt*********end mbam.txt****************

4.2 Ran StopZilla anti-spyware successfully. Found 27 items. Repaired successfully.
4.3 Reboot test. Rebooted PC successfully, but still had the SetDllDirectoryW error. Pushed on!

5. GMER Rootkit Scanner - downloaded rootkit scanner, ran successfully as described. Created log, 'ark.txt' (below)

*******begin ark.txt********begin ark.txt***********begin ark.txt *****************

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2009-12-30 06:49:25
Windows 5.1.2600
Running: gmer.exe; Driver: C:\DOCUME~1\DAVIDR~1\LOCALS~1\Temp\pgldiaod.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwCreateKey [0xBACDF6EA]
SSDT \SystemRoot\System32\DRIVERS\kmxagent.sys (HIPS Agent Driver/CA) ZwCreateSection [0xF5868FD2]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwCreateSymbolicLinkObject [0xBACE040B]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwMakeTemporaryObject [0xBACE075C]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwOpenKey [0xBACDF64E]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwOpenSection [0xBACE0130]
SSDT \SystemRoot\System32\DRIVERS\kmxagent.sys (HIPS Agent Driver/CA) ZwSetInformationProcess [0xF5868662]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwSetSystemInformation [0xBACE0538]

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs kmxagent.sys (HIPS Agent Driver/CA)
AttachedDevice \FileSystem\Ntfs \Ntfs KmxFile.sys (HIPS File Guard driver/CA)
AttachedDevice \FileSystem\Ntfs \Ntfs VET-FILT.SYS (CA Antivirus File Protection Driver/Computer Associates International, Inc.)
AttachedDevice \FileSystem\Ntfs \Ntfs VET-REC.SYS (CA Antivirus File Protection Driver/Computer Associates International, Inc.)

Device \Driver\Tcpip \Device\Ip kmxfw.sys (HIPS Firewall Driver/CA)
Device \Driver\Tcpip \Device\Tcp kmxfw.sys (HIPS Firewall Driver/CA)
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\USBSTOR \Device\00000068 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\Tcpip \Device\Udp kmxfw.sys (HIPS Firewall Driver/CA)
Device \Driver\Tcpip \Device\RawIp kmxfw.sys (HIPS Firewall Driver/CA)
Device \Driver\USBSTOR \Device\0000006a sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\Tcpip \Device\IPMULTICAST kmxfw.sys (HIPS Firewall Driver/CA)
Device \Driver\AFD \Device\Afd KmxCF.sys (HIPS Content Filter Driver/CA)

AttachedDevice \FileSystem\Fastfat \Fat kmxagent.sys (HIPS Agent Driver/CA)
AttachedDevice \FileSystem\Fastfat \Fat KmxFile.sys (HIPS File Guard driver/CA)
AttachedDevice \FileSystem\Fastfat \Fat VET-REC.SYS (CA Antivirus File Protection Driver/Computer Associates International, Inc.)

Device \FileSystem\Cdfs \Cdfs B6A0439A

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\controlset002\control\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType 2
Reg HKLM\SYSTEM\controlset002\control\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics 256
Reg HKLM\SYSTEM\controlset002\control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType 7
Reg HKLM\SYSTEM\controlset002\control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics 256
Reg HKLM\SYSTEM\controlset002\control\Class\{4D36E969-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType 4
Reg HKLM\SYSTEM\controlset002\control\Class\{4D36E969-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics 256
Reg HKLM\SYSTEM\controlset002\control\Class\{4D36E96A-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType 4
Reg HKLM\SYSTEM\controlset002\control\Class\{4D36E96A-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics 256
Reg HKLM\SYSTEM\controlset002\control\Class\{4D36E97B-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType 4
Reg HKLM\SYSTEM\controlset002\control\Class\{4D36E97B-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics 256
Reg HKLM\SYSTEM\controlset002\control\Class\{4D36E980-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType 7
Reg HKLM\SYSTEM\controlset002\control\Class\{4D36E980-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics 256
Reg HKLM\SYSTEM\controlset002\Services\MRxDAV\EncryptedDirectories@

---- EOF - GMER 1.0.15 ----
********end ark.txt************end ark.txt*********end ark.txt***************


6. Post an OTL log. Ran successfully as described. created 'otl.txt' (below)

***** begin otl.txt ********* begin otl.txt ******** begin otl.txt ****************

OTL logfile created on: 12/30/2009 6:51:47 AM - Run 1
OTL by OldTimer - Version 3.1.20.1 Folder = F:\downloads
Windows XP Home Edition (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2600.0000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 258.00 Mb Available Physical Memory | 50.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): c:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 13.06 Gb Free Space | 17.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 249.72 Mb Total Space | 29.88 Mb Free Space | 11.96% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DAVID-HOME
Current User Name: David Ristau
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2009/12/29 19:00:36 | 00,513,536 | ---- | M] (OldTimer Tools) -- F:\downloads\OTL.exe
PRC - [2009/12/01 17:01:38 | 00,238,832 | ---- | M] (CA, Inc.) -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe
PRC - [2009/12/01 17:01:38 | 00,230,664 | ---- | M] (CA, Inc.) -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\cavrid.exe
PRC - [2009/11/03 16:58:02 | 00,165,312 | R--- | M] (iS3, Inc.) -- c:\Program Files\STOPzilla!\STOPzilla.exe
PRC - [2009/10/27 10:01:40 | 00,057,344 | R--- | M] (iS3, Inc.) -- c:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
PRC - [2009/07/30 15:57:55 | 00,214,256 | ---- | M] (CA, Inc.) -- C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
PRC - [2009/07/30 15:57:54 | 00,177,392 | ---- | M] (CA, Inc.) -- C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
PRC - [2009/02/08 19:25:29 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe
PRC - [2009/01/23 11:33:34 | 00,349,424 | ---- | M] (CA, Inc.) -- C:\Program Files\CA\CA Internet Security Suite\ccupdate\ccupdate.exe
PRC - [2008/09/30 14:06:50 | 00,485,208 | ---- | M] (Nikon Corporation) -- C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
PRC - [2008/09/24 20:03:39 | 00,181,488 | ---- | M] (CA, Inc.) -- C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
PRC - [2008/09/24 20:03:39 | 00,173,296 | ---- | M] (CA, Inc.) -- C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
PRC - [2008/09/24 20:01:38 | 00,014,088 | ---- | M] (CA) -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
PRC - [2008/06/24 18:10:30 | 00,281,104 | ---- | M] (CA) -- C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
PRC - [2007/12/11 10:56:54 | 00,286,720 | ---- | M] (Apple Inc.) -- C:\Program Files\QuickTime\QTTask.exe
PRC - [2007/10/18 09:24:46 | 01,010,192 | ---- | M] (CA) -- C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
PRC - [2007/10/18 09:24:46 | 00,801,296 | ---- | M] (CA) -- C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
PRC - [2007/08/20 12:27:26 | 00,144,960 | ---- | M] (Computer Associates International, Inc.) -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe
PRC - [2007/08/16 20:10:16 | 00,189,704 | ---- | M] (CA, Inc.) -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
PRC - [2007/08/16 20:10:14 | 00,218,376 | ---- | M] (CA, Inc.) -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
PRC - [2007/01/04 11:10:22 | 00,280,080 | ---- | M] (CA, Inc.) -- C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
PRC - [2005/07/20 19:07:00 | 00,127,043 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2001/10/09 16:15:42 | 00,159,806 | ---- | M] (Eastman Kodak Company) -- C:\WINDOWS\system32\drivers\dcfssvc.exe
PRC - [2001/08/31 07:44:30 | 00,025,600 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\devldr32.exe
PRC - [2001/08/18 06:00:00 | 01,000,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [1999/12/13 03:01:00 | 00,044,032 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\system32\CTSVCCDA.EXE


========== Modules (SafeList) ==========

MOD - [2009/12/29 19:00:36 | 00,513,536 | ---- | M] (OldTimer Tools) -- F:\downloads\OTL.exe
MOD - [2008/09/24 20:01:38 | 00,083,208 | ---- | M] (CA) -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOEHook.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (ZipToA)
SRV - [2009/12/01 17:01:38 | 00,238,832 | ---- | M] (CA, Inc.) [Auto | Running] -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe -- (VETMSGNT)
SRV - [2009/10/27 10:01:40 | 00,057,344 | R--- | M] (iS3, Inc.) [Auto | Running] -- c:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe -- (szserver)
SRV - [2009/07/30 15:57:55 | 00,214,256 | ---- | M] (CA, Inc.) [On_Demand | Running] -- C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe -- (CaCCProvSP)
SRV - [2009/05/14 16:12:49 | 00,183,280 | ---- | M] (Google) [Auto | Stopped] -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc)
SRV - [2009/02/08 19:25:29 | 00,133,104 | ---- | M] (Google Inc.) [Auto | Stopped] -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1c98a556202b96e) Google Update Service (gupdate1c98a556202b96e)
SRV - [2008/06/24 18:10:30 | 00,281,104 | ---- | M] (CA) [Auto | Running] -- C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe -- (UmxPol)
SRV - [2007/10/18 09:24:46 | 01,010,192 | ---- | M] (CA) [Auto | Running] -- C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe -- (UmxAgent)
SRV - [2007/10/18 09:24:46 | 00,801,296 | ---- | M] (CA) [Auto | Running] -- C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe -- (UmxCfg)
SRV - [2007/10/18 09:24:44 | 00,145,936 | ---- | M] (CA) [Auto | Stopped] -- C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe -- (UmxFwHlp)
SRV - [2007/08/20 12:27:26 | 00,144,960 | ---- | M] (Computer Associates International, Inc.) [Auto | Running] -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe -- (CAISafe)
SRV - [2007/08/16 20:10:16 | 00,189,704 | ---- | M] (CA, Inc.) [On_Demand | Running] -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe -- (PPCtlPriv)
SRV - [2007/01/04 11:10:22 | 00,280,080 | ---- | M] (CA, Inc.) [Auto | Running] -- C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe -- (ITMRTSVC)
SRV - [2005/07/20 19:07:00 | 00,127,043 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc)
SRV - [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2001/10/09 16:15:42 | 00,159,806 | ---- | M] (Eastman Kodak Company) [Auto | Running] -- C:\WINDOWS\system32\drivers\dcfssvc.exe -- (Dcfssvc)
SRV - [1999/12/13 03:01:00 | 00,044,032 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\WINDOWS\system32\CTSVCCDA.EXE -- (Creative Service for CDROM Access)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapp...rch/search.html
IE - HKLM\..\URLSearchHook: {D3F669EB-57CE-4f45-8FBD-E245CBB46366} - c:\Program Files\STOPzilla!\Toolbar\SZIESearchHook.dll (iS3 Inc.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{780044d1-e8c0-488f-8059-4522ddbfc2ea}: c:\Program Files\Stopzilla!\Toolbar\Extension [2009/11/03 16:52:14 | 00,000,000 | ---D | M]


O1 HOSTS File: (728 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {09F0F280-FB9A-481B-B69A-CB00DC44D027} - No CLSID value found.
O2 - BHO: (ZILLAbar Browser Helper Object) - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - c:\Program Files\STOPzilla!\Toolbar\SZSG.dll (iS3, Inc)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (STOPzilla Browser Helper Object) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - c:\Program Files\STOPzilla!\SZIEBHO.dll (iS3, Inc.)
O2 - BHO: (no name) - {F2669320-B2D5-7AB9-9F98-990103B4DE36} - No CLSID value found.
O3 - HKLM\..\Toolbar: (&Radio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx ()
O3 - HKLM\..\Toolbar: (STOPzilla) - {98828DED-A591-462F-83BA-D2F62A68B8B8} - c:\Program Files\STOPzilla!\Toolbar\SZSG.dll (iS3, Inc)
O3 - HKLM\..\Toolbar: (no name) - SITEguard - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [abu] C:\WINDOWS\System32\abu.exe ()
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe (CA, Inc.)
O4 - HKLM..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe (CA, Inc.)
O4 - HKLM..\Run: [CAVRID] C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe (CA, Inc.)
O4 - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.)
O4 - HKLM..\Run: [Nikon Transfer Monitor] C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [QOELOADER] C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe (CA)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [MRC] C:\Program Files\MAXpc\MAXpc.exe (iS3)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HPAiODevice(hp psc 900 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 900 series\Bin\hpobrt07.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\David Ristau\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Yahoo! Dictionary - C:\Program Files\Yahoo!\Common [2003/12/09 11:50:28 | 00,000,000 | ---D | M]
O8 - Extra context menu item: Yahoo! Search - C:\Program Files\Yahoo!\Common [2003/12/09 11:50:28 | 00,000,000 | ---D | M]
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm ()
O9 - Extra 'Tools' menuitem : @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm ()
O9 - Extra Button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKCU\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos.walmar...martActivia.cab (Snapfish Activia)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://bin.mcafee.co...81/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://bin.mcafee.co...,19/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {C1C2AC28-5E4B-4228-B7A0-05E986FFCE14} http://www.directplugin.com/tl4000.dll (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx ()
O20 - AppInit_DLLs: (NVDESK32.DLL) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\PFW: DllName - UmxWnp.Dll - C:\WINDOWS\System32\UmxWNP.dll (CA)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/29 15:39:08 | 00,000,034 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/12/28 20:18:22 | 00,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16610528319242240)

========== Files/Folders - Created Within 14 Days ==========

[2009/12/29 19:39:00 | 00,000,000 | ---D | C] -- C:\Documents and Settings\David Ristau\Application Data\Malwarebytes
[2009/12/29 19:38:53 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/12/29 19:38:51 | 00,018,520 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/12/29 19:38:51 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/12/29 19:38:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/12/29 19:37:45 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/12/29 19:36:04 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/12/29 19:27:04 | 00,021,504 | ---- | C] (Doug Knox) -- C:\Documents and Settings\David Ristau\Desktop\SysRestorePoint.exe
[2009/12/28 21:48:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Temp
[2009/12/28 20:33:26 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2009/12/28 20:26:42 | 00,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2009/12/28 20:26:42 | 00,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2009/12/28 20:26:42 | 00,026,624 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw330ext.dll
[2009/12/28 20:25:07 | 00,057,856 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esuimgd.dll
[2009/12/28 20:25:07 | 00,045,056 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esunid.dll
[2009/12/28 20:25:07 | 00,031,744 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esucmd.dll
[2009/12/28 20:24:42 | 00,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2009/12/28 20:14:06 | 00,405,504 | ---- | C] (Macromedia, Inc.) -- C:\WINDOWS\System32\dllcache\swflash.ocx
[2009/12/28 20:11:58 | 00,272,896 | ---- | C] (Cinematronics) -- C:\WINDOWS\System32\dllcache\pinball.exe
[2009/12/28 19:50:43 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups
[2009/12/28 19:40:05 | 00,023,070 | ---- | C] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\System32\drivers\RTL8139.sys
[2009/02/09 05:36:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/02/08 19:26:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2007/02/01 17:56:00 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2005/12/27 22:43:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2005/12/10 23:28:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\BIKE ENC TONS
[2003/12/17 19:12:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2003/11/21 21:23:27 | 00,065,536 | R--- | C] ( ) -- C:\WINDOWS\System32\A3d.dll
[2003/11/21 15:58:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2003/11/21 15:54:55 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft

========== Files - Modified Within 14 Days ==========

[2009/12/29 21:51:59 | 00,001,992 | ---- | M] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2009/12/29 19:53:08 | 00,029,204 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/12/29 19:51:55 | 00,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2009/12/29 19:50:18 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/12/29 19:49:42 | 05,242,880 | ---- | M] () -- C:\Documents and Settings\David Ristau\NTUSER.DAT
[2009/12/29 19:49:41 | 00,084,010 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2009/12/29 19:49:41 | 00,000,064 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2009/12/29 19:49:41 | 00,000,064 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2009/12/29 19:49:41 | 00,000,064 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2009/12/29 19:49:41 | 00,000,064 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2009/12/29 19:49:41 | 00,000,064 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2009/12/29 19:49:41 | 00,000,064 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2009/12/29 19:49:41 | 00,000,064 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2009/12/29 19:49:25 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/12/29 19:49:18 | 00,000,280 | -HS- | M] () -- C:\Documents and Settings\David Ristau\ntuser.ini
[2009/12/29 19:38:56 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/12/29 19:37:00 | 00,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/12/29 19:36:22 | 00,000,767 | ---- | M] () -- C:\Documents and Settings\David Ristau\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/12/29 19:36:05 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\David Ristau\Desktop\NTREGOPT.lnk
[2009/12/29 19:36:05 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\David Ristau\Desktop\ERUNT.lnk
[2009/12/29 19:27:06 | 00,021,504 | ---- | M] (Doug Knox) -- C:\Documents and Settings\David Ristau\Desktop\SysRestorePoint.exe
[2009/12/29 19:21:04 | 00,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/12/29 19:00:00 | 00,000,290 | -H-- | M] () -- C:\WINDOWS\tasks\BDBA23F59425CCF9.job
[2009/12/29 19:00:00 | 00,000,254 | -H-- | M] () -- C:\WINDOWS\tasks\E4A30AD09BCCCF74.job
[2009/12/29 19:00:00 | 00,000,254 | -H-- | M] () -- C:\WINDOWS\tasks\A965F95692F67572.job
[2009/12/29 18:37:08 | 00,001,543 | ---- | M] () -- C:\Documents and Settings\David Ristau\Desktop\Command Prompt.lnk
[2009/12/29 18:09:40 | 00,000,020 | ---- | M] () -- C:\WINDOWS\Hposcv07.INI
[2009/12/29 18:09:30 | 00,000,863 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/12/28 21:55:56 | 00,001,915 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2009/12/28 21:11:14 | 00,002,575 | ---- | M] () -- C:\WINDOWS\Attachmate_Uninstall.MIF
[2009/12/28 21:03:20 | 00,175,616 | ---- | M] () -- C:\Documents and Settings\David Ristau\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/28 20:37:38 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/12/28 20:31:28 | 00,259,048 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/12/28 20:29:19 | 00,000,293 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2009/12/28 20:23:15 | 00,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2009/12/28 20:22:46 | 00,025,065 | ---- | M] () -- C:\WINDOWS\System32\wmpscheme.xml
[2009/12/28 20:22:41 | 00,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2009/12/28 20:22:41 | 00,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2009/12/28 20:22:39 | 00,299,552 | ---- | M] () -- C:\WINDOWS\WMSysPrx.prx
[2009/12/28 20:18:52 | 00,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2009/12/28 20:14:45 | 00,000,488 | RH-- | M] () -- C:\WINDOWS\System32\WindowsLogon.manifest
[2009/12/28 20:14:45 | 00,000,488 | RH-- | M] () -- C:\WINDOWS\System32\logonui.exe.manifest
[2009/12/28 20:14:35 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2009/12/28 20:14:35 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\WindowsShell.Manifest
[2009/12/28 20:14:35 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\sapi.cpl.manifest
[2009/12/28 20:14:35 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\nwc.cpl.manifest
[2009/12/28 20:14:35 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\ncpa.cpl.manifest
[2009/12/28 20:14:35 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\cdplayer.exe.manifest
[2009/12/28 20:13:04 | 00,022,704 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/12/28 20:12:38 | 00,354,232 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/12/28 20:12:38 | 00,311,604 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/12/28 20:12:38 | 00,039,992 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/12/28 20:11:20 | 00,000,211 | -HS- | M] () -- C:\boot.ini
[2009/12/28 19:51:41 | 00,000,588 | ---- | M] () -- C:\WINDOWS\System32\settingsbkup.sfm
[2009/12/28 19:51:41 | 00,000,588 | ---- | M] () -- C:\WINDOWS\System32\settings.sfm
[2009/12/28 19:38:19 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/12/22 21:57:20 | 00,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT

========== Files Created - No Company Name ==========

[2009/12/29 19:54:12 | 00,001,992 | ---- | C] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2009/12/29 19:38:56 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/12/29 19:36:22 | 00,000,767 | ---- | C] () -- C:\Documents and Settings\David Ristau\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/12/29 19:36:05 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\David Ristau\Desktop\NTREGOPT.lnk
[2009/12/29 19:36:05 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\David Ristau\Desktop\ERUNT.lnk
[2009/12/29 18:37:05 | 00,001,543 | ---- | C] () -- C:\Documents and Settings\David Ristau\Desktop\Command Prompt.lnk
[2009/12/28 21:55:56 | 00,001,915 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2009/12/28 20:26:31 | 00,294,975 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2009/12/28 20:25:50 | 01,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2009/12/28 20:25:38 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2009/12/28 20:25:37 | 00,196,662 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2009/12/28 20:25:34 | 00,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2009/12/28 20:25:22 | 13,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2009/12/28 20:25:16 | 00,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2009/12/28 20:25:11 | 00,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll
[2009/12/28 20:24:47 | 00,299,069 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2009/12/28 20:14:45 | 00,000,488 | RH-- | C] () -- C:\WINDOWS\System32\logonui.exe.manifest
[2009/12/28 20:14:35 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2009/12/28 20:14:35 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\WindowsShell.Manifest
[2009/12/28 20:14:35 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\sapi.cpl.manifest
[2009/12/28 20:14:35 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\ncpa.cpl.manifest
[2009/12/28 20:13:56 | 00,348,160 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msinfo.dll
[2009/12/28 20:13:52 | 00,004,639 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.exe
[2009/12/28 19:51:41 | 00,000,588 | ---- | C] () -- C:\WINDOWS\System32\settingsbkup.sfm
[2009/12/28 19:51:41 | 00,000,588 | ---- | C] () -- C:\WINDOWS\System32\settings.sfm
[2009/12/28 19:38:00 | 00,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2009/12/28 19:38:00 | 00,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2009/12/28 19:38:00 | 00,031,136 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT
[2009/12/28 19:38:00 | 00,013,608 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT
[2009/12/28 19:38:00 | 00,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2009/12/28 19:38:00 | 00,010,024 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2009/12/28 19:38:00 | 00,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2009/12/28 19:38:00 | 00,007,100 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2009/12/28 19:38:00 | 00,007,046 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2009/12/28 19:37:59 | 01,761,253 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT
[2009/12/28 19:37:59 | 00,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2009/12/28 19:37:59 | 00,379,415 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2009/11/29 16:14:40 | 00,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\HomePageService
[2009/11/29 16:14:39 | 00,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT
[2009/02/11 18:32:36 | 00,009,088 | -H-- | C] () -- C:\WINDOWS\System32\drivers\CrucialSMBusScan.sys
[2007/03/23 11:56:37 | 00,000,600 | ---- | C] () -- C:\WINDOWS\rtcwgoty.INI
[2007/03/10 09:57:51 | 00,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2007/02/03 12:30:03 | 00,000,044 | ---- | C] () -- C:\WINDOWS\SOF_LOG_.INI
[2007/02/03 12:29:50 | 00,151,040 | ---- | C] () -- C:\WINDOWS\System32\IR32.DLL
[2007/02/03 12:29:50 | 00,077,664 | ---- | C] () -- C:\WINDOWS\System32\IR21_R.DLL
[2006/01/24 18:19:11 | 00,000,287 | ---- | C] () -- C:\WINDOWS\game.ini
[2005/12/03 14:17:29 | 00,053,248 | R--- | C] () -- C:\WINDOWS\System32\P17CPI.dll
[2005/12/03 14:17:26 | 00,060,928 | R--- | C] () -- C:\WINDOWS\System32\P17.dll
[2005/07/20 19:07:00 | 00,540,672 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2004/10/10 19:22:57 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\4169e071.dll
[2004/08/29 15:38:57 | 00,000,000 | ---- | C] () -- C:\WINDOWS\gigen.INI
[2004/08/29 15:27:32 | 00,136,384 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll
[2004/08/08 11:41:32 | 00,548,864 | ---- | C] () -- C:\WINDOWS\System32\SZFrame.dll
[2004/08/08 11:38:18 | 00,217,088 | ---- | C] () -- C:\WINDOWS\System32\IS3MFC.dll
[2004/08/01 15:47:37 | 00,000,012 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\DragToDiscUserNameE.txt
[2004/08/01 15:11:00 | 00,000,020 | ---- | C] () -- C:\WINDOWS\Hposcv07.INI
[2004/04/24 20:15:22 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\hpcoinst.dll
[2004/04/03 21:37:14 | 00,000,175 | ---- | C] () -- C:\WINDOWS\kodakPS.David Ristau.ini
[2004/03/28 20:11:10 | 00,067,428 | ---- | C] () -- C:\WINDOWS\System32\LudaP17.ini
[2004/01/08 17:04:53 | 00,000,432 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2003/12/21 21:16:57 | 00,000,784 | ---- | C] () -- C:\Documents and Settings\David Ristau\Application Data\mpauth.dat
[2003/11/26 00:23:17 | 00,175,616 | ---- | C] () -- C:\Documents and Settings\David Ristau\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2003/11/21 21:22:58 | 00,000,231 | ---- | C] () -- C:\WINDOWS\ac3api.ini
[2003/11/21 21:22:33 | 00,000,186 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2003/11/21 20:58:42 | 00,073,839 | ---- | C] () -- C:\WINDOWS\System32\KodakOneTouch.dll
[2003/11/21 19:15:50 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2003/11/21 16:09:03 | 00,179,007 | ---- | C] () -- C:\WINDOWS\System32\DaConfig.dll
[2003/11/21 16:03:40 | 00,010,368 | ---- | C] () -- C:\WINDOWS\System32\drivers\omci.sys
[2003/03/04 02:29:00 | 00,000,029 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2001/08/18 06:00:00 | 00,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[1997/03/31 23:00:00 | 01,664,272 | ---- | C] () -- C:\WINDOWS\System32\MSO97V.DLL
[1997/03/31 23:00:00 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
[1997/03/31 23:00:00 | 00,016,384 | ---- | C] () -- C:\WINDOWS\System32\MSORFS.DLL

========== LOP Check ==========

[2006/04/17 07:40:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Admin show software plan
[2008/09/24 20:16:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CA
[2009/11/29 16:14:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2009/11/29 16:19:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nikon
[2009/11/29 16:14:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Organs
[2009/09/12 08:38:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SITEguard
[2004/10/02 18:07:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\sizelogointernetextra
[2009/12/30 06:42:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2009/11/29 16:14:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2008/02/11 22:18:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ZILLAbar
[2006/04/17 07:40:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\David Ristau\Application Data\BIKE ENC TONS
[2005/12/10 22:39:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\David Ristau\Application Data\Cake Wait Copy
[2008/09/25 05:38:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\David Ristau\Application Data\Lycos
[2009/12/10 20:42:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\David Ristau\Application Data\Nikon
[2006/11/02 20:51:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\David Ristau\Application Data\Snapfish
[2004/11/14 10:09:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\David Ristau\Application Data\STOPzilla!
[2009/12/29 19:00:00 | 00,000,254 | -H-- | M] () -- C:\WINDOWS\Tasks\A965F95692F67572.job
[2009/12/29 19:00:00 | 00,000,290 | -H-- | M] () -- C:\WINDOWS\Tasks\BDBA23F59425CCF9.job
[2009/11/18 22:06:43 | 00,000,528 | ---- | M] () -- C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as David Ristau at 9 01 PM.job
[2009/12/29 19:00:00 | 00,000,254 | -H-- | M] () -- C:\WINDOWS\Tasks\E4A30AD09BCCCF74.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2001/08/18 06:00:00 | 00,025,472 | ---- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF -- C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2001/08/18 06:00:00 | 00,086,656 | ---- | M] (Microsoft Corporation) MD5=A64013E98426E1877CB653685C5C0009 -- C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2001/08/18 06:00:00 | 00,047,616 | ---- | M] (Microsoft Corporation) MD5=A510B91253544D56B5712D66BE8371E9 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2001/08/18 06:00:00 | 00,047,616 | ---- | M] (Microsoft Corporation) MD5=A510B91253544D56B5712D66BE8371E9 -- C:\WINDOWS\system32\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2001/08/18 06:00:00 | 00,397,824 | ---- | M] (Microsoft Corporation) MD5=F41C1602DC79AB72035F2388FCA0255F -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2001/08/18 06:00:00 | 00,397,824 | ---- | M] (Microsoft Corporation) MD5=F41C1602DC79AB72035F2388FCA0255F -- C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2001/08/18 06:00:00 | 00,174,080 | ---- | M] (Microsoft Corporation) MD5=73968C834C316ADC7A2F07DC4B5F3665 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2001/08/18 06:00:00 | 00,174,080 | ---- | M] (Microsoft Corporation) MD5=73968C834C316ADC7A2F07DC4B5F3665 -- C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
< End of report >

*****end otl.txt ******* end otl.txt *******end otl.txt ************************

I tried to include everything possible in my adventure to destruction. Hopefully I didn't make your efforts to help me more difficult. I think this is all fixable, I just don't have the knowledge base to do so.

Thank you in advance!
Dave.
  • 0

Advertisements


#2
rshaffer61

rshaffer61

    Moderator

  • Moderator
  • 34,114 posts
I suggest you go to the Malware Removal and Spyware Removal Forum and run all the steps located in the
START HERE. These self-help tools will help you clean up 70% of problems on your own.
If you are still having problems after doing the steps, then please post the reguested logs in THAT forum.
If you are unable to run any of the tools then start a new topic in the malware forum and put this in the subject line...I am unable to run any malware tools

If you are still having problems after being given a clean bill of health from the malware expert, then please return to THIS thread and we will pursue other options to help you solve your current problem(s).

Add a link to this topic so that malware tech can see what steps have been taken here
  • 0

#3
tauman

tauman

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
Thanks for getting back to me so quickly. As I stated in my original Post, I have gone to Malware Removal and Spyware Removal Forum. I've downloaded all the recommended tools and ran through all the steps successfully. The logs from running the various downloads are in my original Post.
  • 0

#4
rshaffer61

rshaffer61

    Moderator

  • Moderator
  • 34,114 posts
You are infected, Please follow my instructions and start a new topic in the malware forum and have the techs assist you in completely cleaning your system of infections.
  • 0

#5
tauman

tauman

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
Thank you!
  • 0

#6
rshaffer61

rshaffer61

    Moderator

  • Moderator
  • 34,114 posts
You are welcome. I will follow along and if you are still having a issue when they have gotten you cleaned then return here and we will continue.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP