I am having a few problems with the laptop I am currently using. AVG started giving warnings for trojans, and it deleted some of them. I downloaded Malwarebytes but after the install, it would not launch; it kept searching for exe, and I've had no luck with it, and it is currently uninstalled.
I don't know anything about viruses, but it seems like one had hijacked AVG, or is impersonating it or something, laughs. It will not uninstall and there is no way to stop it from running in the background with ctrl, alt delete. It simply replicates itself when you try to end program.
Below are my OTL logs, and rootkit logs. I have been unable to do MBAM, but hopefully that can be done later with your help.
Thanks alot, Danneroo.
OTL logfile created on: 3/31/2010 6:58:29 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Leslie Caronia\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
255.00 Mb Total Physical Memory | 69.00 Mb Available Physical Memory | 27.00% Memory free
626.00 Mb Paging File | 206.00 Mb Available in Paging File | 33.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.59 Gb Total Space | 1.56 Gb Free Space | 8.37% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: D4QB7Z11
Current User Name: Leslie Caronia
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/03/31 18:54:56 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Leslie Caronia\Desktop\OTL.exe
PRC - [2010/03/18 13:57:15 | 002,046,816 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2010/02/20 03:04:29 | 000,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/08/24 19:09:21 | 000,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/08/24 19:09:10 | 000,693,016 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2009/08/24 19:08:32 | 000,595,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2009/08/24 19:05:58 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2009/08/24 19:04:35 | 000,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2007/06/13 06:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2002/07/11 03:15:20 | 000,270,336 | ---- | M] () -- C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
PRC - [2001/08/06 07:41:48 | 000,028,672 | ---- | M] () -- C:\WINDOWS\Nhksrv.exe
========== Modules (SafeList) ==========
MOD - [2010/03/31 18:54:56 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Leslie Caronia\Desktop\OTL.exe
MOD - [2006/08/25 11:45:55 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2009/08/24 19:05:58 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd)
SRV - [2009/08/24 19:04:35 | 000,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG8\avgemc.exe -- (avg8emc)
SRV - [2001/08/06 07:41:48 | 000,028,672 | ---- | M] () [Auto | Running] -- C:\WINDOWS\Nhksrv.exe -- (Nhksrv)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drs...esearch.cgi?id=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dogpile.com/
IE - HKCU\..\URLSearchHook: *{0026AD90-C86F-4269-97F3-DAB4897C6D06} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Ask"
FF - prefs.js..browser.search.order.1: "Ask"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://start.mozilla...en-US:official"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: avg@igeared:3.011.025.005
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0.464
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..keyword.URL: "http://us.yhs.search...2-tb-web_us&p="
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/12/21 12:40:57 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG8\Toolbar\Firefox\avg@igeared [2009/12/28 12:36:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/03/01 00:09:06 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/03/24 23:20:24 | 000,000,000 | ---D | M]
[2008/09/06 01:17:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Leslie Caronia\Application Data\Mozilla\Extensions
[2010/03/30 22:19:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Leslie Caronia\Application Data\Mozilla\Firefox\Profiles\0n0bnvmz.default\extensions
[2009/11/03 00:05:04 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Leslie Caronia\Application Data\Mozilla\Firefox\Profiles\0n0bnvmz.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/15 20:51:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Leslie Caronia\Application Data\Mozilla\Firefox\Profiles\0n0bnvmz.default\extensions\[email protected]
[2005/03/02 22:58:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Leslie Caronia\Application Data\Mozilla\Firefox\Profiles\0n0bnvmz.default\extensions\temp
[2008/10/08 21:46:31 | 000,000,681 | ---- | M] () -- C:\Documents and Settings\Leslie Caronia\Application Data\Mozilla\Firefox\Profiles\0n0bnvmz.default\searchplugins\ask.xml
[2010/03/30 22:19:39 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2004/11/12 23:36:20 | 000,005,120 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Mozilla Firefox\plugins\NPAdbESD.dll
O1 HOSTS File: ([2004/09/14 23:19:04 | 000,000,734 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IncrediFindBHO Class) - {0026AD90-C86F-4269-97F3-DAB4897C6D06} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL File not found
O2 - BHO: (no name) - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - No CLSID value found.
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {9e91eb99-32b1-4cd9-b747-f10c780f76f3} - File not found
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe ()
O4 - HKLM..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE File not found
O4 - HKLM..\Run: [kigurakel] C:\WINDOWS\System32\ronihuni.DLL File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [resuraluti] File not found
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.micr...922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://codecs.micros...386/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {8522F9B3-0000-0000-0000-000000000000} http://38.144.58.87/sex/xxxmovies.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 71.242.0.12
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O21 - SSODL: bototukeb - {66a68100-37cb-4bcc-a0fa-b20a154009b7} - C:\WINDOWS\System32\ronihuni.dll File not found
O22 - SharedTaskScheduler: {66a68100-37cb-4bcc-a0fa-b20a154009b7} - jugezatag - C:\WINDOWS\System32\ronihuni.dll File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Leslie Caronia\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Leslie Caronia\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O27 - HKLM IFEO\MpCmdRun.exe: Debugger - C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/11/14 19:31:14 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\SYSTEM32\IAS [2002/10/09 19:44:52 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\SYSTEM32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (206158430208)
========== Files/Folders - Created Within 14 Days ==========
[2010/03/31 18:54:46 | 000,555,520 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Leslie Caronia\Desktop\OTL.exe
[2010/03/31 01:32:47 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/03/31 01:32:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/03/31 01:32:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/03/31 01:32:46 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/03/31 01:26:43 | 005,918,768 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Leslie Caronia\Desktop\random.exe
[2010/03/31 01:24:13 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/03/31 01:22:50 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\Leslie Caronia\Desktop\erunt_setup.exe
[2010/03/31 01:09:14 | 000,444,416 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Leslie Caronia\Desktop\TFC.exe
[2010/03/30 11:54:27 | 000,000,000 | --SD | C] -- C:\combo-fix24491c
[2010/03/30 02:07:02 | 000,000,000 | ---D | C] -- C:\cmdcons
[2010/03/30 01:56:47 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/03/30 01:56:46 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/03/30 01:56:46 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/03/30 01:56:46 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/03/30 01:56:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/03/30 01:55:50 | 000,000,000 | --SD | C] -- C:\combo-fix
[2010/03/30 01:52:21 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/03/30 01:32:38 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/30 01:32:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/03/30 01:32:34 | 000,020,824 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/23 11:21:59 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/21 16:55:51 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2010/03/20 18:02:32 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2009/06/26 00:19:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\AVGTOOLBAR
[2008/12/01 20:18:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
========== Files - Modified Within 14 Days ==========
[2099/01/01 12:00:00 | 000,070,656 | -HS- | M] () -- C:\WINDOWS\System32\vomayopu.dll
[2099/01/01 12:00:00 | 000,000,001 | -HS- | M] () -- C:\WINDOWS\System32\dapipobi.dll
[2099/01/01 12:00:00 | 000,000,001 | -HS- | M] () -- C:\WINDOWS\System32\bebotaka.dll
[2010/03/31 18:54:56 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Leslie Caronia\Desktop\OTL.exe
[2010/03/31 18:46:38 | 000,008,736 | ---- | M] () -- C:\WINDOWS\System32\nvModes.001
[2010/03/31 17:20:37 | 058,333,217 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/31 02:00:02 | 000,000,296 | ---- | M] () -- C:\WINDOWS\tasks\domyyall.job
[2010/03/31 01:28:23 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/31 01:27:07 | 005,918,768 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Leslie Caronia\Desktop\random.exe
[2010/03/31 01:24:25 | 000,000,611 | ---- | M] () -- C:\Documents and Settings\Leslie Caronia\Desktop\NTREGOPT.lnk
[2010/03/31 01:24:25 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\Leslie Caronia\Desktop\ERUNT.lnk
[2010/03/31 01:22:56 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\Leslie Caronia\Desktop\erunt_setup.exe
[2010/03/31 01:15:01 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/03/31 01:14:43 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2010/03/31 01:14:34 | 267,440,128 | -HS- | M] () -- C:\hiberfil.sys
[2010/03/31 01:13:13 | 004,194,304 | -H-- | M] () -- C:\Documents and Settings\Leslie Caronia\NTUSER.DAT
[2010/03/31 01:13:13 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Leslie Caronia\NTUSER.INI
[2010/03/31 01:09:18 | 000,444,416 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Leslie Caronia\Desktop\TFC.exe
[2010/03/30 12:17:44 | 000,001,170 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2010/03/30 11:58:56 | 006,291,456 | -H-- | M] () -- C:\Documents and Settings\Leslie Caronia\Local Settings\Application Data\IconCache.db
[2010/03/30 11:44:53 | 003,906,159 | R--- | M] () -- C:\Documents and Settings\Leslie Caronia\Desktop\combo-fix.exe
[2010/03/30 02:08:00 | 000,000,281 | RHS- | M] () -- C:\BOOT.INI
[2010/03/30 00:46:30 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/30 00:45:52 | 000,020,824 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/24 17:08:36 | 000,000,001 | -HS- | M] () -- C:\WINDOWS\System32\vowiwiki.dll
[2010/03/24 16:44:54 | 000,002,713 | -HS- | M] () -- C:\WINDOWS\System32\mutelupo.dll
========== Files Created - No Company Name ==========
[2099/01/01 12:00:00 | 000,070,656 | -HS- | C] () -- C:\WINDOWS\System32\vomayopu.dll
[2099/01/01 12:00:00 | 000,000,001 | -HS- | C] () -- C:\WINDOWS\System32\dapipobi.dll
[2099/01/01 12:00:00 | 000,000,001 | -HS- | C] () -- C:\WINDOWS\System32\bebotaka.dll
[2010/03/31 01:24:25 | 000,000,611 | ---- | C] () -- C:\Documents and Settings\Leslie Caronia\Desktop\NTREGOPT.lnk
[2010/03/31 01:24:25 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\Leslie Caronia\Desktop\ERUNT.lnk
[2010/03/30 11:44:41 | 003,906,159 | R--- | C] () -- C:\Documents and Settings\Leslie Caronia\Desktop\combo-fix.exe
[2010/03/30 02:08:00 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010/03/30 02:07:54 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010/03/30 01:56:47 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/03/30 01:56:46 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/03/30 01:56:46 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/03/30 01:56:46 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/03/30 01:56:46 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/03/30 01:32:45 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/24 17:08:36 | 000,000,001 | -HS- | C] () -- C:\WINDOWS\System32\vowiwiki.dll
[2010/03/24 16:44:54 | 000,002,713 | -HS- | C] () -- C:\WINDOWS\System32\mutelupo.dll
[2010/03/23 23:03:19 | 000,000,296 | ---- | C] () -- C:\WINDOWS\tasks\domyyall.job
[2008/11/23 20:55:49 | 000,000,025 | ---- | C] () -- C:\WINDOWS\System32\sysogg.dll
[2008/10/05 22:22:47 | 000,000,117 | ---- | C] () -- C:\Documents and Settings\Leslie Caronia\Application Data\burnaware.ini
[2008/10/05 21:39:59 | 000,000,205 | ---- | C] () -- C:\Documents and Settings\Leslie Caronia\Application Data\DVD2MobileConfig.ini
[2008/03/01 18:43:06 | 000,004,469 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/10/08 00:30:43 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/03/15 10:52:40 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\Leslie Caronia\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/09/04 22:37:12 | 000,000,360 | ---- | C] () -- C:\WINDOWS\CDToMP3WAVMaker.ini
[2005/09/04 22:35:01 | 000,003,082 | ---- | C] () -- C:\WINDOWS\System32\affv11300p1now.sys
[2005/02/17 22:40:42 | 000,000,027 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2005/02/01 22:37:22 | 000,000,056 | ---- | C] () -- C:\WINDOWS\BRPfX04A.INI
[2005/02/01 22:36:58 | 000,000,087 | ---- | C] () -- C:\WINDOWS\brmx2001.ini
[2005/02/01 22:36:58 | 000,000,084 | ---- | C] () -- C:\WINDOWS\opt_2460.ini
[2005/02/01 22:36:46 | 000,000,480 | ---- | C] () -- C:\WINDOWS\brwmark.ini
[2005/01/13 23:53:41 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Leslie Caronia\Application Data\dm.ini
[2005/01/13 23:53:40 | 000,001,219 | ---- | C] () -- C:\Documents and Settings\Leslie Caronia\Application Data\AdobeDLM.log
[2004/09/25 22:24:48 | 000,000,045 | ---- | C] () -- C:\WINDOWS\IIGDGNN.ini
[2004/07/22 21:14:32 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2004/06/23 23:43:28 | 000,000,661 | ---- | C] () -- C:\WINDOWS\System32\FWNToolbar.dll.manifest
[2004/03/05 12:01:20 | 000,331,776 | ---- | C] () -- C:\WINDOWS\System32\NCTAudioCDRipper2.dll
[2003/08/07 14:01:52 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2003/01/06 17:34:26 | 000,028,672 | ---- | C] () -- C:\WINDOWS\MMKeybd.dll
[2003/01/06 17:34:24 | 000,000,312 | ---- | C] () -- C:\WINDOWS\MMKEYBD.INI
[2003/01/06 17:34:24 | 000,000,269 | ---- | C] () -- C:\WINDOWS\MSIOSD.INI
[2003/01/06 17:34:17 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2002/10/09 21:31:58 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2002/10/09 21:19:33 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2002/10/09 19:51:38 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2001/11/14 20:19:38 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[1999/01/22 14:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2010/03/24 01:47:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/02/26 22:13:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CA
[2004/04/10 15:19:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/11/23 21:48:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/10/08 22:21:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Leslie Caronia\Application Data\Any Video Converter
[2009/02/25 21:36:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Leslie Caronia\Application Data\AVGTOOLBAR
[2010/03/31 02:00:02 | 000,000,296 | ---- | M] () -- C:\WINDOWS\Tasks\domyyall.job
[2002/10/17 03:36:49 | 000,000,258 | ---- | M] () -- C:\WINDOWS\Tasks\ISP signup reminder 1.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2006/09/21 22:23:09 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp2.cab:AGP440.sys
[2006/09/21 22:23:09 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\agp440.sys
[2004/08/04 02:07:41 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2004/08/04 02:07:41 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\SYSTEM32\DRIVERS\agp440.sys
[2001/08/17 01:58:00 | 000,025,472 | ---- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF -- C:\I386\AGP440.SYS
[2001/08/17 01:58:00 | 000,025,472 | ---- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2001/08/17 01:58:00 | 000,025,472 | ---- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF -- C:\WINDOWS\SYSTEM32\ReinstallBackups\0003\DriverFiles\i386\AGP440.SYS
[2001/08/17 01:58:00 | 000,025,472 | ---- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF -- C:\WINDOWS\SYSTEM32\ReinstallBackups\0017\DriverFiles\i386\AGP440.SYS
< MD5 for: ATAPI.SYS >
[2006/09/21 22:23:09 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp2.cab:atapi.sys
[2006/09/21 22:23:09 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2002/01/30 02:49:08 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=48BC2767CEEC6E8B0E15B0289F18232E -- C:\I386\atapi.sys
[2002/01/30 02:49:08 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=48BC2767CEEC6E8B0E15B0289F18232E -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\atapi.sys
[2004/08/04 01:59:42 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2004/08/04 01:59:42 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\SYSTEM32\DRIVERS\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\eventlog.dll
[2004/08/04 03:56:42 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2004/08/04 03:56:42 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\SYSTEM32\eventlog.dll
[2001/08/17 18:00:00 | 000,047,616 | ---- | M] (Microsoft Corporation) MD5=A510B91253544D56B5712D66BE8371E9 -- C:\I386\EVENTLOG.DLL
[2001/08/17 18:00:00 | 000,047,616 | ---- | M] (Microsoft Corporation) MD5=A510B91253544D56B5712D66BE8371E9 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/04 03:56:44 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2004/08/04 03:56:44 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\SYSTEM32\netlogon.dll
[2001/08/17 18:00:00 | 000,397,824 | ---- | M] (Microsoft Corporation) MD5=F41C1602DC79AB72035F2388FCA0255F -- C:\I386\NETLOGON.DLL
[2001/08/17 18:00:00 | 000,397,824 | ---- | M] (Microsoft Corporation) MD5=F41C1602DC79AB72035F2388FCA0255F -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 03:56:44 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2004/08/04 03:56:44 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\SYSTEM32\scecli.dll
[2001/08/17 18:00:00 | 000,174,080 | ---- | M] (Microsoft Corporation) MD5=73968C834C316ADC7A2F07DC4B5F3665 -- C:\I386\SCECLI.DLL
[2001/08/17 18:00:00 | 000,174,080 | ---- | M] (Microsoft Corporation) MD5=73968C834C316ADC7A2F07DC4B5F3665 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2001/11/14 19:22:22 | 000,090,112 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2001/11/14 19:22:22 | 000,606,208 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2001/11/14 19:22:22 | 000,380,928 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV
< End of report >
OTL Extras logfile created on: 3/31/2010 6:58:29 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Leslie Caronia\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
255.00 Mb Total Physical Memory | 69.00 Mb Available Physical Memory | 27.00% Memory free
626.00 Mb Paging File | 206.00 Mb Available in Paging File | 33.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.59 Gb Total Space | 1.56 Gb Free Space | 8.37% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: D4QB7Z11
Current User Name: Leslie Caronia
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 File not found
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- File not found
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Explorer -- (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Professional
"{01001202-823E-46CD-A70E-BEE818F97169}" = Microsoft Encarta Encyclopedia Standard 2002
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java 6 Update 17
"{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{44A537A5-859C-43A6-8285-C0668142A090}" = iPod for Windows 2005-03-23
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{91E8A85F-2960-40ED-BA84-7F4567BB00C0}" = Dell | Support
"{A1B7B9B3-E1D2-41CA-9B4A-F18DC2710704}" = Microsoft Works 6.0
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{BD3DCAB0-3FE5-44FB-90DA-EFB0A2CD1387}" = Works Synchronization
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3A439E4-7303-491F-A678-CEA36A87D517}" = Microsoft Works Suite Add-in for Microsoft Word
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DC19E750-988B-4005-A355-85EF66055EFE}" = Works Suite OS Pack
"{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F958CA02-BB40-4007-894B-258729456EE4}" = QuickTime
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AdobeESD" = Adobe Download Manager 2.0 (Remove Only)
"AVG8Uninstall" = AVG Free 8.5
"CNXT_MODEM_PCI_VEN_8086&DEV_2486&SUBSYS_542114F1" = Actiontec MD56ORD V92 MDC Modem
"ERUNT_is1" = ERUNT 1.1j
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{44A537A5-859C-43A6-8285-C0668142A090}" = iPod for Windows 2005-03-23
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MicroGrade 6.1.0" = MicroGrade 6.1.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.8)" = Mozilla Firefox (3.5.8)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"RealPlayer 6.0" = RealPlayer Basic
"Shockwave" = Shockwave
"WIC" = Windows Imaging Component
"Windows XP Service Pack" = Windows XP Service Pack 2
"Works2002Setup" = Microsoft Works 2002 Setup Launcher
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"bddd472159704f26" = macProVideo.com NED Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 3/1/2010 5:42:31 PM | Computer Name = D4QB7Z11 | Source = ESENT | ID = 489
Description = wuauclt (1272) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).
Error - 3/1/2010 5:42:31 PM | Computer Name = D4QB7Z11 | Source = ESENT | ID = 455
Description = wuaueng.dll (1272) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
Error - 3/1/2010 5:42:41 PM | Computer Name = D4QB7Z11 | Source = ESENT | ID = 489
Description = wuauclt (1272) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).
Error - 3/1/2010 5:42:41 PM | Computer Name = D4QB7Z11 | Source = ESENT | ID = 455
Description = wuaueng.dll (1272) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
Error - 3/11/2010 9:35:47 PM | Computer Name = D4QB7Z11 | Source = Application Hang | ID = 1002
Description = Hanging application avgtray.exe, version 8.5.0.427, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 3/24/2010 12:10:18 AM | Computer Name = D4QB7Z11 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16981, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/24/2010 4:42:07 PM | Computer Name = D4QB7Z11 | Source = Application Hang | ID = 1002
Description = Hanging application avgtray.exe, version 8.5.0.437, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 3/24/2010 5:22:25 PM | Computer Name = D4QB7Z11 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16981, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/24/2010 5:22:30 PM | Computer Name = D4QB7Z11 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16981, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/24/2010 5:22:30 PM | Computer Name = D4QB7Z11 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16981, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 3/30/2010 1:37:16 PM | Computer Name = D4QB7Z11 | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 00022D608F30. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 3/31/2010 1:10:35 AM | Computer Name = D4QB7Z11 | Source = Service Control Manager | ID = 7034
Description = The Netropa NHK Server service terminated unexpectedly. It has done
this 1 time(s).
Error - 3/31/2010 1:10:35 AM | Computer Name = D4QB7Z11 | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.
Error - 3/31/2010 1:10:35 AM | Computer Name = D4QB7Z11 | Source = Service Control Manager | ID = 7031
Description = The AVG Free8 WatchDog service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 0 milliseconds:
Restart the service.
Error - 3/31/2010 1:10:35 AM | Computer Name = D4QB7Z11 | Source = Service Control Manager | ID = 7034
Description = The Bonjour Service service terminated unexpectedly. It has done
this 1 time(s).
Error - 3/31/2010 1:10:35 AM | Computer Name = D4QB7Z11 | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).
Error - 3/31/2010 1:10:35 AM | Computer Name = D4QB7Z11 | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Driver Helper Service service terminated unexpectedly.
It has done this 1 time(s).
Error - 3/31/2010 1:10:35 AM | Computer Name = D4QB7Z11 | Source = Service Control Manager | ID = 7034
Description = The AVG Free8 E-mail Scanner service terminated unexpectedly. It
has done this 1 time(s).
Error - 3/31/2010 1:10:57 AM | Computer Name = D4QB7Z11 | Source = Service Control Manager | ID = 7034
Description = The iPod Service service terminated unexpectedly. It has done this
1 time(s).
Error - 3/31/2010 7:22:43 PM | Computer Name = D4QB7Z11 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
< End of report >
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-04 01:20:50
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\LESLIE~1\LOCALS~1\Temp\uwtoapog.sys
---- System - GMER 1.0.15 ----
INT 0x37 ? FDD48724
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Processes - GMER 1.0.15 ----
Library C:\WINDOWS\system32\bezogebu.dll (*** hidden *** ) @ C:\DOCUME~1\LESLIE~1\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe [136] 0x00C00000
Library C:\WINDOWS\system32\bezogebu.dll (*** hidden *** ) @ C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe [1160] 0x00C50000
Library C:\WINDOWS\system32\bezogebu.dll (*** hidden *** ) @ C:\Program Files\Dell\Support\Alert\bin\DAMon.exe [1500] 0x01210000
Library C:\WINDOWS\system32\bezogebu.dll (*** hidden *** ) @ C:\WINDOWS\Explorer.EXE [1592] 0x10000000
Library C:\WINDOWS\system32\bezogebu.dll (*** hidden *** ) @ C:\Program Files\iTunes\iTunesHelper.exe [1788] 0x00E80000
Library C:\WINDOWS\system32\bezogebu.dll (*** hidden *** ) @ C:\PROGRA~1\AVG\AVG8\avgtray.exe [1792] 0x10000000
Library C:\WINDOWS\system32\bezogebu.dll (*** hidden *** ) @ C:\WINDOWS\system32\dwwin.exe [2008] 0x00D70000
Library C:\WINDOWS\system32\bezogebu.dll (*** hidden *** ) @ C:\WINDOWS\system32\ctfmon.exe [2016] 0x10000000
Library C:\WINDOWS\system32\bezogebu.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\IEXPLORE.EXE [2240] 0x00C80000
Library C:\WINDOWS\system32\bezogebu.dll (*** hidden *** ) @ C:\Program Files\Mozilla Firefox\firefox.exe [3392] 0x012A0000
Library C:\WINDOWS\system32\bezogebu.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\IEXPLORE.EXE [3852] 0x10000000
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@LoadAppInit_DLLs 1
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\SYSTEM32\loyiroge.dll 70656 bytes
File C:\WINDOWS\SYSTEM32\riwapoko 6456 bytes
File C:\WINDOWS\SYSTEM32\bezogebu.dll 70656 bytes
File C:\WINDOWS\SYSTEM32\yaruyava.dll 70656 bytes
---- EOF - GMER 1.0.15 ----