Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

1351.

Solve : Is this to much protection?

Answer»

Hello i was wondering if this is to much protection and if having all of these could give less protection
I have

eusing free registry cleaner
malwarebytes antimalwar
ccleaner
superantispyware free edidtion
avira antivirus
hijack this
spybot
smart defrag 1.20
tweak cleaner

I heard that having two anti virus protections probably wouldn't hurt
if you only have ONE for live protection and use the others for just scanning

is having two or more registry cleaners are malware removers good for a computer are it bad for a computer i ran a registry cleaner and i found that i had to pay for it to fix most of the registrys it would only fix 15 it seemed to be the best registry program by the reviews i read online that it found more registry errors than the others so i thought i would try a couple others to get rid of most of the errors and i would use the other one to fix what was ever left over but it wasn't under 15 erros like i thought it would be  i think it was at are near what it said before like 300
but the other two got rid of like 350 why didn't the other registry detect
these.If I were you I'd get rid of the registry cleaners and spybot and I would ADD Spyware Blaster (for passive protection).

In other words, keep Avira, MalwareBytes, ccleaner (optional) & add spyware blaster. Don't care about your defragger.i agree with alan in a few things , keep

avira                     
ccleaner             use once a week
malwarebytes      ..    ..     ..     ..
superanti...          ..    ..     ..     ..

and i would keep smart defrag and use once a month or so
Hello James. The only full time protections you now have are Avira Anti-virus and Spybot S&D. All the others are just for scanning UNLESS you have the paid for versions. It won't hurt if you use another AV for scanning only. Just make you are not running both. You would be wise to install SpywareBlaster.Sorry if you guys frown on this tagging on, but l was interested in James's post and the replies, especially from Allen, and then Harry.
My list is not so large, ie -

Avast
SAS (paid)
MBAM
CCleaner
Auslogics Defrag
 
Downloaded SpywareBlaster just to see what it's all about, and it seems pretty good, and l QUITE like it. However, the question is -
I used to use Spybot, who's database is updated every Wednesday.
Have now downloaded Spyware Blaster, and the last available database update seems to be 23rd Sept.
So, why is SWB supposedly better than SPYBOT if its' database isn't as up to date as that of Spybot?
Thanks

for the "sheer *censored* of it" and found it a lot betternot all protection is updated every week i check them all and MAY only get 2 that need itthe database doesn't need to be as recently updated if  the program uses more accurate heuristics.Spyware Blaster is passive protection (it makes entries in the reigstry) - Spybot is active (RESIDENT or for scanning). And anyway, Spybot is now considered passe - the current best of breed are MalwareBytes & Super Antispyware.

1352.

Solve : Microsoft's Free Anti Virus Suite Arriving Soon?

Answer» http://www.pcpro.co.uk/news/security/351739/microsofts-free-antivirus-suite-arriving-in-weeksI hope it works better than that crappy one care they made.Personally I'll stick with Kaspersky. While I know there are some fine free AV utilities, I've always FELT that VIRUS PROTECTION is not something to buy based on cost.
1353.

Solve : AuthUpdater message...what is it??

Answer»

I also had this pop up SAYING "AuthUpdater has encountered a problem and needs to CLOSE."  It created an error report and happened approximately every 30 seconds or so.  I DISCOVERED that it is a problem with Bigpond Security.  You need to call 133 933 and they will talk you through uninstalling the software and REINSTALLING it again.  You will need your Activation code, but don't worry if you don't have it anymore as they will read it back out to you.

1354.

Solve : an unhandled win32 exception occurred in svchost.exe?

Answer»

currently i m using XP professional OS version 2002  (SP2).
while i m connecting to my internet, its working for 5mins (few mins).
then all pages displaying error. and after few mins its showing the following errors one by one...

an unhandled win32 exception occurred in svchost.exe[900]
an unhandled win32 exception occurred in svchost.exe[884]
an unhandled win32 exception occurred in svchost.exe[812]

 whn i try to play my audio its throwing an error "bad directsound driver. please install proper drivers or select another device in configuration.error code: 88780078"...

i used dds software (provided in this forum) and attached my files. plz do the needful ASAP

- karan

[attachment deleted by admin]try update your windows dude..oh my god. i have only one XP OS CD.... there is no way to escape from this problem? need to re-install or update it? i have only very less usage for my internet... :-( now other go? plz guide meI can see some temp viruses.
Please download TFC By Old Timer

  • Save any unsaved work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program
  • If prompted, click "Yes" to reboot.
Quote from: cat-bomb on October 02, 2009, 02:33:16 PM
I can see some temp viruses.
Please download TFC By Old Timer
  • Save any unsaved work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program
  • If prompted, click "Yes" to reboot.

cat-bomb , you should not be giving advice you are not a malware expert


karan_21584 , if you have 2 anti-virus in your pc please remove 1 of them

i checked your logs and you seem to have a lot of threats BUT you need an expert to help youi have only one anti virus... NAV. i removed nav and processed. the same problem occur. again i installed avg ANTIVIRUS. again the same problem remains. while i m shut-down the machine "umdmgr.exe" is occuring many times. if i give "end now" then only the SYSTEM gettin shutdown or restart. is that major problem? help me plz. moreover if i click the any page link (mozilla browser) for 10-15 times, the page getting loaded (that too rare case). help mehttp://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039/

you must have had norton in your pc at one time use this to clean it out

you will have to wait for an expert i can do a little to help but do not want to HARM your pc , harryHello Karan, My name is Superdave but you can just CALL me SD. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your replies. The first thing I will need you to do is to go to this link and follow the directions precisely. If you can't access the internet with your infected computer you will have to download and transfer any PROGRAMS to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line. If you can't run any step, just jump to the next one. Please let me know how you are doing or have any questions. Initially, I will need the SuperAntiSpyware, MBAM and HJT logs. Please copy and paste any logs that you can generate.nice to see you on board superdave
1355.

Solve : What is proxy server?

Answer»

This poped up what is it and is it anything to worry about

[attachment deleted by admin]I'm guessing you did not installed a proxy server or you forgot that you installed one.

Try asking around your family/room mates if they used your computer and installed a proxy server. If they did not try following the steps here.
].Actually, this isn't related to a "proxy server" but rather a "proxy desktop".

This thread here has a few suggestions; and a few members appear to have been SUCCESSFUL with them.

http://www.outpostfirewall.com/forum/showthread.php?t=6212this happend the day after i uninstalled my superanti spyware could this be why

And nobody else uses my computer I use a password and make sure my i'm log off everytime i'm not around but I do have a guest account
and no i didn't download this i never heard of this

and i run all those logs regularly I just did the logs two days and posted themI found this from here: http://www.outpostfirewall.com/forum/showthread.php?t=6212

Quote

The proxy desktop is related to windows Explorer freezing. If you open Task Manager you should see multiple instances of Explorer.exe. Ending the processes in Task Manager should stop the error message.

There's a rather OBFUSCATED explanation at MSDN, under remarks.

In addition, please untick- Windows Explorer >Tools > FOLDER Options > View > Launch folder windows in a separate PROCESS - and see if that helps. Having this on is supposed to increase system stability by opening each folder in a separate part of memory. But sometimes performance takes a hit and may be related to this problem. Experiment!
1356.

Solve : malware and viruses?

Answer»

Yesterday my computer all of a sudden restarted and was then stuck in a restart loop. It went to the option to use safe mode so i selected the option to use the last known working settings which fixed the restart loop. After that i tried to scan for viruses/malware/spyware with spybot and malwarebytes neither of which will work. malwarebytes will start scan for about 2-5 seconds then closes and when i try to open it it tells me i dont have permissions. spybot tells me that spybotsd.exe is read only and wont install or run. i used combofix to create a log which is here:


ComboFix 09-09-30.01 - Charissa 09/30/2009 17:48.1.2 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.1022.592 [GMT -7:00]
Running from: c:\documents and settings\Charissa\My Documents\Downloads\ComboFix.exe
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\17065314
c:\documents and settings\All Users\Application Data\17065314\17065314
c:\documents and settings\All Users\Application Data\17065314\17065314.exe
c:\documents and settings\All Users\Application Data\17065314\pc17065314ins
c:\program files\Adware Professional
c:\program files\Adware Professional\noadware4_092909.na
c:\windows\Installer\617438.msi
c:\windows\system32\drivers\gasfkyexmyeoqd.sys
c:\windows\system32\gasfkyesmusiwu.dat
c:\windows\system32\gasfkyjxomtivp.dll
c:\windows\system32\gasfkykaliubyb.dat
c:\windows\system32\gasfkymlgiyuht.dll
c:\windows\system32\gasfkywptevrxm.dat
c:\windows\system32\gasfkyxnbevmet.dll
c:\windows\system32\gasfkyxvbuyamd.dll

Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\eventlog.dll

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}


(((((((((((((((((((((((((   Files Created from 2009-09-01 to 2009-10-01  )))))))))))))))))))))))))))))))
.

2009-10-01 00:38 . 2008-05-30 08:06   34296   ----a-w-   c:\windows\system32\drivers\mbamcatchme.sys
2009-09-30 21:47 . 2009-09-30 21:47   --------   d-----w-   C:\WTablet
2009-09-30 21:12 . 2009-09-10 21:54   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-30 11:17 . 2009-09-30 11:17   --------   dc-h--w-   c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-09-30 11:10 . 2009-10-01 00:37   --------   d-----w-   c:\program files\Spybot - Search & Destroy
2009-09-30 11:10 . 2009-10-01 00:34   --------   d-----w-   c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-30 10:45 . 2008-12-11 15:38   159600   ----a-w-   c:\windows\system32\drivers\pctgntdi.sys
2009-09-30 10:44 . 2009-08-24 21:05   206256   ----a-w-   c:\windows\system32\drivers\PCTCore.sys
2009-09-30 10:44 . 2009-08-19 18:01   86888   ----a-w-   c:\windows\system32\drivers\PCTAppEvent.sys
2009-09-30 10:43 . 2009-09-30 10:48   --------   d-----w-   c:\program files\Common Files\PC Tools
2009-09-30 10:43 . 2008-12-10 18:36   64392   ----a-w-   c:\windows\system32\drivers\pctplsg.sys
2009-09-30 10:42 . 2009-09-30 10:42   --------   d-----w-   c:\documents and settings\Charissa\Application Data\PC Tools
2009-09-30 10:42 . 2009-09-30 10:42   --------   d-----w-   c:\documents and settings\All Users\Application Data\PC Tools
2009-09-30 10:40 . 2009-10-01 00:35   --------   d---a-w-   c:\documents and settings\All Users\Application Data\TEMP
2009-09-30 09:54 . 2009-09-30 09:54   --------   d-----w-   c:\documents and settings\Charissa\Application Data\Malwarebytes
2009-09-30 09:54 . 2009-09-30 09:54   --------   d-----w-   c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-30 09:54 . 2009-10-01 00:38   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2009-09-30 09:54 . 2008-05-30 08:06   15864   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-09-30 08:56 . 2009-09-30 08:56   --------   d-----w-   c:\program files\InterVideo Information Service
2009-09-30 08:56 . 2009-09-30 08:56   --------   d-----w-   c:\program files\Common Files\Ulead
2009-09-30 08:55 . 2009-09-30 08:55   --------   d-----w-   c:\documents and settings\All Users\Application Data\InstallShield
2009-09-30 08:50 . 2008-05-30 21:18   238088   ----a-w-   c:\windows\system32\xactengine3_1.dll
2009-09-30 08:39 . 2009-09-30 09:07   --------   d--h--w-   c:\windows\msdownld.tmp
2009-09-30 07:04 . 2009-09-30 23:56   0   ----a-r-   c:\windows\win32k.sys
2009-09-30 01:37 . 2009-09-30 01:36   411368   ----a-w-   c:\windows\system32\deploytk.dll
2009-09-30 01:34 . 2009-09-30 01:34   152576   ----a-w-   c:\documents and settings\Charissa\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2009-09-28 08:24 . 2009-09-28 08:24   127872   ----a-w-   c:\documents and settings\Charissa\Application Data\Move Networks\uninstall.exe
2009-09-28 08:24 . 2009-09-28 08:24   --------   d-----w-   c:\documents and settings\Charissa\Application Data\Move Networks
2009-09-28 05:12 . 2009-09-28 05:12   --------   d-----w-   c:\documents and settings\LocalService\Application Data\WTablet
2009-09-23 20:22 . 2009-09-23 20:22   --------   d-----w-   c:\program files\iPod
2009-09-23 20:21 . 2009-09-23 20:23   --------   d-----w-   c:\program files\iTunes
2009-09-22 10:18 . 2009-09-22 10:18   --------   d-----w-   c:\program files\Veoh Networks
2009-09-16 18:42 . 2009-09-16 18:44   --------   d-----w-   c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-16 18:39 . 2009-09-16 18:40   --------   d-----w-   c:\program files\QuickTime
2009-09-15 00:02 . 2009-09-15 00:02   8704   ----a-w-   c:\documents and settings\Charissa\Application Data\Thinstall\Visual Thesaurus 3.0.2\400000c00003i\java.exe
2009-09-15 00:02 . 2009-09-15 00:02   --------   d-----w-   c:\documents and settings\Charissa\Application Data\Thinstall
2009-09-14 03:49 . 2009-09-14 03:49   --------   d-----w-   c:\program files\Black Isle
2009-09-14 01:12 . 2009-09-14 01:12   --------   d-----w-   c:\documents and settings\Charissa\Application Data\EPSON
2009-09-13 06:58 . 2009-09-28 05:14   --------   d-----w-   c:\program files\RapidBIT
2009-09-13 06:29 . 2009-09-13 06:29   --------   d-----w-   c:\documents and settings\Charissa\Application Data\dvdcss
2009-09-13 06:24 . 2008-05-06 06:01   45056   ----a-w-   c:\windows\system32\WNASPI32.DLL
2009-09-13 06:24 . 2008-05-06 06:01   16512   ----a-w-   c:\windows\system32\drivers\ASPI32.SYS
2009-09-13 06:23 . 2009-09-13 07:01   --------   d-----w-   c:\program files\ImTOO
2009-09-10 05:28 . 2009-09-10 05:28   --------   d-sh--w-   c:\documents and settings\Charissa\IECompatCache
2009-09-03 02:39 . 2009-10-01 00:55   --------   d-----w-   c:\documents and settings\Charissa\Application Data\WTablet
2009-09-03 02:38 . 2004-08-04 07:56   21504   -c--a-w-   c:\windows\system32\dllcache\hidserv.dll
2009-09-03 02:38 . 2004-08-04 07:56   21504   ----a-w-   c:\windows\system32\hidserv.dll
2009-09-03 02:38 . 2004-08-04 05:58   14848   -c--a-w-   c:\windows\system32\dllcache\kbdhid.sys
2009-09-03 02:38 . 2004-08-04 05:58   14848   ----a-w-   c:\windows\system32\drivers\kbdhid.sys
2009-09-03 02:38 . 2007-02-16 00:11   11440   ----a-w-   c:\windows\system32\drivers\WacomVKHid.sys
2009-09-03 02:38 . 2007-02-16 19:12   11312   ----a-w-   c:\windows\system32\drivers\wacommousefilter.sys
2009-09-03 02:38 . 2007-02-16 18:30   12848   ----a-w-   c:\windows\system32\drivers\wacomvhid.sys
2009-09-03 02:37 . 2009-09-03 02:37   --------   d-----w-   c:\windows\system32\WTablet
2009-09-03 02:37 . 2007-09-07 18:09   128296   ------w-   c:\windows\system32\Pen_Tablet.dll
2009-09-03 02:37 . 2007-09-07 17:55   181544   ------w-   c:\windows\system32\Wintab32.dll
2009-09-03 02:37 . 2007-09-07 18:16   1373480   ------w-   c:\windows\system32\Pen_Tablet.exe
2009-09-03 02:37 . 2009-09-03 02:38   --------   d-----w-   c:\program files\Tablet

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-01 00:55 . 2009-06-27 22:05   --------   d-----w-   c:\program files\DNA
2009-10-01 00:55 . 2009-06-27 22:05   --------   d-----w-   c:\documents and settings\Charissa\Application Data\DNA
2009-10-01 00:54 . 2009-06-18 06:02   0   ----a-w-   c:\windows\system32\drivers\lvuvc.hs
2009-10-01 00:54 . 2009-06-18 06:00   0   ----a-w-   c:\windows\system32\drivers\logiflt.iad
2009-09-30 21:47 . 2009-06-13 07:39   74096   ----a-w-   c:\documents and settings\Charissa\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-30 21:12 . 2009-06-13 07:33   --------   d--h--w-   c:\program files\InstallShield Installation Information
2009-09-30 08:58 . 2009-06-27 22:06   --------   d-----w-   c:\documents and settings\Charissa\Application Data\BitTorrent
2009-09-30 08:57 . 2009-06-17 00:23   --------   d-----w-   c:\documents and settings\All Users\Application Data\Apple Computer
2009-09-30 08:53 . 2009-06-13 07:32   --------   d-----w-   c:\program files\Common Files\InstallShield
2009-09-30 08:06 . 2009-06-17 06:40   --------   d-----w-   c:\documents and settings\Charissa\Application Data\Skype
2009-09-30 06:32 . 2009-06-17 06:41   --------   d-----w-   c:\documents and settings\Charissa\Application Data\skypePM
2009-09-30 01:36 . 2009-06-13 07:18   --------   d-----w-   c:\program files\Java
2009-09-28 08:24 . 2009-06-16 06:35   4183416   ----a-w-   c:\documents and settings\Charissa\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-09-24 18:40 . 2009-06-17 00:24   --------   d-----w-   c:\documents and settings\Charissa\Application Data\Apple Computer
2009-09-23 20:22 . 2009-06-17 00:23   --------   d-----w-   c:\program files\Common Files\Apple
2009-09-16 19:47 . 2009-08-26 06:12   --------   d-----w-   c:\program files\Diablo II
2009-09-16 19:47 . 2009-08-26 06:27   21840   ----atw-   c:\windows\system32\SIntfNT.dll
2009-09-16 19:47 . 2009-08-26 06:27   17212   ----atw-   c:\windows\system32\SIntf32.dll
2009-09-16 19:47 . 2009-08-26 06:27   12067   ----atw-   c:\windows\system32\SIntf16.dll
2009-09-10 01:56 . 2009-08-28 13:18   --------   d-----w-   c:\program files\RootsMagic
2009-09-05 00:44 . 2009-09-30 08:51   515416   ----a-w-   c:\windows\system32\XAudio2_5.dll
2009-09-05 00:44 . 2009-09-30 08:51   238936   ----a-w-   c:\windows\system32\xactengine3_5.dll
2009-09-05 00:29 . 2009-09-30 08:51   235344   ----a-w-   c:\windows\system32\d3dx11_42.dll
2009-09-05 00:29 . 2009-09-30 08:51   453456   ----a-w-   c:\windows\system32\d3dx10_42.dll
2009-09-05 00:29 . 2009-09-30 08:51   1974616   ----a-w-   c:\windows\system32\D3DCompiler_42.dll
2009-09-05 00:29 . 2009-09-30 08:51   5501792   ----a-w-   c:\windows\system32\d3dcsx_42.dll
2009-09-05 00:29 . 2009-09-30 08:51   1892184   ----a-w-   c:\windows\system32\D3DX9_42.dll
2009-09-03 04:19 . 2009-09-03 04:19   --------   d-----w-   c:\documents and settings\Charissa\Application Data\InstallShield
2009-09-03 04:19 . 2009-09-03 04:16   --------   d-----w-   c:\program files\epson
2009-08-31 09:31 . 2009-08-31 09:15   --------   d-----w-   c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-31 09:28 . 2009-08-31 09:28   --------   d-----w-   c:\program files\Microsoft Works
2009-08-31 09:28 . 2009-08-31 09:28   --------   d-----w-   c:\program files\MSBuild
2009-08-31 09:24 . 2009-08-31 09:24   --------   d-----w-   c:\program files\Microsoft.NET
2009-08-31 09:20 . 2009-08-31 09:20   --------   d-----w-   c:\program files\Microsoft Visual Studio 8
2009-08-31 09:08 . 2009-07-05 21:59   --------   d-----w-   c:\program files\RoughDraft
2009-08-29 06:08 . 2009-08-29 06:08   --------   d-----w-   c:\documents and settings\All Users\Application Data\FLEXnet
2009-08-29 05:52 . 2009-08-27 04:09   --------   d-----w-   c:\program files\DAEMON Tools Lite
2009-08-29 05:41 . 2009-06-22 18:38   --------   d-----w-   c:\program files\Common Files\Adobe
2009-08-29 05:34 . 2009-08-29 05:34   --------   d-----w-   c:\program files\Common Files\Macrovision Shared
2009-08-28 20:32 . 2009-08-28 13:18   --------   d-----w-   c:\documents and settings\Charissa\Application Data\RootsMagic
2009-08-28 20:32 . 2009-08-28 13:18   --------   d-----w-   c:\documents and settings\All Users\Application Data\RootsMagic
2009-08-28 14:12 . 2009-08-28 14:12   --------   d-----w-   c:\program files\Common Files\RootsMagic Shared
2009-08-28 14:12 . 2009-08-28 14:12   --------   d-----w-   c:\program files\RootsMagic 4
2009-08-28 13:17 . 2009-08-27 01:14   --------   d-----w-   c:\documents and settings\Charissa\Application Data\DAEMON Tools Lite
2009-08-27 04:16 . 2009-08-26 06:18   34587   ----a-w-   c:\windows\DIIUnin.dat
2009-08-27 04:12 . 2009-08-27 04:12   --------   d-----w-   c:\documents and settings\Charissa\Application Data\DAEMON Tools Pro
2009-08-27 04:09 . 2009-08-27 04:09   --------   d-----w-   c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-08-27 04:09 . 2009-08-27 04:09   --------   d-----w-   c:\program files\DAEMON Tools Toolbar
2009-08-27 01:14 . 2009-08-27 01:14   721904   ----a-w-   c:\windows\system32\drivers\sptd.sys
2009-08-26 22:40 . 2009-08-26 22:39   --------   d-----w-   c:\program files\ATT-PRT22-WISE
2009-08-26 22:40 . 2009-08-26 22:40   --------   d-----w-   c:\program files\att-prt22
2009-08-26 22:40 . 2009-08-26 22:39   --------   d-----w-   c:\program files\Common Files\Motive
2009-08-26 22:40 . 2009-08-26 22:40   --------   d-----w-   c:\documents and settings\All Users\Application Data\Motive
2009-08-26 09:01 . 2009-08-26 09:01   --------   d-----w-   c:\documents and settings\Charissa\Application Data\MSN6
2009-08-26 09:01 . 2009-08-26 09:01   --------   d-----w-   c:\documents and settings\All Users\Application Data\MSN6
2009-08-26 06:18 . 2009-08-26 06:18   94208   ----a-w-   c:\windows\DIIUnin.exe
2009-08-26 06:18 . 2009-08-26 06:18   2829   ----a-w-   c:\windows\DIIUnin.pif
2009-08-26 05:53 . 2009-08-25 05:02   --------   d-----w-   c:\documents and settings\Charissa\Application Data\Ahead
2009-08-25 05:02 . 2009-08-25 05:00   --------   d-----w-   c:\program files\Common Files\Ahead
2009-08-25 05:00 . 2009-08-25 05:00   --------   d-----w-   c:\program files\Nero
2009-08-24 11:31 . 2009-08-24 11:31   --------   d-----w-   c:\documents and settings\Charissa\Application Data\Final Draft
2009-08-14 13:58 . 2009-09-30 10:44   7396   ----a-w-   c:\windows\system32\drivers\pctcore.cat
2009-08-03 13:45 . 2009-08-03 13:45   0   ---ha-w-   c:\windows\system32\drivers\Msft_User_ZuneDriver_01_07_00.Wdf
2009-08-03 13:45 . 2009-08-03 13:45   0   ---ha-w-   c:\windows\system32\drivers\Msft_Kernel_WinUSB_01007.Wdf
2009-08-03 13:43 . 2009-08-03 13:43   0   ---ha-w-   c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2009-07-05 22:20 . 2009-07-05 22:17   1102   ----a-w-   c:\windows\PowerReg.dat
2009-07-03 17:09 . 2003-03-31 12:00   915456   ----a-w-   c:\windows\system32\wininet.dll
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & LEGIT default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]
"Google Update"="c:\documents and settings\Charissa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-06-16 133104]
"Logitech Vid"="c:\program files\Logitech\Logitech Vid\vid.exe" [2009-06-02 5451536]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-06-27 321344]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-21 39408]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-08-20 2000120]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-04 61440]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-05-08 2780432]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-22 198160]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-12-12 157312]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-30 149280]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2008-06-19 77824]
"AlcWzrd"="ALCWZRD.EXE" - c:\windows\ALCWZRD.EXE [2008-06-19 2808832]

c:\documents and settings\Charissa\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe"=

R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [9/2/2009 7:37 PM 1373480]
S2 FlexService;Remote Connections Service;"c:\program files\RapidBIT\cisvc.exe" --> c:\program files\RapidBIT\cisvc.exe [?]
S2 gupdate1ca09a1297cbeca;Google Update Service (gupdate1ca09a1297cbeca);c:\program files\Google\Update\GoogleUpdate.exe [7/20/2009 6:18 PM 133104]
S3 PciCon;PciCon;\??\j:\pcicon.sys --> j:\PciCon.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-09-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2009-10-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-21 01:17]

2009-10-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-21 01:18]

2009-10-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-21 01:18]

2009-09-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-73586283-725345543-1004Core.job
- c:\documents and settings\Charissa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-16 06:41]

2009-10-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-73586283-725345543-1004UA.job
- c:\documents and settings\Charissa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-16 06:41]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.daemon-search.com/startpage
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-MSMSGS - c:\program files\Messenger\msmsgs.exe
HKLM-Run-ISUSPM - c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
HKLM-Run-NWEReboot - (no file)
AddRemove-{F37167DD-4436-4641-90B6-329D60632DDA} - c:\program files\InstallShield Installation Information\{F37167DD-4436-4641-90B6-329D60632DDA}\Setup.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-30 17:55
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
Denied: (A 2) (Everyone)
="FlashBroker"
"LocalizedString"="c:\\WINDOWS\\System32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
="c:\\WINDOWS\\System32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
Denied: (A 2) (Everyone)
="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3768)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\documents and settings\Charissa\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\system32\ZuneBusEnum.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-10-01 17:59 - machine was rebooted
ComboFix-quarantined-files.txt  2009-10-01 00:59

Pre-Run: 99,820,617,728 bytes free
Post-Run: 102,137,978,880 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

316   --- E O F ---   2009-07-29 10:00
Hi, I see that you have used combofix. What website did you download it from?i don't remember, probably the main one. why is it bad if i hadn't?Download and SAVE the below to your PC (save it anywhere you can find it. The Desktop is fine). Then doube click on it to run it.

AVPFind.bat

It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running.

----------

Now download and Run exeHelper

  • Please download exeHelper to your desktop.
  • Double-click on exeHelper.com to run the fix.
  • A black window should pop up, press any key to close once the fix is completed.
  • Post the contents of log.txt (Will be created in the DIRECTORY where you ran exeHelper.com)
.
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

----------

Also please try running this online scan: http://www.superantispyware.com/onlinescan.html

Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log from it and post it in the next reply.

-----

Next post please add:

  • AVPFind log
  • exeHelper log
  • Superantispyware log (if you could save one)
1357.

Solve : generic host process for win32 services has encountered a problem and needs to c?

Answer»

generic HOST process for win32 services has encountered a problem and needs to close,  i ALWAYS recieve this message everytime i open my computer, when it accurs i will be disconnected to the network, and my audio also will be lost.

im using microsoft windows XP version 2002 service pack 2, celeron(R) CPU 2.53GHZ, 2.00GB of ram......

could someone pls help me when this error ACCUR and how to fix this error..... thank you very much... and sorry for my bad english..See if this helps: http://support.microsoft.com/?kbid=894391#top

1358.

Solve : Amature in need of malware removal help?

Answer»

I have somehow downloaded a virus or malware and it keeps opening porn icons on my desktop I've tried to scan it with my trend MICRO INTERNET security it gets to 41% and the current target it stops at is, HKLM\SOFTWARE\Cla...539c680f,',1.1) then wont go no further. I tried the procedures under malware removal and the program starts the scan gets so far then stops with no log files. Then when i try to run the program again i get a message that says (Windows cannot access the specified device, path, or file. You may not have permission to access them.) Any help with my problem WOULD be much appreciated thank you.Try DOWNLOADING ubuntu and burning it to a CD on another computer. Then BOOT from the Ubuntu CD and use it as a live CD (don't install). When it boots put Avast or Malwarebytes on it and use it to scan your hard drive.

1359.

Solve : Can't download and run malwarebytes and explorer opens windows by itself.?

Answer»

I had malwarebytes' anti-malware on my computer before.  After a trip to myspace my computer started running very slow and explorer opens by itself, even when i am running firefox.  I have been back to the malwarebytes WEBSITE and tried to download it again and i get an error message:

Unable to execute file:
c:\ProgramFiles\Malwarebytes' Anti-Malware\mbam.exe

Create Process failed; CODE 2
The system cannot find the file specified.

Has anybody had this problem?  And, can SOMEONE please help me out?

ThanksThe first thing I will need you to do is to go to this link and follow the directions precisely. If you can't access the internet with your INFECTED computer you will have to download and transfer any PROGRAMS to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line. If you can't run any step, just jump to the next one. Please let me know how you are doing or have any questions. Initially, I will need the SuperAntiSpyware, MBAM and HJT logs. Please post any logs that you can generate.Thank you for your help.  I have tried the suggestions and tried to follow the instructions to download the c batch file.  When I try to open up my taskmanager, i get the message that it has been disabled by my administrator!  This is very aggravating and I've tried every way to find it and open it.  Any other suggestions? Quote

download the c batch file.
I'm not sure what file you're talking about.
Quote
When I try to open up my taskmanager, i get the message that it has been disabled by my administrator! 
This is a sure sign of infection.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line. If you can't run any step, just jump to the next one. Please let me know how you are doing or have any questions. Initially, I will need the SuperAntiSpyware, MBAM and HJT logs. Please post any logs that you can generate.
1360.

Solve : Search engines rerouting to different sites?

Answer»

I've read pretty much everything and done pretty much everything about this problem. I have Norton Antivirus 2009, and have used Avast! antivirus, I have and have used spybot search and destroy, and have used Malwarebytes, I have used hijack this and killbox and all that other crap but nothing works. I am using windows vista business, and now everytime i restart my computer, there is a blue screen which says "error_page_nonpage_area" or something along those lines, and will not restart until i put in the windows vista business install cd. The black "start windows normally, etc" screen says 1)put in the OS install cd, 2) select language and click next, 3) click "repair my computer." I have not done that YET, as the  computer starts up when I put the cd into the drive. The reason I haven't done that yet is because I fear I will have to do it every time I attempt to get rid of this virus, SINCE nothing works.

Can you help me?
What more information would you need?
Post the EXACT and complete error message please.I've restarted 4 times each a different way, and the message never came up again, and the vista business cd was not in the cd drive. However, something that i forgot about every time the computer starts up I get 2 messages reading 1

"Error Loading: C/users/PATRIC~1/ntload.dll
C/users/PATRIC~1/ntload.dll is not a valid Win32 application."

and 2 is the same format but the file is "C/windows/system32/notepad.dll"

Also, if it helps my computer is under a constant barrage of viruses, I get a message from norton saying my computer was just attacked by a virus, but everything is safe almost every 5 minutes.Go to the malware forum on this site and follow the instructions at the top of that forum.C:\Windows\System32\Drivers\ucchpibq.sys

avast just found this file...what does it do? should i delete it? Quote from: Allan on December 26, 2009, 02:36:10 PM

Go to the malware forum on this site and follow the instructions at the top of that forum.
SAS log:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/26/2009 at 09:01 PM

Application Version : 4.32.1000

Core Rules Database Version : 4412
Trace Rules Database Version: 2243

Scan type       : Complete Scan
Total Scan Time : 06:43:55

Memory items scanned      : 745
Memory threats detected   : 0
Registry items scanned    : 7212
Registry threats detected : 9
File items scanned        : 469292
File threats detected     : 283

Rogue.AntiVirusPlus
   HKLM\Software\Classes\CLSID\{C2B5AAB8-2183-4be7-81A6-F11493C45872}
   HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C2B5AAB8-2183-4be7-81A6-F11493C45872}
   HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C2B5AAB8-2183-4BE7-81A6-F11493C45872}
   HKU\S-1-5-21-3593084958-1206254983-1428058218-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C2B5AAB8-2183-4BE7-81A6-F11493C45872}
   HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C2B5AAB8-2183-4BE7-81A6-F11493C45872}
   HKCR\CLSID\{C2B5AAB8-2183-4BE7-81A6-F11493C45872}
   HKCR\CLSID\{C2B5AAB8-2183-4BE7-81A6-F11493C45872}\InProcServer32
   HKCR\CLSID\{C2B5AAB8-2183-4BE7-81A6-F11493C45872}\InProcServer32#ThreadingModel

Adware.Tracking Cookie
   C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Documents and Settings\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Documents and Settings\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][2].txt
   C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][2].txt
   C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][2].txt
   C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][2].txt
   C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][2].txt
   C:\Documents and Settings\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Patrick McMahon\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Cookies\[email protected][2].txt
   C:\Users\Patrick McMahon\Cookies\pat[email protected][1].txt
   C:\Users\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Cookies\[email protected][2].txt
   C:\Users\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Cookies\[email protected][2].txt
   C:\Users\Patrick McMahon\Cookies\[email protected][2].txt
   C:\Users\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Users\Patrick McMahon\Cookies\[email protected][2].txt
   C:\Users\Patrick McMahon\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected]rld[2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected]ultfriendfinder[1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][3].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][3].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected]questionmarket[1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][3].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][3].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][3].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt

Trojan.Agent/Gen
   C:\Windows\system32\critical_warning.html
   C:\Windows\system32\winhelper86.dll

Rogue.InternetSecurity2010
   HKU\S-1-5-21-3593084958-1206254983-1428058218-1000\Software\IS2010
   C:\Program Files\InternetSecurity2010
   C:\Users\Patrick McMahon\AppData\Roaming\Microsoft\Windows\Start Menu\Internet Security 2010.lnk
   C:\Users\Patrick McMahon\Start Menu\Internet Security 2010.lnk

Rogue.Agent/Gen-Nullo[DLL]
   C:\WINDOWS\SYSTEM32\BIBOSUYI.DLL
   C:\WINDOWS\SYSTEM32\BOFUJIDE.DLL
   C:\WINDOWS\SYSTEM32\DASULELO.DLL
   C:\WINDOWS\SYSTEM32\DUMOPIPE.DLL
   C:\WINDOWS\SYSTEM32\DURIBEGI.DLL
   C:\WINDOWS\SYSTEM32\FOSINOWA.DLL
   C:\WINDOWS\SYSTEM32\HEGUYAZO.DLL
   C:\WINDOWS\SYSTEM32\HIGEWOMU.DLL
   C:\WINDOWS\SYSTEM32\HOGUDARU.DLL
   C:\WINDOWS\SYSTEM32\HOVIVUYI.DLL
   C:\WINDOWS\SYSTEM32\HUVOMIFI.DLL
   C:\WINDOWS\SYSTEM32\JUBATEYA.DLL
   C:\WINDOWS\SYSTEM32\KANAGULE.DLL
   C:\WINDOWS\SYSTEM32\KUFOMAHI.DLL
   C:\WINDOWS\SYSTEM32\LABESUFI.DLL
   C:\WINDOWS\SYSTEM32\LIMOWUYU.DLL
   C:\WINDOWS\SYSTEM32\LIRUTOGA.DLL
   C:\WINDOWS\SYSTEM32\LITABIRU.DLL
   C:\WINDOWS\SYSTEM32\LIVIWEGU.DLL
   C:\WINDOWS\SYSTEM32\NAKUWIYI.DLL
   C:\WINDOWS\SYSTEM32\NAWEMONA.DLL
   C:\WINDOWS\SYSTEM32\PEFEPISA.DLL
   C:\WINDOWS\SYSTEM32\POHUNAZI.DLL
   C:\WINDOWS\SYSTEM32\RIYIGABU.DLL
   C:\WINDOWS\SYSTEM32\SAFIMUSI.DLL
   C:\WINDOWS\SYSTEM32\SANITUTU.DLL
   C:\WINDOWS\SYSTEM32\SULEKIPI.DLL
   C:\WINDOWS\SYSTEM32\TILAKIPU.DLL
   C:\WINDOWS\SYSTEM32\VAKAKAYU.DLL
   C:\WINDOWS\SYSTEM32\VETAGAMA.DLL
   C:\WINDOWS\SYSTEM32\VINOKUNI.DLL
   C:\WINDOWS\SYSTEM32\WELIMALA.DLL
   C:\WINDOWS\SYSTEM32\WIDUJUDA.DLL
   C:\WINDOWS\SYSTEM32\WUHELIDI.DLL
   C:\WINDOWS\SYSTEM32\YUZOKEWA.DLL
   C:\WINDOWS\SYSTEM32\ZOKEFAFO.DLL

Rogue.Agent/Gen-Nullo[EXE]
   C:\WINDOWS\SYSTEM32\NULORAKU.EXE

Mbam log:
Malwarebytes' Anti-Malware 1.42
Database version: 3437
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

12/27/2009 12:34:02 AM
mbam-log-2009-12-27 (00-34-02).txt

Scan type: Quick Scan
Objects scanned: 96898
Time elapsed: 6 minute(s), 39 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 3
Registry Data Items Infected: 5
Folders Infected: 0
Files Infected: 23

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\notepad (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\notepad (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\System32\bazahabe.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\System32\bikobaka.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\System32\dobapoda.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\System32\fimijole.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\System32\giniduna.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\System32\gitubazo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\System32\jiyegine.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\System32\mifuwape.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\System32\nonituwo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\System32\papororo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\System32\pawehuhe.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\System32\pinigati.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\System32\winiyavi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\System32\yewohosi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\System32\zujedafu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\system32\Drivers\ucchpibq.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Users\Patrick McMahon\AppData\Roaming\avp.ico (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\notepad.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\Temp\nsrbgxod.bak (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\AVR10.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Patrick McMahon\ntload.dll (Trojan.Agent) -> Quarantined and deleted successfully.

HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:47:15 AM, on 12/27/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe
C:\Program Files\Uniblue\DriverScanner\DriverScanner.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\Sniper.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O1 - Hosts: ::1 localhost127.0.0.1 thepiratebay.org
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {28134def-d748-436c-9fcb-e8af34670009} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\IPSBHO.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra CONTEXT menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {44990B00-3C9D-426D-81DF-AAB636FA4345} (Symantec Configuration Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlcm.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll
O20 - AppInit_DLLs: jegofoto.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPAHelper.exe - Unknown owner - C:\Program Files\iPod Access for Windows\iPAHelper.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

--
End of file - 7046 bytes
do you need anymore information? So i'm screwed?Now I have to reformat my computer because no one here was nice enough to actually help me with my problem. I only have one day left until I NEED this problem fixed, BUT I didn't post logs in the first post (even though I had done all you had said to do earlier, and none of it worked), so you decided I was just another little retarded punk who didn't know what was going on...thank you so very much for your time. Quote from: vikingkid3 on December 28, 2009, 10:22:38 PM
Now I have to reformat my computer because no one here was nice enough to actually help me with my problem.

... Please contact the accounts department. You are entitled to a full refund of your enrolment fee. However, did you read the instructions properly? If so, why have you bumped 3 times? (Over Christmas!) Like, duh!

Quote
We also request patience.  The Experts here are Volunteers and are not here 24/7.  This is not a live session either.  If it takes a few hours or overnight for them to get back to you, trust me it is worth the wait.  See here* why not to not bump your thread.

Quote
*WHEN YOU BUMP YOUR THREAD OR ADD UNNECESSARY POSTS YOU LENGTHEN THE TIME TO GET A RESPONSE!
 
It does not matter whether the bump is intentional or not. Each time you bump your thread by posting another message you do not bump to the top, you bump to the bottom of the list. You are better off posting once and waiting for an answer. Even starting another thread (which you should not do anyway) will not help because of the procedure we use to work through new threads. We work from oldest thread to newest. Bumping your thread could cost you hours or even days of additional waiting time. Also when a topic has multiple answers it looks as if someone is already helping you. Be patient.
vikingkid3, I'm sorry for the delay. It's been a very busy couple of weeks. Do you still need help?
1361.

Solve : browser redirects?

Answer»

Dave - You really super.  No redirects and computer SEEMS to be operating properly.  Is there anything a lay person can do (besides just saying thank you) to insure that the INVALUABLE help that you and this website will carry on ?  Thank you very much !
Quote

Is there anything a lay person can do (besides just saying thank you) to insure that the INVALUABLE help that you and this website will carry on ?  Thank you very much !
Thank you. The only thing you need to do is to spread the word about us and to help someone else in whatever way you can.
If there are no other issues, we can do some cleanup.

To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
****************************************************
To set a new Restore Point.

Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection.  If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard DISK, clear the check box next to the disk, and then click OK. Reboot to Normal Mode.
Click the Start button , click Control Panel, click System and Maintenance, and then click System.
In the left pane, click System Protection.  If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK.
This will give you a new, clean Restore Point.
*******************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have SAVED all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
*****************************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
*****************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything LISTED.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's EASY and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
1362.

Solve : Laptop mouse not responding?

Answer»

The mouse on my laptop is not working at all.
I am having to NAVIGATE AROUND using only the keypad.
I have tried a full restart but I am a real BEGINNER to fixing computer problems so I  don't KNOW what ELSE to do. I really hope someone can help me.

1363.

Solve : potential malware?

Answer»

Quote

I still need to reinstall antivirus, is there a preference between avast or avg?
You can choose from this list below. I, myself, prefer MicroSoft Security Essentials. Very efficient, updates automatically and not a resource hog.

Remember to only install one antivirus!
 
1) Avast! Home Edition
2) AVG Free Edition
3) Avira AntiVir Personal
4) Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download
4-a) Microsoft Security Essentials for Windows XP
5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
6) PC Tools AntiVirus Free Edition

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.
********************************************
Please run Notepad (start > All Programs > Accessories >
Notepad) and copy and paste the text in the CODE box into a new file:

Code: [Select]echo off
>Log1.txt (
ipconfig /all
nslookup google.com
nslookup yahoo.com
ping -n 2 google.com
ping -n 2 yahoo.com
route print
)
start Log1.txt
del %0

•Go to the File menu at the top of the Notepad and select Save as.

•Select save in: desktop

•Fill in File name: test.bat

•Save as type: All file types (*.*)

•Click save.

•Close the Notepad.

•Locate and double-click test.bat on the desktop.

•A notepad opens, copy and paste the content it (log1.txt) to your reply.

Windows IP Configuration

   Host Name . . . . . . . . . . . . : cgeiger-PC
   Primary Dns Suffix  . . . . . . . :
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : launchmodem.com

Ethernet adapter LOCAL Area Connection:

   Connection-specific DNS Suffix  . : launchmodem.com
   Description . . . . . . . . . . . : NVIDIA nForce Networking Controller
   Physical Address. . . . . . . . . : 00-1A-92-13-01-71
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::15b3:2ca9:7d55:787d%8(Preferred)
   IPv4 Address. . . . . . . . . . . : 192.168.1.97(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Saturday, April 02, 2011 2:44:05 PM
   Lease Expires . . . . . . . . . . : Sunday, April 03, 2011 2:44:05 PM
   Default Gateway . . . . . . . . . : 192.168.1.254
   DHCP Server . . . . . . . . . . . : 192.168.1.254
   DHCPv6 IAID . . . . . . . . . . . : 201332979
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-0D-21-C2-1C-00-1A-92-13-01-71
   DNS Servers . . . . . . . . . . . : 192.168.1.254
                                       192.168.1.254
   NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter Local Area Connection* 6:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : isatap.launchmodem.com
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 7:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 02-00-54-55-4E-01
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : 2001:0:4137:9e76:8ac:730:3f57:fe9e(Preferred)
   Link-local IPv6 Address . . . . . : fe80::8ac:730:3f57:fe9e%9(Preferred)
   Default Gateway . . . . . . . . . : ::
   NetBIOS over Tcpip. . . . . . . . : Disabled

Tunnel adapter Local Area Connection* 11:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : launchmodem.com
   Description . . . . . . . . . . . : isatap.launchmodem.com
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
Server:  launchmodem
Address:  192.168.1.254

Name:    google.com
Addresses:  74.125.45.147
     74.125.45.99
     74.125.45.103
     74.125.45.106
     74.125.45.105
     74.125.45.104

Server:  launchmodem
Address:  192.168.1.254

Name:    yahoo.com
Addresses:  69.147.125.65
     72.30.2.43
     98.137.149.56
     209.191.122.70
     67.195.160.76



Pinging google.com [74.125.45.147] with 32 bytes of data:

Reply from 74.125.45.147: bytes=32 time=12ms TTL=52

Reply from 74.125.45.147: bytes=32 time=12ms TTL=52



Ping statistics for 74.125.45.147:

    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

    Minimum = 12ms, Maximum = 12ms, Average = 12ms



Pinging yahoo.com [209.191.122.70] with 32 bytes of data:

Reply from 209.191.122.70: bytes=32 time=73ms TTL=49

Reply from 209.191.122.70: bytes=32 time=69ms TTL=49



Ping statistics for 209.191.122.70:

    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

    Minimum = 69ms, Maximum = 73ms, Average = 71ms

===========================================================================
Interface List
  8 ...00 1a 92 13 01 71 ...... NVIDIA nForce Networking Controller
  1 ........................... Software Loopback Interface 1
 12 ...00 00 00 00 00 00 00 e0  isatap.launchmodem.com
  9 ...02 00 54 55 4e 01 ...... Teredo Tunneling Pseudo-Interface
 13 ...00 00 00 00 00 00 00 e0  isatap.launchmodem.com
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0    192.168.1.254     192.168.1.97     20
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      192.168.1.0    255.255.255.0         On-link      192.168.1.97    276
     192.168.1.97  255.255.255.255         On-link      192.168.1.97    276
    192.168.1.255  255.255.255.255         On-link      192.168.1.97    276
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link      192.168.1.97    276
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link      192.168.1.97    276
===========================================================================
Persistent Routes:
  None

IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
  9     18 ::/0                     On-link
  1    306 ::1/128                  On-link
  9     18 2001::/32                On-link
  9    266 2001:0:4137:9e76:8ac:730:3f57:fe9e/128
                                    On-link
  8    276 fe80::/64                On-link
  9    266 fe80::/64                On-link
  9    266 fe80::8ac:730:3f57:fe9e/128
                                    On-link
  8    276 fe80::15b3:2ca9:7d55:787d/128
                                    On-link
  1    306 ff00::/8                 On-link
  9    266 ff00::/8                 On-link
  8    276 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None


Sure do appreciate your help and patience!  Will run the first essentials scan after I get this to you, would also like to know your thougths on upgrading to 7 after we fix allOk. We need to clear your DNS cache.

Please navigate to Start>Run and type cmd

in the window that pops up type ipconfig /flushdns

Now try to see if IE works in Normal Mode. I could only do the flush in safe mode, so IE shut down after beginning to open in regular mode  (the installer window continues to run as well, saying the network source is no longer available, for an .msi file)

in regular mode it said it needed elevation?wow, I just did a reset of EI and now it is working in regular, still got the elevation notice and the REPETITIVE insstaller.  Will intall WOT and and I think you recommended cc slim?, will wait for the other cleaning til I hear from you, thanks!During Comodo install the options to uncheck did not come up, there were 3 versions to choose from, think I chose the middle and the GEEK Buddy? Quote
During Comodo install the options to uncheck did not come up, there were 3 versions to choose from, think I chose the middle and the Geek Buddy?
Sorry, I'm not familiar with Comodo AV.

Quote
still got the elevation notice and the repetitive insstaller.
I'm sure this is not malware related. Perhaps you could ask this question in the proper software forum.
Please let me know when you're finished with the clean up so I can lock this thread.Sorry, it is the comodo firewall, not the AV Quote
Sorry, it is the comodo firewall, not the AV
It shouldn't matter from where you downloaded it; they should all be the same. This link that I gave you is a old canned speech. They must have changed the program. I don't remember those options when I installed my Comodo Firewall. Clean up is done!  Thanks SuperDave!You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
1364.

Solve : How to get rid of iMesh??

Answer»

Howdy people,

iMesh is on my laptop and will not go, been through uninstall/remove, nothing there, still as my homepage etc. no MATTER how MANY times I have CHANGED it. Please help, this is a trojan/virus no?

Rim.its not a virus, its peer to peer, TRY this

http://www.hmc.edu/cis/doc/how-to/network/sharing/remove_imesh.shtml

1365.

Solve : Everytime I try to open a program, I'm prompted to "Open With"?

Answer»

So... I've looked at the criteria for posting and recieving help, and I've tried to download and run the programs necessary... but even when I try to do that, I still end up staring perplexed at the "Open With" window, and can't run the programs.

I'm not very software-savvy, so maybe there's something I'm missing that would seem obvious to someone else. Please help?

EDIT: I guess it might help if I told you that I'm running Windows XP Home Edition on a laptop, huh?Click on the link below, then look to the "EXE File Association Fix", and download the .zip file to your computer desktop.. Once there, unzip the file, then double click on the "xp_exe_fix.reg" file that is inside, CHOOSE "OK/Yes, when it asks "Are you sure?".. Restart the computer.. It should now run those problem programs and Control Panel icons.

http://www.dougknox.com/xp/file_assoc.htmThank you so much! Quote from: LadyViolet on APRIL 11, 2011, 05:47:56 PM

Thank you so much!

So it did work?

Now it would be good to determine why this happened.

Download TrendMicro HijackThis.exe (HJT) to the desktop.

* Double-click on HJTInstall.
* Click on the Install button.
* It will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe.
* Upon install, HijackThis should open for you.
* Important! If using Windows Vista or Windows 7, close HijackThis. Now right-click HijackThis and Run As Administrator
* Click on the Do a system scan and SAVE a log file button
* HijackThis will scan and then a log will open in notepad.
* Copy and then paste the entire contents of the log in your post.
* Do not have HijackThis fix ANYTHING yet. Most of what it finds will be harmless or even required.
1366.

Solve : Trojan.Vundo-Variant/F C:\WINDOWS\SYSWOW64\DESW32DL.DLL?

Answer»

I have been using Microsoft Security Essentials which did not FIND this file with a complete SCAN. So I uninstalled MSE and INSTALLED AVG 2011 version10.0.1209. AVG did find the file (corrupted executable file) and it is now in the AGV 'virus vault'.
Subsequent full scan with SAS shows 'no problems found'.
Is it safe to keep this file as is - in the AVG virus vault - or is further action needed?Now, a NEW AVG scan shows C:\WINDOWS\SYSWOW64\temp.000 (corrupted executable file) (moved to virus vault).

What now SD? Quote

Is it safe to keep this file as is - in the AVG virus vault - or is further action needed?
It's safe in the vault or, if you WISH, you can empty the vault.
Edited.
1367.

Solve : Spy/mal-ware infection on my vista desktop, unable to get on internet, etc.?

Answer»

I un-installed the AVG.Free 9.0.
Here the log that poped up.
Thank you for the advise and the avast uninstall tool.
I will try that now.

ComboFix 11-04-03.01 - Owner 03/04/2011  21:55:56.1.4 - x64
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.2.1033.18.4085.2841 [GMT -4:00]
Running from: c:\users\Owner\Pictures\Downloads\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
AV: AVG Anti-Virus Free *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: AVG Anti-Virus Free *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\jusched.exe
.
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_WMPNetworkSvc
.
.
(((((((((((((((((((((((((   Files Created from 2011-03-04 to 2011-04-04  )))))))))))))))))))))))))))))))
.
.
2011-04-04 02:02 . 2011-04-04 02:04   --------   d-----w-   c:\users\Owner\AppData\Local\temp
2011-04-04 02:02 . 2011-04-04 02:02   --------   d-----w-   c:\users\Default\AppData\Local\temp
2011-04-03 23:07 . 2011-04-03 23:07   --------   d-----w-   C:\_OTL
2011-03-28 20:30 . 2011-03-28 20:30   --------   d-----w-   c:\program files (x86)\Common Files\McAfee
2011-03-28 20:29 . 2011-03-29 16:15   --------   d-----w-   c:\program files (x86)\McAfee
2011-03-27 16:25 . 2011-03-27 16:25   --------   d-----w-   c:\users\Owner\AppData\Local\{CBBA9F6A-5EBB-4741-821E-D82E75EEC89E}
2011-03-26 13:16 . 2011-03-26 13:16   --------   d-----w-   c:\users\Owner\AppData\Local\{4470D77A-E11F-45A6-A9E0-729F4C4E9CE9}
2011-03-25 20:10 . 2011-03-25 20:10   --------   d-----w-   c:\users\Owner\AppData\Local\{A9E1FAD2-22DD-48B0-8E29-55EF316C4171}
2011-03-24 23:36 . 2011-03-24 23:36   --------   d-----w-   c:\program files (x86)\Microsoft
2011-03-24 11:05 . 2011-03-24 11:06   --------   d-----w-   c:\users\Owner\AppData\Local\{DF441B98-1BF7-4E6D-B31A-2D764105DE28}
2011-03-23 23:05 . 2011-03-23 23:05   --------   d-----w-   c:\users\Owner\AppData\Local\{47D884B2-F3B4-47E7-9BED-FC7BF6AED343}
2011-03-23 10:49 . 2011-02-22 14:47   479744   ----a-w-   c:\windows\system32\XpsGdiConverter.dll
2011-03-23 10:49 . 2011-02-22 14:13   288768   ----a-w-   c:\windows\SysWow64\XpsGdiConverter.dll
2011-03-23 10:49 . 2011-02-22 13:53   1555968   ----a-w-   c:\windows\system32\DWrite.dll
2011-03-23 10:49 . 2011-02-22 13:53   1149440   ----a-w-   c:\windows\system32\FntCache.dll
2011-03-23 10:49 . 2011-02-22 13:33   1068544   ----a-w-   c:\windows\SysWow64\DWrite.dll
2011-03-23 10:42 . 2011-03-23 10:43   --------   d-----w-   c:\users\Owner\AppData\Local\{E572A2F1-6DA3-4321-A0FE-1E12F4D8D404}
2011-03-22 11:45 . 2011-03-22 11:45   --------   d-----w-   c:\users\Owner\AppData\Local\{1621B3CC-19D5-4933-A98E-CC9DAC557333}
2011-03-21 07:07 . 2011-03-21 07:07   --------   d-----w-   c:\users\Owner\AppData\Local\{A6C7E9B1-8BAF-4F9F-AA7F-91D0E4CA6358}
2011-03-20 17:38 . 2011-03-20 17:39   --------   d-----w-   c:\users\Owner\AppData\Local\{98A71E93-2707-4C25-AC5C-108B8094C478}
2011-03-19 19:21 . 2011-03-19 19:21   --------   d-----w-   c:\users\Owner\AppData\Local\{7F7537D7-FB8E-47EB-8320-2A466ED1CA2A}
2011-03-19 16:37 . 2011-03-21 17:36   --------   d-----w-   c:\program files (x86)\McAfee Security SCAN
2011-03-19 15:12 . 2011-03-19 15:12   605960   ----a-w-   c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-03-17 11:22 . 2011-03-17 11:22   --------   d-----w-   c:\users\Owner\AppData\Local\{8E111FB5-56A1-4F21-9911-CC369D808F46}
2011-03-17 07:01 . 2009-10-09 21:56   2048   ----a-w-   c:\windows\SysWow64\winrsmgr.dll
2011-03-17 07:01 . 2009-10-09 21:35   2048   ----a-w-   c:\windows\system32\winrsmgr.dll
2011-03-17 07:01 . 2009-10-09 21:35   13312   ----a-w-   c:\windows\system32\wsmplpxy.dll
2011-03-17 07:01 . 2009-10-09 21:34   13312   ----a-w-   c:\windows\system32\winrssrv.dll
2011-03-17 04:26 . 2011-03-17 04:26   159744   ----a-w-   c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
2011-03-17 04:25 . 2011-03-17 04:25   --------   d-----w-   c:\programdata\Apple Computer
2011-03-17 04:25 . 2011-03-17 04:25   --------   d-----w-   c:\users\Owner\AppData\Local\Apple
2011-03-17 04:25 . 2011-03-17 04:25   --------   d-----w-   c:\program files (x86)\Apple Software Update
2011-03-17 04:24 . 2011-03-17 04:24   --------   d-----w-   c:\program files\Common Files\Apple
2011-03-17 04:24 . 2011-03-17 04:24   --------   d-----w-   c:\program files\Bonjour
2011-03-17 04:24 . 2011-03-17 04:24   --------   d-----w-   c:\program files (x86)\Bonjour
2011-03-17 04:23 . 2011-03-17 04:24   --------   d-----w-   c:\program files (x86)\Common Files\Apple
2011-03-17 04:23 . 2011-03-17 04:23   --------   d-----w-   c:\programdata\Apple
2011-03-17 04:16 . 2010-12-17 17:34   2425344   ----a-w-   c:\windows\system32\mstscax.dll
2011-03-17 04:16 . 2010-12-17 15:45   2067968   ----a-w-   c:\windows\SysWow64\mstscax.dll
2011-03-17 04:16 . 2010-12-17 15:41   731136   ----a-w-   c:\windows\system32\mstsc.exe
2011-03-17 04:16 . 2010-12-17 13:54   677888   ----a-w-   c:\windows\SysWow64\mstsc.exe
2011-03-17 04:16 . 2010-12-29 19:01   416768   ----a-w-   c:\windows\system32\sbe.dll
2011-03-17 04:16 . 2010-12-29 19:01   559616   ----a-w-   c:\windows\system32\EncDec.dll
2011-03-17 04:16 . 2010-12-29 18:59   226816   ----a-w-   c:\windows\system32\mpg2splt.ax
2011-03-17 04:16 . 2010-12-29 18:28   322560   ----a-w-   c:\windows\SysWow64\sbe.dll
2011-03-17 04:16 . 2010-12-29 18:28   429056   ----a-w-   c:\windows\SysWow64\EncDec.dll
2011-03-17 04:16 . 2010-12-29 18:26   177664   ----a-w-   c:\windows\SysWow64\mpg2splt.ax
2011-03-17 04:16 . 2010-12-29 19:01   210944   ----a-w-   c:\windows\system32\sbeio.dll
2011-03-17 04:16 . 2010-12-29 18:28   153088   ----a-w-   c:\windows\SysWow64\sbeio.dll
2011-03-17 04:15 . 2011-03-17 04:15   --------   d--h--w-   c:\programdata\Common Files
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-17 04:06 . 2010-06-24 15:33   18328   ----a-w-   c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-01-20 16:46 . 2011-02-14 19:13   900480   ----a-w-   c:\windows\system32\drivers\dxgkrnl.sys
2011-01-20 16:17 . 2011-02-14 19:13   366592   ----a-w-   c:\windows\system32\winspool.drv
2011-01-20 16:17 . 2011-02-14 19:13   625152   ----a-w-   c:\windows\system32\dxgi.dll
2011-01-20 16:16 . 2011-02-14 19:13   287232   ----a-w-   c:\windows\system32\d3d10core.dll
2011-01-20 16:16 . 2011-02-14 19:13   327680   ----a-w-   c:\windows\system32\d3d10_1core.dll
2011-01-20 16:16 . 2011-02-14 19:13   196096   ----a-w-   c:\windows\system32\d3d10_1.dll
2011-01-20 16:16 . 2011-02-14 19:13   1268224   ----a-w-   c:\windows\system32\d3d10.dll
2011-01-20 16:16 . 2011-02-14 19:13   748544   ----a-w-   c:\windows\system32\stobject.dll
2011-01-20 16:16 . 2011-02-14 19:13   47104   ----a-w-   c:\windows\system32\cdd.dll
2011-01-20 16:16 . 2011-02-14 19:13   3548672   ----a-w-   c:\windows\system32\mf.dll
2011-01-20 16:16 . 2011-02-14 19:13   35840   ----a-w-   c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:14 . 2011-02-14 19:13   278528   ----a-w-   c:\windows\system32\mfplat.dll
2011-01-20 16:14 . 2011-02-14 19:13   195072   ----a-w-   c:\windows\system32\mfps.dll
2011-01-20 16:08 . 2011-02-14 19:13   478720   ----a-w-   c:\windows\SysWow64\dxgi.dll
2011-01-20 16:08 . 2011-02-14 19:13   219648   ----a-w-   c:\windows\SysWow64\d3d10_1core.dll
2011-01-20 16:08 . 2011-02-14 19:13   160768   ----a-w-   c:\windows\SysWow64\d3d10_1.dll
2011-01-20 16:08 . 2011-02-14 19:13   1029120   ----a-w-   c:\windows\SysWow64\d3d10.dll
2011-01-20 16:08 . 2011-02-14 19:13   189952   ----a-w-   c:\windows\SysWow64\d3d10core.dll
2011-01-20 16:07 . 2011-02-14 19:13   258048   ----a-w-   c:\windows\SysWow64\winspool.drv
2011-01-20 16:07 . 2011-02-14 19:13   586240   ----a-w-   c:\windows\SysWow64\stobject.dll
2011-01-20 16:06 . 2011-02-14 19:13   2873344   ----a-w-   c:\windows\SysWow64\mf.dll
2011-01-20 16:04 . 2011-02-14 19:13   209920   ----a-w-   c:\windows\SysWow64\mfplat.dll
2011-01-20 16:04 . 2011-02-14 19:13   98816   ----a-w-   c:\windows\SysWow64\mfps.dll
2011-01-20 15:01 . 2011-02-14 19:13   3068416   ----a-w-   c:\windows\system32\xpsservices.dll
2011-01-20 15:01 . 2011-02-14 19:13   1653760   ----a-w-   c:\windows\system32\XpsPrint.dll
2011-01-20 14:59 . 2011-02-14 19:13   1032192   ----a-w-   c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:58 . 2011-02-14 19:13   1461760   ----a-w-   c:\windows\system32\OpcServices.dll
2011-01-20 14:57 . 2011-02-14 19:13   231936   ----a-w-   c:\windows\system32\XpsRasterService.dll
2011-01-20 14:42 . 2011-02-14 19:13   1257984   ----a-w-   c:\windows\system32\MFH264Dec.dll
2011-01-20 14:41 . 2011-02-14 19:13   428544   ----a-w-   c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:40 . 2011-02-14 19:13   345088   ----a-w-   c:\windows\system32\mfreadwrite.dll
2011-01-20 14:40 . 2011-02-14 19:13   34304   ----a-w-   c:\windows\system32\mfpmp.exe
2011-01-20 14:40 . 2011-02-14 19:13   377344   ----a-w-   c:\windows\system32\mfmp4src.dll
2011-01-20 14:37 . 2011-02-14 19:13   2002944   ----a-w-   c:\windows\system32\d3d10warp.dll
2011-01-20 14:35 . 2011-02-14 19:13   566272   ----a-w-   c:\windows\system32\d3d10level9.dll
2011-01-20 14:28 . 2011-02-14 19:13   1554432   ----a-w-   c:\windows\SysWow64\xpsservices.dll
2011-01-20 14:27 . 2011-02-14 19:13   876032   ----a-w-   c:\windows\SysWow64\XpsPrint.dll
2011-01-20 14:25 . 2011-02-14 19:13   847360   ----a-w-   c:\windows\SysWow64\OpcServices.dll
2011-01-20 14:24 . 2011-02-14 19:13   135680   ----a-w-   c:\windows\SysWow64\XpsRasterService.dll
2011-01-20 14:15 . 2011-02-14 19:13   979456   ----a-w-   c:\windows\SysWow64\MFH264Dec.dll
2011-01-20 14:14 . 2011-02-14 19:13   357376   ----a-w-   c:\windows\SysWow64\MFHEAACdec.dll
2011-01-20 14:14 . 2011-02-14 19:13   302592   ----a-w-   c:\windows\SysWow64\mfmp4src.dll
2011-01-20 14:14 . 2011-02-14 19:13   261632   ----a-w-   c:\windows\SysWow64\mfreadwrite.dll
2011-01-20 14:12 . 2011-02-14 19:13   1172480   ----a-w-   c:\windows\SysWow64\d3d10warp.dll
2011-01-20 14:11 . 2011-02-14 19:13   486400   ----a-w-   c:\windows\SysWow64\d3d10level9.dll
2011-01-20 14:06 . 2011-02-14 19:13   834048   ----a-w-   c:\windows\system32\d2d1.dll
2011-01-20 13:47 . 2011-02-14 19:13   683008   ----a-w-   c:\windows\SysWow64\d2d1.dll
2011-01-13 10:20 . 2011-01-28 07:11   7844688   ----a-w-   c:\programdata\Microsoft\Windows Defender\Definition Updates\{7F58F427-5672-44B3-87E9-477EA0C28659}\mpengine.dll
2011-01-13 08:47 . 2011-01-24 00:26   237168   ----a-w-   c:\windows\system32\aswBoot.exe
2011-01-08 09:03 . 2011-02-14 19:12   48128   ----a-w-   c:\windows\system32\atmlib.dll
2011-01-08 08:47 . 2011-02-14 19:12   34304   ----a-w-   c:\windows\SysWow64\atmlib.dll
2011-01-08 06:45 . 2011-02-14 19:12   367104   ----a-w-   c:\windows\system32\atmfd.dll
2011-01-08 06:28 . 2011-02-14 19:12   292352   ----a-w-   c:\windows\SysWow64\atmfd.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-03-06 39408]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
"AdobeUpdater"="c:\program files (x86)\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-09-26 2356088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2010-11-30 281768]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http:" [X]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\CONTROL\SafeBoot\Minimal\!SASCORE]
=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-06 135664]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 LVcKap64;Logitech AEC Driver;c:\windows\system32\DRIVERS\LVcKap64.sys


R3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys

R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam_x64.sys

R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 netr7364;Linksys Compact Wireless-G USB Adapter Driver for Vista;c:\windows\system32\DRIVERS\WUSB54GCx64.sys

R3 ScreamBAudioSvc;ScreamBee Audio;c:\windows\system32\drivers\ScreamingBAudio64.sys

R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
R4 PdiService;Portrait Displays SDK Service;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2009-06-23 109168]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe

S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2010-11-30 135336]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe [2011-02-16 101048]
S3 LVUVC64;Logitech Webcam 500(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys

S3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;c:\windows\system32\DRIVERS\WUSB54GCv3.sys

.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt   REG_MULTI_SZ      hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-06 10:38]
.
2011-04-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-06 10:38]
.
2011-04-03 c:\windows\Tasks\User_Feed_Synchronization-{79662777-9144-4FDC-9878-A688B6B1948B}.job
- c:\windows\system32\msfeedssync.exe [2011-02-14 04:47]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="%ProgramFiles%\Windows Defender\MSASCui.exe -hide" [X]
"combofix"="c:\combofix\CF13003.cfxxe" [X]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://www.yahoo.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://ca.search.yahoo.com/search?fr=mcafee&p=%s
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\769657z5.default\
FF - prefs.js: browser.search.selectedEngine - Secure Search
FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4b8497d4&v=6.103.018.001&i=23&tp=ab&iy=&ychte=ca&lng=en-GB&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: McAfee SiteAdvisor: {B7082FAA-CB62-4872-9106-E42DD88EDE45} - c:\program files (x86)\McAfee\SiteAdvisor
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Wow6432Node-HKLM-Run-WindowsLiveDeviceIntegrator - c:\program files (x86)\Windows Live\Device Integrator\wldi.exe
SafeBoot-mcmscsvc
SafeBoot-MCODS
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{4E7BD74F-2B8D-469E-85B2-BC27FE9AAE2E} - (no file)
AddRemove-sp44626 - c:\hp\Softpaq\sp44626\sp44626.exe
AddRemove-WindowsLiveDeviceIntegrator - c:\program files (x86)\Windows Live\Device Integrator\InstallDI.exe
AddRemove-WinLiveSuite - c:\program files (x86)\Windows Live\Installer\wlarp.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
Denied: (A 2) (Everyone)
="FlashBroker"
"LocalizedString"="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
Denied: (A 2) (Everyone)
="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
Denied: (A 2) (Everyone)
="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
Denied: (A 2) (Everyone)
="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
Denied: (A 2) (Everyone)
=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\ACR0065\4&98671ce&0&UID16843008\Properties\{83da6326-97a6-4088-9453-a1923f573b29}]
DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\ACR0065\4&98671ce&0&UID16843008\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}]
DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\Default_Monitor\4&98671ce&0&UID16843008\Properties\{83da6326-97a6-4088-9453-a1923f573b29}]
DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\Default_Monitor\4&98671ce&0&UID16843008\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}]
DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\HWP26A8\4&98671ce&0&UID16843008\Device Parameters\MODES]
DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\HWP26A8\4&98671ce&0&UID16843008\Properties\{83da6326-97a6-4088-9453-a1923f573b29}]
DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\HWP26A8\4&98671ce&0&UID16843008\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}]
DACL=(02 0000)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
c:\windows\SysWOW64\rundll32.exe
.
**************************************************************************
.
Completion time: 2011-04-03  22:09:37 - machine was rebooted
ComboFix-quarantined-files.txt  2011-04-04 02:09
.
Pre-Run: 376,976,920,576 bytes free
Post-Run: 376,517,332,992 bytes free
.
- - End Of File - - 0F2952DAFA973D05741C739009A56F27
Please download the Sophos Anti-Rootkit Scanner and save it to your desktop.

You will need to enter your name, e-mail address and location in order to access the download page.

  • Once you have downloaded the file, double click the sarsfx icon
  • Review the licence agreement and click on the Accept button
  • The scanner will prompt you to extract the files to C:\SOPHTEMP - DO NOT change this location, simply click the Install button

  • Once the files have been extracted; using Windows Explorer, navigate to C:\SOPHTEMP and double click on the blue shield icon called sargui
  • Ensure that there are checkmarks next to Running processes, Windows registry and Local hard drives, then click Start scan
  • Allow the program to scan your computer - please be patient as it may take some time
  • Once the scan has completed a window will POP-up with the results of the scan - click OK to this
  • In the main window, you will see each of the entries found by the scan (if any)
    • If the scanner generated any warning messages, please click on each warning and copy and paste the text of it into this thread for me to review
    • Once you have posted any warning messages here, you can close the scanner and wait for me to get back to you
  • If you have not had any warnings, any entries which can be cleaned up by the scanner will have a box with a green checkmark in it next to the entry
  • To clean up these entries click on the Clean up checked items button
  • If you accidentally check a file NOT recommended for clean up, you will get a warning message and if necessary can re-select the entries you want to clean up
  • Once you have cleaned the selected files, you will be prompted to re-boot your computer - please do so
  • When you have re-booted, please post a fresh HijackThis log into this thread and tell me how your computer is running now
"Ensure that there are checkmarks next to Running processes, Windows registry and Local hard drives"
Won't let me checkmark "Running Processes".

 [/url]Ok. Please try this:

Please download Rooter and Save it to your desktop.
  • Double click it to start the tool.Vista and Windows7 run as administrator.
  • Click Scan.
  • Eventually, a Notepad file containing the report will open, also found at C:\Rooter.txt. Post that log in your next reply.

Won't work.
That's weird. Please try this one to see if it will work.

SysProt Antirootkit

Download
SysProt Antirootkit from the link below (you will find it at the bottom
of the page under attachments, or you can get it from one of the
mirrors).

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.
  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select the following items.
    • Process << Selected
    • Kernel Modules << Selected
    • SSDT << Selected
    • Kernel Hooks << Selected
    • IRP Hooks << NOT Selected
    • Ports << NOT Selected
    • Hidden Files << Selected
  • At the bottom of the page
    • Hidden Objects Only << Selected
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should APPEAR.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to. Open the text file and copy/paste the log here.


I got that pop up and I put run under Administrator.
So I'm not sure if the log showed everything.

SysProt AntiRootkit v1.0.1.0
by swatkat

******************************************************************************************
******************************************************************************************

No Hidden Processes found

******************************************************************************************
******************************************************************************************
No Hidden Kernel Modules found

******************************************************************************************
******************************************************************************************
No SSDT Hooks found

******************************************************************************************
******************************************************************************************
No Kernel Hooks found

******************************************************************************************
******************************************************************************************
No hidden files/folders found

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
[email protected] as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
[email protected] as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=53251
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6425
# api_version=3.0.2
# EOSSerial=161aeaa8969a0844a3567aa7a0e6a701
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-04-14 07:15:46
# local_time=2011-04-14 03:15:46 (-0500, Eastern Daylight Time)
# country="Canada"
# lang=4105
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=768 16777215 100 0 0 0 0 0
# compatibility_mode=1024 16777215 100 0 34903983 34903983 0 0
# compatibility_mode=1797 16775165 100 94 0 38396138 0 0
# compatibility_mode=5892 16776573 100 56 0 139401495 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=186383
# found=0
# cleaned=0
# scan_time=5757
How's your computer running now? Any other issues?
1368.

Solve : ROOT hacking?

Answer»

If someone were to hack your root, how would you make sure that you're rooted and what should you do to get it REMOVED?

It is just interest out of personal hobby and because I had this sad happening like MANY years ago.By 'root hacking' you mean 'rootkit'.
Rootkit
http://en.wikipedia.org/wiki/Rootkit

The like above gives a good definition of what a Rootkit is. (There term at one time had a more narrow meaning. It was a rick to be used by administrators to recover a failing system.)

Here on this FORUM they do not encourage 'root hacking' as a politically corret hobby.

For more info, use the term 'rootkit' in yurt SEARCH.

1369.

Solve : How do you fix dll errors then?

Answer»

Want to know if you get a dll error what do you need to do to FIX it? Should you download the missing file? What if you cannot enter the internet then? Where do you copy the missing file to? Thanksi think this is in the wrong aria, this section os about PC viruses, you may need to POST this question somewere elce, SORRY for not beeing helpful. you can download the .dll FILES but they MIGHT not be the right vertion.

1370.

Solve : Need help...please?

Answer»

Quote

Do I need to Delete the quarantined files? and also is this a program that I should uninstall or will I use it regularly from now on?
You can wait about a week then empty the quarantine folder.
Mp4 Player is supposed to be a safe application.
How's your computer running now?Hey Dave,

My computer seems pretty "normal".  I can print fine now and the screen looks "normal" for a while it looked just odd. I have been using it and so far so good. I have not rebooted it for a day or so.  It feels good to have it be "OK". Should I back it up now or wait a week to delete the quarantined files?  Also, what do you suggest I as a virus protection. I use Malwarebytes every couple of weeks. Honestly I have never had any problems until this past week.

Thanks. Quote
Should I back it up now or wait a week to delete the quarantined files?
If everything is running fine you can empty the quarantine folder.

Quote
Also, what do you suggest I as a virus protection. I use Malwarebytes every couple of weeks. Honestly I have never had any problems until this past week.

First of all, you need a good, up-to-date Anti-Virus program and a third-party firewall. MBAM and SAS are good to run every so often. I will suggest some others when we are finished. One more scan, please.

Download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

link # 1
Link # 2
If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Right-click combofix.exe and select Run as Administrator and follow the prompts.
When finished, ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.
Yeah, able to do both of those now

ComboFix 11-04-15.06 - jjsangelandjan 04/16/2011  16:40:12.1.2 - x86
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.3062.1786 [GMT -4:00]
Running from: c:\users\jjsangelandjan\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\BSTIeprintctl1.dll
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
.
.
(((((((((((((((((((((((((   Files Created from 2011-03-16 to 2011-04-16  )))))))))))))))))))))))))))))))
.
.
2011-04-16 20:48 . 2011-04-16 20:49   --------   d-----w-   c:\users\jjsangelandjan\AppData\Local\temp
2011-04-16 20:48 . 2011-04-16 20:48   --------   d-----w-   c:\users\IUSR_NMPR\AppData\Local\temp
2011-04-16 20:48 . 2011-04-16 20:48   --------   d-----w-   c:\users\Default\AppData\Local\temp
2011-04-16 20:48 . 2011-04-16 20:48   --------   d-----w-   c:\users\Lisa Long\AppData\Local\temp
2011-04-16 20:48 . 2011-04-16 20:48   --------   d-----w-   c:\users\Hazel\AppData\Local\temp
2011-04-16 20:48 . 2011-04-16 20:48   --------   d-----w-   c:\users\Giving Works Today\AppData\Local\temp
2011-04-16 20:48 . 2011-04-16 20:48   --------   d-----w-   c:\users\Danielas Account\AppData\Local\temp
2011-04-16 20:48 . 2011-04-16 20:48   --------   d-----w-   c:\users\Bens Account\AppData\Local\temp
2011-04-16 20:48 . 2011-04-16 20:48   --------   d-----w-   c:\users\Roberts Account\AppData\Local\temp
2011-04-16 20:48 . 2011-04-16 20:48   --------   d-----w-   c:\users\Administrator\AppData\Local\temp
2011-04-16 16:51 . 2011-04-16 16:51   --------   d-----w-   c:\users\jjsangelandjan\AppData\Local\{26C05198-F838-40AB-82CC-5A7758DB2BE6}
2011-04-15 17:18 . 2011-02-22 13:24   213504   ----a-w-   c:\windows\system32\drivers\mrxsmb10.sys
2011-04-15 16:50 . 2011-04-16 04:51   --------   d-----w-   c:\users\jjsangelandjan\AppData\Local\{E23B81FE-69BB-4308-A2B8-5344BB8931C1}
2011-04-15 06:01 . 2011-03-15 04:05   6792528   ----a-w-   c:\programdata\Microsoft\Windows Defender\Definition UPDATES\{588CD8F9-C519-48D0-A67F-872FCB2670A1}\mpengine.dll
2011-04-14 21:58 . 2011-04-14 21:58   --------   d-----w-   c:\program files\ESET
2011-04-13 02:10 . 2011-04-13 14:11   --------   d-----w-   c:\users\jjsangelandjan\AppData\Local\{21B88FEE-85C9-4800-868D-B744E8938192}
2011-04-12 12:59 . 2011-04-12 12:59   --------   d-----w-   c:\users\jjsangelandjan\AppData\Roaming\SUPERAntiSpyware.com
2011-04-12 12:59 . 2011-04-12 12:59   --------   d-----w-   c:\programdata\SUPERAntiSpyware.com
2011-04-12 12:59 . 2011-04-12 12:59   --------   d-----w-   c:\program files\SUPERAntiSpyware
2011-04-11 01:47 . 2011-04-11 13:48   --------   d-----w-   c:\users\jjsangelandjan\AppData\Local\{1BE5394E-D636-4DC3-B969-EBCA40A40D82}
2011-04-08 01:30 . 2011-04-10 13:32   --------   d-----w-   c:\users\jjsangelandjan\AppData\Local\{93BDE59F-4BB9-4979-AA6E-86734974B9CA}
2011-04-06 10:04 . 2011-04-07 10:05   --------   d-----w-   c:\users\jjsangelandjan\AppData\Local\{F742A92F-9581-4369-9336-D547166C376A}
2011-04-05 22:04 . 2011-04-05 22:04   --------   d-----w-   c:\users\jjsangelandjan\AppData\Local\{33BDE833-9B1B-42C6-AE08-FCE7B62A873C}
2011-04-04 10:03 . 2011-04-05 10:03   --------   d-----w-   c:\users\jjsangelandjan\AppData\Local\{3F64CE41-12A6-4ABB-8792-33437B8B4A00}
2011-04-03 22:00 . 2011-04-03 22:00   --------   d-----w-   c:\users\Administrator\AppData\Roaming\HPAppData
2011-03-31 22:01 . 2011-04-03 22:03   --------   d-----w-   c:\users\jjsangelandjan\AppData\Local\{8973526F-506B-44D8-B587-4EE36E0894D5}
2011-03-29 17:05 . 2011-03-31 05:06   --------   d-----w-   c:\users\jjsangelandjan\AppData\Local\{38701BC8-0FE8-437A-9B11-DEA83A2E95E4}
2011-03-26 02:42 . 2011-03-26 02:42   --------   d-----w-   c:\users\Public\summer_floral_48258
2011-03-25 23:48 . 2011-03-25 23:48   4284416   ----a-w-   c:\windows\system32\GPhotos.scr
2011-03-23 12:56 . 2011-03-29 00:59   --------   d-----w-   c:\users\jjsangelandjan\AppData\Local\{A4C4797D-0F19-4C78-B7C1-9A0AAE84986C}
2011-03-22 21:45 . 2011-02-22 14:13   288768   ----a-w-   c:\windows\system32\XpsGdiConverter.dll
2011-03-22 21:45 . 2011-02-22 13:33   1068544   ----a-w-   c:\windows\system32\DWrite.dll
2011-03-22 21:45 . 2011-02-22 13:33   797696   ----a-w-   c:\windows\system32\FntCache.dll
2011-03-21 09:30 . 2011-03-22 21:31   --------   d-----w-   c:\users\jjsangelandjan\AppData\Local\{3AE8680E-5F41-4375-9506-FBBE49C8945B}
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-10 02:49 . 2010-06-24 16:33   18328   ----a-w-   c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-02-02 22:11 . 2009-10-02 16:51   222080   ------w-   c:\windows\system32\MpSigStub.exe
2011-01-20 16:37 . 2011-02-09 04:29   638336   ----a-w-   c:\windows\system32\drivers\dxgkrnl.sys
2011-01-20 16:08 . 2011-02-09 04:29   478720   ----a-w-   c:\windows\system32\dxgi.dll
2011-01-20 16:08 . 2011-02-09 04:29   219648   ----a-w-   c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08 . 2011-02-09 04:29   160768   ----a-w-   c:\windows\system32\d3d10_1.dll
2011-01-20 16:08 . 2011-02-09 04:29   1029120   ----a-w-   c:\windows\system32\d3d10.dll
2011-01-20 16:08 . 2011-02-09 04:29   189952   ----a-w-   c:\windows\system32\d3d10core.dll
2011-01-20 16:07 . 2011-02-09 04:29   37376   ----a-w-   c:\windows\system32\cdd.dll
2011-01-20 16:07 . 2011-02-09 04:29   258048   ----a-w-   c:\windows\system32\winspool.drv
2011-01-20 16:07 . 2011-02-09 04:29   586240   ----a-w-   c:\windows\system32\stobject.dll
2011-01-20 16:06 . 2011-02-09 04:29   2873344   ----a-w-   c:\windows\system32\mf.dll
2011-01-20 16:06 . 2011-02-09 04:29   26112   ----a-w-   c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04 . 2011-02-09 04:29   209920   ----a-w-   c:\windows\system32\mfplat.dll
2011-01-20 16:04 . 2011-02-09 04:29   98816   ----a-w-   c:\windows\system32\mfps.dll
2011-01-20 14:28 . 2011-02-09 04:29   1554432   ----a-w-   c:\windows\system32\xpsservices.dll
2011-01-20 14:27 . 2011-02-09 04:29   876032   ----a-w-   c:\windows\system32\XpsPrint.dll
2011-01-20 14:26 . 2011-02-09 04:29   667648   ----a-w-   c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25 . 2011-02-09 04:29   847360   ----a-w-   c:\windows\system32\OpcServices.dll
2011-01-20 14:24 . 2011-02-09 04:29   135680   ----a-w-   c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15 . 2011-02-09 04:29   979456   ----a-w-   c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14 . 2011-02-09 04:29   357376   ----a-w-   c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14 . 2011-02-09 04:29   261632   ----a-w-   c:\windows\system32\mfreadwrite.dll
2011-01-20 14:14 . 2011-02-09 04:29   302592   ----a-w-   c:\windows\system32\mfmp4src.dll
2011-01-20 14:12 . 2011-02-09 04:29   1172480   ----a-w-   c:\windows\system32\d3d10warp.dll
2011-01-20 14:11 . 2011-02-09 04:29   486400   ----a-w-   c:\windows\system32\d3d10level9.dll
2011-01-20 13:47 . 2011-02-09 04:29   683008   ----a-w-   c:\windows\system32\d2d1.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"HPADVISOR"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-08-05 1644088]
"googletalk"="c:\users\jjsangelandjan\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-03-16 2423752]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 4874240]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-10-24 107112]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2006-10-26 22696]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-04-19 151552]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-29 583048]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-01 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-01 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-01 133656]
"QuickTime Task"="e:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"iTunesHelper"="e:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-05 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"Malwarebytes' Anti-Malware (reboot)"="e:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-25 44136]
.
c:\users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]
.
c:\users\Roberts Account\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]
.
c:\users\Bens Account\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]
.
c:\users\Hazel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]
.
c:\users\Lisa Long\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]
.
c:\users\jjsangelandjan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 IntelDHSvcConf;Intel DH Service;c:\program files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe [2006-05-10 29696]
R3 SoundMovieServer;SoundMovieServer;c:\windows\system32\snmvtsvc.exe [2008-06-04 184320]
R3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 987648]
R3 VSTHWBS2;VSTHWBS2;c:\windows\system32\DRIVERS\VSTBS23.SYS [2006-11-02 251904]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20071204.001\IDSvix86.sys [2007-11-06 180272]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-09-03 208896]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2007-09-21 112688]
S3 hcw18bda;Hauppauge WinTV 418 Driver;c:\windows\system32\drivers\hcw18bda.sys [2006-11-22 336000]
S3 MovRVDrv32;MovRVDrv32;c:\windows\system32\DRIVERS\MovRVDrv32.sys [2008-06-04 3768]
S3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\SYMNDISV.SYS [2008-10-03 37936]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - COMHOST
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12   REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt   REG_MULTI_SZ      hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation   REG_MULTI_SZ      FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-16 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Lisa Long.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2006-11-07 17:48]
.
2011-04-15 c:\windows\Tasks\User_Feed_Synchronization-{FC857FE0-93F1-49AE-9D69-02E072DD5496}.job
- c:\windows\system32\msfeedssync.exe [2011-04-15 04:43]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: eBay Search - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
FF - ProfilePath - c:\users\jjsangelandjan\AppData\Roaming\Mozilla\Firefox\Profiles\m8jvtigk.default\
FF - prefs.js: browser.startup.homepage - www.ipburger.com
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D51D388B-F5DC-471A-A1CE-5E2D671091C0} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-16 16:49
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ... 
.
scanning hidden autostart entries ...
.
scanning hidden files ... 
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.0.6002 Disk: SAMSUNG_SP2504C rev.VT100-49 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-1
.
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user != kernel MBR !!!
sectors 488397166 (+255): user != kernel
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
Denied: (A) (Users)
Denied: (A) (Everyone)
Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
Denied: (A) (Users)
Denied: (A) (Everyone)
Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
Denied: (A) (Users)
Denied: (A) (Everyone)
Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-04-16  16:52:43
ComboFix-quarantined-files.txt  2011-04-16 20:52
.
Pre-Run: 98,973,835,264 bytes free
Post-Run: 99,919,798,272 bytes free
.
- - End Of File - - CEA3191586138A204C013A4F60FF9073


here is the hijack log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:43:26 PM, on 4/16/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19048)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
E:\Program Files\QuickTime\QTTask.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
E:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Hewlett-Packard\HP Advisor\SSDK04.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\sdclt.exe
C:\Windows\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "E:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
O4 - HKCU\..\Run: [googletalk] C:\Users\jjsangelandjan\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - E:\Program Files\SoundTaxi\YouTubeRipper.dll
O9 - Extra 'Tools' menuitem: Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - E:\Program Files\SoundTaxi\YouTubeRipper.dll
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} (Auctiva Image Uploader Control) - http://www.auctiva.com/Aurigma/ImageUploader57.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: SoundMovieServer - SoundMovieServer - C:\Windows\system32\snmvtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 11035 bytes


The only thing I notice that is different now is the it seems to take FOREVER to boot up. I dont remember it ever taking so long.

THANKS! Quote
The only thing I notice that is different now is the it seems to take FOREVER to boot up. I dont remember it ever taking so long.
I will include a program so you can look at and adjust what starts in startup.
A couple of items to fix in HJT and we can do some cleanup.

Open HijackThis and select Do a system scan only

Place a check mark next to the following entries: (if there)

O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "E:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript


Important: Close all open windows except for HijackThis and then click Fix checked.

Once completed, exit HijackThis.
*********************************************
StartupLite

Download StartupLite by MalwareBytes to your Desktop.
Doubleclick StartupLite.exe to launch the program.
Ensure the Disable box is checked.
Click Continue.
A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer.
Re-start your computer.
****************************************
To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
*************************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
****************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Hi Dave,

I have done everything that you have suggested except the firewall. My vista fire wall is "ON" do you advise adding an additional firewall on top of that?

My computer still takes a long time to boot up....it still seems longer than it used to but I have not used a couple of the clean up tools listed on the "SLOW computer" page that you suggested.

I have used a program CALLED: "Clean up" by Steven Gould that seems to have worked well in the past....are you familiar with this? and if so is it adequate or would the "CCleaner" be better?

I am planning to add another memory card here soon.

Thanks again for your help and the clear easy to follow steps!

Lisa Just a follow up...I updated my Spybot today and than ran a scan. It FOUND a trojan hiding as well. Is there anything else I should be running? Quote
My computer still takes a long time to boot up....it still seems longer than it used to but I have not used a couple of the clean up tools listed on the "SLOW computer" page that you suggested.
How much time are we talking about?

Quote
I have used a program called: "Clean up" by Steven Gould that seems to have worked well in the past....are you familiar with this? and if so is it adequate or would the "CCleaner" be better?
Looks like a bit like CCleaner with a few more bells and whistles.
Quote
Is there anything else I should be running?
You should keep SAS and MBAM. Update them and run them on a regular basis. Quote from: SuperDave on April 18, 2011, 12:04:57 PM
How much time are we talking about?

It takes it about 8 - 10 minutes to boot up, then another 5 - 6 minutes to open my main user up. I never timed it before but it seemed before to boot up in about 5 minutes and may be 3 - 4  minutes for the main user. Now, I have done all of the updates with the browsers and when it booted the last time, I wondered if this might have something to do with it....normally my computer is very fast.   Otherwise other than getting used to the "new" look of the browsers things seem pretty fine. I used my system as NORMAL today

Thanks!Did you find anything when you ran StartupLite? If there a lot of apps starting it can really slow things down.Yes, I removed about 8 things with the STARTUPLite! Here's a bunch of links concerning slow boot with Vista. I hope it helps.ok Great!

You are a very valuable knowledgeable asset to this forum. Thanks for being willing to share that with all of us who struggle against these nasty virus'. No words to really express my gratitude!

Take care You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
1371.

Solve : Unable to open in safe mode due to virus?

Answer»

Can you tell me another way to get into safe mode? I am apparently under attack by worms,trojan, etc. I TRIED to open in safe mode to do the fix but it does not work. Any other way to get in? The screen stays black when I TRY to restart and hit F8....
Thank youDuplicate post. I'm WORKING with this OP on the original post. I will lock this ONE.

1372.

Solve : Virus in computer i think slowing computer right down :(?

Answer»

Still got some the Background on my screen is just black now no picture i have tried to put the 1 back on but will not let me also When you go into documents all the files have no picture of a file just a name but you have to click the invisible file Maybe be easier just to make back up disc of WINDOWS VISTA  if can find the file of it put on disc then wipe computer not done that for over 2 years so might just need wiping clean GOOD CLEAN UP, Like still don't know what the TASK ENG.EXE running 3 times when i look at task manager it will not let me close it all them down when  i close others it just starts up again few seconds later.
I tried to run ComboFix again to try get you a log but still says CORRUPT COPY.

Sorry about all the trouble SuperDave i know you good cos it was you that got my computer going last time on different computer

THANK YOU FOR THE HELP WILL WAIT TO SEE WHAT YOU WANT NEXT.

JENZO  Still no good with ComboFix i have kept trying & have tried different links to it as well but still said Corrupt Copy. Do you think we will be able to work out what the trouble is ??, Have you seen anything wrong so far in any of the logs that might be 1 of the problems if there is more than 1 i say they is. Hope you can help me out SuperDave will check in today every 2hrs to see if any replies.

THANK YOU SuperDave

JENZO    Done a new HTJ log for you so you can look at it just in case there is something new on it from last time , Also done other scans but they have found nothing so far.

HTJ LOG:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:41:16, on 16/04/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\dvd43\DVD43_Tray.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Steam\steam.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Electronic Arts\EADM\EADMUI\EADMUI.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Electronic Arts\EADM\EADMUI\EADM.exe
C:\PROGRA~1\ELECTR~1\EADM\EADMUI\EACoreServer.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Windows Defender\MSASCui.exe
c:\users\Jenzo\Documents\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.msn.com/?ocid=OIE9HP
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/1me10IE9ENGB/110
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer, optimized for Bing and MSN
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\rmtray.exe /H
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [EADM] "C:\Program Files\Electronic Arts\EADM\EADMUI\EADMUI.exe"
O9 - Extra button: C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 7137 bytes
Quote

Still got some the Background on my screen is just black now no picture i have tried to put the 1 back on but will not let me also When you go into documents all the files have no picture of a file just a name but you have to click the invisible file
This sounds like a monitor or driver problem Can you give me screenshots of these two problems?
How to post screenshots or images

Quote
Do you think we will be able to work out what the trouble is ??, Have you seen anything wrong so far in any of the logs that might be 1 of the problems if there is more than 1 i say they is.
I haven't seen anything that would cause this sort of problems. Did you install anything new or make any changes to your computer prior to these problems beginning?
Please run this even if you don't have the disk.

1/ Click the Start button.

2/ From the Start Menu, Click All programs followed by Accessories.

3/ In the Accessories menu, Right Click on the Command Prompt option.

4/ From the drop down menu that appears, Click on the Run as administrator option.

5/ If you have the User Account Control (UAC) enabled you will be asked for authorisation prior to the command prompt opening. You may simply need to press the Continue button if you are the administrator or insert the administrator password etc.

6/ In the Command Prompt window, type: sfc /scannow and then press Enter.

7/ A message will appear stating that the system scan will begin.

8/ Be patient because the scan may take some time.

9/ If any files require replacing SFC will replace them. You may be asked to insert your Vista DVD for this process to continue.

10/ If everything is okay you should, after the scan, see the following message Windows resource protection did not find any integrity violations.

11/ After the scan has completed, Close the command prompt window.
Sorry was not faster with replies computer acting up now,The question you asked about did I install anything before this happened well the online game i play called CONQUER ONLINE done a Auto Update and when it was done the MS REMOVAL TOOL CAME UP?? , I have been playing this game over 4yrs now and sometime there is just a problem with update but not a virus i have asked a few friends on the site as well if they got a virus from the update and all say no & none detected as well.

IMAGES that you asked for.
SCREEN SHOT :  http://img151.imageshack.us/img151/558/blackscreen.jpg[/IMG]
By jenzos

FILE SHOT :  http://img713.imageshack.us/img713/9783/justfilenames.jpg[/IMG]
By jenzos

The scan that you ask me to run i have done but it will not let me get the CBS logs from the Windows file just says ACCESS DENIED
SORRY COULD NOT GET LOG FOR YOU THIS TIME  . will try again when you might have way to get logs

THANK YOU SuperDave for all the time that you have spared for helping me on this matter PURE LIFE SAVER SO FAR computer still going I know you will get it ALL WORKING AGAIN 

JENZO Thank you. Did you try adding some wallpaper to you desktop? As for the filenames, try clicking on view and choose a different setting such as thumbnails.
Did you try to run SFC as described in Reply # 18?

Please download the latest version of Kaspersky GetSystemInfo (GSI) from Kaspersky and save it to your Desktop.

Note: please close all other applications running on your system.

Double click GetSystemInfo.exe to open it. It will display an agreement. Click on I Agree to continue.

Click the Settings button.



Set the slider to Maximum.



IMPORTANT! Then, click Customize - choose Driver / Ports tab and uncheck Scan Ports.



On the General tab, make sure all of the boxes are checked.



On the Misc tab, make sure all the checkboxes are checked.

Then, click OK on the windows that you launched.


Click Create Report to run it.


It will begin scanning.

It will create a zip folder called GetSystemInfo_XXXXXXXXXXXXXX.zip on your Desktop.

It should automatically upload it to http://www.getsysteminfo.com. If it does not, then please SUBMIT it manually by going to the site and doing the upload process.

It will redirect to a page, where it will provide a sharing URL for specialists. Copy and paste the url of the GSI Parser report in your next reply..
This is the Link for the scan you ask me to run.

http://www.getsysteminfo.com/read.php?file=9611b27f6d736101e8a00701428f6410

Also i did run the SFC scan that you ask me to as i said in last report it would not let me get logs from CBS kept saying ACCESS DENIED. but did run the scan as you said just the logs could not get for you i found them no problem but would not let me open them.

THANK YOU SuperDave

JENZO Quote
Also i did run the SFC scan that you ask me to as i said in last report it would not let me get logs from CBS kept saying ACCESS DENIED. but did run the scan as you said just the logs could not get for you i found them no problem but would not let me open them.
I don't believe SFC will produce a log. If it finds a corrupt file it will replace it with one from the disk. If there is no disk, then it will ask for the disk. That's a tipoff that there's something amiss with the files.

Did you try my suggestions for the black screen and the files?

Download OTL  to your Desktop
  • Double click on the icon to run it. Make sure all other windows are CLOSED and to let it run uninterrupted.
  • Under the Custom Scan box paste this in
netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%SYSTEMDRIVE%\*.exe
%systemroot%\*. /mp /s
c:\$recycle.bin\*.* /s
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
nvstor32.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
explorer.exe
svchost.exe
userinit.exe
qmgr.dll
ws2_32.dll
proquota.exe
imm32.dll
kernel32.dll
ndis.sys
autochk.exe
spoolsv.exe
xmlprov.dll
ntmssvc.dll
mswsock.dll
Beep.SYS
ntfs.sys
termsrv.dll
sfcfiles.dll
st3shark.sys
ahcix86.sys
srsvc.dll
nvrd32.sys
/md5stop
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time
Hi SuperDave yes i have tried the things you said about the files & screen saver but it works on the files till i go back on to the mail desktop then go back to the file they all blank again also the screen is still black i have tried to put different pictures mighjt all work when what ever is wrong with computer it will fix it, Just as well the SFC did not ask for a disk my computer came with VISTA installed on it so do not have a disk.

LOG FOR OTL:

OTL logfile created on: 20/04/2011 10:41:53 - Run 2
OTL by OldTimer - Version 3.2.22.3     Folder = C:\Users\Jenzo\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
 
3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 40.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): ?:\pagefile.sys
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 458.92 Gb Total Space | 195.68 Gb Free Space | 42.64% Space Free | Partition Type: NTFS
 
Computer Name: MY | User Name: Jenzo | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011/04/20 10:41:16 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Jenzo\Desktop\OTL.exe
PRC - [2011/04/11 17:12:59 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2011/04/11 17:12:58 | 000,281,768 | ---- | M] (Avira GmbH) -- c:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011/04/11 17:12:58 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/03/23 09:20:39 | 000,403,240 | ---- | M] (Valve Corporation) -- C:\Program Files\Common Files\Steam\SteamService.exe
PRC - [2011/03/19 07:13:34 | 011,857,920 | ---- | M] (Electronic Arts) -- C:\Program Files\Electronic Arts\EADM\EADMUI\EADMUI.exe
PRC - [2011/03/19 07:10:46 | 002,437,120 | ---- | M] (Electronic Arts) -- C:\Program Files\Electronic Arts\EADM\EADMUI\EADM.exe
PRC - [2011/03/19 07:05:02 | 000,759,088 | ---- | M] (Electronic Arts) -- C:\Program Files\Electronic Arts\EADM\EADMUI\EACoreServer.exe
PRC - [2011/03/18 18:57:02 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/02/22 14:57:34 | 000,378,128 | ---- | M] (PC Tools) -- C:\Program Files\ThreatFire\TFTray.exe
PRC - [2011/01/07 22:06:12 | 000,803,432 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
PRC - [2011/01/07 20:48:56 | 000,378,984 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2010/12/14 13:34:57 | 001,242,448 | ---- | M] (Valve Corporation) -- C:\Program Files\Steam\steam.exe
PRC - [2010/12/13 15:37:46 | 000,135,536 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe
PRC - [2010/01/14 22:12:21 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009/10/23 20:34:36 | 000,827,904 | ---- | M] () -- C:\Program Files\dvd43\DVD43_Tray.exe
PRC - [2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
 
 
========== Modules (SafeList) ==========
 
MOD - [2011/04/20 10:41:16 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Jenzo\Desktop\OTL.exe
MOD - [2010/08/31 16:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [Disabled | Stopped] --  -- (ServiceLayer)
SRV - [2011/04/11 17:12:59 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011/04/11 17:12:58 | 000,421,032 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE -- (AntiVirWebService)
SRV - [2011/04/11 17:12:58 | 000,339,624 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe -- (AntiVirMailService)
SRV - [2011/04/11 17:12:58 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011/03/23 09:20:39 | 000,403,240 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011/02/22 14:57:30 | 000,070,928 | ---- | M] (PC Tools) [Auto | Stopped] -- C:\Program Files\ThreatFire\TFService.exe -- (ThreatFire)
SRV - [2011/01/07 20:48:56 | 000,378,984 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2010/12/13 15:37:46 | 000,135,536 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc)
SRV - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/01/21 03:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011/04/17 02:43:32 | 000,279,712 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2011/04/17 02:43:32 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2011/04/11 17:12:59 | 000,137,656 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2011/04/11 17:12:59 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011/02/23 08:27:00 | 010,468,360 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2011/02/22 14:57:52 | 000,069,392 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\TfSysMon.sys -- (TfSysMon)
DRV - [2011/02/22 14:57:52 | 000,033,552 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\TfNetMon.sys -- (TfNetMon)
DRV - [2011/02/22 14:57:50 | 000,051,984 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\TfFsMon.sys -- (TfFsMon)
DRV - [2010/12/02 23:30:44 | 000,025,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nx6000.sys -- (MSHUSBVideo)
DRV - [2010/08/16 08:50:16 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010/08/16 08:50:14 | 000,102,856 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avfwot.sys -- (avfwot)
DRV - [2010/08/16 08:50:14 | 000,079,432 | ---- | M] (Avira GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\avfwim.sys -- (avfwim)
DRV - [2010/06/23 09:21:32 | 000,259,176 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2010/05/26 21:12:57 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 11:25:50 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2010/02/17 11:15:58 | 000,012,872 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2009/09/16 10:22:48 | 000,214,664 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2009/09/16 10:22:48 | 000,079,816 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2009/09/16 10:22:48 | 000,040,552 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfesmfk.sys -- (mfesmfk)
DRV - [2009/09/16 10:22:48 | 000,035,272 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2009/09/16 10:22:14 | 000,034,248 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdk.sys -- (mferkdk)
DRV - [2009/02/03 16:36:58 | 000,059,000 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2008/01/21 03:23:26 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\irsir.sys -- (irsir)
DRV - [2007/06/02 15:59:42 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\PeerGuardian2\pgfilter.sys -- (pgfilter)
DRV - [2007/03/20 11:33:26 | 000,028,672 | ---- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\libusb0.sys -- (libusb0)
DRV - [2007/02/08 18:44:43 | 000,083,320 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfvfs02.sys -- (sfvfs02) StarForce Protection VFS Driver (version 2.x)
DRV - [2006/07/10 17:19:58 | 000,027,032 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x)
DRV - [2006/06/14 15:56:56 | 000,013,680 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.msn.com/?ocid=OIE9HP
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/1me10IE9ENGB/110
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B3 45 3A 13 17 56 CA 01  [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultthis.en gineName: "ZoneAlarm Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2611275&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "ZoneAlarm Customized Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.19.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:20110101
FF - prefs.js..keyword.URL: "chrome://browser-region/locale/region.properties"
 
 
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/24 11:13:52 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/24 11:13:51 | 000,000,000 | ---D | M]
 
[2009/08/24 15:58:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenzo\AppData\Roaming\Mozilla\Extensions
[2011/04/10 06:04:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenzo\AppData\Roaming\Mozilla\Firefox\Profiles\4w1ng7ty.default\extensions
[2010/04/27 08:48:44 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Jenzo\AppData\Roaming\Mozilla\Firefox\Profiles\4w1ng7ty.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/29 21:39:54 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Users\Jenzo\AppData\Roaming\Mozilla\Firefox\Profiles\4w1ng7ty.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}(12)
[2011/03/25 08:44:07 | 000,000,000 | ---D | M] (Zynga Community Toolbar) -- C:\Users\Jenzo\AppData\Roaming\Mozilla\Firefox\Profiles\4w1ng7ty.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/04/10 06:04:31 | 000,000,000 | ---D | M] (Battlefield Play4Free) -- C:\Users\Jenzo\AppData\Roaming\Mozilla\Firefox\Profiles\4w1ng7ty.default\extensions\[email protected]
[2010/12/17 16:14:25 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Users\Jenzo\AppData\Roaming\Mozilla\Firefox\Profiles\4w1ng7ty.default\extensions\[email protected]
[2011/03/12 16:39:26 | 000,000,000 | ---D | M] (Personas) -- C:\Users\Jenzo\AppData\Roaming\Mozilla\Firefox\Profiles\4w1ng7ty.default\extensions\[email protected]
[2010/06/08 23:00:34 | 000,000,921 | ---- | M] () -- C:\Users\Jenzo\AppData\Roaming\Mozilla\Firefox\Profiles\4w1ng7ty.default\searchplugins\conduit.xml
[2011/03/24 11:13:52 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/12/18 13:35:27 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/07/23 15:20:35 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/08 15:14:10 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/13 02:49:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/16 19:03:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/17 23:12:15 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) --
() (No name found) -- C:\USERS\JENZO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4W1NG7TY.DEFAULT\EXTENSIONS\{340C2BBC-CE74-4362-90B5-7C26312808EF}.XPI
() (No name found) -- C:\USERS\JENZO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4W1NG7TY.DEFAULT\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}.XPI
() (No name found) -- C:\USERS\JENZO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4W1NG7TY.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/03/18 18:57:02 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/05/05 06:17:35 | 000,024,683 | ---- | M] (Ask.com) -- C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll
[2011/02/02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 09:00:00 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/01/01 09:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2010/01/01 09:00:00 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/01/01 09:00:00 | 000,001,180 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/01/01 09:00:00 | 000,001,135 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
 
O1 HOSTS File: ([2011/04/13 05:29:58 | 000,000,052 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [dvd43] C:\Program Files\dvd43\DVD43_Tray.exe ()
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe (PC Tools)
O4 - HKCU..\Run: [EADM] C:\Program Files\Electronic Arts\EADM\EADMUI\EADMUI.exe (Electronic Arts)
O4 - HKCU..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\rmtray.exe (PC Tools)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil10o_Plugin.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\DisableRegistryTools:  = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\DisableRegistryTools\ShowInfoTip:  = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Users\Jenzo\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Jenzo\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [ = comfile] -- "%1" %*
O37 - HKLM\...exe [ = exefile] -- "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - StartUpFolder: C:^Users^Jenzo^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CNET TechTracker.lnk - Reg Error: Value error. - File not found
MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg: Messenger (Yahoo!) - hkey= - key= - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
MsConfig - StartUpReg: msnmsgr - hkey= - key= - C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
MsConfig - StartUpReg: Sidebar - hkey= - key= - C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
MsConfig - StartUpReg: Windows Defender - hkey= - key= -  File not found
MsConfig - State: "startup" - 2
MsConfig - State: "services" - 2
 
SafeBootMin: AppMgmt -  File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PEVSystemStart - Service
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: procexp90.Sys - Driver
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt -  File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: MpfService - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PEVSystemStart - Service
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: procexp90.Sys - Driver
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vsmon - Service
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error.
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{0d6d480a-b17b-4aa2-9156-ce888156e8d2} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011/04/20 10:41:16 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\Jenzo\Desktop\OTL.exe
[2011/04/19 20:15:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/04/19 20:14:55 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/04/19 19:55:11 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/04/19 19:55:04 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/04/19 19:14:59 | 000,611,624 | ---- | C] (Kaspersky Lab) -- C:\Users\Jenzo\Desktop\GetSystemInfo.exe
[2011/04/18 08:47:07 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{8B8FDA98-FB47-4CCE-AA3A-3F13D3197CFC}
[2011/04/17 21:07:09 | 000,000,000 | ---D | C] -- C:\ProgramData\SpecialBit
[2011/04/17 19:05:50 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{8D72AA64-1097-4593-8FB2-B6EA9F1B5658}
[2011/04/17 02:43:46 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Roaming\Games
[2011/04/17 02:42:48 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallShield
[2011/04/17 02:41:58 | 000,000,000 | ---D | C] -- C:\Windows\LastGood
[2011/04/17 02:41:51 | 000,000,000 | ---D | C] -- C:\Windows\System32\AGEIA
[2011/04/17 02:41:50 | 000,000,000 | ---D | C] -- C:\Program Files\AGEIA Technologies
[2011/04/17 02:41:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Focus
[2011/04/17 02:38:36 | 000,000,000 | ---D | C] -- C:\Program Files\Focus
[2011/04/17 02:33:16 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{E3B986F9-998E-42C2-957C-8DCCEE57C0D2}
[2011/04/16 16:43:36 | 000,000,000 | ---D | C] -- C:\ProgramData\SpecialBit Games
[2011/04/16 16:42:22 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haunted Hotel II - Believe the Lies
[2011/04/16 16:42:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haunted Hotel II - Believe the Lies
[2011/04/16 16:42:22 | 000,000,000 | ---D | C] -- C:\Program Files\Haunted Hotel II - Believe the Lies
[2011/04/16 16:41:44 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haunted Hotel
[2011/04/16 16:41:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haunted Hotel
[2011/04/16 16:41:44 | 000,000,000 | ---D | C] -- C:\Program Files\Haunted Hotel
[2011/04/16 16:41:31 | 000,000,000 | ---D | C] -- C:\Program Files\bfgclient
[2011/04/16 16:41:25 | 000,000,000 | ---D | C] -- C:\BigFishGamesCache
[2011/04/16 13:16:34 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{A66A2B64-BA03-414A-933F-BCD41AE937C5}
[2011/04/16 01:55:06 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\Documents\Battlefield 2
[2011/04/16 01:48:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\EasyInfo
[2011/04/16 01:16:07 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{5A7887E3-D55B-4CD5-AF36-C827D7669E15}
[2011/04/15 22:05:23 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/15 11:13:09 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\Desktop\Kew Association V Barnes
[2011/04/15 08:22:44 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011/04/15 02:09:15 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{5D0BABCF-8578-4EDB-81BE-C0B63D612E95}
[2011/04/13 05:38:35 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{A17467E1-0301-4E81-A57F-109882E50878}
[2011/04/13 05:38:25 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Roaming\Windows Live Writer
[2011/04/13 05:38:25 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\Windows Live Writer
[2011/04/13 05:04:56 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{E25CE24C-2DDA-4EF2-BAB5-44F2D3321744}
[2011/04/11 17:10:44 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Roaming\Avira
[2011/04/11 14:33:07 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\Documents\Battlefield Play4Free
[2011/04/10 16:06:21 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{CD71DF95-AEE1-46FB-9877-BA17845BEF77}
[2011/04/10 04:05:54 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{5E4A142B-A8AC-42A6-91B9-0899EDDA128F}
[2011/04/09 14:36:59 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{0BEE5CEB-D003-4DB2-96AD-558A1342BF4E}
[2011/04/07 11:45:43 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\Macroplant,_LLC
[2011/04/06 11:31:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2011/04/05 15:39:53 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{1355D98B-7E6E-4CD4-86CB-D61DF846BD8F}
[2011/04/05 03:39:24 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{4F75B93E-DEE1-4CBF-A3F9-2AE5EA85919D}
[2011/03/31 11:41:52 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\Documents\SHIFT 2 UNLEASHED
[2011/03/31 10:17:43 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\{223F4ADE-FE60-40AF-858A-67E46B993228}
[2011/03/28 11:41:41 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\AppData\Local\Macroplant
[2011/03/28 11:37:50 | 000,000,000 | ---D | C] -- C:\Program Files\iPhone Explorer
[2011/03/27 05:40:28 | 000,043,520 | ---- | C] (http://libusb-win32.sourceforge.net) -- C:\Windows\System32\libusb0.dll
[2011/03/27 05:40:28 | 000,028,672 | ---- | C] (http://libusb-win32.sourceforge.net) -- C:\Windows\System32\drivers\libusb0.sys
[2011/03/27 03:32:49 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\.shsh
[2011/03/25 15:14:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeerGuardian 2
[2011/03/25 15:14:45 | 000,000,000 | ---D | C] -- C:\Program Files\PeerGuardian2
[2011/03/25 09:45:24 | 000,000,000 | ---D | C] -- C:\ProgramData\SecTaskMan
[2011/03/22 09:49:36 | 000,000,000 | ---D | C] -- C:\Users\Jenzo\Favorites
[2010/10/04 12:01:30 | 000,726,384 | ---- | C] (Electronic Arts) -- C:\Program Files\AutoRun.exe
[2009/08/26 13:26:35 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Jenzo\AppData\Roaming\pcouffin.sys
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[18 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011/04/20 10:41:16 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Jenzo\Desktop\OTL.exe
[2011/04/20 10:32:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/04/19 20:41:45 | 000,003,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/19 20:41:45 | 000,003,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/19 20:29:31 | 000,000,799 | ---- | M] () -- C:\Users\Jenzo\Desktop\cleanup.bat
[2011/04/19 20:18:06 | 329,933,934 | ---- | M] () -- C:\Users\Jenzo\Desktop\sn0wbreeze_iPhone 3G-4.2.1.ipsw
[2011/04/19 20:15:52 | 000,001,669 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/04/19 19:23:27 | 000,292,565 | ---- | M] () -- C:\Users\Jenzo\Desktop\GetSystemInfo_MY_Jenzo_2011_04_19_19_19_22.zip
[2011/04/19 19:14:59 | 000,611,624 | ---- | M] (Kaspersky Lab) -- C:\Users\Jenzo\Desktop\GetSystemInfo.exe
[2011/04/19 13:16:33 | 001,116,318 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/04/19 13:16:33 | 000,362,214 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/04/17 22:40:20 | 000,002,305 | ---- | M] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/04/17 22:26:37 | 338,579,762 | R--- | M] () -- C:\Users\Jenzo\Desktop\iPhone1,2_4.2.1_8C148_Restore.ipsw
[2011/04/17 02:43:32 | 000,279,712 | ---- | M] () -- C:\Windows\System32\drivers\atksgt.sys
[2011/04/17 02:43:32 | 000,025,888 | ---- | M] () -- C:\Windows\System32\drivers\lirsgt.sys
[2011/04/17 02:41:02 | 000,002,181 | ---- | M] () -- C:\Users\Public\Desktop\Play Sherlock Holmes versus Jack the Ripper.lnk
[2011/04/16 16:42:46 | 000,001,938 | ---- | M] () -- C:\Users\Public\Desktop\Play Haunted Hotel II - Believe the Lies.lnk
[2011/04/16 16:41:59 | 000,001,740 | ---- | M] () -- C:\Users\Public\Desktop\Play Haunted Hotel.lnk
[2011/04/16 16:41:31 | 000,001,729 | ---- | M] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Manager.lnk
[2011/04/16 16:41:31 | 000,001,705 | ---- | M] () -- C:\Users\Public\Desktop\Game Manager.lnk
[2011/04/16 12:48:42 | 026,093,317 | ---- | M] () -- C:\Users\Jenzo\Documents\EA-Battlefield-Bad-Company-2.zip
[2011/04/16 02:09:43 | 000,001,996 | ---- | M] () -- C:\Users\Public\Desktop\Play BF2 SF Online Now!.lnk
[2011/04/16 02:09:43 | 000,001,974 | ---- | M] () -- C:\Users\Public\Desktop\Battlefield 2 Special Forces.lnk
[2011/04/16 01:51:38 | 000,001,890 | ---- | M] () -- C:\Users\Public\Desktop\Play BF2 Online Now!.lnk
[2011/04/16 01:51:38 | 000,001,868 | ---- | M] () -- C:\Users\Public\Desktop\Battlefield 2.lnk
[2011/04/15 12:16:00 | 000,333,100 | ---- | M] () -- C:\Users\Jenzo\AppData\Roaming\vso_ts_preview.xml
[2011/04/15 09:05:47 | 000,001,854 | ---- | M] () -- C:\Users\Public\Desktop\Safari.lnk
[2011/04/15 08:06:13 | 000,303,008 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/04/15 02:01:16 | 000,000,574 | ---- | M] () -- C:\cleanup.bat
[2011/04/13 21:20:41 | 000,138,264 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011/04/13 21:20:10 | 000,234,768 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
[2011/04/13 20:48:50 | 000,000,104 | ---- | M] () -- C:\Users\Jenzo\Desktop\Recycle Bin - Shortcut.lnk
[2011/04/13 20:16:24 | 000,000,809 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011/04/13 10:57:27 | 000,071,282 | ---- | M] () -- C:\Users\Jenzo\Documents\Great New Movies BY JENZO.XtoDVD
[2011/04/13 05:29:58 | 000,000,052 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/04/11 17:12:59 | 000,137,656 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011/04/11 17:12:59 | 000,061,960 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2011/04/10 06:23:37 | 000,138,056 | ---- | M] () -- C:\Users\Jenzo\AppData\Roaming\PnkBstrK.sys
[2011/04/10 06:13:11 | 000,902,709 | ---- | M] () -- C:\Users\Jenzo\Documents\iTunes Diagnostics.spx
[2011/04/10 06:13:11 | 000,003,916 | ---- | M] () -- C:\Users\Jenzo\Documents\iTunes Diagnostics.rtf
[2011/04/10 04:22:15 | 000,015,699 | ---- | M] () -- C:\Users\Jenzo\AppData\Roaming\UserTile.png
[2011/04/09 13:20:10 | 000,000,948 | ---- | M] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/04/06 11:42:13 | 000,000,620 | ---- | M] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\vlc-1.1.8-win32 - Shortcut.lnk
[2011/04/06 11:30:59 | 020,586,196 | ---- | M] () -- C:\Users\Jenzo\Documents\vlc-1.1.8-win32.exe
[2011/04/05 02:08:17 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat
[2011/04/05 02:08:17 | 000,001,988 | ---- | M] () -- C:\Windows\System32\ticrf.rat
[2011/04/05 02:08:09 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2011/04/03 15:37:05 | 000,002,401 | ---- | M] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\Skype.lnk
[2011/03/31 11:41:39 | 000,000,136 | ---- | M] () -- C:\Users\Jenzo\Desktop\SHIFT 2 UNLEASHED™.LNK
[2011/03/29 18:10:46 | 000,001,356 | ---- | M] () -- C:\Users\Jenzo\AppData\Local\d3d9caps.dat
[2011/03/29 17:05:40 | 000,000,080 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.umbrella
[2011/03/29 15:09:10 | 000,604,499 | ---- | M] () -- C:\Users\Jenzo\Desktop\greenpois0n rc5.exe
[2011/03/28 15:36:20 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2011/03/28 06:15:37 | 005,298,620 | ---- | M] () -- C:\Users\Jenzo\Desktop\greenpois0n rc6.exe
[2011/03/27 23:04:48 | 000,000,799 | ---- | M] () -- C:\Windows\System32\cleanup.bat
[2011/03/27 22:48:33 | 018,147,328 | ---- | M] (iH8sn0w) -- C:\Users\Jenzo\Desktop\sn0wbreeze-2.2.1.exe
[2011/03/25 15:21:52 | 000,001,669 | ---- | M] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011/03/25 15:14:46 | 000,000,775 | ---- | M] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\PeerGuardian.lnk
[2011/03/25 15:14:46 | 000,000,751 | ---- | M] () -- C:\Users\Jenzo\Desktop\PeerGuardian.lnk
[2011/03/25 05:59:56 | 000,000,136 | ---- | M] () -- C:\Users\Jenzo\Desktop\Crysis® 2 - Shortcut.lnk
[2011/03/24 13:50:18 | 000,001,052 | ---- | M] () -- C:\Users\Public\Desktop\EA Download Manager.lnk
[2011/03/24 11:13:54 | 000,000,875 | ---- | M] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/24 11:13:54 | 000,000,851 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/03/23 09:09:25 | 000,001,892 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[18 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011/04/19 20:29:31 | 000,000,799 | ---- | C] () -- C:\Users\Jenzo\Desktop\cleanup.bat
[2011/04/19 20:17:05 | 329,933,934 | ---- | C] () -- C:\Users\Jenzo\Desktop\sn0wbreeze_iPhone 3G-4.2.1.ipsw
[2011/04/19 20:15:52 | 000,001,669 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/04/19 19:20:59 | 000,292,565 | ---- | C] () -- C:\Users\Jenzo\Desktop\GetSystemInfo_MY_Jenzo_2011_04_19_19_19_22.zip
[2011/04/17 22:21:47 | 338,579,762 | R--- | C] () -- C:\Users\Jenzo\Desktop\iPhone1,2_4.2.1_8C148_Restore.ipsw
[2011/04/17 02:41:15 | 000,279,712 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2011/04/17 02:41:14 | 000,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2011/04/17 02:41:02 | 000,002,181 | ---- | C] () -- C:\Users\Public\Desktop\Play Sherlock Holmes versus Jack the Ripper.lnk
[2011/04/16 16:42:46 | 000,001,938 | ---- | C] () -- C:\Users\Public\Desktop\Play Haunted Hotel II - Believe the Lies.lnk
[2011/04/16 16:41:59 | 000,001,740 | ---- | C] () -- C:\Users\Public\Desktop\Play Haunted Hotel.lnk
[2011/04/16 16:41:31 | 000,001,729 | ---- | C] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Manager.lnk
[2011/04/16 16:41:31 | 000,001,717 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Manager.lnk
[2011/04/16 16:41:31 | 000,001,705 | ---- | C] () -- C:\Users\Public\Desktop\Game Manager.lnk
[2011/04/16 12:47:08 | 026,093,317 | ---- | C] () -- C:\Users\Jenzo\Documents\EA-Battlefield-Bad-Company-2.zip
[2011/04/16 02:09:43 | 000,001,996 | ---- | C] () -- C:\Users\Public\Desktop\Play BF2 SF Online Now!.lnk
[2011/04/16 02:09:43 | 000,001,974 | ---- | C] () -- C:\Users\Public\Desktop\Battlefield 2 Special Forces.lnk
[2011/04/16 01:51:38 | 000,001,890 | ---- | C] () -- C:\Users\Public\Desktop\Play BF2 Online Now!.lnk
[2011/04/16 01:51:38 | 000,001,868 | ---- | C] () -- C:\Users\Public\Desktop\Battlefield 2.lnk
[2011/04/15 02:01:16 | 000,000,574 | ---- | C] () -- C:\cleanup.bat
[2011/04/13 10:57:27 | 000,071,282 | ---- | C] () -- C:\Users\Jenzo\Documents\Great New Movies BY JENZO.XtoDVD
[2011/04/10 04:22:15 | 000,015,699 | ---- | C] () -- C:\Users\Jenzo\AppData\Roaming\UserTile.png
[2011/04/06 11:42:13 | 000,000,620 | ---- | C] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\vlc-1.1.8-win32 - Shortcut.lnk
[2011/04/06 11:30:42 | 020,586,196 | ---- | C] () -- C:\Users\Jenzo\Documents\vlc-1.1.8-win32.exe
[2011/04/05 02:08:09 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2011/03/31 11:41:39 | 000,000,136 | ---- | C] () -- C:\Users\Jenzo\Desktop\SHIFT 2 UNLEASHED™.LNK
[2011/03/27 22:44:51 | 000,000,799 | ---- | C] () -- C:\Windows\System32\cleanup.bat
[2011/03/27 02:24:25 | 000,902,709 | ---- | C] () -- C:\Users\Jenzo\Documents\iTunes Diagnostics.spx
[2011/03/27 02:24:25 | 000,003,916 | ---- | C] () -- C:\Users\Jenzo\Documents\iTunes Diagnostics.rtf
[2011/03/25 15:21:52 | 000,001,669 | ---- | C] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011/03/25 15:14:46 | 000,000,775 | ---- | C] () -- C:\Users\Jenzo\Application Data\Microsoft\Internet Explorer\Quick Launch\PeerGuardian.lnk
[2011/03/25 15:14:46 | 000,000,751 | ---- | C] () -- C:\Users\Jenzo\Desktop\PeerGuardian.lnk
[2011/03/25 05:59:56 | 000,000,136 | ---- | C] () -- C:\Users\Jenzo\Desktop\Crysis® 2 - Shortcut.lnk
[2011/03/24 11:13:54 | 000,000,863 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/03/24 11:13:54 | 000,000,851 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/03/12 16:58:21 | 000,084,480 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2010/12/18 13:40:37 | 000,000,048 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/12/16 15:25:49 | 000,682,280 | ---- | C] () -- C:\Windows\System32\pbsvc.exe
[2010/12/03 06:42:02 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2010/10/14 02:36:44 | 000,179,263 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2010/10/04 12:01:30 | 000,000,157 | ---- | C] () -- C:\Program Files\autorun.inf
[2010/10/04 12:01:28 | 009,822,208 | ---- | C] () -- C:\Program Files\autorun.dat
[2010/10/04 12:01:28 | 000,000,185 | ---- | C] () -- C:\Program Files\p0.cab
[2010/10/04 12:01:22 | 063,013,682 | ---- | C] () -- C:\Program Files\o0.cab
[2010/10/04 11:59:28 | 1508,976,877 | ---- | C] () -- C:\Program Files\d0.cab
[2010/10/04 11:59:28 | 006,866,468 | ---- | C] () -- C:\Program Files\c0.cab
[2010/10/04 11:59:24 | 000,138,264 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2010/10/04 11:59:08 | 000,234,768 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2010/10/04 11:59:02 | 002,601,752 | ---- | C] () -- C:\Windows\System32\pbsvc_moh.exe
[2010/10/04 11:59:02 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2010/07/30 17:41:14 | 000,001,184 | ---- | C] () -- C:\Windows\eReg.dat
[2010/05/05 07:58:25 | 000,000,597 | ---- | C] () -- C:\Windows\wininit.ini
[2010/04/08 16:44:47 | 000,001,356 | ---- | C] () -- C:\Users\Jenzo\AppData\Local\d3d9caps.dat
[2010/03/19 19:47:58 | 000,138,056 | ---- | C] () -- C:\Users\Jenzo\AppData\Roaming\PnkBstrK.sys
[2009/12/03 09:27:30 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2009/10/07 12:38:38 | 000,069,632 | ---- | C] () -- C:\Windows\System32\xmltok.dll
[2009/10/07 12:38:38 | 000,036,864 | ---- | C] () -- C:\Windows\System32\xmlparse.dll
[2009/09/27 07:10:34 | 000,000,100 | ---- | C] () -- C:\Users\Jenzo\AppData\Roaming\wklnhst.dat
[2009/09/23 12:12:16 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/09/23 12:12:16 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/08/26 13:27:06 | 000,333,100 | ---- | C] () -- C:\Users\Jenzo\AppData\Roaming\vso_ts_preview.xml
[2009/08/26 13:26:35 | 000,007,887 | ---- | C] () -- C:\Users\Jenzo\AppData\Roaming\pcouffin.cat
[2009/08/26 13:26:35 | 000,001,144 | ---- | C] () -- C:\Users\Jenzo\AppData\Roaming\pcouffin.inf
[2009/08/26 13:17:37 | 000,007,680 | ---- | C] () -- C:\Users\Jenzo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009/06/23 16:57:30 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2007/10/25 17:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2006/11/02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 13:47:37 | 000,303,008 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 11:33:01 | 001,116,318 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 11:33:01 | 000,362,214 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
 
========== LOP Check ==========
 
[2011/04/19 18:55:54 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\BitTorrent
[2010/03/26 20:30:01 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\CBS Interactive
[2010/07/15 10:22:02 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\CheckPoint
[2009/11/16 20:03:03 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/07/21 12:31:26 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\ESET
[2010/11/17 00:00:58 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Flood Light Games
[2010/11/16 23:30:49 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\FloodLightGames
[2011/04/17 02:44:55 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Games
[2010/12/03 06:46:20 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\MAGIX
[2010/09/22 10:58:26 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Mount&Blade Warband
[2010/09/09 12:02:02 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Need for Speed World
[2010/02/03 22:10:07 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Nokia
[2010/02/03 21:14:51 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\PC Suite
[2010/10/13 00:38:54 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\ProtectDISC
[2010/07/02 12:00:11 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Samsung
[2010/05/27 13:38:11 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\SEGA Corporation
[2010/06/05 21:22:26 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Sports Interactive
[2011/04/16 12:44:18 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\SystemRequirementsLab
[2009/09/27 07:12:06 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Template
[2010/11/16 09:40:40 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Tropico 3 Demo
[2010/03/27 21:45:26 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\TS3Client
[2010/04/10 11:08:11 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Ubisoft
[2011/04/15 12:16:01 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Vso
[2011/04/13 05:38:25 | 000,000,000 | ---D | M] -- C:\Users\Jenzo\AppData\Roaming\Windows Live Writer
[2011/04/16 12:17:23 | 000,032,648 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %SYSTEMDRIVE%\*.exe >
[2007/11/07 09:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
 
< %systemroot%\*. /mp /s >
 
< c:\$recycle.bin\*.* /s >
[2011/04/18 08:57:24 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$I1D7MMA.mp3
[2011/04/18 09:01:08 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$I9WYJ2Q.mp3
[2011/04/20 10:40:12 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$IFS6Z3O.html
[2011/04/19 19:53:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$IKZU7Q2.ipa
[2011/04/18 08:57:10 | 058,959,727 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$R1D7MMA.mp3
[2011/04/18 08:53:09 | 031,099,986 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$R9WYJ2Q.mp3
[2011/04/20 10:39:44 | 000,009,390 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RFS6Z3O.html
[2011/03/12 22:24:23 | 021,372,799 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RKZU7Q2.ipa
[2010/07/21 10:15:23 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\desktop.ini
[2010/10/26 21:17:00 | 000,000,402 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$R0HRNJ1\Favorites\desktop.ini
[2010/04/09 06:58:44 | 000,000,080 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$R0HRNJ1\Favorites\Links\desktop.ini
[2009/10/19 12:32:19 | 000,000,382 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$R2TESFY\desktop.ini
[2009/05/15 23:23:34 | 000,000,317 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$R2TESFY\Black Eyed Peas - Monkey Business (2005) - 320 KBPS by blondu4all\desktop.ini
[2009/08/30 19:39:16 | 000,000,296 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$R7NZS7O\desktop.ini
[2009/10/10 11:56:18 | 000,000,391 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RAO8EEK\desktop.ini
[2009/06/14 14:33:22 | 000,000,328 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RDFEJXC\desktop.ini
[2010/03/22 07:21:50 | 000,000,362 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RHTRIBM\desktop.ini
[2010/03/22 07:31:35 | 000,000,298 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RITT528\desktop.ini
[2009/10/19 12:33:04 | 000,000,322 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RRX81K4\desktop.ini
[2010/03/26 20:33:27 | 000,000,402 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RV620Y3\Favorites\desktop.ini
[2010/10/26 21:27:00 | 000,000,402 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RX6G98Z\Favorites\desktop.ini
[2010/11/06 21:31:31 | 000,000,080 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RX6G98Z\Favorites\Links\desktop.ini
[2010/12/15 06:27:00 | 000,000,402 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RY566S7\Favorites\desktop.ini
[2011/01/08 09:53:09 | 000,000,080 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RY566S7\Favorites\Links\desktop.ini
[2009/11/10 14:48:49 | 000,000,391 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2445409639-1796169833-2764227393-1000\$RZ6T9NS\desktop.ini
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-19 08:28:52
 
 
< MD5 for: AGP440.SYS  >
[2008/01/21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\ERDNT\cache\AGP440.sys
[2008/01/21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys
[2008/01/21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009/04/11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\ERDNT\cache\atapi.sys
[2009/04/11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009/04/11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/21 03:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/21 03:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 10:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) I was looking at ThreatFire  under the ADVANCED TOOLS >> SYSTEM ACTIVITY MONITOR >> PROTECTED and i found a file by the name of

6ac3f99b-de48-4ea7-8e9d-9ab6f1df2286.exe  I tried to look this file up on the start menu but nothing came up & asked for more info on this file but nothing , I have looked it up on goggle but nothing on there as well so just wondering if this was any good to you just in case might mean something to you.

Hope this helps you in any way
THANKS FOR ALL THE HELP SO FAR SuperDave

JENZO I look in my ThreatFire but I can't find Protection in Advanced Tools. Neither can I find that exe file.
It's been about one week since we started this cleaning. Other than the black background, is there anything else wrong with the computer?
If Vista came install do you have the Recovery Console installed?With ThreatFire on the Advance Tools made a pic of the place to find it PROTECED is at the bottom on the left list  on pic the program is not there now


By jenzos at 2011-04-20

the computer is still slow the anti virus keeps closing down by itself then back on again. I know might have to wipe computer but 1 thing I HAVE NO RECOVERY DISC  did not get 1 with computer when new it came installed with VISTA  already is there a way to make RECOVERY DISC if so if you can tell me i do that & wipe computer start from new because you cannot find nothing so what ever it is attacking my computer is hiding well from you IF YOU CANNOT FIND IT SuperDave then i have no chance but to wipe it  .

If you can please tell me where to get main Vista file to make BACK UP DISC i do that will not take up more of your time you have tried your best for me you helped me out 2 times before & we cleaned up the computers but this 1 has got me 

THANK YOU FOR THE HELP SO FAR SuperDave  sorry if wasted your time if i wipe computer 

JENZO

JUST FOUND IN TREATFIRE  Quarantine: FILE C:\CLEANUP.EXE  Trojan.Zapchast!sd6   15/04/11   02:08:07

Computer just keeps freezing up when your typing or opening programs & as i said SECURITY system keeps shutting & opening up when it likes My version of ThreatFire doesn't have that tab.

Quote
I HAVE NO RECOVERY DISC  did not get 1 with computer when new it came installed with VISTA  already is there a way to make RECOVERY DISC if so if you can tell me i do that & wipe computer start from new because you cannot find nothing so what ever it is attacking my computer is hiding well from you IF YOU CANNOT FIND IT SuperDave then i have no chance but to wipe it 
It either has the Recovery Console installed or you have the ability to create a RC disk. That's what I had to do with my laptop. Of course, that was a few years ago. I would imagine they all come with the RC installed. If it's there, you should see a separate partition on your C: drive

Quote
If you can please tell me where to get main Vista file to make BACK UP DISC i do that will not take up more of your time you have tried your best for me you helped me out 2 times before & we cleaned up the computers but this 1 has got me 
On my laptop it has a Recovery Disk Creator. You probably should ask that question in the Vista forum

Quote
THANK YOU FOR THE HELP SO FAR SuperDave  sorry if wasted your time if i wipe computer 
You're welcome but I don't consider it a waste of time. We've run a lot of scans and really couldn't find anything serious.Thank you so much for all the time that you have spent helping me. i think i look into one of the courses that teach you how to look for & fix spyware & malaware  would be good to help people give something back.

will let you know how i get on i have to go away tomorrow so back in 2 weeks so will leave you a PM how i get on.

Take Care mate all the best     SuperDave   

JENZO Quote
i think i look into one of the courses that teach you how to look for & fix spyware & malaware  would be good to help people give something back.
Great, I could use the help. Thanks. I will lock this thread. If you need it re-opened, please send me a pm.
1373.

Solve : broken digital signature?

Answer»

Hi

I did a scan with AVG and it came up with broken digital signatures from MALAWARE BYTES. What does this mean and should I remove Malaware bytes. Is this harmful to my computer?

I READ AVG is difficult to install unlike other problems where you simply uninstall at CONTROL panel wondering the best way to go about this and if it is true.

thanks
LeighDuplicate post. Locked

1374.

Solve : NO SOUND ON MY DELL VOSTRO 1520?

Answer»

Hi,
    I need your help. I read a few threads where you helped people resolve w32.sillyFDC virus.

    My laptop- windows 7- was working perfectly fine untill 2 days back. I was watching a show on VLC media player, the sound suddenly started scratching and then disappeared. Since then I have done the following:-
    1. Updated all drivers
    2. Cleaned up temporary files
    3. ran ad-aware, malware as well as norton anti virus protections. They all showed different problems and said they were fixed. the latest one is on norton which shows three HIGH risks- 1. w32.sillyFDC 2. w32.changeup.C 3. Trojanhorse. The norton log says it has been fixed and no action required.
    4. I also tried system restore to an earlier point, but it gives me an error "not successfull as an anti-virus program is running in the background" even when there is no spyware running.

    Please help me in fixing this.

i have read the manula and below are my logs from superantispyware, mbam and hijack this-

superantispyware log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 04/10/2011 at 10:18 PM

Application Version : 4.50.1002

Core Rules Database Version : 6799
Trace Rules Database Version: 4611

Scan type       : Complete Scan
Total Scan Time : 01:43:04

Memory items scanned      : 753
Memory threats detected   : 0
Registry items scanned    : 10921
Registry threats detected : 0
File items scanned        : 155425
File threats detected     : 119

Adware.Tracking Cookie
   C:\Users\Namrata\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Namrata\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Namrata\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Namrata\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Namrata\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][3].txt
   C:\Users\Namrata\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Namrata\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Namrata\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Namrata\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Namrata\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Namrata\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   s0.2mdn.net [ C:\Users\Guest\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3ENSHXAY ]
   .chitika.net [ C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\piiaz0s2.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   statse.webtrendslive.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .content.yieldmanager.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .doubleclick.net [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   fidelity.rotator.hadj7.adjuggler.net [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   fidelity.rotator.hadj7.adjuggler.net [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   fidelity.rotator.hadj7.adjuggler.net [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .mm.chitika.net [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .technoratimedia.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .technoratimedia.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .technoratimedia.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .technoratimedia.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .technoratimedia.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .technoratimedia.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   wstat.wibiya.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .yieldmanager.net [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.googleadservices.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .imrworldwide.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .imrworldwide.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   vlc-media-player.en.softonic.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   vlc-media-player.en.softonic.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   vlc-media-player.en.softonic.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .vlcmediaplayer.org [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .vlcmediaplayer.org [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .vlcmediaplayer.org [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   trekmedia.net [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.trekmedia.net [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.visit-tracker.biz [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.trekmedia.net [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.visit-tracker.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.visit-tracker.biz [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.visit-tracker.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .smartadserver.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .smartadserver.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .smartadserver.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .smartadserver.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .kontera.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .xiti.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .collective-media.net [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .kontera.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .smartadserver.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .interclick.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .kontera.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .kontera.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .interclick.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   segment-pixel.invitemedia.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .collective-media.net [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .atdmt.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .atdmt.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .at.atwola.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tacoda.at.atwola.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tacoda.at.atwola.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tacoda.at.atwola.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tacoda.at.atwola.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .at.atwola.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tacoda.at.atwola.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tacoda.net [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ar.atwola.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adserver.adtechus.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .www.burstnet.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .burstnet.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .burstnet.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.burstnet.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tribalfusion.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .content.yieldmanager.com [ C:\Users\Namrata\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adserver.adtechus.com [ C:\Users\Namrata\AppData\Roaming\Mozilla\Firefox\Profiles\febi2yip.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\Namrata\AppData\Roaming\Mozilla\Firefox\Profiles\febi2yip.default\cookies.sqlite ]
   .doubleclick.net [ C:\Users\Namrata\AppData\Roaming\Mozilla\Firefox\Profiles\febi2yip.default\cookies.sqlite ]
   .mm.chitika.net [ C:\Users\Namrata\AppData\Roaming\Mozilla\Firefox\Profiles\febi2yip.default\cookies.sqlite ]
   .zedo.com [ C:\Users\Namrata\AppData\Roaming\Mozilla\Firefox\Profiles\febi2yip.default\cookies.sqlite ]
   .zedo.com [ C:\Users\Namrata\AppData\Roaming\Mozilla\Firefox\Profiles\febi2yip.default\cookies.sqlite ]
   .zedo.com [ C:\Users\Namrata\AppData\Roaming\Mozilla\Firefox\Profiles\febi2yip.default\cookies.sqlite ]
   .zedo.com [ C:\Users\Namrata\AppData\Roaming\Mozilla\Firefox\Profiles\febi2yip.default\cookies.sqlite ]
   .zedo.com [ C:\Users\Namrata\AppData\Roaming\Mozilla\Firefox\Profiles\febi2yip.default\cookies.sqlite ]
   .zedo.com [ C:\Users\Namrata\AppData\Roaming\Mozilla\Firefox\Profiles\febi2yip.default\cookies.sqlite ]
   .2o7.net [ C:\Users\Namrata\AppData\Roaming\Mozilla\Firefox\Profiles\febi2yip.default\cookies.sqlite ]

Adware.Agent/Gen-Zango
   C:\USERS\NAMRATA\DOWNLOADS\EMULESETUP.EXE



MBAM log:-

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6325

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

10-04-2011 23:09:12
mbam-log-2011-04-10 (23-09-12).txt

Scan type: Quick scan
Objects scanned: 184349
Time elapsed: 4 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 5
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
c:\Windows\System32\supxwatraqwvcgdch.dll (Adware.AdRotator) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{862C6A68-E35F-A359-9031-79DFA8FF365E} (Adware.AdRotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{862C6A68-E35F-A359-9031-79DFA8FF365E} (Adware.AdRotator) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{862C6A68-E35F-A359-9031-79DFA8FF365E} (Adware.AdRotator) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{862C6A68-E35F-A359-9031-79DFA8FF365E} (Adware.AdRotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hfdfwjpsrmiowup (Adware.AdRotator) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kbgrecvqxkyyg (Adware.AdRotator) -> Value: kbgrecvqxkyyg -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Windows\System32\supxwatraqwvcgdch.dll (Adware.AdRotator) -> Delete on reboot.
c:\Users\Namrata\AppData\Local\Temp\browserhotfix1.exe (Adware.Agent) -> Quarantined and deleted successfully.
c:\Users\Namrata\local settings\temporary internet files\Content.IE5\3MMH8ISL\setup[1].exe (Adware.Agent) -> Quarantined and deleted successfully.


hijackthislog:-

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:20:25, on 10-04-2011
Platform: Windows 7  (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\OEM13Mon.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\conhost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\regsvr32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PcSync2.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Program Files\SUPERAntiSpyware\6354c80e-8a16-4371-beda-9ff4579d8d9e.com
C:\Windows\system32\wuauclt.exe
C:\Windows\System32\NOTEPAD.EXE
C:\Users\Namrata\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Namrata\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Namrata\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\System32\NOTEPAD.EXE
C:\Windows\System32\NOTEPAD.EXE
C:\Users\Namrata\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Namrata\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HiJackThis\sniper.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USSMB/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,START Page = http://search.conduit.com?SearchSource=10&ctid=CT2405280
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MIF5BA~1\Office12\GR469A~1.DLL
O2 - BHO: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O3 - Toolbar: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
O3 - Toolbar: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [OEM13Mon.exe] C:\Windows\OEM13Mon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [basicsmssmenu] "C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java UPDATE\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [googletalk] C:\Users\Namrata\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PcSync2.exe" /NoDialog
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Google Update] "C:\Users\Namrata\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [TimeSheet] C:\Program Files\TimeSheet\TimeSheet.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: []  (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TimeSheet] C:\Program Files\TimeSheet\TimeSheet.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: []  (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MIF5BA~1\Office12\GRA32A~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Basics Service - Seagate Technology LLC - C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: IPOD Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
O23 - Service: O2FLASH - O2Micro International - C:\Windows\system32\DRIVERS\o2flash.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5f120bca41bba11b\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

--
End of file - 9975 bytes
Your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help. First Warning!Ignore the above post.

1375.

Solve : Got registry bugs........?

Answer»

Please uninstall Antivirus 2010. It is malware.

* Open OTL
* Copy and Paste the following text in the codebox into the Custom Scans/Fixes window.

Code: [Select]:OTL
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} -  File not found
O3 - HKLM\..\Toolbar: (ZoneAlarm Spy Blocker Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} -  File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Spy Blocker Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} -  File not found
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ClientGW]  File not found
O4 - HKLM..\Run: [PCDrProfiler]  File not found
O15 - HKCU\..Trusted Domains: internet ([]about in Internet)

:Files
C:\WINDOWS\tasks\At10.job
C:\WINDOWS\tasks\At9.job
C:\WINDOWS\tasks\At8.job
C:\WINDOWS\tasks\At7.job
C:\WINDOWS\tasks\At6.job
C:\WINDOWS\tasks\At5.job
C:\WINDOWS\tasks\At23.job
C:\WINDOWS\tasks\At22.job
C:\WINDOWS\tasks\At21.job
C:\WINDOWS\tasks\At20.job
C:\WINDOWS\tasks\At19.job
C:\WINDOWS\tasks\At18.job
 C:\WINDOWS\tasks\At17.job
C:\WINDOWS\tasks\At16.job
C:\WINDOWS\tasks\At11.job
C:\WINDOWS\tasks\At15.job
C:\WINDOWS\tasks\At14.job
C:\WINDOWS\tasks\At13.job
C:\WINDOWS\tasks\At12.job
C:\WINDOWS\tasks\At4.job
C:\WINDOWS\tasks\At3.job
C:\WINDOWS\tasks\At24.job
C:\WINDOWS\tasks\At2.job
C:\WINDOWS\tasks\At1.job
:COMMANDS
[resethosts]
[purity]
[emptytemp]
[start explorer]

* Click Run Fix
* OTLI2 may ask to reboot the machine. Please do so if asked.
* Click OK
* A report will open. Copy and Paste that report in your next reply.
***************************************************
Download Security CHECK by screen317 from one of the following links and SAVE it to your desktop.

Link 1
Link 2

* Unzip SecurityCheck.zip and a folder named Security Check should appear.
* Open the Security Check folder and double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
As I mentioned earlier, 'Anti virus 2010' will not uninstall through control panel. If I could find the file, perhaps I could wipe it with DPwiper, but I don't know how to find it, and a search for 'anti virus 2010' comes up blank.

Below are the logs you requested:

All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{201f27d4-3704-41d6-89c1-aa35e39143ed}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{3041d03e-fd4b-44e0-b742-2d9b88305f98} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3041d03e-fd4b-44e0-b742-2d9b88305f98}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{3041D03E-FD4B-44E0-B742-2D9B88305F98} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3041D03E-FD4B-44E0-B742-2D9B88305F98}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ClientGW deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\PCDrProfiler deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\internet\ deleted successfully.
========== FILES ==========
C:\WINDOWS\tasks\At10.job moved successfully.
C:\WINDOWS\tasks\At9.job moved successfully.
C:\WINDOWS\tasks\At8.job moved successfully.
C:\WINDOWS\tasks\At7.job moved successfully.
C:\WINDOWS\tasks\At6.job moved successfully.
C:\WINDOWS\tasks\At5.job moved successfully.
C:\WINDOWS\tasks\At23.job moved successfully.
C:\WINDOWS\tasks\At22.job moved successfully.
C:\WINDOWS\tasks\At21.job moved successfully.
C:\WINDOWS\tasks\At20.job moved successfully.
C:\WINDOWS\tasks\At19.job moved successfully.
C:\WINDOWS\tasks\At18.job moved successfully.
C:\WINDOWS\tasks\At17.job moved successfully.
C:\WINDOWS\tasks\At16.job moved successfully.
C:\WINDOWS\tasks\At11.job moved successfully.
C:\WINDOWS\tasks\At15.job moved successfully.
C:\WINDOWS\tasks\At14.job moved successfully.
C:\WINDOWS\tasks\At13.job moved successfully.
C:\WINDOWS\tasks\At12.job moved successfully.
C:\WINDOWS\tasks\At4.job moved successfully.
C:\WINDOWS\tasks\At3.job moved successfully.
C:\WINDOWS\tasks\At24.job moved successfully.
C:\WINDOWS\tasks\At2.job moved successfully.
C:\WINDOWS\tasks\At1.job moved successfully.
========== COMMANDS ==========
HOSTS file reset successfully
 
[EMPTYTEMP]
 
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 2096855 bytes
->Flash cache emptied: 456 bytes
 
User: All Users
 
User: Compaq_Owner
->Temp folder emptied: 57661349 bytes
->Temporary Internet Files folder emptied: 15735455 bytes
->Java cache emptied: 2379 bytes
->FireFox cache emptied: 94265900 bytes
->Flash cache emptied: 7167 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32768 bytes
 
User: LocalService
->Temp folder emptied: 1056392 bytes
->Temporary Internet Files folder emptied: 33264 bytes
->FireFox cache emptied: 3717997 bytes
 
User: misc pics
 
User: NetworkService
->Temp folder emptied: 1982008 bytes
->Temporary Internet Files folder emptied: 1008811 bytes
->Flash cache emptied: 3557 bytes
 
User: New Folder
 
User: savanah pics
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 19569 bytes
%systemroot%\System32 .tmp files removed: 2952721 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 27838375 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 885602 bytes
RecycleBin emptied: 26624 bytes
 
Total Files Cleaned = 200.00 mb
 
 
OTL by OldTimer - Version 3.2.22.3 log created on 04232011_073419

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...


--------------------------------



 Results of screen317's Security Check version 0.99.10 
 Windows XP Service Pack 3 (UAC is disabled!)
 Internet Explorer 8 
``````````````````````````````
Antivirus/Firewall Check:

 Windows Firewall Disabled! 
 Avira AntiVir Personal - Free Antivirus
 WWII: Normandy     
 Antivirus 2010     
 PC Tools Firewall Plus 6.0 
 ZoneAlarm Spy Blocker Toolbar   
 ZoneAlarm     
 Avira successfully updated!
```````````````````````````````
Anti-malware/Other Utilities Check:

 Malwarebytes' Anti-Malware   
 CCleaner     
 Java(TM) 6 Update 17 
 Out of date Java installed!
 Adobe Flash Player    10.1.102.64 
Adobe Reader 7.0
Out of date Adobe Reader installed!
 Mozilla Thunderbird (3.1.9)
````````````````````````````````
Process Check: 
objlist.exe by Laurent

 Avira Antivir avgnt.exe
 Avira Antivir avguard.exe
 PC Tools Firewall Plus FirewallGUI.exe   
 PC Tools Firewall Plus FWService.exe   
``````````End of Log````````````



Update Your Java (JRE)

Old versions of Java have vulnerabilities that malware can use to infect your system.

First Verify your Java Version

If there are any other version(s) installed then update now.

Get the new version (if needed)

If your version is out of date install the newest version of the Sun Java Runtime Environment.

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close ALL open web browsers before starting the installation.

Remove any old versions

1. Download JavaRa and unzip the file to your Desktop.
2. Open JavaRA.exe and choose Remove Older Versions
3. Once complete exit JavaRA.
4. Run CCleaner.

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
*************************************************
Please download the newest version of Adobe Acrobat Reader from Adobe.com

Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

Once old versions are gone, please install the newest version.
*****************************************************
Quote

As I mentioned earlier, 'Anti virus 2010' will not uninstall through control panel. If I could find the file, perhaps I could wipe it with DPwiper, but I don't know how to find it, and a search for 'anti virus 2010' comes up blank.
Sorry. Let's try to get rid of it this way. Please run another Security Check after you've done this.

* Open OTL
* Copy and Paste the following text in the codebox into the Custom Scans/Fixes window.

Code: [Select]:OTL

:folders
Antivirus 2010

:Processes -- this is the command for killing processes.
:COMMANDS
[resethosts]
[purity]
[emptytemp]
[start explorer]

* Click Run Fix
* OTLI2 may ask to reboot the machine. Please do so if asked.
* Click OK
* A report will open. Copy and Paste that report in your next reply.
All processes killed
========== OTL ==========
Error: Unable to interpret <:folders> in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret <:Processes -- this is the command for killing processes.> in the current context!
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
[EMPTYTEMP]
 
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: All Users
 
User: Compaq_Owner
->Temp folder emptied: 2526 bytes
->Temporary Internet Files folder emptied: 1440836 bytes
->Java cache emptied: 2027 bytes
->FireFox cache emptied: 45779653 bytes
->Flash cache emptied: 456 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56466 bytes
 
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 0 bytes
 
User: misc pics
 
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes
 
User: New Folder
 
User: savanah pics
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 452 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 45.00 mb
 
 
OTL by OldTimer - Version 3.2.22.3 log created on 04232011_172541

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...
Please run Security Check again to see if it has been removed. Results of screen317's Security Check version 0.99.10 
 Windows XP Service Pack 3 (UAC is disabled!)
 Internet Explorer 8 
``````````````````````````````
Antivirus/Firewall Check:

 Windows Firewall Disabled! 
 Avira AntiVir Personal - Free Antivirus
 WWII: Normandy     
 Antivirus 2010     
 PC Tools Firewall Plus 6.0 
 McAfee Security Scan Plus   
 ZoneAlarm Spy Blocker Toolbar   
 ZoneAlarm     
 Avira successfully updated!
```````````````````````````````
Anti-malware/Other Utilities Check:

 Malwarebytes' Anti-Malware   
 CCleaner     
 Java(TM) 6 Update 25 
 Out of date Java installed!
 Adobe Flash Player    10.1.102.64 
Adobe Reader X (10.0.1)
 Mozilla Thunderbird (3.1.9)
````````````````````````````````
Process Check: 
objlist.exe by Laurent

 Avira Antivir avgnt.exe
 Avira Antivir avguard.exe
 PC Tools Firewall Plus FWService.exe   
 PC Tools Firewall Plus FirewallGUI.exe   
``````````End of Log````````````
Please update and run MBAM in Normal mode and post the log.Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6435

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

4/24/2011 4:59:43 PM
mbam-log-2011-04-24 (16-59-43).txt

Scan type: Full scan (C:\|)
Objects scanned: 221571
Time ELAPSED: 1 hour(s), 6 minute(s), 37 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
SysProt Antirootkit

Download
SysProt Antirootkit from the link below (you will find it at the bottom
of the PAGE under attachments, or you can get it from one of the
mirrors).

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.
  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select the following items.
    • Process << Selected
    • Kernel Modules << Selected
    • SSDT << Selected
    • Kernel Hooks << Selected
    • IRP Hooks << NOT Selected
    • Ports << NOT Selected
    • Hidden Files << Selected
  • At the bottom of the page
    • Hidden Objects Only << Selected
  • Click on the Create Log button on the bottom right.
  • After a few SECONDS a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to. Open the text file and copy/paste the log here.
SysProt AntiRootkit v1.0.1.0
by swatkat

*************************************
***************************************

No Hidden Processes found

***************************************************
***************************************************
Kernel Modules:
Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: B4B05000
Module End: B4B1D000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
Service Name: ---
Module Base: BA5F4000
Module End: BA5F6000
Hidden: Yes

********************************************************
********************************************************
SSDT:
Function Name: ZwCreateFile
Address: B278ED80
Driver Base: B2761000
Driver End: B27F1000
Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys

Function Name: ZwCreateKey
Address: B27B3070
Driver Base: B2761000
Driver End: B27F1000
Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys

Function Name: ZwCreateThread
Address: BA7D1AEC
Driver Base: 0
Driver End: 0
Driver Name: _unknown_

Function Name: ZwDeleteFile
Address: B278FC60
Driver Base: B2761000
Driver End: B27F1000
Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys

Function Name: ZwDeleteKey
Address: B27B4780
Driver Base: B2761000
Driver End: B27F1000
Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys

Function Name: ZwDeleteValueKey
Address: B27B4160
Driver Base: B2761000
Driver End: B27F1000
Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys

Function Name: ZwLoadKey
Address: B27B5080
Driver Base: B2761000
Driver End: B27F1000
Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys

Function Name: ZwLoadKey2
Address: B27B52B0
Driver Base: B2761000
Driver End: B27F1000
Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys

Function Name: ZwOpenFile
Address: B278F750
Driver Base: B2761000
Driver End: B27F1000
Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys

Function Name: ZwOpenProcess
Address: BA7D1AD8
Driver Base: 0
Driver End: 0
Driver Name: _unknown_

Function Name: ZwOpenThread
Address: BA7D1ADD
Driver Base: 0
Driver End: 0
Driver Name: _unknown_

Function Name: ZwRenameKey
Address: B27B6430
Driver Base: B2761000
Driver End: B27F1000
Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys

Function Name: ZwReplaceKey
Address: B27B5A40
Driver Base: B2761000
Driver End: B27F1000
Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys

Function Name: ZwRestoreKey
Address: B27B60D0
Driver Base: B2761000
Driver End: B27F1000
Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys

Function Name: ZwSetInformationFile
Address: B2790080
Driver Base: B2761000
Driver End: B27F1000
Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys

Function Name: ZwSetSecurityObject
Address: B27B68E0
Driver Base: B2761000
Driver End: B27F1000
Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys

Function Name: ZwSetValueKey
Address: B27B3970
Driver Base: B2761000
Driver End: B27F1000
Driver Name: \??\C:\WINDOWS\system32\vsdatant.sys

Function Name: ZwTerminateProcess
Address: BA7D1AE7
Driver Base: 0
Driver End: 0
Driver Name: _unknown_

********************************************************
********************************************************
No Kernel Hooks found

*************************************************************
**************************************************************
Hidden files/folders:
Object: C:\System Volume Information\MountPointManagerRemoteDatabase
Status: Access denied

Object: C:\System Volume Information\tracking.log
Status: Access denied

Object: C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}
Status: Access denied

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
1376.

Solve : Loss of internet connection after spyware problem?

Answer»

Quote

I use Firefox and also Internet explorer.
And, neither one can connect to the internet?

Please download the latest version of Kaspersky GetSystemInfo (GSI) from Kaspersky and save it to your Desktop.

Note: please close all other applications running on your system.

Double click GetSystemInfo.exe to open it. It will display an agreement. Click on I Agree to continue.

Click the Settings button.



Set the slider to Maximum.



IMPORTANT! Then, click Customize - choose Driver / Ports tab and uncheck Scan Ports.



On the General tab, make sure all of the boxes are checked.



On the Misc tab, make sure all the checkboxes are checked.

Then, click OK on the WINDOWS that you launched.


Click Create Report to run it.


It will begin scanning.

It will create a zip folder called GetSystemInfo_XXXXXXXXXXXXXX.zip on your Desktop.

It should automatically upload it to http://www.getsysteminfo.com. If it does not, then please submit it manually by going to the site and doing the upload process.

It will redirect to a page, where it will provide a sharing URL for specialists. Copy and paste the url of the GSI Parser report in your next reply..
http://www.getsysteminfo.com/read.php?file=a761082afdd05f4f1cfb540a1406f389Download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

link # 1
Link # 2
If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

Close any open WEB browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Right-click combofix.exe and select Run as Administrator and follow the prompts.
When finished, ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.Here is the combo fix one - not sure if i sucessfully turned off norton thoug:


ComboFix 11-04-17.03 - franki 18/04/2011  22:27:05.1.2 - x86
Microsoft® Windows Vista™ Home Premium   6.0.6000.0.1252.44.1033.18.1014.276 [GMT 1:00]
Running from: c:\users\franki\Desktop\ComboFix.exe
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_usnjsvc
.
.
(((((((((((((((((((((((((   Files Created from 2011-03-18 to 2011-04-18  )))))))))))))))))))))))))))))))
.
.
2011-04-18 21:19 . 2011-04-18 21:20   --------   d-----w-   C:\32788R22FWJFW
2011-04-11 20:10 . 2011-04-11 20:10   --------   d-----w-   c:\users\franki\AppData\Roaming\SUPERAntiSpyware.com
2011-04-10 16:28 . 2011-04-10 16:30   --------   d-----w-   c:\users\Administrator
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-01 21:02 . 2009-05-01 21:02   1044480   ----a-w-   c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02   200704   ----a-w-   c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-03-31 21:47 . 2009-08-17 21:57   324976   ----a-w-   c:\program files\mozilla firefox\components\coFFPlgn.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-12-09 17:40   333192   ----a-w-   c:\program files\AskBarDis\bar\bin\askBar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{474597C5-AB09-49d6-A4D5-2E8D7341384E}]
2010-09-07 06:23   585096   ----a-w-   c:\progra~1\IMESHA~1\MediaBar\Datamngr\IEBHO.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F}]
2009-11-20 17:34   87472   ----a-w-   c:\progra~1\IMESHA~1\MediaBar\ToolBar\iMeshMediaBarDx.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-09 333192]
"{ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F}"= "c:\progra~1\IMESHA~1\MediaBar\ToolBar\iMeshMediaBarDx.dll" [2009-11-20 87472]
.
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
.
[HKEY_CLASSES_ROOT\clsid\{abb49b3b-ab7d-4ed0-9135-93fd5aa4f69f}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-09 333192]
.
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-10 1232896]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-11-27 1032376]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-01 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-31 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-31 151552]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-31 126976]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 827392]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-03-29 176128]
"NapsterShell"="c:\program files\Napster\napster.exe" [2007-01-13 323216]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-12 50696]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe" [2007-04-24 77824]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"4oD"="c:\program files\Kontiki\KHost.exe" [2007-11-27 1032376]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
.
c:\users\franki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Audible Download Manager.lnk - c:\program files\Audible\Bin\AudibleDownloadHelper.exe [2009-9-23 1791320]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\IMESHA~1\MediaBar\Datamngr\datamngr.dll c:\progra~1\IMESHA~1\MediaBar\Datamngr\IEBHO.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-05-02 135664]
R3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\SYMNDISV.SYS [2009-02-19 41008]
S0 RapportKELL;RapportKELL;c:\windows\System32\Drivers\RapportKELL.sys [2010-10-03 59240]
S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080911.001\IDSvix86.sys [2008-08-08 261680]
S1 RapportCerberus_19917;RapportCerberus_19917;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys [2010-10-03 34792]
S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [2010-10-03 169320]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
S2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [2010-10-03 767208]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-02 21:40]
.
2011-04-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-02 21:40]
.
2011-04-18 c:\windows\Tasks\User_Feed_Synchronization-{1A1E9A67-A002-4FB0-9411-2BA1D61AA15B}.job
- c:\windows\system32\msfeedssync.exe [2010-12-28 04:56]
.
.
------- Supplementary Scan -------
.
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=73&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} - hxxp://assets.photobox.com/assets/aurigma/ImageUploader5.cab?20101221064513
FF - ProfilePath - c:\users\franki\AppData\Roaming\Mozilla\Firefox\Profiles\nqjfmbrz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - iMesh Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.imesh.com/
FF - prefs.js: keyword.URL - hxxp://search.imesh.com/web?src=ffb&systemid=1&q=
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - c:\program files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: MediaBar: {28D35620-51D9-11DE-9D13-2DB156D89593} - %profile%\extensions\{28D35620-51D9-11DE-9D13-2DB156D89593}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
.
------- File Associations -------
.
inifile=%SystemRoot%\System32\NOTEPAD.EXE %1"
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-QlbCtrl - %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
HKLM-Run-hpWirelessAssistant - %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
HKLM-Run-WAWifiMessage - %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
SafeBoot-klmdb.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-18 22:49
Windows 6.0.6000  NTFS
.
scanning hidden processes ... 
.
scanning hidden autostart entries ...
.
scanning hidden files ... 
.
.
c:\windows\TEMP\TMP00000012CF9B031445299DCB 524288 bytes executable
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
Denied: (A) (Users)
Denied: (A) (Everyone)
Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
Denied: (A) (Users)
Denied: (A) (Everyone)
Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
Denied: (A) (Users)
Denied: (A) (Everyone)
Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(3352)
c:\program files\Trusteer\Rapport\bin\rooksbas.dll
c:\windows\system32\imapi2.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\lxdacoms.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\system32\WUDFHost.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\windows\system32\DllHost.exe
c:\windows\system32\vssvc.exe
.
**************************************************************************
.
Completion time: 2011-04-18  22:57:33 - MACHINE was rebooted
ComboFix-quarantined-files.txt  2011-04-18 21:57
.
Pre-Run: 10,001,489,920 bytes free
Post-Run: 8,793,120,768 bytes free
.
- - End Of File - - 4DA887D544D059E7895194C9DAB74592
Please go to Jotti's malware scan
(If more than one file needs scanned they must be done separately and links posted for each one)

* Copy the file path in the below Code box:

Code: [Select]C:\Windows\System32\igfxCoIn_v1187.dll
* At the upload site, click once inside the window next to Browse.
* Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
* Next click Submit file
* Your file will possibly be entered into a queue which normally takes less than a minute to clear.
* This will perform a scan across multiple different virus scanning engines.
* Important: Wait for all of the scanning engines to complete.
* Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.
Something else to try:

Make sure, your computer is set to obtain IP address automatically.
1. Go Start>Settings>Control Panel (Vista/7 users: Start>Control Panel)
2. Double click Network CONNECTIONS (Vista/7 users: Network and Sharing Center)
3. Vista/7 users - From the list of tasks on the left, click Manage network connections.
4. For a wired network connection, right-click Local Area Connection, and then select Properties.
For a wireless network connection, right-click Wireless Network Connection, and then select Properties.
5. From the General tab (Vista/7 users: Networking tab), click Internet Protocol (TCP/IP), make sure it is checked, and then click Properties
6. Click Obtain an IP Address Automatically, and then click OK.

Didn't find anything! http://virusscan.jotti.org/en-GB/scanresult/9148c0cb6a1cdaaa76848a7c21491d9ba25cad32Ok. Please try the IP fix I posted.Yep I tried that, the settings are all as they should be.Please run the ping test in Reply # 5. I want to see if anything has changed.

Turn off computer. Disconnect router, and modem from power source for 1 minute. At the same time disconnect ethernet cable as well.
Reconnect everything.
Restart computer.
Nothing seemed to be working so I had to wipe the disk and start again - internet now connects. Hopefully I won't get anything that bad again. thanks for your help!I'm sorry it had to come to that. Please make sure you have a good AV and a good firewall. I will post some links below.

Remember to only install one antivirus!
 
1) Avast! Home Edition
2) AVG Free Edition
3) Avira AntiVir Personal
4) Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download
4-a) Microsoft Security Essentials for Windows XP
5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
6) PC Tools AntiVirus Free Edition

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
1377.

Solve : Post-Antimalware Doctor Internet Problems?

Answer»

Dave, I hope I'm not speaking prematurely but that appears to have done it.  I can access Microsoft Update, Google Chrome is working, the Windows theme is finally back to normal, this is great. I can't thank you enough.

Only one thing, on your template (well, I'm assuming your instruction guides are templates) for the Recovery Console, the second and third pictures are inverted. It caused a second of minor confusion until I realized what it was supposed to look like. Very minor, I just thought I might let you know about that. Quote

Only one thing, on your template (well, I'm assuming your instruction guides are templates) for the Recovery Console, the second and third pictures are inverted. It caused a second of minor confusion until I realized what it was supposed to look like. Very minor, I just thought I might let you know about that.
Thanks for the feedback. I got that template from another malware fighter and I'll inform him about that.
I would like you to run DDS as described in Reply # 16 and TDSSKiller as described in Reply # 7
Also, please run the Security Check below.

Download Security Check by screen317 from one of the following links and save it to your desktop.

LINK 1
Link 2

* Unzip SecurityCheck.zip and a folder named Security Check should appear.
* Open the Security Check folder and double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.2011/04/24 16:00:17.0234 6040   TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
2011/04/24 16:00:17.0640 6040   ================================================================================
2011/04/24 16:00:17.0640 6040   SystemInfo:
2011/04/24 16:00:17.0640 6040   
2011/04/24 16:00:17.0640 6040   OS Version: 5.1.2600 ServicePack: 3.0
2011/04/24 16:00:17.0640 6040   Product type: Workstation
2011/04/24 16:00:17.0640 6040   ComputerName: TELKERNEW
2011/04/24 16:00:17.0640 6040   UserName: MATT
2011/04/24 16:00:17.0640 6040   Windows directory: C:\WINDOWS
2011/04/24 16:00:17.0640 6040   System windows directory: C:\WINDOWS
2011/04/24 16:00:17.0640 6040   Processor architecture: Intel x86
2011/04/24 16:00:17.0640 6040   Number of processors: 2
2011/04/24 16:00:17.0640 6040   Page size: 0x1000
2011/04/24 16:00:17.0640 6040   Boot type: Normal boot
2011/04/24 16:00:17.0640 6040   ================================================================================
2011/04/24 16:00:17.0859 6040   INITIALIZE success
2011/04/24 16:02:01.0859 4912   ================================================================================
2011/04/24 16:02:01.0859 4912   Scan started
2011/04/24 16:02:01.0859 4912   Mode: Manual;
2011/04/24 16:02:01.0859 4912   ================================================================================
2011/04/24 16:02:02.0203 4912   ACPI            (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/04/24 16:02:02.0234 4912   ACPIEC          (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2011/04/24 16:02:02.0281 4912   aec             (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/04/24 16:02:02.0312 4912   AFD             (7618d5218f2a614672ec61a80d854a37) C:\WINDOWS\System32\drivers\afd.sys
2011/04/24 16:02:02.0468 4912   Aken            (66c6d13334efc090347c7f4f3e57034c) C:\Documents and Settings\Matt\Local Settings\Application Data\0 A.D. alpha\binaries\system\aken.sys
2011/04/24 16:02:02.0593 4912   Ambfilt         (267fc636801edc5ab28e14036349e3be) C:\WINDOWS\system32\drivers\Ambfilt.sys
2011/04/24 16:02:02.0671 4912   amdide          (6e58654cb25730b2579e45e1fd116a47) C:\WINDOWS\system32\DRIVERS\amdide.sys
2011/04/24 16:02:02.0718 4912   AmdPPM          (033448d435e65c4bd72e70521fd05c76) C:\WINDOWS\system32\DRIVERS\AmdPPM.sys
2011/04/24 16:02:02.0812 4912   AsyncMac        (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/04/24 16:02:02.0828 4912   atapi           (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/04/24 16:02:02.0953 4912   ati2mtag        (eb0531822aabcf843a0940d4ca8a90a9) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
2011/04/24 16:02:03.0015 4912   AtiHdmiService  (b9bc23b57765c167806a1feb7a3d16a6) C:\WINDOWS\system32\drivers\AtiHdmi.sys
2011/04/24 16:02:03.0046 4912   Atmarpc         (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/04/24 16:02:03.0078 4912   audstub         (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/04/24 16:02:03.0125 4912   Beep            (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/04/24 16:02:03.0265 4912   cbidf2k         (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/04/24 16:02:03.0312 4912   CCDECODE        (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/04/24 16:02:03.0343 4912   Cdaudio         (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/04/24 16:02:03.0375 4912   Cdfs            (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/04/24 16:02:03.0421 4912   Cdr4_xp         (c3e76b0c05ebf7261abfb08d9e75822e) C:\WINDOWS\system32\drivers\Cdr4_xp.sys
2011/04/24 16:02:03.0437 4912   Cdralw2k        (17590dfe29e02842a6e3a463e443d1b9) C:\WINDOWS\system32\drivers\Cdralw2k.sys
2011/04/24 16:02:03.0453 4912   Cdrom           (4b0a100eaf5c49ef3cca8c641431eacc) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/04/24 16:02:03.0500 4912   cmderd          (61b20ca85950870fa23587b26f3e4d7d) C:\WINDOWS\system32\DRIVERS\cmderd.sys
2011/04/24 16:02:03.0515 4912   cmdGuard        (dd530ee7d9efbb0ec42aebe7226b8a93) C:\WINDOWS\system32\DRIVERS\cmdguard.sys
2011/04/24 16:02:03.0531 4912   cmdHlp          (07cbbe993ed08a52dafac1e6cf27b6a5) C:\WINDOWS\system32\DRIVERS\cmdhlp.sys
2011/04/24 16:02:03.0609 4912   Disk            (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/04/24 16:02:03.0640 4912   dmboot          (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2011/04/24 16:02:03.0656 4912   dmio            (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\DRIVERS\dmio.sys
2011/04/24 16:02:03.0671 4912   dmload          (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/04/24 16:02:03.0703 4912   DMusic          (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/04/24 16:02:03.0781 4912   drmkaud         (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/04/24 16:02:03.0796 4912   Fastfat         (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/04/24 16:02:03.0828 4912   Fdc             (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2011/04/24 16:02:03.0843 4912   Fips            (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2011/04/24 16:02:03.0843 4912   Flpydisk        (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2011/04/24 16:02:03.0875 4912   FltMgr          (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/04/24 16:02:03.0921 4912   Fs_Rec          (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/04/24 16:02:03.0953 4912   Ftdisk          (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/04/24 16:02:04.0000 4912   GEARAspiWDM     (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
2011/04/24 16:02:04.0015 4912   Gpc             (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/04/24 16:02:04.0046 4912   hamachi         (833051c6c6c42117191935f734cfbd97) C:\WINDOWS\system32\DRIVERS\hamachi.sys
2011/04/24 16:02:04.0078 4912   HDAudBus        (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2011/04/24 16:02:04.0093 4912   HidUsb          (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/04/24 16:02:04.0156 4912   HPZid412        (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
2011/04/24 16:02:04.0203 4912   HPZipr12        (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
2011/04/24 16:02:04.0218 4912   HPZius12        (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
2011/04/24 16:02:04.0250 4912   HTTP            (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/04/24 16:02:04.0281 4912   i8042prt        (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/04/24 16:02:04.0343 4912   Imapi           (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/04/24 16:02:04.0421 4912   Inspect         (8154a2c13b72b08db11157673c60c3eb) C:\WINDOWS\system32\DRIVERS\inspect.sys
2011/04/24 16:02:04.0578 4912   IntcAzAudAddService (262b0ab01671882e1c14ba8573583c32) C:\WINDOWS\system32\drivers\RtkHDAud.sys
2011/04/24 16:02:04.0640 4912   Ip6Fw           (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/04/24 16:02:04.0671 4912   IpFilterDriver  (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/04/24 16:02:04.0687 4912   IpInIp          (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/04/24 16:02:04.0718 4912   IpNat           (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/04/24 16:02:04.0734 4912   IPSec           (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/04/24 16:02:04.0781 4912   IRENUM          (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/04/24 16:02:04.0828 4912   isapnp          (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/04/24 16:02:04.0875 4912   ISODrive        (2f03ceb28307983f3b36216d35ffa5aa) C:\Program Files\UltraISO\drivers\ISODrive.sys
2011/04/24 16:02:04.0890 4912   JGOGO           (c995c0e8b4503fac38793bb0236ad246) C:\WINDOWS\system32\DRIVERS\JGOGO.sys
2011/04/24 16:02:04.0906 4912   JRAID           (66a54519ed42ec2ccca592f47eb02c5d) C:\WINDOWS\system32\DRIVERS\jraid.sys
2011/04/24 16:02:04.0937 4912   Kbdclass        (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/04/24 16:02:04.0968 4912   kmixer          (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/04/24 16:02:05.0000 4912   KSecDD          (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/04/24 16:02:05.0046 4912   LHidFlt2        (27bbea62dfafc495e956d3911ebc3045) C:\WINDOWS\system32\DRIVERS\LHidFlt2.sys
2011/04/24 16:02:05.0078 4912   LKbdFlt2        (bbc297ea4fc97fc7b85f70915345c80a) C:\WINDOWS\system32\DRIVERS\LKbdFlt2.sys
2011/04/24 16:02:05.0109 4912   LMouFlt2        (45df10f44f6a140a4f3dd377676603f2) C:\WINDOWS\system32\DRIVERS\LMouFlt2.sys
2011/04/24 16:02:05.0140 4912   mnmdd           (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/04/24 16:02:05.0171 4912   Modem           (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2011/04/24 16:02:05.0234 4912   Monfilt         (c7d9f9717916b34c1b00dd4834af485c) C:\WINDOWS\system32\drivers\Monfilt.sys
2011/04/24 16:02:05.0265 4912   Mouclass        (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/04/24 16:02:05.0296 4912   mouhid          (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/04/24 16:02:05.0328 4912   MountMgr        (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/04/24 16:02:05.0359 4912   MRxDAV          (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/04/24 16:02:05.0390 4912   MRxSmb          (0ea4d8ed179b75f8afa7998ba22285ca) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/04/24 16:02:05.0421 4912   Msfs            (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/04/24 16:02:05.0453 4912   MSKSSRV         (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/04/24 16:02:05.0468 4912   MSPCLOCK        (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/04/24 16:02:05.0484 4912   MSPQM           (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/04/24 16:02:05.0531 4912   mssmbios        (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/04/24 16:02:05.0562 4912   MSTEE           (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/04/24 16:02:05.0578 4912   Mup             (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2011/04/24 16:02:05.0640 4912   NABTSFEC        (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/04/24 16:02:05.0671 4912   NDIS            (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/04/24 16:02:05.0703 4912   NdisIP          (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/04/24 16:02:05.0734 4912   NdisTapi        (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/04/24 16:02:05.0750 4912   Ndisuio         (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/04/24 16:02:05.0765 4912   NdisWan         (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/04/24 16:02:05.0812 4912   NDProxy         (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/04/24 16:02:05.0859 4912   NetBIOS         (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/04/24 16:02:05.0875 4912   NetBT           (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/04/24 16:02:05.0906 4912   Npfs            (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/04/24 16:02:05.0921 4912   Ntfs            (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/04/24 16:02:05.0984 4912   Null            (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/04/24 16:02:06.0031 4912   NwlnkFlt        (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/04/24 16:02:06.0046 4912   NwlnkFwd        (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/04/24 16:02:06.0093 4912   OVT511Plus      (c5739be3a8eecdf951955a38e1741f45) C:\WINDOWS\system32\Drivers\omcamvid.sys
2011/04/24 16:02:06.0109 4912   Parport         (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys
2011/04/24 16:02:06.0125 4912   PartMgr         (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/04/24 16:02:06.0171 4912   ParVdm          (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/04/24 16:02:06.0187 4912   PCI             (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/04/24 16:02:06.0218 4912   PCIIde          (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\drivers\PCIIde.sys
2011/04/24 16:02:06.0250 4912   Pcmcia          (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
2011/04/24 16:02:06.0390 4912   PptpMiniport    (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/04/24 16:02:06.0406 4912   Processor       (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
2011/04/24 16:02:06.0421 4912   PSched          (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/04/24 16:02:06.0437 4912   Ptilink         (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/04/24 16:02:06.0453 4912   PxHelp20        (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/04/24 16:02:06.0562 4912   RasAcd          (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/04/24 16:02:06.0609 4912   Rasl2tp         (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/04/24 16:02:06.0625 4912   RasPppoe        (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/04/24 16:02:06.0640 4912   Raspti          (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/04/24 16:02:06.0656 4912   Rdbss           (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/04/24 16:02:06.0671 4912   RDPCDD          (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/04/24 16:02:06.0703 4912   rdpdr           (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/04/24 16:02:06.0734 4912   RDPWD           (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/04/24 16:02:06.0750 4912   redbook         (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/04/24 16:02:06.0796 4912   RimUsb          (f17713d108aca124a139fde877eef68a) C:\WINDOWS\system32\Drivers\RimUsb.sys
2011/04/24 16:02:06.0859 4912   RTLE8023xp      (e511d68f1ba6170a7178b7c4267c26cb) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
2011/04/24 16:02:06.0937 4912   SASDIFSV        (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
2011/04/24 16:02:06.0968 4912   SASKUTIL        (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
2011/04/24 16:02:07.0015 4912   Secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/04/24 16:02:07.0062 4912   Serial          (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys
2011/04/24 16:02:07.0093 4912   Sfloppy         (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/04/24 16:02:07.0140 4912   SLIP            (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/04/24 16:02:07.0203 4912   splitter        (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/04/24 16:02:07.0265 4912   sptd            (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\system32\Drivers\sptd.sys
2011/04/24 16:02:07.0312 4912   sr              (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/04/24 16:02:07.0343 4912   Srv             (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/04/24 16:02:07.0390 4912   StillCam        (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys
2011/04/24 16:02:07.0421 4912   streamip        (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/04/24 16:02:07.0437 4912   swenum          (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/04/24 16:02:07.0484 4912   swmidi          (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/04/24 16:02:07.0562 4912   sysaudio        (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/04/24 16:02:07.0625 4912   Tcpip           (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/04/24 16:02:07.0656 4912   TDPIPE          (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/04/24 16:02:07.0687 4912   TDTCP           (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/04/24 16:02:07.0703 4912   TermDD          (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/04/24 16:02:07.0765 4912   Udfs            (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/04/24 16:02:07.0828 4912   Update          (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/04/24 16:02:07.0875 4912   USBAAPL         (d4fb6ecc60a428564ba8768b0e23c0fc) C:\WINDOWS\system32\Drivers\usbaapl.sys
2011/04/24 16:02:07.0968 4912   usbaudio        (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
2011/04/24 16:02:07.0984 4912   usbccgp         (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/04/24 16:02:08.0000 4912   usbehci         (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/04/24 16:02:08.0015 4912   usbhub          (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/04/24 16:02:08.0031 4912   usbohci         (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
2011/04/24 16:02:08.0078 4912   usbprint        (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/04/24 16:02:08.0093 4912   usbscan         (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/04/24 16:02:08.0125 4912   USBSTOR         (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/04/24 16:02:08.0140 4912   VgaSave         (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/04/24 16:02:08.0218 4912   VolSnap         (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/04/24 16:02:08.0250 4912   Wanarp          (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/04/24 16:02:08.0281 4912   wanatw          (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINDOWS\system32\DRIVERS\wanatw4.sys
2011/04/24 16:02:08.0328 4912   Wdf01000        (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys
2011/04/24 16:02:08.0406 4912   wdmaud          (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/04/24 16:02:08.0468 4912   WmiAcpi         (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
2011/04/24 16:02:08.0546 4912   WSTCODEC        (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/04/24 16:02:08.0609 4912   WudfPf          (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/04/24 16:02:08.0625 4912   WudfRd          (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/04/24 16:02:08.0781 4912   ================================================================================
2011/04/24 16:02:08.0781 4912   Scan finished
2011/04/24 16:02:08.0781 4912   ================================================================================
.
DDS (Ver_11-03-05.01) - NTFSx86 
Run by Matt at 16:03:43.34 on Sun 04/24/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.3327.2309 [GMT -4:00]
.
AV: COMODO Antivirus *Enabled/Updated* {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: COMODO Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Browny02\Brother\BrStMonW.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
svchost.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Hamachi\hamachi-2.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Browny02\BrYNSvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Matt\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: ChromeFrame BHO: {ecb3c477-1a0a-44bd-bb57-78f9efe34fa7} - c:\program files\google\chrome frame\application\10.0.648.205\npchrome_frame.dll
TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [RoxioEngineUtility] "c:\program files\common files\roxio shared\system\EngUtil.exe"
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [36X Raid Configurer] c:\windows\system32\xRaidSetup.exe boot
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini"
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [BrStsMon00] c:\program files\browny02\brother\BrStMonW.exe /AUTORUN
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe
dRunOnce: [RunNarrator] Narrator.exe
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
StartupFolder: c:\docume~1\matt\startm~1\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpoddt~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - /105
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} - hxxp://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1294469241906
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.53.0.cab
DPF: {7E1C8369-99C1-46BA-86C7-1BF331ADEB2B} - hxxps://www51.honeywell.com/checkbrowser/ax/CBSystemCheck.CAB
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} - hxxps://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.26.2.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {D8B65097-3AB9-476E-83B5-699E51D7B4D8} = 156.154.70.22,156.154.71.22
Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - c:\program files\google\chrome frame\application\10.0.648.205\npchrome_frame.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: AtiExtEvent - Ati2evxx.dll
AppInit_DLLs: c:\windows\system32\guard32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\matt\applic~1\mozilla\firefox\profiles\xcgcf8sm.default\
FF - plugin: c:\documents and settings\matt\local settings\application data\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\documents and settings\matt\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: [email protected] - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Torbutton: {e0204bd5-9d31-402b-a99d-a6aa8ffebdca} - %profile%\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
FF - Ext: vShare: [email protected] - %profile%\extensions\[email protected]
.
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
============= SERVICES / DRIVERS ===============
.
R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [2010-6-1 15592]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2010-6-4 239368]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-6-1 27576]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2010-6-1 1803224]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\hamachi\hamachi-2.exe [2011-3-28 1242504]
R3 BrYNSvc;BrYNSvc;c:\program files\browny02\BrYNSvc.exe [2011-2-13 245760]
R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-11-29 135664]
S3 Aken;Aken;c:\documents and settings\matt\local settings\application data\0 a.d. alpha\binaries\system\aken.sys [2007-6-17 3712]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-9-10 1691480]
S3 icsak;icsak;\??\c:\program files\checkpoint\zaforcefield\ak\icsak.sys --> c:\program files\checkpoint\zaforcefield\ak\icsak.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.1.121\McCHSvc.exe [2010-9-3 227232]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\e3.tmp --> c:\windows\system32\E3.tmp [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-3-25 30969208]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-8-4 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-04-24 01:40:34   --------   d-sha-r-   C:\cmdcons
2011-04-24 01:22:09   98816   ----a-w-   c:\windows\sed.exe
2011-04-24 01:22:09   89088   ----a-w-   c:\windows\MBR.exe
2011-04-24 01:22:09   256512   ----a-w-   c:\windows\PEV.exe
2011-04-24 01:22:09   161792   ----a-w-   c:\windows\SWREG.exe
2011-04-22 21:36:00   --------   d-----w-   c:\program files\Sophos
2011-04-21 15:56:12   --------   d-----w-   c:\docume~1\matt\applic~1\SUPERAntiSpyware.com
2011-04-21 15:56:12   --------   d-----w-   c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2011-04-21 15:55:53   --------   d-----w-   c:\program files\SUPERAntiSpyware
2011-04-21 15:29:09   --------   d-----w-   c:\windows\system32\wbem\repository\FS
2011-04-21 15:29:09   --------   d-----w-   c:\windows\system32\wbem\Repository
2011-04-21 05:05:11   --------   d-----w-   c:\program files\common files\iS3
2011-04-21 05:05:10   --------   d-----w-   c:\docume~1\alluse~1\applic~1\STOPzilla!
2011-03-29 13:56:20   --------   d-----w-   c:\program files\Hamachi
.
==================== Find3M  ====================
.
2011-03-07 05:33:50   692736   ----a-w-   c:\windows\system32\inetcomm.dll
2011-03-04 06:37:06   420864   ----a-w-   c:\windows\system32\vbscript.dll
2011-03-03 13:21:11   1857920   ----a-w-   c:\windows\system32\win32k.sys
2011-02-22 23:06:29   916480   ----a-w-   c:\windows\system32\wininet.dll
2011-02-22 23:06:29   43520   ------w-   c:\windows\system32\licmgr10.dll
2011-02-22 23:06:29   1469440   ------w-   c:\windows\system32\inetcpl.cpl
2011-02-22 11:41:59   385024   ------w-   c:\windows\system32\html.iec
2011-02-18 21:36:58   4184352   ----a-w-   c:\windows\system32\usbaaplrc.dll
2011-02-17 12:32:12   5120   ----a-w-   c:\windows\system32\xpsp4res.dll
2011-02-15 12:56:39   290432   ----a-w-   c:\windows\system32\atmfd.dll
2011-02-09 13:53:52   270848   ----a-w-   c:\windows\system32\sbe.dll
2011-02-09 13:53:52   186880   ----a-w-   c:\windows\system32\encdec.dll
2011-02-08 13:33:55   978944   ----a-w-   c:\windows\system32\mfc42.dll
2011-02-08 13:33:55   974848   ----a-w-   c:\windows\system32\mfc42u.dll
2011-02-03 02:40:23   472808   ----a-w-   c:\windows\system32\deployJava1.dll
2011-02-03 00:19:39   73728   ----a-w-   c:\windows\system32\javacpl.cpl
2011-02-02 07:58:35   2067456   ----a-w-   c:\windows\system32\mstscax.dll
2011-01-27 11:57:06   677888   ----a-w-   c:\windows\system32\mstsc.exe
2011-01-26 22:35:04   1112576   ----a-w-   c:\windows\system32\ativvamv.dll
.
============= FINISH: 16:06:44.89 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 1/8/2011 1:31:05 AM
System Uptime: 4/24/2011 3:20:15 PM (1 hours ago)
.
Motherboard: ECS |  | A780GM-A Ultra
Processor: AMD Athlon(tm) II X2 240 Processor | CPU 1 | 2800/200mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 298 GiB total, 139.07 GiB free.
D: is CDROM ()
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP21: 1/21/2011 12:22:03 PM - System Checkpoint
RP22: 1/22/2011 1:00:38 PM - System Checkpoint
RP23: 1/23/2011 1:04:26 PM - System Checkpoint
RP24: 1/23/2011 2:52:57 PM - Printer Driver EPSON Stylus Photo R280 Series Installed
RP25: 1/25/2011 4:44:04 PM - System Checkpoint
RP26: 1/26/2011 6:45:53 PM - System Checkpoint
RP27: 1/27/2011 10:50:41 PM - System Checkpoint
RP28: 1/28/2011 1:24:12 AM - DMX_DriverMax Driver Installation
RP29: 1/28/2011 1:32:43 AM - DMX_DriverMax Driver Installation
RP30: 1/29/2011 12:26:03 PM - System Checkpoint
RP31: 1/29/2011 1:04:35 PM - DMX_DriverMax Driver Installation
RP32: 1/29/2011 1:09:57 PM - DMX_DriverMax Driver Installation
RP33: 2/2/2011 3:17:18 PM - System Checkpoint
RP34: 2/4/2011 6:27:12 PM - System Checkpoint
RP35: 2/6/2011 9:10:09 PM - System Checkpoint
RP36: 2/8/2011 4:12:23 PM - System Checkpoint
RP37: 2/9/2011 11:28:14 PM - Software Distribution Service 3.0
RP38: 2/12/2011 1:39:38 PM - Software Distribution Service 3.0
RP39: 2/13/2011 3:43:27 PM - System Checkpoint
RP40: 2/13/2011 6:50:30 PM - Installed ScanSoft PaperPort 11
RP41: 2/13/2011 6:52:02 PM - Installed PaperPort Image Printer
RP42: 2/13/2011 6:52:14 PM - Printer Driver Nuance Image Printer Driver Installed
RP43: 2/13/2011 6:56:24 PM - Installed Brother Software Suite
RP44: 2/13/2011 6:58:10 PM - Unsigned printer driver Brother PC-FAX v.2.1 installed.
RP45: 2/14/2011 8:28:06 PM - System Checkpoint
RP46: 2/16/2011 12:41:33 PM - System Checkpoint
RP47: 2/27/2011 2:39:07 PM - System Checkpoint
RP48: 2/28/2011 5:41:38 PM - System Checkpoint
RP49: 3/1/2011 5:59:19 PM - System Checkpoint
RP50: 3/3/2011 4:03:55 PM - System Checkpoint
RP51: 3/4/2011 6:27:59 PM - System Checkpoint
RP52: 3/5/2011 4:03:10 PM - Installed Java(TM) 6 Update 24
RP53: 3/5/2011 4:03:48 PM - Installed Java Runtime Environment
RP54: 3/6/2011 6:50:11 PM - System Checkpoint
RP55: 3/6/2011 11:33:49 PM - Installed Mobile Mouse Server.
RP56: 3/7/2011 11:09:09 PM - Software Distribution Service 3.0
RP57: 3/8/2011 9:36:40 PM - Software Distribution Service 3.0
RP58: 3/8/2011 10:07:17 PM - Removed XBList
RP59: 3/9/2011 6:22:42 PM - Removed ATI Catalyst Install Manager
RP60: 3/10/2011 6:56:40 PM - System Checkpoint
RP61: 3/10/2011 6:58:30 PM - Removed Network Magic
RP62: 3/10/2011 6:59:07 PM - Removed Pure Networks Platform
RP63: 3/10/2011 7:05:02 PM - Removed TortoiseSVN 1.6.7.18415 (32 bit)
RP64: 3/11/2011 7:20:37 PM - System Checkpoint
RP65: 3/12/2011 8:36:25 PM - System Checkpoint
RP66: 3/15/2011 4:47:27 PM - System Checkpoint
RP67: 3/16/2011 8:25:23 PM - System Checkpoint
RP68: 3/17/2011 9:24:07 PM - System Checkpoint
RP69: 3/19/2011 3:30:39 PM - System Checkpoint
RP70: 3/20/2011 3:52:39 PM - System Checkpoint
RP71: 3/21/2011 5:29:42 PM - System Checkpoint
RP72: 3/22/2011 7:09:03 PM - System Checkpoint
RP73: 3/23/2011 4:22:37 PM - Software Distribution Service 3.0
RP74: 3/24/2011 4:32:01 PM - System Checkpoint
RP75: 3/25/2011 6:00:31 PM - System Checkpoint
RP76: 3/27/2011 12:33:09 PM - System Checkpoint
RP77: 3/28/2011 4:06:28 PM - System Checkpoint
RP78: 3/29/2011 5:16:46 PM - System Checkpoint
RP79: 3/30/2011 5:19:31 PM - System Checkpoint
RP80: 3/31/2011 5:21:09 PM - System Checkpoint
RP81: 4/1/2011 6:26:30 PM - System Checkpoint
RP82: 4/2/2011 8:43:47 PM - System Checkpoint
RP83: 4/4/2011 5:15:25 PM - System Checkpoint
RP84: 4/5/2011 7:07:37 PM - System Checkpoint
RP85: 4/7/2011 4:59:37 PM - System Checkpoint
RP86: 4/8/2011 8:07:06 PM - System Checkpoint
RP87: 4/10/2011 11:42:38 AM - System Checkpoint
RP88: 4/11/2011 4:55:29 PM - System Checkpoint
RP89: 4/12/2011 5:34:37 PM - System Checkpoint
RP90: 4/13/2011 7:49:47 PM - System Checkpoint
RP91: 4/14/2011 11:00:32 PM - Software Distribution Service 3.0
RP92: 4/16/2011 9:54:19 AM - System Checkpoint
RP93: 4/17/2011 1:13:27 PM - System Checkpoint
RP94: 4/18/2011 3:06:27 PM - System Checkpoint
RP95: 4/19/2011 4:46:53 PM - System Checkpoint
RP96: 4/20/2011 5:02:51 PM - System Checkpoint
RP97: 4/21/2011 1:05:03 AM - Installed STOPzilla. Available with Windows Installer version 1.2 and later.
RP98: 4/21/2011 1:30:10 AM - Removed STOPzilla. Available with Windows Installer version 1.2 and later.
RP99: 4/21/2011 11:25:41 AM - Restore Operation
RP100: 4/21/2011 11:28:15 AM - Restore Operation
RP101: 4/24/2011 3:47:48 PM - System Checkpoint
.
==== Installed Programs ======================
.
µTorrent
0 A.D.
7-Zip 9.20
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.4.3
Advertising Center
Alien Swarm
Alien Swarm - SDK
AOL Uninstaller (Choose which Products to Remove)
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI AVIVO Codecs
ATI Catalyst Install Manager
ATI Parental Control & Encoder
ATI Problem Report Wizard
ATI Stream SDK v2 Developer
Battlefield 2(TM)
Battlefield 2: Special Forces
Battlefield Play4Free (Matt)
Bonjour
Brother MFL-Pro Suite MFC-J265W
Call of Duty
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center HydraVision Full
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CCleaner
Chinese Traditional Fonts Support For Adobe Reader 9
COMODO Internet Security
Compatibility Pack for the 2007 Office system
Dedicated Server
Definition update for Microsoft Office 2010 (KB982726)
DivX Setup
DNA
DolbyFiles
Download Updater (AOL LLC)
DriverMax 5
Game Booster
Garry's Mod
Google Chrome
Google Chrome Frame
Google Earth
Google Update Helper
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB973442)
Hotfix for Windows XP (KB932716-v2)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
HP Photo and Imaging 2.0 - All-in-One
HP Photo and Imaging 2.0 - All-in-One Drivers
hp psc 2200 series
HyperCam 2
ImagXpress
iPhone Configuration Utility
iTunes
Java Auto Updater
Java(TM) 6 Update 24
JMicron JMB36X Driver
Junk Mail filter update
LAME v3.98.2 for Audacity
LogMeIn Hamachi
Malwarebytes' Anti-Malware
McAfee Security Scan Plus
Menu Templates - Starter Kit
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office Live Add-in 1.4
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Professional Edition 2003
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Word MUI (English) 2010
Microsoft Silverlight
Microsoft Software Update for Web Folders  (English) 14
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Mobile Mouse Server
MobileMe Control Panel
Movie Templates - Starter Kit
Mozilla Firefox (3.6.16)
MSN
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NaturalMotion endorphin 2.7.1
Nero 8 Essentials
Nero 9 Essentials
Nero BurnRights
Nero BurnRights Help
Nero ControlCenter
Nero CoverDesigner
Nero CoverDesigner Help
Nero DiscSpeed
Nero DiscSpeed Help
Nero DriveSpeed
Nero DriveSpeed Help
Nero Express Help
Nero InfoTool
Nero InfoTool Help
Nero Installer
Nero Online Upgrade
Nero ShowTime
Nero StartSmart
Nero StartSmart Help
Nero Vision
Nero Vision Help
NeroExpress
neroxml
NVIDIA PhysX
OGA Notifier 2.0.0048.0
ooVoo
OpenAL
PaperPort Image Printer
Polipo 1.0.4.1
Portal
Project Reality 0909 Full - Part 1 of 2
Project Reality 0909 Full - Part 2 of 2
Project Reality 0917 Patch
Project S
PunkBuster Services
QuickTime
Readiris 7.5
Realtek High Definition Audio Driver
Rootkit Unhooker LE 3.8 SR 2
Roxio PhotoSuite 5
Safari
ScanSoft PaperPort 11
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft Excel 2010 (KB2466146)
Security Update for Microsoft Office 2010 (KB2289078)
Security Update for Microsoft Office 2010 (KB2289161)
Security Update for Microsoft PowerPoint 2010 (KB2519975)
Security Update for Microsoft Publisher 2010 (KB2409055)
Security Update for Microsoft Word 2010 (KB2345000)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB2497640)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB979402)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2416400)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Segoe UI
Sid Meier's Civilization 4
Snood 4
Sophos Anti-Rootkit 1.5.4
Source SDK
Source SDK Base
SpywareBlaster 4.2
SpywareGuard v2.2
Stay On Top
Steam
SUPERAntiSpyware
System Requirements Lab
System Requirements Lab CYRI
Team Fortress 2
Team Fortress 2 Dedicated Server
Tor 0.2.2.19-alpha
Trader's Little Helper 2.6.0
UltraISO Premium V9.36
Uninstall AOL Emergency Connect Utility 1.0
Unity Web Player
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2010 (KB2202188)
Update for Microsoft Office 2010 (KB2413186)
Update for Microsoft OneNote 2010 (KB2493983)
Update for Microsoft Outlook Social Connector (KB2441641)
Update for Microsoft Windows (KB971513)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VC 9.0 Runtime
VC80CRTRedist - 8.0.50727.4053
VCRedistSetup
Vegas Movie Studio HD Platinum 10.0
Ventrilo Client
Vidalia 0.2.10
Viewpoint Media Player
Virus Guard - powered by BitDefender
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Mail
Windows Live Messenger
Windows Live Upload Tool
Windows Management Framework Core
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinSCP 4.3.1 beta
WolfQuest
.
==== Event Viewer Messages From Past Week ========
.
90884761 AmdPPM cmdGuard Fips PCIIde SASDIFSV SASKUTIL setup_9.0.0.722_21.04.2011_20-58[1]drv sptd
4/23/2011 12:15:42 PM, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the iPod Service service to connect.
4/23/2011 12:15:42 PM, error: Service Control Manager [7000]  - The iPod Service service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
4/23/2011 12:15:31 PM, error: DCOM [10005]  - DCOM got error "%1053" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
4/23/2011 10:33:12 PM, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
4/23/2011 10:33:12 PM, error: Service Control Manager [7000]  - The IMAPI CD-Burning COM Service service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
4/22/2011 8:22:31 PM, error: DCOM [10005]  - DCOM got error "%1053" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
4/22/2011 8:15:29 PM, error: DCOM [10005]  - DCOM got error "%1053" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
4/22/2011 8:08:36 PM, error: DCOM [10005]  - DCOM got error "%1053" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
4/22/2011 2:44:18 PM, error: DCOM [10005]  - DCOM got error "%1053" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
4/22/2011 2:40:19 PM, error: DCOM [10005]  - DCOM got error "%1053" attempting to start the service winmgmt with arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
4/22/2011 12:12:41 PM, error: Service Control Manager [7031]  - The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
4/22/2011 1:34:30 PM, error: WMPNetworkSvc [14344]  - A new media server was not initialized because WMCreateDeviceRegistration() encountered error '0xc00d2711'. The Windows Media DRM components on your computer might be corrupted. Verify that protected files play correctly in Windows Media Player, and then restart the WMPNetworkSvc service.
4/22/2011 1:12:49 PM, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
4/21/2011 5:26:58 PM, error: Service Control Manager [7000]  - The SASDIFSV service failed to start due to the following error:  Cannot create a file when that file already exists.
4/21/2011 5:24:57 PM, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  PCIIde sptd
4/21/2011 5:22:19 PM, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
4/21/2011 4:44:18 PM, error: Service Control Manager [7034]  - The LogMeIn Hamachi 2.0 Tunneling Engine service terminated unexpectedly.  It has done this 1 time(s).
4/21/2011 4:41:01 PM, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:
4/20/2011 11:00:09 AM, error: WMPNetworkSvc [14344]  - A new media server was not initialized because WMCreateDeviceRegistration() encountered error '0xc00d2721'. The Windows Media DRM components on your computer might be corrupted. Verify that protected files play correctly in Windows Media Player, and then restart the WMPNetworkSvc service.
4/20/2011 10:59:50 AM, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  sptd
4/20/2011 10:59:28 AM, error: Service Control Manager [7000]  - The Zune Bus Enumerator Driver service failed to start due to the following error:  The system cannot find the file specified.
4/20/2011 10:58:57 AM, error: DCOM [10005]  - DCOM got error "%1058" attempting to start the service NMIndexingService with arguments "" in order to run the server: {E8933C4B-2C90-4A04-A677-E958D9509F1A}
4/20/2011 10:58:46 AM, error: sptd [4]  - Driver detected an internal error in its data structures for .
.
==== End Of File ===========================
It says there is an out of date Adobe Reader installed but I just updated it and it is current, to the best of my knowledge.

  Results of screen317's Security Check version 0.99.10 
 Windows XP Service Pack 3 
 Internet Explorer 8 
``````````````````````````````
Antivirus/Firewall Check:

 Windows Firewall Enabled! 
 Virus Guard - powered by BitDefender
 McAfee Security Scan Plus   
 Antivirus up to date! 
```````````````````````````````
Anti-malware/Other Utilities Check:

 Malwarebytes' Anti-Malware   
 CCleaner     
 Java(TM) 6 Update 24 
 Adobe Flash Player    10.2.152.26 
Adobe Reader 9.4.4
Chinese Traditional Fonts Support For Adobe Reader 9
Out of date Adobe Reader installed!
 Mozilla Firefox (x86 en-US..)
````````````````````````````````
Process Check: 
objlist.exe by Laurent

 Comodo Firewall cmdagent.exe
 Comodo Firewall cfp.exe
``````````End of Log````````````
The DDS log shows that you're running COMODO Antivirus but the Security check shows Virus Guard - powered by BitDefender  and
McAfee Security Scan Plus. You should only run on AV program.
Please run RootKitUnhooker as suggested in Reply # 19.Wow that thing takes forever. 3 hours later it tells me I have possible rootkit activity. That's saddening.

I attached the log due to its length.

[recovering disk space - old attachment deleted by admin]I wouldn't worry about it. The other scans came back clean. It's going to take some time to go throught the log. In the meantime, please run this scan and post the log.

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the ICON on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
Here's the ESET log.

C:\System Volume Information\_restore{9B7DE55D-7ECA-4DF7-A547-785275B6B0CA}\RP100\A0060161.ini   Win32/Adware.AntimalwareDoctor.AE.Gen application   cleaned by deleting - quarantined
C:\System Volume Information\_restore{9B7DE55D-7ECA-4DF7-A547-785275B6B0CA}\RP100\A0062295.exe   Win32/TrojanDownloader.FakeAlert.BBT trojan   cleaned by deleting - quarantined

Ok. If there's nothing else let's do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
********************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
**********************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
*********************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping SITES. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Okay, I should be all set. As I've said many times before, I truly can't thank you enough! Best wishes to you.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
1378.

Solve : Possible Virus, otherwise Registry Issue?

Answer»

I removed SysProt and ESET. Is there SOMETHING I installed that replaces SAS and MBAM? I don't mind keeping them around as I've had them for years.

My computer has 1GB installed ram and it's using up to 16% when I checked.
It has 76.6GB on the hard drive and I'm using 37.4GB.

I know it's old and I should UPGRADE, but this is what I've got for now.

I installed Windows Defender, TFC, and Secunia. Should I delete CCLEANER if I installed TFC?

And the Avast situation...why isn't it coming on automatically anymore?
Quote

Is there something I installed that replaces SAS and MBAM?
Windows Defender should do just about the same thing but I LIKE to run them on a regular basis.
Quote
TFC, and Secunia. Should I delete CCleaner if I installed TFC?
You can get rid of all three, if you wish. You can do the same thing by using "disk cleanup"
Quote
And the Avast situation...why isn't it coming on automatically anymore?
If I were you, I would get rid of Avast and install MicroSoft SECURITY Essentials. No need to register it and it updates automatically.

Microsoft Security Essentials for Windows XP
1379.

Solve : I have a trojan?

Answer»

That's GREAT news. PLEASE keep me updated.Sorry, I was PREMATURE in thinking that the PROBLEM was solved. I'm still LOOKING though.

1380.

Solve : Can't run pgms. I am trying to install ran Hijackthis posted log. Anyone??

Answer»

Please run ESET again and this time, fix the infections and post the log.doneSo, how's your computer running now? Any other issues?Still unable run the pgm. Quote

Still unable run the pgm.
Please explain. Do you mean you can't run any programs? Do you get any error messages?Ok probably should have covered this question at the front end, but here we go
1. Bought a little pgm
wouldn't run got error msg

They eventually responded and said I needed the .net 4 framework.
Net 4 said I needed a WIC file/pgm, whatever, found here  http://www.microsoft.com/downloads/en/details.aspx?FamilyId=8E011506-6307-445B-B950-215DEF45DDD8&displaylang=en#AffinityDownloads

When I saw this page and instructions at bottom didn't know which to download, sounded like there was suppose to be a download button for the whole package. So I downloaded the .esn one for English I'm guessing. Anyway was able to install .Net 4 . Now I get another error msg.

Wondering do I need Net 2 or other or diff wic package?

Very confusing.


[recovering disk space - old attachment deleted by admin]I don't want to sound dense but what is a little pgm?

Quote
They eventually responded and said I needed the .net 4 framework.
Who is They?
I did a bit of checking about Net 4 network and there are a couple of sites where you can download it from MS. I'm sorry but I can't help you with that problem. You might have better luck posting that problem in the software forum.
Let's do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the RESULTS pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
**********************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, EXECUTION time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
**************************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block OUTGOING connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
***************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security ADDON for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT WARNS you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
1381.

Solve : Have virus. Need to copy information. Please help.?

Answer»

I have a virus that is preventing me from UPLOADING my files to a CD. I don't need help with the virus. Just with transferring my files. I just bought a mac and need to transfer the files. Is there a virtual website that I can TEMPORARILY store my files? Or, would I have better LUCK with a flash DRIVE? Many thanks.

1382.

Solve : Can someone help me please!!?

Answer» http://virusscan.jotti.org/en-gb/scanresult/01b7612528486ee80756776c20e5be28dd792b5f

http://virusscan.jotti.org/en-gb/scanresult/fc5eb0e11068590e5fbc6d3b16b706d3f8e4a611

http://virusscan.jotti.org/en-gb/scanresult/84391c69438966404bbdce4fc504ddcf4e87473f

http://virusscan.jotti.org/en-gb/scanresult/9880348cf42936dbe2702d75b9841c5bebf7b9f7

Sorry i couldn't find the last link you listed.ComboFix 11-05-09.03 - Owner 10/05/2011  18:13:20.2.2 - x86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.44.1033.18.1014.545 [GMT 1:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\bL28601CaIgA28601
c:\documents and settings\All Users\Application Data\bL28601CaIgA28601\bL28601CaIgA28601
c:\documents and settings\Owner\Application Data\xfgkxer1hbbxwfxokvojijtyebjdow3k2
.
.
(((((((((((((((((((((((((   Files Created from 2011-04-10 to 2011-05-10  )))))))))))))))))))))))))))))))
.
.
2011-05-08 11:48 . 2011-05-09 16:33   --------   d-----w-   c:\documents and settings\Owner\Application Data\Ulirmo
2011-05-05 21:25 . 2011-05-05 21:25   135680   ----a-w-   c:\windows\system32\drivers\ethxylvf.sys
2011-05-05 21:22 . 2011-05-05 21:22   388096   ----a-r-   c:\documents and settings\Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-05-05 21:22 . 2011-05-05 21:22   --------   d-----w-   c:\program files\Trend Micro
2011-05-05 21:20 . 2011-05-05 21:20   --------   d-----w-   c:\program files\Common Files\Java
2011-05-05 20:44 . 2011-05-05 20:44   --------   d-----w-   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-05-05 20:35 . 2010-12-20 17:09   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-05 20:35 . 2010-12-20 17:08   20952   ----a-w-   c:\windows\system32\drivers\mbam.sys
2011-05-05 20:32 . 2011-05-05 20:32   --------   d-----w-   c:\program files\CCleaner
2011-05-05 18:46 . 2011-05-05 18:46   114176   --sha-r-   c:\windows\system32\rpcns4H.dll
2011-05-05 18:46 . 2011-05-05 18:46   114176   --sha-r-   c:\windows\system32\logonuiv.dll
2011-05-05 18:46 . 2011-05-05 18:46   114176   --sha-r-   c:\windows\system32\ialmuTHAU.dll
2011-05-05 18:41 . 2011-04-11 07:04   7071056   ----a-w-   c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7C8C2A59-AC6B-4305-BF8F-AA42A1FBBBC0}\mpengine.dll
2011-04-29 12:34 . 2011-04-29 12:34   --------   d-----w-   c:\windows\system32\wbem\Repository
2011-04-29 12:30 . 2011-04-29 12:33   --------   d-s---w-   c:\documents and settings\Administrator
2011-04-29 06:43 . 2011-04-29 06:43   --------   d-----w-   c:\documents and settings\Owner\Application Data\Sibelius Software
2011-04-28 23:18 . 2011-04-28 23:18   --------   d-----w-   c:\documents and settings\Owner\Application Data\Malwarebytes
2011-04-28 23:18 . 2011-04-28 23:18   --------   d-----w-   c:\documents and settings\All Users\Application Data\Malwarebytes
2011-04-28 23:18 . 2011-05-05 20:35   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2011-04-28 22:38 . 2011-04-28 22:38   --------   d-----w-   c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com
2011-04-28 22:38 . 2011-05-08 11:50   --------   d-----w-   c:\program files\SUPERAntiSpyware
2011-04-25 15:51 . 2011-04-25 15:51   --------   d-----w-   c:\program files\iPod
2011-04-25 15:51 . 2011-04-25 15:53   --------   d-----w-   c:\program files\iTunes
2011-04-25 15:46 . 2011-04-25 15:46   --------   d-----w-   c:\program files\Bonjour
2011-04-25 14:07 . 2011-04-25 14:07   --------   d-----r-   C:\MSOCache
2011-04-25 13:59 . 2011-04-25 13:59   --------   d-----w-   c:\documents and settings\Owner\Local Settings\Application Data\SoftGrid Client
2011-04-25 13:59 . 2011-05-09 17:10   --------   d-----w-   c:\documents and settings\Owner\Application Data\SoftGrid Client
2011-04-25 13:59 . 2011-04-25 13:59   --------   d-----w-   c:\windows\system32\config\systemprofile\Application Data\{90140011-0062-0409-0000-0000000FF1CE}
2011-04-25 13:59 . 2011-05-09 17:10   --------   d-----w-   c:\windows\system32\config\systemprofile\Application Data\SoftGrid Client
2011-04-25 13:57 . 2011-04-25 13:57   --------   d-----w-   c:\documents and settings\All Users\Microsoft
2011-04-25 13:57 . 2011-04-29 12:38   --------   d-----w-   c:\program files\Microsoft Application Virtualization Client
2011-04-25 13:56 . 2011-04-25 14:01   --------   d-----w-   c:\documents and settings\Owner\Application Data\TP
2011-04-18 21:13 . 2011-04-18 21:13   --------   d-----w-   c:\documents and settings\Owner\Application Data\Amazon
2011-04-18 21:12 . 2011-04-18 21:12   --------   d-----w-   c:\program files\Amazon
2011-04-17 14:07 . 2011-04-17 14:07   --------   d-----w-   c:\windows\Sun
2011-04-16 14:29 . 2011-04-16 14:29   --------   d-----w-   c:\documents and settings\Owner\Application Data\OpenOffice.org
2011-04-16 14:26 . 2011-04-16 14:26   --------   d-----w-   c:\program files\OpenOffice.org 3
2011-04-16 14:25 . 2011-04-14 04:07   472808   ----a-w-   c:\windows\system32\deployJava1.dll
2011-04-16 14:25 . 2011-04-14 01:40   73728   ----a-w-   c:\windows\system32\javacpl.cpl
2011-04-16 14:25 . 2011-05-05 21:20   --------   d-----w-   c:\program files\Java
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSTITL.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSTEXT.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSSTMP.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSSPEC.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSSCRP.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSREH_.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSMET_.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSCHOR.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRS____.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSTEXT.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSSE__.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSS___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSROMC.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSPC__.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSP___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSO___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSNN__.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSM___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSFS__.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSFBE_.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSFB__.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSCSC_.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSCS__.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSC___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUS____.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\INKPEN2_.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\INK2TEXT.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\INK2SPEC.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\INK2SCRI.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\INK2METR.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\INK2CHOR.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\HELST___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\HELSS___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\HELSM___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\HELSINKI.FOT
2011-04-11 07:04 . 2011-02-06 22:20   7071056   ----a-w-   c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-04-06 15:20 . 2011-04-06 15:20   91424   ----a-w-   c:\windows\system32\dnssd.dll
2011-04-06 15:20 . 2011-04-06 15:20   75040   ----a-w-   c:\windows\system32\jdns_sd.dll
2011-04-06 15:20 . 2011-04-06 15:20   197920   ----a-w-   c:\windows\system32\dnssdX.dll
2011-04-06 15:20 . 2011-04-06 15:20   107808   ----a-w-   c:\windows\system32\dns-sd.exe
2011-03-07 05:33 . 2011-01-11 19:25   692736   ----a-w-   c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2004-08-04 10:00   420864   ----a-w-   c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2004-08-04 10:00   1857920   ----a-w-   c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2006-03-04 03:33   916480   ----a-w-   c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2004-08-04 10:00   43520   ------w-   c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2004-08-04 10:00   1469440   ------w-   c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2004-08-04 10:00   385024   ------w-   c:\windows\system32\html.iec
2011-02-17 13:18 . 2004-08-04 10:00   455936   ----a-w-   c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2004-08-04 10:00   357888   ----a-w-   c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2011-01-19 20:06   5120   ----a-w-   c:\windows\system32\xpsp4res.dll
2011-02-15 12:56 . 2004-08-04 10:00   290432   ----a-w-   c:\windows\system32\atmfd.dll
.
.
(((((((((((((((((((((((((((((   [email protected]_16.53.14   )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-01-11 09:59 . 2011-01-11 09:59   51024              c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_214ee422\vcomp90.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   59728              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90rus.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   42832              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90kor.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   43344              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90jpn.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   61264              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90ita.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   62800              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90fra.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   61776              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90esp.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   61776              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90esn.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   53584              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90enu.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   63312              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90deu.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   36688              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90cht.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   35664              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90chs.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   59904              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfcm90u.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   59904              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfcm90.dll
+ 2011-05-10 17:19 . 2011-05-10 17:19   16384              c:\windows\temp\Perflib_Perfdata_798.dat
+ 2011-01-11 09:59 . 2011-01-11 09:59   653136              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcr90.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   569680              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcp90.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   225280              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcm90.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   159048              c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_65b7a93a\atl90.dll
+ 2011-05-09 17:10 . 2011-05-09 17:10   223232              c:\windows\Installer\186080.msi
+ 2011-01-11 09:59 . 2011-01-11 09:59   3780936              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfc90u.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   3766088              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfc90.dll
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-08 2424192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-02-18 49208]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
ykitl.exe [2011-5-8 284160]
.
c:\documents and settings\Owner\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP DIGITAL Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21   548352   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 19:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 19:41 67656]
R2 ASTRA32;ASTRA32 Kernel Driver 5.2.1.0;c:\program files\ASTRA32\astra32.sys [22/02/2007 12:28 30864]
R2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [28/02/2010 02:33 821664]
R2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [24/04/2010 01:10 483688]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfsxp.sys [02/12/2009 22:23 554344]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplayxp.sys [02/12/2009 22:23 211432]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [02/12/2009 22:23 20584]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvolxp.sys [02/12/2009 22:23 18280]
R3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [24/04/2010 01:10 209768]
S0 nwba;nwba;c:\windows\system32\drivers\fxufjr.sys --> c:\windows\system32\drivers\fxufjr.sys [?]
S1 ethxylvf;ethxylvf;c:\windows\system32\drivers\ethxylvf.sys [05/05/2011 22:25 135680]
S2 AMService;AMService;c:\windows\TEMP\kixd\setup.exe run --> c:\windows\TEMP\kixd\setup.exe run [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 14:16 130384]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 21:37 4640000]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [04/08/2004 11:00 14336]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;f:\zune\WMZuneComm.exe --> f:\zune\WMZuneComm.exe [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 14:16 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM   REG_MULTI_SZ      WINRM
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-10 18:20
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ... 
.
scanning hidden autostart entries ...
.
scanning hidden files ... 
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
Denied: (A 2) (Everyone)
="FlashBroker"
"LocalizedString"="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
Denied: (A 2) (Everyone)
="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(640)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(560)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\wscntfy.exe
c:\windows\stsystra.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2011-05-10  18:23:43 - machine was rebooted
ComboFix-quarantined-files.txt  2011-05-10 17:23
ComboFix2.txt  2011-05-09 16:54
.
Pre-Run: 488,152,834,048 bytes free
Post-Run: 488,185,438,208 bytes free
.
- - End Of File - - 39F9F2BE1C45ACA3A07C972651ABE405Ok. Just a few more things to do. Any improvement in your computer?

Re-running ComboFix to remove infections:

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Open notepad and copy/paste the text in the quotebox below into it:
    Quote
    KillAll::

    File::
    c:\windows\system32\drivers\ethxylvf.sys
    c:\documents and settings\Default User\Start Menu\Programs\Startup\
    ykitl.exe

    Driver::
    ethxylvf
  • Save this as CFScript.txt, in the same location as ComboFix.exe



  • Referring to the picture above, drag CFScript into ComboFix.exe
  • When finished, it shall produce a log for you at C:\ComboFix.txt
  • Please post the contents of the log in your next reply.
******************************************************
DOWNLOAD Security Check by screen317 from one of the following links and save it to your desktop.

Link 1
Link 2

* Unzip SecurityCheck.zip and a folder named Security Check should appear.
* Open the Security Check folder and double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so. Results of screen317's Security Check version 0.99.10 
 Windows XP Service Pack 3 
 Internet Explorer 8 
``````````````````````````````
Antivirus/Firewall Check:

 Windows Firewall Enabled! 
 Microsoft Security Essentials   
```````````````````````````````
Anti-malware/Other Utilities Check:

 Malwarebytes' Anti-Malware   
 CCleaner     
 Java(TM) 6 Update 25 
 Out of date Java installed!
 Adobe Flash Player   
````````````````````````````````
Process Check: 
objlist.exe by Laurent

 Microsoft Security Essentials msseces.exe
``````````End of Log```````````` ComboFix 11-05-10.02 - Owner 11/05/2011  18:10:05.3.2 - x86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.44.1033.18.1014.559 [GMT 1:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"c:\documents and settings\Default User\Start Menu\Programs\Startup\"
"c:\windows\system32\drivers\ethxylvf.sys"
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\drivers\ethxylvf.sys
.
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_ethxylvf
.
.
(((((((((((((((((((((((((   Files Created from 2011-04-11 to 2011-05-11  )))))))))))))))))))))))))))))))
.
.
2011-05-08 11:48 . 2011-05-09 16:33   --------   d-----w-   c:\documents and settings\Owner\Application Data\Ulirmo
2011-05-05 21:22 . 2011-05-05 21:22   388096   ----a-r-   c:\documents and settings\Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-05-05 21:22 . 2011-05-05 21:22   --------   d-----w-   c:\program files\Trend Micro
2011-05-05 21:20 . 2011-05-05 21:20   --------   d-----w-   c:\program files\Common Files\Java
2011-05-05 20:44 . 2011-05-05 20:44   --------   d-----w-   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-05-05 20:35 . 2010-12-20 17:09   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-05 20:35 . 2010-12-20 17:08   20952   ----a-w-   c:\windows\system32\drivers\mbam.sys
2011-05-05 20:32 . 2011-05-05 20:32   --------   d-----w-   c:\program files\CCleaner
2011-05-05 18:46 . 2011-05-05 18:46   114176   --sha-r-   c:\windows\system32\rpcns4H.dll
2011-05-05 18:46 . 2011-05-05 18:46   114176   --sha-r-   c:\windows\system32\logonuiv.dll
2011-05-05 18:46 . 2011-05-05 18:46   114176   --sha-r-   c:\windows\system32\ialmuTHAU.dll
2011-05-05 18:41 . 2011-04-11 07:04   7071056   ----a-w-   c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7C8C2A59-AC6B-4305-BF8F-AA42A1FBBBC0}\mpengine.dll
2011-04-29 12:34 . 2011-04-29 12:34   --------   d-----w-   c:\windows\system32\wbem\Repository
2011-04-29 12:30 . 2011-04-29 12:33   --------   d-s---w-   c:\documents and settings\Administrator
2011-04-29 06:43 . 2011-04-29 06:43   --------   d-----w-   c:\documents and settings\Owner\Application Data\Sibelius Software
2011-04-28 23:18 . 2011-04-28 23:18   --------   d-----w-   c:\documents and settings\Owner\Application Data\Malwarebytes
2011-04-28 23:18 . 2011-04-28 23:18   --------   d-----w-   c:\documents and settings\All Users\Application Data\Malwarebytes
2011-04-28 23:18 . 2011-05-05 20:35   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2011-04-28 22:38 . 2011-04-28 22:38   --------   d-----w-   c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com
2011-04-28 22:38 . 2011-05-08 11:50   --------   d-----w-   c:\program files\SUPERAntiSpyware
2011-04-25 15:51 . 2011-04-25 15:51   --------   d-----w-   c:\program files\iPod
2011-04-25 15:51 . 2011-04-25 15:53   --------   d-----w-   c:\program files\iTunes
2011-04-25 15:46 . 2011-04-25 15:46   --------   d-----w-   c:\program files\Bonjour
2011-04-25 14:07 . 2011-04-25 14:07   --------   d-----r-   C:\MSOCache
2011-04-25 13:59 . 2011-04-25 13:59   --------   d-----w-   c:\documents and settings\Owner\Local Settings\Application Data\SoftGrid Client
2011-04-25 13:59 . 2011-05-10 18:53   --------   d-----w-   c:\documents and settings\Owner\Application Data\SoftGrid Client
2011-04-25 13:59 . 2011-04-25 13:59   --------   d-----w-   c:\windows\system32\config\systemprofile\Application Data\{90140011-0062-0409-0000-0000000FF1CE}
2011-04-25 13:59 . 2011-05-10 18:53   --------   d-----w-   c:\windows\system32\config\systemprofile\Application Data\SoftGrid Client
2011-04-25 13:57 . 2011-04-25 13:57   --------   d-----w-   c:\documents and settings\All Users\Microsoft
2011-04-25 13:57 . 2011-04-29 12:38   --------   d-----w-   c:\program files\Microsoft Application Virtualization Client
2011-04-25 13:56 . 2011-04-25 14:01   --------   d-----w-   c:\documents and settings\Owner\Application Data\TP
2011-04-18 21:13 . 2011-04-18 21:13   --------   d-----w-   c:\documents and settings\Owner\Application Data\Amazon
2011-04-18 21:12 . 2011-04-18 21:12   --------   d-----w-   c:\program files\Amazon
2011-04-17 14:07 . 2011-04-17 14:07   --------   d-----w-   c:\windows\Sun
2011-04-16 14:29 . 2011-04-16 14:29   --------   d-----w-   c:\documents and settings\Owner\Application Data\OpenOffice.org
2011-04-16 14:26 . 2011-04-16 14:26   --------   d-----w-   c:\program files\OpenOffice.org 3
2011-04-16 14:25 . 2011-04-14 04:07   472808   ----a-w-   c:\windows\system32\deployJava1.dll
2011-04-16 14:25 . 2011-04-14 01:40   73728   ----a-w-   c:\windows\system32\javacpl.cpl
2011-04-16 14:25 . 2011-05-05 21:20   --------   d-----w-   c:\program files\Java
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSTITL.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSTEXT.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSSTMP.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSSPEC.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSSCRP.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSREH_.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSMET_.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSCHOR.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRS____.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSTEXT.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSSE__.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSS___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSROMC.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSPC__.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSP___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSO___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSNN__.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSM___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSFS__.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSFBE_.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSFB__.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSCSC_.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSCS__.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSC___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUS____.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\INKPEN2_.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\INK2TEXT.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\INK2SPEC.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\INK2SCRI.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\INK2METR.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\INK2CHOR.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\HELST___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\HELSS___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\HELSM___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\HELSINKI.FOT
2011-04-11 07:04 . 2011-02-06 22:20   7071056   ----a-w-   c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-04-06 15:20 . 2011-04-06 15:20   91424   ----a-w-   c:\windows\system32\dnssd.dll
2011-04-06 15:20 . 2011-04-06 15:20   75040   ----a-w-   c:\windows\system32\jdns_sd.dll
2011-04-06 15:20 . 2011-04-06 15:20   197920   ----a-w-   c:\windows\system32\dnssdX.dll
2011-04-06 15:20 . 2011-04-06 15:20   107808   ----a-w-   c:\windows\system32\dns-sd.exe
2011-03-07 05:33 . 2011-01-11 19:25   692736   ----a-w-   c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2004-08-04 10:00   420864   ----a-w-   c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2004-08-04 10:00   1857920   ----a-w-   c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2006-03-04 03:33   916480   ----a-w-   c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2004-08-04 10:00   43520   ------w-   c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2004-08-04 10:00   1469440   ------w-   c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2004-08-04 10:00   385024   ------w-   c:\windows\system32\html.iec
2011-02-17 13:18 . 2004-08-04 10:00   455936   ----a-w-   c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2004-08-04 10:00   357888   ----a-w-   c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2011-01-19 20:06   5120   ----a-w-   c:\windows\system32\xpsp4res.dll
2011-02-15 12:56 . 2004-08-04 10:00   290432   ----a-w-   c:\windows\system32\atmfd.dll
.
.
(((((((((((((((((((((((((((((   [email protected]_16.53.14   )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-01-11 09:59 . 2011-01-11 09:59   51024              c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_214ee422\vcomp90.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   59728              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90rus.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   42832              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90kor.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   43344              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90jpn.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   61264              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90ita.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   62800              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90fra.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   61776              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90esp.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   61776              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90esn.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   53584              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90enu.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   63312              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90deu.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   36688              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90cht.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   35664              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90chs.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   59904              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfcm90u.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   59904              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfcm90.dll
+ 2011-05-11 17:15 . 2011-05-11 17:15   16384              c:\windows\temp\Perflib_Perfdata_660.dat
+ 2011-01-11 09:59 . 2011-01-11 09:59   653136              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcr90.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   569680              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcp90.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   225280              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcm90.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   159048              c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_65b7a93a\atl90.dll
+ 2011-05-09 17:10 . 2011-05-09 17:10   223232              c:\windows\Installer\186080.msi
+ 2011-01-11 09:59 . 2011-01-11 09:59   3780936              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfc90u.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   3766088              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfc90.dll
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-08 2424192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-02-18 49208]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
ykitl.exe [2011-5-8 284160]
.
c:\documents and settings\Owner\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21   548352   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 19:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 19:41 67656]
R2 ASTRA32;ASTRA32 Kernel Driver 5.2.1.0;c:\program files\ASTRA32\astra32.sys [22/02/2007 12:28 30864]
R2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [28/02/2010 02:33 821664]
R2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [24/04/2010 01:10 483688]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfsxp.sys [02/12/2009 22:23 554344]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplayxp.sys [02/12/2009 22:23 211432]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [02/12/2009 22:23 20584]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvolxp.sys [02/12/2009 22:23 18280]
R3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [24/04/2010 01:10 209768]
S0 nwba;nwba;c:\windows\system32\drivers\fxufjr.sys --> c:\windows\system32\drivers\fxufjr.sys [?]
S2 AMService;AMService;c:\windows\TEMP\kixd\setup.exe run --> c:\windows\TEMP\kixd\setup.exe run [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 14:16 130384]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 21:37 4640000]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [04/08/2004 11:00 14336]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;f:\zune\WMZuneComm.exe --> f:\zune\WMZuneComm.exe [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 14:16 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM   REG_MULTI_SZ      WINRM
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-11 18:16
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ... 
.
scanning hidden autostart entries ...
.
scanning hidden files ... 
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
Denied: (A 2) (Everyone)
="FlashBroker"
"LocalizedString"="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
Denied: (A 2) (Everyone)
="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(620)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(3248)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\wscntfy.exe
c:\windows\stsystra.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2011-05-11  18:19:13 - machine was rebooted
ComboFix-quarantined-files.txt  2011-05-11 17:19
ComboFix2.txt  2011-05-10 17:23
ComboFix3.txt  2011-05-09 16:54
.
Pre-Run: 488,131,448,832 bytes free
Post-Run: 488,109,334,528 bytes free
.
- - End Of File - - 3134006567461E2BA064FDD000367D38
SysProt Antirootkit

Download
SysProt Antirootkit from the link below (you will find it at the bottom
of the page under attachments, or you can get it from one of the
mirrors).

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.
  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select the following items.
    • Process << Selected
    • Kernel Modules << Selected
    • SSDT << Selected
    • Kernel Hooks << Selected
    • IRP Hooks << NOT Selected
    • Ports << NOT Selected
    • Hidden Files << Selected
  • At the bottom of the page
    • Hidden Objects Only << Selected
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan ROOT Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to. Open the text file and copy/paste the log here.
SysProt AntiRootkit v1.0.1.0
by swatkat

******************************************************************************************
******************************************************************************************

No Hidden Processes found

******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: AA45C000
Module End: AA474000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
Service Name: ---
Module Base: F7B58000
Module End: F7B5A000
Hidden: Yes

Module Name: C:\WINDOWS\system32\DRIVERS\WinUSB.sys
Service Name: WinUSB
Module Base: F7966000
Module End: F796E000
Hidden: Yes

Module Name: C:\WINDOWS\system32\DRIVERS\wudfrd.sys
Service Name: WudfRd
Module Base: AA1CC000
Module End: AA1ED000
Hidden: Yes

******************************************************************************************
******************************************************************************************
SSDT:
Function Name: ZwTerminateProcess
Address: AA567620
Driver Base: AA55D000
Driver End: AA57F000
Driver Name: \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS

******************************************************************************************
******************************************************************************************
No Kernel Hooks found

******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: C:\Qoobox\BackEnv\AppData.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Cache.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Cookies.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Desktop.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Favorites.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\History.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Music.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\NetHood.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Personal.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Pictures.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\PrintHood.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Profiles.Folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Programs.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Recent.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SendTo.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SetPath.bat
Status: Access denied

Object: C:\Qoobox\BackEnv\StartMenu.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\StartUp.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SysPath.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Templates.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\VikPev00
Status: Access denied

Looking good. Let's try this scan.

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be PATIENT as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\37\4bb6a8a5-26d0d414   Java/TrojanDownloader.OpenStream.NBV trojan
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\31\3ba0d75f-12867f1f   Java/TrojanDownloader.OpenStream.NBV trojan
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\6\27241306-4d955265   Java/TrojanDownloader.Agent.NCQ trojan
Please run ESET again and this time, clean the infections. How's your computer working now? Any other issues?The first and last file i couldn't find but here are the results for the rest.

http://virusscan.jotti.org/en-gb/scanresult/d6ffeee1d24a1531e91b17f4e2e35fe86b924006

http://virusscan.jotti.org/en-gb/scanresult/84391c69438966404bbdce4fc504ddcf4e87473f/66ee4b78e7f4dca13e54b43985109d4933be4897

http://virusscan.jotti.org/en-gb/scanresult/f1504c02d1a67e8a72aee63a14005f4f091f3c5dComboFix 11-05-14.01 - Owner 15/05/2011  10:25:44.4.2 - x86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.44.1033.18.1014.331 [GMT 1:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
(((((((((((((((((((((((((   Files Created from 2011-04-15 to 2011-05-15  )))))))))))))))))))))))))))))))
.
.
2011-05-15 09:33 . 2011-05-15 09:33   28752   ----a-w-   c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3A938866-38C7-452E-BE72-C0210707AC87}\MpKsld931e1f3.sys
2011-05-15 09:15 . 2011-05-15 09:15   28752   ----a-w-   c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3A938866-38C7-452E-BE72-C0210707AC87}\MpKslca26fab0.sys
2011-05-15 09:14 . 2011-04-11 07:04   7071056   ----a-w-   c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3A938866-38C7-452E-BE72-C0210707AC87}\mpengine.dll
2011-05-15 09:06 . 2011-05-15 09:06   404640   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-14 10:34 . 2011-05-14 10:34   --------   d-----w-   c:\documents and settings\All Users\Application Data\VirtualizedApplications
2011-05-14 08:29 . 2011-05-14 08:29   --------   d-----w-   c:\program files\ESET
2011-05-08 11:48 . 2011-05-09 16:33   --------   d-----w-   c:\documents and settings\Owner\Application Data\Ulirmo
2011-05-05 21:22 . 2011-05-05 21:22   388096   ----a-r-   c:\documents and settings\Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-05-05 21:22 . 2011-05-05 21:22   --------   d-----w-   c:\program files\Trend Micro
2011-05-05 21:20 . 2011-05-05 21:20   --------   d-----w-   c:\program files\Common Files\Java
2011-05-05 20:44 . 2011-05-05 20:44   --------   d-----w-   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-05-05 20:35 . 2010-12-20 17:09   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-05 20:35 . 2010-12-20 17:08   20952   ----a-w-   c:\windows\system32\drivers\mbam.sys
2011-05-05 20:32 . 2011-05-05 20:32   --------   d-----w-   c:\program files\CCleaner
2011-05-05 18:46 . 2011-05-05 18:46   114176   --sha-r-   c:\windows\system32\rpcns4H.dll
2011-05-05 18:46 . 2011-05-05 18:46   114176   --sha-r-   c:\windows\system32\logonuiv.dll
2011-05-05 18:46 . 2011-05-05 18:46   114176   --sha-r-   c:\windows\system32\ialmuTHAU.dll
2011-04-29 12:34 . 2011-04-29 12:34   --------   d-----w-   c:\windows\system32\wbem\Repository
2011-04-29 12:30 . 2011-04-29 12:33   --------   d-s---w-   c:\documents and settings\Administrator
2011-04-29 06:43 . 2011-04-29 06:43   --------   d-----w-   c:\documents and settings\Owner\Application Data\Sibelius Software
2011-04-28 23:18 . 2011-04-28 23:18   --------   d-----w-   c:\documents and settings\Owner\Application Data\Malwarebytes
2011-04-28 23:18 . 2011-04-28 23:18   --------   d-----w-   c:\documents and settings\All Users\Application Data\Malwarebytes
2011-04-28 23:18 . 2011-05-05 20:35   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2011-04-28 22:38 . 2011-04-28 22:38   --------   d-----w-   c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com
2011-04-28 22:38 . 2011-05-08 11:50   --------   d-----w-   c:\program files\SUPERAntiSpyware
2011-04-25 15:51 . 2011-04-25 15:51   --------   d-----w-   c:\program files\iPod
2011-04-25 15:51 . 2011-04-25 15:53   --------   d-----w-   c:\program files\iTunes
2011-04-25 15:46 . 2011-04-25 15:46   --------   d-----w-   c:\program files\Bonjour
2011-04-25 14:07 . 2011-04-25 14:07   --------   d-----r-   C:\MSOCache
2011-04-25 13:59 . 2011-04-25 13:59   --------   d-----w-   c:\documents and settings\Owner\Local Settings\Application Data\SoftGrid Client
2011-04-25 13:59 . 2011-05-14 11:28   --------   d-----w-   c:\documents and settings\Owner\Application Data\SoftGrid Client
2011-04-25 13:59 . 2011-04-25 13:59   --------   d-----w-   c:\windows\system32\config\systemprofile\Application Data\{90140011-0062-0409-0000-0000000FF1CE}
2011-04-25 13:59 . 2011-05-14 11:28   --------   d-----w-   c:\windows\system32\config\systemprofile\Application Data\SoftGrid Client
2011-04-25 13:57 . 2011-04-25 13:57   --------   d-----w-   c:\documents and settings\All Users\Microsoft
2011-04-25 13:57 . 2011-04-29 12:38   --------   d-----w-   c:\program files\Microsoft Application Virtualization Client
2011-04-25 13:56 . 2011-04-25 14:01   --------   d-----w-   c:\documents and settings\Owner\Application Data\TP
2011-04-18 21:13 . 2011-04-18 21:13   --------   d-----w-   c:\documents and settings\Owner\Application Data\Amazon
2011-04-18 21:12 . 2011-04-18 21:12   --------   d-----w-   c:\program files\Amazon
2011-04-17 14:07 . 2011-04-17 14:07   --------   d-----w-   c:\windows\Sun
2011-04-16 14:29 . 2011-04-16 14:29   --------   d-----w-   c:\documents and settings\Owner\Application Data\OpenOffice.org
2011-04-16 14:26 . 2011-04-16 14:26   --------   d-----w-   c:\program files\OpenOffice.org 3
2011-04-16 14:25 . 2011-04-14 04:07   472808   ----a-w-   c:\windows\system32\deployJava1.dll
2011-04-16 14:25 . 2011-04-14 01:40   73728   ----a-w-   c:\windows\system32\javacpl.cpl
2011-04-16 14:25 . 2011-05-05 21:20   --------   d-----w-   c:\program files\Java
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSTITL.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSTEXT.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSSTMP.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSSPEC.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSSCRP.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSREH_.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSMET_.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRSCHOR.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\RPRS____.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSTEXT.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSSE__.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSS___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSROMC.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSPC__.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSP___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSO___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSNN__.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSM___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSFS__.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSFBE_.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSFB__.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSCSC_.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSCS__.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUSC___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\OPUS____.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\INKPEN2_.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\INK2TEXT.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\INK2SPEC.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\INK2SCRI.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\INK2METR.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\INK2CHOR.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\HELST___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\HELSS___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\HELSM___.FOT
2011-04-29 06:43 . 2011-04-29 06:43   1409   ----a-w-   c:\windows\Fonts\HELSINKI.FOT
2011-04-11 07:04 . 2011-02-06 22:20   7071056   ----a-w-   c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-04-06 15:20 . 2011-04-06 15:20   91424   ----a-w-   c:\windows\system32\dnssd.dll
2011-04-06 15:20 . 2011-04-06 15:20   75040   ----a-w-   c:\windows\system32\jdns_sd.dll
2011-04-06 15:20 . 2011-04-06 15:20   197920   ----a-w-   c:\windows\system32\dnssdX.dll
2011-04-06 15:20 . 2011-04-06 15:20   107808   ----a-w-   c:\windows\system32\dns-sd.exe
2011-03-07 05:33 . 2011-01-11 19:25   692736   ----a-w-   c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2004-08-04 10:00   420864   ----a-w-   c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2004-08-04 10:00   1857920   ----a-w-   c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2006-03-04 03:33   916480   ----a-w-   c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2004-08-04 10:00   43520   ------w-   c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2004-08-04 10:00   1469440   ------w-   c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2004-08-04 10:00   385024   ------w-   c:\windows\system32\html.iec
2011-02-17 13:18 . 2004-08-04 10:00   455936   ----a-w-   c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2004-08-04 10:00   357888   ----a-w-   c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2011-01-19 20:06   5120   ----a-w-   c:\windows\system32\xpsp4res.dll
2011-02-15 12:56 . 2004-08-04 10:00   290432   ----a-w-   c:\windows\system32\atmfd.dll
.
.
(((((((((((((((((((((((((((((   [email protected]_16.53.14   )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-01-11 09:59 . 2011-01-11 09:59   51024              c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_214ee422\vcomp90.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   59728              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90rus.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   42832              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90kor.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   43344              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90jpn.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   61264              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90ita.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   62800              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90fra.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   61776              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90esp.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   61776              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90esn.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   53584              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90enu.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   63312              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90deu.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   36688              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90cht.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   35664              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90chs.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   59904              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfcm90u.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   59904              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfcm90.dll
+ 2011-05-15 09:33 . 2011-05-15 09:33   16384              c:\windows\temp\Perflib_Perfdata_74c.dat
+ 2011-01-11 09:59 . 2011-01-11 09:59   653136              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcr90.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   569680              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcp90.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   225280              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcm90.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   159048              c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_65b7a93a\atl90.dll
+ 2011-05-15 09:06 . 2011-05-15 09:06   240288              c:\windows\system32\Macromed\Flash\FlashUtil10q_ActiveX.exe
+ 2011-05-15 09:06 . 2011-05-15 09:06   321184              c:\windows\system32\Macromed\Flash\FlashUtil10q_ActiveX.dll
+ 2011-05-09 17:10 . 2011-05-09 17:10   223232              c:\windows\Installer\186080.msi
+ 2011-01-11 09:59 . 2011-01-11 09:59   3780936              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfc90u.dll
+ 2011-01-11 09:59 . 2011-01-11 09:59   3766088              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfc90.dll
+ 2011-01-19 20:26 . 2011-05-11 17:41   42829768              c:\windows\system32\MRT.exe
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-08 2424192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-02-18 49208]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Owner\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21   548352   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R1 MpKslca26fab0;MpKslca26fab0;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3A938866-38C7-452E-BE72-C0210707AC87}\MpKslca26fab0.sys [15/05/2011 10:15 28752]
R1 MpKsld931e1f3;MpKsld931e1f3;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3A938866-38C7-452E-BE72-C0210707AC87}\MpKsld931e1f3.sys [15/05/2011 10:33 28752]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 19:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 19:41 67656]
R2 ASTRA32;ASTRA32 Kernel Driver 5.2.1.0;c:\program files\ASTRA32\astra32.sys [22/02/2007 12:28 30864]
R2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [28/02/2010 02:33 821664]
R2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [24/04/2010 01:10 483688]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfsxp.sys [02/12/2009 22:23 554344]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplayxp.sys [02/12/2009 22:23 211432]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [02/12/2009 22:23 20584]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvolxp.sys [02/12/2009 22:23 18280]
R3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [24/04/2010 01:10 209768]
S0 nwba;nwba;c:\windows\system32\drivers\fxufjr.sys --> c:\windows\system32\drivers\fxufjr.sys [?]
S2 AMService;AMService;c:\windows\TEMP\kixd\setup.exe run --> c:\windows\TEMP\kixd\setup.exe run [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 14:16 130384]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 21:37 4640000]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [04/08/2004 11:00 14336]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;f:\zune\WMZuneComm.exe [11/11/2010 14:57 268528]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 14:16 753504]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSLD931E1F3
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM   REG_MULTI_SZ      WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-15 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 12:26]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-15 10:35
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ... 
.
scanning hidden autostart entries ...
.
scanning hidden files ... 
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
Denied: (A 2) (Everyone)
="FlashBroker"
"LocalizedString"="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10q_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10q_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
Denied: (A 2) (Everyone)
="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(620)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(724)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
f:\zune\ZuneBusEnum.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\stsystra.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2011-05-15  10:38:24 - machine was rebooted
ComboFix-quarantined-files.txt  2011-05-15 09:38
ComboFix2.txt  2011-05-11 17:19
ComboFix3.txt  2011-05-10 17:23
ComboFix4.txt  2011-05-09 16:54
.
Pre-Run: 487,744,663,552 bytes free
Post-Run: 487,813,476,352 bytes free
.
- - End Of File - - 089C36B5AA4188206B2D13BE7F2779A3
SORRY! READ THE WRONG PAGE. DONT WORRY ABOUT THE PREVIOUS COUPLE OF POSTS!!I've scanned again and got rid of the infections. Touch wood, everything seems to be okay at the mo i think...That's great. Let's do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
*******************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
*******************************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
**************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
1383.

Solve : Thanks anyway?

Answer»

Hi,

THANKS so much for your speedy replies and I'm sorry I havne't been responsive.  I have also been in and out of town, so it's been HARD to get to my computer.  I look forward to your return.

I'm having trouble deleting all my temporary files, so I'm GOING to hold off disabling system restore until I can do that.  My computer won't let me delete a file called etilqs_8U5En2QaP8il3mcnXby9 because
"this file is currently in use by another program."  I started out with only one file whose name started with etilqs_ _____, and now I somehow have 3.  Is this part of the virus?  I keep hitting "try again" and it's no use.

THanks again, and I hope you have a good trip!Sq Lite is a Firefox add on.
You should be able to delete the files in Safe mode.
Try REMOVING FirFox and do a re install
of the latest version without SQLite.
there is a program called ccleaner formly called crap cleaner but for reasons it was changed.  This should allow you to remove it safely an select what you want to remove.http://ccollomb.free.fr/unlocker/


go here DOWNLOAD it and it will take out anything , harry

1384.

Solve : Everything has disappeared?

Answer»

HP Pavilion dv9000 notebook
Vista
used at office on network

I was searching on Google Video using the new Google Chrome browser.
Search was LIMITED to "videos playable on Google".
I got a drop-down on the browser stating that I needed to install Quicktime plug-in, which I proceeded to do.
After a few minutes of download, the Chrome browser froze, and would not close using Task Manager.
Tried a restart....desktop came up EMPTY except for recycle bin and desktop.ini
No programs show under the start menu.  Almost EVERYTHING in My Documents has disappeared.
Windows explorer still shows some program files, but others are missing.
Windows Defender will not start.
Windows Restore shows no restore points available.
Could not access my computer thru the Symantec Client software on the network server


I've downloaded and run the following:
AntiVir Personal...nothing detected
Nothing unusual in Add/Remove programs
CCleaner Slim...nothing unusual
SuperAntispyware...nothing detected
Malwarebytes Anti-Malware...see attached log
Tried to update with latest Java...kept getting message that it could not access network resource.  Removed old versions using JavaRA
HijackThis...see attached log


Thank you for your HELP



[attachment DELETED by admin]

1385.

Solve : I Need To Know if This Trojan is Gone?

Answer»

I had a Trojan that I had to remove manually because no software could remove it completely nor could it detect it. However there are some files that I did not modify, delete, or restore because I wasn't sure how to.

Those files would be

    * %System%\kernel32.dll
    * %System%\powrprof.dll
    * %System%\wininet.dll
    * %System%\dllcache\kernel32.dll
    * %System%\dllcache\powrprof.dll
    * %System%\dllcache\wininet.dll

I am worried that these might be infected because the write up on this Trojan says that it infects those files. Here is the Trojan Info on Symantecs Website.

So far I haven't noticed any further problems but I want to make sure my system is clean and that there isn't anything lurking around or hiding. Is there a way to see if these are infected or should I just restore new copies of the files? I do not know how to restore new copies so I would need assistance with that.

Here are my logs and I appreciate any assistance.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/11/2009 at 02:15 PM

Application Version : 4.26.1002

Core Rules Database Version : 3886
Trace Rules Database Version: 1834

Scan type       : Complete Scan
Total Scan Time : 00:59:46

Memory items scanned      : 636
Memory threats detected   : 0
Registry items scanned    : 7207
Registry threats detected : 0
File items scanned        : 10206
File threats detected     : 0
========================

Malwarebytes' Anti-Malware 1.36
Database version: 2099
Windows 5.1.2600 Service Pack 2

5/11/2009 5:04:25 PM
mbam-log-2009-05-11 (17-04-25).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 313611
Time elapsed: 2 hour(s), 46 minute(s), 30 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

=======================
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:13:15 PM, on 5/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CSHelper.exe
c:\Program Files\Pure Digital Technologies\FlipShare\FlipShareService.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\MozyHome\mozybackup.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Logitech\PktDrvr\LVCOMS.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\X3watch\x3watch.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\IObit\Advanced WindowsCare V2\Awcl.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\program files\microsoft activesync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\MozyHome\mozystat.exe
C:\Program Files\Dropbox\Dropbox.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wbls.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - c:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no NAME) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\PktDrvr\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [x3watch] C:\Program Files\X3watch\x3watch.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [Advanced WindowsCare V2 Personal] "C:\Program Files\IObit\Advanced WindowsCare V2\Awcl.exe" /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\program files\quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [trojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [H/PC CONNECTION Agent] "C:\program files\microsoft activesync\wcescomm.exe"
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [eFax 4.4] "C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe" /R
O4 - HKCU\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-21-221286951-3871430604-1572435002-1006\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-221286951-3871430604-1572435002-1006\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?')
O4 - HKUS\S-1-5-21-221286951-3871430604-1572435002-1006\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (User '?')
O4 - HKUS\S-1-5-21-221286951-3871430604-1572435002-1006\..\Run: [H/PC Connection Agent] "C:\program files\microsoft activesync\wcescomm.exe" (User '?')
O4 - HKUS\S-1-5-21-221286951-3871430604-1572435002-1006\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter (User '?')
O4 - HKUS\S-1-5-21-221286951-3871430604-1572435002-1006\..\Run: [Aim6]  (User '?')
O4 - HKUS\S-1-5-21-221286951-3871430604-1572435002-1006\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO (User '?')
O4 - HKUS\S-1-5-21-221286951-3871430604-1572435002-1006\..\Run: [eFax 4.4] "C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe" /R (User '?')
O4 - HKUS\S-1-5-21-221286951-3871430604-1572435002-1006\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart (User '?')
O4 - HKUS\S-1-5-21-221286951-3871430604-1572435002-1006\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (User '?')
O4 - HKUS\S-1-5-18\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User '?')
O4 - HKUS\.DEFAULT\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'Default user')
O4 - S-1-5-21-221286951-3871430604-1572435002-1006 Startup: Dropbox.lnk = C:\Program Files\Dropbox\Dropbox.exe (User '?')
O4 - Startup: Dropbox.lnk = C:\Program Files\Dropbox\Dropbox.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - c:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - c:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.acddirect.com
O15 - Trusted Zone: http://www..acddirect.com
O15 - Trusted Zone: http://www2.callswithoutwalls.com
O15 - Trusted Zone: http://*.statcounter.com
O15 - Trusted Zone: http://*.vacd.biz
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center BASE Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://pcpitstop.com/antivirus/PitPav.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec PASSWORD Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\WINDOWS\system32\CSHelper.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: FlipShare Service - Unknown owner - c:\Program Files\Pure Digital Technologies\FlipShare\FlipShareService.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: MozyHome Backup Service (mozybackup) - Mozy, Inc. - C:\Program Files\MozyHome\mozybackup.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 21362 bytes



you should have only 1 anti-virus on your pc , you have avg , mcafee and looks like nortonI only use AVG. My Mcafee subscription has expired and hasn't been used in a year. well why have it in your pc

1386.

Solve : Help! I'm infected with a Trojan Horse!?

Answer»

Hi Mr. & Mrs. HOPE! For about 2 weeks I've noticed major issues with my computer. At first I suspected my Verizon Security Suite was the gateway to these issues and despite removing it, ladies and gents, the damage has been already done!

At start-up "Data Execution Prevention" MS window pops up "To help protect your computer, Windows has closed this program." Name: Windows Update Automatic Updates Publisher: Microsoft Corporation. Then the only option is to close message.

Once I close message a whole slew of MS windows pops up. Let me know if you need this info. In the meantime, I came here and followed all the steps for House Cleaning. I think everything went well.

Except I have AVG running and I keep getting a pop up "Threat detected!" File name: C:\WINDOWS\system32\hsvnrtf.dll Threat name: Virus IDENTIFIED Win32/Cryptor Detected on open. (Whenever I open IE) AVG won't allow me to heal or move this to the vault.

Let me know what should be the next step. Here are my logs: (Oh and THANK YOU! for your ANTICIPATED help!...really thanks!)

Here is AVG Virus Vault prior to the other steps:

"Infection";"Trojan horse Generic13.XKB";"C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP4\A0000018.exe";"";"5/4/2009, 1:25:10 PM"
"Infection";"Virus identified Win32/Cryptor";"C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP4\A0000004.dll";"";"5/4/2009, 1:25:08 PM"
"Infection";"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\hsvnrtf.dll";"";"5/4/2009, 1:10:24 PM"
"Infection";"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\hsvnrtf.dll";"";"5/4/2009, 1:05:13 PM"
"Infection";"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\hsvnrtf.dll";"";"5/4/2009, 12:51:28 PM"
"Warning";"Found Tracking cookie.Tacoda";"C:\Documents and Settings\Lopez\Cookies\[email protected][2].txt";"";"5/4/2009, 12:25:41 PM"
"Warning";"Found Tracking cookie.Realmedia";"C:\Documents and Settings\Lopez\Cookies\[email protected][2].txt";"";"5/4/2009, 12:25:41 PM"
"Warning";"Found Tracking cookie.Atdmt";"C:\Documents and Settings\Lopez\Cookies\[email protected][1].txt";"";"5/4/2009, 12:25:41 PM"
"Infection";"Virus identified Java/ByteVerify";"C:\Documents and Settings\Lopez\Application Data\Sun\Java\Deployment\cache\6.0\22\74018dd6-52ca3251";"";"5/4/2009, 12:23:24 PM"
"Infection";"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\hsvnrtf.dll";"";"5/4/2009, 12:10:04 PM"
"Infection";"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\hsvnrtf.dll";"";"5/4/2009, 11:51:59 AM"
"Infection";"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\hsvnrtf.dll";"";"5/4/2009, 11:16:00 AM"
"Infection";"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\hsvnrtf.dll";"";"5/4/2009, 10:27:43 AM"
"Infection";"Trojan horse Generic13.XKB";"C:\WINDOWS\system32\sdra64.exe";"";"5/2/2009, 10:57:08 PM"
"Warning";"Found Tracking cookie.Zedo";"C:\Documents and Settings\Phoenix\Cookies\[email protected][1].txt";"";"5/2/2009, 10:00:42 PM"
"Warning";"Found Tracking cookie.Tribalfusion";"C:\Documents and Settings\Phoenix\Cookies\[email protected][2].txt";"";"5/2/2009, 10:00:42 PM"
"Warning";"Found Tracking cookie.Webtrendslive";"C:\Documents and Settings\Phoenix\Cookies\[email protected][2].txt";"";"5/2/2009, 10:00:42 PM"
"Warning";"Found Tracking cookie.Revsci";"C:\Documents and Settings\Phoenix\Cookies\[email protected][1].txt";"";"5/2/2009, 10:00:42 PM"
"Warning";"Found Tracking cookie.Questionmarket";"C:\Documents and Settings\Phoenix\Cookies\[email protected][1].txt";"";"5/2/2009, 10:00:41 PM"
"Warning";"Found Tracking cookie.Mediaplex";"C:\Documents and Settings\Phoenix\Cookies\[email protected][2].txt";"";"5/2/2009, 10:00:41 PM"
"Warning";"Found Tracking cookie.Adrevolver";"C:\Documents and Settings\Phoenix\Cookies\[email protected][1].txt";"";"5/2/2009, 10:00:41 PM"
"Warning";"Found Tracking cookie.Webtrends";"C:\Documents and Settings\Phoenix\Cookies\[email protected][2].txt";"";"5/2/2009, 10:00:41 PM"
"Warning";"Found Tracking cookie.Doubleclick";"C:\Documents and Settings\Phoenix\Cookies\[email protected][2].txt";"";"5/2/2009, 10:00:41 PM"
"Warning";"Found Tracking cookie.Atdmt";"C:\Documents and Settings\Phoenix\Cookies\[email protected][2].txt";"";"5/2/2009, 10:00:41 PM"
"Warning";"Found Tracking cookie.Advertising";"C:\Documents and Settings\Phoenix\Cookies\[email protected][2].txt";"";"5/2/2009, 10:00:41 PM"
"Warning";"Found Tracking cookie.Adbrite";"C:\Documents and Settings\Phoenix\Cookies\[email protected][2].txt";"";"5/2/2009, 10:00:41 PM"
"Warning";"Found Tracking cookie.Yieldmanager";"C:\Documents and Settings\Phoenix\Cookies\[email protected][1].txt";"";"5/2/2009, 10:00:40 PM"
"Warning";"Found Tracking cookie.247realmedia";"C:\Documents and Settings\Phoenix\Cookies\[email protected][1].txt";"";"5/2/2009, 10:00:38 PM"
"Infection";"Trojan horse Downloader.Generic8.AGSF";"C:\Documents and Settings\Lopez\Local Settings\Temp\wJQs.exe";"";"5/2/2009, 9:55:37 PM"
"Infection";"Trojan horse Generic13.XKB";"C:\Documents and Settings\Lopez\Local Settings\Temp\futu.exe";"";"5/2/2009, 9:55:31 PM"
"Warning";"Found Tracking cookie.Tribalfusion";"C:\Documents and Settings\Lopez\Cookies\[email protected][1].txt";"";"5/2/2009, 9:54:39 PM"
"Warning";"Found Tracking cookie.Trafficmp";"C:\Documents and Settings\Lopez\Cookies\[email protected][1].txt";"";"5/2/2009, 9:54:39 PM"
"Warning";"Found Tracking cookie.Tacoda";"C:\Documents and Settings\Lopez\Cookies\[email protected][1].txt";"";"5/2/2009, 9:54:39 PM"
"Warning";"Found Tracking cookie.Serving-sys";"C:\Documents and Settings\Lopez\Cookies\[email protected][2].txt";"";"5/2/2009, 9:54:38 PM"
"Warning";"Found Tracking cookie.Revsci";"C:\Documents and Settings\Lopez\Cookies\[email protected][1].txt";"";"5/2/2009, 9:54:38 PM"
"Warning";"Found Tracking cookie.Realmedia";"C:\Documents and Settings\Lopez\Cookies\[email protected][1].txt";"";"5/2/2009, 9:54:38 PM"
"Warning";"Found Tracking cookie.Webtrends";"C:\Documents and Settings\Lopez\Cookies\[email protected][1].txt";"";"5/2/2009, 9:54:38 PM"
"Warning";"Found Tracking cookie.Serving-sys";"C:\Documents and Settings\Lopez\Cookies\[email protected][1].txt";"";"5/2/2009, 9:54:37 PM"
"Warning";"Found Tracking cookie.Atdmt";"C:\Documents and Settings\Lopez\Cookies\[email protected][2].txt";"";"5/2/2009, 9:54:37 PM"
"Warning";"Found Tracking cookie.2o7";"C:\Documents and Settings\Lopez\Application Data\Mozilla\Firefox\Profiles\xmikmln5.default\cookies.txt";"";"5/2/2009, 9:52:57 PM"
"Warning";"Found Tracking cookie.Zedo";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:53 PM"
"Warning";"Found Tracking cookie.Valueclick";"C:\Documents and Settings\Becky\Cookies\[email protected][2].txt";"";"5/2/2009, 9:45:53 PM"
"Warning";"Found Tracking cookie.Trafficmp";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:53 PM"
"Warning";"Found Tracking cookie.Tribalfusion";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:53 PM"
"Warning";"Found Tracking cookie.Tacoda";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:53 PM"
"Warning";"Found Tracking cookie.Webtrendslive";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:53 PM"
"Warning";"Found Tracking cookie.Revsci";"C:\Documents and Settings\Becky\Cookies\[email protected][2].txt";"";"5/2/2009, 9:45:52 PM"
"Warning";"Found Tracking cookie.Questionmarket";"C:\Documents and Settings\Becky\Cookies\[email protected][2].txt";"";"5/2/2009, 9:45:52 PM"
"Warning";"Found Tracking cookie.Pro-market";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:52 PM"
"Warning";"Found Tracking cookie.Overture";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:51 PM"
"Warning";"Found Tracking cookie.Overture";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:51 PM"
"Warning";"Found Tracking cookie.Mediaplex";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:51 PM"
"Warning";"Found Tracking cookie.Adrevolver";"C:\Documents and Settings\Becky\Cookies\[email protected][3].txt";"";"5/2/2009, 9:45:51 PM"
"Warning";"Found Tracking cookie.Hitbox";"C:\Documents and Settings\Becky\Cookies\[email protected][2].txt";"";"5/2/2009, 9:45:51 PM"
"Warning";"Found Tracking cookie.Fastclick";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:50 PM"
"Warning";"Found Tracking cookie.Doubleclick";"C:\Documents and Settings\Becky\Cookies\[email protected][2].txt";"";"5/2/2009, 9:45:50 PM"
"Warning";"Found Tracking cookie.Casalemedia";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:50 PM"
"Warning";"Found Tracking cookie.Burstnet";"C:\Documents and Settings\Becky\Cookies\[email protected][2].txt";"";"5/2/2009, 9:45:50 PM"
"Warning";"Found Tracking cookie.Atdmt";"C:\Documents and Settings\Becky\Cookies\[email protected][2].txt";"";"5/2/2009, 9:45:49 PM"
"Warning";"Found Tracking cookie.Advertising";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:49 PM"
"Warning";"Found Tracking cookie.Adrevolver";"C:\Documents and Settings\Becky\Cookies\[email protected]evolver[2].txt";"";"5/2/2009, 9:45:49 PM"
"Warning";"Found Tracking cookie.Adbrite";"C:\Documents and Settings\Becky\Cookies\[email protected][2].txt";"";"5/2/2009, 9:45:49 PM"
"Warning";"Found Tracking cookie.2o7";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:49 PM"
"Warning";"Found Tracking cookie.Yieldmanager";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:49 PM"
"Warning";"Found Tracking cookie.Zedo";"C:\Documents and Settings\Becky\Application Data\Mozilla\Firefox\Profiles\jaazt64k.default\cookies.txt";"";"5/2/2009, 9:45:34 PM"

End AVG

[attachment deleted by ADMIN]after your pm

you now have sas and malware run them every week

http://www.filehippo.com/download_ccleaner/

go to above and download run every week

and keep them all up to date

avg 8 is not very good if you want to take it out come back

and download avast or AVIRA both free

1387.

Solve : nebiteda.dll and goradoja.dll?

Answer»

Hi. This is kind of STRANGE, but here goes. Whenever I boot up windows I receive the FOLLOWING error:

Quote

RUNDLL
Error loading C:\WINDOWS\system32\nebiteda.dll
Access is denied.

I also get an error for "goradoja.dll". Problem is, the computer freezes soon after this happens. I can still move the mouse and all but no programs respond. Safe Mode WAS working for a little while, but now it just stops at "Mup.sys" when loading.
Closest to a solution I've found: I have two user accounts on XP, one of which I never use. I get the same error when I log in, but for some reason it doesn't freeze unless I try to get rid of the RUNDLL error messages. I scanned for nebiteda.dll and deleted it. Then I WENT to the registry to delete all the keys that reference it, but since that user account doesn't have admin status I can't do anything.

A FRIEND told me I could manually delete files with the Recovery Console, but... for some weird reason the console is way too big for my screen. i try to adjust my monitor, but all I can MAKE out is the right hand side of the screen.

it's a bit strange! please help me out if you know a solutionHave you tried a registry cleaner?

http://majorgeeks.com/Wise_Registry_Cleaner_d5437.html
1388.

Solve : Is it required to enable the antivirus software to run during the startup??

Answer»

Is it required to enable the ANTIVIRUS software to run  during the startup?Your AV software NEEDS to be active at all times.
There are a few exceptions.
Example: To upgrade Windows XP from sp-2 to sp-3 you would foloow this method:
1. DOWNLOAD teh full SP-3 update.
2. Disable the internet
3. Disable the AV
4. Install SP-3

Once the update is finished, you reboot the PC ,  activate the AV and activate the Internet.

Thank you for the INFORMATION.

1389.

Solve : wdmaud. sys (computer virus?)?

Answer»

Your online posting here so it isn't your service.

o Start > Run (Start search in VISTA) then type in: cmd

Click OK (in Vista, while holding CTRL, and SHIFT, press Enter).

At the Command Prompt, type in:

netsh winsock reset catalog

On the KEYBOARD press Enter.

Do that again and type in:

netsh int ip reset reset.log

Press Enter.

Restart the computer.

Note: Resetting the Winsock using netsh winsock reset catalog command in SP2 removes all  the third-party LSPs and restores Winsock to factory default setting. Existing programs that uses their own LSPs need to be reinstalled again. Example: Google Desktop Search.

----------

Go Start > Run (Start search in Vista) and type in: cmd

Click OK (in Vista, while holding CTRL, and SHIFT, press Enter).

In the Command Prompt window type in following commands, and press Enter after each one:

ipconfig /flushdns
ipconfig /registerdns
ipconfig /release
ipconfig /renew


Note the space before the forward slash /

Restart the computer.

Is it connecting now?It isn't, but thanks for all your help!

I'm going to take it to a repair shop on Monday.. since I'm probably doing something wrong. 

Have you tried resetting your router? If you can't find the reset button (hold it in for 10 seconds) then just unplug it for 10 seconds then plug it back in.I have the same file, except it's named wdmaud.drv.

I tried straight deleting it with malwarebytes fiile assassin, then the computer won't start normally and will crash before loading windows. If I MOVE it, then the google searches work normally but then the file comes back after a MINUTE or two. So I'm sure there's another file regenerating it. I somehow revived the computer, but the file keeps coming up.

I ran Malwarebyes and nothing really comes up. Never delete a file unless you are 100% sure you know what it is.

Wdmaud.drv is a WDM Audio driver mapper.
wdmaud.drv is a part of Microsoft® Windows® Operating System.
Manufacturer: Microsoft Corp.
www.microsoft.com

Also PLEASE start a new topic for your computer.

1390.

Solve : Malware Personal Antivirus?

Answer»

I had ADWARE, took laptop in and after $150 it worked and then a message popped up: CRITICAL warning.
I went to remove programs it was there with install, but would not work, it is in my taskbar at the bottom and keeps popping up, with warnings.
Went on line to down load free malware, but after PUTTING in information it scanned, but would not remove until I gave $29.99
I am on disability and cannot afford all of this,
please helpThat is not a real antivirus, it's a scam.

Run this, it's free.

If you already have Malwarebytes be sure to update it before running the SCAN!

Download Malwarebytes' Anti-Malware (MBAM)

Alternate MBAM download link

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra NOTE)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy and Paste the entire report in your next reply.
    .
    Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

    ----------
    1391.

    Solve : is the virus still there??

    Answer»

    Hi,

    I'm on an XP, SP3 machine which I use for work. Running ESET Nod 32 antivirus.

    Symptoms -  Yesterday morning my network stopped working. I could get an ip address just fine, but could not get any routing. I could not even reach my default router 192.168.1.1. Same thing both on wireless and wired network.

    In safe mode with networking, my network worked just fine. ESET reported a few viruses:
    Code: [Select]2009-05-13 09:33:26 Real-time file SYSTEM protection file C:\System Volume Information\_restore{A84ED1A6-CF4C-4F28-AFCA-EFE889754B6D}\RP159\A0142371.dll Win32/TrojanDownloader.FakeAlert.AAX trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\WINDOWS\System32\svchost.exe.
    2009-05-12 23:36:06 Real-time file system protection file C:\WINDOWS\system32\msxml71.dll Win32/TrojanDownloader.FakeAlert.AAX trojan cleaned by deleting (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\WINDOWS\system32\msiexec.exe.
    2009-05-12 22:18:18 Real-time file system protection file C:\WINDOWS\system32\10701.exe Win32/Agent.NXT trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
    2009-05-12 17:22:42 Real-time file system protection file C:\DOCUME~1\stema\LOCALS~1\Temp\3681.exe Win32/TrojanDownloader.FakeAlert.ABV trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to run the file by the application: C:\DOCUME~1\stema\LOCALS~1\Temp\3681.exe.

    Key file here is c:\windows\system32\10701.exe.

    After this I tried disabling SERVICES via msconfig, and found out that if I disable a service called ipfw_helper, then my network starts working fine again. This service points to c:\windows\system32\10701.exe. Funny thing is that that file does not exist any more (I guess ESET removed it). However, if I enabled the service again in msconfig, then my network stopped working again.

    Question is, is the virus still there somewhere? And how do I get rid of the service?

    Log files are attached.

    [attachment DELETED by admin]

    1392.

    Solve : here are the 3 logs i was asked to post by evilfantasy...?

    Answer»

    Hi, my computer is acting weird and is getting worse every day. My homepage toolbar looks different, I dont have forward and backward keys, tabs dont work the same, some words are getting cut off, I have trouble navigating in some SITES, my email switched to Outlook by itself, some sites tell me I dont have Java or FLASH player installed, but I do, etc...I own a 3 year old e-machine T6528 with Widows XP Home. I have the free versions of AVG anti-virus and Comodo firewall and their scans come up clean..... HELP!!! 
     
     
     


    [attachment deleted by ADMIN]

    1393.

    Solve : AVG 8.5 Resident Shield Quarentined two trojans?

    Answer»

    I can't find them, where did they go? 

    Older Gateway HP Pavillion Windows XP Home v 5.1.26
    Service PAck 3
    128 MB RAM
    Windows Explorer 8

    I always follow your 'read me first' thread.

    Problems several:

    Outlook Express auto asked me to Q two trojans, I didnt write them down before I OK'd it.

    Open up an Outlook Express 6 email text and the print function popup automatically appears.

    One trusted persons text email attachments always comes to me in a .eml format.  Only notepad tries to open it up.  (I deleted OpenOffice.org)  If there is a picture in the email you can't see it, it turns it into 0's and ones type.

    I can't use youtube; evertime I open it I get the "You don't have the latest Flash Player".  I've deleted what Adobe I had and tried to reinstall. 

    Malwarebytes does not work anymore.  Won't startup, one of the error msg's: Error Load Data Base-Line # 67253.(0)

    Super Anti-SPyware ran--No defects to report
    MBAM doesn't work anymore.
    HJT Log posted


    Thanks

    Tom

    I FORGOT to mention another problem with AVG, At any given pc start up, the email scanner is turned off. Something is turning it off.  I just opened the overiew in AVG an it says's, " There are no active components".  All the components are missing as if AVG doesn't exist anymore.

    Am I doing somthing wrong?

    [attachment deleted by admin]What's happening when you ATTEMPT to run MBAM? Have you also tried running this from Safe Mode?Thanks for replying CH Admin Guru.  I was WONDERING if I'd done something wrong applying for your expertise--I thought I was being ignored for doing something wrong with my request.  That hasn't yet ever happened before.  Again thanks.

    I was using the HJT Process Tool when either it's time to go to work or the machine turned into a snail.

    As for your questions (2):

    1.  I still get the same error msg in my first thread attempting to bring up MBAM; "Error Loading Database. Line#62567. (0)."

    2.  For some reason I cannot successfully restart my PC in safe mode.  It just ignores my F8 tapping, no sounds I just slowly eventually restart.

    Additional symptoms of PC activity.  Running real slow during start up and after start for three days now.  I finally got back on line after shutting down 3x times trying safe mode and things are working (as for this moment) somewhat smoothly.

    Are these signs of pending disk and even RAM failure.

    Did anything look suspect in my HJT log, you didn't mention anything yet?

    Thanks again,

    Tom  Your HijackThis log looked fine from what I can see. I also tried searching for the error you are getting with MBAM and couldn't come up with anything so not exactly sure what's causing that error.

    This could potentially be a disk or RAM error. However, based off your description of your issue I'd tend to believe that it's more likely a software issue. If you still are unable to get into Windows Safe Mode you may just want to erase the hard disk DRIVE and re-install Windows with the CD that came with your computer.

    1394.

    Solve : There is porn sites in my temp.files and history!?

    Answer»

    Quote from: squall_01 on May 05, 2009, 06:36:35 PM

    thats good but I ment that alot more depthful.  But USUALLY you get this stuff when your on something your not supposed to be.  But ad's can have them not sure so much anymore.

    Was that DIRECTED to me? Yeah i dont know, might been because we have watched "normal" movies online, and had to download like zango, divx etc.. to view them. Could be that he has looked at some porn site, but i dont honestly want to believe, that he has looked at that many sites while im at work in one day... Or the kind of porn there was on my temporary internet files.

    We'll see, after i get this problem solved and off my computer, i might just install a keylogger or something, to see if he is lying. 

    Thanks for the help, i look forward to hearing more  Quote from: squall_01 on May 06, 2009, 04:08:56 AM
    I ment how you get stuff.  I was TOLD that any ad can contain stuff.  Ment like once its there its hard to remove an requires alot of cleaning.

    Oh yeah, sounds possible. We get a lot of pop ups, when no one is on the internet. But this porn only shows up in the temp.files, and kanoodle links sometimes in the BROWSER history.

    Most of the sites also have the same ending, like trannysmile.com, teensmile, asiansmile.. etc.. etc... Its driving me mad.  All considering most maleware scanners would pick that up then.  The BEST thing would be to confront him.  If you get what I mean??? Quote from: squall_01 on May 06, 2009, 04:38:03 AM
    All considering most maleware scanners would pick that up then.  The best thing would be to confront him.  If you get what I mean???

    I have already, many times... He denies it every time & blames it on the virus..thats not what I ment use a bit of charm.  Jesus Squall, this is a malware topic. I told you to stop.

    Malware Specialists look for topics with least number of posts first. You just bumped Mimmi to the bottom of the list.

    Mimmi, I suggest starting a new topic with a brief explanation of what is going on (virus problem). Don't forget to include the logs. Quote from: Carbon Dudeoxide on May 06, 2009, 05:07:26 AM
    Jesus Squall, this is a malware topic. I told you to stop.

    Malware Specialists look for topics with least number of posts first. You just bumped Mimmi to the bottom of the list.

    Mimmi, I suggest starting a new topic with a brief explanation of what is going on (virus problem). Don't forget to include the logs.

    Oh i didnt get what he ment at first, im not a native english speaker!  But that was not nice.

    Ok, i will start a new one. Thanks.Ok. I'll close this one then. Quote from: Carbon Dudeoxide on May 06, 2009, 05:07:26 AM
    Malware Specialists look for topics with least number of posts first. You just bumped Mimmi to the bottom of the list.

    Actually, we typically look for the oldest topics first, but you get the general idea.  I'm sorry to see that Squall is still here causing problems...
    1395.

    Solve : virus won't let me access my computer!?

    Answer»

    nope, sorry....just tried. i can't get online....it says my router card is not plugged in...which it is...

    what a mess...sorry.

    Note: In Safe Mode, using Task Manager, I was able to find out the name of the bug that did this to me. Opening Avira thru the Task Manager, I saw this:

    "Virus or unwanted program 'TR/Crypt.FKM.Gen[trojan]'
    detected in file 'C:\\WINDOWS\system32\uiakbacq.old.
    Action performed: Move file to quarantine"

    thnxTried the Avira Rescue System. HOWEVER, CD did not work in affected computer. Booted with CD in, and the entire system froze. Could not even log into Windows. When CD drive was opened, the computer started again, I was able to log onto Windows as before, but nothing had changed, still no desktop.



    I have written Avira to see if there is a way to use the Rescue System with a flashdrive instead of a CD. I am awaiting their response.

    As always, any suggestions you might have are welcome.

    thnx   You might be able to use it from a flash drive but since you are not able to use the computer...... it probably won't work. Plus if it won't boot from the CD then I'm sure it wouldn't boot from a Flash Drive either.

    Since you can open Avira through Task manager can you also run it?

    I'm wondering if this is even a virus to blame.

    Hello again.

    I finally heard from Avira, and they just gave me the instructions on how to burn their disc. Not the info I needed...giving up on that, as you suggested it wouldn't work anyway.

    However, digging around in Task Manager today I discovered how to access nearly all my files, and even get online. That done, I got the updated SAS as you suggested and ran another scan. I ran another HijackThis scan afterwards as well. Here are the logs for the new scans:

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 05/06/2009 at 01:29 PM

    Application Version : 4.26.1002

    Core Rules Database Version : 3879
    Trace Rules Database Version: 1827

    Scan type       : Complete Scan
    Total Scan Time : 03:06:38

    Memory items scanned      : 365
    Memory threats detected   : 0
    Registry items scanned    : 5744
    Registry threats detected : 1
    File items scanned        : 53283
    File threats detected     : 5

    Adware.Tracking Cookie
       C:\Documents and Settings\user\Cookies\[email protected][1].txt
       C:\Documents and Settings\user\Cookies\[email protected][1].txt
       C:\Documents and Settings\user\Cookies\[email protected][2].txt
       C:\Documents and Settings\user\Cookies\[email protected][1].txt
       C:\Documents and Settings\user\Cookies\[email protected][2].txt

    Trojan.SVCHost/Fake
       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe#Debugger [ "c:\windows\system32\uiakbacq.old" ]

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16.39.47, on 06/05/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Programmi\Avira\AntiVir Desktop\avguard.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\WgaTray.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\Microsoft Office\OFFICE11\WINWORD.EXE
    C:\WINDOWS\msagent\AgentSvr.exe
    C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.alltheweb.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre6\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre6\bin\jp2iexp.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre6\bin\jp2iexp.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programmi\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

    --
    End of file - 4562 bytes


    thx...any of your thoughts are welcome at this point How is the computer running now?

    If you already have Malwarebytes be sure to update it before running the scan!

    Download Malwarebytes' Anti-Malware (MBAM)

    Alternate MBAM download link

    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to the following:
      • Update Malwarebytes' Anti-Malware
      • Launch Malwarebytes' Anti-Malware
      • Then click Finish.
      • If an update is found, it will download and install the latest version.
      • Once the program has loaded, select Perform quick scan, then click Scan.
      • When the scan is complete, click OK, then Show RESULTS to view the results.
      • Be sure that everything is checked, and click Remove Selected.
      • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
      • The log is automatically saved by MBAM and can be viewed by clicking the Logs TAB in MBAM.
      • Copy and Paste the entire report in your next reply.
      .
      Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.Hi

      My apologies for the delay in getting back to you. After all this...I believe your thought on this not being a virus was correct. After looking around on the internet, I saw other people had the same kind of problem as I have, after deleting AdAware, which is something I did. I didn't mention it before, because I completely forgot actually.

      At any rate, I have surrendered. My computer has had nothing but problems since the day I bought it. It was used, cheap, and as I was to assume with time, most LIKELY stolen. The copy of Windows was not registered, so I could never get help from MS, couldn't download things I needed and so on.

      So, the time has come. I'm just wiping the thing clean, and starting over with a new install of Windows. That should just about take care of everything I hope.

      Thank you so much to everyone that helped me through this. I truly appreciate CH being here...you guys have been a great help to me time and again. As well as being teachers! If any good has come from two years of dinkin' around with this laptop from *censored*...I certainly have learned A LOT!!! Actually, I'm looking into some IT classes now...I actually love learning all this stuff!

      THANKS again to all   Thanks for letting me know.
      1396.

      Solve : Re: HiJack Log?

      Answer»

      It is very simple to solve this problem.
      If you are REFERRING to the Legacy reg keys, you need to change the permissions PRIOR to deleting the keys. This holds true for any registry KEY that you can not delete, but of COURSE, use caution and back up the registry before clicking away.

      Right click on the reg key you want to delete > Open "Permissions" > Click "Users" > Check "Full Control" > OK > proceed to delete key.
      Symantec registry keys can delete in this manner.
      Good luck to u!
       
      # For korean, Read the following comment.
      시맨텍사의 제품의 경우 언인스톨을 시켜도 레지스트리에 찌꺼기 키값들이 남아있게 됩니다.
      남아있는 키값들은 시맨텍사의 평가판을 재설치할시 평가판 사용기간이 지났다는 메시지와 함께 라이센스를 구입하라고 표시하는 근거자료로 사용됩니다. 
      따라서 삭제할려는 해당 키값에서 오른쪽클릭후, 레지스트리의 사용권한을 먼저 변경해주어야 합니다.
      사용자의 사용권한을 모든권한으로 변경해준다음 레지스트리 키값삭제를 시도하면 문제없이 지워집니다.
      아울러 노턴 제품의 평가판의 기간도 다시 리셋되므로 다시 설치하여 사용할수가 있게 됩니다.
       
      Note: USE WITH CAUTION!
      This was ADDED to a post which is a year old so I removed it.

      Also we like to leave registry fixes out of the forums unless extra instructions like backing it up first are given.

      Quote

      Note: USE WITH CAUTION!

      That's not very reassuring!
      1397.

      Solve : Windows update redirects to Google search page?

      Answer»

      Malwarebytes worked this time. Here are my logs.

      [attachment deleted by admin]Looks good. How is the computer running now?

      • Click START then RUN
      • Now type Combofix /u in the runbox
      • Make sure there's a space between Combofix and /u
      • Then hit Enter.
      .
      .
      The above procedure will:
      • Delete: ComboFix and its ASSOCIATED files and folders.
      • Reset the clock settings.
      • Hide file extensions, if required.
      • Hide System/Hidden files, if required.
      • Set a new, clean Restore Point.
      .
      ----------

      Use the Secunia Software Inspector to check for out of date software.
      • Click Start Now
      • Check the box next to Enable thorough system inspection.
      • Click Start
      • Allow the scan to finish and scroll down to see if any updates are needed.
      • Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and GET all critical updates.

      ----------

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and UNRELIABLE shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop CERTAIN COOKIES from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Everything seems to be working fine now. Thank You very much for your help!Your welcome.

      Safe surfing...
      1398.

      Solve : aviar scan could someone have a look please?

      Answer» COULD someone have a look at the scan the only problem i can see is below in red , harry


      its ok evil , i put this part below in it will do


      Starting the file scan:

      Begin scan in 'C:\' <CM99-G4>
      C:\hiberfil.sys
          [WARNING]   The file could not be opened!
          [NOTE]      This file is a Windows system file.
          [NOTE]      This file cannot be opened for scanning.
      C:\pagefile.sys
          [WARNING]   The file could not be opened!
          [NOTE]      This file is a Windows system file.
          [NOTE]      This file cannot be opened for scanning.C:\Documents and Settings\harold mullan\DoctorWeb\Quarantine\UninstallHelper.exe
          [DETECTION] Contains recognition pattern of the DR/Tool.PsKill.1101.46 dropper

      Beginning disinfection:
      C:\Documents and Settings\harold mullan\DoctorWeb\Quarantine\UninstallHelper.exe
          [DETECTION] Contains recognition pattern of the DR/Tool.PsKill.1101.46 dropper
          [NOTE]      The file was moved to '4a742544.qua'!


      [attachment deleted by admin]I don't KNOW how to read Avira logs. It looks like WHATEVER was found has been taken care of though.ok evil , its just i thought that avira wanted to open the FILES or would that not be any problem for it to do that

      and what id , dr,tool / pskillLook at the file path.

      C:\Documents and Settings\harold mullan\DoctorWeb\Quarantine\UninstallHelper.exe

      That is in DoctorWebs Quarantine folder...ok now that you show me and i read it i understand , thank you as usual , harry
      1399.

      Solve : Indonesaian text at top of web browser & intermitten connection to website?

      Answer»

      have above problem and done the TrendMicro HijackThis scan  here is the scanned log file.
      Can anyone help to anlayse what has gone wrong ? thanks.

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:39:42 AM, on 2/5/2009
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      c:\PROGRA~1\mcafee.com\agent\mcagent.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\Windows\RtHDVCpl.exe
      C:\Acer\Empowering Technology\SysMonitor.exe
      C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
      C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
      C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
      C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\WordWeb\wweb32.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
      C:\Windows\system32\conime.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wahai anak2 Triakti... Belajarlah yang rajin. Jangan ngebokep mulu...
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
      R3 - URLSearchHook: (no name) - ~EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      O1 - Hosts: ::1 localhost
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
      O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
      O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
      O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [ALaunch] C:\Acer\ALaunch\AlaunchClient.exe
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
      O4 - HKLM\..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
      O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
      O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
      O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe"
      O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
      O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
      O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
      O8 - Extra context menu item: &WordWeb... - res://C:\Windows\wweb32.dll/lookup.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
      O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-SG/a-UNO1/GAME_UNO1.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
      O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
      O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
      O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
      O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
      O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
      O23 - Service: Google Update Service (gupdate1c9876777235ff) (gupdate1c9876777235ff) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
      O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - (no file)
      O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
      O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
      O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
      O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
      O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
      O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
      O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
      O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
      O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

      --
      End of file - 11013 bytes
      Go to Add or Remove Programs and uninstall:

      • Cyberdefender
      • Live Update  - Symantec Corporation
      .
      ----------

      Download the Norton Removal Tool (SymNRT) to your Desktop.

      Once downloaded please close ALL open browsers, also save any work because this may require a restart.
      • Go to your desktop and double click on the removal tool and then click SETUP.
      • Once open Click Next
      • Accept the license agreement and click Next
      • Type in the letters/numbers that you see into the text box then click Next.
      • Then click Next and the tool will start running.
      • Once finished restart the PC.
      • Delete Nortonremoval tool from your Desktop.
      .
      ----------

      Open HijackThis and select Do a system scan only.

      Place a check mark next to the following entries: (if there)

      • R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
      • R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      • R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      • R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wahai anak2 Triakti... Belajarlah yang rajin. Jangan ngebokep mulu...
      • R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      • R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
      • R3 - URLSearchHook: (no name) - ~EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      • O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      .
      Important: Close all windows except for HijackThis and then click Fix checked.

      Exit HijackThis.

      ----------

      Download Malwarebytes' Anti-Malware (MBAM)

      Alternate MBAM download link

      • Double-click mbam-setup.exe and follow the prompts to install the program.
      • At the end, be sure a checkmark is placed next to the following:
        • Update Malwarebytes' Anti-Malware
        • Launch Malwarebytes' Anti-Malware
        • Then click Finish.
        • If an update is found, it will download and install the latest version.
        • Once the program has loaded, select Perform quick scan, then click Scan.
        • When the scan is complete, click OK, then Show Results to view the results.
        • Be sure that everything is checked, and click Remove Selected.
        • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
        • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
        • Copy and Paste the entire report in your next reply.
        .
        Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.Thanks for your advice :after follow your instruction, the "Indonesian text" disappeared. 

        But I still facing problem in using "Internet Explorer " to get into any Website.   
        Most of the time, I receive statement "Internet Explorer cannot display the Webpage ". Have to logout and log in Explorer many times. By chance, have to repaet several times before success.
        I though it was due to  " Indonesian text visrus " . Now the text is gone, Internet Explorer log in problem still there . Please advice solution . Thanks in advance for your help .


        nb. As requested , here is the logfile after "Anti-Malware" scanned.


        Malwarebytes' Anti-Malware 1.36
        Database version: 2069
        Windows 6.0.6001 Service Pack 1

        3/5/2009 7:44:32 PM
        mbam-log-2009-05-03 (19-44-32).txt

        Scan type: Quick Scan
        Objects scanned: 68595
        Time elapsed: 4 minute(s), 43 second(s)

        Memory Processes Infected: 0
        Memory Modules Infected: 0
        Registry Keys Infected: 2
        Registry Values Infected: 0
        Registry Data Items Infected: 0
        Folders Infected: 5
        Files Infected: 220

        Memory Processes Infected:
        (No malicious items detected)

        Memory Modules Infected:
        (No malicious items detected)

        Registry Keys Infected:
        HKEY_LOCAL_MACHINE\SOFTWARE\RegTool (Rogue.RegTool) -&GT; Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.

        Registry Values Infected:
        (No malicious items detected)

        Registry Data Items Infected:
        (No malicious items detected)

        Folders Infected:
        C:\Users\Acer\AppData\Roaming\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\Logs (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010 (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\Results (Rogue.RegTool) -> Quarantined and deleted successfully.

        Files Infected:
        C:\Users\Acer\AppData\Roaming\RegTool\Logs\2009-04-28 19-29-120.log (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\filelist.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-0.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-1.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-10.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-100.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-101.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-102.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-103.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-104.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-105.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-106.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-107.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-108.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-109.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-11.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-110.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-111.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-112.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-113.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-114.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-115.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-116.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-117.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-118.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-119.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-12.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-120.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-121.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-122.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-123.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-124.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-125.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-126.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-127.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-128.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-129.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-13.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-130.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-131.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-132.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-133.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-134.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-135.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-136.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-137.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-138.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-139.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-14.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-140.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-141.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-142.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-143.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-144.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-145.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-146.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-147.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-148.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-149.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-15.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-150.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-151.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-152.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-153.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-154.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-155.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-156.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-157.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-158.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-159.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-16.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-160.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-161.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-162.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-163.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-164.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-165.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-166.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-167.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-168.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-169.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-17.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-170.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-171.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-172.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-173.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-174.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-175.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-176.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-177.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-178.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-179.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-18.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-180.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-181.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-182.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-183.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-184.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-185.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-186.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-187.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-188.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-189.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-19.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-190.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-191.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-192.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-193.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-194.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-195.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-196.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-197.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-198.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-199.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-2.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-20.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-200.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-201.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-202.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-203.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-204.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-205.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-206.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-207.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-208.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-209.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-21.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-210.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-211.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-212.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-22.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-23.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-24.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-25.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-26.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-27.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-28.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-29.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-3.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-30.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-31.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-32.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-33.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-34.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-35.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-36.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-37.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-38.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-39.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-4.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-40.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-41.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-42.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-43.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-44.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-45.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-46.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-47.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-48.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-49.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-5.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-50.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-51.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-52.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-53.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-54.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-55.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-56.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-57.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-58.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-59.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-6.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-60.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-61.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-62.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-63.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-64.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-65.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-66.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-67.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-68.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-69.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-7.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-70.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-71.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-72.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-73.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-74.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-75.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-76.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-77.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-78.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-79.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-8.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-80.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-81.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-82.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-83.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-84.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-85.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-86.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-87.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-88.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-89.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-9.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-90.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-91.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-92.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-93.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-94.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-95.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-96.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-97.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-98.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\QuarantineW\2009-04-28 19-32-010\regb-99.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\Results\Evidence.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\Results\Junk.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\Results\Registry.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Users\Acer\AppData\Roaming\RegTool\Results\Update.db (Rogue.RegTool) -> Quarantined and deleted successfully.
        C:\Windows\Tasks\RegTool Scan.job (Rogue.RegTool) -> Quarantined and deleted successfully.
        Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

        Link #1
        Link #2

        **Note:  It is important that it is saved directly to your Desktop

        Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

        Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
         
        Double click combofix.exe & follow the prompts.
        When finished ComboFix will produce a log for you.
        Post the ComboFix log in your next reply.

        Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

        Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

        If you have problems with ComboFix usage, see How to use ComboFix
        Follow your instruction and here is the ComboFix log, please help to analyse . Thanks .

        --------------------------------------------------------------------------------------------------------------------

        ComboFix 09-05-03.1 - Acer 04/05/2009 23:09.1 - NTFSx86
        Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.1.1033.18.2047.1290 [GMT 8:00]
        Running from: c:\users\Acer\Desktop\ComboFix.exe
        .

        (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
        .

        c:\windows\system32\x64
        D:\Autorun.inf

        .
        (((((((((((((((((((((((((   Files Created from 2009-04-04 to 2009-05-04  )))))))))))))))))))))))))))))))
        .

        2009-05-03 10:34 . 2009-05-03 10:34   --------   d-----w   c:\programdata\NortonInstaller
        2009-05-03 10:34 . 2009-05-03 10:34   --------   d-----w   c:\users\All Users\NortonInstaller
        2009-05-02 03:37 . 2009-05-02 03:37   --------   d-----w   c:\program files\Trend Micro
        2009-04-27 16:35 . 2009-04-27 16:35   --------   d-----w   c:\program files\RegCure
        2009-04-27 14:21 . 2009-04-27 14:21   --------   d-----w   c:\users\Acer\AppData\Roaming\Malwarebytes
        2009-04-27 14:21 . 2009-04-06 07:32   15504   ----a-w   c:\windows\system32\drivers\mbam.sys
        2009-04-27 14:21 . 2009-04-06 07:32   38496   ----a-w   c:\windows\system32\drivers\mbamswissarmy.sys
        2009-04-27 14:21 . 2009-04-27 14:21   --------   d-----w   c:\programdata\Malwarebytes
        2009-04-27 14:21 . 2009-04-27 14:21   --------   d-----w   c:\users\All Users\Malwarebytes
        2009-04-27 14:21 . 2009-05-03 11:38   --------   d-----w   c:\program files\Malwarebytes' Anti-Malware
        2009-04-25 09:17 . 2009-04-25 09:17   --------   d-----w   c:\programdata\SiteAdvisor
        2009-04-25 09:17 . 2009-04-25 09:17   --------   d-----w   c:\users\All Users\SiteAdvisor
        2009-04-25 09:17 . 2009-04-25 09:22   --------   d-----w   c:\program files\SiteAdvisor
        2009-04-25 09:14 . 2009-03-25 03:06   40552   ----a-w   c:\windows\system32\drivers\mfesmfk.sys
        2009-04-25 09:14 . 2009-03-25 03:06   35272   ----a-w   c:\windows\system32\drivers\mfebopk.sys
        2009-04-25 09:14 . 2009-03-25 03:06   79880   ----a-w   c:\windows\system32\drivers\mfeavfk.sys
        2009-04-25 09:14 . 2008-10-23 05:08   130424   ----a-w   c:\windows\system32\drivers\Mpfp.sys
        2009-04-25 09:14 . 2009-04-25 09:14   --------   d-----w   c:\program files\Common Files\McAfee
        2009-04-25 09:14 . 2009-04-25 09:14   --------   d-----w   c:\program files\McAfee.com
        2009-04-25 09:14 . 2009-04-27 14:18   --------   d-----w   c:\program files\McAfee
        2009-04-25 09:13 . 2009-03-25 03:05   34216   ----a-w   c:\windows\system32\drivers\mferkdk.sys
        2009-04-25 09:00 . 2009-04-25 09:18   --------   d-----w   c:\programdata\McAfee
        2009-04-25 09:00 . 2009-04-25 09:18   --------   d-----w   c:\users\All Users\McAfee
        2009-04-20 12:06 . 2009-04-25 08:39   81984   ----a-w   c:\windows\system32\bdod.bin
        2009-04-20 12:02 . 2009-04-20 12:02   --------   d-----w   c:\program files\BitDefender
        2009-04-20 11:54 . 2009-04-20 15:39   --------   d-----w   c:\program files\Common Files\BitDefender
        2009-04-19 00:58 . 2009-04-19 00:58   --------   d-----w   C:\Sounds
        2009-04-19 00:53 . 2008-09-03 22:27   24832   ----a-w   c:\windows\system32\drivers\lgusbmodem.sys
        2009-04-19 00:53 . 2008-09-03 22:28   19968   ----a-w   c:\windows\system32\drivers\lgusbdiag.sys
        2009-04-19 00:53 . 2008-09-03 22:27   13056   ----a-w   c:\windows\system32\drivers\lgusbbus.sys
        2009-04-19 00:53 . 2009-04-19 00:53   --------   d-----w   c:\program files\LG Electronics
        2009-04-19 00:51 . 2007-11-08 08:26   1164728   ----a-w   c:\windows\system32\NMSDVDXU.dll
        2009-04-19 00:51 . 2009-04-19 09:59   --------   d-----w   c:\users\Acer\AppData\Roaming\LG Electronics
        2009-04-19 00:51 . 2009-04-19 10:00   --------   d-----w   c:\program files\LG PC Suite II

        .
        ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2009-05-04 14:59 . 2009-03-24 11:17   420   ---ha-w   c:\windows\Tasks\User_Feed_Synchronization-{FCED9B55-8DFE-46EE-B608-B7626366AB7D}.job
        2009-05-04 14:43 . 2008-12-20 14:28   868   ----a-w   c:\windows\Tasks\Google Software Updater.job
        2009-05-04 14:38 . 2009-02-05 07:54   882   ----a-w   c:\windows\Tasks\GoogleUpdateTaskMachine.job
        2009-05-04 14:38 . 2009-04-28 11:29   352   ----a-w   c:\windows\Tasks\RegTool Startup.job
        2009-05-04 14:38 . 2009-04-27 16:35   436   ----a-w   c:\windows\Tasks\RegCure Program Check.job
        2009-05-04 14:38 . 2006-11-02 13:01   6   ---ha-w   c:\windows\Tasks\SA.DAT
        2009-05-03 10:35 . 2007-07-17 06:57   --------   d-----w   c:\program files\Common Files\Symantec Shared
        2009-04-28 10:52 . 2009-04-27 16:35   370   ----a-w   c:\windows\Tasks\RegCure.job
        2009-04-26 04:06 . 2009-04-25 09:14   338   ----a-w   c:\windows\Tasks\McDefragTask.job
        2009-04-26 04:06 . 2009-04-25 09:14   330   ----a-w   c:\windows\Tasks\McQcTask.job
        2009-04-19 00:56 . 2006-11-02 10:25   86016   ----a-w   c:\windows\inf\infstor.dat
        2009-04-19 00:56 . 2006-11-02 10:25   51200   ----a-w   c:\windows\inf\infpub.dat
        2009-04-19 00:56 . 2006-11-02 10:25   143360   ----a-w   c:\windows\inf\infstrng.dat
        2009-04-19 00:53 . 2007-07-17 06:18   --------   d--h--w   c:\program files\InstallShield Installation Information
        2009-04-19 00:50 . 2008-01-21 08:04   7376   ----a-w   c:\users\Acer\AppData\Local\d3d9caps.dat
        2009-04-17 12:42 . 2006-11-02 11:18   --------   d-----w   c:\program files\Windows Mail
        2009-04-01 13:02 . 2008-12-20 14:28   --------   d-----w   c:\program files\Google
        2009-03-25 03:06 . 2009-03-25 03:06   214024   ----a-w   c:\windows\system32\drivers\mfehidk.sys
        2009-03-17 03:38 . 2009-04-17 11:15   40960   ----a-w   c:\windows\AppPatch\apihex86.dll
        2009-03-17 03:38 . 2009-04-17 11:15   13824   ----a-w   c:\windows\system32\apilogen.dll
        2009-03-17 03:38 . 2009-04-17 11:15   24064   ----a-w   c:\windows\system32\amxread.dll
        2009-03-08 11:34 . 2009-03-24 11:06   914944   ----a-w   c:\windows\system32\wininet.dll
        2009-03-08 11:34 . 2009-03-24 11:06   43008   ----a-w   c:\windows\system32\licmgr10.dll
        2009-03-08 11:33 . 2009-03-24 11:06   18944   ----a-w   c:\windows\system32\corpol.dll
        2009-03-08 11:33 . 2009-03-24 11:06   109056   ----a-w   c:\windows\system32\iesysprep.dll
        2009-03-08 11:33 . 2009-03-24 11:06   109568   ----a-w   c:\windows\system32\PDMSetup.exe
        2009-03-08 11:33 . 2009-03-24 11:06   132608   ----a-w   c:\windows\system32\ieUnatt.exe
        2009-03-08 11:33 . 2009-03-24 11:06   107520   ----a-w   c:\windows\system32\RegisterIEPKEYs.exe
        2009-03-08 11:33 . 2009-03-24 11:06   107008   ----a-w   c:\windows\system32\SetIEInstalledDate.exe
        2009-03-08 11:33 . 2009-03-24 11:06   103936   ----a-w   c:\windows\system32\SetDepNx.exe
        2009-03-08 11:33 . 2009-03-24 11:06   420352   ----a-w   c:\windows\system32\vbscript.dll
        2009-03-08 11:32 . 2009-03-24 11:06   72704   ----a-w   c:\windows\system32\admparse.dll
        2009-03-08 11:32 . 2009-03-24 11:06   71680   ----a-w   c:\windows\system32\iesetup.dll
        2009-03-08 11:32 . 2009-03-24 11:06   66560   ----a-w   c:\windows\system32\wextract.exe
        2009-03-08 11:32 . 2009-03-24 11:06   169472   ----a-w   c:\windows\system32\iexpress.exe
        2009-03-08 11:31 . 2009-03-24 11:06   34816   ----a-w   c:\windows\system32\imgutil.dll
        2009-03-08 11:31 . 2009-03-24 11:06   48128   ----a-w   c:\windows\system32\mshtmler.dll
        2009-03-08 11:31 . 2009-03-24 11:06   45568   ----a-w   c:\windows\system32\mshta.exe
        2009-03-08 11:22 . 2009-03-24 11:06   156160   ----a-w   c:\windows\system32\msls31.dll
        2009-03-08 06:33 . 2009-03-08 06:33   --------   d-----w   c:\program files\Rationale 2
        2009-03-03 04:46 . 2009-04-17 11:15   3599328   ----a-w   c:\windows\system32\ntkrnlpa.exe
        2009-03-03 04:46 . 2009-04-17 11:15   3547632   ----a-w   c:\windows\system32\ntoskrnl.exe
        2009-03-03 04:39 . 2009-04-17 11:15   183296   ----a-w   c:\windows\system32\sdohlp.dll
        2009-03-03 04:39 . 2009-04-17 11:15   551424   ----a-w   c:\windows\system32\rpcss.dll
        2009-03-03 04:39 . 2009-04-17 11:15   26112   ----a-w   c:\windows\system32\printfilterpipelineprxy.dll
        2009-03-03 04:37 . 2009-04-17 11:15   98304   ----a-w   c:\windows\system32\iasrecst.dll
        2009-03-03 04:37 . 2009-04-17 11:15   54784   ----a-w   c:\windows\system32\iasads.dll
        2009-03-03 04:37 . 2009-04-17 11:15   44032   ----a-w   c:\windows\system32\iasdatastore.dll
        2009-03-03 03:04 . 2009-04-17 11:15   666624   ----a-w   c:\windows\system32\printfilterpipelinesvc.exe
        2009-03-03 02:38 . 2009-04-17 11:15   17408   ----a-w   c:\windows\system32\iashost.exe
        2009-02-13 08:49 . 2009-04-17 11:15   72704   ----a-w   c:\windows\system32\secur32.dll
        2009-02-13 08:49 . 2009-04-17 11:15   1255936   ----a-w   c:\windows\system32\lsasrv.dll
        2009-02-09 03:10 . 2009-03-11 10:12   2033152   ----a-w   c:\windows\system32\win32k.sys
        2008-08-31 14:39 . 2006-11-02 12:50   174   --sha-w   c:\program files\desktop.ini
        .

        (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* empty entries & legit default entries are not shown
        REGEDIT4

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
        "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
        "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-02 393216]
        "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "ALaunch"="c:\acer\ALaunch\AlaunchClient.exe" [2007-01-26 540672]
        "Acer Empowering Technology Monitor"="c:\acer\Empowering Technology\SysMonitor.exe" [2007-06-15 326440]
        "PCMMediaSharing"="c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2007-06-22 204908]
        "SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-02-02 630784]
        "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
        "PlayMovie"="c:\program files\Acer Arcade Live\Acer PlayMovie\PMVService.exe" [2007-07-14 178280]
        "Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-05-22 151552]
        "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-09 144784]
        "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
        "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
        "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696]
        "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
        "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-03-25 645328]
        "McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-01-09 1176808]
        "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-06-20 4493312]

        c:\users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
        OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
        WordWeb.lnk - c:\program files\WordWeb\wweb32.exe [2008-4-22 42168]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
        "EnableUIADesktopToggle"= 0 (0x0)

        HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
        "wave2"= serwvdrv.dll

        [HKEY_LOCAL_MACHINE\software\microsoft\security center]
        "UacDisableNotify"=dword:00000001
        "InternetSettingsDisableNotify"=dword:00000001
        "AutoUpdateDisableNotify"=dword:00000001

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
        "DisableMonitoring"=dword:00000001

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
        "DisableMonitoring"=dword:00000001

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
        "DisableMonitoring"=dword:00000001

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
        "EnableFirewall"= 0 (0x0)
        "DefaultOutboundAction"= 0 (0x0)
        "DefaultInboundAction"= 1 (0x1)
        "DisableUnicastResponsesToMulticastBroad cast"= 0 (0x0)
        "DoNotAllowExceptions"= 0 (0x0)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
        "{CC798B78-DE13-4976-9DBA-0015A8CE56F8}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
        "{81030BAF-357C-40FB-8793-B99ADE4212A8}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
        "{4C0E0174-247F-4069-9F52-9AD19DC71D83}"= c:\program files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
        "{560429FD-BAD7-4E9A-857F-AA8C893A477F}"= c:\program files\Acer Arcade Live\Acer DV Magician\Acer DV Magician.exe:Acer DV Magician
        "{ED9E9E19-C630-464A-87A6-C20269418FC1}"= c:\program files\Acer Arcade Live\Acer DVDivine\Acer DVDivine.exe:Acer DVDivine
        "{492EC220-FB41-4472-8B20-E400B5B81034}"= c:\program files\Acer Arcade Live\Acer HomeMedia\Acer HomeMedia.exe:Acer HomeMedia
        "{63C2B5ED-23AB-4CB2-AC71-1114E8E91419}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Acer HomeMedia Connect.exe:Acer HomeMedia Connect
        "{9C8A4F83-9400-4816-BA61-125CC31F09BB}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:Acer HomeMedia Connect Service
        "{D174244A-0FBB-4C36-8948-020059CF029E}"= c:\program files\Acer Arcade Live\Acer SlideShow DVD\Acer SlideShow DVD.exe:Acer SlideShow DVD
        "{7DDAC852-04CD-4EFE-8DE0-1361BE28FB87}"= c:\program files\Acer Arcade Live\Acer VideoMagician\Acer VideoMagician.exe:Acer VideoMagician
        "{A737C415-9154-4556-87F7-B5F30470A416}"= c:\program files\Acer Arcade Live\Acer PlayMovie\PlayMovie.exe:Acer Play Movie
        "{5D969526-27C1-40B7-9F52-8278DA307BA0}"= c:\program files\Acer Arcade Live\Acer PlayMovie\PMVService.exe:Acer Play Movie Resident Program
        "{3C4ED021-08D7-40ED-B0AD-E27D445943AF}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
        "{7675F91E-FBB7-4E0C-9628-6432ED104CA4}"= UDP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:Sony Ericsson Media Manager 1.0
        "{50E32A91-4CD3-4573-90F9-B49D58FF0C3A}"= TCP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:Sony Ericsson Media Manager 1.0
        "{D6C8BEFB-D7A5-43B3-AEC2-F1A90A04DF7D}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
        "{89879D53-A003-402C-835D-7BFE787E063A}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
        "{9C6250F4-9A47-482F-89D3-7CD7534C3986}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
        "{E8376ABB-C3B1-4964-95E9-E750169D22B5}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
        "{2B15D7A0-01B8-4442-B9F8-24F7164354DE}"= UDP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
        "{38BE90AF-D3C8-4C9E-94E6-E0A458035CB9}"= TCP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
        "{6B4DD4C0-2194-43F9-A598-60A6148EFAA6}"= Profile=Private|Profile=Public|c:\program files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
        "EnableFirewall"= 0 (0x0)
        "DefaultOutboundAction"= 0 (0x0)
        "DefaultInboundAction"= 1 (0x1)
        "DoNotAllowExceptions"= 0 (0x0)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
        "EnableFirewall"= 0 (0x0)
        "DefaultOutboundAction"= 0 (0x0)
        "DefaultInboundAction"= 1 (0x1)
        "DoNotAllowExceptions"= 0 (0x0)

        R2 gupdate1c9876777235ff;Google Update Service (gupdate1c9876777235ff);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 133104]
        R3 s816bus;Sony Ericsson Device 816 driver (WDM);c:\windows\system32\DRIVERS\s816bus.sys [2007-06-18 81832]
        S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Live\Acer PlayMovie\000.fcl [2006-11-02 23:51 13560]
        S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2007-06-22 269448]
        S2 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [2007-01-26 50688]
        S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-02-11 210216]
        S3 netr73;RT73 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr73.sys [2008-02-26 493568]


        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
        \shell\AutoRun\command - L:\LaunchU3.exe -a

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09f3f3c6-b6f5-11dd-9a93-0019214a2749}]
        \shell\AutoRun\command - E:\LaunchU3.exe -a

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1bccb4bb-ccfc-11dd-8560-0019214a2749}]
        \shell\AutoRun\command - K:\LaunchU3.exe -a

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{678b971c-d966-11dc-b513-00120e82456d}]
        \shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe k4l0n62.sys.vbs

        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
        "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
        .
        Contents of the 'Scheduled Tasks' folder

        2009-05-04 c:\windows\Tasks\Google Software Updater.job
        - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-20 09:38]

        2009-05-04 c:\windows\Tasks\GoogleUpdateTaskMachine.job
        - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 07:54]

        2009-04-26 c:\windows\Tasks\McDefragTask.job
        - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-25 02:53]

        2009-04-26 c:\windows\Tasks\McQcTask.job
        - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-25 02:53]

        2009-05-04 c:\windows\Tasks\RegCure Program Check.job
        - c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]

        2009-04-28 c:\windows\Tasks\RegCure.job
        - c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]

        2009-05-04 c:\windows\Tasks\User_Feed_Synchronization-{FCED9B55-8DFE-46EE-B608-B7626366AB7D}.job
        - c:\windows\system32\msfeedssync.exe [2009-03-24 11:31]
        .
        - - - - ORPHANS REMOVED - - - -

        HKCU-Run-Acer Tour Reminder - (no file)


        .
        ------- Supplementary Scan -------
        .
        uStart Page = hxxp://www.google.com/
        uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
        mStart Page = hxxp://en.us.acer.yahoo.com
        uInternet Settings,ProxyOverride = *.local
        uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
        IE: &WordWeb... - c:\windows\wweb32.dll/lookup.html
        IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
        FF - ProfilePath - c:\users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\rgir4l13.default\
        FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
        FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
        FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
        FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
        FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
        .

        **************************************************************************

        catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2009-05-04 23:15
        Windows 6.0.6001 Service Pack 1 NTFS

        scanning hidden processes ... 

        scanning hidden autostart entries ...

        scanning hidden files ... 

        scan completed successfully
        hidden files: 0

        **************************************************************************
        .
        --------------------- LOCKED REGISTRY KEYS ---------------------

        [HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}]
        Denied: (A 2) (Everyone)
        ="FlashBroker"
        "LocalizedString"="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101"

        [HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation]
        "Enabled"=dword:00000001

        [HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32]
        ="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe"

        [HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib]
        ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
        Denied: (A 2) (Everyone)
        ="Shockwave Flash Object"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
        ="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx"
        "ThreadingModel"="Apartment"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
        ="0"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
        ="ShockwaveFlash.ShockwaveFlash.10"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
        ="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx, 1"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
        ="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
        ="1.0"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
        ="ShockwaveFlash.ShockwaveFlash"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
        Denied: (A 2) (Everyone)
        ="Macromedia Flash Factory Object"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
        ="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx"
        "ThreadingModel"="Apartment"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
        ="FlashFactory.FlashFactory.1"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
        ="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx, 1"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
        ="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
        ="1.0"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
        ="FlashFactory.FlashFactory"

        [HKEY_USERS\software\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
        Denied: (A 2) (Everyone)
        ="IFlashBroker2"

        [HKEY_USERS\software\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]
        ="{00020424-0000-0000-C000-000000000046}"

        [HKEY_USERS\software\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
        ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
        "Version"="1.0"

        [HKEY_USERS\software\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
        Denied: (A 2) (Everyone)

        [HKEY_USERS\software\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
        ="Shockwave Flash"

        [HKEY_USERS\software\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
        Denied: (A 2) (Everyone)
        =""

        [HKEY_USERS\software\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
        ="FlashBroker"

        [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
        Denied: (A) (Users)
        Denied: (A) (Everyone)
        Allowed: (B 1 2 3 4 5) (S-1-5-20)
        "BlindDial"=dword:00000000
        "MSCurrentCountry"=dword:000000b5

        [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
        Denied: (A) (Users)
        Denied: (A) (Everyone)
        Allowed: (B 1 2 3 4 5) (S-1-5-20)
        "BlindDial"=dword:00000000

        [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
        Denied: (A) (Users)
        Denied: (A) (Everyone)
        Allowed: (B 1 2 3 4 5) (S-1-5-20)
        "BlindDial"=dword:00000000

        [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
        Denied: (A) (Users)
        Denied: (A) (Everyone)
        Allowed: (B 1 2 3 4 5) (S-1-5-20)
        "BlindDial"=dword:00000000

        [HKEY_USERS\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
        Denied: (A) (Users)
        Denied: (A) (Everyone)
        Allowed: (B 1 2 3 4 5) (S-1-5-20)
        "BlindDial"=dword:00000000
        "MSCurrentCountry"=dword:000000b5

        [HKEY_USERS\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
        Denied: (A) (Users)
        Denied: (A) (Everyone)
        Allowed: (B 1 2 3 4 5) (S-1-5-20)
        "BlindDial"=dword:00000000

        [HKEY_USERS\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
        Denied: (A) (Users)
        Denied: (A) (Everyone)
        Allowed: (B 1 2 3 4 5) (S-1-5-20)
        "BlindDial"=dword:00000000

        [HKEY_USERS\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
        Denied: (A) (Users)
        Denied: (A) (Everyone)
        Allowed: (B 1 2 3 4 5) (S-1-5-20)
        "BlindDial"=dword:00000000
        .
        Completion time: 2009-05-04 23:17
        ComboFix-quarantined-files.txt  2009-05-04 15:17

        Pre-Run: 101,571,207,168 bytes free
        Post-Run: 102,403,452,928 bytes free

        358   --- E O F ---   2009-05-03 08:57
        Delete these files/folders, as follows:

        1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
        It must be Notepad, not Wordpad.
        2. Copy the text in the below code box by highlighting all the text and PRESSING Ctrl+C

        Code: [Select]KillAll::

        FixCSet::

        Folder::
        c:\programdata\NortonInstaller
        c:\users\All Users\NortonInstaller

        [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

        [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

        3. Go to the Notepad window and click Edit > Paste
        4. Then click File > Save
        5. Name the file CFScript.txt - Save the file to your Desktop
        6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



        ComboFix will begin to execute, just follow the prompts.
        After reboot (in case it asks to reboot), it will produce a log for you.
        Post that log (Combofix.txt) in your next reply.

        Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezePerformed the activity as per instructed.

        It is noticed that there is a new  "Internet Explorer " icon appear at the Desktop, and the old "Internet Explorer " icon still there . Which one shall I use or delete ?

        Here is the latest Combofix.txt logfile. Please advice the next cause of action . thanks.


        --------------------------------------- logfile --------------------------------------------------

        ComboFix 09-05-03.1 - Acer 05/05/2009 20:23.2 - NTFSx86
        Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.1.1033.18.2047.1279 [GMT 8:00]
        Running from: c:\users\Acer\Desktop\ComboFix.exe
        Command switches used :: c:\users\Acer\Desktop\CFScript.txt
        .

        (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
        .

        c:\programdata\NortonInstaller
        c:\programdata\NortonInstaller\Logs\05-03-2009-18h34m01s\SymNRT-05-03-2009-18h34m01s.log
        c:\programdata\NortonInstaller\Logs\05-03-2009-18h34m01s\SymNRT.1.mft.7z
        c:\programdata\NortonInstaller\Settings\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}.7z
        c:\users\All Users\NortonInstaller\Logs\05-03-2009-18h34m01s\SymNRT-05-03-2009-18h34m01s.log
        c:\users\All Users\NortonInstaller\Logs\05-03-2009-18h34m01s\SymNRT.1.mft.7z
        c:\users\All Users\NortonInstaller\Settings\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}.7z

        .
        (((((((((((((((((((((((((   Files Created from 2009-04-05 to 2009-05-05  )))))))))))))))))))))))))))))))
        .

        2009-05-02 03:37 . 2009-05-02 03:37   --------   d-----w   c:\program files\Trend Micro
        2009-04-27 16:35 . 2009-04-27 16:35   --------   d-----w   c:\program files\RegCure
        2009-04-27 14:21 . 2009-04-27 14:21   --------   d-----w   c:\users\Acer\AppData\Roaming\Malwarebytes
        2009-04-27 14:21 . 2009-04-06 07:32   15504   ----a-w   c:\windows\system32\drivers\mbam.sys
        2009-04-27 14:21 . 2009-04-06 07:32   38496   ----a-w   c:\windows\system32\drivers\mbamswissarmy.sys
        2009-04-27 14:21 . 2009-04-27 14:21   --------   d-----w   c:\programdata\Malwarebytes
        2009-04-27 14:21 . 2009-04-27 14:21   --------   d-----w   c:\users\All Users\Malwarebytes
        2009-04-27 14:21 . 2009-05-03 11:38   --------   d-----w   c:\program files\Malwarebytes' Anti-Malware
        2009-04-25 09:17 . 2009-04-25 09:17   --------   d-----w   c:\programdata\SiteAdvisor
        2009-04-25 09:17 . 2009-04-25 09:17   --------   d-----w   c:\users\All Users\SiteAdvisor
        2009-04-25 09:17 . 2009-04-25 09:22   --------   d-----w   c:\program files\SiteAdvisor
        2009-04-25 09:14 . 2009-03-25 03:06   40552   ----a-w   c:\windows\system32\drivers\mfesmfk.sys
        2009-04-25 09:14 . 2009-03-25 03:06   35272   ----a-w   c:\windows\system32\drivers\mfebopk.sys
        2009-04-25 09:14 . 2009-03-25 03:06   79880   ----a-w   c:\windows\system32\drivers\mfeavfk.sys
        2009-04-25 09:14 . 2008-10-23 05:08   130424   ----a-w   c:\windows\system32\drivers\Mpfp.sys
        2009-04-25 09:14 . 2009-04-25 09:14   --------   d-----w   c:\program files\Common Files\McAfee
        2009-04-25 09:14 . 2009-04-25 09:14   --------   d-----w   c:\program files\McAfee.com
        2009-04-25 09:14 . 2009-04-27 14:18   --------   d-----w   c:\program files\McAfee
        2009-04-25 09:13 . 2009-03-25 03:05   34216   ----a-w   c:\windows\system32\drivers\mferkdk.sys
        2009-04-25 09:00 . 2009-04-25 09:18   --------   d-----w   c:\programdata\McAfee
        2009-04-25 09:00 . 2009-04-25 09:18   --------   d-----w   c:\users\All Users\McAfee
        2009-04-20 12:06 . 2009-04-25 08:39   81984   ----a-w   c:\windows\system32\bdod.bin
        2009-04-20 12:02 . 2009-04-20 12:02   --------   d-----w   c:\program files\BitDefender
        2009-04-20 11:54 . 2009-04-20 15:39   --------   d-----w   c:\program files\Common Files\BitDefender
        2009-04-19 00:58 . 2009-04-19 00:58   --------   d-----w   C:\Sounds
        2009-04-19 00:53 . 2008-09-03 22:27   24832   ----a-w   c:\windows\system32\drivers\lgusbmodem.sys
        2009-04-19 00:53 . 2008-09-03 22:28   19968   ----a-w   c:\windows\system32\drivers\lgusbdiag.sys
        2009-04-19 00:53 . 2008-09-03 22:27   13056   ----a-w   c:\windows\system32\drivers\lgusbbus.sys
        2009-04-19 00:53 . 2009-04-19 00:53   --------   d-----w   c:\program files\LG Electronics
        2009-04-19 00:51 . 2007-11-08 08:26   1164728   ----a-w   c:\windows\system32\NMSDVDXU.dll
        2009-04-19 00:51 . 2009-04-19 09:59   --------   d-----w   c:\users\Acer\AppData\Roaming\LG Electronics
        2009-04-19 00:51 . 2009-04-19 10:00   --------   d-----w   c:\program files\LG PC Suite II

        .
        ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2009-05-05 12:26 . 2009-02-05 07:54   882   ----a-w   c:\windows\Tasks\GoogleUpdateTaskMachine.job
        2009-05-05 12:26 . 2009-04-28 11:29   352   ----a-w   c:\windows\Tasks\RegTool Startup.job
        2009-05-05 12:26 . 2009-04-27 16:35   436   ----a-w   c:\windows\Tasks\RegCure Program Check.job
        2009-05-05 12:26 . 2008-12-20 14:28   868   ----a-w   c:\windows\Tasks\Google Software Updater.job
        2009-05-05 12:26 . 2006-11-02 13:01   6   ---ha-w   c:\windows\Tasks\SA.DAT
        2009-05-04 14:59 . 2009-03-24 11:17   420   ---ha-w   c:\windows\Tasks\User_Feed_Synchronization-{FCED9B55-8DFE-46EE-B608-B7626366AB7D}.job
        2009-05-03 10:35 . 2007-07-17 06:57   --------   d-----w   c:\program files\Common Files\Symantec Shared
        2009-04-28 10:52 . 2009-04-27 16:35   370   ----a-w   c:\windows\Tasks\RegCure.job
        2009-04-26 04:06 . 2009-04-25 09:14   338   ----a-w   c:\windows\Tasks\McDefragTask.job
        2009-04-26 04:06 . 2009-04-25 09:14   330   ----a-w   c:\windows\Tasks\McQcTask.job
        2009-04-19 00:56 . 2006-11-02 10:25   86016   ----a-w   c:\windows\inf\infstor.dat
        2009-04-19 00:56 . 2006-11-02 10:25   51200   ----a-w   c:\windows\inf\infpub.dat
        2009-04-19 00:56 . 2006-11-02 10:25   143360   ----a-w   c:\windows\inf\infstrng.dat
        2009-04-19 00:53 . 2007-07-17 06:18   --------   d--h--w   c:\program files\InstallShield Installation Information
        2009-04-19 00:50 . 2008-01-21 08:04   7376   ----a-w   c:\users\Acer\AppData\Local\d3d9caps.dat
        2009-04-17 12:42 . 2006-11-02 11:18   --------   d-----w   c:\program files\Windows Mail
        2009-04-01 13:02 . 2008-12-20 14:28   --------   d-----w   c:\program files\Google
        2009-03-25 03:06 . 2009-03-25 03:06   214024   ----a-w   c:\windows\system32\drivers\mfehidk.sys
        2009-03-17 03:38 . 2009-04-17 11:15   40960   ----a-w   c:\windows\AppPatch\apihex86.dll
        2009-03-17 03:38 . 2009-04-17 11:15   13824   ----a-w   c:\windows\system32\apilogen.dll
        2009-03-17 03:38 . 2009-04-17 11:15   24064   ----a-w   c:\windows\system32\amxread.dll
        2009-03-08 11:34 . 2009-03-24 11:06   914944   ----a-w   c:\windows\system32\wininet.dll
        2009-03-08 11:34 . 2009-03-24 11:06   43008   ----a-w   c:\windows\system32\licmgr10.dll
        2009-03-08 11:33 . 2009-03-24 11:06   18944   ----a-w   c:\windows\system32\corpol.dll
        2009-03-08 11:33 . 2009-03-24 11:06   109056   ----a-w   c:\windows\system32\iesysprep.dll
        2009-03-08 11:33 . 2009-03-24 11:06   109568   ----a-w   c:\windows\system32\PDMSetup.exe
        2009-03-08 11:33 . 2009-03-24 11:06   132608   ----a-w   c:\windows\system32\ieUnatt.exe
        2009-03-08 11:33 . 2009-03-24 11:06   107520   ----a-w   c:\windows\system32\RegisterIEPKEYs.exe
        2009-03-08 11:33 . 2009-03-24 11:06   107008   ----a-w   c:\windows\system32\SetIEInstalledDate.exe
        2009-03-08 11:33 . 2009-03-24 11:06   103936   ----a-w   c:\windows\system32\SetDepNx.exe
        2009-03-08 11:33 . 2009-03-24 11:06   420352   ----a-w   c:\windows\system32\vbscript.dll
        2009-03-08 11:32 . 2009-03-24 11:06   72704   ----a-w   c:\windows\system32\admparse.dll
        2009-03-08 11:32 . 2009-03-24 11:06   71680   ----a-w   c:\windows\system32\iesetup.dll
        2009-03-08 11:32 . 2009-03-24 11:06   66560   ----a-w   c:\windows\system32\wextract.exe
        2009-03-08 11:32 . 2009-03-24 11:06   169472   ----a-w   c:\windows\system32\iexpress.exe
        2009-03-08 11:31 . 2009-03-24 11:06   34816   ----a-w   c:\windows\system32\imgutil.dll
        2009-03-08 11:31 . 2009-03-24 11:06   48128   ----a-w   c:\windows\system32\mshtmler.dll
        2009-03-08 11:31 . 2009-03-24 11:06   45568   ----a-w   c:\windows\system32\mshta.exe
        2009-03-08 11:22 . 2009-03-24 11:06   156160   ----a-w   c:\windows\system32\msls31.dll
        2009-03-08 06:33 . 2009-03-08 06:33   --------   d-----w   c:\program files\Rationale 2
        2009-03-03 04:46 . 2009-04-17 11:15   3599328   ----a-w   c:\windows\system32\ntkrnlpa.exe
        2009-03-03 04:46 . 2009-04-17 11:15   3547632   ----a-w   c:\windows\system32\ntoskrnl.exe
        2009-03-03 04:39 . 2009-04-17 11:15   183296   ----a-w   c:\windows\system32\sdohlp.dll
        2009-03-03 04:39 . 2009-04-17 11:15   551424   ----a-w   c:\windows\system32\rpcss.dll
        2009-03-03 04:39 . 2009-04-17 11:15   26112   ----a-w   c:\windows\system32\printfilterpipelineprxy.dll
        2009-03-03 04:37 . 2009-04-17 11:15   98304   ----a-w   c:\windows\system32\iasrecst.dll
        2009-03-03 04:37 . 2009-04-17 11:15   54784   ----a-w   c:\windows\system32\iasads.dll
        2009-03-03 04:37 . 2009-04-17 11:15   44032   ----a-w   c:\windows\system32\iasdatastore.dll
        2009-03-03 03:04 . 2009-04-17 11:15   666624   ----a-w   c:\windows\system32\printfilterpipelinesvc.exe
        2009-03-03 02:38 . 2009-04-17 11:15   17408   ----a-w   c:\windows\system32\iashost.exe
        2009-02-13 08:49 . 2009-04-17 11:15   72704   ----a-w   c:\windows\system32\secur32.dll
        2009-02-13 08:49 . 2009-04-17 11:15   1255936   ----a-w   c:\windows\system32\lsasrv.dll
        2009-02-09 03:10 . 2009-03-11 10:12   2033152   ----a-w   c:\windows\system32\win32k.sys
        2008-08-31 14:39 . 2006-11-02 12:50   174   --sha-w   c:\program files\desktop.ini
        .

        (((((((((((((((((((((((((((((   [email protected]_15.15.22   )))))))))))))))))))))))))))))))))))))))))
        .
        - 2007-07-17 06:24 . 2009-05-04 14:40   69044              c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
        + 2007-07-17 06:24 . 2009-05-05 12:07   69044              c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
        + 2006-11-02 13:05 . 2009-05-05 12:07   74370              c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
        - 2008-01-19 09:10 . 2009-05-04 14:40   18066              c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-339563597-1808007692-2602482230-1000_UserData.bin
        + 2008-01-19 09:10 . 2009-05-05 12:07   18066              c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-339563597-1808007692-2602482230-1000_UserData.bin
        + 2007-10-19 08:34 . 2009-05-05 12:27   32768              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
        - 2007-10-19 08:34 . 2009-05-04 15:15   32768              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
        + 2007-10-19 08:34 . 2009-05-05 12:27   16384              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
        - 2007-10-19 08:34 . 2009-05-04 15:15   16384              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
        - 2009-05-04 14:44 . 2009-05-04 14:44   5828              c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\B855EB17AFD3537FD667244F8CB86F6C92AE4254\B855EB17AFD3537FD667244F8CB86F6C92AE4254\Data.dat
        + 2009-05-05 12:08 . 2009-05-05 12:08   5828              c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\B855EB17AFD3537FD667244F8CB86F6C92AE4254\B855EB17AFD3537FD667244F8CB86F6C92AE4254\Data.dat
        + 2009-05-05 12:07 . 2009-05-05 12:07   5220              c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\AFA0228517D559C72225EDC64521ED7E04459E89\AFA0228517D559C72225EDC64521ED7E04459E89\Data.dat
        - 2009-05-04 14:41 . 2009-05-04 14:41   5220              c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\AFA0228517D559C72225EDC64521ED7E04459E89\AFA0228517D559C72225EDC64521ED7E04459E89\Data.dat
        + 2009-05-05 12:07 . 2009-05-05 12:07   7994              c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\74A956292B9D7ED29866593C7E501FA45B187192\74A956292B9D7ED29866593C7E501FA45B187192\Data.dat
        + 2009-05-05 12:06 . 2009-05-05 12:06   6202              c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\1D392462A204CC01DF4399DA2E6E264AAC23F1AA\1D392462A204CC01DF4399DA2E6E264AAC23F1AA\Data.dat
        - 2009-05-04 14:44 . 2009-05-04 14:44   6202              c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\1D392462A204CC01DF4399DA2E6E264AAC23F1AA\1D392462A204CC01DF4399DA2E6E264AAC23F1AA\Data.dat
        - 2009-05-04 14:38 . 2009-05-04 14:38   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
        + 2009-05-05 12:26 . 2009-05-05 12:26   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
        + 2007-10-19 08:34 . 2009-05-05 12:27   131072              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
        - 2007-10-19 08:34 . 2009-05-04 15:15   131072              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
        .
        (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* empty entries & legit default entries are not shown
        REGEDIT4

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
        "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
        "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-02 393216]
        "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
        "Acer Tour Reminder"="" [BU]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "ALaunch"="c:\acer\ALaunch\AlaunchClient.exe" [2007-01-26 540672]
        "Acer Empowering Technology Monitor"="c:\acer\Empowering Technology\SysMonitor.exe" [2007-06-15 326440]
        "PCMMediaSharing"="c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2007-06-22 204908]
        "SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-02-02 630784]
        "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
        "PlayMovie"="c:\program files\Acer Arcade Live\Acer PlayMovie\PMVService.exe" [2007-07-14 178280]
        "Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-05-22 151552]
        "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-09 144784]
        "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
        "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
        "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696]
        "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
        "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-03-25 645328]
        "McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-01-09 1176808]
        "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-06-20 4493312]

        c:\users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
        OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
        WordWeb.lnk - c:\program files\WordWeb\wweb32.exe [2008-4-22 42168]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
        "EnableUIADesktopToggle"= 0 (0x0)

        HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
        "wave2"= serwvdrv.dll

        [HKEY_LOCAL_MACHINE\software\microsoft\security center]
        "UacDisableNotify"=dword:00000001
        "InternetSettingsDisableNotify"=dword:00000001
        "AutoUpdateDisableNotify"=dword:00000001

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
        "DisableMonitoring"=dword:00000001

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
        "DisableMonitoring"=dword:00000001

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
        "DisableMonitoring"=dword:00000001

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
        "EnableFirewall"= 0 (0x0)
        "DefaultOutboundAction"= 0 (0x0)
        "DefaultInboundAction"= 1 (0x1)
        "DisableUnicastResponsesToMulticastBroad cast"= 0 (0x0)
        "DoNotAllowExceptions"= 0 (0x0)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
        "{CC798B78-DE13-4976-9DBA-0015A8CE56F8}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
        "{81030BAF-357C-40FB-8793-B99ADE4212A8}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
        "{4C0E0174-247F-4069-9F52-9AD19DC71D83}"= c:\program files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
        "{560429FD-BAD7-4E9A-857F-AA8C893A477F}"= c:\program files\Acer Arcade Live\Acer DV Magician\Acer DV Magician.exe:Acer DV Magician
        "{ED9E9E19-C630-464A-87A6-C20269418FC1}"= c:\program files\Acer Arcade Live\Acer DVDivine\Acer DVDivine.exe:Acer DVDivine
        "{492EC220-FB41-4472-8B20-E400B5B81034}"= c:\program files\Acer Arcade Live\Acer HomeMedia\Acer HomeMedia.exe:Acer HomeMedia
        "{63C2B5ED-23AB-4CB2-AC71-1114E8E91419}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Acer HomeMedia Connect.exe:Acer HomeMedia Connect
        "{9C8A4F83-9400-4816-BA61-125CC31F09BB}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:Acer HomeMedia Connect Service
        "{D174244A-0FBB-4C36-8948-020059CF029E}"= c:\program files\Acer Arcade Live\Acer SlideShow DVD\Acer SlideShow DVD.exe:Acer SlideShow DVD
        "{7DDAC852-04CD-4EFE-8DE0-1361BE28FB87}"= c:\program files\Acer Arcade Live\Acer VideoMagician\Acer VideoMagician.exe:Acer VideoMagician
        "{A737C415-9154-4556-87F7-B5F30470A416}"= c:\program files\Acer Arcade Live\Acer PlayMovie\PlayMovie.exe:Acer Play Movie
        "{5D969526-27C1-40B7-9F52-8278DA307BA0}"= c:\program files\Acer Arcade Live\Acer PlayMovie\PMVService.exe:Acer Play Movie Resident Program
        "{3C4ED021-08D7-40ED-B0AD-E27D445943AF}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
        "{7675F91E-FBB7-4E0C-9628-6432ED104CA4}"= UDP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:Sony Ericsson Media Manager 1.0
        "{50E32A91-4CD3-4573-90F9-B49D58FF0C3A}"= TCP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:Sony Ericsson Media Manager 1.0
        "{D6C8BEFB-D7A5-43B3-AEC2-F1A90A04DF7D}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
        "{89879D53-A003-402C-835D-7BFE787E063A}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
        "{9C6250F4-9A47-482F-89D3-7CD7534C3986}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
        "{E8376ABB-C3B1-4964-95E9-E750169D22B5}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
        "{2B15D7A0-01B8-4442-B9F8-24F7164354DE}"= UDP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
        "{38BE90AF-D3C8-4C9E-94E6-E0A458035CB9}"= TCP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
        "{6B4DD4C0-2194-43F9-A598-60A6148EFAA6}"= Profile=Private|Profile=Public|c:\program files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
        "EnableFirewall"= 0 (0x0)
        "DefaultOutboundAction"= 0 (0x0)
        "DefaultInboundAction"= 1 (0x1)
        "DoNotAllowExceptions"= 0 (0x0)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
        "EnableFirewall"= 0 (0x0)
        "DefaultOutboundAction"= 0 (0x0)
        "DefaultInboundAction"= 1 (0x1)
        "DoNotAllowExceptions"= 0 (0x0)

        R2 gupdate1c9876777235ff;Google Update Service (gupdate1c9876777235ff);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 133104]
        R3 s816bus;Sony Ericsson Device 816 driver (WDM);c:\windows\system32\DRIVERS\s816bus.sys [2007-06-18 81832]
        S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Live\Acer PlayMovie\000.fcl [2006-11-02 23:51 13560]
        S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2007-06-22 269448]
        S2 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [2007-01-26 50688]
        S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-02-11 210216]
        S3 netr73;RT73 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr73.sys [2008-02-26 493568]


        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
        \shell\AutoRun\command - L:\LaunchU3.exe -a

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09f3f3c6-b6f5-11dd-9a93-0019214a2749}]
        \shell\AutoRun\command - E:\LaunchU3.exe -a

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1bccb4bb-ccfc-11dd-8560-0019214a2749}]
        \shell\AutoRun\command - K:\LaunchU3.exe -a

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{678b971c-d966-11dc-b513-00120e82456d}]
        \shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe k4l0n62.sys.vbs

        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
        "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
        .
        Contents of the 'Scheduled Tasks' folder

        2009-05-05 c:\windows\Tasks\Google Software Updater.job
        - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-20 09:38]

        2009-05-05 c:\windows\Tasks\GoogleUpdateTaskMachine.job
        - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 07:54]

        2009-04-26 c:\windows\Tasks\McDefragTask.job
        - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-25 02:53]

        2009-04-26 c:\windows\Tasks\McQcTask.job
        - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-25 02:53]

        2009-05-05 c:\windows\Tasks\RegCure Program Check.job
        - c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]

        2009-04-28 c:\windows\Tasks\RegCure.job
        - c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]

        2009-05-04 c:\windows\Tasks\User_Feed_Synchronization-{FCED9B55-8DFE-46EE-B608-B7626366AB7D}.job
        - c:\windows\system32\msfeedssync.exe [2009-03-24 11:31]
        .
        .
        ------- Supplementary Scan -------
        .
        uStart Page = hxxp://www.google.com/
        uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
        mStart Page = hxxp://en.us.acer.yahoo.com
        uInternet Settings,ProxyOverride = *.local
        uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
        IE: &WordWeb... - c:\windows\wweb32.dll/lookup.html
        IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
        FF - ProfilePath - c:\users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\rgir4l13.default\
        FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
        FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
        FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
        FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
        FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
        .

        **************************************************************************

        catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2009-05-05 20:27
        Windows 6.0.6001 Service Pack 1 NTFS

        scanning hidden processes ... 

        scanning hidden autostart entries ...

        scanning hidden files ... 

        scan completed successfully
        hidden files: 0

        **************************************************************************
        .
        --------------------- LOCKED REGISTRY KEYS ---------------------

        [HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}]
        Denied: (A 2) (Everyone)
        ="FlashBroker"
        "LocalizedString"="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101"

        [HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation]
        "Enabled"=dword:00000001

        [HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32]
        ="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe"

        [HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib]
        ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
        Denied: (A 2) (Everyone)
        ="Shockwave Flash Object"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
        ="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx"
        "ThreadingModel"="Apartment"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
        ="0"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
        ="ShockwaveFlash.ShockwaveFlash.10"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
        ="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx, 1"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
        ="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
        ="1.0"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
        ="ShockwaveFlash.ShockwaveFlash"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
        Denied: (A 2) (Everyone)
        ="Macromedia Flash Factory Object"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
        ="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx"
        "ThreadingModel"="Apartment"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
        ="FlashFactory.FlashFactory.1"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
        ="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx, 1"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
        ="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
        ="1.0"

        [HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
        ="FlashFactory.FlashFactory"

        [HKEY_USERS\software\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
        Denied: (A 2) (Everyone)
        ="IFlashBroker2"

        [HKEY_USERS\software\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]
        ="{00020424-0000-0000-C000-000000000046}"

        [HKEY_USERS\software\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
        ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
        "Version"="1.0"

        [HKEY_USERS\software\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
        Denied: (A 2) (Everyone)

        [HKEY_USERS\software\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
        ="Shockwave Flash"

        [HKEY_USERS\software\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
        Denied: (A 2) (Everyone)
        =""

        [HKEY_USERS\software\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
        ="FlashBroker"

        [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
        Denied: (A) (Users)
        Denied: (A) (Everyone)
        Allowed: (B 1 2 3 4 5) (S-1-5-20)
        "BlindDial"=dword:00000000
        "MSCurrentCountry"=dword:000000b5

        [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
        Denied: (A) (Users)
        Denied: (A) (Everyone)
        Allowed: (B 1 2 3 4 5) (S-1-5-20)
        "BlindDial"=dword:00000000

        [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
        Denied: (A) (Users)
        Denied: (A) (Everyone)
        Allowed: (B 1 2 3 4 5) (S-1-5-20)
        "BlindDial"=dword:00000000

        [HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
        Denied: (A) (Users)
        Denied: (A) (Everyone)
        Allowed: (B 1 2 3 4 5) (S-1-5-20)
        "BlindDial"=dword:00000000

        [HKEY_USERS\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
        Denied: (A) (Users)
        Denied: (A) (Everyone)
        Allowed: (B 1 2 3 4 5) (S-1-5-20)
        "BlindDial"=dword:00000000
        "MSCurrentCountry"=dword:000000b5

        [HKEY_USERS\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
        Denied: (A) (Users)
        Denied: (A) (Everyone)
        Allowed: (B 1 2 3 4 5) (S-1-5-20)
        "BlindDial"=dword:00000000

        [HKEY_USERS\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
        Denied: (A) (Users)
        Denied: (A) (Everyone)
        Allowed: (B 1 2 3 4 5) (S-1-5-20)
        "BlindDial"=dword:00000000

        [HKEY_USERS\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
        Denied: (A) (Users)
        Denied: (A) (Everyone)
        Allowed: (B 1 2 3 4 5) (S-1-5-20)
        "BlindDial"=dword:00000000
        .
        --------------------- DLLs Loaded Under Running Processes ---------------------

        - - - - - - - > 'Explorer.exe'(2016)
        c:\program files\McAfee\SiteAdvisor\saHook.dll
        .
        ------------------------ Other Running Processes ------------------------
        .
        c:\windows\System32\Ati2evxx.exe
        c:\windows\System32\audiodg.exe
        c:\windows\System32\Ati2evxx.exe
        c:\acer\Empowering Technology\ePerformance\MemCheck.exe
        c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        c:\program files\Bonjour\mDNSResponder.exe
        c:\acer\Empowering Technology\eDataSecurity\eDSService.exe
        c:\program files\Common Files\LightScribe\LSSrvc.exe
        c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
        c:\windows\System32\rundll32.exe
        c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
        c:\program files\McAfee\MPF\MpfSrv.exe
        c:\program files\McAfee\MSK\msksrver.exe
        c:\program files\CyberLink\Shared Files\RichVideo.exe
        c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
        c:\progra~1\McAfee\MSC\mcmscsvc.exe
        c:\progra~1\McAfee.com\Agent\mcagent.exe
        c:\windows\System32\conime.exe
        c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
        c:\windows\ehome\ehmsas.exe
        c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
        c:\program files\Windows Media Player\wmpnetwk.exe
        c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
        c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
        c:\windows\servicing\TrustedInstaller.exe
        .
        **************************************************************************
        .
        Completion time: 2009-05-05 20:32 - machine was rebooted
        ComboFix-quarantined-files.txt  2009-05-05 12:32
        ComboFix2.txt  2009-05-04 15:17

        Pre-Run: 102,314,172,416 bytes free
        Post-Run: 102,181,163,008 bytes free

        419   --- E O F ---   2009-05-03 08:57
        I have no idea where the new IE icon came from...

        Download GMER and save it your desktop.

        * Extract it to your desktop and double-click GMER.exe
        * Click the rootkit tab and then scan.
        * Don't check the Show All box while scanning in progress!
        * When scanning is finished click Copy.
        * This copies the log to clipboard
        * Post the log in your reply.Before doing GMER scan, computer seems get back to normal -> no more IE log in problem and faster log in .
        Nevertheless, still perform GMER-> rootkit-> scan as instructed .
        During scanning, counter problem and following statement appear :
        ----------------------------------------------------------------------------------
        gmer.exe has stopped working
        A problem caused the program to stop working correctly.
        Window will close the program and notify you if solution is available
        -------------------------------------------------------------------------------------
        After this, computer seems performing some work and never shut down . Waited for more than half an hour and finally I do a click the  "shut down " commant at the right bottom of above statement and get out of the loop .

        What has gone wrong with GMER?
        Since no IE log in problem. Is there any more thing to be done ?
        Thanks .  Download Rooter.exe to your desktop

        * Double click Rooter.exe to start the tool.
        * A DOS window will appear and show the scan progress.
        * Once complete a notepad file containing the report will open.
        * Copy & paste the results in your next reply.
        * Close notepad and Rooter will close.

        A log will also save at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have Windows installed).after double click Rooter.exe, following message came out on screen ( not in DOS window) :
        --------------------------------------------------------------------
        Exception Processing message 0xc0000013 parameters 0x75D792A0 ox00000004 0x75D792A0 0x75D79A0
        3x choices are given : stop, try again or continue
        -------------------------------------------------------------

        Select " continue " , Dos window shows
        ---------------------------------------------------
        C:\windows\prefetch\webmediaplayer
        --------------------------------------------------

        this statement stay in Dos window and no further progress, after 5 minutes, following message appear on screen ( not in DOS window ) :
         Find String (QGREP) utility has stopped working , click close program ....

        Please advice how to proceed ? thanks .
        ( NB. the computer seems working perfectly now, no problem to log in to IE ) .Right click it and choose 'Run as Administrator'Done !
        same problem and message as before .* Download  The Avenger by Swandog46
        * Unzip/extract it to a folder on your desktop.
        * Right click on avenger.exe and choose 'Run as Administrator'
        * Click OK
        * Make sure that the box next to Scan for rootkits has a mark in it and that the box next to Automatically disable any rootkits found does not have a mark in it.
        * Click the Execute button.
        * You will be asked No script has been entered. Do you want to execute a rootkit scan only?.
        * Click Yes.
        * You will now be asked First step completed ... The Avenger has been successfully set up to run on next boot. Reboot now?
        * Click Yes
        * Your PC will now be rebooted.
        * After your PC has completed the necessary reboots, a log should automatically open. If it does not automatically open, then the log can be found at
        %systemdrive%avenger.txt (typically C:avenger.txt).
        * Please post the Avenger log in your next reply.PLease see Avenger log file .
        Kindly advice next action. thanks

        Logfile of The Avenger Version 2.0, (c) by Swandog46
        http://swandog46.geekstogo.com

        Platform:  Windows Vista

        *******************

        Script file opened successfully.
        Script file read successfully.

        Backups DIRECTORY opened successfully at C:\Avenger

        *******************

        Beginning to process script file:

        Rootkit scan active.
        No rootkits found!


        Completed script processing.

        *******************

        Finished!  Terminate.
        1400.

        Solve : removal question BIOS?

        Answer»

        If I got a VIRUS on my COMPUTER could I erase everything off my BIOS and reset it and would doing this get rid of the virus?A virus very rarely infects the bios. 99.9999999% of the time they STAY on the hard drive.

        You also can't erase the bios. If you did, your computer wouldn't know how to turn on!! You can clear the CMOS (the memory of the BIOS) but that won't get rid of the virus.Silly me!

        I was talking about the CMOS not the BIOS

        thanks for the help anyway Quote from: Griff on May 16, 2009, 05:58:16 PM

        A virus very rarely infects the bios. 99.9999999% of the time they stay on the hard drive.

        You also can't erase the bios. If you did, your computer wouldn't know how to turn on!! You can clear the CMOS (the memory of the BIOS) but that won't get rid of the virus.

        EXCELLENT advice!!

        Just to add, the rule of thumb with your BIOS is leave it alone unless you are 110% positive you know what you are doing! Quote from: evilfantasy on May 16, 2009, 06:39:04 PM
        Excellent advice!!

        Just to add, the rule of thumb with your BIOS is leave it alone unless you are 110% positive you know what you are doing!

        This same good advice applies to the registry as well........... Quote from: evilfantasy on May 16, 2009, 06:39:04 PM
        ... unless you are 110% positive you know what you are doing!
        Not relevant. Does not apply to anybody here.