Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

1451.

Solve : advanced care system?

Answer»

do any of the experts USE ADVANCED care system , i would like to know more about the utilities sectionWhilst you are waiting for an expert reply, my experience with it was good until it updated a couple of months AGO and caused problems. AWC forum was not helpful to either me or OTHERS who POSTED the same problem, so I have ditched it.
I've had no problems, but i've not updated it.

I think i'll update and let you know!!

1452.

Solve : Panda update?

Answer»

Recently updated Panda and ran a scan, then logged off.  Now can't log back in.  When I shut off the POWER and restart windows looks like it's going to load but then goes into this saving your settings, logging off, saving your settings, logging off type loop.
I can't start up in safe mode, same thing happens but different messages ( loading personal settings, saving your settings loop)
Can't do the last known good one either that gives the first loop.
and safe mode command PROMPT goes same as safe mode.

Not SURE what to do and I am in the beginner to NOVICE range for COMPUTERS

1453.

Solve : I'm pretty sure I have a root kit, but I can't get rid of it.?

Answer»

About a week and a half ago, I CLICKED on a link on another forum that gave me a bunch of viruses and spyware(it was a tinyurl link, which I know I shouldn't have clicked on...).  I've managed to get almost all of it out, but there's one thing I can't get rid of.  It's a file called "88e25094" and it's located in F:\WINDOWS\system32\drivers.

Avast! will detect it, say it's a root kit, but I can't perform any actions on it.  Webroot Antivirus with Antispyware will detect it and have me reboot so it can delete it early, but it'll say that the file is missing.  Malwarebytes' Anti-Malware detects it and SAYS it'll delete the file on reboot, but the file is still there.  If I try to delete it myself, I get this error: "Cannot delete 88e25094: cannot find the specified file."

My computer started acting real sluggish when I originally got the viruses and spyware and considerably improved since then, but it's still not running anywhere near as well as before.


I've FOLLOWED everything in the sticky and attached the logs for SuperAntispyware, Malwarebytes' Anti-Malware, and HijackThis.


Thanks to anyone who can help.  If you need any more information about anything, I'll be checking this thread often, so I'll get you whatever you need asap.

[attachment deleted by admin]just try the avast boottime scan and i am sure u can delete or modify it...................



if u dont know how to run boot time scan read avast FAQ....








The first thing you need to do is boot into Safe Mode and try scanning that way.  Most infections LAY dormant in Safe Mode, which makes them easier to detect and remove.  So, while in Safe Mode, scan with MBAM, SAS, and Avast, one at a time.  When you're DONE, post the logs and here and let us know if the file is still returning.

1454.

Solve : Norton subscription expires soon?

Answer»

hello

I run Windows Vista on my laptop, which is almost a year old. When i first got it, i INSTALLED Norton Internet Security as my antivirus and it has worked fairly well (although i had a huge problem with Brontok virus last year, but that's been cleared up now).

My Norton SUBSCRIPTION expires in a couple weeks and i'm considering switching to a free antivirus program that can be found online, LIKE AVG or Avast. is this a bad idea? will i be compromising my laptop's security? any feedback would be greatly appreciated.

Thanks a bunch

Dee
Avira or Avast are the best bets.......


Here's the removal tool for Norton...Make sure you remove it completely.....

http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039/Some experts here like this one:
http://www.free-av.com/

AVG or Avast ave both very good.

As for Norton, I will bite my tongue. 



Thanks for the input! Even after my subscription expires, should i still uninstall the Norton? can't i just disable evrything and not risk causing any trouble?

Thanks again

PS i forgot to mention that i was also considering BitDefender


Another good choice, but it may be a bit tougher on resources.......Completely remove Norton. Quote from: Karnac on September 13, 2009, 08:04:17 AM
Avira or Avast are the best bets.......


Here's the removal tool for Norton...Make sure you remove it completely.....

http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039/




Quote from: Karnac on September 13, 2009, 08:29:38 AM
Another good choice, but it may be a bit tougher on resources.......Completely remove Norton.


adeeba222 , the above advice is goodHere's my two cents. I have no problem with free software. But when it COMES to certain utilities (with ANTI VIRUS sw at the very top of the list) there's no way I'm looking to go cheap - I want the BEST available. In my opinion that's Kaspersky. But hey, that's me. Regardless of your choice, make sure it's updated regularly and kept resident at all times. Quote
there's no way I'm looking to go cheap - I want the BEST available
But most of the best software is free. Look at Linux for example. I'm not arguing here, but giving my opinion...) Quote from: kpac on September 13, 2009, 12:11:20 PM
But most of the best software is free.
And my opinion is --- I disagree.Heh okay. No persuasion at all? Quote from: kpac on September 13, 2009, 12:16:50 PM
Heh okay. No persuasion at all?
No persuasion? I don't understand your question.As in, I can't persuade you to change your mind about free software...No persuasion needed. I try not to speak unless I know what I'm TALKING about. My input is based on empirical data.Okay - no harm done.
1455.

Solve : An Infected E-mail attachment.?

Answer»

Hi,

I have a query.

If you get an attachment with an email that is infected, does it AFFECT your inbox or emails or anything at all.
Like, does the VIRUS SPREAD even though you haven't downloaded the attachment into your computer.

Thanks a lot.If you do not open the attachment you should be fine. Just delete the email.Yeah, So one has to delete the email, does that MEAN it will affect things?Again, not if you don't open the attachment, no. But you should delete the email just so nobody CAN open the attachment.Oh I see,

Thank you so much.Sure.its best not to open any unknown mail from the unknown PERSON which contain attachements(any format)............

1456.

Solve : Malware in flash drive?

Answer»

I have the reader_s VIRUS in my Flash drive but I have something I need in there too. Is there anyway I can get what I need out of the flash drive, without getting infected? I'm using windows xp PROFESSIONAL sp3. If u need to know what KIND of file I want to get from the flash drive, its some cpp files and some PICS (I think they're jpg).
Is it safe to put it in the pc and than scan it, or it might be dangerous?Well, make sure you have your av ready to scan and plug in your flash drive. Scan it and remove any viruses then copy anything you need to keep. Format your FLASHDRIVE then do a FULL scan of your computer.
Hold your "shift" key down while you're plugging in your USB drive, then perform the scan with your AV and any other protective programs you have. hold the shiftkey down for atleast 30 secs during and after you pluged it in
scan the JPGS scanning the CPP files is unneccary because they are text files and cannot be executeddHave a look here....

http://www.kusangpalo.com/2008/usb-drive-tip-hold-down-shift-key.htmlbefore opening your flashdrive you must scan it with any spyware you got, but I highly prefer AVG or avast, after scanning you can easily see files that are infected and remove them, after that you can easily copy anything you want without worries. Quote from: printerface on September 08, 2009, 04:33:45 AM

before opening your flashdrive you must scan it with any spyware you got, but I highly prefer AVG or avast, after scanning you can easily see files that are infected and remove them, after that you can easily copy anything you want without worries.
AVG or Avast will not catch spyware/malware.
1457.

Solve : Eraser?

Answer»

I have installed 'Eraser' on my PC as I wish to CREATE a Nuke Boot Disk on a CD-R. We have an older model PC that we wish to dispose of, and want to wipe out the hard drive. We originally had this unit custom made without the internet options as we were not in an area where the internet was available ( on a REMOTE island !! ) The Eraser instructions specify - Start>All programs>Eraser>Create Nuke Boot Disk, but this last step doesn't appear anywhere -  - Any suggestions?? -  Well, if your gonna throw it away then I would suggest just SMASHING the hard drive with a HAMMER. Nope, not throwing it away - we want to DONATE it.Your windows disk can format the drive.

1458.

Solve : Problems with pop ups--Hijack this posted last entry of thread?

Answer»

To answer all questions, everything is fine. We will take care of the IMGRogue-WiniFighter_Small[1].gif. before we are done.

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

RegLockDel::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeEvilfantasy, I had problems. I did what you asked and I received response that it had not been initialized properly. I attempted to use print screen button to "save" the messages to paste in paint and I received the reply that Paint was a key marked for deletion. Also, Combofix wanted to delete Avast key, Internet Explorer and Foxfire as well.  I thought I closed everything again or maybe I did things too soon. It did reboot to give the log---. After that I rebooted to safe mode and choose last known good restore point...Not sure of the terminology and I don't know much about restore points.  Also the magnifier which usually starts up on boot up or restart appeared and it has not been a problem until now....unless you count scattering the icons on desktop a problem. It is usually the bottom row and rightmost 2-3 columns that get moved or a random single one. The google sidebar reappeared; just prior to Combofix it wasn't there---just the google destop and I don't know how I had ended up with both! Also Combofix moved from bottom of my screen to top of screen and more towards the right.

In case it matters, Internet Explorer does not have a "run as administrator" selection while Foxfire does; Internet Explorer is the default browser.... Foxfire when originally put on this computer by a friend was the default; I changed it back to IE long ago.
Log follows:

ComboFix 09-08-28.01 - Susan M 08/28/2009 23:45.4.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.1982.1072 [GMT -4:00]
Running from: c:\users\Susan M\Desktop\ComboFix.exe
Command switches used :: c:\users\Susan M\Desktop\CFScript.txt
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((   Files Created from 2009-07-28 to 2009-08-29  )))))))))))))))))))))))))))))))
.

2009-08-29 03:50 . 2009-08-29 03:52   --------   d-----w-   c:\users\Susan M\AppData\Local\temp
2009-08-29 03:50 . 2009-08-29 03:50   --------   d-----w-   c:\users\Public\AppData\Local\temp
2009-08-29 03:50 . 2009-08-29 03:50   --------   d-----w-   c:\users\Default\AppData\Local\temp
2009-08-27 21:46 . 2009-08-27 22:44   --------   d-----w-   c:\programdata\Spybot - Search & Destroy
2009-08-27 21:46 . 2009-08-27 21:49   --------   d-----w-   c:\program files\Spybot - Search & Destroy
2009-08-27 12:44 . 2009-08-27 12:44   --------   d-----w-   c:\programdata\Office Genuine Advantage
2009-08-26 18:01 . 2009-06-22 10:09   2048   ----a-w-   c:\windows\system32\tzres.dll
2009-08-26 12:56 . 2009-06-05 09:40   28672   ----a-w-   c:\windows\system32\Apphlpdm.dll
2009-08-26 12:56 . 2009-06-05 09:53   4240384   ----a-w-   c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-25 21:47 . 2009-08-28 13:03   --------   d-----w-   c:\program files\SpywareBlaster
2009-08-22 22:17 . 2009-08-22 22:17   --------   d-----w-   c:\program files\Trend Micro
2009-08-12 00:25 . 2009-06-04 12:07   2066432   ----a-w-   c:\windows\system32\mstscax.dll
2009-08-11 05:05 . 2009-08-17 16:04   51376   ----a-w-   c:\windows\system32\drivers\aswTdi.sys
2009-08-11 05:05 . 2009-08-17 16:04   23152   ----a-w-   c:\windows\system32\drivers\aswRdr.sys
2009-08-11 05:05 . 2009-08-17 16:02   97480   ----a-w-   c:\windows\system32\AvastSS.scr
2009-08-11 05:05 . 2009-08-17 16:05   114768   ----a-w-   c:\windows\system32\drivers\aswSP.sys
2009-08-11 05:05 . 2009-08-17 16:05   20560   ----a-w-   c:\windows\system32\drivers\aswFsBlk.sys
2009-08-11 05:05 . 2009-08-17 16:10   1279456   ----a-w-   c:\windows\system32\aswBoot.exe
2009-08-11 05:05 . 2009-08-17 16:05   53328   ----a-w-   c:\windows\system32\drivers\aswMonFlt.sys
2009-08-11 05:05 . 2009-08-11 05:05   --------   d-----w-   c:\program files\Alwil Software
2009-08-03 19:07 . 2009-08-03 19:07   403816   ----a-w-   c:\windows\system32\OGACheckControl.dll
2009-08-03 19:07 . 2009-08-03 19:07   322928   ----a-w-   c:\windows\system32\OGAAddin.dll
2009-08-03 19:07 . 2009-08-03 19:07   230768   ----a-w-   c:\windows\system32\OGAEXEC.exe

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-29 03:52 . 2007-12-30 18:45   --------   d-----w-   c:\program files\Dl_cats
2009-08-29 03:51 . 2007-12-21 20:23   12   ----a-w-   c:\windows\bthservsdp.dat
2009-08-29 03:39 . 2009-06-23 01:32   117760   ----a-w-   c:\users\Susan M\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-08-19 01:40 . 2009-02-24 00:46   --------   d-----w-   c:\program files\Java
2009-08-12 00:27 . 2006-11-02 11:18   --------   d-----w-   c:\program files\Windows Mail
2009-08-11 02:38 . 2009-06-23 01:32   --------   d-----w-   c:\program files\SUPERAntiSpyware
2009-08-11 02:28 . 2009-07-11 23:51   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2009-08-11 01:38 . 2009-07-16 04:53   3942048   ----a-w-   c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-09 01:09 . 2007-12-31 22:49   9720   ----a-w-   c:\users\Susan M\AppData\Roaming\wklnhst.dat
2009-08-08 23:04 . 2009-04-02 01:38   --------   d-----w-   c:\program files\Microsoft Silverlight
2009-08-03 17:36 . 2009-07-11 23:51   38160   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 17:36 . 2009-07-11 23:51   19096   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-07-29 12:51 . 2008-09-10 13:08   --------   d-----w-   c:\program files\Dell DataSafe Online
2009-07-29 12:50 . 2008-11-23 05:05   8270752   ----a-w-   c:\users\Susan M\AppData\Roaming\DataSafeDotNet.exe
2009-07-29 12:50 . 2008-11-23 05:05   8270752   ----a-w-   c:\users\Susan M\AppData\Roaming\DataSafeDotNet.exe
2009-07-25 09:23 . 2009-02-24 00:46   411368   ----a-w-   c:\windows\system32\deploytk.dll
2009-07-25 04:13 . 2009-07-25 04:13   713992   ----a-w-   c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-07-21 21:52 . 2009-07-30 05:01   915456   ----a-w-   c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-30 05:01   109056   ----a-w-   c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-30 05:01   71680   ----a-w-   c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-30 05:01   133632   ----a-w-   c:\windows\system32\ieUnatt.exe
2009-07-17 13:54 . 2009-08-12 00:24   71680   ----a-w-   c:\windows\system32\atl.dll
2009-07-15 12:40 . 2009-08-12 00:24   8147456   ----a-w-   c:\windows\system32\wmploc.DLL
2009-07-15 12:39 . 2009-08-12 00:24   313344   ----a-w-   c:\windows\system32\wmpdxm.dll
2009-07-15 12:39 . 2009-08-12 00:24   4096   ----a-w-   c:\windows\system32\dxmasf.dll
2009-07-15 12:39 . 2009-08-12 00:24   7680   ----a-w-   c:\windows\system32\spwmp.dll
2009-06-27 20:47 . 2009-06-27 20:47   709566   ----a-w-   c:\programdata\SPL736E.tmp
2009-06-15 23:15 . 2009-08-12 00:24   439864   ----a-w-   c:\windows\system32\drivers\ksecdd.sys
2009-06-15 14:54 . 2009-08-12 00:24   175104   ----a-w-   c:\windows\system32\wdigest.dll
2009-06-15 14:53 . 2009-07-15 12:37   156672   ----a-w-   c:\windows\system32\t2embed.dll
2009-06-15 14:53 . 2009-08-12 00:24   72704   ----a-w-   c:\windows\system32\secur32.dll
2009-06-15 14:53 . 2009-08-12 00:24   270848   ----a-w-   c:\windows\system32\schannel.dll
2009-06-15 14:53 . 2009-08-12 00:24   218624   ----a-w-   c:\windows\system32\msv1_0.dll
2009-06-15 14:52 . 2009-08-12 00:24   1259008   ----a-w-   c:\windows\system32\lsasrv.dll
2009-06-15 14:52 . 2009-07-15 12:37   23552   ----a-w-   c:\windows\system32\lpk.dll
2009-06-15 14:52 . 2009-08-12 00:24   499712   ----a-w-   c:\windows\system32\kerberos.dll
2009-06-15 14:52 . 2009-07-15 12:37   72704   ----a-w-   c:\windows\system32\fontsub.dll
2009-06-15 14:51 . 2009-07-15 12:37   10240   ----a-w-   c:\windows\system32\dciman32.dll
2009-06-15 12:48 . 2009-08-12 00:24   9728   ----a-w-   c:\windows\system32\lsass.exe
2009-06-15 12:42 . 2009-07-15 12:37   289792   ----a-w-   c:\windows\system32\atmfd.dll
2009-06-13 04:04 . 2006-11-02 10:25   665600   ----a-w-   c:\windows\inf\drvindex.dat
2009-06-10 11:42 . 2009-08-12 00:24   160256   ----a-w-   c:\windows\system32\wkssvc.dll
2009-06-10 11:38 . 2009-08-12 00:24   91136   ----a-w-   c:\windows\system32\avifil32.dll
2007-12-22 04:05 . 2007-12-22 03:55   8192   --sha-w-   c:\windows\Users\Default\NTUSER.DAT
.

(((((((((((((((((((((((((((((   [email protected]_00.00.47   )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-30 18:29 . 2009-08-28 23:23   32768              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-12-30 18:29 . 2009-08-29 03:52   32768              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-12-30 18:29 . 2009-08-29 03:52   32768              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-30 18:29 . 2009-08-28 23:23   32768              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-30 18:29 . 2009-08-29 03:52   16384              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2007-12-30 18:29 . 2009-08-28 23:23   16384              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-04-29 21:26 . 2009-08-29 03:52   245760              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-04-29 21:26 . 2009-08-28 23:23   245760              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-21 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-03-26 29744]
"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2009-07-07 1779952]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 92704]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2007-01-12 292336]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 926\memcard.exe" [2006-11-03 304008]
"DLCXCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-17 4907008]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05   356352   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):91,33,f5,30,dd,eb,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3588662981-376592854-2214661680-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000002

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{F7822FD6-F6D0-4F27-91A7-C0AD1B1CE73A}"= UDP:c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe:Device Monitor
"{BBF1B85C-9643-4C02-BD3C-FA25A6F9BE88}"= TCP:c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe:Device Monitor
"{44FD6BC8-7F41-43A1-9F58-D5CDCA6A9105}"= UDP:c:\program files\Dell Photo AIO Printer 926\dlcxaiox.exe:All In One Center
"{90BC60DF-E730-4E61-8553-2B8C95354F7D}"= TCP:c:\program files\Dell Photo AIO Printer 926\dlcxaiox.exe:All In One Center
"{5141C4D6-F916-4E5F-BBCD-E5F3FC805E18}"= UDP:c:\windows\System32\dlcxcoms.exe:Lexmark Communications System
"{555B5C3C-690B-4093-9958-548FD832EF6E}"= TCP:c:\windows\System32\dlcxcoms.exe:Lexmark Communications System
"{09F02723-E8DC-45BC-B597-CED5202C2053}"= Disabled:UDP:135:TCP Port 135
"{E4E2D9D1-38EB-458A-853C-5E570C668A6A}"= Disabled:UDP:5000:TCP Port 5000
"{8930DE8D-6342-40F7-B226-E2D29B3749E2}"= Disabled:UDP:5001:TCP Port 5001
"{B68E5541-B4A1-49C4-8541-1CA11A153574}"= Disabled:UDP:5002:TCP Port 5002
"{9383E65A-FB56-4452-9170-8AF1145134E5}"= Disabled:UDP:5003:TCP Port 5003
"{9AD3CFDB-563C-423D-AF13-6139D94A7BE8}"= Disabled:UDP:5004:TCP Port 5004
"{FB2775F1-A7D2-47D3-B44F-BD45DD501FA5}"= Disabled:UDP:5005:TCP Port 5005
"{9C9104CA-5C33-42DB-9EC6-4B913D1C9387}"= Disabled:UDP:5006:TCP Port 5006
"{9BA2B06B-3350-40CE-82CE-A6A24181BB60}"= Disabled:UDP:5007:TCP Port 5007
"{BCA0B46D-96C8-4591-9B76-C092D1FEDFB3}"= Disabled:UDP:5008:TCP Port 5008
"{F62C0116-57CF-4E62-9B29-581269121CF4}"= Disabled:UDP:5009:TCP Port 5009
"{83F76203-F020-46D3-8632-B19A04E36EE6}"= Disabled:UDP:5010:TCP Port 5010
"{E5EC9F2D-D603-4C5D-90F4-89DE21F04C3F}"= Disabled:UDP:5011:TCP Port 5011
"{64B4E585-7F91-4F66-AB9B-52B3D5F87E4C}"= Disabled:UDP:5012:TCP Port 5012
"{0B64EFC9-3170-4C27-8B4E-CD72F1D271D8}"= Disabled:UDP:5013:TCP Port 5013
"{F18631F7-456F-493A-8015-F92EEF249626}"= Disabled:UDP:5014:TCP Port 5014
"{EC80A2F9-608E-4565-84A6-6C09F23935FA}"= Disabled:UDP:5015:TCP Port 5015
"{A7CE6CE9-35EF-4F90-AF9A-07BA5015B253}"= Disabled:UDP:5016:TCP Port 5016
"{85536E9B-0CA0-4BDF-9688-18363CB7C91B}"= Disabled:UDP:5017:TCP Port 5017
"{C8111B12-510B-4B77-BBA5-AC98074626F4}"= Disabled:UDP:5018:TCP Port 5018
"{0FE1E5F5-682B-4063-B281-29D250911D38}"= Disabled:UDP:5019:TCP Port 5019
"{7F7A26C4-ED89-4A15-93CB-B4CB9F633419}"= Disabled:UDP:5020:TCP Port 5020
"{A0309D64-84C6-4595-9D74-C8ED3AD93864}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{3BF97467-1B54-46DA-986F-132DFD17D223}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{080DC243-A175-4EA0-AF2F-D65824C4F48C}c:\\program files\\popcap games\\alchemy deluxe\\winalch.exe"= UDP:c:\program files\popcap games\alchemy deluxe\winalch.exe:WinAlch
"UDP Query User{2DB51784-3EEF-4CC0-A4BC-0CC3A5C6465F}c:\\program files\\popcap games\\alchemy deluxe\\winalch.exe"= TCP:c:\program files\popcap games\alchemy deluxe\winalch.exe:WinAlch
"{B5A4A89A-5F98-4D80-BBCE-8250779AC25C}"= UDP:c:\windows\System32\dlcxcoms.exe:Lexmark Communications System
"{94FA2DBB-D677-420C-A5B5-5A2FDC57060C}"= TCP:c:\windows\System32\dlcxcoms.exe:Lexmark Communications System
"{9DF1615C-182A-4560-9A61-A341AD56A4F2}"= UDP:c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe:Device Monitor
"{C8AA90C9-F508-43F6-ACC4-5F19FA0CC2A6}"= TCP:c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe:Device Monitor
"{BD893CB9-D840-4005-8523-71F1CF74607F}"= UDP:c:\program files\Dell Photo AIO Printer 926\dlcxaiox.exe:All In One Center
"{A28901B6-CBA9-48AD-A979-4FD5AB4054BD}"= TCP:c:\program files\Dell Photo AIO Printer 926\dlcxaiox.exe:All In One Center
"{9BDDD5D0-5870-4717-A362-A803560E1604}"= UDP:c:\users\Susan M\Desktop\HouseCall.exe:HouseCall.exe
"{F43BC75E-E07C-41BF-A1FD-51839A4312FB}"= TCP:c:\users\Susan M\Desktop\HouseCall.exe:HouseCall.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)

R3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-03-26 29744]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-05-26 7408]
S1 aswSP;avast! Self Protection;


S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-05-26 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-08-11 74480]
S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-05 77824]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-08-17 20560]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2009-08-17 53328]
S2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe [2006-10-11 532480]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs   REG_MULTI_SZ      BthServ
WindowsMobile   REG_MULTI_SZ      wcescomm rapimgr
LocalServiceRestricted   REG_MULTI_SZ      WcesComm RapiMgr

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-08-29 c:\windows\Tasks\User_Feed_Synchronization-{34BB2544-E314-4CD1-A261-BD1AA15CAABB}.job
- c:\windows\system32\msfeedssync.exe [2009-07-30 20:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.comcast.net/a/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: comcast.net\www
FF - ProfilePath - c:\users\Susan M\AppData\Roaming\Mozilla\Firefox\Profiles\wlpwrnl4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/a/
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-28 23:52
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  DLCXCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,[email protected]??

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\System32\drivers\XAudio.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\System32\rundll32.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehmsas.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2009-08-29 23:58 - machine was rebooted
ComboFix-quarantined-files.txt  2009-08-29 03:58
ComboFix2.txt  2009-08-29 00:03

Pre-Run: 236,156,841,984 bytes free
Post-Run: 235,897,585,664 bytes free

247   --- E O F ---   2009-08-28 12:30


npersn31Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /u in the runbox
* Make sure there's a space between Combofix and /u
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

----------

Use the Kaspersky Lab Online Scanner

In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

  • Click on SCAN NOW
  • Click ACCEPT.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
  • The scan will take a while, so be patient and let it finish.
When the scan is done, in the Scan is complete window, any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.

To obtain the report:
Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop.
  • In the File name area use KScan, or SOMETHING similar.
  • In Save as type: click the drop arrow and select: Text file [*.txt]
  • Then, click: Save


Copy and paste the Kaspersky Online Scanner Report in your next reply.

Note for Internet Explorer 7 and 8 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.

If needed, this animation will guide you through the process.I am concerned about what should be on and when as I am afraid stuff will interfer with other stuff, including stuff that appears in the tray, stuff that appears to the right of the Windows 'pearl'(Belarc icon, computer icon, internet explorer icon,Office Note 2007icon,Display Desktop icon,Firefox icon, Windows Media icon,Switch between windows icon,Spybot Search and Destroy icon [Tea timer icon not currently in system tray.]). In system tray upon start up/restart are Dell Support Center,Google Desktop[Desktop currently has both Google gadget icon and Google side bar],the button with options to add google gadgets(hides/shows sidebar),Dell Data Online,Avast, Avast Virus Recovery Database Generator icon,network icon,Realtek HD Audio Manager icon,  and Safely remove hardware icon. What do I need to do about these?

And now for the major questions:
Questions to be answered before I run this:
1) I know where to find Tools on Internet Explorer favorites bar and from there Internet options and on General tab under Browsing History find Delete. I find :preserve favorites website data; temporary internet files;cookies;history;form data;passwords;InPrivate filtering data. Under this there is a delete button and a cancel button. I think that the Disk Cleanup used to have a regularly scheduled time, but when I had McAfee I got rid of that and McAfee's default cleaning as it was messing with D: where shadow copies are causing unauthorized access message in Event Viewer. How do I delete temporary internet files and temporary files?

2)What must be off when I run this Combo /u?  I have turned on everything back on/or options
to have in tray when run (SuperAntiSpyware Free) in order to go onto the internet. Does the firewall need to be off? And when I go back on to run TFC by OldTimer what do I do? 
Do I turn stuff off for the online download, and then, while modem is on standby, turn everything off? Then run TFC.exe?

3)What about that start up magnifier, the Dell Support Center in the tray, and the google gadget button with the google sidebar(on right side of screen)? Also,Dell Data online is in the tray upon start up? Will these interfer with anything?

4)After TfC.exe run: turn Windows firewall on with everything else off to do Kaspersky run? 

5)Will Kaspersky let me choose settings before it starts scan? I looked at your automation for Kaspersky and noticed that you need to run Internet Explorer as administrator and I have no such option. What do I do about this?

6)What about dds.scr which is still on my desktop?

7)What about the C:\Program Files\Trend Micro\sniper.exe?  The sniper shortcut on desk top and the downloaded sniper2.exe? I had problems with the renaming....

8)Any special instructions for Spyware Blaster and SpyBot Search and Destroy?  Tea time is still off --- I assume so since I have not gone back to Advanced Mode to turn it on.

9)I don't know if you need to know about PEB Corruption error that showed up in Problem reports in Windows vista(date of entry August 28). Do you?

Sorry for the list of concerns and questions but I don't want to mess up.  I think the last thing we tried had to do with siv, a program that I uninstalled long ago and tried to get it out of the registry without success. Also a long time ago a computer repair person put a marker in the registry--I think--so someone who knew what they were doing would find it.Did you read my list of questionable programs in an earlier post in this thread? Trying to make sure all the bases get covered! Thanks so much for the help thus far.
npersn31 Quote
How do I delete temporary internet files and temporary files?

You will be doing that by running TFC from my prior instructions.

Quote
What must be off when I run this Combo /u?

Nothing needs to be turned off. Just run Combo /u and then TFC.

Quote
Will Kaspersky let me choose settings before it starts scan?

All of the options should already be set.

Quote
I looked at your automation for Kaspersky and noticed that you need to run Internet Explorer as administrator and I have no such option. What do I do about this?

Right click the Internet Explorer icon in the system tray (bottom left) and choose Runs as Administrator.

Quote
What about dds.scr which is still on my desktop?

Delete it.

Quote
What about the C:\Program Files\Trend Micro\sniper.exe

Leave it for now. When we are done you can uninstall it in Add or Remove Programs.

Quote
Any special instructions for Spyware Blaster and SpyBot Search and Destroy?  Tea time is still off

Leave Tea Timer off. Don't worry about Spywareblaster.

Quote
I don't know if you need to know about PEB Corruption error that showed up in Problem reports in Windows vista(date of entry August 28). Do you?

I have no clue what that is. Just run Kaspersky so we can see if any malware is left. Then we will deal with any remaining issues.







Instructions followed; many files deleted, clicked IE 8 icon near pearl to run as administrator. Still got message that with Windows Vista you must run Kaspersky as administrator. Report follows.  Did remove dds.scr to Recycle Bin and from there deleted it [after Combofix removal.] TFC.exe still on desktop. Npersn31 calling it a night. Reply when convenient and thanks!
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
 Sunday, August 30, 2009
 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002)
 Kaspersky Online Scanner version: 7.0.26.13
 Last database update: Sunday, August 30, 2009 03:34:54
 Records in database: 2718240
--------------------------------------------------------------------------------

Scan settings:
   scan using the following database: extended
   Scan archives: yes
   Scan e-mail databases: yes

Scan area - My Computer:
   C:\
   D:\
   E:\
   F:\

Scan statistics:
   Objects scanned: 110011
   Threats found: 0
   Infected objects found: 0
   Suspicious objects found: 0
   Scan duration: 01:52:19

No threats found. Scanned area is clean.

Selected area has been scanned.
Quote
PEB Corruption error

Are you sure this is spelled right?Evilfantasy: Here is the text taken from the Event viewer-----and you tell me!

Product
PEB_CORRUPTION

Problem
Driver host process disconnect

Date
8/28/2009 11:45 PM

Status
Report Sent

Description
The Windows User-Mode Driver Framework detected that a driver host-process disconnected unexpectedly. 
This report contains information about the process and the drivers running within and will be used to improve the quality of these drivers.

Problem signature
Problem Event Name:   WUDFHostProblem
EventClass:   HostProblem
Problem:   HostDisconnect
DetectedBy:   2
UMDFVersion:   6.0.6001.18000. (longhorn_rtm.080118-1840)
ExitCode:   ffffffffffffffff
Operation:   0
Message:   0
Status:   ffffffff
OS Version:   6.0.6002.2.2.0.768.3
Locale ID:   1033

Extra information about the problem
Bucket ID:   169643709
I have more details about what has been going on ,but don't have the time yet.
npersn31 signing off.That error is most likely not malware related so we can finish up here. Post the information about the error in the Microsoft Windows forum and someone there will help. I deal with malware...

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Evilfantasy, lots of files were deleted but quarantine in SuperAntiSpyware was not affected.Trace.Known Threat Sources
   C:\Users\Susan M\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZE8Y5QVT\IMGRogue-WiniFighter_Small[1].gif
was still in quarantine and whether it was adviseable to remove,  it has been done.  I also checked to see if anything from McAfee had been forgotten and it had: some logs from McAfee(exported text),some logs from McAfee Virtual TECHNICIAN (html form),McAfee manuals(Adobe Acrobat pdf). I am going to remove these. Last hjt that I ran just to see what it looked like after all this(including reverted to last known good configuration with Combofix problem and not having ever removing/stopping any restore points before running a/v) showed:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/a/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: ::1 localhost

Which doesn't take me where I want to go--- most of them.
Im not sure what I am going to do next. The Avast questions, I guess I'll have to ask in Avast forum and ask about Windows firewall elsewhere too. Internet Explorer not having administrative rights is puzzling since when I had attempted to use BitDefender scanner I used administrative rights selection from a shortcut on my desktop instead of the one to the right of the 'pearl'.
npersn31All of the entries in the HJT log are legitimate. You don't have to worry about them or you can fix them with HJT.

What is wrong with Avast and Windows Firewall?Before I forget,I hope you don't take this as a request for instant help---I appreciate the help when it comes. Also I still have the Oldtimer executable on my desktop: what does it take to get this removed?

In reference to your question about Avast and my firewall, I would refer you to the hjt that I just used the tool to evaluate  but I cannot figure how to get back to the evaluation. This evaluation did not recognize my firewall. As for what is wrong with Avast, I cannot get it to scan my email in my Windows Mail inbox. I do not understand their settings and what they mean by redirected email. I don't think that I used your method to run IE 8 as administrator when installing Avast and am wondering if I need to reinstall it. What do you think?

Also there seems to be a reference to McAfee here:O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5551/mcfscan.cab. What about it?

Here is the HJT that I used:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:03:18 PM, on 9/1/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/a/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar NOTIFIER BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [dlcxmon.exe] "C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 926\memcard.exe"
O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,[email protected]
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - http://support.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5551/mcfscan.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: dlcx_device -   - C:\Windows\system32\dlcxcoms.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 7140 bytes
npersn31 Quote
Also I still have the Oldtimer executable on my desktop: what does it take to get this removed?

Just delete it.

Quote
In reference to your question about Avast and my firewall, I would refer you to the hjt that I just used the tool to evaluate  but I cannot figure how to get back to the evaluation. This evaluation did not recognize my firewall. As for what is wrong with Avast, I cannot get it to scan my email in my Windows Mail inbox. I do not understand their settings and what they mean by redirected email. I don't think that I used your method to run IE 8 as administrator when installing Avast and am wondering if I need to reinstall it. What do you think?

Your files are scanned automatically. You don't need to do anything.

Quote
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5551/mcfscan.cab

Fix it with HJT.evil fantasy, I ran the Secunia Software Inspector and it ran over an hour, hanging up on D:---or so it seemed to me. I ran it after updating Java 6 update 15 to Java 6 update 16. Backtracking a second, recall that the Internet explorer 8 shortcut as well as the Internet explorer "e" icon on the desktop had no "run as administrator" option available in previous steps of this malware chase, I have used the one in the tray to create a new "launch Internet Explorer" shortcut with the option desired. Using this shortcut and the available "run as administrator" option, I ran the Secunia Inspector in Internet Explorer 8[I do have Foxfire, but not as default browser.] I am logged in as administrator, so I don't know if this was necessary or not---right clicking the option, that is. Just making sure circumstances surrounding the "hanging up" on D: are clearly understood. D: has the "shadow copies" and is not a separate drive from C:. The insecure programs were listed as the process went on and 8 programs were listed as found, 3 were insecure,5 were patched.  I choose to go directly to sites to get the updates. Adobe Flash, Adobe Acrobat Reader,and Mozilla Foxfire were the insecure ones.

I have had second thoughts about those legitimate sites you said I could take out using HJT. I have asked someone about the PEB corruption, and am wondering if my administrative rights questions are too much to ask. I have not posted any internet explorer questions yet.


If you think this is ok, we can end this thread. I wait your reply and thank you so much for your patience and help.
npersn31Yes we can wrap this up now.
1459.

Solve : Tidserv, Packed Mystic, Bogus AV, etc?

Answer»

You're WELCOME, CHUCK. KEEP SAFE

1460.

Solve : Got problems, virus or malware?

Answer»

Hey folks,

My boy opened his computer and saw the alert that "Windows security alert. Windows reports that computer is infected, and TRIES to steer you to update to some fix.  1)I have Bitdefender and it is up to DATE. 2)Firewall is enabled through Bitdefender 3)Had to GO to Safe Mode to populate Add-Remove programs removed LoudMo Contexual Adware(saw nothing else) 4)Ran CCleaner Slim in SafeMode and deleted all cookies 5)SuperAntispyware would not load in Safe or regular mode (message SAID 'system admin has set policies to prevent this installation'6)Loaded MBAM in safemode (could not get to net to update in either mode)attached a quick scan and full scan log.  7)Will not let me get to the net to update java Could not load HijackThis in regular mode, but did in SafeMode.  Cant get to net, open programs in desktop.  Please help when you get time and thanks for the help

[Saving space, attachment deleted by admin]Hi

It is probably a rogue.

Download OTL  to your Desktop

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\*.exe /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%SYSTEMDRIVE%\*.*
%PROGRAMFILES%\*.
netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
adp3132.sys
mv61xx.sys
/md5stop
CREATERESTOREPOINT
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time
1461.

Solve : Need Help Opening My Programs!!!?

Answer»

I recently had a COMPUTER problem, where it was telling me i had no firewall, and wouldn't let me GO on mozilla. I installed Super antispyware thinking it would work, it showed alot of viruses and trojans amongst other things . When i deleted all the intrusions, it asked to restart and when i did, i can't click on any of my icons or my system restore, everytime i click on them it brings up a open with, and when i go to the program and click on it it won't work. When i try to go to my control panel and try to click on any icons there it says application not found. Now i am completely lost in what this is or how to fix it. I am up for any HELP here.......Go to this link to create a Rescue CD or to this site to create a Rescue USB. Carefully follow all the instructions for whichever method you choose.i don't get it, i did everything they instructed me to do. With the avira rescue cd i waited 1 1/2 HRS because it SAID it was loading modules and never loaded, and i can't start a scan until it finishes loading modules. With the weblive cd i got to the point to start the scan but when i get to it my mouse doesn't work and i can't go to start scan as if it froze up. Any suggestions....I couldn't get it to work, i scanned the computer and it found 177 warnings, and 7 records. It didn't delete any of them or repair any of them. I don't where i was suppose to delete them. but i still have th problem.

Did you create the Rescue CD on a clean computer?

1462.

Solve : MSE wants to UPGRADE but wont??

Answer»

Quote

I tried to download and install the updates but have been continually failed as the Microsoft installer seems to be inoperative/corrupted, inaccessible.
Are you getting any errors when you try this?Yes SuperDave, the Windows Installer seems to be the main problem.
Quote from: ImnoGuru on March 22, 2011, 07:58:57 PM
I went there and did Dial-a-Fix and it came back with,

1. Windows Installer access denied.

2. Dial-a-fix error code 2147467259 was encountered while trying to unregister C:\windows\system32\msxml3.dll. Error text is unspecified error.

After that there are a string of other error codes from Dial-a-Fix. There were that many that copying them became excessive, so I photographed them as they came up.

Other updates that I have tried also fail with the primary fail message "Windows Installer cannot be accessed." There are no other error messages from the Windows Installer other than "Access denied".

It seems a general, across the board problem that all other fails COME up with as well, such as Abobe Reader update "Error 1604", MSE and others.


I guess maybe I should start looking for my Windows CD.What I meant was were there any error messages when you try to get the Windows updates?
Let's try this to make sure there are no corrupt files.

Do you have an XP CD?

If so, place it in your CD ROM drive and follow the instructions below:
•Click on Start > Run and type sfc /scannow then press Enter (note the space between scf and /scannow)
*Let this run undisturbed until the window with the blue  progress bar goes away
SFC - Which stands for System File Checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.SuperDave, over the years I have got/bought/inherited/found several copies of XP (and you must admit by todays STANDARDS XP is a bit outdated), and I am not sure which one is on this computer.
I suppose that I should just keep this computer as XP Pro and that is that.

Is there a way to find out which CD is the right one for this computer (usually I write it on the CD)?

I have in the past tried the wrong CD in different machines and it tries to install a new copy all the time.
Can I find out the Registration Key Code from the machine somewhere?

I have 2 here in front of me with different key codes. A slipstream bootable CD of W2K and another that says it is service pack 3 (probably this one), and then there are my laptops which should have new CD's for each x 3 for Vista?
( I mean obviously not the Vista ones, what I was thinking is, is it worth upgrading to Vista maybe? Or would that cause more problems for me?

Oh my head hurts...
Lets just stick to the CD's and reg keys OK.
Thank you ImnoGuru.  Quote
Is there a way to find out which CD is the right one for this computer (usually I write it on the CD)?
If you right-click on My Computer and select Properties the info. should be there under the General tab.Or, you could just run SFC. If it asks for a disk, just insert the ones you have.

Quote
I have in the past tried the wrong CD in different machines and it tries to install a new copy all the time.
SFC will not install a new copy.I tried all the CD's I had found SuperDave, but none of them were the right disk.

"Start run SFD" went through the check, but none of the files were accepted and I had to click the "skip file" box all the way through.

Right now, I dont seem to have this Windows install CD. 

Actually just thinking deeply about it ... I think I inherited this machine from someone.
Which means of course that I dont have access to the original install disk.

I remember at one time recently that Patio recommended I use Macrium Reflect to take a copy of the drive, which I did, to an external hard drive.
Would that be able to help with this problem SuperDave?

Thank you ImnoGuru.From what you're telling me, there is a problem with some of the Windows files. If you made a copy of your harddrive, you could use it to restore your computer back to when the copy was made and you should be back in business. I will check with my buddy to see if there's anything else we can.
  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • Click the Report button and copy/paste the contents of it into your next reply
Note:It will also create a log in the C:\ directory..
**************************************************
Download OTL  to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in
netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%SYSTEMDRIVE%\*.exe
%systemroot%\*. /mp /s
c:\$recycle.bin\*.* /s
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
nvstor32.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
explorer.exe
svchost.exe
userinit.exe
qmgr.dll
ws2_32.dll
proquota.exe
imm32.dll
kernel32.dll
ndis.sys
autochk.exe
spoolsv.exe
xmlprov.dll
ntmssvc.dll
mswsock.dll
Beep.SYS
ntfs.sys
termsrv.dll
sfcfiles.dll
st3shark.sys
ahcix86.sys
srsvc.dll
nvrd32.sys
/md5stop
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time
Thanks SuperDave, I ran the TDSSKiller and got this report.

2011/03/30 15:14:05.0218 4232   TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
2011/03/30 15:14:07.0218 4232   ================================================================================
2011/03/30 15:14:07.0218 4232   SystemInfo:
2011/03/30 15:14:07.0218 4232   
2011/03/30 15:14:07.0218 4232   OS Version: 5.1.2600 ServicePack: 3.0
2011/03/30 15:14:07.0218 4232   Product type: Workstation
2011/03/30 15:14:07.0218 4232   ComputerName: DELLCOMPUTER1
2011/03/30 15:14:07.0218 4232   UserName: Administrator
2011/03/30 15:14:07.0218 4232   Windows directory: C:\WINDOWS
2011/03/30 15:14:07.0218 4232   System windows directory: C:\WINDOWS
2011/03/30 15:14:07.0218 4232   Processor architecture: Intel x86
2011/03/30 15:14:07.0218 4232   Number of processors: 1
2011/03/30 15:14:07.0218 4232   Page size: 0x1000
2011/03/30 15:14:07.0218 4232   Boot type: Normal boot
2011/03/30 15:14:07.0218 4232   ================================================================================
2011/03/30 15:14:08.0656 4232   Initialize success
2011/03/30 15:14:53.0421 5668   ================================================================================
2011/03/30 15:14:53.0421 5668   Scan started
2011/03/30 15:14:53.0421 5668   Mode: Manual;
2011/03/30 15:14:53.0421 5668   ================================================================================
2011/03/30 15:14:53.0796 5668   ACPI            (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/03/30 15:14:53.0859 5668   ACPIEC          (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2011/03/30 15:14:53.0968 5668   aec             (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/03/30 15:14:54.0093 5668   AFD             (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2011/03/30 15:14:54.0625 5668   Aspi32          (20d04091eba710f6988f710507d85868) C:\WINDOWS\system32\drivers\Aspi32.sys
2011/03/30 15:14:54.0671 5668   AsyncMac        (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/03/30 15:14:54.0703 5668   atapi           (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/03/30 15:14:54.0781 5668   Atmarpc         (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/03/30 15:14:54.0843 5668   audstub         (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/03/30 15:14:54.0937 5668   AVGIDSDriver    (0c61f066f4d94bd67063dc6691935143) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
2011/03/30 15:14:55.0000 5668   AVGIDSEH        (84853f800cd69252c3c764fe50d0346f) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
2011/03/30 15:14:55.0046 5668   AVGIDSFilter    (28d6adcd03e10f3838488b9b5d407dd4) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
2011/03/30 15:14:55.0109 5668   AVGIDSShim      (0eb16f4dbbb946360af30d2b13a52d1d) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
2011/03/30 15:14:55.0140 5668   Avgldx86        (5fe5a2c2330c376a1d8dcff8d2680a2d) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
2011/03/30 15:14:55.0187 5668   Avgmfx86        (54f1a9b4c9b540c2d8ac4baa171696b1) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
2011/03/30 15:14:55.0218 5668   Avgrkx86        (8da3b77993c5f354cc2977b7ea06d03a) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
2011/03/30 15:14:55.0281 5668   Avgtdix         (660788ec46f10ece80274d564fa8b4aa) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
2011/03/30 15:14:55.0359 5668   Beep            (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/03/30 15:14:55.0453 5668   Ca533av         (a8eae8e358de3a21e6eb54f4fc7f65ec) C:\WINDOWS\system32\Drivers\Ca533av.sys
2011/03/30 15:14:55.0531 5668   cbidf2k         (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/03/30 15:14:55.0578 5668   CCDECODE        (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/03/30 15:14:55.0656 5668   Cdaudio         (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/03/30 15:14:55.0687 5668   Cdfs            (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/03/30 15:14:55.0718 5668   Cdrom           (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/03/30 15:14:55.0953 5668   Disk            (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/03/30 15:14:56.0015 5668   dmboot          (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2011/03/30 15:14:56.0062 5668   dmio            (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
2011/03/30 15:14:56.0078 5668   dmload          (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/03/30 15:14:56.0140 5668   DMusic          (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/03/30 15:14:56.0265 5668   drmkaud         (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/03/30 15:14:56.0375 5668   E100B           (98b46b331404a951cabad8b4877e1276) C:\WINDOWS\system32\DRIVERS\e100b325.sys
2011/03/30 15:14:56.0546 5668   Fastfat         (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/03/30 15:14:56.0578 5668   Fdc             (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2011/03/30 15:14:56.0609 5668   Fips            (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2011/03/30 15:14:56.0640 5668   Flpydisk        (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2011/03/30 15:14:56.0703 5668   FltMgr          (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
2011/03/30 15:14:56.0765 5668   Fs_Rec          (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/03/30 15:14:56.0796 5668   Ftdisk          (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/03/30 15:14:56.0859 5668   giveio          (77ebf3e9386daa51551af429052d88d0) C:\WINDOWS\system32\giveio.sys
2011/03/30 15:14:56.0921 5668   Gpc             (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/03/30 15:14:57.0046 5668   HidUsb          (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/03/30 15:14:57.0125 5668   HPZid412        (30ca91e657cede2f95359d6ef186f650) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
2011/03/30 15:14:57.0156 5668   HPZipr12        (efd31afa752aa7c7bbb57bcbe2b01c78) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
2011/03/30 15:14:57.0218 5668   HPZius12        (7ac43c38ca8fd7ed0b0a4466f753e06e) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
2011/03/30 15:14:57.0296 5668   HTTP            (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/03/30 15:14:57.0406 5668   i8042prt        (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/03/30 15:14:57.0500 5668   ialm            (da58a8be6a445835f603720c4bc8837e) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
2011/03/30 15:14:57.0593 5668   Imapi           (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/03/30 15:14:57.0656 5668   InCDfs          (868883fb2c9ab158df2a5015837e2f3a) C:\WINDOWS\system32\drivers\InCDfs.sys
2011/03/30 15:14:57.0671 5668   InCDPass        (15d32c0e4b24276e76f180b508f5deba) C:\WINDOWS\system32\DRIVERS\InCDPass.sys
2011/03/30 15:14:57.0734 5668   InCDrec         (dbfb05d659500a268797bbc32f3742f0) C:\WINDOWS\system32\drivers\InCDrec.sys
2011/03/30 15:14:57.0812 5668   incdrm          (9d1adfe6ce5c2e2a42f3b8aa57821d87) C:\WINDOWS\system32\drivers\incdrm.sys
2011/03/30 15:14:58.0062 5668   IntelIde        (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
2011/03/30 15:14:58.0125 5668   intelppm        (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/03/30 15:14:58.0171 5668   Ip6Fw           (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
2011/03/30 15:14:58.0218 5668   IpFilterDriver  (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/03/30 15:14:58.0250 5668   IpInIp          (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/03/30 15:14:58.0312 5668   IpNat           (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/03/30 15:14:58.0390 5668   IPSec           (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/03/30 15:14:58.0484 5668   IRENUM          (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/03/30 15:14:58.0625 5668   isapnp          (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/03/30 15:14:58.0687 5668   Kbdclass        (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/03/30 15:14:58.0765 5668   kbdhid          (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
2011/03/30 15:14:58.0843 5668   kmixer          (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/03/30 15:14:58.0890 5668   KSecDD          (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/03/30 15:14:59.0000 5668   mnmdd           (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/03/30 15:14:59.0078 5668   Modem           (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2011/03/30 15:14:59.0125 5668   Mouclass        (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/03/30 15:14:59.0203 5668   mouhid          (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/03/30 15:14:59.0234 5668   MountMgr        (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/03/30 15:14:59.0296 5668   MpFilter        (c98301ad8173a2235a9ab828955c32bb) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
2011/03/30 15:14:59.0343 5668   MRxDAV          (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/03/30 15:14:59.0437 5668   MRxSmb          (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/03/30 15:14:59.0484 5668   Msfs            (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/03/30 15:14:59.0562 5668   MSKSSRV         (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/03/30 15:14:59.0609 5668   MSPCLOCK        (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/03/30 15:14:59.0640 5668   MSPQM           (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/03/30 15:14:59.0687 5668   mssmbios        (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/03/30 15:14:59.0765 5668   MSTEE           (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/03/30 15:14:59.0796 5668   Mup             (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2011/03/30 15:14:59.0859 5668   NABTSFEC        (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/03/30 15:14:59.0921 5668   NCHSSVAD        (e78ce4b8e70ccc1a6e63008c3660867c) C:\WINDOWS\system32\drivers\nchssvad.sys
2011/03/30 15:15:00.0109 5668   NDIS            (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/03/30 15:15:00.0156 5668   NdisIP          (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/03/30 15:15:00.0203 5668   NdisTapi        (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/03/30 15:15:00.0265 5668   Ndisuio         (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/03/30 15:15:00.0312 5668   NdisWan         (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/03/30 15:15:00.0390 5668   NDProxy         (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/03/30 15:15:00.0546 5668   NetBIOS         (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/03/30 15:15:00.0593 5668   NetBT           (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/03/30 15:15:00.0750 5668   Npfs            (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/03/30 15:15:00.0812 5668   Ntfs            (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/03/30 15:15:00.0890 5668   Null            (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/03/30 15:15:00.0921 5668   NwlnkFlt        (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/03/30 15:15:00.0953 5668   NwlnkFwd        (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/03/30 15:15:01.0031 5668   Parport         (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
2011/03/30 15:15:01.0062 5668   PartMgr         (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/03/30 15:15:01.0093 5668   ParVdm          (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/03/30 15:15:01.0156 5668   PCI             (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/03/30 15:15:01.0218 5668   PCIIde          (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\drivers\PCIIde.sys
2011/03/30 15:15:01.0265 5668   Pcmcia          (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
2011/03/30 15:15:01.0343 5668   PCTAppEvent     (cc174f32cc9c18ea3109c4b0fc2ca8df) C:\WINDOWS\system32\drivers\PCTAppEvent.sys
2011/03/30 15:15:01.0421 5668   PCTFW-PacketFilter (4a7ef973fcd9c6cad6040ebb61262a5c) C:\WINDOWS\system32\drivers\pctNdis-PacketFilter.sys
2011/03/30 15:15:01.0484 5668   pctgntdi        (d15669bd3e1cf18f00b46a7949ea541f) C:\WINDOWS\system32\drivers\pctgntdi.sys
2011/03/30 15:15:01.0562 5668   pctNDIS         (8bbe917bc4da64b0ba8db33d4c0e0b7d) C:\WINDOWS\system32\DRIVERS\pctNdis.sys
2011/03/30 15:15:01.0671 5668   pctplfw         (6d74df36716a458619a62dd764fc4f8b) C:\WINDOWS\system32\drivers\pctplfw.sys
2011/03/30 15:15:02.0218 5668   PptpMiniport    (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/03/30 15:15:02.0390 5668   pssnap          (32c45180bbc19abeb5742b5b9dc4b8d7) C:\WINDOWS\system32\DRIVERS\pssnap.sys
2011/03/30 15:15:02.0453 5668   Ptilink         (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/03/30 15:15:02.0515 5668   QCDonner        (fddd1aeb9f81ef1e6e48ae1edc2a97d6) C:\WINDOWS\system32\DRIVERS\OVCD.sys
2011/03/30 15:15:02.0703 5668   RasAcd          (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/03/30 15:15:02.0765 5668   Rasl2tp         (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/03/30 15:15:02.0828 5668   RasPppoe        (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/03/30 15:15:02.0859 5668   Raspti          (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/03/30 15:15:02.0906 5668   Rdbss           (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/03/30 15:15:02.0937 5668   RDPCDD          (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/03/30 15:15:03.0000 5668   rdpdr           (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/03/30 15:15:03.0078 5668   RDPWD           (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/03/30 15:15:03.0156 5668   redbook         (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/03/30 15:15:03.0359 5668   SASKUTIL        (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
2011/03/30 15:15:03.0421 5668   Secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/03/30 15:15:03.0515 5668   senfilt         (b9c7617c1e8ab6fdff75d3c8dafcb4c8) C:\WINDOWS\system32\drivers\senfilt.sys
2011/03/30 15:15:03.0578 5668   serenum         (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2011/03/30 15:15:03.0718 5668   Serial          (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
2011/03/30 15:15:03.0875 5668   Sfloppy         (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/03/30 15:15:03.0984 5668   SLIP            (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/03/30 15:15:04.0031 5668   smwdm           (c6d9959e493682f872a639b6ec1b4a08) C:\WINDOWS\system32\drivers\smwdm.sys
2011/03/30 15:15:04.0109 5668   speedfan        (5d6401db90ec81b71f8e2c5c8f0fef23) C:\WINDOWS\system32\speedfan.sys
2011/03/30 15:15:04.0218 5668   splitter        (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/03/30 15:15:04.0312 5668   sr              (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/03/30 15:15:04.0375 5668   Srv             (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/03/30 15:15:04.0453 5668   sscdbus         (2d4027c46b4c6e45875e3c4ba3f67492) C:\WINDOWS\system32\DRIVERS\sscdbus.sys
2011/03/30 15:15:04.0500 5668   sscdmdfl        (f548f1eba107bc19e91189e6a460bd0e) C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys
2011/03/30 15:15:04.0531 5668   sscdmdm         (71d348d53597379dfe1de255d70af13c) C:\WINDOWS\system32\DRIVERS\sscdmdm.sys
2011/03/30 15:15:04.0593 5668   StarOpen        (306521935042fc0a6988d528643619b3) C:\WINDOWS\system32\drivers\StarOpen.sys
2011/03/30 15:15:04.0640 5668   streamip        (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/03/30 15:15:04.0687 5668   swenum          (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/03/30 15:15:04.0750 5668   swmidi          (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/03/30 15:15:04.0890 5668   sysaudio        (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/03/30 15:15:05.0000 5668   Tcpip           (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/03/30 15:15:05.0078 5668   TDPIPE          (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/03/30 15:15:05.0125 5668   TDTCP           (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/03/30 15:15:05.0187 5668   TermDD          (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/03/30 15:15:05.0296 5668   Udfs            (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/03/30 15:15:05.0375 5668   Update          (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/03/30 15:15:05.0468 5668   usbaudio        (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
2011/03/30 15:15:05.0609 5668   USBCamera       (0c28dd9ec68ccb6e95d49bfd24fd2c11) C:\WINDOWS\system32\Drivers\Bulk533.sys
2011/03/30 15:15:05.0734 5668   usbccgp         (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/03/30 15:15:05.0781 5668   usbehci         (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/03/30 15:15:05.0812 5668   usbhub          (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/03/30 15:15:05.0875 5668   usbprint        (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/03/30 15:15:05.0890 5668   usbscan         (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/03/30 15:15:05.0953 5668   USBSTOR         (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/03/30 15:15:06.0000 5668   usbuhci         (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/03/30 15:15:06.0031 5668   VgaSave         (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/03/30 15:15:06.0109 5668   VolSnap         (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/03/30 15:15:06.0171 5668   Wanarp          (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/03/30 15:15:06.0250 5668   wceusbsh        (4c0b8ef721783f52f8e531fbdc4b1f74) C:\WINDOWS\system32\DRIVERS\wceusbsh.sys
2011/03/30 15:15:06.0343 5668   wdmaud          (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/03/30 15:15:06.0484 5668   WpdUsb          (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
2011/03/30 15:15:06.0546 5668   WS2IFSL         (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2011/03/30 15:15:06.0625 5668   WSTCODEC        (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/03/30 15:15:06.0671 5668   WudfPf          (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/03/30 15:15:06.0703 5668   WudfRd          (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/03/30 15:15:06.0906 5668   ================================================================================
2011/03/30 15:15:06.0906 5668   Scan finished
2011/03/30 15:15:06.0906 5668   ================================================================================

It was very fast, ran all the way through and reported that there were no infections found.
Now I am downloading OTL to run.and here is my OTL report.

OTL logfile created on: 30/03/2011 3:23:16 PM - Run 1
OTL by OldTimer - Version 3.2.22.3     Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
 
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 72.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 211.41 Gb Free Space | 45.39% Space Free | Partition Type: NTFS
 
Computer Name: DELLCOMPUTER1 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011/03/30 15:21:28 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
PRC - [2011/03/24 18:11:25 | 000,167,936 | ---- | M] (Applian Technologies, Inc.) -- C:\Program Files\Freecorder\FLVSrvc.exe
PRC - [2011/01/07 01:22:54 | 002,747,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2011/01/07 01:22:44 | 001,084,256 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2011/01/06 15:23:20 | 000,737,872 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2011/01/06 15:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2010/12/05 16:26:40 | 000,654,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2010/12/05 16:26:12 | 000,650,592 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2010/10/22 04:56:58 | 000,845,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgcsrvx.exe
PRC - [2010/09/28 23:02:58 | 000,220,128 | ---- | M] () -- C:\Program Files\Macrium\Reflect\ReflectService.exe
PRC - [2010/01/12 12:41:00 | 003,168,216 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
PRC - [2009/11/09 12:20:14 | 000,818,432 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Firewall Plus\FWService.exe
PRC - [2008/12/04 13:24:30 | 000,665,424 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Epson Software\Event Manager\EEventManager.exe
PRC - [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/12/18 09:00:00 | 000,143,872 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
PRC - [2007/08/09 18:27:52 | 000,073,728 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
PRC - [2007/01/12 09:02:00 | 000,113,664 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
PRC - [2004/02/27 17:02:32 | 001,269,870 | ---- | M] (Ahead Software AG) -- C:\Program Files\Ahead\InCD\InCD.exe
PRC - [2004/02/27 17:02:02 | 000,847,984 | ---- | M] (Ahead Software AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe
 
 
========== Modules (SafeList) ==========
 
MOD - [2011/03/30 15:21:28 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
MOD - [2011/03/28 10:40:18 | 000,018,432 | ---- | M] (Applian Technologies, Inc.) -- C:\Documents and Settings\Administrator\Local Settings\Application Data\FLVService\lib\FLVSrvLib.dll
MOD - [2010/08/24 03:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/07/12 00:02:02 | 000,653,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
MOD - [2006/05/03 22:53:54 | 000,174,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\framedyn.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [On_Demand | Stopped] --  -- (UPS)
SRV - [2011/01/06 15:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/09/28 23:02:58 | 000,220,128 | ---- | M] () [Auto | Running] -- C:\Program Files\Macrium\Reflect\ReflectService.exe -- (ReflectService)
SRV - [2010/08/02 00:13:09 | 000,028,766 | ---- | M] (IWON) [Auto | Stopped] -- C:\Program Files\IWONG\bar\1.bin\9ubarsvc.exe -- (IWONGService)
SRV - [2010/02/19 19:31:44 | 000,067,360 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus(R)
SRV - [2009/11/09 12:20:14 | 000,818,432 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\PC Tools Firewall Plus\FWService.exe -- (PCToolsFirewallPlus)
SRV - [2007/12/18 09:00:00 | 000,143,872 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE -- (EPSON_EB_RPCV4_01) EPSON V5 Service4(01)
SRV - [2007/08/09 18:27:52 | 000,073,728 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (PML Driver HPZ12)
SRV - [2007/01/12 09:02:00 | 000,113,664 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE -- (EPSON_PM_RPCV4_01) EPSON V3 Service4(01)
SRV - [2004/02/27 17:02:02 | 000,847,984 | ---- | M] (Ahead Software AG) [Auto | Running] -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2010/12/08 04:12:38 | 000,251,728 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2010/11/12 13:19:38 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2010/09/28 23:03:21 | 000,015,328 | ---- | M] (Macrium Software) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\pssnap.sys -- (pssnap)
DRV - [2010/09/13 15:27:24 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2010/09/07 03:48:56 | 000,034,384 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2010/09/07 03:48:50 | 000,026,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2010/08/03 15:23:36 | 000,026,192 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2010/08/03 15:23:34 | 000,123,472 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010/08/03 15:23:32 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2010/05/11 05:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/03/01 00:35:13 | 000,033,848 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nchssvad.sys -- (NCHSSVAD) SoundTap Recorder (32 Bit)
DRV - [2010/02/05 10:17:56 | 000,233,136 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\pctgntdi.sys -- (pctgntdi)
DRV - [2010/01/13 09:59:28 | 000,115,216 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pctplfw.sys -- (pctplfw)
DRV - [2010/01/12 10:34:14 | 000,070,664 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pctNdis-PacketFilter.sys -- (PCTFW-PacketFilter)
DRV - [2010/01/07 12:35:06 | 000,058,816 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pctNdis.sys -- (pctNDIS)
DRV - [2009/11/23 14:54:20 | 000,088,040 | ---- | M] (PC Tools) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\PCTAppEvent.sys -- (PCTAppEvent)
DRV - [2009/02/03 19:30:13 | 000,005,632 | ---- | M] () [File_System | System | Running] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2006/09/25 00:28:46 | 000,005,248 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2006/03/23 18:15:56 | 000,033,536 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\InCDrm.sys -- (incdrm)
DRV - [2005/12/22 12:24:52 | 000,137,884 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2005/12/22 12:24:52 | 000,010,864 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2005/12/22 12:24:50 | 000,080,272 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
DRV - [2004/09/17 10:02:54 | 000,732,928 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt)
DRV - [2004/02/27 17:03:56 | 000,027,440 | ---- | M] (Ahead Software AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass)
DRV - [2004/02/27 17:03:46 | 000,094,320 | ---- | M] (Ahead Software AG) [File_System | Disabled | Running] -- C:\WINDOWS\System32\drivers\InCDfs.sys -- (InCDfs)
DRV - [2002/10/21 12:37:16 | 000,515,803 | ---- | M] (Digital Camera) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\Ca533av.sys -- (Ca533av) Icatch(IV)
DRV - [2002/07/25 12:19:48 | 000,010,986 | ---- | M] (USB BULK) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Bulk533.sys -- (USBCamera) Icatch(IV)
DRV - [1997/12/23 13:02:46 | 000,023,936 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\aspi32.sys -- (Aspi32)
DRV - [1996/04/04 06:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\prxtbFre0.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
 
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\IWONG\bar\1.bin [2011/03/17 15:37:03 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2011/03/16 18:09:57 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/16 15:07:51 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/18 01:45:30 | 000,000,000 | ---D | M]
 
[2009/12/29 15:33:03 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2011/03/30 11:10:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions
[2011/03/28 10:49:11 | 000,000,000 | ---D | M] (Freecorder Community Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2011/03/28 09:55:47 | 000,000,000 | ---D | M] (TwitterBar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}
[2010/04/28 23:14:21 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/28 09:55:51 | 000,000,000 | ---D | M] ("ToolbarBrowser") -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{2e710e6b-5e9d-44ba-8f4e-09a040978b49}
[2009/11/23 12:42:54 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
[2009/11/23 12:42:53 | 000,000,000 | ---D | M] (FEBE) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}(2)
[2010/01/20 23:55:18 | 000,000,000 | ---D | M] (CashKeywords Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{9eb64fa9-57c4-4a41-9940-e12e0418b693}(2)
[2011/03/28 09:55:46 | 000,000,000 | ---D | M] ("Shorten URL") -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{a1109c2a-1187-4027-901d-13097b755625}
[2010/01/20 23:56:54 | 000,000,000 | ---D | M] (FireFTP) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}(2)
[2010/12/15 20:31:07 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/01/07 21:49:20 | 000,000,000 | ---D | M] (Web Developer) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2011/03/28 09:55:47 | 000,000,000 | ---D | M] (Fast Video Download (with SearchMenu)) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
[2010/03/14 18:23:04 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/10/02 17:43:54 | 000,000,000 | ---D | M] (Разпознаване на устройство Logitech) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\[email protected]
[2011/03/28 10:49:09 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\[email protected]
[2009/11/23 12:43:55 | 000,000,000 | ---D | M] (Firebug) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\[email protected](2).com
[2010/01/20 23:54:44 | 000,000,000 | ---D | M] (FirePHP) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\[email protected](2).org
[2009/11/23 12:44:25 | 000,000,000 | ---D | M] (FastestFox) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\[email protected](2).com
[2011/03/28 09:55:50 | 000,000,000 | ---D | M] (Echofon) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\[email protected]
[2010/01/19 19:31:27 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\[email protected](2).org\__MACOSX(2)
[2010/01/20 23:54:44 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\[email protected](2).org\chrome(2)
[2010/01/20 23:54:44 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\[email protected](2).org\defaults(2)
[2011/03/29 10:56:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/05/09 18:32:19 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/10 11:55:37 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/12/16 08:09:03 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/16 15:10:03 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/11/12 18:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
 
O1 HOSTS File: ([2011/03/20 23:15:57 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: ::1       localhost
O2 - BHO: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\prxtbFre0.dll (Conduit Ltd.)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll (Google Inc.)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\prxtbFre0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (&Save Flash) - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll (TODO: )
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKCU\..\Toolbar\WebBrowser: (Freecorder Toolbar) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - C:\Program Files\Freecorder\prxtbFre0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Save Flash) - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll (TODO: )
O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [00PCTFW] C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe (PC Tools)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe (Ahead Software AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKCU..\Run: [Wisdom-soft AutoScreenRecorder 3.1 Pro]  File not found
O4 - HKCU..\Run: [Wisdom-soft ScreenHunter 5.1 Pro]  File not found
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil10n_Plugin.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuPinnedList = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll (Google Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab (EPUImageControl Class)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WALLPAPER: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/09/14 16:05:25 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [ = ComFile] -- "%1" %*
O37 - HKLM\...exe [ = exefile] -- "%1" %*
 
NetSvcs: 6to4 -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Iprip -  File not found
NetSvcs: Irmon -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: WmdmPmSp -  File not found
 
 
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - HUMAN Interface Devices
 
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906)
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {2F6EFCE6-10DF-49F9-9E64-9AE3775B2588} - Microsoft .NET Framework 1.1 Security Update (KB2416447)
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Security Update for Windows XP (KB923789)
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {75D04B76-E0D3-9685-9369-AF82CB13E868} - Microsoft Windows Media Player
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8DB52A01-AEF7-9ACF-7808-55F420F23178} - Browser Customizations
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} -
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
 
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.SP54 - C:\WINDOWS\System32\SP5X_32.DLL (Sunplus)
Drivers32: VIDC.SP55 - C:\WINDOWS\System32\SP5X_32.DLL (Sunplus)
Drivers32: VIDC.SP56 - C:\WINDOWS\System32\SP5X_32.DLL (Sunplus)
Drivers32: VIDC.SP57 - C:\WINDOWS\System32\SP5X_32.DLL (Sunplus)
Drivers32: VIDC.SP58 - C:\WINDOWS\System32\SP5X_32.DLL (Sunplus)
Drivers32: VIDC.XFR1 - C:\WINDOWS\System32\xfcodec.dll ()
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011/03/30 15:21:26 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/03/30 15:13:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\tdsskiller
[2011/03/28 11:23:17 | 000,116,224 | ---- | C] (Xerox) -- C:\WINDOWS\System32\dllcache\xrxwiadr.dll
[2011/03/28 11:23:17 | 000,023,040 | ---- | C] (Xerox Corporation) -- C:\WINDOWS\System32\dllcache\xrxwbtmp.dll
[2011/03/28 11:23:16 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xrxflnch.exe
[2011/03/28 11:22:06 | 000,019,455 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wvchntxx.sys
[2011/03/28 11:22:06 | 000,016,970 | ---- | C] (US Robotics MCD (Megahertz)) -- C:\WINDOWS\System32\dllcache\xem336n5.sys
[2011/03/28 11:22:03 | 000,012,063 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wsiintxx.sys
[2011/03/28 11:22:02 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wshirda.dll
[2011/03/28 11:21:50 | 000,008,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiacpi.sys
[2011/03/28 11:21:49 | 000,154,624 | ---- | C] (Lucent Technologies) -- C:\WINDOWS\System32\dllcache\wlluc48.sys
[2011/03/28 11:21:49 | 000,034,890 | ---- | C] (Raytheon Corp.) -- C:\WINDOWS\System32\dllcache\wlandrv2.sys
[2011/03/28 11:21:43 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wiafbdrv.dll
[2011/03/28 11:21:43 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wiamsmud.dll
[2011/03/28 11:21:35 | 000,035,871 | ---- | C] (Winbond Electronics Corp.) -- C:\WINDOWS\System32\dllcache\wbfirdma.sys
[2011/03/28 11:21:35 | 000,023,615 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wch7xxnt.sys
[2011/03/28 11:21:33 | 000,033,599 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\watv04nt.sys
[2011/03/28 11:21:33 | 000,025,471 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\watv10nt.sys
[2011/03/28 11:21:33 | 000,022,271 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\watv06nt.sys
[2011/03/28 11:21:33 | 000,019,551 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\watv02nt.sys
[2011/03/28 11:21:32 | 000,029,311 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\watv01nt.sys
[2011/03/28 11:21:27 | 000,011,935 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv11nt.sys
[2011/03/28 11:21:26 | 000,011,871 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv09nt.sys
[2011/03/28 11:21:26 | 000,011,807 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv07nt.sys
[2011/03/28 11:21:26 | 000,011,775 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv05nt.sys
[2011/03/28 11:21:26 | 000,011,295 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv08nt.sys
[2011/03/28 11:21:25 | 000,012,415 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv01nt.sys
[2011/03/28 11:21:25 | 000,012,127 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv02nt.sys
[2011/03/28 11:21:22 | 000,019,528 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w840nd.sys
[2011/03/28 11:21:22 | 000,019,016 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w926nd.sys
[2011/03/28 11:21:22 | 000,016,925 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w940nd.sys
[2011/03/28 11:21:08 | 000,042,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\viaagp.sys
[2011/03/28 11:21:08 | 000,024,576 | ---- | C] (VIA Technologies, Inc.) -- C:\WINDOWS\System32\dllcache\viairda.sys
[2011/03/28 11:21:08 | 000,005,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\viaide.sys
[2011/03/28 11:21:05 | 000,011,325 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\vchnt5.dll
[2011/03/28 11:20:23 | 000,121,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbvideo.sys
[2011/03/28 11:20:22 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbser.sys
[2011/03/28 11:20:22 | 000,017,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbohci.sys
[2011/03/28 11:20:21 | 000,032,384 | ---- | C] (KLSI USA, Inc.) -- C:\WINDOWS\System32\dllcache\usb101et.sys
[2011/03/28 11:20:21 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usb8023x.sys
[2011/03/28 11:20:19 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxud32.dll
[2011/03/28 11:20:18 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxu12.dll
[2011/03/28 11:20:18 | 000,050,688 | ---- | C] (UMAX DATA SYSTEMS INC.) -- C:\WINDOWS\System32\dllcache\umaxscan.dll
[2011/03/28 11:20:18 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxu40.dll
[2011/03/28 11:20:18 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxu22.dll
[2011/03/28 11:20:18 | 000,022,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxpcls.sys
[2011/03/28 11:20:17 | 000,211,968 | ---- | C] (UMAX Data Systems Inc.) -- C:\WINDOWS\System32\dllcache\um54scan.dll
[2011/03/28 11:20:17 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxp60.dll
[2011/03/28 11:20:17 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxcam.dll
[2011/03/28 11:20:16 | 000,216,064 | ---- | C] (UMAX Data Systems Inc.) -- C:\WINDOWS\System32\dllcache\um34scan.dll
[2011/03/28 11:20:16 | 000,036,736 | ---- | C] (Promise Technology, Inc.) -- C:\WINDOWS\System32\dllcache\ultra.sys
[2011/03/28 11:20:14 | 000,044,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\uagp35.sys
[2011/03/28 11:20:08 | 000,525,568 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridxp.dll
[2011/03/28 11:20:08 | 000,166,784 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridxpm.sys
[2011/03/28 11:20:08 | 000,159,232 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridkbm.sys
[2011/03/28 11:20:07 | 000,440,576 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridkb.dll
[2011/03/28 11:20:07 | 000,222,336 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\trid3dm.sys
[2011/03/28 11:20:06 | 000,315,520 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\trid3d.dll
[2011/03/28 11:20:06 | 000,034,375 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\tpro4.sys
[2011/03/28 11:19:58 | 000,004,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\toside.sys
[2011/03/28 11:19:53 | 000,028,232 | ---- | C] (TOSHIBA Corporation) -- C:\WINDOWS\System32\dllcache\tos4mo.sys
[2011/03/28 11:19:48 | 000,138,528 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tgiulnt5.sys
[2011/03/28 11:19:48 | 000,081,408 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tgiul50.dll
[2011/03/28 11:19:47 | 000,149,376 | ---- | C] (M-Systems) -- C:\WINDOWS\System32\dllcache\tffsport.sys
[2011/03/28 11:19:44 | 000,037,961 | ---- | C] (TDK Corporation) -- C:\WINDOWS\System32\dllcache\tdk100b.sys
[2011/03/28 11:19:44 | 000,017,129 | ---- | C] (TDK Corporation) -- C:\WINDOWS\System32\dllcache\tdkcd31.sys
[2011/03/28 11:19:23 | 000,032,640 | ---- | C] (LSI Logic) -- C:\WINDOWS\System32\dllcache\symc8xx.sys
[2011/03/28 11:19:23 | 000,016,256 | ---- | C] (Symbios Logic Inc.) -- C:\WINDOWS\System32\dllcache\symc810.sys
[2011/03/28 11:19:22 | 000,030,688 | ---- | C] (LSI Logic) -- C:\WINDOWS\System32\dllcache\sym_u3.sys
[2011/03/28 11:19:22 | 000,028,384 | ---- | C] (LSI Logic) -- C:\WINDOWS\System32\dllcache\sym_hi.sys
[2011/03/28 11:19:18 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sw_wheel.dll
[2011/03/28 11:19:18 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swpidflt.dll
[2011/03/28 11:19:18 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swpdflt2.dll
[2011/03/28 11:19:18 | 000,003,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swusbflt.sys
[2011/03/28 11:19:17 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sw_effct.dll
[2011/03/28 11:19:09 | 000,016,896 | ---- | C] (SCM Microsystems, Inc.) -- C:\WINDOWS\System32\dllcache\stcusb.sys
[2011/03/28 11:19:04 | 000,048,736 | ---- | C] (3Com) -- C:\WINDOWS\System32\dllcache\srwlnd5.sys
[2011/03/28 11:19:03 | 000,099,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srusd.dll
[2011/03/28 11:18:52 | 000,019,072 | ---- | C] (Adaptec, Inc.) -- C:\WINDOWS\System32\dllcache\sparrow.sys
[2011/03/28 11:18:51 | 000,007,552 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\sonypvu1.sys
[2011/03/28 11:18:47 | 000,009,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sonymc.sys
[2011/03/28 11:18:44 | 000,007,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snyaitmc.sys
[2011/03/28 11:18:25 | 000,058,368 | ---- | C] (Silicon Motion Inc.) -- C:\WINDOWS\System32\dllcache\smiminib.sys
[2011/03/28 11:18:22 | 000,147,200 | ---- | C] (Silicon Motion Inc.) -- C:\WINDOWS\System32\dllcache\smidispb.dll
[2011/03/28 11:18:20 | 000,035,913 | ---- | C] (SMC) -- C:\WINDOWS\System32\dllcache\smcirda.sys
[2011/03/28 11:18:20 | 000,025,034 | ---- | C] (SMC Networks, Inc.) -- C:\WINDOWS\System32\dllcache\smcpwr2n.sys
[2011/03/28 11:18:19 | 000,024,576 | ---- | C] (SMC Networks, Inc.) -- C:\WINDOWS\System32\dllcache\smc8000n.sys
[2011/03/28 11:18:19 | 000,006,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smbclass.sys
[2011/03/28 11:18:19 | 000,006,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smbhc.sys
[2011/03/28 11:18:18 | 000,016,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smbbatt.sys
[2011/03/28 11:18:18 | 000,005,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smbali.sys
[2011/03/28 11:18:16 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smb3w.dll
[2011/03/28 11:18:15 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smb0w.dll
[2011/03/28 11:18:13 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sma0w.dll
[2011/03/28 11:18:07 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm91w.dll
[2011/03/28 11:17:37 | 000,091,294 | ---- | C] (SysKonnect, a business unit of Schneider & Koch & Co. Datensysteme GmbH.) -- C:\WINDOWS\System32\dllcache\skfpwin.sys
[2011/03/28 11:17:37 | 000,063,547 | ---- | C] (Symbol Technologies) -- C:\WINDOWS\System32\dllcache\sla30nd5.sys
[2011/03/28 11:17:36 | 000,157,696 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisv256.dll
[2011/03/28 11:17:36 | 000,094,698 | ---- | C] (SysKonnect GmbH.) -- C:\WINDOWS\System32\dllcache\sk98xwin.sys
[2011/03/28 11:17:36 | 000,050,432 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisv.sys
[2011/03/28 11:17:35 | 000,238,592 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisgrv.dll
[2011/03/28 11:17:35 | 000,104,064 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisgrp.sys
[2011/03/28 11:17:35 | 000,040,960 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisagp.sys
[2011/03/28 11:17:35 | 000,032,768 | ---- | C] (SiS Corporation) -- C:\WINDOWS\System32\dllcache\sisnic.sys
[2011/03/28 11:17:34 | 000,252,032 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis300iv.dll
[2011/03/28 11:17:34 | 000,150,144 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis6306v.dll
[2011/03/28 11:17:34 | 000,101,760 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis300ip.sys
[2011/03/28 11:17:34 | 000,068,608 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis6306p.sys
[2011/03/28 11:17:33 | 000,003,901 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\siint5.dll
[2011/03/28 11:17:18 | 000,098,080 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\sgiulnt5.sys
[2011/03/28 11:17:17 | 000,386,560 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\sgiul50.dll
[2011/03/28 11:17:17 | 000,036,480 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\sfmanm.sys
[2011/03/28 11:17:13 | 000,017,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sermouse.sys
[2011/03/28 11:17:13 | 000,006,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\serscan.sys
[2011/03/28 11:17:07 | 000,006,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\seaddsmc.sys
[2011/03/28 11:17:06 | 000,011,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scsiprnt.sys
[2011/03/28 11:17:06 | 000,011,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scsiscan.sys
[2011/03/28 11:17:03 | 000,017,280 | ---- | C] (SCM Microsystems) -- C:\WINDOWS\System32\dllcache\scr111.sys
[2011/03/28 11:17:03 | 000,016,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scmstcs.sys
[2011/03/28 11:17:02 | 000,023,936 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\sccmusbm.sys
[2011/03/28 11:17:02 | 000,023,936 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\sccmn50m.sys
[2011/03/28 11:17:01 | 000,495,616 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\sblfx.dll
[2011/03/28 11:17:01 | 000,043,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sbp2port.sys
[2011/03/28 11:17:00 | 000,245,632 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\dllcache\s3savmx.dll
[2011/03/28 11:17:00 | 000,075,392 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\dllcache\s3savmxm.sys
[2011/03/28 11:16:59 | 000,198,400 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav4.dll
[2011/03/28 11:16:59 | 000,077,824 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav4m.sys
[2011/03/28 11:16:59 | 000,061,504 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav3dm.sys
[2011/03/28 11:16:58 | 000,179,264 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav3d.dll
[2011/03/28 11:16:54 | 000,182,272 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mt3d.dll
[2011/03/28 11:16:54 | 000,041,216 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mt3d.sys
[2011/03/28 11:16:49 | 000,397,056 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\dllcache\s3gnb.dll
[2011/03/28 11:16:49 | 000,166,912 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\dllcache\s3gnbm.sys
[2011/03/28 11:16:47 | 000,082,432 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia450.dll
[2011/03/28 11:16:47 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia430.dll
[2011/03/28 11:16:43 | 000,029,696 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw450ext.dll
[2011/03/28 11:16:42 | 000,027,648 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw430ext.dll
[2011/03/28 11:16:34 | 000,020,992 | ---- | C] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\dllcache\rtl8139.sys
[2011/03/28 11:16:33 | 000,030,720 | ---- | C] (Conexant Systems Inc.) -- C:\WINDOWS\System32\dllcache\rthwcls.sys
[2011/03/28 11:16:33 | 000,019,017 | ---- | C] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\dllcache\rtl8029.sys
[2011/03/28 11:16:32 | 000,009,216 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\rsmgrstr.dll
[2011/03/28 11:16:31 | 000,003,840 | ---- | C] (Conexant Systems Inc.) -- C:\WINDOWS\System32\dllcache\rpfun.sys
[2011/03/28 11:16:28 | 000,030,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rndismpx.sys
[2011/03/28 11:16:27 | 000,059,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rfcomm.sys
[2011/03/28 11:16:27 | 000,037,563 | ---- | C] (RadioLAN) -- C:\WINDOWS\System32\dllcache\rlnet5.sys
[2011/03/28 11:16:13 | 000,019,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rasirda.sys
[2011/03/28 11:16:07 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\qvusd.dll
[2011/03/28 11:16:07 | 000,003,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\qv2kux.sys
[2011/03/28 11:15:53 | 000,049,024 | ---- | C] (QLogic Corporation) -- C:\WINDOWS\System32\dllcache\ql1280.sys
[2011/03/28 11:15:53 | 000,045,312 | ---- | C] (QLogic Corporation) -- C:\WINDOWS\System32\dllcache\ql12160.sys
[2011/03/28 11:15:53 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ql1240.sys
[2011/03/28 11:15:52 | 000,040,320 | ---- | C] (QLogic Corporation) -- C:\WINDOWS\System32\dllcache\ql1080.sys
[2011/03/28 11:15:52 | 000,033,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ql10wnt.sys
[2011/03/28 11:15:43 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ptpusd.dll
[2011/03/28 11:15:43 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ptpusb.dll
[2011/03/28 11:15:42 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\psisload.dll
[2011/03/28 11:15:42 | 000,016,128 | ---- | C] (SCM Microsystems, Inc.) -- C:\WINDOWS\System32\dllcache\pscr.sys
[2011/03/28 11:15:40 | 000,017,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ppa3.sys
[2011/03/28 11:15:39 | 000,017,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ppa.sys
[2011/03/28 11:15:39 | 000,008,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\powerfil.sys
[2011/03/28 11:15:38 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pnrmc.sys
[2011/03/28 11:15:30 | 000,121,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\phvfwext.dll
[2011/03/28 11:15:30 | 000,092,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\phildec.sys
[2011/03/28 11:15:30 | 000,019,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\philtune.sys
[2011/03/28 11:15:29 | 000,173,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\philcam2.sys
[2011/03/28 11:15:29 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\phdsext.ax
[2011/03/28 11:15:29 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\philcam1.sys
[2011/03/28 11:15:29 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\philcam1.dll
[2011/03/28 11:15:28 | 000,259,328 | ---- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) -- C:\WINDOWS\System32\dllcache\perm3dd.dll
[2011/03/28 11:15:28 | 000,028,032 | ---- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) -- C:\WINDOWS\System32\dllcache\perm3.sys
[2011/03/28 11:15:27 | 000,211,584 | ---- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) -- C:\WINDOWS\System32\dllcache\perm2dll.dll
[2011/03/28 11:15:27 | 000,027,904 | ---- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) -- C:\WINDOWS\System32\dllcache\perm2.sys
[2011/03/28 11:15:26 | 000,027,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\perc2.sys
[2011/03/28 11:15:26 | 000,005,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\perc2hib.sys
[2011/03/28 11:15:25 | 000,169,984 | ---- | C] (Cisco Systems) -- C:\WINDOWS\System32\dllcache\pcx500.sys
[2011/03/28 11:15:23 | 000,035,328 | ---- | C] (AMD Inc.) -- C:\WINDOWS\System32\dllcache\pcntpci5.sys
[2011/03/28 11:15:23 | 000,030,282 | ---- | C] (AMD Inc.) -- C:\WINDOWS\System32\dllcache\pcntn5hl.sys
[2011/03/28 11:15:23 | 000,029,769 | ---- | C] (AMD Inc.) -- C:\WINDOWS\System32\dllcache\pcntn5m.sys
[2011/03/28 11:15:18 | 000,030,495 | ---- | C] (Linksys) -- C:\WINDOWS\System32\dllcache\pc100nds.sys
[2011/03/28 11:15:16 | 000,031,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ovce.sys
[2011/03/28 11:15:16 | 000,025,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ovsound2.sys
[2011/03/28 11:15:15 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ovca.sys
[2011/03/28 11:15:06 | 000,043,689 | ---- | C] (Ositech Communications, Inc.) -- C:\WINDOWS\System32\dllcache\otceth5.sys
[2011/03/28 11:15:06 | 000,027,209 | ---- | C] (Ositech Communications, Inc.) -- C:\WINDOWS\System32\dllcache\otc06x5.sys
[2011/03/28 11:15:05 | 000,054,528 | ---- | C] (Yamaha Corp.) -- C:\WINDOWS\System32\dllcache\opl3sax.sys
[2011/03/28 11:15:04 | 000,061,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ohci1394.sys
[2011/03/28 11:15:01 | 004,274,816 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\dllcache\nv4_disp.dll
[2011/03/28 11:15:01 | 001,897,408 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\dllcache\nv4_mini.sys
[2011/03/28 11:15:00 | 000,198,144 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\dllcache\nv3.sys
[2011/03/28 11:15:00 | 000,123,776 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\dllcache\nv3.dll
[2011/03/28 11:14:50 | 000,009,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntapm.sys
[2011/03/28 11:14:50 | 000,007,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nsmmc.sys
[2011/03/28 11:14:49 | 000,028,672 | ---- | C] (National Semiconductor Corporation) -- C:\WINDOWS\System32\dllcache\nscirda.sys
[2011/03/28 11:14:48 | 000,126,080 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\nm5a2wdm.sys
[2011/03/28 11:14:48 | 000,087,040 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\nm6wdm.sys
[2011/03/28 11:14:47 | 000,032,840 | ---- | C] (NETGEAR Corporation.) -- C:\WINDOWS\System32\dllcache\ngrpci.sys
[2011/03/28 11:14:46 | 000,132,695 | ---- | C] (802.11b) -- C:\WINDOWS\System32\dllcache\netwlan5.sys
[2011/03/28 11:14:44 | 000,065,278 | ---- | C] (Compaq Computer Corporation) -- C:\WINDOWS\System32\dllcache\netflx3.sys
[2011/03/28 11:14:43 | 000,060,480 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\neo20xx.dll
[2011/03/28 11:14:43 | 000,039,264 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\neo20xx.sys
[2011/03/28 11:14:43 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ne2000.sys
[2011/03/28 11:14:28 | 000,128,000 | ---- | C] (Compaq Computer Corporation) -- C:\WINDOWS\System32\dllcache\n100325.sys
[2011/03/28 11:14:28 | 000,052,255 | ---- | C] (Compaq Computer Corporation) -- C:\WINDOWS\System32\dllcache\n1000nt5.sys
[2011/03/28 11:14:23 | 000,019,968 | ---- | C] (Macronix International Co., Ltd.                                               ) -- C:\WINDOWS\System32\dllcache\mxnic.sys
[2011/03/28 11:14:10 | 001,737,856 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\mtxparhd.dll
[2011/03/28 11:14:10 | 000,452,736 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\mtxparhm.sys
[2011/03/28 11:14:10 | 000,103,296 | ---- | C] (Matrox Graphics Inc) -- C:\WINDOWS\System32\dllcache\mtxvideo.sys
[2011/03/28 11:13:56 | 000,012,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msriffwv.sys
[2011/03/28 11:13:53 | 000,002,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msmpu401.sys
[2011/03/28 11:13:51 | 000,022,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msircomm.sys
[2011/03/28 11:13:41 | 000,035,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msgame.sys
[2011/03/28 11:13:41 | 000,006,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfsio.sys
[2011/03/28 11:13:40 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdv.sys
[2011/03/28 11:13:36 | 000,017,280 | ---- | C] (American Megatrends Inc.) -- C:\WINDOWS\System32\dllcache\mraid35x.sys
[2011/03/28 11:13:34 | 000,015,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mpe.sys
[2011/03/28 11:13:32 | 000,016,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\modemcsa.sys
[2011/03/28 11:13:20 | 000,320,384 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\mgaum.sys
[2011/03/28 11:13:20 | 000,235,648 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\mgaud.dll
[2011/03/28 11:13:12 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\memgrp.dll
[2011/03/28 11:13:12 | 000,026,112 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\memstpci.sys
[2011/03/28 11:13:11 | 000,008,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\memcard.sys
[2011/03/28 11:13:10 | 000,164,586 | ---- | C] (Madge Networks Ltd) -- C:\WINDOWS\System32\dllcache\mdgndis5.sys
[2011/03/28 11:13:03 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\m3092dc.dll
[2011/03/28 11:13:03 | 000,058,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\m3091dc.dll
[2011/03/28 11:13:03 | 000,048,768 | ---- | C] (ESS Technology, Inc.) -- C:\WINDOWS\System32\dllcache\maestro.sys
[2011/03/28 11:13:02 | 000,022,848 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\dllcache\lwusbhid.sys
[2011/03/28 11:13:02 | 000,020,864 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\dllcache\lwadihid.sys
[2011/03/28 11:12:45 | 000,004,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\loop.sys
[2011/03/28 11:12:43 | 000,070,730 | ---- | C] (Linksys Group, Inc.) -- C:\WINDOWS\System32\dllcache\lne100tx.sys
[2011/03/28 11:12:43 | 000,020,573 | ---- | C] (The Linksts Group ) -- C:\WINDOWS\System32\dllcache\lne100.sys
[2011/03/28 11:12:42 | 000,025,065 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\lmndis3.sys
[2011/03/28 11:12:42 | 000,015,744 | ---- | C] (Litronic Industries) -- C:\WINDOWS\System32\dllcache\lit220p.sys
[2011/03/28 11:12:40 | 000,034,688 | ---- | C] (Toshiba Corp.) -- C:\WINDOWS\System32\dllcache\lbrtfdc.sys
[2011/03/28 11:12:40 | 000,026,442 | ---- | C] (SMSC) -- C:\WINDOWS\System32\dllcache\lanepic5.sys
[2011/03/28 11:12:39 | 000,019,016 | ---- | C] (Kingston Technology Company                                                             ) -- C:\WINDOWS\System32\dllcache\ktc111.sys
[2011/03/28 11:12:38 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kousd.dll
[2011/03/28 11:12:33 | 000,253,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kdsusd.dll
[2011/03/28 11:12:32 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kdsui.dll
[2011/03/28 11:10:28 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irmon.dll
[2011/03/28 11:10:28 | 000,026,624 | ---- | C] (SigmaTel, Inc.) -- C:\WINDOWS\System32\dllcache\irstusb.sys
[2011/03/28 11:10:The OTL Extra.txt log is missing. Quote from: ImnoGuru on March 29, 2011, 10:42:27 PM
and here is my OTL report.


[2011/03/28 11:12:40 | 000,034,688 | ---- | C] (Toshiba Corp.) -- C:\WINDOWS\System32\dllcache\lbrtfdc.sys
[2011/03/28 11:12:40 | 000,026,442 | ---- | C] (SMSC) -- C:\WINDOWS\System32\dllcache\lanepic5.sys
[2011/03/28 11:12:39 | 000,019,016 | ---- | C] (Kingston Technology Company                                                             ) -- C:\WINDOWS\System32\dllcache\ktc111.sys
[2011/03/28 11:12:38 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kousd.dll
[2011/03/28 11:12:33 | 000,253,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kdsusd.dll
[2011/03/28 11:12:32 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kdsui.dll
[2011/03/28 11:10:28 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irmon.dll
[2011/03/28 11:10:28 | 000,026,624 | ---- | C] (SigmaTel, Inc.) -- C:\WINDOWS\System32\dllcache\irstusb.sys
[2011/03/28 11:10:

Yes I found that part that was missing SuperDave. I highlighted a bit of the overlap for you to continue from. (Hope I was accurate with that) 
Maybe it was to big to process the whole thing? OR it could have been an operators mistake?

2011/03/28 11:12:40 | 000,034,688 | ---- | C] (Toshiba Corp.) -- C:\WINDOWS\System32\dllcache\lbrtfdc.sys
[2011/03/28 11:12:40 | 000,026,442 | ---- | C] (SMSC) -- C:\WINDOWS\System32\dllcache\lanepic5.sys
[2011/03/28 11:12:39 | 000,019,016 | ---- | C] (Kingston Technology Company                                                             ) -- C:\WINDOWS\System32\dllcache\ktc111.sys
[2011/03/28 11:12:38 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kousd.dll
[2011/03/28 11:12:33 | 000,253,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kdsusd.dll
[2011/03/28 11:12:32 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kdsui.dll
[2011/03/28 11:10:28 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irmon.dll
[2011/03/28 11:10:28 | 000,026,624 | ---- | C] (SigmaTel, Inc.) -- C:\WINDOWS\System32\dllcache\irstusb.sys
[2011/03/28 11:10:28 | 000,018,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irsir.sys
[2011/03/28 11:10:27 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irftp.exe
[2011/03/28 11:10:27 | 000,088,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irda.sys
[2011/03/28 11:10:27 | 000,023,552 | ---- | C] (MKNet Corporation) -- C:\WINDOWS\System32\dllcache\irmk7.sys
[2011/03/28 11:10:26 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irbus.sys
[2011/03/28 11:10:17 | 000,013,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inport.sys
[2011/03/28 11:10:16 | 000,016,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ini910u.sys
[2011/03/28 11:09:40 | 000,100,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam5usb.sys
[2011/03/28 11:09:39 | 000,154,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam4usb.sys
[2011/03/28 11:09:39 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam5com.dll
[2011/03/28 11:09:39 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam5ext.dll
[2011/03/28 11:09:38 | 000,141,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam3.sys
[2011/03/28 11:09:38 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam4com.dll
[2011/03/28 11:09:38 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam4ext.dll
[2011/03/28 11:09:38 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam3ext.dll
[2011/03/28 11:09:37 | 000,109,085 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\ibmtrp.sys
[2011/03/28 11:09:37 | 000,100,936 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\ibmtok.sys
[2011/03/28 11:09:37 | 000,038,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ibmvcap.sys
[2011/03/28 11:09:36 | 000,161,020 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\i81xnt5.sys
[2011/03/28 11:09:36 | 000,028,700 | ---- | C] (IBM Corp.) -- C:\WINDOWS\System32\dllcache\ibmexmp.sys
[2011/03/28 11:09:36 | 000,009,216 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\ibmsgnet.dll
[2011/03/28 11:09:35 | 000,702,845 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\i81xdnt5.dll
[2011/03/28 11:09:35 | 000,353,184 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\i740dnt5.dll
[2011/03/28 11:09:35 | 000,058,592 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\i740nt5.sys
[2011/03/28 11:09:34 | 000,018,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\i2omp.sys
[2011/03/28 11:09:34 | 000,008,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\i2omgmt.sys
[2011/03/28 11:08:55 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hr1w.dll
[2011/03/28 11:08:52 | 000,324,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpojwia.dll
[2011/03/28 11:08:52 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpgtmcro.dll
[2011/03/28 11:08:52 | 000,025,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpn.sys
[2011/03/28 11:08:52 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpsjmcro.dll
[2011/03/28 11:08:51 | 000,068,608 | ---- | C] (Avisioin) -- C:\WINDOWS\System32\dllcache\hpgt53tk.dll
[2011/03/28 11:08:51 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpgt42tk.dll
[2011/03/28 11:08:50 | 000,126,976 | ---- | C] (Hewlett Packard) -- C:\WINDOWS\System32\dllcache\hpgt34tk.dll
[2011/03/28 11:08:50 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpgt33tk.dll
[2011/03/28 11:08:49 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpgt21tk.dll
[2011/03/28 11:08:49 | 000,119,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpdigwia.dll
[2011/03/28 11:08:47 | 000,019,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidir.sys
[2011/03/28 11:08:47 | 000,008,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidgame.sys
[2011/03/28 11:08:47 | 000,002,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidswvd.sys
[2011/03/28 11:08:46 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidbth.sys
[2011/03/28 11:08:46 | 000,020,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidbatt.sys
[2011/03/28 11:08:42 | 000,028,288 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\grserial.sys
[2011/03/28 11:08:41 | 000,082,304 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\grclass.sys
[2011/03/28 11:08:40 | 000,017,408 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\gpr400.sys
[2011/03/28 11:08:39 | 000,059,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\gckernel.sys
[2011/03/28 11:08:39 | 000,010,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\gameenum.sys
[2011/03/28 11:08:38 | 001,733,120 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\g400d.dll
[2011/03/28 11:08:38 | 000,322,432 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\g400m.sys
[2011/03/28 11:08:38 | 000,046,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\gagp30kx.sys
[2011/03/28 11:08:37 | 000,470,144 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\g200d.dll
[2011/03/28 11:08:37 | 000,320,384 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\g200m.sys
[2011/03/28 11:07:58 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fuusd.dll
[2011/03/28 11:07:41 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fnfilter.dll
[2011/03/28 11:07:38 | 000,027,165 | ---- | C] (VIA Technologies, Inc.              ) -- C:\WINDOWS\System32\dllcache\fetnd5.sys
[2011/03/28 11:07:37 | 000,022,090 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\fem556n5.sys
[2011/03/28 11:07:34 | 000,024,618 | ---- | C] (NETGEAR) -- C:\WINDOWS\System32\dllcache\fa410nd5.sys
[2011/03/28 11:07:34 | 000,016,074 | ---- | C] (NETGEAR Corp.) -- C:\WINDOWS\System32\dllcache\fa312nd5.sys
[2011/03/28 11:07:33 | 000,012,362 | ---- | C] (FUJITSU LIMITED) -- C:\WINDOWS\System32\dllcache\f3ab18xi.sys
[2011/03/28 11:07:33 | 000,011,850 | ---- | C] (FUJITSU LIMITED) -- C:\WINDOWS\System32\dllcache\f3ab18xj.sys
[2011/03/28 11:07:30 | 000,016,998 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\ex10.sys
[2011/03/28 11:07:24 | 000,045,568 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esunib.dll
[2011/03/28 11:07:24 | 000,045,568 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esuni.dll
[2011/03/28 11:07:22 | 000,034,816 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esuimg.dll
[2011/03/28 11:07:20 | 000,137,088 | ---- | C] (ESS Technology, Inc.) -- C:\WINDOWS\System32\dllcache\essm2e.sys
[2011/03/28 11:07:20 | 000,043,008 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esucm.dll
[2011/03/28 11:07:19 | 000,063,360 | ---- | C] (ESS Technology, Inc.) -- C:\WINDOWS\System32\dllcache\ess.sys
[2011/03/28 11:07:10 | 000,174,464 | ---- | C] (ESS Technology, Inc.) -- C:\WINDOWS\System32\dllcache\es198x.sys
[2011/03/28 11:07:10 | 000,072,192 | ---- | C] (ESS Technology Inc.) -- C:\WINDOWS\System32\dllcache\es1969.sys
[2011/03/28 11:07:10 | 000,040,704 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\es1371mp.sys
[2011/03/28 11:07:10 | 000,037,120 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\es1370mp.sys
[2011/03/28 11:06:59 | 000,144,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\epcfw2k.sys
[2011/03/28 11:06:59 | 000,114,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\epstw2k.sys
[2011/03/28 11:06:59 | 000,018,503 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\epro4.sys
[2011/03/28 11:06:59 | 000,006,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\enum1394.sys
[2011/03/28 11:06:58 | 000,283,904 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\emu10k1m.sys
[2011/03/28 11:06:57 | 000,171,520 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el99xn51.sys
[2011/03/28 11:06:57 | 000,025,159 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\elnk3.sys
[2011/03/28 11:06:57 | 000,019,996 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\em556n4.sys
[2011/03/28 11:06:57 | 000,007,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\elmsmc.sys
[2011/03/28 11:06:56 | 000,455,199 | ---- | C] (3Com Corporation.) -- C:\WINDOWS\System32\dllcache\el985n51.sys
[2011/03/28 11:06:56 | 000,153,631 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el90xnd5.sys
[2011/03/28 11:06:56 | 000,070,174 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el98xn5.sys
[2011/03/28 11:06:56 | 000,066,591 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el90xbc5.sys
[2011/03/28 11:06:53 | 000,077,386 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el656nd5.sys
[2011/03/28 11:06:42 | 000,069,194 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el656cd5.sys
[2011/03/28 11:06:42 | 000,026,141 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el589nd5.sys
[2011/03/28 11:06:41 | 000,069,692 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el575nd5.sys
[2011/03/28 11:06:41 | 000,055,999 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el556nd5.sys
[2011/03/28 11:06:41 | 000,024,653 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el574nd4.sys
[2011/03/28 11:06:40 | 000,044,103 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el515.sys
[2011/03/28 11:06:38 | 000,050,719 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\e1000nt5.sys
[2011/03/28 11:06:38 | 000,019,594 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\e100isa4.sys
[2011/03/28 11:06:35 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dshowext.ax
[2011/03/28 11:06:34 | 000,334,208 | ---- | C] (Yamaha Corp.) -- C:\WINDOWS\System32\dllcache\ds1wdm.sys
[2011/03/28 11:06:33 | 000,020,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dpti2o.sys
[2011/03/28 11:06:30 | 000,206,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dot4.sys
[2011/03/28 11:06:30 | 000,028,062 | ---- | C] (National Semiconductor Coproration) -- C:\WINDOWS\System32\dllcache\dp83820.sys
[2011/03/28 11:06:30 | 000,023,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dot4usb.sys
[2011/03/28 11:06:30 | 000,012,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dot4prt.sys
[2011/03/28 11:06:30 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dot4scan.sys
[2011/03/28 11:06:27 | 000,029,696 | ---- | C] (CNet Technology, Inc.                                                    ) -- C:\WINDOWS\System32\dllcache\dm9pci5.sys
[2011/03/28 11:06:24 | 000,026,698 | ---- | C] (D-Link Corporation) -- C:\WINDOWS\System32\dllcache\dlh5xnd5.sys
[2011/03/28 11:05:24 | 000,024,649 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\dfe650d.sys
[2011/03/28 11:05:24 | 000,024,648 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\dfe650.sys
[2011/03/28 11:05:23 | 000,256,512 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\devcon32.dll
[2011/03/28 11:05:23 | 000,024,064 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\devldr32.exe
[2011/03/28 11:05:23 | 000,020,928 | ---- | C] (Digital Networks, LLC) -- C:\WINDOWS\System32\dllcache\defpa.sys
[2011/03/28 11:05:22 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dc260usd.dll
[2011/03/28 11:05:22 | 000,007,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ddsmc.sys
[2011/03/28 11:05:21 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dc240usd.dll
[2011/03/28 11:05:21 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dc210usd.dll
[2011/03/28 11:05:21 | 000,063,208 | ---- | C] (Intel Corporation.) -- C:\WINDOWS\System32\dllcache\dc21x4.sys
[2011/03/28 11:05:21 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dc210_32.dll
[2011/03/28 11:05:17 | 000,179,584 | ---- | C] (Mylex Corporation) -- C:\WINDOWS\System32\dllcache\dac2w2k.sys
[2011/03/28 11:05:17 | 000,014,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dac960nt.sys
[2011/03/28 11:05:16 | 000,117,760 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\d100ib5.sys
[2011/03/28 11:05:02 | 000,093,952 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcwdm.sys
[2011/03/28 11:05:02 | 000,048,640 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwrwdm.sys
[2011/03/28 11:05:01 | 000,111,872 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcspud.sys
[2011/03/28 11:05:01 | 000,072,832 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbwdm.sys
[2011/03/28 11:05:01 | 000,003,584 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcosnt5.sys
[2011/03/28 11:05:01 | 000,003,072 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbmidi.sys
[2011/03/28 11:05:00 | 000,004,096 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\ctwdm32.dll
[2011/03/28 11:05:00 | 000,003,072 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbase.sys
[2011/03/28 11:04:58 | 000,096,256 | ---- | C] (Copyright (C) Creative Technology Ltd. 1994-2001) -- C:\WINDOWS\System32\dllcache\ctlsb16.sys
[2011/03/28 11:04:58 | 000,003,712 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\ctljystk.sys
[2011/03/28 11:04:57 | 000,006,912 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\ctlfacem.sys
[2011/03/28 11:04:56 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\csamsp.dll
[2011/03/28 11:04:56 | 000,042,112 | ---- | C] (Conexant Systems Inc.) -- C:\WINDOWS\System32\dllcache\crtaud.sys
[2011/03/28 11:04:55 | 000,216,064 | ---- | C] (COMPAQ Inc.) -- C:\WINDOWS\System32\dllcache\cpscan.dll
[2011/03/28 11:04:51 | 000,021,533 | ---- | C] (Compaq Computer Corporation) -- C:\WINDOWS\System32\dllcache\cpqndis5.sys
[2011/03/28 11:04:51 | 000,014,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cpqarray.sys
[2011/03/28 11:04:47 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\compbatt.sys
[2011/03/28 11:04:46 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cnusd.dll
[2011/03/28 11:04:46 | 000,039,936 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\dllcache\cnxt1803.sys
[2011/03/28 11:04:45 | 000,006,656 | ---- | C] (CMD Technology, Inc.) -- C:\WINDOWS\System32\dllcache\cmdide.sys
[2011/03/28 11:04:44 | 000,020,736 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\cmbp0wdm.sys
[2011/03/28 11:04:44 | 000,013,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cmbatt.sys
[2011/03/28 11:04:10 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\changer.sys
[2011/03/28 11:04:06 | 000,015,423 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\ch7xxnt5.dll
[2011/03/28 11:04:05 | 000,049,182 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cem56n5.sys
[2011/03/28 11:04:05 | 000,027,164 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\ce3n5.sys
[2011/03/28 11:04:05 | 000,022,044 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cem33n5.sys
[2011/03/28 11:04:05 | 000,022,044 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cem28n5.sys
[2011/03/28 11:04:04 | 000,021,530 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\ce2n5.sys
[2011/03/28 11:04:03 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cd20xrnt.sys
[2011/03/28 11:04:00 | 000,046,108 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cben5.sys
[2011/03/28 11:04:00 | 000,039,680 | ---- | C] (Silicom Ltd.) -- C:\WINDOWS\System32\dllcache\cb325.sys
[2011/03/28 11:04:00 | 000,037,916 | ---- | C] (Fast Ethernet Controller Provider) -- C:\WINDOWS\System32\dllcache\cb102.sys
[2011/03/28 11:03:50 | 000,244,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\camext20.ax
[2011/03/28 11:03:50 | 000,236,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\camext20.dll
[2011/03/28 11:03:50 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\camext30.dll
[2011/03/28 11:03:50 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\camext30.ax
[2011/03/28 11:03:49 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\camdrv21.sys
[2011/03/28 11:03:49 | 000,171,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\camdrv30.sys
[2011/03/28 11:03:49 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\camexo20.dll
[2011/03/28 11:03:49 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\camexo20.ax
[2011/03/28 11:03:48 | 000,314,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\camdro21.sys
[2011/03/28 11:03:31 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bulltlp3.sys
[2011/03/28 11:03:30 | 000,036,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthprint.sys
[2011/03/28 11:03:30 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthusb.sys
[2011/03/28 11:03:29 | 000,101,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthpan.sys
[2011/03/28 11:03:29 | 000,037,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthmodem.sys
[2011/03/28 11:03:29 | 000,031,529 | ---- | C] (BreezeCOM) -- C:\WINDOWS\System32\dllcache\brzwlan.sys
[2011/03/28 11:03:29 | 000,017,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthenum.sys
[2011/03/28 11:03:28 | 000,060,416 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brserwdm.sys
[2011/03/28 11:03:28 | 000,011,008 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brusbmdm.sys
[2011/03/28 11:03:28 | 000,010,368 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brusbscn.sys
[2011/03/28 11:03:28 | 000,009,728 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brserif.dll
[2011/03/28 11:03:27 | 000,039,552 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brparwdm.sys
[2011/03/28 11:03:27 | 000,005,120 | ---- | C] (Brother Industries,Ltd.) -- C:\WINDOWS\System32\dllcache\brscnrsm.dll
[2011/03/28 11:03:26 | 000,003,168 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brparimg.sys
[2011/03/28 11:03:25 | 000,041,472 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmfusb.dll
[2011/03/28 11:03:25 | 000,032,256 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmfrsmg.exe
[2011/03/28 11:03:25 | 000,029,696 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmflpt.dll
[2011/03/28 11:03:24 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\brmfcwia.dll
[2011/03/28 11:03:24 | 000,015,360 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmfbidi.dll
[2011/03/28 11:03:24 | 000,003,968 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brfiltup.sys
[2011/03/28 11:03:23 | 000,012,800 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brevif.dll
[2011/03/28 11:03:23 | 000,012,160 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brfiltlo.sys
[2011/03/28 11:03:23 | 000,002,944 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brfilt.sys
[2011/03/28 11:03:22 | 000,019,456 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brbidiif.dll
[2011/03/28 11:03:22 | 000,009,728 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brcoinst.dll
[2011/03/28 11:03:18 | 000,102,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\binlsvc.dll
[2011/03/28 11:03:18 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bdasup.sys
[2011/03/28 11:03:17 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bdaplgin.ax
[2011/03/28 11:03:15 | 000,054,271 | ---- | C] (Broadcom Corporation) -- C:\WINDOWS\System32\dllcache\bcm42xx5.sys
[2011/03/28 11:03:15 | 000,026,568 | ---- | C] (Broadcom Corporation) -- C:\WINDOWS\System32\dllcache\bcm4e5.sys
[2011/03/28 11:03:14 | 000,066,557 | ---- | C] (Broadcom Corporation) -- C:\WINDOWS\System32\dllcache\bcm42u.sys
[2011/03/28 11:03:14 | 000,036,128 | ---- | C] (3Dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\banshee.sys
[2011/03/28 11:03:14 | 000,014,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\battc.sys
[2011/03/28 11:03:13 | 000,342,336 | ---- | C] (3Dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\banshee.dll
[2011/03/28 11:03:13 | 000,096,640 | ---- | C] (Broadcom Corporation) -- C:\WINDOWS\System32\dllcache\b57xp32.sys
[2011/03/28 11:03:10 | 000,036,992 | ---- | C] (Aztech Systems Ltd) -- C:\WINDOWS\System32\dllcache\aztw2320.sys
[2011/03/28 11:02:55 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\avc.sys
[2011/03/28 11:02:55 | 000,036,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\avcaudio.sys
[2011/03/28 11:02:53 | 000,025,471 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\atv04nt5.dll
[2011/03/28 11:02:53 | 000,017,279 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\atv10nt5.dll
[2011/03/28 11:02:53 | 000,014,143 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\atv06nt5.dll
[2011/03/28 11:02:53 | 000,011,359 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\atv02nt5.dll
[2011/03/28 11:02:52 | 000,021,183 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\atv01nt5.dll
[2011/03/28 11:02:51 | 000,516,768 | ---- | C] (ATI Technologies Inc. ) -- C:\WINDOWS\System32\dllcache\ativvaxx.dll
[2011/03/28 11:02:50 | 000,032,768 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ativtmxx.dll
[2011/03/28 11:02:50 | 000,023,040 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ativmvxx.ax
[2011/03/28 11:02:50 | 000,009,728 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ativdaxx.ax
[2011/03/28 11:02:43 | 000,063,488 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinxsxx.sys
[2011/03/28 11:02:42 | 000,073,216 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atintuxx.sys
[2011/03/28 11:02:42 | 000,031,744 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinxbxx.sys
[2011/03/28 11:02:42 | 000,028,672 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinsnxx.sys
[2011/03/28 11:02:42 | 000,013,824 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinttxx.sys
[2011/03/28 11:02:41 | 000,104,960 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinrvxx.sys
[2011/03/28 11:02:41 | 000,057,856 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinbtxx.sys
[2011/03/28 11:02:41 | 000,052,224 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinraxx.sys
[2011/03/28 11:02:41 | 000,014,336 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinpdxx.sys
[2011/03/28 11:02:41 | 000,013,824 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinmdxx.sys
[2011/03/28 11:02:40 | 000,289,664 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atimpab.sys
[2011/03/28 11:02:40 | 000,281,600 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atimtai.sys
[2011/03/28 11:02:40 | 000,075,136 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atimpae.sys
[2011/03/28 11:02:40 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\atievxx.exe
[2011/03/28 11:02:39 | 000,382,592 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atidrab.dll
[2011/03/28 11:02:39 | 000,268,160 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atidvai.dll
[2011/03/28 11:02:39 | 000,137,216 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atidrae.dll
[2011/03/28 11:02:38 | 001,888,992 | ---- | C] (ATI Technologies Inc. ) -- C:\WINDOWS\System32\dllcache\ati3duag.dll
[2011/03/28 11:02:38 | 000,870,784 | ---- | C] (ATI Technologies Inc. ) -- C:\WINDOWS\System32\dllcache\ati3d1ag.dll
[2011/03/28 11:02:38 | 000,701,440 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati2mtag.sys
[2011/03/28 11:02:37 | 000,377,984 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati2dvaa.dll
[2011/03/28 11:02:37 | 000,327,040 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati2mtaa.sys
[2011/03/28 11:02:37 | 000,201,728 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati2dvag.dll
[2011/03/28 11:02:36 | 000,229,376 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati2cqag.dll
[2011/03/28 11:02:36 | 000,036,463 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1tuxx.sys
[2011/03/28 11:02:36 | 000,034,735 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1xsxx.sys
[2011/03/28 11:02:36 | 000,029,455 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1xbxx.sys
[2011/03/28 11:02:36 | 000,021,343 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1ttxx.sys
[2011/03/28 11:02:35 | 000,063,663 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1rvxx.sys
[2011/03/28 11:02:35 | 000,030,671 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1raxx.sys
[2011/03/28 11:02:35 | 000,026,367 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1snxx.sys
[2011/03/28 11:02:34 | 000,056,623 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1btxx.sys
[2011/03/28 11:02:34 | 000,012,047 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1pdxx.sys
[2011/03/28 11:02:34 | 000,011,615 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1mdxx.sys
[2011/03/28 11:02:27 | 000,097,354 | ---- | C] (Bay Networks, Inc.) -- C:\WINDOWS\System32\dllcache\aspndis3.sys
[2011/03/28 11:02:21 | 000,014,848 | ---- | C] (Advanced System Products, Inc.) -- C:\WINDOWS\System32\dllcache\asc3550.sys
[2011/03/28 11:02:20 | 000,026,496 | ---- | C] (Advanced System Products, Inc.) -- C:\WINDOWS\System32\dllcache\asc.sys
[2011/03/28 11:02:20 | 000,022,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\asc3350p.sys
[2011/03/28 11:02:05 | 000,006,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\apmbatt.sys
[2011/03/28 11:02:04 | 000,043,008 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\System32\dllcache\amdagp.sys
[2011/03/28 11:02:04 | 000,036,224 | ---- | C] (ADMtek Incorporated.) -- C:\WINDOWS\System32\dllcache\an983.sys
[2011/03/28 11:02:04 | 000,012,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\amsint.sys
[2011/03/28 11:02:03 | 000,042,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\alim1541.sys
[2011/03/28 11:02:03 | 000,016,969 | ---- | C] (AmbiCom, Inc.) -- C:\WINDOWS\System32\dllcache\amb8002.sys
[2011/03/28 11:02:03 | 000,005,248 | ---- | C] (Acer Laboratories Inc.) -- C:\WINDOWS\System32\dllcache\aliide.sys
[2011/03/28 11:02:02 | 000,027,678 | ---- | C] (Acer Laboratories Inc.) -- C:\WINDOWS\System32\dllcache\ali5261.sys
[2011/03/28 11:02:02 | 000,026,624 | ---- | C] (Acer Laboratories Inc.) -- C:\WINDOWS\System32\dllcache\alifir.sys
[2011/03/28 11:02:01 | 000,056,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aic78xx.sys
[2011/03/28 11:02:01 | 000,055,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aic78u2.sys
[2011/03/28 11:02:01 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aha154x.sys
[2011/03/28 11:01:55 | 000,044,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agpcpq.sys
[2011/03/28 11:01:55 | 000,042,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agp440.sys
[2011/03/28 11:01:54 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agcgauge.ax
[2011/03/28 11:01:53 | 000,003,775 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\adv11nt5.dll
[2011/03/28 11:01:53 | 000,003,711 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\adv09nt5.dll
[2011/03/28 11:01:53 | 000,003,647 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\adv07nt5.dll
[2011/03/28 11:01:53 | 000,003,135 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\adv08nt5.dll
[2011/03/28 11:01:52 | 000,004,255 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\adv01nt5.dll
[2011/03/28 11:01:52 | 000,003,967 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\adv02nt5.dll
[2011/03/28 11:01:52 | 000,003,615 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\adv05nt5.dll
[2011/03/28 11:01:47 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\adpu160m.sys
[2011/03/28 11:01:47 | 000,046,112 | ---- | C] (Adaptec, Inc ) -- C:\WINDOWS\System32\dllcache\adptsf50.sys
[2011/03/28 11:01:46 | 000,010,880 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\admjoy.sys
[2011/03/28 11:01:45 | 000,747,392 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8830.sys
[2011/03/28 11:01:45 | 000,553,984 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8820.sys
[2011/03/28 11:01:44 | 000,584,448 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8810.sys
[2011/03/28 11:01:44 | 000,020,160 | ---- | C] (ADMtek Incorporated) -- C:\WINDOWS\System32\dllcache\adm8511.sys
[2011/03/28 11:01:44 | 000,007,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\adicvls.sys
[2011/03/28 11:01:43 | 000,061,440 | ---- | C] (Color Flatbed Scanner) -- C:\WINDOWS\System32\dllcache\acerscad.dll
[2011/03/28 11:01:42 | 000,297,728 | ---- | C] (Silicon Integrated Systems Corp.) -- C:\WINDOWS\System32\dllcache\ac97sis.sys
[2011/03/28 11:01:42 | 000,084,480 | ---- | C] (VIA Technologies, Inc.) -- C:\WINDOWS\System32\dllcache\ac97via.sys
[2011/03/28 11:01:41 | 000,231,552 | ---- | C] (Acer Laboratories Inc.) -- C:\WINDOWS\System32\dllcache\ac97ali.sys
[2011/03/28 11:01:41 | 000,096,256 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\ac97intc.sys
[2011/03/28 11:01:41 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\abp480n5.sys
[2011/03/28 11:01:40 | 000,462,848 | ---- | C] (Aureal Inc.) -- C:\WINDOWS\System32\dllcache\a3dapi.dll
[2011/03/28 11:01:40 | 000,098,304 | ---- | C] (Aureal Semiconductor) -- C:\WINDOWS\System32\dllcache\a3d.dll
[2011/03/28 11:01:34 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\61883.sys
[2011/03/28 11:01:32 | 000,148,352 | ---- | C] (3dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\3dfxvsm.sys
[2011/03/28 11:01:31 | 000,689,216 | ---- | C] (3dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\3dfxvs.dll
[2011/03/28 11:01:28 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\1394vdbg.sys
[2011/03/28 11:01:27 | 000,053,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\1394bus.sys
[2011/03/28 11:00:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2011/03/28 11:00:21 | 000,109,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp98swin.exe
[2011/03/28 11:00:21 | 000,014,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp98sadm.exe
[2011/03/28 10:42:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\PriceGong
[2011/03/28 10:41:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Freecorder
[2011/03/28 10:41:48 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
[2011/03/28 10:41:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\ConduitEngine
[2011/03/28 10:41:38 | 000,000,000 | ---D | C] -- C:\Program Files\ConduitEngine
[2011/03/28 10:40:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\Freecorder
[2011/03/28 10:40:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\FLVService
[2011/03/28 10:40:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Freecorder
[2011/03/28 10:39:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\Freecorder
[2011/03/28 10:39:58 | 000,000,000 | ---D | C] -- C:\Program Files\Freecorder
[2011/03/23 12:31:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2011/03/23 11:22:11 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2011/03/16 19:10:46 | 000,000,000 | -H-D | C] -- C:\$AVG
[2011/03/16 18:14:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\AVG10
[2011/03/16 18:10:53 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011/03/16 18:10:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2011
[2011/03/16 18:09:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2011/03/16 18:09:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
[2011/03/16 18:09:15 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2011/03/16 17:47:15 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/03/16 13:29:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/03/10 11:34:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/03/09 10:56:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\VS Revo Group
[2011/03/09 10:56:03 | 000,027,064 | ---- | C] (VS Revo Group) -- C:\WINDOWS\System32\drivers\revoflt.sys
[2011/03/09 10:56:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Revo Uninstaller Pro
[2011/03/09 10:55:56 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[6 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[46 C:\Documents and Settings\Administrator\My Documents\*.tmp files -> C:\Documents and Settings\Administrator\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011/03/30 15:24:21 | 000,000,410 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{8BFB428B-A956-4BAC-B2D4-FDCAD16CEE5B}.job
[2011/03/30 15:21:28 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/03/30 15:13:03 | 001,263,721 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\tdsskiller.zip
[2011/03/30 14:48:00 | 000,000,900 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/30 13:45:20 | 007,858,208 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\2 Winning Tattslotto Tickets.jpg
[2011/03/30 13:09:46 | 013,496,453 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\3 Winning Tattslotto Tickets.jpg
[2011/03/30 12:38:36 | 013,702,958 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\5 Winning Tattslotto Tickets 2.jpg
[2011/03/30 12:07:08 | 011,507,368 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\5 Winning Tattslotto Tickets.jpg
[2011/03/30 09:41:28 | 110,353,329 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/03/30 05:48:00 | 000,000,896 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/29 18:35:11 | 000,106,698 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/03/29 09:41:18 | 110,164,074 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm.old
[2011/03/28 09:53:07 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/03/28 09:53:05 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/03/23 12:32:43 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2011/03/23 12:32:43 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2011/03/23 11:41:50 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/03/23 11:25:59 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/03/23 11:24:28 | 000,000,873 | ---- | M] () -- C:\WINDOWS\System32\spupdsvc.inf
[2011/03/22 23:54:16 | 006,854,650 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Barcode Petrol Voucher.jpg
[2011/03/22 11:26:19 | 002,157,440 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/03/20 23:15:57 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2011/03/10 11:40:51 | 000,010,158 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\AVGInstLog.cab
[2011/03/09 11:49:55 | 000,002,115 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[6 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[46 C:\Documents and Settings\Administrator\My Documents\*.tmp files -> C:\Documents and Settings\Administrator\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011/03/30 15:12:54 | 001,263,721 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\tdsskiller.zip
[2011/03/30 13:44:56 | 007,858,208 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\2 Winning Tattslotto Tickets.jpg
[2011/03/30 13:09:18 | 013,496,453 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\3 Winning Tattslotto Tickets.jpg
[2011/03/30 12:37:46 | 013,702,958 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\5 Winning Tattslotto Tickets 2.jpg
[2011/03/30 12:06:35 | 011,507,368 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\5 Winning Tattslotto Tickets.jpg
[2011/03/30 09:41:28 | 110,353,329 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/03/29 18:35:10 | 000,106,698 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/03/29 09:41:18 | 110,164,074 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm.old
[2011/03/28 11:23:17 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xrxftplt.exe
[2011/03/28 11:23:17 | 000,018,944 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xrxscnui.dll
[2011/03/28 11:15:42 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\dllcache\psisdecd.dll
[2011/03/28 11:15:42 | 000,033,280 | ---- | C] () -- C:\WINDOWS\System32\dllcache\psisrndr.ax
[2011/03/28 11:13:40 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msdvbnp.ax
[2011/03/28 11:08:51 | 000,165,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt53.dll
[2011/03/28 11:08:51 | 000,093,696 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt42.dll
[2011/03/28 11:08:50 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt34.dll
[2011/03/28 11:08:50 | 000,089,088 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt33.dll
[2011/03/28 11:08:49 | 000,083,968 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt21.dll
[2011/03/28 11:07:48 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll
[2011/03/28 11:02:51 | 000,026,624 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativxbar.sys
[2011/03/28 11:02:51 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atixbar.sys
[2011/03/28 11:02:50 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativttxx.sys
[2011/03/28 11:02:50 | 000,009,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativmdcd.sys
[2011/03/28 11:02:49 | 000,026,880 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atirtsnd.sys
[2011/03/28 11:02:49 | 000,017,152 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atitvsnd.sys
[2011/03/28 11:02:49 | 000,017,152 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atitunep.sys
[2011/03/28 11:02:48 | 000,049,920 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atirtcap.sys
[2011/03/28 11:02:43 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atipcxxx.sys
[2011/03/28 11:02:39 | 000,046,464 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atibt829.sys
[2011/03/28 10:44:23 | 000,000,410 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{8BFB428B-A956-4BAC-B2D4-FDCAD16CEE5B}.job
[2011/03/23 11:24:28 | 000,000,873 | ---- | C] () -- C:\WINDOWS\System32\spupdsvc.inf
[2011/03/22 23:53:37 | 006,854,650 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Barcode Petrol Voucher.jpg
[2011/03/10 11:40:51 | 000,010,158 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\AVGInstLog.cab
[2010/09/05 04:10:46 | 000,000,013 | ---- | C] () -- C:\WINDOWS\popcinfo.dat
[2010/07/10 06:04:40 | 000,041,872 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll
[2010/06/18 14:17:34 | 000,000,155 | ---- | C] () -- C:\WINDOWS\viewer.ini
[2010/06/18 14:17:27 | 000,000,083 | ---- | C] () -- C:\WINDOWS\artgalry.ini
[2010/06/18 14:16:59 | 000,004,028 | ---- | C] () -- C:\WINDOWS\MSWORKS3.INI
[2010/02/27 21:42:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EEventManager.INI
[2010/02/27 21:05:16 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2010/02/27 21:05:15 | 000,111,932 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2010/02/27 21:05:15 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat
[2010/02/27 21:05:15 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat
[2010/02/27 21:05:15 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2010/02/27 21:05:15 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
[2010/02/27 21:05:15 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
[2010/02/27 21:05:15 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
[2010/02/27 21:05:15 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
[2010/02/27 21:05:15 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
[2010/02/27 21:05:15 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2010/02/27 21:05:15 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2010/02/27 21:05:15 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2010/02/27 21:05:15 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2010/02/27 21:05:15 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2010/02/27 21:05:15 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2010/02/27 21:05:15 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2010/02/27 21:05:15 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2010/02/27 21:05:15 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2009/10/18 18:58:39 | 000,000,016 | ---- | C] () -- C:\WINDOWS\aebconfig.ini
[2009/09/18 17:19:08 | 000,000,023 | ---- | C] () -- C:\WINDOWS\ovas.ini
[2009/09/17 09:10:07 | 000,000,053 | ---- | C] () -- C:\WINDOWS\ArticleAssistant.ini
[2009/09/05 19:25:10 | 000,000,381 | ---- | C] () -- C:\WINDOWS\EMSOFT.INI
[2009/09/01 02:12:10 | 000,000,059 | ---- | C] () -- C:\WINDOWS\FAX.INI
[2009/08/09 17:29:06 | 000,000,637 | ---- | C] () -- C:\WINDOWS\aasinst.ini
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/08/01 13:54:53 | 000,000,221 | ---- | C] () -- C:\WINDOWS\NCLogConfig.ini
[2009/04/21 13:13:53 | 000,000,730 | ---- | C] () -- C:\WINDOWS\videoimp.ini
[2009/04/21 13:13:45 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2009/04/21 13:13:33 | 000,000,021 | ---- | C] () -- C:\WINDOWS\VI_setup.ini
[2009/04/21 13:11:22 | 000,000,021 | ---- | C] () -- C:\WINDOWS\PI4_setup.ini
[2009/04/21 13:10:08 | 000,118,784 | ---- | C] () -- C:\WINDOWS\ShowBmp.exe
[2009/04/21 13:10:08 | 000,001,888 | ---- | C] () -- C:\WINDOWS\CA533A.INI
[2009/04/21 13:10:08 | 000,001,325 | ---- | C] () -- C:\WINDOWS\Remove.ini
[2009/04/13 20:37:45 | 000,001,450 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\filterclsid.dat
[2009/03/22 09:43:41 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2009/03/04 13:36:00 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2009/03/04 12:30:54 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
[2009/02/15 21:18:11 | 000,029,184 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/03 19:30:45 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2009/02/03 19:03:00 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2008/09/18 17:01:08 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/09/15 23:57:18 | 000,000,281 | ---- | C] () -- C:\WINDOWS\EReg072.dat
[2008/09/15 23:50:27 | 000,000,168 | ---- | C] () -- C:\WINDOWS\atoms.ini
[2008/09/15 01:56:18 | 000,004,346 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008/09/15 01:55:18 | 002,157,440 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/09/15 00:10:21 | 000,000,737 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/09/14 23:51:17 | 000,000,095 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2008/09/14 22:33:02 | 000,000,139 | ---- | C] () -- C:\WINDOWS\SYMGAMES.INI
[2008/09/14 22:26:02 | 000,000,445 | ---- | C] () -- C:\WINDOWS\EntPack.dat
[2008/09/14 22:26:02 | 000,000,045 | ---- | C] () -- C:\WINDOWS\EntPack.ini
[2008/09/14 21:30:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/09/14 16:51:05 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
[2008/09/14 16:05:48 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008/09/14 16:02:11 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/04/14 05:55:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2006/12/31 07:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2001/08/23 22:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 22:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 22:00:00 | 000,440,646 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 22:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 22:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 22:00:00 | 000,070,516 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 22:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 22:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 22:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 22:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2001/07/07 03:00:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[1997/07/11 01:00:00 | 000,047,104 | ---- | C] () -- C:\WINDOWS\System32\WRKGADM.EXE
[1997/07/11 01:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/11 01:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/11 01:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
[1996/04/04 06:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
 
========== Custom Scans ==========
 
 
< %SYSTEMDRIVE%\*.exe >
 
< %systemroot%\*. /mp /s >
 
< c:\$recycle.bin\*.* /s >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-18 13:28:15
 
 
< MD5 for: AGP440.SYS  >
[2008/05/17 03:03:46 | 016,511,184 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/04/13 14:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\dllcache\agp440.sys
 
< MD5 for: ATAPI.SYS  >
[2008/05/17 03:03:46 | 016,511,184 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
 
< MD5 for: AUTOCHK.EXE  >
[2008/04/14 05:42:14 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\cmdcons\autochk.exe
[2008/04/14 05:42:14 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\WINDOWS\system32\autochk.exe
[2008/04/14 05:42:14 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\WINDOWS\system32\dllcache\autochk.exe
 
< MD5 for: BEEP.SYS  >
[2001/08/23 22:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\ERDNT\cache\beep.sys
[2001/08/23 22:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\system32\dllcache\beep.sys
[2001/08/23 22:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\system32\drivers\beep.sys
 
< MD5 for: EVENTLOG.DLL  >
[2008/04/14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
 
< MD5 for: EXPLORER.EXE  >
[2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\system32\dllcache\explorer.exe
 
< MD5 for: IMM32.DLL  >
[2008/04/14 05:41:56 | 000,110,080 | ---- | M] (Microsoft Corporation) MD5=0DA85218E92526972A821587E6A8BF8F -- C:\WINDOWS\ERDNT\cache\imm32.dll
[2008/04/14 05:41:56 | 000,110,080 | ---- | M] (Microsoft Corporation) MD5=0DA85218E92526972A821587E6A8BF8F -- C:\WINDOWS\system32\dllcache\imm32.dll
[2008/04/14 05:41:56 | 000,110,080 | ---- | M] (Microsoft Corporation) MD5=0DA85218E92526972A821587E6A8BF8F -- C:\WINDOWS\system32\imm32.dll
 
< MD5 for: KERNEL32.DLL  >
[2009/03/22 01:06:58 | 000,989,696 | ---- | M] (Microsoft Corporation) MD5=B921FB870C9AC0D509B2CCABBBBE95F3 -- C:\WINDOWS\ERDNT\cache\kernel32.dll
[2009/03/22 01:06:58 | 000,989,696 | ---- | M] (Microsoft Corporation) MD5=B921FB870C9AC0D509B2CCABBBBE95F3 -- C:\WINDOWS\system32\dllcache\kernel32.dll
[2009/03/22 01:06:58 | 000,989,696 | ---- | M] (Microsoft Corporation) MD5=B921FB870C9AC0D509B2CCABBBBE95F3 -- C:\WINDOWS\system32\kernel32.dll
[2008/04/14 05:41:58 | 000,989,696 | ---- | M] (Microsoft Corporation) MD5=C24B983D211C34DA8FCC1AC38477971D -- C:\WINDOWS\$NtUninstallKB959426$\kernel32.dll
[2009/03/22 00:59:23 | 000,991,744 | ---- | M] (Microsoft Corporation) MD5=DA11D9D6ECBDF0F93436A4B7C13F7BEC -- C:\WINDOWS\$hf_mig$\KB959426\SP3QFE\kernel32.dll
 
< MD5 for: MSWSOCK.DLL  >
[2008/06/21 04:46:57 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=832E4DD8964AB7ACC880B2837CB1ED20 -- C:\WINDOWS\ERDNT\cache\mswsock.dll
[2008/06/21 04:46:57 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=832E4DD8964AB7ACC880B2837CB1ED20 -- C:\WINDOWS\system32\dllcache\mswsock.dll
[2008/06/21 04:46:57 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=832E4DD8964AB7ACC880B2837CB1ED20 -- C:\WINDOWS\system32\mswsock.dll
[2008/04/14 05:42:02 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=B4138E99236F0F57D4CF49BAE98A0746 -- C:\WINDOWS\$NtUninstallKB951748$\mswsock.dll
[2008/06/21 04:43:05 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=FCEE5FCB99F7C724593365C706D28388 -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\mswsock.dll
 
< MD5 for: NDIS.SYS  >
[2008/04/14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ERDNT\cache\ndis.sys
[2008/04/14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\dllcache\ndis.sys
[2008/04/14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
 
< MD5 for: NETLOGON.DLL  >
[2008/04/14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
 
< MD5 for: NTFS.SYS  >
[2008/04/14 00:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\ERDNT\cache\ntfs.sys
[2008/04/14 00:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\system32\dllcache\ntfs.sys
[2008/04/14 00:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\system32\drivers\ntfs.sys
[2004/08/04 00:15:10 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\cmdcons\NTFS.SYS
 
< MD5 for: NTMSSVC.DLL  >
[2008/04/14 05:42:04 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=156F64A3345BD23C600655FB4D10BC08 -- C:\WINDOWS\ERDNT\cache\ntmssvc.dll
[2008/04/14 05:42:04 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=156F64A3345BD23C600655FB4D10BC08 -- C:\WINDOWS\system32\dllcache\ntmssvc.dll
[2008/04/14 05:42:04 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=156F64A3345BD23C600655FB4D10BC08 -- C:\WINDOWS\system32\ntmssvc.dll
 
< MD5 for: PROQUOTA.EXE  >
[2008/04/14 05:42:34 | 000,050,176 | ---- | M] (Microsoft Corporation) MD5=F6465A2EEF75468988A4FCF124148FA8 -- C:\WINDOWS\system32\dllcache\proquota.exe
[2008/04/14 05:42:34 | 000,050,176 | ---- | M] (Microsoft Corporation) MD5=F6465A2EEF75468988A4FCF124148FA8 -- C:\WINDOWS\system32\proquota.exe
 
< MD5 for: QMGR.DLL  >
[2008/04/14 05:42:04 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\ERDNT\cache\qmgr.dll
[2008/04/14 05:42:04 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\system32\dllcache\qmgr.dll
[2008/04/14 05:42:04 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\system32\qmgr.dll
 
< MD5 for: SCECLI.DLL  >
[2008/04/14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
 
< MD5 for: SFCFILES.DLL  >
[2008/04/14 05:42:06 | 001,614,848 | ---- | M] (Microsoft Corporation) MD5=9DD07AF82244867CA36681EA2D29CE79 -- C:\WINDOWS\ERDNT\cache\sfcfiles.dll
[2008/04/14 05:42:06 | 001,614,848 | ---- | M] (Microsoft Corporation) MD5=9DD07AF82244867CA36681EA2D29CE79 -- C:\WINDOWS\system32\dllcache\sfcfiles.dll
[2008/04/14 05:42:06 | 001,614,848 | ---- | M] (Microsoft Corporation) MD5=9DD07AF82244867CA36681EA2D29CE79 -- C:\WINDOWS\system32\sfcfiles.dll
 
< MD5 for: SPOOLSV.EXE  >
[2010/08/18 00:19:36 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=258DD5D4283FD9F9A7166BE9AE45CE73 -- C:\WINDOWS\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe
[2010/08/18 00:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\ERDNT\cache\spoolsv.exe
[2010/08/18 00:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\system32\dllcache\spoolsv.exe
[2010/08/18 00:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\system32\spoolsv.exe
[2008/04/14 05:42:38 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=D8E14A61ACIt's been almost a month since we started on this. Is there any change in your computer?Yes SuperDave I think there has been a significant improvement.

The drive has had a complete cleaning of unwanted programs and is running quite smoothly now. Viruses and potential threats have been removed and I feel that the drive/computer is once again reliable and safe to use for my banking. (This above all else is my greatest concern SuperDave.)

We have discovered during this journey that the system restore did not resolve the problem. MSE is removed but still wont reinstall, Security center will not change the automatic updates configuration and Adobe update installs, still fail. 
AVG is running and updating regularly.

Also that there is a problem with the Windows files and I dont have the CD for this build. (which just goes to show, me/others how important it is to back up your data.(Thank you Allan. See here for discussion/thread)).


I have learned different operations, that before hand I would not have had the confidence to even try.
I think that is what, you and CH ultimately are all about... teaching others and not just relying on the specialists and to build confidence to try things yourself always knowing that there is help at hand if I get stuck.

I have the external drive now.

Quote from: SuperDave on March 28, 2011, 12:50:56 PM
From what you're telling me, there is a problem with some of the Windows files. If you made a copy of your harddrive, you could use it to restore your computer back to when the copy was made and you should be back in business. I will check with my buddy to see if there's anything else we can do.

and with a little more help maybe I can restore my corrupted Windows file/s.

I think my computer is as good and clean as we can make it.

I am quite happy to start a new thread to restore the files, in a different forum if that is what you wish, because obviously your time to help one individual can be consuming when you can direct your expertise to others in need of your help.

I can only say at this time "Thank you" for your continued assistance and support SuperDave.

Thank you ImnoGuru.

Ok. You may be able to remove MSE with this tool.

Revo Uninstaller

Malware is often stored in System Restore so that every time you use System Restore you re-infect the computer.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
******************************************************
To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
*************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
**************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
1463.

Solve : memory stick, external HD errors from infection??

Answer»

I regularly use memory sticks and and external harddrive. Yesterday when I plugged in the external hard drive, I tried to open the drive in My COMPUTER. I get the following error message. Error loading setup 50045.fon The SPECIFIED module could not be FOUND. I RAN Malwarebytes and it did find a couple of items. I rebooted the computer and same thing. I plugged in a memory stick and it has the same error too. I re-ran MBAM, and it found a few things while scanning the external hard drive and the memory stick. Is this from one of the infections or something ELSE?

thanks

Chris

1464.

Solve : Malware Help Needed!?

Answer»

I've fixed the problem, what next?Please tell me how your computer is running. Any other issues?Running much better than it was but still seems slow when i go to access programs.   Once i pull up the internet, no issues there.  Just if i step away for awhile and then try to click on something, the response time is slow. Ok. Let's clean up. I have some instructions at the bottom for a slow computer.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its FOLDERS and files, hides System files and folders, and resets System Restore.
***************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how OFTEN you clean temp files, execution time should be ANYWHERE from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
*************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet SECURITY addon for your browser. It will KEEP you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Thank you Dave for all your help.  Seems to be doing much better.  You're welcome, Katman. I will lock this thread. If you need it opened, please pm me.
1465.

Solve : After running superantispyware my pc won't boot OS and blue screens!?

Answer»

Ok, that will take me a few days. Will you still be here? I should probably have it done by Sunday at the latest. I work during the day, that's why it will take so long. Quote

Will you still be here?
Unless the Grim Reaper gets me.All right, well I ran the Dr. Web Live CD and the BitDefender bootable USB. Both of them found viruses/spyware and I deleted/cleaned all of them. Unfortunately, my system still does not boot in regular or safe mode! 

I think I am MISSING a system file or something that tells my computer that an OS is installed. That's my best guess at least.

PS: thanks for waiting!

Some google searching showed me this website, which seems to confirm what I am suspecting. I think that Superantispyware did what this website says AVG does. I am missing a vital file for my computer to run which needs to be located and replaced. I haven't followed any other help sites or anything, I am just looking at information. Let me know what you think and thanks!

http://mikemstech.blogspot.com/2012/01/troubleshooting-0xc0000135.htmlPlease tell me what happens when you boot with the OS disk. When I boot the OS disk it goes to the install screen and I click the "repair" option in the bottom left. The next screen says "choose your OS" and has a little white box, but there is nothing in the box! There is no OS or anything. The other option in this screen is to "search for drivers." This allows me to search through my hard drive for a file, but I don't know which file I am supposed to find that will show that I have an OS installed.

When I was backing up my files I could navigate to the windows folder and look at all the system files I had there, so I know that my OS is still installed. A google search for this problem showed that a COMMON cause of this problem is missing a DLL or some other system file so my computer/OS disk no longer RECOGNIZES the OS. I really do not want to format and reinstall!

When I try to boot into regular or safe mode I still get the same blue screen mentioned in my first post and the article I linked in my last post.Here's a rescue disk that will let you boot your computer,run a scan and post the log. You can boot your computer again using this disk and save your important documents.

We are going to be using a Windows Recovery Environment to help disinfect the system so it may boot again.

Download the OTLPE Standard REATOGO Windows Recovery Environment.
  • Place a blank CD-R disc in to your CD burning drive.
  • Download OTLPEStd.exe and double-click on it to burn to a CD using an ISO Burner. One can be found here.
  • Reboot your system using the boot CD you just created.
  • Note : If you do not know how to set your computer to boot from CD follow the steps here
  • Your system should now display a REATOGO-X-PE desktop.
  • Double-click on the OTLPE icon.
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start. Change the following settings
  • Change Drivers to Non-Microsoft
  • Press Run Scan to start the scan.
  • When finished, the file will be saved  in drive C:\_OTL\MovedFiles
  • Copy this file to your USB drive if you do not have internet connection on this system
  • Please post the contents of the OTL.txt file in your reply.
Sorry for the long wait. I have been busy at work. I did the scan with OTLPE as you said. Here is the log:

OTL logfile created on: 1/30/2012 9:20:38 PM - Run
OTLPE by OldTimer - Version 3.1.48.0     Folder = X:\Programs\OTLPE
64bit-Windows 7 Ultimate Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): c:\pagefile.sys 9216 18432 [binary data]
 
%SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86)
Drive C: | 100.00 Mb Total Space | 73.82 Mb Free Space | 73.82% Space Free | Partition Type: NTFS
Drive D: | 931.50 Gb Total Space | 312.03 Gb Free Space | 33.50% Space Free | Partition Type: NTFS
Drive E: | 931.41 Gb Total Space | 104.63 Gb Free Space | 11.23% Space Free | Partition Type: NTFS
Drive X: | 284.12 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
 
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2011/11/09 18:40:36 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto] -- E:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE)
SRV:64bit: - [2009/11/26 01:47:36 | 000,665,320 | ---- | M] () [Auto] -- E:\Windows\System32\atwtusb.exe -- (WTService)
SRV:64bit: - [2009/07/13 20:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\System32\appmgmts.dll -- (AppMgmt)
SRV - [2011/12/15 04:39:18 | 000,008,192 | ---- | M] () [Auto] -- E:\Windows\SysWOW64\srvany.exe -- (KMService)
SRV - [2011/09/02 08:29:30 | 002,152,152 | ---- | M] (Lavasoft Limited) [On_Demand] -- E:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2011/08/03 06:50:00 | 002,255,464 | ---- | M] (NVIDIA Corporation) [Auto] -- E:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011/08/03 05:31:42 | 000,379,496 | ---- | M] (NVIDIA Corporation) [Auto] -- E:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011/07/12 19:27:09 | 000,411,432 | ---- | M] (Valve Corporation) [On_Demand] -- E:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011/06/06 14:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- E:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010/03/18 16:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled] -- E:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2007/09/21 13:02:02 | 000,393,216 | ---- | M] (NetGear) [Auto] -- E:\Windows\SysWOW64\WN311BFCS.exe -- (WN311BFCS)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2011/08/01 17:59:06 | 000,045,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\point64.sys -- (Point64)
DRV:64bit: - [2011/07/22 11:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- E:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV:64bit: - [2011/07/12 16:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- E:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV:64bit: - [2011/05/10 04:41:27 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2011/01/19 20:47:18 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto] -- E:\Windows\System32\drivers\cpuz135_x64.sys -- (cpuz135)
DRV:64bit: - [2010/11/20 06:07:06 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 06:03:44 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010/04/27 18:57:20 | 000,016,200 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\WmVirHid.sys -- (WmVirHid)
DRV:64bit: - [2010/04/27 18:57:12 | 000,026,440 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\WmBEnum.sys -- (WmBEnum)
DRV:64bit: - [2010/04/27 16:03:12 | 000,077,512 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\WmXlCore.sys -- (WmXlCore)
DRV:64bit: - [2010/04/27 16:02:42 | 000,043,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\WmFilter.sys -- (WmFilter)
DRV:64bit: - [2010/04/03 05:31:50 | 003,058,168 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\WN311B64.SYS -- (NTG43XX)
DRV:64bit: - [2009/08/26 00:15:10 | 000,007,552 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand] -- E:\Windows\System32\drivers\walvhid.sys -- (vhidmini)
DRV:64bit: - [2009/07/08 03:45:50 | 002,769,400 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009/07/01 14:20:56 | 000,339,744 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\nvmf6264.sys -- (NVNET)
DRV:64bit: - [2009/06/10 15:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- E:\Windows\System32\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 15:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\nvm62x64.sys -- (NVENETFD)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\system32\DRIVERS\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\system32\DRIVERS\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/05/14 11:26:24 | 000,015,416 | ---- | M] () [Kernel | On_Demand] -- E:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)
DRV:64bit: - [2009/03/08 06:16:14 | 000,007,680 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand] -- E:\Windows\System32\drivers\moufiltr.sys -- (moufiltr)
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\Administrator_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\Curtis_&_Andrea_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\Curtis_&_Andrea_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\Curtis_&_Andrea_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F0 E4 5B BA 76 D0 CB 01  [binary data]
IE - HKU\Curtis_&_Andrea_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
 
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:1.5.260.0
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6
FF - prefs.js..extensions.enabledItems: {1f91cde0-c040-11da-a94d-0800200c9a66}:4.1
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: [email protected]:1.6.2
FF - prefs.js..extensions.enabledItems: {2e61e246-e640-4c56-b1ed-f146dbed48cd}:1.2.1
 
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/FlashPlayer: E:\Windows\System32\Macromed\Flash\NPSWF64_11_1_102.dll ()
FF:64bit: - HKLM\Software\MozillaPlugins\microsoft.com/GENUINE:  File not found
FF:64bit: - HKLM\Software\MozillaPlugins\microsoft.com/OfficeAuthz,version=14.0: E:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\adobe.com/FlashPlayer: E:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\adobe.com/ShockwavePlayer: E:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\checkpoint.com/FFApi:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\divx.com/DivX Browser Plugin,version=1.0.0: E:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\divx.com/DivX VOD Helper,version=1.0.0: E:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\google.com/npPicasa3,version=3.0.0: E:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\microsoft.com/GENUINE:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\Microsoft.com/NpCtrl,version=1.0: E:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\microsoft.com/OfficeAuthz,version=14.0: E:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\microsoft.com/SharePoint,version=14.0: E:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\microsoft.com/WLPG,version=15.4.3502.0922: E:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\microsoft.com/WLPG,version=15.4.3508.1109: E:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\nvidia.com/3DVision: E:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\nvidia.com/3DVisionStreaming: E:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: E:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: E:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2011/04/26 14:45:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2011/04/26 14:45:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/01/02 12:39:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/09/15 16:17:27 | 000,000,000 | ---D | M]
 
[2011/02/19 15:52:41 | 000,000,000 | ---D | M] (No name found) -- E:\Users\Curtis & Andrea\AppData\Roaming\Mozilla\Extensions
[2011/12/25 00:40:16 | 000,000,000 | ---D | M] (No name found) -- E:\Users\Curtis & Andrea\AppData\Roaming\Mozilla\Firefox\Profiles\h1x3w93d.default\extensions
[2011/12/25 00:40:16 | 000,000,000 | ---D | M] (DownloadHelper) -- E:\Users\Curtis & Andrea\AppData\Roaming\Mozilla\Firefox\Profiles\h1x3w93d.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/05/05 18:19:22 | 000,000,000 | ---D | M] (No name found) -- E:\Users\Curtis & Andrea\AppData\Roaming\Mozilla\Firefox\Profiles\h1x3w93d.default\extensions\nostmp
[2011/03/12 15:16:28 | 000,000,000 | ---D | M] (Personas) -- E:\Users\Curtis & Andrea\AppData\Roaming\Mozilla\Firefox\Profiles\h1x3w93d.default\extensions\[email protected]
[2011/11/09 20:58:15 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) --
() (No name found) -- E:\USERS\CURTIS & ANDREA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H1X3W93D.DEFAULT\EXTENSIONS\{1F91CDE0-C040-11DA-A94D-0800200C9A66}.XPI
[2012/01/02 12:39:40 | 000,121,816 | ---- | M] (Mozilla Foundation) -- E:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/09/10 11:57:33 | 000,466,944 | ---- | M] (Catalina Marketing Corporation) -- E:\Program Files (x86)\mozilla firefox\plugins\NPcol400.dll
[2011/05/04 06:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/10/04 01:01:42 | 000,002,252 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/11/09 20:58:14 | 000,002,040 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
 
O1 HOSTS File: ([2012/01/15 18:41:54 | 000,000,098 | ---- | M]) - E:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: ::1       localhost
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - E:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - E:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O4:64bit: - HKLM..\Run: [IntelliPoint] E:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [MacroKeyManager] E:\Windows\System32\WTMKM.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] E:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Start WingMan Profiler] E:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [amd_dc_opt] E:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [AS00_WN311B] E:\Program Files\NETGEAR\WN311B\Utility\WN311B.exe (NetGear)
O4 - HKLM..\Run: [DivXUpdate] E:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKU\UpdatusUser_ON_E..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\UpdatusUser_ON_E..\RunOnce: [mctadmin]  File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\Administrator_ON_E\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Administrator_ON_E\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\Administrator_ON_E\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Administrator_ON_E\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 0
O7 - HKU\Curtis_&_Andrea_ON_E\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Curtis_&_Andrea_ON_E\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\Curtis_&_Andrea_ON_E\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Curtis_&_Andrea_ON_E\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\Curtis_&_Andrea_ON_E\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKU\LocalService_ON_E\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\LocalService_ON_E\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\NetworkService_ON_E\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\NetworkService_ON_E\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\systemprofile_ON_E\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\systemprofile_ON_E\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\UpdatusUser_ON_E\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\UpdatusUser_ON_E\Software\Policies\Microsoft\Internet Explorer\restrictions present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - E:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 -  File not found
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O34 - HKLM BootExecute: (lsdelete) -  File not found
64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found
64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
O37:64bit: - HKLM\...com [ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [ = exefile] -- "%1" %*
O37 - HKLM\...com [ = ComFile] -- "%1" %*
O37 - HKLM\...exe [ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/01/15 18:41:52 | 000,000,000 | ---D | C] -- E:\_OTL
[2012/01/14 18:47:53 | 000,000,000 | ---D | C] -- E:\.Trash-999
[3 E:\Windows\*.tmp files -> E:\Windows\*.tmp -> ]
[1 E:\Windows\SysWow64\*.tmp files -> E:\Windows\SysWow64\*.tmp -> ]
[1 E:\Windows\System32\drivers\*.tmp files -> E:\Windows\System32\drivers\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012/01/24 00:43:42 | 000,067,584 | --S- | M] () -- E:\Windows\bootstat.dat
[2012/01/24 00:43:35 | 535,683,071 | -HS- | M] () -- E:\hiberfil.sys
[2012/01/02 17:41:09 | 000,000,064 | ---- | M] () -- E:\Windows\SysWow64\rp_stats.dat
[2012/01/02 17:41:09 | 000,000,044 | ---- | M] () -- E:\Windows\SysWow64\rp_rules.dat
[2012/01/02 16:09:31 | 000,014,224 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/02 16:09:31 | 000,014,224 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/02 16:06:50 | 000,675,566 | ---- | M] () -- E:\Windows\System32\perfh009.dat
[2012/01/02 16:06:50 | 000,442,594 | ---- | M] () -- E:\Windows\System32\perfh012.dat
[2012/01/02 16:06:50 | 000,431,000 | ---- | M] () -- E:\Windows\System32\perfh011.dat
[2012/01/02 16:06:50 | 000,415,426 | ---- | M] () -- E:\Windows\System32\prfh0404.dat
[2012/01/02 16:06:50 | 000,398,324 | ---- | M] () -- E:\Windows\System32\prfh0804.dat
[2012/01/02 16:06:50 | 000,126,238 | ---- | M] () -- E:\Windows\System32\perfc011.dat
[2012/01/02 16:06:50 | 000,126,238 | ---- | M] () -- E:\Windows\System32\perfc009.dat
[2012/01/02 16:06:50 | 000,124,526 | ---- | M] () -- E:\Windows\System32\perfc012.dat
[2012/01/02 16:06:50 | 000,124,098 | ---- | M] () -- E:\Windows\System32\prfc0804.dat
[2012/01/02 16:06:50 | 000,119,184 | ---- | M] () -- E:\Windows\System32\prfc0404.dat
[2012/01/02 14:19:55 | 001,008,141 | ---- | M] () -- E:\Users\Curtis & Andrea\Desktop\rkill.com
[2012/01/02 14:17:40 | 001,578,288 | ---- | M] (Kaspersky Lab ZAO) -- E:\Users\Curtis & Andrea\Desktop\TDSSKiller.exe
[2012/01/02 14:11:46 | 000,000,000 | ---D | M] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/02 13:52:30 | 000,002,056 | ---- | M] () -- E:\Users\Curtis & Andrea\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/01/02 13:51:22 | 000,004,976 | -HS- | M] () -- E:\Users\Curtis & Andrea\AppData\Local\381wif72x512qf62m5wdo2u735427n12o0160
[2012/01/02 13:51:22 | 000,004,976 | -HS- | M] () -- E:\ProgramData\381wif72x512qf62m5wdo2u735427n12o0160
[3 E:\Windows\*.tmp files -> E:\Windows\*.tmp -> ]
[1 E:\Windows\SysWow64\*.tmp files -> E:\Windows\SysWow64\*.tmp -> ]
[1 E:\Windows\System32\drivers\*.tmp files -> E:\Windows\System32\drivers\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012/01/02 14:19:57 | 001,008,141 | ---- | C] () -- E:\Users\Curtis & Andrea\Desktop\rkill.com
[2012/01/02 12:53:15 | 000,004,976 | -HS- | C] () -- E:\Users\Curtis & Andrea\AppData\Local\381wif72x512qf62m5wdo2u735427n12o0160
[2012/01/02 12:53:15 | 000,004,976 | -HS- | C] () -- E:\ProgramData\381wif72x512qf62m5wdo2u735427n12o0160
[2011/12/31 00:19:01 | 000,001,674 | -HS- | C] () -- E:\Users\Curtis & Andrea\AppData\Local\s88mw2s78q
[2011/12/31 00:19:01 | 000,001,674 | -HS- | C] () -- E:\ProgramData\s88mw2s78q
[2011/12/28 04:11:47 | 000,002,052 | -HS- | C] () -- E:\Users\Curtis & Andrea\AppData\Local\le2sw25wpe16000eq3d62u3e361d6d868423f5o4g3goj
[2011/12/28 04:11:47 | 000,002,052 | -HS- | C] () -- E:\ProgramData\le2sw25wpe16000eq3d62u3e361d6d868423f5o4g3goj
[2011/12/26 22:36:14 | 000,009,530 | -HS- | C] () -- E:\ProgramData\dd36rm417bn1dh83kl0kjq27l5kl3207o3jv40n0318j3
[2011/12/12 20:35:01 | 000,008,988 | -HS- | C] () -- E:\ProgramData\nyvwwc4t3eyg0eco4bml8d514w2m
[2011/12/11 11:50:50 | 000,010,930 | -HS- | C] () -- E:\ProgramData\kkkyie8v2dkr8ipq7ofa1g307g6b
[2011/09/28 19:44:14 | 000,179,271 | ---- | C] () -- E:\Windows\SysWow64\xlive.dll.cat
[2011/08/03 05:31:54 | 000,311,912 | ---- | C] () -- E:\Windows\SysWow64\nvStreaming.exe
[2011/06/27 14:44:15 | 000,256,512 | ---- | C] () -- E:\Windows\PEV.exe
[2011/06/27 14:44:15 | 000,208,896 | ---- | C] () -- E:\Windows\MBR.exe
[2011/06/27 14:44:15 | 000,098,816 | ---- | C] () -- E:\Windows\sed.exe
[2011/06/27 14:44:15 | 000,080,412 | ---- | C] () -- E:\Windows\grep.exe
[2011/06/27 14:44:15 | 000,068,096 | ---- | C] () -- E:\Windows\zip.exe
[2011/06/03 19:41:12 | 000,155,745 | ---- | C] () -- E:\Windows\SysWow64\installservice.exe
[2011/05/24 01:49:53 | 000,085,504 | ---- | C] () -- E:\Windows\SysWow64\ff_vfw.dll
[2011/05/02 16:40:30 | 000,000,064 | ---- | C] () -- E:\Windows\SysWow64\rp_stats.dat
[2011/05/02 16:40:30 | 000,000,044 | ---- | C] () -- E:\Windows\SysWow64\rp_rules.dat
[2011/04/29 03:19:00 | 000,004,096 | ---- | C] () -- E:\Windows\d3dx.dat
[2011/04/19 15:23:11 | 000,008,229 | ---- | C] () -- E:\Windows\aiptbl.ini
[2011/02/23 21:06:35 | 000,061,440 | ---- | C] () -- E:\Windows\SysWow64\FDI.exe
[2011/02/23 20:28:56 | 000,252,928 | ---- | C] () -- E:\Windows\SysWow64\DShowRdpFilter.dll
[2011/02/19 22:42:19 | 000,000,000 | ---- | C] () -- E:\Windows\nsreg.dat
[2011/02/19 21:44:01 | 000,008,192 | ---- | C] () -- E:\Windows\SysWow64\srvany.exe
[2011/02/19 17:54:26 | 000,640,957 | ---- | C] () -- E:\Windows\unins000.exe
[2011/02/19 17:54:26 | 000,000,805 | ---- | C] () -- E:\Windows\unins000.dat
[2011/02/19 17:06:06 | 000,073,220 | ---- | C] () -- E:\Windows\SysWow64\EPPICPrinterDB.dat
[2011/02/19 17:06:06 | 000,031,053 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern131.dat
[2011/02/19 17:06:06 | 000,029,114 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern1.dat
[2011/02/19 17:06:06 | 000,027,417 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern121.dat
[2011/02/19 17:06:06 | 000,021,021 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern3.dat
[2011/02/19 17:06:06 | 000,015,670 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern5.dat
[2011/02/19 17:06:06 | 000,013,280 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern2.dat
[2011/02/19 17:06:06 | 000,010,673 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern4.dat
[2011/02/19 17:06:06 | 000,004,943 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern6.dat
[2011/02/19 17:06:06 | 000,001,140 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_PT.dat
[2011/02/19 17:06:06 | 000,001,140 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_BP.dat
[2011/02/19 17:06:06 | 000,001,137 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_ES.dat
[2011/02/19 17:06:06 | 000,001,130 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_FR.dat
[2011/02/19 17:06:06 | 000,001,130 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_CF.dat
[2011/02/19 17:06:06 | 000,001,104 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_EN.dat
[2011/02/19 17:06:06 | 000,000,097 | ---- | C] () -- E:\Windows\SysWow64\PICSDK.ini
[2011/02/19 15:43:12 | 002,870,032 | ---- | C] () -- E:\Windows\SysWow64\PerfStringBackup.INI
[2011/02/19 15:39:01 | 000,921,665 | ---- | C] () -- E:\Windows\SysWow64\msvcrt-ruby18.dll
[2011/02/19 15:39:01 | 000,271,264 | ---- | C] () -- E:\Windows\SysWow64\vbrun100.dll
[2011/02/19 15:39:01 | 000,210,944 | ---- | C] () -- E:\Windows\SysWow64\msvcrt10.dll
[2011/02/19 15:39:01 | 000,027,136 | ---- | C] () -- E:\Windows\SysWow64\pythonw.exe
[2011/02/19 15:39:01 | 000,026,624 | ---- | C] () -- E:\Windows\SysWow64\python.exe
[2011/02/19 15:39:01 | 000,020,537 | ---- | C] () -- E:\Windows\SysWow64\rubyw.exe
[2011/02/19 15:39:01 | 000,020,536 | ---- | C] () -- E:\Windows\SysWow64\ruby.exe
[2009/11/10 22:28:02 | 000,129,768 | ---- | C] () -- E:\Windows\RmTablet.exe
[2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- E:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- E:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- E:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- E:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- E:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:25:04 | 000,197,632 | ---- | C] () -- E:\Windows\SysWow64\ir32_32.dll
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- E:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- E:\Windows\SysWow64\mlang.dat
 
========== LOP Check ==========
 
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Application Data
[2011/05/29 01:27:26 | 000,000,000 | ---D | M] -- E:\ProgramData\AVAST Software
[2011/02/19 16:42:50 | 000,000,000 | ---D | M] -- E:\ProgramData\CheckPoint
[2011/09/09 15:15:36 | 000,000,000 | ---D | M] -- E:\ProgramData\DAEMON Tools Lite
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Desktop
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Documents
[2011/07/05 21:15:40 | 000,000,000 | ---D | M] -- E:\ProgramData\eMule
[2011/02/19 17:05:59 | 000,000,000 | ---D | M] -- E:\ProgramData\EPSON
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favorites
[2011/05/25 19:18:20 | 000,000,000 | ---D | M] -- E:\ProgramData\IObit
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Start Menu
[2011/04/19 15:23:48 | 000,000,000 | ---D | M] -- E:\ProgramData\Tablet
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Templates
[2011/12/17 03:56:28 | 000,000,000 | ---D | M] -- E:\ProgramData\Zoom Player
[2011/07/27 14:07:16 | 000,032,544 | ---- | M] () -- E:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
< End of report >


Computer still blue screens with same error upon boot and also with safe mode!It appears that your OS is located on the E drive and there is only 11% free space on that drive. Windows requires at least 15% free space to operate which could be one of your problems. This is also why it cannot find the OS when you boot with the OS disk.

* Open OTL
* Copy and Paste the following text in the codebox into the Custom Scans/Fixes window.

CODE: [Select]:OTL

:Files

E:\ProgramData\nyvwwc4t3eyg0eco4bml8d514w2m
E:\ProgramData\kkkyie8v2dkr8ipq7ofa1g307g6b

:COMMANDS
[resethosts]
[purity]
[start explorer]

* Click Run Fix
* OTLI2 may ask to reboot the machine. Please do so if asked.
* Click OK
* A report will open. Copy and Paste that report in your next reply.
*************************************************************
Please try re-booting in Normal Mode after doing the above.
Sorry for the delay, I am still really busy. I have two jobs, and one of them is high school teacher, so I have grading and WHATNOT to do when I get home. I really appreciate your help, and I'm sorry to make you wait like this.

Here is the log from the fix you gave me. I also deleted some games and movies on my hard drive that I didn't need in the hopes of clearing some more space for the OS.

========== OTL ==========
========== FILES ==========
E:\ProgramData\nyvwwc4t3eyg0eco4bml8d514w2m moved successfully.
E:\ProgramData\kkkyie8v2dkr8ipq7ofa1g307g6b moved successfully.
========== COMMANDS ==========
E:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTLPE by OldTimer - Version 3.1.48.0 log created on 02042012_175645

Booting normally and in safe mode still give the same bluescreen, and the windows CD still doesn't detect the OS. Quote
am still really busy. I have two jobs, and one of them is high school teacher, so I have grading and whatnot to do when I get home. I really appreciate your help, and I'm sorry to make you wait like this.
No need to apologize. Your job comes first especially in these trying times. I'm here every day.

Quote
and the windows CD still doesn't detect the OS.
Usually that means that the OS disk doesn't match the OS on the computer. In your case it's probably because the OS is on the E drive.
Download BlueScreenView to your desktop.
BlueScreenView
unzip downloaded file and double click on BlueScreenView.exe to run the program.
when scanning is done, go to EDIT - Select All
Go to FILE - SAVE Selected Items, and save the report as BSOD.txt
Open BSOD.txt in Notepad, copy all of the content, and paste it into your next reply.
How am I supposed to run it? I tried running through the OTPLE startup disc, but it didn't do anything.Unfortunately, we've come to the point where you should boot your computer using the OTLPE rescue disk and save all your important data to memory sticks or DVD's and prepare to reinstall your OS.SIGH, okay, well thank you for all your help. Quote from: CuNaMo on February 05, 2012, 03:03:37 PM
SIGH, okay, well thank you for all your help.
You're welcome. Sometimes you win some and sometimes you lose.
1466.

Solve : Website has been hacked again?

Answer»

I have a website hosted on Startlogic and it keeps getting hacked. I have changed my password and deleted all files and replaced with new ones that I have on my external hd.  When trying to open my website Advast blocked it from opening so I ran a scan through http://sitecheck.sucuri.net. (Log also attached). But even after deleting all files it still SCANS with the same results. Is there anyway for me to find these and remove them without paying to have it done. Also I ran a scan on my computer Windows 8.1 with MALWAREBYTES Anti-Malware and the log is also attached. I wasn't able to download the other two as requested. One wouldn't allow me to download and the other was a dead link. Any help would be greatly appreciated.  Startlogic is only suggesting hiring sitelock.


[attachment deleted by admin to conserve space]It appears that the problem is not with your computer but with the website. You should have Startlogic fix it for you.Thank you so much for your reply! I've already asked but they singled me out and said it wasn't on their end it was on mine. Do you know of any way to figure out how they're getting into my website? This is about the 6th time this has happened. I don't think it's my computer because I've scanned it with everything I can think of. I've gotten a couple of adware and removed pup, whatever that is - but it's showing it's CLEAN now with running 3 different anti virus and malware programs. THANKS again for your response. I wasn't able to download Adwcleaner yesterday. Could you TAKE a look at this attachment and see what you think? I'm not sure if  I should clean or not?

[attachment deleted by admin to conserve space]Yes, clean it.Your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help.Dave.

1467.

Solve : Game.EXE Bad Image Error?

Answer»

Hi
I have a serious problem
When I run the any game, two or THREE times on the error, and after a few minutes to play, the game will hang
These programs also got tested, but that does not work
SpyHunter
malwarebytes
ccleaner

Curious as to why you feel this is a virus or malware?

 It appears to be a bad install of the game, hopefully a legal install of the game and not an illegally downloaded IMAGE copy of Witcher 3 bundled with a trojan. The error message itself is telling you to uninstall and install a clean copy of the game.Based on a cursory search, The Witcher 3's minimum requirements INCLUDE specs like 6GB of RAM which leads me to believe the game doesn't work on 32-bit SYSTEMS.

1468.

Solve : Recently had a RUNDLL malware.?

Answer»

Hi I had a RUNDLL problem that said it was missing. Then i tried the forums guide on how to remove malware. It hasn't been showing but I am not sure if it is good.

Malwarebytes' Anti-Malware 1.24
Database version: 1036
Windows 5.1.2600 Service Pack 2

10:13:11 PM 09/08/2008
mbam-log-8-9-2008 (22-13-11).txt

Scan type: Quick Scan
Objects scanned: 45971
Time elapsed: 6 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 11
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 4
Files Infected: 9

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f8395920-840d-4347-b1d9-b5694a6d077f} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f8395920-840d-4347-b1d9-b5694a6d077f} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d7fd6c15-4927-4aae-bf12-fbdabd287eb1} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d7fd6c15-4927-4aae-bf12-fbdabd287eb1} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{d7fd6c15-4927-4aae-bf12-fbdabd287eb1} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bm07a827e6 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\zangotoolbar 4.8.2 (Adware.Zango) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\Outerinfo (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Temporary (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Dot1XCfg (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\JavaCore (Trojan.Downloader) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\kdjkmqst.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\000050.exe (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\Program Files\JavaCore\JavaCore .exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM07a827e6.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM07a827e6.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\oqtss.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\ijjistarter2FxB.exe (Trojan.Agent) -> Quarantined and deleted successfully.




HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:54:49 PM, on 25/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\FotomatDeviceConnect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel MATRIX Storage Manager\iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PAVILION&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PAVILION&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=1607
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PAVILION&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O2 - BHO: (no name) - {F5048629-2F0A-49BB-89BA-7C55D59AA570} - C:\WINDOWS\SYSTEM32\SSTQO.DLL (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ViewpointPhotosDeviceConnect] C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\FotomatDeviceConnect.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Download with ImTOO YouTube Video Converter - C:\Program Files\ImTOO\YouTube Video Converter\upod_link.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim .exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon/download/DSL/tgctlcm.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: iifdabb - iifdabb.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Creative Service for CDROM ACCESS - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 11717 bytes
Welcome to CH.

Download ViewpointKiller.zip

  • Unzip the program and all of the contents of ViewpointKiller.zip to a location such as your desktop.
  • Double click the ViewpointKiller icon to run ViewpointKiller.exe.
  • Select the File menu, and select Check to see if you have Viewpoint installed.
  • If ViewpointKiller indicates that any of the Viewpoint variants are installed, select the proper KILL option in the File menu.
  • Follow the prompts and instructions very carefully, answering Yes or No depending on which option you are most comfortable with.
  • The MSCONFIG instructions are very important, so be sure to read them carefully.
  • Note: When done with ViewpointKiller right click and delete all files that were unzipped.
.
----------

Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note:  It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
 
Double click combofix.exe & follow the prompts.
When finished ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.Hi thanks for the help, much appreciation.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:40:19 PM, on 25/08/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Xfire\xfire.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PAVILION&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=1607
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PAVILION&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll
O3 - Toolbar: (no name) - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - (no file)
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Download with ImTOO YouTube Video Converter - C:\Program Files\ImTOO\YouTube Video Converter\upod_link.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim .exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon/download/DSL/tgctlcm.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 10568 bytes


[recovering disk space -- attachment deleted by admin]
Download the Norton Removal Tool (SymNRT) to your Desktop.

Once downloaded please close ALL open browsers, also save any work because this may require a restart.

  • Go to your desktop and double click on the removal tool and then click Setup.
  • Once open Click Next
  • Accept the license agreement and click Next
  • Type in the letters/numbers that you see into the text box then click Next.
  • Then click Next and the tool will start running.
  • Once finished restart the PC and run the tool again to ensure everything has been removed.
----------

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

Folder::
C:\Program Files\AskSBar

RENV::
----a-w            67,112 2008-02-22 20:00:08  C:\Program Files\AIM\aim .exe
----a-w           180,269 2008-02-22 19:59:59  C:\Program Files\Common Files\Real\Update_OB\realsched .exe
----a-w           692,224 2008-02-22 20:00:09  C:\Program Files\Creative\Sync Manager Unicode\CTSyncU .exe
----a-w         1,077,248 2008-02-22 19:59:52  C:\Program Files\DISC\DISCover .exe
----a-w            61,440 2008-02-22 19:59:52  C:\Program Files\DISC\DiscUpdMgr .exe
----a-w           249,856 2008-02-22 19:59:53  C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp   .exe
----a-w            49,152 2008-02-22 19:59:52  C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08 .exe
----a-w            90,112 2008-02-22 19:59:52  C:\Program Files\HP DigitalMedia Archive\DMAScheduler .exe
----a-w           139,264 2008-02-22 19:59:50  C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif .exe
----a-w            83,608 2008-02-22 19:59:55  C:\Program Files\Java\jre1.6.0_01\bin\jusched .exe
----a-w         1,694,208 2008-02-22 20:00:03  C:\Program Files\Messenger\msmsgs .exe
----a-w           282,624 2008-02-22 19:59:59  C:\Program Files\QuickTime\qttask    .exe
----a-w         1,266,936 2008-02-22 20:00:11  C:\Program Files\Steam\Steam .exe
----a-w         3,477,504 2008-02-22 20:00:13  C:\Program Files\Veoh Networks\Veoh\VeohClient .exe
----a-w           438,359 2008-02-22 19:59:54  C:\Program Files\verizon\SmartBridge\MotiveSB .exe
----a-w           663,552 2008-02-22 19:59:55  C:\WINDOWS\CREATOR\Remind_XP .exe
----a-w           208,952 2008-02-22 19:59:56  C:\WINDOWS\ime\imjp8_1\IMJPMIG .EXE
----a-w            44,032 2008-02-22 19:59:57  C:\WINDOWS\ime\imkr6_1\IMEKRMIG .EXE
----a-w           237,568 2008-02-22 19:59:53  C:\WINDOWS\SMINST\RECGUARD .EXE
----a-w            15,360 2008-02-22 20:00:05  C:\WINDOWS\system32\ctfmon .exe
----a-w            77,824 2008-02-22 19:59:50  C:\WINDOWS\system32\hkcmd .exe
----a-w           118,784 2008-02-22 19:59:50  C:\WINDOWS\system32\igfxpers .exe
----a-w            59,392 2008-02-22 19:59:57  C:\WINDOWS\system32\IME\PINTLGNT\ImScInst .exe
----a-w           455,168 2008-02-22 19:59:58  C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP .EXE

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"=-
[-HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\[u]0[/u]49b147a]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM07a827e6]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dot1XCfg]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrModule12]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick combofix's window while it is running. That may cause your system to freezeHey I've attached the log because it was too large and exceeded the maximum allowed length.

[recovering disk space -- attachment deleted by admin]Looking better.

You may want to look here and get your antivirus updated to the latest supported version. AVG 7.5 Free ends 31st August 2008

----------

Your Java is out of date.

Older versions have vulnerabilities that malicious sites can use to infect your system.

Download JavaRa to your Desktop and unzip it to its own folder.

  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts. A log will appear (JavaRa.log), please post the contents of this log on the forum.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) 6 Update 7 (5th one down the list) version for your computer.
.
----------

  • Click START then RUN
  • Now type Combofix /u in the runbox
  • MAKE sure there's a space between Combofix and /u
  • Then hit Enter.

  • The above procedure will:
  • Delete the following:
  • ComboFix and its associated files and folders.
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Set a new, clean Restore Point.
.
----------

How is everything now?
1469.

Solve : Internet connection issue (Network cable unplugged/enabled)...Virus the cause??

Answer»

So here is the deal

My tech folks have came out and deemed my cable(ish) INTERNET (it is wirelessly transmitted from their tower to my roof and then via cord transfered to what they dubed a modem [teeeeeny thing] that then plugs into my computer) connection is...well fine. Its my computer ( my barely a month old HP pavillion dv9000) that is causing the connection to flicker at a consistent rate from "enabled" to "Network Cable Unplugged" .  I called HP and they  told me that is a virus that is doing this. Ahem. One I picked up from facebook and or myspace that automatically installs itself via java not necessarily from even someones page i visited but possibly a page ten times removed due to both sites being networking sites.  Idk. And at this point dont care I just want the darn thing fixed. I can pick up wireless connections with out an issue and will be going probably tommorow to pick up a wireless router, but i still would like to know what the drama is with my computer!

Any input would be appreciated and all three logs are attached, Thank You!!

[recovering disk space -- attachment deleted by admin]Hey there, Hanna, glad to see you took my advice and decided to stop by.  I'll take a quick look at your logs right now.Well, everything looks pretty clean to me.  You had nice easy logs.  Heh.  You don't have a third-party firewall installed (which I would recommend doing), but I'm usually a bit more lenient about this with Vista because the Vista Firewall is supposed to have decent protection.  You may still want to consider third-party SOFTWARE, however.

Other than that, things seem to look okay infection-wise.  But just so I know...who is your Internet Service Provider?  An entry in your HijackThis log points to a company called Ad-Base, which I'm not familiar with, so I'm a bit curious.Air Advantage, i think its a relatively new company. I appreciate you looking into it for me Chris! Just curious, I went through the satellite type of connection process with my aunts new PC about a month ago. Everything (including the tiny modem) was mailed to her and it was a straight forward procedure.....until I connected to the net.

A few new grey hairs, hours on the phone and a service call from the ISP and it was discovered that the filters between the PC and wall jack (telephone line) were the wrong kind. A new filter and everything was smoking right along.

Just a thought. It was working fine actually for a while, a storm hit and knocked out something on their tower, they fixed it the next day but my stuff wasnt up and running like it should have been. And someone hooked up to the connection effortlessly on their laptop so its an issue with mine.

My connection doesn't actually deal with a wall jack or even phone line  at all. I was wondering that since you didn't mention any phone line but thought I would voice my frustrations anyway I'm trying to find some sort of connection between Air Advantage and Ad-Base Systems/Group, but nothing's coming up so far.  I'm still looking into it, but it seems a LITTLE suspicious to me.

I'm going to have you TRY something real quick.  It's something I would normally advise against (anyone else reading this should not try anything like this), but I'm curious.  I'm going to go ahead and have you remove the entry in question.  If it's not supposed to be there, then everything should be fine.  If it's actually important, then it will likely disconnect you from the internet, but I will explain how to reverse the process...


1.  Open HijackThis (sniper) and click on Do a system scan only.
2.  Check the following entry:
O17 - HKLM\System\CCS\Services\Tcpip\..\{CA02BDA1-5EF4-4FAD-8EE0-38DC0765AED5}: NameServer = 64.136.173.5 64.136.164.77
3.  Click on Fix Checked.

This will remove the information from your computer's registry.  Now try performing your regular online activities.  Are you able to be online normally?  If following my steps has broken your internet connection, then do the following...

1.  Open HijackThis again.
2.  Click on View the list of backups.
3.  Place a checkmark next to the entry you removed, and then click on Restore.

This should return your internet access.  It may require you to restart, but you shouldn't have to.



Give this a try and see what happens.Keep in mind that this isn't something we normally try, but because I know you, I've decided that it gives me permission to test it out.  Heh.lol guinea pig ey? haha ok im going to give that a go.It should be just fine.  But just in case anything goes awry, I sent my phone number to your private messages.  Ha.ok did it, and still connected it seems.  wait.. maybe....And my internet connection is still doing what it was doing no change... and google refused to load for me. Haha. perhaps i should restore it?
If you are experiencing any problems, then yes, go ahead and restore it.  You said the internet connects to a sort of modem that then TRANSMITS the signal to your computer?  Since I can't see anything wrong software-wise, I suspect that either you are getting a weak signal (it's being transmitted a couple of times), or your modem and/or cable may be to blame.  Because you can still pick up a wireless signal without any trouble, I don't think your computer is at fault here.Ok rebooted back to normal. 

It connects to the modem and that plugs into my computer. Nothing right now is being wirelessly transmitted to m,y computer, it was just when i called tech support they told ,me to see if I was having this problem with wireless too so I had to lug it to school and tote it around all day while running errands.


And the modem and cable was working fine when it was plugged into the techs computer. *shrugs* he even commented on how fast of a connection I had, and i seen it was indeed working on his.

Its all odd as far as im concerned

1470.

Solve : trojan-zlob?

Answer»

I seem to have BECOME infected with a trojan! After running the prerequisites, Webroot  says I'm clean but would like some confirmation...

Logs attached. Thanks!!!! Reading the previous threads has been very helpful in "battling" this infection.


[recovering disk space -- attachment deleted by admin]Getting ready to take a look right now.  This should only take a few moments...Well, the scans seem to have picked up just about everything, so let's just remove these entries with HijackThis (close all other windows, including this one)...

R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O16 - DPF: {050A3800-6C03-48A5-A6D7-14CCF18A700D} (v4 silent install) - https://hef.metafileonline.com/tsweb/v4rdpchk.cab
O16 - DPF: {30439117-02CA-4FBA-ADAF-84C2D8E2004D} (v3 silent install) - http://hef.metafileonline.com/tsweb/v3rdpchk.cab



You may want to consider removing this one as well...
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe" -l

It is not MALICIOUS, but some people think of it as a form of spyware.  It's up to you.  Removing it will not harm your Earthlink connection.

Also, you have a program on your computer called SpiralFrog.  Is this related to the music site?  If so, you can leave it alone.

Another thing...you have anti-spyware, but I didn't notice any anti-virus.  You should look into getting a program such as Avast! or AVG.  I also don't see a reliable firewall.  You're vulnerable without a firewall, so you should look into getting either ZONEALARM, Kerio Personal Firewall, or Comodo.  They're all good free firewalls.  Just be sure you only have one installed at a time!  Download the firewall of your choice, DISCONNECT from the internet, disable Windows Firewall, and install your new firewall.




How's your computer running?Awesome! Thanks for the help.

I do use the music site SpiralFrog so that's the origin of that. Also, I use Webroot Spy Sweeper with Anti-Virus so I thought I had anti-virus protection. I'll take your firewall advice as well! Webroot is considered anti-spyware, which doesn't work the same as anti-virus.  I see that you have Symantec products on your computer, but it doesn't appear to be related to anti-virus (but I could be wrong).

1471.

Solve : take a look please?

Answer»

Did a stupid thing yesterday , tried downloading atorrent software from mininova which badly infected my computer to the extent that i had to reinstall windows.
Everything is now working fine but i still ran a couple of scans ,spybot , superanti spyware, and malwarebites which all found something ,so can one of you experts  take a look at my logs to see if alls ok.
when i say everything is ok it is except a couple of keys are not right the is now on the 2 key and the " is on the key ?
skyblue

[recovering disk space -- attachment deleted by admin]Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note:  It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
 
Double click combofix.exe & follow the prompts.
When finished ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

Important: Do not MOUSECLICK ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFixCheers evilfantasy
logs you need

[recovering disk space -- attachment deleted by admin]

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    ----------

    Use the
Kaspersky Online Scanner

In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon and choose Run as Administrator.

Click on SCAN NOW
Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • In Save as type: click the drop arrow and select: Text file [*.txt]
  • Then, click: Save
  • Save the file to your desktop.
Post the Kaspersky log in your next reply.

Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.scan report
oddjob

[recovering disk space -- attachment deleted by admin]You will end up destroying your Hard Drive using cracked software.

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Now download The Avenger by Swandog46 and save it to your Desktop.
  • Extract avenger.exe from the Zip file and save it to your Desktop
  • Run avenger.exe by double-clicking on it.
  • Do not change any CHECK box options!!
  • Copy everything in the Code box below, and paste it into the Input script here window:
Code: [Select]Comment:

Files to delete:
C:\Documents and Settings\Mike\Desktop\Anti Virus\VundoFix.exe
C:\Documents and Settings\Mike\Local Settings\Application Data\Microsoft\Outlook\outlook.pst
C:\Documents and Settings\Mike Carney\My Documents\Downloads\RegCure 1.5.0.0 + Crack + Latest Version + Keygens\CRACK\RegCure.exe
C:\Documents and Settings\Mike Carney\My Documents\Downloads\RegCure 1.5.0.0 + Crack + Latest Version + Keygens\RegCure 1.5.0.0 Trial.exe
C:\Documents and Settings\Mike Carney\My Documents\Downloads From Mininova\Mcafee 2008\McAfee    Total    Protection    2008  (Retail)  -  HeartBug\CDSetup.exe
C:\Documents and Settings\Mike Carney\My Documents\Downloads From Mininova\Nero 8 Ultra Edition 8.3.2.1 New  KeyGen + Activation + Serials[Full Activated]\Nero-8.3.2.1_eng_f.u.l.l\Nero-8.3.2.1_eng_trial_2.exe
C:\Documents and Settings\Mike.ATLAS-FEA1386A2\My Documents\Downloads From Mininova\Mcafee 2008\McAfee    Total    Protection    2008  (Retail)  -  HeartBug\CDSetup.exe
C:\Documents and Settings\Mike.ATLAS-FEA1386A2\My Documents\Downloads From Mininova\Nero 8 Ultra Edition 8.3.2.1 New  KeyGen + Activation + Serials[Full Activated]\Nero-8.3.2.1_eng_f.u.l.l\Nero-8.3.2.1_eng_trial_2.exe

  • Now click the Execute button.
  • Click YES to the prompt to confirm you want to execute.
  • Click Yes to the "Reboot now?" question that will appear when Avenger finishes running.
  • Your PC should reboot, if not, reboot it yourself.
  • A log file from Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
.
  • Add the Avenger log in your next post.
log

[recovering disk space -- attachment deleted by admin]Please do the following:

1. Download this diagnostics tool MGADiag.exe and save this to your Desktop.
2. Double-click on MGADiag.exe and click Continue
3. When the program has finished, click on Copy
4. Post the results in your next reply.
Quote
You will end up destroying your Hard Drive using cracked software.
Thanks for your advice i think i have learnt that lesson
btw the key board issue i have resolved in languages and region

cant do a copy of the report sshot
oddjob

[recovering disk space -- attachment deleted by admin]
    Download
OTMoveIt2 by OldTimer
  • Save it to your desktop.
Note: If you are running on Vista, right-click on OTMoveIt2.exe and choose Run As Administrator.

  • Double-click OTMoveIt2.exe to run it.
  • Copy the lines in the codebox below.
Code: [Select][kill explorer]
C:\Documents and Settings\Mike\Desktop\Anti Virus\VundoFix.exe
C:\Documents and Settings\Mike\Local Settings\Application Data\Microsoft\Outlook\outlook.pst
C:\Documents and Settings\Mike Carney\My Documents\Downloads\RegCure 1.5.0.0 + Crack + Latest Version + Keygens\CRACK\RegCure.exe
C:\Documents and Settings\Mike Carney\My Documents\Downloads\RegCure 1.5.0.0 + Crack + Latest Version + Keygens\RegCure 1.5.0.0 Trial.exe
C:\Documents and Settings\Mike Carney\My Documents\Downloads From Mininova\Mcafee 2008\McAfee    Total    Protection    2008  (Retail)  -  HeartBug\CDSetup.exe
C:\Documents and Settings\Mike Carney\My Documents\Downloads From Mininova\Nero 8 Ultra Edition 8.3.2.1 New  KeyGen + Activation + Serials[Full Activated]\Nero-8.3.2.1_eng_f.u.l.l\Nero-8.3.2.1_eng_trial_2.exe
C:\Documents and Settings\Mike.ATLAS-FEA1386A2\My Documents\Downloads From Mininova\Mcafee 2008\McAfee    Total    Protection    2008  (Retail)  -  HeartBug\CDSetup.exe
C:\Documents and Settings\Mike.ATLAS-FEA1386A2\My Documents\Downloads From Mininova\Nero 8 Ultra Edition 8.3.2.1 New  KeyGen + Activation + Serials[Full Activated]\Nero-8.3.2.1_eng_f.u.l.l\Nero-8.3.2.1_eng_trial_2.exe
EmptyTemp
[start explorer]
  • Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) and paste it in your next reply.
  • Close OTMoveIt2
.
----------

Now run a new HijackThis scan and post the log.where are we going with this, am i infected?
Explorer killed successfully
File/Folder C:\Documents and Settings\Mike\Desktop\Anti Virus\VundoFix.exe not found.
File/Folder C:\Documents and Settings\Mike\Local Settings\Application Data\Microsoft\Outlook\outlook.pst not found.
File/Folder C:\Documents and Settings\Mike Carney\My Documents\Downloads\RegCure 1.5.0.0 + Crack + Latest Version + Keygens\CRACK\RegCure.exe not found.
File/Folder C:\Documents and Settings\Mike Carney\My Documents\Downloads\RegCure 1.5.0.0 + Crack + Latest Version + Keygens\RegCure 1.5.0.0 Trial.exe not found.
File/Folder C:\Documents and Settings\Mike Carney\My Documents\Downloads From Mininova\Mcafee 2008\McAfee    Total    Protection    2008  (Retail)  -  HeartBug\CDSetup.exe not found.
< C:\Documents and Settings\Mike Carney\My Documents\Downloads From Mininova\Nero 8 Ultra Edition 8.3.2.1 New  KeyGen + Activation + Serials[Full Activated]\Nero-8.3.2.1_eng_f.u.l.l\Nero-8.3.2.1_eng_trial_2.exe >
File/Folder C:\Documents and Settings\Mike Carney\My Documents\Downloads From Mininova\Nero 8 Ultra Edition 8.3.2.1 New  KeyGen + Activation + Serials[Full Activated]\Nero-8.3.2.1_eng_f.u.l.l\Nero-8.3.2.1_eng_trial_2.exe not found.
File/Folder C:\Documents and Settings\Mike.ATLAS-FEA1386A2\My Documents\Downloads From Mininova\Mcafee 2008\McAfee    Total    Protection    2008  (Retail)  -  HeartBug\CDSetup.exe not found.
< C:\Documents and Settings\Mike.ATLAS-FEA1386A2\My Documents\Downloads From Mininova\Nero 8 Ultra Edition 8.3.2.1 New  KeyGen + Activation + Serials[Full Activated]\Nero-8.3.2.1_eng_f.u.l.l\Nero-8.3.2.1_eng_trial_2.exe >
File/Folder C:\Documents and Settings\Mike.ATLAS-FEA1386A2\My Documents\Downloads From Mininova\Nero 8 Ultra Edition 8.3.2.1 New  KeyGen + Activation + Serials[Full Activated]\Nero-8.3.2.1_eng_f.u.l.l\Nero-8.3.2.1_eng_trial_2.exe not found.
< EmptyTemp >
File delete failed. C:\DOCUME~1\MIKE~1.ATL\LOCALS~1\Temp\~DF2475.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\MIKE~1.ATL\LOCALS~1\Temp\~DF2489.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\MIKE~1.ATL\LOCALS~1\Temp\~DFC204.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\PCPalSrvHost.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_2Fe45bzcI1jfxQI scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_31g49IvlLdhrJcc scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_J2mg6aSWeVftDZf scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
Explorer started successfully
 
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08172008_190850hjt log

[recovering disk space -- attachment deleted by admin] Quote
where are we going with this

Cleaning the computer... Would you rather stop?

Run this online scan. Requires Internet Explorer

Use the ESET Nod32 Online Scanner

1. Check the box next to YES, I accept the Terms of Use.
2. Click Start
3. When asked, allow the activex control to install
4. Click Start
5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
6. Click Scan
7. Wait for the scan to finish
8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply Quote
Cleaning the computer... Would you rather stop?
not at all, just thought that if i did a complete reinstall of windows that it would take care of any viruses and problems i was having ,so thou i did a complete install that viruses are still lurking ? btw that scan was 5 hours
skyblue

[recovering disk space -- attachment deleted by admin]Reinstalling is always the safest way as it will remove anything that we may never find this way.

The log is clean though.

1. Double click OTMoveIt2.exe to launch it.
Vista users right click and choose Run As Administrator
2. Click on the CleanUp! button.
3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
5. Once complete exit out of OTMoveIt2

----------

Set a New Restore Point to prevent possible reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
  • Go to Start > Programs > Accessories > System Tools and click System Restore
  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
  • The new restore point will be stamped with the current date and time. KEEP a log of this so you can find it easily should you need to use System Restore.
  • Next go to Start > Run and type Cleanmgr
  • Click OK
  • Click the More Options Tab.
  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide or Windows Vista System Restore Guide
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

----------

Please keep these programs up-to-date and run them whenever you suspect a problem. A number of programs have resident protection and it is a GOOD idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall and scanning anti-spyware program at a time. Passive protectors, like SpywareBlaster can be run with any of them.

Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

To prevent unknown applications from being installed on your computer install WinPatrol 2008
* Using Winpatrol to protect your computer from malicious software

I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
1472.

Solve : Installing Spybot ( other programs without internet access? )?

Answer» YEP, were DONE here.
1473.

Solve : Virus and spyware removal?

Answer» NONE
1474.

Solve : Windows Data Execution Prevention closes IE8?

Answer»

Everytime I close a page or tab in IE8, I get a message saying "Internet Explorer has stopped working...Windows is checking for a SOLUTION to this problem" Then I have to hit Close Program. After that a box pops up in my toolbar saying"Data Execution Prevention has closed internet explorer to protect your computer" (copied from a Jul 6 message)

I have the same problem. I read the "Read this before requesting malware..." and have accomplished steps A, 1, & 5.  Don't believe that I'm smart ENOUGH to TRY your self help process as it has taken me quite a long time to figure out how to get this WINDOW to open.  I will try to start step #2 while I WAIT for your response.
Thanks, RonI tried steps 2 & 3. Step 3 log is attached - I hope.

[attachment deleted by admin]Here are the logs from steps 4 & 6 - I hope

[attachment deleted by admin]

1475.

Solve : AVG detections?

Answer»

Well, I had AVG turned off (Resident Shield that is) that whole time before and after ComboFix did it's job. I just now turned it back on and the constant trojan notifications have stopped.. so problem solved there. All AVG seems to be running fine now. Is it safe to empty the vault of all those "infections"?

As for Malwarebytes'... I'm still having the same issue. I assume you don't know the problem there, eh?Not sure what's going on with MBAM.

Please do this.

1. Uninstall Malwarebytes' Anti-Malware using Add/Remove programs in the control panel. (if you can)
2. Restart your computer (very important)
3. Download and run this utility. http://www.malwarebytes.org/mbam-clean.exe
4. It will ask to restart your computer (please allow it to).

Now go ahead with the other steps. We can try MBAM again after everything else is done.
Alright, I did the ComboFix uninstall, TFC, and Kscan. The latter's report is posted below.

A couple questions...

The ComboFix uninstall didn't get rid of the icon on the desktop. Should I delete that since all the other things related to it were (probably) uninstalled? And in general... what programs (that you've had me install throughout the process) would you suggest I keep to help keep the computer in shape on a regular basis? Are there any that I can/should get rid of when I'm done?

On a related note (to the remaining ComboFix icon), I downloaded JavaRa to get rid of older Java VERSIONS (when I went through your removal tutorial). When I used the program it said that it got rid of jre1.6.0_07 but when I look in my program files, there's still an 80mb folder there. I assume it did it's job, but I was curious about that.

And finally, it seems several things around my computer have returned to default settings. Is that a "side effect" of ComboFix? Things like the wallpaper changing and icons returning (without performing a system restore) make me a little wary.


As for Malwarebytes', I uninstalled that yesterday after we tried the redownload and installation. I'm pretty sure I've restarted several times since then. Should I restart yet again and then try your link?


--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
 Saturday, July 18, 2009
 Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001)
 Kaspersky Online Scanner  version: 7.0.26.13
 Program database last update: Saturday, July 18, 2009 09:35:29
 Records in database: 2486942
--------------------------------------------------------------------------------

Scan settings:
   Scan using the following database: extended
   Scan archives: yes
   Scan mail databases: yes

Scan area - My Computer:
   C:\
   D:\
   E:\

Scan statistics:
   Files scanned: 132957
   Threat name: 0
   Infected objects: 0
   Suspicious objects: 0
   Duration of the scan: 01:53:30

No malware has been detected. The scan area is clean.

The selected area was scanned.


---

It seems this is clean One note on it THOUGH. I assume it performed a complete scan, but I can't be sure since I went to sleep and after waking up, the computer was in sleep mode. I assume I wouldn't suspend while the scan was going...

Is there a way to check the number of files on the computer matches what was scanned? Quote

The ComboFix uninstall didn't get rid of the icon on the desktop. Should I delete that since all the other things related to it were (probably) uninstalled?

You can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt

Quote
And in general... what programs (that you've had me install throughout the process) would you suggest I keep to help keep the computer in shape on a regular basis? Are there any that I can/should get rid of when I'm done?

Keep Malwarebytes and SUPERAntispyware. Update ans run them now and then to be sure nothing else has gotten into the computer.

Also keep CCleaner. You can use it as a daily drive cleaner.

Quote
got rid of jre1.6.0_07 but when I look in my program files, there's still an 80mb folder there.

There should only be one folder inside of the Java folder from the newest version of Java.

Quote
And finally, it seems several things around my computer have returned to default settings. Is that a "side effect" of ComboFix? Things like the wallpaper changing and icons returning (without performing a system restore) make me a little wary.

Yes some of the tools we use reset Windows to it's default settings.


Quote
As for Malwarebytes', I uninstalled that yesterday after we tried the redownload and installation. I'm pretty sure I've restarted several times since then. Should I restart yet again and then try your link?

Try malwarebytes again. If it won't work let me know the exact error you get.Thank you for the advice.

I used the MBAM cleaner and then reinstalled and I still get the same problem. Right after the installation bar is complete a Microsoft Windows notification pops-up that says "Malwarebytes' Anti-Malware has stopped working" then it searches for a solution, then says "A problem caused the program to stop working correctly. Windows will close the program and notify you if a solution is available". Then I press the close button. Then the same notification pops up again. It always happens twice. After that, it says it installed successfully and then whenever it/I try to launch it, the same notification pops up twice again.

The way I got that scan that I provided you before is because I rebooted in safe mode and it worked there.I'm not sure I've ever seen that error with MBAM before. You might want to mention it in their forums. http://www.malwarebytes.org/forums/index.php?showforum=41

Final steps and suggestions.

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to SEE if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Alright, I might mention the Malwarebytes' issue there when I get the chance.

I updated everything detected in SSI. I'll be checking out the rest in the near future. I also wanted to know if there is a safe registry cleaner that you'd recommend or if you think it's best to leave it alone. I just want to make sure everything is cleaned out when I uninstall programs. I was also curious about the Kapersky Scan. Is there anything I need to clear out that it downloaded? Lastly, I use the No Script add-on for Firefox sometime. I got that malware when I had it disabled. I dislike how it restricts so many things on websites, but I've never had virus issues while using it. What's you opinion on that add-on?

And about the Java updates. I now have 3 folders in C:\Program Files\Java  (jre6, jre1.6.0_07, jre1.6.0_13). Since you said I should only have 1, should I delete any of them?



Thank you so much for your time and help Kevin. I'm very grateful. Quote
I also wanted to know if there is a safe registry cleaner that you'd recommend or if you think it's best to leave it alone.

Unless you really know what you are doing then leave them alone. Use Revo Uninstaller to completely and safely remove software.

* Open Revo and let the list populate (can take several seconds to finish).
* Right click what you want to uninstall and choose Uninstall
* Next choose Advanced then click Next
* This will (try to) launch the programs built in uninstaller and go through the normal uninstall process.
* If the uninstaller fails just continue on with the Revo instructions.
* Once complete: In Revo Uninstaller click Next and Revo will scan the registry for LEFTOVERS.
* This scan can take several seconds.
* Once the results are shown look at each one to ensure they are all related to the program that was uninstalled.
* Choose Select All then click Delete
* Click Next and Revo will scan for any files or folders that were not removed.
* If any files/folders are found choose Select all > Delete

Quote
I was also curious about the Kapersky Scan. Is there anything I need to clear out that it downloaded?

I think there is a Kaspersky entry in Add/Remove Programs you can uninstall.

Quote
Lastly, I use the No Script add-on for Firefox

I'm the same as you. NoScript is a great add on but it blocks too much so I don't use it. I rely on Spywareblaster and Spybots Immunize. Those and Avast antivirus have kept me safe.

Quote
(jre6, jre1.6.0_07, jre1.6.0_13)

The newest version is Sun Java Runtime Environment 6 Update 14 so you are still out of date.

First install the new Sun Java Runtime Environment

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close all browser windows before beginning the install.

Remove the old version(s)

Download JavaRa
* Unzip the file and open the JavaRa.exe
* Click Remove Older Versions
* JavaRa will search for and remove any outdated version of Java and remove any that are found.
* Click ADDITIONAL Tasks
* Place a check next to Remove Useless JRE Files and click Go
* Exit JavaRa
* Delete the JavaRa files from the Desktop

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

Quote
Thank you so much for your time and help Kevin. I'm very grateful.

Your welcome. Let us know if anything else comes up.



1476.

Solve : DLLHOST.EXE/SVCHOST.EXE malicious actions??

Answer»

Hi, can anyone tell me how to fix this problem? Every few minutes the following message pops up on my computer from spyware dr:

"MALICIOUS ACTION BLOCKED

Spyware Doctor has blocked an application svchost.exe attempting to access a file.

Path:
C:\WINDOWS\SYSTEM32\DLLHOST.EXE"


I followed the steps in the "Before you post" posting and below are my logs attached

[attachment deleted by admin]Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copy and pasting it into the reply.thank you, here they are:


DDS (Ver_09-06-26.01) - NTFSx86
Run by PhilS at 17:35:36.99 on Sat 07/18/2009
Internet Explorer: 8.0.6001.18783 BrowserJavaVersion: 1.6.0_13
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.2814.1816 [GMT -7:00]

SP: Windows DEFENDER *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\SMINST\BLService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\PhilS\Desktop\dds.com
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.aol.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = *.local
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\2.0"
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\phils\appdata\roaming\mozilla\firefox\profiles\r2or64x5.default\
FF - prefs.js: browser.startup.homepage - hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-3-29 130936]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2009-3-29 51488]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2009-3-29 39200]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2009-3-29 159600]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-6-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-6-23 72944]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\sminst\BLService.exe [2008-8-4 361808]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2008-12-25 348752]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-12-26 24652]
R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2008-8-4 193840]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-5-9 43040]
R3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2009-3-29 64392]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2009-3-29 33056]
R3 ThreatFire;ThreatFire;c:\program files\spyware doctor\tfengine\tfservice.exe service --> c:\program files\spyware doctor\tfengine\TFService.exe service [?]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-6-23 7408]

=============== Created Last 30 ================

2009-07-17 14:47   1,056,768   a-------   c:\windows\system32\defltbase.sdb
2009-07-17 03:37      --dsh---   C:\$RECYCLE.BIN
2009-07-17 03:17   219,648   a-------   c:\windows\PEV.exe
2009-07-17 03:17   161,792   a-------   c:\windows\SWREG.exe
2009-07-17 03:17   98,816   a-------   c:\windows\sed.exe
2009-07-15 14:01      --d-----   c:\program files\Trend Micro
2009-07-15 01:51      --d-----   c:\users\phils\appdata\roaming\Malwarebytes
2009-07-15 01:51   38,160   a-------   c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-15 01:51      --d-----   c:\programdata\Malwarebytes
2009-07-15 01:51      --d-----   c:\progra~2\Malwarebytes
2009-07-15 01:51   19,096   a-------   c:\windows\system32\drivers\mbam.sys
2009-07-15 01:51      --d-----   c:\program files\Malwarebytes' Anti-Malware
2009-07-14 13:11   156,672   a-------   c:\windows\system32\t2embed.dll
2009-07-14 13:11   72,704   a-------   c:\windows\system32\fontsub.dll
2009-07-14 13:11   289,792   a-------   c:\windows\system32\atmfd.dll
2009-07-14 13:11   23,552   a-------   c:\windows\system32\lpk.dll
2009-07-14 13:11   10,240   a-------   c:\windows\system32\dciman32.dll
2009-07-14 10:16   224   a-------   c:\windows\system32\9B13A86D.plf
2009-07-14 10:06      --d-----   c:\programdata\Cached Installations
2009-07-14 10:06      --d-----   c:\progra~2\Cached Installations
2009-07-14 10:02      --d-----   c:\users\phils\appdata\roaming\ParetoLogic
2009-07-14 10:00      --d-----   c:\programdata\Downloaded Installations
2009-07-14 10:00      --d-----   c:\progra~2\Downloaded Installations
2009-07-14 09:59      --d-----   c:\users\phils\appdata\roaming\DriverCure
2009-07-14 09:58      --d-----   c:\programdata\ParetoLogic
2009-07-14 09:58      --d-----   c:\programdata\DriverCure
2009-07-14 09:58      --d-----   c:\progra~2\ParetoLogic
2009-07-14 09:58      --d-----   c:\progra~2\DriverCure
2009-07-14 01:25      --d-----   c:\programdata\RegCure
2009-07-14 01:25      --d-----   c:\progra~2\RegCure
2009-07-13 10:41      --d-----   c:\programdata\SUPERAntiSpyware.com
2009-07-13 10:41      --d-----   c:\progra~2\SUPERAntiSpyware.com
2009-07-13 10:40      --d-----   c:\users\phils\appdata\roaming\SUPERAntiSpyware.com
2009-07-13 10:40      --d-----   c:\program files\SUPERAntiSpyware
2009-07-13 10:39      --d-----   c:\program files\common files\Wise Installation Wizard
2009-07-10 16:43      --d-----   c:\users\phils\appdata\roaming\funkitron
2009-07-09 02:08      --d-----   c:\users\phils\appdata\roaming\iWin
2009-07-04 14:05      --d-----   c:\windows\system32\eu-ES
2009-07-04 14:05      --d-----   c:\windows\system32\ca-ES
2009-07-04 14:05      --d-----   c:\windows\system32\vi-VN
2009-07-04 12:40      --d-----   c:\windows\system32\EventProviders
2009-07-04 12:36   289,792   a-------   c:\windows\system32\spinstall.exe
2009-07-04 12:35   409,600   a-------   c:\windows\system32\odbc32.dll
2009-07-04 12:34   638,976   a-------   c:\windows\system32\Utilman.exe
2009-07-04 12:33   140,288   a-------   c:\windows\system32\wpcsvc.dll
2009-07-04 12:32   83,968   a-------   c:\windows\system32\wbem\wmiutils.dll
2009-07-04 12:32   744,448   a-------   c:\windows\system32\wbem\wbemcore.dll
2009-07-04 12:32   614,912   a-------   c:\windows\system32\wbem\fastprox.dll
2009-07-04 12:32   265,728   a-------   c:\windows\system32\wbem\repdrvfs.dll
2009-07-04 12:32   265,728   a-------   c:\windows\system32\wbem\esscli.dll
2009-07-04 12:32   189,440   a-------   c:\windows\system32\wbem\mofd.dll
2009-07-04 12:32   30,208   a-------   c:\windows\system32\wbem\wbemprox.dll
2009-07-04 12:32   705,536   a-------   c:\windows\system32\SmiEngine.dll
2009-07-04 12:32   218,624   a-------   c:\windows\system32\wdscore.dll
2009-07-04 12:32   130,560   a-------   c:\windows\system32\PkgMgr.exe
2009-07-04 12:32   247,808   a-------   c:\windows\system32\drvstore.dll
2009-06-25 01:20      --d-----   c:\program files\SystemRequirementsLab
2009-06-21 14:50   68,640   a-------   c:\windows\unTMV.exe
2009-06-21 14:50      --d-----   c:\program files\SoftMaker Viewer
2009-06-19 04:32      --d-----   c:\programdata\NCH Swift Sound
2009-06-19 04:32      --d-----   c:\program files\NCH Software
2009-06-19 04:31      --d-----   c:\program files\NCH Swift Sound
2009-06-19 04:28      --d-----   c:\programdata\FreeRIP
2009-06-19 04:28      --d-----   c:\progra~2\FreeRIP
2009-06-19 04:28      --d-----   c:\program files\FreeRIP3

==================== Find3M  ====================

2009-07-18 17:35   27,839   a-------   c:\programdata\nvModes.dat
2009-07-18 17:35   27,839   a-------   c:\progra~2\nvModes.dat
2009-07-14 17:12   1,092   a-------   c:\users\phils\appdata\roaming\wklnhst.dat
2009-07-14 10:06   51,200   a-------   c:\windows\inf\infpub.dat
2009-07-14 10:06   143,360   a-------   c:\windows\inf\infstrng.dat
2009-07-14 10:06   86,016   a-------   c:\windows\inf\infstor.dat
2009-07-04 14:05   665,600   a-------   c:\windows\inf\drvindex.dat
2009-06-30 15:36   18,696   a-------   c:\windows\help\oem\scripts\HC_BatteryReplaceNew.exe
2009-06-30 15:10   18,696   a-------   c:\windows\help\oem\scripts\HC_BatteryNoTravel.exe
2009-06-30 15:03   18,696   a-------   c:\windows\help\oem\scripts\HC_BatteryAccessories.exe
2009-06-30 12:44   18,184   a-------   c:\windows\help\oem\scripts\HC_BatteryWeakNew.exe
2009-06-26 18:36   18,184   a-------   c:\windows\help\oem\scripts\HC_BatteryUpgrade.exe
2009-05-08 22:50   915,456   a-------   c:\windows\system32\wininet.dll
2009-05-08 22:34   71,680   a-------   c:\windows\system32\iesetup.dll
2009-05-01 14:02   90,112   a-------   c:\windows\system32\dpl100.dll
2009-05-01 14:02   823,296   a-------   c:\windows\system32\divx_xx0c.dll
2009-05-01 14:02   823,296   a-------   c:\windows\system32\divx_xx07.dll
2009-05-01 14:02   815,104   a-------   c:\windows\system32\divx_xx0a.dll
2009-05-01 14:02   811,008   a-------   c:\windows\system32\divx_xx16.dll
2009-05-01 14:02   802,816   a-------   c:\windows\system32\divx_xx11.dll
2009-05-01 14:02   685,056   a-------   c:\windows\system32\DivX.dll
2009-04-23 05:15   784,896   a-------   c:\windows\system32\rpcrt4.dll
2009-04-23 05:14   623,616   a-------   c:\windows\system32\localspl.dll
2009-04-21 04:39   2,034,688   a-------   c:\windows\system32\win32k.sys
2008-01-20 19:43   174   a--sh---   c:\program files\desktop.ini
2006-11-02 05:42   287,440   a-------   c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 05:42   287,440   a-------   c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 05:42   30,674   a-------   c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 05:42   30,674   a-------   c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 02:20   287,440   a-------   c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 02:20   287,440   a-------   c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 02:20   30,674   a-------   c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 02:20   30,674   a-------   c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 17:36:54.89 ===============







DDS (Ver_09-06-26.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 11/5/2008 6:50:33 PM
System Uptime: 7/18/2009 2:26:10 PM (3 hours ago)

Motherboard: Wistron |  | 303C
Processor: AMD Turion Dual-Core RM-70 | Socket A | 2000/133mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 139 GiB total, 71.407 GiB FREE.
D: is FIXED (NTFS) - 10 GiB total, 1.732 GiB free.
E: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0000
Manufacturer: Microsoft
Name: Microsoft ISATAP Adapter
PNP Device ID: ROOT\*ISATAP\0000
Service: tunnel

Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft Tun Miniport Adapter
Device ID: ROOT\*TUNMP\0001
Manufacturer: Microsoft
Name: Microsoft Tun Miniport Adapter #2
PNP Device ID: ROOT\*TUNMP\0001
Service: tunmp

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================

AAC Decoder
ActiveCheck component for HP Active Support Library
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.1.6
Adobe Shockwave Player
Adobe Shockwave Player 11.5
AIM 6
Apple Mobile Device Support
Apple Software Update
Atheros Driver Installation Program
AutoUpdate
Bonjour
CAM UnZip 4.42
Cards_Calendar_OrderGift_DoMorePlugout
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Conexant HD Audio
CyberLink DVD Suite
CyberLink YouCam
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Version Checker
DivX Web Player
ESU for Microsoft Vista
Express Burn
Express Rip
FreeRIP v3.1
GPL MPEG-1/2 DirectShow Decoder Filter
H.264 Decoder
HDAUDIO Soft Data Fax Modem with SmartCP
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Doc Viewer
HP DVD Play 3.7
HP Help and Support
HP Photosmart Essential 2.5
HP Quick Launch Buttons 6.40 D3
HP Smart Web Printing
HP Total Care Advisor
HP Update
HP User Guides 0118
HP Wireless Assistant
HPAsset component for HP Active Support Library
HPNetworkAssistant
HPPhotoSmartDiscLabel_PaperLabel
HPPhotoSmartDiscLabel_PrintOnDisc
HPPhotoSmartDiscLabel_Tattoo
HPPhotoSmartDiscLabelContent1
hpphotosmartdisclabelplugin
HPPhotoSmartPhotobookHolidayPack1
HPPhotoSmartPhotobookModernPack1
HPPhotoSmartPhotobookPlayfulPack1
HPPhotoSmartPhotobookScrapbookPack1
HPPhotoSmartPhotobookWebPack1
HPTCSSetup
iTunes
Java(TM) 6 Update 13
Java(TM) 6 Update 5
LabelPrint
Last.fm 1.5.4.24567
Malwarebytes' Anti-Malware
Microsoft .NET Framework 3.5 SP1
Microsoft Silverlight
Microsoft Visual C Runtime
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
MKV Splitter
Mozilla Firefox (3.0.11)
MSXML 4.0 SP2 (KB954430)
muvee autoProducer 6.1
My HP Games
NetWaiting
NVIDIA Drivers
Power2Go
PowerDirector
PSSWCORE
QuickPlay SlingPlayer 0.4.6
QuickTime
Realtek USB 2.0 Card Reader
RegCure 1.6.0.0
Spelling Dictionaries Support For Adobe Reader 8
Spyware Doctor 6.0
SUPERAntiSpyware Free Edition
Switch Sound File Converter
Synaptics Pointing Device Driver
System Requirements Lab
TextMaker Viewer
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
VC80CRTRedist - 8.0.50727.762
VideoToolkit01
Viewpoint Media Player
VLC media player 0.9.9
WavePad Sound Editor

==== Event Viewer Messages From Past Week ========

7/18/2009 5:36:58 PM, Error: Microsoft-Windows-DistributedCOM [10000]  - Unable to start a DCOM Server: {883FF1FC-09E1-48E5-8E54-E2469ACB0CFD}. The error: "5" Happened while starting this command: C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}
7/18/2009 12:58:24 PM, Error: Microsoft-Windows-DistributedCOM [10000]  - Unable to start a DCOM Server: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}. The error: "5" Happened while starting this command: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
7/18/2009 12:58:19 PM, Error: Microsoft-Windows-DistributedCOM [10000]  - Unable to start a DCOM Server: {56EA1054-1959-467F-BE3B-A2A787C4B6EA}. The error: "5" Happened while starting this command: C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
7/18/2009 12:58:17 PM, Error: Service Control Manager [7000]  - The Parallel port driver service failed to start due to the following error:  The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
7/18/2009 12:57:59 PM, Error: EventLog [6008]  - The previous system shutdown at 12:57:01 PM on 7/18/2009 was unexpected.
7/18/2009 12:48:26 PM, Error: Microsoft-Windows-DistributedCOM [10000]  - Unable to start a DCOM Server: {4D111E08-CBF7-4F12-A926-2C7920AF52FC}. The error: "5" Happened while starting this command: C:\Windows\system32\DllHost.exe /Processid:{4D111E08-CBF7-4F12-A926-2C7920AF52FC}
7/18/2009 1:01:40 PM, Error: Microsoft-Windows-DistributedCOM [10000]  - Unable to start a DCOM Server: {86D5EB8A-859F-4C7B-A76B-2BD819B7A850}. The error: "5" Happened while starting this command: C:\Windows\system32\DllHost.exe /Processid:{86D5EB8A-859F-4C7B-A76B-2BD819B7A850}
7/17/2009 8:04:59 PM, Error: Microsoft-Windows-DistributedCOM [10000]  - Unable to start a DCOM Server: {FCC74B77-EC3E-4DD8-A80B-008A702075A9}. The error: "5" Happened while starting this command: C:\Windows\system32\DllHost.exe /Processid:{FCC74B77-EC3E-4DD8-A80B-008A702075A9}
7/17/2009 8:00:40 PM, Error: Microsoft-Windows-DistributedCOM [10000]  - Unable to start a DCOM Server: {3AD05575-8857-4850-9277-11B85BDB8E09}. The error: "5" Happened while starting this command: C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}
7/17/2009 5:38:38 PM, Error: Microsoft-Windows-DistributedCOM [10000]  - Unable to start a DCOM Server: {A2D8CFE7-7BA4-4BAD-B86B-851376B59134}. The error: "5" Happened while starting this command: C:\Windows\system32\DllHost.exe /Processid:{A2D8CFE7-7BA4-4BAD-B86B-851376B59134}
7/17/2009 5:33:26 PM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the sdCoreService service.
7/17/2009 3:31:17 AM, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the PEVSystemStart service to connect.
7/17/2009 3:31:16 AM, Error: Service Control Manager [7030]  - The PEVSystemStart service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.
7/16/2009 9:43:33 PM, Error: Microsoft-Windows-DistributedCOM [10000]  - Unable to start a DCOM Server: {BBD8C065-5E6C-4E88-BFD7-BE3E6D1C063B}. The error: "5" Happened while starting this command: C:\Windows\system32\DllHost.exe /Processid:{BBD8C065-5E6C-4E88-BFD7-BE3E6D1C063B}
7/15/2009 12:43:38 AM, Error: Microsoft-Windows-DistributedCOM [10000]  - Unable to start a DCOM Server: {E9495B87-D950-4AB5-87A5-FF6D70BF3E90}. The error: "5" Happened while starting this command: C:\Windows\system32\DllHost.exe /Processid:{E9495B87-D950-4AB5-87A5-FF6D70BF3E90}
7/15/2009 12:42:46 AM, Error: Microsoft-Windows-DistributedCOM [10000]  - Unable to start a DCOM Server: {A2D75874-6750-4931-94C1-C99D3BC9D0C7}. The error: "5" Happened while starting this command: C:\Windows\system32\DllHost.exe /Processid:{A79DB36D-6218-48E6-9EC9-DCBA9A39BF0F}
7/14/2009 10:23:16 AM, Error: Microsoft-Windows-Dhcp-Client [1002]  - The IP address lease 192.168.0.10 for the Network Card with network address 00234E139720 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
7/14/2009 10:12:38 AM, Error: Microsoft-Windows-DistributedCOM [10000]  - Unable to start a DCOM Server: {D1F60CCB-8329-406E-976F-660B1BDF0D97}. The error: "5" Happened while starting this command: C:\Windows\system32\DllHost.exe /Processid:{D1F60CCB-8329-406E-976F-660B1BDF0D97}
7/14/2009 1:46:03 AM, Error: Microsoft-Windows-DistributedCOM [10000]  - Unable to start a DCOM Server: {1F2E5C40-9550-11CE-99D2-00AA006E086C}. The error: "5" Happened while starting this command: C:\Windows\system32\DllHost.exe /Processid:{1F2E5C40-9550-11CE-99D2-00AA006E086C}
7/14/2009 1:23:01 AM, Error: Microsoft-Windows-DistributedCOM [10000]  - Unable to start a DCOM Server: {9DF523B0-A6C0-4EA9-B5F1-F4565C3AC8B8}. The error: "5" Happened while starting this command: C:\Windows\system32\DllHost.exe /Processid:{9DF523B0-A6C0-4EA9-B5F1-F4565C3AC8B8}
7/11/2009 7:52:05 PM, Error: Microsoft-Windows-DistributedCOM [10000]  - Unable to start a DCOM Server: {BB46F03E-7CD2-489F-8F95-BB950F395FDB}. The error: "5" Happened while starting this command: C:\Windows\system32\DllHost.exe /Processid:{16D99191-6280-4B33-A2F5-04805A0FC582}
7/11/2009 2:39:06 PM, Error: Microsoft-Windows-Dhcp-Client [1002]  - The IP address lease 76.105.214.195 for the Network Card with network address 001F16498BEF has been denied by the DHCP server 192.168.100.1 (The DHCP Server sent a DHCPNACK message).
7/11/2009 2:35:55 PM, Error: Microsoft-Windows-DistributedCOM [10000]  - Unable to start a DCOM Server: {BA126F01-2166-11D1-B1D0-00805FC1270E}. The error: "5" Happened while starting this command: C:\Windows\system32\DllHost.exe /Processid:{BA126F01-2166-11D1-B1D0-00805FC1270E}
7/11/2009 1:11:58 AM, Error: Microsoft-Windows-DistributedCOM [10000]  - Unable to start a DCOM Server: {71E7431B-17AA-4018-B62B-08C5F9AA4D8E}. The error: "5" Happened while starting this command: C:\Windows\system32\DllHost.exe /Processid:{71E7431B-17AA-4018-B62B-08C5F9AA4D8E}

==== End Of File ===========================
Go to Add or Remove Programs and uninstall:

  • RegCure 1.6.0.0
  • Viewpoint Media Player
.
--------

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note:  It is important that it is saved directly to your Desktop

DO NOT run it yet!

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type NOTEPAD.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

Driver::
Viewpoint Manager Service

DDS::
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File

Firefox::
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll

Folder::
c:\program files\viewpoint
c:\users\phils\appdata\roaming\ParetoLogic
c:\users\phils\appdata\roaming\DriverCure
c:\programdata\ParetoLogic
c:\programdata\DriverCure
c:\progra~2\ParetoLogic
c:\progra~2\DriverCure
c:\programdata\RegCure
c:\progra~2\RegCure


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

----------

Your Java is out of date.

Older versions have vulnerabilities that malicious sites can use to infect your system.

First install the new Sun Java Runtime Environment

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close all browser windows before beginning the install.

Remove the old version(s)

Download JavaRa
* Unzip the file and open the JavaRa.exe
* Click Remove Older Versions
* JavaRa will search for and remove any outdated version of Java and remove any that are found.
* Click Additional Tasks
* Place a check next to Remove Useless JRE Files and click Go
* Exit JavaRa
* Delete the JavaRa files from the Desktop

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.ok, i keep gettting this popup - "You don't have sufficient access to uninstall ____. Please contact your system administrator."   when trying to uninstall anything..

javara worked. i could not install the new java...i got an error message saying "Unzipping core files failed." and the installation exited.




ComboFix 09-07-14.08 - PhilS 07/18/2009 18:45.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.2814.1659 [GMT -7:00]
Running from: c:\users\PhilS\Desktop\ComboFix.exe
Command switches used :: c:\users\PhilS\Desktop\CFScript.txt
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\progra~2\DriverCure
c:\progra~2\DriverCure\9B13A86D3456.plf
c:\progra~2\ParetoLogic
c:\progra~2\ParetoLogic\Privacy Controls\AppPreferences.dat
c:\progra~2\ParetoLogic\UUS2\DriverCure\Master.xml
c:\progra~2\ParetoLogic\UUS2\DriverCure\Patch.xml
c:\progra~2\ParetoLogic\UUS2\DriverCure\Update.xml
c:\progra~2\RegCure
c:\progra~2\RegCure\whitelist.dat
c:\program files\viewpoint
c:\program files\viewpoint\Common\ViewpointService.exe
c:\program files\viewpoint\Common\VistaBoot.sdll
c:\program files\viewpoint\Viewpoint Media Player\AxMetaStream.dll
c:\program files\viewpoint\Viewpoint Media Player\ClassIDs.ini
c:\program files\viewpoint\Viewpoint Media Player\ComponentMgr.dll
c:\program files\viewpoint\Viewpoint Media Player\ComponentRegistry.ini
c:\program files\viewpoint\Viewpoint Media Player\Components\AOLUserShell.dll
c:\program files\viewpoint\Viewpoint Media Player\Components\Cursors.dll
c:\program files\viewpoint\Viewpoint Media Player\Components\JpegReader.dll
c:\program files\viewpoint\Viewpoint Media Player\Components\Mts3Reader.dll
c:\program files\viewpoint\Viewpoint Media Player\Components\SceneComponent.dll
c:\program files\viewpoint\Viewpoint Media Player\Components\SreeDMMX.dll
c:\program files\viewpoint\Viewpoint Media Player\Components\SWFView.dll
c:\program files\viewpoint\Viewpoint Media Player\Components\VETScriptInterpreter.dll
c:\program files\viewpoint\Viewpoint Media Player\Components\VMPSpeech.dll
c:\program files\viewpoint\Viewpoint Media Player\Components\VMPVideo2.dll
c:\program files\viewpoint\Viewpoint Media Player\HostRegistry.ini
c:\program files\viewpoint\Viewpoint Media Player\MetaStreamConfig.ini
c:\program files\viewpoint\Viewpoint Media Player\MetaStreamID.ini
c:\program files\viewpoint\Viewpoint Media Player\MtsAxInstaller.exe
c:\program files\viewpoint\Viewpoint Media Player\MTSDownloadSites.txt
c:\program files\viewpoint\Viewpoint Media Player\npViewpoint.dll
c:\program files\viewpoint\Viewpoint Media Player\npViewpoint.xpt
c:\programdata\DriverCure\9B13A86D3456.plf
c:\programdata\ParetoLogic\Privacy Controls\AppPreferences.dat
c:\programdata\ParetoLogic\UUS2\DriverCure\Master.xml
c:\programdata\ParetoLogic\UUS2\DriverCure\Patch.xml
c:\programdata\ParetoLogic\UUS2\DriverCure\Update.xml
c:\programdata\RegCure\whitelist.dat
c:\users\phils\appdata\roaming\DriverCure
c:\users\phils\appdata\roaming\DriverCure\Client.txt
c:\users\phils\appdata\roaming\DriverCure\LogFile.txt
c:\users\phils\appdata\roaming\DriverCure\Server.txt
c:\users\phils\appdata\roaming\ParetoLogic
c:\users\phils\appdata\roaming\ParetoLogic\Privacy Controls\CleanPreferences.db

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_Viewpoint Manager Service


(((((((((((((((((((((((((   Files Created from 2009-06-19 to 2009-07-19  )))))))))))))))))))))))))))))))
.

2009-07-19 01:56 . 2009-07-19 02:01   --------   d-----w-   c:\users\PhilS\AppData\Local\temp
2009-07-15 21:01 . 2009-07-15 21:01   --------   d-----w-   c:\program files\Trend Micro
2009-07-15 08:51 . 2009-07-15 08:51   --------   d-----w-   c:\users\PhilS\AppData\Roaming\Malwarebytes
2009-07-15 08:51 . 2009-07-13 20:36   38160   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-15 08:51 . 2009-07-15 08:51   --------   d-----w-   c:\programdata\Malwarebytes
2009-07-15 08:51 . 2009-07-15 08:51   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2009-07-15 08:51 . 2009-07-13 20:36   19096   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-07-14 20:11 . 2009-06-15 14:53   156672   ----a-w-   c:\windows\system32\t2embed.dll
2009-07-14 20:11 . 2009-06-15 14:52   72704   ----a-w-   c:\windows\system32\fontsub.dll
2009-07-14 20:11 . 2009-06-15 12:42   289792   ----a-w-   c:\windows\system32\atmfd.dll
2009-07-14 20:11 . 2009-06-15 14:52   23552   ----a-w-   c:\windows\system32\lpk.dll
2009-07-14 20:11 . 2009-06-15 14:51   10240   ----a-w-   c:\windows\system32\dciman32.dll
2009-07-14 17:06 . 2009-07-14 17:06   --------   d-----w-   c:\programdata\Cached Installations
2009-07-14 17:00 . 2009-07-14 17:00   --------   d-----w-   c:\programdata\Downloaded Installations
2009-07-14 08:25 . 2009-07-14 08:39   --------   d-----w-   c:\program files\RegCure
2009-07-13 17:41 . 2009-07-16 00:48   117760   ----a-w-   c:\users\PhilS\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-13 17:41 . 2009-07-13 17:41   --------   d-----w-   c:\programdata\SUPERAntiSpyware.com
2009-07-13 17:40 . 2009-07-13 17:40   --------   d-----w-   c:\program files\SUPERAntiSpyware
2009-07-13 17:40 . 2009-07-13 17:40   --------   d-----w-   c:\users\PhilS\AppData\Roaming\SUPERAntiSpyware.com
2009-07-13 17:39 . 2009-07-13 17:39   --------   d-----w-   c:\program files\Common Files\Wise Installation Wizard
2009-07-10 23:43 . 2009-07-10 23:43   --------   d-----w-   c:\users\PhilS\AppData\Roaming\funkitron
2009-07-09 09:08 . 2009-07-09 09:08   --------   d-----w-   c:\users\PhilS\AppData\Roaming\iWin
2009-07-04 21:05 . 2009-07-04 21:06   --------   d-----w-   c:\windows\system32\ca-ES
2009-07-04 21:05 . 2009-07-04 21:06   --------   d-----w-   c:\windows\system32\eu-ES
2009-07-04 21:05 . 2009-07-04 21:06   --------   d-----w-   c:\windows\system32\vi-VN
2009-07-04 19:40 . 2009-07-04 19:40   --------   d-----w-   c:\windows\system32\EventProviders
2009-07-04 19:36 . 2009-04-11 06:28   289792   ----a-w-   c:\windows\system32\spinstall.exe
2009-07-04 19:35 . 2009-04-11 06:28   71680   ----a-w-   c:\windows\system32\propdefs.dll
2009-07-04 19:34 . 2009-04-11 06:28   152576   ----a-w-   c:\windows\system32\secproc_ssp_isv.dll
2009-07-04 19:33 . 2009-04-11 06:28   140288   ----a-w-   c:\windows\system32\wpcsvc.dll
2009-07-04 19:32 . 2009-04-11 06:28   83968   ----a-w-   c:\windows\system32\wbem\wmiutils.dll
2009-07-04 19:32 . 2009-04-11 06:28   744448   ----a-w-   c:\windows\system32\wbem\wbemcore.dll
2009-07-04 19:32 . 2009-04-11 06:28   30208   ----a-w-   c:\windows\system32\wbem\wbemprox.dll
2009-07-04 19:32 . 2009-04-11 06:28   265728   ----a-w-   c:\windows\system32\wbem\repdrvfs.dll
2009-07-04 19:32 . 2009-04-11 06:28   189440   ----a-w-   c:\windows\system32\wbem\mofd.dll
2009-07-04 19:32 . 2009-04-11 06:28   614912   ----a-w-   c:\windows\system32\wbem\fastprox.dll
2009-07-04 19:32 . 2009-04-11 06:28   265728   ----a-w-   c:\windows\system32\wbem\esscli.dll
2009-07-04 19:32 . 2009-04-11 06:28   705536   ----a-w-   c:\windows\system32\SmiEngine.dll
2009-07-04 19:32 . 2009-04-11 06:28   218624   ----a-w-   c:\windows\system32\wdscore.dll
2009-07-04 19:32 . 2009-04-11 06:27   130560   ----a-w-   c:\windows\system32\PkgMgr.exe
2009-07-04 19:32 . 2009-04-11 06:28   247808   ----a-w-   c:\windows\system32\drvstore.dll
2009-06-25 08:20 . 2009-06-25 08:24   --------   d-----w-   c:\program files\SystemRequirementsLab
2009-06-25 08:20 . 2009-06-25 08:21   --------   d-----w-   c:\users\PhilS\AppData\Roaming\SystemRequirementsLab
2009-06-25 08:20 . 2009-06-25 08:20   290816   ----a-w-   c:\users\PhilS\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_4.dll
2009-06-25 08:20 . 2009-06-25 08:20   290816   ----a-w-   c:\users\PhilS\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_3.dll
2009-06-25 08:20 . 2009-06-25 08:20   290816   ----a-w-   c:\users\PhilS\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_2.dll
2009-06-25 08:20 . 2009-06-25 08:20   290816   ----a-w-   c:\users\PhilS\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_1.dll
2009-06-22 10:42 . 2009-06-24 11:14   --------   d-----w-   c:\users\PhilS\AppData\Roaming\dvdcss
2009-06-21 21:50 . 2009-06-05 11:33   68640   ----a-w-   c:\windows\unTMV.exe
2009-06-21 21:50 . 2009-06-21 21:50   --------   d-----w-   c:\program files\SoftMaker Viewer
2009-06-19 19:58 . 2009-06-19 19:58   --------   d-----w-   c:\users\PhilS\AppData\Roaming\Recordpad
2009-06-19 11:32 . 2009-06-19 11:33   --------   d-----w-   c:\programdata\NCH Swift Sound
2009-06-19 11:32 . 2009-06-19 11:33   --------   d-----w-   c:\users\PhilS\AppData\Roaming\NCH Swift Sound
2009-06-19 11:32 . 2009-06-19 11:32   --------   d-----w-   c:\program files\NCH Software
2009-06-19 11:31 . 2009-06-27 03:50   --------   d-----w-   c:\program files\NCH Swift Sound
2009-06-19 11:28 . 2009-06-19 11:28   --------   d-----w-   c:\programdata\FreeRIP
2009-06-19 11:28 . 2009-06-19 11:28   --------   d-----w-   c:\program files\FreeRIP3

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-19 01:59 . 2008-12-26 00:31   --------   d-----w-   c:\program files\Spyware Doctor
2009-07-19 00:35 . 2008-12-26 00:22   27839   ----a-w-   c:\programdata\nvModes.dat
2009-07-15 06:38 . 2006-11-02 11:18   --------   d-----w-   c:\program files\Windows Mail
2009-07-15 00:12 . 2008-12-26 00:25   1092   ----a-w-   c:\users\PhilS\AppData\Roaming\wklnhst.dat
2009-07-14 17:11 . 2008-12-26 00:31   --------   d-----w-   c:\program files\Common Files\PC Tools
2009-07-14 17:07 . 2008-12-30 00:43   --------   d-----w-   c:\users\PhilS\AppData\Roaming\uTorrent
2009-07-14 08:56 . 2008-12-26 07:54   74432   ----a-w-   c:\users\PhilS\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-11 11:16 . 2008-08-04 17:19   --------   d-----w-   c:\programdata\WildTangent
2009-07-04 21:06 . 2006-11-02 12:37   --------   d-----w-   c:\program files\Windows Sidebar
2009-07-04 21:06 . 2006-11-02 12:37   --------   d-----w-   c:\program files\Windows Photo Gallery
2009-07-04 21:06 . 2006-11-02 12:37   --------   d-----w-   c:\program files\Windows Collaboration
2009-07-04 21:06 . 2006-11-02 12:37   --------   d-----w-   c:\program files\Windows Calendar
2009-07-04 21:06 . 2006-11-02 12:37   --------   d-----w-   c:\program files\Windows Defender
2009-07-04 21:05 . 2006-11-02 10:25   665600   ----a-w-   c:\windows\inf\drvindex.dat
2009-07-04 19:58 . 2008-11-06 03:37   --------   d-----w-   c:\programdata\NVIDIA
2009-07-04 19:47 . 2006-11-02 12:37   37665   ----a-w-   c:\windows\Fonts\GlobalUserInterface.CompositeFont
2009-06-30 22:36 . 2009-07-12 05:36   18696   ----a-w-   c:\windows\Help\OEM\scripts\HC_BatteryReplaceNew.exe
2009-06-30 22:10 . 2009-07-12 05:36   18696   ----a-w-   c:\windows\Help\OEM\scripts\HC_BatteryNoTravel.exe
2009-06-30 22:03 . 2009-07-12 05:36   18696   ----a-w-   c:\windows\Help\OEM\scripts\HC_BatteryAccessories.exe
2009-06-30 19:44 . 2009-07-12 05:36   18184   ----a-w-   c:\windows\Help\OEM\scripts\HC_BatteryWeakNew.exe
2009-06-27 01:36 . 2009-07-12 05:36   18184   ----a-w-   c:\windows\Help\OEM\scripts\HC_BatteryUpgrade.exe
2009-06-21 08:52 . 2009-06-18 10:22   --------   d-----w-   c:\users\PhilS\AppData\Roaming\vlc
2009-06-18 10:21 . 2009-06-18 10:21   --------   d-----w-   c:\program files\VideoLAN
2009-06-18 10:15 . 2009-06-18 10:13   --------   d-----w-   c:\program files\GPL MPEG Decoder
2009-06-13 10:03 . 2008-08-04 17:50   --------   d-----w-   c:\program files\Microsoft Works
2009-06-07 06:27 . 2009-01-09 00:06   --------   d-----w-   c:\program files\DivX
2009-06-07 06:23 . 2009-06-07 06:23   --------   d-----w-   c:\program files\Common Files\DivX Shared
2009-06-07 05:54 . 2009-04-08 05:13   --------   d-----w-   c:\users\PhilS\AppData\Roaming\DivX
2009-05-09 05:50 . 2009-06-12 14:11   915456   ----a-w-   c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-12 14:11   71680   ----a-w-   c:\windows\system32\iesetup.dll
2009-05-01 21:02 . 2009-05-01 21:02   90112   ----a-w-   c:\windows\system32\dpl100.dll
2009-05-01 21:02 . 2009-05-01 21:02   823296   ----a-w-   c:\windows\system32\divx_xx0c.dll
2009-05-01 21:02 . 2009-05-01 21:02   823296   ----a-w-   c:\windows\system32\divx_xx07.dll
2009-05-01 21:02 . 2009-05-01 21:02   815104   ----a-w-   c:\windows\system32\divx_xx0a.dll
2009-05-01 21:02 . 2009-05-01 21:02   811008   ----a-w-   c:\windows\system32\divx_xx16.dll
2009-05-01 21:02 . 2009-05-01 21:02   802816   ----a-w-   c:\windows\system32\divx_xx11.dll
2009-05-01 21:02 . 2009-05-01 21:02   685056   ----a-w-   c:\windows\system32\DivX.dll
2009-04-23 12:15 . 2009-06-12 14:11   784896   ----a-w-   c:\windows\system32\rpcrt4.dll
2009-04-23 12:14 . 2009-06-12 14:12   623616   ----a-w-   c:\windows\system32\localspl.dll
2009-04-21 11:39 . 2009-06-12 14:12   2034688   ----a-w-   c:\windows\system32\win32k.sys
2009-04-20 06:26 . 2009-03-30 00:32   39200   ----a-w-   c:\windows\system32\drivers\TfSysMon.sys
2009-04-20 06:26 . 2009-03-30 00:32   33056   ----a-w-   c:\windows\system32\drivers\TfNetMon.sys
2009-04-20 06:26 . 2009-03-30 00:32   51488   ----a-w-   c:\windows\system32\drivers\TfFsMon.sys
2009-04-20 06:26 . 2009-03-30 00:32   12576   ----a-w-   c:\windows\system32\drivers\TfKbMon.sys
2009-04-20 06:26 . 2009-03-30 00:30   130936   ----a-w-   c:\windows\system32\drivers\PCTCore.sys
2009-06-12 10:19 . 2009-01-06 23:26   134648   ----a-w-   c:\program files\mozilla firefox\components\brwsrcmp.dll
2009-05-01 21:02 . 2009-05-01 21:02   1044480   ----a-w-   c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02   200704   ----a-w-   c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-08-04 15:03 . 2008-08-04 15:03   8192   --sha-w-   c:\windows\Users\Default\NTUSER.DAT
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-06-12 468264]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-06-02 80896]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-12-08 1173384]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-11 13543968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-11 92704]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05   356352   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):d7,86,ac,d9,ec,fc,c9,01

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{053E5549-ECD5-4FE4-8DB9-641DFB10CF77}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{C1BAABB6-21B7-49B7-91E1-E455B4B6BC44}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{C55EE582-4D18-4465-B67C-01CCBFDC83AC}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{B2DD7404-A6FC-40B9-8308-6C878692A3C9}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{61163C9B-D9DA-4470-B24F-3F12B829515A}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{5FFDBBF0-35FB-4F2D-9936-1E5CA81749AD}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM
"UDP Query User{557017AC-78EB-4FEF-B5BA-785EC157B329}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM
"TCP Query User{C02004D7-C5DA-4F5A-9748-7C6D34C4B495}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:µTorrent
"UDP Query User{F9002FAE-E853-4411-9606-D546AA53E040}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:µTorrent
"{C584877B-5ED8-4DE5-AF02-3B55F5AEF3FD}"= Disabled:UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{1AFE8673-5972-4C8A-BC15-0B44CC879F75}"= Disabled:TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{7D94000C-BBBC-44EB-BCCA-577F962A31C6}"= Disabled:UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{17ECCB8F-DF6F-416B-884A-F0B83C4C6A41}"= Disabled:TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DoNotAllowExceptions"= 1 (0x1)

R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [3/29/2009 5:30 PM 130936]
R0 TfFsMon;TfFsMon;c:\windows\System32\drivers\TfFsMon.sys [3/29/2009 5:32 PM 51488]
R0 TfSysMon;TfSysMon;c:\windows\System32\drivers\TfSysMon.sys [3/29/2009 5:32 PM 39200]
R1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi.sys [3/29/2009 5:30 PM 159600]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [8/4/2008 11:43 AM 361808]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [12/25/2008 5:31 PM 348752]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [8/4/2008 10:15 AM 193840]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [5/9/2008 12:17 PM 43040]
R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg.sys [3/29/2009 5:30 PM 64392]
R3 TfNetMon;TfNetMon;c:\windows\System32\drivers\TfNetMon.sys [3/29/2009 5:32 PM 33056]
R3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service --> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408]

--- Other Services/Drivers In Memory ---

*Deregistered* - mchInjDrv

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-18 c:\windows\Tasks\HPCeeScheduleForPhilS.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-08-04 03:03]

2009-07-19 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]

2009-07-19 c:\windows\Tasks\RegCure Startup.job
- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]

2009-07-14 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]

2009-07-18 c:\windows\Tasks\User_Feed_Synchronization-{9051D44C-782E-4E8D-B571-01D8B4400FEE}.job
- c:\windows\system32\msfeedssync.exe [2009-04-06 11:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = *.local
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
FF - ProfilePath - c:\users\PhilS\AppData\Roaming\Mozilla\Firefox\Profiles\r2or64x5.default\
FF - prefs.js: browser.startup.homepage - hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-18 19:00
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
Denied: (A) (Users)
Denied: (A) (Everyone)
Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1196)
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll

- - - - - - - > 'lsass.exe'(660)
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll

- - - - - - - > 'Explorer.exe'(3008)
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\wlanext.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\windows\System32\drivers\XAudio.exe
c:\program files\Spyware Doctor\TFEngine\TFService.exe
c:\windows\System32\rundll32.exe
c:\program files\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
.
**************************************************************************
.
Completion time: 2009-07-19 19:10 - machine was rebooted
ComboFix-quarantined-files.txt  2009-07-19 02:10
ComboFix2.txt  2009-07-17 10:37

Pre-Run: 75,693,498,368 bytes free
Post-Run: 75,118,772,224 bytes free

318   --- E O F ---   2009-07-15 06:38
Is this a limited account?

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

File::
c:\windows\Tasks\RegCure Program Check.job
c:\windows\Tasks\RegCure Startup.job
c:\windows\Tasks\RegCure.job

Folder::
c:\program files\RegCure

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

RegLock::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeIt never was...these limitations saying "PhilS" is not the admin began with the spyware doctor dllhost/svchost messages , I dont know what's going on.    doing combofix now..ComboFix 09-07-14.08 - PhilS 07/19/2009  0:43.3.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.2814.1746 [GMT -7:00]
Running from: c:\users\PhilS\Desktop\ComboFix.exe
Command switches used :: c:\users\PhilS\Desktop\CFScript.txt
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

FILE ::
"c:\windows\Tasks\RegCure Program Check.job"
"c:\windows\Tasks\RegCure Startup.job"
"c:\windows\Tasks\RegCure.job"
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\program files\RegCure
c:\program files\RegCure\0_days.htm
c:\program files\RegCure\1_days.htm
c:\program files\RegCure\15_days.htm
c:\program files\RegCure\2_days.htm
c:\program files\RegCure\30_days.htm
c:\program files\RegCure\5_days.htm
c:\program files\RegCure\Animated-Bar.gif
c:\program files\RegCure\AutoUpdate.dll
c:\program files\RegCure\Backup\RegCureBak_July_14_09_01_39_51.bak
c:\program files\RegCure\Backup\RegCureBak_July_14_09_01_39_51.reg
c:\program files\RegCure\Backup\RegCureBak_July_14_09_01_39_51\Sample Music.lnk
c:\program files\RegCure\Backup\RegCureBak_July_14_09_01_39_51\Sample Videos.lnk
c:\program files\RegCure\Backup\RegCureBak_July_14_09_09_45_18.reg
c:\program files\RegCure\Backup\RegCureBak_July_16_09_02_29_39.bak
c:\program files\RegCure\Backup\RegCureBak_July_16_09_02_29_39.reg
c:\program files\RegCure\Backup\RegCureBak_July_16_09_02_29_39\Recently Changed.lnk
c:\program files\RegCure\blue_duo.jpg
c:\program files\RegCure\buttonfill.jpg
c:\program files\RegCure\buttonfill_expire.jpg
c:\program files\RegCure\buttonfill_mo.jpg
c:\program files\RegCure\buttonfill_mo_expire.jpg
c:\program files\RegCure\BuyNags.htm
c:\program files\RegCure\center_gradient.jpg
c:\program files\RegCure\container_content_bkimg.gif
c:\program files\RegCure\container_content_leftimg.gif
c:\program files\RegCure\container_content_rightimg.gif
c:\program files\RegCure\contentwrapper.gif
c:\program files\RegCure\email.htm
c:\program files\RegCure\expire.css
c:\program files\RegCure\footerbar.gif
c:\program files\RegCure\green_duo.jpg
c:\program files\RegCure\help.chm
c:\program files\RegCure\info_bubble.jpg
c:\program files\RegCure\left_gradient.jpg
c:\program files\RegCure\logo.jpg
c:\program files\RegCure\Logs\Regcure-14-07-09-01-39-53.zip
c:\program files\RegCure\Logs\Regcure-14-07-09-09-45-19.zip
c:\program files\RegCure\Logs\Regcure-16-07-09-02-29-39.zip
c:\program files\RegCure\Logs\SystemInfo.zip
c:\program files\RegCure\LogSettings.xml
c:\program files\RegCure\main.css
c:\program files\RegCure\main_nag.css
c:\program files\RegCure\main_showstats.css
c:\program files\RegCure\package_titlebar_bkimg.jpg
c:\program files\RegCure\process-animation.gif
c:\program files\RegCure\RegCure.exe
c:\program files\RegCure\regcure.gif
c:\program files\RegCure\right_gradient.jpg
c:\program files\RegCure\settings.xml
c:\program files\RegCure\showstats.htm
c:\program files\RegCure\small_vbxregcure.jpg
c:\program files\RegCure\special_offer.jpg
c:\program files\RegCure\special_offer_nag.jpg
c:\program files\RegCure\subtitlebar.gif
c:\program files\RegCure\tile_titlebar.jpg
c:\program files\RegCure\Tip1.html
c:\program files\RegCure\Tip10.html
c:\program files\RegCure\Tip11.html
c:\program files\RegCure\Tip12.html
c:\program files\RegCure\Tip13.html
c:\program files\RegCure\Tip14.html
c:\program files\RegCure\Tip15.html
c:\program files\RegCure\Tip2.html
c:\program files\RegCure\Tip3.html
c:\program files\RegCure\Tip4.html
c:\program files\RegCure\Tip5.html
c:\program files\RegCure\Tip6.html
c:\program files\RegCure\Tip7.html
c:\program files\RegCure\Tip8.html
c:\program files\RegCure\Tip9.html
c:\program files\RegCure\titlebar_left.jpg
c:\program files\RegCure\titlebar_right.jpg
c:\program files\RegCure\tp.css
c:\program files\RegCure\TrialPay.htm
c:\program files\RegCure\underline.gif
c:\program files\RegCure\uninst.exe
c:\program files\RegCure\zlibwapi.dll
c:\windows\Tasks\RegCure Program Check.job
c:\windows\Tasks\RegCure Startup.job
c:\windows\Tasks\RegCure.job

.
(((((((((((((((((((((((((   Files Created from 2009-06-19 to 2009-07-19  )))))))))))))))))))))))))))))))
.

2009-07-19 07:52 . 2009-07-19 07:55   --------   d-----w-   c:\users\PhilS\AppData\Local\temp
2009-07-19 07:38 . 2009-07-19 07:38   --------   d-----w-   c:\programdata\McAfee
2009-07-15 21:01 . 2009-07-15 21:01   --------   d-----w-   c:\program files\Trend Micro
2009-07-15 08:51 . 2009-07-15 08:51   --------   d-----w-   c:\users\PhilS\AppData\Roaming\Malwarebytes
2009-07-15 08:51 . 2009-07-13 20:36   38160   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-15 08:51 . 2009-07-15 08:51   --------   d-----w-   c:\programdata\Malwarebytes
2009-07-15 08:51 . 2009-07-15 08:51   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2009-07-15 08:51 . 2009-07-13 20:36   19096   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-07-14 20:11 . 2009-06-15 14:53   156672   ----a-w-   c:\windows\system32\t2embed.dll
2009-07-14 20:11 . 2009-06-15 14:52   72704   ----a-w-   c:\windows\system32\fontsub.dll
2009-07-14 20:11 . 2009-06-15 12:42   289792   ----a-w-   c:\windows\system32\atmfd.dll
2009-07-14 20:11 . 2009-06-15 14:52   23552   ----a-w-   c:\windows\system32\lpk.dll
2009-07-14 20:11 . 2009-06-15 14:51   10240   ----a-w-   c:\windows\system32\dciman32.dll
2009-07-14 17:06 . 2009-07-14 17:06   --------   d-----w-   c:\programdata\Cached Installations
2009-07-14 17:00 . 2009-07-14 17:00   --------   d-----w-   c:\programdata\Downloaded Installations
2009-07-13 17:41 . 2009-07-16 00:48   117760   ----a-w-   c:\users\PhilS\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-13 17:41 . 2009-07-13 17:41   --------   d-----w-   c:\programdata\SUPERAntiSpyware.com
2009-07-13 17:40 . 2009-07-13 17:40   --------   d-----w-   c:\program files\SUPERAntiSpyware
2009-07-13 17:40 . 2009-07-13 17:40   --------   d-----w-   c:\users\PhilS\AppData\Roaming\SUPERAntiSpyware.com
2009-07-13 17:39 . 2009-07-13 17:39   --------   d-----w-   c:\program files\Common Files\Wise Installation Wizard
2009-07-10 23:43 . 2009-07-10 23:43   --------   d-----w-   c:\users\PhilS\AppData\Roaming\funkitron
2009-07-09 09:08 . 2009-07-09 09:08   --------   d-----w-   c:\users\PhilS\AppData\Roaming\iWin
2009-07-04 21:05 . 2009-07-04 21:06   --------   d-----w-   c:\windows\system32\ca-ES
2009-07-04 21:05 . 2009-07-04 21:06   --------   d-----w-   c:\windows\system32\eu-ES
2009-07-04 21:05 . 2009-07-04 21:06   --------   d-----w-   c:\windows\system32\vi-VN
2009-07-04 19:40 . 2009-07-04 19:40   --------   d-----w-   c:\windows\system32\EventProviders
2009-07-04 19:36 . 2009-04-11 06:28   289792   ----a-w-   c:\windows\system32\spinstall.exe
2009-07-04 19:35 . 2009-04-11 06:28   71680   ----a-w-   c:\windows\system32\propdefs.dll
2009-07-04 19:34 . 2009-04-11 06:28   152576   ----a-w-   c:\windows\system32\secproc_ssp_isv.dll
2009-07-04 19:33 . 2009-04-11 06:28   140288   ----a-w-   c:\windows\system32\wpcsvc.dll
2009-07-04 19:32 . 2009-04-11 06:28   83968   ----a-w-   c:\windows\system32\wbem\wmiutils.dll
2009-07-04 19:32 . 2009-04-11 06:28   744448   ----a-w-   c:\windows\system32\wbem\wbemcore.dll
2009-07-04 19:32 . 2009-04-11 06:28   30208   ----a-w-   c:\windows\system32\wbem\wbemprox.dll
2009-07-04 19:32 . 2009-04-11 06:28   265728   ----a-w-   c:\windows\system32\wbem\repdrvfs.dll
2009-07-04 19:32 . 2009-04-11 06:28   189440   ----a-w-   c:\windows\system32\wbem\mofd.dll
2009-07-04 19:32 . 2009-04-11 06:28   614912   ----a-w-   c:\windows\system32\wbem\fastprox.dll
2009-07-04 19:32 . 2009-04-11 06:28   265728   ----a-w-   c:\windows\system32\wbem\esscli.dll
2009-07-04 19:32 . 2009-04-11 06:28   705536   ----a-w-   c:\windows\system32\SmiEngine.dll
2009-07-04 19:32 . 2009-04-11 06:28   218624   ----a-w-   c:\windows\system32\wdscore.dll
2009-07-04 19:32 . 2009-04-11 06:27   130560   ----a-w-   c:\windows\system32\PkgMgr.exe
2009-07-04 19:32 . 2009-04-11 06:28   247808   ----a-w-   c:\windows\system32\drvstore.dll
2009-06-25 08:20 . 2009-06-25 08:24   --------   d-----w-   c:\program files\SystemRequirementsLab
2009-06-25 08:20 . 2009-06-25 08:21   --------   d-----w-   c:\users\PhilS\AppData\Roaming\SystemRequirementsLab
2009-06-25 08:20 . 2009-06-25 08:20   290816   ----a-w-   c:\users\PhilS\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_4.dll
2009-06-25 08:20 . 2009-06-25 08:20   290816   ----a-w-   c:\users\PhilS\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_3.dll
2009-06-25 08:20 . 2009-06-25 08:20   290816   ----a-w-   c:\users\PhilS\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_2.dll
2009-06-25 08:20 . 2009-06-25 08:20   290816   ----a-w-   c:\users\PhilS\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_1.dll
2009-06-22 10:42 . 2009-06-24 11:14   --------   d-----w-   c:\users\PhilS\AppData\Roaming\dvdcss
2009-06-21 21:50 . 2009-06-05 11:33   68640   ----a-w-   c:\windows\unTMV.exe
2009-06-21 21:50 . 2009-06-21 21:50   --------   d-----w-   c:\program files\SoftMaker Viewer
2009-06-19 19:58 . 2009-06-19 19:58   --------   d-----w-   c:\users\PhilS\AppData\Roaming\Recordpad
2009-06-19 11:32 . 2009-06-19 11:33   --------   d-----w-   c:\programdata\NCH Swift Sound
2009-06-19 11:32 . 2009-06-19 11:33   --------   d-----w-   c:\users\PhilS\AppData\Roaming\NCH Swift Sound
2009-06-19 11:32 . 2009-06-19 11:32   --------   d-----w-   c:\program files\NCH Software
2009-06-19 11:31 . 2009-06-27 03:50   --------   d-----w-   c:\program files\NCH Swift Sound
2009-06-19 11:28 . 2009-06-19 11:28   --------   d-----w-   c:\programdata\FreeRIP
2009-06-19 11:28 . 2009-06-19 11:28   --------   d-----w-   c:\program files\FreeRIP3

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-19 07:54 . 2008-12-26 00:31   --------   d-----w-   c:\program files\Spyware Doctor
2009-07-19 00:35 . 2008-12-26 00:22   27839   ----a-w-   c:\programdata\nvModes.dat
2009-07-15 06:38 . 2006-11-02 11:18   --------   d-----w-   c:\program files\Windows Mail
2009-07-15 00:12 . 2008-12-26 00:25   1092   ----a-w-   c:\users\PhilS\AppData\Roaming\wklnhst.dat
2009-07-14 17:11 . 2008-12-26 00:31   --------   d-----w-   c:\program files\Common Files\PC Tools
2009-07-14 17:07 . 2008-12-30 00:43   --------   d-----w-   c:\users\PhilS\AppData\Roaming\uTorrent
2009-07-14 08:56 . 2008-12-26 07:54   74432   ----a-w-   c:\users\PhilS\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-11 11:16 . 2008-08-04 17:19   --------   d-----w-   c:\programdata\WildTangent
2009-07-04 21:06 . 2006-11-02 12:37   --------   d-----w-   c:\program files\Windows Sidebar
2009-07-04 21:06 . 2006-11-02 12:37   --------   d-----w-   c:\program files\Windows Photo Gallery
2009-07-04 21:06 . 2006-11-02 12:37   --------   d-----w-   c:\program files\Windows Collaboration
2009-07-04 21:06 . 2006-11-02 12:37   --------   d-----w-   c:\program files\Windows Calendar
2009-07-04 21:06 . 2006-11-02 12:37   --------   d-----w-   c:\program files\Windows Defender
2009-07-04 21:05 . 2006-11-02 10:25   665600   ----a-w-   c:\windows\inf\drvindex.dat
2009-07-04 19:58 . 2008-11-06 03:37   --------   d-----w-   c:\programdata\NVIDIA
2009-07-04 19:47 . 2006-11-02 12:37   37665   ----a-w-   c:\windows\Fonts\GlobalUserInterface.CompositeFont
2009-06-30 22:36 . 2009-07-12 05:36   18696   ----a-w-   c:\windows\Help\OEM\scripts\HC_BatteryReplaceNew.exe
2009-06-30 22:10 . 2009-07-12 05:36   18696   ----a-w-   c:\windows\Help\OEM\scripts\HC_BatteryNoTravel.exe
2009-06-30 22:03 . 2009-07-12 05:36   18696   ----a-w-   c:\windows\Help\OEM\scripts\HC_BatteryAccessories.exe
2009-06-30 19:44 . 2009-07-12 05:36   18184   ----a-w-   c:\windows\Help\OEM\scripts\HC_BatteryWeakNew.exe
2009-06-27 01:36 . 2009-07-12 05:36   18184   ----a-w-   c:\windows\Help\OEM\scripts\HC_BatteryUpgrade.exe
2009-06-21 08:52 . 2009-06-18 10:22   --------   d-----w-   c:\users\PhilS\AppData\Roaming\vlc
2009-06-18 10:21 . 2009-06-18 10:21   --------   d-----w-   c:\program files\VideoLAN
2009-06-18 10:15 . 2009-06-18 10:13   --------   d-----w-   c:\program files\GPL MPEG Decoder
2009-06-13 10:03 . 2008-08-04 17:50   --------   d-----w-   c:\program files\Microsoft Works
2009-06-07 06:27 . 2009-01-09 00:06   --------   d-----w-   c:\program files\DivX
2009-06-07 06:23 . 2009-06-07 06:23   --------   d-----w-   c:\program files\Common Files\DivX Shared
2009-06-07 05:54 . 2009-04-08 05:13   --------   d-----w-   c:\users\PhilS\AppData\Roaming\DivX
2009-05-09 05:50 . 2009-06-12 14:11   915456   ----a-w-   c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-12 14:11   71680   ----a-w-   c:\windows\system32\iesetup.dll
2009-05-01 21:02 . 2009-05-01 21:02   90112   ----a-w-   c:\windows\system32\dpl100.dll
2009-05-01 21:02 . 2009-05-01 21:02   823296   ----a-w-   c:\windows\system32\divx_xx0c.dll
2009-05-01 21:02 . 2009-05-01 21:02   823296   ----a-w-   c:\windows\system32\divx_xx07.dll
2009-05-01 21:02 . 2009-05-01 21:02   815104   ----a-w-   c:\windows\system32\divx_xx0a.dll
2009-05-01 21:02 . 2009-05-01 21:02   811008   ----a-w-   c:\windows\system32\divx_xx16.dll
2009-05-01 21:02 . 2009-05-01 21:02   802816   ----a-w-   c:\windows\system32\divx_xx11.dll
2009-05-01 21:02 . 2009-05-01 21:02   685056   ----a-w-   c:\windows\system32\DivX.dll
2009-04-23 12:15 . 2009-06-12 14:11   784896   ----a-w-   c:\windows\system32\rpcrt4.dll
2009-04-23 12:14 . 2009-06-12 14:12   623616   ----a-w-   c:\windows\system32\localspl.dll
2009-04-21 11:39 . 2009-06-12 14:12   2034688   ----a-w-   c:\windows\system32\win32k.sys
2009-06-12 10:19 . 2009-01-06 23:26   134648   ----a-w-   c:\program files\mozilla firefox\components\brwsrcmp.dll
2009-05-01 21:02 . 2009-05-01 21:02   1044480   ----a-w-   c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02   200704   ----a-w-   c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-08-04 15:03 . 2008-08-04 15:03   8192   --sha-w-   c:\windows\Users\Default\NTUSER.DAT
.

(((((((((((((((((((((((((((((   [email protected]_02.00.53   )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-11-02 13:05 . 2009-07-19 07:34   79512              c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-12-26 07:42 . 2009-07-19 01:58   16384              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-12-26 07:42 . 2009-07-19 07:54   16384              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-12-26 07:42 . 2009-07-19 01:58   32768              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-26 07:42 . 2009-07-19 07:54   32768              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-26 07:42 . 2009-07-19 07:54   16384              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-12-26 07:42 . 2009-07-19 01:58   16384              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-19 07:53 . 2009-07-19 07:53   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-07-19 01:58 . 2009-07-19 01:58   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-07-19 01:58 . 2009-07-19 01:58   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-19 07:53 . 2009-07-19 07:53   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-12-26 04:27 . 2009-07-19 07:05   254518              c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2006-11-02 10:33 . 2009-07-19 07:38   595684              c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-07-18 20:03   595684              c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-07-19 07:38   101350              c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-07-18 20:03   101350              c:\windows\System32\perfc009.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-06-12 468264]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-06-02 80896]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-12-08 1173384]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-11 13543968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-11 92704]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05   356352   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):d7,86,ac,d9,ec,fc,c9,01

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{053E5549-ECD5-4FE4-8DB9-641DFB10CF77}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{C1BAABB6-21B7-49B7-91E1-E455B4B6BC44}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{C55EE582-4D18-4465-B67C-01CCBFDC83AC}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{B2DD7404-A6FC-40B9-8308-6C878692A3C9}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{61163C9B-D9DA-4470-B24F-3F12B829515A}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{5FFDBBF0-35FB-4F2D-9936-1E5CA81749AD}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM
"UDP Query User{557017AC-78EB-4FEF-B5BA-785EC157B329}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM
"TCP Query User{C02004D7-C5DA-4F5A-9748-7C6D34C4B495}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:µTorrent
"UDP Query User{F9002FAE-E853-4411-9606-D546AA53E040}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:µTorrent
"{C584877B-5ED8-4DE5-AF02-3B55F5AEF3FD}"= Disabled:UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{1AFE8673-5972-4C8A-BC15-0B44CC879F75}"= Disabled:TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{7D94000C-BBBC-44EB-BCCA-577F962A31C6}"= Disabled:UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{17ECCB8F-DF6F-416B-884A-F0B83C4C6A41}"= Disabled:TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DoNotAllowExceptions"= 1 (0x1)

R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [3/29/2009 5:30 PM 130936]
R0 TfFsMon;TfFsMon;c:\windows\System32\drivers\TfFsMon.sys [3/29/2009 5:32 PM 51488]
R0 TfSysMon;TfSysMon;c:\windows\System32\drivers\TfSysMon.sys [3/29/2009 5:32 PM 39200]
R1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi.sys [3/29/2009 5:30 PM 159600]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [8/4/2008 11:43 AM 361808]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [12/25/2008 5:31 PM 348752]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [5/9/2008 12:17 PM 43040]
R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg.sys [3/29/2009 5:30 PM 64392]
R3 TfNetMon;TfNetMon;c:\windows\System32\drivers\TfNetMon.sys [3/29/2009 5:32 PM 33056]
R3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service --> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [8/4/2008 10:15 AM 193840]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408]

--- Other Services/Drivers In Memory ---

*Deregistered* - mchInjDrv

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-18 c:\windows\Tasks\HPCeeScheduleForPhilS.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-08-04 03:03]

2009-07-19 c:\windows\Tasks\User_Feed_Synchronization-{9051D44C-782E-4E8D-B571-01D8B4400FEE}.job
- c:\windows\system32\msfeedssync.exe [2009-04-06 11:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = *.local
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
FF - ProfilePath - c:\users\PhilS\AppData\Roaming\Mozilla\Firefox\Profiles\r2or64x5.default\
FF - prefs.js: browser.startup.homepage - hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-19 00:54
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 


c:\users\PhilS\AppData\Local\Temp\catchme.dll 53248 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1140)
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll

- - - - - - - > 'lsass.exe'(660)
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll

- - - - - - - > 'Explorer.exe'(2912)
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\wlanext.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\windows\System32\drivers\XAudio.exe
c:\program files\Spyware Doctor\TFEngine\TFService.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2009-07-19  1:03 - machine was rebooted
ComboFix-quarantined-files.txt  2009-07-19 08:03
ComboFix2.txt  2009-07-19 02:10
ComboFix3.txt  2009-07-17 10:37

Pre-Run: 73,999,659,008 bytes free
Post-Run: 74,679,185,408 bytes free

356   --- E O F ---   2009-07-15 06:38
* Click START then RUN
* Now type Combofix /u in the runbox
* Make sure there's a space between Combofix and /u
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

----------

Use the Kaspersky Lab Online Scanner

In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

  • Click on SCAN NOW
  • Click Accept.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
  • The scan will take a while, so be patient and let it finish.
When the scan is done, in the Scan is complete window, any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.

To obtain the report:
Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop.
  • In the File name area use KScan, or something similar.
  • In Save as type: click the drop arrow and select: Text file [*.txt]
  • Then, click: Save


Copy and paste the Kaspersky Online Scanner Report in your next reply.

Note for Internet Explorer 7 and 8 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.

If needed, this animation will guide you through the process.
1477.

Solve : Internet Explorer has virus, I think. Keeps reappearing even after I delete it?

Answer»

Thanks to combo-fix, I think everything is OK now! Thanks!Uninstall ComboFix

Click Start then Run and enter everything from the Code box below into the run box and then click OK.
Code: [Select]"%userprofile%\Desktop\Combo-Fix" /u
Note: The space between the Combo-fix" and the /u must be there.

The above procedure will

  • Delete ComboFix and its associated files and folders.
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Set a new, clean Restore Point.
.
----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make SURE you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* PLEASE let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search &AMP; Destroy. Guide: Use Spybot's Immunize Feature to PREVENT spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free TOOLS to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
1478.

Solve : Pwdump?

Answer»

Hi guy's any idea why this keeps cropping up?

[attachment deleted by ADMIN] Quote

Behavior
Pwdump is a hack tool that is used to grab Windows password hashes from a REMOTE Windows computer.

HTTP://www.symantec.com/security_response/writeup.jsp?docid=2005-032616-0025-99&tabid=1Thanks EVIL I did search symantec but I may of done a typo ERROR. Thanks again.
1479.

Solve : Having a bit of trouble...?

Answer»

Hi,

I'm having some trouble with my computer. Its being slower then normal and when I go to shut down there are a couple of errors that always pop up. And they're not always the same ones. One POPS up sometimes saying that yahoo messenger has stopped responding or one called sprtmcd.exe, I think it is. Also, I've been recently getting one with app and then a bunch of numbers when I shut down.

I recently switched internet providers and am going with MSN for internet instead of AOL. And I -thought- that I removed everything AOL related aside from AIM but... on the processes it lists aolsoftware.exe. Which, seems to slow down MSN sometimes. But after I cancel it out my internet works fine. Anyway I can delete it?

Have already run a HiJackThis log and here it is:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:54:10 PM, on 7/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dlcdcoms.exe
C:\Program Files\MSN\MSNCoreFiles\msn.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\MSN\MSNIA\CC\MSNCC\logonmgr.exe
C:\Program Files\MSN\MSNIA\CC\MSNCC\msncc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\MSN\MSNIA\CC\MSNCC\WA\MSNAccel.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Dell Support Center\gs_agent\dsc.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://kucampus.kaplan.edu/Login/Login.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9022
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1138933720\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [DLCDCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll,[email protected]
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp /HIDEBL
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Update Page Content - C:\Program Files\MSN\MSNIA\CC\MSNCC\WA\refreshpage.htm
O8 - Extra context menu item: View All Originals On Page - C:\Program Files\MSN\MSNIA\CC\MSNCC\WA\getoriginal.htm
O8 - Extra context menu item: View Original Image - C:\Program Files\MSN\MSNIA\CC\MSNCC\WA\getoriginal.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\DOCUMENTS and Settings\Laci Bailey\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} -
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} -
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_02) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{5B0A3E34-A88D-4821-A324-9B2429F65F46}: NameServer = 209.244.0.3 209.244.0.4
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! ANTIVIRUS - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: dlcd_device - Unknown owner - C:\WINDOWS\system32\dlcdcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 10376 bytesYou have Viewpoint installed.

Viewpoint Media Player/Manager/Toolbar is considered as  http://en.wikipedia.org/wiki/Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".

More information:

http://www.greatis.com/appdata/u/v/viewmgr.exe.htm


It is suggested to remove the program now.
Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.
•Viewpoint

•Viewpoint Manager

•Viewpoint Media Player

•Viewpoint Toolbar

•Viewpoint Experience Technology

1480.

Solve : One Tough Virus Infection will not allow any application to launch?

Answer»

Computer is slow at certain task, like going to any sites that have microsoft URL.  Still have major problems with microsoft update.  I did a services pack update, which did give a clue that something is running under stealth.  I've reloaded hundreds of XP systems, and have updated services packs many times.  But this one exhibits one strange behavior, on reboot (after service pack 3 applied) it had three command windows open after windows was completely loaded.  They stayed open about 10 second then closed.Download Dial-a-Fix by djlizard, save it to the desktop then extract it to it's own folder.

  • Open the folder and run Dial-a-fix.exe
  • 2 windows will open. Close the one in the background LABELED Restrictive Policies
  • Check the box in section 1, Empty temp folders.
  • Check the box in section 2, Fix Windows Installer.
  • Check the box in section 3, Fix Windows Update.
  • Check the box in section 4, labeled SSL/HTTPS/Cryptography. The 4 boxes under it should be pre-checked
  • Check all boxes in section 5, labeled Registration Center.
  • Click Go
  • OK any error messages if received, but write them down and post them here.
  • Restart the computer when done.
.
Is the problem fixed?

----------

If not...

Do you have an XP CD?

If so, place it in your CD ROM drive and follow the instructions below:
  • Click on Start > Run and type sfc /scannow then press Enter (note the space between scf and /scannow)
    • Let this run undisturbed until the window with the blue  progress bar goes away
SFC - Which stands for System File Checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.  Dial-a-fix did the job.  Upon reboot, system connected to MS update, downloaded all updates, system installed the updates.  I now have confidence that this system will be able to operate normally. 

Thanks for your EXCELLENT professional Troubleshooting and Malware extraction techniques!

With High Regards

Atech  Hmmm, just when you though it was safe to go back-into-thMalwarebytes' Anti-Malware 1.38
Database version: 2411
Windows 5.1.2600 Service Pack 3

7/13/2009 12:51:40 AM
mbam-log-2009-07-13 (00-51-33).txt

Scan type: Full Scan (C:\|F:\|)
Objects scanned: 198453
Time elapsed: 2 hour(s), 7 minute(s), 9 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegedit (Hijack.Regedit) -> No ACTION taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
e water!   And there's more

Here's what spynot has to say


Win32.Iroffer.af: [SBI $E19E27B1]  Data (File, nothing done)
  C:\WINNT\Client
  Properties.size=0
  Properties.md5=D41D8CD98F00B204E9800998ECF8427E
  Properties.filedate=1065381757
  Properties.filedatetext=2003-10-05 12:22:36

Win32.Agent.pz: [SBI $7EC6899E] Settings (Registry value, nothing done)
  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Network\UID

Win32.Agent.pz: [SBI $8980C6CD] Settings (Registry value, nothing done)
  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Network\UID

MyWay.MyWebSearch: [SBI $D6FC06E2] Class ID (Registry key, nothing done)
  HKEY_CLASSES_ROOT\CLSID\{DC250EB2-2928-41c5-89C9-5FF86FEE1691}

WildTangent: [SBI $CC7760FE] Settings (Registry value, nothing done)
  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Java VM\ClassPath=...;C:\Program Files\WildTangent\Apps\DRM0301Java.jar...

Microsoft.WindowsSecurityCenter.AntiVir usOverride: [SBI $3604910C] Settings (Registry change, nothing done)
  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride

BonziBuddy: [SBI $0ABCD7B1] Program directory (Directory, nothing done)
  C:\Program Files\BonziBuddy\

BonziBuddy: [SBI $EBA31E67] Settings (Registry key, nothing done)
  HKEY_USERS\S-1-5-21-3563514748-1417066420-3376078148-1006\Software\VB and VBA Program Settings\BONZIBUDDY

NewtonKnows: [SBI $9F6FF28E] Class ID (Registry key, nothing done)
  HKEY_CLASSES_ROOT\CLSID\{6600D22F-083F-11D6-99DE-D172E92EBC2A}

NewtonKnows: [SBI $FA85E989] Interface (Registry key, nothing done)
  HKEY_CLASSES_ROOT\Interface\{6600D22C-083F-11D6-99DE-D172E92EBC2A}

NewtonKnows: [SBI $0D7AE83A] Type library (Registry key, nothing done)
  HKEY_CLASSES_ROOT\TypeLib\{6600D220-083F-11D6-99DE-D172E92EBC2A}

StarWare: [SBI $A82637BF] Settings (Registry key, nothing done)
  HKEY_USERS\.DEFAULT\Software\Starware322

StarWare: [SBI $A82637BF] Settings (Registry key, nothing done)
  HKEY_USERS\S-1-5-18\Software\Starware322

StarWare: [SBI $8008440B] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\BrowserSearch\

StarWare: [SBI $157F2D4F] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Configurator\

StarWare: [SBI $9780440A] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\ErrorSearch\

StarWare: [SBI $76047FA3] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Layouts\

StarWare: [SBI $E5A2946D] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Manager\

StarWare: [SBI $3F6D43DB] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Reference\

StarWare: [SBI $461B2748] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\RelatedSearch\

StarWare: [SBI $D5728ACA] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Toolbar\

StarWare: [SBI $007CB757] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\ToolbarLogo\

StarWare: [SBI $F5040D20] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\ToolbarSearch\

StarWare: [SBI $6F569955] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\TravelSearch\

StarWare: [SBI $FDA327EC] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Weather\

StarWare: [SBI $F26334AD]  Web page (File, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Weather\AlertArchive.xml
  Properties.size=112
  Properties.md5=895945C70D7AB748FFDA17CA2338D3D2
  Properties.filedate=1187326290
  Properties.filedatetext=2007-08-16 21:51:30

StarWare: [SBI $A6C3D1ED] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\

StarWare: [SBI $4AFA1DB7] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Games\

StarWare: [SBI $BF882AFD] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Games\images\

StarWare: [SBI $37E48ACD] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Games\images\active\

StarWare: [SBI $4A2FB6EE]  Picture (File, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Games\images\active\Games0.bmp
  Properties.size=1208
  Properties.md5=984A8652D52AE5D4F27503FF3F851D76
  Properties.filedate=1187326300
  Properties.filedatetext=2007-08-16 21:51:39

StarWare: [SBI $465B4952] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Games\images\default\

StarWare: [SBI $2ABAE699] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Movies\

StarWare: [SBI $3C8A2EAC] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Movies\images\

StarWare: [SBI $ACFB606D] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Movies\images\active\

StarWare: [SBI $9016F550] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Movies\images\default\

StarWare: [SBI $D7FD12CF] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Screensavers\

StarWare: [SBI $0C066ECE] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\ScreensaversMarketingSitePager\

StarWare: [SBI $78757AD7] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\ScreensaversMarketingSitePager\images\

StarWare: [SBI $0B99A6BB] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\ScreensaversMarketingSitePager\images\active\

StarWare: [SBI $FF01E077] Program directory (Directory, nothing done)
  C:\WINNT\system32\config\systemprofile\Application Data\Starware322\ScreensaversMarketingSitePager\images\default\

Right Media: Tracking cookie (Internet Explorer: Bill) (Cookie, nothing done)
 


--- Spybot - Search & Destroy version: 1.6.2  (build: 20090126) ---

2009-01-26 blindman.exe (1.0.0.
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2009-07-07 unins000.exe (51.41.0.0)
2009-07-07 unins001.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-01-26 advcheck.dll (1.6.2.15)
2007-04-02 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2009-05-19 Includes\Adware.sbi (*)
2009-06-02 Includes\AdwareC.sbi (*)
2009-01-22 Includes\Cookies.sbi (*)
2009-05-19 Includes\Dialer.sbi (*)
2009-06-02 Includes\DialerC.sbi (*)
2009-01-22 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2009-07-07 Includes\HijackersC.sbi (*)
2009-06-23 Includes\Keyloggers.sbi (*)
2009-07-07 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2009-06-30 Includes\Malware.sbi (*)
2009-07-07 Includes\MalwareC.sbi (*)
2009-03-25 Includes\PUPS.sbi (*)
2009-07-07 Includes\PUPSC.sbi (*)
2009-01-22 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2009-06-02 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2009-04-07 Includes\Spyware.sbi (*)
2009-07-07 Includes\SpywareC.sbi (*)
2009-06-08 Includes\Tracks.uti
2009-07-07 Includes\Trojans.sbi (*)
2009-07-08 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
Just let SpyBot fix those. They are not a real threat but should be fixed still.

  • Click START then RUN
  • Now type Combofix /u in the runbox
  • Make sure there's a space between Combofix and /u
  • Then hit Enter.
.
.
The above procedure will:
  • Delete: ComboFix and its associated files and folders.
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Set a new, clean Restore Point.
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware INFECTION in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Hmm, I've cleaned all of the cache's done all of the suggested items.  The system will  appear totally clean... for about 3 reboots... then strange things begin to happen.  Now mind this, I've totally isolated this system from the internet.  So it's not going on-line and down loading these new infections.  There has to be a generator somewhere on the system that start the process all over again, locking out the registry, infecting exe files, changing system polices.  The system has degraded so badly I am no longer able to launch any spyware or virus applications loaded.  I know how to remedy all of this, but it seems like a futile effort...  Are you (or do you know of anyone who is) proficient with Icesword?

Thanks for your thoughts in-advance
AtechYou don't need IceSword, we already RAN GMER. Besides it hasn't updated in a very long time.

Download Lop S&D by Eric_71 and save it to your Desktop. Lop S&D will only run on Windows XP and Windows Vista

Disable your antivirus and antimalware programs so they do not interfere with the running of Lop S&D. If needed see: How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Double click LopSD.exe - If you are using Windows Vista, right-click on the LopSD icon and select Run as administrator to perform this scan.

  • Choose the language by typing of the corresponding letter and press Enter
  • Click OK at the informative window
  • Type 1, to choose Option 1 (Search) then press Enter
  • Wait until the end of the scan
  • A report will be generated, post the contents of it in your next reply.
.
A copy of the report can be found at this location: %systemdrive%\lopR.txt, in most cases C:\lopR.txtHello EF,
I hate it when forum users don't log the final outcome of a problem. That being said, I am here to share the outcome of all our efforts.  The system degraded to a state worse then the first case. All of the steps I used to access the registry failed, no exe or com files where able to launch, unable to browse the internet freely. Meaning I could go to any search engine, but was not allowed to open any sites that had to do with virus, spyware, malware, if I did the browser closed.  I know we gave it our best shot, but this system could not be saved.  I imaged the drive and then D-bombed it this evening (a type of low level reformat) and will do a fresh system install.  No data extracted from the old system will be moved forward to the new one, until we better understand what we are dealing with.

Thanks till you are better paid
AtechThanks for letting me know.
1481.

Solve : Problem with CLayoutEngine-Tooltip?

Answer»

During computer shut down, I get a message that CLayoutEngine-Tooltip is having a PROBLEM shutting down. I eventually have to click "END" to close it.  I know that this type of occurrence SOMETIMES indicates a problem which may be associated with viruses or spy-ware.

Can anyone help please?

"CLayoutEngine-Tooltip" is a part of YAHOO messenger.

I'd try downloading and reinstalling the NEWEST version of yahoo messenger, and see if that fixes the issue.Thanks for that I'll give it a try.

1482.

Solve : HijackThis / Superantispyware / Malwarebytes - Logs posted?

Answer»

Have had Internet connection loss at regular intervals requiring a reboot, which has coincided with a rather active DVD ROM drive drawer opening and closing repeatedly at given periods.

Requested logs attached:


***HIJACK THIS***

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:22:48, on 20/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://uk.search.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://uk.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://uk.search.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://uk.search.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://uk.search.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Tiscali 10.0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows LIVE Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn3\yt.dll
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Adobe\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: Logitech Desktop Messenger.lnk.disabled
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\WINDOWS\System32\shdocvw.dll (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/tiny/
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/common/cab/DjVuControlLite_EN.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20011217/qtinstall.info.apple.com/qt505/us/win/QuickTimeInstaller.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1133029434858
O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} - http://fdl.msn.com/public/chat/msnchat42.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.communities.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {E87A6788-1D0F-4444-8898-1D25829B6755} - http://fdl.msn.com/public/chat/msnchat4.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{32603D8A-B0E2-4EDB-A061-83F6DAE2D8C6}: NameServer = 212.139.132.105 212.139.132.107
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Update Service (gupdate1c9b95a98ef3fc2) (gupdate1c9b95a98ef3fc2) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: TrueVector Internet MONITOR (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
O24 - Desktop Component 0: (no name) - http://www.palantir.net/2001/gfx/main.jpg

--
End of file - 11995 bytes


***MALWAREBYTES***

Malwarebytes' Anti-Malware 1.39
Database version: 2467
Windows 5.1.2600 Service Pack 3

20/07/2009 16:20:18
mbam-log-2009-07-20 (16-20-18).txt

Scan type: Quick Scan
Objects scanned: 120332
Time elapsed: 16 minute(s), 30 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


***Superantispyware***


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/20/2009 at 03:42 PM

Application Version : 4.26.1006

Core Rules Database Version : 4004
Trace Rules Database Version: 1944

Scan type       : Complete Scan
Total Scan Time : 03:54:05

Memory items scanned      : 453
Memory threats detected   : 0
Registry items scanned    : 8456
Registry threats detected : 0
File items scanned        : 111822
File threats detected     : 2

Adware.Tracking Cookie
   C:\Documents and Settings\James Pauley\Cookies\[email protected][1].txt
   C:\Documents and Settings\James Pauley\Cookies\[email protected][1].txt



1483.

Solve : Question about Virus damage!?

Answer»

I have just a simple question:
Can a Virus DAMAGE a hardware part on the computer?
Cheers.
Probably not.

Although I suppose, if they were CORRECTLY written, they might be able to say, overclock a component and cause it to fail, but that would be fairly SPECIFIC to each PC, not something you could make into a generic virus.

1484.

Solve : GMER shows rootkit in registry but cannot delete????

Answer»

Okay have run the combofix and the cleaner.  Now the Kapersky Lab ask that you turn off antivirus programs to run but I don't feel comfortable doing that is that safe?Yes it's safe.Okay, here is the Kscan report and GMER:


Sunday, July 19, 2009
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Sunday, July 19, 2009 15:18:32
Records in database: 2494909
Scan settings
Scan using the following database    extended
Scan archives    yes
Scan mail databases    yes
Scan area    My Computer
C:\
D:\
E:\
Scan statistics
Files scanned    110042
Threat name    0
Infected objects    0
Suspicious objects    0
Duration of the scan    01:41:27

No malware has been detected. The scan area is clean.
The selected area was scanned.


GMER:

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-19 22:19:25
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.15 ----

SSDT            spcs.sys                                                          ZwEnumerateKey [0xB9EC6CA2]
SSDT            spcs.sys                                                          ZwEnumerateValueKey [0xB9EC7030]

Code            fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)  IoCreateDevice

---- Devices - GMER 1.0.15 ----

Device          \FileSystem\Ntfs \Ntfs                                            8A6501F8
Device          \Driver\Tcpip \Device\Ip                                          fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device          \Driver\Tcpip \Device\Tcp                                         fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device          \Driver\Tcpip \Device\Udp                                         fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device          \Driver\Tcpip \Device\RawIp                                       fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)

AttachedDevice  \Driver\Kbdclass \Device\KeyboardClass0                           SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice  \Driver\Kbdclass \Device\KeyboardClass1                           SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

---- EOF - GMER 1.0.15 ----


higruidmydckil & UACd.sys are still showing up in my registry even though everything seems clean, is there anything that will delete them? Thank you for all your help!Download Registry Search by Bobbi Flekman
(see the link titled RegSearch Download Link)

* Extract the files from Regsearch.zip into a folder.
* Doubleclick regsearch.exe to start the program.
* Enter UACd.sys in the top area of the form and then click OK
* Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well).
* Add the contents of the Notepad file to your next reply.

----------

Also search for higruidmydckil and post that log.Here are the logs from the registry search::

Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.6.0

; Results at 7/20/2009 10:22:47 AM for strings:
;  'hjgruidmydckil'
; Strings excluded from search:
;  (None)
; Search in:
; Registry Keys  Registry Values  Registry Data 
; HKEY_LOCAL_MACHINE  HKEY_USERS 


[HKEY_USERS\S-1-5-21-1277242506-2705649472-1450290610-1007\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit]
"LastKey"="My Computer\\HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet003\\Services\\hjgruidmydckil"

; End Of The Log...



Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.6.0

; Results at 7/20/2009 10:51:28 AM for strings:
;  'uacd.sys'
; Strings excluded from search:
;  (None)
; Search in:
; Registry Keys  Registry Values  Registry Data 
; HKEY_LOCAL_MACHINE  HKEY_USERS 


[HKEY_USERS\S-1-5-21-1277242506-2705649472-1450290610-1007\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit]
"LastKey"="My Computer\\HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet003\\Services\\UACd.sys"

; End Of The Log...


Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note:  It is important that it is saved directly to your Desktop

DO NOT run it yet!

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

FixCSet::

Quit::

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

----------

Now the registry again for those entries and post the logs.

.okay here are the logs:

ComboFix 09-07-20.03 - Suil 07/20/2009 20:25.4.2 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.2046.1385 [GMT -4:00]
Running from: c:\documents and settings\Suil\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Suil\Desktop\CFScript.txt

AV: EMBARQ® Online Security 8.00 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: EMBARQ® Online Security 8.00 *disabled* {D4747503-0346-49EB-9262-997542F79BF4}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((   Files Created from 2009-06-21 to 2009-07-21  )))))))))))))))))))))))))))))))
.

2009-07-20 18:24 . 2009-07-20 18:24   --------   d-----w-   c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-07-20 16:51 . 2009-07-20 16:51   --------   d-----w-   c:\windows\system32\wbem\Repository
2009-07-18 03:00 . 2009-07-18 03:00   --------   d-----w-   C:\Rooter$
2009-07-17 17:38 . 2009-07-17 19:22   117760   ----a-w-   c:\documents and settings\\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-17 17:37 . 2009-07-17 17:37   --------   d-----w-   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-07-17 17:37 . 2009-07-20 16:59   --------   d-----w-   c:\program files\SUPERAntiSpyware
2009-07-17 17:37 . 2009-07-20 16:23   --------   d-----w-   c:\documents and settings\\Application Data\SUPERAntiSpyware.com
2009-07-17 00:02 . 2009-07-17 00:02   --------   d-----w-   c:\program files\Alwil Software
2009-07-16 19:56 . 2009-07-16 19:56   --------   d-----w-   c:\documents and settings\\Application Data\ImgBurn
2009-07-16 19:50 . 2009-07-16 19:50   --------   d-----w-   c:\program files\ImgBurn
2009-07-16 14:17 . 2008-06-13 13:10   272128   -c----w-   c:\windows\system32\dllcache\bthport.sys
2009-07-16 14:17 . 2008-10-24 11:10   453632   -c----w-   c:\windows\system32\dllcache\mrxsmb.sys
2009-07-16 14:15 . 2009-02-06 09:49   2020864   -c----w-   c:\windows\system32\dllcache\ntkrpamp.exe
2009-07-16 14:15 . 2009-02-06 09:49   2062976   -c----w-   c:\windows\system32\dllcache\ntkrnlpa.exe
2009-07-16 02:44 . 2009-07-16 02:44   717296   ----a-w-   c:\windows\system32\drivers\sptd.sys
2009-07-16 00:09 . 2009-07-20 16:47   --------   d-----w-   C:\UBCD4Win
2009-07-15 21:02 . 2001-08-17 18:56   66048   -c--a-w-   c:\windows\system32\dllcache\s3legacy.dll
2009-07-15 20:29 . 2009-07-15 20:29   410984   ----a-w-   c:\windows\system32\deploytk.dll
2009-07-15 20:28 . 2009-07-15 20:28   152576   ----a-w-   c:\documents and settings\\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-07-15 19:30 . 2009-07-15 19:30   3775176   ----a-w-   c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-07-15 17:29 . 2004-08-04 10:00   456704   -c--a-w-   c:\windows\system32\dllcache\smtpsvc.dll
2009-07-15 17:28 . 2004-08-04 10:00   10129408   -c--a-w-   c:\windows\system32\dllcache\hwxkor.dll
2009-07-15 17:27 . 2004-08-04 10:00   829440   -c--a-w-   c:\windows\system32\dllcache\inetmgr.dll
2009-07-15 17:24 . 2004-08-04 10:00   16384   -c--a-w-   c:\windows\system32\dllcache\isignup.exe
2009-07-15 17:08 . 2004-08-04 10:00   24661   -c--a-w-   c:\windows\system32\dllcache\spxcoins.dll
2009-07-15 17:08 . 2004-08-04 10:00   24661   ----a-w-   c:\windows\system32\spxcoins.dll
2009-07-15 17:08 . 2004-08-04 10:00   13312   -c--a-w-   c:\windows\system32\dllcache\irclass.dll
2009-07-15 17:08 . 2004-08-04 10:00   13312   ----a-w-   c:\windows\system32\irclass.dll
2009-07-15 17:08 . 2009-07-15 17:08   --------   d-s---w-   c:\windows\system32\config\systemprofile\History
2009-07-15 12:54 . 2009-07-15 12:54   --------   d-----w-   c:\windows\dell
2009-07-14 19:35 . 2009-07-14 19:35   --------   d-----w-   c:\program files\Windows Resource Kits
2009-07-14 18:09 . 2009-07-14 18:09   --------   d-sh--w-   c:\documents and settings\\PrivacIE
2009-07-14 18:05 . 2009-07-14 18:05   --------   d-sh--w-   c:\documents and settings\\IETldCache
2009-07-14 18:04 . 2009-07-14 18:04   --------   d-sh--w-   c:\windows\system32\config\systemprofile\IETldCache
2009-07-14 18:03 . 2009-07-14 18:03   --------   d-sh--w-   c:\documents and settings\LocalService\IETldCache
2009-07-14 18:01 . 2009-07-14 18:01   --------   d-----w-   c:\windows\ie8updates
2009-07-14 17:59 . 2009-07-14 18:00   --------   dc-h--w-   c:\windows\ie8
2009-07-13 00:22 . 2009-07-13 00:22   --------   d-----w-   c:\documents and settings\\Application Data\Apple Computer
2009-07-12 23:52 . 2009-07-12 23:52   --------   d-----w-   c:\program files\Trend Micro
2009-07-12 00:29 . 2009-07-12 00:29   --------   d-----w-   c:\documents and settings\\Application Data\Malwarebytes
2009-07-12 00:29 . 2009-07-13 17:36   38160   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-12 00:29 . 2009-07-15 19:30   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2009-07-12 00:29 . 2009-07-13 17:36   19096   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-07-12 00:29 . 2009-07-12 00:29   --------   d-----w-   c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-11 01:26 . 2009-07-11 01:26   --------   d--h--w-   c:\windows\system32\GroupPolicy
2009-07-09 00:00 . 2009-07-09 00:01   --------   d-----w-   c:\program files\QuickTime
2009-07-09 00:00 . 2009-07-09 00:00   --------   d-----w-   c:\documents and settings\All Users\Application Data\Apple Computer
2009-07-09 00:00 . 2009-07-09 00:00   --------   d-----w-   c:\documents and settings\\Local Settings\Application Data\Apple
2009-07-08 23:59 . 2009-07-09 00:00   --------   d-----w-   c:\program files\Apple Software Update
2009-07-08 23:59 . 2009-07-08 23:59   --------   d-----w-   c:\documents and settings\All Users\Application Data\Apple
2009-07-08 23:59 . 2009-07-08 23:59   --------   d-----w-   c:\documents and settings\\Local Settings\Application Data\Apple Computer
2009-06-29 21:10 . 2009-06-29 21:10   --------   d-----w-   c:\program files\IKEA HomePlanner
2009-06-29 21:10 . 2009-07-20 16:59   --------   d-----w-   c:\program files\Common Files\Wise Installation Wizard
2009-06-23 12:14 . 2009-06-23 12:14   --------   d-----w-   c:\documents and settings\All Users\Application Data\HPSSUPPLY
2009-06-23 12:14 . 2009-06-23 12:14   --------   d-----w-   c:\documents and settings\\Application Data\HPAppData
2009-06-23 12:11 . 2009-06-23 12:11   --------   d-----w-   c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-06-23 12:07 . 2009-07-09 13:46   145901   ----a-w-   c:\windows\hpoins21.dat
2009-06-23 12:07 . 2007-09-05 18:26   8138   ----a-w-   c:\windows\hpomdl21.dat

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-21 00:03 . 2009-06-05 16:12   --------   d-----w-   c:\program files\Mozilla Thunderbird
2009-07-20 21:04 . 2008-11-14 22:09   --------   d-----w-   c:\program files\Embarq Online Security 8
2009-07-20 16:53 . 2008-09-15 14:49   --------   d-----w-   c:\documents and settings\All Users\Application Data\Google Updater
2009-07-17 19:35 . 2006-05-30 20:23   --------   d-----w-   c:\program files\Java
2009-07-17 02:28 . 2006-06-04 16:29   204744   ----a-w-   c:\documents and settings\\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-16 02:44 . 2006-05-30 20:26   --------   d--h--w-   c:\program files\InstallShield Installation Information
2009-07-15 19:21 . 2006-06-07 22:14   302   ----a-w-   c:\windows\system32\wacom.dat
2009-07-15 17:23 . 2004-08-11 22:12   23428   ----a-w-   c:\windows\system32\emptyregdb.dat
2009-07-11 00:58 . 2006-06-14 20:25   163712   ----a-w-   c:\windows\system32\drivers\vidstub.*censored*
2009-07-08 13:44 . 2008-11-14 22:21   33920   ----a-w-   c:\windows\system32\drivers\fsbts.sys
2009-06-23 12:14 . 2006-10-15 23:19   --------   d-----w-   c:\program files\HP
2009-06-23 00:57 . 2006-10-15 23:21   --------   d-----w-   c:\documents and settings\All Users\Application Data\HP
2009-06-16 14:55 . 2004-08-04 10:00   82432   ----a-w-   c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2004-08-04 10:00   119808   ----a-w-   c:\windows\system32\t2embed.dll
2009-06-11 14:55 . 2009-06-11 14:56   25784   ----a-w-   c:\windows\Fonts\ROTORCAP.TTF
2009-06-11 14:43 . 2009-06-11 14:44   37388   ----a-w-   c:\windows\Fonts\visitor2.ttf
2009-06-11 14:43 . 2009-06-11 14:44   3520   ----a-w-   c:\windows\Fonts\VISITOR.FON
2009-06-11 14:43 . 2009-06-11 14:44   3856   ----a-w-   c:\windows\Fonts\mints-strong.fon
2009-06-11 14:39 . 2009-06-11 14:40   256880   ----a-w-   c:\windows\Fonts\Calibribold.ttf
2009-06-11 14:39 . 2009-06-11 14:40   367620   ----a-w-   c:\windows\Fonts\CalibriIz.TTF
2009-06-11 14:39 . 2009-06-11 14:40   36648   ----a-w-   c:\windows\Fonts\MARKEN__.TTF
2009-06-11 14:39 . 2009-06-11 14:40   36552   ----a-w-   c:\windows\Fonts\MARKEN__CAPS.ttf
2009-06-11 14:35 . 2009-06-11 14:36   52680   ----a-w-   c:\windows\Fonts\STAN0757CAPS.TTF
2009-06-11 14:35 . 2009-06-11 14:36   316876   ----a-w-   c:\windows\Fonts\arialcaps.ttf
2009-06-11 02:44 . 2009-06-11 02:45   46596   ----a-w-   c:\windows\Fonts\Arial Special G1 Caps.ttf
2009-06-11 02:12 . 2009-06-11 02:13   71132   ----a-w-   c:\windows\Fonts\ITC Avant Garde Gothic LT Bold.ttf
2009-06-11 02:12 . 2009-06-11 02:13   70040   ----a-w-   c:\windows\Fonts\ITC Avant Garde Gothic LT Medium.ttf
2009-06-11 02:12 . 2009-06-11 02:13   6928   ----a-w-   c:\windows\Fonts\HaxrCorp 4088.fon
2009-06-11 02:12 . 2009-06-11 02:13   64396   ----a-w-   c:\windows\Fonts\ITC Avant Garde Gothic LT Medium Caps.ttf
2009-06-11 02:12 . 2009-06-11 02:13   4240   ----a-w-   c:\windows\Fonts\HaxrCorp Caps.FON
2009-06-11 02:12 . 2009-06-11 02:13   254296   ----a-w-   c:\windows\Fonts\calibri.ttf
2009-06-11 02:03 . 2009-06-11 02:03   --------   d-----w-   c:\program files\Free RAR Extract Frog
2009-06-07 03:15 . 2009-06-07 03:15   47792   ----a-w-   c:\windows\Fonts\HOOG0554.TTF
2009-06-07 02:52 . 2009-06-07 02:53   46368   ----a-w-   c:\windows\Fonts\Kroe0555caps.ttf
2009-06-07 02:52 . 2009-06-07 02:53   3952   ----a-w-   c:\windows\Fonts\Kroeger0.fon
2009-06-07 02:52 . 2009-06-07 02:53   22464   ----a-w-   c:\windows\Fonts\pf_tempesta_seven_extended.ttf
2009-06-07 02:52 . 2009-06-07 02:53   22176   ----a-w-   c:\windows\Fonts\pf_tempesta_seven.ttf
2009-06-07 02:52 . 2009-06-07 02:53   22160   ----a-w-   c:\windows\Fonts\pf_tempesta_seven_extended_bold.ttf
2009-06-07 02:52 . 2009-06-07 02:53   21780   ----a-w-   c:\windows\Fonts\pf_tempesta_seven_bold.ttf
2009-06-07 02:52 . 2009-06-07 02:53   21616   ----a-w-   c:\windows\Fonts\pf_tempesta_seven_condensed.ttf
2009-06-07 02:52 . 2009-06-07 02:53   21160   ----a-w-   c:\windows\Fonts\pf_tempesta_seven_condensed_bold.ttf
2009-06-07 02:52 . 2009-06-07 02:53   20796   ----a-w-   c:\windows\Fonts\pf_tempesta_seven_compressed_bold.ttf
2009-06-07 02:52 . 2009-06-07 02:53   20396   ----a-w-   c:\windows\Fonts\pf_tempesta_seven_compressed.ttf
2009-06-07 02:37 . 2009-06-07 02:38   48080   ----a-w-   c:\windows\Fonts\KROE0555.TTF
2009-06-07 02:37 . 2009-06-07 02:38   365264   ----a-w-   c:\windows\Fonts\Segoe UI .ttf
2009-06-07 02:37 . 2009-06-07 02:38   12056   ----a-w-   c:\windows\Fonts\Blank.ttf
2009-06-05 16:13 . 2009-06-05 16:13   --------   d-----w-   c:\documents and settings\Suil\Application Data\Thunderbird
2009-06-03 19:27 . 2004-08-04 10:00   1290752   ----a-w-   c:\windows\system32\quartz.dll
2009-05-07 15:44 . 2004-08-04 10:00   344064   ----a-w-   c:\windows\system32\localspl.dll
2009-04-29 04:52 . 2006-03-04 03:33   659456   ----a-w-   c:\windows\system32\wininet.dll
2009-04-29 04:52 . 2004-08-04 10:00   81920   ----a-w-   c:\windows\system32\ieencode.dll
2009-06-15 14:37 . 2008-09-17 21:10   134648   ----a-w-   c:\program files\mozilla firefox\components\brwsrcmp.dll
2006-06-05 22:05 . 2006-06-05 22:05   56   --sha-r-   c:\windows\system32\0E1A64F2CB.sys
2006-06-05 22:05 . 2006-06-05 22:05   1890   --sha-w-   c:\windows\system32\KGyGaAvL.sys
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2002-07-17 200767]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-15 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-04-06 1032192]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"LogonStudio"="c:\program files\WinCustomize\LogonStudio\logonstudio.exe" [2002-09-03 987187]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-06-16 180269]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-07-25 188416]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"F-Secure Manager"="c:\program files\Embarq Online Security 8\Common\FSM32.EXE" [2008-09-23 182936]
"F-Secure TNB"="c:\program files\Embarq Online Security 8\FSGUI\TNBUtil.exe" [2008-09-23 957024]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-15 148888]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-11-16 397312]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-6-4 98304]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-6-4 98304]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-5-30 24576]
HotSync Manager.lnk - c:\program files\Palm\Hotsync.exe [2004-6-9 471040]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"TabletService"=2 (0x2)
"stllssvr"=3 (0x3)
"gusvc"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=

R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [11/14/2008 6:21 PM 33920]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [11/14/2008 6:10 PM 79904]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\Embarq Online Security 8\HIPS\drivers\fshs.sys [11/14/2008 6:10 PM 66720]
R2 Pervasive.SQL Workgroup Engine;Pervasive.SQL Workgroup Engine;c:\windows\system32\srvany.exe [7/22/2006 10:40 AM 8192]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Embarq Online Security 8\Anti-Virus\minifilter\fsgk.sys [11/14/2008 6:09 PM 99960]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files\Embarq Online Security 8\ORSP Client\fsorsp.exe [11/14/2008 6:10 PM 55904]
S2 BootScreen;BootScreen;c:\windows\system32\drivers\vidstub.sys --> c:\windows\system32\drivers\vidstub.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [11/13/2008 5:49 PM 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [11/13/2008 5:49 PM 8320]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [11/13/2008 5:49 PM 23680]
S3 VirtualDK;VirtualDK;\??\c:\ubcd4win\vdk.sys --> c:\ubcd4win\vdk.sys [?]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Embarq Online Security 8\Anti-Virus\win2k\fsfilter.sys [11/14/2008 6:09 PM 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Embarq Online Security 8\Anti-Virus\win2k\fsrec.sys [11/14/2008 6:09 PM 25184]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12   REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt   REG_MULTI_SZ      hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-07-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-07-21 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-14 03:06]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com/?ctid=CT1978305
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyServer = 127.0.0.1:8100
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Embarq Online Security 8\FSPS\program\fslsp.dll
Trusted Zone: musicmatch.com\online
FF - ProfilePath - c:\documents and settings\\Application Data\Mozilla\Firefox\Profiles\9lqkiec1.Default User\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/accounts/ServiceLogin?continue=http://www.google.com/ig&followup=http://www.google.com/ig&service=ig&passive=true&cd=US&hl=en&nui=1&ltmpl=default
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-20 20:32
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\Æ  3*]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(876)
c:\windows\system32\Ati2evxx.dll
c:\program files\Embarq Online Security 8\FWES\Program\fsdc32.dll

- - - - - - - > 'lsass.exe'(932)
c:\program files\Embarq Online Security 8\FSPS\program\fslsp.dll
c:\program files\Embarq Online Security 8\FWES\Program\fsdc32.dll

- - - - - - - > 'explorer.exe'(5384)
c:\program files\Embarq Online Security 8\Spam Control\fsscoepl.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll

- - - - - - - > 'csrss.exe'(848)
c:\program files\Embarq Online Security 8\FWES\Program\fsdc32.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Embarq Online Security 8\Anti-Virus\fsgk32st.exe
c:\program files\Embarq Online Security 8\Common\FSMA32.EXE
c:\program files\Embarq Online Security 8\Anti-Virus\fsgk32.exe
c:\program files\Embarq Online Security 8\Common\FSMB32.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\pvsw\bin\w3dbsmgr.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Embarq Online Security 8\Common\FCH32.EXE
c:\program files\Embarq Online Security 8\Anti-Virus\fsqh.exe
c:\program files\Embarq Online Security 8\Common\FAMEH32.EXE
c:\program files\Embarq Online Security 8\FSPC\fspc.exe
c:\program files\Embarq Online Security 8\FSAUA\program\fsaua.exe
c:\program files\Embarq Online Security 8\Anti-Virus\fssm32.exe
c:\program files\Embarq Online Security 8\FWES\program\fsdfwd.exe
c:\program files\Embarq Online Security 8\FSAUA\program\fsus.exe
c:\progra~1\EMBARQ~1\ANTI-V~1\fsav32.exe
c:\windows\system32\ati2evxx.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\progra~1\EMBARQ~1\Common\FSM32.EXE
c:\program files\Embarq Online Security 8\FSGUI\fsguidll.exe
c:\program files\Dell Support Center\gs_agent\dsc.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Completion time: 2009-07-21 20:39 - machine was rebooted
ComboFix-quarantined-files.txt  2009-07-21 00:39

Pre-Run: 10,793,132,032 bytes free
Post-Run: 10,828,546,048 bytes free

436   --- E O F ---   2009-07-19 20:13


Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.6.0

; Results at 7/20/2009 8:48:40 PM for strings:
;  'hjgruidmydckil'
; Strings excluded from search:
;  (None)
; Search in:
; Registry Keys  Registry Values  Registry Data 
; HKEY_LOCAL_MACHINE  HKEY_USERS 


; End Of The Log...


Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.6.0

; Results at 7/20/2009 8:44:06 PM for strings:
;  'uacd.sys'
; Strings excluded from search:
;  (None)
; Search in:
; Registry Keys  Registry Values  Registry Data 
; HKEY_LOCAL_MACHINE  HKEY_USERS 


; End Of The Log...Looks like that fixed it.

How is the computer running now?Thank you Mr.EvilFantasy!!! it seems to be doing FINE.  I am having a few other issues but I think that is because I had to replace a system file and NOTHING to do with viruses... all well...thanks again and I will send anyone else with a malware problem your way.... Your welcome.

  • Click START then RUN
  • Now type Combofix /u in the runbox
  • Make sure there's a space between Combofix and /u
  • Then hit Enter.
.
.
The above procedure will:
  • Delete: ComboFix and its associated files and folders.
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Set a new, clean Restore Point.
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - WEB of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

----------

Let me know if anything else comes up.

Safe surfing..,
1485.

Solve : Virus that changes my administrator pass.....and changes my folder to applicatio?

Answer»

Here's my Combo Fix Log..... the Kaspersky Online Scanner is not done yet....

ComboFix 09-07-21.02 - Administrator 07/22/2009 10:06.2.2 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.895.316 [GMT 8:00]
Running from: c:\documents and settings\Administrator.SECURITY-928BF1\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator.SECURITY-928BF1\Desktop\CFScript.txt
AV: G DATA AntiVirus *On-access scanning disabled* (Outdated) {71310606-6F3B-49F2-9A81-8315AA75FBB3}
.

(((((((((((((((((((((((((   Files Created from 2009-06-22 to 2009-07-22  )))))))))))))))))))))))))))))))
.

2099-03-07 06:37 . 2009-07-18 07:59   --------   d-sh--r-   C:\TONYOK GWAPO KUNO '08
2099-03-07 06:35 . 2009-07-18 07:26   --------   d-sh--r-   C:\philhealth
2099-03-07 06:12 . 2099-03-07 06:12   --------   d-----w-   c:\documents and settings\All Users\Application Data\Yahoo!
2099-03-07 06:12 . 2099-03-07 06:12   --------   d-----w-   c:\PROGRAM files\Common Files\Adobe AIR
2099-03-07 06:12 . 2099-03-07 06:12   --------   d-sh--r-   c:\program files\Yahoo!
2099-03-07 06:11 . 2099-03-07 06:11   --------   d-sh--r-   c:\program files\VideoLAN
2099-03-07 06:11 . 2009-07-04 04:31   --------   d-----w-   c:\program files\Common Files\Adobe
2099-03-07 06:11 . 2099-03-07 06:11   --------   d-----w-   c:\documents and settings\All Users\Application Data\CyberLink
2099-03-07 06:10 . 2001-03-08 10:30   24064   ----a-w-   c:\windows\system32\msxml3a.dll
2099-03-07 06:10 . 2099-03-07 06:10   --------   d-sh--r-   c:\program files\CyberLink
2099-03-07 06:10 . 2003-03-18 12:14   499712   ----a-w-   c:\windows\system32\msvcp71.dll
2099-03-07 06:10 . 2003-02-20 20:42   348160   ----a-w-   c:\windows\system32\msvcr71.dll
2099-03-07 06:09 . 2009-07-16 08:50   --------   d-sh--r-   c:\program files\ESET
2099-03-07 00:32 . 2020-09-05 02:33   --------   d-----w-   c:\documents and settings\All Users\Application Data\Microsoft Help

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2099-03-06 09:54 . 2099-03-06 09:54   --------   d-sh--r-   c:\program files\Nero
2099-03-06 09:54 . 2099-03-06 09:54   --------   d-----w-   c:\documents and settings\All Users\Application Data\Nero
2099-03-06 09:49 . 2099-03-06 09:47   --------   d-----w-   c:\program files\SiS VGA Utilities V3.81
2099-03-06 09:49 . 2099-03-06 09:49   --------   d-sh--r-   c:\program files\sisagp
2099-03-06 09:45 . 2099-03-06 09:45   --------   d-sh--r-   c:\program files\Realtek
2099-03-06 09:45 . 2099-03-06 09:45   315392   ----a-w-   c:\windows\HideWin.exe
2009-07-22 02:04 . 2009-03-09 05:45   --------   d-sh--r-   c:\program files\D2D
2009-07-22 00:49 . 2009-07-15 03:17   --------   d-sh--r-   c:\program files\Enigma Software Group
2009-07-22 00:49 . 2009-06-24 01:18   --------   d-sh--r-   c:\program files\RegCure
2009-07-21 10:06 . 2009-07-21 02:02   --------   d-----w-   c:\documents and settings\Administrator.SECURITY-928BF1\Application Data\Skype
2009-07-21 05:24 . 2009-04-14 08:29   --------   d-----w-   c:\documents and settings\All Users\Application Data\Google Updater
2009-07-21 02:04 . 2009-07-21 02:04   --------   d-----w-   c:\documents and settings\Administrator.SECURITY-928BF1\Application Data\skypePM
2009-07-21 01:38 . 2009-07-21 01:38   --------   d-----w-   c:\documents and settings\Administrator.SECURITY-928BF1\Application Data\Apple Computer
2009-07-20 09:24 . 2009-07-20 09:24   70280   ----a-w-   c:\documents and settings\Administrator.SECURITY-928BF1\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-20 04:24 . 2009-07-20 04:24   --------   d-----w-   c:\documents and settings\Administrator.SECURITY-928BF1\Application Data\Morpheus Software
2009-07-18 06:01 . 2009-07-18 06:01   --------   d-sh--r-   c:\program files\Panda USB Vaccine
2009-07-18 02:05 . 2009-07-16 11:44   117760   ----a-w-   c:\documents and settings\Administrator.SECURITY-928BF1\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-16 11:41 . 2009-07-16 11:41   --------   d-----w-   c:\documents and settings\Administrator.SECURITY-928BF1\Application Data\SUPERAntiSpyware.com
2009-07-16 10:50 . 2009-03-14 02:59   --------   d---a-w-   c:\documents and settings\All Users\Application Data\TEMP
2009-07-16 10:45 . 2099-03-06 09:45   --------   d-sh--r-   c:\program files\InstallShield Installation Information
2009-07-16 10:45 . 2009-07-16 10:45   --------   d-sh--r-   c:\program files\LSoft Technologies
2009-07-16 10:19 . 2009-07-16 10:19   --------   d-sh--r-   c:\program files\Nucleus Kernel for FAT and NTFS Demo
2009-07-16 09:44 . 2009-07-16 09:44   --------   d-----w-   c:\documents and settings\Administrator.SECURITY-928BF1\Application Data\Search Settings
2009-07-16 09:42 . 2009-07-16 09:42   --------   d-----w-   c:\documents and settings\Administrator.SECURITY-928BF1\Application Data\Nero
2009-07-16 09:35 . 2009-07-16 08:51   68296   ----a-w-   c:\windows\system32\drivers\GRD.sys
2009-07-16 08:54 . 2009-07-16 08:47   --------   d-----w-   c:\documents and settings\All Users\Application Data\G DATA
2009-07-16 08:47 . 2009-07-16 08:47   50888   ----a-w-   c:\windows\system32\drivers\MiniIcpt.sys
2009-07-16 08:47 . 2009-07-16 08:47   50888   ----a-w-   c:\windows\system32\drivers\GDTdiIcpt.sys
2009-07-16 08:47 . 2009-07-16 08:47   32200   ----a-w-   c:\windows\system32\drivers\HookCentre.sys
2009-07-16 08:46 . 2009-07-16 08:45   --------   d-----w-   c:\program files\Common Files\G DATA
2009-07-16 08:45 . 2009-07-16 08:45   --------   d-sh--r-   c:\program files\G DATA
2009-07-16 06:23 . 2009-07-16 05:36   117760   ----a-w-   c:\documents and settings\a\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-16 05:34 . 2009-07-16 05:34   --------   d-----w-   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-07-16 05:34 . 2009-07-16 05:34   --------   d-sh--r-   c:\program files\SUPERAntiSpyware
2009-07-16 05:34 . 2009-07-16 05:34   --------   d-----w-   c:\documents and settings\a\Application Data\SUPERAntiSpyware.com
2009-07-16 05:34 . 2009-07-16 05:34   --------   d-----w-   c:\program files\Common Files\Wise Installation Wizard
2009-07-16 05:29 . 2009-07-16 05:29   --------   d-sh--r-   c:\program files\CCleaner
2009-07-16 05:13 . 2009-06-24 05:08   24416   ----a-w-   c:\windows\system32\drivers\regguard.sys
2009-07-16 04:58 . 2009-06-24 02:02   --------   d-sh--r-   c:\program files\Spyware Doctor
2009-07-16 04:31 . 2009-07-16 04:31   --------   d-----w-   c:\documents and settings\a\Application Data\Malwarebytes
2009-07-16 04:31 . 2009-07-16 04:31   --------   d-sh--r-   c:\program files\Malwarebytes' Anti-Malware
2009-07-16 04:31 . 2009-07-16 04:31   --------   d-----w-   c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-16 03:28 . 2009-05-13 07:21   --------   d-sh--r-   c:\program files\DBF Viewer 2000
2009-07-16 03:28 . 2009-05-13 06:57   --------   d-sh--r-   c:\program files\DBFView Trial
2009-07-16 03:28 . 2009-06-17 05:01   --------   d-sh--r-   c:\program files\MailList King
2009-07-16 03:26 . 2009-05-19 07:00   --------   d-----w-   c:\program files\Common Files\Intuit
2009-07-15 09:28 . 2009-07-15 09:28   70280   ----a-w-   c:\documents and settings\a\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-15 05:45 . 2009-07-15 05:45   --------   d-----w-   c:\documents and settings\a\Application Data\Search Settings
2009-07-15 05:42 . 2009-03-14 02:58   --------   d-sh--r-   c:\program files\SpeedBitPlus
2009-07-15 05:42 . 2009-07-15 05:42   --------   d-----w-   c:\documents and settings\a\Application Data\Nero
2009-07-15 04:56 . 2009-07-15 04:59   102664   ----a-w-   c:\windows\system32\drivers\tmcomm.sys
2009-07-15 01:55 . 2099-03-06 09:35   24252   ----a-w-   c:\windows\system32\emptyregdb.dat
2009-07-14 05:22 . 2009-07-14 05:22   --------   d-sh--r-   c:\program files\Trend Micro
2009-07-14 04:59 . 2009-07-14 04:57   --------   dc-h--w-   c:\documents and settings\All Users\Application Data\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}
2009-07-14 03:33 . 2009-07-14 03:33   --------   d-sh--r-   c:\program files\Uniblue
2009-07-13 05:36 . 2009-07-16 04:31   38160   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 05:36 . 2009-07-16 04:31   19096   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-07-11 02:27 . 2009-07-11 02:26   95744   ----a-w-   c:\documents and settings\All Users\Application Data\SpeedBit\DAP\Updates\Condition.dll
2009-07-10 02:29 . 2009-03-14 03:22   83456   ----a-w-   c:\documents and settings\All Users\Application Data\SpeedBit\DAP\SDCondition.dll
2009-07-08 01:34 . 2009-07-08 01:34   --------   d-----w-   c:\documents and settings\Guest\Application Data\Search Settings
2009-07-08 01:34 . 2009-07-08 01:34   --------   d-----w-   c:\documents and settings\Guest\Application Data\Dealio
2009-07-06 03:24 . 2009-07-06 03:24   --------   d-sh--r-   c:\program files\Alchemy Mindworks
2009-07-06 01:55 . 2009-07-06 01:55   --------   d-sh--r-   c:\program files\Morpheus Photo Animation Suite
2009-07-04 01:17 . 2009-07-01 09:29   26286   ----a-w-   c:\windows\scunin.dat
2009-07-04 01:17 . 2009-07-01 09:29   967   ----a-w-   c:\windows\ScUnin.pif
2009-07-04 01:17 . 2009-07-01 09:29   94208   ----a-w-   c:\windows\ScUnin.exe
2009-07-02 06:19 . 2009-04-14 08:29   --------   d-sh--r-   c:\program files\Google
2009-06-27 08:54 . 2009-03-17 03:23   14   ----a-w-   c:\windows\popcinfo.dat
2009-06-24 05:09 . 2009-06-24 05:09   34760   ----a-w-   c:\windows\system32\drivers\Partizan.sys
2009-06-24 05:08 . 2009-06-24 05:08   32480   ----a-w-   c:\windows\system32\Partizan.exe
2009-06-24 05:05 . 2009-06-24 05:05   2   --shatr-   c:\windows\winstart.bat
2009-06-24 04:04 . 2099-03-06 09:38   --------   d-sh--r-   c:\program files\microsoft frontpage
2009-06-24 00:34 . 2009-03-14 05:06   --------   d-sh--r-   c:\program files\SpeedBit Video Accelerator
2009-06-16 10:44 . 2009-06-16 10:44   --------   d-sh--r-   c:\program files\Qualcomm
2009-06-15 01:04 . 2009-06-15 01:04   --------   d-----w-   c:\documents and settings\Guest\Application Data\Nero
2009-06-15 01:04 . 2009-06-15 01:04   --------   d-----w-   c:\documents and settings\Guest\Application Data\PC Suite
2009-06-02 01:45 . 2009-06-02 01:45   --------   d-sh--r-   c:\program files\Cheetah Burner
2009-05-28 00:38 . 2009-05-28 00:37   --------   d-sh--r-   c:\program files\iTunes
2009-05-28 00:38 . 2009-05-28 00:37   --------   d-----w-   c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-28 00:38 . 2009-05-28 00:38   --------   d-sh--r-   c:\program files\iPod
2009-05-28 00:37 . 2009-05-28 00:36   --------   d-----w-   c:\documents and settings\All Users\Application Data\Apple Computer
2009-05-28 00:37 . 2009-05-28 00:37   --------   d-----w-   c:\program files\Common Files\Apple
2009-05-28 00:36 . 2009-05-28 00:36   --------   d-sh--r-   c:\program files\Bonjour
2009-05-28 00:36 . 2009-05-28 00:36   --------   d-sh--r-   c:\program files\QuickTime
2009-05-28 00:36 . 2009-05-28 00:36   --------   d-sh--r-   c:\program files\Apple Software Update
2009-05-28 00:36 . 2009-05-28 00:36   --------   d-----w-   c:\documents and settings\All Users\Application Data\Apple
2009-05-27 09:03 . 2009-05-27 09:03   --------   d-sh--r-   c:\program files\ImTOO
2009-05-27 06:31 . 2009-05-27 06:31   --------   d-----w-   c:\program files\Common Files\eSellerate
2009-05-27 06:27 . 2009-05-27 06:27   --------   d-sh--r-   c:\program files\Senuti iPod Rip
2009-05-26 05:24 . 2009-05-26 05:24   --------   d-sh--r-   c:\program files\Xilisoft
2009-02-20 01:43 . 2009-03-07 08:07   134648   ----a-w-   c:\program files\mozilla firefox\components\brwsrcmp.dll
2004-08-03 22:56 . 2004-08-03 22:56   6144   --sha-r-   c:\windows\system32\csrss.exe
.

(((((((((((((((((((((((((((((   [email protected]_01.09.03   )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-22 02:11 . 2009-07-22 02:11   16384              c:\windows\Temp\Perflib_Perfdata_3a8.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{60270dc7-9ea0-472f-9b77-66652c06246e}]
2008-06-03 16:26   1542168   ----a-w-   c:\program files\SpeedBitPlus\tbSpee.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{60270dc7-9ea0-472f-9b77-66652c06246e}"= "c:\program files\SpeedBitPlus\tbSpee.dll" [2008-06-03 1542168]

[HKEY_CLASSES_ROOT\clsid\{60270dc7-9ea0-472f-9b77-66652c06246e}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{60270DC7-9EA0-472F-9B77-66652C06246E}"= "c:\program files\SpeedBitPlus\tbSpee.dll" [2008-06-03 1542168]

[HKEY_CLASSES_ROOT\clsid\{60270dc7-9ea0-472f-9b77-66652c06246e}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-12-17 3810544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-02 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"G DATA AntiVirus Trayapplication"="c:\program files\G DATA\AntiVirus\AVKTray\AVKTray.exe" [2008-09-22 993352]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2007-08-03 1826816]
"SiSPower"="SiSPower.dll" - c:\windows\system32\SiSPower.dll [2007-06-25 53248]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-08-20 16384512]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"Run"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 04:05   356352   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 GRD;G DATA Rootkit Detector Driver;c:\windows\system32\drivers\GRD.sys [7/16/2009 4:51 PM 68296]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944]
R2 AVKProxy;G DATA AntiVirus Proxy;c:\program files\Common Files\G DATA\AVKProxy\AVKProxy.exe [9/22/2008 11:09 AM 650824]
R2 AVKService;G DATA Scheduler;c:\program files\G DATA\AntiVirus\AVK\AVKService.exe [9/22/2008 11:09 AM 386120]
R2 AVKWCtl;AntiVirus Monitor;c:\program files\G DATA\AntiVirus\AVK\AVKWCtl.exe [8/14/2008 8:55 AM 1185496]
R2 GDTdiInterceptor;GDTdiInterceptor;c:\windows\system32\drivers\GDTdiIcpt.sys [7/16/2009 4:47 PM 50888]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~2\VideoAcceleratorService.exe -start -scm --&GT; c:\progra~1\SPEEDB~2\VideoAcceleratorService.exe -start -scm [?]
R3 GDMnIcpt;GDMnIcpt;c:\windows\system32\drivers\MiniIcpt.sys [7/16/2009 4:47 PM 50888]
R3 HookCentre;HookCentre;c:\windows\system32\drivers\HookCentre.sys [7/16/2009 4:47 PM 32200]
S2 gupdate1c9bcdceee47b6;Google Update Service (gupdate1c9bcdceee47b6);c:\program files\Google\Update\GoogleUpdate.exe [4/14/2009 4:36 PM 133104]
S3 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys [6/24/2009 1:09 PM 34760]
S3 RegGuard;RegGuard;c:\windows\system32\drivers\regguard.sys [6/24/2009 1:08 PM 24416]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408]
.
Contents of the 'Scheduled Tasks' folder

2009-07-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 04:34]

2009-07-22 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-14 08:29]

2009-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-14 08:35]

2009-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-14 08:35]

2009-07-22 c:\windows\Tasks\PandaUSBVaccine.job
- c:\program files\Panda USB Vaccine\RunInteractiveWin.exe [2009-07-18 04:30]
.
.
------- Supplementary Scan -------
.
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrator.SECURITY-928BF1\Application Data\Mozilla\Firefox\Profiles\k7dhg610.default\
FF - prefs.js: browser.search.selectedEngine - Searchme
FF - component: c:\program files\Mozilla Firefox\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170633FE}\components\AvkWebFilterFF.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[email protected]\components\Shim.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[email protected]\components\SearchSettingsFF.dll
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-22 10:11
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(692)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(1036)
c:\program files\Microsoft Office\OFFICE11\msohev.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Panda USB Vaccine\USBVaccine.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\progra~1\SPEEDB~2\VideoAcceleratorService.exe
c:\progra~1\SPEEDB~2\VideoAcceleratorEngine.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-22 10:13 - machine was rebooted
ComboFix-quarantined-files.txt  2009-07-22 02:13
ComboFix2.txt  2009-07-22 01:11

Pre-Run: 6,467,457,024 bytes free
Post-Run: 6,453,354,496 bytes free

Current=2 Default=2 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
249


I'll just post the Kaspersky Log when its done scanning my computer....
Ok, here's my Kaspersky Log....

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
 Wednesday, July 22, 2009
 Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
 Kaspersky Online Scanner  version: 7.0.26.13
 Program database last update: Wednesday, July 22, 2009 05:51:12
 Records in database: 2510764
--------------------------------------------------------------------------------

Scan settings:
   Scan using the following database: extended
   Scan archives: yes
   Scan mail databases: yes

Scan area - My Computer:
   A:\
   C:\
   D:\
   E:\

Scan statistics:
   Files scanned: 57344
   Threat name: 3
   Infected objects: 372
   Suspicious objects: 0
   Duration of the scan: 03:35:28


File name / Threat name / Threats count
C:\Documents and Settings\Administrator.SECURITY-928BF1\Desktop\Recovered Files\Back-up D2D Loan\Pag-IBIG LOANS.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\Desktop\Recovered Files\Back-up Database\SENTINEL SECURITY5162009.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\Desktop\Recovered Files\Claire\converted movies.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\Desktop\Recovered Files\Claire\ddo revised.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\Desktop\Recovered Files\Claire\Pictures.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\Desktop\Recovered Files\Claire\scandal.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\$hf_mig$.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\$MSI31Uninstall_KB893803v2$.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\$NtUninstallKB888111WXPSP2$.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\0525.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\45004b0a61070e440a2d792392c2.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\a.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Active Data Recovery Software.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\addins.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Administrator.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Adobe.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\After Image.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Ahead.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Alchemy Mindworks.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Alchemy.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Alcohol 120%.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Alcohol Soft.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\All User0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\All Users.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\ambethia-smtp-tls-7d62b44411d8e8d662a7df302ea10ade7ab3287c.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Apple Software Update.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\AppPatch.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\AUTHORIZATION.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Avenger.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\BACK-BILLING COLLECTION.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Back-up D2D Loan.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Back-up D2D Premium.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Back-up Database.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Back-up Philhealth.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\BACK-UP.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\bamboo.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Billing Codes.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Billing-Collection Back-up.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Billing-Collection Summary FORMAT.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\BILLING-FP.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\BIR 2316 forms.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\BIR Documents.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\BIR Remittances.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\BIRALPHA0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\BIRALPHA3.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\BITMAPS.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\BITMAPS0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Bonjour.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Bookworm Adventures Deluxe.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\BookWorm Adventures From GameHouse & Keygen.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Borland.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Caesar3.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\CCleaner.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Certification-Philhealth.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Certification.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\characters.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Cheetah Burner.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\cherish.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\CHEVRON GUARDS.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\CHRISTMAS SONG.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Claire.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\cmd.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Common Files.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\ComPlus Applications.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Conduit.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Config.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Connection Wizard.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Contacts.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Converted Data Base.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Converted Database.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\converted movies.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\creed.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\cruisin'.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Crystal.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\csrss.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Cursors.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\CyberLin0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\CyberLink.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\D2D.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\D2D____0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\D2D____1.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\DAP.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\DATA.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\data0000.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\data0001.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Database.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\DataLink.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\DATA___0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\DATA___1.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\DATA___2.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\DATA___3.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Data___4.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\DBF Converter.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\DBF Converters Shell.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\DBF to XLS.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\DBF Viewer 2000.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\DBFView Trial.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\ddo revised.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\DDO.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Dealio Toolbar.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Debug.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Decompiled.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Default User.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\DIFX.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Documents and Settings.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Documents.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\domain.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\DOMAIN.EXE.del   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\domain_0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Downloaded Program Files.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Downloads.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Driver Cache.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\eAlpha.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\eAlpha_0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\ehome.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Emulator.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Enigma Software Group.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Error.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Error__0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\ESET.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\EXTRACT HER0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\EXTRACT HERE.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\FILES.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Fix.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Fonts.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\forms.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\from Jonas I-pod.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\G DATA.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Gameboy Advance.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\GameHous0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\GameHouse.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Google.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Guest.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\help.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\help___0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Help___1.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\HP.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Icons.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Icons__0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\ime.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\ImTOO.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Income Statement.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\index_files.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\inf.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Installer.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\InstallShield Installation Information.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\InstallShield.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Internet Explorer.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Intuit.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Intuit_0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\iostrea0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\iostrea1.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\iostream.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\iPod.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\ips.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\iTunes.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Java.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\java___0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\LastGood.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\LEDGERS.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\LEERZ.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\LIBS.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\LIBS___0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\LimeWir0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\LimeWire.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\lmstdxp.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\LocalService.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Logs.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Logs___0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Logs___1.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\LSoft Technologies.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\MailList King.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Malwarebytes' Anti-Malware.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\maps.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\MDB to DBF.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Media.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\MENUS.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\MENUS__0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Messenger.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Microsoft ActiveSync.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\microsoft frontpage.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Microsoft Office.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Microsoft Visual Studio.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Microsoft Works.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Minidump.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Misc.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Morpheus Photo Animation Suite.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Morpheus.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\MountPointManagerRemoteDatabase.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Movie Maker.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Mozilla Firefox.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\msagent.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\msapps.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\MSN Gaming Zone.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\MSN.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\MSOCache.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\mui.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\My Animation Workshop Documents.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\My Completed Downloads.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\My documents.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\My Installations.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\My Musi0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\My Musi1.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\My Music.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\My Picture0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\My Picture1.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\My Pictures.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\My Videos.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Nero.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\NeroVision.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Nes Emulator.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\NetMeeting.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\NetworkService.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\New Databas0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\New Database.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\NEW Payroll.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Nintendo DS.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Nokia.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\NovaLogic.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\ntldr.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Nucleus Kernel for FAT and NTFS Demo.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Offline Web Pages.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\oLd payroll '08.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Online Services.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Outlook Express.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Overtime.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Pag-IBIG LOANS.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Pag-ibig-Monthly.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Panda USB Vaccine.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Passware.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\PAYROLL.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\PC Connectivity Solution.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\pchealth.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\PeerNet.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\PER30S.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\PER30S_0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\PH Database.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\PHILHEALT0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\philhealt1.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\philhealt2.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\PhilHealth Program.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\PhilHealth-Monthl0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\PhilHealth-Monthly.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Philhealth-remittanc0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Philhealth-remittance.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\philhealth.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\PICTURE & LETTER.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Pictures.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\PIF.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\PPRS2.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\PPRS2__0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\PPRS2__1.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\PPRS2__2.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\PREDATA.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\PREDATA0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Prefetch.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Program Files.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Project Profile.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Provisioning.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Qualcomm.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\QuickTime.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\RA2.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\RealArcade.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Realtek.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\reanimitor.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\RECYCLE0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\RECYCLE1.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\RECYCLER.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\RegCure.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\RegisteredPackages.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Registration.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\registry cure.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\RegRun2.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\RegRun20.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\repair.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Report Formats.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\REPORTS.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\REPORTS0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Reports1.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Requests.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Resources.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Ron.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Ronald.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\S-1-5-21-1177238915-1275210071-725345543-1000.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\S-1-5-21-1177238915-1275210071-725345543-1006.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\S-1-5-21-1177238915-1275210071-725345543-1007.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\S-1-5-21-1177238915-1275210071-725345543-1008.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\S-1-5-21-1177238915-1275210071-725345543-500.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\S-1-5-21-1177238915-1275210071-725345543-501.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\S-1-5-21-1177238915-1275210071-725345543-502.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Sage Software.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\samples.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\save.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\save___0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\scandal.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\screenshots.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\scripts.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\SEC accredited auditors.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\security.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\securityagenc0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\securityagency.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Sentinel Billing-Collectio0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Sentinel Billing-Collection.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\SENTINEL SECURITY5162009.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Senuti iPod Rip.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\ShellNew.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Sierra On-Line.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\SIERRA.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\SIS.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\sisagp.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Skype.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\SMRTNTKY.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\SOC - REPORTS.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\SoftwareDistribution.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\solcache.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\SpeedBit Video Accelerator.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\SpeedBitPlus.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Spyware Doctor.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\srchasst.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\SSS LOAN.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\SSS PREMIUM AND LOAN.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\SSS.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Starcraft.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\states.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\SUMMARY REPORTS 2008.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\SUMMARY REPORTS 2009.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Sun.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\SUPERAntiSpyware.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\System Volume Informatio0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\System Volume Information.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\system.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\System_0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\system~0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Tasks.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Temp.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Template0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Templates.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Temp___0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\ToGo Game.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\TONYO COLLECTION REPORT.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\TONYOK GWAPO KUNO '08.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Trend Micro.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Tutil32.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Tutil320.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\twain_32.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Uniblue.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Uninstall Information.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\update.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Utherverse Digital Inc.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\VideoLAN.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Web Publish.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Web.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Windows Media Player.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Windows NT.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\WindowsUpdate.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\WinRAR.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\WinSxS.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\X-Files.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\X-Files0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\X-Files1.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\xerox.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Xilisoft Corporation.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Xilisoft.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\Yahoo!.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\YouTube Downloader.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\_resto~1.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\ñiäw.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Administrator.SECURITY-928BF1\DoctorWeb\Quarantine\ñiäw___0.exe   Infected: Worm.Win32.Agent.uw   1
C:\Documents and Settings\Guest\Desktop\ophcrack-win32-installer-3.3.0.exe   Infected: not-a-virus:PSWTool.Win32.PWDump.at   1
C:\Documents and Settings\Guest\Desktop\ophcrack-win32-installer-3.3.0.exe   Infected: not-a-virus:PSWTool.Win32.PWDump.ar   1
C:\Documents and Settings\Guest\Local Settings\Application Data\Mozilla\Firefox\Profiles\jpqidczh.default\Cache\1FE7AB4Dd01   Infected: not-a-virus:PSWTool.Win32.PWDump.at   1
C:\Documents and Settings\Guest\Local Settings\Application Data\Mozilla\Firefox\Profiles\jpqidczh.default\Cache\1FE7AB4Dd01   Infected: not-a-virus:PSWTool.Win32.PWDump.ar   1

The selected area was scanned.



As of the moment, my computer is running satisfactorily.... no more administrator pass change...... but my file folders are gone....... i think they are being quarantined by Dr. Web Cure It!..
....... my internet connection is quite sluggish
....... folder options on control panel is gone

I just have one question, can we retrieve those files and folders at the quarantine after the infections are compromised?

that's all... and thank you very much for your help at this problem.... Your Recovered Files are all infected as well as what Dr Web quarantined. Recovering them will just reinfect the computer. At this point your BEST option is to reformat and reinstall. Further cleaning will just make the computer more unstable.
So reformatting is the only option to totally get rid of the infections......
I have recovered some of my infected files, and burn it on CD & DVD..... does it mean that the files i have burned are all infected? If i COPY it to my new formatted drives, would the infection also transfer from my disk to the drives? any suggestion on how to prevent this infections on transferring to my newly formatted drive?

Currently, im using G Data Antivirus but its only a trial, it is not updated.  Any suggestion on an effective AV which can block this infections from transferring?

Anyway, thank you very much for your efforts and time on solving this case.......
Im very grateful for all of your help.....One area that is infected is here. C:\Documents and Settings\Administrator.SECURITY-928BF1\Desktop\Recovered Files

If those are what you backed up to the CD then they are infected. Is this what you backed up to CD?

Quote

Currently, im using G Data Antivirus but its only a trial, it is not updated.

You need to get a good updated antivirus installed ASAP.

Download one of these to the desktop but before installing it uninstall G Data, restart the computer and then install the new one before going online.

Remember to only install one antivirus!
 
1) Avast! Home Free Edition
2) AVG Free Edition
3) Avira AntiVir Personal

Then run a full scan with the new antivirus. You can place your backup CD in the drive and let it be scanned also.

Let me know how that goes.
1486.

Solve : An unhandled win32 exception has occurred in xxx.exe?

Answer» THANK you once again EVILFANTASY!

REGARDS,

FRIDAY
1487.

Solve : This is not a bump but I'm not sure what else to do...?

Answer»

I posted my logs on July 18 under the "Need HELP with malware" thread. I also read evilfantasy's post stating that we should not bump and that help would be given starting from the oldest posts to the newest, so I have not posted again. But I am seeing others receiving direction that have posted more recently. I'm wondering if maybe my thread has been forgotten since it has lapsed to page 2.

Please know I mean no offense - I am so appreciative of what you are doing here for people and the time it takes to do it. I'm only posting because I'm not sure if I've been forgotten or just need to continue being patient; and my computer is still in need of your technical expertise to SET it free from the bondage of malware wrecking havoc on its internal functions.

IF you are GOING to bump a post actually bump the thread itself, making a new thread won't help us find your original thread  SORRY - that was part of the dilemma. Since bumping would put the original post back at the bottom of the list in terms of who's up NEXT, I wasn't sure if that was what should be done.You will get more sympathy bumping an existing thread than starting a new thread.

Depending on the age of the original thread anyway.  If it's older than three days I would bump it.  That will probably make evil hate me, *censored*.

1488.

Solve : Blue screen appeared need help, slow computer?

Answer»

Hi All,

I am a new member and i am not a pro on a computer, here is the list of problems I am experiencing with the computer   windows xp... ( I have a current norton antivirus subscription and I have the service pack 3 also) ... I use internet explorer version 8
My computer starts up slow, only shows desktop items and MENU bar at the bottom only after SEVERAL minutes, when I am surfing the net, computer sometimes becomes unresponsive and then i must close open programs and then normal activity can resume, when I look at the task manager i see that I have two iexplore.exe running only when I run it though but one of them uses in excess of 100 mb
I downloaded hijack this and here is the log below........ I also expereinced a blue screen and had to restart the computer in safe mode......
If someone can help it would be great ......... here is the log

Logfile of TREND Micro HijackThis v2.0.2
Scan SAVED at 09:55:46, on 24/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Dell\MFP_DELL\deMntrService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\ADOBE\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\O2\O2 Broadband USB Modem\O2 Broadband\O2 Broadband.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.euro.dell.com/
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [ScanSoft OmniPage SE 4-reminder] "C:\Program Files\ScanSoft\OmniPageSE4\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\OmniPageSE4.0\Ereg\Ereg.ini
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe"  /autorun
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [DeStatusMon] "C:\Program Files\Dell\MFP_DELL\deDvcStatus.exe" dvcStatusMinimize
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.eircom.net
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Monopoly\Images\stg_drm.ocx
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file://C:\Program Files\Monopoly\Images\armhelper.ocx
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F52CDF4B-1D96-4AEF-B847-EDBB9706EFA7}: NameServer = 62.40.32.33 62.40.32.34
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Dell AIO Center Service (deMntrService) - Dell - C:\Program Files\Dell\MFP_DELL\deMntrService.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O24 - Desktop Component 0: (no name) - http://paddypowerpoker.com/pokerhands/images/grdnt_bg.jpg

--
End of file - 10562 bytes

1489.

Solve : Data Execution Prevention Issue?

Answer»

Gateway 7330Gz LAPTOP
Windows XP Home, Version 2002, SP 3
3.06 GHz, 3.06 GHz, 480 MB of RAM

Yesterday, I inserted a new SD card into my internal card reader, and my problem started shortly after.
The SD card had been used by my Wife with her laptop just fine before, this was just the first time I'd tried it.
First off, the SD card and the drive it was in didn't show up in Explorer, nor did the AutoPlay prompt load.
It did show in the Device Manager though.
I tried to Safely Remove Hardware when it became clear it wasn't working properly (8G card, I'd read SOMEWHERE certain computers couldn't deal with SD cards over 1G...thought maybe that was the case with mine), but it froze up and I had to just TAKE out the card...

I decided to reboot and give it another try, and upon reboot I received a Data Execution Prevention message.
Later, when I got home, I tried the SD card in my Wife's laptop...it of course worked fine like it had before on her computer, BUT when she rebooted, she received the same Data Execution Prevision message, and upon investigation, it is flagging the same files as mine was...

I've ran full scans with fully updated AVG, SAS, and MBAM, and although suspected/known items were removed with SAS and MBAM, upon reboot the problem was still there.
I reran AVG, SAS, and MBAM, and got clean results for all.
I updated my Windows online to SP 3.5 I believe, that didn't fix anything.
I've checked and compared HJT logs...nothing that jumps out at me.

When I click the Data Execution message, it opens the Send Error Report box, if I send it, or if I don't, upon close of the Error Report message, the Data Execution message pops up again; this is a cycle that just CONTINUES....during this I see a process in Task Manager, rundll32.exe, load and then dissappear, load and then dissappear, etc.  I've checked the location of rundll32.exe, and it is in the Windows32 folder that it should be in, so I don't think this is the problem...but am not sure...

I've attached all the Logs I think I should attach, including the Manifest and information from the Data Execution/Error Report.

Hoping I can get this figured out and then fix my Wife's laptop also.

Thank you in advance for the help!




[attachment deleted by admin]

1490.

Solve : Spotty Face of Avira Mascot!??

Answer»

Hi Geeks!

IM a BIG FAN of 'Avira Antivir', but WONDER that which Browser's window it opens up to display 'Notifier' during its updation?This Notifier tries to entice the users to opt for the Premium version(The PAID one!).

Secondly, has anyone ever observed the 'Secret' behind the SPOTTY Face of Avira Mascot?!

Is the glimpse intend to shoo away or lure the users to buy the Premium product?

Check out the 'Complimentary Screenshot'!

[attachment DELETED by admin]How to: Disable the Avira AntiVir avnotify & splash screenThanks a lot Evil!

I unnecessarily tried to brag a point!

I simply couldn't ask the things in a simple way...??! One of the few splash screens I probably would not disable.   I don't know. that's a spotty claim, at best.

maybe if she was nekkid, or in a lude pose. but if she's just going to smile menacingly while forcing US to use our imaginations, well, I don't think that's very nice at all.  Thank you evilfantasy, I hate that splash screen

1491.

Solve : needing help with uacd.sys trojan?

Answer»

Hi there , looks like i just got a nasty virus......... downloaded combofix and got a report.

ComboFix 09-07-23.04 - Robert 24/07/2009 18:01.1.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic   6.0.6001.1.1252.2.1033.18.1279.630 [GMT -4:00]
Running from: c:\USERS\Robert\Desktop\Combo-Fix.exe
SP: MalwareRemovalBot *enabled* (Updated) {D4EAEECB-3C46-498D-9317-ADD33A6A381B}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-2966507171-1947029991-789456440-1002
c:\progra~2\Microsoft\Network\Downloader\qmgr0.dat
c:\progra~2\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\INSTALL.LOG
c:\temp\1cb
c:\users\Lisa\Lisa.exe
c:\windows\system32\d1
c:\windows\system32\drivers\UACtjdrjxqjso.sys
c:\windows\system32\FhgQAGgh.ini
c:\windows\system32\UACeuytyutuas.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACneegwpcfow.dll
c:\windows\system32\UACnxmiqeixic.dll
c:\windows\system32\UACoipotetais.dll
c:\windows\system32\UACqhvbecgpbe.dat
c:\windows\system32\UACrdfpdayajr.dll
c:\windows\system32\UACuycqowxpfh.db

----- BITS: Possible infected sites -----

hxxp://updates.swarmcast.net
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_UACd.sys
-------\Service_iWinGamesInstaller


(((((((((((((((((((((((((   Files Created from 2009-06-24 to 2009-07-24  )))))))))))))))))))))))))))))))
.

2009-07-24 22:13 . 2009-07-24 22:16   --------   d-----w-   c:\users\Robert\AppData\Local\temp
2009-07-24 22:13 . 2009-07-24 22:13   --------   d-----w-   c:\users\Lisa\AppData\Local\temp
2009-07-23 20:13 . 2009-07-23 20:13   6247   ----a-w-   c:\windows\system32\uacinit.dll.vir
2009-07-23 02:01 . 2009-07-23 02:01   --------   d-----w-   c:\program files\Macrovision Corporation
2009-07-23 01:53 . 2009-07-23 07:55   --------   d-----w-   c:\progra~2\SITEguard
2009-07-23 01:52 . 2009-07-23 19:51   --------   d-----w-   c:\progra~2\STOPzilla!
2009-07-23 01:52 . 2009-07-23 01:52   --------   d-----w-   c:\program files\Common Files\iS3
2009-07-23 01:00 . 2009-07-23 01:29   --------   d-----w-   c:\users\Robert\AppData\Roaming\MalwareRemovalBot
2009-07-23 01:00 . 2009-07-23 01:36   --------   d-----w-   c:\program files\MalwareRemovalBot
2009-07-22 14:03 . 2009-07-22 14:03   262   ----a-w-   c:\users\Lisa\YWJTGJ.bat
2009-07-22 14:03 . 2009-07-22 14:03   196608   ----a-w-   c:\users\Lisa\hiupol.exe
2009-07-19 15:40 . 2009-07-19 15:59   --------   d-----w-   c:\users\Robert\AppData\Local\WMTools Downloaded Files
2009-07-19 15:39 . 2009-07-19 15:40   --------   d-----w-   c:\program files\Movie MAKER 2.6
2009-07-14 17:33 . 2009-06-15 15:24   156672   ----a-w-   c:\windows\system32\t2embed.dll
2009-07-14 17:33 . 2009-06-15 15:20   72704   ----a-w-   c:\windows\system32\fontsub.dll
2009-07-14 17:33 . 2009-06-15 15:20   10240   ----a-w-   c:\windows\system32\dciman32.dll
2009-07-14 17:33 . 2009-06-15 12:52   289792   ----a-w-   c:\windows\system32\atmfd.dll
2009-07-12 17:02 . 2009-07-12 17:02   200704   ----a-w-   c:\users\Lisa\AppData\Roaming\Microsoft\Windows\.autobahn\libwin32sparsefileutil.dll
2009-07-12 17:02 . 2009-07-12 17:02   65536   ----a-w-   c:\users\Lisa\AppData\Roaming\Microsoft\Windows\.autobahn\libwin32proxyconfig.dll
2009-07-12 17:02 . 2009-07-12 17:02   --------   d-----w-   c:\users\Lisa\AppData\Local\Autobahn
2009-07-12 17:02 . 2009-07-12 17:02   --------   d-----w-   c:\users\Lisa\Swarmcast
2009-07-08 18:34 . 2007-12-26 21:30   679936   ----a-w-   c:\windows\system32\D3DX81ab.dll
2009-07-08 18:34 . 2007-12-26 21:30   1970176   ----a-w-   c:\windows\system32\d3dx9.dll
2009-07-08 18:34 . 2009-07-23 20:55   --------   d-----w-   c:\program files\Cheat ENGINE

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-24 22:00 . 2007-07-25 23:12   --------   d-----w-   c:\program files\Google
2009-07-23 20:12 . 2007-11-01 20:42   --------   d-----w-   c:\program files\Trojan Remover
2009-07-23 20:12 . 2007-11-01 20:35   --------   d-----w-   c:\users\Robert\AppData\Roaming\Simply Super Software
2009-07-23 19:11 . 2009-07-23 02:05   960   ----a-w-   c:\windows\system32\drivers\kgpcpy.cfg
2009-07-23 04:57 . 2009-07-23 04:57   304   ----a-w-   c:\windows\system32\drivers\kgpfr2.cfg
2009-07-23 02:17 . 2008-01-05 13:36   --------   d-----w-   c:\program files\Spybot - Search & Destroy
2009-07-23 02:01 . 2008-07-02 21:34   --------   d-----w-   c:\users\Robert\AppData\Roaming\InstallShield
2009-07-23 00:38 . 2009-03-21 15:44   --------   d-----w-   c:\program files\Microsoft Silverlight
2009-07-23 00:36 . 2008-07-02 21:28   --------   d-----w-   c:\progra~2\Bell
2009-07-23 00:36 . 2008-07-02 23:52   --------   d-----w-   c:\users\Lisa\AppData\Roaming\Bell
2009-07-23 00:36 . 2008-07-02 21:28   --------   d-----w-   c:\users\Robert\AppData\Roaming\Bell
2009-07-23 00:36 . 2008-07-02 21:28   --------   d-----w-   c:\program files\Bell
2009-07-22 18:15 . 2007-07-25 21:46   --------   d-----w-   c:\program files\BadgeHelp
2009-07-20 15:01 . 2009-05-19 00:37   --------   d-----w-   c:\users\Lisa\AppData\Roaming\FrostWire
2009-07-14 19:05 . 2006-11-02 11:18   --------   d-----w-   c:\program files\Windows Mail
2009-07-13 23:11 . 2008-04-23 20:41   --------   d-----w-   c:\users\Robert\AppData\Roaming\Image Zone Express
2009-06-26 00:35 . 2007-12-22 00:33   --------   d-----w-   c:\progra~2\PopCap Games
2009-06-26 00:35 . 2007-12-22 00:33   --------   d-----w-   c:\program files\PopCap Games
2009-06-18 11:20 . 2007-07-25 07:58   --------   d-----w-   c:\users\Lisa\AppData\Roaming\LimeWire
2009-06-17 23:57 . 2007-07-25 02:16   --------   d-----w-   c:\progra~2\Yahoo!
2009-06-17 23:50 . 2007-07-25 09:46   --------   d-----w-   c:\users\Robert\AppData\Roaming\yahoo!
2009-06-17 23:50 . 2007-07-25 01:02   --------   d-----w-   c:\program files\Yahoo!
2009-06-03 21:42 . 2009-05-14 23:42   --------   d-----w-   c:\users\Robert\AppData\Roaming\FrostWire
2009-05-27 22:15 . 2008-12-16 11:37   --------   d-----w-   c:\program files\iWin Games
2009-05-27 20:42 . 2008-01-05 13:36   --------   d-----w-   c:\progra~2\Spybot - Search & Destroy
2009-05-19 10:00 . 2009-05-19 10:00   0   ----a-w-   c:\users\Lisa\AppData\Roaming\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
2009-05-14 23:51 . 2009-05-14 23:51   0   ----a-w-   c:\users\Robert\AppData\Roaming\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
2009-05-09 05:50 . 2009-06-11 19:32   915456   ----a-w-   c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-11 19:32   71680   ----a-w-   c:\windows\system32\iesetup.dll
2009-07-15 20:30 . 2008-09-23 14:35   137208   ----a-w-   c:\program files\mozilla firefox\components\brwsrcmp.dll
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"?r"="" [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer5"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Desktop Manager.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Desktop Manager.lnk
backup=c:\windows\pss\Desktop Manager.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk
backup=c:\windows\pss\Empowering Technology Launcher.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Lisa^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^DW_Start.lnk]
path=c:\users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DW_Start.lnk
backup=c:\windows\pss\DW_Start.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^Lisa^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^iWin Desktop Alerts.lnk]
path=c:\users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iWin Desktop Alerts.lnk
backup=c:\windows\pss\iWin Desktop Alerts.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiSpywareOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{7F93DF26-6D19-4F48-804C-3C5CBC2B2B65}"= UDP:c:\acer\Empowering Technology\eMode\PCM\PCMService.exe:CyberLink PowerCinema Resident Program
"{BDC03457-3E19-4BC0-9E2E-46097CBB3128}"= TCP:c:\acer\Empowering Technology\eMode\PCM\PCMService.exe:CyberLink PowerCinema Resident Program
"{DB1C8E0D-6ECC-4E34-A574-80B5B4287F69}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{E65D93F9-26A7-4493-8000-BC27E0CA38C9}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{10CF1C0D-FEFA-4E13-A609-BBD99BE276DD}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{8B5558FA-0263-4F93-8FCF-BCE9F4E5B300}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{988ABD83-E64D-4734-BED4-88DC83B9C616}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{B35C1E9D-E803-4422-9786-308CE7A23CE5}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{E8F1DBDD-D143-4372-AA29-6E84639F23C6}f:\\program files\\pogo games\\ricochet lost worlds to go\\ricochet.exe"= UDP:f:\program files\pogo games\ricochet lost worlds to go\ricochet.exe:Ricochet
"UDP Query User{9E84EF5D-68E3-4FA0-84C1-77E26C20B7C9}f:\\program files\\pogo games\\ricochet lost worlds to go\\ricochet.exe"= TCP:f:\program files\pogo games\ricochet lost worlds to go\ricochet.exe:Ricochet
"TCP Query User{4D2F9970-7FD9-4E2F-A1E8-C7A350B0B895}f:\\program files\\zone.com deluxe games\\hexic deluxe\\hexicdeluxe.exe"= UDP:f:\program files\zone.com deluxe games\hexic deluxe\hexicdeluxe.exe:Hexic Deluxe
"UDP Query User{CD11E0B7-F215-439E-8378-0CFCE8DFB7CA}f:\\program files\\zone.com deluxe games\\hexic deluxe\\hexicdeluxe.exe"= TCP:f:\program files\zone.com deluxe games\hexic deluxe\hexicdeluxe.exe:Hexic Deluxe
"TCP Query User{B270BCB0-202B-4D33-946E-983639919DC0}c:\\users\\dan\\desktop\\mirc\\mirc.exe"= UDP:c:\users\dan\desktop\mirc\mirc.exe:mirc.exe
"UDP Query User{AC8A6737-8458-43DB-BD05-38FA8465ADF6}c:\\users\\dan\\desktop\\mirc\\mirc.exe"= TCP:c:\users\dan\desktop\mirc\mirc.exe:mirc.exe
"TCP Query User{4355B497-F6A6-43FA-8F28-4D7EEB261ACF}c:\\users\\robert\\desktop\\utorrent.exe"= UDP:c:\users\robert\desktop\utorrent.exe:utorrent.exe
"UDP Query User{EEFB1F6F-082D-4E25-8DC3-B53BF8E650CD}c:\\users\\robert\\desktop\\utorrent.exe"= TCP:c:\users\robert\desktop\utorrent.exe:utorrent.exe
"TCP Query User{4CCBBBD4-A691-44AF-BD3D-1B43A40C1CE3}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{1AF16DFB-FFFF-4130-AE60-0932B5D2A3BE}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{2C704A67-A81E-4A95-BD6C-01A060F5F434}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{E6001E11-7872-4746-98DA-621612DBD9A6}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"TCP Query User{8186460D-5A8E-48A0-9859-2845ADC13761}f:\\program files\\gamehouse\\ricochet\\ricochet.exe"= UDP:f:\program files\gamehouse\ricochet\ricochet.exe:Ricochet
"UDP Query User{AB3AEEAE-16D1-4869-B088-3C5BC58D7188}f:\\program files\\gamehouse\\ricochet\\ricochet.exe"= TCP:f:\program files\gamehouse\ricochet\ricochet.exe:Ricochet
"{3D74FD8A-CF51-4C86-87F7-DFB8FA3E0C71}"= UDP:F:3\Vent\Ventrilo.exe:Ventrilo.exe
"{2BA35272-C693-4597-9128-12C9CF48FF59}"= TCP:F:3\Vent\Ventrilo.exe:Ventrilo.exe
"{EE2A1038-8758-4743-AB52-6C630F6F801F}"= UDP:c:\program files\iWin Games\iWinGames.exe:iWin Games application.
"{D5B8586E-64B5-4633-8A87-3D0993E0E285}"= TCP:c:\program files\iWin Games\iWinGames.exe:iWin Games application.
"{7295CA47-8052-42E4-A3EC-759707D5B313}"= UDP:c:\program files\iWin Games\WebUpdater.exe:iWin Games updater.
"{3085F41E-83B6-4B30-BF68-3ED78474B158}"= TCP:c:\program files\iWin Games\WebUpdater.exe:iWin Games updater.
"{6F207A0F-186A-42A1-B9B2-A7340B52E220}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"TCP Query User{FF855656-C270-4DB7-A4A2-D1EFDC20F0EA}c:\\program files\\frostwire\\frostwire.exe"= UDP:c:\program files\frostwire\frostwire.exe:FrostWire
"UDP Query User{07C3C17E-EA08-4F78-A45E-BC31319C356F}c:\\program files\\frostwire\\frostwire.exe"= TCP:c:\program files\frostwire\frostwire.exe:FrostWire

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)

R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [05/01/2008 9:36 AM 1153368]
R3 LTXMD_VAC;Litex Media Virtual Audio Cabel (WDM);c:\windows\System32\drivers\lmvac.sys [01/03/2008 10:37 AM 17920]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [21/03/2009 11:43 AM 55280]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 6:08 PM 533360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork   REG_MULTI_SZ      PLA DPS BFE mpssvc
HPZ12   REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt   REG_MULTI_SZ      hpqcxs08 hpqddsvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Acer Tour - (no file)
HKLM-Run-eRecoveryService - (no file)


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://en.ca.acer.yahoo.com
uSearchURL,(Default) = hxxp://ca.rd.yahoo.com/customize/ycomp/defaults/su/*http://ca.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Post Image to Blog - c:\program files\ImageShackToolbar\ImageShackToolbar.dll/5003
IE: Tag This Image - c:\program files\ImageShackToolbar\ImageShackToolbar.dll/5002
IE: Transload Image to ImageShack - c:\program files\ImageShackToolbar\ImageShackToolbar.dll/5004
IE: UPLOAD All Images to ImageShack - c:\program files\ImageShackToolbar\ImageShackToolbar.dll/5000
IE: Upload Image to ImageShack - c:\program files\ImageShackToolbar\ImageShackToolbar.dll/5001
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
DPF: {983A9C21-8207-4B58-BBB8-0EBC3D7C5505} - hxxp://student.sl.on.ca/dwa8W.cab
FF - ProfilePath - c:\users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\04qtubxv.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.pogo.com/home/home.do
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota",      5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default _setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history",     true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata",    true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords",   false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads",   true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies",     true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache",       true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions",    true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history",                 true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata",                true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords",               false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads",               true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies",                 true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache",                   true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions",                true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps",             false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings",            false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs",    false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_pa ge", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_ enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-24 18:16
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
Denied: (A) (Users)
Denied: (A) (Everyone)
Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
Denied: (A) (Users)
Denied: (A) (Everyone)
Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
Denied: (A) (Users)
Denied: (A) (Everyone)
Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
Denied: (A) (Users)
Denied: (A) (Everyone)
Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
Denied: (A) (Users)
Denied: (A) (Everyone)
Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(6496)
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\acer\Empowering Technology\ePerformance\MemCheck.exe
c:\program files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
c:\acer\Empowering Technology\eMode\PCM\Kernel\TV\CLCapSvc.exe
c:\acer\Empowering Technology\eDataSecurity\eDSService.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\acer\Empowering Technology\eMode\PCM\Kernel\TV\CLSched.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2009-07-24 18:27 - machine was rebooted
ComboFix-quarantined-files.txt  2009-07-24 22:26

Pre-Run: 20,455,661,568 bytes free
Post-Run: 20,324,003,840 bytes free

324   --- E O F ---   2009-07-22 07:01

1492.

Solve : trojans in itunes?

Answer»

Hi can you HELP SEEN this POST in forums but somewhere is says sent a new post to get personal help HOPE this is okay THANKS Sorry, what?

1493.

Solve : Is my friends computer infected??

Answer»

Logfile of Trend Micro HijackThis v2.0.2
Scan SAVED at 18:11:25, on 25-7-2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\APPLE\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\WINDOWS\system32\RunDll32.exe
C:\PROGRA~1\CA\ETRUST~1\realmon.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\Program Files\Hamachi\hamachi.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files\MSN MESSENGER\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\RDSHOST.exe
C:\WINDOWS\system32\sessmgr.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\MICROSOFT\Internet Explorer\Main,Start Page = http://www.ask.com/?o=13928&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.caiway.nl:80
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ThreeShips IEHelper - {17FDB9F8-DCC4-4F6A-AE07-B16018A48469} - C:\Program Files\Common Files\Threeships Shared\DLL\ThreeShipsIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ATI CATALYST System Tray] "C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe" SystemTray
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.msn.nl/
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab
O16 - DPF: {4E218431-2F07-40BD-A9D3-035324C1F13F} (DyynoX Class) - http://webserver.dyyno.com/DyynoClient/DyynoCAB.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1129630230875
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1129630354187
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5428/mcfscan.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple INC. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

--
End of file - 11255 bytes


Thats the hijackthis log.

Reports of hang on start up and hang when opening programs.

1494.

Solve : Ok, I have followed your request & here is the SAS results?

Answer» THANK you, I will TRY that. I'll LET you know.
roc
1495.

Solve : The post you requested dmoody?

Answer»

Malwarebytes' Anti-Malware 1.39
Database version: 2421
Windows 5.1.2600 Service Pack 3

7/25/2009 9:15:25 PM
mbam-log-2009-07-25 (21-15-07).txt

Scan type: Quick Scan
Objects scanned: 82567
Time elapsed: 6 minute(s), 41 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry VALUES Infected: 1
Registry Data Items Infected: 1
Folders Infected: 2
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mxlivemedia (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\SoftLand Ltd (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Protection System (Rogue.ProtectionSystem) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Protection System (Rogue.ProtectionSystem) -> No action taken.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\protection system (Rogue.ProtectionSystem) -> No action taken.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.

Folders Infected:
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd (Rogue.XPAntiVirus) -> No action taken.
c:\documents and settings\all users\application data\softland ltd\Antivirus 2008 XP (Rogue.XPAntiVirus) -> No action taken.

Files Infected:
c:\WINDOWS\system32\wingenocx.dll (Trojan.FakeAlert) -> No action taken.
c:\WINDOWS\system32\xdhocinsoj.exe (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> No action taken.
C:\Documents and Settings\All Users\Desktop\Protection System.lnk (Rogue.ProtectionSystem) -> No action taken.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:28:09 PM, on 7/25/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\RegCure\RegCure.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\WINDOWS\system32\wscsvc32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: (no name) - CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: YAHOO! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar NOTIFIER BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (USER 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1191622388107
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Background INTELLIGENT Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\

--
End of file - 7054 bytes

1496.

Solve : Cross Partition Virus/Malware infectability??

Answer»

It's not really an "updated version" but, rather a FORK from the original source as Virtual PC.

I can't find any product, specifically called, "Java Virtual Box" But Sun Does own Virtual Box, which is based off the same source as Virtual PC; kind of like, how PC-DOS and MS-DOS had a common ancestor.Hold on. I think I'm talking about two different things here. Sorry.

Microsoft was using the name Microsoft Java Virtual Machine after they sold the Java platform to Sun. A lawsuit followed and MS removed the word Java from the name and continued with using Microsoft Virtual Machine.

Sorry about that. I should have done all of my digging at once. MS NEVER owned the name Java.The Java technology has changed owners a few times. Microsoft (or IBM) are the ones who pioneered it. Sun took it and made it what it is today.

Quote

http://en.wikipedia.org/wiki/Microsoft_Java_Virtual_Machine
The Microsoft Java Virtual Machine was a proprietary Java Virtual Machine computer program from Microsoft. It was first made available for Internet Explorer version 3 so that users could run Java applets when browsing on the World Wide Web.
Yes, but it was never owned by MS, and Virtual PC allows you to run alternate OS's.  I'm not sure that I understand what you are trying to say, can you please rephrase it?Technology is owned by someone... right?

What am I unclear on? Quote from: BC_Programmer on July 20, 2009, 03:45:48 PM
He wants multiple Installations of his OS. One of which he will use on-line, and another mostly off-line; that is, his important data on the "off-line" partition.

His question is wether the On-line partition can infect the off-line one.



If you don't assign a drive letter to the "clean" partition as seen from the "dirty" partition, then I doubt any virus would infect it. If you access files on the "clean" parition from your dirty partition then you'll RISK spreading file infector type viruses from the dirty partition to the clean partition.

As an alternative, you could setup a guest OS install within virtual PC, which would be even better  then two partitions.

Yes, you've got it exactly   That's what I meant.

So, if I'm getting this right, you COULD hide the "dirty" partition using a boot mgr and it'd be cool.  One Q on that though, I seem to remember reading something about a Hide flag VS an "actual" hide.  The flag was supposedly not totally secure on this or that, but I forget exactly what the issue was.  Would say, BootIt or Partition Magic do the full hide?
Oh, and a little off subj, which proggy is better in your opinion?
I've heard polar opposites on opinions.  In my personal exp, Norton when down the toilet after the last DOS ver of Norton Utilities.  AFAIK PM was bought by them.
It's possible PM had some "break" in the quality, like before X ver good and after crap.

Now, as far as the file infectability on a 3rd partition, would data files be safe from the "dirty" partition?  Used to be nice and simple, executable was executable and everything else was not.  Now it seems to blur a little.  I know there was the scarey JPG virus a ways back, but IIRC it only got you if you used an M$ prog to view the pic.  All others were immune (shocker huh).

Anyway, my data partition(s) would have huge newsgroup data files, tons of jpgs, AVI, M4V, email datafiles (but they're Pegasus Mail
Obviously, I need to share some stuff between the dirty and clean or I'd have to do something insane like save to USB drive dirty, scan with AV running clean, then access.  UG!
How much should I worry!
I have a friend who DOES worry that much, heheh.
But then, he believes there not only isn't GLOBAL warming, it's cooling!
AFAIK, he's not on crack either!
Quote from: evilfantasy on July 20, 2009, 04:31:15 PM
Hold on. I think I'm talking about two different things here. Sorry.

Microsoft was using the name Microsoft Java Virtual Machine after they sold the Java platform to Sun. A lawsuit followed and MS removed the word Java from the name and continued with using Microsoft Virtual Machine.

Sorry about that. I should have done all of my digging at once.


err


MS never owned Java, they licensed it from Sun, who started a project they called "oak" that was supposed to be a generic and easy way to program appliances, such as coffee makers and refridgerators and so forth (I think it was more aimed at the manufacturers, rather then the end user, which is to say, they intended to sell the VM to the manufacturers, who could use it instead of a set of hard-coded IC's that they usually used for features such as the temperature control and so forth. I can't remember exactly what happened, but it ended up being a viable language for more then just programming simple appliances.


ahh, here it is:

http://www.java.com/en/javahistory/timeline.jsp


the confusion with MS and Java is that their license was revoked by Sun after Microsoft Visual J++, and the WFC and the various other bastardizations that MS made to their VM, which ended up making it possible that a Java Program would run on the MS VM but not on any others. (namely, the integrated support for COM). Since MS was no longer able to create anything using Java technology, I believe they transformed J++ into Visual Basic .NET, speaking of which one might surmise that the whole Java License thing could have sparked MS to create .NET in the first place- they are both virtual machines, after all, the Java VM and the CLR...


not to mention the whole thing get's even more confused when you have companies like netscape producing completely different technologies (LiveScript) and then renaming them based on the latest craze (which is how we got JavaScript.... JavaScript and Java are so unrelated the mere fact that the name of one is used in another is utterly ridiculous. Java runs in a VM on a client and is a strongly-typed, purely object oriented language that is compiled to bytecode. JavaScript is a Client-side scripting language that barely supports the basics of object access, let alone the creation of objects (real objects- not this IDispatchEx crap- I mean, Objects have VTABLE's, *censored*!)

woops. sorry. went off on a tangent there.


for hiding the partition- there aren't any flags to set- you merely don't give the clean partition a drive letter in the Infectable OS. basically- think of the infectable OS as completely untrusted from the viewpoint of the Clean OS. if the infecteable OS cannot access the clean partition it simply cannot infect it... (although, as you said, you'd still be susceptible to a MBR virus)


if you use a third partition to store data; any data/executables on that partition can be infected if that partition is accessible from the "infectable" OS. for example, if it got infected with Virut/Sality, then chances are any installers, programs, WMV files, HTML files, etc you had on the data drive would be infected. running any of these from teh "Clean" OS could easily infect it, especially if virus protection was only kept on the "infectable" machine and you don't access the net via the clean parittion at all. This would leave you with two infected OS's and a need to reinstall and then check all your data files.



Quote
I have a friend who DOES worry that much, heheh.
But then, he believes there not only isn't global warming, it's cooling!

Well... maps recovered from sea-faring civilizations in the 1300-1400's showed rivers and lakes on the surface of Antarctica. Interesting stuff to ponder... how did they map it? supposedly nobody went to Antarctica until much later; but it kind of goes to show that we cannot assume when their was a first time for anything, I guess.



Thanks BC. Although personally in examples like this, since MS could pretty much do with it as they pleased, I think the difference between license and ownership is a thin line.I think, "license" as it pertains to say licensing a technology from another company is different then the more consumer-based use of the term for licensing software- but they are definitely similar- with a copy of windows or most software, for example, your really paying for the license to use the software, rather then the software itself. Since, in actuality you can do whatever you wished with the contents of the CD, I think that in a very basic way you "own" the CD and it's contents.

I think, the license, more or less pertains to the source code and related libraries and so forth; and in the case of the Java VM, Sun had specific licensing requirements that basically said that the licensee could do whatever they pleased with their VM, as long as it adhered to a specific set of standards, most of which were in place to make sure that the Virtual Machines were consistent across platforms. For example, All VM's implement garbage collection, because it's part of the specification; However, within that limit the creators of the VM could do what they pleased to implement that garbage collection; for example, many VMs use something called "mark and sweep" which goes through the list of objects in memory, and marks those that are unused; then goes through again and disposes of those objects that were marked. Others, for example, the Microsoft VM did this, if I recall, was called "Stop and copy" and was pretty similar, however, instead of going through twice, the objects are looped through just once, and all active objects are copied to a new memory location, the old one is deallocated, and the new one copied back into it's place. this method is faster but more memory intensive (heh, MS always goes for the faster but more memory consuming options...)

In a way, it's similar to the Patent on the GIF/LZW file format that is held my Compuserve/Unisys; a license. which allows you to implement the algorithm legally, is prohibitively expensive, but it really isn't that hard to implement the code; it uses LZW compression, which is a very common and well documented format; basically the patent covers how the file is organized rather then how it is compressed, which is a kind of lame thing to patent. it would be like patenting a living room layout and then charging people who used that layout a "licensing fee".

The way I like to think of it, is that, Owning it, is when you have, and legally obtained, the source code to the product. licensing the product usually means that the company gives you precompiled OBJ files that you can link into your program.

Of course this line is blurred when the licensee is actually given a license for the actual source code. I believe Russia has the source code for windows to meet some sort of esoteric government rule regulating software; but does this mean that Russia owns windows? Well, not really. They just wanted it probably to make sure there wasn't any anti-communist stuff embedded in it, not to modify it.

I added that  "obtained legally" bit for obvious reasons; take the Half-Life 2 Source code leak; it was obtained illegally; but without that clause it would fit under the definition of ownership.


Another definition is who wrote it, which, IMO is the fairest of all, but is too cumbersome to implement. Big companies that have thousands of employees usually have their employees sign a contract which basically signs over anything they write programming-wise to be owned by the company; this includes stuff they write at home. (In my opinion this is dangerously close to breaching some form of human right, (freedom to... express themselves? I don't know... just seems odd). This means that all the source is owned by the company rather then the original writer of the source, which also, seems fair since the company in general paid them to write the program/module.

The real issue with such a setup is when the same programmer writes a utility or small program for public consumption. Before they are able to release it, they literally need to get their own source code given to them, since, because of the aforementioned agreement the company owns it. In general this is to avoid, for example, a company releasing a program, and then one of the employees releasing a competing program that uses portions of the companies code (which may include the work of their co-workers); however because of the wide coverage of the contract a company could practically silence all the work of a programmer except for that done for the company. (the programmer can of course release them anonymously)Hey BC.

Doesn't it seem like every time we start a conversation about Java + Microsoft we end up learning more than we want to.

Quote from: BC_Programmer on July 21, 2009, 03:48:26 AM
woops. sorry. went off on a tangent there.

for hiding the partition- there aren't any flags to set- you merely don't give the clean partition a drive letter in the Infectable OS. basically- think of the infectable OS as completely untrusted from the viewpoint of the Clean OS. if the infecteable OS cannot access the clean partition it simply cannot infect it... (although, as you said, you'd still be susceptible to a MBR virus)

if you use a third partition to store data; any data/executables on that partition can be infected if that partition is accessible from the "infectable" OS. for example, if it got infected with Virut/Sality, then chances are any installers, programs, WMV files, HTML files, etc you had on the data drive would be infected. running any of these from teh "Clean" OS could easily infect it, especially if virus protection was only kept on the "infectable" machine and you don't access the net via the clean parittion at all. This would leave you with two infected OS's and a need to reinstall and then check all your data files.



Well... maps recovered from sea-faring civilizations in the 1300-1400's showed rivers and lakes on the surface of Antarctica. Interesting stuff to ponder... how did they map it? supposedly nobody went to Antarctica until much later; but it kind of goes to show that we cannot assume when their was a first time for anything, I guess.





I wouldn't totally doubt they got to Antarctica since we know some Norse dude found America way before Columbus.  If it WAS warm there, they coulda done it I guess.
My DEAL with the warming is all about the ice cores taken.
Shows the atmospheric content up to 600K yrs ago.
If it was high, coulda been warm.  It goes in big 1000yr+ cycles.
FYI, did yall know there was 60% more oxygen content in the air in dino times?
Apparently that explains why everything was so huge.  Always wondered about that myself.
There's my tangent back at ya, heheh.


By data partition and non-executables, I consider html, all web scripting, doc, wmv, and a couple other M$-made tragedies.  If those are out, would TRUELY data only files be safe or are there viruses that alter them.. I guess just to trash them, as they couldn't run any code thru them?

Looks like the answer to the Q is not exactly a cross partition virus could get you with this setup, but a MBR could infect that which affects all?
No way to protect that other than run AV on all OS partitions?  I plan to do that, but there is the lag time issue as with all malware.
I haven't heard of any MBR virs in a long time, but didn't somebody say they were resurging?  Hows the dmg they do these days rate as far as virs go?

I think my move should be to reinstall everything from clean M$ CD, then pull M$ updates, then the AV update, burn boot CD, scan everything on the backed up drive(s), then scan the whole F-ing dirty partition with the latest update every time I switch to the clean one.
Guess I better keep it small!  Man, I need to comps like my friend does.  Grrr.

It was sooooo nice back in BBS days when you could just scan every file you dl'd and every floppy you put in, and you were good to go
Cursed web!



BTW, how about we separate out the Java posts, the specific virus prob posts, and whatever else into separate threads?
I'm exempting me and you about Antarctica though ;>
That makes a lot more sense now.  Thanks for the information guys, you just schooled me.
1497.

Solve : Fatal System Error (associated w/ csrss.exe) PLEASE HELP!!?

Answer»

**THANK YOU IN ADVANCE FOR ALL THE HELP & ASSISTANCE**

Ok,....I like to think of myself as an "above-average" person when it comes to the health & welfare of computers.  In most cases, I wouldn't trade my computers that are 5 or 6 YEARS old for some of my friends that are only 6 MONTHS old.  But I guess that's irrelevant.

I'VE FINALLY BEEN HIT!!.....AND HIT GOOD!!  Sometime over the last week or so, I managed to get "virused" and "malwared" REALLY BAD!!  I've isolated and/or deleted some of the less harmful ones, but apparently, the really bad ones remain.  In researching, I found that a particular TROJAN likes to MASK itself as CSRSS.EXE.  Well,....I took it upon myself to delete it, and now I get the 0xc0000005 Fatal System Error message.  I also researched and found that that particular F.S.E. message is associated with CSRSS.EXE.

So,....in short, I can't boot in normal mode.  I can't boot in safe mode.  I can't boot in safe mode with command prompt.  It's also worth noting that one of the GAZILLION viruses/malwares/adwares that I've picked up over the last week, won't allow me to use System Restore neither.  I also do not know where my system restore CD is neither.

This is just the begining.  If we can get this fixed/addressed, I'm going to need you fine folks to help me get back to a DECENT working order.

PLEASE HELP!!  I REALLY NEED IT.  Thank you again in advance.Go here and follow the directions.

A specialist will be with you. Quote from: Quantos on July 25, 2009, 10:02:18 PM

Go here and follow the directions.

A specialist will be with you.

Thanks for the reply.  However, I don't think posting there will do me any good (right now), because I can't even boot up the computer.  I can't run HiJack This and/or anything else.  Basically,.....right now, I am dead in water.

Believe me though.  If I can get this first step resolved, I WILL be posting there!  Thanks.Do you know anybody that has a windows XP disc that you can borrow? Quote from: iamtonsoffun247 on July 25, 2009, 10:34:13 PM
Do you know anybody that has a windows XP disc that you can borrow?

Thank you for the reply.

Not readily available.  I do, however, have a Dell "operating system" CD from a different Dell I have.  (My problem is on my Dell Inspiron laptop.  I have the system recovery CD for a Dell Dimension desktop.)  Both the laptop and desktop run XP.  However, I just attempted to boot the CD ROM first, as opposed to the hard drive, because I was attempting to see if I could get MalwareBytes & HiJackThis to run/load.  No such luck.  Still got the Fatal System Error.
1498.

Solve : Sit & Meditate while your SuperAntispyware Updates!?

Answer»

Hi Geeks!

I have kept 'SuperAntispyware' in my armory just because of its impeccable 'Repair Features' (with Repair Broken NETWORK Connection being my favorite); otherwise its 'Definition Update' feature is enough to fickle anyone's mind to trash this product &  opt for something Better!

Release after Release....their developers keep on throwing LIES within their 'Change Log' & have often claimed 'Drastic Improvements' in its Definition Update efficiency!....??..Utter Falsehood!

It takes not less than 2.5 minutes to accomplish A-Z of Definition Update PROCEDURE!

What's your take....?! Is there a workaround to tweak this application for Quick Update Procedure!?Why do you insist on STARTING every post with 'Hi Geeks'?

Are there any errors when SAS is updating? Has it always taken this long?Hello Carbon!

SAS used to much better with versions released till year 2007.No, it do not pose any Error Message!

Secondly, after downloading & installing the 'NEW Definitions'; it continues... till it reflect the Description of the New definitions?!..what's its worth?

Surely, I'll alter my Salutations to keep it afresh! If you aren't happy with SAS why don't you try Malwarebytes?Hi Quantos!

Gr8 to see your 'Cool' Avatar! I already have Malwarebytes product in my Armory.
Its just because of 'Repair Tools', Iam stick to this Product.

What about you folks? Does SAS works perfect during 'Definition Update'?You can get other repair tools, why tie yourself to something you HATE?anyway, superantispyware software itself has been updated as of today.

But sure, get other antimalware tools that you like, as long as it can be updated at least once a day or manually. SAS takes ages to update...? Is it a direct download from an FTP server? Or have they since 2007 or whenever started also using bit torrent protocols to dish out the updates?

Is your router or firewall causing the slow down?...

Anyway 2.5mins isn't a very long time in the real world. Wish, if I could showcase the Screen Activity by recording it in a Flash File!?I don know how to do that & with which application?

I prefer downloads from Filehippo.com & use Windows Firewall.

You think that 'Adding an exception' to the Windows Firewall can make this application Zoom past to fetch the latest update definitions!? Which parts of the utility do you rely on.  There are many other utilities that may do the same thing.  Tell us what parts you use.Hi Quantos!

I wish to showcase that how SAS updates in 'Real Time' through a Flash Recording.

Simply putting it, the Procedure goes:

Step1: Downloading Definitions, you see a progressing bar

Step2: Box appears that depicts 'Checking for Updates', stays on  for a while for say 40-45 seconds.

Step3:
Again a progressing bar & you see list of updated definitions.One that lists Vundo,Worm.Z...etc.

& not to forget that unusually 'Long time' SAS takes to launch itself (First Instance) when an Icon is clicked or through Launchy.

Overall experience is to SIT & MEDITATE till SAS launches & download latest definition updates!
Yes, I understand that.  What program features are tying you to SAS though?

There is a whole world of software out there that you may like better.Everyone seems to empathize with me but no one has told that do they also experience the same 'Wait & Watch' kind of a gimmick with SAS?!


& replying to Quantos:

"Repair Broken Internet Connection" is that factor tying me with SAS!

Can you please compile a list of utilities that can help achieve the same Objective?

& Yes, also a favorable 'Screen Recording' app to let me share the agony I encounter with SAS, everytime!

"Wait and Watch gimmick"? It doesn't bother me, so I didn't think of it as such.  Quote from: Saurabhdua on July 31, 2009, 04:39:30 AM


"Repair Broken Internet Connection" is that factor tying me with SAS!

Can you please compile a list of utilities that can help achieve the same Objective?

& Yes, also a favorable 'Screen Recording' app to let me share the agony I encounter with SAS, everytime!



Windows itself will repair the connection, you can access that utility in networks, and Windows also has the ability to take a screen capture.  Extra utilities aren't necessary for those two.
1499.

Solve : Hyjack log after Firefox mystery?

Answer»

i posted about a problem that i'm having with firefox 3.5 in the browser forum and karnac suggested that i post my hyjack scan here.

After running it i ran malwarebytes ( quick scan ) and the only thing it came up with was something called hyjack log.
i'm going to run a full scan now...that will take an hour or more.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:24:02 PM, on 7/26/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://blank/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TSMAgent] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
O4 - HKLM\..\Run: [CLMLServer for HP TouchSmart] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll (file missing)
O20 - AppInit_DLLs:   C:\Windows\SysWOW64\guard32.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_bd5387da\AESTSr64.exe (file missing)
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: %SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: %SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: %systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files (x86)\SMINST\BLService.exe
O23 - Service: %systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: %SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: %SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: %SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: %systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_bd5387da\STacSV64.exe (file missing)
O23 - Service: TV Background Capture Service (TVBCS) (TVCapSvc) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
O23 - Service: TV Task Scheduler (TVTS) (TVSched) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
O23 - Service: %SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: %SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: %systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: %Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: %ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9355 bytes
and this:

Malwarebytes' Anti-Malware 1.39
Database version: 2505
Windows 6.0.6001 Service Pack 1

7/26/2009 2:02:48 PM
mbam-log-2009-07-26 (14-02-41).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 234944
Time elapsed: 31 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory MODULES Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No ACTION taken.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

1500.

Solve : downloading free avg to a mamory stick to be transfered to another p.c.??

Answer»

I ahve an old 2001 compaq with a lot of VIRUSES on it it won't let me connect to the INTERNET so need to down load avg to a memory stick on my LAPTOP and transfer it to my old desktop.  How can I do that please help!!!Just hold tight man.  A virus specialist will be with you.

In the mean time can you go here and follow the directions that they give?just do it as you would with anything else

but do as quantos says and post the 3 logs hereJust download the AVG  setup file and save it to the desktop of a working PC....................Then transfer it  to the usb stick and transfer to the infected PCs' desktop.....continue as normal, OPEN the setup file and run AVG.....then do the same with the other 3 programs and post your logs.