Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic of your own. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
 
Closed TopicStart new topic
Browser hijack [Closed], Trojan
Michael435
post Oct 25 2009, 04:53 PM
Post #1


New Member
*
Posts: 6
OS: Windows Vista



Virus similiar to jadi929
Searching on google/yahoo etc. gets redirected to some [bleep] site. I believe it's some sort of trojan.

Spybot S&D wont install at all after renaming.
Malwarebytes will install but after running the scan you get Windows cannot access the specified file, path or device. You may not have the appropriate permissions to access the item."

I ran AVG and it removed 2 trojans.
When I restart my computer it says "RunDLL : Cannot run calc.dll" - AVG said it was a trojan and removed it.

I did a AVG Rootkit scan and it found nothing.

Note: I did not do a full scan with AVG because I thought that would be it but as OTL was opening/scanning files AVG found a few other trojans.

Regedit is disabled
AVG detected: Trojan horse SHeur.BMZG
Trojan horse BHO.KHJ
Trojan Horse Generic15.HF
Trojan Horse Generic15.HI

OTL Log:
OTL logfile created on: 10/24/2009 3:33:47 PM - Run 1
OTL by OldTimer - Version 3.0.22.1 Folder = C:\Users\Michael\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16916)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1021.87 Mb Total Physical Memory | 312.54 Mb Available Physical Memory | 30.58% Memory free
2.26 Gb Paging File | 1.24 Gb Available in Paging File | 54.79% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 113.20 Gb Total Space | 43.69 Gb Free Space | 38.60% Space Free | Partition Type: NTFS
Drive D: | 112.85 Gb Total Space | 83.24 Gb Free Space | 73.76% Space Free | Partition Type: NTFS
Drive E: | 4.38 Gb Total Space | 4.24 Gb Free Space | 96.82% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MICHAEL-PC
Current User Name: Michael
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2009/10/24 15:26:44 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Users\Michael\Desktop\OTL.exe
PRC - [2009/10/24 12:56:13 | 02,010,904 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2009/10/24 12:56:01 | 00,600,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2009/10/24 12:52:44 | 01,055,000 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2009/10/24 12:52:41 | 00,827,160 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgam.exe
PRC - [2009/10/24 12:46:53 | 00,502,040 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2009/10/24 12:46:52 | 00,702,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2009/10/24 12:46:31 | 00,906,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgemc.exe
PRC - [2009/10/24 12:46:23 | 00,285,392 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2009/10/24 11:52:20 | 00,316,664 | ---- | M] (Valve Corporation) -- C:\Program Files\Common Files\Steam\SteamService.exe
PRC - [2009/10/23 21:25:36 | 01,217,808 | ---- | M] (Valve Corporation) -- C:\Program Files\Steam\Steam.exe
PRC - [2009/05/20 21:18:57 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe
PRC - [2009/05/09 14:09:24 | 00,606,720 | ---- | M] (http://tortoisesvn.net) -- D:\TSVN\bin\TSVNCache.exe
PRC - [2009/03/09 05:19:17 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/03/05 19:41:15 | 00,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/02/27 16:27:31 | 02,923,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\Explorer.EXE
PRC - [2009/02/27 16:15:48 | 01,232,896 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Sidebar\sidebar.exe
PRC - [2009/02/23 20:43:12 | 00,576,000 | ---- | M] (MagicISO, Inc.) -- C:\Program Files\MagicDisc\MagicDisc.exe
PRC - [2009/02/06 19:51:28 | 03,885,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
PRC - [2009/02/03 23:58:34 | 00,729,088 | ---- | M] (ATI Technologies Inc.) -- C:\Windows\System32\Ati2evxx.exe
PRC - [2008/12/18 15:32:52 | 00,049,152 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
PRC - [2008/12/18 14:19:44 | 00,049,152 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/11/24 22:31:12 | 00,087,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
PRC - [2008/11/24 22:31:08 | 00,239,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
PRC - [2008/08/27 18:19:20 | 00,233,588 | ---- | M] (Creative Technology Ltd) -- D:\Program Files\Creative\USB Headsets\Volume Panel\VolPanlu.exe
PRC - [2008/04/29 21:27:50 | 00,417,792 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe
PRC - [2006/12/08 16:45:32 | 00,045,056 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
PRC - [2006/11/12 13:35:58 | 00,393,216 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
PRC - [2006/11/08 21:57:52 | 03,784,704 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2006/11/02 07:36:04 | 00,895,488 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe
PRC - [2006/11/02 07:36:04 | 00,201,728 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe
PRC - [2006/11/02 07:34:36 | 00,151,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\notepad.exe
PRC - [2006/11/02 04:46:02 | 00,143,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WUDFHost.exe
PRC - [2006/10/19 16:52:24 | 00,061,440 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2006/06/26 10:34:58 | 00,166,448 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\QuickCam10\COCIManager.exe
PRC - [2006/06/26 10:34:40 | 00,614,960 | ---- | M] () -- C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
PRC - [2006/06/26 10:33:42 | 00,099,888 | ---- | M] (Logitech Inc.) -- c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
PRC - [2006/06/26 10:33:32 | 00,243,248 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
PRC - [2006/06/26 09:46:04 | 00,497,200 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe

========== Win32 Services (SafeList) ==========

SRV - File not found -- -- (CLTNetCnService [Auto | Stopped])
SRV - [2009/10/24 12:46:31 | 00,906,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgemc.exe -- (avg9emc [Auto | Running])
SRV - [2009/10/24 12:46:23 | 00,285,392 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd [Auto | Running])
SRV - [2009/10/24 11:52:20 | 00,316,664 | ---- | M] (Valve Corporation) -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service [On_Demand | Running])
SRV - [2009/10/06 19:34:21 | 00,079,360 | ---- | M] (Creative Labs) -- C:\Program Files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe -- (Creative Media Toolbox 6 Licensing Service [Disabled | Stopped])
SRV - [2009/10/06 19:31:31 | 00,079,360 | ---- | M] (Creative Labs) -- C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe -- (Creative ALchemy AL1 Licensing Service [Disabled | Stopped])
SRV - [2009/10/06 19:24:31 | 00,079,360 | ---- | M] (Creative Labs) -- C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service [Disabled | Stopped])
SRV - [2009/09/15 15:29:04 | 00,057,640 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE -- (HssTrayService [Disabled | Stopped])
SRV - [2009/09/15 15:28:52 | 00,204,848 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe -- (HotspotShieldService [Disabled | Stopped])
SRV - [2009/09/15 15:04:58 | 00,331,824 | ---- | M] (AnchorFree Inc.) -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv [Disabled | Stopped])
SRV - [2009/07/13 14:02:50 | 00,542,496 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Stopped])
SRV - [2009/07/09 12:22:18 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Disabled | Stopped])
SRV - [2009/05/28 08:32:26 | 00,053,760 | ---- | M] (tzuk) -- C:\Program Files\Sandboxie\SbieSvc.exe -- (SbieSvc [Disabled | Stopped])
SRV - [2009/05/24 13:56:33 | 00,075,064 | ---- | M] () -- C:\Windows\System32\PnkBstrA.exe -- (PnkBstrA [Disabled | Stopped])
SRV - [2009/05/20 21:18:57 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1c9d9ba82edd358 [Auto | Stopped])
SRV - [2009/05/20 21:18:31 | 00,183,280 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [Auto | Stopped])
SRV - [2009/04/05 19:59:08 | 00,655,624 | ---- | M] (Acresso Software Inc.) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service [Disabled | Stopped])
SRV - [2009/03/10 17:42:00 | 03,121,464 | ---- | M] (INCA Internet Co., Ltd.) -- C:\Windows\System32\GameMon.des -- (npggsvc [Disabled | Stopped])
SRV - [2009/02/27 16:41:25 | 00,265,912 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend [Auto | Stopped])
SRV - [2009/02/03 23:58:34 | 00,729,088 | ---- | M] (ATI Technologies Inc.) -- C:\Windows\System32\Ati2evxx.exe -- (Ati External Event Utility [Auto | Running])
SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2008/11/24 22:31:12 | 00,087,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter [Auto | Running])
SRV - [2008/11/24 22:31:10 | 29,263,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -- (MSSQL$SQLEXPRESS [Disabled | Stopped])
SRV - [2008/11/24 22:31:08 | 00,239,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser [Auto | Running])
SRV - [2008/11/24 22:31:08 | 00,045,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe -- (MSSQLServerADHelper [Disabled | Stopped])
SRV - [2008/07/29 13:10:46 | 03,201,024 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe -- (msvsmon90 [Disabled | Stopped])
SRV - [2008/07/27 13:00:25 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/06/19 20:18:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/06/19 20:17:50 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/06/19 20:17:49 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008/04/29 21:27:50 | 00,417,792 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService [Auto | Running])
SRV - [2006/12/08 16:45:32 | 00,045,056 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe -- (eRecoveryService [Auto | Running])
SRV - [2006/11/02 07:36:04 | 00,895,488 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Running])
SRV - [2006/11/02 07:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [On_Demand | Stopped])
SRV - [2006/11/02 07:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehstart.dll -- (ehstart [Auto | Stopped])
SRV - [2006/11/02 07:35:28 | 00,291,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehRecvr.exe -- (ehRecvr [On_Demand | Stopped])
SRV - [2006/11/02 04:46:13 | 00,989,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wevtsvc.dll -- (Eventlog [Auto | Running])
SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2006/10/19 16:52:24 | 00,061,440 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running])
SRV - [2006/06/26 10:33:56 | 00,091,696 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe -- (LVSrvLauncher [Auto | Stopped])
SRV - [2006/06/26 10:33:42 | 00,099,888 | ---- | M] (Logitech Inc.) -- c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe -- (LVPrcSrv [Auto | Running])

========== Modules (SafeList) ==========

MOD - [2009/10/24 15:26:44 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Users\Michael\Desktop\OTL.exe
MOD - [2009/10/24 12:47:40 | 00,012,464 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll
MOD - [2006/11/02 07:34:48 | 00,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\LINKINFO.dll
MOD - [2006/11/02 04:38:57 | 01,648,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll
MOD - [2006/06/26 10:33:42 | 00,091,696 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com


IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com [binary data]
IE - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SEARCH PAGE = http://us.rd.yahoo.com/customize/ycomp/def...//www.yahoo.com
IE - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe...-8&fr=b1ie7
IE - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-316218746-153266152-3376316544-1000\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-316218746-153266152-3376316544-1000\S-1-5-21-316218746-153266152-3376316544-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1
FF - prefs.js..extensions.enabledItems: {bb6bc1bb-f824-4702-90cd-35e2fb24f25c}:0.2.1.3
FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.4.3
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:0.0.0
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.8
FF - prefs.js..extensions.enabledItems: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:10.1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14
FF - prefs.js..network.proxy.no_proxies_on: "*.local"

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/02 15:44:40 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2009/10/24 13:02:39 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/17 15:29:42 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/10/24 12:40:17 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

[2009/05/05 18:09:10 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Extensions
[2009/05/05 18:09:10 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/03/13 13:39:13 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org
[2009/10/24 12:47:22 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\3xm87rlz.default\extensions
[2009/08/10 19:30:36 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\3xm87rlz.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/09/07 10:33:20 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\3xm87rlz.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
[2009/09/07 10:33:20 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\3xm87rlz.default\extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25c}
[2009/07/28 14:26:02 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\3xm87rlz.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/10/06 12:11:09 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\3xm87rlz.default\extensions\firebug@software.joehewitt.com
[2009/05/05 18:08:26 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/09/17 15:29:42 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/09/17 15:29:28 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/09/17 15:29:28 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/09/17 15:29:33 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009/09/04 21:06:03 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/09/04 21:06:04 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/09/04 21:06:04 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/09/04 21:06:04 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/09/04 21:06:04 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/09/04 21:06:04 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/09/04 21:06:04 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2009/08/03 09:10:30 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/08/03 09:10:30 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/08/03 09:10:30 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/08/03 09:10:30 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/08/03 09:10:30 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/08/03 09:10:30 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/08/03 09:10:30 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (871 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: http://208.43.115.136/~tnban/ www.taconbanana.com
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.alexspage.co.uk
O1 - Hosts: 127.0.0.1 alexspage.co.uk
O2 - BHO: (C:\Windows\system32\zkcw2lfbht.dll) - {A2234B15-23F2-42AD-F4E4-00AAC39C0004} - C:\Windows\System32\zkcw2lfbht.dll File not found
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-316218746-153266152-3376316544-1000\..\Toolbar\ShellBrowser: (no name) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - No CLSID value found.
O3 - HKU\S-1-5-21-316218746-153266152-3376316544-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [calc] C:\Windows\System32\calc.DLL File not found
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe File not found
O4 - HKLM..\Run: [IgfxTray] C:\Windows\System32\igfxtray.exe File not found
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam10\QuickCam10.exe ()
O4 - HKLM..\Run: [LVCOMSX] C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe (Logitech Inc.)
O4 - HKLM..\Run: [Persistence] C:\Windows\System32\igfxpers.exe File not found
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [VolPanel] D:\Program Files\Creative\USB Headsets\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.DLL (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.DLL (Microsoft Corporation)
O4 - HKU\S-1-5-21-316218746-153266152-3376316544-1000..\Run: [cdloader] C:\Users\Michael\AppData\Roaming\mjusbsp\cdloader2.exe (magicJack L.P.)
O4 - HKU\S-1-5-21-316218746-153266152-3376316544-1000..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-316218746-153266152-3376316544-1000..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-316218746-153266152-3376316544-1000..\Run: [Speech Recognition] C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-316218746-153266152-3376316544-1000..\Run: [Steam] c:\program files\steam\steam.exe (Valve Corporation)
O4 - HKU\S-1-5-21-316218746-153266152-3376316544-1000..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKU\S-1-5-21-316218746-153266152-3376316544-1000..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-316218746-153266152-3376316544-1000..\Run: [捁牥吠畯r] File not found
O4 - Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O7 - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\.DEFAULT\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-18\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-316218746-153266152-3376316544-1000\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.systemrequirementslab.com/srl_b...sreqlab_srl.cab (System Requirements Lab Class)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 74.128.17.114 74.128.19.102
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - File not found
O22 - SharedTaskScheduler: {A2234B15-23F2-42AD-F4E4-00AAC39C0004} - gsajkfh873whdngo8wuidgs4rgfr4 - C:\Windows\System32\zkcw2lfbht.dll File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{791278b3-b84d-11de-b1bc-00192154d15d}\Shell\AutoRun\command - "" = M:\autorun.exe -- File not found
O33 - MountPoints2\{791278b3-b84d-11de-b1bc-00192154d15d}\Shell\phone\command - "" = M:\autorun.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found

========== Files/Folders - Created Within 14 Days ==========

[2009/10/24 12:46:19 | 00,000,000 | ---D | C] -- C:\ProgramData\avg9
[2009/10/24 14:05:04 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009/10/24 14:05:11 | 00,000,000 | ---D | C] -- C:\Users\Michael\AppData\Roaming\Malwarebytes
[2009/10/13 18:22:48 | 00,000,000 | ---D | C] -- C:\Users\Michael\AppData\Roaming\mjusbsp
[2009/10/14 16:25:00 | 00,000,000 | ---D | C] -- C:\Users\Michael\AppData\Local\Blizzard Entertainment
[2009/10/14 15:30:00 | 00,000,000 | ---D | C] -- C:\Users\Michael\AppData\Local\tjnet
[2009/10/21 16:06:35 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2009/10/24 12:46:20 | 00,000,000 | ---D | C] -- C:\Program Files\AVG
[2009/10/18 20:43:15 | 00,000,000 | ---D | C] -- C:\Program Files\Hackers Paradise
[2009/10/24 14:05:04 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/10/21 16:07:21 | 00,000,000 | ---D | C] -- C:\Program Files\VentSrv
[2009/10/24 15:26:34 | 00,521,728 | ---- | C] (OldTimer Tools) -- C:\Users\Michael\Desktop\OTL.exe
[2009/10/24 14:19:01 | 00,000,000 | -H-D | C] -- C:\Windows\PIF
[2009/10/24 14:05:06 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/10/24 14:05:04 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/10/24 12:47:46 | 00,000,000 | -H-D | C] -- C:\$AVG
[2009/10/24 12:47:40 | 00,012,464 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll
[2009/10/24 12:47:39 | 00,161,800 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgrkx86.sys
[2009/10/24 12:47:38 | 00,360,584 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgtdix.sys
[2009/10/24 12:47:27 | 00,333,192 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys
[2009/10/24 12:47:26 | 00,028,424 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgmfx86.sys
[2009/10/24 12:47:06 | 00,000,000 | ---D | C] -- C:\Windows\System32\drivers\Avg
[2009/10/24 12:38:46 | 93,477,512 | ---- | C] (AVG Technologies) -- C:\Users\Michael\Desktop\avg_avwt_stf_all_90_663a1706.exe
[2009/10/17 14:27:24 | 00,000,000 | ---D | C] -- C:\Users\Michael\Desktop\kl
[2009/10/17 09:05:27 | 00,000,000 | ---D | C] -- C:\Windows\SQLTools9_KB970892_ENU
[2009/10/16 17:09:48 | 00,000,000 | ---D | C] -- C:\msdn
[2009/03/14 19:07:07 | 00,047,360 | ---- | C] (VSO Software) -- C:\Users\Michael\AppData\Roaming\pcouffin.sys

========== Files - Modified Within 14 Days ==========

[2 C:\Windows\System32\*.tmp files]
[2009/10/24 15:33:01 | 00,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2009/10/24 15:26:44 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Users\Michael\Desktop\OTL.exe
[2009/10/24 14:51:15 | 00,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2009/10/24 14:47:53 | 00,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2009/10/24 14:45:29 | 00,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/10/24 14:45:29 | 00,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/10/24 14:45:25 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/10/24 14:45:18 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/10/24 14:45:17 | 00,000,000 | ---- | M] () -- C:\Windows\win32k.sys
[2009/10/24 14:45:14 | 10,721,56672 | -HS- | M] () -- C:\hiberfil.sys
[2009/10/24 14:38:13 | 00,000,822 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/24 14:18:35 | 16,409,960 | ---- | M] () -- C:\Users\Michael\Desktop\lold.exe
[2009/10/24 13:31:02 | 02,978,722 | -H-- | M] () -- C:\Users\Michael\AppData\Local\IconCache.db
[2009/10/24 12:56:07 | 00,360,584 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgtdix.sys
[2009/10/24 12:56:01 | 00,028,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgmfx86.sys
[2009/10/24 12:55:33 | 43,828,872 | ---- | M] () -- C:\Windows\System32\drivers\Avg\incavi.avm
[2009/10/24 12:52:42 | 00,161,800 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgrkx86.sys
[2009/10/24 12:52:42 | 00,050,548 | ---- | M] () -- C:\Windows\System32\drivers\Avg\microavi.avg
[2009/10/24 12:47:40 | 00,012,464 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll
[2009/10/24 12:47:40 | 00,001,651 | ---- | M] () -- C:\Users\Public\Desktop\AVG 9.0.lnk
[2009/10/24 12:47:27 | 00,333,192 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys
[2009/10/24 12:47:26 | 00,113,461 | ---- | M] () -- C:\Windows\System32\drivers\Avg\iavichjw.avm
[2009/10/24 12:47:08 | 06,061,540 | ---- | M] () -- C:\Windows\System32\drivers\Avg\avi7.avg
[2009/10/24 12:47:08 | 00,492,629 | ---- | M] () -- C:\Windows\System32\drivers\Avg\miniavi.avg
[2009/10/23 21:22:36 | 14,317,8533 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2009/10/23 21:19:41 | 00,000,819 | -HS- | M] () -- C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scandisk.lnk
[2009/10/22 17:37:49 | 00,048,556 | ---- | M] () -- C:\Users\Michael\Desktop\harvester_of_sorrow_ver2.gp4
[2009/10/22 15:30:12 | 00,665,118 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009/10/22 15:30:12 | 00,121,460 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009/10/22 15:30:11 | 00,782,756 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009/10/18 20:43:17 | 00,002,303 | ---- | M] () -- C:\Users\Public\Desktop\Systemerror's Security toolkit.lnk
[2009/10/16 17:11:56 | 00,000,000 | ---- | M] () -- C:\Windows\chatter.INI
[2009/10/14 16:24:15 | 00,000,518 | ---- | M] () -- C:\Windows\win.ini
[2009/10/11 17:31:48 | 00,010,752 | ---- | M] () -- C:\Users\Michael\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/11 09:28:55 | 93,477,512 | ---- | M] (AVG Technologies) -- C:\Users\Michael\Desktop\avg_avwt_stf_all_90_663a1706.exe

========== Files - No Company Name ==========
[2009/10/24 14:45:14 | 10,721,56672 | -HS- | C] () -- C:\hiberfil.sys
[2009/10/24 14:18:17 | 16,409,960 | ---- | C] () -- C:\Users\Michael\Desktop\lold.exe
[2009/10/24 14:05:08 | 00,000,822 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/24 12:47:40 | 00,001,651 | ---- | C] () -- C:\Users\Public\Desktop\AVG 9.0.lnk
[2009/10/24 12:47:26 | 00,113,461 | ---- | C] () -- C:\Windows\System32\drivers\Avg\iavichjw.avm
[2009/10/24 12:47:08 | 43,828,872 | ---- | C] () -- C:\Windows\System32\drivers\Avg\incavi.avm
[2009/10/24 12:47:08 | 00,492,629 | ---- | C] () -- C:\Windows\System32\drivers\Avg\miniavi.avg
[2009/10/24 12:47:08 | 00,050,548 | ---- | C] () -- C:\Windows\System32\drivers\Avg\microavi.avg
[2009/10/24 12:47:06 | 06,061,540 | ---- | C] () -- C:\Windows\System32\drivers\Avg\avi7.avg
[2009/10/23 21:19:41 | 00,000,000 | ---- | C] () -- C:\Windows\win32k.sys
[2009/10/22 17:37:48 | 00,048,556 | ---- | C] () -- C:\Users\Michael\Desktop\harvester_of_sorrow_ver2.gp4
[2009/10/18 20:43:17 | 00,002,303 | ---- | C] () -- C:\Users\Public\Desktop\Systemerror's Security toolkit.lnk
[2009/10/16 17:11:56 | 00,000,000 | ---- | C] () -- C:\Windows\chatter.INI
[2009/10/06 19:27:09 | 00,025,199 | R--- | C] () -- C:\Windows\System32\xfisk.ini
[2009/10/06 19:27:09 | 00,000,052 | R--- | C] () -- C:\Windows\System32\ctzapxx.ini
[2009/10/06 19:27:01 | 00,001,209 | R--- | C] () -- C:\Windows\skSPcfg.ini
[2009/10/06 19:27:01 | 00,000,381 | R--- | C] () -- C:\Windows\skMCcfg.ini
[2009/10/06 19:26:49 | 00,127,488 | ---- | C] () -- C:\Windows\System32\APOMngr.DLL
[2009/10/06 19:26:49 | 00,069,120 | ---- | C] () -- C:\Windows\System32\CmdRtr.DLL
[2009/10/05 13:59:45 | 01,589,248 | ---- | C] () -- C:\Windows\System32\libmysql_d.dll
[2009/08/29 07:56:50 | 00,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini
[2009/07/30 12:06:17 | 00,002,288 | ---- | C] () -- C:\Windows\Sandboxie.ini
[2009/07/30 09:27:25 | 01,970,176 | ---- | C] () -- C:\Windows\System32\d3dx9.dll
[2009/07/28 15:02:04 | 00,000,172 | ---- | C] () -- C:\Windows\ODBC.INI
[2009/05/24 14:37:51 | 00,107,520 | ---- | C] () -- C:\Windows\System32\SIMANT.DLL
[2009/05/24 14:37:51 | 00,027,136 | ---- | C] () -- C:\Windows\System32\VERMONT1.DLL
[2009/05/24 14:37:51 | 00,012,416 | ---- | C] () -- C:\Windows\System32\VRX1.DLL
[2009/05/10 15:11:11 | 00,000,318 | ---- | C] () -- C:\Windows\WPE PRO.INI
[2009/05/03 20:04:55 | 00,000,318 | ---- | C] () -- C:\Windows\WPE PRO - modified.INI
[2009/05/02 13:59:51 | 00,021,840 | ---- | C] () -- C:\Windows\System32\SIntfNT.dll
[2009/05/02 13:59:51 | 00,017,212 | ---- | C] () -- C:\Windows\System32\SIntf32.dll
[2009/05/02 13:59:51 | 00,012,067 | ---- | C] () -- C:\Windows\System32\SIntf16.dll
[2009/03/29 18:13:50 | 00,022,334 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2009/03/14 19:08:08 | 00,000,034 | ---- | C] () -- C:\Users\Michael\AppData\Roaming\pcouffin.log
[2009/03/14 19:07:07 | 00,087,608 | ---- | C] () -- C:\Users\Michael\AppData\Roaming\inst.exe
[2009/03/14 19:07:07 | 00,007,887 | ---- | C] () -- C:\Users\Michael\AppData\Roaming\pcouffin.cat
[2009/03/14 19:07:07 | 00,001,144 | ---- | C] () -- C:\Users\Michael\AppData\Roaming\pcouffin.inf
[2009/03/14 18:58:19 | 00,000,671 | ---- | C] () -- C:\Users\Michael\AppData\Roaming\vso_ts_preview.xml
[2009/03/12 19:39:15 | 00,815,104 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009/03/12 19:39:15 | 00,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009/03/08 15:19:59 | 00,010,752 | ---- | C] () -- C:\Users\Michael\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/27 19:10:53 | 00,139,904 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2009/02/27 19:10:53 | 00,022,328 | ---- | C] () -- C:\Users\Michael\AppData\Roaming\PnkBstrK.sys
[2009/02/26 17:54:15 | 02,978,722 | -H-- | C] () -- C:\Users\Michael\AppData\Local\IconCache.db
[2009/02/26 17:49:25 | 00,051,504 | ---- | C] () -- C:\Users\Michael\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/02/04 00:00:07 | 00,011,264 | ---- | C] () -- C:\Windows\System32\atimuixx.dll
[2006/12/12 22:46:07 | 00,013,952 | ---- | C] () -- C:\Windows\System32\drivers\UBHelper.sys
[2006/12/12 22:17:29 | 00,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN4.dll
[2006/12/12 21:22:55 | 00,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1129.dll
[2006/12/12 21:22:55 | 00,001,029 | ---- | C] () -- C:\Windows\generic.ini
[2006/12/12 21:22:55 | 00,000,117 | ---- | C] () -- C:\Windows\Alaunch.ini
[2006/12/12 21:22:54 | 00,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2006/11/16 14:20:10 | 00,086,016 | ---- | C] () -- C:\Windows\System32\MSNSpook.dll
[2006/11/16 14:19:10 | 00,037,376 | ---- | C] () -- C:\Windows\System32\MSNChatHook.dll
[2006/11/02 07:50:50 | 00,000,174 | -HS- | C] () -- C:\Program Files\desktop.ini
[2006/11/02 07:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:23:31 | 00,000,518 | ---- | C] () -- C:\Windows\win.ini
[2006/11/02 05:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini
[2006/11/02 03:43:04 | 00,061,952 | ---- | C] () -- C:\Windows\System32\cngaudit.dll
[2006/11/02 02:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/06/26 10:33:40 | 00,023,472 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys
[2001/12/26 18:12:30 | 00,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll
[2001/09/04 01:46:38 | 00,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll
[2001/07/30 18:33:56 | 00,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll
[2001/07/24 00:04:36 | 00,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll

========== LOP Check ==========

[2006/11/02 07:37:34 | 00,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming
[2006/11/02 07:37:34 | 00,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Media Center Programs
[2006/11/02 07:37:34 | 00,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming
[2006/11/02 07:37:34 | 00,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Media Center Programs
[2009/10/24 14:05:11 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming
[2009/08/23 15:21:35 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\acccore
[2009/02/26 18:00:24 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Acer
[2009/02/27 22:23:57 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\ATI
[2009/05/18 17:31:29 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Datarescue
[2009/03/14 13:40:16 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\ESET
[2009/10/23 19:49:31 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\FileZilla
[2009/10/24 12:04:44 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\HLSW
[2009/05/02 13:37:39 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\ImgBurn
[2009/03/23 16:39:10 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\JCreator
[2009/02/26 18:00:22 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Leadertech
[2009/09/21 20:52:11 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\LimeWire
[2009/09/04 16:20:47 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Mael
[2006/11/02 07:37:34 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Media Center Programs
[2009/09/28 20:46:32 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mIRC
[2009/10/13 18:23:31 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mjusbsp
[2009/09/04 16:37:05 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Notepad++
[2009/07/30 15:25:56 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Renoise
[2009/08/29 12:20:54 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\SmartFTP
[2009/05/16 13:57:27 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Subversion
[2009/05/24 11:27:15 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\TortoiseSVN
[2009/10/24 12:55:21 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\uTorrent
[2009/03/20 21:17:38 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Ventrilo
[2009/05/02 12:42:09 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Vso
[2009/09/15 20:20:02 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Warsow
[2009/07/27 11:57:07 | 00,000,000 | ---D | M] -- C:\Users\Michael_2\AppData\Roaming
[2009/06/27 17:03:48 | 00,000,000 | ---D | M] -- C:\Users\Michael_2\AppData\Roaming\ATI
[2006/11/02 07:37:34 | 00,000,000 | ---D | M] -- C:\Users\Michael_2\AppData\Roaming\Media Center Programs
[2009/07/27 11:57:07 | 00,000,000 | ---D | M] -- C:\Users\Michael_2\AppData\Roaming\Subversion
[2009/10/24 14:47:53 | 00,000,868 | ---- | M] () -- C:\Windows\Tasks\Google Software Updater.job
[2009/10/24 14:51:15 | 00,000,882 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2009/10/24 15:33:01 | 00,000,886 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2009/10/24 14:45:25 | 00,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT
[2009/10/24 13:31:46 | 00,032,614 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >

< %systemroot%\system32\eventlog.dll >

< %systemroot%\system32\scecli.dll >
[2006/11/02 04:46:12 | 00,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\scecli.dll
[2 C:\Windows\system32\*.tmp files]

< %systemroot%\netlogon.dll >

< %systemroot%\system32\cngaudit.dll >
[2006/11/02 04:46:03 | 00,061,952 | ---- | M] () -- C:\Windows\system32\cngaudit.dll
[2 C:\Windows\system32\*.tmp files]

< %systemroot%\system32\sceclt.dll >

< %systemroot%\ntelogon.dll >

< %systemroot%\system32\logevent.dll >
[2006/11/02 04:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\logevent.dll
[2 C:\Windows\system32\*.tmp files]

< %systemroot%\system32\drivers\iaStor.sys >
[2006/06/13 15:56:40 | 00,247,808 | ---- | M] (Intel Corporation) -- C:\Windows\system32\drivers\iaStor.sys

< %systemroot%\System32\drivers\nvstor.sys >
[2006/11/02 04:50:13 | 00,040,040 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvstor.sys

< %systemroot%\system32\drivers\atapi.sys >
[2009/02/27 16:28:20 | 00,021,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\drivers\atapi.sys

< %systemroot%\system32\drivers\IdeChnDr.sys >

========== Alternate Data Streams ==========

@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:54D4173A
< End of report >

Extras Log:
OTL Extras logfile created on: 10/24/2009 3:33:47 PM - Run 1
OTL by OldTimer - Version 3.0.22.1 Folder = C:\Users\Michael\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16916)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1021.87 Mb Total Physical Memory | 312.54 Mb Available Physical Memory | 30.58% Memory free
2.26 Gb Paging File | 1.24 Gb Available in Paging File | 54.79% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 113.20 Gb Total Space | 43.69 Gb Free Space | 38.60% Space Free | Partition Type: NTFS
Drive D: | 112.85 Gb Total Space | 83.24 Gb Free Space | 73.76% Space Free | Partition Type: NTFS
Drive E: | 4.38 Gb Total Space | 4.24 Gb Free Space | 96.82% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MICHAEL-PC
Current User Name: Michael
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{068ECA10-8A02-4B04-8502-7290E9EEA4C9}" = rport=139 | protocol=6 | dir=out | app=system |
"{1C1BF42B-1E82-48B3-BA05-2A0C46FE2677}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |
"{23AE9CD6-73D5-4BDB-87A6-70BE1C59F767}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{23E2CC50-7BF5-4561-99C7-F92D714BFE4D}" = lport=138 | protocol=17 | dir=in | app=system |
"{25AD4EE5-F33E-4A28-A7B1-1E38123DF7D2}" = lport=137 | protocol=17 | dir=in | app=system |
"{2C507BA4-6395-41B1-A3BB-60FF23EF97E9}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{3771231F-13D7-42AC-8111-6910CBD93E1F}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 |
"{3B2A6122-E572-4027-9D03-BC250E0AB4FF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{4CBDA73F-C141-43CE-A12F-BB3A9C6E9F28}" = rport=137 | protocol=17 | dir=out | app=system |
"{5B23B3C1-449E-4101-8351-0465530C2B95}" = lport=1735 | protocol=6 | dir=in | name=eaviphiv |
"{6C0C1057-D978-41D7-84C4-9E9F5A03F7E8}" = lport=445 | protocol=6 | dir=in | app=system |
"{70D9BA0B-0063-4ACA-8654-C27D75C75261}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{BA04F881-2E53-46DF-89F6-D059F7A83736}" = lport=80 | protocol=6 | dir=in | name=apache |
"{BB865549-537C-4897-9ACE-88A359746D18}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C37F7013-D53B-4542-A71A-2775B642F9FD}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{C9745962-C16B-451B-82E2-043042571869}" = lport=139 | protocol=6 | dir=in | app=system |
"{D9E5C5B2-5CC8-4E21-9BDF-CC236D21BFE5}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{DA5C52C8-F98C-418E-903E-7A097B8F6B58}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E8FB4CD6-CAB5-416A-97E1-998C8392AD20}" = lport=80 | protocol=17 | dir=in | name=apache |
"{EF06B059-1896-46EA-AB9D-3FBFDA9F9EE5}" = rport=445 | protocol=6 | dir=out | app=system |
"{F5C897D3-9FFC-4C91-A588-470A8741656F}" = rport=138 | protocol=17 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04BA2E6E-44D8-4A03-A27E-FC830ECB08D6}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{0661BA2C-0E6B-4518-B25D-5ED01D24F6B9}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe |
"{07A46220-80AB-4911-ABA0-F24941DDAEAD}" = protocol=6 | dir=in | app=c:\users\michael\appdata\roaming\mjusbsp\magicjack.exe |
"{167C6915-AD96-405E-B605-203F97290411}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{16E1EDB1-A15D-4D9D-A85E-25BC964EDA54}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-0.3.0.10522-enus-ptr-downloader.exe |
"{176476BF-A21E-4C2D-892E-8899031EF779}" = protocol=17 | dir=in | app=c:\users\michael\appdata\roaming\mjusbsp\magicjack.exe |
"{1D78E303-70E9-4943-A079-2F7E5DA36309}" = protocol=6 | dir=in | app=c:\program files\acer zone\acer zone softdma\softdma.exe |
"{1F60CDE7-D481-44A4-98F0-A30C1862CC06}" = protocol=17 | dir=in | app=c:\program files\acer zone\acer zone softdma\softdma.exe |
"{259177E6-B9A0-444F-9A31-039A5B533BBE}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe |
"{2BE66DC6-08FB-435D-80BE-8A1399C08448}" = protocol=17 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{2CCC04A8-305F-437D-9878-473E45BD9CE7}" = protocol=17 | dir=in | app=d:\program files\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\xr_3da.exe |
"{2D7907D7-31EB-4734-9B4E-AAC7155FCB45}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{3CF2E0F9-A144-4AB0-B430-0EC3D9B6C6BE}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-0.3.0.10571-to-0.3.0.10596-enus-ptr-downloader.exe |
"{44F5C103-1111-46A3-925C-1C80AD0488F5}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{4A5617ED-3FCC-4B49-8CFE-39E64490C1FA}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{4E61581C-3707-4123-9072-A2F58F124724}" = protocol=6 | dir=in | app=d:\program files\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\xr_3da.exe |
"{53A9F2F5-65B2-41A4-8F6E-6039C0190BFC}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{545E20A9-04ED-42C9-861E-602B5AB56569}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"{569A1AC5-0619-433F-88D2-58ECA3E2B578}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{5D5B4EBC-605F-4CB6-8A4B-A7688CC11530}" = dir=in | app=c:\program files\avg\avg9\avgupd.exe |
"{6095D56A-C749-4B74-B933-4EA63557F2E5}" = dir=in | app=c:\program files\avg\avg9\avgdiagex.exe |
"{642287D5-2E06-4A01-B33D-261440D83042}" = protocol=17 | dir=in | app=c:\program files\acer zone\acer zone main page\mce deluxe suite.exe |
"{65A75A0C-11D7-4D00-81EA-BF7B80219122}" = dir=in | app=c:\program files\avg\avg9\avgnsx.exe |
"{6AC9D0A6-D988-492A-9291-6028EB3F274E}" = dir=in | app=c:\program files\avg\avg9\avgam.exe |
"{7112D327-523F-4220-AA94-10B17C488C63}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe |
"{7601C2B2-0371-44AB-B77C-74222A7BCAA7}" = protocol=17 | dir=in | app=c:\program files\acer zone\acer picture slide dvd\component\clsldvd.exe |
"{798D38B2-F81A-4EB7-8BC2-E015E018CBC7}" = protocol=6 | dir=in | app=d:\program files\smartftp client\smartftp.exe |
"{87024B47-8663-4778-93AD-BE79976DE572}" = protocol=17 | dir=in | app=d:\program files\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\dedicated\xr_3da.exe |
"{884C0214-E5EC-48FA-91B3-10C8777F326F}" = protocol=6 | dir=in | app=d:\program files\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\dedicated\xr_3da.exe |
"{89BBC071-8908-4460-A7B4-6F8A8F8BF845}" = protocol=6 | dir=in | app=c:\program files\acer zone\acer picture slide dvd\component\clsldvd.exe |
"{92791BE2-254D-4CCE-8E81-373A0DEC1921}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{954E4407-A0BD-4F1A-9CF9-75487AED7AE1}" = protocol=6 | dir=in | app=c:\program files\acer zone\acer plug and record\component\dvax2process.exe |
"{95859EB9-E3FE-447A-AB74-6C66E8FE00C5}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-0.3.0.10571-to-0.3.0.10596-enus-ptr-downloader.exe |
"{9670EFFB-4C48-4811-80C1-EBFD813CE114}" = protocol=6 | dir=in | app=d:\world of warcraft ps\backgrounddownloader.exe |
"{969E8518-922A-4D9F-B3AE-EDA7FD994711}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe |
"{9C5A90EA-8C90-40EB-B360-F57DEBC65F02}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-0.3.0.10554-to-0.3.0.10571-enus-ptr-downloader.exe |
"{9FF30AB1-6D96-464A-B6AC-5F6676B6D132}" = protocol=17 | dir=in | app=d:\world of warcraft ps\backgrounddownloader.exe |
"{A1987ECD-2321-42DB-B9C0-7DB176A8F5D5}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{A850B542-5E0D-45F4-897F-57F4C005BE85}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{AA7A3A9C-5DA7-4CA1-B385-8B2565DA73D4}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{AB99C17F-678B-44DA-85E8-CC6DBF042482}" = protocol=17 | dir=in | app=d:\program files\smartftp client\smartftp.exe |
"{ACF88DCE-FA43-4EE6-9A89-6E9E183B906F}" = protocol=17 | dir=in | app=d:\combat arms\nmservice.exe |
"{AD5C0732-F722-4859-AE16-B32CE74E0916}" = protocol=6 | dir=in | app=c:\program files\acer zone\acer zone main page\mce deluxe suite.exe |
"{AF26E52A-F89F-4D07-B5F2-4E96A67723DC}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-0.3.0.10522-to-0.3.0.10554-enus-ptr-downloader.exe |
"{B7907916-D45F-467D-B166-54E8D6824F90}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{BBD9AD56-056D-4ABF-811F-5D3280A5511E}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-0.3.0.10554-to-0.3.0.10571-enus-ptr-downloader.exe |
"{BF3AEAD9-D747-45C9-ACF6-C41566EE1CED}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{C0024237-3E77-491F-98D8-827F95B5EC16}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{C31A35D3-376F-4F94-9B28-0A63448A24C1}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe |
"{C4694198-63D5-483E-A87C-87E8BEFEAE57}" = protocol=6 | dir=in | app=c:\program files\acer zone\acer plug and record\component\arawp.exe |
"{C47E397A-0BD7-49CC-8014-8E209657F25F}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{C60F270B-F38C-42B1-9FC0-9475126F2C27}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C77F3757-EB3F-4851-8F9F-24F743561F01}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{CBA2C7D8-8D2B-4D50-A3B9-D8CD3E6867FC}" = protocol=6 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{CE5BC572-45FC-425A-9A16-167D328EEA00}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"{CF72FB78-EAD1-4A47-BC94-CF5B99122B34}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{CF99901E-C817-4C67-83BB-B096D8AF0CFD}" = protocol=17 | dir=in | app=c:\program files\acer zone\acer plug and record\component\arawp.exe |
"{CFFB5CC4-0371-4218-A146-EC52277CBDCB}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{D1B8133B-9347-4BF5-BE0B-A6C1C11805C9}" = protocol=6 | dir=in | app=d:\combat arms\nmservice.exe |
"{D3A3E982-306F-4481-BB85-C7616A14811D}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-0.3.0.10522-to-0.3.0.10554-enus-ptr-downloader.exe |
"{D3D73BCE-9299-4D35-A897-D6A121C99D00}" = protocol=6 | dir=in | app=c:\users\michael\desktop\hacks\hiv.exe |
"{D5A7ECFD-4E6C-4BDC-96F7-0B8860C7CF9A}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{D669B33E-B05B-40ED-9BDD-44675FB5D4EE}" = dir=in | app=c:\program files\avg\avg9\avgemc.exe |
"{D9EFF23B-89B5-46F1-87D8-064ADA40B8E5}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{DA03857F-513D-4FBA-95A5-F346CBB0304D}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{DC16D869-87FE-4887-87D2-0D20C84FFB22}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe |
"{E758B8F6-DBB4-4FEC-986D-1F7F103176AC}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe |
"{EDAE6165-B53F-4736-8ED2-31D3053D0C07}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{F83598BE-AC2A-4EED-A7F4-83C8E99DB965}" = protocol=17 | dir=in | app=c:\program files\acer zone\acer plug and record\component\dvax2process.exe |
"{F8E35B0B-6F7C-4F5A-8D72-C769E1F953EF}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-0.3.0.10522-enus-ptr-downloader.exe |
"{F9763A84-6AE8-4A8D-880F-A26FE5EFEA7E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{FB0ACEEA-FE28-435B-AA04-A1C2C3F1BAEA}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{FC9747AD-836F-4D94-9141-F7EF90B232BE}" = protocol=17 | dir=in | app=c:\users\michael\desktop\hacks\hiv.exe |
"{FCBAD027-9CF6-4B8C-980C-1BAE666EBD9A}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"{FDD26DE0-3FA3-4484-8CBC-77D4A84DF05E}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe |
"TCP Query User{0778D959-3EF1-4D7C-A27C-55D987DFF8E0}C:\program files\steam\steamapps\sgtbaker\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\sgtbaker\counter-strike source\hl2.exe |
"TCP Query User{084866D9-5AD7-4523-B330-FEEBBBF87E76}D:\program files\valve\half-life\hl.exe" = protocol=6 | dir=in | app=d:\program files\valve\half-life\hl.exe |
"TCP Query User{12E6DC48-0D52-4C2A-8784-16C1A55BB62E}C:\program files\steam\steamapps\twocrazymen23\garrysmod\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\twocrazymen23\garrysmod\hl2.exe |
"TCP Query User{1A9E03F0-B364-49D3-B569-9D0C2F02E278}C:\program files\steam\steamapps\enkouchan\garrysmod\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\enkouchan\garrysmod\hl2.exe |
"TCP Query User{1CF0D186-7D47-4E53-A2AE-EE9C25FAB7F5}C:\program files\steam\steamapps\twocrazymen23\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\twocrazymen23\counter-strike source\hl2.exe |
"TCP Query User{21E9165B-757D-41A2-B7F4-EE54493DA459}D:\world of warcraft public test\launcher.exe" = protocol=6 | dir=in | app=d:\world of warcraft public test\launcher.exe |
"TCP Query User{2D5077FA-99CD-4A6C-873C-B2FF92C8AD9B}C:\program files\steam\steamapps\enkouchan\ricochet\hl.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\enkouchan\ricochet\hl.exe |
"TCP Query User{4C76D329-AFCB-4836-9DF0-326BBAE89FDD}C:\program files\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files\mirc\mirc.exe |
"TCP Query User{57076E6F-F4AE-4D43-8F3F-EF59CA002EB9}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{5B938AF2-0383-4FAD-9BE6-B0BEDC0FFF73}C:\program files\steam\steamapps\pwner553\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\pwner553\counter-strike source\hl2.exe |
"TCP Query User{88D600F5-9C0B-48D0-99A4-824A78B318E8}C:\program files\steam\steamapps\pwner553\garrysmod\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\pwner553\garrysmod\hl2.exe |
"TCP Query User{8ECD5F4F-0EF6-416A-9AAF-D01E46E57724}C:\windows\system32\java.exe" = protocol=6 | dir=in | app=c:\windows\system32\java.exe |
"TCP Query User{98944721-2A7F-401B-A78B-648CC51A95E6}C:\webserver\xampp\mysql\bin\mysqld.exe" = protocol=6 | dir=in | app=c:\webserver\xampp\mysql\bin\mysqld.exe |
"TCP Query User{AD616A91-F7EC-4062-AA67-1B1046C1F3B8}C:\program files\steam\steamapps\enkouchan\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\enkouchan\counter-strike source\hl2.exe |
"TCP Query User{B7A305FF-9309-4422-B420-3C069B235709}C:\webserver\xampp\apache\bin\apache.exe" = protocol=6 | dir=in | app=c:\webserver\xampp\apache\bin\apache.exe |
"TCP Query User{C598F16A-A519-421B-8324-23BDF5F28899}C:\program files\steam\steamapps\core435\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\core435\counter-strike source\hl2.exe |
"TCP Query User{CC2C4D75-009E-4870-9012-A0EB7DF1FF09}C:\program files\steam\steamapps\pwner553\counter-strike\hl.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\pwner553\counter-strike\hl.exe |
"TCP Query User{DDAFD525-CD04-498A-A56E-226C03062E8F}D:\world of warcraft ps\launcher.exe" = protocol=6 | dir=in | app=d:\world of warcraft ps\launcher.exe |
"TCP Query User{DFC64B3F-B45F-48D6-A308-B7EC1F4259AF}D:\program files\wolfenstein - enemy territory\et.exe" = protocol=6 | dir=in | app=d:\program files\wolfenstein - enemy territory\et.exe |
"TCP Query User{E4DF2091-B164-47BF-B936-D50982B1CB76}C:\program files\ventsrv\ventrilo_srv.exe" = protocol=6 | dir=in | app=c:\program files\ventsrv\ventrilo_srv.exe |
"TCP Query User{EEE1FA31-35EE-447F-9289-2AF7F2FD318A}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{06BF7D5E-D77F-46BE-B391-0795FD03A5D0}C:\program files\steam\steamapps\sgtbaker\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\sgtbaker\counter-strike source\hl2.exe |
"UDP Query User{18E738D0-104B-49EA-A2D6-3332AC90E090}C:\program files\steam\steamapps\pwner553\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\pwner553\counter-strike source\hl2.exe |
"UDP Query User{3A7D0D43-3E22-40A7-B829-0E9B7EBF3EC5}C:\program files\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files\mirc\mirc.exe |
"UDP Query User{51122165-718F-4412-8EC8-C09D5A48FFC7}D:\world of warcraft public test\launcher.exe" = protocol=17 | dir=in | app=d:\world of warcraft public test\launcher.exe |
"UDP Query User{5273E7D1-45E1-4F58-9570-C105BCFE16F2}C:\windows\system32\java.exe" = protocol=17 | dir=in | app=c:\windows\system32\java.exe |
"UDP Query User{5A1306D1-2ED6-4865-AECD-D2122C399E5D}C:\program files\steam\steamapps\pwner553\garrysmod\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\pwner553\garrysmod\hl2.exe |
"UDP Query User{62D948FB-84A0-4A63-ABBD-AAE964486514}C:\webserver\xampp\mysql\bin\mysqld.exe" = protocol=17 | dir=in | app=c:\webserver\xampp\mysql\bin\mysqld.exe |
"UDP Query User{66DDE59E-7511-4D99-84F0-55C679CB9FCF}C:\webserver\xampp\apache\bin\apache.exe" = protocol=17 | dir=in | app=c:\webserver\xampp\apache\bin\apache.exe |
"UDP Query User{7BE51F73-91CF-4AB1-8FED-07D3184B0387}D:\program files\valve\half-life\hl.exe" = protocol=17 | dir=in | app=d:\program files\valve\half-life\hl.exe |
"UDP Query User{8290A9A4-0B9A-4716-B27A-AF497C36507A}C:\program files\steam\steamapps\enkouchan\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\enkouchan\counter-strike source\hl2.exe |
"UDP Query User{835E2B49-EADA-4E39-99FB-E74695DE4BBA}D:\world of warcraft ps\launcher.exe" = protocol=17 | dir=in | app=d:\world of warcraft ps\launcher.exe |
"UDP Query User{8629AA92-A593-40EA-8D22-DB7DEEDDF69A}C:\program files\steam\steamapps\enkouchan\garrysmod\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\enkouchan\garrysmod\hl2.exe |
"UDP Query User{8630B0F7-7528-4E0B-A3AB-7DA1B5B9A3B1}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{9F96D305-FA2B-49DA-90E2-BD6652A8BA37}D:\program files\wolfenstein - enemy territory\et.exe" = protocol=17 | dir=in | app=d:\program files\wolfenstein - enemy territory\et.exe |
"UDP Query User{BC9338C3-ED63-46AD-ACE9-D9F4E95DA452}C:\program files\steam\steamapps\pwner553\counter-strike\hl.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\pwner553\counter-strike\hl.exe |
"UDP Query User{C1958EAB-4B88-4C4A-8A4E-0881F8E77D02}C:\program files\steam\steamapps\core435\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\core435\counter-strike source\hl2.exe |
"UDP Query User{C6F44333-F8EE-4664-9F20-128084CFB384}C:\program files\steam\steamapps\twocrazymen23\garrysmod\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\twocrazymen23\garrysmod\hl2.exe |
"UDP Query User{D6A3AB4A-B202-4A5C-846D-561E3E7469CF}C:\program files\ventsrv\ventrilo_srv.exe" = protocol=17 | dir=in | app=c:\program files\ventsrv\ventrilo_srv.exe |
"UDP Query User{E0E424E4-9335-41E8-A1C5-6154427F32E6}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{E7C70071-6A4E-4CF4-A21E-67CB1A0DF166}C:\program files\steam\steamapps\twocrazymen23\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\twocrazymen23\counter-strike source\hl2.exe |
"UDP Query User{FF83208A-8840-49BF-A8B2-632E1F60DF76}C:\program files\steam\steamapps\enkouchan\ricochet\hl.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\enkouchan\ricochet\hl.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{02EBDBB9-4600-41D3-B566-40CB861511D2}" = World of Warcraft FREE Trial
"{03DEEAD2-F3B7-45BF-9006-A25D015F00D2}" = Adobe Flash Player 10 Plugin
"{044F9133-B8D7-4d11-BF39-803FA20F5C8B}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{05EC21B8-4593-3037-A781-A6B5AFFCB19D}" = Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools - enu
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0C19D563-5F25-4621-BF10-01F741BD283F}" = Microsoft SQL Server Compact 3.5 SP1 Design Tools English
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0DF3AE91-E533-3960-8516-B23737F8B7A2}" = Visual C++ 2008 x64 Runtime - (v9.0.30729)
"{0DF3AE91-E533-3960-8516-B23737F8B7A2}.vc_x64runtime_30729_01" = Visual C++ 2008 x64 Runtime - v9.0.30729.01
"{0ED1A22E-39F3-0B9A-FFDC-33ABCEE505C0}" = Skins
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1D46A3A0-B37D-423A-91C2-101A49E2FF80}" = Ventrilo Server
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2168245A-B5AD-40D8-A641-48E3E070B5B6}" = Adobe Flash CS4 STI-en
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{22E23C71-C27A-3F30-8849-BB6129E50679}" = Visual C++ 2008 IA64 Runtime - (v9.0.30729)
"{22E23C71-C27A-3F30-8849-BB6129E50679}.vc_i64runtime_30729_01" = Visual C++ 2008 IA64 Runtime - v9.0.30729.01
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23A858EF-56C9-408A-B1F0-A0E40124FF8A}" = SmartFTP Client
"{241F2BF7-69EB-42A4-9156-96B2426C7504}" = Microsoft SQL Server Compact 3.5 for Devices ENU
"{24508D50-EB8F-4FE6-B69D-B4935D8745EF}_is1" = Warsow 0.42
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 13
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{291B3A3B-F808-45B8-8113-DF232FCB6C82}" = Microsoft .NET Compact Framework 3.5
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
"{32A3A4F4-B792-11D6-A78A-00B0D0160120}" = Java™ SE Development Kit 6 Update 12
"{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}" = SQL Server System CLR Types
"{35CB6715-41F8-4F99-8881-6FC75BF054B0}" = Oblivion
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3A6829EF-0791-4FDD-9382-C690DD0821B9}" = Adobe Flash Player 10 ActiveX
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C11D2DA-6802-3F66-BE6B-B2C046AFE866}" = Visual C++ 2008 x64 Runtime - (v9.0.30729.4148)
"{3C11D2DA-6802-3F66-BE6B-B2C046AFE866}.vc_x64runtime_30729_4148" = Visual C++ 2008 x64 Runtime - v9.0.30729.4148
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{4402084F-61EE-48B2-AFCB-AC1EC2454C79}" = MySQL Server 5.1
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{49253DE2-FC99-4BE3-99A4-DAB01A8E6088}" = Camtasia Studio 6
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{5A3E8FF2-F163-2B00-9B47-D8C84CF12C7A}" = Catalyst Control Center InstallProxy
"{5B3A354B-C059-4861-A85B-CA46F1089E15}" = Creative USB Headsets
"{5BE1E709-30E4-3D6D-A708-96CE8D5E5E8D}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{6468C32A-026A-37DD-A013-C8A8B0995B52}" = Catalyst Control Center Graphics Light
"{64c5b887-b5ee-42b8-8596-78905a6b5f1f}" = Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense
"{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008
"{67A58A97-9612-C607-0245-F3F417EFDB6D}" = Catalyst Control Center Core Implementation
"{67ADE9AF-5CD9-4089-8825-55DE4B366799}" = NTI Backup NOW! 4.7
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69F6B6BC-D64C-BE30-6334-C7A76E9FF2AD}" = CCC Help English
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6C9F6D23-E9AD-43C9-B43A-011562AAF876}" = Windows Mobile 5.0 SDK R2 for Pocket PC
"{6F2A00E1-46C9-6DAE-E6E3-BEE4C9D5A0C3}" = ccc-core-static
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.3.4.107
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{793D1D88-6141-43DE-BE58-59BCE31B4090}" = Adobe Flash CS4 Extension - Flash Lite STI en
"{7B33F480-496D-334A-BAC2-205DEC0CBC2D}" = Visual C++ 2008 x86 Runtime - (v9.0.30729.4148)
"{7B33F480-496D-334A-BAC2-205DEC0CBC2D}.vc_x86runtime_30729_4148" = Visual C++ 2008 x86 Runtime - v9.0.30729.4148
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{80C06CCD-7D07-3DB6-86CD-B57B3F0614D8}" = Microsoft Visual Studio Team System 2008 Team Suite - ENU
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{842FAF7C-50EF-4463-9B8F-6222E1384D7D}" = Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
"{8AC049F7-1383-45C3-9E7D-F93CA667F9E1}" = UMVPLStandalone
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0021-0000-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer 2007
"{90120000-0021-0000-0000-0000000FF1CE}_VisualWebDeveloper_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0021-0409-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9656F3AC-6BA9-43F0-ABED-F214B5DAB27B}" = Windows Mobile 5.0 SDK R2 for Smartphone
"{998D6972-F58E-479D-9248-8F179E55AE38}" = Java DB 10.4.1.3
"{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}" = iTunes
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A33B83D-FFC4-44CF-BEEF-632DECEF2FCD}" = Microsoft SQL Server Database Publishing Wizard 1.3
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9cc89170-000b-457d-91f1-53691f85b223}" = Python 2.6.1
"{9D1DE3AD-75C5-9C43-3F07-206600BB2D30}" = Catalyst Control Center Graphics Full New
"{9F827E95-123C-EAA5-6CCD-9D9E8FC2A80E}" = ATI Catalyst Install Manager
"{A035580E-3EDF-EA34-F229-0E17DF3A6E7C}" = ccc-utility
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3797713-6859-379F-4E0C-ADCB3BE3C87E}" = Catalyst Control Center Graphics Previews Common
"{A5D254CC-7E37-48D6-A013-895A9A4EB91E}" = Quake Live Internet Explorer Plugin
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA467959-A1D6-4F45-90CD-11DC57733F32}" = Crystal Reports Basic for Visual Studio 2008
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{AFF84D5E-EB68-728E-1BD5-10BCFDCF25FF}" = Catalyst Control Center HydraVision Full
"{B268E9A1-04A9-40D0-9866-846BE2B74BA7}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Win32 Tools
"{B28FC790-C93F-3A9C-A913-7E891487D1F1}" = Visual C++ 2008 IA64 Runtime - (v9.0.30729.4148)
"{B28FC790-C93F-3A9C-A913-7E891487D1F1}.vc_i64runtime_30729_4148" = Visual C++ 2008 IA64 Runtime - v9.0.30729.4148
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B32E7732-B2FB-3FD0-81AC-6025B1104C66}" = Microsoft Device Emulator version 3.0 - ENU
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C337BDAF-CB4E-47E2-BE1A-CB31BB7DD0E3}" = Apple Mobile Device Support
"{C357E7BE-A832-CFAF-A1B2-23EC0C08011E}" = Catalyst Control Center Graphics Previews Vista
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CAA376AF-0DE8-4FCA-942E-C6AC579B94B3}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Tools
"{CC016F21-3970-11DE-B878-005056806466}" = Google Earth
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D244622B-F2BC-AD1E-6BA6-40345EC55BAA}" = Catalyst Control Center Graphics Full Existing
"{D3B1C799-CB73-42DE-BA0F-2344793A095C}" = Catalyst Control Center - Branding
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{D8087907-E255-3A41-A46D-D0F798709C71}" = Microsoft Visual C++ 2008 Express Edition with SP1 - ENU
"{DD622B1D-A78E-3FE8-9C8C-246F5764B0D0}" = Microsoft Visual Basic 2008 Express Edition with SP1 - ENU
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{E1180142-3B31-4DCC-9D27-7AC2D37662BF}" = LightScribe 1.4.124.1
"{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English
"{E5CFDA19-A86E-4276-AB8E-5165E2FC98B8}" = Hero_Online
"{E5FCED12-3E77-4C0E-A305-5AEB38A52A70}" = AdobeColorCommonSetCMYK
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator
"{EB3F5C2A-0754-38B8-8722-7B537006BF46}" = Microsoft Visual Studio 2008 Performance Collection Tools - ENU
"{EC42ED6A-751D-45C0-A4F9-8CD00E4690FC}" = Logitech QuickCam
"{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin
"{EDDF99D9-9FE3-4871-A7DB-D1522C51EE9A}" = Microsoft .NET Compact Framework 2.0 SP2
"{EED50C97-C79E-4149-BD82-7C5A22437708}" = Adobe Setup
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1A14CB2-A048-45A6-AFDA-3571296E1D76}" = Creative Media Toolbox 6
"{F2E36994-BCB8-4035-B45A-4F37D64BFC8F}" = Jiffy Gmail Creator
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F5E87B12-3C27-452F-8E78-21D42164FD83}" = Microsoft SQL Server 2008 Management Objects
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FC2642E7-9CA0-49A2-B785-2647699E571A}" = Jiffy Gmail Creator
"{FCA37CD2-7BA4-4A5A-8979-B64EA712F4CB}" = TortoiseSVN 1.6.2.16344 (32 bit)
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup
"{FF29527A-44CD-3422-945E-981A13584000}" = VC Runtimes MSI
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3
"Adobe_a68eec966ce913ddaa63251dc82ed31" = Adobe Flash CS4 Professional
"Advanced Port Scanner v1.3" = Advanced Port Scanner v1.3
"AIM_6" = AIM 6
"ALchemy X-Fi" = Creative ALchemy (X-Fi Edition)
"AV Voice Changer Software DIAMOND 6.0" = AV Voice Changer Software DIAMOND 6.0
"AVG9Uninstall" = AVG 9.0
"Cavaj Java Decompiler" = Cavaj Java Decompiler
"Cheat Engine 5.5_is1" = Cheat Engine 5.5
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Combat Arms" = Combat Arms
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Diablo II" = Diablo II
"Diablo II Shareware" = Diablo II Shareware
"Google Updater" = Google Updater
"Guitar Pro 5_is1" = Guitar Pro 5.2
"Half-Life_is1" = Half-Life
"HotspotShield" = Hotspot Shield 1.30
"HxD Hex Editor_is1" = HxD Hex Editor version 1.7.7.0
"IDA Pro Free_is1" = IDA Pro Free v4.9
"ImgBurn" = ImgBurn
"InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"JCreator Pro_is1" = JCreator Pro 4.50
"LimeWire" = LimeWire 5.1.2
"Magic ISO Maker v5.5 (build 0261)" = Magic ISO Maker v5.5 (build 0261)
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Visual Basic 2008 Express Edition with SP1 - ENU" = Microsoft Visual Basic 2008 Express Edition with SP1 - ENU
"Microsoft Visual C++ 2008 Express Edition with SP1 - ENU" = Microsoft Visual C++ 2008 Express Edition with SP1 - ENU
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Microsoft Visual Studio Team System 2008 Team Suite - ENU" = Microsoft Visual Studio Team System 2008 Team Suite - ENU
"mIRC" = mIRC
"Mozilla Firefox (3.0.14)" = Mozilla Firefox (3.0.14)
"No-IP.com DUC" = No-IP.com DUC (remove only)
"PremiumSoft Navicat Lite 8.2_is1" = PremiumSoft Navicat Lite 8.2
"PunkBusterSvc" = PunkBuster Services
"QcDrv" = Logitech® Camera Driver
"Renoise 2.0.0_is1" = Renoise 2.0.0
"S.T.A.L.K.E.R. - Shadow of Chernobyl_is1" = S.T.A.L.K.E.R. - Shadow of Chernobyl [v1.0004]
"Sandboxie" = Sandboxie 3.38
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SmartFTP Client 3.0 Setup Files" = SmartFTP Client 3.0 Setup Files (remove only)
"ST6UNST #1" = Hero Editor V0.96
"Steam App 10" = Counter-Strike
"Steam App 215" = Source SDK Base
"Steam App 240" = Counter-Strike: Source
"Steam App 300" = Day of Defeat: Source
"Steam App 4000" = Garry's Mod
"Steam App 60" = Ricochet
"SvenCoop" = Sven Co-op 4.0B
"SysInfo" = Creative System Information
"System_0" = System error's toolkit 1.0
"SystemRequirementsLab" = System Requirements Lab
"Uninstaller_B4736000_Creative Media Toolbox 6" = Creative Media Toolbox 6 (Shared Components)
"VB Decompiler Lite_is1" = VB Decompiler Lite
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime
"VisualWebDeveloper" = Microsoft Visual Studio Web Authoring Component
"Warcraft III" = Warcraft III
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Wolfenstein - Enemy Territory" = Wolfenstein - Enemy Territory
"World of Warcraft" = World of Warcraft
"xampp" = XAMPP 1.7.0
"Xvid_is1" = Xvid 1.2.1 final uninstall
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Diablo II Shareware" = Diablo II Shareware
"ScapeRune 513 v1.8" = ScapeRune 513 v1.8
"uTorrent" = µTorrent
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/20/2009 7:32:41 PM | Computer Name = Michael-PC | Source = Application Error | ID = 1000
Description = Faulting application hl2.exe, version 0.0.0.0, time stamp 0x470c11ae,
faulting module materialsystem.dll, version 0.0.0.0, time stamp 0x48acb3f5, exception
code 0xc0000005, fault offset 0x00014e6a, process id 0x1328, application start time
0x01ca51d317e0ec61.

Error - 10/21/2009 8:08:41 PM | Computer Name = Michael-PC | Source = Application Error | ID = 1000
Description = Faulting application hl2.exe, version 0.0.0.0, time stamp 0x470c11ae,
faulting module materialsystem.dll, version 0.0.0.0, time stamp 0x48acb3f5, exception
code 0xc0000005, fault offset 0x00014e6a, process id 0x1788, application start time
0x01ca52935cde9dac.

Error - 10/23/2009 10:19:28 PM | Computer Name = Michael-PC | Source = Application Error | ID = 1000
Description = Faulting application AcroRd32.exe, version 7.0.0.0, time stamp 0x41bee02d,
faulting module ntdll.dll, version 6.0.6000.16386, time stamp 0x4549bdc9, exception
code 0xc0000005, fault offset 0x0002294f, process id 0xa18, application start time
0x01ca5450604b68c0.

Error - 10/24/2009 1:08:43 PM | Computer Name = Michael-PC | Source = VSS | ID = 8194
Description =

Error - 10/24/2009 1:29:02 PM | Computer Name = Michael-PC | Source = SDWinSec.exe | ID = 0
Description =

Error - 10/24/2009 1:32:37 PM | Computer Name = Michael-PC | Source = VSS | ID = 8194
Description =

Error - 10/24/2009 1:51:02 PM | Computer Name = Michael-PC | Source = VSS | ID = 8194
Description =

Error - 10/24/2009 1:56:20 PM | Computer Name = Michael-PC | Source = VSS | ID = 8194
Description =

Error - 10/24/2009 3:24:29 PM | Computer Name = Michael-PC | Source = EventSystem | ID = 4609
Description =

Error - 10/24/2009 3:43:02 PM | Computer Name = Michael-PC | Source = EventSystem | ID = 4609
Description =

[ System Events ]
Error - 10/24/2009 3:24:31 PM | Computer Name = Michael-PC | Source = DCOM | ID = 10005
Description =

Error - 10/24/2009 3:25:04 PM | Computer Name = Michael-PC | Source = DCOM | ID = 10005
Description =

Error - 10/24/2009 3:40:21 PM | Computer Name = Michael-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 2:38:28 PM on 10/24/2009 was unexpected.

Error - 10/24/2009 3:42:55 PM | Computer Name = Michael-PC | Source = DCOM | ID = 10005
Description =

Error - 10/24/2009 3:43:02 PM | Computer Name = Michael-PC | Source = DCOM | ID = 10005
Description =

Error - 10/24/2009 3:43:04 PM | Computer Name = Michael-PC | Source = DCOM | ID = 10005
Description =

Error - 10/24/2009 3:43:04 PM | Computer Name = Michael-PC | Source = DCOM | ID = 10005
Description =

Error - 10/24/2009 3:43:04 PM | Computer Name = Michael-PC | Source = DCOM | ID = 10005
Description =

Error - 10/24/2009 3:43:37 PM | Computer Name = Michael-PC | Source = DCOM | ID = 10005
Description =

Error - 10/24/2009 3:46:46 PM | Computer Name = Michael-PC | Source = Service Control Manager | ID = 7000
Description =


< End of report >
Go to the top of the page
 
+Quote Post
Raktor
post Oct 25 2009, 10:17 PM
Post #2


Trusted Helper
Group Icon
Posts: 212
OS: Windows 7 Professional x64 RTM, Mac OS X 10.5



Hi, welcome to the G2G Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:

  • Absence of symptoms does not always mean the computer is clean
  • Please do not run any scans or fixes without my direction.
  • Finally, stay with this topic until I give you the final 'All clear' post.


1) exeHelper
Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

2) DDS

Please download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop.


3) RR
Please download RootRepeal.zip.
Save it to your Desktop. Alternate download links here or here.
Please print these instructions, you will not have an Internet connection!
If you have a 3rd party "unzipping" program...use it to open the zipped file...then skip to Step 5. Otherwise...
  1. Right click on RootRepeal.zip and select "Extract All"....
  2. Click Next on the "Welcome to the Compressed (zipped) Folders Extraction Wizard."
  3. Click on the Browse...button, then click on Desktop, then click OK.
  4. Once done, check (tick) the Show extracted files box and click Finish.
  5. Before running RootRepeal:
      Disconnect from the Internet as your system will be unprotected while using this tool.
      Close all programs and temporarily disable your anti-virus, Firewall and any anti-malware real-time protection before performing a scan.
  6. Open the RootRepeal folder and double-click on RootRepeal.exe to launch it.
  7. When the program opens, click the Report tab at the bottom, then click the Scan button.
  8. In the Select Scan, dialog which asks What do you want to include in the scan?, check ALL the boxes.
  9. Click OK.
  10. In the Select Drives, dialog Please select drives to scan: select all drives showing, then click OK.
    The scan can take some time to finish. Do not use the computer while the scan is running.
    When the scan has completed, a list of files will be generated in the RootRepeal window.
  11. Click on the Save Report button and save it as "rootrepeal.txt" to your desktop.
  12. Close and exit RootRepeal
  13. Double-click on the file rootrepeal.txt... Notepad will open... copy/paste the file contents in your next reply.


Make sure to enable your anti-virus, Firewall and any other security programs you disabled.
Note: If RootRepeal cannot complete a scan and results in a crash report, try repeating the scan in "safe mode".

4) What You Will Need To Post:
  • exeHelper log
  • DDS logs
  • RR log
Go to the top of the page
 
+Quote Post
Michael435
post Oct 26 2009, 07:20 AM
Post #3


New Member
*
Posts: 6
OS: Windows Vista



exeHelper instantly closes, says something but I can't see it

DDS will run but - "The Process cannot access the file because it is bsing used by another process." x2

Rootrepeal gets a [bleep]load of memory read errors, probably same reason, the virus is using all of the access points. Crashes and gives me no log.
Go to the top of the page
 
+Quote Post
Raktor
post Oct 26 2009, 05:35 PM
Post #4


Trusted Helper
Group Icon
Posts: 212
OS: Windows 7 Professional x64 RTM, Mac OS X 10.5



Please redownload exeHelper from here. It will be called explorer.exe.

Run that, and post the log produced (if it doesn't close instantly).
Go to the top of the page
 
+Quote Post
Michael435
post Oct 26 2009, 06:47 PM
Post #5


New Member
*
Posts: 6
OS: Windows Vista



exeHelper by Raktor
Build 20091021
Run at 19:46:57 on 10/26/09
Now searching...
Checking for numerical processes...
Checking for bad processes...
Checking for bad files...
Deleting file C:\Users\Michael\Start Menu\Programs\Startup\scandisk.lnk
Checking for bad registry entries...
Removing HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A2234B15-23F2-42AD-F4E4-00AAC39C0004}
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values...
Resetting policies...


DDS (Ver_09-10-26.01) - NTFSx86
Run by Michael at 19:48:28.93 on Mon 10/26/2009
Internet Explorer: 7.0.6000.16916
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1022.488 [GMT -5:00]

AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Internet Security *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Windows\system32\lsm.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
D:\TSVN\bin\TSVNCache.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
D:\Program Files\Creative\USB Headsets\Volume Panel\VolPanlu.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Logitech\QuickCam10\COCIManager.exe
C:\Program Files\Common Files\Steam\SteamService.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Michael\Desktop\dds.pif
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://google.com/
uSEARCH PAGE = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://en.us.acer.yahoo.com
mDefault_Page_URL = hxxp://en.us.acer.yahoo.com
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: Web Test Recorder 9.0: {3c7adade-d1e8-45d2-bdcd-7f8d8b99b2a2} - mscoree.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [????r]
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [Speech Recognition] "c:\windows\speech\common\sapisvr.exe" -SpeechUX -Startup
uRun: [cdloader] "c:\users\michael\appdata\roaming\mjusbsp\cdloader2.exe" MAGICJACK
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [eRecoveryService]
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logitech\lcommgr\Communications_Helper.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam10\QuickCam10.exe" /hide
mRun: [LVCOMSX] "c:\program files\common files\logitech\lcommgr\LVComSX.exe"
mRun: [VolPanel] "d:\program files\creative\usb headsets\volume panel\VolPanlu.exe" /r
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [MSConfig] "c:\windows\system32\msconfig.exe" /auto
mExplorerRun: [explorer32] c:\windows\system32\spy-net\WinHelper32.exe.exe
StartupFolder: c:\users\michael\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\empowe~1.lnk - c:\acer\empowering technology\eAPLauncher.exe
mPolicies-system: EnableLUA = 0 (0x0)
LSP: c:\windows\system32\wpclsp.dll
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.systemrequirementslab.com/srl_bin/sysreqlab_srl.cab
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: avgrsstx.dll
STS: c:\windows\system32\zkcw2lfbht.dll: {a2234b15-23f2-42ad-f4e4-00aac39c0004} - c:\windows\system32\zkcw2lfbht.dll
mASetup: {66GQ7556-22WN-35GR-E1TH-QSTQN766Q5L8} - c:\windows\system32\spy-net\WinHelper32.exe.exe Restart

================= FIREFOX ===================

FF - ProfilePath - c:\users\michael\appdata\roaming\mozilla\firefox\profiles\3xm87rlz.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\program files\google\google updater\2.4.1591.6512\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

============= SERVICES / DRIVERS ===============

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-10-24 161800]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-10-24 333192]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-10-24 360584]
R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2009-10-24 906520]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-10-24 285392]
R3 HssDrv;Hotspot Shield Helper Miniport;c:\windows\system32\drivers\HssDrv.sys [2009-9-15 37376]
R3 skfiltv;skfiltv;c:\windows\system32\drivers\skfiltv.sys [2009-10-6 17408]
R3 taphss;Anchorfree HSS Adapter;c:\windows\system32\drivers\taphss.sys [2009-9-15 32768]
S2 gupdate1c9d9ba82edd358;Google Update Service (gupdate1c9d9ba82edd358);c:\program files\google\update\GoogleUpdate.exe [2009-5-20 133104]
S3 SbieDrv;SbieDrv;c:\program files\sandboxie\SbieDrv.sys [2009-5-28 108032]
S3 VSPerfDrv90;Performance Tools Driver 9.0;c:\program files\microsoft visual studio 9.0\team tools\performance tools\VSPerfDrv90.sys [2007-9-4 55664]
S4 Creative ALchemy AL1 Licensing Service;Creative ALchemy AL1 Licensing Service;c:\program files\common files\creative labs shared\service\AL1Licensing.exe [2009-10-6 79360]
S4 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2009-10-6 79360]
S4 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files\common files\creative labs shared\service\MT6Licensing.exe [2009-10-6 79360]
S4 HssSrv;Hotspot Shield Routing Service;c:\program files\hotspot shield\hsswpr\hsssrv.exe [2009-9-15 331824]
S4 HssTrayService;Hotspot Shield Tray Service;c:\program files\hotspot shield\bin\HssTrayService.exe [2009-9-15 57640]
S4 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
SUnknown {79007602-0CDB-4405-9DBF-1257BB3226EE};{79007602-0CDB-4405-9DBF-1257BB3226EE}; [x]

=============== Created Last 30 ================

2009-10-24 19:19:01 0 d--h--w- c:\windows\PIF
2009-10-24 19:05:11 0 d-----w- c:\users\michael\appdata\roaming\Malwarebytes
2009-10-24 19:05:06 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-24 19:05:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-24 19:05:04 0 d-----w- c:\programdata\Malwarebytes
2009-10-24 19:05:04 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-24 17:47:46 0 d--h--w- C:\$AVG
2009-10-24 17:47:40 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-10-24 17:47:39 161800 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-10-24 17:47:38 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-10-24 17:47:27 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-10-24 17:47:06 0 d-----w- c:\windows\system32\drivers\Avg
2009-10-24 17:46:20 0 d-----w- c:\program files\AVG
2009-10-24 17:46:19 0 d-----w- c:\programdata\avg9
2009-10-24 02:19:41 0 ----a-w- c:\windows\win32k.sys
2009-10-21 21:07:21 0 d-----w- c:\program files\VentSrv
2009-10-21 21:06:35 0 d-----w- c:\program files\common files\Wise Installation Wizard
2009-10-20 20:35:42 206848 ----a-w- c:\windows\system32\telnet.exe
2009-10-19 01:43:15 0 d-----w- c:\program files\Hackers Paradise
2009-10-17 14:05:27 0 d-----w- c:\windows\SQLTools9_KB970892_ENU
2009-10-16 22:11:56 0 ----a-w- c:\windows\chatter.INI
2009-10-16 22:09:48 0 d-----w- C:\msdn
2009-10-16 20:57:00 216576 ----a-w- c:\windows\system32\msv1_0.dll
2009-10-16 20:55:45 428032 ----a-w- c:\windows\system32\EncDec.dll
2009-10-16 20:55:45 292352 ----a-w- c:\windows\system32\psisdecd.dll
2009-10-16 20:55:45 217088 ----a-w- c:\windows\system32\psisrndr.ax
2009-10-16 20:55:41 80896 ----a-w- c:\windows\system32\MSNP.ax
2009-10-16 20:55:41 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
2009-10-16 20:55:41 1244672 ----a-w- c:\windows\system32\mcmde.dll
2009-10-16 20:55:39 68608 ----a-w- c:\windows\system32\Mpeg2Data.ax
2009-10-16 20:55:39 177152 ----a-w- c:\windows\system32\mpg2splt.ax
2009-10-16 20:51:20 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-10-16 20:51:15 130048 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-10-16 20:51:11 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2009-10-13 23:22:48 0 d-----w- c:\users\michael\appdata\roaming\mjusbsp
2009-10-12 23:28:49 0 d-----w- c:\windows\system32\wbem\repository
2009-10-07 14:33:00 0 d-----w- c:\windows\system32\wbem\repository_bad2
2009-10-07 00:35:45 7062 ----a-w- c:\windows\system32\audiopid.vxd
2009-10-07 00:34:39 647872 ------w- c:\windows\system32\Mscomct2.ocx
2009-10-07 00:34:38 53248 ------w- c:\windows\Ctregrun.exe
2009-10-07 00:32:34 0 d-----w- c:\programdata\Creative
2009-10-07 00:29:03 0 d-----w- c:\program files\common files\Creative
2009-10-07 00:29:00 0 d--h--w- c:\program files\Creative Installation Information
2009-10-07 00:27:10 497152 ----a-w- c:\windows\system32\CTAPO32.dll
2009-10-07 00:27:10 47104 ----a-w- c:\windows\system32\ctppld.dll
2009-10-07 00:27:09 8704 ----a-w- c:\windows\ResDefE.exe
2009-10-07 00:27:09 52 ----a-r- c:\windows\system32\ctzapxx.ini
2009-10-07 00:27:09 25199 ----a-r- c:\windows\system32\xfisk.ini
2009-10-07 00:27:09 181760 ----a-w- c:\windows\system32\ctdvinst.dll
2009-10-07 00:27:09 17408 ----a-w- c:\windows\system32\drivers\skfiltv.sys
2009-10-07 00:27:01 381 ----a-r- c:\windows\skMCcfg.ini
2009-10-07 00:27:01 1209 ----a-r- c:\windows\skSPcfg.ini
2009-10-07 00:26:49 69120 ----a-w- c:\windows\system32\CmdRtr.DLL
2009-10-07 00:26:49 207 ---ha-r- c:\windows\ctfile.rfc
2009-10-07 00:26:49 127488 ----a-w- c:\windows\system32\APOMngr.DLL
2009-10-07 00:26:43 782336 ----a-r- c:\windows\system32\tmp71A6.tmp
2009-10-07 00:26:43 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2009-10-07 00:26:43 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2009-10-07 00:26:42 782336 ----a-r- c:\windows\system32\tmp707C.tmp
2009-10-07 00:26:41 2869728 ------w- c:\windows\system32\Sens_oal.dll
2009-10-07 00:26:24 0 d-----w- c:\programdata\Creative Labs
2009-10-07 00:24:31 0 d-----w- c:\program files\common files\Creative Labs Shared
2009-10-07 00:24:10 0 d-----w- c:\program files\Creative
2009-10-06 20:24:15 107864 ----a-w- c:\windows\system32\tsccvid.dll
2009-10-06 20:24:14 0 d-----w- c:\windows\system32\QuickTime
2009-10-06 20:23:56 0 d-----w- c:\programdata\TechSmith
2009-10-06 20:23:38 0 d-----w- c:\program files\common files\TechSmith Shared
2009-10-06 19:41:03 0 d-----w- C:\Hotspot Shield
2009-10-06 19:38:50 0 d-----w- c:\program files\Hotspot Shield
2009-10-05 18:59:45 1589248 ----a-w- c:\windows\system32\libmysql_d.dll
2009-10-05 18:59:40 0 d-----w- c:\program files\PremiumSoft
2009-10-05 18:29:32 0 d-----w- c:\programdata\MySQL
2009-10-05 18:29:32 0 d-----w- c:\program files\MySQL
2009-10-02 20:35:18 195440 ------w- c:\windows\system32\MpSigStub.exe

==================== Find3M ====================

2009-10-07 00:27:57 86016 ----a-w- c:\windows\inf\infstrng.dat
2009-10-07 00:27:57 51200 ----a-w- c:\windows\inf\infpub.dat
2009-10-07 00:27:26 86016 ----a-w- c:\windows\inf\infstor.dat
2009-09-15 20:04:58 37376 ----a-w- c:\windows\system32\drivers\HssDrv.sys
2009-09-15 20:04:58 32768 ----a-w- c:\windows\system32\drivers\taphss.sys
2009-09-13 14:03:18 92464 ---ha-w- c:\windows\system32\mlfcache.dat
2009-09-12 19:26:15 139904 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-09-12 19:26:06 189744 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-08-29 03:41:42 1686528 ----a-w- c:\windows\system32\gameux.dll
2009-08-29 03:40:31 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-28 23:31:54 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-27 14:02:34 832512 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 13:57:38 56320 ----a-w- c:\windows\system32\iesetup.dll
2009-08-27 13:57:36 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-27 13:56:05 72704 ----a-w- c:\windows\system32\admparse.dll
2009-08-27 11:24:10 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-08-27 09:51:45 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-08-18 04:33:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-14 16:42:08 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2009-08-14 16:40:56 103936 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:40:52 15360 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 14:25:18 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:25:16 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:25:15 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:25:14 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:25:10 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:25:10 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:25:10 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 14:23:53 22016 ----a-w- c:\windows\system32\netiougc.exe
2009-08-05 14:28:45 3502152 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-08-05 14:28:44 3467864 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-02-28 00:22:25 174 --sha-w- c:\program files\desktop.ini
2009-02-28 00:17:23 665600 ----a-w- c:\windows\inf\drvindex.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-05-16 17:55:55 16384 --sha-w- c:\windows\temp\cookies\index.dat
2009-05-16 17:55:55 16384 --sha-w- c:\windows\temp\history\history.ie5\index.dat
2009-05-16 17:55:55 32768 --sha-w- c:\windows\temp\temporary internet files\content.ie5\index.dat

============= FINISH: 19:50:16.65 ===============


--Finished--


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-10-26.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 2/26/2009 6:36:26 PM
System Uptime: 10/26/2009 7:54:50 AM (12 hours ago)

Motherboard: Acer | | E946GZ
Processor: Intel® Pentium® D CPU 3.00GHz | Socket 775 | 3000/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 113 GiB total, 43.327 GiB free.
D: is FIXED (NTFS) - 113 GiB total, 83.242 GiB free.
E: is CDROM (UDF)
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is CDROM ()
K: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP256: 10/24/2009 12:08:47 PM - Removed Eamonn
RP258: 10/24/2009 12:32:40 PM - Configured Chessmaster Grandmaster Edition
RP259: 10/24/2009 12:45:34 PM - Installed AVG 9.0
RP261: 10/24/2009 12:51:02 PM - Avg8 Update
RP263: 10/24/2009 12:56:20 PM - Avg8 Update
RP264: 10/25/2009 7:46:17 AM - Windows Update
RP265: 10/26/2009 8:00:53 AM - Windows Update

==== Installed Programs ======================

µTorrent
Adobe AIR
Adobe Anchor Service CS3
Adobe Anchor Service CS4
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge CS4
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps CS4
Adobe Color - Photoshop Specific
Adobe Color EU Extra Settings CS4
Adobe Color JA Extra Settings CS4
Adobe Color NA Recommended Settings CS4
Adobe CSI CS4
Adobe Default Language CS4
Adobe Device Central CS3
Adobe Device Central CS4
Adobe Drive CS4
Adobe Dynamiclink Support
Adobe ExtendScript Toolkit 2
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS4
Adobe Flash CS4
Adobe Flash CS4 Extension - Flash Lite STI en
Adobe Flash CS4 Professional
Adobe Flash CS4 STI-en
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Flash Player 9 ActiveX
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Linguistics CS3
Adobe Linguistics CS4
Adobe Media Encoder CS4
Adobe Media Encoder CS4 Importer
Adobe Media Player
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Photoshop CS3
Adobe Reader 7.0
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Stock Photos CS3
Adobe Type Support CS4
Adobe Update Manager CS3
Adobe Update Manager CS4
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS3
Adobe XMP Panels CS4
AdobeColorCommonSetCMYK
AdobeColorCommonSetRGB
Advanced Port Scanner v1.3
AIM 6
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Install Manager
AV Voice Changer Software DIAMOND 6.0
AVG 9.0
Bonjour
Camtasia Studio 6
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center HydraVision Full
Catalyst Control Center InstallProxy
Cavaj Java Decompiler
ccc-core-static
ccc-utility
CCC Help English
Cheat Engine 5.5
Choice Guard
Combat Arms
Connect
ConvertXtoDVD 3.3.4.107
Counter-Strike
Counter-Strike: Source
Creative ALchemy (X-Fi Edition)
Creative Media Toolbox 6
Creative Media Toolbox 6 (Shared Components)
Creative MediaSource 5
Creative Software AutoUpdate
Creative System Information
Creative USB Headsets
Crystal Reports Basic for Visual Studio 2008
Day of Defeat: Source
Diablo II
Diablo II Shareware
Full Tilt Poker
Garry's Mod
GDR 4053 for SQL Server Tools and Workstation Components 2005 ENU (KB970892)
Google Earth
Google Toolbar for Internet Explorer
Google Update Helper
Google Updater
Guitar Pro 5.2
Half-Life
Hero Editor V0.96
Hero_Online
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB945282)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB946040)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB946308)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB946344)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB947540)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB947789)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB948127)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB951708)
Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB945282)
Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB946040)
Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB946308)
Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB947540)
Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB947789)
Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB948127)
Hotfix for Microsoft Visual Studio Team System 2008 Team Suite - ENU (KB971091)
Hotfix for Microsoft Visual Studio Team System 2008 Team Suite - ENU (KB971092)
Hotfix for Microsoft Visual Studio Team System 2008 Team Suite - ENU (KB973674)
Hotspot Shield 1.30
HxD Hex Editor version 1.7.7.0
IDA Pro Free v4.9
ImgBurn
iTunes
Java DB 10.4.1.3
Java™ 6 Update 13
Java™ SE Development Kit 6 Update 12
JCreator Pro 4.50
Jiffy Gmail Creator
kuler
LightScribe 1.4.124.1
LimeWire 5.1.2
Logitech Audio Echo Cancellation Component
Logitech QuickCam
Logitech Video Enumerator
Logitech® Camera Driver
Magic ISO Maker v5.5 (build 0261)
MagicDisc 2.7.106
Malwarebytes' Anti-Malware
Microsoft .NET Compact Framework 2.0 SP2
Microsoft .NET Compact Framework 3.5
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Device Emulator version 3.0 - ENU
Microsoft Document Explorer 2008
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Visual Web Developer 2007
Microsoft Office Visual Web Developer MUI (English) 2007
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
Microsoft SQL Server 2005 Tools Express Edition
Microsoft SQL Server 2008 Management Objects
Microsoft SQL Server Compact 3.5 for Devices ENU
Microsoft SQL Server Compact 3.5 SP1 Design Tools English
Microsoft SQL Server Compact 3.5 SP1 English
Microsoft SQL Server Database Publishing Wizard 1.3
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Microsoft VC9 runtime libraries
Microsoft Visual Basic 2008 Express Edition with SP1 - ENU
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Express Edition with SP1 - ENU
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual Studio 2005 Tools for Office Runtime
Microsoft Visual Studio 2008 Performance Collection Tools - ENU
Microsoft Visual Studio Team System 2008 Team Suite - ENU
Microsoft Visual Studio Team System 2008 Team Suite - ENU Service Pack 1 (KB945140)
Microsoft Visual Studio Web Authoring Component
Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools - enu
Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense
Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
Microsoft Windows SDK for Visual Studio 2008 SP1 Tools
Microsoft Windows SDK for Visual Studio 2008 SP1 Win32 Tools
mIRC
Mozilla Firefox (3.0.14)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MySQL Server 5.1
No-IP.com DUC (remove only)
NTI Backup NOW! 4.7
NTI CD & DVD-Maker
Oblivion
PDF Settings CS4
Photoshop Camera Raw
Pixel Bender Toolkit
PremiumSoft Navicat Lite 8.2
PunkBuster Services
Python 2.6.1
Quake Live Internet Explorer Plugin
QuickTime
Realtek High Definition Audio Driver
Renoise 2.0.0
Ricochet
S.T.A.L.K.E.R. - Shadow of Chernobyl [v1.0004]
Sandboxie 3.38
ScapeRune 513 v1.8
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Visual Studio Team System 2008 Team Suite - ENU (KB972222)
Security Update for Microsoft Visual Studio Team System 2008 Team Suite - ENU (KB973675)
Skins
SmartFTP Client
SmartFTP Client 3.0 Setup Files (remove only)
Source SDK Base
SQL Server System CLR Types
Steam
Suite Shared Configuration CS4
Sven Co-op 4.0B
System error's toolkit 1.0
System Requirements Lab
TortoiseSVN 1.6.2.16344 (32 bit)
UMVPLStandalone
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Visual Studio Web Authoring Component (KB945140)
VB Decompiler Lite
VC Runtimes MSI
Ventrilo Server
Visual C++ 2008 IA64 Runtime - (v9.0.30729)
Visual C++ 2008 IA64 Runtime - (v9.0.30729.4148)
Visual C++ 2008 IA64 Runtime - v9.0.30729.01
Visual C++ 2008 IA64 Runtime - v9.0.30729.4148
Visual C++ 2008 x64 Runtime - (v9.0.30729)
Visual C++ 2008 x64 Runtime - (v9.0.30729.4148)
Visual C++ 2008 x64 Runtime - v9.0.30729.01
Visual C++ 2008 x64 Runtime - v9.0.30729.4148
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - (v9.0.30729.4148)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Visual C++ 2008 x86 Runtime - v9.0.30729.4148
Visual Studio 2005 Tools for Office Second Edition Runtime
Visual Studio Tools for the Office system 3.0 Runtime
Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258)
Warcraft III
Warcraft III: All Products
Warsow 0.42
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Mobile 5.0 SDK R2 for Pocket PC
Windows Mobile 5.0 SDK R2 for Smartphone
WinRAR archiver
Wolfenstein - Enemy Territory
World of Warcraft
World of Warcraft FREE Trial
XAMPP 1.7.0
Xvid 1.2.1 final uninstall
Yahoo! Toolbar

==== Event Viewer Messages From Past Week ========

10/24/2009 11:54:19 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
10/24/2009 11:54:19 AM, Error: Service Control Manager [7000] - The Steam Client Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/24/2009 11:40:38 AM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for SQL Server 2005 Service Pack 3 (KB970892).
10/24/2009 11:36:45 AM, Error: Service Control Manager [7000] - The adfs service failed to start due to the following error: The system cannot find the file specified.

==== End Of File ===========================

Rootrepeal - Still does not run - memory errors


This post has been edited by Michael435: Oct 26 2009, 06:54 PM
Go to the top of the page
 
+Quote Post
Raktor
post Oct 26 2009, 08:45 PM
Post #6


Trusted Helper
Group Icon
Posts: 212
OS: Windows 7 Professional x64 RTM, Mac OS X 10.5



Download Combofix from any of the links below but rename it to michael.com before saving it to your desktop.

Link 1
Link 2


==================================

Double click on the renamed ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.
Go to the top of the page
 
+Quote Post
Michael435
post Oct 27 2009, 03:49 PM
Post #7


New Member
*
Posts: 6
OS: Windows Vista



ComboFix 09-10-26.06 - Michael 10/27/2009 15:53.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1022.411 [GMT -5:00]
Running from: c:\users\Michael\Desktop\michael.com
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Internet Security *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Michael\AppData\Roaming\inst.exe
c:\windows\system32\images
c:\windows\system32\images\toolbar\calendar.gif
c:\windows\system32\images\toolbar\crlogo.gif
c:\windows\system32\images\toolbar\export.gif
c:\windows\system32\images\toolbar\export_over.gif
c:\windows\system32\images\toolbar\exportd.gif
c:\windows\system32\images\toolbar\First.gif
c:\windows\system32\images\toolbar\first_over.gif
c:\windows\system32\images\toolbar\Firstd.gif
c:\windows\system32\images\toolbar\gotopage.gif
c:\windows\system32\images\toolbar\gotopage_over.gif
c:\windows\system32\images\toolbar\gotopaged.gif
c:\windows\system32\images\toolbar\grouptree.gif
c:\windows\system32\images\toolbar\grouptree_over.gif
c:\windows\system32\images\toolbar\grouptreed.gif
c:\windows\system32\images\toolbar\grouptreepressed.gif
c:\windows\system32\images\toolbar\Last.gif
c:\windows\system32\images\toolbar\last_over.gif
c:\windows\system32\images\toolbar\Lastd.gif
c:\windows\system32\images\toolbar\Next.gif
c:\windows\system32\images\toolbar\next_over.gif
c:\windows\system32\images\toolbar\Nextd.gif
c:\windows\system32\images\toolbar\Prev.gif
c:\windows\system32\images\toolbar\prev_over.gif
c:\windows\system32\images\toolbar\Prevd.gif
c:\windows\system32\images\toolbar\print.gif
c:\windows\system32\images\toolbar\print_over.gif
c:\windows\system32\images\toolbar\printd.gif
c:\windows\system32\images\toolbar\Refresh.gif
c:\windows\system32\images\toolbar\refresh_over.gif
c:\windows\system32\images\toolbar\refreshd.gif
c:\windows\system32\images\toolbar\Search.gif
c:\windows\system32\images\toolbar\search_over.gif
c:\windows\system32\images\toolbar\searchd.gif
c:\windows\system32\images\toolbar\up.gif
c:\windows\system32\images\toolbar\up_over.gif
c:\windows\system32\images\toolbar\upd.gif
c:\windows\system32\images\tree\begindots.gif
c:\windows\system32\images\tree\beginminus.gif
c:\windows\system32\images\tree\beginplus.gif
c:\windows\system32\images\tree\blank.gif
c:\windows\system32\images\tree\blankdots.gif
c:\windows\system32\images\tree\dots.gif
c:\windows\system32\images\tree\lastdots.gif
c:\windows\system32\images\tree\lastminus.gif
c:\windows\system32\images\tree\lastplus.gif
c:\windows\system32\images\tree\Magnify.gif
c:\windows\system32\images\tree\minus.gif
c:\windows\system32\images\tree\minusbox.gif
c:\windows\system32\images\tree\plus.gif
c:\windows\system32\images\tree\plusbox.gif
c:\windows\system32\images\tree\singleminus.gif
c:\windows\system32\images\tree\singleplus.gif

Infected copy of c:\windows\system32\cngaudit.dll was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}


((((((((((((((((((((((((( Files Created from 2009-09-27 to 2009-10-27 )))))))))))))))))))))))))))))))
.

2009-10-27 21:09 . 2009-10-27 21:15 -------- d-----w- c:\users\Michael\AppData\Local\temp
2009-10-27 21:09 . 2009-10-27 21:09 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-27 21:09 . 2009-10-27 21:09 -------- d-----w- c:\users\Michael_2\AppData\Local\temp
2009-10-25 16:55 . 2009-10-26 23:08 0 ----a-w- c:\users\Michael\AppData\Local\prvlcl.dat
2009-10-24 19:19 . 2009-10-27 21:11 -------- d--h--w- c:\windows\PIF
2009-10-24 19:05 . 2009-10-24 19:05 -------- d-----w- c:\users\Michael\AppData\Roaming\Malwarebytes
2009-10-24 19:05 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-24 19:05 . 2009-10-24 19:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-24 19:05 . 2009-10-24 19:05 -------- d-----w- c:\programdata\Malwarebytes
2009-10-24 19:05 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-24 17:47 . 2009-10-24 17:59 -------- d-----w- C:\$AVG
2009-10-24 17:47 . 2009-10-24 17:47 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-10-24 17:47 . 2009-10-24 17:52 161800 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-10-24 17:47 . 2009-10-24 17:56 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-10-24 17:47 . 2009-10-24 17:47 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-10-24 17:47 . 2009-10-24 17:56 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-10-24 17:47 . 2009-10-27 20:27 -------- d-----w- c:\windows\system32\drivers\Avg
2009-10-24 17:46 . 2009-10-24 17:46 -------- d-----w- c:\program files\AVG
2009-10-24 17:46 . 2009-10-24 18:03 -------- d-----w- c:\programdata\avg9
2009-10-24 02:19 . 2009-10-27 20:17 0 ----a-r- c:\windows\win32k.sys
2009-10-21 21:07 . 2009-10-24 17:28 -------- d-----w- c:\program files\VentSrv
2009-10-21 21:06 . 2009-10-21 21:06 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-20 20:35 . 2009-06-10 11:41 206848 ----a-w- c:\windows\system32\telnet.exe
2009-10-19 01:43 . 2009-10-19 01:43 -------- d-----w- c:\program files\Hackers Paradise
2009-10-17 14:05 . 2009-10-17 14:05 -------- d-----w- c:\windows\SQLTools9_KB970892_ENU
2009-10-16 22:09 . 2009-10-16 22:09 -------- d-----w- C:\msdn
2009-10-16 20:57 . 2009-09-10 17:38 216576 ----a-w- c:\windows\system32\msv1_0.dll
2009-10-16 20:55 . 2009-08-31 15:21 292352 ----a-w- c:\windows\system32\psisdecd.dll
2009-10-16 20:55 . 2009-08-31 15:16 428032 ----a-w- c:\windows\system32\EncDec.dll
2009-10-16 20:55 . 2009-08-31 15:17 1244672 ----a-w- c:\windows\system32\mcmde.dll
2009-10-16 20:51 . 2009-09-04 12:38 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-10-16 20:51 . 2009-09-14 09:50 130048 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-10-16 20:51 . 2009-04-02 11:50 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2009-10-14 21:25 . 2009-10-14 21:25 -------- d-----w- c:\users\Michael\AppData\Local\Blizzard Entertainment
2009-10-14 20:30 . 2009-10-14 20:30 -------- d-----w- c:\users\Michael\AppData\Local\tjnet
2009-10-13 23:22 . 2009-10-13 23:23 -------- d-----w- c:\users\Michael\AppData\Roaming\mjusbsp
2009-10-12 23:28 . 2009-10-27 21:14 -------- d-----w- c:\windows\system32\wbem\repository
2009-10-07 14:33 . 2009-10-12 20:23 -------- d-----w- c:\windows\system32\wbem\repository_bad2
2009-10-07 00:40 . 2009-10-07 00:40 -------- d-----w- c:\users\Michael\AppData\Roaming\Creative
2009-10-07 00:34 . 2006-10-06 06:17 53248 ------w- c:\windows\Ctregrun.exe
2009-10-07 00:32 . 2009-10-07 00:49 -------- d-----w- c:\programdata\Creative
2009-10-07 00:29 . 2009-10-07 00:29 -------- d-----w- c:\program files\Common Files\Creative
2009-10-07 00:29 . 2009-10-07 00:34 -------- d--h--w- c:\program files\Creative Installation Information
2009-10-07 00:27 . 2008-09-10 02:54 47104 ----a-w- c:\windows\system32\ctppld.dll
2009-10-07 00:27 . 2008-09-10 02:54 497152 ----a-w- c:\windows\system32\CTAPO32.dll
2009-10-07 00:27 . 2008-09-30 03:23 181760 ----a-w- c:\windows\system32\ctdvinst.dll
2009-10-07 00:27 . 2008-08-26 08:30 8704 ----a-w- c:\windows\ResDefE.exe
2009-10-07 00:27 . 2008-08-14 06:48 17408 ----a-w- c:\windows\system32\drivers\skfiltv.sys
2009-10-07 00:26 . 2008-05-12 20:32 127488 ----a-w- c:\windows\system32\APOMngr.DLL
2009-10-07 00:26 . 2008-03-11 15:55 69120 ----a-w- c:\windows\system32\CmdRtr.DLL
2009-10-07 00:26 . 2009-10-07 00:26 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2009-10-07 00:26 . 2009-10-07 00:26 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2009-10-07 00:26 . 2008-06-26 00:10 2869728 ------w- c:\windows\system32\Sens_oal.dll
2009-10-07 00:26 . 2009-10-07 00:26 -------- d-----w- c:\programdata\Creative Labs
2009-10-07 00:24 . 2009-10-07 00:34 -------- d-----w- c:\program files\Common Files\Creative Labs Shared
2009-10-07 00:24 . 2009-10-07 00:34 -------- d-----w- c:\program files\Creative
2009-10-06 20:24 . 2008-07-10 19:56 107864 ----a-w- c:\windows\system32\tsccvid.dll
2009-10-06 20:24 . 2009-10-06 20:24 -------- d-----w- c:\windows\system32\QuickTime
2009-10-06 20:23 . 2009-10-06 20:23 -------- d-----w- c:\programdata\TechSmith
2009-10-06 20:23 . 2009-10-06 20:23 -------- d-----w- c:\program files\Common Files\TechSmith Shared
2009-10-06 19:41 . 2009-10-06 19:41 -------- d-----w- C:\Hotspot Shield
2009-10-06 19:38 . 2009-10-06 19:41 -------- d-----w- c:\program files\Hotspot Shield
2009-10-05 18:59 . 2009-07-10 17:33 1589248 ----a-w- c:\windows\system32\libmysql_d.dll
2009-10-05 18:59 . 2009-10-05 18:59 -------- d-----w- c:\program files\PremiumSoft
2009-10-05 18:29 . 2009-10-05 18:29 -------- d-----w- c:\programdata\MySQL
2009-10-05 18:29 . 2009-10-05 18:29 -------- d-----w- c:\program files\MySQL
2009-10-02 20:35 . 2009-10-01 15:29 195440 ------w- c:\windows\system32\MpSigStub.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-27 20:20 . 2009-02-27 00:26 -------- d-----w- c:\program files\Steam
2009-10-24 18:08 . 2009-02-27 00:26 -------- d-----w- c:\program files\Common Files\Steam
2009-10-24 18:00 . 2009-03-01 16:12 -------- d-----w- c:\program files\uTorrent
2009-10-24 17:55 . 2009-03-01 16:11 -------- d-----w- c:\users\Michael\AppData\Roaming\uTorrent
2009-10-24 17:39 . 2009-05-01 22:38 -------- d-----w- c:\programdata\Media Center Programs
2009-10-24 17:09 . 2006-12-13 03:37 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-24 17:04 . 2009-03-15 19:50 -------- d-----w- c:\users\Michael\AppData\Roaming\HLSW
2009-10-24 00:49 . 2009-08-15 20:45 -------- d-----w- c:\users\Michael\AppData\Roaming\FileZilla
2009-10-17 22:22 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-10-17 14:14 . 2009-03-17 01:39 -------- d-----w- c:\programdata\Microsoft Help
2009-10-17 14:06 . 2009-03-17 01:44 -------- d-----w- c:\program files\Microsoft SQL Server
2009-10-15 00:27 . 2009-03-14 14:56 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2009-10-10 01:46 . 2009-03-04 01:26 -------- d-----w- c:\program files\Warsow
2009-09-29 01:46 . 2009-04-08 21:17 -------- d-----w- c:\users\Michael\AppData\Roaming\mIRC
2009-09-29 00:43 . 2009-04-08 21:17 -------- d-----w- c:\program files\mIRC
2009-09-22 01:52 . 2009-03-13 18:38 -------- d-----w- c:\users\Michael\AppData\Roaming\LimeWire
2009-09-16 01:20 . 2009-03-06 00:44 -------- d-----w- c:\users\Michael\AppData\Roaming\Warsow
2009-09-15 20:04 . 2009-09-15 20:04 37376 ----a-w- c:\windows\system32\drivers\HssDrv.sys
2009-09-15 20:04 . 2009-09-15 20:04 32768 ----a-w- c:\windows\system32\drivers\taphss.sys
2009-09-13 14:03 . 2009-07-28 19:44 92464 ---ha-w- c:\windows\system32\mlfcache.dat
2009-09-12 19:26 . 2009-02-28 00:10 139904 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-09-12 19:26 . 2009-02-28 00:10 189744 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-09-11 20:44 . 2009-03-17 01:39 -------- d-----w- c:\program files\Common Files\Merge Modules
2009-09-09 23:34 . 2009-08-22 20:38 -------- d-----w- c:\program files\Windows Live Safety Center
2009-09-07 18:13 . 2009-03-17 01:39 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2009-09-07 17:49 . 2009-09-07 17:49 -------- d-----w- c:\program files\Advanced Port Scanner
2009-09-07 17:21 . 2009-05-18 22:31 -------- d-----w- c:\program files\IDA Free
2009-09-07 14:20 . 2009-09-07 14:20 -------- d-----w- c:\programdata\Blizzard Entertainment
2009-09-05 02:15 . 2009-09-05 02:08 -------- d-----w- c:\users\Michael\AppData\Roaming\Apple Computer
2009-09-05 02:13 . 2009-09-05 01:58 -------- d-----w- c:\programdata\Apple
2009-09-05 02:07 . 2009-09-05 02:07 -------- d-----w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-09-05 02:07 . 2009-09-05 02:07 -------- d-----w- c:\program files\iTunes
2009-09-05 02:07 . 2009-09-05 02:07 -------- d-----w- c:\program files\iPod
2009-09-05 02:07 . 2009-09-05 01:58 -------- d-----w- c:\program files\Common Files\Apple
2009-09-05 02:07 . 2009-09-05 02:05 -------- d-----w- c:\programdata\Apple Computer
2009-09-05 02:06 . 2009-03-14 19:06 -------- d-----w- c:\program files\Bonjour
2009-09-05 02:06 . 2009-09-05 02:05 -------- d-----w- c:\program files\QuickTime
2009-09-05 02:04 . 2009-09-05 02:04 -------- d-----w- c:\program files\Apple Software Update
2009-09-04 21:37 . 2009-09-04 21:36 -------- d-----w- c:\users\Michael\AppData\Roaming\Notepad++
2009-09-04 21:20 . 2009-09-04 21:20 -------- d-----w- c:\users\Michael\AppData\Roaming\Mael
2009-08-29 17:20 . 2009-08-29 17:20 -------- d-----w- c:\users\Michael\AppData\Roaming\SmartFTP
2009-08-29 03:41 . 2009-09-02 23:23 1686528 ----a-w- c:\windows\system32\gameux.dll
2009-08-29 03:40 . 2009-09-02 23:23 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-28 23:31 . 2009-09-02 23:23 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-27 14:02 . 2009-10-16 20:56 832512 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 13:57 . 2009-10-16 20:56 56320 ----a-w- c:\windows\system32\iesetup.dll
2009-08-27 13:57 . 2009-10-16 20:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-27 13:56 . 2009-10-16 20:56 72704 ----a-w- c:\windows\system32\admparse.dll
2009-08-27 11:24 . 2009-10-16 20:56 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-08-27 09:51 . 2009-10-16 20:56 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-08-18 04:33 . 2009-08-18 04:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-14 17:16 . 2009-09-10 20:51 213592 ----a-w- c:\windows\system32\drivers\netio.sys
2009-08-14 16:42 . 2009-09-10 20:51 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2009-08-14 16:40 . 2009-09-10 20:51 103936 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:40 . 2009-09-10 20:51 15360 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 14:25 . 2009-09-10 20:51 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:25 . 2009-09-10 20:51 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:25 . 2009-09-10 20:51 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:25 . 2009-09-10 20:51 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:25 . 2009-09-10 20:51 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:25 . 2009-09-10 20:51 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:25 . 2009-09-10 20:51 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 14:24 . 2009-09-10 20:51 813568 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 14:23 . 2009-09-10 20:51 22016 ----a-w- c:\windows\system32\netiougc.exe
2009-08-13 18:28 . 2009-06-27 22:03 51504 ----a-w- c:\users\Michael_2\AppData\Local\GDIPFONTCACHEV1.DAT
2009-08-05 14:28 . 2009-10-16 20:56 3502152 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-08-05 14:28 . 2009-10-16 20:56 3467864 ----a-w- c:\windows\system32\ntoskrnl.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 14:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 14:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 14:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 14:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 14:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 14:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 14:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 14:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 14:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"????r"="" [?]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-02-27 1232896]
"Steam"="c:\program files\steam\steam.exe" [2009-10-24 1217808]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-07 3885408]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-06 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"Speech Recognition"="c:\windows\Speech\Common\sapisvr.exe" [2006-11-02 49664]
"cdloader"="c:\users\Michael\AppData\Roaming\mjusbsp\cdloader2.exe" [2009-08-01 50520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2009-02-27 1006264]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-04 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"LogitechCommunicationsManager"="c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-06-26 497200]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" [2006-06-26 614960]
"LVCOMSX"="c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-06-26 243248]
"VolPanel"="d:\program files\Creative\USB Headsets\Volume Panel\VolPanlu.exe" [2008-08-27 233588]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-10-24 2010904]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-11-09 3784704]

c:\users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-3-7 576000]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2006-12-12 528384]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

R0 AvgRkx86;avgrkx86.sys;c:\windows\System32\drivers\avgrkx86.sys [10/24/2009 12:47 PM 161800]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [10/24/2009 12:47 PM 333192]
R1 AvgTdiX;AVG Network Redirector;c:\windows\System32\drivers\avgtdix.sys [10/24/2009 12:47 PM 360584]
R2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [10/24/2009 12:46 PM 906520]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [10/24/2009 12:46 PM 285392]
R3 skfiltv;skfiltv;c:\windows\System32\drivers\skfiltv.sys [10/6/2009 7:27 PM 17408]
S2 gupdate1c9d9ba82edd358;Google Update Service (gupdate1c9d9ba82edd358);c:\program files\Google\Update\GoogleUpdate.exe [5/20/2009 9:19 PM 133104]
S3 SbieDrv;SbieDrv;c:\program files\Sandboxie\SbieDrv.sys [5/28/2009 8:32 AM 108032]
S3 VSPerfDrv90;Performance Tools Driver 9.0;c:\program files\Microsoft Visual Studio 9.0\Team Tools\Performance Tools\VSPerfDrv90.sys [9/4/2007 4:53 PM 55664]
S4 Creative ALchemy AL1 Licensing Service;Creative ALchemy AL1 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe [10/6/2009 7:31 PM 79360]
S4 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [10/6/2009 7:24 PM 79360]
S4 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [10/6/2009 7:34 PM 79360]
S4 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{66GQ7556-22WN-35GR-E1TH-QSTQN766Q5L8}]
c:\windows\System32\Spy-Net\WinHelper32.exe.exe Restart
.
Contents of the 'Scheduled Tasks' folder

2009-10-27 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-28 02:18]

2009-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-21 02:18]

2009-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-21 02:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://en.us.acer.yahoo.com
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
LSP: c:\windows\system32\wpclsp.dll
FF - ProfilePath - c:\users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\3xm87rlz.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1591.6512\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-IgfxTray - c:\windows\system32\igfxtray.exe
HKLM-Run-HotKeysCmds - c:\windows\system32\hkcmd.exe
HKLM-Run-Persistence - c:\windows\system32\igfxpers.exe
HKLM-Run-eRecoveryService - (no file)
HKLM-Explorer_Run-explorer32 - c:\windows\System32\Spy-Net\WinHelper32.exe.exe
SharedTaskScheduler-{A2234B15-23F2-42AD-F4E4-00AAC39C0004} - c:\windows\system32\zkcw2lfbht.dll
AddRemove-AV Voice Changer Software DIAMOND 6.0 - c:\progra~1\AVVCS6~1.0DI\UNWISE.EXE
AddRemove-Half-Life_is1 - d:\program files\Valve\Half-Life\unins000.exe
AddRemove-S.T.A.L.K.E.R. - Shadow of Chernobyl_is1 - d:\program files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\unins000.exe
AddRemove-SimAntv1.0 - d:\maxis\SimAnt\DeIsL1.isu
AddRemove-SmartFTP Client 3.0 Setup Files - c:\program files\SmartFTP Client 3.0 Setup Files\uninst-sftp.exe
AddRemove-VB Decompiler Lite_is1 - c:\program files\VB Decompiler Lite\unins000.exe
AddRemove-ScapeRune 513 v1.8 - c:\users\Michael\Documents\ScapeRune 513 v1.8\Uninstal.exe



**************************************************************************
scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PBDOWNFORCE_SERVICE]
"ImagePath"="\??\c:\users\Michael\AppData\Local\Temp\PHQA93B.tmp"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tdlserv]
"imagepath"="\??\c:\windows\TEMP\96F5.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(660)
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
d:\tsvn\bin\TortoiseStub.dll
d:\tsvn\bin\TortoiseSVN.dll
d:\tsvn\bin\libaprutil_tsvn.dll
d:\tsvn\bin\intl3_tsvn.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Creative\Shared Files\CTAudSvc.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\AVG\AVG9\avgam.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\WUDFHost.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\michael\CF9634.exe
d:\tsvn\bin\TSVNCache.exe
c:\program files\AVG\AVG9\avgtray.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\acer\Empowering Technology\eRecovery\ERAGENT.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Logitech\QuickCam10\COCIManager.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
c:\michael\PEV.cfxxe
.
**************************************************************************
.
Completion time: 2009-10-27 16:26 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-27 21:26

Pre-Run: 46,357,651,456 bytes free
Post-Run: 47,107,096,576 bytes free

- - End Of File - - EE1E5CC7B39B48C15D922A797348494A
Go to the top of the page
 
+Quote Post
Raktor
post Oct 28 2009, 04:37 PM
Post #8


Trusted Helper
Group Icon
Posts: 212
OS: Windows 7 Professional x64 RTM, Mac OS X 10.5



1) Combofix
1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

QUOTE
File::
c:\windows\win32k.sys

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"????r"=-


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe




Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

2) MBAM
Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


3) ESET
You can use either Internet Explorer or Mozilla FireFox for this scan.

  • Please go here then click on:
    QUOTE
    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
  • Select the option YES, I accept the Terms of Use then click on:
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:

    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on:
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on:
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.


4) What You Will Need To Post:
  • Combofix log
  • MBAM log
  • ESET log
Go to the top of the page
 
+Quote Post
Raktor
post Nov 5 2009, 04:14 AM
Post #9


Trusted Helper
Group Icon
Posts: 212
OS: Windows 7 Professional x64 RTM, Mac OS X 10.5



Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies / Views Topic Information
No New Posts   6 / 727 23rd April 2009 - 12:55 PM
bretty1980 started - last by Rorschach112
No New Posts   2 / 575 20th June 2009 - 01:42 PM
Adam Lonsdale started - last by Rorschach112
No New Posts   8 / 167 4th August 2009 - 11:02 PM
amans started - last by fenzodahl512
No New Posts   10 / 152 23rd August 2009 - 03:52 AM
scitom started - last by Rorschach112

RSS Time is now: 21st November 2009 - 06:21 AM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising