Browser hijack [Closed], Trojan |
![]() ![]() |
Browser hijack [Closed], Trojan |
Oct 25 2009, 04:53 PM
Post
#1
|
|
|
New Member ![]() Posts: 6 OS: Windows Vista |
Virus similiar to jadi929
Searching on google/yahoo etc. gets redirected to some [bleep] site. I believe it's some sort of trojan. Spybot S&D wont install at all after renaming. Malwarebytes will install but after running the scan you get Windows cannot access the specified file, path or device. You may not have the appropriate permissions to access the item." I ran AVG and it removed 2 trojans. When I restart my computer it says "RunDLL : Cannot run calc.dll" - AVG said it was a trojan and removed it. I did a AVG Rootkit scan and it found nothing. Note: I did not do a full scan with AVG because I thought that would be it but as OTL was opening/scanning files AVG found a few other trojans. Regedit is disabled AVG detected: Trojan horse SHeur.BMZG Trojan horse BHO.KHJ Trojan Horse Generic15.HF Trojan Horse Generic15.HI OTL Log: OTL logfile created on: 10/24/2009 3:33:47 PM - Run 1 OTL by OldTimer - Version 3.0.22.1 Folder = C:\Users\Michael\Desktop Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 7.0.6000.16916) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1021.87 Mb Total Physical Memory | 312.54 Mb Available Physical Memory | 30.58% Memory free 2.26 Gb Paging File | 1.24 Gb Available in Paging File | 54.79% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 113.20 Gb Total Space | 43.69 Gb Free Space | 38.60% Space Free | Partition Type: NTFS Drive D: | 112.85 Gb Total Space | 83.24 Gb Free Space | 73.76% Space Free | Partition Type: NTFS Drive E: | 4.38 Gb Total Space | 4.24 Gb Free Space | 96.82% Space Free | Partition Type: UDF F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: MICHAEL-PC Current User Name: Michael Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 14 Days Output = Standard Quick Scan ========== Processes (SafeList) ========== PRC - [2009/10/24 15:26:44 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Users\Michael\Desktop\OTL.exe PRC - [2009/10/24 12:56:13 | 02,010,904 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe PRC - [2009/10/24 12:56:01 | 00,600,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe PRC - [2009/10/24 12:52:44 | 01,055,000 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe PRC - [2009/10/24 12:52:41 | 00,827,160 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgam.exe PRC - [2009/10/24 12:46:53 | 00,502,040 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe PRC - [2009/10/24 12:46:52 | 00,702,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe PRC - [2009/10/24 12:46:31 | 00,906,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgemc.exe PRC - [2009/10/24 12:46:23 | 00,285,392 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe PRC - [2009/10/24 11:52:20 | 00,316,664 | ---- | M] (Valve Corporation) -- C:\Program Files\Common Files\Steam\SteamService.exe PRC - [2009/10/23 21:25:36 | 01,217,808 | ---- | M] (Valve Corporation) -- C:\Program Files\Steam\Steam.exe PRC - [2009/05/20 21:18:57 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe PRC - [2009/05/09 14:09:24 | 00,606,720 | ---- | M] (http://tortoisesvn.net) -- D:\TSVN\bin\TSVNCache.exe PRC - [2009/03/09 05:19:17 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe PRC - [2009/03/05 19:41:15 | 00,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe PRC - [2009/02/27 16:27:31 | 02,923,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\Explorer.EXE PRC - [2009/02/27 16:15:48 | 01,232,896 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Sidebar\sidebar.exe PRC - [2009/02/23 20:43:12 | 00,576,000 | ---- | M] (MagicISO, Inc.) -- C:\Program Files\MagicDisc\MagicDisc.exe PRC - [2009/02/06 19:51:28 | 03,885,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe PRC - [2009/02/03 23:58:34 | 00,729,088 | ---- | M] (ATI Technologies Inc.) -- C:\Windows\System32\Ati2evxx.exe PRC - [2008/12/18 15:32:52 | 00,049,152 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe PRC - [2008/12/18 14:19:44 | 00,049,152 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe PRC - [2008/11/24 22:31:12 | 00,087,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe PRC - [2008/11/24 22:31:08 | 00,239,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe PRC - [2008/08/27 18:19:20 | 00,233,588 | ---- | M] (Creative Technology Ltd) -- D:\Program Files\Creative\USB Headsets\Volume Panel\VolPanlu.exe PRC - [2008/04/29 21:27:50 | 00,417,792 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe PRC - [2006/12/08 16:45:32 | 00,045,056 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe PRC - [2006/11/12 13:35:58 | 00,393,216 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE PRC - [2006/11/08 21:57:52 | 03,784,704 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe PRC - [2006/11/02 07:36:04 | 00,895,488 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe PRC - [2006/11/02 07:36:04 | 00,201,728 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe PRC - [2006/11/02 07:34:36 | 00,151,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\notepad.exe PRC - [2006/11/02 04:46:02 | 00,143,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WUDFHost.exe PRC - [2006/10/19 16:52:24 | 00,061,440 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe PRC - [2006/06/26 10:34:58 | 00,166,448 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\QuickCam10\COCIManager.exe PRC - [2006/06/26 10:34:40 | 00,614,960 | ---- | M] () -- C:\Program Files\Logitech\QuickCam10\QuickCam10.exe PRC - [2006/06/26 10:33:42 | 00,099,888 | ---- | M] (Logitech Inc.) -- c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe PRC - [2006/06/26 10:33:32 | 00,243,248 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe PRC - [2006/06/26 09:46:04 | 00,497,200 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe ========== Win32 Services (SafeList) ========== SRV - File not found -- -- (CLTNetCnService [Auto | Stopped]) SRV - [2009/10/24 12:46:31 | 00,906,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgemc.exe -- (avg9emc [Auto | Running]) SRV - [2009/10/24 12:46:23 | 00,285,392 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd [Auto | Running]) SRV - [2009/10/24 11:52:20 | 00,316,664 | ---- | M] (Valve Corporation) -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service [On_Demand | Running]) SRV - [2009/10/06 19:34:21 | 00,079,360 | ---- | M] (Creative Labs) -- C:\Program Files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe -- (Creative Media Toolbox 6 Licensing Service [Disabled | Stopped]) SRV - [2009/10/06 19:31:31 | 00,079,360 | ---- | M] (Creative Labs) -- C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe -- (Creative ALchemy AL1 Licensing Service [Disabled | Stopped]) SRV - [2009/10/06 19:24:31 | 00,079,360 | ---- | M] (Creative Labs) -- C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service [Disabled | Stopped]) SRV - [2009/09/15 15:29:04 | 00,057,640 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE -- (HssTrayService [Disabled | Stopped]) SRV - [2009/09/15 15:28:52 | 00,204,848 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe -- (HotspotShieldService [Disabled | Stopped]) SRV - [2009/09/15 15:04:58 | 00,331,824 | ---- | M] (AnchorFree Inc.) -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv [Disabled | Stopped]) SRV - [2009/07/13 14:02:50 | 00,542,496 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Stopped]) SRV - [2009/07/09 12:22:18 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Disabled | Stopped]) SRV - [2009/05/28 08:32:26 | 00,053,760 | ---- | M] (tzuk) -- C:\Program Files\Sandboxie\SbieSvc.exe -- (SbieSvc [Disabled | Stopped]) SRV - [2009/05/24 13:56:33 | 00,075,064 | ---- | M] () -- C:\Windows\System32\PnkBstrA.exe -- (PnkBstrA [Disabled | Stopped]) SRV - [2009/05/20 21:18:57 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1c9d9ba82edd358 [Auto | Stopped]) SRV - [2009/05/20 21:18:31 | 00,183,280 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [Auto | Stopped]) SRV - [2009/04/05 19:59:08 | 00,655,624 | ---- | M] (Acresso Software Inc.) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service [Disabled | Stopped]) SRV - [2009/03/10 17:42:00 | 03,121,464 | ---- | M] (INCA Internet Co., Ltd.) -- C:\Windows\System32\GameMon.des -- (npggsvc [Disabled | Stopped]) SRV - [2009/02/27 16:41:25 | 00,265,912 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend [Auto | Stopped]) SRV - [2009/02/03 23:58:34 | 00,729,088 | ---- | M] (ATI Technologies Inc.) -- C:\Windows\System32\Ati2evxx.exe -- (Ati External Event Utility [Auto | Running]) SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running]) SRV - [2008/11/24 22:31:12 | 00,087,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter [Auto | Running]) SRV - [2008/11/24 22:31:10 | 29,263,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -- (MSSQL$SQLEXPRESS [Disabled | Stopped]) SRV - [2008/11/24 22:31:08 | 00,239,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser [Auto | Running]) SRV - [2008/11/24 22:31:08 | 00,045,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe -- (MSSQLServerADHelper [Disabled | Stopped]) SRV - [2008/07/29 13:10:46 | 03,201,024 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe -- (msvsmon90 [Disabled | Stopped]) SRV - [2008/07/27 13:00:25 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) SRV - [2008/06/19 20:18:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped]) SRV - [2008/06/19 20:17:50 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped]) SRV - [2008/06/19 20:17:49 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped]) SRV - [2008/04/29 21:27:50 | 00,417,792 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService [Auto | Running]) SRV - [2006/12/08 16:45:32 | 00,045,056 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe -- (eRecoveryService [Auto | Running]) SRV - [2006/11/02 07:36:04 | 00,895,488 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Running]) SRV - [2006/11/02 07:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [On_Demand | Stopped]) SRV - [2006/11/02 07:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehstart.dll -- (ehstart [Auto | Stopped]) SRV - [2006/11/02 07:35:28 | 00,291,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehRecvr.exe -- (ehRecvr [On_Demand | Stopped]) SRV - [2006/11/02 04:46:13 | 00,989,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wevtsvc.dll -- (Eventlog [Auto | Running]) SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped]) SRV - [2006/10/19 16:52:24 | 00,061,440 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running]) SRV - [2006/06/26 10:33:56 | 00,091,696 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe -- (LVSrvLauncher [Auto | Stopped]) SRV - [2006/06/26 10:33:42 | 00,099,888 | ---- | M] (Logitech Inc.) -- c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe -- (LVPrcSrv [Auto | Running]) ========== Modules (SafeList) ========== MOD - [2009/10/24 15:26:44 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Users\Michael\Desktop\OTL.exe MOD - [2009/10/24 12:47:40 | 00,012,464 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll MOD - [2006/11/02 07:34:48 | 00,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\LINKINFO.dll MOD - [2006/11/02 04:38:57 | 01,648,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll MOD - [2006/06/26 10:33:42 | 00,091,696 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com [binary data] IE - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm IE - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SEARCH PAGE = http://us.rd.yahoo.com/customize/ycomp/def...//www.yahoo.com IE - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search IE - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe...-8&fr=b1ie7 IE - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/ IE - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-316218746-153266152-3376316544-1000\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) IE - HKU\S-1-5-21-316218746-153266152-3376316544-1000\S-1-5-21-316218746-153266152-3376316544-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/" FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1 FF - prefs.js..extensions.enabledItems: {bb6bc1bb-f824-4702-90cd-35e2fb24f25c}:0.2.1.3 FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.4.3 FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:0.0.0 FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.8 FF - prefs.js..extensions.enabledItems: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:10.1.0 FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14 FF - prefs.js..network.proxy.no_proxies_on: "*.local" FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/02 15:44:40 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2009/10/24 13:02:39 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/17 15:29:42 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/10/24 12:40:17 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2009/05/05 18:09:10 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Extensions [2009/05/05 18:09:10 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/03/13 13:39:13 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org [2009/10/24 12:47:22 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\3xm87rlz.default\extensions [2009/08/10 19:30:36 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\3xm87rlz.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232} [2009/09/07 10:33:20 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\3xm87rlz.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947} [2009/09/07 10:33:20 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\3xm87rlz.default\extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25c} [2009/07/28 14:26:02 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\3xm87rlz.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2009/10/06 12:11:09 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mozilla\Firefox\Profiles\3xm87rlz.default\extensions\firebug@software.joehewitt.com [2009/05/05 18:08:26 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2009/09/17 15:29:42 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/09/17 15:29:28 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009/09/17 15:29:28 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2009/09/17 15:29:33 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll [2009/09/04 21:06:03 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2009/09/04 21:06:04 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2009/09/04 21:06:04 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2009/09/04 21:06:04 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2009/09/04 21:06:04 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2009/09/04 21:06:04 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll [2009/09/04 21:06:04 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll [2009/08/03 09:10:30 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml [2009/08/03 09:10:30 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml [2009/08/03 09:10:30 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml [2009/08/03 09:10:30 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml [2009/08/03 09:10:30 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2009/08/03 09:10:30 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml [2009/08/03 09:10:30 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml O1 HOSTS File: (871 bytes) - C:\Windows\System32\drivers\etc\Hosts O1 - Hosts: http://208.43.115.136/~tnban/ www.taconbanana.com O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O1 - Hosts: 127.0.0.1 www.alexspage.co.uk O1 - Hosts: 127.0.0.1 alexspage.co.uk O2 - BHO: (C:\Windows\system32\zkcw2lfbht.dll) - {A2234B15-23F2-42AD-F4E4-00AAC39C0004} - C:\Windows\System32\zkcw2lfbht.dll File not found O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O3 - HKU\S-1-5-21-316218746-153266152-3376316544-1000\..\Toolbar\ShellBrowser: (no name) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - No CLSID value found. O3 - HKU\S-1-5-21-316218746-153266152-3376316544-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [calc] C:\Windows\System32\calc.DLL File not found O4 - HKLM..\Run: [eRecoveryService] File not found O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe File not found O4 - HKLM..\Run: [IgfxTray] C:\Windows\System32\igfxtray.exe File not found O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe (Logitech Inc.) O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam10\QuickCam10.exe () O4 - HKLM..\Run: [LVCOMSX] C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe (Logitech Inc.) O4 - HKLM..\Run: [Persistence] C:\Windows\System32\igfxpers.exe File not found O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [VolPanel] D:\Program Files\Creative\USB Headsets\Volume Panel\VolPanlu.exe (Creative Technology Ltd) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.DLL (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.DLL (Microsoft Corporation) O4 - HKU\S-1-5-21-316218746-153266152-3376316544-1000..\Run: [cdloader] C:\Users\Michael\AppData\Roaming\mjusbsp\cdloader2.exe (magicJack L.P.) O4 - HKU\S-1-5-21-316218746-153266152-3376316544-1000..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-316218746-153266152-3376316544-1000..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-316218746-153266152-3376316544-1000..\Run: [Speech Recognition] C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-316218746-153266152-3376316544-1000..\Run: [Steam] c:\program files\steam\steam.exe (Valve Corporation) O4 - HKU\S-1-5-21-316218746-153266152-3376316544-1000..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - HKU\S-1-5-21-316218746-153266152-3376316544-1000..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-316218746-153266152-3376316544-1000..\Run: [捁牥吠畯r] File not found O4 - Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17 O7 - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1 O7 - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2 O7 - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1 O7 - HKU\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\napinsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O13 - gopher Prefix: missing O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKU\.DEFAULT\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKU\S-1-5-18\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKU\S-1-5-21-316218746-153266152-3376316544-1000\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.systemrequirementslab.com/srl_b...sreqlab_srl.cab (System Requirements Lab Class) O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...r/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab (MessengerStatsClient Class) O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 74.128.17.114 74.128.19.102 O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation) O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - File not found O22 - SharedTaskScheduler: {A2234B15-23F2-42AD-F4E4-00AAC39C0004} - gsajkfh873whdngo8wuidgs4rgfr4 - C:\Windows\System32\zkcw2lfbht.dll File not found O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/09/18 16:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{791278b3-b84d-11de-b1bc-00192154d15d}\Shell\AutoRun\command - "" = M:\autorun.exe -- File not found O33 - MountPoints2\{791278b3-b84d-11de-b1bc-00192154d15d}\Shell\phone\command - "" = M:\autorun.exe -- File not found O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found O35 - comfile [open] -- "%1" %* File not found O35 - exefile [open] -- "%1" %* File not found ========== Files/Folders - Created Within 14 Days ========== [2009/10/24 12:46:19 | 00,000,000 | ---D | C] -- C:\ProgramData\avg9 [2009/10/24 14:05:04 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2009/10/24 14:05:11 | 00,000,000 | ---D | C] -- C:\Users\Michael\AppData\Roaming\Malwarebytes [2009/10/13 18:22:48 | 00,000,000 | ---D | C] -- C:\Users\Michael\AppData\Roaming\mjusbsp [2009/10/14 16:25:00 | 00,000,000 | ---D | C] -- C:\Users\Michael\AppData\Local\Blizzard Entertainment [2009/10/14 15:30:00 | 00,000,000 | ---D | C] -- C:\Users\Michael\AppData\Local\tjnet [2009/10/21 16:06:35 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard [2009/10/24 12:46:20 | 00,000,000 | ---D | C] -- C:\Program Files\AVG [2009/10/18 20:43:15 | 00,000,000 | ---D | C] -- C:\Program Files\Hackers Paradise [2009/10/24 14:05:04 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2009/10/21 16:07:21 | 00,000,000 | ---D | C] -- C:\Program Files\VentSrv [2009/10/24 15:26:34 | 00,521,728 | ---- | C] (OldTimer Tools) -- C:\Users\Michael\Desktop\OTL.exe [2009/10/24 14:19:01 | 00,000,000 | -H-D | C] -- C:\Windows\PIF [2009/10/24 14:05:06 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2009/10/24 14:05:04 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2009/10/24 12:47:46 | 00,000,000 | -H-D | C] -- C:\$AVG [2009/10/24 12:47:40 | 00,012,464 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll [2009/10/24 12:47:39 | 00,161,800 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgrkx86.sys [2009/10/24 12:47:38 | 00,360,584 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgtdix.sys [2009/10/24 12:47:27 | 00,333,192 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys [2009/10/24 12:47:26 | 00,028,424 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgmfx86.sys [2009/10/24 12:47:06 | 00,000,000 | ---D | C] -- C:\Windows\System32\drivers\Avg [2009/10/24 12:38:46 | 93,477,512 | ---- | C] (AVG Technologies) -- C:\Users\Michael\Desktop\avg_avwt_stf_all_90_663a1706.exe [2009/10/17 14:27:24 | 00,000,000 | ---D | C] -- C:\Users\Michael\Desktop\kl [2009/10/17 09:05:27 | 00,000,000 | ---D | C] -- C:\Windows\SQLTools9_KB970892_ENU [2009/10/16 17:09:48 | 00,000,000 | ---D | C] -- C:\msdn [2009/03/14 19:07:07 | 00,047,360 | ---- | C] (VSO Software) -- C:\Users\Michael\AppData\Roaming\pcouffin.sys ========== Files - Modified Within 14 Days ========== [2 C:\Windows\System32\*.tmp files] [2009/10/24 15:33:01 | 00,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2009/10/24 15:26:44 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Users\Michael\Desktop\OTL.exe [2009/10/24 14:51:15 | 00,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2009/10/24 14:47:53 | 00,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job [2009/10/24 14:45:29 | 00,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2009/10/24 14:45:29 | 00,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2009/10/24 14:45:25 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2009/10/24 14:45:18 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2009/10/24 14:45:17 | 00,000,000 | ---- | M] () -- C:\Windows\win32k.sys [2009/10/24 14:45:14 | 10,721,56672 | -HS- | M] () -- C:\hiberfil.sys [2009/10/24 14:38:13 | 00,000,822 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2009/10/24 14:18:35 | 16,409,960 | ---- | M] () -- C:\Users\Michael\Desktop\lold.exe [2009/10/24 13:31:02 | 02,978,722 | -H-- | M] () -- C:\Users\Michael\AppData\Local\IconCache.db [2009/10/24 12:56:07 | 00,360,584 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgtdix.sys [2009/10/24 12:56:01 | 00,028,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgmfx86.sys [2009/10/24 12:55:33 | 43,828,872 | ---- | M] () -- C:\Windows\System32\drivers\Avg\incavi.avm [2009/10/24 12:52:42 | 00,161,800 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgrkx86.sys [2009/10/24 12:52:42 | 00,050,548 | ---- | M] () -- C:\Windows\System32\drivers\Avg\microavi.avg [2009/10/24 12:47:40 | 00,012,464 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll [2009/10/24 12:47:40 | 00,001,651 | ---- | M] () -- C:\Users\Public\Desktop\AVG 9.0.lnk [2009/10/24 12:47:27 | 00,333,192 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys [2009/10/24 12:47:26 | 00,113,461 | ---- | M] () -- C:\Windows\System32\drivers\Avg\iavichjw.avm [2009/10/24 12:47:08 | 06,061,540 | ---- | M] () -- C:\Windows\System32\drivers\Avg\avi7.avg [2009/10/24 12:47:08 | 00,492,629 | ---- | M] () -- C:\Windows\System32\drivers\Avg\miniavi.avg [2009/10/23 21:22:36 | 14,317,8533 | ---- | M] () -- C:\Windows\MEMORY.DMP [2009/10/23 21:19:41 | 00,000,819 | -HS- | M] () -- C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scandisk.lnk [2009/10/22 17:37:49 | 00,048,556 | ---- | M] () -- C:\Users\Michael\Desktop\harvester_of_sorrow_ver2.gp4 [2009/10/22 15:30:12 | 00,665,118 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2009/10/22 15:30:12 | 00,121,460 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2009/10/22 15:30:11 | 00,782,756 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI [2009/10/18 20:43:17 | 00,002,303 | ---- | M] () -- C:\Users\Public\Desktop\Systemerror's Security toolkit.lnk [2009/10/16 17:11:56 | 00,000,000 | ---- | M] () -- C:\Windows\chatter.INI [2009/10/14 16:24:15 | 00,000,518 | ---- | M] () -- C:\Windows\win.ini [2009/10/11 17:31:48 | 00,010,752 | ---- | M] () -- C:\Users\Michael\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/10/11 09:28:55 | 93,477,512 | ---- | M] (AVG Technologies) -- C:\Users\Michael\Desktop\avg_avwt_stf_all_90_663a1706.exe ========== Files - No Company Name ========== [2009/10/24 14:45:14 | 10,721,56672 | -HS- | C] () -- C:\hiberfil.sys [2009/10/24 14:18:17 | 16,409,960 | ---- | C] () -- C:\Users\Michael\Desktop\lold.exe [2009/10/24 14:05:08 | 00,000,822 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2009/10/24 12:47:40 | 00,001,651 | ---- | C] () -- C:\Users\Public\Desktop\AVG 9.0.lnk [2009/10/24 12:47:26 | 00,113,461 | ---- | C] () -- C:\Windows\System32\drivers\Avg\iavichjw.avm [2009/10/24 12:47:08 | 43,828,872 | ---- | C] () -- C:\Windows\System32\drivers\Avg\incavi.avm [2009/10/24 12:47:08 | 00,492,629 | ---- | C] () -- C:\Windows\System32\drivers\Avg\miniavi.avg [2009/10/24 12:47:08 | 00,050,548 | ---- | C] () -- C:\Windows\System32\drivers\Avg\microavi.avg [2009/10/24 12:47:06 | 06,061,540 | ---- | C] () -- C:\Windows\System32\drivers\Avg\avi7.avg [2009/10/23 21:19:41 | 00,000,000 | ---- | C] () -- C:\Windows\win32k.sys [2009/10/22 17:37:48 | 00,048,556 | ---- | C] () -- C:\Users\Michael\Desktop\harvester_of_sorrow_ver2.gp4 [2009/10/18 20:43:17 | 00,002,303 | ---- | C] () -- C:\Users\Public\Desktop\Systemerror's Security toolkit.lnk [2009/10/16 17:11:56 | 00,000,000 | ---- | C] () -- C:\Windows\chatter.INI [2009/10/06 19:27:09 | 00,025,199 | R--- | C] () -- C:\Windows\System32\xfisk.ini [2009/10/06 19:27:09 | 00,000,052 | R--- | C] () -- C:\Windows\System32\ctzapxx.ini [2009/10/06 19:27:01 | 00,001,209 | R--- | C] () -- C:\Windows\skSPcfg.ini [2009/10/06 19:27:01 | 00,000,381 | R--- | C] () -- C:\Windows\skMCcfg.ini [2009/10/06 19:26:49 | 00,127,488 | ---- | C] () -- C:\Windows\System32\APOMngr.DLL [2009/10/06 19:26:49 | 00,069,120 | ---- | C] () -- C:\Windows\System32\CmdRtr.DLL [2009/10/05 13:59:45 | 01,589,248 | ---- | C] () -- C:\Windows\System32\libmysql_d.dll [2009/08/29 07:56:50 | 00,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini [2009/07/30 12:06:17 | 00,002,288 | ---- | C] () -- C:\Windows\Sandboxie.ini [2009/07/30 09:27:25 | 01,970,176 | ---- | C] () -- C:\Windows\System32\d3dx9.dll [2009/07/28 15:02:04 | 00,000,172 | ---- | C] () -- C:\Windows\ODBC.INI [2009/05/24 14:37:51 | 00,107,520 | ---- | C] () -- C:\Windows\System32\SIMANT.DLL [2009/05/24 14:37:51 | 00,027,136 | ---- | C] () -- C:\Windows\System32\VERMONT1.DLL [2009/05/24 14:37:51 | 00,012,416 | ---- | C] () -- C:\Windows\System32\VRX1.DLL [2009/05/10 15:11:11 | 00,000,318 | ---- | C] () -- C:\Windows\WPE PRO.INI [2009/05/03 20:04:55 | 00,000,318 | ---- | C] () -- C:\Windows\WPE PRO - modified.INI [2009/05/02 13:59:51 | 00,021,840 | ---- | C] () -- C:\Windows\System32\SIntfNT.dll [2009/05/02 13:59:51 | 00,017,212 | ---- | C] () -- C:\Windows\System32\SIntf32.dll [2009/05/02 13:59:51 | 00,012,067 | ---- | C] () -- C:\Windows\System32\SIntf16.dll [2009/03/29 18:13:50 | 00,022,334 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini [2009/03/14 19:08:08 | 00,000,034 | ---- | C] () -- C:\Users\Michael\AppData\Roaming\pcouffin.log [2009/03/14 19:07:07 | 00,087,608 | ---- | C] () -- C:\Users\Michael\AppData\Roaming\inst.exe [2009/03/14 19:07:07 | 00,007,887 | ---- | C] () -- C:\Users\Michael\AppData\Roaming\pcouffin.cat [2009/03/14 19:07:07 | 00,001,144 | ---- | C] () -- C:\Users\Michael\AppData\Roaming\pcouffin.inf [2009/03/14 18:58:19 | 00,000,671 | ---- | C] () -- C:\Users\Michael\AppData\Roaming\vso_ts_preview.xml [2009/03/12 19:39:15 | 00,815,104 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2009/03/12 19:39:15 | 00,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll [2009/03/08 15:19:59 | 00,010,752 | ---- | C] () -- C:\Users\Michael\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/02/27 19:10:53 | 00,139,904 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2009/02/27 19:10:53 | 00,022,328 | ---- | C] () -- C:\Users\Michael\AppData\Roaming\PnkBstrK.sys [2009/02/26 17:54:15 | 02,978,722 | -H-- | C] () -- C:\Users\Michael\AppData\Local\IconCache.db [2009/02/26 17:49:25 | 00,051,504 | ---- | C] () -- C:\Users\Michael\AppData\Local\GDIPFONTCACHEV1.DAT [2009/02/04 00:00:07 | 00,011,264 | ---- | C] () -- C:\Windows\System32\atimuixx.dll [2006/12/12 22:46:07 | 00,013,952 | ---- | C] () -- C:\Windows\System32\drivers\UBHelper.sys [2006/12/12 22:17:29 | 00,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN4.dll [2006/12/12 21:22:55 | 00,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1129.dll [2006/12/12 21:22:55 | 00,001,029 | ---- | C] () -- C:\Windows\generic.ini [2006/12/12 21:22:55 | 00,000,117 | ---- | C] () -- C:\Windows\Alaunch.ini [2006/12/12 21:22:54 | 00,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll [2006/11/16 14:20:10 | 00,086,016 | ---- | C] () -- C:\Windows\System32\MSNSpook.dll [2006/11/16 14:19:10 | 00,037,376 | ---- | C] () -- C:\Windows\System32\MSNChatHook.dll [2006/11/02 07:50:50 | 00,000,174 | -HS- | C] () -- C:\Program Files\desktop.ini [2006/11/02 07:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006/11/02 05:23:31 | 00,000,518 | ---- | C] () -- C:\Windows\win.ini [2006/11/02 05:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini [2006/11/02 03:43:04 | 00,061,952 | ---- | C] () -- C:\Windows\System32\cngaudit.dll [2006/11/02 02:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006/06/26 10:33:40 | 00,023,472 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys [2001/12/26 18:12:30 | 00,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll [2001/09/04 01:46:38 | 00,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll [2001/07/30 18:33:56 | 00,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll [2001/07/24 00:04:36 | 00,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll ========== LOP Check ========== [2006/11/02 07:37:34 | 00,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming [2006/11/02 07:37:34 | 00,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Media Center Programs [2006/11/02 07:37:34 | 00,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming [2006/11/02 07:37:34 | 00,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Media Center Programs [2009/10/24 14:05:11 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming [2009/08/23 15:21:35 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\acccore [2009/02/26 18:00:24 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Acer [2009/02/27 22:23:57 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\ATI [2009/05/18 17:31:29 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Datarescue [2009/03/14 13:40:16 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\ESET [2009/10/23 19:49:31 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\FileZilla [2009/10/24 12:04:44 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\HLSW [2009/05/02 13:37:39 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\ImgBurn [2009/03/23 16:39:10 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\JCreator [2009/02/26 18:00:22 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Leadertech [2009/09/21 20:52:11 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\LimeWire [2009/09/04 16:20:47 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Mael [2006/11/02 07:37:34 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Media Center Programs [2009/09/28 20:46:32 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mIRC [2009/10/13 18:23:31 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\mjusbsp [2009/09/04 16:37:05 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Notepad++ [2009/07/30 15:25:56 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Renoise [2009/08/29 12:20:54 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\SmartFTP [2009/05/16 13:57:27 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Subversion [2009/05/24 11:27:15 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\TortoiseSVN [2009/10/24 12:55:21 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\uTorrent [2009/03/20 21:17:38 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Ventrilo [2009/05/02 12:42:09 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Vso [2009/09/15 20:20:02 | 00,000,000 | ---D | M] -- C:\Users\Michael\AppData\Roaming\Warsow [2009/07/27 11:57:07 | 00,000,000 | ---D | M] -- C:\Users\Michael_2\AppData\Roaming [2009/06/27 17:03:48 | 00,000,000 | ---D | M] -- C:\Users\Michael_2\AppData\Roaming\ATI [2006/11/02 07:37:34 | 00,000,000 | ---D | M] -- C:\Users\Michael_2\AppData\Roaming\Media Center Programs [2009/07/27 11:57:07 | 00,000,000 | ---D | M] -- C:\Users\Michael_2\AppData\Roaming\Subversion [2009/10/24 14:47:53 | 00,000,868 | ---- | M] () -- C:\Windows\Tasks\Google Software Updater.job [2009/10/24 14:51:15 | 00,000,882 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [2009/10/24 15:33:01 | 00,000,886 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [2009/10/24 14:45:25 | 00,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT [2009/10/24 13:31:46 | 00,032,614 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < %systemroot%\system32\eventlog.dll > < %systemroot%\system32\scecli.dll > [2006/11/02 04:46:12 | 00,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\scecli.dll [2 C:\Windows\system32\*.tmp files] < %systemroot%\netlogon.dll > < %systemroot%\system32\cngaudit.dll > [2006/11/02 04:46:03 | 00,061,952 | ---- | M] () -- C:\Windows\system32\cngaudit.dll [2 C:\Windows\system32\*.tmp files] < %systemroot%\system32\sceclt.dll > < %systemroot%\ntelogon.dll > < %systemroot%\system32\logevent.dll > [2006/11/02 04:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\logevent.dll [2 C:\Windows\system32\*.tmp files] < %systemroot%\system32\drivers\iaStor.sys > [2006/06/13 15:56:40 | 00,247,808 | ---- | M] (Intel Corporation) -- C:\Windows\system32\drivers\iaStor.sys < %systemroot%\System32\drivers\nvstor.sys > [2006/11/02 04:50:13 | 00,040,040 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvstor.sys < %systemroot%\system32\drivers\atapi.sys > [2009/02/27 16:28:20 | 00,021,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\drivers\atapi.sys < %systemroot%\system32\drivers\IdeChnDr.sys > ========== Alternate Data Streams ========== @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:54D4173A < End of report > Extras Log: OTL Extras logfile created on: 10/24/2009 3:33:47 PM - Run 1 OTL by OldTimer - Version 3.0.22.1 Folder = C:\Users\Michael\Desktop Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 7.0.6000.16916) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1021.87 Mb Total Physical Memory | 312.54 Mb Available Physical Memory | 30.58% Memory free 2.26 Gb Paging File | 1.24 Gb Available in Paging File | 54.79% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 113.20 Gb Total Space | 43.69 Gb Free Space | 38.60% Space Free | Partition Type: NTFS Drive D: | 112.85 Gb Total Space | 83.24 Gb Free Space | 73.76% Space Free | Partition Type: NTFS Drive E: | 4.38 Gb Total Space | 4.24 Gb Free Space | 96.82% Space Free | Partition Type: UDF F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: MICHAEL-PC Current User Name: Michael Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 14 Days Output = Standard Quick Scan ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation) .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* File not found helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "UacDisableNotify" = 0 "InternetSettingsDisableNotify" = 0 "AutoUpdateDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{068ECA10-8A02-4B04-8502-7290E9EEA4C9}" = rport=139 | protocol=6 | dir=out | app=system | "{1C1BF42B-1E82-48B3-BA05-2A0C46FE2677}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 | "{23AE9CD6-73D5-4BDB-87A6-70BE1C59F767}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{23E2CC50-7BF5-4561-99C7-F92D714BFE4D}" = lport=138 | protocol=17 | dir=in | app=system | "{25AD4EE5-F33E-4A28-A7B1-1E38123DF7D2}" = lport=137 | protocol=17 | dir=in | app=system | "{2C507BA4-6395-41B1-A3BB-60FF23EF97E9}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{3771231F-13D7-42AC-8111-6910CBD93E1F}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 | "{3B2A6122-E572-4027-9D03-BC250E0AB4FF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{4CBDA73F-C141-43CE-A12F-BB3A9C6E9F28}" = rport=137 | protocol=17 | dir=out | app=system | "{5B23B3C1-449E-4101-8351-0465530C2B95}" = lport=1735 | protocol=6 | dir=in | name=eaviphiv | "{6C0C1057-D978-41D7-84C4-9E9F5A03F7E8}" = lport=445 | protocol=6 | dir=in | app=system | "{70D9BA0B-0063-4ACA-8654-C27D75C75261}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{BA04F881-2E53-46DF-89F6-D059F7A83736}" = lport=80 | protocol=6 | dir=in | name=apache | "{BB865549-537C-4897-9ACE-88A359746D18}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{C37F7013-D53B-4542-A71A-2775B642F9FD}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{C9745962-C16B-451B-82E2-043042571869}" = lport=139 | protocol=6 | dir=in | app=system | "{D9E5C5B2-5CC8-4E21-9BDF-CC236D21BFE5}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{DA5C52C8-F98C-418E-903E-7A097B8F6B58}" = lport=2869 | protocol=6 | dir=in | app=system | "{E8FB4CD6-CAB5-416A-97E1-998C8392AD20}" = lport=80 | protocol=17 | dir=in | name=apache | "{EF06B059-1896-46EA-AB9D-3FBFDA9F9EE5}" = rport=445 | protocol=6 | dir=out | app=system | "{F5C897D3-9FFC-4C91-A588-470A8741656F}" = rport=138 | protocol=17 | dir=out | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{04BA2E6E-44D8-4A03-A27E-FC830ECB08D6}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe | "{0661BA2C-0E6B-4518-B25D-5ED01D24F6B9}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe | "{07A46220-80AB-4911-ABA0-F24941DDAEAD}" = protocol=6 | dir=in | app=c:\users\michael\appdata\roaming\mjusbsp\magicjack.exe | "{167C6915-AD96-405E-B605-203F97290411}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe | "{16E1EDB1-A15D-4D9D-A85E-25BC964EDA54}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-0.3.0.10522-enus-ptr-downloader.exe | "{176476BF-A21E-4C2D-892E-8899031EF779}" = protocol=17 | dir=in | app=c:\users\michael\appdata\roaming\mjusbsp\magicjack.exe | "{1D78E303-70E9-4943-A079-2F7E5DA36309}" = protocol=6 | dir=in | app=c:\program files\acer zone\acer zone softdma\softdma.exe | "{1F60CDE7-D481-44A4-98F0-A30C1862CC06}" = protocol=17 | dir=in | app=c:\program files\acer zone\acer zone softdma\softdma.exe | "{259177E6-B9A0-444F-9A31-039A5B533BBE}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe | "{2BE66DC6-08FB-435D-80BE-8A1399C08448}" = protocol=17 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe | "{2CCC04A8-305F-437D-9878-473E45BD9CE7}" = protocol=17 | dir=in | app=d:\program files\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\xr_3da.exe | "{2D7907D7-31EB-4734-9B4E-AAC7155FCB45}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{3CF2E0F9-A144-4AB0-B430-0EC3D9B6C6BE}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-0.3.0.10571-to-0.3.0.10596-enus-ptr-downloader.exe | "{44F5C103-1111-46A3-925C-1C80AD0488F5}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe | "{4A5617ED-3FCC-4B49-8CFE-39E64490C1FA}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe | "{4E61581C-3707-4123-9072-A2F58F124724}" = protocol=6 | dir=in | app=d:\program files\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\xr_3da.exe | "{53A9F2F5-65B2-41A4-8F6E-6039C0190BFC}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{545E20A9-04ED-42C9-861E-602B5AB56569}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe | "{569A1AC5-0619-433F-88D2-58ECA3E2B578}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{5D5B4EBC-605F-4CB6-8A4B-A7688CC11530}" = dir=in | app=c:\program files\avg\avg9\avgupd.exe | "{6095D56A-C749-4B74-B933-4EA63557F2E5}" = dir=in | app=c:\program files\avg\avg9\avgdiagex.exe | "{642287D5-2E06-4A01-B33D-261440D83042}" = protocol=17 | dir=in | app=c:\program files\acer zone\acer zone main page\mce deluxe suite.exe | "{65A75A0C-11D7-4D00-81EA-BF7B80219122}" = dir=in | app=c:\program files\avg\avg9\avgnsx.exe | "{6AC9D0A6-D988-492A-9291-6028EB3F274E}" = dir=in | app=c:\program files\avg\avg9\avgam.exe | "{7112D327-523F-4220-AA94-10B17C488C63}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe | "{7601C2B2-0371-44AB-B77C-74222A7BCAA7}" = protocol=17 | dir=in | app=c:\program files\acer zone\acer picture slide dvd\component\clsldvd.exe | "{798D38B2-F81A-4EB7-8BC2-E015E018CBC7}" = protocol=6 | dir=in | app=d:\program files\smartftp client\smartftp.exe | "{87024B47-8663-4778-93AD-BE79976DE572}" = protocol=17 | dir=in | app=d:\program files\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\dedicated\xr_3da.exe | "{884C0214-E5EC-48FA-91B3-10C8777F326F}" = protocol=6 | dir=in | app=d:\program files\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\dedicated\xr_3da.exe | "{89BBC071-8908-4460-A7B4-6F8A8F8BF845}" = protocol=6 | dir=in | app=c:\program files\acer zone\acer picture slide dvd\component\clsldvd.exe | "{92791BE2-254D-4CCE-8E81-373A0DEC1921}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe | "{954E4407-A0BD-4F1A-9CF9-75487AED7AE1}" = protocol=6 | dir=in | app=c:\program files\acer zone\acer plug and record\component\dvax2process.exe | "{95859EB9-E3FE-447A-AB74-6C66E8FE00C5}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-0.3.0.10571-to-0.3.0.10596-enus-ptr-downloader.exe | "{9670EFFB-4C48-4811-80C1-EBFD813CE114}" = protocol=6 | dir=in | app=d:\world of warcraft ps\backgrounddownloader.exe | "{969E8518-922A-4D9F-B3AE-EDA7FD994711}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe | "{9C5A90EA-8C90-40EB-B360-F57DEBC65F02}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-0.3.0.10554-to-0.3.0.10571-enus-ptr-downloader.exe | "{9FF30AB1-6D96-464A-B6AC-5F6676B6D132}" = protocol=17 | dir=in | app=d:\world of warcraft ps\backgrounddownloader.exe | "{A1987ECD-2321-42DB-B9C0-7DB176A8F5D5}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{A850B542-5E0D-45F4-897F-57F4C005BE85}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe | "{AA7A3A9C-5DA7-4CA1-B385-8B2565DA73D4}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{AB99C17F-678B-44DA-85E8-CC6DBF042482}" = protocol=17 | dir=in | app=d:\program files\smartftp client\smartftp.exe | "{ACF88DCE-FA43-4EE6-9A89-6E9E183B906F}" = protocol=17 | dir=in | app=d:\combat arms\nmservice.exe | "{AD5C0732-F722-4859-AE16-B32CE74E0916}" = protocol=6 | dir=in | app=c:\program files\acer zone\acer zone main page\mce deluxe suite.exe | "{AF26E52A-F89F-4D07-B5F2-4E96A67723DC}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-0.3.0.10522-to-0.3.0.10554-enus-ptr-downloader.exe | "{B7907916-D45F-467D-B166-54E8D6824F90}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe | "{BBD9AD56-056D-4ABF-811F-5D3280A5511E}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-0.3.0.10554-to-0.3.0.10571-enus-ptr-downloader.exe | "{BF3AEAD9-D747-45C9-ACF6-C41566EE1CED}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{C0024237-3E77-491F-98D8-827F95B5EC16}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe | "{C31A35D3-376F-4F94-9B28-0A63448A24C1}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe | "{C4694198-63D5-483E-A87C-87E8BEFEAE57}" = protocol=6 | dir=in | app=c:\program files\acer zone\acer plug and record\component\arawp.exe | "{C47E397A-0BD7-49CC-8014-8E209657F25F}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{C60F270B-F38C-42B1-9FC0-9475126F2C27}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{C77F3757-EB3F-4851-8F9F-24F743561F01}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe | "{CBA2C7D8-8D2B-4D50-A3B9-D8CD3E6867FC}" = protocol=6 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe | "{CE5BC572-45FC-425A-9A16-167D328EEA00}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe | "{CF72FB78-EAD1-4A47-BC94-CF5B99122B34}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{CF99901E-C817-4C67-83BB-B096D8AF0CFD}" = protocol=17 | dir=in | app=c:\program files\acer zone\acer plug and record\component\arawp.exe | "{CFFB5CC4-0371-4218-A146-EC52277CBDCB}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{D1B8133B-9347-4BF5-BE0B-A6C1C11805C9}" = protocol=6 | dir=in | app=d:\combat arms\nmservice.exe | "{D3A3E982-306F-4481-BB85-C7616A14811D}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-0.3.0.10522-to-0.3.0.10554-enus-ptr-downloader.exe | "{D3D73BCE-9299-4D35-A897-D6A121C99D00}" = protocol=6 | dir=in | app=c:\users\michael\desktop\hacks\hiv.exe | "{D5A7ECFD-4E6C-4BDC-96F7-0B8860C7CF9A}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{D669B33E-B05B-40ED-9BDD-44675FB5D4EE}" = dir=in | app=c:\program files\avg\avg9\avgemc.exe | "{D9EFF23B-89B5-46F1-87D8-064ADA40B8E5}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe | "{DA03857F-513D-4FBA-95A5-F346CBB0304D}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe | "{DC16D869-87FE-4887-87D2-0D20C84FFB22}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe | "{E758B8F6-DBB4-4FEC-986D-1F7F103176AC}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe | "{EDAE6165-B53F-4736-8ED2-31D3053D0C07}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe | "{F83598BE-AC2A-4EED-A7F4-83C8E99DB965}" = protocol=17 | dir=in | app=c:\program files\acer zone\acer plug and record\component\dvax2process.exe | "{F8E35B0B-6F7C-4F5A-8D72-C769E1F953EF}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-0.3.0.10522-enus-ptr-downloader.exe | "{F9763A84-6AE8-4A8D-880F-A26FE5EFEA7E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{FB0ACEEA-FE28-435B-AA04-A1C2C3F1BAEA}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe | "{FC9747AD-836F-4D94-9141-F7EF90B232BE}" = protocol=17 | dir=in | app=c:\users\michael\desktop\hacks\hiv.exe | "{FCBAD027-9CF6-4B8C-980C-1BAE666EBD9A}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe | "{FDD26DE0-3FA3-4484-8CBC-77D4A84DF05E}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe | "TCP Query User{0778D959-3EF1-4D7C-A27C-55D987DFF8E0}C:\program files\steam\steamapps\sgtbaker\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\sgtbaker\counter-strike source\hl2.exe | "TCP Query User{084866D9-5AD7-4523-B330-FEEBBBF87E76}D:\program files\valve\half-life\hl.exe" = protocol=6 | dir=in | app=d:\program files\valve\half-life\hl.exe | "TCP Query User{12E6DC48-0D52-4C2A-8784-16C1A55BB62E}C:\program files\steam\steamapps\twocrazymen23\garrysmod\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\twocrazymen23\garrysmod\hl2.exe | "TCP Query User{1A9E03F0-B364-49D3-B569-9D0C2F02E278}C:\program files\steam\steamapps\enkouchan\garrysmod\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\enkouchan\garrysmod\hl2.exe | "TCP Query User{1CF0D186-7D47-4E53-A2AE-EE9C25FAB7F5}C:\program files\steam\steamapps\twocrazymen23\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\twocrazymen23\counter-strike source\hl2.exe | "TCP Query User{21E9165B-757D-41A2-B7F4-EE54493DA459}D:\world of warcraft public test\launcher.exe" = protocol=6 | dir=in | app=d:\world of warcraft public test\launcher.exe | "TCP Query User{2D5077FA-99CD-4A6C-873C-B2FF92C8AD9B}C:\program files\steam\steamapps\enkouchan\ricochet\hl.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\enkouchan\ricochet\hl.exe | "TCP Query User{4C76D329-AFCB-4836-9DF0-326BBAE89FDD}C:\program files\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files\mirc\mirc.exe | "TCP Query User{57076E6F-F4AE-4D43-8F3F-EF59CA002EB9}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "TCP Query User{5B938AF2-0383-4FAD-9BE6-B0BEDC0FFF73}C:\program files\steam\steamapps\pwner553\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\pwner553\counter-strike source\hl2.exe | "TCP Query User{88D600F5-9C0B-48D0-99A4-824A78B318E8}C:\program files\steam\steamapps\pwner553\garrysmod\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\pwner553\garrysmod\hl2.exe | "TCP Query User{8ECD5F4F-0EF6-416A-9AAF-D01E46E57724}C:\windows\system32\java.exe" = protocol=6 | dir=in | app=c:\windows\system32\java.exe | "TCP Query User{98944721-2A7F-401B-A78B-648CC51A95E6}C:\webserver\xampp\mysql\bin\mysqld.exe" = protocol=6 | dir=in | app=c:\webserver\xampp\mysql\bin\mysqld.exe | "TCP Query User{AD616A91-F7EC-4062-AA67-1B1046C1F3B8}C:\program files\steam\steamapps\enkouchan\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\enkouchan\counter-strike source\hl2.exe | "TCP Query User{B7A305FF-9309-4422-B420-3C069B235709}C:\webserver\xampp\apache\bin\apache.exe" = protocol=6 | dir=in | app=c:\webserver\xampp\apache\bin\apache.exe | "TCP Query User{C598F16A-A519-421B-8324-23BDF5F28899}C:\program files\steam\steamapps\core435\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\core435\counter-strike source\hl2.exe | "TCP Query User{CC2C4D75-009E-4870-9012-A0EB7DF1FF09}C:\program files\steam\steamapps\pwner553\counter-strike\hl.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\pwner553\counter-strike\hl.exe | "TCP Query User{DDAFD525-CD04-498A-A56E-226C03062E8F}D:\world of warcraft ps\launcher.exe" = protocol=6 | dir=in | app=d:\world of warcraft ps\launcher.exe | "TCP Query User{DFC64B3F-B45F-48D6-A308-B7EC1F4259AF}D:\program files\wolfenstein - enemy territory\et.exe" = protocol=6 | dir=in | app=d:\program files\wolfenstein - enemy territory\et.exe | "TCP Query User{E4DF2091-B164-47BF-B936-D50982B1CB76}C:\program files\ventsrv\ventrilo_srv.exe" = protocol=6 | dir=in | app=c:\program files\ventsrv\ventrilo_srv.exe | "TCP Query User{EEE1FA31-35EE-447F-9289-2AF7F2FD318A}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe | "UDP Query User{06BF7D5E-D77F-46BE-B391-0795FD03A5D0}C:\program files\steam\steamapps\sgtbaker\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\sgtbaker\counter-strike source\hl2.exe | "UDP Query User{18E738D0-104B-49EA-A2D6-3332AC90E090}C:\program files\steam\steamapps\pwner553\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\pwner553\counter-strike source\hl2.exe | "UDP Query User{3A7D0D43-3E22-40A7-B829-0E9B7EBF3EC5}C:\program files\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files\mirc\mirc.exe | "UDP Query User{51122165-718F-4412-8EC8-C09D5A48FFC7}D:\world of warcraft public test\launcher.exe" = protocol=17 | dir=in | app=d:\world of warcraft public test\launcher.exe | "UDP Query User{5273E7D1-45E1-4F58-9570-C105BCFE16F2}C:\windows\system32\java.exe" = protocol=17 | dir=in | app=c:\windows\system32\java.exe | "UDP Query User{5A1306D1-2ED6-4865-AECD-D2122C399E5D}C:\program files\steam\steamapps\pwner553\garrysmod\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\pwner553\garrysmod\hl2.exe | "UDP Query User{62D948FB-84A0-4A63-ABBD-AAE964486514}C:\webserver\xampp\mysql\bin\mysqld.exe" = protocol=17 | dir=in | app=c:\webserver\xampp\mysql\bin\mysqld.exe | "UDP Query User{66DDE59E-7511-4D99-84F0-55C679CB9FCF}C:\webserver\xampp\apache\bin\apache.exe" = protocol=17 | dir=in | app=c:\webserver\xampp\apache\bin\apache.exe | "UDP Query User{7BE51F73-91CF-4AB1-8FED-07D3184B0387}D:\program files\valve\half-life\hl.exe" = protocol=17 | dir=in | app=d:\program files\valve\half-life\hl.exe | "UDP Query User{8290A9A4-0B9A-4716-B27A-AF497C36507A}C:\program files\steam\steamapps\enkouchan\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\enkouchan\counter-strike source\hl2.exe | "UDP Query User{835E2B49-EADA-4E39-99FB-E74695DE4BBA}D:\world of warcraft ps\launcher.exe" = protocol=17 | dir=in | app=d:\world of warcraft ps\launcher.exe | "UDP Query User{8629AA92-A593-40EA-8D22-DB7DEEDDF69A}C:\program files\steam\steamapps\enkouchan\garrysmod\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\enkouchan\garrysmod\hl2.exe | "UDP Query User{8630B0F7-7528-4E0B-A3AB-7DA1B5B9A3B1}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe | "UDP Query User{9F96D305-FA2B-49DA-90E2-BD6652A8BA37}D:\program files\wolfenstein - enemy territory\et.exe" = protocol=17 | dir=in | app=d:\program files\wolfenstein - enemy territory\et.exe | "UDP Query User{BC9338C3-ED63-46AD-ACE9-D9F4E95DA452}C:\program files\steam\steamapps\pwner553\counter-strike\hl.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\pwner553\counter-strike\hl.exe | "UDP Query User{C1958EAB-4B88-4C4A-8A4E-0881F8E77D02}C:\program files\steam\steamapps\core435\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\core435\counter-strike source\hl2.exe | "UDP Query User{C6F44333-F8EE-4664-9F20-128084CFB384}C:\program files\steam\steamapps\twocrazymen23\garrysmod\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\twocrazymen23\garrysmod\hl2.exe | "UDP Query User{D6A3AB4A-B202-4A5C-846D-561E3E7469CF}C:\program files\ventsrv\ventrilo_srv.exe" = protocol=17 | dir=in | app=c:\program files\ventsrv\ventrilo_srv.exe | "UDP Query User{E0E424E4-9335-41E8-A1C5-6154427F32E6}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "UDP Query User{E7C70071-6A4E-4CF4-A21E-67CB1A0DF166}C:\program files\steam\steamapps\twocrazymen23\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\twocrazymen23\counter-strike source\hl2.exe | "UDP Query User{FF83208A-8840-49BF-A8B2-632E1F60DF76}C:\program files\steam\steamapps\enkouchan\ricochet\hl.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\enkouchan\ricochet\hl.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4 "{02EBDBB9-4600-41D3-B566-40CB861511D2}" = World of Warcraft FREE Trial "{03DEEAD2-F3B7-45BF-9006-A25D015F00D2}" = Adobe Flash Player 10 Plugin "{044F9133-B8D7-4d11-BF39-803FA20F5C8B}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32 "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3 "{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4 "{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4 "{05EC21B8-4593-3037-A781-A6B5AFFCB19D}" = Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools - enu "{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour "{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting "{098727E1-775A-4450-B573-3F441F1CA243}" = kuler "{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger "{0C19D563-5F25-4621-BF10-01F741BD283F}" = Microsoft SQL Server Compact 3.5 SP1 Design Tools English "{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4 "{0DF3AE91-E533-3960-8516-B23737F8B7A2}" = Visual C++ 2008 x64 Runtime - (v9.0.30729) "{0DF3AE91-E533-3960-8516-B23737F8B7A2}.vc_x64runtime_30729_01" = Visual C++ 2008 x64 Runtime - v9.0.30729.01 "{0ED1A22E-39F3-0B9A-FFDC-33ABCEE505C0}" = Skins "{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4 "{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker "{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4 "{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4 "{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin "{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR "{1D46A3A0-B37D-423A-91C2-101A49E2FF80}" = Ventrilo Server "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool "{2168245A-B5AD-40D8-A641-48E3E070B5B6}" = Adobe Flash CS4 STI-en "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{22E23C71-C27A-3F30-8849-BB6129E50679}" = Visual C++ 2008 IA64 Runtime - (v9.0.30729) "{22E23C71-C27A-3F30-8849-BB6129E50679}.vc_i64runtime_30729_01" = Visual C++ 2008 IA64 Runtime - v9.0.30729.01 "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{23A858EF-56C9-408A-B1F0-A0E40124FF8A}" = SmartFTP Client "{241F2BF7-69EB-42A4-9156-96B2426C7504}" = Microsoft SQL Server Compact 3.5 for Devices ENU "{24508D50-EB8F-4FE6-B69D-B4935D8745EF}_is1" = Warsow 0.42 "{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java 6 Update 13 "{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition "{291B3A3B-F808-45B8-8113-DF232FCB6C82}" = Microsoft .NET Compact Framework 3.5 "{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3 "{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS) "{32A3A4F4-B792-11D6-A78A-00B0D0160120}" = Java SE Development Kit 6 Update 12 "{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}" = SQL Server System CLR Types "{35CB6715-41F8-4F99-8881-6FC75BF054B0}" = Oblivion "{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4 "{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime "{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player "{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4 "{3A6829EF-0791-4FDD-9382-C690DD0821B9}" = Adobe Flash Player 10 ActiveX "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform "{3C11D2DA-6802-3F66-BE6B-B2C046AFE866}" = Visual C++ 2008 x64 Runtime - (v9.0.30729.4148) "{3C11D2DA-6802-3F66-BE6B-B2C046AFE866}.vc_x64runtime_30729_4148" = Visual C++ 2008 x64 Runtime - v9.0.30729.4148 "{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3 "{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin "{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit "{4402084F-61EE-48B2-AFCB-AC1EC2454C79}" = MySQL Server 5.1 "{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant "{49253DE2-FC99-4BE3-99A4-DAB01A8E6088}" = Camtasia Studio 6 "{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension "{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English) "{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3 "{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4 "{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer "{5A3E8FF2-F163-2B00-9B47-D8C84CF12C7A}" = Catalyst Control Center InstallProxy "{5B3A354B-C059-4861-A85B-CA46F1089E15}" = Creative USB Headsets "{5BE1E709-30E4-3D6D-A708-96CE8D5E5E8D}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu "{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support "{6468C32A-026A-37DD-A013-C8A8B0995B52}" = Catalyst Control Center Graphics Light "{64c5b887-b5ee-42b8-8596-78905a6b5f1f}" = Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense "{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008 "{67A58A97-9612-C607-0245-F3F417EFDB6D}" = Catalyst Control Center Core Implementation "{67ADE9AF-5CD9-4089-8825-55DE4B366799}" = NTI Backup NOW! 4.7 "{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4 "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{69F6B6BC-D64C-BE30-6334-C7A76E9FF2AD}" = CCC Help English "{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All "{6C9F6D23-E9AD-43C9-B43A-011562AAF876}" = Windows Mobile 5.0 SDK R2 for Pocket PC "{6F2A00E1-46C9-6DAE-E6E3-BEE4C9D5A0C3}" = ccc-core-static "{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3 "{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.3.4.107 "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{793D1D88-6141-43DE-BE58-59BCE31B4090}" = Adobe Flash CS4 Extension - Flash Lite STI en "{7B33F480-496D-334A-BAC2-205DEC0CBC2D}" = Visual C++ 2008 x86 Runtime - (v9.0.30729.4148) "{7B33F480-496D-334A-BAC2-205DEC0CBC2D}.vc_x86runtime_30729_4148" = Visual C++ 2008 x86 Runtime - v9.0.30729.4148 "{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3 "{80C06CCD-7D07-3DB6-86CD-B57B3F0614D8}" = Microsoft Visual Studio Team System 2008 Team Suite - ENU "{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer "{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4 "{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4 "{842FAF7C-50EF-4463-9B8F-6222E1384D7D}" = Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries "{8AC049F7-1383-45C3-9E7D-F93CA667F9E1}" = UMVPLStandalone "{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3 "{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime "{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard "{90120000-0021-0000-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer 2007 "{90120000-0021-0000-0000-0000000FF1CE}_VisualWebDeveloper_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{90120000-0021-0409-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3 "{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4 "{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4 "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9656F3AC-6BA9-43F0-ABED-F214B5DAB27B}" = Windows Mobile 5.0 SDK R2 for Smartphone "{998D6972-F58E-479D-9248-8F179E55AE38}" = Java DB 10.4.1.3 "{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}" = iTunes "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9A33B83D-FFC4-44CF-BEEF-632DECEF2FCD}" = Microsoft SQL Server Database Publishing Wizard 1.3 "{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3 "{9cc89170-000b-457d-91f1-53691f85b223}" = Python 2.6.1 "{9D1DE3AD-75C5-9C43-3F07-206600BB2D30}" = Catalyst Control Center Graphics Full New "{9F827E95-123C-EAA5-6CCD-9D9E8FC2A80E}" = ATI Catalyst Install Manager "{A035580E-3EDF-EA34-F229-0E17DF3A6E7C}" = ccc-utility "{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific "{A3797713-6859-379F-4E0C-ADCB3BE3C87E}" = Catalyst Control Center Graphics Previews Common "{A5D254CC-7E37-48D6-A013-895A9A4EB91E}" = Quake Live Internet Explorer Plugin "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AA467959-A1D6-4F45-90CD-11DC57733F32}" = Crystal Reports Basic for Visual Studio 2008 "{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0 "{AFF84D5E-EB68-728E-1BD5-10BCFDCF25FF}" = Catalyst Control Center HydraVision Full "{B268E9A1-04A9-40D0-9866-846BE2B74BA7}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Win32 Tools "{B28FC790-C93F-3A9C-A913-7E891487D1F1}" = Visual C++ 2008 IA64 Runtime - (v9.0.30729.4148) "{B28FC790-C93F-3A9C-A913-7E891487D1F1}.vc_i64runtime_30729_4148" = Visual C++ 2008 IA64 Runtime - v9.0.30729.4148 "{B29AD377-CC12-490A-A480-1452337C618D}" = Connect "{B32E7732-B2FB-3FD0-81AC-6025B1104C66}" = Microsoft Device Emulator version 3.0 - ENU "{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0 "{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module "{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client "{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5 "{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component "{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2 "{C337BDAF-CB4E-47E2-BE1A-CB31BB7DD0E3}" = Apple Mobile Device Support "{C357E7BE-A832-CFAF-A1B2-23EC0C08011E}" = Catalyst Control Center Graphics Previews Vista "{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries "{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4 "{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials "{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime "{CAA376AF-0DE8-4FCA-942E-C6AC579B94B3}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Tools "{CC016F21-3970-11DE-B878-005056806466}" = Google Earth "{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client "{D244622B-F2BC-AD1E-6BA6-40345EC55BAA}" = Catalyst Control Center Graphics Full Existing "{D3B1C799-CB73-42DE-BA0F-2344793A095C}" = Catalyst Control Center - Branding "{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker "{D8087907-E255-3A41-A46D-D0F798709C71}" = Microsoft Visual C++ 2008 Express Edition with SP1 - ENU "{DD622B1D-A78E-3FE8-9C8C-246F5764B0D0}" = Microsoft Visual Basic 2008 Express Edition with SP1 - ENU "{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4 "{E1180142-3B31-4DCC-9D27-7AC2D37662BF}" = LightScribe 1.4.124.1 "{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English "{E5CFDA19-A86E-4276-AB8E-5165E2FC98B8}" = Hero_Online "{E5FCED12-3E77-4C0E-A305-5AEB38A52A70}" = AdobeColorCommonSetCMYK "{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3 "{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator "{EB3F5C2A-0754-38B8-8722-7B537006BF46}" = Microsoft Visual Studio 2008 Performance Collection Tools - ENU "{EC42ED6A-751D-45C0-A4F9-8CD00E4690FC}" = Logitech QuickCam "{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin "{EDDF99D9-9FE3-4871-A7DB-D1522C51EE9A}" = Microsoft .NET Compact Framework 2.0 SP2 "{EED50C97-C79E-4149-BD82-7C5A22437708}" = Adobe Setup "{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F1A14CB2-A048-45A6-AFDA-3571296E1D76}" = Creative Media Toolbox 6 "{F2E36994-BCB8-4035-B45A-4F37D64BFC8F}" = Jiffy Gmail Creator "{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729) "{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01 "{F5E87B12-3C27-452F-8E78-21D42164FD83}" = Microsoft SQL Server 2008 Management Objects "{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call "{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4 "{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4 "{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4 "{FC2642E7-9CA0-49A2-B785-2647699E571A}" = Jiffy Gmail Creator "{FCA37CD2-7BA4-4A5A-8979-B64EA712F4CB}" = TortoiseSVN 1.6.2.16344 (32 bit) "{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner "{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup "{FF29527A-44CD-3422-945E-981A13584000}" = VC Runtimes MSI "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3 "Adobe_a68eec966ce913ddaa63251dc82ed31" = Adobe Flash CS4 Professional "Advanced Port Scanner v1.3" = Advanced Port Scanner v1.3 "AIM_6" = AIM 6 "ALchemy X-Fi" = Creative ALchemy (X-Fi Edition) "AV Voice Changer Software DIAMOND 6.0" = AV Voice Changer Software DIAMOND 6.0 "AVG9Uninstall" = AVG 9.0 "Cavaj Java Decompiler" = Cavaj Java Decompiler "Cheat Engine 5.5_is1" = Cheat Engine 5.5 "com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player "Combat Arms" = Combat Arms "Creative Software AutoUpdate" = Creative Software AutoUpdate "Diablo II" = Diablo II "Diablo II Shareware" = Diablo II Shareware "Google Updater" = Google Updater "Guitar Pro 5_is1" = Guitar Pro 5.2 "Half-Life_is1" = Half-Life "HotspotShield" = Hotspot Shield 1.30 "HxD Hex Editor_is1" = HxD Hex Editor version 1.7.7.0 "IDA Pro Free_is1" = IDA Pro Free v4.9 "ImgBurn" = ImgBurn "InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker "JCreator Pro_is1" = JCreator Pro 4.50 "LimeWire" = LimeWire 5.1.2 "Magic ISO Maker v5.5 (build 0261)" = Magic ISO Maker v5.5 (build 0261) "MagicDisc 2.7.106" = MagicDisc 2.7.106 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008 "Microsoft SQL Server 2005" = Microsoft SQL Server 2005 "Microsoft Visual Basic 2008 Express Edition with SP1 - ENU" = Microsoft Visual Basic 2008 Express Edition with SP1 - ENU "Microsoft Visual C++ 2008 Express Edition with SP1 - ENU" = Microsoft Visual C++ 2008 Express Edition with SP1 - ENU "Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime "Microsoft Visual Studio Team System 2008 Team Suite - ENU" = Microsoft Visual Studio Team System 2008 Team Suite - ENU "mIRC" = mIRC "Mozilla Firefox (3.0.14)" = Mozilla Firefox (3.0.14) "No-IP.com DUC" = No-IP.com DUC (remove only) "PremiumSoft Navicat Lite 8.2_is1" = PremiumSoft Navicat Lite 8.2 "PunkBusterSvc" = PunkBuster Services "QcDrv" = Logitech® Camera Driver "Renoise 2.0.0_is1" = Renoise 2.0.0 "S.T.A.L.K.E.R. - Shadow of Chernobyl_is1" = S.T.A.L.K.E.R. - Shadow of Chernobyl [v1.0004] "Sandboxie" = Sandboxie 3.38 "ShockwaveFlash" = Adobe Flash Player 9 ActiveX "SmartFTP Client 3.0 Setup Files" = SmartFTP Client 3.0 Setup Files (remove only) "ST6UNST #1" = Hero Editor V0.96 "Steam App 10" = Counter-Strike "Steam App 215" = Source SDK Base "Steam App 240" = Counter-Strike: Source "Steam App 300" = Day of Defeat: Source "Steam App 4000" = Garry's Mod "Steam App 60" = Ricochet "SvenCoop" = Sven Co-op 4.0B "SysInfo" = Creative System Information "System_0" = System error's toolkit 1.0 "SystemRequirementsLab" = System Requirements Lab "Uninstaller_B4736000_Creative Media Toolbox 6" = Creative Media Toolbox 6 (Shared Components) "VB Decompiler Lite_is1" = VB Decompiler Lite "Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime "VisualWebDeveloper" = Microsoft Visual Studio Web Authoring Component "Warcraft III" = Warcraft III "Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner "WinLiveSuite_Wave3" = Windows Live Essentials "WinRAR archiver" = WinRAR archiver "Wolfenstein - Enemy Territory" = Wolfenstein - Enemy Territory "World of Warcraft" = World of Warcraft "xampp" = XAMPP 1.7.0 "Xvid_is1" = Xvid 1.2.1 final uninstall "Yahoo! Companion" = Yahoo! Toolbar "Yahoo! Toolbar" = Yahoo! Toolbar ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-316218746-153266152-3376316544-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Diablo II Shareware" = Diablo II Shareware "ScapeRune 513 v1.8" = ScapeRune 513 v1.8 "uTorrent" = µTorrent "Warcraft III" = Warcraft III: All Products ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 10/20/2009 7:32:41 PM | Computer Name = Michael-PC | Source = Application Error | ID = 1000 Description = Faulting application hl2.exe, version 0.0.0.0, time stamp 0x470c11ae, faulting module materialsystem.dll, version 0.0.0.0, time stamp 0x48acb3f5, exception code 0xc0000005, fault offset 0x00014e6a, process id 0x1328, application start time 0x01ca51d317e0ec61. Error - 10/21/2009 8:08:41 PM | Computer Name = Michael-PC | Source = Application Error | ID = 1000 Description = Faulting application hl2.exe, version 0.0.0.0, time stamp 0x470c11ae, faulting module materialsystem.dll, version 0.0.0.0, time stamp 0x48acb3f5, exception code 0xc0000005, fault offset 0x00014e6a, process id 0x1788, application start time 0x01ca52935cde9dac. Error - 10/23/2009 10:19:28 PM | Computer Name = Michael-PC | Source = Application Error | ID = 1000 Description = Faulting application AcroRd32.exe, version 7.0.0.0, time stamp 0x41bee02d, faulting module ntdll.dll, version 6.0.6000.16386, time stamp 0x4549bdc9, exception code 0xc0000005, fault offset 0x0002294f, process id 0xa18, application start time 0x01ca5450604b68c0. Error - 10/24/2009 1:08:43 PM | Computer Name = Michael-PC | Source = VSS | ID = 8194 Description = Error - 10/24/2009 1:29:02 PM | Computer Name = Michael-PC | Source = SDWinSec.exe | ID = 0 Description = Error - 10/24/2009 1:32:37 PM | Computer Name = Michael-PC | Source = VSS | ID = 8194 Description = Error - 10/24/2009 1:51:02 PM | Computer Name = Michael-PC | Source = VSS | ID = 8194 Description = Error - 10/24/2009 1:56:20 PM | Computer Name = Michael-PC | Source = VSS | ID = 8194 Description = Error - 10/24/2009 3:24:29 PM | Computer Name = Michael-PC | Source = EventSystem | ID = 4609 Description = Error - 10/24/2009 3:43:02 PM | Computer Name = Michael-PC | Source = EventSystem | ID = 4609 Description = [ System Events ] Error - 10/24/2009 3:24:31 PM | Computer Name = Michael-PC | Source = DCOM | ID = 10005 Description = Error - 10/24/2009 3:25:04 PM | Computer Name = Michael-PC | Source = DCOM | ID = 10005 Description = Error - 10/24/2009 3:40:21 PM | Computer Name = Michael-PC | Source = EventLog | ID = 6008 Description = The previous system shutdown at 2:38:28 PM on 10/24/2009 was unexpected. Error - 10/24/2009 3:42:55 PM | Computer Name = Michael-PC | Source = DCOM | ID = 10005 Description = Error - 10/24/2009 3:43:02 PM | Computer Name = Michael-PC | Source = DCOM | ID = 10005 Description = Error - 10/24/2009 3:43:04 PM | Computer Name = Michael-PC | Source = DCOM | ID = 10005 Description = Error - 10/24/2009 3:43:04 PM | Computer Name = Michael-PC | Source = DCOM | ID = 10005 Description = Error - 10/24/2009 3:43:04 PM | Computer Name = Michael-PC | Source = DCOM | ID = 10005 Description = Error - 10/24/2009 3:43:37 PM | Computer Name = Michael-PC | Source = DCOM | ID = 10005 Description = Error - 10/24/2009 3:46:46 PM | Computer Name = Michael-PC | Source = Service Control Manager | ID = 7000 Description = < End of report > |
|
|
Oct 25 2009, 10:17 PM
Post
#2
|
|
![]() Trusted Helper Posts: 211 OS: Windows 7 Professional x64 RTM, Mac OS X 10.5 |
Hi, welcome to the G2G Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:
1) exeHelper Please download exeHelper to your desktop. Double-click on exeHelper.com to run the fix. A black window should pop up, press any key to close once the fix is completed. Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan) Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file). 2) DDS ![]() Please download DDS and save it to your desktop from here or here or here. Disable any script blocker, and then double click dds.scr to run the tool.
3) RR Please download RootRepeal.zip. Save it to your Desktop. Alternate download links here or here. Please print these instructions, you will not have an Internet connection! If you have a 3rd party "unzipping" program...use it to open the zipped file...then skip to Step 5. Otherwise...
Make sure to enable your anti-virus, Firewall and any other security programs you disabled. Note: If RootRepeal cannot complete a scan and results in a crash report, try repeating the scan in "safe mode". 4) What You Will Need To Post:
|
|
|
Oct 26 2009, 07:20 AM
Post
#3
|
|
|
New Member ![]() Posts: 6 OS: Windows Vista |
exeHelper instantly closes, says something but I can't see it
DDS will run but - "The Process cannot access the file because it is bsing used by another process." x2 Rootrepeal gets a [bleep]load of memory read errors, probably same reason, the virus is using all of the access points. Crashes and gives me no log. |
|
|
Oct 26 2009, 05:35 PM
Post
#4
|
|
![]() Trusted Helper Posts: 211 OS: Windows 7 Professional x64 RTM, Mac OS X 10.5 |
Please redownload exeHelper from here. It will be called explorer.exe.
Run that, and post the log produced (if it doesn't close instantly). |
|
|
Oct 26 2009, 06:47 PM
Post
#5
|
|
|
New Member ![]() Posts: 6 OS: Windows Vista |
exeHelper by Raktor
Build 20091021 Run at 19:46:57 on 10/26/09 Now searching... Checking for numerical processes... Checking for bad processes... Checking for bad files... Deleting file C:\Users\Michael\Start Menu\Programs\Startup\scandisk.lnk Checking for bad registry entries... Removing HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A2234B15-23F2-42AD-F4E4-00AAC39C0004} Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values... Resetting policies... DDS (Ver_09-10-26.01) - NTFSx86 Run by Michael at 19:48:28.93 on Mon 10/26/2009 Internet Explorer: 7.0.6000.16916 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1022.488 [GMT -5:00] AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: AVG Internet Security *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Windows\system32\lsm.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\Creative\Shared Files\CTAudSvc.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\AVG\AVG9\avgam.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files\AVG\AVG9\avgemc.exe C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\taskeng.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe D:\TSVN\bin\TSVNCache.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe C:\Program Files\Logitech\QuickCam10\QuickCam10.exe C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe C:\Program Files\Windows Media Player\wmpnscfg.exe D:\Program Files\Creative\USB Headsets\Volume Panel\VolPanlu.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Steam\Steam.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\MagicDisc\MagicDisc.exe C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Logitech\QuickCam10\COCIManager.exe C:\Program Files\Common Files\Steam\SteamService.exe C:\Windows\system32\wuauclt.exe C:\Windows\explorer.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\notepad.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Michael\Desktop\dds.pif C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://google.com/ uSEARCH PAGE = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com uSearch Bar = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mStart Page = hxxp://en.us.acer.yahoo.com mDefault_Page_URL = hxxp://en.us.acer.yahoo.com uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll EB: Web Test Recorder 9.0: {3c7adade-d1e8-45d2-bdcd-7f8d8b99b2a2} - mscoree.dll uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [????r] uRun: [Steam] "c:\program files\steam\steam.exe" -silent uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [Speech Recognition] "c:\windows\speech\common\sapisvr.exe" -SpeechUX -Startup uRun: [cdloader] "c:\users\michael\appdata\roaming\mjusbsp\cdloader2.exe" MAGICJACK mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [eRecoveryService] mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [LogitechCommunicationsManager] "c:\program files\common files\logitech\lcommgr\Communications_Helper.exe" mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam10\QuickCam10.exe" /hide mRun: [LVCOMSX] "c:\program files\common files\logitech\lcommgr\LVComSX.exe" mRun: [VolPanel] "d:\program files\creative\usb headsets\volume panel\VolPanlu.exe" /r mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe mRun: [MSConfig] "c:\windows\system32\msconfig.exe" /auto mExplorerRun: [explorer32] c:\windows\system32\spy-net\WinHelper32.exe.exe StartupFolder: c:\users\michael\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\empowe~1.lnk - c:\acer\empowering technology\eAPLauncher.exe mPolicies-system: EnableLUA = 0 (0x0) LSP: c:\windows\system32\wpclsp.dll DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.systemrequirementslab.com/srl_bin/sysreqlab_srl.cab DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Notify: igfxcui - igfxdev.dll AppInit_DLLs: avgrsstx.dll STS: c:\windows\system32\zkcw2lfbht.dll: {a2234b15-23f2-42ad-f4e4-00aac39c0004} - c:\windows\system32\zkcw2lfbht.dll mASetup: {66GQ7556-22WN-35GR-E1TH-QSTQN766Q5L8} - c:\windows\system32\spy-net\WinHelper32.exe.exe Restart ================= FIREFOX =================== FF - ProfilePath - c:\users\michael\appdata\roaming\mozilla\firefox\profiles\3xm87rlz.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll FF - plugin: c:\program files\google\google updater\2.4.1591.6512\npCIDetect13.dll FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ ============= SERVICES / DRIVERS =============== R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-10-24 161800] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-10-24 333192] R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-10-24 360584] R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2009-10-24 906520] R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-10-24 285392] R3 HssDrv;Hotspot Shield Helper Miniport;c:\windows\system32\drivers\HssDrv.sys [2009-9-15 37376] R3 skfiltv;skfiltv;c:\windows\system32\drivers\skfiltv.sys [2009-10-6 17408] R3 taphss;Anchorfree HSS Adapter;c:\windows\system32\drivers\taphss.sys [2009-9-15 32768] S2 gupdate1c9d9ba82edd358;Google Update Service (gupdate1c9d9ba82edd358);c:\program files\google\update\GoogleUpdate.exe [2009-5-20 133104] S3 SbieDrv;SbieDrv;c:\program files\sandboxie\SbieDrv.sys [2009-5-28 108032] S3 VSPerfDrv90;Performance Tools Driver 9.0;c:\program files\microsoft visual studio 9.0\team tools\performance tools\VSPerfDrv90.sys [2007-9-4 55664] S4 Creative ALchemy AL1 Licensing Service;Creative ALchemy AL1 Licensing Service;c:\program files\common files\creative labs shared\service\AL1Licensing.exe [2009-10-6 79360] S4 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2009-10-6 79360] S4 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files\common files\creative labs shared\service\MT6Licensing.exe [2009-10-6 79360] S4 HssSrv;Hotspot Shield Routing Service;c:\program files\hotspot shield\hsswpr\hsssrv.exe [2009-9-15 331824] S4 HssTrayService;Hotspot Shield Tray Service;c:\program files\hotspot shield\bin\HssTrayService.exe [2009-9-15 57640] S4 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?] SUnknown {79007602-0CDB-4405-9DBF-1257BB3226EE};{79007602-0CDB-4405-9DBF-1257BB3226EE}; [x] =============== Created Last 30 ================ 2009-10-24 19:19:01 0 d--h--w- c:\windows\PIF 2009-10-24 19:05:11 0 d-----w- c:\users\michael\appdata\roaming\Malwarebytes 2009-10-24 19:05:06 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-24 19:05:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-10-24 19:05:04 0 d-----w- c:\programdata\Malwarebytes 2009-10-24 19:05:04 0 d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-10-24 17:47:46 0 d--h--w- C:\$AVG 2009-10-24 17:47:40 12464 ----a-w- c:\windows\system32\avgrsstx.dll 2009-10-24 17:47:39 161800 ----a-w- c:\windows\system32\drivers\avgrkx86.sys 2009-10-24 17:47:38 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2009-10-24 17:47:27 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2009-10-24 17:47:06 0 d-----w- c:\windows\system32\drivers\Avg 2009-10-24 17:46:20 0 d-----w- c:\program files\AVG 2009-10-24 17:46:19 0 d-----w- c:\programdata\avg9 2009-10-24 02:19:41 0 ----a-w- c:\windows\win32k.sys 2009-10-21 21:07:21 0 d-----w- c:\program files\VentSrv 2009-10-21 21:06:35 0 d-----w- c:\program files\common files\Wise Installation Wizard 2009-10-20 20:35:42 206848 ----a-w- c:\windows\system32\telnet.exe 2009-10-19 01:43:15 0 d-----w- c:\program files\Hackers Paradise 2009-10-17 14:05:27 0 d-----w- c:\windows\SQLTools9_KB970892_ENU 2009-10-16 22:11:56 0 ----a-w- c:\windows\chatter.INI 2009-10-16 22:09:48 0 d-----w- C:\msdn 2009-10-16 20:57:00 216576 ----a-w- c:\windows\system32\msv1_0.dll 2009-10-16 20:55:45 428032 ----a-w- c:\windows\system32\EncDec.dll 2009-10-16 20:55:45 292352 ----a-w- c:\windows\system32\psisdecd.dll 2009-10-16 20:55:45 217088 ----a-w- c:\windows\system32\psisrndr.ax 2009-10-16 20:55:41 80896 ----a-w- c:\windows\system32\MSNP.ax 2009-10-16 20:55:41 57856 ----a-w- c:\windows\system32\MSDvbNP.ax 2009-10-16 20:55:41 1244672 ----a-w- c:\windows\system32\mcmde.dll 2009-10-16 20:55:39 68608 ----a-w- c:\windows\system32\Mpeg2Data.ax 2009-10-16 20:55:39 177152 ----a-w- c:\windows\system32\mpg2splt.ax 2009-10-16 20:51:20 60928 ----a-w- c:\windows\system32\msasn1.dll 2009-10-16 20:51:15 130048 ----a-w- c:\windows\system32\drivers\srv2.sys 2009-10-16 20:51:11 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL 2009-10-13 23:22:48 0 d-----w- c:\users\michael\appdata\roaming\mjusbsp 2009-10-12 23:28:49 0 d-----w- c:\windows\system32\wbem\repository 2009-10-07 14:33:00 0 d-----w- c:\windows\system32\wbem\repository_bad2 2009-10-07 00:35:45 7062 ----a-w- c:\windows\system32\audiopid.vxd 2009-10-07 00:34:39 647872 ------w- c:\windows\system32\Mscomct2.ocx 2009-10-07 00:34:38 53248 ------w- c:\windows\Ctregrun.exe 2009-10-07 00:32:34 0 d-----w- c:\programdata\Creative 2009-10-07 00:29:03 0 d-----w- c:\program files\common files\Creative 2009-10-07 00:29:00 0 d--h--w- c:\program files\Creative Installation Information 2009-10-07 00:27:10 497152 ----a-w- c:\windows\system32\CTAPO32.dll 2009-10-07 00:27:10 47104 ----a-w- c:\windows\system32\ctppld.dll 2009-10-07 00:27:09 8704 ----a-w- c:\windows\ResDefE.exe 2009-10-07 00:27:09 52 ----a-r- c:\windows\system32\ctzapxx.ini 2009-10-07 00:27:09 25199 ----a-r- c:\windows\system32\xfisk.ini 2009-10-07 00:27:09 181760 ----a-w- c:\windows\system32\ctdvinst.dll 2009-10-07 00:27:09 17408 ----a-w- c:\windows\system32\drivers\skfiltv.sys 2009-10-07 00:27:01 381 ----a-r- c:\windows\skMCcfg.ini 2009-10-07 00:27:01 1209 ----a-r- c:\windows\skSPcfg.ini 2009-10-07 00:26:49 69120 ----a-w- c:\windows\system32\CmdRtr.DLL 2009-10-07 00:26:49 207 ---ha-r- c:\windows\ctfile.rfc 2009-10-07 00:26:49 127488 ----a-w- c:\windows\system32\APOMngr.DLL 2009-10-07 00:26:43 782336 ----a-r- c:\windows\system32\tmp71A6.tmp 2009-10-07 00:26:43 413696 ----a-w- c:\windows\system32\wrap_oal.dll 2009-10-07 00:26:43 110592 ----a-w- c:\windows\system32\OpenAL32.dll 2009-10-07 00:26:42 782336 ----a-r- c:\windows\system32\tmp707C.tmp 2009-10-07 00:26:41 2869728 ------w- c:\windows\system32\Sens_oal.dll 2009-10-07 00:26:24 0 d-----w- c:\programdata\Creative Labs 2009-10-07 00:24:31 0 d-----w- c:\program files\common files\Creative Labs Shared 2009-10-07 00:24:10 0 d-----w- c:\program files\Creative 2009-10-06 20:24:15 107864 ----a-w- c:\windows\system32\tsccvid.dll 2009-10-06 20:24:14 0 d-----w- c:\windows\system32\QuickTime 2009-10-06 20:23:56 0 d-----w- c:\programdata\TechSmith 2009-10-06 20:23:38 0 d-----w- c:\program files\common files\TechSmith Shared 2009-10-06 19:41:03 0 d-----w- C:\Hotspot Shield 2009-10-06 19:38:50 0 d-----w- c:\program files\Hotspot Shield 2009-10-05 18:59:45 1589248 ----a-w- c:\windows\system32\libmysql_d.dll 2009-10-05 18:59:40 0 d-----w- c:\program files\PremiumSoft 2009-10-05 18:29:32 0 d-----w- c:\programdata\MySQL 2009-10-05 18:29:32 0 d-----w- c:\program files\MySQL 2009-10-02 20:35:18 195440 ------w- c:\windows\system32\MpSigStub.exe ==================== Find3M ==================== 2009-10-07 00:27:57 86016 ----a-w- c:\windows\inf\infstrng.dat 2009-10-07 00:27:57 51200 ----a-w- c:\windows\inf\infpub.dat 2009-10-07 00:27:26 86016 ----a-w- c:\windows\inf\infstor.dat 2009-09-15 20:04:58 37376 ----a-w- c:\windows\system32\drivers\HssDrv.sys 2009-09-15 20:04:58 32768 ----a-w- c:\windows\system32\drivers\taphss.sys 2009-09-13 14:03:18 92464 ---ha-w- c:\windows\system32\mlfcache.dat 2009-09-12 19:26:15 139904 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2009-09-12 19:26:06 189744 ----a-w- c:\windows\system32\PnkBstrB.exe 2009-08-29 03:41:42 1686528 ----a-w- c:\windows\system32\gameux.dll 2009-08-29 03:40:31 28672 ----a-w- c:\windows\system32\Apphlpdm.dll 2009-08-28 23:31:54 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2009-08-27 14:02:34 832512 ----a-w- c:\windows\system32\wininet.dll 2009-08-27 13:57:38 56320 ----a-w- c:\windows\system32\iesetup.dll 2009-08-27 13:57:36 78336 ----a-w- c:\windows\system32\ieencode.dll 2009-08-27 13:56:05 72704 ----a-w- c:\windows\system32\admparse.dll 2009-08-27 11:24:10 26624 ----a-w- c:\windows\system32\ieUnatt.exe 2009-08-27 09:51:45 48128 ----a-w- c:\windows\system32\mshtmler.dll 2009-08-18 04:33:52 1193832 ----a-w- c:\windows\system32\FM20.DLL 2009-08-14 16:42:08 167424 ----a-w- c:\windows\system32\tcpipcfg.dll 2009-08-14 16:40:56 103936 ----a-w- c:\windows\system32\netiohlp.dll 2009-08-14 16:40:52 15360 ----a-w- c:\windows\system32\netevent.dll 2009-08-14 14:25:18 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE 2009-08-14 14:25:16 17920 ----a-w- c:\windows\system32\ROUTE.EXE 2009-08-14 14:25:15 11264 ----a-w- c:\windows\system32\MRINFO.EXE 2009-08-14 14:25:14 27136 ----a-w- c:\windows\system32\NETSTAT.EXE 2009-08-14 14:25:10 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE 2009-08-14 14:25:10 19968 ----a-w- c:\windows\system32\ARP.EXE 2009-08-14 14:25:10 10240 ----a-w- c:\windows\system32\finger.exe 2009-08-14 14:23:53 22016 ----a-w- c:\windows\system32\netiougc.exe 2009-08-05 14:28:45 3502152 ----a-w- c:\windows\system32\ntkrnlpa.exe 2009-08-05 14:28:44 3467864 ----a-w- c:\windows\system32\ntoskrnl.exe 2009-02-28 00:22:25 174 --sha-w- c:\program files\desktop.ini 2009-02-28 00:17:23 665600 ----a-w- c:\windows\inf\drvindex.dat 2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat 2009-05-16 17:55:55 16384 --sha-w- c:\windows\temp\cookies\index.dat 2009-05-16 17:55:55 16384 --sha-w- c:\windows\temp\history\history.ie5\index.dat 2009-05-16 17:55:55 32768 --sha-w- c:\windows\temp\temporary internet files\content.ie5\index.dat ============= FINISH: 19:50:16.65 =============== --Finished-- UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-10-26.01) Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 2/26/2009 6:36:26 PM System Uptime: 10/26/2009 7:54:50 AM (12 hours ago) Motherboard: Acer | | E946GZ Processor: Intel® Pentium® D CPU 3.00GHz | Socket 775 | 3000/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 113 GiB total, 43.327 GiB free. D: is FIXED (NTFS) - 113 GiB total, 83.242 GiB free. E: is CDROM (UDF) F: is Removable G: is Removable H: is Removable I: is Removable J: is CDROM () K: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP256: 10/24/2009 12:08:47 PM - Removed Eamonn RP258: 10/24/2009 12:32:40 PM - Configured Chessmaster Grandmaster Edition RP259: 10/24/2009 12:45:34 PM - Installed AVG 9.0 RP261: 10/24/2009 12:51:02 PM - Avg8 Update RP263: 10/24/2009 12:56:20 PM - Avg8 Update RP264: 10/25/2009 7:46:17 AM - Windows Update RP265: 10/26/2009 8:00:53 AM - Windows Update ==== Installed Programs ====================== µTorrent Adobe AIR Adobe Anchor Service CS3 Adobe Anchor Service CS4 Adobe Asset Services CS3 Adobe Bridge CS3 Adobe Bridge CS4 Adobe Bridge Start Meeting Adobe Camera Raw 4.0 Adobe CMaps CS4 Adobe Color - Photoshop Specific Adobe Color EU Extra Settings CS4 Adobe Color JA Extra Settings CS4 Adobe Color NA Recommended Settings CS4 Adobe CSI CS4 Adobe Default Language CS4 Adobe Device Central CS3 Adobe Device Central CS4 Adobe Drive CS4 Adobe Dynamiclink Support Adobe ExtendScript Toolkit 2 Adobe ExtendScript Toolkit CS4 Adobe Extension Manager CS4 Adobe Flash CS4 Adobe Flash CS4 Extension - Flash Lite STI en Adobe Flash CS4 Professional Adobe Flash CS4 STI-en Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Flash Player 9 ActiveX Adobe Fonts All Adobe Help Viewer CS3 Adobe Linguistics CS3 Adobe Linguistics CS4 Adobe Media Encoder CS4 Adobe Media Encoder CS4 Importer Adobe Media Player Adobe Output Module Adobe PDF Library Files CS4 Adobe Photoshop CS3 Adobe Reader 7.0 Adobe Search for Help Adobe Service Manager Extension Adobe Setup Adobe Stock Photos CS3 Adobe Type Support CS4 Adobe Update Manager CS3 Adobe Update Manager CS4 Adobe Version Cue CS3 Client Adobe WinSoft Linguistics Plugin Adobe XMP Panels CS3 Adobe XMP Panels CS4 AdobeColorCommonSetCMYK AdobeColorCommonSetRGB Advanced Port Scanner v1.3 AIM 6 Apple Mobile Device Support Apple Software Update ATI Catalyst Install Manager AV Voice Changer Software DIAMOND 6.0 AVG 9.0 Bonjour Camtasia Studio 6 Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Common Catalyst Control Center Graphics Previews Vista Catalyst Control Center HydraVision Full Catalyst Control Center InstallProxy Cavaj Java Decompiler ccc-core-static ccc-utility CCC Help English Cheat Engine 5.5 Choice Guard Combat Arms Connect ConvertXtoDVD 3.3.4.107 Counter-Strike Counter-Strike: Source Creative ALchemy (X-Fi Edition) Creative Media Toolbox 6 Creative Media Toolbox 6 (Shared Components) Creative MediaSource 5 Creative Software AutoUpdate Creative System Information Creative USB Headsets Crystal Reports Basic for Visual Studio 2008 Day of Defeat: Source Diablo II Diablo II Shareware Full Tilt Poker Garry's Mod GDR 4053 for SQL Server Tools and Workstation Components 2005 ENU (KB970892) Google Earth Google Toolbar for Internet Explorer Google Update Helper Google Updater Guitar Pro 5.2 Half-Life Hero Editor V0.96 Hero_Online Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB945282) Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB946040) Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB946308) Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB946344) Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB947540) Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB947789) Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB948127) Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB951708) Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB945282) Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB946040) Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB946308) Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB947540) Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB947789) Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB948127) Hotfix for Microsoft Visual Studio Team System 2008 Team Suite - ENU (KB971091) Hotfix for Microsoft Visual Studio Team System 2008 Team Suite - ENU (KB971092) Hotfix for Microsoft Visual Studio Team System 2008 Team Suite - ENU (KB973674) Hotspot Shield 1.30 HxD Hex Editor version 1.7.7.0 IDA Pro Free v4.9 ImgBurn iTunes Java DB 10.4.1.3 Java 6 Update 13 Java SE Development Kit 6 Update 12 JCreator Pro 4.50 Jiffy Gmail Creator kuler LightScribe 1.4.124.1 LimeWire 5.1.2 Logitech Audio Echo Cancellation Component Logitech QuickCam Logitech Video Enumerator Logitech® Camera Driver Magic ISO Maker v5.5 (build 0261) MagicDisc 2.7.106 Malwarebytes' Anti-Malware Microsoft .NET Compact Framework 2.0 SP2 Microsoft .NET Compact Framework 3.5 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Device Emulator version 3.0 - ENU Microsoft Document Explorer 2008 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Visual Web Developer 2007 Microsoft Office Visual Web Developer MUI (English) 2007 Microsoft SQL Server 2005 Microsoft SQL Server 2005 Express Edition (SQLEXPRESS) Microsoft SQL Server 2005 Tools Express Edition Microsoft SQL Server 2008 Management Objects Microsoft SQL Server Compact 3.5 for Devices ENU Microsoft SQL Server Compact 3.5 SP1 Design Tools English Microsoft SQL Server Compact 3.5 SP1 English Microsoft SQL Server Database Publishing Wizard 1.3 Microsoft SQL Server Native Client Microsoft SQL Server Setup Support Files (English) Microsoft SQL Server VSS Writer Microsoft VC9 runtime libraries Microsoft Visual Basic 2008 Express Edition with SP1 - ENU Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Express Edition with SP1 - ENU Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual Studio 2005 Tools for Office Runtime Microsoft Visual Studio 2008 Performance Collection Tools - ENU Microsoft Visual Studio Team System 2008 Team Suite - ENU Microsoft Visual Studio Team System 2008 Team Suite - ENU Service Pack 1 (KB945140) Microsoft Visual Studio Web Authoring Component Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools - enu Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32 Microsoft Windows SDK for Visual Studio 2008 SP1 Tools Microsoft Windows SDK for Visual Studio 2008 SP1 Win32 Tools mIRC Mozilla Firefox (3.0.14) MSVCRT MSXML 4.0 SP2 (KB954430) MySQL Server 5.1 No-IP.com DUC (remove only) NTI Backup NOW! 4.7 NTI CD & DVD-Maker Oblivion PDF Settings CS4 Photoshop Camera Raw Pixel Bender Toolkit PremiumSoft Navicat Lite 8.2 PunkBuster Services Python 2.6.1 Quake Live Internet Explorer Plugin QuickTime Realtek High Definition Audio Driver Renoise 2.0.0 Ricochet S.T.A.L.K.E.R. - Shadow of Chernobyl [v1.0004] Sandboxie 3.38 ScapeRune 513 v1.8 Security Update for 2007 Microsoft Office System (KB951944) Security Update for CAPICOM (KB931906) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Visual Studio Team System 2008 Team Suite - ENU (KB972222) Security Update for Microsoft Visual Studio Team System 2008 Team Suite - ENU (KB973675) Skins SmartFTP Client SmartFTP Client 3.0 Setup Files (remove only) Source SDK Base SQL Server System CLR Types Steam Suite Shared Configuration CS4 Sven Co-op 4.0B System error's toolkit 1.0 System Requirements Lab TortoiseSVN 1.6.2.16344 (32 bit) UMVPLStandalone Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Visual Studio Web Authoring Component (KB945140) VB Decompiler Lite VC Runtimes MSI Ventrilo Server Visual C++ 2008 IA64 Runtime - (v9.0.30729) Visual C++ 2008 IA64 Runtime - (v9.0.30729.4148) Visual C++ 2008 IA64 Runtime - v9.0.30729.01 Visual C++ 2008 IA64 Runtime - v9.0.30729.4148 Visual C++ 2008 x64 Runtime - (v9.0.30729) Visual C++ 2008 x64 Runtime - (v9.0.30729.4148) Visual C++ 2008 x64 Runtime - v9.0.30729.01 Visual C++ 2008 x64 Runtime - v9.0.30729.4148 Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - (v9.0.30729.4148) Visual C++ 2008 x86 Runtime - v9.0.30729.01 Visual C++ 2008 x86 Runtime - v9.0.30729.4148 Visual Studio 2005 Tools for Office Second Edition Runtime Visual Studio Tools for the Office system 3.0 Runtime Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) Warcraft III Warcraft III: All Products Warsow 0.42 Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Messenger Windows Live OneCare safety scanner Windows Live Sign-in Assistant Windows Live Upload Tool Windows Mobile 5.0 SDK R2 for Pocket PC Windows Mobile 5.0 SDK R2 for Smartphone WinRAR archiver Wolfenstein - Enemy Territory World of Warcraft World of Warcraft FREE Trial XAMPP 1.7.0 Xvid 1.2.1 final uninstall Yahoo! Toolbar ==== Event Viewer Messages From Past Week ======== 10/24/2009 11:54:19 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect. 10/24/2009 11:54:19 AM, Error: Service Control Manager [7000] - The Steam Client Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 10/24/2009 11:40:38 AM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for SQL Server 2005 Service Pack 3 (KB970892). 10/24/2009 11:36:45 AM, Error: Service Control Manager [7000] - The adfs service failed to start due to the following error: The system cannot find the file specified. ==== End Of File =========================== Rootrepeal - Still does not run - memory errors This post has been edited by Michael435: Oct 26 2009, 06:54 PM |
|
|
Oct 26 2009, 08:45 PM
Post
#6
|
|
![]() Trusted Helper Posts: 211 OS: Windows 7 Professional x64 RTM, Mac OS X 10.5 |
Download Combofix from any of the links below but rename it to michael.com before saving it to your desktop.
Link 1 Link 2 ================================== Double click on the renamed ComboFix.exe & follow the prompts.
|
|
|
Oct 27 2009, 03:49 PM
Post
#7
|
|
|
New Member ![]() Posts: 6 OS: Windows Vista |
ComboFix 09-10-26.06 - Michael 10/27/2009 15:53.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1022.411 [GMT -5:00] Running from: c:\users\Michael\Desktop\michael.com AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: AVG Internet Security *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\users\Michael\AppData\Roaming\inst.exe c:\windows\system32\images c:\windows\system32\images\toolbar\calendar.gif c:\windows\system32\images\toolbar\crlogo.gif c:\windows\system32\images\toolbar\export.gif c:\windows\system32\images\toolbar\export_over.gif c:\windows\system32\images\toolbar\exportd.gif c:\windows\system32\images\toolbar\First.gif c:\windows\system32\images\toolbar\first_over.gif c:\windows\system32\images\toolbar\Firstd.gif c:\windows\system32\images\toolbar\gotopage.gif c:\windows\system32\images\toolbar\gotopage_over.gif c:\windows\system32\images\toolbar\gotopaged.gif c:\windows\system32\images\toolbar\grouptree.gif c:\windows\system32\images\toolbar\grouptree_over.gif c:\windows\system32\images\toolbar\grouptreed.gif c:\windows\system32\images\toolbar\grouptreepressed.gif c:\windows\system32\images\toolbar\Last.gif c:\windows\system32\images\toolbar\last_over.gif c:\windows\system32\images\toolbar\Lastd.gif c:\windows\system32\images\toolbar\Next.gif c:\windows\system32\images\toolbar\next_over.gif c:\windows\system32\images\toolbar\Nextd.gif c:\windows\system32\images\toolbar\Prev.gif c:\windows\system32\images\toolbar\prev_over.gif c:\windows\system32\images\toolbar\Prevd.gif c:\windows\system32\images\toolbar\print.gif c:\windows\system32\images\toolbar\print_over.gif c:\windows\system32\images\toolbar\printd.gif c:\windows\system32\images\toolbar\Refresh.gif c:\windows\system32\images\toolbar\refresh_over.gif c:\windows\system32\images\toolbar\refreshd.gif c:\windows\system32\images\toolbar\Search.gif c:\windows\system32\images\toolbar\search_over.gif c:\windows\system32\images\toolbar\searchd.gif c:\windows\system32\images\toolbar\up.gif c:\windows\system32\images\toolbar\up_over.gif c:\windows\system32\images\toolbar\upd.gif c:\windows\system32\images\tree\begindots.gif c:\windows\system32\images\tree\beginminus.gif c:\windows\system32\images\tree\beginplus.gif c:\windows\system32\images\tree\blank.gif c:\windows\system32\images\tree\blankdots.gif c:\windows\system32\images\tree\dots.gif c:\windows\system32\images\tree\lastdots.gif c:\windows\system32\images\tree\lastminus.gif c:\windows\system32\images\tree\lastplus.gif c:\windows\system32\images\tree\Magnify.gif c:\windows\system32\images\tree\minus.gif c:\windows\system32\images\tree\minusbox.gif c:\windows\system32\images\tree\plus.gif c:\windows\system32\images\tree\plusbox.gif c:\windows\system32\images\tree\singleminus.gif c:\windows\system32\images\tree\singleplus.gif Infected copy of c:\windows\system32\cngaudit.dll was found and disinfected Restored copy from - c:\windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED} -------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE} ((((((((((((((((((((((((( Files Created from 2009-09-27 to 2009-10-27 ))))))))))))))))))))))))))))))) . 2009-10-27 21:09 . 2009-10-27 21:15 -------- d-----w- c:\users\Michael\AppData\Local\temp 2009-10-27 21:09 . 2009-10-27 21:09 -------- d-----w- c:\users\Default\AppData\Local\temp 2009-10-27 21:09 . 2009-10-27 21:09 -------- d-----w- c:\users\Michael_2\AppData\Local\temp 2009-10-25 16:55 . 2009-10-26 23:08 0 ----a-w- c:\users\Michael\AppData\Local\prvlcl.dat 2009-10-24 19:19 . 2009-10-27 21:11 -------- d--h--w- c:\windows\PIF 2009-10-24 19:05 . 2009-10-24 19:05 -------- d-----w- c:\users\Michael\AppData\Roaming\Malwarebytes 2009-10-24 19:05 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-24 19:05 . 2009-10-24 19:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-10-24 19:05 . 2009-10-24 19:05 -------- d-----w- c:\programdata\Malwarebytes 2009-10-24 19:05 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-10-24 17:47 . 2009-10-24 17:59 -------- d-----w- C:\$AVG 2009-10-24 17:47 . 2009-10-24 17:47 12464 ----a-w- c:\windows\system32\avgrsstx.dll 2009-10-24 17:47 . 2009-10-24 17:52 161800 ----a-w- c:\windows\system32\drivers\avgrkx86.sys 2009-10-24 17:47 . 2009-10-24 17:56 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2009-10-24 17:47 . 2009-10-24 17:47 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2009-10-24 17:47 . 2009-10-24 17:56 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2009-10-24 17:47 . 2009-10-27 20:27 -------- d-----w- c:\windows\system32\drivers\Avg 2009-10-24 17:46 . 2009-10-24 17:46 -------- d-----w- c:\program files\AVG 2009-10-24 17:46 . 2009-10-24 18:03 -------- d-----w- c:\programdata\avg9 2009-10-24 02:19 . 2009-10-27 20:17 0 ----a-r- c:\windows\win32k.sys 2009-10-21 21:07 . 2009-10-24 17:28 -------- d-----w- c:\program files\VentSrv 2009-10-21 21:06 . 2009-10-21 21:06 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-10-20 20:35 . 2009-06-10 11:41 206848 ----a-w- c:\windows\system32\telnet.exe 2009-10-19 01:43 . 2009-10-19 01:43 -------- d-----w- c:\program files\Hackers Paradise 2009-10-17 14:05 . 2009-10-17 14:05 -------- d-----w- c:\windows\SQLTools9_KB970892_ENU 2009-10-16 22:09 . 2009-10-16 22:09 -------- d-----w- C:\msdn 2009-10-16 20:57 . 2009-09-10 17:38 216576 ----a-w- c:\windows\system32\msv1_0.dll 2009-10-16 20:55 . 2009-08-31 15:21 292352 ----a-w- c:\windows\system32\psisdecd.dll 2009-10-16 20:55 . 2009-08-31 15:16 428032 ----a-w- c:\windows\system32\EncDec.dll 2009-10-16 20:55 . 2009-08-31 15:17 1244672 ----a-w- c:\windows\system32\mcmde.dll 2009-10-16 20:51 . 2009-09-04 12:38 60928 ----a-w- c:\windows\system32\msasn1.dll 2009-10-16 20:51 . 2009-09-14 09:50 130048 ----a-w- c:\windows\system32\drivers\srv2.sys 2009-10-16 20:51 . 2009-04-02 11:50 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL 2009-10-14 21:25 . 2009-10-14 21:25 -------- d-----w- c:\users\Michael\AppData\Local\Blizzard Entertainment 2009-10-14 20:30 . 2009-10-14 20:30 -------- d-----w- c:\users\Michael\AppData\Local\tjnet 2009-10-13 23:22 . 2009-10-13 23:23 -------- d-----w- c:\users\Michael\AppData\Roaming\mjusbsp 2009-10-12 23:28 . 2009-10-27 21:14 -------- d-----w- c:\windows\system32\wbem\repository 2009-10-07 14:33 . 2009-10-12 20:23 -------- d-----w- c:\windows\system32\wbem\repository_bad2 2009-10-07 00:40 . 2009-10-07 00:40 -------- d-----w- c:\users\Michael\AppData\Roaming\Creative 2009-10-07 00:34 . 2006-10-06 06:17 53248 ------w- c:\windows\Ctregrun.exe 2009-10-07 00:32 . 2009-10-07 00:49 -------- d-----w- c:\programdata\Creative 2009-10-07 00:29 . 2009-10-07 00:29 -------- d-----w- c:\program files\Common Files\Creative 2009-10-07 00:29 . 2009-10-07 00:34 -------- d--h--w- c:\program files\Creative Installation Information 2009-10-07 00:27 . 2008-09-10 02:54 47104 ----a-w- c:\windows\system32\ctppld.dll 2009-10-07 00:27 . 2008-09-10 02:54 497152 ----a-w- c:\windows\system32\CTAPO32.dll 2009-10-07 00:27 . 2008-09-30 03:23 181760 ----a-w- c:\windows\system32\ctdvinst.dll 2009-10-07 00:27 . 2008-08-26 08:30 8704 ----a-w- c:\windows\ResDefE.exe 2009-10-07 00:27 . 2008-08-14 06:48 17408 ----a-w- c:\windows\system32\drivers\skfiltv.sys 2009-10-07 00:26 . 2008-05-12 20:32 127488 ----a-w- c:\windows\system32\APOMngr.DLL 2009-10-07 00:26 . 2008-03-11 15:55 69120 ----a-w- c:\windows\system32\CmdRtr.DLL 2009-10-07 00:26 . 2009-10-07 00:26 413696 ----a-w- c:\windows\system32\wrap_oal.dll 2009-10-07 00:26 . 2009-10-07 00:26 110592 ----a-w- c:\windows\system32\OpenAL32.dll 2009-10-07 00:26 . 2008-06-26 00:10 2869728 ------w- c:\windows\system32\Sens_oal.dll 2009-10-07 00:26 . 2009-10-07 00:26 -------- d-----w- c:\programdata\Creative Labs 2009-10-07 00:24 . 2009-10-07 00:34 -------- d-----w- c:\program files\Common Files\Creative Labs Shared 2009-10-07 00:24 . 2009-10-07 00:34 -------- d-----w- c:\program files\Creative 2009-10-06 20:24 . 2008-07-10 19:56 107864 ----a-w- c:\windows\system32\tsccvid.dll 2009-10-06 20:24 . 2009-10-06 20:24 -------- d-----w- c:\windows\system32\QuickTime 2009-10-06 20:23 . 2009-10-06 20:23 -------- d-----w- c:\programdata\TechSmith 2009-10-06 20:23 . 2009-10-06 20:23 -------- d-----w- c:\program files\Common Files\TechSmith Shared 2009-10-06 19:41 . 2009-10-06 19:41 -------- d-----w- C:\Hotspot Shield 2009-10-06 19:38 . 2009-10-06 19:41 -------- d-----w- c:\program files\Hotspot Shield 2009-10-05 18:59 . 2009-07-10 17:33 1589248 ----a-w- c:\windows\system32\libmysql_d.dll 2009-10-05 18:59 . 2009-10-05 18:59 -------- d-----w- c:\program files\PremiumSoft 2009-10-05 18:29 . 2009-10-05 18:29 -------- d-----w- c:\programdata\MySQL 2009-10-05 18:29 . 2009-10-05 18:29 -------- d-----w- c:\program files\MySQL 2009-10-02 20:35 . 2009-10-01 15:29 195440 ------w- c:\windows\system32\MpSigStub.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-27 20:20 . 2009-02-27 00:26 -------- d-----w- c:\program files\Steam 2009-10-24 18:08 . 2009-02-27 00:26 -------- d-----w- c:\program files\Common Files\Steam 2009-10-24 18:00 . 2009-03-01 16:12 -------- d-----w- c:\program files\uTorrent 2009-10-24 17:55 . 2009-03-01 16:11 -------- d-----w- c:\users\Michael\AppData\Roaming\uTorrent 2009-10-24 17:39 . 2009-05-01 22:38 -------- d-----w- c:\programdata\Media Center Programs 2009-10-24 17:09 . 2006-12-13 03:37 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-10-24 17:04 . 2009-03-15 19:50 -------- d-----w- c:\users\Michael\AppData\Roaming\HLSW 2009-10-24 00:49 . 2009-08-15 20:45 -------- d-----w- c:\users\Michael\AppData\Roaming\FileZilla 2009-10-17 22:22 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2009-10-17 14:14 . 2009-03-17 01:39 -------- d-----w- c:\programdata\Microsoft Help 2009-10-17 14:06 . 2009-03-17 01:44 -------- d-----w- c:\program files\Microsoft SQL Server 2009-10-15 00:27 . 2009-03-14 14:56 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment 2009-10-10 01:46 . 2009-03-04 01:26 -------- d-----w- c:\program files\Warsow 2009-09-29 01:46 . 2009-04-08 21:17 -------- d-----w- c:\users\Michael\AppData\Roaming\mIRC 2009-09-29 00:43 . 2009-04-08 21:17 -------- d-----w- c:\program files\mIRC 2009-09-22 01:52 . 2009-03-13 18:38 -------- d-----w- c:\users\Michael\AppData\Roaming\LimeWire 2009-09-16 01:20 . 2009-03-06 00:44 -------- d-----w- c:\users\Michael\AppData\Roaming\Warsow 2009-09-15 20:04 . 2009-09-15 20:04 37376 ----a-w- c:\windows\system32\drivers\HssDrv.sys 2009-09-15 20:04 . 2009-09-15 20:04 32768 ----a-w- c:\windows\system32\drivers\taphss.sys 2009-09-13 14:03 . 2009-07-28 19:44 92464 ---ha-w- c:\windows\system32\mlfcache.dat 2009-09-12 19:26 . 2009-02-28 00:10 139904 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2009-09-12 19:26 . 2009-02-28 00:10 189744 ----a-w- c:\windows\system32\PnkBstrB.exe 2009-09-11 20:44 . 2009-03-17 01:39 -------- d-----w- c:\program files\Common Files\Merge Modules 2009-09-09 23:34 . 2009-08-22 20:38 -------- d-----w- c:\program files\Windows Live Safety Center 2009-09-07 18:13 . 2009-03-17 01:39 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0 2009-09-07 17:49 . 2009-09-07 17:49 -------- d-----w- c:\program files\Advanced Port Scanner 2009-09-07 17:21 . 2009-05-18 22:31 -------- d-----w- c:\program files\IDA Free 2009-09-07 14:20 . 2009-09-07 14:20 -------- d-----w- c:\programdata\Blizzard Entertainment 2009-09-05 02:15 . 2009-09-05 02:08 -------- d-----w- c:\users\Michael\AppData\Roaming\Apple Computer 2009-09-05 02:13 . 2009-09-05 01:58 -------- d-----w- c:\programdata\Apple 2009-09-05 02:07 . 2009-09-05 02:07 -------- d-----w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-09-05 02:07 . 2009-09-05 02:07 -------- d-----w- c:\program files\iTunes 2009-09-05 02:07 . 2009-09-05 02:07 -------- d-----w- c:\program files\iPod 2009-09-05 02:07 . 2009-09-05 01:58 -------- d-----w- c:\program files\Common Files\Apple 2009-09-05 02:07 . 2009-09-05 02:05 -------- d-----w- c:\programdata\Apple Computer 2009-09-05 02:06 . 2009-03-14 19:06 -------- d-----w- c:\program files\Bonjour 2009-09-05 02:06 . 2009-09-05 02:05 -------- d-----w- c:\program files\QuickTime 2009-09-05 02:04 . 2009-09-05 02:04 -------- d-----w- c:\program files\Apple Software Update 2009-09-04 21:37 . 2009-09-04 21:36 -------- d-----w- c:\users\Michael\AppData\Roaming\Notepad++ 2009-09-04 21:20 . 2009-09-04 21:20 -------- d-----w- c:\users\Michael\AppData\Roaming\Mael 2009-08-29 17:20 . 2009-08-29 17:20 -------- d-----w- c:\users\Michael\AppData\Roaming\SmartFTP 2009-08-29 03:41 . 2009-09-02 23:23 1686528 ----a-w- c:\windows\system32\gameux.dll 2009-08-29 03:40 . 2009-09-02 23:23 28672 ----a-w- c:\windows\system32\Apphlpdm.dll 2009-08-28 23:31 . 2009-09-02 23:23 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2009-08-27 14:02 . 2009-10-16 20:56 832512 ----a-w- c:\windows\system32\wininet.dll 2009-08-27 13:57 . 2009-10-16 20:56 56320 ----a-w- c:\windows\system32\iesetup.dll 2009-08-27 13:57 . 2009-10-16 20:56 78336 ----a-w- c:\windows\system32\ieencode.dll 2009-08-27 13:56 . 2009-10-16 20:56 72704 ----a-w- c:\windows\system32\admparse.dll 2009-08-27 11:24 . 2009-10-16 20:56 26624 ----a-w- c:\windows\system32\ieUnatt.exe 2009-08-27 09:51 . 2009-10-16 20:56 48128 ----a-w- c:\windows\system32\mshtmler.dll 2009-08-18 04:33 . 2009-08-18 04:33 1193832 ----a-w- c:\windows\system32\FM20.DLL 2009-08-14 17:16 . 2009-09-10 20:51 213592 ----a-w- c:\windows\system32\drivers\netio.sys 2009-08-14 16:42 . 2009-09-10 20:51 167424 ----a-w- c:\windows\system32\tcpipcfg.dll 2009-08-14 16:40 . 2009-09-10 20:51 103936 ----a-w- c:\windows\system32\netiohlp.dll 2009-08-14 16:40 . 2009-09-10 20:51 15360 ----a-w- c:\windows\system32\netevent.dll 2009-08-14 14:25 . 2009-09-10 20:51 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE 2009-08-14 14:25 . 2009-09-10 20:51 17920 ----a-w- c:\windows\system32\ROUTE.EXE 2009-08-14 14:25 . 2009-09-10 20:51 11264 ----a-w- c:\windows\system32\MRINFO.EXE 2009-08-14 14:25 . 2009-09-10 20:51 27136 ----a-w- c:\windows\system32\NETSTAT.EXE 2009-08-14 14:25 . 2009-09-10 20:51 19968 ----a-w- c:\windows\system32\ARP.EXE 2009-08-14 14:25 . 2009-09-10 20:51 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE 2009-08-14 14:25 . 2009-09-10 20:51 10240 ----a-w- c:\windows\system32\finger.exe 2009-08-14 14:24 . 2009-09-10 20:51 813568 ----a-w- c:\windows\system32\drivers\tcpip.sys 2009-08-14 14:23 . 2009-09-10 20:51 22016 ----a-w- c:\windows\system32\netiougc.exe 2009-08-13 18:28 . 2009-06-27 22:03 51504 ----a-w- c:\users\Michael_2\AppData\Local\GDIPFONTCACHEV1.DAT 2009-08-05 14:28 . 2009-10-16 20:56 3502152 ----a-w- c:\windows\system32\ntkrnlpa.exe 2009-08-05 14:28 . 2009-10-16 20:56 3467864 ----a-w- c:\windows\system32\ntoskrnl.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal] @="{C5994560-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}] 2008-11-02 14:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified] @="{C5994561-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}] 2008-11-02 14:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict] @="{C5994562-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}] 2008-11-02 14:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked] @="{C5994563-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}] 2008-11-02 14:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly] @="{C5994564-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}] 2008-11-02 14:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted] @="{C5994565-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}] 2008-11-02 14:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded] @="{C5994566-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}] 2008-11-02 14:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored] @="{C5994567-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}] 2008-11-02 14:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned] @="{C5994568-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}] 2008-11-02 14:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "????r"="" [?] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-02-27 1232896] "Steam"="c:\program files\steam\steam.exe" [2009-10-24 1217808] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-07 3885408] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-06 39408] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728] "Speech Recognition"="c:\windows\Speech\Common\sapisvr.exe" [2006-11-02 49664] "cdloader"="c:\users\Michael\AppData\Roaming\mjusbsp\cdloader2.exe" [2009-08-01 50520] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2009-02-27 1006264] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-04 61440] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888] "LogitechCommunicationsManager"="c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-06-26 497200] "LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" [2006-06-26 614960] "LVCOMSX"="c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-06-26 243248] "VolPanel"="d:\program files\Creative\USB Headsets\Volume Panel\VolPanlu.exe" [2008-08-27 233588] "AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-10-24 2010904] "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-11-09 3784704] c:\users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-3-7 576000] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696] Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2006-12-12 528384] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 R0 AvgRkx86;avgrkx86.sys;c:\windows\System32\drivers\avgrkx86.sys [10/24/2009 12:47 PM 161800] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [10/24/2009 12:47 PM 333192] R1 AvgTdiX;AVG Network Redirector;c:\windows\System32\drivers\avgtdix.sys [10/24/2009 12:47 PM 360584] R2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [10/24/2009 12:46 PM 906520] R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [10/24/2009 12:46 PM 285392] R3 skfiltv;skfiltv;c:\windows\System32\drivers\skfiltv.sys [10/6/2009 7:27 PM 17408] S2 gupdate1c9d9ba82edd358;Google Update Service (gupdate1c9d9ba82edd358);c:\program files\Google\Update\GoogleUpdate.exe [5/20/2009 9:19 PM 133104] S3 SbieDrv;SbieDrv;c:\program files\Sandboxie\SbieDrv.sys [5/28/2009 8:32 AM 108032] S3 VSPerfDrv90;Performance Tools Driver 9.0;c:\program files\Microsoft Visual Studio 9.0\Team Tools\Performance Tools\VSPerfDrv90.sys [9/4/2007 4:53 PM 55664] S4 Creative ALchemy AL1 Licensing Service;Creative ALchemy AL1 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe [10/6/2009 7:31 PM 79360] S4 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [10/6/2009 7:24 PM 79360] S4 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [10/6/2009 7:34 PM 79360] S4 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{66GQ7556-22WN-35GR-E1TH-QSTQN766Q5L8}] c:\windows\System32\Spy-Net\WinHelper32.exe.exe Restart . Contents of the 'Scheduled Tasks' folder 2009-10-27 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-28 02:18] 2009-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-21 02:18] 2009-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-21 02:18] . . ------- Supplementary Scan ------- . uStart Page = hxxp://google.com/ uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mStart Page = hxxp://en.us.acer.yahoo.com uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com LSP: c:\windows\system32\wpclsp.dll FF - ProfilePath - c:\users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\3xm87rlz.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll FF - plugin: c:\program files\Google\Google Updater\2.4.1591.6512\npCIDetect13.dll FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . - - - - ORPHANS REMOVED - - - - HKLM-Run-IgfxTray - c:\windows\system32\igfxtray.exe HKLM-Run-HotKeysCmds - c:\windows\system32\hkcmd.exe HKLM-Run-Persistence - c:\windows\system32\igfxpers.exe HKLM-Run-eRecoveryService - (no file) HKLM-Explorer_Run-explorer32 - c:\windows\System32\Spy-Net\WinHelper32.exe.exe SharedTaskScheduler-{A2234B15-23F2-42AD-F4E4-00AAC39C0004} - c:\windows\system32\zkcw2lfbht.dll AddRemove-AV Voice Changer Software DIAMOND 6.0 - c:\progra~1\AVVCS6~1.0DI\UNWISE.EXE AddRemove-Half-Life_is1 - d:\program files\Valve\Half-Life\unins000.exe AddRemove-S.T.A.L.K.E.R. - Shadow of Chernobyl_is1 - d:\program files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\unins000.exe AddRemove-SimAntv1.0 - d:\maxis\SimAnt\DeIsL1.isu AddRemove-SmartFTP Client 3.0 Setup Files - c:\program files\SmartFTP Client 3.0 Setup Files\uninst-sftp.exe AddRemove-VB Decompiler Lite_is1 - c:\program files\VB Decompiler Lite\unins000.exe AddRemove-ScapeRune 513 v1.8 - c:\users\Michael\Documents\ScapeRune 513 v1.8\Uninstal.exe ************************************************************************** scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: ************************************************************************** [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PBDOWNFORCE_SERVICE] "ImagePath"="\??\c:\users\Michael\AppData\Local\Temp\PHQA93B.tmp" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tdlserv] "imagepath"="\??\c:\windows\TEMP\96F5.tmp" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'Explorer.exe'(660) c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll d:\tsvn\bin\TortoiseStub.dll d:\tsvn\bin\TortoiseSVN.dll d:\tsvn\bin\libaprutil_tsvn.dll d:\tsvn\bin\intl3_tsvn.dll c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\program files\Creative\Shared Files\CTAudSvc.exe c:\windows\system32\Ati2evxx.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe c:\program files\AVG\AVG9\avgam.exe c:\program files\AVG\AVG9\avgnsx.exe c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\windows\system32\WUDFHost.exe c:\program files\AVG\AVG9\avgchsvx.exe c:\program files\AVG\AVG9\avgrsx.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\michael\CF9634.exe d:\tsvn\bin\TSVNCache.exe c:\program files\AVG\AVG9\avgtray.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe c:\acer\Empowering Technology\eRecovery\ERAGENT.EXE c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe c:\program files\Logitech\QuickCam10\COCIManager.exe c:\program files\Windows Live\Contacts\wlcomm.exe c:\michael\PEV.cfxxe . ************************************************************************** . Completion time: 2009-10-27 16:26 - machine was rebooted ComboFix-quarantined-files.txt 2009-10-27 21:26 Pre-Run: 46,357,651,456 bytes free Post-Run: 47,107,096,576 bytes free - - End Of File - - EE1E5CC7B39B48C15D922A797348494A |
|
|
Oct 28 2009, 04:37 PM
Post
#8
|
|
![]() Trusted Helper Posts: 211 OS: Windows 7 Professional x64 RTM, Mac OS X 10.5 |
1) Combofix
1. Close any open browsers. 2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 3. Open notepad and copy/paste the text in the quotebox below into it: QUOTE File:: c:\windows\win32k.sys Registry:: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "????r"=- Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe Refering to the picture above, drag CFScript into ComboFix.exe When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply. 2) MBAM Please download Malwarebytes' Anti-Malware to your desktop.
3) ESET You can use either Internet Explorer or Mozilla FireFox for this scan.
4) What You Will Need To Post:
|
|
|
Nov 5 2009, 04:14 AM
Post
#9
|
|
![]() Trusted Helper Posts: 211 OS: Windows 7 Professional x64 RTM, Mac OS X 10.5 |
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
6 / 727 | 23rd April 2009 - 12:55 PM bretty1980 started - last by Rorschach112 |
|||||
![]() |
2 / 575 | 20th June 2009 - 01:42 PM Adam Lonsdale started - last by Rorschach112 |
|||||
![]() |
8 / 167 | 4th August 2009 - 11:02 PM amans started - last by fenzodahl512 |
|||||
![]() |
10 / 152 | 23rd August 2009 - 03:52 AM scitom started - last by Rorschach112 |
|||||
|
Time is now: 21st November 2009 - 06:08 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising