Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Can not find script file C: WINDOWS system32 winjpg jpg


  • This topic is locked This topic is locked

#1
MPoslon

MPoslon

    Member

  • Member
  • PipPip
  • 11 posts
Hello,
I am sure that you can help me.
Every time I press CTRL+ALT+DEL I get the message 'Can not find script file "C:\WINDOWS\system32\winjpg.jpg".'
I had problems with runnig System Restore and opening my hard drives, was getting messages:'Can not find script file "C:\winfile.jpg"' or 'Can not find script file "D:\winfile.jpg"', and something like that. But after I followed your guide I solved that, now there's only the task manager problem. Avast can't seem to find the trojan, or whatever it is, in the \system32 directory.
Here is the MBAM log(I apologize, it's in Croatian, if it's a problem I can translate):
Malwarebytes' Anti-Malware 1.37
Verzija baze podataka: 2229
Windows 5.1.2600 Service Pack 3

4.6.2009 20:55:30
mbam-log-2009-06-04 (20-55-30).txt

Tip provjere: Brza Provjera
Provjerenih objekata: 83544
Vrijeme trajanja: 3 minute(s), 4 second(s)

Zaraženi procesi u memoriji: 0
Zaraženi moduli u memoriji: 0
Zaraženi ključevi u registru: 5
Zaražene vrijednosti u registru: 4
Zaraženi podaci u registru: 1
Zaraženi spremnici: 0
Zaražene datoteke: 0

Zaraženi procesi u memoriji:
(Zloćudne stavke nisu otkrivene)

Zaraženi moduli u memoriji:
(Zloćudne stavke nisu otkrivene)

Zaraženi ključevi u registru:
HKEY_CURRENT_USER\SOFTWARE\MediaHoldings (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexp.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe (Security.Hijack) -> Quarantined and deleted successfully.

Zaražene vrijednosti u registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\host-domain-lookup.com (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\mysearchnow.com (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\www.host-domain-lookup.com (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\www.mysearchnow.com (Malware.Trace) -> Quarantined and deleted successfully.

Zaraženi podaci u registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Zaraženi spremnici:
(Zloćudne stavke nisu otkrivene)

Zaražene datoteke:
(Zloćudne stavke nisu otkrivene)

Rooter log:
Rooter.exe (v1.0) by Eric_71
¨
Microsoft Windows XP Professional (5.1.2600) Service Pack 3
32_bits - x86 Family 15 Model 43 Stepping 1, AuthenticAMD
¨
A:\ [Removable]
C:\ [Fixed-NTFS] .. ( Total:141517 Mo - Free:39110 Mo )
D:\ [Fixed-NTFS] .. ( Total:97848 Mo - Free:32119 Mo )
E:\ [CD_Rom]
F:\ [CD_Rom]
G:\ [Fixed-NTFS] .. ( Total:476938 Mo - Free:419221 Mo )
¨
Scan : 19:57.45
Path : C:\Documents and Settings\Decky\Desktop\Rooter.exe
User : Decky ( Administrator -> YES )
¨
----------------------\\ Processes
¨
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (700)
______ \??\C:\windows\system32\csrss.exe (764)
______ \??\C:\windows\system32\winlogon.exe (792)
______ C:\windows\system32\services.exe (836)
______ C:\windows\system32\lsass.exe (848)
______ C:\windows\system32\svchost.exe (1024)
______ C:\windows\system32\svchost.exe (1072)
______ C:\windows\System32\svchost.exe (1168)
______ C:\windows\system32\svchost.exe (1344)
______ C:\windows\system32\svchost.exe (1420)
______ C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (1484)
______ C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (1500)
______ C:\Program Files\Alwil Software\Avast4\ashServ.exe (1636)
______ C:\windows\Explorer.exe (1804)
______ C:\windows\system32\spoolsv.exe (352)
______ C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe (420)
______ C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe (476)
______ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (484)
______ C:\Program Files\QuickTime\QTTask.exe (496)
______ C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe (568)
______ C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe (592)
______ C:\Program Files\Java\jre6\bin\jusched.exe (872)
______ C:\windows\SOUNDMAN.EXE (992)
______ C:\windows\system32\RUNDLL32.EXE (1116)
______ C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (1128)
______ C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe (1140)
______ C:\Program Files\BugCD Pretrazivac\BugCD Pretrazivac.exe (1152)
______ C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (1188)
______ C:\windows\system32\ctfmon.exe (1244)
______ C:\Program Files\Messenger\msmsgs.exe (1260)
______ C:\Program Files\Steam\Steam.exe (1288)
______ C:\windows\system32\svchost.exe (1780)
______ C:\Program Files\Java\jre6\bin\jqs.exe (2092)
______ C:\Program Files\Common Files\LightScribe\LSSrvc.exe (2132)
______ C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (2152)
______ C:\windows\system32\nvsvc32.exe (2172)
______ C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe (2240)
______ C:\windows\system32\svchost.exe (2348)
______ C:\Program Files\Canon\CAL\CALMAIN.exe (3208)
______ C:\Program Files\Common Files\Teleca Shared\Generic.exe (3324)
______ C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (3572)
______ C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe (3664)
______ C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (3736)
______ C:\WINDOWS\system32\wbem\unsecapp.exe (3768)
______ C:\windows\system32\wbem\wmiprvse.exe (280)
______ C:\windows\System32\alg.exe (748)
______ C:\windows\system32\wuauclt.exe (3004)
______ C:\Program Files\Mozilla Firefox\firefox.exe (2668)
______ C:\Documents and Settings\Decky\Desktop\Rooter.exe (3548)
¨
----------------------\\ Device\Harddisk0\
¨
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
¨
\Device\Harddisk0\Partition1 --[ MBR ]-- (Start_Offset:32256 | Length:148392244224)
\Device\Harddisk0\Partition0 (Start_Offset:148392276480 | Length:102602142720)
\Device\Harddisk0\Partition2 (Start_Offset:148392308736 | Length:102602110464)
¨
----------------------\\ Scheduled Tasks
¨
C:\windows\Tasks\Ad-Aware Update (Weekly).job
C:\windows\Tasks\desktop.ini
C:\windows\Tasks\SA.DAT
C:\windows\Tasks\SmartDefrag.job
C:\windows\Tasks\WGASetup.job
¨
----------------------\\ Registry
¨
¨
----------------------\\ Files & Folders
¨
----------------------\\ Scan completed at 19:58.10
¨
C:\Rooter$\Rooter_1.txt - (14/06/2009 | 19:58.10)

OTL log:
OTL logfile created on: 14.6.2009 20:01:09 - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\Decky\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 0000041A | Country: Croatia | Language: HRV | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 1,40 Gb Available Physical Memory | 70,12% Memory free
3,35 Gb Paging File | 2,83 Gb Available in Paging File | 84,64% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 138,20 Gb Total Space | 38,19 Gb Free Space | 27,64% Space Free | Partition Type: NTFS
Drive D: | 95,56 Gb Total Space | 31,37 Gb Free Space | 32,83% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 465,76 Gb Total Space | 409,40 Gb Free Space | 87,90% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DECKY-E93819898
Current User Name: Decky
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\windows\Explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe (Sony Ericsson Mobile Communications AB)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
PRC - C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe (IObit)
PRC - C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe (Teleca Software Solutions AB)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\windows\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files\BugCD Pretrazivac\BugCD Pretrazivac.exe ()
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Program Files\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
PRC - C:\windows\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe (Rocket Division Software)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Program Files\Common Files\Teleca Shared\Generic.exe (Teleca Software Solutions)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe (Sony Ericsson Mobile Communications AB)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\windows\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Decky\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe LM Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (avast! Antivirus [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (CCALib8 [Auto | Running]) -- C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) -- C:\windows\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Stopped]) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LightScribeService [Auto | Running]) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (Macromedia Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe (Macromedia)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (nTuneService [Auto | Running]) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
SRV - (NVSvc [Auto | Running]) -- C:\windows\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (StarWindService [Auto | Running]) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe (Rocket Division Software)
SRV - (usnjsvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WLSetupSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (Aavmker4 [System | Running]) -- C:\windows\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (ALCXWDM [On_Demand | Running]) -- C:\windows\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AmdLLD [On_Demand | Running]) -- C:\windows\system32\DRIVERS\AmdLLD.sys (AMD, Inc.)
DRV - (ASAPIW2k [On_Demand | Running]) -- C:\windows\system32\drivers\ASAPIW2k.sys (Pinnacle Systems GmbH)
DRV - (Aspi32 [Auto | Running]) -- C:\windows\System32\drivers\aspi32.sys (Adaptec)
DRV - (aswFsBlk [Auto | Running]) -- C:\windows\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) -- C:\windows\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) -- C:\windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) -- C:\windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) -- C:\windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (athsgt [Auto | Running]) -- C:\windows\system32\DRIVERS\athsgt.sys ()
DRV - (enodpl [Auto | Running]) -- C:\windows\System32\drivers\enodpl.sys ()
DRV - (ENTECH [On_Demand | Stopped]) -- C:\windows\system32\DRIVERS\ENTECH.sys (EnTech Taiwan)
DRV - (k510bus [On_Demand | Stopped]) -- C:\windows\system32\DRIVERS\k510bus.sys (MCCI)
DRV - (k510mdfl [On_Demand | Stopped]) -- C:\windows\system32\DRIVERS\k510mdfl.sys (MCCI)
DRV - (k510mdm [On_Demand | Stopped]) -- C:\windows\system32\DRIVERS\k510mdm.sys (MCCI)
DRV - (k510mgmt [On_Demand | Stopped]) -- C:\windows\system32\DRIVERS\k510mgmt.sys (MCCI)
DRV - (k510obex [On_Demand | Stopped]) -- C:\windows\system32\DRIVERS\k510obex.sys (MCCI)
DRV - (k750bus [On_Demand | Stopped]) -- C:\windows\system32\DRIVERS\k750bus.sys (MCCI)
DRV - (k750mdfl [On_Demand | Stopped]) -- C:\windows\system32\DRIVERS\k750mdfl.sys (MCCI)
DRV - (k750mdm [On_Demand | Stopped]) -- C:\windows\system32\DRIVERS\k750mdm.sys (MCCI)
DRV - (k750mgmt [On_Demand | Stopped]) -- C:\windows\system32\DRIVERS\k750mgmt.sys (MCCI)
DRV - (k750obex [On_Demand | Stopped]) -- C:\windows\system32\DRIVERS\k750obex.sys (MCCI)
DRV - (Lbd [Boot | Running]) -- C:\windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (limsgt [Auto | Running]) -- C:\windows\system32\DRIVERS\limsgt.sys ()
DRV - (nv [On_Demand | Running]) -- C:\windows\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvatabus [Boot | Running]) -- C:\windows\system32\DRIVERS\nvatabus.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) -- C:\windows\system32\DRIVERS\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) -- C:\windows\system32\DRIVERS\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVR0Dev [On_Demand | Running]) -- C:\windows\nvoclock.sys (NVidia Corp.)
DRV - (PQNTDrv [System | Running]) -- C:\windows\System32\drivers\PQNTDRV.sys (PowerQuest Corporation)
DRV - (prodrv06 [System | Running]) -- C:\windows\System32\drivers\prodrv06.sys (Protection Technology)
DRV - (prohlp02 [Boot | Running]) -- C:\windows\System32\drivers\prohlp02.sys (Protection Technology)
DRV - (prosync1 [Boot | Running]) -- C:\windows\System32\drivers\prosync1.sys (Protection Technology)
DRV - (Ptilink [On_Demand | Running]) -- C:\windows\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (RivaTuner32 [On_Demand | Running]) -- C:\Program Files\RivaTuner v2.24\RivaTuner32.sys ()
DRV - (SCDEmu [System | Running]) -- C:\windows\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (Secdrv [Auto | Running]) -- C:\windows\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sfhlp01 [Boot | Running]) -- C:\windows\System32\drivers\sfhlp01.sys (Protection Technology)
DRV - (sfhlp02 [Boot | Running]) -- C:\windows\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (sfsync03 [Boot | Running]) -- C:\windows\System32\drivers\sfsync03.sys (Protection Technology)
DRV - (sfvfs02 [Boot | Running]) -- C:\windows\System32\drivers\sfvfs02.sys (Protection Technology)
DRV - (sptd [Boot | Running]) -- C:\windows\System32\Drivers\sptd.sys ()
DRV - (tandpl [Auto | Running]) -- C:\windows\System32\drivers\tandpl.sys ()
DRV - (Vax347b [Boot | Running]) -- C:\windows\system32\DRIVERS\Vax347b.sys ( )
DRV - (Vax347s [Boot | Running]) -- C:\windows\System32\Drivers\Vax347s.sys ( )

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Update_Check_Page = http://www.microsoft...mp;Ar=ie5update
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.hr/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.oglasnik.hr/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.3.0
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.3
FF - prefs.js..extensions.enabledItems: {b66bc4c3-6d25-4a10-8c59-01daa9063051}:1.4.18.11
FF - prefs.js..extensions.enabledItems: {463F6CA5-EE3C-4be1-B7E6-7FEE11953374}:3.5.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {6e764c17-863a-450f-bdd0-6772bd5aaa18}:1.0.3
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.3.3
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD [2008.06.15 22:38:29 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009.01.16 16:20:56 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009.06.14 10:01:51 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009.06.14 10:01:51 | 00,000,000 | ---D | M]

[2008.06.25 23:02:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Decky\Application Data\mozilla\Extensions
[2008.06.25 23:02:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Decky\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009.06.14 19:56:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Decky\Application Data\mozilla\Firefox\Profiles\be0vk58y.default\extensions
[2009.05.07 20:59:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Decky\Application Data\mozilla\Firefox\Profiles\be0vk58y.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2009.04.29 09:08:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Decky\Application Data\mozilla\Firefox\Profiles\be0vk58y.default\extensions\{6e764c17-863a-450f-bdd0-6772bd5aaa18}
[2009.06.14 19:56:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Decky\Application Data\mozilla\Firefox\Profiles\be0vk58y.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009.02.22 14:47:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Decky\Application Data\mozilla\Firefox\Profiles\be0vk58y.default\extensions\{b66bc4c3-6d25-4a10-8c59-01daa9063051}
[2009.05.10 09:33:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Decky\Application Data\mozilla\Firefox\Profiles\be0vk58y.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2008.01.11 13:06:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Decky\Application Data\mozilla\Firefox\Profiles\be0vk58y.default\extensions\[email protected]
[2009.05.05 17:25:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Decky\Application Data\mozilla\Firefox\Profiles\be0vk58y.default\extensions\[email protected]
[2009.06.14 19:56:17 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009.06.14 10:01:51 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008.08.21 09:21:07 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009.01.16 16:21:10 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009.04.09 12:26:43 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009.06.14 10:01:43 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009.06.14 10:01:43 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009.05.03 12:59:11 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009.05.03 12:59:11 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009.05.03 12:59:11 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009.05.03 12:59:11 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009.05.03 12:59:12 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009.05.03 12:59:12 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009.05.03 12:59:12 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (311670 bytes) - C:\windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 10680 more lines...
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\windows\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKLM..\Run: [PinnacleDriverCheck] C:\windows\system32\PSDrvCheck.exe -CheckReg ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.24\RivaTuner.exe" /S ()
O4 - HKLM..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp (IObit)
O4 - HKLM..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions (Sony Ericsson Mobile Communications AB)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" (Nero AG)
O4 - HKCU..\Run: [BugCD Pretrazivac] C:\Program Files\BugCD Pretrazivac\BugCD Pretrazivac.exe ()
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear (NVIDIA)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent (Valve Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\Decky\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: English<->French - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-French) for Windows\Plugins\IE.htm ()
O8 - Extra context menu item: English<->German - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-German) for Windows\Plugins\IE.htm ()
O8 - Extra context menu item: English<->Italian - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Italian) for Windows\Plugins\IE.htm ()
O8 - Extra context menu item: English<->Latin - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Latin) for Windows\Plugins\IE.htm ()
O8 - Extra context menu item: English<->Spanish - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Spanish) for Windows\Plugins\IE.htm ()
O8 - Extra context menu item: eng-scr - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Croatian) for Windows\Plugins\IE.htm ()
O8 - Extra context menu item: I&zvoz u Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Stavi na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Stavi na blog u Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: English<->German - {2DDEE708-A225-6449-889B-1941E2FBAB6D} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-German) for Windows\Plugins\IE.htm ()
O9 - Extra 'Tools' menuitem : English<->German - {2DDEE708-A225-6449-889B-1941E2FBAB6D} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-German) for Windows\Plugins\IE.htm ()
O9 - Extra Button: English<->Latin - {4629E725-138D-0F4C-B01A-09EBD3D67834} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Latin) for Windows\Plugins\IE.htm ()
O9 - Extra 'Tools' menuitem : English<->Latin - {4629E725-138D-0F4C-B01A-09EBD3D67834} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Latin) for Windows\Plugins\IE.htm ()
O9 - Extra Button: English<->Italian - {73AD0419-12E3-E74C-B893-EA4EF48F451F} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Italian) for Windows\Plugins\IE.htm ()
O9 - Extra 'Tools' menuitem : English<->Italian - {73AD0419-12E3-E74C-B893-EA4EF48F451F} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Italian) for Windows\Plugins\IE.htm ()
O9 - Extra Button: Istraživanje - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: English<->French - {9771B718-0C1C-3248-A000-C378A44BF07B} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-French) for Windows\Plugins\IE.htm ()
O9 - Extra 'Tools' menuitem : English<->French - {9771B718-0C1C-3248-A000-C378A44BF07B} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-French) for Windows\Plugins\IE.htm ()
O9 - Extra Button: English<->Spanish - {A9919568-CF8E-C140-84DC-0FF917685E69} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Spanish) for Windows\Plugins\IE.htm ()
O9 - Extra 'Tools' menuitem : English<->Spanish - {A9919568-CF8E-C140-84DC-0FF917685E69} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Spanish) for Windows\Plugins\IE.htm ()
O9 - Extra Button: English<->Croatian - {B05D861D-C01F-7C4C-A7FF-A8003A8FE77C} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Croatian) for Windows\Plugins\IE.htm ()
O9 - Extra 'Tools' menuitem : eng-scr - {B05D861D-C01F-7C4C-A7FF-A8003A8FE77C} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Croatian) for Windows\Plugins\IE.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 51 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.srtest.co.../sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.mi...b?1200047154156 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\dwwinxp.exe: Debugger - C:\WINDOWS\system32\winxp.exe File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{9484c51a-f4c1-11db-98e7-00016ce45155}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a1a75f18-faf5-11db-98fc-00016ce45155}\Shell\Auto\command - "" = H:\AdobeR.exe -- File not found
O33 - MountPoints2\{a1a75f18-faf5-11db-98fc-00016ce45155}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{cc6329a9-9efa-11db-97dd-00016ce45155}\Shell\Auto\command - "" = AdobeR.exe e
O33 - MountPoints2\{cc6329a9-9efa-11db-97dd-00016ce45155}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{da4bcfdb-5b8a-11d9-ba0e-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{da4bcfdb-5b8a-11d9-ba0e-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{da4bcfdb-5b8a-11d9-ba0e-806d6172696f}\Shell\AutoRun\command - "" = C:\windows\system32\setup.exe -- [2008.04.14 05:42:36 | 00,023,040 | ---- | M] (Microsoft Corporation)
O33 - MountPoints2\{dc6fa386-8f9f-11db-97a1-00016ce45155}\Shell - "" = AutoRun
O33 - MountPoints2\{dc6fa386-8f9f-11db-97a1-00016ce45155}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{dc6fa386-8f9f-11db-97a1-00016ce45155}\Shell\AutoRun\command - "" = N:\autorun.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009.06.14 19:59:11 | 00,000,000 | ---D | M]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\windows\System32\lsdelete.exe ()
O34 - HKLM BootExecute: (lsdelete) - C:\windows\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[58 C:\Documents and Settings\All Users\Application Data\*.tmp files]
[2009.06.14 19:59:11 | 00,501,760 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Decky\Desktop\OTL.exe
[2009.06.14 19:58:10 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009.06.14 19:54:36 | 00,170,029 | ---- | C] (Eric_71) -- C:\Documents and Settings\Decky\Desktop\Rooter.exe
[2009.06.14 11:40:39 | 00,000,836 | ---- | C] () -- C:\Documents and Settings\Decky\Desktop\F1 2oo9 Delux Game (TPTB).lnk
[2009.06.13 14:17:19 | 00,056,982 | ---- | C] () -- C:\Documents and Settings\Decky\Desktop\Death.Race[2008][Unrated.Edition]DvDrip-aXXo.4560022.TPB.torrent
[2009.06.13 13:46:27 | 00,019,021 | ---- | C] () -- C:\Documents and Settings\Decky\Desktop\Transformers[2007]DvDrip[Eng]-aXXo.4477411.TPB.torrent
[2009.06.12 00:34:45 | 00,054,156 | -H-- | C] () -- C:\windows\QTFont.qfn
[2009.06.12 00:34:45 | 00,001,409 | ---- | C] () -- C:\windows\QTFont.for
[2009.06.08 18:09:31 | 00,000,285 | ---- | C] () -- C:\Documents and Settings\Decky\Desktop\Shortcut to Local Disk (G).lnk
[2009.06.07 21:55:44 | 00,053,248 | ---- | C] () -- C:\Documents and Settings\Decky\My Documents\Neutrum, das sächliche Geschlecht.ppt
[2009.06.04 22:17:25 | 00,015,688 | ---- | C] () -- C:\windows\System32\lsdelete.exe
[2009.06.04 22:09:35 | 00,064,160 | ---- | C] (Lavasoft AB) -- C:\windows\System32\drivers\Lbd.sys
[2009.06.04 22:09:13 | 00,000,472 | ---- | C] () -- C:\windows\tasks\Ad-Aware Update (Weekly).job
[2009.06.04 22:02:28 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009.06.04 22:02:27 | 00,000,867 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009.06.04 21:59:04 | 37,452,296 | ---- | C] (Lavasoft ) -- C:\Documents and Settings\Decky\Desktop\Ad-AwareAE.exe
[2009.06.04 21:36:54 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- C:\Documents and Settings\Decky\Desktop\setup-spybotsd162.exe
[2009.06.04 20:49:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Decky\Application Data\Malwarebytes
[2009.06.04 20:49:57 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009.06.04 20:49:55 | 00,040,160 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys
[2009.06.04 20:49:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009.06.04 20:49:53 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys
[2009.06.04 20:49:53 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009.06.04 20:47:57 | 03,371,376 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Decky\Desktop\mbam-setup.exe
[2009.06.04 20:47:26 | 00,000,000 | ---D | C] -- C:\windows\ERDNT
[2009.06.04 20:46:33 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\Decky\Desktop\NTREGOPT.lnk
[2009.06.04 20:46:33 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\Decky\Desktop\ERUNT.lnk
[2009.06.04 20:46:32 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009.06.04 20:43:53 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\Decky\Desktop\erunt_setup.exe
[2009.06.04 20:37:12 | 00,021,504 | ---- | C] (Doug Knox) -- C:\Documents and Settings\Decky\Desktop\SysRestorePoint.exe
[2009.06.04 20:30:44 | 00,265,216 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Decky\Desktop\TFC.exe
[2009.06.04 19:57:11 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\Decky\Desktop\HijackThis.lnk
[2009.06.04 19:57:11 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009.06.02 18:13:27 | 00,020,258 | ---- | C] () -- C:\Documents and Settings\Decky\Desktop\S.T.A.L.K.E.R_Clear_sky(Eng).mds.4380925.TPB [mininova].torrent
[2009.05.19 16:01:36 | 18,373,590 | ---- | C] () -- C:\Documents and Settings\Decky\Desktop\MVI_1387.avi
[2009.05.19 15:38:12 | 30,565,050 | ---- | C] () -- C:\Documents and Settings\Decky\Desktop\MVI_1384.avi
[2009.05.01 13:06:50 | 00,118,784 | ---- | C] () -- C:\windows\System32\NxExtensions.dll
[2009.04.09 12:50:52 | 00,000,164 | R--- | C] () -- C:\windows\avrack.ini
[2009.03.27 10:03:00 | 01,724,416 | ---- | C] () -- C:\windows\System32\nvwdmcpl.dll
[2009.03.27 10:03:00 | 01,503,232 | ---- | C] () -- C:\windows\System32\nview.dll
[2009.03.27 10:03:00 | 01,101,824 | ---- | C] () -- C:\windows\System32\nvwimg.dll
[2009.03.27 10:03:00 | 00,466,944 | ---- | C] () -- C:\windows\System32\nvshell.dll
[2008.10.07 09:13:30 | 00,197,912 | ---- | C] () -- C:\windows\System32\physxcudart_20.dll
[2008.10.07 09:13:22 | 00,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelTraditionalChinese.dll
[2008.10.07 09:13:20 | 00,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelSwedish.dll
[2008.10.07 09:13:20 | 00,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelSpanish.dll
[2008.10.07 09:13:20 | 00,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelSimplifiedChinese.dll
[2008.10.07 09:13:20 | 00,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelPortugese.dll
[2008.10.07 09:13:20 | 00,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelKorean.dll
[2008.10.07 09:13:20 | 00,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelJapanese.dll
[2008.10.07 09:13:20 | 00,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelGerman.dll
[2008.10.07 09:13:20 | 00,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelFrench.dll
[2008.08.27 23:03:26 | 00,042,320 | ---- | C] () -- C:\windows\System32\xfcodec.dll
[2008.04.13 20:27:32 | 00,000,012 | ---- | C] () -- C:\windows\dirsaver.ini
[2008.04.09 09:33:50 | 00,027,648 | -HS- | C] () -- C:\windows\System32\Smab0.dll
[2008.02.03 21:37:27 | 00,022,328 | ---- | C] () -- C:\windows\System32\drivers\PnkBstrK.sys
[2007.12.24 00:29:00 | 00,000,391 | ---- | C] () -- C:\windows\wininit.ini
[2007.11.30 16:44:58 | 00,408,576 | ---- | C] () -- C:\windows\System32\Smab.dll
[2007.11.30 16:44:57 | 00,027,648 | ---- | C] () -- C:\windows\System32\AVSredirect.dll
[2007.06.20 10:54:02 | 00,000,065 | ---- | C] () -- C:\windows\mp3wavcon.ini
[2007.03.25 20:02:58 | 00,639,224 | ---- | C] () -- C:\windows\System32\drivers\sptd.sys
[2007.03.12 13:01:30 | 00,217,088 | ---- | C] () -- C:\windows\NVGfxOgl.dll
[2007.01.31 00:12:44 | 00,000,023 | ---- | C] () -- C:\windows\BlendSettings.ini
[2007.01.08 11:40:01 | 00,000,000 | ---- | C] () -- C:\windows\mngui.INI
[2006.10.22 18:45:06 | 00,000,200 | ---- | C] () -- C:\windows\MATLAB.INI
[2006.07.29 09:22:15 | 00,043,520 | ---- | C] () -- C:\windows\System32\CmdLineExt03.dll
[2006.07.28 16:13:57 | 00,069,632 | R--- | C] () -- C:\windows\System32\xmltok.dll
[2006.07.28 16:13:57 | 00,036,864 | R--- | C] () -- C:\windows\System32\xmlparse.dll
[2006.07.27 18:21:10 | 00,164,992 | ---- | C] () -- C:\windows\System32\drivers\athsgt.sys
[2006.07.27 18:21:10 | 00,012,544 | ---- | C] () -- C:\windows\System32\drivers\limsgt.sys
[2006.07.26 18:43:10 | 00,007,552 | ---- | C] () -- C:\windows\System32\drivers\enodpl.sys
[2006.07.26 18:43:10 | 00,004,736 | ---- | C] () -- C:\windows\System32\drivers\tandpl.sys
[2006.07.13 13:05:32 | 00,000,632 | ---- | C] () -- C:\windows\CoDUO.INI
[2006.07.12 16:49:18 | 00,034,308 | ---- | C] () -- C:\windows\System32\BASSMOD.dll
[2006.07.12 16:46:50 | 00,159,616 | ---- | C] ( ) -- C:\windows\System32\drivers\Vax347b.sys
[2006.07.12 16:46:50 | 00,005,248 | ---- | C] ( ) -- C:\windows\System32\drivers\Vax347s.sys
[2006.07.12 12:49:58 | 00,000,394 | ---- | C] () -- C:\windows\ODBC.INI
[2006.07.12 11:55:58 | 00,000,116 | ---- | C] () -- C:\windows\NeroDigital.ini
[2006.07.11 10:12:08 | 00,000,204 | ---- | C] () -- C:\windows\RtlRack.ini
[2006.07.11 10:09:50 | 00,156,672 | R--- | C] () -- C:\windows\System32\RTLCPAPI.dll
[2005.06.19 09:49:00 | 00,010,752 | ---- | C] () -- C:\windows\System32\ff_vfw.dll
[2005.06.11 11:47:00 | 00,045,056 | ---- | C] () -- C:\windows\System32\fpprintmon.dll
[2005.02.24 18:56:45 | 00,000,547 | ---- | C] () -- C:\windows\System32\ff_vfw.dll.manifest
[2003.12.22 14:40:06 | 01,663,068 | ---- | C] () -- C:\windows\System32\libmmd.dll
[2003.08.07 14:01:52 | 00,237,568 | ---- | C] () -- C:\windows\System32\lame_enc.dll
[2003.07.01 09:36:02 | 00,005,373 | ---- | C] () -- C:\windows\System32\OUTLPERF.INI
[2001.08.23 14:00:00 | 00,000,981 | ---- | C] () -- C:\windows\win.ini
[2001.08.23 14:00:00 | 00,000,231 | ---- | C] () -- C:\windows\system.ini
[1995.03.22 09:00:00 | 00,056,832 | ---- | C] () -- C:\windows\System32\iyvu9_32.dll

========== Files - Modified Within 30 Days ==========

[58 C:\Documents and Settings\All Users\Application Data\*.tmp files]
[2009.06.14 19:59:11 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Decky\Desktop\OTL.exe
[2009.06.14 19:54:36 | 00,170,029 | ---- | M] (Eric_71) -- C:\Documents and Settings\Decky\Desktop\Rooter.exe
[2009.06.14 19:47:02 | 00,000,260 | ---- | M] () -- C:\windows\tasks\WGASetup.job
[2009.06.14 19:46:59 | 00,212,296 | ---- | M] () -- C:\windows\System32\nvapps.xml
[2009.06.14 19:46:54 | 00,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT
[2009.06.14 19:46:51 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Decky\Local Settings\desktop.ini
[2009.06.14 19:46:49 | 00,002,048 | --S- | M] () -- C:\windows\bootstat.dat
[2009.06.14 15:30:39 | 00,000,565 | ---- | M] () -- C:\Documents and Settings\Decky\My Documents\Moje mape za zajedničko korištenje.lnk
[2009.06.14 12:45:55 | 00,311,670 | R--- | M] () -- C:\windows\System32\drivers\etc\hosts
[2009.06.14 12:41:48 | 00,000,981 | ---- | M] () -- C:\windows\win.ini
[2009.06.14 12:17:26 | 00,000,836 | ---- | M] () -- C:\Documents and Settings\Decky\Desktop\F1 2oo9 Delux Game (TPTB).lnk
[2009.06.14 09:58:45 | 00,002,206 | ---- | M] () -- C:\windows\System32\wpa.dbl
[2009.06.13 14:17:19 | 00,056,982 | ---- | M] () -- C:\Documents and Settings\Decky\Desktop\Death.Race[2008][Unrated.Edition]DvDrip-aXXo.4560022.TPB.torrent
[2009.06.13 13:46:27 | 00,019,021 | ---- | M] () -- C:\Documents and Settings\Decky\Desktop\Transformers[2007]DvDrip[Eng]-aXXo.4477411.TPB.torrent
[2009.06.12 11:14:39 | 00,439,264 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2009.06.12 11:14:39 | 00,070,968 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2009.06.12 11:14:38 | 00,516,804 | ---- | M] () -- C:\windows\System32\PerfStringBackup.INI
[2009.06.12 11:12:25 | 00,270,984 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2009.06.12 09:35:56 | 00,001,374 | ---- | M] () -- C:\windows\imsins.BAK
[2009.06.12 00:34:45 | 00,054,156 | -H-- | M] () -- C:\windows\QTFont.qfn
[2009.06.12 00:34:45 | 00,001,409 | ---- | M] () -- C:\windows\QTFont.for
[2009.06.11 22:09:34 | 00,000,472 | ---- | M] () -- C:\windows\tasks\Ad-Aware Update (Weekly).job
[2009.06.08 18:09:31 | 00,000,285 | ---- | M] () -- C:\Documents and Settings\Decky\Desktop\Shortcut to Local Disk (G).lnk
[2009.06.07 21:55:44 | 00,053,248 | ---- | M] () -- C:\Documents and Settings\Decky\My Documents\Neutrum, das sächliche Geschlecht.ppt
[2009.06.04 22:09:01 | 00,015,688 | ---- | M] () -- C:\windows\System32\lsdelete.exe
[2009.06.04 22:08:51 | 00,064,160 | ---- | M] (Lavasoft AB) -- C:\windows\System32\drivers\Lbd.sys
[2009.06.04 22:02:27 | 00,000,867 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009.06.04 22:01:12 | 37,452,296 | ---- | M] (Lavasoft ) -- C:\Documents and Settings\Decky\Desktop\Ad-AwareAE.exe
[2009.06.04 21:54:31 | 00,000,391 | ---- | M] () -- C:\windows\wininit.ini
[2009.06.04 21:41:05 | 00,311,656 | R--- | M] () -- C:\windows\System32\drivers\etc\hosts.20090614-124555.backup
[2009.06.04 21:38:34 | 00,000,933 | ---- | M] () -- C:\Documents and Settings\Decky\Desktop\Spybot - Search & Destroy.lnk
[2009.06.04 21:37:27 | 16,409,960 | ---- | M] (Safer Networking Limited ) -- C:\Documents and Settings\Decky\Desktop\setup-spybotsd162.exe
[2009.06.04 20:49:57 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009.06.04 20:49:25 | 03,371,376 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Decky\Desktop\mbam-setup.exe
[2009.06.04 20:46:33 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\Decky\Desktop\NTREGOPT.lnk
[2009.06.04 20:46:33 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\Decky\Desktop\ERUNT.lnk
[2009.06.04 20:43:54 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\Decky\Desktop\erunt_setup.exe
[2009.06.04 20:37:12 | 00,021,504 | ---- | M] (Doug Knox) -- C:\Documents and Settings\Decky\Desktop\SysRestorePoint.exe
[2009.06.04 20:30:44 | 00,265,216 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Decky\Desktop\TFC.exe
[2009.06.04 19:57:11 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Decky\Desktop\HijackThis.lnk
[2009.06.02 18:13:27 | 00,020,258 | ---- | M] () -- C:\Documents and Settings\Decky\Desktop\S.T.A.L.K.E.R_Clear_sky(Eng).mds.4380925.TPB [mininova].torrent
[2009.06.01 18:51:12 | 23,635,392 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\MRT.exe
[2009.05.31 22:00:00 | 00,000,384 | ---- | M] () -- C:\windows\tasks\SmartDefrag.job
[2009.05.26 13:20:08 | 00,040,160 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys
[2009.05.26 13:19:56 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys
[2009.05.21 13:54:31 | 00,000,116 | ---- | M] () -- C:\windows\NeroDigital.ini
[2009.05.20 16:57:43 | 00,000,023 | ---- | M] () -- C:\windows\BlendSettings.ini
[2009.05.20 12:14:12 | 00,002,377 | ---- | M] () -- C:\Documents and Settings\Decky\Desktop\FBWH BenchTool.lnk
[2009.05.19 16:01:36 | 18,373,590 | ---- | M] () -- C:\Documents and Settings\Decky\Desktop\MVI_1387.avi
[2009.05.19 15:38:12 | 30,565,050 | ---- | M] () -- C:\Documents and Settings\Decky\Desktop\MVI_1384.avi
< End of report >

OTL Extras:
OTL Extras logfile created on: 14.6.2009 20:01:09 - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\Decky\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 0000041A | Country: Croatia | Language: HRV | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 1,40 Gb Available Physical Memory | 70,12% Memory free
3,35 Gb Paging File | 2,83 Gb Available in Paging File | 84,64% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 138,20 Gb Total Space | 38,19 Gb Free Space | 27,64% Space Free | Partition Type: NTFS
Drive D: | 95,56 Gb Total Space | 31,37 Gb Free Space | 32,83% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 465,76 Gb Total Space | 409,40 Gb Free Space | 87,90% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DECKY-E93819898
Current User Name: Decky
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = Opera.HTML] -- C:\Program Files\Opera\opera.exe (Opera Software)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"15155:TCP" = 15155:TCP:*:Enabled:NortonAV
"16556:TCP" = 16556:TCP:*:Enabled:NortonAV
"17096:TCP" = 17096:TCP:*:Enabled:NortonAV
"17464:TCP" = 17464:TCP:*:Enabled:NortonAV
"13299:TCP" = 13299:TCP:*:Enabled:NortonAV
"12569:TCP" = 12569:TCP:*:Enabled:NortonAV
"15798:TCP" = 15798:TCP:*:Enabled:NortonAV
"17026:TCP" = 17026:TCP:*:Enabled:NortonAV
"13516:TCP" = 13516:TCP:*:Enabled:NortonAV
"13575:TCP" = 13575:TCP:*:Enabled:NortonAV
"18893:TCP" = 18893:TCP:*:Enabled:NortonAV
"18350:TCP" = 18350:TCP:*:Enabled:NortonAV
"16026:TCP" = 16026:TCP:*:Enabled:NortonAV
"18699:TCP" = 18699:TCP:*:Enabled:NortonAV
"18167:TCP" = 18167:TCP:*:Enabled:NortonAV
"17674:TCP" = 17674:TCP:*:Enabled:NortonAV
"18146:TCP" = 18146:TCP:*:Enabled:NortonAV
"12715:TCP" = 12715:TCP:*:Enabled:NortonAV
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\EA GAMES\Medal of Honor Pacific Assault™\mohpa.exe:*:Disabled:Medal of Honor Pacific Assault™ File not found
C:\Program Files\Atari\BOILING POINT\Xenus.exe:*:Disabled:Xenus ()
D:\Program Files\THQ\MotoGP URT 3\motogp.exe:*:Disabled:motogp File not found
D:\Program Files\EA GAMES\Need For Speed Underground\Speed.exe:*:Disabled:Speed File not found
D:\Atari\Test Drive Unlimited\TestDriveUnlimited.exe:*:Disabled:Test Drive Unlimited File not found
D:\Program Files\Live for Speed S2\LFSspotter.exe:*:Disabled:LFSspotter ()
D:\Program Files\Live for Speed S2\LFS.exe:*:Disabled:LFS ()
D:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe:*:Disabled:DarkCrusade (THQ Canada Inc.)
D:\Program Files\THQ\Dawn of War\W40k.exe:*:Disabled:W40K File not found
D:\Program Files\Atari\Test Drive Unlimited\TestDriveUnlimited.exe:*:Disabled:Test Drive Unlimited (Eden Games)
D:\Program Files\Firefly Studios\Stronghold 2\Stronghold2.exe:*:Enabled:Stronghold 2 (Firefly Studios)
C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent File not found
C:\Program Files\Opera\Opera.exe:*:Enabled:Opera Internet Browser (Opera Software)
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Internet Security 7.0.1.321\English\setup.exe:*:Enabled:Kaspersky Internet Security 7.0 Setup (Kaspersky Lab)
C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer (RealNetworks, Inc.)
C:\Program Files\Participatory Culture Foundation\Miro\Miro_Downloader.exe:*:Enabled:Miro_Downloader File not found
C:\Program Files\DNA\btdna.exe:*:Enabled:DNA (BitTorrent, Inc.)
C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent File not found
D:\Program Files\EA SPORTS\FIFA 07\fifa07.exe:*:Enabled:fifa07 File not found
C:\WINDOWS\system32\oykfqe.exe:*:Enabled:oykfqe File not found
C:\WINDOWS\winlogon.exe File not found
C:\Program Files\DC++\DCPlusPlus.exe:*:Enabled:DC++ File not found
D:\Program Files\Team6 game studios\Scooter War3z\Scooter.exe:*:Enabled:Scooter File not found
C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:LimeWire (FrostWire Group)
C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA ()
C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB ()
C:\Program Files\Xfire\xfire.exe:*:Enabled:Xfire (Xfire Inc.)
C:\Program Files\MessengerDiscovery\MessengerDiscovery Live.exe:*:Enabled:MessengerDiscovery Live the Windows Live Messenger addon (MessengerDiscovery)
D:\Program Files\Activision Value\Soldier of Fortune Payback\sof3.exe:*:Enabled:sof3 File not found
C:\Program Files\TVUPlayer\TVUPlayer.exe:*:Enabled:TVUPlayer Component File not found
C:\Program Files\Atari\Shadow Ops Red Mercury\System\RM.exe:*:Enabled:RM File not found
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
C:\Program Files\DrivingSpeed2\DrivingSpeed.exe:*:Enabled:Driving Speed Application File not found
C:\Program Files\Ea Sports\F1 Challenge 2007\F1Challenge2007.exe:*:Enabled:F1 Challenge 99-02 File not found
C:\Program Files\Empire Interactive\FlatOut\flatout.exe:*:Enabled:flatout File not found
D:\Program Files\TmNationsForever\TmForever.exe:*:Enabled:TmForever File not found
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) (Microsoft Corporation)
C:\Documents and Settings\Decky\My Documents\Download\Programi\SRO_NEW_Full-Client_Downloader.exe:*:Enabled:Full-Client Downloader File not found
C:\Program Files\Ubisoft\Splinter Cell Pandora Tomorrow\pandora.exe:*:Enabled:pandora ()
C:\Program Files\Eidos\25 to Life\TTL.exe:*:Enabled:TTL File not found
D:\Program Files\UFOAI-2.2.1\ufo.exe:*:Enabled:UFO:Alien Invasion File not found
C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test (Microsoft Corporation)
C:\Program Files\Crave Entertainment\World Championship Poker 2\WCP2.exe:*:Enabled:WCP2 ()
D:\Program Files\Techland\Xpand Rally\xpandrally.exe:*:Disabled:XpandRally (Techland)
D:\Program Files\id Software\Quake 4\Quake4.exe:*:Disabled:Quake 4 File not found
D:\Program Files\Electronic Arts\Need for Speed Carbon\NFSC.exe:*:Enabled:NFSC File not found
D:\Program Files\THQ\Dawn of War\W40kWA.exe:*:Enabled:W40kWA File not found
C:\Program Files\eMule\emule.exe:*:Enabled:eMule File not found
C:\Program Files\BitLord\BitLord.exe:*:Enabled:BitLord (www.BitLord.com)
C:\Program Files\Sierra\FEARCombat\FEARServer.exe:*:Enabled:F.E.A.R. - Stand-Alone Server File not found
D:\Program Files\THQ\Dawn of War - Soulstorm\Soulstorm.exe:*:Enabled:Soulstorm (THQ Canada Inc.)
D:\Program Files\Half-Life 2\hl2 -steam -console.exe:*:Disabled:hl2 -steam -console File not found
C:\Program Files\Steam\steamapps\mposlon\half-life 2 deathmatch\hl2.exe:*:Enabled:hl2 ()
C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP3a\WNt500x86\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service File not found
D:\Program Files\UT2004\System\UT2004.exe:*:Enabled:UT2004 ()

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0297C87B-CC40-446F-865A-031B4FC0CF22}" = Race Driver 3
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0837A661-FEC3-48B3-876C-91E7D32048A9}" = Macromedia Dreamweaver 8
"{084A9731-D05B-4ADA-B4A0-0ADD25FD7152}" = Splinter Cell Pandora Tomorrow
"{0D093D4A-C6F5-4258-8E13-94F8EA6C6A4C}" = PilotDown
"{1064CABD-7390-4336-94E4-8A53DFBCB636}_is1" = GT Legends 1.0.0.0
"{10E33F6D-16E6-400E-BA1E-DF9F1BCD1B30}" = SuperUtility
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{16D2C649-CBA8-44EE-B730-12584667D487}" = Stronghold 2 Deluxe
"{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}" = QuickTime
"{1D2CF076-A63F-41A5-00A1-5924FADFAD9D}" = The Godfather™ The Game
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Multimedia Launcher
"{20533183-D42D-4261-A125-956736FBEA8C}" = Dawn of War - Soulstorm
"{2315B23D-3E21-4920-837D-AE6460934ECB}" = FIFA 09
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{252436F1-9583-4AD7-AA11-619AFFB96543}" = Xpand Rally
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{2BD5C305-1B27-4D41-B690-7A61172D2FEB}" = Macromedia Flash 8
"{300A470B-681B-449F-82AE-6D19114702CE}" = PhysX Screen Saver
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{34B9B494-EF4A-4592-87A8-BE40D0442E86}" = Dawn of War - Soulstorm
"{35CB6715-41F8-4F99-8881-6FC75BF054B0}" = Oblivion
"{4781569D-5404-1F26-4B2B-6DF444441031}" = Nero 7 Premium
"{47836B39-2465-4F39-9D7E-52F70A1C3D72}" = Axis & Allies
"{478DCE85-E854-4E55-9B6A-D285F9CABAFF}" = Windows Live installer
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{4B9535BF-CC90-4158-AF32-CAF57A8820CA}" = Macromedia Contribute 3.11
"{4C24A8C1-7CFA-4650-AF15-732F5BD7B46D}" = Macromedia Fireworks 8
"{4E074808-1B86-4230-A9EB-0904942EC4AE}" = LEGO Star Wars II
"{544DB849-AB59-4C12-A333-2F214E24870F}" = Commandos Strike Force
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{58AC967F-CE64-4065-AF54-FA66BAF31FE8}" = BOILING POINT
"{63D64340-C694-48C4-893F-481AD9A1ACCE}" = Windows Live Writer
"{657201DD-30C8-4E50-88AD-164B3812E8F5}" = Framebuffer Crysis WARHEAD Benchmark Tool
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PartitionMagic
"{6E65247F-58F9-41CA-BE69-0316F7907170}" = Disc2Phone
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7353BAE6-5E49-46C4-A9B5-8A269A313789}" = Crysis WARHEAD®
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"{7CCEBC24-62DB-4280-A8EC-BFA49F167920}" = Software Update for Web Folders
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{83ED1E80-A1B7-4256-BCF1-AC4A88151A6B}" = Microsoft MapPoint Europe 2006
"{844A01D6-3B94-4CAC-BAF8-22ECF081C14F}" = Windows Live Mail
"{851367C1-2F9F-4087-B3E8-8DECFE328370}" = The Da Vinci Code
"{8795CBED-55E2-4693-9F14-84EC446935BE}" = SpeechRedist
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}" = Macromedia Flash 8 Video Encoder
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{9011041A-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{939740B5-0064-4779-854A-8C1086181C05}" = Macromedia FreeHand MXa
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{97C0EA4A-1A0B-4C53-ACEB-49984DA79C90}" = Google Earth
"{97DDA53A-8346-467A-880C-655E847CC7D3}" = Ski Racing 2006
"{993A94A9-DCE3-4774-B35D-D8C74FC1E0BE}" = Royale Remixed Theme
"{9C27ADE1-EAFB-4BB7-9FE3-5DD9BA9A3DD2}" = Crashday
"{9DF0196F-B6B8-4C3A-8790-DE42AA530101}" = SPORE™
"{9E491AB7-4589-48CA-9CBB-874CB2788391}" = Studio 9
"{A267A14C-6FDA-41A1-8B22-50A5D1E4444E}" = Mathematica 5
"{A7651FB4-AC2E-4020-90E2-B71C8C379F48}" = Macromedia Captivate
"{ABB2901A-3D0A-4F21-8324-2F13C3EFE163}" = LightScribe 1.4.62.1
"{AC76BA86-7AD7-1033-7B44-A70700000002}" = Adobe Reader 7.0.7
"{B2E01847-F5DF-4BD9-B20F-260A794EF934}" = Windows Live Galerija fotografija
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B97CF5C3-0487-11D8-A36E-0050BAE317E1}" = DVD Solution
"{BABAEBE4-9FFB-4B5D-9453-64FF11517CA2}" = Tom Clancy's Splinter Cell Chaos Theory
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BCA02FAD-2C86-4C8C-A815-51C09F4E51FF}" = Dual-Core Optimizer
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C098DAEC-29EF-4A59-B18E-0E950169CA3C}" = Western Australian Time Zone Update
"{C37A0BC1-52EE-4F97-8223-5CA9FC0357B0}" = Test Drive Unlimited
"{C550F6FC-6C3C-4CB4-BC13-3960B17959DD}" = Windows Live Messenger
"{C5ADA65A-7828-4D85-B071-ECC52B51F794}" = Sony Ericsson PC Suite 1.20.173
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC419DDC-E0F0-4013-B25A-6FA036516F0D}" = Need for Speed™ ProStreet
"{CC67770B-581D-4E96-B72A-A7907CE18725}" = Colin McRae Rally 2005
"{DD1865F0-AD73-40FB-B23E-1822E02396FF}" = NVIDIA PhysX
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E1BBBAC5-2857-4155-82A6-54492CE88620}" = Opera 9.64
"{E4628D0D-5DC8-49EC-985A-F0C12EDBF1D2}" = Agatha Christie - And Then There Were None
"{E6D22FE1-AB5F-42CA-9480-6F70B96DDD88}" = Need for Speed™ Undercover
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{E9F81423-211E-46B6-9AE0-38568BC5CF6F}" =
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FA075505-EFF6-4006-8E9F-921E09774684}" = Big Mutha Truckers 2
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FBF91C7D-988A-432A-91C3-5081787C85C1}" = World Championship Poker 2
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FF39FC01-819B-42E4-AE49-1968AF12DDD4}" = Dawn of War - Dark Crusade
"7-Zip" = 7-Zip 4.57
"AC3Filter" = AC3Filter (remove only)
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Analyze for Speed" = Analyze for Speed 1.0
"Audacity_is1" = Audacity 1.2.6
"avast!" = avast! Antivirus
"BitLord" = BitLord 1.1
"BSPlayer1" = BSPlayer
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"CD Recovery Toolbox Free_is1" = CD Recovery Toolbox Free 1.1
"Crysis WARHEAD®" = Crysis WARHEAD®
"CSCLIB" = Canon Camera Support Core Library
"EOS Utility" = Canon Utilities EOS Utility
"ERUNT_is1" = ERUNT 1.1j
"F1 Screensaver 2006" = F1 Screensaver 2006
"F1PerfView" = F1PerfView 1.24
"ferrari_marzo2008.scr" = ferrari_marzo2008 ScreenSaver
"ffdshow_is1" = ffdshow [rev 1228] [2007-06-03]
"FLV Player2.0 " = FLV Player
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"Free Pascal_is1" = Free Pascal 2.0.4
"FrostWire" = FrostWire 4.17.2
"Gear Ratio Calculator" = Gear Ratio Calculator 2.5.2
"GSplit21Set" = GSplit 2.1
"HijackThis" = HijackThis 2.0.2
"Hollywood FX 5" = Pinnacle Hollywood FX 5
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Infinite Patience v2.2_is1" = Infinite Patience v2.2
"InSim RaceAnalyzer" = InSim RaceAnalyzer 0.1.1.11
"InstallShield_{252436F1-9583-4AD7-AA11-619AFFB96543}" = Xpand Rally
"InstallShield_{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty® 4 - Modern Warfare™ 1.4 Patch
"InstallShield_{4E074808-1B86-4230-A9EB-0904942EC4AE}" = LEGO Star Wars II
"InstallShield_{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PowerQuest PartitionMagic 8.0
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"InstallShield_{A267A14C-6FDA-41A1-8B22-50A5D1E4444E}" = Mathematica 5
"IsoBuster_is1" = IsoBuster 1.9.1
"KIMI RÄIKKÖNEN Screen Saver" = KIMI RÄIKKÖNEN Screen Saver
"LFS GhostcarMod" = LFS GhostcarMod 1.01
"LFS PitSpotter" = LFS PitSpotter 1.1b
"LFS SmokeMod" = LFS SmokeMod 1.1
"LingvoSoft Talking Dictionary 2007 English<->Croatian for Windows" = LingvoSoft Talking Dictionary 2007 English<->Croatian for Windows
"LingvoSoft Talking Dictionary 2007 English<->French for Windows" = LingvoSoft Talking Dictionary 2007 English<->French for Windows
"LingvoSoft Talking Dictionary 2007 English<->German for Windows" = LingvoSoft Talking Dictionary 2007 English<->German for Windows
"LingvoSoft Talking Dictionary 2007 English<->Italian for Windows" = LingvoSoft Talking Dictionary 2007 English<->Italian for Windows
"LingvoSoft Talking Dictionary 2007 English<->Latin for Windows" = LingvoSoft Talking Dictionary 2007 English<->Latin for Windows
"LingvoSoft Talking Dictionary 2007 English<->Spanish for Windows" = LingvoSoft Talking Dictionary 2007 English<->Spanish for Windows
"Live for Speed S2" = Live for Speed S2 0.5Q
"Live for Speed S2 Car Skin" = Live for Speed S2 Car Skin
"Live for Speed S2 Dedicated Host" = Live for Speed S2 Dedicated Host 0.5Q
"Live for Speed S2 HiRes Sky Textures" = Live for Speed S2 HiRes Sky Textures
"Live for Speed S2 Music Tracks" = Live for Speed S2 Music Tracks
"Magic DVD Ripper_is1" = Magic DVD Ripper V3.2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MatlabDeinstKey" = MATLAB 10-22-2006
"Messenger Plus! Live" = Messenger Plus! Live & Sponsor (CiD)
"MessengerDiscovery Live_is1" = MessengerDiscovery Live 1.4.5408
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox (3.0.11)" = Mozilla Firefox (3.0.11)
"MPE" = MyPhoneExplorer
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PhotoStitch" = Canon Utilities PhotoStitch
"PowerISO" = PowerISO
"PunkBusterSvc" = PunkBuster Services
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 6.0" = RealPlayer
"Registry Repair_is1" = Registry Repair 2.4
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"RivaTuner" = RivaTuner v2.24
"Sketchpad" = Sketchpad
"Smart Defrag_is1" = Smart Defrag 1.11
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.5.2.20
"SubtitleWorkshop" = Subtitle Workshop 2.51
"SUPER ©" = SUPER © Version 2008.bld.30 (Mar 22, 2008)
"SystemRequirementsLab" = System Requirements Lab
"UT2004" = Unreal Tournament 2004
"VLC media player" = VideoLAN VLC media player 0.8.6d
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows Script" = Microsoft Windows Script 5.7
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent DNA" = DNA

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 31.3.2009 14:59:11 | Computer Name = DECKY-E93819898 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\windows\system32\uxtheme.dll failed, 00000005.

Error - 18.4.2009 13:07:16 | Computer Name = DECKY-E93819898 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\windows\system32\UxTheme.dll failed, 00000005.

Error - 26.5.2009 15:29:59 | Computer Name = DECKY-E93819898 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\windows\system32\uxtheme.dll failed, 00000005.

Error - 28.5.2009 9:24:51 | Computer Name = DECKY-E93819898 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\windows\system32\uxtheme.dll failed, 00000005.

Error - 31.5.2009 4:25:27 | Computer Name = DECKY-E93819898 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\windows\system32\uxtheme.dll failed, 00000005.

Error - 1.6.2009 2:42:51 | Computer Name = DECKY-E93819898 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\windows\system32\uxtheme.dll failed, 00000005.

Error - 3.6.2009 9:07:56 | Computer Name = DECKY-E93819898 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\windows\system32\uxtheme.dll failed, 00000005.

Error - 7.6.2009 13:44:57 | Computer Name = DECKY-E93819898 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\WINDOWS\SYSTEM32\UXTHEME.DLL failed, 00000005.

Error - 10.6.2009 9:59:32 | Computer Name = DECKY-E93819898 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\windows\system32\UxTheme.dll failed, 00000005.

Error - 10.6.2009 11:16:45 | Computer Name = DECKY-E93819898 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://s52.hotfile.c...en_june.iso.001
failed, 00000084.

[ Application Events ]
Error - 4.4.2009 3:04:44 | Computer Name = DECKY-E93819898 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This operation returned because the timeout period expired.

[ System Events ]
Error - 14.6.2009 13:38:37 | Computer Name = DECKY-E93819898 | Source = Service Control Manager | ID = 7001
Description = The DHCP Client service depends on the NetBios over Tcpip service
which failed to start because of the following error: %%31

Error - 14.6.2009 13:38:37 | Computer Name = DECKY-E93819898 | Source = Service Control Manager | ID = 7001
Description = The DNS Client service depends on the TCP/IP Protocol Driver service
which failed to start because of the following error: %%31

Error - 14.6.2009 13:38:37 | Computer Name = DECKY-E93819898 | Source = Service Control Manager | ID = 7001
Description = The TCP/IP NetBIOS Helper service depends on the AFD service which
failed to start because of the following error: %%31

Error - 14.6.2009 13:38:37 | Computer Name = DECKY-E93819898 | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 14.6.2009 13:38:37 | Computer Name = DECKY-E93819898 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Aavmker4 AFD aswSP aswTdi Fips IPSec MRxSmb NetBIOS NetBT Processor prodrv06 RasAcd Rdbss SCDEmu
Tcpip

Error - 14.6.2009 13:38:48 | Computer Name = DECKY-E93819898 | Source = sfsync03 | ID = 262145
Description =

Error - 14.6.2009 13:39:03 | Computer Name = DECKY-E93819898 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 14.6.2009 13:39:09 | Computer Name = DECKY-E93819898 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 14.6.2009 13:39:31 | Computer Name = DECKY-E93819898 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 14.6.2009 13:45:40 | Computer Name = DECKY-E93819898 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}


< End of report >

Many thanks in advance, I'll be very grateful if you can help me!
  • 0

Advertisements


#2
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Hi MPoslon,

Welcome to Geeks to Go! My name is SpySentinel and I will be helping you fix your computer problem.
Sorry for the delay, we have been very busy lately, and I apologize for your wait.



Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2

Posted Image


Posted Image
--------------------------------------------------------------------

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a HijackThis log so we can continue cleaning the system.

  • 0

#3
MPoslon

MPoslon

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
No need to apologize, I didn't wait too long, after all, you have been helping other people :)
It seems the problem is solved, I can now run task manager! :) Thank you so much! :)
Here is combofix.txt:
ComboFix 09-06-17.04 - Decky 18.06.2009 13:49.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.385.1033.18.2047.1485 [GMT 2:00]
Running from: c:\documents and settings\Decky\Desktop\Combo-Fix.exe
AV: avast! antivirus 4.8.1335 [VPS 090617-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Decky\RavMonLog

.
((((((((((((((((((((((((( Files Created from 2009-05-18 to 2009-06-18 )))))))))))))))))))))))))))))))
.

2009-06-14 17:58 . 2009-06-14 17:58 -------- d-----w- C:\Rooter$
2009-06-14 17:43 . 2009-06-14 17:43 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-06-04 20:17 . 2009-06-04 20:09 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-04 20:09 . 2009-06-04 20:08 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-04 20:09 . 2009-06-04 20:09 314200 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-06-04 20:09 . 2009-06-04 20:09 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-06-04 20:09 . 2009-06-04 20:09 169312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-06-04 20:09 . 2009-06-04 20:09 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-06-04 20:09 . 2009-06-04 20:09 348496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-06-04 20:09 . 2009-06-04 20:09 294240 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-06-04 20:08 . 2009-06-04 20:08 83808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-06-04 20:08 . 2009-06-04 20:08 1630048 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-06-04 20:08 . 2009-06-04 20:08 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-06-04 20:08 . 2009-06-04 20:08 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-06-04 20:08 . 2009-06-04 20:08 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-06-04 20:08 . 2009-06-04 20:08 640360 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-06-04 20:08 . 2009-06-04 20:08 540536 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-06-04 20:08 . 2009-06-04 20:08 559464 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-06-04 20:08 . 2009-06-04 20:08 2352456 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-06-04 20:08 . 2009-06-04 20:08 627536 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-06-04 20:08 . 2009-06-04 20:08 518488 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-06-04 20:08 . 2009-06-04 20:08 1005904 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-06-04 20:02 . 2009-06-04 20:02 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-04 20:02 . 2009-03-12 08:17 2902048 -c--a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-04 18:49 . 2009-06-04 18:49 -------- d-----w- c:\documents and settings\Decky\Application Data\Malwarebytes
2009-06-04 18:49 . 2009-05-26 11:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-04 18:49 . 2009-06-04 18:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-04 18:49 . 2009-06-04 18:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-04 18:49 . 2009-05-26 11:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-04 18:46 . 2009-06-04 18:46 -------- d-----w- c:\program files\ERUNT
2009-06-04 17:57 . 2009-06-04 17:57 -------- d-----w- c:\program files\Trend Micro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-18 10:21 . 2009-03-21 08:40 -------- d-----w- c:\program files\Steam
2009-06-10 18:05 . 2007-04-11 21:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Test Drive Unlimited
2009-06-07 10:00 . 2006-07-11 08:09 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-04 20:11 . 2008-01-11 13:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-04 20:02 . 2006-09-19 21:17 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-04 19:40 . 2008-01-11 13:18 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-05-29 13:50 . 2008-02-02 19:28 -------- d-----w- c:\documents and settings\Decky\Application Data\FrostWire
2009-05-15 17:11 . 2009-05-15 17:11 2311 ----a-w- c:\documents and settings\All Users\Application Data\xml92.tmp
2009-05-15 17:11 . 2009-05-15 17:11 13257 ----a-w- c:\documents and settings\All Users\Application Data\xml91.tmp
2009-05-15 17:11 . 2009-05-15 17:11 7890 ----a-w- c:\documents and settings\All Users\Application Data\xml90.tmp
2009-05-07 15:32 . 2004-08-04 07:56 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-06 12:23 . 2009-05-07 18:59 372736 ----a-w- c:\documents and settings\Decky\Application Data\Mozilla\Firefox\Profiles\be0vk58y.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
2009-05-03 10:28 . 2009-05-03 10:28 10134 ----a-r- c:\documents and settings\Decky\Application Data\Microsoft\Installer\{657201DD-30C8-4E50-88AD-164B3812E8F5}\_D578AC58F14BD73AA16534.exe
2009-05-03 10:28 . 2009-05-03 10:28 10134 ----a-r- c:\documents and settings\Decky\Application Data\Microsoft\Installer\{657201DD-30C8-4E50-88AD-164B3812E8F5}\_1BC1E915D9D4E09E0D35C7.exe
2009-05-03 10:28 . 2009-05-03 10:28 10134 ----a-r- c:\documents and settings\Decky\Application Data\Microsoft\Installer\{657201DD-30C8-4E50-88AD-164B3812E8F5}\_11054A45FAD4581FFD16AF.exe
2009-05-01 11:06 . 2009-05-01 11:06 -------- d-----w- c:\program files\The Game Creators
2009-05-01 11:06 . 2009-05-01 11:05 -------- d-----w- c:\documents and settings\Decky\Application Data\Download Manager
2009-05-01 09:22 . 2006-07-29 06:31 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-05-01 09:21 . 2009-05-01 09:21 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{0691F710-1ECA-4B5A-9727-25554F1BFDC6}
2009-05-01 09:11 . 2009-05-01 09:11 8586 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2009-05-01 09:09 . 2006-07-29 06:44 -------- d-----w- c:\program files\Electronic Arts
2009-04-29 06:28 . 2009-04-29 06:28 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
2009-04-29 04:56 . 2004-08-04 07:56 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-28 20:33 . 2008-02-12 18:34 -------- d-----w- c:\program files\AGEIA Technologies
2009-04-17 12:26 . 2004-08-04 06:17 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-04 07:56 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-09 10:26 . 2009-04-09 10:26 152576 ----a-w- c:\documents and settings\Decky\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-05 17:37 . 2006-07-11 10:25 68224 ----a-w- c:\documents and settings\Decky\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-27 06:14 . 2009-02-14 14:01 453152 ----a-w- c:\windows\system32\NVUNINST.EXE
2004-10-01 13:00 . 2006-07-11 08:40 40960 ----a-w- c:\program files\Uninstall_CDS.exe
2006-05-03 09:06 . 2007-11-30 14:44 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2007-11-30 14:44 31232 --sh--r- c:\windows\system32\msfDX.dll
2007-12-17 12:43 . 2008-04-09 07:33 27648 --sh--w- c:\windows\system32\Smab0.dll
.

------- Sigcheck -------

[-] 2008-04-14 03:42 1423872 DC7C3534CF32C669705016AAE6D8A334 c:\windows\explorer.exe
[-] 2007-06-13 11:26 1033216 7712DF0CDDE3A5AC89843E61CD5B3658 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2007-06-13 10:23 1423360 E4368D08C22012B357BEF3BA239AC667 c:\windows\$NtServicePackUninstall$\explorer.exe
[7] 2004-08-04 07:56 1032192 A0732187050030AE399B241436565E64 c:\windows\$NtUninstallKB938828$\explorer.exe
[7] 2008-04-14 03:42 1033728 12896823FB95BFB3DC9B46BCAEDC9923 c:\windows\ServicePackFiles\i386\explorer.exe
[7] 2008-04-14 03:42 1033728 12896823FB95BFB3DC9B46BCAEDC9923 c:\windows\system32\VITrans\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-03 94208]
"BugCD Pretrazivac"="c:\program files\BugCD Pretrazivac\BugCD Pretrazivac.exe" [2002-08-12 49152]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Steam"="c:\program files\Steam\Steam.exe" [2009-06-10 1217784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 77824]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-28 413696]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2003-12-04 406016]
"SmartDefrag"="c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" [2009-02-13 1986896]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"RivaTunerStartupDaemon"="c:\program files\RivaTuner v2.24\RivaTuner.exe" [2009-02-25 2781184]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-04 518488]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-27 1657376]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2005-05-17 77824]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]

c:\documents and settings\Decky\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\drwtsn32.exe]
"Debugger"=c:\windows\system32\wscript.exe /E:vbs c:\windows\system32\winjpg.jpg

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dwwinxp.exe]
"Debugger"=c:\windows\system32\winxp.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0autocheck lsdelete\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Atari\\BOILING POINT\\Xenus.exe"=
"d:\\Program Files\\Live for Speed S2\\LFSspotter.exe"=
"d:\\Program Files\\Live for Speed S2\\LFS.exe"=
"d:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"d:\\Program Files\\Atari\\Test Drive Unlimited\\TestDriveUnlimited.exe"=
"d:\\Program Files\\Firefly Studios\\Stronghold 2\\Stronghold2.exe"=
"c:\\Program Files\\Opera\\Opera.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.321\\English\\setup.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Ubisoft\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Crave Entertainment\\World Championship Poker 2\\WCP2.exe"=
"d:\\Program Files\\Techland\\Xpand Rally\\xpandrally.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"d:\\Program Files\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe"=
"c:\\Program Files\\Steam\\steamapps\\mposlon\\half-life 2 deathmatch\\hl2.exe"=
"d:\\Program Files\\UT2004\\System\\UT2004.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15155:TCP"= 15155:TCP:NortonAV
"16556:TCP"= 16556:TCP:NortonAV
"17096:TCP"= 17096:TCP:NortonAV
"17464:TCP"= 17464:TCP:NortonAV
"13299:TCP"= 13299:TCP:NortonAV
"12569:TCP"= 12569:TCP:NortonAV
"15798:TCP"= 15798:TCP:NortonAV
"17026:TCP"= 17026:TCP:NortonAV
"13516:TCP"= 13516:TCP:NortonAV
"13575:TCP"= 13575:TCP:NortonAV
"18893:TCP"= 18893:TCP:NortonAV
"18350:TCP"= 18350:TCP:NortonAV
"16026:TCP"= 16026:TCP:NortonAV
"18699:TCP"= 18699:TCP:NortonAV
"18167:TCP"= 18167:TCP:NortonAV
"17674:TCP"= 17674:TCP:NortonAV
"18146:TCP"= 18146:TCP:NortonAV
"12715:TCP"= 12715:TCP:NortonAV

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [4.6.2009 22:09 64160]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [6.12.2005 17:11 35328]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2.4.2008 21:05 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2.4.2008 21:05 20560]
R2 athsgt;athsgt;c:\windows\system32\drivers\athsgt.sys [27.7.2006 18:21 164992]
R2 limsgt;limsgt;c:\windows\system32\drivers\limsgt.sys [27.7.2006 18:21 12544]
R3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;c:\program files\Windows Live\Messenger\usnsvc.exe [18.10.2007 12:31 98328]
S3 FXDRV;FXDRV;\??\e:\fxdrv.sys --> e:\Fxdrv.sys [?]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);c:\windows\system32\drivers\k510bus.sys [8.1.2007 11:27 58288]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;c:\windows\system32\drivers\k510mdfl.sys [8.1.2007 11:27 8336]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;c:\windows\system32\drivers\k510mdm.sys [8.1.2007 11:27 94064]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\k510mgmt.sys [8.1.2007 11:27 85408]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;c:\windows\system32\drivers\k510obex.sys [8.1.2007 11:27 83344]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9.3.2009 21:06 1005904]
.
Contents of the 'Scheduled Tasks' folder

2009-06-15 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 20:08]

2009-06-14 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-01-17 17:15]

2009-06-18 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-07 20:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.hr/
uInternet Connection Wizard,ShellNext = iexplore
IE: eng-scr - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Croatian) for Windows\Plugins\IE.htm
IE: English<->French - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-French) for Windows\Plugins\IE.htm
IE: English<->German - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-German) for Windows\Plugins\IE.htm
IE: English<->Italian - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Italian) for Windows\Plugins\IE.htm
IE: English<->Latin - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Latin) for Windows\Plugins\IE.htm
IE: English<->Spanish - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Spanish) for Windows\Plugins\IE.htm
IE: I&zvoz u Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{2DDEE708-A225-6449-889B-1941E2FBAB6D} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-German) for Windows\Plugins\IE.htm
IE: {{4629E725-138D-0F4C-B01A-09EBD3D67834} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Latin) for Windows\Plugins\IE.htm
IE: {{73AD0419-12E3-E74C-B893-EA4EF48F451F} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Italian) for Windows\Plugins\IE.htm
IE: {{9771B718-0C1C-3248-A000-C378A44BF07B} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-French) for Windows\Plugins\IE.htm
IE: {{A9919568-CF8E-C140-84DC-0FF917685E69} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Spanish) for Windows\Plugins\IE.htm
IE: {{B05D861D-C01F-7C4C-A7FF-A8003A8FE77C} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Croatian) for Windows\Plugins\IE.htm
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-18 13:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1085031214-492894223-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,63,1b,9e,89,00,
bf,5b,73,c8,28,51,af,b0,29,a3,98,30,a9,fd,c2,d5,be,73,f8,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,15,64,5d,be,a9,
24,c6,5e,71,3b,04,66,8b,46,0d,96,72,a8,60,a4,23,5e,97,e0,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,31,5f,d2,35,70,
96,44,4a,25,da,ec,7e,55,20,c9,26,48,ba,30,33,53,d5,a4,a2,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,f7,b0,04,1e,ae,
35,08,0f,3e,1e,9e,e0,57,5a,93,61,61,c9,6d,a4,d9,e6,f9,6a,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,b6,aa,22,00,8a,
b1,5c,d0,cd,44,cd,b9,a6,33,6c,cd,45,a8,36,94,91,08,12,74,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,82,16,0c,80,96,
eb,a8,30,b0,18,ed,a7,3f,8d,37,a4,21,3f,38,48,28,08,72,9c,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,60,95,bd,7f,e9,
84,8f,a1,31,77,e1,ba,b1,f8,68,02,2d,a7,6a,8e,fa,df,1d,03,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,9b,9a,64,a6,02,
c4,98,35,83,6c,56,8b,a0,85,96,ab,9f,d1,20,47,89,83,6f,e6,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,0e,8b,22,d2,0a,
1d,84,9f,51,fa,6e,91,28,9e,14,cc,c5,3b,b3,54,0a,58,b6,e7,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,e8,34,73,8a,76,
e7,48,a9,b1,cd,45,5a,a8,c4,f8,b9,3b,a7,d2,53,6d,d5,39,02,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,d3,ab,e0,b7,97,
82,fe,98,e3,0e,66,d5,eb,bc,2f,6b,85,52,ce,c6,84,43,50,8b,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,fa,e3,de,b8,1c,
1e,61,cb,fa,ea,66,7f,d4,3b,6b,70,db,b1,d5,59,65,26,88,f8,6c,43,2d,1e,aa,22,\

[HKEY_LOCAL_MACHINE\System\MountedDevices]
@Denied: (Read) (Administrators)
"\\DosDevices\\C:"=hex:21,04,21,04,00,7e,00,00,00,00,00,00
"\\??\\Volume{da4bcfda-5b8a-11d9-ba0e-806d6172696f}"=hex:5c,00,3f,00,3f,00,5c,
00,46,00,44,00,43,00,23,00,47,00,45,00,4e,00,45,00,52,00,49,00,43,00,5f,00,\
"\\??\\Volume{da4bcfdb-5b8a-11d9-ba0e-806d6172696f}"=hex:5c,00,3f,00,3f,00,5c,
00,49,00,44,00,45,00,23,00,43,00,64,00,52,00,6f,00,6d,00,48,00,4c,00,2d,00,\
"\\DosDevices\\A:"=hex:5c,00,3f,00,3f,00,5c,00,46,00,44,00,43,00,23,00,47,00,
45,00,4e,00,45,00,52,00,49,00,43,00,5f,00,46,00,4c,00,4f,00,50,00,50,00,59,\
"\\??\\Volume{da4bcfdd-5b8a-11d9-ba0e-806d6172696f}"=hex:21,04,21,04,00,7e,00,
00,00,00,00,00
"\\??\\Volume{2dab15ca-10b4-11db-b103-806d6172696f}"=hex:5c,00,3f,00,3f,00,5c,
00,49,00,44,00,45,00,23,00,43,00,64,00,52,00,6f,00,6d,00,48,00,4c,00,2d,00,\
"\\??\\Volume{a5f4bb56-11b5-11db-b10a-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\??\\Volume{cfc954ee-1298-11db-b10e-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\F:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,53,00,43,00,53,\
"\\??\\Volume{24904c40-12a2-11db-bdc5-806d6172696f}"=hex:21,04,21,04,00,f0,de,
8c,22,00,00,00
"\\DosDevices\\G:"=hex:44,4d,49,4f,3a,49,44,3a,28,e8,52,b7,71,28,a5,4a,ae,32,
b4,c2,ea,e5,96,0f
"\\DosDevices\\D:"=hex:21,04,21,04,00,f0,de,8c,22,00,00,00
"\\DosDevices\\E:"=hex:5c,00,3f,00,3f,00,5c,00,49,00,44,00,45,00,23,00,43,00,
64,00,52,00,6f,00,6d,00,48,00,4c,00,2d,00,44,00,54,00,2d,00,53,00,54,00,5f,\
"\\??\\Volume{70beaf14-1e42-11db-bdeb-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\H:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,54,00,4f,00,52,00,41,00,
47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,76,00,61,00,62,00,6c,00,65,00,4d,\
"\\??\\Volume{69d1bce4-1eeb-11db-9617-806d6172696f}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\I:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,54,00,4f,00,52,00,41,00,
47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,76,00,61,00,62,00,6c,00,65,00,4d,\
"\\??\\Volume{d0fbd5fd-2d1b-11db-9633-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\J:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,47,00,65,00,6e,\
"\\??\\Volume{229bd68e-2d1e-11db-9634-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\K:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,47,00,65,00,6e,\
"\\??\\Volume{229bd68f-2d1e-11db-9634-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\L:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,47,00,65,00,6e,\
"\\??\\Volume{707402be-780a-11db-9743-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\DosDevices\\M:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,53,00,43,00,53,\
"\\??\\Volume{9cf8fbf4-7d83-11db-975a-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{f50d8190-7e53-11db-9761-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{ffdf0afa-7e56-11db-9762-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{ffdf0afb-7e56-11db-9762-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{dc6fa383-8f9f-11db-97a1-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\??\\Volume{dc6fa386-8f9f-11db-97a1-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\N:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,53,00,43,00,53,\
"\\??\\Volume{7cb172c4-978c-11db-97c4-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\O:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,53,00,43,00,53,\
"\\??\\Volume{cc6329a9-9efa-11db-97dd-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\DosDevices\\P:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,54,00,4f,00,52,00,41,00,
47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,76,00,61,00,62,00,6c,00,65,00,4d,\
"\\??\\Volume{9617b388-dafb-11db-988c-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\??\\Volume{df235132-dc92-11db-9898-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{00f2196c-e745-11db-98b9-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{9484c51a-f4c1-11db-98e7-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{a1a75f18-faf5-11db-98fc-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{87549574-41a0-11dc-99e4-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{9f4e1236-8c73-11dc-9a9f-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{a5621da2-a9b0-11dc-9af4-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{10a3ee57-bb01-11dc-9b43-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{5a37773e-c6ac-11dc-9b71-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{6fbc0310-d288-11dc-abeb-806d6172696f}"=hex:a6,06,ef,19,00,7e,00,
00,00,00,00,00
"\\??\\Volume{5e4e5d9e-0889-11dd-acd4-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{7d41f5af-4109-11dd-ad95-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{929aaf67-43ab-11dd-ad9f-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{10b141ce-6af8-11dd-ae17-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{5a8143c3-6d38-11dd-ae1f-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{0738d30c-8a40-11dd-ae66-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{44bcd168-faa9-11dd-afa2-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{d25c7a00-1bb5-11de-b074-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{7e2a2a22-38de-11de-b0fc-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(792)
c:\windows\system32\cscui.dll
.
Completion time: 2009-06-18 13:57
ComboFix-quarantined-files.txt 2009-06-18 11:57

Pre-Run: 40.795.947.008 bytes free
Post-Run: 40.870.125.568 bytes free

423 --- E O F --- 2009-06-12 07:38

and hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:00:14, on 18.6.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\BugCD Pretrazivac\BugCD Pretrazivac.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\windows\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\windows\system32\svchost.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\windows\system32\wscntfy.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\windows\system32\notepad.exe
C:\windows\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.hr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\windows\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.24\RivaTuner.exe" /S
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BugCD Pretrazivac] C:\Program Files\BugCD Pretrazivac\BugCD Pretrazivac.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: eng-scr - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Croatian) for Windows\Plugins\IE.htm
O8 - Extra context menu item: English<->French - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-French) for Windows\Plugins\IE.htm
O8 - Extra context menu item: English<->German - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-German) for Windows\Plugins\IE.htm
O8 - Extra context menu item: English<->Italian - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Italian) for Windows\Plugins\IE.htm
O8 - Extra context menu item: English<->Latin - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Latin) for Windows\Plugins\IE.htm
O8 - Extra context menu item: English<->Spanish - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Spanish) for Windows\Plugins\IE.htm
O8 - Extra context menu item: I&zvoz u Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Stavi na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Stavi na blog u Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: English<->German - {2DDEE708-A225-6449-889B-1941E2FBAB6D} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-German) for Windows\Plugins\IE.htm
O9 - Extra 'Tools' menuitem: English<->German - {2DDEE708-A225-6449-889B-1941E2FBAB6D} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-German) for Windows\Plugins\IE.htm
O9 - Extra button: English<->Latin - {4629E725-138D-0F4C-B01A-09EBD3D67834} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Latin) for Windows\Plugins\IE.htm
O9 - Extra 'Tools' menuitem: English<->Latin - {4629E725-138D-0F4C-B01A-09EBD3D67834} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Latin) for Windows\Plugins\IE.htm
O9 - Extra button: English<->Italian - {73AD0419-12E3-E74C-B893-EA4EF48F451F} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Italian) for Windows\Plugins\IE.htm
O9 - Extra 'Tools' menuitem: English<->Italian - {73AD0419-12E3-E74C-B893-EA4EF48F451F} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Italian) for Windows\Plugins\IE.htm
O9 - Extra button: Istraživanje - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: English<->French - {9771B718-0C1C-3248-A000-C378A44BF07B} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-French) for Windows\Plugins\IE.htm
O9 - Extra 'Tools' menuitem: English<->French - {9771B718-0C1C-3248-A000-C378A44BF07B} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-French) for Windows\Plugins\IE.htm
O9 - Extra button: English<->Spanish - {A9919568-CF8E-C140-84DC-0FF917685E69} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Spanish) for Windows\Plugins\IE.htm
O9 - Extra 'Tools' menuitem: English<->Spanish - {A9919568-CF8E-C140-84DC-0FF917685E69} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Spanish) for Windows\Plugins\IE.htm
O9 - Extra button: English<->Croatian - {B05D861D-C01F-7C4C-A7FF-A8003A8FE77C} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Croatian) for Windows\Plugins\IE.htm
O9 - Extra 'Tools' menuitem: eng-scr - {B05D861D-C01F-7C4C-A7FF-A8003A8FE77C} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Croatian) for Windows\Plugins\IE.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.co.../sysreqlab3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1200047154156
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

--
End of file - 12482 bytes

Edited by MPoslon, 18 June 2009 - 06:12 AM.

  • 0

#4
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Hi MPoslon,

Glad to hear Task Manager works again!


Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    o Click Preferences, then click the Statistics/Logs tab.
    o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    o Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.



Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.

  • 0

#5
MPoslon

MPoslon

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Hi,

Sorry for the delay :)
Strange, SUPERAntispyware and Kaspersky didn't find anything :)

SUPERAntispyware log:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 06/23/2009 at 05:55 PM

Application Version : 4.26.1004

Core Rules Database Version : 3947
Trace Rules Database Version: 1889

Scan type : Complete Scan
Total Scan Time : 02:22:35

Memory items scanned : 517
Memory threats detected : 0
Registry items scanned : 7023
Registry threats detected : 0
File items scanned : 221982
File threats detected : 0

Kaspersky report:
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Tuesday, June 23, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Tuesday, June 23, 2009 17:19:06
Records in database: 2383998
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\

Scan statistics:
Files scanned: 227332
Threat name: 0
Infected objects: 0
Suspicious objects: 0
Duration of the scan: 02:59:08

No malware has been detected. The scan area is clean.

The selected area was scanned.
  • 0

#6
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Hi MPoslon,

That seems like good news, lets take a deeper look to make sure nothing is hiding


Step #1

Download RootRepeal.zip and unzip it to your Desktop.
  • Double click RootRepeal.exe to start the program
  • Click on the Report tab at the bottom of the program window
  • Click the Scan button
  • In the Select Scan dialog, check:
    • Drivers
    • Files
    • Processes
    • SSDT
    • Stealth Objects
    • Hidden Services
  • Click the OK button
  • In the next dialog, select all drives showing
  • Click OK to start the scan

    Note: The scan can take some time. DO NOT run any other programs while the scan is running

  • When the scan is complete, the Save Report button will become available
  • Click this and save the report to your Desktop as RootRepeal.txt
  • Go to File, then Exit to close the program
If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on Posted Image to insert the attachment into your post



Step #2

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)

  • 0

#7
MPoslon

MPoslon

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Attached File  RootRepeal.txt   107.08KB   183 downloads

Hi,

here are all the reports.
By the way, I got a message from RootRepeal that it can't scan drive G. :)
rsit log.txt:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Decky at 2009-06-24 12:06:11
Microsoft Windows XP Professional Service Pack 3
System drive C: has 39 GB (28%) free of 142 GB
Total RAM: 2047 MB (75% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:06:19, on 24.6.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\windows\Explorer.EXE
C:\windows\system32\spoolsv.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\windows\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\windows\system32\nvsvc32.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\windows\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\windows\system32\wuauclt.exe
C:\windows\system32\wscntfy.exe
C:\Documents and Settings\Decky\Desktop\RootRepeal.exe
C:\Documents and Settings\Decky\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Decky.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.hr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\windows\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.24\RivaTuner.exe" /S
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BugCD Pretrazivac] C:\Program Files\BugCD Pretrazivac\BugCD Pretrazivac.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: eng-scr - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Croatian) for Windows\Plugins\IE.htm
O8 - Extra context menu item: English<->French - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-French) for Windows\Plugins\IE.htm
O8 - Extra context menu item: English<->German - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-German) for Windows\Plugins\IE.htm
O8 - Extra context menu item: English<->Italian - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Italian) for Windows\Plugins\IE.htm
O8 - Extra context menu item: English<->Latin - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Latin) for Windows\Plugins\IE.htm
O8 - Extra context menu item: English<->Spanish - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Spanish) for Windows\Plugins\IE.htm
O8 - Extra context menu item: I&zvoz u Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Stavi na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Stavi na blog u Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: English<->German - {2DDEE708-A225-6449-889B-1941E2FBAB6D} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-German) for Windows\Plugins\IE.htm
O9 - Extra 'Tools' menuitem: English<->German - {2DDEE708-A225-6449-889B-1941E2FBAB6D} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-German) for Windows\Plugins\IE.htm
O9 - Extra button: English<->Latin - {4629E725-138D-0F4C-B01A-09EBD3D67834} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Latin) for Windows\Plugins\IE.htm
O9 - Extra 'Tools' menuitem: English<->Latin - {4629E725-138D-0F4C-B01A-09EBD3D67834} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Latin) for Windows\Plugins\IE.htm
O9 - Extra button: English<->Italian - {73AD0419-12E3-E74C-B893-EA4EF48F451F} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Italian) for Windows\Plugins\IE.htm
O9 - Extra 'Tools' menuitem: English<->Italian - {73AD0419-12E3-E74C-B893-EA4EF48F451F} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Italian) for Windows\Plugins\IE.htm
O9 - Extra button: Istraživanje - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: English<->French - {9771B718-0C1C-3248-A000-C378A44BF07B} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-French) for Windows\Plugins\IE.htm
O9 - Extra 'Tools' menuitem: English<->French - {9771B718-0C1C-3248-A000-C378A44BF07B} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-French) for Windows\Plugins\IE.htm
O9 - Extra button: English<->Spanish - {A9919568-CF8E-C140-84DC-0FF917685E69} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Spanish) for Windows\Plugins\IE.htm
O9 - Extra 'Tools' menuitem: English<->Spanish - {A9919568-CF8E-C140-84DC-0FF917685E69} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Spanish) for Windows\Plugins\IE.htm
O9 - Extra button: English<->Croatian - {B05D861D-C01F-7C4C-A7FF-A8003A8FE77C} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Croatian) for Windows\Plugins\IE.htm
O9 - Extra 'Tools' menuitem: eng-scr - {B05D861D-C01F-7C4C-A7FF-A8003A8FE77C} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Croatian) for Windows\Plugins\IE.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.co.../sysreqlab3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1200047154156
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

--
End of file - 12372 bytes

======Scheduled tasks folder======

C:\windows\tasks\Ad-Aware Update (Weekly).job
C:\windows\tasks\SmartDefrag.job
C:\windows\tasks\WGASetup.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-12 63128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-06-15 308856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-09 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-09 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"=C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe [2004-11-02 32768]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"amd_dc_opt"=C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2006-11-17 77824]
"Sony Ericsson PC Suite"=C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe [2005-10-26 159744]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-02-05 81000]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-03-28 413696]
"PinnacleDriverCheck"=C:\windows\system32\PSDrvCheck.exe [2003-12-04 406016]
"SmartDefrag"=C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-02-13 1986896]
"NvCplDaemon"=C:\windows\system32\NvCpl.dll [2009-03-27 13684736]
"nwiz"=nwiz.exe /install []
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-09 148888]
"SoundMan"=C:\windows\SOUNDMAN.EXE [2005-05-17 77824]
"RivaTunerStartupDaemon"=C:\Program Files\RivaTuner v2.24\RivaTuner.exe [2009-02-25 2781184]
"NvMediaCenter"=C:\windows\system32\NvMcTray.dll [2009-03-27 86016]
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2009-06-18 518488]
"KernelFaultCheck"=C:\windows\system32\dumprep 0 -k []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe [2005-09-03 94208]
"BugCD Pretrazivac"=C:\Program Files\BugCD Pretrazivac\BugCD Pretrazivac.exe [2002-08-12 49152]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"ctfmon.exe"=C:\windows\system32\ctfmon.exe [2008-04-14 15360]
"NVIDIA nTune"=C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe [2007-09-04 81920]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"Steam"=C:\Program Files\Steam\Steam.exe [2009-06-10 1217784]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2009-05-26 1830128]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

C:\Documents and Settings\Decky\Start Menu\Programs\Startup
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2008-12-22 356352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\windows\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Atari\BOILING POINT\Xenus.exe"="C:\Program Files\Atari\BOILING POINT\Xenus.exe:*:Disabled:Xenus"
"D:\Program Files\Live for Speed S2\LFSspotter.exe"="D:\Program Files\Live for Speed S2\LFSspotter.exe:*:Disabled:LFSspotter"
"D:\Program Files\Live for Speed S2\LFS.exe"="D:\Program Files\Live for Speed S2\LFS.exe:*:Disabled:LFS"
"D:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe"="D:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe:*:Disabled:DarkCrusade"
"D:\Program Files\Atari\Test Drive Unlimited\TestDriveUnlimited.exe"="D:\Program Files\Atari\Test Drive Unlimited\TestDriveUnlimited.exe:*:Disabled:Test Drive Unlimited"
"D:\Program Files\Firefly Studios\Stronghold 2\Stronghold2.exe"="D:\Program Files\Firefly Studios\Stronghold 2\Stronghold2.exe:*:Enabled:Stronghold 2"
"C:\Program Files\Opera\Opera.exe"="C:\Program Files\Opera\Opera.exe:*:Enabled:Opera Internet Browser"
"C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Internet Security 7.0.1.321\English\setup.exe"="C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Internet Security 7.0.1.321\English\setup.exe:*:Enabled:Kaspersky Internet Security 7.0 Setup"
"C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA"
"C:\Program Files\FrostWire\FrostWire.exe"="C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:LimeWire"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\Xfire\xfire.exe"="C:\Program Files\Xfire\xfire.exe:*:Enabled:Xfire"
"C:\Program Files\MessengerDiscovery\MessengerDiscovery Live.exe"="C:\Program Files\MessengerDiscovery\MessengerDiscovery Live.exe:*:Enabled:MessengerDiscovery Live the Windows Live Messenger addon"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\Ubisoft\Splinter Cell Pandora Tomorrow\pandora.exe"="C:\Program Files\Ubisoft\Splinter Cell Pandora Tomorrow\pandora.exe:*:Enabled:pandora"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\Crave Entertainment\World Championship Poker 2\WCP2.exe"="C:\Program Files\Crave Entertainment\World Championship Poker 2\WCP2.exe:*:Enabled:WCP2"
"D:\Program Files\Techland\Xpand Rally\xpandrally.exe"="D:\Program Files\Techland\Xpand Rally\xpandrally.exe:*:Disabled:XpandRally"
"C:\Program Files\BitLord\BitLord.exe"="C:\Program Files\BitLord\BitLord.exe:*:Enabled:BitLord"
"D:\Program Files\THQ\Dawn of War - Soulstorm\Soulstorm.exe"="D:\Program Files\THQ\Dawn of War - Soulstorm\Soulstorm.exe:*:Enabled:Soulstorm"
"C:\Program Files\Steam\steamapps\mposlon\half-life 2 deathmatch\hl2.exe"="C:\Program Files\Steam\steamapps\mposlon\half-life 2 deathmatch\hl2.exe:*:Enabled:hl2"
"D:\Program Files\UT2004\System\UT2004.exe"="D:\Program Files\UT2004\System\UT2004.exe:*:Enabled:UT2004"
"G:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe"="G:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club"
"G:\Program Files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe"="G:\Program Files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV"
"G:\Program Files\Rockstar Games\Grand Theft Auto IV\GTAIV.exe"="G:\Program Files\Rockstar Games\Grand Theft Auto IV\GTAIV.exe:*:Enabled:Grand Theft Auto IV"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

======File associations======

.js - edit - "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe" "%1"

======List of files/folders created in the last 1 months======

2009-06-24 12:06:11 ----D---- C:\rsit
2009-06-24 12:03:39 ----A---- C:\RootRepeal report 06-24-09 (12-03-39).txt
2009-06-19 09:34:42 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-19 09:34:38 ----D---- C:\Program Files\SUPERAntiSpyware
2009-06-19 09:34:38 ----D---- C:\Documents and Settings\Decky\Application Data\SUPERAntiSpyware.com
2009-06-18 18:54:26 ----D---- C:\windows\system32\xlive
2009-06-18 18:54:25 ----D---- C:\Program Files\Microsoft Games for Windows - LIVE
2009-06-18 14:07:11 ----SHD---- C:\RECYCLER
2009-06-18 13:57:19 ----A---- C:\ComboFix.txt
2009-06-18 13:48:32 ----A---- C:\windows\zip.exe
2009-06-18 13:48:32 ----A---- C:\windows\SWXCACLS.exe
2009-06-18 13:48:32 ----A---- C:\windows\SWSC.exe
2009-06-18 13:48:32 ----A---- C:\windows\SWREG.exe
2009-06-18 13:48:32 ----A---- C:\windows\sed.exe
2009-06-18 13:48:32 ----A---- C:\windows\PEV.exe
2009-06-18 13:48:32 ----A---- C:\windows\NIRCMD.exe
2009-06-18 13:48:32 ----A---- C:\windows\grep.exe
2009-06-18 13:48:27 ----SD---- C:\Combo-Fix
2009-06-18 13:47:08 ----D---- C:\Qoobox
2009-06-14 19:58:10 ----D---- C:\Rooter$
2009-06-14 19:38:25 ----A---- C:\windows\ntbtlog.txt
2009-06-12 09:36:01 ----HDC---- C:\windows\$NtUninstallKB961501$
2009-06-12 09:35:51 ----HDC---- C:\windows\$NtUninstallKB969898$
2009-06-12 09:33:44 ----HDC---- C:\windows\$NtUninstallKB970238$
2009-06-12 09:32:22 ----HDC---- C:\windows\$NtUninstallKB968537$
2009-06-04 22:17:25 ----A---- C:\windows\system32\lsdelete.exe
2009-06-04 22:02:28 ----HDC---- C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-04 20:49:59 ----D---- C:\Documents and Settings\Decky\Application Data\Malwarebytes
2009-06-04 20:49:54 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-06-04 20:49:53 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-06-04 20:47:26 ----D---- C:\windows\ERDNT
2009-06-04 20:46:32 ----D---- C:\Program Files\ERUNT
2009-06-04 19:57:11 ----D---- C:\Program Files\Trend Micro

======List of files/folders modified in the last 1 months======

2009-06-24 12:06:08 ----D---- C:\windows\Prefetch
2009-06-24 12:04:03 ----D---- C:\Program Files\Mozilla Firefox
2009-06-24 11:58:05 ----D---- C:\windows\system32\drivers
2009-06-24 11:57:20 ----D---- C:\windows\Temp
2009-06-24 11:49:00 ----D---- C:\Program Files\Steam
2009-06-24 11:48:49 ----D---- C:\WINDOWS
2009-06-24 11:33:55 ----A---- C:\windows\SchedLgU.Txt
2009-06-23 22:12:44 ----D---- C:\windows\system32\CatRoot2
2009-06-23 20:05:42 ----A---- C:\windows\win.ini
2009-06-21 12:38:33 ----D---- C:\windows\Minidump
2009-06-20 21:50:06 ----A---- C:\windows\NeroDigital.ini
2009-06-20 15:58:50 ----D---- C:\Documents and Settings\Decky\Application Data\FrostWire
2009-06-19 09:34:41 ----SHD---- C:\windows\Installer
2009-06-19 09:34:41 ----SHD---- C:\Config.Msi
2009-06-19 09:34:38 ----D---- C:\Program Files
2009-06-19 09:34:29 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-06-19 09:26:50 ----D---- C:\windows\system32
2009-06-18 21:09:19 ----D---- C:\windows\system32\DirectX
2009-06-18 21:09:18 ----HD---- C:\windows\inf
2009-06-18 21:09:00 ----RSD---- C:\windows\assembly
2009-06-18 21:08:26 ----D---- C:\windows\system32\CatRoot
2009-06-18 20:54:26 ----HD---- C:\Program Files\InstallShield Installation Information
2009-06-18 18:55:07 ----D---- C:\Program Files\Windows Media Player
2009-06-18 18:54:26 ----D---- C:\windows\WinSxS
2009-06-18 18:24:02 ----SD---- C:\windows\Tasks
2009-06-18 13:55:36 ----A---- C:\windows\system.ini
2009-06-18 13:53:01 ----D---- C:\windows\AppPatch
2009-06-18 13:52:54 ----D---- C:\Program Files\Common Files
2009-06-14 19:38:41 ----D---- C:\Documents and Settings
2009-06-12 11:14:39 ----D---- C:\windows\system32\wbem
2009-06-12 11:14:38 ----A---- C:\windows\system32\PerfStringBackup.INI
2009-06-12 09:36:04 ----RSHDC---- C:\windows\system32\dllcache
2009-06-12 09:35:56 ----A---- C:\windows\imsins.BAK
2009-06-12 09:35:50 ----HD---- C:\windows\$hf_mig$
2009-06-12 09:32:49 ----D---- C:\windows\system32\en-US
2009-06-12 09:32:49 ----D---- C:\Program Files\Internet Explorer
2009-06-12 09:32:39 ----D---- C:\windows\ie7updates
2009-06-10 20:05:15 ----D---- C:\Documents and Settings\All Users\Application Data\Test Drive Unlimited
2009-06-04 22:12:01 ----D---- C:\windows\system32\Restore
2009-06-04 22:12:00 ----SHD---- C:\System Volume Information
2009-06-04 22:11:34 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-04 22:09:35 ----DC---- C:\windows\system32\DRVSTORE
2009-06-04 21:54:31 ----A---- C:\windows\wininit.ini
2009-06-04 21:40:18 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-06-04 21:05:55 ----D---- C:\windows\SoftwareDistribution
2009-06-01 18:51:12 ----A---- C:\windows\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\windows\system32\drivers\Aavmker4.sys [2009-02-05 26944]
R1 aswSP;avast! Self Protection; C:\windows\system32\drivers\aswSP.sys [2009-02-05 114768]
R1 aswTdi;avast! Network Shield Support; C:\windows\system32\drivers\aswTdi.sys [2009-02-05 51376]
R1 PQNTDrv;PQNTDrv; C:\windows\system32\drivers\PQNTDrv.sys [2002-09-16 4228]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\windows\System32\drivers\prodrv06.sys [2004-08-09 53920]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R1 SCDEmu;SCDEmu; C:\windows\system32\drivers\SCDEmu.sys [2008-07-07 56108]
R2 Aspi32;Aspi32; C:\windows\System32\drivers\aspi32.sys [2002-07-17 16877]
R2 aswFsBlk;aswFsBlk; C:\windows\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
R2 aswMon2;avast! Standard Shield Support; C:\windows\system32\drivers\aswMon2.sys [2009-02-05 94032]
R2 athsgt;athsgt; C:\windows\system32\DRIVERS\athsgt.sys [2006-07-27 164992]
R2 enodpl;enodpl; C:\windows\System32\drivers\enodpl.sys [2003-03-02 7552]
R2 limsgt;limsgt; C:\windows\system32\DRIVERS\limsgt.sys [2006-07-27 12544]
R2 rspndr;Link-Layer Topology Discovery Responder; C:\windows\system32\DRIVERS\rspndr.sys [2006-11-08 62336]
R2 tandpl;tandpl; C:\windows\System32\drivers\tandpl.sys [2003-04-19 4736]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\windows\system32\drivers\ALCXWDM.SYS [2005-05-18 2319680]
R3 AmdLLD;AMD Low Level Device Driver; C:\windows\system32\DRIVERS\AmdLLD.sys [2006-11-01 33280]
R3 ASAPIW2k;ASAPIW2K; C:\windows\system32\drivers\ASAPIW2k.sys [2003-12-04 11264]
R3 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr.sys [2009-02-05 23152]
R3 hidusb;Microsoft HID Class Driver; C:\windows\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Mouse HID Driver; C:\windows\system32\DRIVERS\mouhid.sys [2001-08-23 12160]
R3 nv;nv; C:\windows\system32\DRIVERS\nv4_mini.sys [2009-03-27 6280416]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\windows\system32\DRIVERS\NVENETFD.sys [2005-02-08 33408]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\windows\system32\DRIVERS\nvnetbus.sys [2005-02-08 12928]
R3 NVR0Dev;NVR0Dev; \??\C:\windows\nvoclock.sys []
R3 RivaTuner32;RivaTuner32; \??\C:\Program Files\RivaTuner v2.24\RivaTuner32.sys []
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\windows\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;USB2 Enabled Hub; C:\windows\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\windows\system32\DRIVERS\usbohci.sys [2008-04-14 17152]
S1 InCDPass;InCDPass; C:\windows\system32\drivers\InCDPass.sys []
S1 InCDRm;InCD Reader; C:\windows\system32\drivers\InCDRm.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\Decky\LOCALS~1\Temp\catchme.sys []
S3 ENTECH;ENTECH; \??\C:\windows\system32\DRIVERS\ENTECH.sys []
S3 FXDRV;FXDRV; \??\E:\Fxdrv.sys []
S3 k510bus;Sony Ericsson K510 Driver driver (WDM); C:\windows\system32\DRIVERS\k510bus.sys [2007-01-08 58288]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter; C:\windows\system32\DRIVERS\k510mdfl.sys [2007-01-08 8336]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver; C:\windows\system32\DRIVERS\k510mdm.sys [2007-01-08 94064]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM); C:\windows\system32\DRIVERS\k510mgmt.sys [2007-01-08 85408]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface; C:\windows\system32\DRIVERS\k510obex.sys [2007-01-08 83344]
S3 k750bus;Sony Ericsson 750 driver (WDM); C:\windows\system32\DRIVERS\k750bus.sys [2005-06-03 55216]
S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter; C:\windows\system32\DRIVERS\k750mdfl.sys [2005-06-03 6576]
S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers; C:\windows\system32\DRIVERS\k750mdm.sys [2005-06-03 89872]
S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers; C:\windows\system32\DRIVERS\k750mgmt.sys [2005-06-03 81728]
S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers; C:\windows\system32\DRIVERS\k750obex.sys [2005-06-03 79488]
S3 usbscan;USB Scanner Driver; C:\windows\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\windows\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\windows\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\windows\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 InCDFs;InCD File System; C:\windows\system32\drivers\InCDFs.sys []
S4 IntelIde;IntelIde; C:\windows\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-02-05 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-02-05 138680]
R2 CCALib8;Canon Camera Access Library 8; C:\Program Files\Canon\CAL\CALMAIN.exe [2006-03-30 96341]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-03-09 152984]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2005-12-18 73728]
R2 nTuneService;nTune Service; C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe [2007-09-04 131072]
R2 NVSvc;NVIDIA Display Driver Service; C:\windows\system32\nvsvc32.exe [2009-03-27 163908]
R2 StarWindService;StarWind iSCSI Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe [2005-04-02 217600]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2006-11-05 72704]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-02-05 254040]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-02-05 352920]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-06-18 1003344]
S3 Macromedia Licensing Service;Macromedia Licensing Service; C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe [2007-09-04 69632]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\windows\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

-----------------EOF-----------------

rsit info.txt:
info.txt logfile of random's system information tool 1.06 2009-06-24 12:06:21

======Uninstall list======

-->MsiExec.exe /X{E9F81423-211E-46B6-9AE0-38568BC5CF6F}
-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->MsiExec /X{DD1865F0-AD73-40FB-B23E-1822E02396FF}
-->MsiExec.exe /I{219B0DA4-8F1A-499D-8795-4A07C632521E}
-->MsiExec.exe /I{644B991F-B109-4360-9DA3-40CDAD13961C}
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
7-Zip 4.57-->"C:\Program Files\7-Zip\Uninstall.exe"
AC3Filter (remove only)-->C:\Program Files\AC3Filter\uninstall.exe
Ad-Aware-->"C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE
Ad-Aware-->C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
Adobe Common File Installer-->MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39}
Adobe Flash Player 10 ActiveX-->C:\windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Help Center 1.0-->MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001}
Adobe Photoshop CS2-->msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}
Adobe Reader 7.0.7-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70700000002}
Adobe Shockwave Player 11.5-->C:\windows\system32\Adobe\uninstaller.exe
Adobe Stock Photos 1.0-->MsiExec.exe /I{786C5747-1033-0000-B58E-000000000001}
Agatha Christie - And Then There Were None-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E4628D0D-5DC8-49EC-985A-F0C12EDBF1D2}\setup.exe" -l0x9 -uninst
Analyze for Speed 1.0-->D:\Program Files\Live for Speed S2\Analyze for Speed\Uninstall AnalyzeforSpeed.exe
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"
avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
Axis & Allies-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{47836B39-2465-4F39-9D7E-52F70A1C3D72}\SETUP.EXE" -l0x9
Big Mutha Truckers 2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FA075505-EFF6-4006-8E9F-921E09774684}\Setup.exe" -l0x9
BitLord 1.1-->C:\Program Files\BitLord\uninst.exe
BOILING POINT-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{58AC967F-CE64-4065-AF54-FA66BAF31FE8}\SETUP.EXE" -l0x9
BSPlayer-->"C:\Program Files\Webteh\BSplayerPro\uninstall.exe"
Call of Duty® 4 - Modern Warfare™ 1.4 Patch-->C:\Program Files\InstallShield Installation Information\{3BD633E0-4BF8-4499-9149-88F0767D449C}\setup.exe -runfromtemp -l0x0409
Canon Camera Access Library-->"C:\Program Files\Common Files\Canon\UIW\1.2.0.0\Uninst.exe" "C:\Program Files\Canon\CAL\Uninst.ini"
Canon Camera Support Core Library-->"C:\Program Files\Common Files\Canon\UIW\1.2.0.0\Uninst.exe" "C:\Program Files\Canon\CSCLIB\Uninst.ini"
Canon Camera Window DC_DV 5 for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.2.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDVC\Uninst.ini"
Canon Camera Window DC_DV 6 for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.2.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDVC6\Uninst.ini"
Canon Camera Window MC 6 for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.2.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowMC\Uninst.ini"
Canon G.726 WMP-Decoder-->"C:\Program Files\Common Files\Canon\UIW\1.2.0.0\Uninst.exe" "C:\Program Files\Canon\G726Decoder\G726DecUnInstall.ini"
Canon MovieEdit Task for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.2.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\MVWUninst.ini"
Canon RAW Image Task for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.2.0.0\Uninst.exe" "C:\Program Files\Canon\RAW Image Task\Uninst.ini"
Canon RemoteCapture Task for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.2.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\RemoteCaptureTask DC\Uninst.ini"
Canon Utilities EOS Utility-->"C:\Program Files\Common Files\Canon\UIW\1.2.0.0\Uninst.exe" "C:\Program Files\Canon\EOS Utility\Uninst.ini"
Canon Utilities PhotoStitch-->"C:\Program Files\Common Files\Canon\UIW\1.2.0.0\Uninst.exe" "C:\Program Files\Canon\PhotoStitch\Uninst.ini"
Canon Utilities ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.2.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\Uninst.ini"
CD Recovery Toolbox Free 1.1-->"C:\Program Files\CD Recovery Toolbox Free\unins000.exe"
Colin McRae Rally 2005-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CC67770B-581D-4E96-B72A-A7907CE18725}\Setup.exe" -l0x9
Commandos Strike Force-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{544DB849-AB59-4C12-A333-2F214E24870F}\Setup.exe" -l0x9 -removeonly
Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Crashday-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9C27ADE1-EAFB-4BB7-9FE3-5DD9BA9A3DD2}\SETUP.EXE" -l0x9 -removeonly
Critical Update for Windows Media Player 11 (KB959772)-->"C:\windows\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
Crysis WARHEAD®-->"C:\Documents and Settings\All Users\Application Data\{0691F710-1ECA-4B5A-9727-25554F1BFDC6}\setup.exe" REMOVE=TRUE MODIFY=FALSE
Crysis WARHEAD®-->C:\Documents and Settings\All Users\Application Data\{0691F710-1ECA-4B5A-9727-25554F1BFDC6}\setup.exe
Dawn of War - Dark Crusade-->C:\Program Files\InstallShield Installation Information\{FF39FC01-819B-42E4-AE49-1968AF12DDD4}\setup.exe -runfromtemp -l0x0009 -removeonly
Dawn of War - Soulstorm-->"C:\Program Files\InstallShield Installation Information\{20533183-D42D-4261-A125-956736FBEA8C}\setup.exe" -runfromtemp -l0x0009 -removeonly
Disc2Phone-->MsiExec.exe /I{6E65247F-58F9-41CA-BE69-0316F7907170}
Dual-Core Optimizer-->MsiExec.exe /X{BCA02FAD-2C86-4C8C-A815-51C09F4E51FF}
DVD Solution-->"C:\Program Files\Uninstall_CDS.exe"
ERUNT 1.1j-->"C:\Program Files\ERUNT\unins000.exe"
F1 Screensaver 2006-->C:\windows\system32\F1 Screensaver 2006.scr /u
F1PerfView 1.24-->D:\Program Files\Live for Speed S2\F1PerfView\Uninstall F1PerfView.exe
ferrari_marzo2008 ScreenSaver-->C:\windows\ferrari_marzo2008.scr /U
ffdshow [rev 1228] [2007-06-03]-->"C:\Program Files\ffdshow\unins000.exe"
FIFA 09-->MsiExec.exe /X{2315B23D-3E21-4920-837D-AE6460934ECB}
FLV Player-->"C:\windows\FLV Player\uninstall.exe" "/U:C:\Program Files\FLV Player\Uninstall\uninstall.xml"
FoxyTunes for Firefox-->"C:\Program Files\Mozilla Firefox\firefox.exe" -chrome chrome://foxytunes/content/extras/uninstallExtension.xul
Framebuffer Crysis WARHEAD Benchmark Tool-->MsiExec.exe /I{657201DD-30C8-4E50-88AD-164B3812E8F5}
Free Pascal 2.0.4-->"C:\FPC\2.0.4\unins000.exe"
FrostWire 4.17.2-->C:\Program Files\FrostWire\Uninstall.exe
Futuremark SystemInfo-->"C:\Program Files\InstallShield Installation Information\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}\setup.exe" -runfromtemp -l0x0009 -removeonly
Gear Ratio Calculator 2.5.2-->D:\Program Files\Live for Speed S2\Gear Ratio Calculator\Uninstall GearRatioCalculator.exe
Google Earth-->MsiExec.exe /I{97C0EA4A-1A0B-4C53-ACEB-49984DA79C90}
Grand Theft Auto IV-->"C:\Program Files\InstallShield Installation Information\{579BA58C-F33D-4970-9953-B94B43768AC3}\setup.exe" -runfromtemp -l0x0009 -removeonly
GSplit 2.1-->C:\Program Files\GSplit\Uninst.exe
GT Legends 1.0.0.0-->"C:\Program Files\GTL\Support\unins000.exe"
HighMAT Extension to Microsoft Windows XP CD Writing Wizard-->MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for MSXML 2 (KB887606)-->"C:\windows\$SQLUninstallMSXML2SP6-KB887606-x86-ENU$\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB928788)-->"C:\windows\$NtUninstallKB928788$\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\windows\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\windows\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\windows\$NtUninstallKB952287$\spuninst\spuninst.exe"
Infinite Patience v2.2-->"C:\windows\UNISTB32.EXE" /U "D:\Program Files\Patience\UNINST0.000" "D:\Program Files\Patience\UNINST1.000"
InSim RaceAnalyzer 0.1.1.11-->D:\Program Files\Live for Speed S2\InSim RaceAnalyzer\Uninstall InSim RaceAnalyser.exe
IsoBuster 1.9.1-->"C:\Program Files\Smart Projects\IsoBuster\Uninst\unins000.exe"
Java™ 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Java™ 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java™ 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
KIMI RÄIKKÖNEN Screen Saver-->C:\Program Files\KIMI RÄIKKÖNEN Screen Saver\Uninstall.exe
LEGO Star Wars II-->C:\Program Files\InstallShield Installation Information\{4E074808-1B86-4230-A9EB-0904942EC4AE}\setup.exe -runfromtemp -l0x0409
LFS GhostcarMod 1.01-->D:\Program Files\Live for Speed S2\Uninstall Ghostcar.exe
LFS PitSpotter 1.1b-->D:\Program Files\Live for Speed S2\Uninstall PitSpotter.exe
LFS SmokeMod 1.1-->D:\Program Files\Live for Speed S2\Uninstall SmokeMod.exe
LingvoSoft Talking Dictionary 2007 English<->Croatian for Windows-->C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Croatian) for Windows\Uninstall Talking Dictionary 2007 English-Croatian for Windows.exe
LingvoSoft Talking Dictionary 2007 English<->French for Windows-->C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-French) for Windows\Uninstall Talking Dictionary 2007 English-French for Windows.exe
LingvoSoft Talking Dictionary 2007 English<->German for Windows-->C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-German) for Windows\Uninstall Talking Dictionary 2007 English-German for Windows.exe
LingvoSoft Talking Dictionary 2007 English<->Italian for Windows-->C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Italian) for Windows\Uninstall Talking Dictionary 2007 English-Italian for Windows.exe
LingvoSoft Talking Dictionary 2007 English<->Latin for Windows-->C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Latin) for Windows\Uninstall Talking Dictionary 2007 English-Latin for Windows.exe
LingvoSoft Talking Dictionary 2007 English<->Spanish for Windows-->C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Spanish) for Windows\Uninstall Talking Dictionary 2007 English-Spanish for Windows.exe
Live for Speed S2 0.5Q-->D:\Program Files\Live for Speed S2\Uninstall Live for Speed S2.exe
Live for Speed S2 Car Skin-->D:\Program Files\Live for Speed S2\Uninstall Skin.exe
Live for Speed S2 Dedicated Host 0.5Q-->C:\Program Files\Live for Speed S2\Dedicated Host\Uninstall DediHost.exe
Live for Speed S2 HiRes Sky Textures-->D:\Program Files\Live for Speed S2\Uninstall Sky Texture.exe
Live for Speed S2 Music Tracks-->D:\Program Files\Live for Speed S2\Uninstall Music.exe
Macromedia Captivate-->MsiExec.exe /X{A7651FB4-AC2E-4020-90E2-B71C8C379F48}
Macromedia Contribute 3.11-->MsiExec.exe /I{4B9535BF-CC90-4158-AF32-CAF57A8820CA}
Macromedia Dreamweaver 8-->MsiExec.exe /I{0837A661-FEC3-48B3-876C-91E7D32048A9}
Macromedia Extension Manager-->MsiExec.exe /I{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}
Macromedia Fireworks 8-->MsiExec.exe /I{4C24A8C1-7CFA-4650-AF15-732F5BD7B46D}
Macromedia Flash 8 Video Encoder-->MsiExec.exe /X{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}
Macromedia Flash 8-->MsiExec.exe /I{2BD5C305-1B27-4D41-B690-7A61172D2FEB}
Macromedia FreeHand MXa-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{939740B5-0064-4779-854A-8C1086181C05}\Setup.exe" -l0x9 UNINSTALL
Magic DVD Ripper V3.2-->"C:\Program Files\MagicDVDRipper\unins000.exe"
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Mathematica 5-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\8\INTEL3~1\IDriver.exe /M{A267A14C-6FDA-41A1-8B22-50A5D1E4444E}
MATLAB 10-22-2006-->C:\WINDOWS\uninst.exe -fc:\MATLABR11\DeIsL1.isu
Messenger Plus! Live & Sponsor (CiD)-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
MessengerDiscovery Live 1.4.5408-->"C:\Program Files\MessengerDiscovery\unins001.exe"
Microsoft .NET Framework 1.1 Hotfix (KB925168)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M925168\M925168Uninstall.msp"
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0-->C:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft .NET Framework 3.0-->c:\windows\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
Microsoft .NET Framework 3.0-->MsiExec.exe /X{15095BF3-A3D7-4DDF-B193-3A496881E003}
Microsoft Base Smart Card Cryptographic Service Provider Package-->"C:\windows\$NtUninstallbasecsp$\spuninst\spuninst.exe"
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\windows\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Games for Windows - LIVE -->MsiExec.exe /X{4D243BA7-9AC4-46D1-90E5-EEB88974F501}
Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{05B49229-22A2-4F88-842A-BBC2EBE1CCF6}
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\windows\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft MapPoint Europe 2006-->MsiExec.exe /I{83ED1E80-A1B7-4256-BCF1-AC4A88151A6B}
Microsoft National Language Support Downlevel APIs-->"C:\windows\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011041A-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\windows\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Windows Script 5.7-->"C:\windows\$NtUninstallscripten$\spuninst\spuninst.exe"
Mozilla Firefox (3.0.11)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
Multimedia Launcher-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
MyPhoneExplorer-->C:\Program Files\MyPhoneExplorer\uninstall.exe
Need for Speed™ ProStreet-->MsiExec.exe /X{CC419DDC-E0F0-4013-B25A-6FA036516F0D}
Need for Speed™ Undercover-->MsiExec.exe /X{E6D22FE1-AB5F-42CA-9480-6F70B96DDD88}
Nero 7 Premium-->MsiExec.exe /I{4781569D-5404-1F26-4B2B-6DF444441031}
NVIDIA Drivers-->C:\windows\system32\nvuninst.exe UninstallGUI
NVIDIA nTune-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF} /l1033
NVIDIA PhysX-->MsiExec.exe /X{DD1865F0-AD73-40FB-B23E-1822E02396FF}
Oblivion-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{35CB6715-41F8-4F99-8881-6FC75BF054B0}\setup.exe" -l0x9 -removeonly
Opera 9.64-->MsiExec.exe /X{E1BBBAC5-2857-4155-82A6-54492CE88620}
PhysX Screen Saver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{300A470B-681B-449F-82AE-6D19114702CE}\Setup.exe" -l0x9
PilotDown-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0D093D4A-C6F5-4258-8E13-94F8EA6C6A4C}\setup.exe" -l0x9 -removeonly
Pinnacle Hollywood FX 5-->C:\windows\unvise32.exe C:\Program Files\Pinnacle\Hollywood FX 5\uninstal.log
PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
PowerISO-->"C:\Program Files\PowerISO\uninstall.exe"
PowerQuest PartitionMagic 8.0-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}
PunkBuster Services-->C:\windows\system32\pbsvc.exe -u
QuickTime-->MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}
Race Driver 3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0297C87B-CC40-446F-865A-031B4FC0CF22}\Setup.exe" -l0x9 -removeonly
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\Setup.exe" -l0x9 -removeonly
Registry Repair 2.4-->"C:\Program Files\Registry Repair\unins000.exe"
RivaTuner v2.24-->"C:\Program Files\RivaTuner v2.24\uninstall.exe"
Rockstar Games Social Club-->"C:\Program Files\InstallShield Installation Information\{08B3869E-D282-424C-9AFC-870E04A4BA14}\setup.exe" -runfromtemp -l0x0009 -removeonly
Royale Remixed Theme-->MsiExec.exe /I{993A94A9-DCE3-4774-B35D-D8C74FC1E0BE}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Microsoft .NET Framework 2.0 (KB928365)-->C:\windows\system32\msiexec.exe /promptrestart /uninstall {8056AC9E-49C5-4375-9ADE-B2F862C9DF51} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
Security Update for Step By Step Interactive Training (KB923723)-->"C:\windows\$NtUninstallKB923723$\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB928090)-->"C:\windows\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB937143)-->"C:\windows\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\windows\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\windows\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\windows\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\windows\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\windows\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB961260)-->"C:\windows\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB963027)-->"C:\windows\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB969897)-->"C:\windows\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\windows\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\windows\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\windows\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"C:\windows\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)-->"C:\windows\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\windows\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\windows\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\windows\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\windows\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\windows\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\windows\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\windows\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\windows\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\windows\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"C:\windows\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\windows\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\windows\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\windows\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\windows\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\windows\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\windows\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\windows\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"C:\windows\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\windows\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\windows\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\windows\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\windows\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\windows\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\windows\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\windows\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958690)-->"C:\windows\$NtUninstallKB958690$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"C:\windows\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\windows\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)-->"C:\windows\$NtUninstallKB960715$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"C:\windows\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961373)-->"C:\windows\$NtUninstallKB961373$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961501)-->"C:\windows\$NtUninstallKB961501$\spuninst\spuninst.exe"
Security Update for Windows XP (KB968537)-->"C:\windows\$NtUninstallKB968537$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969898)-->"C:\windows\$NtUninstallKB969898$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970238)-->"C:\windows\$NtUninstallKB970238$\spuninst\spuninst.exe"
Sketchpad-->D:\PROGRA~1\SKETCH~1\UNWISE.EXE D:\PROGRA~1\SKETCH~1\INSTALL.LOG
Ski Racing 2006-->MsiExec.exe /I{97DDA53A-8346-467A-880C-655E847CC7D3}
Smart Defrag 1.11-->"C:\Program Files\IObit\IObit SmartDefrag\unins000.exe"
Sony Ericsson PC Suite 1.20.173-->MsiExec.exe /I{C5ADA65A-7828-4D85-B071-ECC52B51F794}
SpeechRedist-->MsiExec.exe /X{8795CBED-55E2-4693-9F14-84EC446935BE}
Splinter Cell Pandora Tomorrow-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{084A9731-D05B-4ADA-B4A0-0ADD25FD7152}\Setup.exe" -l0x9
SPORE™-->"C:\Program Files\InstallShield Installation Information\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}\SPORESetup.exe" -runfromtemp -l0x0009 -removeonly
Spybot - Search & Destroy 1.5.2.20-->"C:\windows\unins000.exe"
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
Stronghold 2 Deluxe-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{16D2C649-CBA8-44EE-B730-12584667D487}\setup.exe" -l0x9 -removeonly
Studio 9-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E491AB7-4589-48CA-9CBB-874CB2788391}\Setup.exe" -l0x9 UNINSTALL
Subtitle Workshop 2.51-->"C:\Program Files\URUSoft\Subtitle Workshop\uninstall.exe"
SUPER © Version 2008.bld.30 (Mar 22, 2008)-->C:\PROGRA~1\ERIGHT~1\SUPER\Setup.exe /remove /q0
SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
SuperUtility-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{10E33F6D-16E6-400E-BA1E-DF9F1BCD1B30}\setup.exe" -l0x9
System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
Test Drive Unlimited-->MsiExec.exe /X{C37A0BC1-52EE-4F97-8223-5CA9FC0357B0}
The Da Vinci Code-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{851367C1-2F9F-4087-B3E8-8DECFE328370}\setup.exe" -l0x9 -removeonly
The Godfather™ The Game-->C:\Program Files\Electronic Arts\The Godfather The Game\EAUninstall.exe
Tom Clancy's Splinter Cell Chaos Theory-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BABAEBE4-9FFB-4B5D-9453-64FF11517CA2}\setup.exe" -l0x9 -removeonly
Unreal Tournament 2004-->D:\Program Files\UT2004\System\Setup.exe uninstall "UT2004"
Update for Windows XP (KB942763)-->"C:\windows\$NtUninstallKB942763$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)-->"C:\windows\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\windows\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\windows\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\windows\$NtUninstallKB967715$\spuninst\spuninst.exe"
VideoLAN VLC media player 0.8.6d-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\windows\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
Western Australian Time Zone Update-->MsiExec.exe /X{C098DAEC-29EF-4A59-B18E-0E950169CA3C}
Windows Communication Foundation-->MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
Windows Imaging Component-->"C:\windows\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live Galerija fotografija-->MsiExec.exe /X{B2E01847-F5DF-4BD9-B20F-260A794EF934}
Windows Live installer-->MsiExec.exe /X{478DCE85-E854-4E55-9B6A-D285F9CABAFF}
Windows Live Mail-->MsiExec.exe /I{844A01D6-3B94-4CAC-BAF8-22ECF081C14F}
Windows Live Messenger-->MsiExec.exe /X{C550F6FC-6C3C-4CB4-BC13-3960B17959DD}
Windows Live Sign-in Assistant-->MsiExec.exe /I{9422C8EA-B0C6-4197-B8FC-DC797658CA00}
Windows Live Writer-->MsiExec.exe /X{63D64340-C694-48C4-893F-481AD9A1ACCE}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\windows\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\windows\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows Workflow Foundation-->MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
Windows XP Service Pack 3-->"C:\windows\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
World Championship Poker 2-->MsiExec.exe /X{FBF91C7D-988A-432A-91C3-5081787C85C1}
Xfire (remove only)-->"C:\Program Files\Xfire\uninst.exe"
Xpand Rally-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{252436F1-9583-4AD7-AA11-619AFFB96543} /Z"UNINSTALL"

======Hosts File======

127.0.0.1 007guard.com
127.0.0.1 www.007guard.com
127.0.0.1 008i.com
127.0.0.1 008k.com
127.0.0.1 www.008k.com
127.0.0.1 00hq.com
127.0.0.1 www.00hq.com
127.0.0.1 010402.com
127.0.0.1 032439.com
127.0.0.1 www.032439.com

======Security center information======

AV: avast! antivirus 4.8.1335 [VPS 090623-0] (disabled)

======System event log======

Computer Name: DECKY-E93819898
Event Code: 4226
Message: TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Record Number: 7373
Source Name: Tcpip
Time Written: 20090605162538.000000+120
Event Type: warning
User:

Computer Name: DECKY-E93819898
Event Code: 4226
Message: TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Record Number: 7372
Source Name: Tcpip
Time Written: 20090605155737.000000+120
Event Type: warning
User:

Computer Name: DECKY-E93819898
Event Code: 4226
Message: TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Record Number: 7371
Source Name: Tcpip
Time Written: 20090605154338.000000+120
Event Type: warning
User:

Computer Name: DECKY-E93819898
Event Code: 10005
Message: DCOM got error "%1058" attempting to start the service wuauserv with arguments ""
in order to run the server:
{E60687F7-01A1-40AA-86AC-DB1CBF673334}

Record Number: 7287
Source Name: DCOM
Time Written: 20090604210550.000000+120
Event Type: error
User: DECKY-E93819898\Decky

Computer Name: DECKY-E93819898
Event Code: 7026
Message: The following boot-start or system-start driver(s) failed to load:
atapi
PCIIde

Record Number: 7265
Source Name: Service Control Manager
Time Written: 20090604205909.000000+120
Event Type: error
User:

=====Application event log=====

Computer Name: DECKY-E93819898
Event Code: 1000
Message: Faulting application shadowstrike_static_retail.exe, version 0.0.0.0, faulting module shadowstrike_static_retail.exe, version 0.0.0.0, fault address 0x0021b4df.

Record Number: 2497
Source Name: Application Error
Time Written: 20090419191538.000000+120
Event Type: error
User:

Computer Name: DECKY-E93819898
Event Code: 1002
Message: Hanging application pandora.exe, version 0.0.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Record Number: 2496
Source Name: Application Hang
Time Written: 20090419180412.000000+120
Event Type: error
User:

Computer Name: DECKY-E93819898
Event Code: 12001
Message: The Messenger Sharing USN Journal Reader service started successfully.

Record Number: 2475
Source Name: usnjsvc
Time Written: 20090419101313.000000+120
Event Type:
User:

Computer Name: DECKY-E93819898
Event Code: 1002
Message: Hanging application pandora.exe, version 0.0.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Record Number: 2468
Source Name: Application Hang
Time Written: 20090418213242.000000+120
Event Type: error
User:

Computer Name: DECKY-E93819898
Event Code: 12001
Message: The Messenger Sharing USN Journal Reader service started successfully.

Record Number: 2463
Source Name: usnjsvc
Time Written: 20090418190422.000000+120
Event Type:
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Common Files\Adobe\AGL;C:\Program Files\Common Files\Teleca Shared;C:\Program Files\QuickTime\QTSystem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 43 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=2b01
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"DEFAULT_CA_NR"=CA6
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
"RGSCLauncher"=G:\Program Files\Rockstar Games\Rockstar Games Social Club
"RGSC"=G:\Program Files\Rockstar Games\Rockstar Games Social Club\1_0_0_0

-----------------EOF-----------------
  • 0

#8
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Hi MPoslon,



Your Adobe Acrobat Reader is out of date. Older versions are vulnerable to attack.

Please go to the link below to update.

http://www.adobe.com.../readstep2.html





Please go to Start > Control Panel > Add/Remove Programs and remove the following (if present):

Java™ 6 Update 13
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7






Posted Image Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

Upgrading Java:
  • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 14.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u14-windows-i586.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u14-windows-i586.exe and select "Run as an Administrator.")




Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.
  • 0

#9
MPoslon

MPoslon

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Hi, SpySentinel

I followed all of your instructions, is there anything else that needs to be done?
  • 0

#10
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
How is your computer running?


Launch Malwarebytes' Anti-Malware
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
  • 0

Advertisements


#11
MPoslon

MPoslon

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Well, I don't have any problems with task manager.
I would say that everything is O.K. now, but there is one more thing that I noticed.
When I get an error message from any kind of program, after it crashes or whatever, and when I close that message, I get the message again 'Can not find script file "C:\WINDOWS\system32\winjpg.jpg".'.
That isn't a problem, but it can be a sign that there is still something infected.

MBAM log:
Malwarebytes' Anti-Malware 1.38
Database version: 2341
Windows 5.1.2600 Service Pack 3

27.6.2009 14:39:15
mbam-log-2009-06-27 (14-39-15).txt

Scan type: Quick Scan
Objects scanned: 97261
Time elapsed: 4 minute(s), 39 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
  • 0

#12
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Hi MPoslon,

Yes you are infected with Email-Worm.Bagel which is indicated by 'Can not find script file "C:\WINDOWS\system32\winjpg.jpg"'


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\winjpg.jpg


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
  • 0

#13
MPoslon

MPoslon

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Hi SpySentinel,

here is ComboFix.txt:
ComboFix 09-06-29.04 - Decky 30.06.2009 17:48.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.385.1033.18.2047.1448 [GMT 2:00]
Running from: c:\documents and settings\Decky\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Decky\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090629-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
"c:\windows\system32\winjpg.jpg"
.

((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-30 )))))))))))))))))))))))))))))))
.

2009-06-30 15:00 . 2008-09-16 19:23 168448 ----a-w- c:\windows\system32\unrar.dll
2009-06-30 15:00 . 2004-05-18 18:16 39936 ----a-w- c:\windows\system32\huffyuv.dll
2009-06-30 15:00 . 2006-04-02 12:47 630784 ----a-w- c:\windows\system32\vp7vfw.dll
2009-06-30 15:00 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2009-06-30 15:00 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2009-06-30 15:00 . 2009-05-01 21:02 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-06-30 15:00 . 2008-11-06 16:37 3596288 ----a-w- c:\windows\system32\qt-dx331.dll
2009-06-30 14:59 . 2009-06-02 16:11 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-06-30 14:59 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\divx.dll
2009-06-30 14:59 . 2009-06-30 15:00 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-06-27 12:22 . 2009-06-27 12:22 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-25 10:18 . 2009-06-25 10:18 279712 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-06-25 10:18 . 2009-06-25 10:18 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2009-06-25 07:33 . 2009-02-12 09:35 38208 ----a-w- c:\documents and settings\Decky\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-06-25 07:33 . 2009-06-25 07:33 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-06-25 07:32 . 2009-06-25 07:32 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-06-25 07:32 . 2009-06-25 07:32 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-06-25 07:32 . 2009-06-25 07:32 -------- d-----w- c:\program files\NOS
2009-06-25 07:32 . 2009-06-04 08:53 31944 ----a-w- c:\documents and settings\Decky\Application Data\Mozilla\Firefox\Profiles\be0vk58y.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-06-25 07:32 . 2009-06-04 08:53 22848 ----a-w- c:\documents and settings\Decky\Application Data\Mozilla\Firefox\Profiles\be0vk58y.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-06-25 07:32 . 2009-06-04 08:53 18776 ----a-w- c:\documents and settings\Decky\Application Data\Mozilla\Firefox\Profiles\be0vk58y.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-06-24 10:06 . 2009-06-24 10:06 -------- d-----w- C:\rsit
2009-06-19 07:35 . 2009-06-30 09:57 117760 ----a-w- c:\documents and settings\Decky\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-19 07:34 . 2009-06-19 07:34 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-19 07:34 . 2009-06-25 08:03 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-06-19 07:34 . 2009-06-19 07:34 -------- d-----w- c:\documents and settings\Decky\Application Data\SUPERAntiSpyware.com
2009-06-18 18:33 . 2009-06-25 11:49 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-18 17:02 . 2009-06-25 11:35 -------- d-----w- c:\documents and settings\Decky\Local Settings\Application Data\Rockstar Games
2009-06-18 16:54 . 2009-06-18 16:54 -------- d-----w- c:\windows\system32\xlive
2009-06-18 16:54 . 2009-06-18 17:13 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2009-06-14 17:58 . 2009-06-14 17:58 -------- d-----w- C:\Rooter$
2009-06-14 17:43 . 2009-06-14 17:43 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-06-04 20:17 . 2009-06-04 20:09 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-04 20:09 . 2009-06-04 20:08 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-04 20:09 . 2009-06-04 20:09 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-06-04 20:08 . 2009-06-29 20:16 84832 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-06-04 20:08 . 2009-06-29 20:15 246128 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-06-04 20:08 . 2009-06-29 20:15 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-06-04 20:08 . 2009-06-04 20:08 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-06-04 20:02 . 2009-06-04 20:02 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-04 20:02 . 2009-03-12 08:17 2902048 -c--a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-04 18:49 . 2009-06-04 18:49 -------- d-----w- c:\documents and settings\Decky\Application Data\Malwarebytes
2009-06-04 18:49 . 2009-06-17 09:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-04 18:49 . 2009-06-04 18:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-04 18:49 . 2009-06-27 12:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-04 18:49 . 2009-06-17 09:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-04 18:46 . 2009-06-04 18:46 -------- d-----w- c:\program files\ERUNT
2009-06-04 17:57 . 2009-06-04 17:57 -------- d-----w- c:\program files\Trend Micro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-30 14:56 . 2006-07-12 11:54 -------- d-----w- c:\program files\ffdshow
2009-06-30 14:54 . 2006-07-12 10:27 -------- d-----w- c:\program files\Webteh
2009-06-30 09:56 . 2009-03-21 08:40 -------- d-----w- c:\program files\Steam
2009-06-29 20:16 . 2009-06-18 20:09 314712 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-06-29 20:16 . 2009-06-18 20:09 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-06-29 20:16 . 2009-06-18 20:09 169312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-06-29 20:16 . 2009-06-18 20:09 348496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-06-29 20:16 . 2009-06-18 20:09 298336 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-06-29 20:16 . 2009-06-18 20:09 1630560 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-06-29 20:15 . 2009-06-18 20:09 85352 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\AAWDriverTool.exe
2009-06-29 20:15 . 2009-06-18 20:09 664424 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-06-29 19:45 . 2008-02-02 19:28 -------- d-----w- c:\documents and settings\Decky\Application Data\FrostWire
2009-06-29 19:44 . 2008-02-02 19:28 -------- d-----w- c:\program files\FrostWire
2009-06-28 21:03 . 2008-02-18 16:29 1392576 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-06-25 16:57 . 2006-07-11 08:09 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-25 08:05 . 2009-01-16 14:21 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-25 08:04 . 2008-01-15 20:22 -------- d-----w- c:\program files\Java
2009-06-25 07:35 . 2006-07-11 08:45 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-19 07:34 . 2006-09-19 21:17 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-18 20:09 . 2009-06-18 20:09 561016 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-06-18 20:09 . 2009-06-18 20:09 565096 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-06-18 20:09 . 2009-06-18 20:09 2349384 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-06-18 20:09 . 2009-06-18 20:09 627536 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-06-18 20:09 . 2009-06-18 20:09 518488 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-06-18 20:09 . 2009-06-18 20:09 1003344 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-06-10 18:05 . 2007-04-11 21:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Test Drive Unlimited
2009-06-04 20:11 . 2008-01-11 13:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-04 19:40 . 2008-01-11 13:18 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-05-15 17:11 . 2009-05-15 17:11 2311 ----a-w- c:\documents and settings\All Users\Application Data\xml92.tmp
2009-05-15 17:11 . 2009-05-15 17:11 13257 ----a-w- c:\documents and settings\All Users\Application Data\xml91.tmp
2009-05-15 17:11 . 2009-05-15 17:11 7890 ----a-w- c:\documents and settings\All Users\Application Data\xml90.tmp
2009-05-07 15:32 . 2004-08-04 07:56 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-06 12:23 . 2009-05-07 18:59 372736 ----a-w- c:\documents and settings\Decky\Application Data\Mozilla\Firefox\Profiles\be0vk58y.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
2009-05-03 10:28 . 2009-05-03 10:28 10134 ----a-r- c:\documents and settings\Decky\Application Data\Microsoft\Installer\{657201DD-30C8-4E50-88AD-164B3812E8F5}\_D578AC58F14BD73AA16534.exe
2009-05-03 10:28 . 2009-05-03 10:28 10134 ----a-r- c:\documents and settings\Decky\Application Data\Microsoft\Installer\{657201DD-30C8-4E50-88AD-164B3812E8F5}\_1BC1E915D9D4E09E0D35C7.exe
2009-05-03 10:28 . 2009-05-03 10:28 10134 ----a-r- c:\documents and settings\Decky\Application Data\Microsoft\Installer\{657201DD-30C8-4E50-88AD-164B3812E8F5}\_11054A45FAD4581FFD16AF.exe
2009-05-01 09:11 . 2009-05-01 09:11 8586 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2009-04-29 04:56 . 2004-08-04 07:56 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-21 22:20 . 2009-04-21 22:20 14311680 ----a-w- c:\windows\system32\xlive.dll
2009-04-21 22:20 . 2009-04-21 22:20 13642496 ----a-w- c:\windows\system32\xlivefnt.dll
2009-04-17 12:26 . 2004-08-04 06:17 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-04 07:56 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-09 10:26 . 2009-04-09 10:26 152576 ----a-w- c:\documents and settings\Decky\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-05 17:37 . 2006-07-11 10:25 68224 ----a-w- c:\documents and settings\Decky\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2004-10-01 13:00 . 2006-07-11 08:40 40960 ----a-w- c:\program files\Uninstall_CDS.exe
2006-05-03 09:06 . 2007-11-30 14:44 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2007-11-30 14:44 31232 --sh--r- c:\windows\system32\msfDX.dll
2007-12-17 12:43 . 2008-04-09 07:33 27648 --sh--w- c:\windows\system32\Smab0.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-06-18_11.55.36 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-06-18 10:22 . 2009-06-18 10:22 16384 c:\windows\Temp\Perflib_Perfdata_8b0.dat
+ 2009-06-30 09:57 . 2009-06-30 09:57 16384 c:\windows\Temp\Perflib_Perfdata_8b0.dat
+ 2009-06-30 09:56 . 2009-06-30 09:56 16384 c:\windows\Temp\Perflib_Perfdata_868.dat
+ 2009-06-30 09:56 . 2009-06-30 09:56 16384 c:\windows\Temp\Perflib_Perfdata_5dc.dat
+ 2006-10-18 21:47 . 2006-10-18 19:47 38400 c:\windows\system32\wpdshextres.dll
- 2006-10-18 21:47 . 2006-10-18 21:47 38400 c:\windows\system32\wpdshextres.dll
+ 2009-06-19 07:34 . 2009-06-19 07:34 65024 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2009-06-19 07:34 . 2009-06-19 07:34 18944 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
- 2009-04-29 19:45 . 2009-04-29 19:45 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2009-06-25 10:15 . 2009-06-25 10:15 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2009-06-25 10:15 . 2009-06-25 10:15 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2009-04-29 19:45 . 2009-04-29 19:45 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2007-11-06 23:19 . 2007-11-06 23:19 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcr90.dll
+ 2007-11-06 23:19 . 2007-11-06 23:19 568832 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcp90.dll
+ 2007-11-06 18:23 . 2007-11-06 18:23 224768 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcm90.dll
+ 2007-11-30 14:44 . 2004-01-25 16:18 217088 c:\windows\system32\yv12vfw.dll
+ 2008-10-22 02:55 . 2008-10-22 02:55 134144 c:\windows\system32\xlive\sqmapi.dll
+ 2006-07-29 06:51 . 2004-12-10 08:03 438272 c:\windows\system32\vp6vfw.dll
- 2006-07-29 06:51 . 2005-06-24 14:24 438272 c:\windows\system32\vp6vfw.dll
+ 2009-06-25 08:05 . 2009-06-25 08:05 148888 c:\windows\system32\javaws.exe
- 2008-08-21 07:21 . 2009-03-09 03:19 148888 c:\windows\system32\javaws.exe
+ 2009-06-25 08:05 . 2009-06-25 08:05 144792 c:\windows\system32\javaw.exe
- 2008-08-21 07:21 . 2009-03-09 03:19 144792 c:\windows\system32\javaw.exe
- 2008-08-21 07:21 . 2009-03-09 03:19 144792 c:\windows\system32\java.exe
+ 2009-06-25 08:05 . 2009-06-25 08:05 144792 c:\windows\system32\java.exe
+ 2009-06-25 10:15 . 2009-06-25 10:15 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2009-04-29 19:45 . 2009-04-29 19:45 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2009-04-29 19:45 . 2009-04-29 19:45 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2009-06-25 10:15 . 2009-06-25 10:15 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2009-06-25 10:15 . 2009-06-25 10:15 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2009-04-29 19:45 . 2009-04-29 19:45 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2009-04-29 19:45 . 2009-04-29 19:45 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2009-06-25 10:15 . 2009-06-25 10:15 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2009-04-29 19:45 . 2009-04-29 19:45 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2009-06-25 10:15 . 2009-06-25 10:15 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2009-06-25 10:15 . 2009-06-25 10:15 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-04-29 19:45 . 2009-04-29 19:45 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-04-29 19:45 . 2009-04-29 19:45 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-25 10:15 . 2009-06-25 10:15 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-04-29 19:45 . 2009-04-29 19:45 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-25 10:15 . 2009-06-25 10:15 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-25 10:15 . 2009-06-25 10:15 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-04-29 19:45 . 2009-04-29 19:45 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-25 10:15 . 2009-06-25 10:15 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-04-29 19:45 . 2009-04-29 19:45 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-04-29 19:45 . 2009-04-29 19:45 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-25 10:15 . 2009-06-25 10:15 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-25 10:15 . 2009-06-25 10:15 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-04-29 19:45 . 2009-04-29 19:45 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-04-29 19:45 . 2009-04-29 19:45 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-25 10:15 . 2009-06-25 10:15 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-04-29 19:45 . 2009-04-29 19:45 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2009-06-25 10:15 . 2009-06-25 10:15 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2007-08-27 13:41 . 2007-08-27 13:41 1089440 c:\windows\system32\msidcrl40.dll
- 2009-04-29 19:45 . 2009-04-29 19:45 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-25 10:15 . 2009-06-25 10:15 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-25 10:15 . 2009-06-25 10:15 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-04-29 19:45 . 2009-04-29 19:45 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-03 94208]
"BugCD Pretrazivac"="c:\program files\BugCD Pretrazivac\BugCD Pretrazivac.exe" [2002-08-12 49152]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Steam"="c:\program files\Steam\Steam.exe" [2009-06-10 1217784]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-06-25 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 77824]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-28 413696]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2003-12-04 406016]
"SmartDefrag"="c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" [2009-02-13 1986896]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"RivaTunerStartupDaemon"="c:\program files\RivaTuner v2.24\RivaTuner.exe" [2009-02-25 2781184]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-18 518488]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-25 148888]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-27 1657376]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2005-05-17 77824]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]

c:\documents and settings\Decky\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 10:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\drwtsn32.exe]
"Debugger"=c:\windows\system32\wscript.exe /E:vbs c:\windows\system32\winjpg.jpg

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dwwinxp.exe]
"Debugger"=c:\windows\system32\winxp.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0autocheck lsdelete\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Atari\\BOILING POINT\\Xenus.exe"=
"d:\\Program Files\\Live for Speed S2\\LFSspotter.exe"=
"d:\\Program Files\\Live for Speed S2\\LFS.exe"=
"d:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"d:\\Program Files\\Atari\\Test Drive Unlimited\\TestDriveUnlimited.exe"=
"d:\\Program Files\\Firefly Studios\\Stronghold 2\\Stronghold2.exe"=
"c:\\Program Files\\Opera\\Opera.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.321\\English\\setup.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Ubisoft\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Crave Entertainment\\World Championship Poker 2\\WCP2.exe"=
"d:\\Program Files\\Techland\\Xpand Rally\\xpandrally.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"d:\\Program Files\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe"=
"c:\\Program Files\\Steam\\steamapps\\mposlon\\half-life 2 deathmatch\\hl2.exe"=
"d:\\Program Files\\UT2004\\System\\UT2004.exe"=
"g:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"g:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"g:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\GTAIV.exe"=
"g:\\Program Files\\Deep Silver\\S.T.A.L.K.E.R. - Clear Sky\\bin\\xrEngine.exe"=
"g:\\Program Files\\Deep Silver\\S.T.A.L.K.E.R. - Clear Sky\\bin\\dedicated\\xrEngine.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15155:TCP"= 15155:TCP:NortonAV
"16556:TCP"= 16556:TCP:NortonAV
"17096:TCP"= 17096:TCP:NortonAV
"17464:TCP"= 17464:TCP:NortonAV
"13299:TCP"= 13299:TCP:NortonAV
"12569:TCP"= 12569:TCP:NortonAV
"15798:TCP"= 15798:TCP:NortonAV
"17026:TCP"= 17026:TCP:NortonAV
"13516:TCP"= 13516:TCP:NortonAV
"13575:TCP"= 13575:TCP:NortonAV
"18893:TCP"= 18893:TCP:NortonAV
"18350:TCP"= 18350:TCP:NortonAV
"16026:TCP"= 16026:TCP:NortonAV
"18699:TCP"= 18699:TCP:NortonAV
"18167:TCP"= 18167:TCP:NortonAV
"17674:TCP"= 17674:TCP:NortonAV
"18146:TCP"= 18146:TCP:NortonAV
"12715:TCP"= 12715:TCP:NortonAV

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [4.6.2009 22:09 64160]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [6.12.2005 17:11 35328]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2.4.2008 21:05 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [26.5.2009 10:05 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [26.5.2009 10:05 72944]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2.4.2008 21:05 20560]
R2 athsgt;athsgt;c:\windows\system32\drivers\athsgt.sys [27.7.2006 18:21 164992]
R2 limsgt;limsgt;c:\windows\system32\drivers\limsgt.sys [27.7.2006 18:21 12544]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [26.5.2009 10:05 7408]
R3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;c:\program files\Windows Live\Messenger\usnsvc.exe [18.10.2007 12:31 98328]
S3 FXDRV;FXDRV;\??\e:\fxdrv.sys --> e:\Fxdrv.sys [?]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [25.6.2009 9:32 66048]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);c:\windows\system32\drivers\k510bus.sys [8.1.2007 11:27 58288]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;c:\windows\system32\drivers\k510mdfl.sys [8.1.2007 11:27 8336]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;c:\windows\system32\drivers\k510mdm.sys [8.1.2007 11:27 94064]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\k510mgmt.sys [8.1.2007 11:27 85408]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;c:\windows\system32\drivers\k510obex.sys [8.1.2007 11:27 83344]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9.3.2009 21:06 1003344]
.
Contents of the 'Scheduled Tasks' folder

2009-06-29 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 20:09]

2009-06-18 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-01-17 17:15]

2009-06-30 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-07 20:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.hr/
uInternet Connection Wizard,ShellNext = iexplore
IE: eng-scr - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Croatian) for Windows\Plugins\IE.htm
IE: English<->French - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-French) for Windows\Plugins\IE.htm
IE: English<->German - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-German) for Windows\Plugins\IE.htm
IE: English<->Italian - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Italian) for Windows\Plugins\IE.htm
IE: English<->Latin - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Latin) for Windows\Plugins\IE.htm
IE: English<->Spanish - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Spanish) for Windows\Plugins\IE.htm
IE: I&zvoz u Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{2DDEE708-A225-6449-889B-1941E2FBAB6D} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-German) for Windows\Plugins\IE.htm
IE: {{4629E725-138D-0F4C-B01A-09EBD3D67834} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Latin) for Windows\Plugins\IE.htm
IE: {{73AD0419-12E3-E74C-B893-EA4EF48F451F} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Italian) for Windows\Plugins\IE.htm
IE: {{9771B718-0C1C-3248-A000-C378A44BF07B} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-French) for Windows\Plugins\IE.htm
IE: {{A9919568-CF8E-C140-84DC-0FF917685E69} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Spanish) for Windows\Plugins\IE.htm
IE: {{B05D861D-C01F-7C4C-A7FF-A8003A8FE77C} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Croatian) for Windows\Plugins\IE.htm
FF - ProfilePath - c:\documents and settings\Decky\Application Data\Mozilla\Firefox\Profiles\be0vk58y.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.oglasnik.hr/
FF - component: c:\documents and settings\Decky\Application Data\Mozilla\Firefox\Profiles\be0vk58y.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - plugin: c:\documents and settings\Decky\Application Data\Mozilla\Firefox\Profiles\be0vk58y.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Opera\program\plugins\np_gp.dll
FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-30 17:54
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1085031214-492894223-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,63,1b,9e,89,00,
bf,5b,73,c8,28,51,af,b0,29,a3,98,30,a9,fd,c2,d5,be,73,f8,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,15,64,5d,be,a9,
24,c6,5e,71,3b,04,66,8b,46,0d,96,72,a8,60,a4,23,5e,97,e0,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,31,5f,d2,35,70,
96,44,4a,25,da,ec,7e,55,20,c9,26,48,ba,30,33,53,d5,a4,a2,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,f7,b0,04,1e,ae,
35,08,0f,3e,1e,9e,e0,57,5a,93,61,61,c9,6d,a4,d9,e6,f9,6a,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,b6,aa,22,00,8a,
b1,5c,d0,cd,44,cd,b9,a6,33,6c,cd,45,a8,36,94,91,08,12,74,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,82,16,0c,80,96,
eb,a8,30,b0,18,ed,a7,3f,8d,37,a4,21,3f,38,48,28,08,72,9c,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,60,95,bd,7f,e9,
84,8f,a1,31,77,e1,ba,b1,f8,68,02,2d,a7,6a,8e,fa,df,1d,03,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,9b,9a,64,a6,02,
c4,98,35,83,6c,56,8b,a0,85,96,ab,9f,d1,20,47,89,83,6f,e6,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,0e,8b,22,d2,0a,
1d,84,9f,51,fa,6e,91,28,9e,14,cc,c5,3b,b3,54,0a,58,b6,e7,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,e8,34,73,8a,76,
e7,48,a9,b1,cd,45,5a,a8,c4,f8,b9,3b,a7,d2,53,6d,d5,39,02,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,d3,ab,e0,b7,97,
82,fe,98,e3,0e,66,d5,eb,bc,2f,6b,85,52,ce,c6,84,43,50,8b,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,fa,e3,de,b8,1c,
1e,61,cb,fa,ea,66,7f,d4,3b,6b,70,db,b1,d5,59,65,26,88,f8,6c,43,2d,1e,aa,22,\

[HKEY_LOCAL_MACHINE\System\MountedDevices]
@Denied: (Read) (Administrators)
"\\DosDevices\\C:"=hex:21,04,21,04,00,7e,00,00,00,00,00,00
"\\??\\Volume{da4bcfda-5b8a-11d9-ba0e-806d6172696f}"=hex:5c,00,3f,00,3f,00,5c,
00,46,00,44,00,43,00,23,00,47,00,45,00,4e,00,45,00,52,00,49,00,43,00,5f,00,\
"\\??\\Volume{da4bcfdb-5b8a-11d9-ba0e-806d6172696f}"=hex:5c,00,3f,00,3f,00,5c,
00,49,00,44,00,45,00,23,00,43,00,64,00,52,00,6f,00,6d,00,48,00,4c,00,2d,00,\
"\\DosDevices\\A:"=hex:5c,00,3f,00,3f,00,5c,00,46,00,44,00,43,00,23,00,47,00,
45,00,4e,00,45,00,52,00,49,00,43,00,5f,00,46,00,4c,00,4f,00,50,00,50,00,59,\
"\\??\\Volume{da4bcfdd-5b8a-11d9-ba0e-806d6172696f}"=hex:21,04,21,04,00,7e,00,
00,00,00,00,00
"\\??\\Volume{2dab15ca-10b4-11db-b103-806d6172696f}"=hex:5c,00,3f,00,3f,00,5c,
00,49,00,44,00,45,00,23,00,43,00,64,00,52,00,6f,00,6d,00,48,00,4c,00,2d,00,\
"\\??\\Volume{a5f4bb56-11b5-11db-b10a-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\??\\Volume{cfc954ee-1298-11db-b10e-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\F:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,53,00,43,00,53,\
"\\??\\Volume{24904c40-12a2-11db-bdc5-806d6172696f}"=hex:21,04,21,04,00,f0,de,
8c,22,00,00,00
"\\DosDevices\\G:"=hex:44,4d,49,4f,3a,49,44,3a,28,e8,52,b7,71,28,a5,4a,ae,32,
b4,c2,ea,e5,96,0f
"\\DosDevices\\D:"=hex:21,04,21,04,00,f0,de,8c,22,00,00,00
"\\DosDevices\\E:"=hex:5c,00,3f,00,3f,00,5c,00,49,00,44,00,45,00,23,00,43,00,
64,00,52,00,6f,00,6d,00,48,00,4c,00,2d,00,44,00,54,00,2d,00,53,00,54,00,5f,\
"\\??\\Volume{70beaf14-1e42-11db-bdeb-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\H:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,54,00,4f,00,52,00,41,00,
47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,76,00,61,00,62,00,6c,00,65,00,4d,\
"\\??\\Volume{69d1bce4-1eeb-11db-9617-806d6172696f}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\I:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,54,00,4f,00,52,00,41,00,
47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,76,00,61,00,62,00,6c,00,65,00,4d,\
"\\??\\Volume{d0fbd5fd-2d1b-11db-9633-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\J:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,47,00,65,00,6e,\
"\\??\\Volume{229bd68e-2d1e-11db-9634-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\K:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,47,00,65,00,6e,\
"\\??\\Volume{229bd68f-2d1e-11db-9634-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\L:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,47,00,65,00,6e,\
"\\??\\Volume{707402be-780a-11db-9743-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\DosDevices\\M:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,53,00,43,00,53,\
"\\??\\Volume{9cf8fbf4-7d83-11db-975a-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{f50d8190-7e53-11db-9761-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{ffdf0afa-7e56-11db-9762-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{ffdf0afb-7e56-11db-9762-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{dc6fa383-8f9f-11db-97a1-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\??\\Volume{dc6fa386-8f9f-11db-97a1-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\N:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,53,00,43,00,53,\
"\\??\\Volume{7cb172c4-978c-11db-97c4-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\O:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,53,00,43,00,53,\
"\\??\\Volume{cc6329a9-9efa-11db-97dd-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\DosDevices\\P:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,54,00,4f,00,52,00,41,00,
47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,76,00,61,00,62,00,6c,00,65,00,4d,\
"\\??\\Volume{9617b388-dafb-11db-988c-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\??\\Volume{df235132-dc92-11db-9898-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{00f2196c-e745-11db-98b9-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{9484c51a-f4c1-11db-98e7-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{a1a75f18-faf5-11db-98fc-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{87549574-41a0-11dc-99e4-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{9f4e1236-8c73-11dc-9a9f-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{a5621da2-a9b0-11dc-9af4-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{10a3ee57-bb01-11dc-9b43-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{5a37773e-c6ac-11dc-9b71-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{6fbc0310-d288-11dc-abeb-806d6172696f}"=hex:a6,06,ef,19,00,7e,00,
00,00,00,00,00
"\\??\\Volume{5e4e5d9e-0889-11dd-acd4-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{7d41f5af-4109-11dd-ad95-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{929aaf67-43ab-11dd-ad9f-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{10b141ce-6af8-11dd-ae17-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{5a8143c3-6d38-11dd-ae1f-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{0738d30c-8a40-11dd-ae66-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{44bcd168-faa9-11dd-afa2-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{d25c7a00-1bb5-11de-b074-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{7e2a2a22-38de-11de-b0fc-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(792)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\cscui.dll

- - - - - - - > 'explorer.exe'(2096)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-06-30 17:56
ComboFix-quarantined-files.txt 2009-06-30 15:55
ComboFix2.txt 2009-06-18 11:57

Pre-Run: 45.194.395.648 bytes free
Post-Run: 45.591.367.680 bytes free

539 --- E O F --- 2009-06-12 07:38
  • 0

#14
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Step #1


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
c:\documents and settings\Decky\Application Data\Mozilla\Firefox\Profiles\be0vk58y.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll

Folder::
c:\program files\Webteh


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.


Step #2

Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.

  • 0

#15
MPoslon

MPoslon

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Hi SpySentinel,

here is the ComboFix.txt:
ComboFix 09-07-02.02 - Decky 03.07.2009 11:20.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.385.1033.18.2047.1504 [GMT 2:00]
Running from: c:\documents and settings\Decky\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Decky\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090630-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
"c:\documents and settings\Decky\Application Data\Mozilla\Firefox\Profiles\be0vk58y.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Decky\Application Data\Mozilla\Firefox\Profiles\be0vk58y.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
c:\program files\Webteh
c:\program files\Webteh\BSplayer\bplay.exe
c:\program files\Webteh\BSplayer\bslib\bslib.dll
c:\program files\Webteh\BSplayer\bslib\BSPMLIB.DAT
c:\program files\Webteh\BSplayer\bslib\BSPMLIB2.DAT
c:\program files\Webteh\BSplayer\bslib\pcnt.dat
c:\program files\Webteh\BSplayer\bspcodecdl.exe
c:\program files\Webteh\BSplayer\bspfilters.sam
c:\program files\Webteh\BSplayer\bsplay.exe
c:\program files\Webteh\BSplayer\bsplayer.exe
c:\program files\Webteh\BSplayer\bsplayer.exe.manifest
c:\program files\Webteh\BSplayer\BSplayer.xml
c:\program files\Webteh\BSplayer\bsplist.bsl
c:\program files\Webteh\BSplayer\bsrendv2.dll
c:\program files\Webteh\BSplayer\changes.txt
c:\program files\Webteh\BSplayer\doc\cmdline.txt
c:\program files\Webteh\BSplayer\doc\ini_files.html
c:\program files\Webteh\BSplayer\EQ.xml
c:\program files\Webteh\BSplayer\insfiles\BSplayer.xml
c:\program files\Webteh\BSplayer\insfiles\BSPMLIB.DAT
c:\program files\Webteh\BSplayer\insfiles\BSPMLIB2.DAT
c:\program files\Webteh\BSplayer\insfiles\EQ.xml
c:\program files\Webteh\BSplayer\lang\Arabic.lng
c:\program files\Webteh\BSplayer\lang\Arabic2.lng
c:\program files\Webteh\BSplayer\lang\Belarusian.lng
c:\program files\Webteh\BSplayer\lang\Bosnian.lng
c:\program files\Webteh\BSplayer\lang\Breton.lng
c:\program files\Webteh\BSplayer\lang\Bulgarian.lng
c:\program files\Webteh\BSplayer\lang\Catalan.lng
c:\program files\Webteh\BSplayer\lang\Chinese_Simplified.lng
c:\program files\Webteh\BSplayer\lang\Chinese_Traditional.lng
c:\program files\Webteh\BSplayer\lang\Croatian.lng
c:\program files\Webteh\BSplayer\lang\Czech.lng
c:\program files\Webteh\BSplayer\lang\Danish.lng
c:\program files\Webteh\BSplayer\lang\Dutch.lng
c:\program files\Webteh\BSplayer\lang\English.lng
c:\program files\Webteh\BSplayer\lang\Esperanto.lng
c:\program files\Webteh\BSplayer\lang\Estonian.lng
c:\program files\Webteh\BSplayer\lang\Finnish.lng
c:\program files\Webteh\BSplayer\lang\French.lng
c:\program files\Webteh\BSplayer\lang\Galician.lng
c:\program files\Webteh\BSplayer\lang\German.lng
c:\program files\Webteh\BSplayer\lang\Greek.lng
c:\program files\Webteh\BSplayer\lang\Hebrew.lng
c:\program files\Webteh\BSplayer\lang\Hungarian.lng
c:\program files\Webteh\BSplayer\lang\Italian.lng
c:\program files\Webteh\BSplayer\lang\lang_changes.txt
c:\program files\Webteh\BSplayer\lang\Latvian.lng
c:\program files\Webteh\BSplayer\lang\Lithuanian.lng
c:\program files\Webteh\BSplayer\lang\Macedonian.lng
c:\program files\Webteh\BSplayer\lang\Norwegian.lng
c:\program files\Webteh\BSplayer\lang\Polish.lng
c:\program files\Webteh\BSplayer\lang\Portuguese.lng
c:\program files\Webteh\BSplayer\lang\Portuguese_Brazilian.lng
c:\program files\Webteh\BSplayer\lang\Romanian.lng
c:\program files\Webteh\BSplayer\lang\Russian.lng
c:\program files\Webteh\BSplayer\lang\Serbian (Cyrillic).lng
c:\program files\Webteh\BSplayer\lang\Serbian (Latin).lng
c:\program files\Webteh\BSplayer\lang\Slovak.lng
c:\program files\Webteh\BSplayer\lang\Slovenian.lng
c:\program files\Webteh\BSplayer\lang\Spanish.lng
c:\program files\Webteh\BSplayer\lang\Swedish.lng
c:\program files\Webteh\BSplayer\lang\Turkish.lng
c:\program files\Webteh\BSplayer\lang\Ukrainian.lng
c:\program files\Webteh\BSplayer\lang\Uzbek.lng
c:\program files\Webteh\BSplayer\lang\Valenciŕ.lng
c:\program files\Webteh\BSplayer\Media\Umek - Posing As Me clip.mp3
c:\program files\Webteh\BSplayer\mmkeybsupp.dll
c:\program files\Webteh\BSplayer\plugins\oldskin.dll
c:\program files\Webteh\BSplayer\sdk\bsp.h
c:\program files\Webteh\BSplayer\sdk\bsp.pas
c:\program files\Webteh\BSplayer\sdk\plugins\bspplg.h
c:\program files\Webteh\BSplayer\sdk\plugins\bspplg.pas
c:\program files\Webteh\BSplayer\sdk\plugins\C\Sample\sample_plugin.def
c:\program files\Webteh\BSplayer\sdk\plugins\C\Sample\sample_plugin.dsp
c:\program files\Webteh\BSplayer\sdk\plugins\C\Sample\sample_plugin.dsw
c:\program files\Webteh\BSplayer\sdk\plugins\C\Sample\sampleplugin.c
c:\program files\Webteh\BSplayer\sdk\plugins\C\sample_subtitles\sample_sub.c
c:\program files\Webteh\BSplayer\sdk\plugins\C\sample_subtitles\sample_sub.def
c:\program files\Webteh\BSplayer\sdk\plugins\C\sample_subtitles\sample_subtitles.dsp
c:\program files\Webteh\BSplayer\sdk\plugins\C\sample_subtitles\sample_subtitles.dsw
c:\program files\Webteh\BSplayer\sdk\plugins\Delphi\sample\sample_plugin.dpr
c:\program files\Webteh\BSplayer\sdk\plugins\Delphi\sample_subtitles\sample_sub.dpr
c:\program files\Webteh\BSplayer\sg.ico
c:\program files\Webteh\BSplayer\Skins\Base\actaspbg.bmp
c:\program files\Webteh\BSplayer\Skins\Base\actsubbg.bmp
c:\program files\Webteh\BSplayer\Skins\Base\actsubpbg.bmp
c:\program files\Webteh\BSplayer\Skins\Base\actvolbg.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b1n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b1u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b2n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b2u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b3a.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b3d.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b3n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b3u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b4a.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b4d.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b4n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b4u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b5a.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b5d.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b5n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b5u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b6n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b7n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b8.bmp
c:\program files\Webteh\BSplayer\Skins\Base\b8n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\balbtnn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\btn_dn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\btn_ln.bmp
c:\program files\Webteh\BSplayer\Skins\Base\btn_rn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\btn_un.bmp
c:\program files\Webteh\BSplayer\Skins\Base\btncolorn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\btngrp1bg.bmp
c:\program files\Webteh\BSplayer\Skins\Base\btnmenun.bmp
c:\program files\Webteh\BSplayer\Skins\Base\btnmenuu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\eq.ini
c:\program files\Webteh\BSplayer\Skins\Base\eqbtn1a.bmp
c:\program files\Webteh\BSplayer\Skins\Base\eqbtn1n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\eqbtn2n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\eqbtn2u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\eqbtnn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\eqmain.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exabtn1n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exabtn1u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exabtn2n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exabtn2u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exabtn3n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exabtn3u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exabtn4n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exabtn4u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exaudioa.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exaudion.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exaudiou.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exdbtn1n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exdbtn1u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exdbtn2n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exdbtn2u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exdbtn3n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exdbtn3u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exdbtn4n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exdbtn4u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exdvda.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exdvdn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exdvdu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exitn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exitu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exradioa.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exradion.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exradiou.bmp
c:\program files\Webteh\BSplayer\Skins\Base\extbg.bmp
c:\program files\Webteh\BSplayer\Skins\Base\extva.bmp
c:\program files\Webteh\BSplayer\Skins\Base\extvn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\extvu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvbtn1a.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvbtn1n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvbtn2n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvbtn2u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvbtn3n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvbtn3u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvbtn4n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvbtn4u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvbtn5n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvbtn5u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvbtn6n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvbtn6u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvbtn7n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvbtn7u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvbtn8n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvbtn8u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvideoa.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvideon.bmp
c:\program files\Webteh\BSplayer\Skins\Base\exvideou.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsactbg.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsb1d.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsb1n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsb1u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsb2d.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsb2n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsb2u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsb3d.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsb3n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsb3u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsb4d.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsb4n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsb4u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsb5d.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsb5n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsb5u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsmain.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsn.BMP
c:\program files\Webteh\BSplayer\Skins\Base\fsnextd.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsnextn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsnextu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsopend.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsopenn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsopenu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fspaused.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fspausen.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fspauseu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsplayd.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsplayn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsplayu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsprevd.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsprevn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsprevu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsseek.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsseeku.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsstopd.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsstopn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsstopu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\fsu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\grp2.bmp
c:\program files\Webteh\BSplayer\Skins\Base\main.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\arr2n.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\arr2u.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\arrn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\arru.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\audiosec.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\audiosec_big.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\bgmedia.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\bottomsec.ini
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnaddn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnaddpln.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnclosed.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnclosen.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btncloseu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnmaxd.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnmaxn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnmaxu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnmind.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnminn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnminu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnnextd.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnnextn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnnextu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnpaused.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnpausen.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnpauseu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnplayd.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnplayn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnplayu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnprevd.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnprevn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnprevu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnrefresha.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnrefreshn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnrepa.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnrepn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnrestd.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnrestn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnrestu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnshufa.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\btnshufn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\busy.mng
c:\program files\Webteh\BSplayer\Skins\Base\medialib\ctrlsimg.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\dvdsec.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\dvdsec_big.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\edb.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\ede.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\img_bar1.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\ltbm.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\main.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\media_tv_sep_top.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\ml_adddn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\ml_adddu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\ml_addfln.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\ml_addflu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\ml_addfn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\ml_addfu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\ml_addln.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\ml_addlu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\ml_pausen.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\ml_pauseu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\ml_playn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\ml_playu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\ml_refrn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\ml_refru.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\ml_video_defaultbg.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\othersec.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\pic_place.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\podsec.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\podsec_big.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\radiosec.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\radiosec_big.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\searchbtn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\seek.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\seekbg.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\seekbtnd.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\seekbtnn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\seekbtnu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\skin.ini
c:\program files\Webteh\BSplayer\Skins\Base\medialib\thumbaudio.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\thumbbg.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\thumbbga.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\tvsec.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\tvsec_big.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\videosec.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\videosec_big.bmp
c:\program files\Webteh\BSplayer\Skins\Base\medialib\volume.bmp
c:\program files\Webteh\BSplayer\Skins\Base\minimizen.bmp
c:\program files\Webteh\BSplayer\Skins\Base\minimizeu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\mutea.bmp
c:\program files\Webteh\BSplayer\Skins\Base\muted.bmp
c:\program files\Webteh\BSplayer\Skins\Base\muten.bmp
c:\program files\Webteh\BSplayer\Skins\Base\muteu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\nextd.bmp
c:\program files\Webteh\BSplayer\Skins\Base\nextn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\nextu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\opend.bmp
c:\program files\Webteh\BSplayer\Skins\Base\openn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\openu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\paused.bmp
c:\program files\Webteh\BSplayer\Skins\Base\pausen.bmp
c:\program files\Webteh\BSplayer\Skins\Base\pauseu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\playd.bmp
c:\program files\Webteh\BSplayer\Skins\Base\playn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\playu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\plist.ini
c:\program files\Webteh\BSplayer\Skins\Base\prevd.bmp
c:\program files\Webteh\BSplayer\Skins\Base\prevn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\prevu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\rgn.dat
c:\program files\Webteh\BSplayer\Skins\Base\rgnfs.dat
c:\program files\Webteh\BSplayer\Skins\Base\seek.bmp
c:\program files\Webteh\BSplayer\Skins\Base\seeku.bmp
c:\program files\Webteh\BSplayer\Skins\Base\skin.ini
c:\program files\Webteh\BSplayer\Skins\Base\skinfs.ini
c:\program files\Webteh\BSplayer\Skins\Base\sm_closed.bmp
c:\program files\Webteh\BSplayer\Skins\Base\sm_closen.bmp
c:\program files\Webteh\BSplayer\Skins\Base\sm_closeu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\sm_maxd.bmp
c:\program files\Webteh\BSplayer\Skins\Base\sm_maxn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\sm_maxu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\sm_mind.bmp
c:\program files\Webteh\BSplayer\Skins\Base\sm_minn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\sm_minu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\smenud.bmp
c:\program files\Webteh\BSplayer\Skins\Base\smenun.bmp
c:\program files\Webteh\BSplayer\Skins\Base\smenuu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\stopd.bmp
c:\program files\Webteh\BSplayer\Skins\Base\stopn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\stopu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\voldd.bmp
c:\program files\Webteh\BSplayer\Skins\Base\voldn.bmp
c:\program files\Webteh\BSplayer\Skins\Base\voldu.bmp
c:\program files\Webteh\BSplayer\Skins\Base\volud.bmp
c:\program files\Webteh\BSplayer\Skins\Base\volume.bmp
c:\program files\Webteh\BSplayer\Skins\Base\volun.bmp
c:\program files\Webteh\BSplayer\Skins\Base\voluu.bmp
c:\program files\Webteh\BSplayer\Skins\Bat lite.bsz
c:\program files\Webteh\BSplayer\Skins\BSplayer.v1.bsz
c:\program files\Webteh\BSplayer\Skins\mediaBOX v-1.bsz
c:\program files\Webteh\BSplayer\Skins\MediaBOX V-2.bsz
c:\program files\Webteh\BSplayer\subt.ico
c:\program files\Webteh\BSplayer\uninstall.EXE
c:\windows\Installer\7b200.msi

.
((((((((((((((((((((((((( Files Created from 2009-06-03 to 2009-07-03 )))))))))))))))))))))))))))))))
.

2009-06-30 15:00 . 2008-09-16 19:23 168448 ----a-w- c:\windows\system32\unrar.dll
2009-06-30 15:00 . 2004-05-18 18:16 39936 ----a-w- c:\windows\system32\huffyuv.dll
2009-06-30 15:00 . 2006-04-02 12:47 630784 ----a-w- c:\windows\system32\vp7vfw.dll
2009-06-30 15:00 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2009-06-30 15:00 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2009-06-30 15:00 . 2009-05-01 21:02 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-06-30 15:00 . 2008-11-06 16:37 3596288 ----a-w- c:\windows\system32\qt-dx331.dll
2009-06-30 14:59 . 2009-06-02 16:11 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-06-30 14:59 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\divx.dll
2009-06-30 14:59 . 2009-06-30 15:00 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-06-27 12:22 . 2009-06-27 12:22 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-25 10:18 . 2009-06-25 10:18 279712 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-06-25 10:18 . 2009-06-25 10:18 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2009-06-25 07:33 . 2009-02-12 09:35 38208 ----a-w- c:\documents and settings\Decky\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-06-25 07:33 . 2009-06-25 07:33 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-06-25 07:32 . 2009-06-25 07:32 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-06-25 07:32 . 2009-06-25 07:32 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-06-25 07:32 . 2009-06-25 07:32 -------- d-----w- c:\program files\NOS
2009-06-25 07:32 . 2009-06-04 08:53 22848 ----a-w- c:\documents and settings\Decky\Application Data\Mozilla\Firefox\Profiles\be0vk58y.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-06-25 07:32 . 2009-06-04 08:53 18776 ----a-w- c:\documents and settings\Decky\Application Data\Mozilla\Firefox\Profiles\be0vk58y.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-06-24 10:06 . 2009-06-24 10:06 -------- d-----w- C:\rsit
2009-06-19 07:35 . 2009-06-30 15:59 117760 ----a-w- c:\documents and settings\Decky\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-19 07:34 . 2009-06-19 07:34 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-19 07:34 . 2009-06-25 08:03 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-06-19 07:34 . 2009-06-19 07:34 -------- d-----w- c:\documents and settings\Decky\Application Data\SUPERAntiSpyware.com
2009-06-18 18:33 . 2009-06-25 11:49 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-18 17:02 . 2009-06-25 11:35 -------- d-----w- c:\documents and settings\Decky\Local Settings\Application Data\Rockstar Games
2009-06-18 16:54 . 2009-06-18 16:54 -------- d-----w- c:\windows\system32\xlive
2009-06-18 16:54 . 2009-06-18 17:13 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2009-06-14 17:58 . 2009-06-14 17:58 -------- d-----w- C:\Rooter$
2009-06-14 17:43 . 2009-06-14 17:43 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-06-04 20:17 . 2009-06-04 20:09 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-04 20:09 . 2009-06-04 20:08 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-04 20:09 . 2009-06-04 20:09 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-06-04 20:08 . 2009-06-29 20:16 84832 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-06-04 20:08 . 2009-06-29 20:15 246128 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-06-04 20:08 . 2009-06-29 20:15 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-06-04 20:08 . 2009-06-04 20:08 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-06-04 20:02 . 2009-06-04 20:02 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-04 20:02 . 2009-03-12 08:17 2902048 -c--a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-04 18:49 . 2009-06-04 18:49 -------- d-----w- c:\documents and settings\Decky\Application Data\Malwarebytes
2009-06-04 18:49 . 2009-06-17 09:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-04 18:49 . 2009-06-04 18:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-04 18:49 . 2009-06-27 12:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-04 18:49 . 2009-06-17 09:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-04 18:46 . 2009-06-04 18:46 -------- d-----w- c:\program files\ERUNT
2009-06-04 17:57 . 2009-06-04 17:57 -------- d-----w- c:\program files\Trend Micro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-03 07:39 . 2009-03-21 08:40 -------- d-----w- c:\program files\Steam
2009-07-02 09:13 . 2008-02-02 19:28 -------- d-----w- c:\documents and settings\Decky\Application Data\FrostWire
2009-06-30 14:56 . 2006-07-12 11:54 -------- d-----w- c:\program files\ffdshow
2009-06-29 20:16 . 2009-06-18 20:09 314712 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-06-29 20:16 . 2009-06-18 20:09 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-06-29 20:16 . 2009-06-18 20:09 169312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-06-29 20:16 . 2009-06-18 20:09 348496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-06-29 20:16 . 2009-06-18 20:09 298336 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-06-29 20:16 . 2009-06-18 20:09 1630560 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-06-29 20:15 . 2009-06-18 20:09 85352 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\AAWDriverTool.exe
2009-06-29 20:15 . 2009-06-18 20:09 664424 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-06-29 19:44 . 2008-02-02 19:28 -------- d-----w- c:\program files\FrostWire
2009-06-28 21:03 . 2008-02-18 16:29 1392576 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-06-25 16:57 . 2006-07-11 08:09 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-25 08:05 . 2009-01-16 14:21 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-25 08:04 . 2008-01-15 20:22 -------- d-----w- c:\program files\Java
2009-06-25 07:35 . 2006-07-11 08:45 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-19 07:34 . 2006-09-19 21:17 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-18 20:09 . 2009-06-18 20:09 561016 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-06-18 20:09 . 2009-06-18 20:09 565096 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-06-18 20:09 . 2009-06-18 20:09 2349384 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-06-18 20:09 . 2009-06-18 20:09 627536 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-06-18 20:09 . 2009-06-18 20:09 518488 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-06-18 20:09 . 2009-06-18 20:09 1003344 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-06-10 18:05 . 2007-04-11 21:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Test Drive Unlimited
2009-06-04 20:11 . 2008-01-11 13:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-04 19:40 . 2008-01-11 13:18 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-05-15 17:11 . 2009-05-15 17:11 2311 ----a-w- c:\documents and settings\All Users\Application Data\xml92.tmp
2009-05-15 17:11 . 2009-05-15 17:11 13257 ----a-w- c:\documents and settings\All Users\Application Data\xml91.tmp
2009-05-15 17:11 . 2009-05-15 17:11 7890 ----a-w- c:\documents and settings\All Users\Application Data\xml90.tmp
2009-05-07 15:32 . 2004-08-04 07:56 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-06 12:23 . 2009-05-07 18:59 372736 ----a-w- c:\documents and settings\Decky\Application Data\Mozilla\Firefox\Profiles\be0vk58y.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
2009-05-03 10:28 . 2009-05-03 10:28 10134 ----a-r- c:\documents and settings\Decky\Application Data\Microsoft\Installer\{657201DD-30C8-4E50-88AD-164B3812E8F5}\_D578AC58F14BD73AA16534.exe
2009-05-03 10:28 . 2009-05-03 10:28 10134 ----a-r- c:\documents and settings\Decky\Application Data\Microsoft\Installer\{657201DD-30C8-4E50-88AD-164B3812E8F5}\_1BC1E915D9D4E09E0D35C7.exe
2009-05-03 10:28 . 2009-05-03 10:28 10134 ----a-r- c:\documents and settings\Decky\Application Data\Microsoft\Installer\{657201DD-30C8-4E50-88AD-164B3812E8F5}\_11054A45FAD4581FFD16AF.exe
2009-05-01 09:11 . 2009-05-01 09:11 8586 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2009-04-29 04:56 . 2004-08-04 07:56 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-21 22:20 . 2009-04-21 22:20 14311680 ----a-w- c:\windows\system32\xlive.dll
2009-04-21 22:20 . 2009-04-21 22:20 13642496 ----a-w- c:\windows\system32\xlivefnt.dll
2009-04-17 12:26 . 2004-08-04 06:17 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-04 07:56 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-09 10:26 . 2009-04-09 10:26 152576 ----a-w- c:\documents and settings\Decky\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-05 17:37 . 2006-07-11 10:25 68224 ----a-w- c:\documents and settings\Decky\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2004-10-01 13:00 . 2006-07-11 08:40 40960 ----a-w- c:\program files\Uninstall_CDS.exe
2006-05-03 09:06 . 2007-11-30 14:44 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2007-11-30 14:44 31232 --sh--r- c:\windows\system32\msfDX.dll
2007-12-17 12:43 . 2008-04-09 07:33 27648 --sh--w- c:\windows\system32\Smab0.dll
.

((((((((((((((((((((((((((((( SnapShot_2009-06-30_15.54.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-03 07:40 . 2009-07-03 07:40 16384 c:\windows\Temp\Perflib_Perfdata_9b0.dat
+ 2009-07-03 07:40 . 2009-07-03 07:40 16384 c:\windows\Temp\Perflib_Perfdata_8e4.dat
+ 2009-07-03 07:39 . 2009-07-03 07:39 16384 c:\windows\Temp\Perflib_Perfdata_5e0.dat
+ 2008-01-13 12:16 . 2008-01-13 12:16 55296 c:\windows\Installer\ebafa6.msi
+ 2008-02-18 16:36 . 2008-02-18 16:36 48128 c:\windows\Installer\79c72b.msi
+ 2008-02-18 16:33 . 2008-02-18 16:33 37888 c:\windows\Installer\79c719.msi
+ 2009-06-25 07:33 . 2009-06-25 07:33 20480 c:\windows\Installer\276bf8.msi
+ 2009-06-25 07:33 . 2009-06-25 07:33 26624 c:\windows\Installer\276bf1.msi
+ 2008-05-30 06:50 . 2007-04-02 22:04 366080 c:\windows\ServicePackFiles\i386\digreqex.msi
+ 2008-05-30 06:50 . 2007-04-02 22:04 863232 c:\windows\ServicePackFiles\i386\digopt.msi
+ 2006-10-30 03:04 . 2006-10-30 03:04 557056 c:\windows\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\vs_setup.msi
+ 2009-04-05 11:20 . 2009-04-05 11:20 355328 c:\windows\Installer\ac5818.msi
+ 2009-05-01 09:21 . 2009-05-01 09:21 450048 c:\windows\Installer\a6af6a.msi
+ 2006-07-11 08:44 . 2006-07-11 08:44 322560 c:\windows\Installer\819ed.msi
+ 2008-02-18 16:37 . 2008-02-18 16:37 431104 c:\windows\Installer\79c73e.msi
+ 2008-02-18 16:37 . 2008-02-18 16:37 871424 c:\windows\Installer\79c732.msi
+ 2008-02-18 16:29 . 2008-02-18 16:29 454144 c:\windows\Installer\79c713.msi
+ 2008-02-18 16:29 . 2008-02-18 16:29 472576 c:\windows\Installer\79c70d.msi
+ 2008-02-18 16:27 . 2008-02-18 16:27 525824 c:\windows\Installer\79c701.msi
+ 2008-02-18 16:20 . 2008-02-18 16:20 272384 c:\windows\Installer\735cf3.msi
+ 2008-02-18 16:19 . 2008-02-18 16:19 916480 c:\windows\Installer\735cea.msi
+ 2007-12-01 19:30 . 2007-12-01 19:30 431104 c:\windows\Installer\6aaff6.msi
+ 2006-11-05 17:53 . 2006-11-05 17:53 537600 c:\windows\Installer\59929.msi
+ 2008-03-26 21:01 . 2008-03-26 21:01 467968 c:\windows\Installer\5759a.msi
+ 2008-02-12 18:20 . 2008-02-12 18:20 470528 c:\windows\Installer\3c9b66.msi
+ 2009-06-04 20:02 . 2009-06-04 20:02 236032 c:\windows\Installer\3b6a1e.msi
+ 2008-02-03 19:31 . 2008-02-03 19:31 331264 c:\windows\Installer\3a4f2.msi
+ 2008-08-24 21:04 . 2008-08-24 21:04 186368 c:\windows\Installer\3305642.msi
+ 2008-07-08 05:12 . 2008-07-08 05:12 690688 c:\windows\Installer\2fdeb.msi
+ 2008-05-30 06:58 . 2008-05-30 06:58 804864 c:\windows\Installer\2e91c.msi
+ 2008-07-22 10:53 . 2008-07-22 10:53 314880 c:\windows\Installer\2cc95.msp
+ 2007-12-15 21:16 . 2007-12-15 21:16 816128 c:\windows\Installer\295b1.msi
+ 2008-01-23 14:50 . 2008-01-23 14:50 579072 c:\windows\Installer\2936c.msp
+ 2008-07-28 12:38 . 2008-07-28 12:38 102912 c:\windows\Installer\29357.msp
+ 2009-06-18 17:13 . 2009-06-18 17:13 824832 c:\windows\Installer\272274.msi
+ 2009-06-18 17:12 . 2009-06-18 17:12 846336 c:\windows\Installer\272268.msi
+ 2006-07-27 16:21 . 2006-07-27 16:21 350208 c:\windows\Installer\23fe8c.msi
+ 2008-11-14 06:51 . 2008-11-14 06:51 432640 c:\windows\Installer\23d82.msi
+ 2009-03-06 07:30 . 2009-03-06 07:30 140288 c:\windows\Installer\1f7b6.msi
+ 2009-05-03 10:28 . 2009-05-03 10:28 372224 c:\windows\Installer\1ed2d1.msi
+ 2006-07-12 14:46 . 2006-07-12 14:46 961536 c:\windows\Installer\1d02983.msi
+ 2008-03-26 21:21 . 2008-03-26 21:21 891904 c:\windows\Installer\1699fc.msi
+ 2008-03-26 21:19 . 2008-03-26 21:19 279040 c:\windows\Installer\1699ec.msi
+ 2007-07-09 13:29 . 2007-07-09 13:29 173568 c:\windows\Installer\147ac8d.msi
+ 2008-09-13 22:52 . 2008-09-13 22:52 216576 c:\windows\Installer\11463f0.msi
+ 2005-08-04 09:42 . 2005-08-04 09:42 106496 c:\windows\Downloaded Installations\Macromedia Contribute 3.11\CT_3.1.1_PatchPackage.msp
+ 2005-08-04 09:41 . 2005-08-04 09:41 106496 c:\windows\Downloaded Installations\Macromedia Contribute 3.11\CT_3.0.1_PatchPackage.msp
+ 2006-07-29 05:52 . 2006-07-29 10:16 829952 c:\windows\Downloaded Installations\DAEMON Tools 3.47\daemon.msi
+ 2007-12-15 21:15 . 2007-12-15 21:15 860672 c:\windows\Downloaded Installations\{B377E244-6468-4BE8-B422-0893C67F9C6C}\Dual-Core Optimizer.msi
+ 2004-07-17 18:35 . 2004-07-17 18:35 1326080 c:\windows\system32\webfldrs.msi
+ 2008-05-30 06:49 . 2007-01-01 18:14 1326080 c:\windows\ServicePackFiles\i386\webfldrs.msi
+ 2008-05-30 06:49 . 2007-04-02 22:12 5080576 c:\windows\ServicePackFiles\i386\msnmsgs.msi
+ 2006-10-30 03:05 . 2006-10-30 03:05 2723840 c:\windows\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\WF_3.0_x86.msi
+ 2008-02-18 16:26 . 2008-02-18 16:26 8044544 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\wcf.msi
+ 2007-05-25 11:08 . 2007-05-25 11:08 9609728 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp
+ 2006-10-11 15:53 . 2006-10-11 15:53 5548032 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M925168\M925168Uninstall.msp
+ 2007-08-30 14:55 . 2007-08-30 14:55 3563520 c:\windows\Installer\fcfaf9.msi
+ 2006-07-23 16:59 . 2006-07-23 16:59 2404352 c:\windows\Installer\f9ab5.msi
+ 2006-07-12 10:49 . 2006-07-12 10:49 5812736 c:\windows\Installer\f76d5c.msi
+ 2009-03-05 13:40 . 2009-03-05 13:40 6819840 c:\windows\Installer\f61748.msp
+ 2007-11-14 20:54 . 2007-11-14 20:54 1285632 c:\windows\Installer\ebafad.msp
+ 2007-08-29 18:26 . 2007-08-29 18:26 8448512 c:\windows\Installer\d415b.msi
+ 2007-08-29 18:21 . 2007-08-29 18:21 4337664 c:\windows\Installer\d4154.msi
+ 2009-01-06 09:12 . 2009-01-06 09:12 9190400 c:\windows\Installer\d16b8.msi
+ 2007-01-08 09:44 . 2007-01-08 09:44 3443712 c:\windows\Installer\a4fb8.msi
+ 2007-08-31 12:14 . 2007-08-31 12:14 2077184 c:\windows\Installer\a428a0.msi
+ 2007-09-04 13:58 . 2007-09-04 13:58 2512384 c:\windows\Installer\80c84.msi
+ 2007-04-09 16:50 . 2007-04-09 16:50 7034368 c:\windows\Installer\79c721.msp
+ 2008-02-18 16:27 . 2008-02-18 16:27 1142784 c:\windows\Installer\79c707.msi
+ 2009-06-19 07:34 . 2009-06-19 07:34 1516544 c:\windows\Installer\77967.msi
+ 2008-02-18 16:25 . 2008-02-18 16:25 2109440 c:\windows\Installer\7737fb.msi
+ 2006-08-17 09:59 . 2006-08-17 09:59 5403136 c:\windows\Installer\714ae1.msi
+ 2009-03-10 17:30 . 2009-03-10 17:30 1828352 c:\windows\Installer\66b7cd.msi
+ 2008-01-04 20:12 . 2008-01-04 20:12 5893120 c:\windows\Installer\6075c.msi
+ 2006-11-05 17:53 . 2006-11-05 17:53 1453568 c:\windows\Installer\59935.msi
+ 2006-11-05 17:53 . 2006-11-05 17:53 1868800 c:\windows\Installer\5992f.msi
+ 2006-11-05 17:49 . 2006-11-05 17:49 5091840 c:\windows\Installer\5991e.msi
+ 2009-06-25 08:05 . 2009-06-25 08:05 1563648 c:\windows\Installer\4ccf4.msi
+ 2008-12-12 10:09 . 2008-12-12 10:09 5517824 c:\windows\Installer\46794.msp
+ 2009-02-11 14:02 . 2009-02-11 14:02 5519872 c:\windows\Installer\406d7.msp
+ 2009-05-01 13:49 . 2009-05-01 13:49 4328960 c:\windows\Installer\3cab4.msp
+ 2009-04-24 10:31 . 2009-04-24 10:31 1425920 c:\windows\Installer\3ca9d.msp
+ 2009-06-04 20:02 . 2009-06-04 20:02 1802240 c:\windows\Installer\3b6a25.msi
+ 2008-02-03 19:38 . 2008-02-03 19:38 3378176 c:\windows\Installer\3a4ff.msi
+ 2009-05-04 05:46 . 2009-05-04 05:46 8299008 c:\windows\Installer\390c4.msp
+ 2009-05-12 11:01 . 2009-05-12 11:01 6818816 c:\windows\Installer\390b9.msp
+ 2009-04-24 10:30 . 2009-04-24 10:30 2583552 c:\windows\Installer\390a2.msp
+ 2009-05-28 10:32 . 2009-05-28 10:32 5518848 c:\windows\Installer\39096.msp
+ 2006-07-13 18:54 . 2006-07-13 18:54 2262016 c:\windows\Installer\3908fa.msi
+ 2009-04-23 15:57 . 2009-04-23 15:57 7672832 c:\windows\Installer\3907f.msp
+ 2009-01-14 14:43 . 2009-01-14 14:43 5520384 c:\windows\Installer\37f96.msp
+ 2008-06-26 08:33 . 2008-06-26 08:33 8984576 c:\windows\Installer\37741a.msi
+ 2008-08-14 13:01 . 2008-08-14 13:01 5517312 c:\windows\Installer\34694.msp
+ 2008-06-10 12:09 . 2008-06-10 12:09 5517312 c:\windows\Installer\3094c.msp
+ 2005-10-26 12:59 . 2005-10-26 12:59 2883072 c:\windows\Installer\2fe35.msp
+ 2008-05-15 07:50 . 2008-05-15 07:50 5515776 c:\windows\Installer\2fe1f.msp
+ 2008-03-25 14:31 . 2008-03-25 14:31 3002880 c:\windows\Installer\2fe09.msp
+ 2008-06-30 17:45 . 2008-06-30 17:45 4753408 c:\windows\Installer\2ef5e.msp
+ 2008-10-22 21:43 . 2008-10-22 21:43 6820352 c:\windows\Installer\2ed07.msp
+ 2008-10-22 21:48 . 2008-10-22 21:48 7672832 c:\windows\Installer\2ecf1.msp
+ 2008-11-05 13:25 . 2008-11-05 13:25 5518336 c:\windows\Installer\2ecdb.msp
+ 2008-07-16 08:39 . 2008-07-16 08:39 5519360 c:\windows\Installer\2bdfb.msp
+ 2008-06-11 13:05 . 2008-06-11 13:05 9994240 c:\windows\Installer\29428.msp
+ 2008-04-01 12:33 . 2008-04-01 12:33 5479936 c:\windows\Installer\293f8.msp
+ 2008-01-31 08:30 . 2008-01-31 08:30 9947648 c:\windows\Installer\293c9.msp
+ 2008-01-14 14:53 . 2008-01-14 14:53 5213696 c:\windows\Installer\293ac.msp
+ 2008-07-08 09:27 . 2008-07-08 09:27 8436736 c:\windows\Installer\29382.msp
+ 2009-04-06 15:00 . 2009-04-06 15:00 5518336 c:\windows\Installer\279af.msp
+ 2009-06-25 07:36 . 2009-06-25 07:36 3938816 c:\windows\Installer\276d34.msi
+ 2008-10-25 08:15 . 2008-10-25 08:15 6227456 c:\windows\Installer\23dad.msp
+ 2008-10-17 08:03 . 2008-10-17 08:03 5518336 c:\windows\Installer\23d97.msp
+ 2009-01-15 02:35 . 2009-01-15 02:35 4830720 c:\windows\Installer\225b4.msp
+ 2008-09-05 11:08 . 2008-09-05 11:08 5515776 c:\windows\Installer\221fa.msp
+ 2008-06-19 16:28 . 2008-06-19 16:28 1573376 c:\windows\Installer\21bb5.msp
+ 2008-10-20 08:18 . 2008-10-20 08:18 6474240 c:\windows\Installer\21b85.msp
+ 2008-10-05 02:12 . 2008-10-05 02:12 4784128 c:\windows\Installer\20a5c.msp
+ 2006-09-17 10:24 . 2006-09-17 10:24 3417600 c:\windows\Installer\203d84.msi
+ 2007-07-09 14:26 . 2007-07-09 14:26 9292800 c:\windows\Installer\1eb9b.msi
+ 2009-04-28 20:33 . 2009-04-28 20:33 1500160 c:\windows\Installer\1dd68.msi
+ 2007-12-25 10:44 . 2007-12-25 10:44 2080768 c:\windows\Installer\1c195f.msi
+ 2009-03-21 08:40 . 2009-03-21 08:40 1100288 c:\windows\Installer\1a6ebc.msi
+ 2008-03-26 21:21 . 2008-03-26 21:21 1105920 c:\windows\Installer\1699f6.msi
+ 2008-11-22 15:48 . 2008-11-22 15:48 6695936 c:\windows\Installer\1657da6.msi
+ 2007-07-09 13:30 . 2007-07-09 13:30 9408000 c:\windows\Installer\147ac8e.msi
+ 2008-06-04 15:01 . 2008-06-04 15:01 4752896 c:\windows\Installer\13afce.msp
+ 2008-06-26 12:37 . 2008-06-26 12:37 1298432 c:\windows\Installer\13afc5.msp
+ 2008-08-27 06:32 . 2008-08-27 06:32 1549312 c:\windows\Installer\1224f5.msi
+ 2008-06-01 13:19 . 2008-06-01 13:19 1395712 c:\windows\Installer\10badf4.msi
+ 2008-02-18 16:19 . 2008-02-18 16:19 1863168 c:\windows\Downloaded Installations\{780E5BBE-E9D9-4FC4-AB21-4E86CE8FD10D}\HMTCDWizard.msi
+ 2006-10-30 03:05 . 2006-10-30 03:05 11390464 c:\windows\Microsoft.NET\Framework\v3.0\WPF\wpf.msi
+ 2008-02-18 16:24 . 2008-02-18 16:24 24863744 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\netfx.msi
+ 2008-01-11 10:15 . 2007-01-19 12:20 16667136 c:\windows\Installer\MSN Messenger 8.1.0178\MsnMsgs.Msi
+ 2007-08-30 14:56 . 2007-08-30 14:56 23867392 c:\windows\Installer\fcfb09.msi
+ 2009-02-25 17:07 . 2009-02-25 17:07 11646464 c:\windows\Installer\f61751.msp
+ 2007-08-29 18:22 . 2007-08-29 18:22 12388864 c:\windows\Installer\d4157.msi
+ 2007-01-08 09:45 . 2007-01-08 09:45 19210240 c:\windows\Installer\a5002.msp
+ 2008-01-20 13:18 . 2008-01-20 13:18 13896704 c:\windows\Installer\7d6af.msi
+ 2008-01-04 20:10 . 2008-01-04 20:10 18848256 c:\windows\Installer\60752.msi
+ 2007-05-29 13:41 . 2007-05-29 13:41 16549888 c:\windows\Installer\5dce2.msp
+ 2008-02-12 18:21 . 2008-02-12 18:21 15256576 c:\windows\Installer\3c9b7d.msp
+ 2008-07-30 06:50 . 2008-07-30 06:50 12506112 c:\windows\Installer\346c0.msp
+ 2008-06-04 11:29 . 2008-06-04 11:29 16905728 c:\windows\Installer\346aa.msp
+ 2008-07-08 08:09 . 2008-07-08 08:09 11887616 c:\windows\Installer\2940e.msp
+ 2008-02-29 20:09 . 2008-02-29 20:09 16907776 c:\windows\Installer\293df.msp
+ 2008-01-14 13:24 . 2008-01-14 13:24 10721280 c:\windows\Installer\29397.msp
+ 2008-07-01 07:25 . 2008-07-01 07:25 11814912 c:\windows\Installer\29342.msp
+ 2008-08-13 12:49 . 2008-08-13 12:49 11816960 c:\windows\Installer\22210.msp
+ 2007-10-14 21:43 . 2007-10-14 21:43 12743168 c:\windows\Installer\21ceb.msp
+ 2008-10-20 08:22 . 2008-10-20 08:22 11758592 c:\windows\Installer\21bc7.msp
+ 2008-08-11 09:51 . 2008-08-11 09:51 15916544 c:\windows\Installer\21bbe.msp
+ 2008-08-11 09:49 . 2008-08-11 09:49 22457344 c:\windows\Installer\21bab.msp
+ 2008-09-24 10:05 . 2008-09-24 10:05 16381440 c:\windows\Installer\21ba2.msp
+ 2007-10-14 21:33 . 2007-10-14 21:33 26646016 c:\windows\Installer\21b9a.msp
+ 2008-07-15 13:19 . 2008-07-15 13:19 14385664 c:\windows\Installer\14b9bad.msi
+ 2007-08-30 15:25 . 2007-08-30 15:25 10284544 c:\windows\Installer\115f2d1.msi
+ 2008-01-11 17:48 . 2008-01-11 17:48 10493440 c:\windows\Installer\{EA618858-FCF5-4A85-9BE4-460EAF2457CE}\Diskeeper 2008 Pro Premier.msi
+ 2005-08-31 02:31 . 2005-08-31 02:31 23870464 c:\windows\Downloaded Installations\Macromedia Flash 8\Macromedia Flash 8.msi
+ 2005-08-24 10:26 . 2005-08-24 10:26 98656256 c:\windows\Downloaded Installations\Macromedia Fireworks 8\Macromedia Fireworks 8.msi
+ 2005-08-30 14:18 . 2005-08-30 14:18 68164096 c:\windows\Downloaded Installations\Macromedia Dreamweaver 8\Macromedia_Dreamweaver_8.msi
+ 2005-08-18 11:17 . 2005-08-18 11:17 43748352 c:\windows\Downloaded Installations\Macromedia Contribute 3.11\Macromedia_Contribute_3.11.msi
+ 2007-08-30 15:23 . 2007-08-30 15:22 45819904 c:\windows\Downloaded Installations\{FA5E3F28-D414-42A3-BC5C-C1C8858368E6}\Macromedia Captivate.msi
+ 2007-08-30 15:28 . 2007-09-04 13:57 51823104 c:\windows\Downloaded Installations\{F25CA4B4-F767-4C74-9D16-CAB291A26EF9}\Macromedia Captivate.msi
+ 2007-01-08 09:27 . 2008-01-04 20:08 48458980 c:\windows\Downloaded Installations\{E2A3BA4B-E704-42B6-AB10-8251332323E2}\Sony Ericsson PC Suite 1.20.173.msi
+ 2007-01-08 09:28 . 2008-01-04 20:08 48458980 c:\windows\Downloaded Installations\{C5ADA65A-7828-4D85-B071-ECC52B51F794}\Sony Ericsson PC Suite 1.20.173.msi
+ 2007-08-30 14:58 . 2007-09-04 14:21 15198720 c:\windows\Downloaded Installations\{803B5463-FB05-4A07-8A82-38F4C27EDD26}\Macromedia FlashPaper 2.msi
+ 2007-07-27 06:34 . 2007-07-27 06:34 112590848 c:\windows\Installer\31c06.msp
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-03 94208]
"BugCD Pretrazivac"="c:\program files\BugCD Pretrazivac\BugCD Pretrazivac.exe" [2002-08-12 49152]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Steam"="c:\program files\Steam\Steam.exe" [2009-06-10 1217784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 77824]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-28 413696]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2003-12-04 406016]
"SmartDefrag"="c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" [2009-02-13 1986896]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"RivaTunerStartupDaemon"="c:\program files\RivaTuner v2.24\RivaTuner.exe" [2009-02-25 2781184]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-18 518488]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-25 148888]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-27 1657376]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2005-05-17 77824]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]

c:\documents and settings\Decky\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 10:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\drwtsn32.exe]
"Debugger"=c:\windows\system32\wscript.exe /E:vbs c:\windows\system32\winjpg.jpg

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dwwinxp.exe]
"Debugger"=c:\windows\system32\winxp.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0autocheck lsdelete\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Atari\\BOILING POINT\\Xenus.exe"=
"d:\\Program Files\\Live for Speed S2\\LFSspotter.exe"=
"d:\\Program Files\\Live for Speed S2\\LFS.exe"=
"d:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"d:\\Program Files\\Atari\\Test Drive Unlimited\\TestDriveUnlimited.exe"=
"d:\\Program Files\\Firefly Studios\\Stronghold 2\\Stronghold2.exe"=
"c:\\Program Files\\Opera\\Opera.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.321\\English\\setup.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Ubisoft\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Crave Entertainment\\World Championship Poker 2\\WCP2.exe"=
"d:\\Program Files\\Techland\\Xpand Rally\\xpandrally.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"d:\\Program Files\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe"=
"c:\\Program Files\\Steam\\steamapps\\mposlon\\half-life 2 deathmatch\\hl2.exe"=
"d:\\Program Files\\UT2004\\System\\UT2004.exe"=
"g:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"g:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"g:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\GTAIV.exe"=
"g:\\Program Files\\Deep Silver\\S.T.A.L.K.E.R. - Clear Sky\\bin\\xrEngine.exe"=
"g:\\Program Files\\Deep Silver\\S.T.A.L.K.E.R. - Clear Sky\\bin\\dedicated\\xrEngine.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15155:TCP"= 15155:TCP:NortonAV
"16556:TCP"= 16556:TCP:NortonAV
"17096:TCP"= 17096:TCP:NortonAV
"17464:TCP"= 17464:TCP:NortonAV
"13299:TCP"= 13299:TCP:NortonAV
"12569:TCP"= 12569:TCP:NortonAV
"15798:TCP"= 15798:TCP:NortonAV
"17026:TCP"= 17026:TCP:NortonAV
"13516:TCP"= 13516:TCP:NortonAV
"13575:TCP"= 13575:TCP:NortonAV
"18893:TCP"= 18893:TCP:NortonAV
"18350:TCP"= 18350:TCP:NortonAV
"16026:TCP"= 16026:TCP:NortonAV
"18699:TCP"= 18699:TCP:NortonAV
"18167:TCP"= 18167:TCP:NortonAV
"17674:TCP"= 17674:TCP:NortonAV
"18146:TCP"= 18146:TCP:NortonAV
"12715:TCP"= 12715:TCP:NortonAV

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [4.6.2009 22:09 64160]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [6.12.2005 17:11 35328]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2.4.2008 21:05 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [26.5.2009 10:05 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [26.5.2009 10:05 72944]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2.4.2008 21:05 20560]
R2 athsgt;athsgt;c:\windows\system32\drivers\athsgt.sys [27.7.2006 18:21 164992]
R2 limsgt;limsgt;c:\windows\system32\drivers\limsgt.sys [27.7.2006 18:21 12544]
R3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;c:\program files\Windows Live\Messenger\usnsvc.exe [18.10.2007 12:31 98328]
S3 FXDRV;FXDRV;\??\e:\fxdrv.sys --> e:\Fxdrv.sys [?]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [25.6.2009 9:32 66048]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);c:\windows\system32\drivers\k510bus.sys [8.1.2007 11:27 58288]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;c:\windows\system32\drivers\k510mdfl.sys [8.1.2007 11:27 8336]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;c:\windows\system32\drivers\k510mdm.sys [8.1.2007 11:27 94064]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\k510mgmt.sys [8.1.2007 11:27 85408]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;c:\windows\system32\drivers\k510obex.sys [8.1.2007 11:27 83344]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9.3.2009 21:06 1003344]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [26.5.2009 10:05 7408]
.
Contents of the 'Scheduled Tasks' folder

2009-06-29 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 20:09]

2009-06-30 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-01-17 17:15]

2009-07-03 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-07 20:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.hr/
uInternet Connection Wizard,ShellNext = iexplore
IE: eng-scr - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Croatian) for Windows\Plugins\IE.htm
IE: English<->French - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-French) for Windows\Plugins\IE.htm
IE: English<->German - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-German) for Windows\Plugins\IE.htm
IE: English<->Italian - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Italian) for Windows\Plugins\IE.htm
IE: English<->Latin - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Latin) for Windows\Plugins\IE.htm
IE: English<->Spanish - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Spanish) for Windows\Plugins\IE.htm
IE: I&zvoz u Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{2DDEE708-A225-6449-889B-1941E2FBAB6D} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-German) for Windows\Plugins\IE.htm
IE: {{4629E725-138D-0F4C-B01A-09EBD3D67834} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Latin) for Windows\Plugins\IE.htm
IE: {{73AD0419-12E3-E74C-B893-EA4EF48F451F} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Italian) for Windows\Plugins\IE.htm
IE: {{9771B718-0C1C-3248-A000-C378A44BF07B} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-French) for Windows\Plugins\IE.htm
IE: {{A9919568-CF8E-C140-84DC-0FF917685E69} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Spanish) for Windows\Plugins\IE.htm
IE: {{B05D861D-C01F-7C4C-A7FF-A8003A8FE77C} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Croatian) for Windows\Plugins\IE.htm
FF - ProfilePath - c:\documents and settings\Decky\Application Data\Mozilla\Firefox\Profiles\be0vk58y.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.oglasnik.hr/
FF - component: c:\documents and settings\Decky\Application Data\Mozilla\Firefox\Profiles\be0vk58y.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - plugin: c:\program files\Opera\program\plugins\np_gp.dll
FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-03 11:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1085031214-492894223-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,63,1b,9e,89,00,
bf,5b,73,c8,28,51,af,b0,29,a3,98,30,a9,fd,c2,d5,be,73,f8,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,15,64,5d,be,a9,
24,c6,5e,71,3b,04,66,8b,46,0d,96,72,a8,60,a4,23,5e,97,e0,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,31,5f,d2,35,70,
96,44,4a,25,da,ec,7e,55,20,c9,26,48,ba,30,33,53,d5,a4,a2,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,f7,b0,04,1e,ae,
35,08,0f,3e,1e,9e,e0,57,5a,93,61,61,c9,6d,a4,d9,e6,f9,6a,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,b6,aa,22,00,8a,
b1,5c,d0,cd,44,cd,b9,a6,33,6c,cd,45,a8,36,94,91,08,12,74,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,82,16,0c,80,96,
eb,a8,30,b0,18,ed,a7,3f,8d,37,a4,21,3f,38,48,28,08,72,9c,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,60,95,bd,7f,e9,
84,8f,a1,31,77,e1,ba,b1,f8,68,02,2d,a7,6a,8e,fa,df,1d,03,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,9b,9a,64,a6,02,
c4,98,35,83,6c,56,8b,a0,85,96,ab,9f,d1,20,47,89,83,6f,e6,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,0e,8b,22,d2,0a,
1d,84,9f,51,fa,6e,91,28,9e,14,cc,c5,3b,b3,54,0a,58,b6,e7,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,e8,34,73,8a,76,
e7,48,a9,b1,cd,45,5a,a8,c4,f8,b9,3b,a7,d2,53,6d,d5,39,02,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,d3,ab,e0,b7,97,
82,fe,98,e3,0e,66,d5,eb,bc,2f,6b,85,52,ce,c6,84,43,50,8b,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\windows\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,fa,e3,de,b8,1c,
1e,61,cb,fa,ea,66,7f,d4,3b,6b,70,db,b1,d5,59,65,26,88,f8,6c,43,2d,1e,aa,22,\

[HKEY_LOCAL_MACHINE\System\MountedDevices]
@Denied: (Read) (Administrators)
"\\DosDevices\\C:"=hex:21,04,21,04,00,7e,00,00,00,00,00,00
"\\??\\Volume{da4bcfda-5b8a-11d9-ba0e-806d6172696f}"=hex:5c,00,3f,00,3f,00,5c,
00,46,00,44,00,43,00,23,00,47,00,45,00,4e,00,45,00,52,00,49,00,43,00,5f,00,\
"\\??\\Volume{da4bcfdb-5b8a-11d9-ba0e-806d6172696f}"=hex:5c,00,3f,00,3f,00,5c,
00,49,00,44,00,45,00,23,00,43,00,64,00,52,00,6f,00,6d,00,48,00,4c,00,2d,00,\
"\\DosDevices\\A:"=hex:5c,00,3f,00,3f,00,5c,00,46,00,44,00,43,00,23,00,47,00,
45,00,4e,00,45,00,52,00,49,00,43,00,5f,00,46,00,4c,00,4f,00,50,00,50,00,59,\
"\\??\\Volume{da4bcfdd-5b8a-11d9-ba0e-806d6172696f}"=hex:21,04,21,04,00,7e,00,
00,00,00,00,00
"\\??\\Volume{2dab15ca-10b4-11db-b103-806d6172696f}"=hex:5c,00,3f,00,3f,00,5c,
00,49,00,44,00,45,00,23,00,43,00,64,00,52,00,6f,00,6d,00,48,00,4c,00,2d,00,\
"\\??\\Volume{a5f4bb56-11b5-11db-b10a-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\??\\Volume{cfc954ee-1298-11db-b10e-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\F:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,53,00,43,00,53,\
"\\??\\Volume{24904c40-12a2-11db-bdc5-806d6172696f}"=hex:21,04,21,04,00,f0,de,
8c,22,00,00,00
"\\DosDevices\\G:"=hex:44,4d,49,4f,3a,49,44,3a,28,e8,52,b7,71,28,a5,4a,ae,32,
b4,c2,ea,e5,96,0f
"\\DosDevices\\D:"=hex:21,04,21,04,00,f0,de,8c,22,00,00,00
"\\DosDevices\\E:"=hex:5c,00,3f,00,3f,00,5c,00,49,00,44,00,45,00,23,00,43,00,
64,00,52,00,6f,00,6d,00,48,00,4c,00,2d,00,44,00,54,00,2d,00,53,00,54,00,5f,\
"\\??\\Volume{70beaf14-1e42-11db-bdeb-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\H:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,54,00,4f,00,52,00,41,00,
47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,76,00,61,00,62,00,6c,00,65,00,4d,\
"\\??\\Volume{69d1bce4-1eeb-11db-9617-806d6172696f}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\I:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,54,00,4f,00,52,00,41,00,
47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,76,00,61,00,62,00,6c,00,65,00,4d,\
"\\??\\Volume{d0fbd5fd-2d1b-11db-9633-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\J:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,47,00,65,00,6e,\
"\\??\\Volume{229bd68e-2d1e-11db-9634-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\K:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,47,00,65,00,6e,\
"\\??\\Volume{229bd68f-2d1e-11db-9634-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\L:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,47,00,65,00,6e,\
"\\??\\Volume{707402be-780a-11db-9743-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\DosDevices\\M:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,53,00,43,00,53,\
"\\??\\Volume{9cf8fbf4-7d83-11db-975a-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{f50d8190-7e53-11db-9761-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{ffdf0afa-7e56-11db-9762-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{ffdf0afb-7e56-11db-9762-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{dc6fa383-8f9f-11db-97a1-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\??\\Volume{dc6fa386-8f9f-11db-97a1-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\N:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,53,00,43,00,53,\
"\\??\\Volume{7cb172c4-978c-11db-97c4-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\O:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,53,00,43,00,53,\
"\\??\\Volume{cc6329a9-9efa-11db-97dd-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\DosDevices\\P:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,54,00,4f,00,52,00,41,00,
47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,76,00,61,00,62,00,6c,00,65,00,4d,\
"\\??\\Volume{9617b388-dafb-11db-988c-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\??\\Volume{df235132-dc92-11db-9898-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{00f2196c-e745-11db-98b9-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{9484c51a-f4c1-11db-98e7-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{a1a75f18-faf5-11db-98fc-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{87549574-41a0-11dc-99e4-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{9f4e1236-8c73-11dc-9a9f-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{a5621da2-a9b0-11dc-9af4-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{10a3ee57-bb01-11dc-9b43-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{5a37773e-c6ac-11dc-9b71-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{6fbc0310-d288-11dc-abeb-806d6172696f}"=hex:a6,06,ef,19,00,7e,00,
00,00,00,00,00
"\\??\\Volume{5e4e5d9e-0889-11dd-acd4-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{7d41f5af-4109-11dd-ad95-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{929aaf67-43ab-11dd-ad9f-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{10b141ce-6af8-11dd-ae17-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{5a8143c3-6d38-11dd-ae1f-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{0738d30c-8a40-11dd-ae66-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{44bcd168-faa9-11dd-afa2-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{d25c7a00-1bb5-11de-b074-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{7e2a2a22-38de-11de-b0fc-00016ce45155}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(792)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\cscui.dll
.
Completion time: 2009-07-03 11:27
ComboFix-quarantined-files.txt 2009-07-03 09:27
ComboFix2.txt 2009-06-30 15:56
ComboFix3.txt 2009-06-18 11:57

Pre-Run: 44.567.740.416 bytes free
Post-Run: 44.640.133.120 bytes free

1045 --- E O F --- 2009-07-03 07:42
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP