Infected but can't get what is it [Solved], I have some weird files and the pc is slow, yet most scan show nothing |
![]() ![]() |
Infected but can't get what is it [Solved], I have some weird files and the pc is slow, yet most scan show nothing |
May 31 2009, 12:27 AM
Post
#1
|
|
|
Member ![]() ![]() Posts: 16 OS: xp |
Hi, the pc shows random activity at moments when there is nothing going on (pc can be on but no application running, yet you can hear the hard drive and fans working overtime), when I open Msconfig it shows some weird files, if I run MBAM it shows nothing but AVG shows a trojan (c:\windows\system32\wlmnokfq.dll), I just want to make sure the pc is clean and it's acting weird cause it's low on memory.
Malwarebytes' Anti-Malware 1.37 Database version: 2199 Windows 5.1.2600 Service Pack 2 31/05/2009 1:47:18 AM mbam-log-2009-05-31 (01-47-17).txt Scan type: Quick Scan Objects scanned: 78723 Time elapsed: 8 minute(s), 16 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Rooter Microsoft Windows XP Home Edition (5.1.2600) Service Pack 2 A:\ [Removable] (Total:0 Mo/Free:0 Mo) C:\ [Fixed] - NTFS - (Total:152625 Mo/Free:199 Mo) D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) 31/05/2009| 1:50 ----------------------\\ Processes.. --Locked-- [System Process] ---------- System ---------- \SystemRoot\System32\smss.exe ---------- \??\C:\WINDOWS\system32\csrss.exe ---------- \??\C:\WINDOWS\system32\winlogon.exe ---------- C:\WINDOWS\system32\services.exe ---------- C:\WINDOWS\system32\lsass.exe ---------- C:\WINDOWS\system32\Ati2evxx.exe ---------- C:\WINDOWS\system32\svchost.exe ---------- C:\WINDOWS\system32\svchost.exe ---------- C:\WINDOWS\System32\svchost.exe ---------- C:\WINDOWS\system32\svchost.exe ---------- C:\WINDOWS\system32\svchost.exe ---------- C:\WINDOWS\system32\svchost.exe --Locked-- vsmon.exe ---------- C:\WINDOWS\system32\Ati2evxx.exe ---------- C:\WINDOWS\Explorer.EXE ---------- C:\WINDOWS\system32\spoolsv.exe ---------- C:\WINDOWS\system32\svchost.exe ---------- C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe ---------- C:\WINDOWS\system32\crypserv.exe ---------- C:\Program Files\Java\jre6\bin\jqs.exe ---------- C:\Program Files\Microsoft LifeCam\MSCamS32.exe ---------- C:\WINDOWS\system32\svchost.exe ---------- C:\WINDOWS\system32\SearchIndexer.exe ---------- C:\PROGRA~1\AVG\AVG8\avgrsx.exe ---------- C:\PROGRA~1\AVG\AVG8\avgnsx.exe ---------- C:\PROGRA~1\AVG\AVG8\avgemc.exe ---------- C:\Program Files\Canon\CAL\CALMAIN.exe ---------- C:\Program Files\AVG\AVG8\avgcsrvx.exe ---------- C:\WINDOWS\System32\alg.exe ---------- C:\WINDOWS\system32\ctfmon.exe ---------- C:\WINDOWS\RTHDCPL.EXE ---------- C:\WINDOWS\System32\svchost.exe ---------- C:\WINDOWS\vVX1000.exe --Locked-- zlclient.exe ---------- C:\PROGRA~1\AVG\AVG8\avgtray.exe ---------- C:\Program Files\Java\jre6\bin\jusched.exe ---------- C:\WINDOWS\system32\wuauclt.exe ---------- C:\WINDOWS\system32\NOTEPAD.EXE ---------- C:\WINDOWS\system32\wbem\wmiprvse.exe ---------- C:\WINDOWS\system32\cmd.exe ---------- C:\Rooter$\RK.exe ----------------------\\ Search.. ==> VUNDO <== ----------------------\\ ROOTKIT !! 1 - "C:\Rooter$\Rooter_1.txt" - 31/05/2009| 1:51 ----------------------\\ Scan completed at 1:51 OTlistIt OTListIt logfile created on: 31/05/2009 1:54:33 AM - Run 1 OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\Owner\Desktop Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.11) Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy 446.48 Mb Total Physical Memory | 117.69 Mb Available Physical Memory | 26.36% Memory free 1.03 Gb Paging File | 0.59 Gb Available in Paging File | 56.88% Paging File free Paging file location(s): C:\pagefile.sys 672 1344 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 149.05 Gb Total Space | 132.19 Gb Free Space | 88.69% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: KIDSC12288 Current User Name: Owner Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Output = Minimal File Age = 30 Days Company Name Whitelist: On ========== Processes (SafeList) ========== PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.) PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD) PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.) PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation) PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) PRC - C:\WINDOWS\system32\crypserv.exe (CrypKey (Canada) Ltd.) PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.) PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation) PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.) PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.) PRC - C:\WINDOWS\vVX1000.exe (Microsoft Corporation) PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD) PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.) PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation) PRC - C:\Documents and Settings\Owner\Desktop\OTListIt2.exe (OldTimer Tools) ========== Win32 Services (SafeList) ========== SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation) SRV - (Ati HotKey Poller [Auto | Running]) -- C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.) SRV - (ATI Smart [Auto | Stopped]) -- C:\WINDOWS\system32\ati2sgag.exe () SRV - (avg8emc [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.) SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) SRV - (CCALib8 [Auto | Running]) -- C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.) SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (Crypkey License [Auto | Running]) -- C:\WINDOWS\system32\crypserv.exe (CrypKey (Canada) Ltd.) SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation) SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation) SRV - (ieik9uaaan [Auto | Stopped]) -- File not found SRV - (iPod Service [On_Demand | Stopped]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.) SRV - (MSCamSvc [Auto | Running]) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation) SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation) SRV - (odserv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation) SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation) SRV - (vsmon [Auto | Running]) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD) SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (Ai2sXP [System | Running]) -- C:\WINDOWS\System32\drivers\Ai2sXP.sys (Ai Squared ) DRV - (ati2mtag [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.) DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.) DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.) DRV - (AvgTdiX [System | Running]) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.) DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.) DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider) DRV - (HPMobileDisk [Auto | Running]) -- C:\WINDOWS\system32\Drivers\hpmobiledisk.sys (HP) DRV - (IntcAzAudAddService [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.) DRV - (Iviaspi [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\iviaspi.sys (InterVideo, Inc.) DRV - (ivicd [Boot | Running]) -- C:\WINDOWS\system32\drivers\ivicd.sys (InterVideo) DRV - (iviudf [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\IviUdf.sys (InterVideo) DRV - (NetworkX [System | Running]) -- C:\WINDOWS\system32\ckldrv.sys () DRV - (nmwcd [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\ccdcmb.sys (Nokia) DRV - (nmwcdc [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\ccdcmbo.sys (Nokia) DRV - (pavboot [Boot | Running]) -- C:\WINDOWS\system32\drivers\pavboot.sys (Panda Security, S.L.) DRV - (Pfc [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.) DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.) DRV - (RT73 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\rt73.sys (Ralink Technology, Corp.) DRV - (RTL8023xp [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys (Realtek Semiconductor Corporation ) DRV - (rtl8139 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation) DRV - (SDTHOOK [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\SDTHOOK.sys (Panda Software) DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) DRV - (SONYPVU1 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS (Sony Corporation) DRV - (srescan [Boot | Running]) -- C:\WINDOWS\system32\ZoneLabs\srescan.sys (Check Point Software Technologies LTD) DRV - (upperdev [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys (Windows ® Codename Longhorn DDK provider) DRV - (usbaudio [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation) DRV - (usbser [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\usbser.sys (Microsoft Corporation) DRV - (UsbserFilt [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys (Windows ® Codename Longhorn DDK provider) DRV - (vsdatant [System | Running]) -- C:\WINDOWS\System32\vsdatant.sys (Check Point Software Technologies LTD) DRV - (VX1000 [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\VX1000.sys (Microsoft Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://by119w.bay119.mail.live.com/mail/InboxLight.aspx?FolderID=00000000-0000-0000-0000-000000000001&n=1363717851" FF - prefs.js..extensions.enabledItems: filtersetg@updater:0.3.1.3 FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.2 FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5 FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.1.8.7 FF - prefs.js..extensions.enabledItems: {77b819fa-95ad-4f2c-ac7c-486b356188a9}:1.5.20090207 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03 FF - prefs.js..extensions.enabledItems: plugin@yontoo.com:1.03.01 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10 FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX [2009/05/18 22:07:11 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/05/19 10:17:56 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/02 19:28:45 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/05/19 10:18:17 | 00,000,000 | ---D | M] [2008/10/19 20:35:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Extensions [2008/10/19 20:35:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/05/30 14:04:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\vuedfkts.default\extensions [2009/05/18 22:23:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\vuedfkts.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34} [2009/05/18 22:23:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\vuedfkts.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9} [2007/08/03 15:03:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\vuedfkts.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e} [2009/05/18 22:23:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\vuedfkts.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2008/02/29 01:30:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\vuedfkts.default\extensions\filtersetg@updater [2009/05/18 22:23:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\vuedfkts.default\extensions\plugin@yontoo.com [2008/06/19 22:57:24 | 00,001,108 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\vuedfkts.default\searchplugins\wikipedia-en.xml [2009/05/30 11:48:17 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2009/04/28 15:14:14 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2008/02/29 21:36:40 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [2009/05/19 10:18:28 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [2009/04/28 15:14:06 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009/04/28 15:14:06 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2008/09/24 21:21:16 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml [2008/09/24 21:21:16 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml [2008/09/24 21:21:16 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml [2008/11/14 14:55:53 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml [2008/09/24 21:21:16 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2008/09/24 21:21:16 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml O1 HOSTS File: (306898 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 www.123topsearch.com O1 - Hosts: 127.0.0.1 123topsearch.com O1 - Hosts: 127.0.0.1 www.132.com O1 - Hosts: 127.0.0.1 132.com O1 - Hosts: 127.0.0.1 www.136136.net O1 - Hosts: 127.0.0.1 136136.net O1 - Hosts: 127.0.0.1 www.163ns.com O1 - Hosts: 127.0.0.1 163ns.com O1 - Hosts: 10566 more lines... O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - Reg Error: Key error. File not found O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (AhIeBho Class) - {10384d0e-2bc1-48b6-844b-ad0e9e6d2511} - C:\Program Files\ZoomText 9.0\AHOI\ah_ie_bho.dll (Ai Squared ) O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) O2 - BHO: (IE to GetRight Helper) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll (Headlight Software, Inc.) O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (no name) - {AA53ED35-9CED-402F-AAE5-32482DDB343D} - C:\WINDOWS\system32\jkhfg.dll File not found O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - Reg Error: Key error. File not found O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found O4 - HKLM..\Run: [Alcmtr] ALCMTR.EXE (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [kgngdne] C:\WINDOWS\system32\kgngdne.exe File not found O4 - HKLM..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe" (Microsoft Corporation) O4 - HKLM..\Run: [NWEReboot] File not found O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.) O4 - HKLM..\Run: [VX1000] C:\WINDOWS\vVX1000.exe (Microsoft Corporation) O4 - HKLM..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" (Check Point Software Technologies LTD) O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent (Malwarebytes Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: &Search - ?p=ZJxdm088YYCA File not found O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx File not found O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm () O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm () O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O15 - HKLM\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKCU\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet) O15 - HKCU\..Trusted Domains: 198 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_01) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03) O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.) O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.) O20 - Winlogon\Notify\opnmnmm: DllName - opnmnmm.dll - File not found O24 - Desktop Components:0 (My Current Home Page) - About:Home O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation) O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\jkhfg.dll) - C:\WINDOWS\system32\jkhfg.dll File not found O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/10/04 16:11:14 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{23158241-53c0-11db-9ca6-806d6172696f}\Shell - "" = AutoRun O33 - MountPoints2\{23158241-53c0-11db-9ca6-806d6172696f}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{23158241-53c0-11db-9ca6-806d6172696f}\Shell\AutoRun\command - "" = D:\EISetup.exe -- File not found O33 - MountPoints2\{acf3bd38-1f8a-11dc-9a2e-0016763ae177}\Shell\AutoRun\command - "" = E:\CDGO.exe -- File not found O33 - MountPoints2\{c2cd46b8-f171-11dd-b198-0016763ae177}\Shell\AutoRun\command - "" = E:\CDGO.exe -- File not found O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - * [2009/05/31 01:52:43 | 00,000,000 | ---D | M] ========== Files/Folders - Created Within 30 Days ========== [2009/05/31 01:53:26 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTListIt2.exe [2009/05/31 01:50:44 | 00,000,000 | ---D | C] -- C:\Rooter$ [2009/05/31 01:26:09 | 00,267,612 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Rooter.exe [2009/05/31 01:17:53 | 00,264,704 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\TFC.exe [2009/05/20 02:35:22 | 00,000,000 | -HSD | C] -- C:\Config.Msi [2009/05/20 01:29:55 | 00,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK [2009/05/20 00:08:58 | 03,426,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_32.dll [2009/05/20 00:08:47 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition [2009/05/20 00:05:11 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft [2009/05/20 00:04:50 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live SkyDrive [2009/05/20 00:04:15 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live [2009/05/19 23:43:13 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live [2009/05/19 23:19:51 | 46,824,2432 | -HS- | C] () -- C:\hiberfil.sys [2009/05/19 15:01:47 | 00,028,544 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\pavboot.sys [2009/05/19 07:55:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\Malwarebytes [2009/05/19 07:55:47 | 00,000,702 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2009/05/19 07:55:46 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2009/05/19 07:55:44 | 00,040,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2009/05/19 07:55:42 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2009/05/19 07:55:42 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2009/05/18 23:30:25 | 00,000,000 | -H-D | C] -- C:\$AVG8.VAULT$ [2009/05/18 23:00:16 | 00,175,888 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\activescan2_en.exe [2009/05/18 22:54:37 | 00,013,824 | -HS- | C] () -- C:\Documents and Settings\Owner\My Documents\Thumbs.db [2009/05/18 22:33:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP [2009/05/18 22:07:42 | 00,001,513 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk [2009/05/18 22:07:41 | 00,108,552 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys [2009/05/18 22:07:41 | 00,011,952 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll [2009/05/18 22:07:40 | 00,325,896 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys [2009/05/18 22:07:29 | 36,557,916 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm [2009/05/18 22:07:29 | 06,061,540 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg [2009/05/18 22:07:29 | 00,434,673 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg [2009/05/18 22:07:29 | 00,063,467 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg [2009/05/18 22:07:29 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg [2009/05/18 22:07:11 | 00,000,000 | ---D | C] -- C:\Program Files\AVG [2009/05/18 22:07:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg8 [2009/05/18 20:50:08 | 00,001,554 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\CCleaner.lnk [2009/05/18 20:50:06 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner [2009/05/13 20:52:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\Advocacy Committee [2009/05/03 13:42:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\Ryerson [2008/07/21 16:14:10 | 00,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll [2008/02/29 14:42:40 | 00,000,988 | ---- | C] () -- C:\WINDOWS\wininit.ini [2008/02/29 01:46:30 | 00,011,776 | ---- | C] () -- C:\WINDOWS\System32\ZPORT4AS.dll [2008/02/29 00:23:19 | 01,249,905 | -HS- | C] () -- C:\WINDOWS\System32\eevxajyv.ini [2008/02/03 17:44:44 | 01,140,140 | -HS- | C] () -- C:\WINDOWS\System32\wevakxdj.ini [2008/02/01 12:40:13 | 01,192,460 | -HS- | C] () -- C:\WINDOWS\System32\uscjcqvl.ini [2008/01/31 12:41:07 | 01,180,987 | -HS- | C] () -- C:\WINDOWS\System32\nuplshji.ini [2008/01/30 12:18:29 | 01,168,751 | -HS- | C] () -- C:\WINDOWS\System32\piyhfbeh.ini [2008/01/28 11:37:31 | 01,244,424 | -HS- | C] () -- C:\WINDOWS\System32\bgbuwmmg.ini [2008/01/27 11:42:04 | 01,324,411 | -HS- | C] () -- C:\WINDOWS\System32\wjmkijdd.ini [2008/01/26 11:51:38 | 01,534,184 | -HS- | C] () -- C:\WINDOWS\System32\cpyfhfrn.ini [2007/12/09 15:17:44 | 00,720,603 | -HS- | C] () -- C:\WINDOWS\System32\ajtafxmt.ini [2007/12/07 00:15:22 | 00,719,703 | -HS- | C] () -- C:\WINDOWS\System32\hbnqpyqu.ini [2007/12/05 21:15:09 | 00,803,075 | -HS- | C] () -- C:\WINDOWS\System32\eeoyibbc.ini [2007/12/03 20:43:19 | 00,909,996 | -HS- | C] () -- C:\WINDOWS\System32\vkqslmnf.ini [2007/12/02 20:41:53 | 00,774,432 | -HS- | C] () -- C:\WINDOWS\System32\vuourgxk.ini [2007/11/30 21:30:49 | 00,788,296 | -HS- | C] () -- C:\WINDOWS\System32\rkhwkutu.ini [2007/11/29 18:38:29 | 00,833,290 | -HS- | C] () -- C:\WINDOWS\System32\tkrocfxf.ini [2007/11/26 23:16:19 | 00,940,968 | -HS- | C] () -- C:\WINDOWS\System32\endrhobk.ini [2007/11/25 14:48:23 | 00,778,118 | -HS- | C] () -- C:\WINDOWS\System32\kscnhita.ini [2007/11/21 02:04:07 | 00,689,343 | -HS- | C] () -- C:\WINDOWS\System32\ynlcqpxf.ini [2007/11/20 22:52:37 | 00,689,163 | -HS- | C] () -- C:\WINDOWS\System32\kkopwehf.ini [2007/11/19 23:39:13 | 00,689,223 | -HS- | C] () -- C:\WINDOWS\System32\pyblkord.ini [2007/11/18 01:16:34 | 00,628,455 | -HS- | C] () -- C:\WINDOWS\System32\giyofkro.ini [2007/11/14 23:45:50 | 00,785,698 | -HS- | C] () -- C:\WINDOWS\System32\wyfltmcl.ini [2007/11/14 22:45:50 | 00,590,536 | -HS- | C] () -- C:\WINDOWS\System32\qldkxmvq.ini [2007/11/12 14:44:29 | 00,590,476 | -HS- | C] () -- C:\WINDOWS\System32\ilsxugas.ini [2007/11/12 01:53:56 | 00,183,060 | -HS- | C] () -- C:\WINDOWS\System32\gfhkj.ini [2007/09/27 10:51:02 | 00,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini [2007/09/27 10:48:48 | 00,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini [2007/09/27 10:48:28 | 00,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini [2007/09/09 16:04:08 | 00,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll [2007/04/27 20:51:23 | 00,796,312 | ---- | C] () -- C:\WINDOWS\System32\libeay32_0.9.6l.dll [2007/01/22 19:21:39 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2006/10/12 10:54:26 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini [2006/10/12 10:18:14 | 00,000,046 | ---- | C] () -- C:\WINDOWS\Crypkey.ini [2006/10/12 10:18:11 | 00,031,846 | ---- | C] () -- C:\WINDOWS\System32\Ckldrv.sys [2006/10/12 10:18:11 | 00,018,432 | ---- | C] () -- C:\WINDOWS\Setup_ck.dll [2006/10/12 10:17:59 | 00,000,380 | ---- | C] () -- C:\WINDOWS\dcmuser.ini [2006/10/12 10:06:45 | 00,000,090 | ---- | C] () -- C:\WINDOWS\TestSupp.ini [2006/10/05 08:50:04 | 00,001,260 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini [2006/10/04 17:56:51 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll [2006/10/04 17:56:51 | 00,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll [2006/10/04 17:56:51 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll [2006/10/04 17:56:51 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll [2006/10/04 17:56:51 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll [2006/10/04 17:56:51 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll [2006/10/04 17:56:21 | 00,005,248 | ---- | C] () -- C:\WINDOWS\System32\drivers\udffsrec.sys [2006/10/04 16:48:29 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2006/10/04 16:41:13 | 00,000,259 | ---- | C] () -- C:\WINDOWS\lgfwup.ini [2006/10/04 16:24:25 | 00,157,184 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll [2006/04/27 06:19:01 | 00,015,498 | ---- | C] () -- C:\WINDOWS\VX1000.ini [2006/02/28 08:00:00 | 00,000,616 | ---- | C] () -- C:\WINDOWS\win.ini [2006/02/28 08:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini ========== Files - Modified Within 30 Days ========== [2009/05/31 01:53:29 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTListIt2.exe [2009/05/31 01:26:42 | 00,267,612 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Rooter.exe [2009/05/31 01:21:14 | 00,350,193 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml [2009/05/31 01:21:05 | 00,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009/05/31 01:20:28 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009/05/31 01:20:13 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Owner\Local Settings\desktop.ini [2009/05/31 01:20:09 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009/05/31 01:20:06 | 46,824,2432 | -HS- | M] () -- C:\hiberfil.sys [2009/05/31 01:17:55 | 00,264,704 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\TFC.exe [2009/05/30 10:25:55 | 00,063,467 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg [2009/05/30 10:25:54 | 36,557,916 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm [2009/05/29 16:30:59 | 00,043,234 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\wklnhst.dat [2009/05/27 10:24:02 | 00,002,257 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk [2009/05/26 13:20:08 | 00,040,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2009/05/26 13:19:56 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2009/05/20 01:50:33 | 00,462,668 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2009/05/20 01:50:33 | 00,078,362 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2009/05/20 01:50:31 | 00,551,752 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2009/05/20 01:45:25 | 00,243,128 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2009/05/20 01:36:52 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2009/05/20 00:07:15 | 00,000,905 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\My Sharing Folders.lnk [2009/05/19 10:07:59 | 00,306,898 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2009/05/19 09:46:27 | 00,306,898 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090519-100759.backup [2009/05/19 07:55:47 | 00,000,702 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2009/05/18 23:00:22 | 00,175,888 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\activescan2_en.exe [2009/05/18 22:54:40 | 00,013,824 | -HS- | M] () -- C:\Documents and Settings\Owner\My Documents\Thumbs.db [2009/05/18 22:41:56 | 00,000,616 | ---- | M] () -- C:\WINDOWS\win.ini [2009/05/18 22:41:56 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini [2009/05/18 22:41:56 | 00,000,211 | RHS- | M] () -- C:\boot.ini [2009/05/18 22:07:42 | 00,001,513 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk [2009/05/18 22:07:41 | 00,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys [2009/05/18 22:07:41 | 00,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll [2009/05/18 22:07:40 | 00,325,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys [2009/05/18 22:07:39 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys [2009/05/18 22:07:29 | 06,061,540 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg [2009/05/18 22:07:29 | 00,434,673 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg [2009/05/18 21:24:40 | 00,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat [2009/05/18 20:50:08 | 00,001,554 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\CCleaner.lnk [2009/05/08 00:02:13 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2009/05/07 00:16:30 | 24,699,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe < End of report > OTlist Extras OTListIt Extras logfile created on: 31/05/2009 1:54:33 AM - Run 1 OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\Owner\Desktop Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.11) Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy 446.48 Mb Total Physical Memory | 117.69 Mb Available Physical Memory | 26.36% Memory free 1.03 Gb Paging File | 0.59 Gb Available in Paging File | 56.88% Paging File free Paging file location(s): C:\pagefile.sys 672 1344 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 149.05 Gb Total Space | 132.19 Gb Free Space | 88.69% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: KIDSC12288 Current User Name: Owner Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Output = Minimal File Age = 30 Days Company Name Whitelist: On ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] "DisableMonitoring" = 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile "EnableFirewall" = 0 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation) C:\Program Files\ZoomText 9.0\Zt.exe:LocalSubNet:Enabled:ZoomText 9.0 (Ai Squared ) C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) File not found C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) File not found C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation) C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation) C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation) C:\Program Files\ZoomText 9.0\Zt.exe:LocalSubNet:Enabled:ZoomText 9.0 (Ai Squared ) C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) File not found C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.) C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:LimeWire (FrostWire Group) C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe (Microsoft Corporation) C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) File not found C:\WINDOWS\system\lsass.exe:*:Enabled:Windows Sharing File not found "C:\WINDOWS\system32\xudimjlq.exe" = C:\WINDOWS\system32\xudiexe:*:Enabled:Windows S C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype (Skype Technologies S.A.) C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe (Microsoft Corporation) C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice (Microsoft Corporation) C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation) C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation) C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync (Microsoft Corporation) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime "{06040048-3E21-46D6-9A91-D927BA08F41D}" = Microsoft Encarta Encyclopedia Standard 2006 "{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger "{17E3A651-12B9-4149-BAE8-E6FB9A5ADC4F}" = Microsoft Works Suite Add-in for Microsoft Word "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{24BEE00C-0DE6-443E-8C3C-00A199B1DCDD}" = ZoomText 9.0 "{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java 6 Update 13 "{2BA00471-0328-3743-93BD-FA813353A783}" = Microsoft .NET Framework 3.0 Service Pack 1 "{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11 "{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java SE Runtime Environment 6 Update 1 "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java 6 Update 3 "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{393711FE-64EB-4DC7-909E-5FB26D1270AA}" = Microsoft Sapi 5.1 "{3972C18C-688F-4312-BE9A-3E065204C33D}" = IBM ViaVoice TTS Runtime v6.610 - UK English "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform "{3C52E7DA-C431-4239-B66B-1BF703D5B194}" = Windows Live Photo Gallery "{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.5 "{5D95AD35-368F-47D5-B63A-A082DDF00116}" = Microsoft Digital Image Standard 2006 Editor "{5E863175-E85D-44A6-8968-82507D34AE7F}" = QuickTime "{6179550A-3E7C-499E-BCC9-9E8113E0A285}" = LG ODD Auto Firmware Update "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{691F4068-81BF-49E3-B32E-FE3E16400112}" = Microsoft Digital Image Standard 2006 Library "{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer "{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{83ED1E80-A1B7-4226-BCF1-AC4A88151A6B}" = Microsoft Streets & Trips 2006 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8AEEE6D6-C95D-465A-B8D3-B7AE2FA7B8B4}" = InterVideo MediaOne "{8CFC7570-DD90-486E-A239-E31D455BDE93}" = Microsoft LifeCam "{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard "{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_PRJSTDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_PRJSTDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_PRJSTDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_PRJSTDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00B4-0409-0000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2007 "{90120000-00B4-0409-0000-0000000FF1CE}_PRJSTDR_{27A9D316-D332-433B-8EB1-1D93EE49F26D}" = Microsoft Office Project 2007 Service Pack 2 (SP2) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_PRJSTDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-003A-0000-0000-0000000FF1CE}" = Microsoft Office Project Standard 2007 "{91120000-003A-0000-0000-0000000FF1CE}_PRJSTDR_{9E73617F-2F38-4864-BD61-BB2DDFE43323}" = Microsoft Office Project 2007 Service Pack 2 (SP2) "{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002 "{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant "{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9D18F7F8-B984-4249-8512-CC621BC59F12}" = Microsoft Location Finder "{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker "{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}" = Windows Live Sync "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI "{AB90749C-7422-4580-8A7A-66CC5E9E5F98}" = iTunes "{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2 "{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8 "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1 "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player "{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation "{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon Camera WIA Driver "{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}" = Nokia Connectivity Cable Driver "{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}" = Windows Rights Management Client with Service Pack 2 "{C1A6B23C-438E-4D08-B508-4E830CA8F335}" = IBM ViaVoice TTS Runtime v6.610 - US English "{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials "{CA9A3609-3ECC-4574-8824-A8161A71A603}" = Canon MP150 "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader "{DE1AF137-C455-494A-A817-EFE44BCCFDEE}" = Works Upgrade "{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management Client Backwards Compatibility SP2 "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F3E7955D-696A-423C-8D38-FCA8A3094F05}" = Microsoft Sapi5 voices for XP "{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call "ActiveScan 2.0" = Panda ActiveScan 2.0 "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "ATI Display Driver" = ATI Display Driver "AVG8Uninstall" = AVG Free 8.5 "CAL" = Canon Camera Access Library "CameraWindowDVC5" = Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX "CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX "CameraWindowLauncher" = Canon Utilities CameraWindow "CCleaner" = CCleaner (remove only) "CSCLIB" = Canon Camera Support Core Library "DPP" = Canon Utilities Digital Photo Professional 3.4 "Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint "Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX "EOS Utility" = Canon Utilities EOS Utility "FrostWire" = FrostWire 4.13.1.7 BETA "GetRight_is1" = GetRight "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "InstallShield_{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon EOS 5D WIA Driver "Macromedia Shockwave Player" = Macromedia Shockwave Player "Magic Academy" = Magic Academy (remove only) "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "mIRC" = mIRC "Money2006b" = Microsoft Money 2006 "Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10) "MP Navigator 2.0" = Canon MP Navigator 2.0 "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "MSNINST" = MSN "MyCamera" = Canon Utilities MyCamera "NeroMultiInstaller!UninstallKey" = Nero Suite "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "Original Data Security Tools" = Canon Utilities Original Data Security Tools "Panda ActiveScan" = Panda ActiveScan "PhotoStitch" = Canon Utilities PhotoStitch "Picture Style Editor" = Canon Utilities Picture Style Editor "PictureItPrem_v11" = Microsoft Digital Image Standard 2006 "PRJSTDR" = Microsoft Office Project Standard 2007 Trial "RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX "RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX "SpywareBlaster_is1" = SpywareBlaster 4.2 "Tweak UI 2.10" = Tweak UI "Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 "WFTK" = Canon Utilities WFT-E1/E2/E3 Utility "WIC" = Windows Imaging Component "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "WinLiveSuite_Wave3" = Windows Live Essentials "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Works2006Setup" = Microsoft Works Suite 2006 Setup Launcher "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "XpsEPSC" = XML Paper Specification Shared Components Pack 1.0 "YInstHelper" = Yahoo! Install Manager "ZoneAlarm" = ZoneAlarm "ZoomBrowser EX" = Canon Utilities ZoomBrowser EX "ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 10/05/2009 7:47:23 PM | Computer Name = KIDSC12288 | Source = Application Error | ID = 1001 Description = Fault bucket 1047666485. Error - 11/05/2009 8:29:40 AM | Computer Name = KIDSC12288 | Source = Microsoft Office 10 | ID = 2001 Description = Rejected Safe Mode action : Microsoft Word. Error - 14/05/2009 1:15:02 AM | Computer Name = KIDSC12288 | Source = Application Hang | ID = 1002 Description = Hanging application AcroRd32.exe, version 8.1.0.137, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 14/05/2009 2:12:07 PM | Computer Name = KIDSC12288 | Source = Application Hang | ID = 1002 Description = Hanging application WINWORD.EXE, version 10.0.6850.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 19/05/2009 9:26:49 PM | Computer Name = KIDSC12288 | Source = Application Error | ID = 1000 Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting module rpcrt4.dll, version 5.1.2600.3173, fault address 0x0000b3d4. Error - 20/05/2009 3:52:29 PM | Computer Name = KIDSC12288 | Source = Application Hang | ID = 1002 Description = Hanging application firefox.exe, version 1.9.0.3399, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 25/05/2009 4:26:54 PM | Computer Name = KIDSC12288 | Source = Application Hang | ID = 1002 Description = Hanging application ZoomBrowser.exe, version 6.1.1.21, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 25/05/2009 4:27:13 PM | Computer Name = KIDSC12288 | Source = Application Hang | ID = 1002 Description = Hanging application ZoomBrowser.exe, version 6.1.1.21, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 25/05/2009 4:28:17 PM | Computer Name = KIDSC12288 | Source = Application Hang | ID = 1001 Description = Fault bucket 593567749. Error - 26/05/2009 7:56:51 AM | Computer Name = KIDSC12288 | Source = Microsoft Office 10 | ID = 2001 Description = Rejected Safe Mode action : Microsoft Word. [ System Events ] Error - 19/05/2009 9:36:58 PM | Computer Name = KIDSC12288 | Source = Service Control Manager | ID = 7001 Description = The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: %%31 Error - 19/05/2009 9:36:58 PM | Computer Name = KIDSC12288 | Source = Service Control Manager | ID = 7001 Description = The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: %%31 Error - 19/05/2009 9:36:58 PM | Computer Name = KIDSC12288 | Source = Service Control Manager | ID = 7001 Description = The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: %%31 Error - 19/05/2009 9:36:58 PM | Computer Name = KIDSC12288 | Source = Service Control Manager | ID = 7001 Description = The TrueVector Internet Monitor service depends on the vsdatant service which failed to start because of the following error: %%31 Error - 19/05/2009 9:36:58 PM | Computer Name = KIDSC12288 | Source = Service Control Manager | ID = 7001 Description = The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: %%31 Error - 19/05/2009 9:36:58 PM | Computer Name = KIDSC12288 | Source = Service Control Manager | ID = 7026 Description = The following boot-start or system-start driver(s) failed to load: AFD Ai2sXP AvgLdx86 AvgMfx86 AvgTdiX Fips intelppm IPSec MRxSmb NetBIOS NetBT NetworkX pavboot RasAcd Rdbss Tcpip vsdatant Error - 19/05/2009 9:37:10 PM | Computer Name = KIDSC12288 | Source = DCOM | ID = 10005 Description = DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} Error - 19/05/2009 9:37:33 PM | Computer Name = KIDSC12288 | Source = DCOM | ID = 10005 Description = DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} Error - 19/05/2009 9:37:56 PM | Computer Name = KIDSC12288 | Source = DCOM | ID = 10005 Description = DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} Error - 19/05/2009 11:18:46 PM | Computer Name = KIDSC12288 | Source = DCOM | ID = 10005 Description = DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} < End of report > Thanks for all your assistance and time. |
|
|
Jun 5 2009, 12:54 AM
Post
#2
|
|
![]() RIP 10/2009 Posts: 2,646 From: NE Victoria, Australia OS: WinXp SP3 |
Hi Noki,
Welcome to Geeks To Go, I'm sorry that we haven't got to you until now, but the forum can get hectic at times. I am sage5, and I will be helping you with this problem. There are a some things that I need to make clear to you, before we continue, that will help us both:
OK, on with the fix: First I need you to download the following tools & save them to your Desktop. ComboFix from one of these locations: Link 1 Link 2 Link 3 * IMPORTANT !!! Save ComboFix.exe to your Desktop
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. ![]() Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: ![]() Click on Yes, to continue scanning for malware. When finished, it shall produce a log for you. Please include the text from C:\ComboFix.txt in your next reply. Cheers, sage5 |
|
|
Jun 10 2009, 07:10 PM
Post
#3
|
|
|
Member ![]() ![]() Posts: 16 OS: xp |
Hi,
Sorry for the delay but I got the log, rt now the pc is very slow and so I decided to unplug it from the inet. Now the log. ComboFix 09-06-09.01 - Owner 10/06/2009 16:29.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.446.120 [GMT -4:00] Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Owner\Favorites\Online Security Guide.lnk c:\windows\system32\ajtafxmt.ini c:\windows\system32\bgbuwmmg.ini c:\windows\system32\cpyfhfrn.ini c:\windows\system32\eeoyibbc.ini c:\windows\system32\eevxajyv.ini c:\windows\system32\endrhobk.ini c:\windows\system32\gfhkj.bak1 c:\windows\system32\gfhkj.bak2 c:\windows\system32\gfhkj.ini c:\windows\system32\giyofkro.ini c:\windows\system32\hbnqpyqu.ini c:\windows\system32\ilsxugas.ini c:\windows\system32\kkopwehf.ini c:\windows\system32\kscnhita.ini c:\windows\system32\nuplshji.ini c:\windows\system32\piyhfbeh.ini c:\windows\system32\pyblkord.ini c:\windows\system32\qldkxmvq.ini c:\windows\system32\rkhwkutu.ini c:\windows\system32\tkrocfxf.ini c:\windows\system32\uscjcqvl.ini c:\windows\system32\vkqslmnf.ini c:\windows\system32\vuourgxk.ini c:\windows\system32\wevakxdj.ini c:\windows\system32\wjmkijdd.ini c:\windows\system32\wyfltmcl.ini c:\windows\system32\ynlcqpxf.ini . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_DOMAINSERVICE ((((((((((((((((((((((((( Files Created from 2009-05-10 to 2009-06-10 ))))))))))))))))))))))))))))))) . 2009-05-31 23:47 . 2009-05-31 23:47 -------- d-----w- c:\windows\system32\scripting 2009-05-31 23:47 . 2009-05-31 23:47 -------- d-----w- c:\windows\l2schemas 2009-05-31 23:47 . 2009-05-31 23:47 -------- d-----w- c:\windows\system32\en 2009-05-31 23:47 . 2009-05-31 23:47 -------- d-----w- c:\windows\system32\bits 2009-05-31 23:42 . 2009-05-31 23:48 -------- d-----w- c:\windows\ServicePackFiles 2009-05-31 23:26 . 2009-05-31 23:26 -------- d-----w- c:\windows\EHome 2009-05-31 22:49 . 2009-05-31 22:49 -------- d-sh--w- c:\documents and settings\Owner\IECompatCache 2009-05-31 22:47 . 2009-05-31 22:47 -------- d-sh--w- c:\documents and settings\Owner\PrivacIE 2009-05-31 22:42 . 2009-05-31 22:42 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache 2009-05-31 22:41 . 2009-05-31 22:41 -------- d-sh--w- c:\documents and settings\Owner\IETldCache 2009-05-31 22:36 . 2009-05-31 22:36 -------- d-----w- c:\windows\ie8updates 2009-05-31 22:35 . 2009-05-12 05:11 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll 2009-05-31 22:31 . 2009-05-31 22:35 -------- dc-h--w- c:\windows\ie8 2009-05-31 15:43 . 2009-05-31 15:44 -------- d-----w- C:\a0339e955f04ee68d2 2009-05-31 15:41 . 2009-05-31 16:05 -------- d-----w- c:\windows\SxsCaPendDel 2009-05-31 05:50 . 2009-05-31 05:51 -------- d-----w- C:\Rooter$ 2009-05-31 05:28 . 2009-05-31 05:28 3371383 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2009-05-20 05:22 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll 2009-05-20 05:22 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll 2009-05-20 05:22 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe 2009-05-20 05:22 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll 2009-05-20 05:22 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe 2009-05-20 05:22 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll 2009-05-20 05:22 . 2009-02-09 12:10 729088 -c----w- c:\windows\system32\dllcache\lsasrv.dll 2009-05-20 05:22 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll 2009-05-20 05:22 . 2009-02-09 12:10 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll 2009-05-20 05:22 . 2009-02-06 11:06 2145280 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe 2009-05-20 05:22 . 2009-02-06 11:08 2189056 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe 2009-05-20 05:22 . 2009-02-06 10:32 2023936 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe 2009-05-20 05:20 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll 2009-05-20 05:20 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe 2009-05-20 04:12 . 2009-05-20 04:12 -------- d-----w- c:\documents and settings\Owner\Tracing 2009-05-20 04:08 . 2006-11-29 17:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll 2009-05-20 04:08 . 2009-05-20 04:08 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition 2009-05-20 04:05 . 2009-05-20 04:05 -------- d-----w- c:\program files\Microsoft 2009-05-20 04:04 . 2009-05-20 04:04 -------- d-----w- c:\program files\Windows Live SkyDrive 2009-05-20 04:04 . 2009-05-20 04:10 -------- d-----w- c:\program files\Windows Live 2009-05-20 03:43 . 2009-05-20 03:43 -------- d-----w- c:\program files\Common Files\Windows Live 2009-05-19 19:01 . 2008-06-19 21:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys 2009-05-19 14:18 . 2009-05-19 14:17 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-05-19 14:15 . 2009-05-19 14:15 152576 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_13\lzma.dll 2009-05-19 11:55 . 2009-05-19 11:55 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes 2009-05-19 11:55 . 2009-05-26 17:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-05-19 11:55 . 2009-05-26 17:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-05-19 11:55 . 2009-05-31 05:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-05-19 11:55 . 2009-05-19 11:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-05-19 03:30 . 2009-06-01 20:33 -------- d--h--w- C:\$AVG8.VAULT$ 2009-05-19 02:33 . 2009-05-19 02:33 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP 2009-05-19 02:23 . 2008-12-04 05:25 120832 ----a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vuedfkts.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}\plugins\npietab.dll 2009-05-19 02:07 . 2009-05-19 02:07 11952 ----a-w- c:\windows\system32\avgrsstx.dll 2009-05-19 02:07 . 2009-05-19 02:07 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2009-05-19 02:07 . 2009-05-19 02:07 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2009-05-19 02:07 . 2009-06-02 16:50 -------- d-----w- c:\windows\system32\drivers\Avg 2009-05-19 02:07 . 2009-05-19 02:07 -------- d-----w- c:\program files\AVG 2009-05-19 02:07 . 2009-05-19 02:07 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8 2009-05-19 01:24 . 2009-02-16 04:10 69000 ----a-w- c:\windows\system32\zlcomm.dll 2009-05-19 01:24 . 2009-02-16 04:10 103816 ----a-w- c:\windows\system32\zlcommdb.dll 2009-05-19 01:24 . 2009-02-16 04:10 1221512 ----a-w- c:\windows\system32\zpeng25.dll 2009-05-19 00:50 . 2009-05-19 00:50 -------- d-----w- c:\program files\CCleaner 2009-05-15 03:33 . 2009-05-15 03:33 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\RcIncidents . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-10 20:22 . 2006-10-04 20:56 42308 ----a-w- c:\documents and settings\Owner\Application Data\wklnhst.dat 2009-06-01 00:32 . 2008-03-01 00:49 -------- d-----w- c:\program files\GetRight 2009-05-31 23:52 . 2006-10-04 20:10 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat 2009-05-29 21:10 . 2008-09-06 22:22 -------- d-----w- c:\documents and settings\Owner\Application Data\Canon 2009-05-27 15:25 . 2007-04-18 23:55 -------- d-----w- c:\documents and settings\Owner\Application Data\Skype 2009-05-20 06:38 . 2009-01-17 05:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-05-20 06:35 . 2006-10-04 20:47 -------- d-----w- c:\program files\Microsoft Works 2009-05-20 05:45 . 2008-02-29 22:04 -------- d-----w- c:\program files\Microsoft Silverlight 2009-05-19 17:49 . 2008-02-29 07:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-05-19 14:17 . 2007-04-28 00:03 -------- d-----w- c:\program files\Java 2009-05-19 14:05 . 2008-02-29 07:25 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-05-19 02:37 . 2008-02-29 07:32 -------- d-----w- c:\program files\SpywareBlaster 2009-05-19 02:23 . 2008-03-01 00:48 167376 ----a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vuedfkts.default\FlashGot.exe 2009-05-19 02:07 . 2008-02-29 07:40 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2009-05-19 01:24 . 2007-04-28 00:51 4212 ---ha-w- c:\windows\system32\zllictbl.dat 2009-05-19 00:58 . 2007-04-18 23:54 -------- d-----w- c:\program files\Google 2009-05-19 00:33 . 2008-02-29 07:36 -------- d-----w- c:\program files\SpywareGuard 2009-05-19 00:33 . 2006-11-29 22:08 -------- d-----w- c:\program files\Windows Live Toolbar 2009-05-19 00:32 . 2007-04-12 15:54 -------- d-----w- c:\program files\Yahoo! 2009-05-17 17:26 . 2009-05-17 17:27 38912 ----a-w- c:\windows\Internet Logs\xDB115.tmp 2009-05-16 14:51 . 2009-05-16 17:59 88064 ----a-w- c:\windows\Internet Logs\xDB114.tmp 2009-05-13 23:38 . 2009-05-13 23:41 77312 ----a-w- c:\windows\Internet Logs\xDB113.tmp 2009-05-11 19:13 . 2009-05-11 19:16 28672 ----a-w- c:\windows\Internet Logs\xDB112.tmp 2009-05-11 12:37 . 2009-05-11 16:30 23040 ----a-w- c:\windows\Internet Logs\xDB111.tmp 2009-05-11 00:59 . 2009-05-11 01:00 28672 ----a-w- c:\windows\Internet Logs\xDB110.tmp 2009-05-10 18:26 . 2009-05-10 23:20 43520 ----a-w- c:\windows\Internet Logs\xDB10F.tmp 2009-05-09 03:42 . 2009-05-09 12:21 33280 ----a-w- c:\windows\Internet Logs\xDB10E.tmp 2009-05-08 04:51 . 2009-05-08 22:18 42496 ----a-w- c:\windows\Internet Logs\xDB10D.tmp 2009-05-07 21:37 . 2009-05-08 02:10 39424 ----a-w- c:\windows\Internet Logs\xDB10C.tmp 2009-05-07 01:28 . 2009-05-07 13:55 68096 ----a-w- c:\windows\Internet Logs\xDB10B.tmp 2009-05-05 01:28 . 2009-05-05 11:26 32256 ----a-w- c:\windows\Internet Logs\xDB10A.tmp 2009-05-04 12:31 . 2009-05-04 23:58 53248 ----a-w- c:\windows\Internet Logs\xDB109.tmp 2009-05-02 23:49 . 2009-05-03 13:04 27648 ----a-w- c:\windows\Internet Logs\xDB108.tmp 2009-05-02 14:00 . 2009-05-02 22:41 27648 ----a-w- c:\windows\Internet Logs\xDB107.tmp 2009-05-02 01:46 . 2009-05-02 12:27 138240 ----a-w- c:\windows\Internet Logs\xDB106.tmp 2009-05-01 11:33 . 2008-04-08 20:03 26936763 ----a-w- c:\windows\Internet Logs\tvDebug.zip 2009-04-28 00:31 . 2009-04-28 12:06 54272 ----a-w- c:\windows\Internet Logs\xDB105.tmp 2009-04-25 20:52 . 2009-04-26 11:19 53248 ----a-w- c:\windows\Internet Logs\xDB104.tmp 2009-04-25 14:20 . 2009-04-25 16:52 27136 ----a-w- c:\windows\Internet Logs\xDB103.tmp 2009-04-24 17:55 . 2009-04-25 12:13 29184 ----a-w- c:\windows\Internet Logs\xDB102.tmp 2009-04-24 01:14 . 2009-04-24 14:54 26112 ----a-w- c:\windows\Internet Logs\xDB101.tmp 2009-04-23 20:51 . 2009-04-23 23:42 96768 ----a-w- c:\windows\Internet Logs\xDB100.tmp 2009-04-21 01:23 . 2009-04-22 00:31 61440 ----a-w- c:\windows\Internet Logs\xDBFF.tmp 2009-04-19 03:11 . 2009-04-19 12:27 66048 ----a-w- c:\windows\Internet Logs\xDBFE.tmp 2009-04-16 17:56 . 2009-04-16 21:52 37888 ----a-w- c:\windows\Internet Logs\xDBFD.tmp 2009-04-15 01:18 . 2009-04-15 19:53 57344 ----a-w- c:\windows\Internet Logs\xDBFC.tmp 2009-04-13 20:41 . 2009-04-14 00:23 36864 ----a-w- c:\windows\Internet Logs\xDBFB.tmp 2009-04-13 03:30 . 2009-04-13 12:16 35840 ----a-w- c:\windows\Internet Logs\xDBFA.tmp 2009-04-12 13:08 . 2009-04-12 17:23 62976 ----a-w- c:\windows\Internet Logs\xDBF9.tmp 2009-04-09 22:19 . 2009-04-09 22:20 31744 ----a-w- c:\windows\Internet Logs\xDBF8.tmp 2009-04-09 20:09 . 2009-04-09 20:30 40960 ----a-w- c:\windows\Internet Logs\xDBF7.tmp 2009-04-08 14:33 . 2009-04-08 19:54 38400 ----a-w- c:\windows\Internet Logs\xDBF6.tmp 2009-04-07 05:08 . 2009-04-07 11:45 61952 ----a-w- c:\windows\Internet Logs\xDBF5.tmp 2009-04-05 00:10 . 2009-04-05 00:11 36864 ----a-w- c:\windows\Internet Logs\xDBF4.tmp 2009-04-04 13:04 . 2009-04-04 15:29 144384 ----a-w- c:\windows\Internet Logs\xDBF3.tmp 2009-03-28 20:52 . 2009-03-29 13:13 34304 ----a-w- c:\windows\Internet Logs\xDBF2.tmp 2009-03-28 13:46 . 2009-03-28 17:21 125440 ----a-w- c:\windows\Internet Logs\xDBF1.tmp 2009-03-27 13:04 . 2009-03-27 23:57 24576 ----a-w- c:\windows\Internet Logs\xDBF0.tmp 2009-03-27 04:46 . 2009-03-27 11:56 146944 ----a-w- c:\windows\Internet Logs\xDBEF.tmp 2009-03-25 10:29 . 2006-10-04 20:27 130432 ----a-w- c:\windows\system32\drivers\Rtnicxp.sys 2009-03-22 15:37 . 2009-03-22 16:06 87040 ----a-w- c:\windows\Internet Logs\xDBEE.tmp 2009-03-21 03:58 . 2009-03-21 11:31 81408 ----a-w- c:\windows\Internet Logs\xDBED.tmp 2009-03-19 23:06 . 2009-03-19 23:07 36352 ----a-w- c:\windows\Internet Logs\xDBEC.tmp 2009-03-19 12:04 . 2009-03-19 13:18 25088 ----a-w- c:\windows\Internet Logs\xDBEB.tmp 2009-03-19 02:07 . 2009-03-19 11:19 50176 ----a-w- c:\windows\Internet Logs\xDBEA.tmp 2009-03-17 19:30 . 2009-03-18 01:03 28672 ----a-w- c:\windows\Internet Logs\xDBE9.tmp 2009-03-17 18:22 . 2009-03-17 18:27 149504 ----a-w- c:\windows\Internet Logs\xDBE8.tmp 2006-10-04 21:57 . 2006-10-04 21:57 56 -c--a-w- c:\program files\Common Files\appop.log . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "VX1000"="c:\windows\vVX1000.exe" [2006-10-13 707376] "ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-16 981384] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-19 1947928] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2005-10-15 14864384] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-05-19 02:07 11952 ----a-w- c:\windows\system32\avgrsstx.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk backup=c:\windows\pss\Windows Search.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\FrostWire\\FrostWire.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"= "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"= "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"= R0 ivicd;Ivi CDVD Filter Driver;c:\windows\system32\drivers\ivicd.sys [04/10/2006 5:56 PM 38784] R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [19/05/2009 3:01 PM 28544] R1 Ai2sXP;Ai2sXP;c:\windows\system32\drivers\Ai2sXP.sys [12/10/2006 10:17 AM 7296] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [18/05/2009 10:07 PM 325896] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [18/05/2009 10:07 PM 108552] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [18/05/2009 10:07 PM 908568] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [18/05/2009 10:07 PM 298776] R2 HPMobileDisk;HPMobileDisk;c:\windows\system32\drivers\hpmobiledisk.sys [05/10/2006 8:49 AM 199040] S2 ieik9uaaan;Print Spooler Service;c:\windows\system32\kgngdne.exe /service --> c:\windows\system32\kgngdne.exe [?] S3 iviudf;iviudf;c:\windows\system32\drivers\IviUdf.sys [04/10/2006 5:56 PM 116224] S3 SDTHOOK;SDTHOOK;c:\windows\system32\drivers\SDTHOOK.SYS [29/02/2008 2:05 AM 44928] --- Other Services/Drivers In Memory --- *Deregistered* - udffsrec [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . - - - - ORPHANS REMOVED - - - - BHO-{AA53ED35-9CED-402F-AAE5-32482DDB343D} - c:\windows\system32\jkhfg.dll HKLM-Run-NWEReboot - (no file) HKU-Default-Run-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe HKU-Default-RunOnce-IETI - c:\program files\Skype\Phone\IEPlugin\unins000.exe Notify-opnmnmm - opnmnmm.dll SafeBoot-procexp90.Sys . ------- Supplementary Scan ------- . uInternet Connection Wizard,ShellNext = iexplore uSearchURL,(Default) = hxxp://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR IE: &Search - ?p=ZJxdm088YYCA IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx IE: Download with GetRight - c:\program files\GetRight\GRdownload.htm IE: Open with GetRight Browser - c:\program files\GetRight\GRbrowse.htm FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vuedfkts.default\ FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPGetRt.dll FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-10 16:37 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(676) c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(2632) c:\windows\system32\ieframe.dll c:\windows\system32\OneX.DLL c:\windows\system32\eappprxy.dll c:\windows\system32\msls31.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\ati2evxx.exe c:\windows\system32\ZoneLabs\vsmon.exe c:\windows\system32\ati2evxx.exe c:\windows\system32\Crypserv.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Microsoft LifeCam\MSCamS32.exe c:\windows\system32\searchindexer.exe c:\program files\AVG\AVG8\avgrsx.exe c:\progra~1\AVG\AVG8\avgnsx.exe c:\program files\Canon\CAL\CALMAIN.exe c:\program files\AVG\AVG8\avgcsrvx.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Completion time: 2009-06-10 16:46 - machine was rebooted ComboFix-quarantined-files.txt 2009-06-10 20:46 Pre-Run: 139,502,366,720 bytes free Post-Run: 139,395,616,768 bytes free 308 --- E O F --- 2009-03-14 02:02 |
|
|
Jun 10 2009, 09:52 PM
Post
#4
|
|
![]() RIP 10/2009 Posts: 2,646 From: NE Victoria, Australia OS: WinXp SP3 |
Hi Noki,
That is looking much better. This is worrying, from the last log: QUOTE ComboFix 09-06-09.01 - Owner 10/06/2009 16:29.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.446.120 [GMT -4:00] Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} * Created a new restore point Do you have a subscription to AVG, or use the free version? If using the freebie, update to the new version, Here If you want to try something else/better: I have listed a couple of free versions below. Please download and install 1 of them Anti-virus: Please install one only: Avast! Free Edition or Avira AntiVir Personal Anti-Virus Tutorials/Manuals: Avast Tutorial Avast Home Edition Manual Antivir Manual Please allow the new Anti-virus to run a full System scan, and at the end of the process you should be able to save a scan log. If the scan report window does not have a "Save as Report" button (or similar), please highlight the text in the window & copy & paste it to a new Notepad file. Save it as C:\avscan.txt if you can. Cheers, sage5 |
|
|
Jun 12 2009, 04:34 PM
Post
#5
|
|
|
Member ![]() ![]() Posts: 16 OS: xp |
Hi, that maybe because the inet on that pc was unplugged the day before or so, since is not updating....besides I never let the AV to run outdated, believe it or not I have cleaned this pc before and thats why I know it should stay updated on every thing.
Btw I did unplugged the inet because the pc is acting weird even after the cleaning, still slow and you can hear the machine working really hard. I'll run the scan and I'll come back with the log. |
|
|
Jun 22 2009, 04:18 PM
Post
#6
|
|
![]() RIP 10/2009 Posts: 2,646 From: NE Victoria, Australia OS: WinXp SP3 |
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic. |
|
|
Jun 25 2009, 01:00 AM
Post
#7
|
|
![]() RIP 10/2009 Posts: 2,646 From: NE Victoria, Australia OS: WinXp SP3 |
Due to the length of time between posts please delete your version of OTL.exe from the Desktop & download a fresh version from:
OTListIt Run OTL:
NOTE: These can be large files, and there is a limit to the number of characters that can be posted at once on this forum. It may require you to make 2 posts, to get all the information to me |
|
|
Jun 25 2009, 10:28 PM
Post
#8
|
|
|
Member ![]() ![]() Posts: 16 OS: xp |
Thx again for re-opening the topic, I'll bring this to you in the next couple days and I'll add a new AV scan log.
|
|
|
Jun 27 2009, 07:58 PM
Post
#9
|
|
|
Member ![]() ![]() Posts: 16 OS: xp |
Hi, these are the logs.
>>> OTL.txt OTL logfile created on: 28/06/2009 7:32:46 PM - Run 1 OTL by OldTimer - Version 3.0.5.3 Folder = C:\Documents and Settings\Owner\Desktop Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy 446.48 Mb Total Physical Memory | 55.61 Mb Available Physical Memory | 12.46% Memory free 1.03 Gb Paging File | 0.68 Gb Available in Paging File | 66.15% Paging File free Paging file location(s): C:\pagefile.sys 672 1344 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 149.05 Gb Total Space | 130.08 Gb Free Space | 87.27% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: KIDSC12288 Current User Name: Owner Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: Off File Age = 30 Days Output = Standard ========== Processes (SafeList) ========== PRC - [2005/08/31 01:36:10 | 00,376,832 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe PRC - [2009/02/16 00:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe PRC - [2005/08/31 01:36:10 | 00,376,832 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe PRC - [2008/04/13 20:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE PRC - [2009/05/18 22:07:12 | 00,298,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe PRC - [2006/01/28 19:35:10 | 00,069,632 | ---- | M] (CrypKey (Canada) Ltd.) -- C:\WINDOWS\System32\crypserv.exe PRC - [2006/10/13 17:01:06 | 00,207,664 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe PRC - [2009/05/18 22:07:20 | 00,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe PRC - [2009/05/18 22:07:20 | 00,594,712 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgnsx.exe PRC - [2009/05/18 22:07:13 | 00,908,568 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe PRC - [2007/01/31 15:55:42 | 00,096,370 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe PRC - [2009/05/18 22:07:20 | 00,692,504 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgcsrvx.exe PRC - [2009/02/06 06:10:02 | 00,227,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\wmiprvse.exe PRC - [2005/10/14 21:51:40 | 14,864,384 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.EXE PRC - [2009/02/16 00:10:22 | 00,981,384 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe PRC - [2009/05/18 22:07:14 | 01,947,928 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgtray.exe PRC - [2009/06/27 21:59:30 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe ========== Win32 Services (SafeList) ========== SRV - [2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped]) SRV - [2005/08/31 01:36:10 | 00,376,832 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Running]) SRV - [2005/08/30 21:05:00 | 00,516,096 | ---- | M] () -- C:\WINDOWS\System32\ati2sgag.exe -- (ATI Smart [Auto | Stopped]) SRV - [2009/05/18 22:07:13 | 00,908,568 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe -- (avg8emc [Auto | Running]) SRV - [2009/05/18 22:07:12 | 00,298,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd [Auto | Running]) SRV - [2007/01/31 15:55:42 | 00,096,370 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8 [Auto | Running]) SRV - [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) SRV - [2006/01/28 19:35:10 | 00,069,632 | ---- | M] (CrypKey (Canada) Ltd.) -- C:\WINDOWS\System32\crypserv.exe -- (Crypkey License [Auto | Running]) SRV - [2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped]) SRV - [2008/04/13 20:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running]) SRV - [2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped]) SRV - File not found -- -- (ieik9uaaan [Auto | Stopped]) SRV - [2007/03/14 19:05:42 | 00,500,800 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Stopped]) SRV - [2009/05/19 10:17:56 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Disabled | Stopped]) SRV - [2006/10/13 17:01:06 | 00,207,664 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc [Auto | Running]) SRV - [2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped]) SRV - [2008/11/04 01:06:28 | 00,441,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped]) SRV - [2006/10/26 15:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped]) SRV - [2009/02/16 00:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe -- (vsmon [Auto | Running]) SRV - [2006/10/18 21:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped]) ========== Driver Services (SafeList) ========== DRV - [2006/05/03 17:08:50 | 00,007,296 | ---- | M] (Ai Squared ) -- C:\WINDOWS\System32\drivers\Ai2sXP.sys -- (Ai2sXP [System | Running]) DRV - [2005/08/31 01:42:36 | 01,333,760 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys -- (ati2mtag [On_Demand | Running]) DRV - [2009/05/18 22:07:40 | 00,325,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgldx86.sys -- (AvgLdx86 [System | Running]) DRV - [2009/05/18 22:07:39 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys -- (AvgMfx86 [System | Running]) DRV - [2009/05/18 22:07:41 | 00,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgtdix.sys -- (AvgTdiX [System | Running]) DRV - [2006/09/19 14:44:04 | 00,015,664 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running]) DRV - [2008/04/13 12:36:05 | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) -- C:\WINDOWS\System32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running]) DRV - [2006/10/05 08:49:30 | 00,199,040 | ---- | M] (HP) -- C:\WINDOWS\System32\Drivers\hpmobiledisk.sys -- (HPMobileDisk [Auto | Running]) DRV - [2005/10/18 17:15:42 | 04,034,048 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running]) DRV - [2003/12/26 09:48:14 | 00,010,752 | ---- | M] (InterVideo, Inc.) -- C:\WINDOWS\System32\drivers\iviaspi.sys -- (Iviaspi [On_Demand | Running]) DRV - [2005/01/12 06:29:28 | 00,038,784 | ---- | M] (InterVideo) -- C:\WINDOWS\system32\drivers\ivicd.sys -- (ivicd [Boot | Running]) DRV - [2005/01/12 20:28:04 | 00,116,224 | ---- | M] (InterVideo) -- C:\WINDOWS\System32\drivers\IviUdf.sys -- (iviudf [On_Demand | Stopped]) DRV - [2006/01/09 22:47:27 | 00,031,846 | ---- | M] () -- C:\WINDOWS\system32\ckldrv.sys -- (NetworkX [System | Running]) DRV - [2008/05/02 11:58:12 | 00,017,536 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\ccdcmb.sys -- (nmwcd [On_Demand | Stopped]) DRV - [2008/05/02 11:58:14 | 00,020,864 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\ccdcmbo.sys -- (nmwcdc [On_Demand | Stopped]) DRV - [2008/06/19 17:24:30 | 00,028,544 | ---- | M] (Panda Security, S.L.) -- C:\WINDOWS\system32\drivers\pavboot.sys -- (pavboot [Boot | Running]) DRV - [2003/09/19 01:47:00 | 00,010,368 | ---- | M] (Padus, Inc.) -- C:\WINDOWS\System32\drivers\pfc.sys -- (Pfc [On_Demand | Running]) DRV - [2006/02/28 08:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running]) DRV - [2005/11/24 19:51:38 | 00,245,248 | ---- | M] (Ralink Technology, Corp.) -- C:\WINDOWS\System32\DRIVERS\rt73.sys -- (RT73 [On_Demand | Stopped]) DRV - [2009/03/25 06:29:52 | 00,130,432 | ---- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\System32\DRIVERS\Rtnicxp.sys -- (RTL8023xp [On_Demand | Stopped]) DRV - [2004/08/03 18:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\DRIVERS\RTL8139.SYS -- (rtl8139 [On_Demand | Stopped]) DRV - [2007/06/05 11:56:40 | 00,044,928 | ---- | M] (Panda Software) -- C:\WINDOWS\System32\DRIVERS\SDTHOOK.sys -- (SDTHOOK [On_Demand | Stopped]) DRV - [2007/11/13 06:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped]) DRV - [2001/08/17 14:56:16 | 00,007,552 | ---- | M] (Sony Corporation) -- C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS -- (SONYPVU1 [On_Demand | Stopped]) DRV - [2008/11/17 02:24:00 | 00,051,688 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\system32\ZoneLabs\srescan.sys -- (srescan [Boot | Running]) DRV - [2008/05/02 11:58:14 | 00,008,064 | ---- | M] (Windows ® Codename Longhorn DDK provider) -- C:\WINDOWS\System32\DRIVERS\usbser_lowerflt.sys -- (upperdev [On_Demand | Stopped]) DRV - [2008/04/13 14:45:12 | 00,060,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbaudio.sys -- (usbaudio [On_Demand | Running]) DRV - [2008/04/13 14:45:36 | 00,026,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbser.sys -- (usbser [On_Demand | Stopped]) DRV - [2008/05/02 11:58:28 | 00,008,064 | ---- | M] (Windows ® Codename Longhorn DDK provider) -- C:\WINDOWS\System32\DRIVERS\usbser_lowerfltj.sys -- (UsbserFilt [On_Demand | Stopped]) DRV - [2009/02/16 00:10:26 | 00,353,672 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\vsdatant.sys -- (vsdatant [System | Running]) DRV - [2006/10/13 17:04:28 | 01,966,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\VX1000.sys -- (VX1000 [On_Demand | Running]) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-673811579-4275867939-2855663147-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKU\S-1-5-21-673811579-4275867939-2855663147-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1 IE - HKU\S-1-5-21-673811579-4275867939-2855663147-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch IE - HKU\S-1-5-21-673811579-4275867939-2855663147-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/ IE - HKU\S-1-5-21-673811579-4275867939-2855663147-1003\S-1-5-21-673811579-4275867939-2855663147-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official" FF - prefs.js..extensions.enabledItems: filtersetg@updater:0.3.1.3 FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.2 FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5 FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.1.8.7 FF - prefs.js..extensions.enabledItems: {77b819fa-95ad-4f2c-ac7c-486b356188a9}:1.5.20090207 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: plugin@yontoo.com:1.03.01 FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10 FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/05/18 22:07:11 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/05/19 10:17:56 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/05/31 11:48:11 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/05/02 19:28:45 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/05/19 10:18:17 | 00,000,000 | ---D | M] [2008/10/19 20:35:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Extensions [2008/10/19 20:35:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/06/03 19:40:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\vuedfkts.default\extensions [2009/05/18 22:23:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\vuedfkts.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34} [2009/05/18 22:23:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\vuedfkts.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9} [2007/08/03 15:03:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\vuedfkts.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e} [2009/05/18 22:23:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\vuedfkts.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2008/02/29 01:30:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\vuedfkts.default\extensions\filtersetg@updater [2009/05/18 22:23:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\vuedfkts.default\extensions\plugin@yontoo.com [2008/06/19 22:57:24 | 00,001,108 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\vuedfkts.default\searchplugins\wikipedia-en.xml [2009/06/02 22:55:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2009/04/28 15:14:14 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2008/02/29 21:36:40 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [2009/05/19 10:18:28 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [2009/04/28 15:14:06 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009/04/28 15:14:06 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2009/05/19 10:17:56 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll [2007/10/19 20:54:06 | 00,717,312 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll [2006/06/06 18:44:12 | 00,108,544 | ---- | M] (Headlight Software, Inc.) -- C:\Program Files\mozilla firefox\plugins\NPGetRt.dll [2009/04/28 15:14:09 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll [2006/10/26 21:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2007/05/10 23:52:34 | 00,095,864 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2007/04/27 21:22:18 | 00,131,072 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2007/04/27 21:22:18 | 00,131,072 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2007/04/27 21:22:18 | 00,131,072 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2007/04/27 21:22:18 | 00,131,072 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2007/04/27 21:22:19 | 00,131,072 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2007/04/27 21:22:19 | 00,131,072 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll [2007/04/27 21:22:19 | 00,131,072 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll [2007/11/20 17:52:00 | 02,884,992 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\NPSWF32.dll [2008/09/24 21:21:16 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml [2008/09/24 21:21:16 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml [2008/09/24 21:21:16 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml [2008/11/14 14:55:53 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml [2008/09/24 21:21:16 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2008/09/24 21:21:16 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No CLSID value found. O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (AhIeBho Class) - {10384d0e-2bc1-48b6-844b-ad0e9e6d2511} - C:\Program Files\ZoomText 9.0\AHOI\ah_ie_bho.dll (Ai Squared ) O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) O2 - BHO: (IE to GetRight Helper) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll (Headlight Software, Inc.) O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) O3 - HKU\S-1-5-21-673811579-4275867939-2855663147-1003\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found. O3 - HKU\S-1-5-21-673811579-4275867939-2855663147-1003\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found. O3 - HKU\S-1-5-21-673811579-4275867939-2855663147-1003\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found. O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-673811579-4275867939-2855663147-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-673811579-4275867939-2855663147-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-21-673811579-4275867939-2855663147-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-21-673811579-4275867939-2855663147-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\S-1-5-21-673811579-4275867939-2855663147-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &Search - File not found O8 - Extra context menu item: Add to Windows &Live Favorites - File not found O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm () O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm () O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O15 - HKLM\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKU\.DEFAULT\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKU\S-1-5-18\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKU\S-1-5-21-673811579-4275867939-2855663147-1003\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet) O15 - HKU\S-1-5-21-673811579-4275867939-2855663147-1003\..Trusted Domains: 198 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_01) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03) O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ipp - No CLSID value found O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.) O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.) O24 - Desktop Components:0 (My Current Home Page) - About:Home O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/10/04 16:11:14 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found ========== Files/Folders - Created Within 30 Days ========== [1 C:\WINDOWS\*.tmp files] [2009/06/28 19:25:35 | 00,000,706 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\DiskAid.lnk [2009/06/28 19:25:33 | 00,000,000 | ---D | C] -- C:\Program Files\DigiDNA [2009/06/28 19:21:51 | 00,513,536 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe [2009/06/18 01:16:53 | 00,043,520 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\GETTING READY TO LEAVE Lesson plan LS III.doc [2009/06/17 21:01:17 | 00,033,792 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\GETTING READY TO LEAVE Lesson plan.doc [2009/06/10 16:56:22 | 00,000,000 | -HSD | C] -- C:\RECYCLER [2009/06/10 16:27:31 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe [2009/06/10 16:27:31 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe [2009/06/10 16:27:31 | 00,155,136 | ---- | C] () -- C:\WINDOWS\PEV.exe [2009/06/10 16:27:31 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe [2009/06/10 16:27:31 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2009/06/10 16:27:31 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2009/06/10 16:27:31 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2009/06/10 16:27:31 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe [2009/06/10 16:24:15 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT [2009/06/10 16:24:08 | 00,000,000 | ---D | C] -- C:\Qoobox [2009/06/10 16:22:03 | 00,001,738 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\LAURA PC.rtf [2009/06/10 16:21:44 | 03,021,343 | R--- | C] () -- C:\Documents and Settings\Owner\Desktop\ComboFix.exe [2009/05/31 20:09:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch [2009/05/31 19:47:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting [2009/05/31 19:47:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\l2schemas [2009/05/31 19:47:37 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\en [2009/05/31 19:47:36 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\bits [2009/05/31 19:42:04 | 00,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles [2009/05/31 19:26:38 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$ [2009/05/31 19:26:26 | 00,000,000 | ---D | C] -- C:\WINDOWS\EHome [2009/05/31 18:36:40 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates [2009/05/31 18:35:40 | 00,102,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iecompat.dll [2009/05/31 18:31:13 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8 [2009/05/31 12:24:26 | 01,089,593 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ntprint.cat [2009/05/31 11:52:19 | 00,000,000 | -HSD | C] -- C:\Config.Msi [2009/05/31 11:43:29 | 00,000,000 | ---D | C] -- C:\a0339e955f04ee68d2 [2009/05/31 11:41:51 | 00,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel [2009/05/31 01:50:44 | 00,000,000 | ---D | C] -- C:\Rooter$ [2009/05/31 01:26:09 | 00,267,612 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Rooter.exe [2009/05/31 01:17:53 | 00,264,704 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\TFC.exe [2008/07/21 16:14:10 | 00,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll [2008/02/29 14:42:40 | 00,000,988 | ---- | C] () -- C:\WINDOWS\wininit.ini [2008/02/29 01:46:30 | 00,011,776 | ---- | C] () -- C:\WINDOWS\System32\ZPORT4AS.dll [2007/09/27 10:51:02 | 00,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini [2007/09/27 10:48:48 | 00,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini [2007/09/27 10:48:28 | 00,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini [2007/09/09 16:04:08 | 00,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll [2007/04/27 20:51:23 | 00,796,312 | ---- | C] () -- C:\WINDOWS\System32\libeay32_0.9.6l.dll [2007/01/22 19:21:39 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2006/10/12 10:54:26 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini [2006/10/12 10:18:14 | 00,000,046 | ---- | C] () -- C:\WINDOWS\Crypkey.ini [2006/10/12 10:18:11 | 00,031,846 | ---- | C] () -- C:\WINDOWS\System32\Ckldrv.sys [2006/10/12 10:18:11 | 00,018,432 | ---- | C] () -- C:\WINDOWS\Setup_ck.dll [2006/10/12 10:17:59 | 00,000,380 | ---- | C] () -- C:\WINDOWS\dcmuser.ini [2006/10/12 10:06:45 | 00,000,090 | ---- | C] () -- C:\WINDOWS\TestSupp.ini [2006/10/05 08:50:04 | 00,001,260 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini [2006/10/04 17:56:51 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll [2006/10/04 17:56:51 | 00,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll [2006/10/04 17:56:51 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll [2006/10/04 17:56:51 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll [2006/10/04 17:56:51 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll [2006/10/04 17:56:51 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll [2006/10/04 17:56:21 | 00,005,248 | ---- | C] () -- C:\WINDOWS\System32\drivers\udffsrec.sys [2006/10/04 16:48:29 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2006/10/04 16:41:13 | 00,000,259 | ---- | C] () -- C:\WINDOWS\lgfwup.ini [2006/10/04 16:24:25 | 00,157,184 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll [2006/04/27 06:19:01 | 00,015,498 | ---- | C] () -- C:\WINDOWS\VX1000.ini [2006/02/28 08:00:00 | 00,000,616 | ---- | C] () -- C:\WINDOWS\win.ini [2006/02/28 08:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini ========== Files - Modified Within 30 Days ========== [1 C:\WINDOWS\*.tmp files] [2009/06/28 19:30:15 | 00,350,193 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml [2009/06/28 19:30:08 | 00,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009/06/28 19:29:35 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009/06/28 19:29:18 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009/06/28 19:29:16 | 46,824,2432 | -HS- | M] () -- C:\hiberfil.sys [2009/06/28 19:25:35 | 00,000,706 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\DiskAid.lnk [2009/06/28 19:23:48 | 37,523,701 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm [2009/06/28 19:23:48 | 06,061,540 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg [2009/06/28 19:23:48 | 00,434,673 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg [2009/06/28 19:23:48 | 00,099,574 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg [2009/06/28 10:04:08 | 00,020,992 | ---- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/06/27 21:59:30 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe [2009/06/26 19:33:57 | 00,042,018 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\wklnhst.dat [2009/06/18 01:16:53 | 00,043,520 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\GETTING READY TO LEAVE Lesson plan LS III.doc [2009/06/17 23:43:57 | 00,063,536 | ---- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT [2009/06/17 21:01:17 | 00,033,792 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\GETTING READY TO LEAVE Lesson plan.doc [2009/06/10 19:07:52 | 00,000,616 | ---- | M] () -- C:\WINDOWS\win.ini [2009/06/10 19:07:52 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini [2009/06/10 19:07:52 | 00,000,211 | RHS- | M] () -- C:\boot.ini [2009/06/10 16:37:40 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2009/06/09 16:47:18 | 00,001,738 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\LAURA PC.rtf [2009/06/09 16:32:12 | 03,021,343 | R--- | M] () -- C:\Documents and Settings\Owner\Desktop\ComboFix.exe [2009/06/08 08:10:10 | 00,155,136 | ---- | M] () -- C:\WINDOWS\PEV.exe [2009/06/01 17:39:54 | 00,063,536 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT [2009/05/31 20:12:34 | 00,462,168 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2009/05/31 20:12:34 | 00,078,114 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2009/05/31 20:12:28 | 00,550,988 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2009/05/31 20:08:23 | 00,244,720 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2009/05/31 20:05:55 | 05,901,874 | -H-- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db [2009/05/31 19:36:02 | 00,250,048 | RHS- | M] () -- C:\ntldr [2009/05/31 01:26:42 | 00,267,612 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Rooter.exe [2009/05/31 01:17:55 | 00,264,704 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\TFC.exe ========== LOP Check ========== [2009/05/19 07:55:42 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data [2008/09/06 18:12:58 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ [2006/10/04 16:40:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CyberLink [2008/02/29 22:55:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier [2009/05/18 22:33:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP [2007/04/18 17:53:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia [2006/11/29 18:08:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar [2009/01/07 14:55:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ZoomBrowser [2006/10/12 10:52:17 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Default User\Application Data [2006/10/12 10:49:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\CyberLink [2006/10/04 17:56:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\InterVideo [2006/10/04 16:58:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\Template [2009/05/18 22:07:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data [2006/10/04 16:14:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data [2009/06/26 20:52:37 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Owner\Application Data [2009/05/29 17:10:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Canon [2007/05/04 19:14:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Chicken Chase [2006/10/12 10:49:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\CyberLink [2008/04/26 07:28:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\FrostWire [2008/07/12 15:02:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\GetRight [2006/10/04 17:56:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\InterVideo [2007/04/27 16:52:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Magic Academy [2009/01/09 20:05:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\McGraw-HillLicensing [2006/11/29 17:32:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\MSNInstaller [2006/10/04 16:58:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Template [2008/09/06 17:18:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Windows Desktop Search [2008/09/27 18:57:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Windows Search [2009/01/07 15:03:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX [2006/02/28 08:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini [2009/06/28 19:29:35 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT ========== Purity Check ========== < End of report > ************************* >>> Extras.txt OTL Extras logfile created on: 28/06/2009 7:32:46 PM - Run 1 OTL by OldTimer - Version 3.0.5.3 Folder = C:\Documents and Settings\Owner\Desktop Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy 446.48 Mb Total Physical Memory | 55.61 Mb Available Physical Memory | 12.46% Memory free 1.03 Gb Paging File | 0.68 Gb Available in Paging File | 66.15% Paging File free Paging file location(s): C:\pagefile.sys 672 1344 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 149.05 Gb Total Space | 130.08 Gb Free Space | 87.27% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: KIDSC12288 Current User Name: Owner Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: Off File Age = 30 Days Output = Standard ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [2008/04/13 14:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 [2006/05/03 17:31:40 | 01,302,528 | ---- | M] (Ai Squared ) -- C:\Program Files\ZoomText 9.0\Zt.exe:LocalSubNet:Enabled:ZoomText 9.0 File not found -- C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) File not found -- C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) [2009/02/06 18:21:00 | 00,583,024 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call [2009/02/06 18:51:28 | 03,885,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger [2009/02/06 18:23:32 | 01,170,272 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [2008/04/13 14:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 [2006/05/03 17:31:40 | 01,302,528 | ---- | M] (Ai Squared ) -- C:\Program Files\ZoomText 9.0\Zt.exe:LocalSubNet:Enabled:ZoomText 9.0 [2007/03/14 19:05:44 | 14,672,448 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes [2006/12/08 06:10:44 | 00,114,688 | ---- | M] (FrostWire Group) -- C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:LimeWire [2006/10/13 17:01:18 | 00,277,296 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe [2007/09/13 13:31:38 | 22,880,040 | R--- | M] (Skype Technologies S.A.) -- C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype [2006/10/13 17:04:52 | 04,201,264 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe [2008/04/13 20:12:21 | 00,769,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice [2009/05/18 22:07:13 | 00,908,568 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe [2009/05/18 22:07:14 | 01,085,208 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe [2009/05/18 22:07:20 | 00,594,712 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe [2009/02/06 18:21:00 | 00,583,024 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call [2009/02/06 18:51:28 | 03,885,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger [2009/02/06 18:23:32 | 01,170,272 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime "{06040048-3E21-46D6-9A91-D927BA08F41D}" = Microsoft Encarta Encyclopedia Standard 2006 "{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger "{17E3A651-12B9-4149-BAE8-E6FB9A5ADC4F}" = Microsoft Works Suite Add-in for Microsoft Word "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{24BEE00C-0DE6-443E-8C3C-00A199B1DCDD}" = ZoomText 9.0 "{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java 6 Update 13 "{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11 "{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java SE Runtime Environment 6 Update 1 "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java 6 Update 3 "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{393711FE-64EB-4DC7-909E-5FB26D1270AA}" = Microsoft Sapi 5.1 "{3972C18C-688F-4312-BE9A-3E065204C33D}" = IBM ViaVoice TTS Runtime v6.610 - UK English "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform "{3C52E7DA-C431-4239-B66B-1BF703D5B194}" = Windows Live Photo Gallery "{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.5 "{5D95AD35-368F-47D5-B63A-A082DDF00116}" = Microsoft Digital Image Standard 2006 Editor "{5E863175-E85D-44A6-8968-82507D34AE7F}" = QuickTime "{6179550A-3E7C-499E-BCC9-9E8113E0A285}" = LG ODD Auto Firmware Update "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{691F4068-81BF-49E3-B32E-FE3E16400112}" = Microsoft Digital Image Standard 2006 Library "{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer "{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{83ED1E80-A1B7-4226-BCF1-AC4A88151A6B}" = Microsoft Streets & Trips 2006 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8AEEE6D6-C95D-465A-B8D3-B7AE2FA7B8B4}" = InterVideo MediaOne "{8CFC7570-DD90-486E-A239-E31D455BDE93}" = Microsoft LifeCam "{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard "{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_PRJSTDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_PRJSTDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_PRJSTDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_PRJSTDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00B4-0409-0000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2007 "{90120000-00B4-0409-0000-0000000FF1CE}_PRJSTDR_{27A9D316-D332-433B-8EB1-1D93EE49F26D}" = Microsoft Office Project 2007 Service Pack 2 (SP2) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_PRJSTDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-003A-0000-0000-0000000FF1CE}" = Microsoft Office Project Standard 2007 "{91120000-003A-0000-0000-0000000FF1CE}_PRJSTDR_{9E73617F-2F38-4864-BD61-BB2DDFE43323}" = Microsoft Office Project 2007 Service Pack 2 (SP2) "{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002 "{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant "{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9D18F7F8-B984-4249-8512-CC621BC59F12}" = Microsoft Location Finder "{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker "{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}" = Windows Live Sync "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{AB90749C-7422-4580-8A7A-66CC5E9E5F98}" = iTunes "{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2 "{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8 "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player "{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation "{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon Camera WIA Driver "{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}" = Nokia Connectivity Cable Driver "{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}" = Windows Rights Management Client with Service Pack 2 "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C1A6B23C-438E-4D08-B508-4E830CA8F335}" = IBM ViaVoice TTS Runtime v6.610 - US English "{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials "{CA9A3609-3ECC-4574-8824-A8161A71A603}" = Canon MP150 "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader "{DE1AF137-C455-494A-A817-EFE44BCCFDEE}" = Works Upgrade "{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management Client Backwards Compatibility SP2 "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F3E7955D-696A-423C-8D38-FCA8A3094F05}" = Microsoft Sapi5 voices for XP "{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call "ActiveScan 2.0" = Panda ActiveScan 2.0 "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "ATI Display Driver" = ATI Display Driver "AVG8Uninstall" = AVG Free 8.5 "CAL" = Canon Camera Access Library "CameraWindowDVC5" = Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX "CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX "CameraWindowLauncher" = Canon Utilities CameraWindow "CCleaner" = CCleaner (remove only) "CSCLIB" = Canon Camera Support Core Library "DiskAid_is1" = DiskAid 3.0 "DPP" = Canon Utilities Digital Photo Professional 3.4 "Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint "Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX "EOS Utility" = Canon Utilities EOS Utility "FrostWire" = FrostWire 4.13.1.7 BETA "GetRight_is1" = GetRight "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "ie8" = Windows Internet Explorer 8 "InstallShield_{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon EOS 5D WIA Driver "Macromedia Shockwave Player" = Macromedia Shockwave Player "Magic Academy" = Magic Academy (remove only) "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "mIRC" = mIRC "Money2006b" = Microsoft Money 2006 "Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10) "MP Navigator 2.0" = Canon MP Navigator 2.0 "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "MSNINST" = MSN "MyCamera" = Canon Utilities MyCamera "NeroMultiInstaller!UninstallKey" = Nero Suite "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "Original Data Security Tools" = Canon Utilities Original Data Security Tools "Panda ActiveScan" = Panda ActiveScan "PhotoStitch" = Canon Utilities PhotoStitch "Picture Style Editor" = Canon Utilities Picture Style Editor "PictureItPrem_v11" = Microsoft Digital Image Standard 2006 "PRJSTDR" = Microsoft Office Project Standard 2007 Trial "RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX "RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX "SpywareBlaster_is1" = SpywareBlaster 4.2 "Tweak UI 2.10" = Tweak UI "Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 "WFTK" = Canon Utilities WFT-E1/E2/E3 Utility "WIC" = Windows Imaging Component "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinLiveSuite_Wave3" = Windows Live Essentials "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Works2006Setup" = Microsoft Works Suite 2006 Setup Launcher "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "XpsEPSC" = XML Paper Specification Shared Components Pack 1.0 "YInstHelper" = Yahoo! Install Manager "ZoneAlarm" = ZoneAlarm "ZoomBrowser EX" = Canon Utilities ZoomBrowser EX "ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 14/05/2009 1:15:02 AM | Computer Name = KIDSC12288 | Source = Application Hang | ID = 1002 Description = Hanging application AcroRd32.exe, version 8.1.0.137, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 14/05/2009 2:12:07 PM | Computer Name = KIDSC12288 | Source = Application Hang | ID = 1002 Description = Hanging application WINWORD.EXE, version 10.0.6850.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 19/05/2009 9:26:49 PM | Computer Name = KIDSC12288 | Source = Application Error | ID = 1000 Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting module rpcrt4.dll, version 5.1.2600.3173, fault address 0x0000b3d4. Error - 20/05/2009 3:52:29 PM | Computer Name = KIDSC12288 | Source = Application Hang | ID = 1002 Description = Hanging application firefox.exe, version 1.9.0.3399, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 25/05/2009 4:26:54 PM | Computer Name = KIDSC12288 | Source = Application Hang | ID = 1002 Description = Hanging application ZoomBrowser.exe, version 6.1.1.21, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 25/05/2009 4:27:13 PM | Computer Name = KIDSC12288 | Source = Application Hang | ID = 1002 Description = Hanging application ZoomBrowser.exe, version 6.1.1.21, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 25/05/2009 4:28:17 PM | Computer Name = KIDSC12288 | Source = Application Hang | ID = 1001 Description = Fault bucket 593567749. Error - 26/05/2009 7:56:51 AM | Computer Name = KIDSC12288 | Source = Microsoft Office 10 | ID = 2001 Description = Rejected Safe Mode action : Microsoft Word. Error - 31/05/2009 10:40:24 AM | Computer Name = KIDSC12288 | Source = Application Error | ID = 1000 Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting module ntdll.dll, version 5.1.2600.3520, fault address 0x00018af2. Error - 27/06/2009 12:53:32 AM | Computer Name = KIDSC12288 | Source = Application Hang | ID = 1002 Description = Hanging application OTListIt2.exe, version 2.0.15.8, hang module hungapp, version 0.0.0.0, hang address 0x00000000. [ System Events ] Error - 19/06/2009 10:23:30 AM | Computer Name = KIDSC12288 | Source = W32Time | ID = 39452701 Description = The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 14 minutes. NtpClient has no source of accurate time. Error - 19/06/2009 10:38:30 AM | Computer Name = KIDSC12288 | Source = W32Time | ID = 39452689 Description = Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 30 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) Error - 19/06/2009 10:38:30 AM | Computer Name = KIDSC12288 | Source = W32Time | ID = 39452701 Description = The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 29 minutes. NtpClient has no source of accurate time. Error - 19/06/2009 11:08:30 AM | Computer Name = KIDSC12288 | Source = W32Time | ID = 39452689 Description = Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 60 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) Error - 19/06/2009 11:08:30 AM | Computer Name = KIDSC12288 | Source = W32Time | ID = 39452701 Description = The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 59 minutes. NtpClient has no source of accurate time. Error - 23/06/2009 7:51:05 PM | Computer Name = KIDSC12288 | Source = Windows Update Agent | ID = 16 Description = Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection. Error - 26/06/2009 10:14:18 AM | Computer Name = KIDSC12288 | Source = Windows Update Agent | ID = 16 Description = Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection. Error - 26/06/2009 3:52:45 PM | Computer Name = KIDSC12288 | Source = W32Time | ID = 39452689 Description = Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) Error - 26/06/2009 3:52:45 PM | Computer Name = KIDSC12288 | Source = W32Time | ID = 39452701 Description = The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 14 minutes. NtpClient has no source of accurate time. Error - 28/06/2009 7:13:34 PM | Computer Name = KIDSC12288 | Source = Windows Update Agent | ID = 16 Description = Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection. < End of report > ****************************************** >>> AVG log. "Scan ""Scan whole computer"" was finished." "No infection was found during this scan" "Folders selected for scanning:";"Scan whole computer" "Scan started:";"June 28, 2009, 7:52:33 PM" "Scan finished:";"June 28, 2009, 8:42:51 PM (50 minute(s) 18 second(s))" "Total object scanned:";"455397" "User who launched the scan:";"Owner" ********************************************* I just realized I used the old version of OTList, I did run the program with new updates. Hope everything is as per your request, the pc has no inet connection since the first post because there is a problem on the ISP connection that it's getting resolved, wiring of the whole building is getting replaced and also because I didn't want for the pc to get access till is completely healed. Thanks again for your assistance. This post has been edited by Noki: Jun 28 2009, 08:33 PM |
|
|
Jun 28 2009, 08:40 PM
Post
#10
|
|
![]() RIP 10/2009 Posts: 2,646 From: NE Victoria, Australia OS: WinXp SP3 |
[Hi Noki,
color=purple]I see you have FrostWire installed on your system.[/color] While the program itself is legal, most of the files downloaded with it, are not. These programs are also one of the major infection routes for an otherwise secure PC. A very high proportion if files on Peer to Peer networks are infected with Trojans & other malware. I highly recommend uninstalling FrostWire as outlined below. Remove folders & files:
Run OTL.exe
|
|
|
Jun 30 2009, 05:32 PM
Post
#11
|
|
|
Member ![]() ![]() Posts: 16 OS: xp |
Hi, so I deleted the copy of Frostwire and ran the fix, here is the log:
******************************************** All processes killed ========== OTL ========== No active process named explorer.exe was found! Service\Driver ieik9uaaan deleted successfully. File File not found not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\msn.com\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//@surf.mar@/\ deleted successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: Owner File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\Perflib_Perfdata_f1c.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\~DF3D9.tmp scheduled to be deleted on reboot. ->Temp folder emptied: 17723432 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 29791293 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 0 bytes File delete failed. C:\WINDOWS\temp\ZLT03d66.TMP scheduled to be deleted on reboot. Windows Temp folder emptied: 3992 bytes RecycleBin emptied: 189440 bytes Total Files Cleaned = 45.61 mb C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully Error: Unable to interpret <[start explorer]> in the current context! OTL by OldTimer - Version 3.0.5.3 log created on 06302009_192240 Files\Folders moved on Reboot... File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\Perflib_Perfdata_f1c.dat not found! C:\Documents and Settings\Owner\Local Settings\Temp\~DF3D9.tmp moved successfully. File\Folder C:\WINDOWS\temp\ZLT03d66.TMP not found! Registry entries deleted on Reboot... ************************************************* Let me know whats next!! |
|
|
Jun 30 2009, 06:34 PM
Post
#12
|
|
![]() RIP 10/2009 Posts: 2,646 From: NE Victoria, Australia OS: WinXp SP3 |
Hi Noki,
Now, let's tidy up a few other bits. Re-run OTL.exe
Please do an online scan with Kaspersky WebScanner Kaspersky online scanner uses JAVA technology to perform the scan. If you do not have the latest JAVA version, follow the instructions below, to download and install the latest version. Upgrading Java:
Proceed with the Scan:
|
|
|
Jul 3 2009, 09:21 PM
Post
#13
|
|
|
Member ![]() ![]() Posts: 16 OS: xp |
Hi, I was able to run the scan using OTL, since the pc has no inet connection I can't use Kas, is there any other scanner that u may suggest that I can run offline?
OTL log: *********************************** ========== OTL ========== Process explorer.exe killed successfully! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry value HKEY_USERS\S-1-5-21-673811579-4275867939-2855663147-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found. Registry value HKEY_USERS\S-1-5-21-673811579-4275867939-2855663147-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}\ not found. Registry value HKEY_USERS\S-1-5-21-673811579-4275867939-2855663147-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&Search\ deleted successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== File\Folder c:\windows\system32\kgngdne.exe not found. ========== COMMANDS ========== OTL by OldTimer - Version 3.0.5.3 log created on 07032009_220237 |
|
|
Jul 3 2009, 10:16 PM
Post
#14
|
|
![]() RIP 10/2009 Posts: 2,646 From: NE Victoria, Australia OS: WinXp SP3 |
I think you are ready to now get that machine back online & update ZoneAlarm & AVG.
Then use the instructions above to run the Kaspersky scan. Let me know how you get on & post the scan results as your next reply. Cheers, sage5 |
|
|
Jul 4 2009, 02:08 PM
Post
#15
|
|
|
Member ![]() ![]() Posts: 16 OS: xp |
Hi Sage, I would love to connect the pc, is just they are about to move to a new place out of the city, and the inet was the first service cut, so for the mean time there is no inet, that's why I wondered if there is another option while the pc is offline.
Thanks so much for your attention and effort. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
8 / 414 | 3rd June 2006 - 08:29 AM Korel started - last by Jag11 |
|||||
![]() |
0 / 102 | 9th January 2009 - 08:22 PM SometimesFound@ started - last by SometimesFound@ |
|||||
![]() |
15 / 466 | 12th May 2009 - 12:10 AM Pyetr started - last by Jimmy2012 |
|||||
![]() |
3 / 457 | 29th June 2009 - 02:54 PM grandma2b started - last by Rorschach112 |
|||||
|
Time is now: 7th November 2009 - 11:20 PM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising