I have had a thread running here and was advised by Broni to come here to check that my machine is clean.
Very briefly, I have had problem with my laptop running slow, having irratic increases in CPU usage (spiking) which has created kind of hanging where everything appears to stop. For details best to read the other topic in full.
I have worked through the cleaning guide and done all the preparation.
MBAM
There was a problem with the installation and it didn't appear to be able to check for updates (the problem shows up in the OTListIt Extras text).
Anyway, I did the scan and it found something which I deleted:
Malwarebytes' Anti-Malware 1.36
Database version: 1945
Windows 5.1.2600 Service Pack 3
13/05/2009 13:33:20
mbam-log-2009-05-13 (13-33-20).txt
Scan type: Quick Scan
Objects scanned: 78624
Time elapsed: 15 minute(s), 14 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\hosts (Trojan.Agent) -> Quarantined and deleted successfully.
Rooter
Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3
C:\ [Fixed] - NTFS - (Total:57231 Mo/Free:3390 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
13/05/2009|13:52
----------------------\\ Processes..
--Locked-- [System Process]
---------- System
---------- \SystemRoot\System32\smss.exe
---------- \??\C:\WINDOWS\system32\csrss.exe
---------- \??\C:\WINDOWS\system32\winlogon.exe
---------- C:\WINDOWS\system32\services.exe
---------- C:\WINDOWS\system32\lsass.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\system32\spoolsv.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\Program Files\a-squared Free\a2service.exe
---------- C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
---------- C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
---------- C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
---------- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
---------- C:\WINDOWS\System32\DVDRAMSV.exe
---------- C:\Program Files\Orange\ICON 225 USB Connect\GtDetectSc.exe
---------- C:\PROGRA~1\AVG\AVG8\avgrsx.exe
---------- C:\Program Files\Java\jre6\bin\jqs.exe
---------- C:\Program Files\Kontiki\KService.exe
---------- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\Program Files\Viewpoint\Common\ViewpointService.exe
---------- C:\WINDOWS\wanmpsvc.exe
---------- C:\WINDOWS\system32\SearchIndexer.exe
---------- C:\WINDOWS\system32\TPWRTRAY.EXE
---------- C:\PROGRA~1\AVG\AVG8\avgtray.exe
---------- C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
---------- C:\WINDOWS\System32\alg.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\system32\ctfmon.exe
---------- C:\Program Files\Outlook Express\msimn.exe
---------- C:\WINDOWS\Explorer.exe
---------- C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
---------- C:\PROGRA~1\AVG\AVG8\avgnsx.exe
---------- C:\Program Files\Internet Explorer\iexplore.exe
---------- C:\Program Files\Internet Explorer\iexplore.exe
---------- C:\WINDOWS\system32\cmd.exe
---------- C:\Rooter$\RK.exe
----------------------\\ Search..
----------------------\\ ROOTKIT !!
1 - "C:\Rooter$\Rooter_1.txt" - 13/05/2009|13:46
2 - "C:\Rooter$\Rooter_2.txt" - 13/05/2009|13:54
OTListIt.Txt
OTListIt logfile created on: 13/05/2009 14:53:32 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.7 Folder = C:\Documents and Settings\Gregg\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
479.48 Mb Total Physical Memory | 120.39 Mb Available Physical Memory | 25.11% Memory free
1.27 Gb Paging File | 0.94 Gb Available in Paging File | 74.05% Paging File free
Paging file location(s): C:\pagefile.sys 900 1440 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 27.32 Gb Free Space | 48.89% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: GREGGLAPTOP
Current User Name: Gregg
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\Program Files\a-squared Free\a2service.exe (Emsi Software GmbH)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE (C-Dilla Ltd)
PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\WINDOWS\System32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\Program Files\Orange\ICON 225 USB Connect\GtDetectSc.exe (OptionNV)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\system32\TPWRTRAY.EXE (TOSHIBA Corporation)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Documents and Settings\Gregg\Desktop\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (a2free [Auto | Running]) -- C:\Program Files\a-squared Free\a2service.exe (Emsi Software GmbH)
SRV - (AOL ACS [Auto | Running]) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (C-DillaSrv [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE (C-Dilla Ltd)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CVPND [Auto | Running]) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (DVD-RAM_Service [Auto | Running]) -- C:\WINDOWS\System32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GtDetectSc [Auto | Running]) -- C:\Program Files\Orange\ICON 225 USB Connect\GtDetectSc.exe (OptionNV)
SRV - (gusvc [Auto | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (Irmon [Auto | Running]) -- C:\WINDOWS\System32\irmon.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KService [Auto | Running]) -- C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (MDM [Auto | Running]) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NwSapAgent [Auto | Stopped]) -- C:\WINDOWS\System32\ipxsap.dll (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)
SRV - (ServiceLayer [On_Demand | Stopped]) -- C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe (Nokia.)
SRV - (SoundMAX Agent Service (default) [Auto | Running]) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
SRV - (TomTomHOMEService [On_Demand | Stopped]) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (Viewpoint Manager Service [Auto | Running]) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (vsmon [On_Demand | Stopped]) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Zone Labs Inc.)
SRV - (WANMiniportService [Auto | Running]) -- C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (ADM8511 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ADM8511.SYS (ADMtek Incorporated)
DRV - (aeaudio [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (AgereSoftModem [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\AGRSM.sys (Agere Systems)
DRV - (alcan5wn [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\alcan5wn.sys (THOMSON)
DRV - (alcaudsl [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\alcaudsl.sys (THOMSON)
DRV - (aliadwdm [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\ac97ali.sys (Acer Laboratories Inc.)
DRV - (ALiAGP [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\ALiAGP.sys (ALi Corporation.)
DRV - (AliIde [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (ALiIRDA [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\aliirda.sys (Acer Laboratories Inc.)
DRV - (AR5211 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ar5211.sys (Atheros Communications, Inc.)
DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (BANTExt [System | Running]) -- C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (C-Dilla [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\CDANT.SYS (Macrovision)
DRV - (CnxEtP [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\CnxEtP.sys (Conexant)
DRV - (CnxEtU [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\CnxEtU.sys (Conexant)
DRV - (CnxTgN [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\CnxTgN.sys (Conexant Systems Inc.)
DRV - (CVirtA [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\CVirtA.sys (Cisco Systems, Inc.)
DRV - (DNE [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\dne2000.sys (Deterministic Networks, Inc.)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (giveio [Boot | Running]) -- C:\WINDOWS\system32\giveio.sys ()
DRV - (GT72NDISIPXP [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\Gt51Ip.sys (Option N.V.)
DRV - (GT72UBUS [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\gt72ubus.sys (Option N.V.)
DRV - (GTPTSER [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\gtptser.sys (Option N.V.)
DRV - (L8042mou [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\L8042mou.Sys (Logitech, Inc.)
DRV - (LHidKe [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\LHidKE.Sys (Logitech, Inc.)
DRV - (LHidUsbK [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\LHidUsbK.Sys (Logitech, Inc.)
DRV - (LMouKE [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\LMouKE.Sys (Logitech, Inc.)
DRV - (MDC8021X [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (meiudf [System | Running]) -- C:\WINDOWS\System32\Drivers\meiudf.sys (Matsushita Electric Industrial Co.,Ltd.)
DRV - (Nokia USB Generic [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\nmwcdc.sys (Nokia)
DRV - (Nokia USB Modem [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\nmwcdcm.sys (Nokia)
DRV - (Nokia USB Phone Parent [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\nmwcd.sys (Nokia)
DRV - (Nokia USB Port [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\nmwcdcj.sys (Nokia)
DRV - (NwlnkIpx [Auto | Stopped]) -- C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys (Microsoft Corporation)
DRV - (NwlnkNb [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys (Microsoft Corporation)
DRV - (PCANDIS5 [On_Demand | Stopped]) -- C:\Program Files\22M Wireless LAN\PCANDIS5.SYS (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (PCASp50 [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (pciSd [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\tossdpci.sys (TOSHIBA)
DRV - (PCX500 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\pcx500.sys (Cisco Systems)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (rtl8139 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\R8139n51.SYS (Realtek Semiconductor Corporation )
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (smwdm [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (snpstd [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\snpstd.sys ()
DRV - (speedfan [Boot | Running]) -- C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (sptd [Boot | Running]) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (TBiosDrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\Tbiosdrv.sys ()
DRV - (TEWLN [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\tewln.sys ( )
DRV - (tridxp [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\tridxpm.sys (Trident Microsystems Inc.)
DRV - (tsdhd [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\tsdhd.sys (TOSHIBA Corporation)
DRV - (TVALD [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\TVALD.SYS (Toshiba Corporation)
DRV - (TVALG [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\TVALG.SYS (TOSHIBA Corporation)
DRV - (usbaudio [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (USB_RNDIS_51 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\usb8023.sys (Microsoft Corporation)
DRV - (vsdatant [On_Demand | Stopped]) -- C:\WINDOWS\System32\vsdatant.sys (Zone Labs LLC)
DRV - (wanatw [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (wlags48b [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wlags48b.sys (Agere Systems)
DRV - (wlluc48 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wlluc48.sys (Lucent Technologies)
DRV - (WLUX96 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\WLUX96F.SYS (3Com Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://morwillsearch...partner&sub_id=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://uk.red.client...fo/bt_side.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://morwillsearch...partner&sub_id=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rover.ebay.co.....www.ebay.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://morwillsearch...partner&sub_id=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://newsvote.bbc....ncy/default.stm
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Rambler"
FF - prefs.js..browser.search.selectedEngine: "Rambler"
FF - prefs.js..browser.startup.homepage: "http://start.qip.ru"
FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008/11/10 23:42:49 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD [2008/11/13 22:08:29 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX [2009/05/10 18:11:08 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/04/14 09:58:03 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 1.5\Extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2008/11/13 22:08:02 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 1.5\Extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/14 22:02:46 | 00,000,000 | ---D | M]
[2009/04/07 14:37:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Gregg\Application Data\mozilla\Extensions
[2009/04/07 14:37:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Gregg\Application Data\mozilla\Extensions\[email protected]
[2008/01/13 14:59:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Gregg\Application Data\mozilla\Firefox\Profiles\hbnn9ban.default\extensions
[2008/03/23 17:18:46 | 00,000,491 | ---- | M] () -- C:\Documents and Settings\Gregg\Application Data\Mozilla\FireFox\Profiles\hbnn9ban.default\searchplugins\rambler.xml
[2008/11/10 23:43:28 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2008/01/13 14:58:27 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/11/10 23:43:29 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2008/01/13 14:58:25 | 00,073,728 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\jar50.dll
[2008/01/13 14:58:27 | 00,061,440 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\jsd3250.dll
[2008/01/13 14:58:25 | 00,180,224 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\xpinstal.dll
[2008/01/13 14:58:37 | 00,000,680 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.png
[2008/01/13 14:58:37 | 00,000,741 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.src
[2008/01/13 14:58:37 | 00,001,150 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.png
[2008/01/13 14:58:37 | 00,000,539 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.src
[2008/01/13 14:58:37 | 00,000,356 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.png
[2008/01/13 14:58:37 | 00,001,007 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.src
[2008/01/13 14:58:37 | 00,000,210 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.gif
[2008/01/13 14:58:37 | 00,001,056 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.src
[2008/01/13 14:58:37 | 00,001,076 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.gif
[2008/01/13 14:58:37 | 00,000,718 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.src
[2008/01/13 14:58:37 | 00,000,088 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.gif
[2008/01/13 14:58:37 | 00,001,122 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.src
O1 HOSTS File: (698 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {468CD8A9-7C25-45FA-969E-3D925C689DC4} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [000StTHK] 000StTHK.exe ()
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Tpwrtray] TPWRTRAY.EXE (TOSHIBA Corporation)
O4 - HKCU..\Run: [Spam Bully for Outlook Express] "C:\Program Files\Axaware\Spam Bully 2 for OE\oespambully.exe" install (Axaware)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: SpecifyDefaultButtons = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Search = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarCustomize = 0
O8 - Extra context menu item: &iSearch The Web - Reg Error: Value error. File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Globet Poker Poker - {2D997C72-3052-495c-B6FF-DAE07A5F0604} - C:\Microgaming\Poker\GlobetSportPokerMPP\MPPoker.exe (Microgaming)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Stan James Poker.com Poker - {7F2F6F5A-CAE2-4954-A461-36B3757B2BFB} - C:\Program Files\stanjamesgibMPP\MPPoker.exe (Microgaming)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Globet Poker - {997F2741-BB7D-4268-A67B-75C5ADB8EC20} - C:\Microgaming\Poker\GlobetPokerMPP\MPPoker.exe File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [WinSock Proxy Name Space provider] - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000036 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000038 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000039 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000040 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000041 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000042 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000043 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000044 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000045 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000046 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000047 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000048 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000049 - C:\Program Files\Microsoft Firewall Client\wspwsp.dll (Microsoft Corporation)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: fonbet.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: globet.tv ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: nationet.com ([olb2] https in Trusted sites)
O15 - HKCU\..Trusted Domains: 5 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} http://messenger.zon...nt.cab27571.cab (MessengerStatsClient Class)
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} http://download.zone...ee/cm/ICSCM.cab (ICSScannerLight Class)
O16 - DPF: {27B84445-9953-4E9B-B01C-73D734A57DEA} http://games.eurobet...RaceControl.ocx (Reg Error: Key error.)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} http://messenger.zon...er.cab31267.cab (Minesweeper Flags Class)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} http://us.chat1.yimg...v45/yacscom.cab (Reg Error: Key error.)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} http://a1540.g.akama...meInstaller.exe (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail....es/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} http://software-dl.r...ip/RdxIE601.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onec...lscbase8300.cab (Windows Live Safety Center Base Module)
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} http://chat.yahoo.com/cab/yacsui.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {8D68BB78-2B9C-4CED-8E23-15BECB870DC7} http://games1.eurobe...dsViewerBig.ocx (Reg Error: Key error.)
O16 - DPF: {8DE6AB9C-8C62-486B-8C06-5C9AD6FD06F1} http://txn02.hkjc.co...ect/eWinCtl.cab (DataStore Class)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zon...nt.cab28177.cab (MessengerStatsClient Class)
O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} http://download.sopc...oad/SOPCORE.CAB (SopCore Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.c.../cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {AA44D0B1-B2B4-4BCC-B710-CB45C6C2C270} http://games1.eurobe...oundsViewer.ocx (Reg Error: Key error.)
O16 - DPF: {B2FC031D-8C74-46AE-8042-BCF4FC03C1EF} http://mercpuk1.glob...in/Spider91.cab (Loader Class v4)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} https://casinoclassi...sic/FlashAX.cab (FlashXControl Object)
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} http://drmlicense.on...e/en/crlocx.ocx (CRLDownloadWrapper Class)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://mwmuk.webex....bex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} http://chat.yahoo.com/cab/yvwrctl.cab (Yahoo! Webcam Viewer Wrapper)
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} http://www.smgradio....abasetup144.cab (Reg Error: Key error.)
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} http://messenger.zon...wn.cab31267.cab (Solitaire Showdown Class)
O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} https://canbet.gamea...et/FlashAX2.cab (Flash Casino Helper Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O21 - SSODL: systemie - {F37BE1FC-A73A-42D9-B98D-C9E7C9AA1984} - File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {93994DE8-8239-4655-B1D1-5F4E91300429} - C:\Program Files\DVD Region+CSS Free\DVDShell.dll (Fengtao Software Inc.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{448ab029-d670-11db-80a7-00038a000015}\Shell\AutoRun\command - "" = F:\InstallTomTomHOME.exe -- File not found
O33 - MountPoints2\{ea23a7f3-8240-11dc-80db-00051c98479f}\Shell\Auto\command - "" = E:\printer.exe -- File not found
O33 - MountPoints2\{ea23a7f3-8240-11dc-80db-00051c98479f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ea23a7f6-8240-11dc-80db-00051c98479f}\Shell\Auto\command - "" = E:\printer.exe -- File not found
O33 - MountPoints2\{ea23a7f6-8240-11dc-80db-00051c98479f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f7f58842-b231-11dd-8173-00051c98479f}\Shell - "" = AutoRun
O33 - MountPoints2\{f7f58842-b231-11dd-8173-00051c98479f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f7f58842-b231-11dd-8173-00051c98479f}\Shell\AutoRun\command - "" = E:\setup.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[1 C:\*.tmp files]
[5 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\Gregg\Desktop\*.tmp files]
[2009/05/13 14:41:56 | 00,000,000 | ---D | C] -- C:\Avenger
[2009/05/13 13:41:08 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/05/13 13:40:43 | 00,267,612 | ---- | C] () -- C:\Documents and Settings\Gregg\Desktop\Rooter.exe
[2009/05/13 09:47:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Gregg\Application Data\Malwarebytes
[2009/05/13 09:46:22 | 00,000,702 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/13 09:46:21 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/13 09:46:18 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/13 09:46:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/05/13 09:46:14 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/05/13 09:43:56 | 02,967,800 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Gregg\Desktop\Malaware.exe
[2009/05/13 09:40:27 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Gregg\Desktop\OTListIt2.exe
[2009/05/13 09:36:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/05/13 09:35:41 | 00,000,617 | ---- | C] () -- C:\Documents and Settings\Gregg\Desktop\NTREGOPT.lnk
[2009/05/13 09:35:41 | 00,000,598 | ---- | C] () -- C:\Documents and Settings\Gregg\Desktop\ERUNT.lnk
[2009/05/13 09:35:27 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/05/13 09:28:54 | 00,021,504 | ---- | C] (Doug Knox) -- C:\Documents and Settings\Gregg\Desktop\SysRestorePoint.exe
[2009/05/12 15:31:40 | 00,092,160 | ---- | C] () -- C:\Documents and Settings\Gregg\Desktop\SOF for credit card.doc
[2009/05/12 14:21:27 | 00,000,026 | ---- | C] () -- C:\WINDOWS\Zone.Identifier
[2009/05/11 14:06:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Gregg\Desktop\Process Explorer
[2009/05/10 18:42:21 | 01,164,037 | ---- | C] () -- C:\Documents and Settings\Gregg\Desktop\Snap.xml
[2009/05/10 18:39:29 | 00,000,676 | ---- | C] () -- C:\Documents and Settings\Gregg\Desktop\What's Running.lnk
[2009/05/10 18:39:27 | 00,000,000 | ---D | C] -- C:\Program Files\WhatsRunning
[2009/05/10 18:27:41 | 00,000,773 | ---- | C] () -- C:\Documents and Settings\Gregg\Desktop\EVEREST Home Edition.lnk
[2009/05/10 18:27:36 | 00,000,000 | ---D | C] -- C:\Program Files\Lavalys
[2009/05/10 14:30:56 | 00,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
[2009/05/10 14:30:56 | 00,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
[2009/05/08 19:23:09 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Gregg\Desktop\Fields Data Recovery
[2009/05/02 22:29:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Gregg\Application Data\aignes
[2009/05/02 19:03:34 | 00,000,000 | ---D | C] -- C:\Program Files\AM-DeadLink
[2009/04/20 13:36:39 | 00,000,422 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{55EAC085-AAE2-4E9A-98E2-980E90BB2160}.job
[2009/04/19 16:59:08 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Gregg\Desktop\Skype Diagnostics
[2009/04/15 21:22:31 | 00,284,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/15 21:22:25 | 00,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\services.exe
[2009/04/15 21:22:23 | 00,227,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/15 21:22:21 | 00,453,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/15 21:22:19 | 00,729,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lsasrv.dll
[2009/04/15 21:18:56 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpsp4res.dll
[2009/04/15 21:18:49 | 00,215,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/04/14 19:55:44 | 00,000,000 | ---D | C] -- C:\Casino
[2009/04/14 13:50:52 | 00,000,000 | -H-D | C] -- C:\WINDOWS\msdownld.tmp
[2009/04/14 13:21:31 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009/04/14 12:21:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Gregg\Application Data\Windows Search
[2009/04/14 12:20:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Gregg\Application Data\Windows Desktop Search
[2009/04/14 12:18:01 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy
[2009/04/14 12:18:01 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Desktop Search
[2009/04/14 11:50:02 | 01,089,593 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/04/14 11:00:21 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2009/04/14 10:34:26 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/04/14 09:52:36 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2009/04/14 09:52:21 | 00,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2009/04/14 09:51:54 | 00,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2009/04/14 09:49:27 | 00,117,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\prntvpt.dll
[2009/04/14 09:49:26 | 00,089,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2009/04/14 09:49:24 | 00,597,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2009/04/14 09:49:21 | 00,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpsshhdr.dll
[2009/04/14 09:49:21 | 00,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2009/04/14 09:49:16 | 01,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpssvcs.dll
[2009/04/14 09:49:16 | 01,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2009/04/14 09:49:07 | 00,000,000 | ---D | C] -- C:\ef0d4a89ed0a60690f66b44b271809df
[2009/04/14 09:43:29 | 00,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel
[2009/03/04 23:58:12 | 00,000,044 | ---- | C] () -- C:\WINDOWS\SMWizard.INI
[2009/02/07 02:11:11 | 00,015,541 | ---- | C] () -- C:\WINDOWS\snpstd.ini
[2009/02/07 02:11:06 | 00,390,656 | ---- | C] () -- C:\WINDOWS\System32\drivers\snpstd.sys
[2009/02/07 02:11:03 | 00,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd.dll
[2009/02/07 02:11:03 | 00,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd.dll
[2009/02/07 02:11:03 | 00,036,864 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd.dll
[2008/12/07 14:46:53 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/12/07 13:52:01 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008/12/03 21:10:33 | 00,003,840 | ---- | C] () -- C:\WINDOWS\System32\drivers\BANTExt.sys
[2008/10/26 08:23:42 | 00,002,069 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2007/12/24 21:30:23 | 00,000,019 | ---- | C] () -- C:\WINDOWS\SoundConverter.INI
[2007/12/18 14:15:50 | 00,000,126 | ---- | C] () -- C:\WINDOWS\mercury.ini
[2007/11/14 12:10:50 | 00,000,155 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
[2007/11/14 12:04:50 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\scanx.dll
[2007/11/14 12:04:43 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\wcp412p6.dll
[2007/10/26 11:28:18 | 00,197,408 | ---- | C] () -- C:\WINDOWS\System32\vpnapi.dll
[2007/10/26 11:28:04 | 00,193,312 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll
[2007/09/27 10:51:02 | 00,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 00,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 00,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/09/08 20:07:06 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\YCRWin32.dll
[2006/01/25 00:04:36 | 00,000,564 | ---- | C] () -- C:\WINDOWS\psnetwork.ini
[2006/01/24 23:51:27 | 00,000,162 | ---- | C] () -- C:\WINDOWS\powerlist.ini
[2006/01/05 00:59:00 | 00,000,596 | ---- | C] () -- C:\WINDOWS\powerplayer.ini
[2005/12/07 10:31:00 | 00,202,752 | R--- | C] () -- C:\WINDOWS\System32\CddbCdda.dll
[2005/11/23 21:36:11 | 00,000,101 | ---- | C] () -- C:\WINDOWS\DVDRegionFree.INI
[2005/11/12 19:42:43 | 00,000,000 | ---- | C] () -- C:\WINDOWS\RAWImage.INI
[2005/09/24 22:27:42 | 00,000,600 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini
[2005/06/11 15:52:11 | 00,065,385 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\TEWLN.SYS
[2005/04/16 21:13:08 | 00,421,888 | ---- | C] () -- C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2005/04/16 21:13:08 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\libfaac.dll
[2005/04/16 21:13:07 | 00,155,648 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2005/04/16 21:13:06 | 00,679,936 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2005/04/16 21:13:02 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
[2004/11/20 18:34:07 | 00,003,072 | R--- | C] () -- C:\WINDOWS\System32\coinst.dll
[2004/10/09 13:19:37 | 00,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2004/08/03 16:43:11 | 00,005,607 | R--- | C] () -- C:\WINDOWS\System32\stci.dll
[2004/03/20 12:55:53 | 00,000,092 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2004/03/03 21:06:27 | 00,651,264 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2004/03/03 21:06:27 | 00,147,456 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2003/08/13 00:55:07 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2003/08/12 23:07:54 | 00,001,532 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2003/08/12 23:01:00 | 00,000,021 | ---- | C] () -- C:\WINDOWS\CS_setup.ini
[2003/08/12 23:00:23 | 00,000,052 | ---- | C] () -- C:\WINDOWS\intuprof.ini
[2003/08/12 23:00:04 | 00,000,626 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2003/08/12 22:52:34 | 00,000,000 | ---- | C] () -- C:\WINDOWS\NDSTray.INI
[2003/08/12 22:52:19 | 00,024,576 | ---- | C] () -- C:\WINDOWS\System32\getnode.dll
[2003/08/12 22:47:23 | 00,000,067 | ---- | C] () -- C:\WINDOWS\swupdate.ini
[2003/08/12 22:35:10 | 00,128,113 | ---- | C] () -- C:\WINDOWS\System32\csellang.ini
[2003/08/12 22:35:10 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\csellang.dll
[2003/08/12 22:35:10 | 00,009,149 | ---- | C] () -- C:\WINDOWS\System32\tosmreg.ini
[2003/08/12 22:35:10 | 00,007,671 | ---- | C] () -- C:\WINDOWS\System32\cseltbl.ini
[2003/08/12 22:29:34 | 00,006,528 | ---- | C] () -- C:\WINDOWS\System32\drivers\Tbiosdrv.sys
[2003/08/12 22:26:34 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2003/08/12 18:39:17 | 00,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2003/08/12 18:32:14 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2003/08/12 18:09:22 | 00,000,382 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2003/08/12 18:08:42 | 00,001,141 | ---- | C] () -- C:\WINDOWS\win.ini
[2003/08/12 18:08:32 | 00,000,270 | ---- | C] () -- C:\WINDOWS\system.ini
[2003/04/25 00:32:58 | 00,069,632 | ---- | C] () -- C:\WINDOWS\System32\TVCtrl.dll
[2003/04/25 00:32:36 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\Multview.dll
[2003/04/25 00:32:12 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\LCDCtrl.dll
[2003/04/25 00:31:48 | 00,090,112 | ---- | C] () -- C:\WINDOWS\System32\GenCtrl.dll
[2003/04/25 00:31:22 | 00,049,152 | ---- | C] () -- C:\WINDOWS\System32\CRTCtrl.dll
[2003/04/25 00:31:00 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\ColorCtr.dll
[2003/01/07 13:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/06 14:30:00 | 00,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[1996/12/08 21:00:00 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
[1996/12/08 21:00:00 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
[1996/04/03 20:33:26 | 00,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
========== Files - Modified Within 30 Days ==========
[1 C:\*.tmp files]
[5 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\Gregg\Desktop\*.tmp files]
[2009/05/13 14:46:12 | 00,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/05/13 14:43:38 | 00,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2009/05/13 14:43:23 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Gregg\Local Settings\desktop.ini
[2009/05/13 14:43:05 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/05/13 14:42:36 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/05/13 14:42:22 | 50,284,5440 | -HS- | M] () -- C:\hiberfil.sys
[2009/05/13 13:40:48 | 00,267,612 | ---- | M] () -- C:\Documents and Settings\Gregg\Desktop\Rooter.exe
[2009/05/13 10:23:52 | 00,000,702 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/13 09:44:10 | 02,967,800 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Gregg\Desktop\Malaware.exe
[2009/05/13 09:40:27 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Gregg\Desktop\OTListIt2.exe
[2009/05/13 09:35:41 | 00,000,617 | ---- | M] () -- C:\Documents and Settings\Gregg\Desktop\NTREGOPT.lnk
[2009/05/13 09:35:41 | 00,000,598 | ---- | M] () -- C:\Documents and Settings\Gregg\Desktop\ERUNT.lnk
[2009/05/13 09:28:54 | 00,021,504 | ---- | M] (Doug Knox) -- C:\Documents and Settings\Gregg\Desktop\SysRestorePoint.exe
[2009/05/13 08:25:19 | 36,026,761 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/05/13 08:25:19 | 00,053,730 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/05/12 22:58:54 | 00,000,422 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{55EAC085-AAE2-4E9A-98E2-980E90BB2160}.job
[2009/05/12 15:31:41 | 00,092,160 | ---- | M] () -- C:\Documents and Settings\Gregg\Desktop\SOF for credit card.doc
[2009/05/12 14:21:27 | 00,000,026 | ---- | M] () -- C:\WINDOWS\Zone.Identifier
[2009/05/12 01:06:31 | 00,035,840 | ---- | M] () -- C:\Documents and Settings\Gregg\Desktop\Operation BW, Balances, Poker Codes.doc
[2009/05/11 00:15:26 | 00,001,141 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/05/11 00:15:26 | 00,000,270 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/05/11 00:15:26 | 00,000,211 | RHS- | M] () -- C:\boot.ini
[2009/05/10 18:42:21 | 01,164,037 | ---- | M] () -- C:\Documents and Settings\Gregg\Desktop\Snap.xml
[2009/05/10 18:39:29 | 00,000,676 | ---- | M] () -- C:\Documents and Settings\Gregg\Desktop\What's Running.lnk
[2009/05/10 18:27:41 | 00,000,773 | ---- | M] () -- C:\Documents and Settings\Gregg\Desktop\EVEREST Home Edition.lnk
[2009/05/10 14:30:56 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2009/05/10 14:30:56 | 00,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2009/05/10 09:59:57 | 00,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/05/10 09:59:52 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/05/10 09:59:51 | 00,325,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/05/10 09:58:16 | 00,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/05/09 21:20:12 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/05/07 20:45:50 | 00,017,591 | ---- | M] () -- C:\Documents and Settings\Gregg\Desktop\BJ Invoice.pdf
[2009/05/07 08:16:29 | 24,699,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/05/06 15:24:14 | 00,074,240 | ---- | M] () -- C:\Documents and Settings\Gregg\Desktop\GW & JR Account 07 - 08.xls
[2009/05/04 20:03:48 | 00,000,101 | ---- | M] () -- C:\WINDOWS\DVDRegionFree.INI
[2009/04/18 09:27:13 | 00,434,673 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/04/17 18:30:38 | 00,466,652 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/04/17 18:30:38 | 00,079,828 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/04/17 18:30:37 | 00,554,316 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/14 13:57:51 | 00,000,076 | -HS- | M] () -- C:\Documents and Settings\Gregg\My Documents\desktop.ini
[2009/04/14 11:04:09 | 00,286,904 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/13 15:49:43 | 00,035,334 | ---- | M] () -- C:\WINDOWS\Gregg.acl
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Gregg\Desktop\BJ Invoice.pdf:DocumentSummaryInformation
@Alternate Data Stream - 184 bytes -> C:\Documents and Settings\Gregg\Desktop\BJ Invoice.pdf:SummaryInformation
< End of report >
Extras.Txt
OTListIt Extras logfile created on: 13/05/2009 14:53:32 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.7 Folder = C:\Documents and Settings\Gregg\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
479.48 Mb Total Physical Memory | 120.39 Mb Available Physical Memory | 25.11% Memory free
1.27 Gb Paging File | 0.94 Gb Available in Paging File | 74.05% Paging File free
Paging file location(s): C:\pagefile.sys 900 1440 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 27.32 Gb Free Space | 48.89% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: GREGGLAPTOP
Current User Name: Gregg
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.inf [@ = inffile] -- Reg Error: Key error. File not found
.ini [@ = inifile] -- C:\WINDOWS\notepad.exe (Microsoft Corporation)
.txt [@ = txtfile] -- C:\WINDOWS\notepad.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL (America Online, Inc)
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe:*:Enabled:AOL (America Online, Inc.)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager (Microsoft Corporation)
C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager (Microsoft Corporation)
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation)
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer (Microsoft Corporation)
C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer (RealNetworks, Inc.)
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe:*:Enabled:Logitech Desktop Messenger (Logitech)
C:\Program Files\Microsoft Games\Links 2003 Demo\LinksMMIII.exe:*:Enabled:Links 2003 (Microsoft Corporation)
C:\Program Files\ppStream\ppStream.exe:*:Enabled:ppStream P2P Streaming Player ()
C:\Program Files\Abacast\Abaclient.exe:*:Enabled:Abaclient (Abacast, Inc.)
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL (America Online, Inc)
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe:*:Enabled:AOL (America Online, Inc.)
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger File not found
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger File not found
C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server File not found
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Kontiki\KService.exe:*:Enabled:Delivery Manager Service (Kontiki Inc.)
C:\Program Files\Yahoo!\Messenger\ypager.exe:*:Enabled:Yahoo! Messenger File not found
C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager (Microsoft Corporation)
C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager (Microsoft Corporation)
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application (Microsoft Corporation)
C:\Documents and Settings\Gregg\Local Settings\Temp\pftA60.tmp\hpjsi.exe:*:Enabled:HP Install Network Printer Wizard File not found
C:\Documents and Settings\Gregg\Local Settings\Temp\pftC.tmp\hpjsi.exe:*:Enabled:HP Install Network Printer Wizard File not found
C:\Documents and Settings\Gregg\Local Settings\Temp\pft3C4.tmp\hpjsi.exe:*:Enabled:HP Install Network Printer Wizard File not found
C:\WINDOWS\system32\rtcshare.exe:*:Enabled:RTC App Sharing (Microsoft Corporation)
C:\Documents and Settings\Gregg\Local Settings\Temp\WZSE0.TMP\SymNRT.exe:*:Enabled:Norton Removal Tool File not found
C:\Program Files\QIP Infium\infium.exe:*:Enabled:QIP Infium File not found
C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver (www.sopcast.com)
C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application (www.sopcast.com)
C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation)
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\TomTom HOME 2\xulrunner\TomTomHOMERuntime.exe:*:Enabled:TomTom HOME (Mozilla Foundation)
C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype ()
C:\Documents and Settings\Gregg\Desktop\SysRestorePoint.exe:*:Enabled:Single Click System Restore Point (Doug Knox)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{02B71D92-A84B-4DFB-9A10-D12BB01AC1F2}" = Nokia N73 highlights
"{06565122-7737-4F0F-ABF3-13019301BF81}" = 22M Wireless LAN Adapter
"{08094E03-AFE4-4853-9D31-6D0743DF5328}" = QuickTime
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0D80391C-0A72-43BB-9BC2-143F63CC111D}" = Nokia PC Connectivity Solution
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{12723C3A-0FF8-4A0C-8BD3-DC958F388F67}" = GoBoingo!
"{184E7118-0295-43C4-B72C-1D54AA75AAF7}" = Windows Live Mail
"{1BAE37F4-250E-4516-ADF1-C5A4C0453F30}" = BetgeniusConsole
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java 6 Update 10
"{27B8F080-8CFF-4675-A990-093EA3A3407F}" = ICON 225 USB Connect
"{2C164906-E68F-462A-9010-70DD022223EF}" = RemoteCapture Task 1.0.2
"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}" = Logitech SetPoint
"{2F81FBFC-9A37-431F-9050-14B55485DF5A}" = Internet Library
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C52E7DA-C431-4239-B66B-1BF703D5B194}" = Windows Live Photo Gallery
"{3CF0858D-1AC5-4308-9DE7-AD15288A8BDC}" = TOSHIBA Console
"{3D5E5C0A-5B36-4F98-99A7-287F7DBDCE03}" = Skype Plugin Manager
"{3EB3B7E8-1466-405A-B5BC-44513AF85E34}_is1" = UltimateBet
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{48CF9A66-5F03-4025-ABD0-B3A3FA095A59}" = TOSHIBA SD Memory Card Format
"{48E16D31-C39F-45CB-91D9-357F7B2CEE52}" = SliQ Invoicing & Quoting
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{531317A5-586A-4E36-87C1-CA823447B375}" = Nokia PC Suite
"{57383270-6F61-4DC8-A9B8-C1745FC29F38}" = USB PC Camera (SN9C102)
"{59359B3D-ABE7-46BF-AB55-43B67A64DC68}" = Nokia MTP driver
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{6882DD11-33B8-4DEA-8305-7E765BF74BD3}" = Nokia Connectivity Cable Driver
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6CF08AD2-00C5-4A63-B74B-2EFFFAFEBE1A}" = Microsoft Outlook Web Access S/MIME
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73E30715-9EC4-4DAE-BE67-64500AEB8012}" = Nokia Nseries Skin for Microsoft Windows Media Player
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{76E46F23-8DFB-4993-895E-80D95FEE6E86}" = Atheros Client Utility
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{77F5816C-64A6-4FBE-BBE5-52EFE5EB84E8}" = Nokia themes for your device
"{7F34A21F-2DEB-4598-BB19-611D6BD24271}" = Managed DirectX (0900)
"{80D95911-28E9-40AC-A6B5-1DA6D9F14B29}" = Software Suite
"{871DF2BE-41D2-4334-AC33-839AF16FC8FE}" = Cisco Systems VPN Client 5.0.02.0090
"{884705D8-575F-4F12-9FA6-E4558866A127}" = Spam Bully 2 for Outlook Express
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B7443F5-E141-42A0-AB61-ED2331AAD606}" = 4oD
"{8B7ADE32-F624-481D-9A76-62B2867C67EB}" = GJUpdate Live Lines
"{8C7A59A8-9ABE-459A-9A93-08C281A4A264}" = Microsoft Firewall Client
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9518F764-C54D-47B2-9E73-154B21E79FD2}" = RAW Image Task 1.0
"{97AA0C55-AFAD-4126-B21C-F1318FB6DADA}" = Realtek Fast Ethernet Adapter Driver
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD 4
"{99CC78D1-2356-497C-84C1-F239884001EC}" = Turbo Lister
"{9D765FA6-F2BC-40AF-8145-50808F9BDF4E}" = DVD-RAM Driver
"{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}" = Windows Live Sync
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A260B422-70E1-41E2-957D-F76FA21266D5}" = Apple Software Update
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A6690C0E-B96E-4F0F-A8EB-D5B332454AC6}" = TOSHIBA Controls
"{A6A286E8-D5C7-4FCB-BB2E-9FA532A8E343}" = ProcessJuggler
"{A962C8E1-4F0B-4BA9-806E-B8D9A3B31F82}" = SurfHere by Toshiba
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{B208806F-A231-4FA0-AB3F-5C1B8979223E}" = Microsoft ActiveSync 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B9B9863A-32FD-4133-ADB7-46244ED77694}" = Camera Support Core Library
"{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree
"{BEF56F2D-56ED-4176-BF72-7B68D4A3B98D}" = Canon PhotoRecord
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}" = Canon Utilities ZoomBrowser EX
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D41FAAA9-8048-4906-86B2-9AADEA1FA0B7}" = SpeedTouch USB Software
"{DDC146FA-73E0-4FA1-A353-841EA14BF600}" = Drag'n Drop CD+DVD
"{DE286975-ACF1-45B8-9EF7-34E162B2C817}" = MovieEdit Task
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{EC16B64A-38A7-4D7D-BA2E-671ED441304F}" = ALi AGP Driver 2.00
"{EE565795-2776-415A-B31C-EB3A8D7C6FA4}" = Nokia Lifeblog 2.1
"{EF4C7EB0-D71B-43A3-9552-8053DE4B0401}" = PhotoStitch
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F37942A8-B21B-4C5A-A1D2-B676BF55EAE0}" = Camera Window
"{F61F2821-694C-475F-99AB-6AF2EFDF40FD}" = Quicken 2003 New User Edition
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F6C405D2-C50D-4D10-B89E-73A233A14D74}" = Toshiba Registration
"3271E907F27C989F2C244ACB3D32020E3DD3CA6F" = Windows Driver Package - Nokia Modem (06/12/2006 6.81.0.21)
"4oD" = 4oD
"Abacast Client" = Abacast Client
"AccessRunner ADSL" = Conexant AccessRunner USB ADSL WAN Adapter
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Agnitum Spam Terrier_is1" = Agnitum Spam Terrier
"aignesamdeadlink" = AM-DeadLink 3.3
"AMCap" = AMCap
"America Online us" = America Online (Choose which version to remove)
"AOL Connectivity Services" = AOL Connectivity Services
"AolCoach" = AOL Coach Version 1.0(Build:20020929.1)
"AOLCoach uk" = AOL Coach Version 1.0(Build:20040229.1 uk)
"a-squared Free_is1" = a-squared Free 4.0
"AT&T Connection Services Software" = AT&T Connection Services Manager
"Atomic Clock Sync" = Atomic Clock Sync
"AVG8Uninstall" = AVG 8.5
"Belarc Advisor" = Belarc Advisor 7.2
"Betfred Casino" = Betfred Casino
"Betfred Poker" = Betfred Poker
"BeTheDealer Casino" = BeTheDealer Casino
"CanbetPoker (Poker)" = Canbet Poker
"CCleaner" = CCleaner (remove only)
"CEDP Stealer 4 for MSN Messenger 6 and 7" = CEDP Stealer 4 for MSN Messenger 6 and 7
"CleanUp!" = CleanUp!
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"DIVXCodec" = DivX Codec 3.1alpha release
"DVD Region+CSS Free_is1" = DVD Region+CSS Free 5.82
"ERUNT_is1" = ERUNT 1.1j
"ESPNMotion" = ESPNMotion
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"Excel" = Microsoft Excel 97
"FAR manager" = FAR file manager
"Fonbet Poker2" = Fonbet Poker (remove only)
"Globet Poker" = Globet Poker
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"HyperLoad" = HyperLoad
"IcoFX_is1" = IcoFX 1.6.4
"Icon Sucker 2 Standard Edition" = Icon Sucker 2 Standard Edition
"IconWorkshop" = Axialis IconWorkshop 6.33
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{2C164906-E68F-462A-9010-70DD022223EF}" = Canon RemoteCapture Task for ZoomBrowser EX
"InstallShield_{2F81FBFC-9A37-431F-9050-14B55485DF5A}" = Canon Internet Library for ZoomBrowser EX
"InstallShield_{9518F764-C54D-47B2-9E73-154B21E79FD2}" = Canon RAW Image Task for ZoomBrowser EX
"InstallShield_{B9B9863A-32FD-4133-ADB7-46244ED77694}" = Canon Camera Support Core Library
"InstallShield_{DE286975-ACF1-45B8-9EF7-34E162B2C817}" = Canon MovieEdit Task for ZoomBrowser EX
"InstallShield_{EF4C7EB0-D71B-43A3-9552-8053DE4B0401}" = Canon Utilities PhotoStitch 3.1
"InstallShield_{F37942A8-B21B-4C5A-A1D2-B676BF55EAE0}" = Canon Camera Window for ZoomBrowser EX
"InstallShield_{F61F2821-694C-475F-99AB-6AF2EFDF40FD}" = Quicken 2003 New User Edition
"InterActual Player" = InterActual Player
"KLiteCodecPack_is1" = K-Lite Codec Pack 2.40 Full
"Links 2003 Demo 1.0" = Microsoft Links 2003 Demo
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mansion Poker" = MansionPoker
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"Mozilla Firefox (1.5)" = Mozilla Firefox (1.5)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MsgPlus! Plugin" = Messenger Plus! 3
"MSN Music Assistant" = MSN Music Assistant
"New Star Soccer 2" = New Star Soccer 2
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Notebook_Maximizer" = Notebook Maximizer
"ObjectDock" = ObjectDock
"PokerSpying.com PokerSpying" = PokerSpying.com PokerSpying
"PokerStars" = PokerStars
"ppStream_is1" = ppStream 1.0.0.98
"QuicktimeAlt_is1" = QuickTime Alternative 1.66
"RealPlayer 6.0" = RealPlayer
"Recuva" = Recuva (remove only)
"Shockwave" = Shockwave
"Skype_is1" = Skype 2.5
"SopCast" = SopCast 2.0.4
"Spam Bully for OE" = Spam Bully for OE 2.0.0.86
"SpeedFan" = SpeedFan (remove only)
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.3
"Stan James Poker.com" = Stan James Poker.com
"TFNF5" = Toshiba Hotkey Utility for Display Devices
"TomTom HOME" = TomTom HOME 2.6.1.1549
"TOSHIBA Access" = TOSHIBA Access
"Toshiba Power Saver" = TOSHIBA Power Saver
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"TOSHIBA Software Upgrades" = TOSHIBA Software Upgrades
"Toshiba Tbiosdrv Driver" = Toshiba Tbiosdrv Driver
"TOSHIBA Utilities" = TOSHIBA Utilities
"TouchED" = TOSHIBA TouchPad On/Off Utility V2.05.00
"Tweak UI 2.10" = Tweak UI
"Unlocker" = Unlocker 1.8.7
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VideoLAN VLC media player 0.8.4a
"What's Running_is1" = What's Running 2.2
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Word8.0" = Microsoft Word 97
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xerox WorkCentre Pro 412 PCL 6" = Xerox WorkCentre Pro 412 PCL 6
"ZoneAlarm" = ZoneAlarm
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"InstallShield_{99CC78D1-2356-497C-84C1-F239884001EC}" = Turbo Lister
"OANDA FXTrade" = OANDA FXTrade
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 10/05/2009 18:58:33 | Computer Name = GREGGLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application teatimer.exe, version 1.6.6.32, faulting module
teatimer.exe, version 1.6.6.32, fault address 0x0006e66e.
Error - 10/05/2009 18:58:37 | Computer Name = GREGGLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application teatimer.exe, version 1.6.6.32, faulting module
teatimer.exe, version 1.6.6.32, fault address 0x0006e66e.
Error - 10/05/2009 18:58:40 | Computer Name = GREGGLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application teatimer.exe, version 1.6.6.32, faulting module
teatimer.exe, version 1.6.6.32, fault address 0x0006e66e.
Error - 10/05/2009 18:58:42 | Computer Name = GREGGLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application teatimer.exe, version 1.6.6.32, faulting module
teatimer.exe, version 1.6.6.32, fault address 0x0006e66e.
Error - 10/05/2009 18:58:57 | Computer Name = GREGGLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application teatimer.exe, version 1.6.6.32, faulting module
teatimer.exe, version 1.6.6.32, fault address 0x0006e66e.
Error - 10/05/2009 18:59:41 | Computer Name = GREGGLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application teatimer.exe, version 1.6.6.32, faulting module
teatimer.exe, version 1.6.6.32, fault address 0x0006e66e.
Error - 11/05/2009 20:24:05 | Computer Name = GREGGLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module sdhelper.dll, version 1.6.2.14, fault address 0x000051ec.
Error - 13/05/2009 05:20:48 | Computer Name = GREGGLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application mbam-setup.tmp, version 51.49.0.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 13/05/2009 05:21:47 | Computer Name = GREGGLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application mbam.exe, version 1.36.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 13/05/2009 05:21:47 | Computer Name = GREGGLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application mbam.exe, version 1.36.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 10/05/2009 21:19:30 | Computer Name = GREGGLAPTOP | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Windows CardSpace service
to connect.
Error - 10/05/2009 21:19:30 | Computer Name = GREGGLAPTOP | Source = Service Control Manager | ID = 7000
Description = The Windows CardSpace service failed to start due to the following
error: %%1053
Error - 11/05/2009 08:05:51 | Computer Name = GREGGLAPTOP | Source = Service Control Manager | ID = 7000
Description = The NWLink IPX/SPX/NetBIOS Compatible Transport Protocol service failed
to start due to the following error: %%87
Error - 11/05/2009 08:05:51 | Computer Name = GREGGLAPTOP | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2
Error - 11/05/2009 08:05:51 | Computer Name = GREGGLAPTOP | Source = Service Control Manager | ID = 7001
Description = The SAP Agent service depends on the NWLink IPX/SPX/NetBIOS Compatible
Transport Protocol service which failed to start because of the following error:
%%87
Error - 11/05/2009 08:22:18 | Computer Name = GREGGLAPTOP | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: "C:\Program Files\Messenger\msmsgs.exe"
-Embedding
Error - 11/05/2009 20:11:10 | Computer Name = GREGGLAPTOP | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.
Error - 13/05/2009 09:45:16 | Computer Name = GREGGLAPTOP | Source = Service Control Manager | ID = 7000
Description = The NWLink IPX/SPX/NetBIOS Compatible Transport Protocol service failed
to start due to the following error: %%87
Error - 13/05/2009 09:45:16 | Computer Name = GREGGLAPTOP | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2
Error - 13/05/2009 09:45:16 | Computer Name = GREGGLAPTOP | Source = Service Control Manager | ID = 7001
Description = The SAP Agent service depends on the NWLink IPX/SPX/NetBIOS Compatible
Transport Protocol service which failed to start because of the following error:
%%87
< End of report >
PHEW!!! I hope all this means something to someone! Thanks in advance !
BTW it took some time to make this post because of hanging - CPU Usage is still up and down from zero to 100, very erratic even after removing the trojan. Also, still 2 iexplore.exe - even though I only have this open!