Yahoo Searches Redirect [Closed] |
![]() ![]() |
Yahoo Searches Redirect [Closed] |
Jun 15 2009, 02:45 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 25 OS: XP Pro |
So just recently my Yahoo.com searches, once clicked, started redirecting to different sites (spam, malicious). I keep running Malwarebytes and Superantispyware, and they aren't really picking up anything anymore. Last night my computer shut off and restarted, and upon restart my background had been changed saying that my computer was infected, and a fake scan occurred. I restarted my computer into safe mode. AVG8.5 detected the junk that caused the background to change, and removed it. Ran CCleaner a couple times since this has started, ran Malwarebytes and Superantispyware again in safe mode, and it 'appears' to be clean. I restarted my computer, and I don't have the junk pretending to be anti-malware anymore, but Yahoo searches still end up causing redirected links to spam.
This is happening in both Firefox and Explorer, and it's ONLY Yahoo. Google and other search engines work fine, and when I do a search via the AVG Yahoo Search bar, search links are okay. It only happens if I go directly to yahoo.com. Needless to say, after the computer restarted and had the fake anti-virus stuff pop up and replace my background desktop image, I'm worried and would like to get this infection removed. This may just be a coincidence, but this seemed to start happening after I tried installing and using ZoneAlarm. I didn't care for it, and had it uninstalled. Windows Firewall is active, and I am connected to the internet through a Netgear router. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:57:33, on 6/15/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\System32\svchost.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\TVersity\Media Server\MediaServer.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\taskmgr.exe C:\WINDOWS\explorer.exe C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll O1 - Hosts: 195.245.119.131 browser-security.microsoft.com O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Super Ad Blocker Toolbar - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\sabtb.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user') O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O17 - HKLM\System\CS1\Services\Tcpip\..\{017659A2-AA14-4D5D-B1EF-FCFB3CABBA94}: NameServer = 192.168.1.1,192.168.1.2 O17 - HKLM\System\CS2\Services\Tcpip\..\{017659A2-AA14-4D5D-B1EF-FCFB3CABBA94}: NameServer = 192.168.1.1,192.168.1.2 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: !SABWinLogon - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe O23 - Service: Super Ad Blocker Service (SABSVC) - SuperAdBlocker.com - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: TVersityMediaServer - Unknown owner - C:\Program Files\TVersity\Media Server\MediaServer.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe -- End of file - 8006 bytes This post has been edited by jaysee: Jun 15 2009, 02:58 PM |
|
|
Jun 15 2009, 02:49 PM
Post
#2
|
|
![]() Unofficial Music Guru Posts: 2,354 From: Massachusetts, USA OS: Vista |
Hello jaysee and welcome to Geeks to Go! I'm Dave and I'll be helping you to clean your computer.
While HJT was once the preferred log to take a look at to begin with, it's fallen significantly behind the times, so we've updated our initial procedures. The first thing I need you to do is go to this page and follow the instructions there: Malware Cleaning Guide - Please Read Before Starting a New Topic. These are the steps that we need you to perform before attempting a removal of malware from your computer. If you're still experiencing problems after following all the steps in that thread, then please post the following logs here for me to take a look at:
Cheers, Dave |
|
|
Jun 15 2009, 04:56 PM
Post
#3
|
|
|
Member ![]() ![]() Posts: 25 OS: XP Pro |
I couldn't run the SystemRestorePoint program. I get a windows error every time. Did everything else.
QUOTE Malwarebytes' Anti-Malware 1.37 Database version: 2284 Windows 5.1.2600 Service Pack 3 6/15/2009 5:27:35 PM mbam-log-2009-06-15 (17-27-35).txt Scan type: Quick Scan Objects scanned: 95410 Time elapsed: 2 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) QUOTE Rooter.exe (v1.0) by Eric_71 ¨ Microsoft Windows XP Professional (5.1.2600) Service Pack 3 32_bits - x86 Family 15 Model 4 Stepping 9, GenuineIntel ¨ A:\ [Removable] C:\ [Fixed-NTFS] .. ( Total:279 Go - Free:36 Go ) D:\ [Fixed-NTFS] .. ( Total:465 Go - Free:30 Go ) E:\ [CD_Rom] F:\ [CD_Rom] ¨ Scan : 18:31.06 Path : C:\Documents and Settings\John Christian\Desktop\Misc Desktops\AntiVirusAd\Rooter.exe User : John Christian ( Administrator -> YES ) ¨ ----------------------\\ Processes ¨ Locked [System Process] (0) ______ System (4) ______ \SystemRoot\System32\smss.exe (736) ______ \??\C:\WINDOWS\system32\csrss.exe (792) ______ \??\C:\WINDOWS\system32\winlogon.exe (816) ______ C:\WINDOWS\system32\services.exe (864) ______ C:\WINDOWS\system32\lsass.exe (876) ______ C:\WINDOWS\system32\svchost.exe (1064) ______ C:\WINDOWS\system32\svchost.exe (1152) ______ C:\WINDOWS\System32\svchost.exe (1256) ______ C:\WINDOWS\system32\svchost.exe (1504) ______ C:\WINDOWS\system32\spoolsv.exe (1720) ______ C:\WINDOWS\system32\svchost.exe (1900) ______ C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (1944) ______ C:\PROGRA~1\AVG\AVG8\avgrsx.exe (2012) ______ C:\PROGRA~1\AVG\AVG8\avgnsx.exe (2020) ______ C:\WINDOWS\System32\svchost.exe (388) ______ C:\WINDOWS\System32\svchost.exe (728) ______ C:\WINDOWS\System32\svchost.exe (956) ______ C:\WINDOWS\system32\svchost.exe (2192) ______ C:\WINDOWS\Explorer.EXE (2208) ______ C:\Program Files\TVersity\Media Server\MediaServer.exe (2236) ______ C:\Program Files\Windows Media Player\WMPNetwk.exe (2416) ______ C:\PROGRA~1\AVG\AVG8\avgtray.exe (3380) ______ C:\Program Files\Mozilla Firefox\firefox.exe (2288) ______ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (3124) ______ C:\Documents and Settings\John Christian\Desktop\Misc Desktops\AntiVirusAd\Rooter.exe (2932) ¨ ----------------------\\ Device\Harddisk0\ ¨ \Device\Harddisk0 [Sectors : 63 x 512 Bytes] ¨ \Device\Harddisk0\Partition1 --[ MBR ]-- (Start_Offset:32256 | Length:300066407424) ¨ ----------------------\\ Scheduled Tasks ¨ C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job C:\WINDOWS\Tasks\desktop.ini C:\WINDOWS\Tasks\Norton Security Online - Run Full System Scan - John Christian.job C:\WINDOWS\Tasks\SA.DAT ¨ ----------------------\\ Registry ¨ ¨ ----------------------\\ Files & Folders ¨ ----------------------\\ Scan completed at 18:31.09 ¨ C:\Rooter$\Rooter_1.txt - (15/06/2009 | 18:31.09) QUOTE OTL logfile created on: 6/15/2009 6:34:02 PM - Run 1 OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\John Christian\Desktop\Misc Desktops\AntiVirusAd Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 2.00 Gb Total Physical Memory | 1.33 Gb Available Physical Memory | 66.58% Memory free 3.85 Gb Paging File | 3.34 Gb Available in Paging File | 86.76% Paging File free Paging file location(s): D:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 279.46 Gb Total Space | 36.65 Gb Free Space | 13.11% Space Free | Partition Type: NTFS Drive D: | 465.76 Gb Total Space | 30.09 Gb Free Space | 6.46% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: JOHN Current User Name: John Christian Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Output = Minimal File Age = 30 Days Company Name Whitelist: On ========== Processes (SafeList) ========== PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation) PRC - C:\Program Files\TVersity\Media Server\MediaServer.exe () PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation) PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) PRC - C:\Documents and Settings\John Christian\Desktop\Misc Desktops\AntiVirusAd\OTL.exe (OldTimer Tools) ========== Win32 Services (SafeList) ========== SRV - (Adobe LM Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems) SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation) SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) SRV - (clr_optimization_v2.0.50727_32 [Auto | Running]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation) SRV - (hpqcxs08 [Disabled | Stopped]) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.) SRV - (hpqddsvc [Disabled | Stopped]) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.) SRV - (HPSLPSVC [Disabled | Stopped]) -- C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL (Hewlett-Packard Co.) SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation) SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation) SRV - (iPod Service [On_Demand | Stopped]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) SRV - (JavaQuickStarterService [Auto | Stopped]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.) SRV - (Lavasoft Ad-Aware Service [Auto | Stopped]) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft) SRV - (LVPrcSrv [Auto | Stopped]) -- c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe (Logitech Inc.) SRV - (LVSrvLauncher [Auto | Stopped]) -- C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.) SRV - (Net Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard) SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation) SRV - (npggsvc [On_Demand | Stopped]) -- C:\WINDOWS\system32\GameMon.des (INCA Internet Co., Ltd.) SRV - (nTuneService [Auto | Stopped]) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA) SRV - (NVSvc [Auto | Stopped]) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation) SRV - (Pml Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard) SRV - (PnkBstrA [Auto | Stopped]) -- C:\WINDOWS\system32\PnkBstrA.exe () SRV - (PnkBstrB [Auto | Stopped]) -- C:\WINDOWS\system32\PnkBstrB.exe () SRV - (ProtexisLicensing [Auto | Stopped]) -- C:\WINDOWS\system32\PSIService.exe () SRV - (SABSVC [Auto | Stopped]) -- C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE (SuperAdBlocker.com) SRV - (Symantec Core LC [On_Demand | Stopped]) -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation) SRV - (TVersityMediaServer [Auto | Running]) -- C:\Program Files\TVersity\Media Server\MediaServer.exe () SRV - (usnjsvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation) SRV - (Viewpoint Manager Service [Auto | Stopped]) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation) SRV - (WLSetupSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation) SRV - (WMPNetworkSvc [Auto | Running]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation) SRV - (ZuneBusEnum [Auto | Stopped]) -- c:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation) SRV - (ZuneNetworkSvc [Auto | Stopped]) -- c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation) SRV - (ZuneWlanCfgSvc [On_Demand | Stopped]) -- c:\WINDOWS\system32\ZuneWlanCfgSvc.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (ALCXWDM [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.) DRV - (atksgt [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\atksgt.sys () DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.) DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.) DRV - (AvgTdiX [System | Running]) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.) DRV - (ENTECH [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ENTECH.sys (EnTech Taiwan) DRV - (FETNDIS [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\fetnd5.sys (VIA Technologies, Inc. ) DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.) DRV - (giveio [Boot | Running]) -- C:\WINDOWS\system32\giveio.sys () DRV - (L8042Kbd [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys (Logitech, Inc.) DRV - (L8042mou [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\L8042mou.sys (Logitech, Inc.) DRV - (Lbd [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB) DRV - (LHidKe [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\LHidKE.Sys (Logitech, Inc.) DRV - (LHidUsbK [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\LHidUsbK.Sys (Logitech, Inc.) DRV - (lirsgt [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\lirsgt.sys () DRV - (LMouKE [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\LMouKE.sys (Logitech, Inc.) DRV - (LVcKap [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\LVcKap.sys () DRV - (LVMVDrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\LVMVDrv.sys (Logitech Inc.) DRV - (LVPr2Mon [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys () DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation) DRV - (NVR0Dev [On_Demand | Running]) -- C:\WINDOWS\nvoclock.sys (NVidia Corp.) DRV - (pfc [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.) DRV - (PhilCam8116 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\CamDrO21.sys (Microsoft Corporation) DRV - (ppsio2 [Auto | Running]) -- C:\WINDOWS\System32\drivers\ppsio2.sys () DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.) DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions) DRV - (RivaTuner32 [On_Demand | Stopped]) -- D:\Program Files\RivaTuner v2.08\RivaTuner32.sys () DRV - (RTL8023xp [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys (Realtek Semiconductor Corporation ) DRV - (rtl8139 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation) DRV - (SABDIFSV [System | Stopped]) -- C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABDIFSV.SYS () DRV - (SABKUTIL [System | Running]) -- C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys () DRV - (SABProcEnum [On_Demand | Stopped]) -- C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABProcEnum.sys (SuperAdBlocker.com) DRV - (SASDIFSV [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV - (SASENUM [On_Demand | Stopped]) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV - (SASKUTIL [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) DRV - (speedfan [Boot | Running]) -- C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider) DRV - (sptd [Boot | Running]) -- C:\WINDOWS\System32\Drivers\sptd.sys () DRV - (StillCam [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\serscan.sys (Microsoft Corporation) DRV - (Tcpip6 [System | Running]) -- C:\WINDOWS\system32\DRIVERS\tcpip6.sys (Microsoft Corporation) DRV - (usbaudio [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation) DRV - (VIAudio [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\vinyl97.sys (VIA Technologies, Inc.) DRV - (ViBus [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ViBus.sys (VIA Technologies, Inc.) DRV - (videX32 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\videX32.sys (VIA Technologies, Inc.) DRV - (ViPrt [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ViPrt.sys (VIA Technologies, Inc.) DRV - (WMDrive [Auto | Running]) -- C:\WINDOWS\system32\drivers\WMDrive.sys () DRV - (X4HSX32 [Auto | Running]) -- C:\Program Files\GameTap\bin\Release\X4HSX32.Sys (Exent Technologies Ltd.) DRV - (xnacc [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\xnacc.sys (Microsoft Corporation) DRV - (zumbus [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\zumbus.sys (Microsoft Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Yahoo" FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p=" FF - prefs.js..browser.search.selectedEngine: "Yahoo" FF - prefs.js..browser.startup.homepage: "" FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5 FF - prefs.js..extensions.enabledItems: {1d5287d1-8a92-0001-1f31-1cec198018d8}:2.1.0.7 FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.10 FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090123.1 FF - prefs.js..extensions.enabledItems: iaplayer@instantaction.com:0.3.4.0 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0 FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.07061050 FF - prefs.js..extensions.enabledItems: {46868735-c3fa-47ce-8ce7-cce51a66aceb}:1.2 FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:3.0.0 FF - prefs.js..extensions.enabledItems: en-US@dictionaries.addons.mozilla.org:3.0.3 FF - prefs.js..extensions.enabledItems: {3414F358-CBBD-4215-8320-ABAECC12AC25}:1.0 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11 FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=ffds1&p=" FF - HKLM\software\mozilla\Firefox\Extensions\\{3414F358-CBBD-4215-8320-ABAECC12AC25}: C:\DOCUMENTS AND SETTINGS\JOHN CHRISTIAN\LOCAL SETTINGS\APPLICATION DATA\{3414F358-CBBD-4215-8320-ABAECC12AC25}\ [2009/01/05 03:05:00 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX [2009/05/04 14:00:08 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{1d5287d1-8a92-0001-1f31-1cec198018d8}: C:\PROGRAM FILES\AVG\AVG8\TOOLBARFF [2009/05/04 14:00:09 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/05/23 19:42:24 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/06/14 17:07:04 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/06/12 00:16:16 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/06/14 17:07:38 | 00,000,000 | ---D | M] [2008/06/27 07:34:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Extensions [2008/06/27 07:34:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/06/15 14:06:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions [2009/04/23 19:19:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2008/06/27 08:11:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{46868735-c3fa-47ce-8ce7-cce51a66aceb} [2008/02/01 12:50:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2007/08/07 01:12:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232} [2008/06/30 10:35:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644} [2009/06/14 18:44:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781} [2008/06/27 07:48:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\en-US@dictionaries.addons.mozilla.org [2008/01/31 20:30:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\iaplayer@instantaction.com [2007/09/12 03:29:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\moveplayer@movenetworks.com [2008/05/08 00:35:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\sp82nxrc.JC01\extensions [2008/02/01 12:40:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\sp82nxrc.JC01\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2008/05/08 00:35:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\sp82nxrc.JC01\extensions\{991A772A-BA13-4c1d-A9EF-F897F31DEC7D} [2008/12/12 14:23:54 | 00,002,158 | ---- | M] () -- C:\Documents and Settings\John Christian\Application Data\Mozilla\FireFox\Profiles\0c457zba.default\searchplugins\MySpace.xml [2009/06/15 14:06:15 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2009/06/12 00:16:16 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2007/11/04 18:06:45 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED} [2009/06/14 17:07:44 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} [2009/06/12 00:16:10 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009/06/12 00:16:10 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2004/05/07 15:31:40 | 00,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\components\MSVCR71.DLL [2006/11/07 12:58:44 | 00,139,264 | ---- | M] () -- C:\Program Files\mozilla firefox\components\SABFF20.DLL [2009/05/11 22:01:14 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml [2009/05/11 22:01:14 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml [2009/05/11 22:01:14 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml [2009/05/11 22:01:14 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml [2009/05/11 22:01:14 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2009/05/11 22:01:14 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml [2009/05/11 22:01:14 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml O1 HOSTS File: (786 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG Technologies CZ, s.r.o.) O3 - HKLM\..\Toolbar: (Super Ad Blocker Toolbar) - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\sabtb.dll () O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - Reg Error: Key error. File not found O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG Technologies CZ, s.r.o.) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft) O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found O4 - HKCU..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear (NVIDIA) O4 - HKCU..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" (BitTorrent, Inc.) O4 - Startup: C:\Documents and Settings\John Christian\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 157 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.) O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.) O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.) O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation) O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKCU\..Trusted Domains: 26 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14) O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\!SABWinLogon: DllName - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL (SuperAdBlocker.com) O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com) O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.) O24 - Desktop Components:0 (My Current Home Page) - About:Home O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000D7} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSEHB.DLL (SuperAdBlocker.com) O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2007/07/28 21:42:25 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{aa9a245e-2b88-11de-9032-00142a7c704f}\Shell - "" = AutoRun O33 - MountPoints2\{aa9a245e-2b88-11de-9032-00142a7c704f}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{aa9a245e-2b88-11de-9032-00142a7c704f}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found O33 - MountPoints2\{b6b3b553-3d36-11dc-a3af-806d6172696f}\Shell - "" = AutoRun O33 - MountPoints2\{b6b3b553-3d36-11dc-a3af-806d6172696f}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{b6b3b553-3d36-11dc-a3af-806d6172696f}\Shell\AutoRun\command - "" = E:\FrameworkCheck.exe -- File not found O33 - MountPoints2\G\Shell - "" = AutoRun O33 - MountPoints2\G\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - * [2009/06/15 18:32:43 | 00,000,000 | ---D | M] O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe () ========== Files/Folders - Created Within 30 Days ========== [2099/01/01 12:00:00 | 00,011,168 | -H-- | C] () -- C:\WINDOWS\System32\tupigovi [2009/06/15 18:07:21 | 00,000,000 | ---D | C] -- C:\Rooter$ [2009/06/15 17:12:01 | 00,000,767 | ---- | C] () -- C:\Documents and Settings\John Christian\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk [2009/06/15 17:11:52 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT [2009/06/15 16:40:15 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro [2009/06/15 16:29:12 | 00,001,720 | ---- | C] () -- C:\WINDOWS\System32\tmp.reg [2009/06/15 16:28:21 | 00,289,144 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\VCCLSID.exe [2009/06/15 16:28:21 | 00,288,417 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\SrchSTS.exe [2009/06/15 16:28:21 | 00,135,168 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swreg.exe [2009/06/15 16:28:21 | 00,087,552 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\VACFix.exe [2009/06/15 16:28:21 | 00,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.exe [2009/06/15 16:28:21 | 00,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.C.exe [2009/06/15 16:28:21 | 00,082,432 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\404Fix.exe [2009/06/15 16:28:21 | 00,080,384 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\o4Patch.exe [2009/06/15 16:28:21 | 00,079,360 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swxcacls.exe [2009/06/15 16:28:21 | 00,078,336 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\Agent.OMZ.Fix.exe [2009/06/15 16:28:21 | 00,075,776 | ---- | C] () -- C:\WINDOWS\System32\WS2Fix.exe [2009/06/15 16:28:21 | 00,053,248 | ---- | C] (http://www.beyondlogic.org) -- C:\WINDOWS\System32\Process.exe [2009/06/15 16:28:21 | 00,051,200 | ---- | C] () -- C:\WINDOWS\System32\dumphive.exe [2009/06/15 16:28:21 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\swsc.exe [2009/06/15 13:41:50 | 00,981,586 | ---- | C] () -- C:\Documents and Settings\John Christian\My Documents\cc_20090615_134143.reg [2009/06/15 05:42:28 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\93338746.ini [2009/06/15 05:42:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\93338746 [2009/06/15 05:42:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\13328754 [2009/06/14 23:02:31 | 01,615,732 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\ProcessExplorer.zip [2009/06/14 20:42:02 | 00,000,000 | ---D | C] -- C:\Program Files\ESET [2009/06/14 19:58:14 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe [2009/06/14 19:58:14 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe [2009/06/14 19:58:14 | 00,155,136 | ---- | C] () -- C:\WINDOWS\PEV.exe [2009/06/14 19:58:14 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe [2009/06/14 19:58:14 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2009/06/14 19:58:14 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2009/06/14 19:58:14 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2009/06/14 19:58:14 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe [2009/06/14 19:57:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT [2009/06/14 19:57:29 | 00,000,000 | --SD | C] -- C:\ComboFix [2009/06/14 19:57:24 | 00,389,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF1521.exe [2009/06/14 19:56:19 | 00,000,000 | ---D | C] -- C:\Qoobox [2009/06/14 19:28:32 | 00,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2009/06/14 19:28:29 | 00,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat [2009/06/14 17:06:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee [2009/06/12 14:10:30 | 04,613,370 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\heartbeats.mp3 [2009/06/11 22:26:13 | 00,215,383 | ---- | C] () -- C:\WINDOWS\System32\nvapps.xml [2009/06/11 22:26:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\nview [2009/06/11 16:59:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\John Christian\My Documents\Prototype [2009/06/11 04:14:24 | 00,000,803 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Prototype.lnk [2009/06/10 03:01:00 | 00,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieproxy.dll [2009/06/10 03:01:00 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpshims.dll [2009/06/08 21:17:31 | 03,099,494 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\boss.bmp [2009/06/05 21:02:27 | 00,000,000 | ---D | C] -- C:\Program Files\Realtek AC97 [2009/06/05 20:59:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters [2009/06/05 20:58:58 | 00,000,000 | ---D | C] -- C:\Program Files\PC Drivers HeadQuarters [2009/06/05 17:30:08 | 00,001,407 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\i j j i.lnk [2009/06/05 17:30:03 | 00,000,000 | ---D | C] -- C:\ijji [2009/06/05 17:30:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\John Christian\Application Data\ijjigame [2009/06/05 17:29:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ijjigame [2009/06/05 17:06:13 | 00,710,064 | ---- | C] (NHN USA) -- C:\WINDOWS\System32\ijjiSetup.exe [2009/06/05 17:06:13 | 00,157,152 | ---- | C] (NHN Corporation) -- C:\WINDOWS\System32\PubPlugin.dll [2009/06/05 17:06:13 | 00,058,800 | ---- | C] (NHN USA Inc.) -- C:\WINDOWS\System32\ijjiProcessRestarter.exe [2009/06/05 17:06:13 | 00,058,800 | ---- | C] (NHN USA Corp.) -- C:\WINDOWS\System32\ijjiPlugin2.dll [2009/06/05 17:06:13 | 00,000,000 | ---D | C] -- C:\Program Files\NHN USA [2009/06/05 15:22:40 | 00,001,341 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Huxley Lite.lnk [2009/06/05 15:22:40 | 00,000,000 | ---D | C] -- C:\Program Files\HuxleyLite [2009/06/05 03:17:47 | 21,148,51485 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\Huxley_Lite_Setup.zip [2009/06/03 23:48:43 | 00,000,854 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\The Sims 3.lnk [2009/06/03 23:26:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MailFrontier [2009/06/03 23:26:23 | 00,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat [2009/06/03 23:25:34 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ZoneLabs [2009/05/25 18:27:25 | 31,796,401 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\169_sc2_cs_pc2_101108_hr.mp4 [2009/05/24 22:40:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\John Christian\Application Data\Games [2009/05/23 22:29:17 | 00,000,000 | ---D | C] -- C:\Program Files\USArmy [2009/05/23 20:36:21 | 01,089,593 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ntprint.cat [2009/05/23 19:44:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AA3DeployClient [2009/05/23 19:44:26 | 00,000,308 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\AA3Deploy.appref-ms [2009/05/23 19:35:30 | 00,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel [2009/05/21 18:51:48 | 00,041,808 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll [2009/05/19 18:27:38 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft WSE [2009/04/22 00:19:06 | 00,172,173 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat [2009/03/27 10:03:00 | 01,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll [2009/03/27 10:03:00 | 01,503,232 | ---- | C] () -- C:\WINDOWS\System32\nview.dll [2009/03/27 10:03:00 | 01,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll [2009/03/27 10:03:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll [2009/02/17 15:13:08 | 00,037,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\WMDrive.sys [2009/02/07 01:33:58 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest [2008/12/19 02:52:42 | 00,000,061 | ---- | C] () -- C:\WINDOWS\WININIT.INI [2008/11/10 02:26:10 | 00,000,004 | ---- | C] () -- C:\WINDOWS\System32\microday08.dll [2008/11/10 02:26:07 | 00,000,070 | ---- | C] () -- C:\WINDOWS\System32\mypath0079.dll [2008/11/10 02:26:07 | 00,000,034 | ---- | C] () -- C:\WINDOWS\System32\MTX0CI.dll [2008/11/06 12:37:32 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2008/11/06 12:34:00 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest [2008/11/06 12:34:00 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest [2008/11/06 12:33:02 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll [2008/11/05 17:29:30 | 00,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys [2008/10/07 10:13:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll [2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll [2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll [2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll [2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll [2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll [2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll [2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll [2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll [2008/08/21 15:05:01 | 00,000,056 | ---- | C] () -- C:\WINDOWS\kgt2k.INI [2008/07/03 19:57:29 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll [2008/07/03 16:32:59 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll [2008/07/03 16:32:59 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll [2008/07/03 16:32:59 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll [2008/06/05 08:58:26 | 00,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll [2008/04/10 12:52:08 | 00,662,016 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2008/04/10 12:52:06 | 03,104,256 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll [2008/04/10 12:52:06 | 00,520,192 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll [2008/04/10 12:52:06 | 00,404,992 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll [2008/04/10 12:52:06 | 00,397,312 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll [2008/04/10 12:52:06 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll [2008/04/10 12:52:06 | 00,167,936 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll [2008/04/10 12:52:06 | 00,143,360 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll [2008/04/10 12:52:06 | 00,135,168 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll [2008/04/10 12:52:06 | 00,122,880 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll [2008/04/10 12:52:06 | 00,118,784 | ---- | C] () -- C:\WINDOWS\System32\ff_realaac.dll [2008/04/10 12:52:06 | 00,102,912 | ---- | C] () -- C:\WINDOWS\System32\ff_tremor.dll [2008/04/10 12:52:06 | 00,054,784 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll [2008/04/10 12:52:06 | 00,038,400 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll [2008/04/10 12:52:06 | 00,026,624 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll [2008/04/10 12:50:40 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2008/03/29 11:42:22 | 00,245,248 | ---- | C] () -- C:\WINDOWS\System32\dxr.dll [2008/03/29 11:42:20 | 00,159,744 | ---- | C] () -- C:\WINDOWS\System32\mmfinfo.dll [2008/03/29 11:42:14 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\avss.dll [2008/03/29 11:42:08 | 00,148,992 | ---- | C] () -- C:\WINDOWS\System32\mkx.dll [2008/03/29 11:42:04 | 00,141,312 | ---- | C] () -- C:\WINDOWS\System32\mp4.dll [2008/03/29 11:42:04 | 00,108,032 | ---- | C] () -- C:\WINDOWS\System32\avi.dll [2008/03/29 11:42:02 | 00,120,832 | ---- | C] () -- C:\WINDOWS\System32\ogm.dll [2008/03/29 11:42:00 | 00,163,840 | ---- | C] () -- C:\WINDOWS\System32\ts.dll [2008/03/29 11:41:54 | 00,097,280 | ---- | C] () -- C:\WINDOWS\System32\avs.dll [2008/03/29 11:41:52 | 00,079,360 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll [2008/03/29 11:41:52 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll [2008/03/14 02:53:39 | 00,000,004 | ---- | C] () -- C:\WINDOWS\info147.sys [2008/01/23 02:39:12 | 00,215,144 | ---- | C] () -- C:\WINDOWS\patchw32.dll [2007/12/31 20:00:00 | 00,741,376 | ---- | C] () -- C:\WINDOWS\System32\audxlib.dll [2007/12/31 20:00:00 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll [2007/12/31 20:00:00 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\ff_kernelDeint.dll [2007/12/08 04:28:38 | 00,000,023 | ---- | C] () -- C:\WINDOWS\BlendSettings.ini [2007/12/01 01:40:08 | 00,279,712 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys [2007/12/01 01:40:07 | 00,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys [2007/11/18 22:56:06 | 00,000,319 | ---- | C] () -- C:\WINDOWS\game.ini [2007/10/13 05:30:20 | 00,000,137 | ---- | C] () -- C:\WINDOWS\System32\Registration.ini [2007/10/01 23:37:38 | 00,032,768 | ---- | C] () -- C:\WINDOWS\System32\mf.dll [2007/10/01 20:25:17 | 00,034,308 | ---- | C] () -- C:\WINDOWS\System32\bassmod.dll [2007/08/27 19:51:31 | 00,000,077 | ---- | C] () -- C:\WINDOWS\mydebug.ini [2007/08/27 19:31:47 | 00,023,200 | ---- | C] () -- C:\WINDOWS\System32\drivers\ppsio2.sys [2007/08/27 19:30:46 | 00,001,020 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI [2007/08/27 19:30:46 | 00,000,090 | ---- | C] () -- C:\WINDOWS\calera.ini [2007/08/27 19:30:39 | 00,269,312 | ---- | C] () -- C:\WINDOWS\System32\FPXIG.DLL [2007/08/27 19:30:39 | 00,068,096 | ---- | C] () -- C:\WINDOWS\System32\IGFPX32P.DLL [2007/08/27 19:30:39 | 00,065,024 | ---- | C] () -- C:\WINDOWS\System32\JPEGACC.DLL [2007/08/27 19:30:27 | 00,101,376 | ---- | C] () -- C:\WINDOWS\System32\WELSOF32.DLL [2007/08/10 10:13:09 | 00,138,920 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys [2007/08/03 00:09:08 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI [2007/07/29 17:43:52 | 00,685,816 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys [2007/07/28 22:58:45 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\YCRWin32.dll [2007/06/28 14:54:10 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2007/03/12 12:01:30 | 00,217,088 | ---- | C] () -- C:\WINDOWS\NVGfxOgl.dll [2007/02/06 17:45:04 | 00,025,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys [2007/02/06 17:42:40 | 01,691,808 | ---- | C] () -- C:\WINDOWS\System32\drivers\Lvckap.sys [2004/08/04 08:00:00 | 00,000,651 | ---- | C] () -- C:\WINDOWS\win.ini [2004/08/04 08:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\SYSTEM.INI [2003/04/05 13:47:42 | 00,147,456 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll [2002/05/15 20:38:40 | 00,091,136 | ---- | C] () -- C:\WINDOWS\System32\mp4fil32.dll [2002/05/04 10:19:00 | 00,049,152 | ---- | C] () -- C:\WINDOWS\System32\avisynthEx.dll [1996/04/03 15:33:26 | 00,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys ========== Files - Modified Within 30 Days ========== [2009/06/15 18:12:58 | 00,008,192 | -HS- | M] () -- C:\WINDOWS\Thumbs.db [2009/06/15 18:00:34 | 00,215,383 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml [2009/06/15 18:00:34 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009/06/15 18:00:15 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\John Christian\Local Settings\desktop.ini [2009/06/15 18:00:07 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009/06/15 17:59:59 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009/06/15 17:56:48 | 00,492,248 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2009/06/15 17:56:48 | 00,435,260 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2009/06/15 17:56:48 | 00,068,156 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2009/06/15 17:17:24 | 37,139,497 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm [2009/06/15 17:17:24 | 00,077,549 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg [2009/06/15 17:12:01 | 00,000,767 | ---- | M] () -- C:\Documents and Settings\John Christian\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk [2009/06/15 16:31:44 | 00,001,720 | ---- | M] () -- C:\WINDOWS\System32\tmp.reg [2009/06/15 13:58:19 | 00,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat [2009/06/15 13:42:29 | 00,981,586 | ---- | M] () -- C:\Documents and Settings\John Christian\My Documents\cc_20090615_134143.reg [2009/06/15 13:37:06 | 00,000,651 | ---- | M] () -- C:\WINDOWS\win.ini [2009/06/15 13:37:06 | 00,000,227 | ---- | M] () -- C:\WINDOWS\SYSTEM.INI [2009/06/15 13:37:06 | 00,000,211 | -HS- | M] () -- C:\boot.ini [2009/06/15 05:42:28 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\93338746.ini [2009/06/14 23:02:33 | 01,615,732 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\ProcessExplorer.zip [2009/06/14 19:56:38 | 00,389,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF1521.exe [2009/06/14 19:28:29 | 00,000,552 | ---- | M] () -- C:\WINDOWS\System32\d3d8caps.dat [2009/06/13 19:19:31 | 00,001,407 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\i j j i.lnk [2009/06/12 14:20:54 | 04,613,370 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\heartbeats.mp3 [2009/06/11 04:14:24 | 00,000,803 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Prototype.lnk [2009/06/10 21:23:45 | 00,386,888 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2009/06/08 22:17:20 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [2009/06/08 21:17:32 | 03,099,494 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\boss.bmp [2009/06/08 20:00:01 | 00,000,594 | ---- | M] () -- C:\WINDOWS\tasks\Norton Security Online - Run Full System Scan - John Christian.job [2009/06/08 08:10:10 | 00,155,136 | ---- | M] () -- C:\WINDOWS\PEV.exe [2009/06/05 15:22:40 | 00,001,341 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Huxley Lite.lnk [2009/06/05 04:36:36 | 21,148,51485 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\Huxley_Lite_Setup.zip [2009/06/03 23:48:43 | 00,000,854 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\The Sims 3.lnk [2009/06/03 23:37:54 | 00,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat [2009/06/02 11:17:27 | 00,075,776 | ---- | M] () -- C:\WINDOWS\System32\WS2Fix.exe [2009/06/01 12:51:12 | 23,635,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe [2009/05/31 22:17:35 | 00,015,688 | ---- | M] () -- C:\WINDOWS\System32\lsdelete.exe [2009/05/26 17:31:26 | 00,058,800 | ---- | M] (NHN USA Inc.) -- C:\WINDOWS\System32\ijjiProcessRestarter.exe [2009/05/26 13:20:08 | 00,040,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2009/05/26 13:19:56 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2009/05/25 18:30:24 | 31,796,401 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\169_sc2_cs_pc2_101108_hr.mp4 [2009/05/23 19:44:26 | 00,000,308 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\AA3Deploy.appref-ms [2009/05/21 18:51:48 | 00,041,808 | ---- | M] () -- C:\WINDOWS\System32\xfcodec.dll ========== Alternate Data Streams ========== @Alternate Data Stream - 451 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF @Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34 < End of report > QUOTE OTL Extras logfile created on: 6/15/2009 6:34:02 PM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\John Christian\Desktop\Misc Desktops\AntiVirusAd Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 2.00 Gb Total Physical Memory | 1.33 Gb Available Physical Memory | 66.58% Memory free 3.85 Gb Paging File | 3.34 Gb Available in Paging File | 86.76% Paging File free Paging file location(s): D:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 279.46 Gb Total Space | 36.65 Gb Free Space | 13.11% Space Free | Partition Type: NTFS Drive D: | 465.76 Gb Total Space | 30.09 Gb Free Space | 6.46% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: JOHN Current User Name: John Christian Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Output = Minimal File Age = 30 Days Company Name Whitelist: On ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 1 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002 "10244:TCP" = 10244:TCP:LocalSubNet:Enabled:Zune Network Sharing Service "10285:UDP" = 10285:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "10286:UDP" = 10286:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "10287:UDP" = 10287:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "10288:UDP" = 10288:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "10289:UDP" = 10289:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 "DisableNotifications" = 0 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 "10244:TCP" = 10244:TCP:LocalSubNet:Enabled:Zune Network Sharing Service "10285:UDP" = 10285:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "10286:UDP" = 10286:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "10287:UDP" = 10287:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "10288:UDP" = 10288:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "10289:UDP" = 10289:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "57909:TCP" = 57909:TCP:*:Disabled:Pando Media Booster "57909:UDP" = 57909:UDP:*:Disabled:Pando Media Booster "10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation) %windir%\system32\drivers\svchost.exe:*:Enabled:svchost File not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:uTorrent (BitTorrent, Inc.) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.) D:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty® 4 - Modern Warfare () C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test (Microsoft Corporation) C:\Program Files\Xfire\xfire.exe:*:Enabled:Xfire (Xfire Inc.) D:\Program Files\America's Army Deploy Client\AADeployClient.exe:*:Disabled:AADeployClient (US Army) E:\bin\IA\Core\MDM_Util.exe:*:Enabled:MDM_Util File not found D:\Program Files\Electronic Arts\Dead Space\Dead Space.exe:*:Enabled:Dead Space ™ () C:\Program Files\Steam\steam.exe:*:Enabled:Steam (Valve Corporation) %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation) C:\Program Files\Bonjour\mDNSResponder.exe:*:Disabled:Bonjour (Apple Inc.) D:\Program Files\Ubisoft\Far Cry 2\bin\FarCry2.exe:*:Disabled:Far Cry 2 (Ubisoft Entertainment) D:\Program Files\Ubisoft\Far Cry 2\bin\FC2Launcher.exe:*:Disabled:Far Cry 2 Updater (Ubisoft) C:\Program Files\iTunes\iTunes.exe:*:Disabled:iTunes (Apple Inc.) D:\Program Files\EA Games\Mirror's Edge\Binaries\MirrorsEdge.exe:*:Enabled:Mirror's Edge™ (EA Digital Illusions CE AB) C:\Documents and Settings\John Christian\Desktop\base\MetalDrift.exe:*:Enabled:MetalDrift File not found %windir%\system32\drivers\svchost.exe:*:Enabled:svchost File not found C:\Program Files\Steam\steamapps\fanible\darwinia\darwinia.exe:*:Enabled:Darwinia File not found C:\Program Files\TVersity\Media Server\MediaServer.exe:*:Enabled:TVersity Media Server () C:\WINDOWS\explorer.exe:*:Enabled:Windows Explorer (Microsoft Corporation) C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox (Mozilla Corporation) C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader (AOL LLC) C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM (AOL LLC) C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\MySpace\IM\MySpaceIM.exe:*:Enabled:MySpaceIM () C:\Program Files\SmartFTP Client\SmartFTP.exe:*:Enabled:SmartFTP Client 3.0 (SmartSoft Ltd.) C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger (America Online, Inc.) C:\Program Files\Steam\steamapps\common\left 4 dead\left4dead.exe:*:Enabled:Left 4 Dead () C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Disabled:Pando Media Booster () C:\Program Files\USArmy\America's Army 3\Binaries\AA3Game.exe:*:Enabled:AA3Game () C:\WINDOWS\Downloaded Program Files\PurpleBean.exe:*:Enabled:PurpleBean.exe () C:\Program Files\HuxleyLite\binaries\HuxleyMMOGame.exe:*:Enabled:Huxley: The Dystopia (WEBZEN) D:\Program Files\Activision\Prototype\prototypef.exe:*:Enabled:Prototype (Activision) C:\Program Files\NovaLogic\Delta Force Xtreme 2 BETA\UPDATE.EXE:*:Disabled:Delta Force Xtreme 2 BETA File not found C:\Program Files\NovaLogic\Delta Force Xtreme 2 BETA\DFX2BETA.EXE:*:Disabled:Delta Force Xtreme 2 BETA File not found D:\Program Files\Ubisoft\Far Cry 2\bin\FC2Editor.exe:*:Disabled:Editor (Ubisoft Entertainment) C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Disabled:Nexon Game Manager (Nexon) D:\Program Files\Combat Arms\NMService.exe:*:Disabled:Nexon Messenger Core File not found ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "_{0C180787-F8C8-42FD-A9D3-689BA44BEAAF}" = Corel Painter Essentials 3 "{001E7FB6-BB6B-4ED0-BEDC-B5404ED96D4E}" = DocProc "{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}" = Zune Language Pack (FR) "{01386D1F-ADE7-43B4-A4E9-312FC5BC726F}_is1" = SWF Opener "{02DFF6B1-1654-411C-8D7B-FD6052EF016F}" = Apple Software Update "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{05B49229-22A2-4F88-842A-BBC2EBE1CCF6}" = Microsoft Games for Windows - LIVE Redistributable "{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime "{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics "{0C180787-F8C8-42FD-A9D3-689BA44BEAAF}" = Corel Painter Essentials 3 "{0CA38F52-F0FA-4B9F-8A36-EC8A9609FBBC}" = Halo 2 for Windows Vista "{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp "{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up "{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter "{1632FD86-1BA4-4FC4-8B25-A8C655D63F68}" = Sid Meier's Pirates! "{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate "{1B0FBB9A-995D-47cd-87CD-13E68B676E4F}" = Mass Effect "{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX "{1C6D9FD0-8BE2-4226-8D9F-4929CBC1C396}" = Camtasia Studio 4 "{1DCC7418-2089-4BDD-B321-3771956160FC}" = ijji Auto Installer "{200A873B-977F-4063-9AD7-C333B069A571}" = HuxleyLite "{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform "{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2 "{245F6C7A-0C22-4DE0-8202-2AAA620A1D3A}" = Microsoft XNA Framework Redistributable 2.0 "{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.5.5 "{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java 6 Update 14 "{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg "{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}" = Logitech SetPoint "{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision "{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty® 4 - Modern Warfare 1.4 Patch "{3F64C088-9A45-41B3-8B99-71AFAB720A77}" = Sherlock Holmes versus Jack the Ripper DEMO "{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker "{405ABBEB-8DF1-4174-86C0-DCB5E1C78F14}" = NetDeviceManager "{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}" = Google Earth "{415CDA53-9100-476F-A7B2-476691E117C7}" = HP Smart Web Printing "{44B2E182-DD85-45FC-9F51-326B81D7C7F1}" = Fax "{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}" = Bonjour "{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply "{4D243BA7-9AC4-46D1-90E5-EEB88974F501}" = Microsoft Games for Windows - LIVE "{4D87DC92-C328-46EC-A7B4-9C88129DC696}" = Dead Space™ "{4F0C7CCF-5666-474B-B02E-AC514A95EC93}" = NVIDIA GAME System Software 2.8.1 "{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger "{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport "{5721A8EA-A30F-4F66-9046-3F40C43AE1DC}" = Driver Detective "{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.6 "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder "{67E158AF-8856-4337-B483-EA21930786AF}" = GameTap "{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package "{6D6204C8-6B1D-4FBA-ADA9-CB6DFF9BF80D}" = America's Army Deploy Client "{6F23C1A3-9F62-470C-BD12-B83F04E67865}" = SmartFTP Client "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{730837D4-FF5E-48DB-BA49-33E732DFF0B3}" = PanoStandAlone "{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762 "{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0 "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec "{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune "{7D2370AC-D8E6-4996-986A-19824F8A167C}" = Logitech QuickCam "{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01 "{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01 "{8503C901-85D7-4262-88D2-8D8B2A7B08B8}" = Call of Duty® 4 - Modern Warfare 1.5 Patch "{870B0889-A92E-4230-A6A1-F739C1D140DD}" = Opera 9.25 "{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder "{8865B208-4759-4308-8DB5-3C18D2F568E2}" = CrazyTalk for Skype "{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty® 4 - Modern Warfare 1.6 Patch "{8AB8D458-939E-403F-0097-9BA1C1F013D5}" = The Sims 2 "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player "{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update "{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer "{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty® 4 - Modern Warfare 1.7 Patch "{9322A850-9091-4D0E-B252-3E82EDA3D94A}" = Prototype "{93F54611-2701-454e-94AB-623F458D9E6B}" = DeviceDiscovery "{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant "{949DBB22-2FB7-4de1-804C-23D495A988D8}" = CuteFTP 8 Home "{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3 "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9DF0196F-B6B8-4C3A-8790-DE42AA530101}" = SPORE™ "{9E478F3F-7A7B-42C5-BE9C-40FC0E07665F}" = The Awakened "{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime "{A129D1F2-CAC4-4AD7-B26D-3C6411B87DCC}" = Psychonauts "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A7A34FC9-DF24-4A36-00AD-D4EFE94CC116}" = SimCity 4 Deluxe "{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer "{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder "{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder "{AC76BA86-7AD7-1033-7B44-A81100000003}" = Adobe Reader 8.1.1 "{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver "{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant "{AEDBD563-24BB-4EE3-8366-A654DAC2D988}" = Mirror's Edge™ "{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder "{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan "{B041ABD7-4A10-482a-A525-577A7AAD8EC7}" = C6200_Help "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter "{B300CF23-C754-4888-84DD-7AF097F06E05}" = HuxleyLite "{B34E4B72-37C6-4f79-A5B3-008EEFC6EA8B}" = PS_AIO_02_Software_min "{B44529FF-501E-47CD-A06D-223C161BE058}" = FinePixViewer Resource "{B46AC30C-22D2-4610-B041-1DA7BB29EB57}" = HP Photosmart All-In-One Software 9.0 "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player "{B7E5D642-E74E-40a4-B5C7-6AB6EE916814}" = PS_AIO_02_ProductContext "{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation "{BC10649A-983B-494e-AD1F-DE0BF717D701}" = PS_AIO_02_Software "{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter "{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component "{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3 "{C06A7DAC-1708-417C-B694-28C84DFE2DF9}" = The Movies Stunts & Effects "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component "{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware "{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm "{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series "{E3B3AB03-8ABC-46CF-8CA9-DB5581E1F368}" = FinePix Studio "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime "{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty® 4 - Modern Warfare "{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox "{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator "{ECCA8FE7-767A-4C8A-9DAA-BAB60F877C41}" = Sins of a Solar Empire "{EE4ACABF-531E-419A-9225-B8E0FA4955AF}" = Zune Language Pack (ES) "{EE5B8E34-973C-4FBE-AC83-99F064009FC7}" = SpyHunter "{EF6C4600-306D-4F6A-A119-C2A877D25B4A}" = iTunes "{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager "{F11ADC64-C89E-47F4-A0B3-3665FF859397}" = World in Conflict "{F138762F-5A1F-4CF0-A5E1-1588EF6088A4}" = The Witcher Enhanced Edition "{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer "{F2835483-37F2-4123-B4FE-0E77D58447F2}" = Far Cry 2 "{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729) "{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01 "{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE "{F73459A3-36B8-42e4-A982-AAF06A44D508}" = C6200_doccd "{F8BA8B13-856D-4DFB-A28F-7EC868142453}" = Super Ad Blocker "{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio "{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status "{FE54D686-ACC0-42db-A46B-987A5B6D8325}" = C6200 "{FF70513F-E3A7-402F-84FB-B7810A064BE2}" = Zune "Acoustica Effects Pack" = Acoustica Effects Pack "Acoustica Mixcraft 3.1" = Acoustica Mixcraft 3.1 "Ad-Aware" = Ad-Aware "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2 "Adobe Shockwave Player" = Adobe Shockwave Player 11.5 "aignesamdeadlink_is1" = AM-DeadLink 2.8.1 "AIM_6" = AIM 6 "AMP WinOFF" = AMP WinOFF "Aquarius Soft PC Alarm Clock Professional" = Aquarius Soft PC Alarm Clock Professional "AVG8Uninstall" = AVG Free 8.5 "AVI Codec Pack" = AVI Codec Pack "Bink and Smacker" = Bink and Smacker "BroadJump Client Foundation" = BroadJump Client Foundation "CCleaner" = CCleaner (remove only) "Conflict-2142 Map Installer 1.2.1" = Conflict-2142 Map Installer 1.2.1 "Diner Dash 2_is1" = Diner Dash 2 "Diner Dash Flo On The Go_is1" = Diner Dash Flo On The Go "Diner Dash_is1" = Diner Dash "DirectVobSub" = DirectVobSub (remove only) "DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters "ERUNT_is1" = ERUNT 1.1j "ESET Online Scanner" = ESET Online Scanner v3 "ffdshow_is1" = ffdshow [rev 1723] [2007-12-24] "FLVPlayer" = FLV Player 1.3.3 "Fraps" = Fraps "HammerHead Rhythm Station" = HammerHead Rhythm Station "Hidden Secrets The Nightmare_is1" = Hidden Secrets The Nightmare "HijackThis" = HijackThis 2.0.2 "HP Imaging Device Functions" = HP Imaging Device Functions 9.0 "HP Photosmart Essential" = HP Photosmart Essential 2.01 "HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0 "HPOCR" = HP OCR Software 9.0 "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "ie8" = Windows Internet Explorer 8 "InstallShield_{0556F885-2415-4666-B53E-33727E46AEA1}" = The Movies Stunts & Effects "InstallShield_{1632FD86-1BA4-4FC4-8B25-A8C655D63F68}" = Sid Meier's Pirates! "InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager "InstallShield_{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty® 4 - Modern Warfare 1.4 Patch "InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune "InstallShield_{8503C901-85D7-4262-88D2-8D8B2A7B08B8}" = Call of Duty® 4 - Modern Warfare 1.5 Multiplayer Patch "InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty® 4 - Modern Warfare 1.6 Patch "InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty® 4 - Modern Warfare 1.7 Patch "InstallShield_{9322A850-9091-4D0E-B252-3E82EDA3D94A}" = Prototype "InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty® 4 - Modern Warfare "InstallShield_{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager "IsoBuster_is1" = IsoBuster 2.1 "Magic ISO Maker v5.3 (build 0221)" = Magic ISO Maker v5.3 (build 0221) "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Media Player - Codec Pack" = Media Player Codec Pack 3.1.0 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package "Mozilla Firefox (3.0.11)" = Mozilla Firefox (3.0.11) "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "MySpaceIM" = MySpaceIM "Mystery Case Files - Huntsville" = Mystery Case Files - Huntsville (remove only) "Mystery Case Files - Prime Suspects" = Mystery Case Files - Prime Suspects (remove only) "Natural Mod" = Natural Mod "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "NVIDIA Drivers" = NVIDIA Drivers "OggDS" = Direct Show Ogg Vorbis Filter (remove only) "OneTouch Version 3.0" = OneTouch Version 3.0 "OpenAL" = OpenAL "PaperPort 7.01" = PaperPort 7.01 "PunkBusterSvc" = PunkBuster Services "QcDrv" = Logitech® Camera Driver "RealPlayer 6.0" = RealPlayer "RivaTuner" = RivaTuner v2.08 "SBC.MCCInstall" = AT&T Self Support Tool "Sins of a Solar Empire" = Sins of a Solar Empire "Sins of a Solar Empirev1.15" = Sins of a Solar Empire "SmartFTP Client 3.0 Setup Files" = SmartFTP Client 3.0 Setup Files (remove only) "SpeedFan" = SpeedFan (remove only) "SpywareBlaster_is1" = SpywareBlaster 4.1 "ST6UNST #1" = Hero Editor V0.95 "Steam App 1500" = Darwinia "Steam App 500" = Left 4 Dead "SystemRequirementsLab" = System Requirements Lab "Task Killer" = Task Killer (remove only) "Total Video Player 1.03_is1" = Total Video Player 1.03 "TVersity Codec Pack" = TVersity Codec Pack 1.2 "TVersity Media Server " = TVersity Media Server 1.0.0.11 RC7 "UltraISO_is1" = UltraISO Premium V8.63 "ViewpointMediaPlayer" = Viewpoint Media Player "VLC media player" = VideoLAN VLC media player 0.8.6c "Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 "WIC" = Windows Imaging Component "Windows Media Encoder 9" = Windows Media Encoder 9 Series "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinMount3_is1" = WinMount V3.1.1219 "WinRAR archiver" = WinRAR archiver "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "Xbox_360_CC_Driver" = Xbox 360 Controller for Windows "Xfire" = Xfire (remove only) "XpsEPSC" = XML Paper Specification Shared Components Pack 1.0 "XviD MPEG4 Video Codec v1.1.2" = XviD MPEG4 Video Codec v1.1.2 (remove only) "Xvid_is1" = Xvid 1.1.3 final uninstall "Yahoo! Applications" = AT&T Yahoo! Applications "Yahoo! Toolbar" = Yahoo! Toolbar "Zune" = Zune ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "2a4f70b48f669acd" = AA3Deploy "Octoshape Streaming Services" = Octoshape Streaming Services "uTorrent" = µTorrent ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 6/11/2009 9:01:42 PM | Computer Name = JOHN | Source = Application Error | ID = 1000 Description = Faulting application xfire.exe, version 1.0.0.13133, faulting module msvcr71.dll, version 7.10.3052.4, fault address 0x00002f30. Error - 6/11/2009 10:26:31 PM | Computer Name = JOHN | Source = MsiInstaller | ID = 1013 Description = Product: NVIDIA PhysX -- Installation terminated Error - 6/13/2009 11:46:22 AM | Computer Name = JOHN | Source = Application Error | ID = 1000 Description = Faulting application xfire.exe, version 1.0.0.13133, faulting module msvcr71.dll, version 7.10.3052.4, fault address 0x00002f30. Error - 6/13/2009 6:47:09 PM | Computer Name = JOHN | Source = Application Error | ID = 1000 Description = Faulting application xfire.exe, version 1.0.0.13133, faulting module msvcr71.dll, version 7.10.3052.4, fault address 0x00002f30. Error - 6/15/2009 5:10:48 PM | Computer Name = JOHN | Source = .NET Runtime 2.0 Error Reporting | ID = 5000 Description = EventType clr20r3, P1 sysrestorepoint.exe, P2 1.3.0.0, P3 485da791, P4 sysrestorepoint, P5 1.3.0.0, P6 485da791, P7 d, P8 ca, P9 system.invalidoperationexception, P10 NIL. Error - 6/15/2009 5:10:58 PM | Computer Name = JOHN | Source = .NET Runtime 2.0 Error Reporting | ID = 5000 Description = EventType clr20r3, P1 sysrestorepoint.exe, P2 1.3.0.0, P3 485da791, P4 sysrestorepoint, P5 1.3.0.0, P6 485da791, P7 d, P8 ca, P9 system.invalidoperationexception, P10 NIL. Error - 6/15/2009 6:08:19 PM | Computer Name = JOHN | Source = Application Hang | ID = 1002 Description = Hanging application Rooter.exe, version 0.0.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 6/15/2009 6:08:23 PM | Computer Name = JOHN | Source = Application Hang | ID = 1001 Description = Fault bucket 495547216. Error - 6/15/2009 6:08:45 PM | Computer Name = JOHN | Source = .NET Runtime 2.0 Error Reporting | ID = 5000 Description = EventType clr20r3, P1 sysrestorepoint.exe, P2 1.3.0.0, P3 485da791, P4 sysrestorepoint, P5 1.3.0.0, P6 485da791, P7 d, P8 ca, P9 system.invalidoperationexception, P10 NIL. Error - 6/15/2009 6:08:56 PM | Computer Name = JOHN | Source = .NET Runtime 2.0 Error Reporting | ID = 5000 Description = EventType clr20r3, P1 sysrestorepointooooo.exe, P2 1.3.0.0, P3 485da791, P4 sysrestorepoint, P5 1.3.0.0, P6 485da791, P7 d, P8 ca, P9 system.invalidoperationexception, P10 NIL. [ System Events ] Error - 6/15/2009 6:06:03 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7034 Description = The nTune Service service terminated unexpectedly. It has done this 1 time(s). Error - 6/15/2009 6:06:06 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7031 Description = The .NET Runtime Optimization Service v2.0.50727_X86 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. Error - 6/15/2009 6:06:08 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7034 Description = The Process Monitor service terminated unexpectedly. It has done this 1 time(s). Error - 6/15/2009 6:06:12 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7031 Description = The Zune Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. Error - 6/15/2009 6:06:13 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7031 Description = The Zune Bus Enumerator service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. Error - 6/15/2009 6:06:14 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7031 Description = The Zune Network Sharing Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. Error - 6/15/2009 6:06:15 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7031 Description = The Zune Bus Enumerator service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. Error - 6/15/2009 6:06:16 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7034 Description = The Zune Network Sharing Service service terminated unexpectedly. It has done this 3 time(s). Error - 6/15/2009 6:06:17 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7034 Description = The Zune Bus Enumerator service terminated unexpectedly. It has done this 3 time(s). Error - 6/15/2009 6:06:18 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7034 Description = The Viewpoint Manager Service service terminated unexpectedly. It has done this 1 time(s). < End of report > This post has been edited by jaysee: Jun 16 2009, 11:10 PM |
|
|
Jun 15 2009, 07:23 PM
Post
#4
|
|
![]() Unofficial Music Guru Posts: 2,354 From: Massachusetts, USA OS: Vista |
Hi jaysee -
I see you're using or have in the past used p2p software such as uTorrent. Although p2p programs are not usually malware in their own right, oftentimes malware is installed alongside them. Even if the program is clean, people often upload infected files to be shared using these programs, and it is very easy to end up compromising your PC. It's your decision about whether or not you use p2p programs, you don't have to remove them to be deemed clean and I'll still give you help if you want to keep them. It's just important that you're aware of the risks. If you want to continue using p2p programs that's fine with me, all I ask is that you not download anything from them until you're clean so we aren't taking steps backwards here. To remove p2p programs if you wish to do so, uninstall them from the Add/Remove Programs (it's Programs and Features in Vista) menu of your Control Panel. Please go to Add/Remove Programs in your Control Panel (Programs and Features if you are a Vista user). Select and remove the following if present, don't worry if they aren't: Viewpoint Media Player - Viewpoint is an annoying media player that installs alongside many different things without your permission, not a good idea to keep it on your computer. Next OTL Fixes
Just need the fresh OTL log in your next reply. |
|
|
Jun 16 2009, 08:39 PM
Post
#5
|
|
|
Member ![]() ![]() Posts: 25 OS: XP Pro |
Uninstalled utorrent, and also Viewpoint Media Player. I didn't know if I was suppose to try or not, but Yahoo.com searches are still being redirected to spam, or fake search engines.
QUOTE OTL logfile created on: 6/16/2009 10:49:24 PM - Run 2
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\John Christian\Desktop\Misc Desktops\AntiVirusAd Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 2.00 Gb Total Physical Memory | 1.50 Gb Available Physical Memory | 75.00% Memory free 3.85 Gb Paging File | 3.48 Gb Available in Paging File | 90.50% Paging File free Paging file location(s): D:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 279.46 Gb Total Space | 34.46 Gb Free Space | 12.33% Space Free | Partition Type: NTFS Drive D: | 465.76 Gb Total Space | 30.68 Gb Free Space | 6.59% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: JOHN Current User Name: John Christian Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Output = Minimal File Age = 30 Days Company Name Whitelist: On ========== Processes (SafeList) ========== PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\TVersity\Media Server\MediaServer.exe () PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation) PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation) PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation) PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation) PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Documents and Settings\John Christian\Desktop\Misc Desktops\AntiVirusAd\OTL.exe (OldTimer Tools) ========== Win32 Services (SafeList) ========== SRV - (Adobe LM Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems) SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation) SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation) SRV - (hpqcxs08 [Disabled | Stopped]) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.) SRV - (hpqddsvc [Disabled | Stopped]) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.) SRV - (HPSLPSVC [Disabled | Stopped]) -- C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL (Hewlett-Packard Co.) SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation) SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation) SRV - (iPod Service [On_Demand | Stopped]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) SRV - (JavaQuickStarterService [Auto | Stopped]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.) SRV - (Lavasoft Ad-Aware Service [Auto | Stopped]) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft) SRV - (LVPrcSrv [Auto | Stopped]) -- c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe (Logitech Inc.) SRV - (LVSrvLauncher [Auto | Stopped]) -- C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.) SRV - (Net Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard) SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation) SRV - (npggsvc [On_Demand | Stopped]) -- C:\WINDOWS\system32\GameMon.des (INCA Internet Co., Ltd.) SRV - (nTuneService [Auto | Stopped]) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA) SRV - (NVSvc [Auto | Stopped]) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation) SRV - (Pml Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard) SRV - (PnkBstrA [Auto | Stopped]) -- C:\WINDOWS\system32\PnkBstrA.exe () SRV - (PnkBstrB [Auto | Stopped]) -- C:\WINDOWS\system32\PnkBstrB.exe () SRV - (ProtexisLicensing [Auto | Stopped]) -- C:\WINDOWS\system32\PSIService.exe () SRV - (SABSVC [Auto | Stopped]) -- C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE (SuperAdBlocker.com) SRV - (Symantec Core LC [On_Demand | Stopped]) -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation) SRV - (TVersityMediaServer [Auto | Running]) -- C:\Program Files\TVersity\Media Server\MediaServer.exe () SRV - (usnjsvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation) SRV - (WLSetupSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation) SRV - (WMPNetworkSvc [Auto | Running]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation) SRV - (ZuneBusEnum [Auto | Stopped]) -- c:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation) SRV - (ZuneNetworkSvc [Auto | Stopped]) -- c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation) SRV - (ZuneWlanCfgSvc [On_Demand | Stopped]) -- c:\WINDOWS\system32\ZuneWlanCfgSvc.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (ALCXWDM [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.) DRV - (atksgt [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\atksgt.sys () DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.) DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.) DRV - (AvgTdiX [System | Running]) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.) DRV - (ENTECH [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ENTECH.sys (EnTech Taiwan) DRV - (FETNDIS [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\fetnd5.sys (VIA Technologies, Inc. ) DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.) DRV - (giveio [Boot | Running]) -- C:\WINDOWS\system32\giveio.sys () DRV - (L8042Kbd [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys (Logitech, Inc.) DRV - (L8042mou [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\L8042mou.sys (Logitech, Inc.) DRV - (Lbd [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB) DRV - (LHidKe [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\LHidKE.Sys (Logitech, Inc.) DRV - (LHidUsbK [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\LHidUsbK.Sys (Logitech, Inc.) DRV - (lirsgt [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\lirsgt.sys () DRV - (LMouKE [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\LMouKE.sys (Logitech, Inc.) DRV - (LVcKap [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\LVcKap.sys () DRV - (LVMVDrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\LVMVDrv.sys (Logitech Inc.) DRV - (LVPr2Mon [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys () DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation) DRV - (NVR0Dev [On_Demand | Running]) -- C:\WINDOWS\nvoclock.sys (NVidia Corp.) DRV - (pfc [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.) DRV - (PhilCam8116 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\CamDrO21.sys (Microsoft Corporation) DRV - (ppsio2 [Auto | Running]) -- C:\WINDOWS\System32\drivers\ppsio2.sys () DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.) DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions) DRV - (RivaTuner32 [On_Demand | Stopped]) -- D:\Program Files\RivaTuner v2.08\RivaTuner32.sys () DRV - (RTL8023xp [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys (Realtek Semiconductor Corporation ) DRV - (rtl8139 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation) DRV - (SABDIFSV [System | Stopped]) -- C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABDIFSV.SYS () DRV - (SABKUTIL [System | Running]) -- C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys () DRV - (SABProcEnum [On_Demand | Stopped]) -- C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABProcEnum.sys (SuperAdBlocker.com) DRV - (SASDIFSV [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV - (SASENUM [On_Demand | Stopped]) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV - (SASKUTIL [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) DRV - (speedfan [Boot | Running]) -- C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider) DRV - (sptd [Boot | Running]) -- C:\WINDOWS\System32\Drivers\sptd.sys () DRV - (StillCam [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\serscan.sys (Microsoft Corporation) DRV - (Tcpip6 [System | Running]) -- C:\WINDOWS\system32\DRIVERS\tcpip6.sys (Microsoft Corporation) DRV - (usbaudio [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation) DRV - (VIAudio [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\vinyl97.sys (VIA Technologies, Inc.) DRV - (ViBus [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ViBus.sys (VIA Technologies, Inc.) DRV - (videX32 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\videX32.sys (VIA Technologies, Inc.) DRV - (ViPrt [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ViPrt.sys (VIA Technologies, Inc.) DRV - (WMDrive [Auto | Running]) -- C:\WINDOWS\system32\drivers\WMDrive.sys () DRV - (X4HSX32 [Auto | Running]) -- C:\Program Files\GameTap\bin\Release\X4HSX32.Sys (Exent Technologies Ltd.) DRV - (xnacc [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\xnacc.sys (Microsoft Corporation) DRV - (zumbus [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\zumbus.sys (Microsoft Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Yahoo" FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p=" FF - prefs.js..browser.search.selectedEngine: "Yahoo" FF - prefs.js..browser.startup.homepage: "" FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5 FF - prefs.js..extensions.enabledItems: {1d5287d1-8a92-0001-1f31-1cec198018d8}:2.1.0.7 FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.10 FF - prefs.js..extensions.enabledItems: iaplayer@instantaction.com:0.3.4.0 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0 FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.07061050 FF - prefs.js..extensions.enabledItems: {46868735-c3fa-47ce-8ce7-cce51a66aceb}:1.2 FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:3.0.0 FF - prefs.js..extensions.enabledItems: en-US@dictionaries.addons.mozilla.org:3.0.3 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11 FF - HKLM\software\mozilla\Firefox\Extensions\\{3414F358-CBBD-4215-8320-ABAECC12AC25}: C:\DOCUMENTS AND SETTINGS\JOHN CHRISTIAN\LOCAL SETTINGS\APPLICATION DATA\{3414F358-CBBD-4215-8320-ABAECC12AC25}\ FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX [2009/05/04 14:00:08 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{1d5287d1-8a92-0001-1f31-1cec198018d8}: C:\PROGRAM FILES\AVG\AVG8\TOOLBARFF [2009/05/04 14:00:09 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/05/23 19:42:24 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/06/14 17:07:04 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/06/16 14:47:13 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/06/16 22:27:35 | 00,000,000 | ---D | M] [2008/06/27 07:34:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Extensions [2008/06/27 07:34:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/06/16 22:23:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions [2009/04/23 19:19:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2008/06/27 08:11:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{46868735-c3fa-47ce-8ce7-cce51a66aceb} [2008/02/01 12:50:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2007/08/07 01:12:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232} [2008/06/30 10:35:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644} [2008/06/27 07:48:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\en-US@dictionaries.addons.mozilla.org [2008/01/31 20:30:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\iaplayer@instantaction.com [2007/09/12 03:29:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\moveplayer@movenetworks.com [2008/05/08 00:35:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\sp82nxrc.JC01\extensions [2008/02/01 12:40:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\sp82nxrc.JC01\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2008/05/08 00:35:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\sp82nxrc.JC01\extensions\{991A772A-BA13-4c1d-A9EF-F897F31DEC7D} [2008/12/12 14:23:54 | 00,002,158 | ---- | M] () -- C:\Documents and Settings\John Christian\Application Data\Mozilla\FireFox\Profiles\0c457zba.default\searchplugins\MySpace.xml [2009/06/16 14:57:25 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2009/06/12 00:16:16 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2007/11/04 18:06:45 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED} [2009/06/14 17:07:44 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} [2009/06/12 00:16:10 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009/06/12 00:16:10 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2004/05/07 15:31:40 | 00,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\components\MSVCR71.DLL [2006/11/07 12:58:44 | 00,139,264 | ---- | M] () -- C:\Program Files\mozilla firefox\components\SABFF20.DLL [2009/05/11 22:01:14 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml [2009/05/11 22:01:14 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml [2009/05/11 22:01:14 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml [2009/05/11 22:01:14 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml [2009/05/11 22:01:14 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2009/05/11 22:01:14 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml [2009/05/11 22:01:14 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml O1 HOSTS File: (786 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG Technologies CZ, s.r.o.) O3 - HKLM\..\Toolbar: (Super Ad Blocker Toolbar) - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\sabtb.dll () O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - Reg Error: Key error. File not found O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG Technologies CZ, s.r.o.) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft) O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found O4 - HKCU..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear (NVIDIA) O4 - Startup: C:\Documents and Settings\John Christian\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 157 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.) O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.) O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.) O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation) O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKCU\..Trusted Domains: 26 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14) O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\!SABWinLogon: DllName - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL (SuperAdBlocker.com) O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com) O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.) O24 - Desktop Components:0 (My Current Home Page) - About:Home O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000D7} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSEHB.DLL (SuperAdBlocker.com) O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - * [2009/06/15 18:35:15 | 00,000,000 | ---D | M] O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe () ========== Files/Folders - Created Within 30 Days ========== [2009/06/16 22:18:50 | 00,000,000 | ---D | C] -- C:\_OTL [2009/06/15 18:07:21 | 00,000,000 | ---D | C] -- C:\Rooter$ [2009/06/15 17:12:01 | 00,000,767 | ---- | C] () -- C:\Documents and Settings\John Christian\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk [2009/06/15 17:11:52 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT [2009/06/15 16:40:15 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro [2009/06/15 16:29:12 | 00,001,720 | ---- | C] () -- C:\WINDOWS\System32\tmp.reg [2009/06/15 16:28:21 | 00,289,144 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\VCCLSID.exe [2009/06/15 16:28:21 | 00,288,417 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\SrchSTS.exe [2009/06/15 16:28:21 | 00,135,168 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swreg.exe [2009/06/15 16:28:21 | 00,087,552 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\VACFix.exe [2009/06/15 16:28:21 | 00,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.exe [2009/06/15 16:28:21 | 00,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.C.exe [2009/06/15 16:28:21 | 00,082,432 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\404Fix.exe [2009/06/15 16:28:21 | 00,080,384 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\o4Patch.exe [2009/06/15 16:28:21 | 00,079,360 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swxcacls.exe [2009/06/15 16:28:21 | 00,078,336 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\Agent.OMZ.Fix.exe [2009/06/15 16:28:21 | 00,075,776 | ---- | C] () -- C:\WINDOWS\System32\WS2Fix.exe [2009/06/15 16:28:21 | 00,053,248 | ---- | C] (http://www.beyondlogic.org) -- C:\WINDOWS\System32\Process.exe [2009/06/15 16:28:21 | 00,051,200 | ---- | C] () -- C:\WINDOWS\System32\dumphive.exe [2009/06/15 16:28:21 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\swsc.exe [2009/06/15 13:41:50 | 00,981,586 | ---- | C] () -- C:\Documents and Settings\John Christian\My Documents\cc_20090615_134143.reg [2009/06/14 23:02:31 | 01,615,732 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\ProcessExplorer.zip [2009/06/14 20:42:02 | 00,000,000 | ---D | C] -- C:\Program Files\ESET [2009/06/14 19:58:14 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe [2009/06/14 19:58:14 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe [2009/06/14 19:58:14 | 00,155,136 | ---- | C] () -- C:\WINDOWS\PEV.exe [2009/06/14 19:58:14 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe [2009/06/14 19:58:14 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2009/06/14 19:58:14 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2009/06/14 19:58:14 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2009/06/14 19:58:14 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe [2009/06/14 19:57:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT [2009/06/14 19:57:29 | 00,000,000 | --SD | C] -- C:\ComboFix [2009/06/14 19:57:24 | 00,389,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF1521.exe [2009/06/14 19:56:19 | 00,000,000 | ---D | C] -- C:\Qoobox [2009/06/14 17:06:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee [2009/06/12 14:10:30 | 04,613,370 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\heartbeats.mp3 [2009/06/11 22:26:13 | 00,215,383 | ---- | C] () -- C:\WINDOWS\System32\nvapps.xml [2009/06/11 22:26:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\nview [2009/06/11 16:59:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\John Christian\My Documents\Prototype [2009/06/11 04:14:24 | 00,000,803 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Prototype.lnk [2009/06/10 03:01:00 | 00,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieproxy.dll [2009/06/10 03:01:00 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpshims.dll [2009/06/08 21:17:31 | 03,099,494 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\boss.bmp [2009/06/05 21:02:27 | 00,000,000 | ---D | C] -- C:\Program Files\Realtek AC97 [2009/06/05 20:59:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters [2009/06/05 20:58:58 | 00,000,000 | ---D | C] -- C:\Program Files\PC Drivers HeadQuarters [2009/06/05 17:30:08 | 00,001,407 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\i j j i.lnk [2009/06/05 17:30:03 | 00,000,000 | ---D | C] -- C:\ijji [2009/06/05 17:30:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\John Christian\Application Data\ijjigame [2009/06/05 17:29:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ijjigame [2009/06/05 17:06:13 | 00,710,064 | ---- | C] (NHN USA) -- C:\WINDOWS\System32\ijjiSetup.exe [2009/06/05 17:06:13 | 00,157,152 | ---- | C] (NHN Corporation) -- C:\WINDOWS\System32\PubPlugin.dll [2009/06/05 17:06:13 | 00,058,800 | ---- | C] (NHN USA Inc.) -- C:\WINDOWS\System32\ijjiProcessRestarter.exe [2009/06/05 17:06:13 | 00,058,800 | ---- | C] (NHN USA Corp.) -- C:\WINDOWS\System32\ijjiPlugin2.dll [2009/06/05 17:06:13 | 00,000,000 | ---D | C] -- C:\Program Files\NHN USA [2009/06/05 15:22:40 | 00,001,341 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Huxley Lite.lnk [2009/06/05 15:22:40 | 00,000,000 | ---D | C] -- C:\Program Files\HuxleyLite [2009/06/05 03:17:47 | 21,148,51485 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\Huxley_Lite_Setup.zip [2009/06/03 23:48:43 | 00,000,854 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\The Sims 3.lnk [2009/06/03 23:26:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MailFrontier [2009/06/03 23:26:23 | 00,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat [2009/06/03 23:25:34 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ZoneLabs [2009/05/25 18:27:25 | 31,796,401 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\169_sc2_cs_pc2_101108_hr.mp4 [2009/05/24 22:40:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\John Christian\Application Data\Games [2009/05/23 22:29:17 | 00,000,000 | ---D | C] -- C:\Program Files\USArmy [2009/05/23 20:36:21 | 01,089,593 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ntprint.cat [2009/05/23 19:44:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AA3DeployClient [2009/05/23 19:44:26 | 00,000,308 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\AA3Deploy.appref-ms [2009/05/21 18:51:48 | 00,041,808 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll [2009/05/19 18:27:38 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft WSE [2009/04/22 00:19:06 | 00,172,173 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat [2009/03/27 10:03:00 | 01,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll [2009/03/27 10:03:00 | 01,503,232 | ---- | C] () -- C:\WINDOWS\System32\nview.dll [2009/03/27 10:03:00 | 01,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll [2009/03/27 10:03:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll [2009/02/17 15:13:08 | 00,037,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\WMDrive.sys [2009/02/07 01:33:58 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest [2008/12/19 02:52:42 | 00,000,061 | ---- | C] () -- C:\WINDOWS\WININIT.INI [2008/11/10 02:26:10 | 00,000,004 | ---- | C] () -- C:\WINDOWS\System32\microday08.dll [2008/11/10 02:26:07 | 00,000,070 | ---- | C] () -- C:\WINDOWS\System32\mypath0079.dll [2008/11/10 02:26:07 | 00,000,034 | ---- | C] () -- C:\WINDOWS\System32\MTX0CI.dll [2008/11/06 12:37:32 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2008/11/06 12:34:00 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest [2008/11/06 12:34:00 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest [2008/11/06 12:33:02 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll [2008/11/05 17:29:30 | 00,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys [2008/10/07 10:13:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll [2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll [2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll [2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll [2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll [2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll [2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll [2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll [2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll [2008/08/21 15:05:01 | 00,000,056 | ---- | C] () -- C:\WINDOWS\kgt2k.INI [2008/07/03 19:57:29 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll [2008/07/03 16:32:59 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll [2008/07/03 16:32:59 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll [2008/07/03 16:32:59 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll [2008/06/05 08:58:26 | 00,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll [2008/04/10 12:52:08 | 00,662,016 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2008/04/10 12:52:06 | 03,104,256 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll [2008/04/10 12:52:06 | 00,520,192 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll [2008/04/10 12:52:06 | 00,404,992 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll [2008/04/10 12:52:06 | 00,397,312 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll [2008/04/10 12:52:06 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll [2008/04/10 12:52:06 | 00,167,936 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll [2008/04/10 12:52:06 | 00,143,360 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll [2008/04/10 12:52:06 | 00,135,168 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll [2008/04/10 12:52:06 | 00,122,880 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll [2008/04/10 12:52:06 | 00,118,784 | ---- | C] () -- C:\WINDOWS\System32\ff_realaac.dll [2008/04/10 12:52:06 | 00,102,912 | ---- | C] () -- C:\WINDOWS\System32\ff_tremor.dll [2008/04/10 12:52:06 | 00,054,784 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll [2008/04/10 12:52:06 | 00,038,400 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll [2008/04/10 12:52:06 | 00,026,624 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll [2008/04/10 12:50:40 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2008/03/29 11:42:22 | 00,245,248 | ---- | C] () -- C:\WINDOWS\System32\dxr.dll [2008/03/29 11:42:20 | 00,159,744 | ---- | C] () -- C:\WINDOWS\System32\mmfinfo.dll [2008/03/29 11:42:14 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\avss.dll [2008/03/29 11:42:08 | 00,148,992 | ---- | C] () -- C:\WINDOWS\System32\mkx.dll [2008/03/29 11:42:04 | 00,141,312 | ---- | C] () -- C:\WINDOWS\System32\mp4.dll [2008/03/29 11:42:04 | 00,108,032 | ---- | C] () -- C:\WINDOWS\System32\avi.dll [2008/03/29 11:42:02 | 00,120,832 | ---- | C] () -- C:\WINDOWS\System32\ogm.dll [2008/03/29 11:42:00 | 00,163,840 | ---- | C] () -- C:\WINDOWS\System32\ts.dll [2008/03/29 11:41:54 | 00,097,280 | ---- | C] () -- C:\WINDOWS\System32\avs.dll [2008/03/29 11:41:52 | 00,079,360 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll [2008/03/29 11:41:52 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll [2008/03/14 02:53:39 | 00,000,004 | ---- | C] () -- C:\WINDOWS\info147.sys [2008/01/23 02:39:12 | 00,215,144 | ---- | C] () -- C:\WINDOWS\patchw32.dll [2007/12/31 20:00:00 | 00,741,376 | ---- | C] () -- C:\WINDOWS\System32\audxlib.dll [2007/12/31 20:00:00 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll [2007/12/31 20:00:00 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\ff_kernelDeint.dll [2007/12/08 04:28:38 | 00,000,023 | ---- | C] () -- C:\WINDOWS\BlendSettings.ini [2007/12/01 01:40:08 | 00,279,712 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys [2007/12/01 01:40:07 | 00,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys [2007/11/18 22:56:06 | 00,000,319 | ---- | C] () -- C:\WINDOWS\game.ini [2007/10/13 05:30:20 | 00,000,137 | ---- | C] () -- C:\WINDOWS\System32\Registration.ini [2007/10/01 23:37:38 | 00,032,768 | ---- | C] () -- C:\WINDOWS\System32\mf.dll [2007/10/01 20:25:17 | 00,034,308 | ---- | C] () -- C:\WINDOWS\System32\bassmod.dll [2007/08/27 19:51:31 | 00,000,077 | ---- | C] () -- C:\WINDOWS\mydebug.ini [2007/08/27 19:31:47 | 00,023,200 | ---- | C] () -- C:\WINDOWS\System32\drivers\ppsio2.sys [2007/08/27 19:30:46 | 00,001,020 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI [2007/08/27 19:30:46 | 00,000,090 | ---- | C] () -- C:\WINDOWS\calera.ini [2007/08/27 19:30:39 | 00,269,312 | ---- | C] () -- C:\WINDOWS\System32\FPXIG.DLL [2007/08/27 19:30:39 | 00,068,096 | ---- | C] () -- C:\WINDOWS\System32\IGFPX32P.DLL [2007/08/27 19:30:39 | 00,065,024 | ---- | C] () -- C:\WINDOWS\System32\JPEGACC.DLL [2007/08/27 19:30:27 | 00,101,376 | ---- | C] () -- C:\WINDOWS\System32\WELSOF32.DLL [2007/08/10 10:13:09 | 00,138,920 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys [2007/08/03 00:09:08 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI [2007/07/29 17:43:52 | 00,685,816 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys [2007/07/28 22:58:45 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\YCRWin32.dll [2007/06/28 14:54:10 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2007/03/12 12:01:30 | 00,217,088 | ---- | C] () -- C:\WINDOWS\NVGfxOgl.dll [2007/02/06 17:45:04 | 00,025,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys [2007/02/06 17:42:40 | 01,691,808 | ---- | C] () -- C:\WINDOWS\System32\drivers\Lvckap.sys [2004/08/04 08:00:00 | 00,000,651 | ---- | C] () -- C:\WINDOWS\win.ini [2004/08/04 08:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\SYSTEM.INI [2003/04/05 13:47:42 | 00,147,456 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll [2002/05/15 20:38:40 | 00,091,136 | ---- | C] () -- C:\WINDOWS\System32\mp4fil32.dll [2002/05/04 10:19:00 | 00,049,152 | ---- | C] () -- C:\WINDOWS\System32\avisynthEx.dll [1996/04/03 15:33:26 | 00,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys ========== Files - Modified Within 30 Days ========== [2009/06/16 22:47:56 | 00,215,383 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml [2009/06/16 22:47:23 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009/06/16 22:47:11 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\John Christian\Local Settings\desktop.ini [2009/06/16 22:46:58 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009/06/16 22:46:53 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009/06/16 22:27:57 | 00,008,192 | -HS- | M] () -- C:\WINDOWS\Thumbs.db [2009/06/16 17:53:07 | 37,160,237 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm [2009/06/16 17:53:07 | 00,078,361 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg [2009/06/15 22:17:08 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [2009/06/15 20:00:00 | 00,000,594 | ---- | M] () -- C:\WINDOWS\tasks\Norton Security Online - Run Full System Scan - John Christian.job [2009/06/15 17:56:48 | 00,492,248 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2009/06/15 17:56:48 | 00,435,260 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2009/06/15 17:56:48 | 00,068,156 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2009/06/15 17:12:01 | 00,000,767 | ---- | M] () -- C:\Documents and Settings\John Christian\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk [2009/06/15 16:31:44 | 00,001,720 | ---- | M] () -- C:\WINDOWS\System32\tmp.reg [2009/06/15 13:42:29 | 00,981,586 | ---- | M] () -- C:\Documents and Settings\John Christian\My Documents\cc_20090615_134143.reg [2009/06/15 13:37:06 | 00,000,651 | ---- | M] () -- C:\WINDOWS\win.ini [2009/06/15 13:37:06 | 00,000,227 | ---- | M] () -- C:\WINDOWS\SYSTEM.INI [2009/06/15 13:37:06 | 00,000,211 | -HS- | M] () -- C:\boot.ini [2009/06/14 23:02:33 | 01,615,732 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\ProcessExplorer.zip [2009/06/14 19:56:38 | 00,389,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF1521.exe [2009/06/13 19:19:31 | 00,001,407 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\i j j i.lnk [2009/06/12 14:20:54 | 04,613,370 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\heartbeats.mp3 [2009/06/11 04:14:24 | 00,000,803 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Prototype.lnk [2009/06/10 21:23:45 | 00,386,888 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2009/06/08 21:17:32 | 03,099,494 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\boss.bmp [2009/06/08 08:10:10 | 00,155,136 | ---- | M] () -- C:\WINDOWS\PEV.exe [2009/06/05 15:22:40 | 00,001,341 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Huxley Lite.lnk [2009/06/05 04:36:36 | 21,148,51485 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\Huxley_Lite_Setup.zip [2009/06/03 23:48:43 | 00,000,854 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\The Sims 3.lnk [2009/06/03 23:37:54 | 00,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat [2009/06/02 11:17:27 | 00,075,776 | ---- | M] () -- C:\WINDOWS\System32\WS2Fix.exe [2009/06/01 12:51:12 | 23,635,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe [2009/05/31 22:17:35 | 00,015,688 | ---- | M] () -- C:\WINDOWS\System32\lsdelete.exe [2009/05/26 17:31:26 | 00,058,800 | ---- | M] (NHN USA Inc.) -- C:\WINDOWS\System32\ijjiProcessRestarter.exe [2009/05/26 13:20:08 | 00,040,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2009/05/26 13:19:56 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2009/05/25 18:30:24 | 31,796,401 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\169_sc2_cs_pc2_101108_hr.mp4 [2009/05/23 19:44:26 | 00,000,308 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\AA3Deploy.appref-ms [2009/05/21 18:51:48 | 00,041,808 | ---- | M] () -- C:\WINDOWS\System32\xfcodec.dll ========== Alternate Data Streams ========== @Alternate Data Stream - 451 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF @Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34 < End of report > This post has been edited by jaysee: Jun 16 2009, 08:56 PM |
|
|
Jun 16 2009, 08:53 PM
Post
#6
|
|
|
Member ![]() ![]() Posts: 25 OS: XP Pro |
*OTL added
|
|
|
Jun 17 2009, 07:07 AM
Post
#7
|
|
![]() Unofficial Music Guru Posts: 2,354 From: Massachusetts, USA OS: Vista |
Let's give this a try:
Please download GooredFix from one of the locations below and save it to your Desktop
- Dave This post has been edited by Transience: Jun 17 2009, 07:08 AM |
|
|
Jun 17 2009, 12:23 PM
Post
#8
|
|
|
Member ![]() ![]() Posts: 25 OS: XP Pro |
Noticed that when I try to pick a link after a Yahoo.com search, first it gives me a long address with my related search topic, where it starts off with a site like "affiliatesite.com" or "nanna.org", and then it has a "Redirect", finally bringing me to the spam/fake page, like that of Toseeka (which I see is a common page that these take you to). So if I look in the back/forward button arrow tab on Firefox, it goes through something like the following after clicking a link
QUOTE test - Yahoo! Search Results ==> affiliatesite.com/result?blahblahblah ==> Redirect ==> Spam site Here's the Goored log: QUOTE GooredFix v1.92 by jpshortstuff
Log created at 14:22 on 17/06/2009 running Option #1 (John Christian) Firefox version 3.0.11 (en-US) =====Suspect Goored Entries===== =====Dumping Registry Values===== [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.11\extensions] "Plugins"="C:\Program Files\Mozilla Firefox\plugins" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.11\extensions] "Components"="C:\Program Files\Mozilla Firefox\components" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "{1d5287d1-8a92-0001-1f31-1cec198018d8}"="C:\Program Files\AVG\AVG8\ToolbarFF" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG8\Firefox" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "{3414F358-CBBD-4215-8320-ABAECC12AC25}"="C:\Documents and Settings\John Christian\Local Settings\Application Data\{3414F358-CBBD-4215-8320-ABAECC12AC25}\" (Folder Missing) This post has been edited by jaysee: Jun 17 2009, 02:01 PM |
|
|
Jun 18 2009, 08:17 AM
Post
#9
|
|
![]() Unofficial Music Guru Posts: 2,354 From: Massachusetts, USA OS: Vista |
1. OTMoveIt3
Please download the OTMoveIt3 by OldTimer.
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, navigate to the open C:\_OTMoveIt\MovedFiles folder. Open the newest .log file present in notepad and post its contents in your next reply. Just need the logs from OTMI and CF in your next reply. Cheers, Dave |
|
|
Jun 21 2009, 07:15 PM
Post
#10
|
|
|
Member ![]() ![]() Posts: 25 OS: XP Pro |
I can't download OTMoveit3. It gives me a "404 Not Found" error page when I try.
This post has been edited by jaysee: Jun 21 2009, 07:16 PM |
|
|
Jun 22 2009, 08:27 AM
Post
#11
|
|
![]() Unofficial Music Guru Posts: 2,354 From: Massachusetts, USA OS: Vista |
That's my fault, link is outdated, sorry about that. Let's do it this way instead:
1. Registry Fixes We're going to use a registry file to make the some changes to your registry. Please copy the complete contents of the box below to a new notepad file (Start > Programs > Accessories > Notepad). Ensure that the code in notepad looks exactly as it does in the box, with no blank lines before the first line of text. Please click on File > Save. In the Save as type: box click the drop-down menu and change the save as type to All files. Then please save the file to your desktop, naming it fix.reg (this name is important and should not be changed). CODE REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "{3414F358-CBBD-4215-8320-ABAECC12AC25}"=- Then run ComboFix per these instructions: 2. ComboFix Please download and save ComboFix from one of these locations: Link 1 | Link 2 | Link 3 * It is very important that ComboFix is saved directly to your desktop. Notes:
![]() Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: ![]() Click on Yes, to continue scanning for malware. The program will scan for malware and then perform various fixes. You may be asked to reboot, okay the prompt and allow your computer to reboot. Log in as normal and allow ComboFix to complete its run without doing anything else. When it's finished, the program's log will appear in notepad and save itself to C:\ComboFix.txt. Please include the full contents of the log in your next reply. Cheers, Dave |
|
|
Jun 22 2009, 11:42 AM
Post
#12
|
|
|
Member ![]() ![]() Posts: 25 OS: XP Pro |
Okay, cool. I believe this fixed the problem. At least, I just tried a few random searches on Yahoo and none of the links I clicked on redirected me.
Real quick, just a couple things. 1. The unsecapp.exe process. Just out of curiousity, what causes it to start running? I've looked it up, and everyone says it's fine, but I've never had it running in my processes before until fairly recently (although long before this infection, as far as I'm aware). 2. Should I go ahead and change all my passwords to be on the safe side (email, general accounts, etc)? Thanks for all the help thus far! QUOTE ComboFix 09-06-21.01 - John Christian 06/22/2009 13:13.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1546 [GMT -4:00] Running from: c:\documents and settings\John Christian\Desktop\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\Manson c:\temp\1cb c:\windows\Downloaded Program Files\PurpleBean.exe c:\windows\system32\drivers\SKYNETeyabbiyu.sys c:\windows\system32\L5 c:\windows\system32\SKYNETaubodjkl.dll c:\windows\system32\SKYNETtobwwyll.dat c:\windows\system32\SKYNETwsqttomq.dll c:\windows\system32\SKYNETxfuwbimk.dat C:\DBI.EXE C:\Documents c:\documents and settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\c.cgm c:\program files\Manson\liser.dll c:\program files\Manson\liser.exe c:\temp\1cb\syscheck.log c:\windows\patchw32.dll c:\windows\system32\404Fix.exe c:\windows\system32\Agent.OMZ.Fix.exe c:\windows\system32\AutoRun.inf c:\windows\system32\comsa32.sys c:\windows\system32\drivers\SKYNETeyabbiyu.sys c:\windows\system32\dumphive.exe c:\windows\system32\IEDFix.C.exe c:\windows\system32\IEDFix.exe c:\windows\system32\o4Patch.exe c:\windows\system32\Process.exe c:\windows\system32\SKYNETaubodjkl.dll c:\windows\system32\SKYNETtobwwyll.dat c:\windows\system32\SKYNETwsqttomq.dll c:\windows\system32\SKYNETxfuwbimk.dat c:\windows\system32\sopidkc.exe c:\windows\system32\SrchSTS.exe c:\windows\system32\tmp.reg c:\windows\system32\tpsaxyd.exe c:\windows\system32\VACFix.exe c:\windows\system32\VCCLSID.exe c:\windows\system32\wiawow32.sys c:\windows\system32\WS2Fix.exe Infected copy of c:\windows\system32\winlogon.exe was found and disinfected Restored copy from - c:\windows\ServicePackFiles\i386\winlogon.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_SKYNETixjoyqje -------\Legacy_HwIOctl -------\Legacy_Memctl -------\Service_HwIOctl -------\Service_Memctl ((((((((((((((((((((((((( Files Created from 2009-05-22 to 2009-06-22 ))))))))))))))))))))))))))))))) . 2009-06-22 16:08 . 2009-06-22 16:08 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache 2009-06-19 23:58 . 2009-06-19 23:58 -------- d-----w- c:\documents and settings\John Christian\Local Settings\Application Data\GHOSTBUSTERS 2009-06-17 23:28 . 2009-06-17 23:28 -------- d-----w- c:\program files\Common Files\DivX Shared 2009-06-17 23:28 . 2009-06-17 23:28 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Mozilla 2009-06-17 02:18 . 2009-06-17 02:18 -------- d-----w- C:\_OTL 2009-06-15 22:07 . 2009-06-15 22:31 -------- d-----w- C:\Rooter$ 2009-06-15 21:11 . 2009-06-15 21:12 -------- d-----w- c:\program files\ERUNT 2009-06-15 20:40 . 2009-06-15 20:40 -------- d-----w- c:\program files\Trend Micro 2009-06-15 10:02 . 2009-06-15 10:02 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE 2009-06-15 09:54 . 2009-06-15 09:54 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Yahoo! 2009-06-15 09:54 . 2009-06-15 10:02 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\AVGTOOLBAR 2009-06-15 00:42 . 2009-06-15 00:42 -------- d-----w- c:\program files\ESET 2009-06-14 22:12 . 2009-06-14 22:12 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache 2009-06-14 21:07 . 2009-06-14 21:07 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-06-14 21:06 . 2009-06-14 21:06 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee 2009-06-14 21:06 . 2009-06-14 21:06 152576 ----a-w- c:\documents and settings\John Christian\Application Data\Sun\Java\jre1.6.0_14\lzma.dll 2009-06-12 02:26 . 2009-06-12 02:26 -------- d-----w- c:\windows\nview 2009-06-11 22:29 . 2009-06-11 22:29 41808 ----a-w- c:\windows\system32\xfcodec.dll 2009-06-10 07:01 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2009-06-10 07:01 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2009-06-08 02:34 . 2009-06-13 23:19 2114851345 ----a-w- c:\documents and settings\John Christian\Application Data\ijjigame\HuxleyLiteSetup.exe 2009-06-06 01:02 . 2009-06-06 01:02 -------- d-----w- c:\program files\Realtek AC97 2009-06-06 00:59 . 2009-06-06 00:59 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters 2009-06-06 00:58 . 2009-06-06 00:58 -------- d-----w- c:\program files\PC Drivers HeadQuarters 2009-06-05 21:30 . 2009-06-08 23:26 -------- d-----w- c:\documents and settings\John Christian\Application Data\ijjigame 2009-06-05 21:30 . 2009-06-05 21:30 -------- d-----w- C:\ijji 2009-06-05 21:29 . 2009-06-05 21:30 558552 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\PLauncher.exe 2009-06-05 21:29 . 2009-06-03 21:48 779720 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\PurpleBean.exe 2009-06-05 21:29 . 2008-09-04 20:34 112048 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjiPrePLauncher.exe 2009-06-05 21:29 . 2008-08-28 16:50 480688 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjistarter2FxB.exe 2009-06-05 21:29 . 2008-08-28 16:50 83376 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjiPreStarter2FxB.exe 2009-06-05 21:29 . 2008-08-28 16:50 50608 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjiNotify2FxB.exe 2009-06-05 21:29 . 2009-06-05 21:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ijjigame 2009-06-05 21:29 . 2008-08-28 16:50 79280 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjiPreNotify2FxB.exe 2009-06-05 21:06 . 2009-06-05 21:06 -------- d-----w- c:\program files\NHN USA 2009-06-05 21:06 . 2009-05-26 21:31 58800 ----a-w- c:\windows\system32\ijjiProcessRestarter.exe 2009-06-05 21:06 . 2009-05-13 00:48 710064 ----a-w- c:\windows\system32\ijjiSetup.exe 2009-06-05 21:06 . 2008-06-12 03:01 58800 ----a-w- c:\windows\system32\ijjiPlugin2.dll 2009-06-05 21:06 . 2008-04-23 18:02 157152 ----a-w- c:\windows\system32\PubPlugin.dll 2009-06-05 19:22 . 2009-06-13 23:19 -------- d-----w- c:\program files\HuxleyLite 2009-06-04 03:26 . 2009-06-05 01:26 -------- d-----w- c:\documents and settings\All Users\Application Data\MailFrontier 2009-06-04 03:26 . 2009-06-04 03:37 4212 ---ha-w- c:\windows\system32\zllictbl.dat 2009-06-04 03:25 . 2009-06-11 01:23 -------- d-----w- c:\windows\system32\ZoneLabs 2009-06-01 02:17 . 2009-06-01 02:17 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe 2009-06-01 02:17 . 2009-06-01 02:17 83808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll 2009-06-01 02:17 . 2009-06-01 02:17 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll 2009-06-01 02:17 . 2009-06-01 02:17 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll 2009-05-25 02:40 . 2009-05-25 18:11 -------- d-----w- c:\documents and settings\John Christian\Application Data\Games 2009-05-24 02:29 . 2009-05-24 02:29 -------- d-----w- c:\program files\USArmy 2009-05-23 23:44 . 2009-06-11 03:12 -------- d-----w- c:\documents and settings\All Users\Application Data\AA3DeployClient 2009-05-23 23:44 . 2009-06-11 02:07 -------- d-----w- c:\documents and settings\John Christian\Local Settings\Application Data\AA3DeployClient 2009-05-23 23:43 . 2009-06-17 05:54 -------- d-----w- c:\documents and settings\John Christian\Local Settings\Application Data\Deployment . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-22 09:12 . 2008-01-24 03:08 -------- d-----w- c:\documents and settings\John Christian\Application Data\Xfire 2009-06-22 08:53 . 2007-09-12 08:25 -------- d-----w- c:\program files\Steam 2009-06-21 18:01 . 2007-07-29 09:18 -------- d-s---w- c:\program files\Xfire 2009-06-21 06:43 . 2008-12-19 08:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-21 06:42 . 2009-01-05 07:31 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2009-06-20 21:07 . 2007-08-10 14:13 137888 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2009-06-20 21:07 . 2007-08-10 14:10 189288 ----a-w- c:\windows\system32\PnkBstrB.exe 2009-06-19 20:57 . 2007-07-29 09:20 -------- d-----w- c:\program files\Atari 2009-06-19 19:56 . 2007-07-29 03:12 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-06-19 00:12 . 2009-05-14 11:03 117760 ----a-w- c:\documents and settings\John Christian\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-06-18 20:42 . 2008-12-19 08:26 -------- d-----w- c:\program files\SUPERAntiSpyware 2009-06-17 23:29 . 2007-07-29 09:24 -------- d-----w- c:\program files\DivX 2009-06-17 15:27 . 2008-12-19 08:41 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-17 15:27 . 2008-12-19 08:41 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-17 06:10 . 2007-07-29 09:24 -------- d-----w- c:\program files\EA Games 2009-06-17 05:55 . 2008-10-14 23:04 -------- d-----w- c:\documents and settings\All Users\Application Data\America's Army Deploy Client 2009-06-17 02:27 . 2007-07-29 21:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint 2009-06-15 01:47 . 2009-04-25 18:55 -------- d-----w- c:\program files\Diner Dash 2 2009-06-14 23:42 . 2009-03-15 14:33 -------- d-----w- c:\documents and settings\John Christian\Application Data\AVGTOOLBAR 2009-06-14 23:05 . 2007-09-14 22:32 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-06-14 21:06 . 2007-07-29 09:41 -------- d-----w- c:\program files\Java 2009-06-12 02:26 . 2007-08-03 09:19 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-06-07 05:42 . 2007-08-09 05:21 -------- d-----w- c:\documents and settings\John Christian\Application Data\Audacity 2009-06-05 01:48 . 2007-07-29 09:37 -------- d-----w- c:\program files\Electronic Arts 2009-06-01 02:17 . 2009-03-09 02:26 15688 ----a-w- c:\windows\system32\lsdelete.exe 2009-05-25 17:38 . 2007-08-04 22:44 -------- d-----w- c:\documents and settings\John Christian\Application Data\Mozilla2 2009-05-24 23:08 . 2007-11-04 04:58 -------- d-----w- c:\program files\AGEIA Technologies 2009-05-24 02:25 . 2007-07-29 02:50 118288 ----a-w- c:\documents and settings\John Christian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-05-24 02:14 . 2008-08-23 17:44 -------- d-----w- c:\program files\MSBuild 2009-05-24 02:14 . 2008-08-23 17:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-05-19 22:27 . 2009-05-19 22:27 10134 ----a-r- c:\documents and settings\John Christian\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe 2009-05-19 22:27 . 2009-05-19 22:27 -------- d-----w- c:\program files\Microsoft WSE 2009-05-14 10:52 . 2009-03-15 14:33 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8 2009-05-13 05:15 . 2004-08-04 12:00 915456 ----a-w- c:\windows\system32\wininet.dll 2009-05-07 15:32 . 2004-08-04 12:00 345600 ----a-w- c:\windows\system32\localspl.dll 2009-05-02 23:59 . 2009-05-02 23:59 -------- d-----w- c:\program files\NovaLogic 2009-05-02 12:29 . 2009-03-15 14:33 11952 ----a-w- c:\windows\system32\avgrsstx.dll 2009-05-02 12:29 . 2009-03-15 14:33 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2009-05-02 12:29 . 2006-06-27 06:07 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2009-05-02 12:28 . 2009-03-15 14:33 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2009-05-01 21:02 . 2009-05-01 21:02 90112 ----a-w- c:\windows\system32\dpl100.dll 2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx0c.dll 2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx07.dll 2009-05-01 21:02 . 2009-05-01 21:02 815104 ----a-w- c:\windows\system32\divx_xx0a.dll 2009-05-01 21:02 . 2009-05-01 21:02 811008 ----a-w- c:\windows\system32\divx_xx16.dll 2009-05-01 21:02 . 2009-05-01 21:02 802816 ----a-w- c:\windows\system32\divx_xx11.dll 2009-05-01 21:02 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\DivX.dll 2009-05-01 04:30 . 2009-05-01 04:30 1194528 ----a-w- c:\windows\system32\nvcplui.exe 2009-05-01 02:02 . 2009-05-01 02:02 1579630 ----a-w- c:\windows\system32\nvdata.bin 2009-05-01 02:02 . 2007-11-20 02:36 457248 ----a-w- c:\windows\system32\nvudisp.exe 2009-04-27 04:42 . 2007-11-20 02:35 457248 ----a-w- c:\windows\system32\NVUNINST.EXE 2009-04-27 02:17 . 2009-04-27 02:17 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys 2009-04-27 02:17 . 2009-03-09 02:17 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys 2009-04-25 18:56 . 2009-04-21 01:55 -------- d-----w- c:\documents and settings\John Christian\Application Data\PlayFirst 2009-04-25 18:56 . 2009-04-21 01:55 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst 2009-04-25 18:33 . 2009-04-21 01:58 -------- d-----w- c:\program files\Diner Dash 2009-04-22 04:20 . 2009-04-22 04:20 14311680 ----a-w- c:\windows\system32\xlive.dll 2009-04-22 04:20 . 2009-04-22 04:20 13642496 ----a-w- c:\windows\system32\xlivefnt.dll 2009-04-17 12:26 . 2004-08-04 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-04-17 06:29 . 2009-04-17 06:29 1878984 ----a-w- c:\documents and settings\John Christian\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe 2009-04-15 14:51 . 2004-08-04 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll 2009-04-03 16:39 . 2009-04-03 16:39 70936 ----a-w- c:\windows\system32\PhysXLoader.dll 2009-03-28 06:49 . 2009-03-28 06:49 7040776 ----a-w- c:\documents and settings\John Christian\Application Data\MySpace\IM\Install\MSIMClientSetup.1.0.789.0-static-A.exe 2004-05-07 19:31 . 2007-08-03 09:20 348160 ----a-w- c:\program files\mozilla firefox\components\MSVCR71.DLL 2006-11-07 16:58 . 2007-08-03 09:20 139264 ----a-w- c:\program files\mozilla firefox\components\SABFF20.DLL 2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll . ------- Sigcheck ------- [7] 2004-08-04 12:00 295424 B60C877D16D9C880B952FDA04ADF16E6 c:\windows\$NtServicePackUninstall$\termsrv.dll [7] 2008-04-14 00:12 295424 FF3477C03BE7201C294C35F684B3479F c:\windows\ServicePackFiles\i386\termsrv.dll [-] 2009-03-14 07:15 295424 63999D0ABD8DABFD76A9C07F6E104868 c:\windows\system32\termsrv.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 81920] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-22 518488] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-02 1947928] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016] "RivaTunerStartupDaemon"="d:\program files\RivaTuner v2.08\RivaTuner.exe" [2008-03-10 2691072] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-27 1657376] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968] c:\documents and settings\John Christian\Start Menu\Programs\Startup\ ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000D7}"= "c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABSEHB.DLL" [2006-11-07 77824] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SABWinLogon] 2007-05-14 17:20 176128 ----a-w- c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-31 09:06 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-05-02 12:29 11952 ----a-w- c:\windows\system32\avgrsstx.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AT&T Self Support Tool.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AT&T Self Support Tool.lnk backup=c:\windows\pss\AT&T Self Support Tool.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ExifLauncher2.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ExifLauncher2.lnk backup=c:\windows\pss\ExifLauncher2.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^John Christian^Start Menu^Programs^Startup^Adobe Gamma.lnk] path=c:\documents and settings\John Christian\Start Menu\Programs\Startup\Adobe Gamma.lnk backup=c:\windows\pss\Adobe Gamma.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^John Christian^Start Menu^Programs^Startup^Aquarius Soft PC Alarm Clock Pro.lnk] path=c:\documents and settings\John Christian\Start Menu\Programs\Startup\Aquarius Soft PC Alarm Clock Pro.lnk backup=c:\windows\pss\Aquarius Soft PC Alarm Clock Pro.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^John Christian^Start Menu^Programs^Startup^reminder-ScanSoft Product Registration.lnk] path=c:\documents and settings\John Christian\Start Menu\Programs\Startup\reminder-ScanSoft Product Registration.lnk backup=c:\windows\pss\reminder-ScanSoft Product Registration.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^John Christian^Start Menu^Programs^Startup^Sins of a Solar Empire Launcher.lnk] path=c:\documents and settings\John Christian\Start Menu\Programs\Startup\Sins of a Solar Empire Launcher.lnk backup=c:\windows\pss\Sins of a Solar Empire Launcher.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "hpqcxs08"=3 (0x3) "HPSLPSVC"=2 (0x2) "hpqddsvc"=2 (0x2) "ZuneWlanCfgSvc"=3 (0x3) "ZuneNetworkSvc"=2 (0x2) "ZuneBusEnum"=2 (0x2) [HKEY_LOCAL_MACHINE\software\microsoft\security center] "FirewallOverride"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "d:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Program Files\\Xfire\\xfire.exe"= "c:\\Program Files\\Steam\\steam.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "d:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"= "d:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "d:\\Program Files\\EA Games\\Mirror's Edge\\Binaries\\MirrorsEdge.exe"= "%windir%\\system32\\drivers\\svchost.exe"= "c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"= "c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"= "c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"= "c:\\Program Files\\AIM\\aim.exe"= "c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"= "c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"= "c:\\Program Files\\USArmy\\America's Army 3\\Binaries\\AA3Game.exe"= "c:\\Program Files\\HuxleyLite\\binaries\\HuxleyMMOGame.exe"= "d:\\Program Files\\Activision\\Prototype\\prototypef.exe"= "d:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"= "c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"= "c:\\Program Files\\Steam\\steamapps\\common\\america's army 3\\Binaries\\AA3Game.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "57909:TCP"= 57909:TCP:*:Disabled:Pando Media Booster "57909:UDP"= 57909:UDP:*:Disabled:Pando Media Booster R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/8/2009 10:17 PM 64160] R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [7/29/2007 3:34 AM 16896] R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [7/29/2007 3:34 AM 52224] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/15/2009 10:33 AM 325896] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/15/2009 10:33 AM 108552] R1 SABKUTIL;SABKUTIL;c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.SYS [2/20/2007 4:02 PM 32256] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12/4/2008 2:50 PM 8944] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/4/2008 2:50 PM 55024] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/15/2009 10:33 AM 298776] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 5:34 PM 1003344] R2 ppsio2;PPDevice;c:\windows\system32\drivers\ppsio2.sys [8/27/2007 7:31 PM 23200] R2 WMDrive;WMDrive;c:\windows\system32\drivers\WMDrive.sys [2/17/2009 3:13 PM 37376] S1 SABDIFSV;SABDIFSV;c:\program files\SuperAdBlocker.com\Super Ad Blocker\sabdifsv.sys [9/21/2005 11:17 AM 5632] S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/4/2008 2:50 PM 7408] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc HPService REG_MULTI_SZ HPSLPSVC [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-06-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 02:17] . - - - - ORPHANS REMOVED - - - - SafeBoot-Winlj13.sys SafeBoot-Winly67.sys SafeBoot-Winnn86.sys . ------- Supplementary Scan ------- . uStart Page = about:blank uInternet Settings,ProxyOverride = 127.0.0.1 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab FF - ProfilePath - . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-22 13:27 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet003\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-1547161642-152049171-1801674531-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:ec,46,bd,6d,c1,8a,a5,c5,3c,4d,bc,4f,7a,44,7e,ef,18,4d,c4,35,46,87,95, 05,56,d3,65,78,e2,22,6d,e2,bb,c0,9a,58,b5,86,dd,0c,82,19,c3,28,8b,56,e9,81,\ "??"=hex:80,40,06,d0,8e,ad,37,15,76,13,ef,74,08,8e,27,0f [HKEY_USERS\S-1-5-21-1547161642-152049171-1801674531-1003\Software\SecuROM\License information*] "datasecu"=hex:d7,cc,7d,6b,10,af,f5,7a,0e,82,a7,31,be,ca,81,d5,24,4f,46,37,ff, 58,66,af,9a,0c,87,a2,14,99,e2,a2,56,28,69,4a,e3,08,87,d1,f0,6a,67,03,9b,57,\ "rkeysecu"=hex:ce,13,31,c2,44,4f,e5,b0,9b,27,0f,62,37,7a,e0,d3 [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ř•€|˙˙˙˙•€|ů•A~*] "5E7CEC10DF0760D4F8DAFB12FDC06CCD"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{01CEC7E5-70FD-4D06-8FAD-BF21DF0CC6DC}\\Registered" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL] @DACL=(02 0000) "Installed"="1" @="" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI] @DACL=(02 0000) "NoChange"="1" "Installed"="1" @="" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS] @DACL=(02 0000) "Installed"="1" @="" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(820) c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL c:\program files\SUPERAntiSpyware\SASWINLO.DLL c:\windows\system32\WININET.dll - - - - - - - > 'explorer.exe'(5716) c:\windows\system32\WININET.dll c:\program files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\NVIDIA Corporation\nTune\nTuneService.exe c:\program files\AVG\AVG8\avgrsx.exe c:\windows\system32\nvsvc32.exe c:\progra~1\AVG\AVG8\avgnsx.exe c:\windows\system32\PnkBstrA.exe c:\windows\system32\PnkBstrB.exe c:\program files\TVersity\Media Server\MediaServer.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\windows\system32\wbem\unsecapp.exe c:\windows\system32\wscntfy.exe c:\windows\system32\rundll32.exe . ************************************************************************** . Completion time: 2009-06-22 13:32 - machine was rebooted ComboFix-quarantined-files.txt 2009-06-22 17:32 Pre-Run: 8,724,213,760 bytes free Post-Run: 8,830,857,216 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect Current=3 Default=3 Failed=2 LastKnownGood=5 Sets=1,2,3,4,5 415 --- E O F --- 2009-06-11 01:21 This post has been edited by jaysee: Jun 22 2009, 11:52 AM |
|
|
Jun 23 2009, 04:49 AM
Post
#13
|
|
![]() Unofficial Music Guru Posts: 2,354 From: Massachusetts, USA OS: Vista |
Glad the redirects are gone
QUOTE 1. The unsecapp.exe process. Just out of curiousity, what causes it to start running? I've looked it up, and everyone says it's fine, but I've never had it running in my processes before until fairly recently (although long before this infection, as far as I'm aware). It's hard to say, it's a windows process, most likely one that wasn't used before but now one of your program needs it. QUOTE 2. Should I go ahead and change all my passwords to be on the safe side (email, general accounts, etc)? That's a good safety measure to take, but it's best to wait until we're positive you're clean (almost there Please go to Add/Remove Programs in your Control Panel (Programs and Features if you are a Vista user). Select and remove the following if present, don't worry if they aren't: Viewpoint Media Player (and anything else that says "Viewpoint") - Viewpoint is an annoying media player that installs alongside many different things without your permission, not a good idea to keep it on your computer. One last script to get a couple minor things: 1. Run a ComboFix script
CODE KillAll:: Folder:: c:\windows\system32\config\systemprofile\PrivacIE FCOPY:: c:\windows\ServicePackFiles\i386\termsrv.dll | c:\windows\system32\termsrv.dll Extra:: SysRst:: Note: If you are not the topic starter, DO NOT download or run this script as it could cause irreversible damage to your computer. Please note that the same procedure applies to running ComboFix this time as before - disable your protection programs beforehand, close all other programs, don't interrupt it for any reason etc. ![]() Once the script is saved, refering to the picture above, drag CFScript.txt into ComboFix.exe. This will cause ComboFix to start again. Allow it to complete running, following any prompts. Once the program has completed the log should appear automatically, if it doesn't it can be found at C:\ComboFix.txt. Please post the contents of that log in your next reply. This post has been edited by Transience: Jun 23 2009, 04:52 AM |
|
|
Jun 23 2009, 12:56 PM
Post
#14
|
|
|
Member ![]() ![]() Posts: 25 OS: XP Pro |
Went ahead and did the ComboFix, posted below. Worth mentioning, though, that last night I ended up getting a redirected page (I believe, unless it's some feature of FireFox3 I don't know about). Yahoo remains fine, and pages don't take me elsewhere, but when I was visiting just a regular site at one point, it redirected me to a page saying that it was blocked, and to "Click here to find out why". As soon as I went back and tried again, it worked as normal.
I ran a full scan with Malwarebytes while I slept and it found six or seven .dll and .exe, "Trojan / Downloaders", which I removed and then restarted my computer. Unfortunately I didn't save the report. So all that happened before I did the ComboFix here today. Then, after I was done doing this second ComboFix run, AVG on it's own picked up the following (disguised as a svchost.exe process), which I removed: ![]() Lastly, ever since I did the first ComboFix, I don't know if it's just a coincidence, but my internet has been very slow at times, most noticeable when loading videos or pictures. QUOTE ComboFix 09-06-22.0E - John Christian 06/23/2009 14:34.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1561 [GMT -4:00] Running from: c:\documents and settings\John Christian\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\John Christian\Desktop\CFScript.txt AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\config\systemprofile\PrivacIE c:\windows\system32\config\systemprofile\PrivacIE\index.dat . --------------- FCopy --------------- c:\windows\ServicePackFiles\i386\termsrv.dll --> c:\windows\system32\termsrv.dll . ((((((((((((((((((((((((( Files Created from 2009-05-23 to 2009-06-23 ))))))))))))))))))))))))))))))) . 2009-06-22 16:08 . 2009-06-22 16:08 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache 2009-06-19 23:58 . 2009-06-19 23:58 -------- d-----w- c:\documents and settings\John Christian\Local Settings\Application Data\GHOSTBUSTERS 2009-06-17 23:28 . 2009-06-17 23:28 -------- d-----w- c:\program files\Common Files\DivX Shared 2009-06-17 23:28 . 2009-06-17 23:28 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Mozilla 2009-06-17 02:18 . 2009-06-17 02:18 -------- d-----w- C:\_OTL 2009-06-15 22:07 . 2009-06-15 22:31 -------- d-----w- C:\Rooter$ 2009-06-15 21:11 . 2009-06-15 21:12 -------- d-----w- c:\program files\ERUNT 2009-06-15 20:40 . 2009-06-15 20:40 -------- d-----w- c:\program files\Trend Micro 2009-06-15 09:54 . 2009-06-15 09:54 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Yahoo! 2009-06-15 09:54 . 2009-06-15 10:02 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\AVGTOOLBAR 2009-06-15 00:42 . 2009-06-15 00:42 -------- d-----w- c:\program files\ESET 2009-06-14 22:12 . 2009-06-14 22:12 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache 2009-06-14 21:07 . 2009-06-14 21:07 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-06-14 21:06 . 2009-06-14 21:06 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee 2009-06-14 21:06 . 2009-06-14 21:06 152576 ----a-w- c:\documents and settings\John Christian\Application Data\Sun\Java\jre1.6.0_14\lzma.dll 2009-06-12 02:26 . 2009-06-12 02:26 -------- d-----w- c:\windows\nview 2009-06-11 22:29 . 2009-06-11 22:29 41808 ----a-w- c:\windows\system32\xfcodec.dll 2009-06-10 07:01 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2009-06-10 07:01 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2009-06-08 02:34 . 2009-06-13 23:19 2114851345 ----a-w- c:\documents and settings\John Christian\Application Data\ijjigame\HuxleyLiteSetup.exe 2009-06-06 01:02 . 2009-06-06 01:02 -------- d-----w- c:\program files\Realtek AC97 2009-06-06 00:59 . 2009-06-06 00:59 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters 2009-06-06 00:58 . 2009-06-06 00:58 -------- d-----w- c:\program files\PC Drivers HeadQuarters 2009-06-05 21:30 . 2009-06-08 23:26 -------- d-----w- c:\documents and settings\John Christian\Application Data\ijjigame 2009-06-05 21:30 . 2009-06-05 21:30 -------- d-----w- C:\ijji 2009-06-05 21:29 . 2009-06-05 21:30 558552 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\PLauncher.exe 2009-06-05 21:29 . 2009-06-03 21:48 779720 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\PurpleBean.exe 2009-06-05 21:29 . 2008-09-04 20:34 112048 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjiPrePLauncher.exe 2009-06-05 21:29 . 2008-08-28 16:50 480688 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjistarter2FxB.exe 2009-06-05 21:29 . 2008-08-28 16:50 83376 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjiPreStarter2FxB.exe 2009-06-05 21:29 . 2008-08-28 16:50 50608 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjiNotify2FxB.exe 2009-06-05 21:29 . 2009-06-05 21:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ijjigame 2009-06-05 21:29 . 2008-08-28 16:50 79280 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjiPreNotify2FxB.exe 2009-06-05 21:06 . 2009-06-05 21:06 -------- d-----w- c:\program files\NHN USA 2009-06-05 21:06 . 2009-05-26 21:31 58800 ----a-w- c:\windows\system32\ijjiProcessRestarter.exe 2009-06-05 21:06 . 2009-05-13 00:48 710064 ----a-w- c:\windows\system32\ijjiSetup.exe 2009-06-05 21:06 . 2008-06-12 03:01 58800 ----a-w- c:\windows\system32\ijjiPlugin2.dll 2009-06-05 21:06 . 2008-04-23 18:02 157152 ----a-w- c:\windows\system32\PubPlugin.dll 2009-06-05 19:22 . 2009-06-13 23:19 -------- d-----w- c:\program files\HuxleyLite 2009-06-04 03:26 . 2009-06-05 01:26 -------- d-----w- c:\documents and settings\All Users\Application Data\MailFrontier 2009-06-04 03:26 . 2009-06-04 03:37 4212 ---ha-w- c:\windows\system32\zllictbl.dat 2009-06-04 03:25 . 2009-06-11 01:23 -------- d-----w- c:\windows\system32\ZoneLabs 2009-06-01 02:17 . 2009-06-01 02:17 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe 2009-06-01 02:17 . 2009-06-01 02:17 83808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll 2009-06-01 02:17 . 2009-06-01 02:17 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll 2009-06-01 02:17 . 2009-06-01 02:17 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll 2009-05-25 02:40 . 2009-05-25 18:11 -------- d-----w- c:\documents and settings\John Christian\Application Data\Games . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-23 08:32 . 2008-01-24 03:08 -------- d-----w- c:\documents and settings\John Christian\Application Data\Xfire 2009-06-23 08:25 . 2007-09-12 08:25 -------- d-----w- c:\program files\Steam 2009-06-22 21:50 . 2007-09-14 22:32 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-06-21 18:01 . 2007-07-29 09:18 -------- d-s---w- c:\program files\Xfire 2009-06-21 06:43 . 2008-12-19 08:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-21 06:42 . 2009-01-05 07:31 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2009-06-20 21:07 . 2007-08-10 14:13 137888 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2009-06-20 21:07 . 2007-08-10 14:10 189288 ----a-w- c:\windows\system32\PnkBstrB.exe 2009-06-19 20:57 . 2007-07-29 09:20 -------- d-----w- c:\program files\Atari 2009-06-19 19:56 . 2007-07-29 03:12 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-06-19 00:12 . 2009-05-14 11:03 117760 ----a-w- c:\documents and settings\John Christian\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-06-18 20:42 . 2008-12-19 08:26 -------- d-----w- c:\program files\SUPERAntiSpyware 2009-06-17 23:29 . 2007-07-29 09:24 -------- d-----w- c:\program files\DivX 2009-06-17 15:27 . 2008-12-19 08:41 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-17 15:27 . 2008-12-19 08:41 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-17 06:10 . 2007-07-29 09:24 -------- d-----w- c:\program files\EA Games 2009-06-17 05:55 . 2008-10-14 23:04 -------- d-----w- c:\documents and settings\All Users\Application Data\America's Army Deploy Client 2009-06-17 02:27 . 2007-07-29 21:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint 2009-06-15 01:47 . 2009-04-25 18:55 -------- d-----w- c:\program files\Diner Dash 2 2009-06-14 23:42 . 2009-03-15 14:33 -------- d-----w- c:\documents and settings\John Christian\Application Data\AVGTOOLBAR 2009-06-14 21:06 . 2007-07-29 09:41 -------- d-----w- c:\program files\Java 2009-06-12 02:26 . 2007-08-03 09:19 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-06-11 03:12 . 2009-05-23 23:44 -------- d-----w- c:\documents and settings\All Users\Application Data\AA3DeployClient 2009-06-07 05:42 . 2007-08-09 05:21 -------- d-----w- c:\documents and settings\John Christian\Application Data\Audacity 2009-06-05 01:48 . 2007-07-29 09:37 -------- d-----w- c:\program files\Electronic Arts 2009-06-01 02:17 . 2009-03-09 02:26 15688 ----a-w- c:\windows\system32\lsdelete.exe 2009-05-25 17:38 . 2007-08-04 22:44 -------- d-----w- c:\documents and settings\John Christian\Application Data\Mozilla2 2009-05-24 23:08 . 2007-11-04 04:58 -------- d-----w- c:\program files\AGEIA Technologies 2009-05-24 02:29 . 2009-05-24 02:29 -------- d-----w- c:\program files\USArmy 2009-05-24 02:25 . 2007-07-29 02:50 118288 ----a-w- c:\documents and settings\John Christian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-05-24 02:14 . 2008-08-23 17:44 -------- d-----w- c:\program files\MSBuild 2009-05-24 02:14 . 2008-08-23 17:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-05-19 22:27 . 2009-05-19 22:27 10134 ----a-r- c:\documents and settings\John Christian\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe 2009-05-19 22:27 . 2009-05-19 22:27 -------- d-----w- c:\program files\Microsoft WSE 2009-05-14 10:52 . 2009-03-15 14:33 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8 2009-05-13 05:15 . 2004-08-04 12:00 915456 ----a-w- c:\windows\system32\wininet.dll 2009-05-07 15:32 . 2004-08-04 12:00 345600 ----a-w- c:\windows\system32\localspl.dll 2009-05-02 23:59 . 2009-05-02 23:59 -------- d-----w- c:\program files\NovaLogic 2009-05-02 12:29 . 2009-03-15 14:33 11952 ----a-w- c:\windows\system32\avgrsstx.dll 2009-05-02 12:29 . 2009-03-15 14:33 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2009-05-02 12:29 . 2006-06-27 06:07 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2009-05-02 12:28 . 2009-03-15 14:33 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2009-05-01 21:02 . 2009-05-01 21:02 90112 ----a-w- c:\windows\system32\dpl100.dll 2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx0c.dll 2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx07.dll 2009-05-01 21:02 . 2009-05-01 21:02 815104 ----a-w- c:\windows\system32\divx_xx0a.dll 2009-05-01 21:02 . 2009-05-01 21:02 811008 ----a-w- c:\windows\system32\divx_xx16.dll 2009-05-01 21:02 . 2009-05-01 21:02 802816 ----a-w- c:\windows\system32\divx_xx11.dll 2009-05-01 21:02 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\DivX.dll 2009-05-01 04:30 . 2009-05-01 04:30 1194528 ----a-w- c:\windows\system32\nvcplui.exe 2009-05-01 02:02 . 2009-05-01 02:02 1579630 ----a-w- c:\windows\system32\nvdata.bin 2009-05-01 02:02 . 2007-11-20 02:36 457248 ----a-w- c:\windows\system32\nvudisp.exe 2009-04-27 04:42 . 2007-11-20 02:35 457248 ----a-w- c:\windows\system32\NVUNINST.EXE 2009-04-27 02:17 . 2009-04-27 02:17 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys 2009-04-27 02:17 . 2009-03-09 02:17 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys 2009-04-25 18:56 . 2009-04-21 01:55 -------- d-----w- c:\documents and settings\John Christian\Application Data\PlayFirst 2009-04-25 18:56 . 2009-04-21 01:55 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst 2009-04-25 18:33 . 2009-04-21 01:58 -------- d-----w- c:\program files\Diner Dash 2009-04-22 04:20 . 2009-04-22 04:20 14311680 ----a-w- c:\windows\system32\xlive.dll 2009-04-22 04:20 . 2009-04-22 04:20 13642496 ----a-w- c:\windows\system32\xlivefnt.dll 2009-04-17 12:26 . 2004-08-04 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-04-17 06:29 . 2009-04-17 06:29 1878984 ----a-w- c:\documents and settings\John Christian\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe 2009-04-15 14:51 . 2004-08-04 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll 2009-04-03 16:39 . 2009-04-03 16:39 70936 ----a-w- c:\windows\system32\PhysXLoader.dll 2009-03-28 06:49 . 2009-03-28 06:49 7040776 ----a-w- c:\documents and settings\John Christian\Application Data\MySpace\IM\Install\MSIMClientSetup.1.0.789.0-static-A.exe 2004-05-07 19:31 . 2007-08-03 09:20 348160 ----a-w- c:\program files\mozilla firefox\components\MSVCR71.DLL 2006-11-07 16:58 . 2007-08-03 09:20 139264 ----a-w- c:\program files\mozilla firefox\components\SABFF20.DLL 2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll . ((((((((((((((((((((((((((((( SnapShot@2009-06-22_17.28.05 ))))))))))))))))))))))))))))))))))))))))) . + 2009-06-23 18:44 . 2009-06-23 18:44 16384 c:\windows\temp\Perflib_Perfdata_794.dat + 2009-06-23 18:44 . 2009-06-23 18:44 16384 c:\windows\temp\Perflib_Perfdata_108.dat + 2007-07-29 01:35 . 2008-04-14 00:12 295424 c:\windows\system32\dllcache\termsrv.dll + 2009-06-23 18:18 . 2009-06-23 18:18 360448 c:\windows\ERDNT\AutoBackup\6-23-2009\Users\00000002\UsrClass.dat + 2009-06-23 18:18 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\6-23-2009\ERDNT.EXE + 2009-06-23 18:18 . 2009-06-23 18:18 19324928 c:\windows\ERDNT\AutoBackup\6-23-2009\Users\00000001\ntuser.dat . ((((((((((((((((((((((((((((((((((((((( System Restore ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\32788r22fwjfw\pv.exe 03/02/2006 11:42 PM 73728 \RP639\A0137685.exe 03/02/2006 11:42 PM 73728 \RP639\A0137686.exe C:\DBI.EXE 12/29/2004 01:57 AM 17505 \RP638\A0137444.EXE 04/13/2008 08:12 PM 26624 c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll 04/13/2008 08:12 PM 26624 \RP634\A0136276.dll 04/13/2008 08:12 PM 26624 \RP639\A0137777.dll c:\program files\Manson\liser.dll 06/22/2009 12:11 PM 24576 \RP638\A0137424.dll c:\program files\Manson\liser.exe 06/22/2009 12:11 PM 61440 \RP638\A0137425.exe 06/12/2009 12:16 AM 17400 c:\program files\Mozilla Firefox\AccessibleMarshal.dll 05/11/2009 10:01 PM 17400 \RP634\A0136371.dll 06/12/2009 12:16 AM 23032 c:\program files\Mozilla Firefox\components\browserdirprovider.dll 05/11/2009 10:01 PM 23032 \RP634\A0136373.dll 06/12/2009 12:16 AM 134648 c:\program files\Mozilla Firefox\components\brwsrcmp.dll 05/11/2009 10:01 PM 134648 \RP634\A0136374.dll 06/12/2009 12:16 AM 185848 c:\program files\Mozilla Firefox\crashreporter.exe 05/11/2009 10:01 PM 185848 \RP634\A0136375.exe 06/12/2009 12:16 AM 307704 c:\program files\Mozilla Firefox\firefox.exe 05/11/2009 10:01 PM 307704 \RP634\A0136376.exe 06/12/2009 12:16 AM 233472 c:\program files\Mozilla Firefox\freebl3.dll 05/11/2009 10:01 PM 233472 \RP634\A0136377.dll 06/12/2009 12:16 AM 694056 c:\program files\Mozilla Firefox\js3250.dll 05/11/2009 10:01 PM 697336 \RP634\A0136378.dll 06/12/2009 12:16 AM 710136 c:\program files\Mozilla Firefox\mozcrt19.dll 05/11/2009 10:01 PM 710136 \RP634\A0136379.dll 06/12/2009 12:16 AM 198136 c:\program files\Mozilla Firefox\nspr4.dll 05/11/2009 10:01 PM 198136 \RP634\A0136380.dll 06/12/2009 12:16 AM 718328 c:\program files\Mozilla Firefox\nss3.dll 05/11/2009 10:01 PM 718328 \RP634\A0136381.dll 06/12/2009 12:16 AM 292344 c:\program files\Mozilla Firefox\nssckbi.dll 05/11/2009 10:01 PM 292344 \RP634\A0136382.dll 06/12/2009 12:16 AM 103928 c:\program files\Mozilla Firefox\nssdbm3.dll 05/11/2009 10:01 PM 103928 \RP634\A0136383.dll 06/12/2009 12:16 AM 87544 c:\program files\Mozilla Firefox\nssutil3.dll 05/11/2009 10:01 PM 87544 \RP634\A0136384.dll 06/12/2009 12:16 AM 20472 c:\program files\Mozilla Firefox\plc4.dll 05/11/2009 10:01 PM 20472 \RP634\A0136386.dll 06/12/2009 12:16 AM 17400 c:\program files\Mozilla Firefox\plds4.dll 05/11/2009 10:01 PM 17400 \RP634\A0136387.dll 06/12/2009 12:16 AM 65528 c:\program files\Mozilla Firefox\plugins\npnul32.dll 05/11/2009 10:01 PM 65528 \RP634\A0136388.dll 06/12/2009 12:16 AM 103928 c:\program files\Mozilla Firefox\smime3.dll 05/11/2009 10:01 PM 103928 \RP634\A0136389.dll 06/12/2009 12:16 AM 151552 c:\program files\Mozilla Firefox\softokn3.dll 05/11/2009 10:01 PM 151552 \RP634\A0136390.dll 06/12/2009 12:16 AM 435704 c:\program files\Mozilla Firefox\sqlite3.dll 05/11/2009 10:01 PM 395768 \RP634\A0136391.dll 06/12/2009 12:16 AM 136696 c:\program files\Mozilla Firefox\ssl3.dll 05/11/2009 10:01 PM 136696 \RP634\A0136392.dll 06/12/2009 12:16 AM 509544 c:\program files\Mozilla Firefox\uninstall\helper.exe 05/11/2009 10:01 PM 509544 \RP634\A0136393.exe 06/12/2009 12:16 AM 242168 c:\program files\Mozilla Firefox\updater.exe 05/11/2009 10:01 PM 242168 \RP634\A0136394.exe 06/12/2009 12:16 AM 17912 c:\program files\Mozilla Firefox\xpcom.dll 05/11/2009 10:01 PM 17912 \RP634\A0136395.dll 06/12/2009 12:16 AM 9777144 c:\program files\Mozilla Firefox\xul.dll 05/11/2009 10:01 PM 9756664 \RP634\A0136396.dll 06/23/2009 01:32 AM 206072 c:\program files\Steam\bin\FileSystem_Steam.dll 06/15/2009 09:03 PM 206072 \RP639\A0137590.dll 06/23/2009 01:32 AM 1336568 c:\program files\Steam\bin\friendsUI.dll 06/15/2009 09:03 PM 1340664 \RP639\A0137591.dll 06/23/2009 01:32 AM 546040 c:\program files\Steam\bin\mss32_s.dll 06/15/2009 09:03 PM 546040 \RP639\A0137592.dll 06/23/2009 01:32 AM 185592 c:\program files\Steam\bin\nattypeprobe.dll 06/15/2009 09:03 PM 185592 \RP639\A0137593.dll 06/23/2009 01:32 AM 2069752 c:\program files\Steam\bin\p2pcore.dll 06/15/2009 09:03 PM 2069752 \RP639\A0137594.dll 06/23/2009 01:32 AM 1213688 c:\program files\Steam\bin\p2pvoice.dll 06/15/2009 09:03 PM 1213688 \RP639\A0137595.dll 06/23/2009 01:32 AM 980216 c:\program files\Steam\bin\ServerBrowser.dll 06/15/2009 09:03 PM 980216 \RP639\A0137596.dll 06/23/2009 01:32 AM 711152 c:\program files\Steam\bin\SteamService.dll 06/15/2009 09:03 PM 711152 \RP639\A0137597.dll 06/23/2009 01:32 AM 316664 c:\program files\Steam\bin\SteamService.exe 06/15/2009 09:03 PM 316664 \RP639\A0137598.exe 06/23/2009 01:32 AM 201976 c:\program files\Steam\bin\vaudio_speex.dll 06/15/2009 09:03 PM 201976 \RP639\A0137599.dll 06/23/2009 01:32 AM 455928 c:\program files\Steam\bin\vgui2.dll 06/15/2009 09:03 PM 455928 \RP639\A0137600.dll 06/23/2009 01:32 AM 122864 c:\program files\Steam\CSERHelper.dll 06/15/2009 09:03 PM 122864 \RP639\A0137605.dll 06/23/2009 01:32 AM 1039192 c:\program files\Steam\dbghelp.dll 06/15/2009 09:03 PM 1039192 \RP639\A0137588.dll 06/23/2009 01:32 AM 242936 c:\program files\Steam\GameOverlayRenderer.dll 06/15/2009 09:03 PM 242936 \RP639\A0137609.dll 06/23/2009 01:32 AM 1082616 c:\program files\Steam\GameOverlayUI.exe 06/15/2009 09:03 PM 1078520 \RP639\A0137610.exe 06/23/2009 01:32 AM 551408 c:\program files\Steam\mss32_s.dll 06/15/2009 09:03 PM 551408 \RP639\A0137611.dll 06/23/2009 01:32 AM 2884856 c:\program files\Steam\Steam.dll 06/15/2009 09:03 PM 2884856 \RP639\A0137589.dll 06/23/2009 01:32 AM 3335416 c:\program files\Steam\steamclient.dll 06/15/2009 09:03 PM 3336688 \RP639\A0137606.dll 06/23/2009 01:32 AM 3093752 c:\program files\Steam\SteamUI.dll 06/15/2009 09:03 PM 3089656 \RP639\A0137587.dll 06/23/2009 01:32 AM 275704 c:\program files\Steam\tier0_s.dll 06/15/2009 09:03 PM 275704 \RP639\A0137607.dll 06/23/2009 01:32 AM 386296 c:\program files\Steam\vstdlib_s.dll 06/15/2009 09:03 PM 386296 \RP639\A0137608.dll 06/23/2009 01:32 AM 256496 c:\program files\Steam\WriteMiniDump.exe 06/15/2009 09:03 PM 256496 \RP639\A0137586.exe c:\windows\LastGood.Tmp\system32\D3DCompiler_33.dll 03/12/2007 05:42 PM 1123696 \RP634\A0136278.dll c:\windows\LastGood.Tmp\system32\D3DCompiler_34.dll 05/16/2007 05:45 PM 1124720 \RP634\A0136279.dll c:\windows\LastGood.Tmp\system32\D3DCompiler_35.dll 07/19/2007 07:14 PM 1358192 \RP634\A0136280.dll c:\windows\LastGood.Tmp\system32\D3DCompiler_36.dll 10/12/2007 04:14 PM 1374232 \RP634\A0136281.dll c:\windows\LastGood.Tmp\system32\D3DCompiler_37.dll 03/05/2008 04:56 PM 1420824 \RP634\A0136282.dll c:\windows\LastGood.Tmp\system32\D3DCompiler_38.dll 05/30/2008 03:11 PM 1491992 \RP634\A0136283.dll c:\windows\LastGood.Tmp\system32\D3DCompiler_39.dll 07/10/2008 12:00 PM 1493528 \RP634\A0136284.dll c:\windows\LastGood.Tmp\system32\D3DCompiler_40.dll 10/10/2008 05:52 AM 2036576 \RP634\A0136285.dll c:\windows\LastGood.Tmp\system32\d3dx10_33.dll 03/15/2007 05:57 PM 443752 \RP634\A0136286.dll c:\windows\LastGood.Tmp\system32\d3dx10_34.dll 05/16/2007 05:45 PM 443752 \RP634\A0136287.dll c:\windows\LastGood.Tmp\system32\d3dx10_35.dll 07/19/2007 07:14 PM 444776 \RP634\A0136288.dll c:\windows\LastGood.Tmp\system32\d3dx10_36.dll 10/02/2007 10:56 AM 444776 \RP634\A0136289.dll c:\windows\LastGood.Tmp\system32\d3dx10_37.dll 02/06/2008 12:07 AM 462864 \RP634\A0136290.dll c:\windows\LastGood.Tmp\system32\d3dx10_38.dll 05/30/2008 03:11 PM 467984 \RP634\A0136291.dll c:\windows\LastGood.Tmp\system32\d3dx10_39.dll 07/10/2008 12:01 PM 467984 \RP634\A0136292.dll c:\windows\LastGood.Tmp\system32\d3dx10_40.dll 10/10/2008 05:52 AM 452440 \RP634\A0136293.dll c:\windows\LastGood.Tmp\system32\d3dx9_24.dll 02/05/2005 08:45 PM 2222800 \RP634\A0136294.dll c:\windows\LastGood.Tmp\system32\d3dx9_25.dll 03/18/2005 06:19 PM 2337488 \RP634\A0136296.dll c:\windows\LastGood.Tmp\system32\d3dx9_26.dll 05/26/2005 04:34 PM 2297552 \RP634\A0136297.dll c:\windows\LastGood.Tmp\system32\d3dx9_27.dll 07/22/2005 08:59 PM 2319568 \RP634\A0136298.dll c:\windows\LastGood.Tmp\system32\d3dx9_28.dll 12/05/2005 07:09 PM 2323664 \RP634\A0136299.dll c:\windows\LastGood.Tmp\system32\d3dx9_29.dll 02/03/2006 09:43 AM 2332368 \RP634\A0136300.dll c:\windows\LastGood.Tmp\system32\d3dx9_30.dll 03/31/2006 01:40 PM 2388176 \RP634\A0136301.dll c:\windows\LastGood.Tmp\system32\d3dx9_31.dll 09/28/2006 05:05 PM 2414360 \RP634\A0136302.dll c:\windows\LastGood.Tmp\system32\d3dx9_32.dll 11/29/2006 02:06 PM 3426072 \RP634\A0136303.dll c:\windows\LastGood.Tmp\system32\d3dx9_33.dll 03/12/2007 05:42 PM 3495784 \RP634\A0136304.dll c:\windows\LastGood.Tmp\system32\d3dx9_34.dll 05/16/2007 05:45 PM 3497832 \RP634\A0136305.dll c:\windows\LastGood.Tmp\system32\d3dx9_35.dll 07/19/2007 07:14 PM 3727720 \RP634\A0136306.dll c:\windows\LastGood.Tmp\system32\d3dx9_36.dll 10/12/2007 04:14 PM 3734536 \RP634\A0136307.dll c:\windows\LastGood.Tmp\system32\D3DX9_37.dll 03/05/2008 04:56 PM 3786760 \RP634\A0136308.dll c:\windows\LastGood.Tmp\system32\D3DX9_38.dll 05/30/2008 03:11 PM 3850760 \RP634\A0136309.dll c:\windows\LastGood.Tmp\system32\D3DX9_39.dll 07/10/2008 12:00 PM 3851784 \RP634\A0136310.dll c:\windows\LastGood.Tmp\system32\D3DX9_40.dll 10/10/2008 05:52 AM 4379984 \RP634\A0136311.dll c:\windows\LastGood.Tmp\system32\DRIVERS\nv4_mini.sys 04/30/2009 10:02 PM 8055584 \RP634\A0136356.sys c:\windows\LastGood.Tmp\system32\nv4_disp.dll 04/30/2009 10:02 PM 5896320 \RP634\A0136357.dll c:\windows\LastGood.Tmp\system32\x3daudio1_0.dll 02/03/2006 09:41 AM 14032 \RP634\A0136312.dll c:\windows\LastGood.Tmp\system32\x3daudio1_1.dll 03/05/2007 01:42 PM 15128 \RP634\A0136313.dll c:\windows\LastGood.Tmp\system32\x3daudio1_2.dll 10/22/2007 04:37 AM 17928 \RP634\A0136314.dll c:\windows\LastGood.Tmp\system32\X3DAudio1_3.dll 03/05/2008 05:00 PM 25608 \RP634\A0136315.dll c:\windows\LastGood.Tmp\system32\X3DAudio1_4.dll 05/30/2008 03:17 PM 25608 \RP634\A0136316.dll c:\windows\LastGood.Tmp\system32\X3DAudio1_5.dll 10/27/2008 11:04 AM 23376 \RP634\A0136317.dll c:\windows\LastGood.Tmp\system32\xactengine2_0.dll 02/03/2006 09:42 AM 230096 \RP634\A0136318.dll c:\windows\LastGood.Tmp\system32\xactengine2_1.dll 03/31/2006 01:39 PM 229584 \RP634\A0136319.dll c:\windows\LastGood.Tmp\system32\xactengine2_10.dll 10/22/2007 04:39 AM 267272 \RP634\A0136320.dll c:\windows\LastGood.Tmp\system32\xactengine2_2.dll 05/31/2006 08:24 AM 230168 \RP634\A0136321.dll c:\windows\LastGood.Tmp\system32\xactengine2_3.dll 07/28/2006 10:30 AM 236824 \RP634\A0136322.dll c:\windows\LastGood.Tmp\system32\xactengine2_4.dll 09/28/2006 05:05 PM 237848 \RP634\A0136323.dll c:\windows\LastGood.Tmp\system32\xactengine2_5.dll 12/08/2006 01:02 PM 251672 \RP634\A0136324.dll c:\windows\LastGood.Tmp\system32\xactengine2_6.dll 01/24/2007 04:27 PM 255848 \RP634\A0136325.dll c:\windows\LastGood.Tmp\system32\xactengine2_7.dll 04/04/2007 07:55 PM 261480 \RP634\A0136326.dll c:\windows\LastGood.Tmp\system32\xactengine2_8.dll 06/20/2007 09:46 PM 266088 \RP634\A0136327.dll c:\windows\LastGood.Tmp\system32\xactengine2_9.dll 07/20/2007 01:57 AM 267112 \RP634\A0136328.dll c:\windows\LastGood.Tmp\system32\xactengine3_0.dll 03/05/2008 05:03 PM 238088 \RP634\A0136329.dll c:\windows\LastGood.Tmp\system32\xactengine3_1.dll 05/30/2008 03:18 PM 238088 \RP634\A0136330.dll c:\windows\LastGood.Tmp\system32\xactengine3_2.dll 07/30/2008 07:20 AM 238088 \RP634\A0136331.dll c:\windows\LastGood.Tmp\system32\xactengine3_3.dll 10/27/2008 11:04 AM 235856 \RP634\A0136332.dll c:\windows\LastGood.Tmp\system32\XAPOFX1_0.dll 05/30/2008 03:17 PM 65032 \RP634\A0136333.dll c:\windows\LastGood.Tmp\system32\XAPOFX1_1.dll 07/30/2008 07:20 AM 68616 \RP634\A0136334.dll c:\windows\LastGood.Tmp\system32\XAPOFX1_2.dll 10/27/2008 11:04 AM 70992 \RP634\A0136335.dll c:\windows\LastGood.Tmp\system32\XAudio2_0.dll 03/05/2008 05:03 PM 479752 \RP634\A0136336.dll c:\windows\LastGood.Tmp\system32\XAudio2_1.dll 05/30/2008 03:19 PM 507400 \RP634\A0136337.dll c:\windows\LastGood.Tmp\system32\XAudio2_2.dll 07/30/2008 07:20 AM 509448 \RP634\A0136338.dll c:\windows\LastGood.Tmp\system32\XAudio2_3.dll 10/27/2008 11:04 AM 514384 \RP634\A0136339.dll c:\windows\LastGood.Tmp\system32\xinput1_1.dll 03/31/2006 01:39 PM 62672 \RP634\A0136340.dll c:\windows\LastGood.Tmp\system32\xinput1_2.dll 07/28/2006 10:30 AM 62744 \RP634\A0136341.dll c:\windows\LastGood.Tmp\system32\xinput1_3.dll 04/04/2007 07:53 PM 81768 \RP634\A0136342.dll c:\windows\LastGood.Tmp\system32\xinput9_1_0.dll 12/05/2005 07:07 PM 61136 \RP634\A0136343.dll c:\windows\patchw32.dll 01/23/2008 02:39 AM 215144 \RP638\A0137466.dll c:\windows\system32\404Fix.exe 08/18/2008 12:19 PM 82432 \RP638\A0137426.exe c:\windows\system32\Agent.OMZ.Fix.exe 12/12/2008 01:57 AM 78336 \RP638\A0137427.exe c:\windows\system32\comsa32.sys 06/21/2009 10:22 AM 8 \RP638\A0137429.sys 03/27/2009 10:03 AM 6186880 c:\windows\system32\dllcache\nv4_disp.dll 10/25/2007 05:17 PM 5767808 \RP634\A0136268.dll 03/27/2009 10:03 AM 6280416 c:\windows\system32\dllcache\nv4_mini.sys 04/30/2009 10:02 PM 8055584 \RP634\A0136267.sys 03/27/2009 10:03 AM 6280416 c:\windows\system32\drivers\nv4_mini.sys 04/30/2009 10:02 PM 8055584 \RP634\A0136347.sys c:\windows\system32\drivers\rubj.sys 06/23/2009 02:12 PM 61440 \RP639\A0137675.sys c:\windows\system32\dumphive.exe 07/31/2004 06:50 PM 51200 \RP638\A0137430.exe c:\windows\system32\IEDFix.C.exe 11/29/2008 06:58 PM 82944 \RP638\A0137431.exe c:\windows\system32\IEDFix.exe 05/18/2008 09:40 PM 82944 \RP638\A0137432.exe 03/27/2009 10:03 AM 436768 c:\windows\system32\keystone.exe 05/01/2009 12:31 AM 436768 \RP634\A0136253.exe 03/27/2009 10:03 AM 6186880 c:\windows\system32\nv4_disp.dll 04/30/2009 10:02 PM 5896320 \RP634\A0136348.dll 03/27/2009 10:03 AM 667648 c:\windows\system32\nvapi.dll 04/30/2009 10:02 PM 806912 \RP634\A0136266.dll 03/27/2009 10:03 AM 449056 c:\windows\system32\nvappbar.exe 05/01/2009 12:31 AM 449056 \RP634\A0136252.exe 03/27/2009 10:03 AM 139264 c:\windows\system32\nvcod.dll 04/30/2009 10:02 PM 143360 \RP634\A0136263.dll 03/27/2009 10:03 AM 139264 c:\windows\system32\nvcodins.dll 04/30/2009 10:02 PM 143360 \RP634\A0136264.dll 03/27/2009 10:03 AM 143360 c:\windows\system32\nvcolor.exe 05/01/2009 12:30 AM 143360 \RP634\A0136265.exe 03/27/2009 10:03 AM 13684736 c:\windows\system32\nvcpl.dll 05/01/2009 12:30 AM 13750272 \RP634\A0136257.dll 03/27/2009 10:03 AM 1560576 c:\windows\system32\nvcuda.dll 04/30/2009 10:02 PM 1720320 \RP634\A0136269.dll c:\windows\system32\nvcuvenc.dll 04/30/2009 10:02 PM 1314816 \RP634\A0136271.dll 03/27/2009 10:03 AM 401408 c:\windows\system32\nvcuvid.dll 04/30/2009 10:02 PM 663552 \RP634\A0136270.dll 03/27/2009 10:03 AM 4710400 c:\windows\system32\nvdisps.dll 05/01/2009 12:30 AM 4014080 \RP634\A0136240.dll 03/27/2009 10:03 AM 1346080 c:\windows\system32\nvdspsch.exe 01/15/2009 09:19 AM 1346080 \RP634\A0136250.exe 03/27/2009 10:03 AM 3489792 c:\windows\system32\nvgames.dll 05/01/2009 12:30 AM 3510272 \RP634\A0136241.dll 03/27/2009 10:03 AM 1503232 c:\windows\system32\nview.dll 05/01/2009 12:31 AM 1507328 \RP634\A0136247.dll 03/27/2009 10:03 AM 229376 c:\windows\system32\nvmccs.dll 05/01/2009 12:30 AM 229376 \RP634\A0136258.dll 03/27/2009 10:03 AM 45056 c:\windows\system32\nvmccsrs.dll 01/15/2009 09:19 AM 45056 \RP634\A0136259.dll 03/27/2009 10:03 AM 188416 c:\windows\system32\nvmccss.dll 05/01/2009 12:30 AM 188416 \RP634\A0136242.dll 03/27/2009 10:03 AM 86016 c:\windows\system32\nvmctray.dll 05/01/2009 12:30 AM 86016 \RP634\A0136260.dll 03/27/2009 10:03 AM 1273856 c:\windows\system32\nvmobls.dll 05/01/2009 12:30 AM 1282048 \RP634\A0136243.dll c:\windows\system32\nvnt4cpl.dll 10/07/2008 01:33 PM 286720 \RP634\A0136255.dll 03/27/2009 10:03 AM 9596928 c:\windows\system32\nvoglnt.dll 04/30/2009 10:02 PM 9994240 \RP634\A0136261.dll 03/27/2009 10:03 AM 466944 c:\windows\system32\nvshell.dll 05/01/2009 12:31 AM 466944 \RP634\A0136248.dll 03/27/2009 10:03 AM 163908 c:\windows\system32\nvsvc32.exe 05/01/2009 12:30 AM 168004 \RP634\A0136262.exe 03/27/2009 10:03 AM 3796992 c:\windows\system32\nvvitvs.dll 05/01/2009 12:30 AM 4038656 \RP634\A0136244.dll 03/27/2009 10:03 AM 81920 c:\windows\system32\nvwddi.dll 05/01/2009 12:30 AM 81920 \RP634\A0136254.dll 03/27/2009 10:03 AM 1724416 c:\windows\system32\nvwdmcpl.dll 05/01/2009 12:31 AM 1724416 \RP634\A0136249.dll 03/27/2009 10:03 AM 1101824 c:\windows\system32\nvwimg.dll 05/01/2009 12:31 AM 1101824 \RP634\A0136251.dll 03/27/2009 10:03 AM 2744320 c:\windows\system32\nvwss.dll 05/01/2009 12:30 AM 3117056 \RP634\A0136245.dll 03/27/2009 10:03 AM 1657376 c:\windows\system32\nwiz.exe 05/01/2009 12:31 AM 1657376 \RP634\A0136256.exe c:\windows\system32\o4Patch.exe 09/20/2008 12:45 PM 80384 \RP638\A0137433.exe c:\windows\system32\Process.exe 06/05/2003 09:13 PM 53248 \RP638\A0137434.exe c:\windows\system32\SKYNETaubodjkl.dll \RP638\A0137404.dll c:\windows\system32\SKYNETwsqttomq.dll \RP638\A0137403.dll c:\windows\system32\sopidkc.exe \RP638\A0137435.exe c:\windows\system32\SrchSTS.exe 04/27/2006 05:49 PM 288417 \RP638\A0137436.exe 04/13/2008 08:12 PM 295424 c:\windows\system32\termsrv.dll 03/14/2009 03:15 AM 295424 \RP639\A0137762.dll c:\windows\system32\tmp.reg 06/15/2009 04:31 PM 1720 \RP638\A0137437.reg c:\windows\system32\tpsaxyd.exe \RP638\A0137438.exe c:\windows\system32\VACFix.exe 10/01/2008 03:51 PM 87552 \RP638\A0137439.exe c:\windows\system32\VCCLSID.exe 09/06/2007 12:22 AM 289144 \RP638\A0137440.exe c:\windows\system32\wiawow32.sys 06/20/2009 10:20 PM 65536 \RP638\A0137441.sys 04/13/2008 08:12 PM 507904 c:\windows\system32\winlogon.exe 03/14/2009 03:15 AM 507904 \RP638\A0137467.exe c:\windows\system32\WS2Fix.exe 06/02/2009 11:17 AM 75776 \RP638\A0137442.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 81920] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-22 518488] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-02 1947928] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016] "RivaTunerStartupDaemon"="d:\program files\RivaTuner v2.08\RivaTuner.exe" [2008-03-10 2691072] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-27 1657376] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968] c:\documents and settings\John Christian\Start Menu\Programs\Startup\ ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000D7}"= "c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABSEHB.DLL" [2006-11-07 77824] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SABWinLogon] 2007-05-14 17:20 176128 ----a-w- c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-31 09:06 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-05-02 12:29 11952 ----a-w- c:\windows\system32\avgrsstx.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AT&T Self Support Tool.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AT&T Self Support Tool.lnk backup=c:\windows\pss\AT&T Self Support Tool.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ExifLauncher2.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ExifLauncher2.lnk backup=c:\windows\pss\ExifLauncher2.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^John Christian^Start Menu^Programs^Startup^Adobe Gamma.lnk] path=c:\documents and settings\John Christian\Start Menu\Programs\Startup\Adobe Gamma.lnk backup=c:\windows\pss\Adobe Gamma.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^John Christian^Start Menu^Programs^Startup^Aquarius Soft PC Alarm Clock Pro.lnk] path=c:\documents and settings\John Christian\Start Menu\Programs\Startup\Aquarius Soft PC Alarm Clock Pro.lnk backup=c:\windows\pss\Aquarius Soft PC Alarm Clock Pro.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^John Christian^Start Menu^Programs^Startup^reminder-ScanSoft Product Registration.lnk] path=c:\documents and settings\John Christian\Start Menu\Programs\Startup\reminder-ScanSoft Product Registration.lnk backup=c:\windows\pss\reminder-ScanSoft Product Registration.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^John Christian^Start Menu^Programs^Startup^Sins of a Solar Empire Launcher.lnk] path=c:\documents and settings\John Christian\Start Menu\Programs\Startup\Sins of a Solar Empire Launcher.lnk backup=c:\windows\pss\Sins of a Solar Empire Launcher.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "hpqcxs08"=3 (0x3) "HPSLPSVC"=2 (0x2) "hpqddsvc"=2 (0x2) "ZuneWlanCfgSvc"=3 (0x3) "ZuneNetworkSvc"=2 (0x2) "ZuneBusEnum"=2 (0x2) [HKEY_LOCAL_MACHINE\software\microsoft\security center] "FirewallOverride"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "d:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Program Files\\Xfire\\xfire.exe"= "c:\\Program Files\\Steam\\steam.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "d:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"= "d:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "d:\\Program Files\\EA Games\\Mirror's Edge\\Binaries\\MirrorsEdge.exe"= "%windir%\\system32\\drivers\\svchost.exe"= "c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"= "c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"= "c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"= "c:\\Program Files\\AIM\\aim.exe"= "c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"= "c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"= "c:\\Program Files\\USArmy\\America's Army 3\\Binaries\\AA3Game.exe"= "c:\\Program Files\\HuxleyLite\\binaries\\HuxleyMMOGame.exe"= "d:\\Program Files\\Activision\\Prototype\\prototypef.exe"= "d:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"= "c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"= "c:\\Program Files\\Steam\\steamapps\\common\\america's army 3\\Binaries\\AA3Game.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "57909:TCP"= 57909:TCP:*:Disabled:Pando Media Booster "57909:UDP"= 57909:UDP:*:Disabled:Pando Media Booster R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/8/2009 10:17 PM 64160] R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [7/29/2007 3:34 AM 16896] R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [7/29/2007 3:34 AM 52224] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/15/2009 10:33 AM 325896] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/15/2009 10:33 AM 108552] R1 SABKUTIL;SABKUTIL;c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.SYS [2/20/2007 4:02 PM 32256] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12/4/2008 2:50 PM 8944] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/4/2008 2:50 PM 55024] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/15/2009 10:33 AM 298776] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 5:34 PM 1003344] R2 ppsio2;PPDevice;c:\windows\system32\drivers\ppsio2.sys [8/27/2007 7:31 PM 23200] R2 WMDrive;WMDrive;c:\windows\system32\drivers\WMDrive.sys [2/17/2009 3:13 PM 37376] S1 SABDIFSV;SABDIFSV;c:\program files\SuperAdBlocker.com\Super Ad Blocker\sabdifsv.sys [9/21/2005 11:17 AM 5632] S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/4/2008 2:50 PM 7408] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc HPService REG_MULTI_SZ HPSLPSVC [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-06-23 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 02:17] . . ------- Supplementary Scan ------- . uStart Page = about:blank uInternet Settings,ProxyOverride = 127.0.0.1 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab FF - ProfilePath - . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-23 14:45 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet003\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-1547161642-152049171-1801674531-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:ec,46,bd,6d,c1,8a,a5,c5,3c,4d,bc,4f,7a,44,7e,ef,18,4d,c4,35,46,87,95, 05,56,d3,65,78,e2,22,6d,e2,bb,c0,9a,58,b5,86,dd,0c,82,19,c3,28,8b,56,e9,81,\ "??"=hex:80,40,06,d0,8e,ad,37,15,76,13,ef,74,08,8e,27,0f [HKEY_USERS\S-1-5-21-1547161642-152049171-1801674531-1003\Software\SecuROM\License information*] "datasecu"=hex:d7,cc,7d,6b,10,af,f5,7a,0e,82,a7,31,be,ca,81,d5,24,4f,46,37,ff, 58,66,af,9a,0c,87,a2,14,99,e2,a2,56,28,69,4a,e3,08,87,d1,f0,6a,67,03,9b,57,\ "rkeysecu"=hex:ce,13,31,c2,44,4f,e5,b0,9b,27,0f,62,37,7a,e0,d3 [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ř•€|˙˙˙˙•€|ů•A~*] "5E7CEC10DF0760D4F8DAFB12FDC06CCD"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{01CEC7E5-70FD-4D06-8FAD-BF21DF0CC6DC}\\Registered" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL] @DACL=(02 0000) "Installed"="1" @="" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI] @DACL=(02 0000) "NoChange"="1" "Installed"="1" @="" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS] @DACL=(02 0000) "Installed"="1" @="" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(820) c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL c:\program files\SUPERAntiSpyware\SASWINLO.DLL c:\windows\system32\WININET.dll - - - - - - - > 'explorer.exe'(6836) c:\windows\system32\WININET.dll c:\program files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABSEHB.DLL c:\program files\SUPERAntiSpyware\SASSEH.DLL . ------------------------ Other Running Processes ------------------------ . c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\NVIDIA Corporation\nTune\nTuneService.exe c:\program files\AVG\AVG8\avgrsx.exe c:\windows\system32\nvsvc32.exe c:\progra~1\AVG\AVG8\avgnsx.exe c:\windows\system32\PnkBstrA.exe c:\windows\system32\PnkBstrB.exe c:\program files\TVersity\Media Server\MediaServer.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\windows\system32\wbem\unsecapp.exe c:\windows\system32\wscntfy.exe c:\windows\system32\rundll32.exe c:\program files\Mozilla Firefox\firefox.exe . ************************************************************************** . Completion time: 2009-06-23 14:51 - machine was rebooted ComboFix-quarantined-files.txt 2009-06-23 18:51 ComboFix2.txt 2009-06-22 17:32 Pre-Run: 5,057,720,320 bytes free Post-Run: 5,098,979,328 bytes free Current=3 Default=3 Failed=2 LastKnownGood=5 Sets=1,2,3,4,5 719 --- E O F --- 2009-06-11 01:21 This post has been edited by jaysee: Jun 23 2009, 02:03 PM |
|
|
Jun 24 2009, 09:20 AM
Post
#15
|
|
![]() Unofficial Music Guru Posts: 2,354 From: Massachusetts, USA OS: Vista |
Those AVG detections are just system restore backups nothing to worry about. The Firefox page problem doesn't sound like a malware redirect to me, but let me know if you get any more.
CF log looks in good shape, so let's run some final checks. Sorry you have to run MBAM again, but I really do want to make sure I get a look at a log of a full scan, not just the quick scan. First we'll clean out your unnecessary temp files to speed up the scans:
Malwarebytes' Anti-Malware Please download Malwarebytes' Anti-Malware from here. Doubleclick mbam-setup.exe to install the program.
Kaspersky Online Scan Kaspersky online scanner uses Java technology to perform the scan. Because your Java is out of date, we need to update it first so that the scan will run without issues. Update Java Please download JavaRa to your desktop and unzip it to its own folder
Scan
So post back with the logs from MBAM and Kaspersky when you have them and give me an update on how the PC is running, and we should have you on your way - Dave |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
5 / 214 | 23rd May 2009 - 12:10 PM talent80 started - last by Rorschach112 |
|||||
![]() |
9 / 165 | 23rd August 2009 - 03:50 AM MasaCheez started - last by Rorschach112 |
|||||
![]() |
19 / 185 | 18th October 2009 - 08:26 AM Watkinsbt started - last by Rorschach112 |
|||||
![]() |
2 / 152 | 26th October 2009 - 04:54 PM deema1 started - last by Rorschach112 |
|||||
|
Time is now: 8th November 2009 - 02:18 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising