Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
   
2 Pages V   1 2 >  
Closed TopicStart new topic
Yahoo Searches Redirect [Closed]
jaysee
post Jun 15 2009, 02:45 PM
Post #1


Member
**
Posts: 25
OS: XP Pro



So just recently my Yahoo.com searches, once clicked, started redirecting to different sites (spam, malicious). I keep running Malwarebytes and Superantispyware, and they aren't really picking up anything anymore. Last night my computer shut off and restarted, and upon restart my background had been changed saying that my computer was infected, and a fake scan occurred. I restarted my computer into safe mode. AVG8.5 detected the junk that caused the background to change, and removed it. Ran CCleaner a couple times since this has started, ran Malwarebytes and Superantispyware again in safe mode, and it 'appears' to be clean. I restarted my computer, and I don't have the junk pretending to be anti-malware anymore, but Yahoo searches still end up causing redirected links to spam.

This is happening in both Firefox and Explorer, and it's ONLY Yahoo. Google and other search engines work fine, and when I do a search via the AVG Yahoo Search bar, search links are okay. It only happens if I go directly to yahoo.com. Needless to say, after the computer restarted and had the fake anti-virus stuff pop up and replace my background desktop image, I'm worried and would like to get this infection removed.

This may just be a coincidence, but this seemed to start happening after I tried installing and using ZoneAlarm. I didn't care for it, and had it uninstalled. Windows Firewall is active, and I am connected to the internet through a Netgear router.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:57:33, on 6/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TVersity\Media Server\MediaServer.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: 195.245.119.131 browser-security.microsoft.com
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Super Ad Blocker Toolbar - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\sabtb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O17 - HKLM\System\CS1\Services\Tcpip\..\{017659A2-AA14-4D5D-B1EF-FCFB3CABBA94}: NameServer = 192.168.1.1,192.168.1.2
O17 - HKLM\System\CS2\Services\Tcpip\..\{017659A2-AA14-4D5D-B1EF-FCFB3CABBA94}: NameServer = 192.168.1.1,192.168.1.2
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SABWinLogon - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Super Ad Blocker Service (SABSVC) - SuperAdBlocker.com - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TVersityMediaServer - Unknown owner - C:\Program Files\TVersity\Media Server\MediaServer.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 8006 bytes

This post has been edited by jaysee: Jun 15 2009, 02:58 PM
Go to the top of the page
 
+Quote Post
Transience
post Jun 15 2009, 02:49 PM
Post #2


Unofficial Music Guru
Group Icon
Posts: 2,354
From: Massachusetts, USA
OS: Vista



Hello jaysee and welcome to Geeks to Go! I'm Dave and I'll be helping you to clean your computer.

While HJT was once the preferred log to take a look at to begin with, it's fallen significantly behind the times, so we've updated our initial procedures.

The first thing I need you to do is go to this page and follow the instructions there: Malware Cleaning Guide - Please Read Before Starting a New Topic. These are the steps that we need you to perform before attempting a removal of malware from your computer.

If you're still experiencing problems after following all the steps in that thread, then please post the following logs here for me to take a look at:
  1. Malwarebytes' Anti-Malware log
  2. OTListIt.txt and Extras.txt, located in the same directory as the OTL program.
  3. Rooter log located at C:\Rooter.txt
Once you've posted those logs for me I'll take a look at them and see where we need to go from there smile.gif.

Cheers,
Dave
Go to the top of the page
 
+Quote Post
jaysee
post Jun 15 2009, 04:56 PM
Post #3


Member
**
Posts: 25
OS: XP Pro



I couldn't run the SystemRestorePoint program. I get a windows error every time. Did everything else.

QUOTE
Malwarebytes' Anti-Malware 1.37
Database version: 2284
Windows 5.1.2600 Service Pack 3

6/15/2009 5:27:35 PM
mbam-log-2009-06-15 (17-27-35).txt

Scan type: Quick Scan
Objects scanned: 95410
Time elapsed: 2 minute(s), 48 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


QUOTE
Rooter.exe (v1.0) by Eric_71
¨
Microsoft Windows XP Professional (5.1.2600) Service Pack 3
32_bits - x86 Family 15 Model 4 Stepping 9, GenuineIntel
¨
A:\ [Removable]
C:\ [Fixed-NTFS] .. ( Total:279 Go - Free:36 Go )
D:\ [Fixed-NTFS] .. ( Total:465 Go - Free:30 Go )
E:\ [CD_Rom]
F:\ [CD_Rom]
¨
Scan : 18:31.06
Path : C:\Documents and Settings\John Christian\Desktop\Misc Desktops\AntiVirusAd\Rooter.exe
User : John Christian ( Administrator -> YES )
¨
----------------------\\ Processes
¨
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (736)
______ \??\C:\WINDOWS\system32\csrss.exe (792)
______ \??\C:\WINDOWS\system32\winlogon.exe (816)
______ C:\WINDOWS\system32\services.exe (864)
______ C:\WINDOWS\system32\lsass.exe (876)
______ C:\WINDOWS\system32\svchost.exe (1064)
______ C:\WINDOWS\system32\svchost.exe (1152)
______ C:\WINDOWS\System32\svchost.exe (1256)
______ C:\WINDOWS\system32\svchost.exe (1504)
______ C:\WINDOWS\system32\spoolsv.exe (1720)
______ C:\WINDOWS\system32\svchost.exe (1900)
______ C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (1944)
______ C:\PROGRA~1\AVG\AVG8\avgrsx.exe (2012)
______ C:\PROGRA~1\AVG\AVG8\avgnsx.exe (2020)
______ C:\WINDOWS\System32\svchost.exe (388)
______ C:\WINDOWS\System32\svchost.exe (728)
______ C:\WINDOWS\System32\svchost.exe (956)
______ C:\WINDOWS\system32\svchost.exe (2192)
______ C:\WINDOWS\Explorer.EXE (2208)
______ C:\Program Files\TVersity\Media Server\MediaServer.exe (2236)
______ C:\Program Files\Windows Media Player\WMPNetwk.exe (2416)
______ C:\PROGRA~1\AVG\AVG8\avgtray.exe (3380)
______ C:\Program Files\Mozilla Firefox\firefox.exe (2288)
______ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (3124)
______ C:\Documents and Settings\John Christian\Desktop\Misc Desktops\AntiVirusAd\Rooter.exe (2932)
¨
----------------------\\ Device\Harddisk0\
¨
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
¨
\Device\Harddisk0\Partition1 --[ MBR ]-- (Start_Offset:32256 | Length:300066407424)
¨
----------------------\\ Scheduled Tasks
¨
C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\Tasks\desktop.ini
C:\WINDOWS\Tasks\Norton Security Online - Run Full System Scan - John Christian.job
C:\WINDOWS\Tasks\SA.DAT
¨
----------------------\\ Registry
¨
¨
----------------------\\ Files & Folders
¨
----------------------\\ Scan completed at 18:31.09
¨
C:\Rooter$\Rooter_1.txt - (15/06/2009 | 18:31.09)


QUOTE
OTL logfile created on: 6/15/2009 6:34:02 PM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\John Christian\Desktop\Misc Desktops\AntiVirusAd
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.33 Gb Available Physical Memory | 66.58% Memory free
3.85 Gb Paging File | 3.34 Gb Available in Paging File | 86.76% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 279.46 Gb Total Space | 36.65 Gb Free Space | 13.11% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 30.09 Gb Free Space | 6.46% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JOHN
Current User Name: John Christian
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\TVersity\Media Server\MediaServer.exe ()
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\John Christian\Desktop\Misc Desktops\AntiVirusAd\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe LM Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32 [Auto | Running]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqcxs08 [Disabled | Stopped]) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc [Disabled | Stopped]) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (HPSLPSVC [Disabled | Stopped]) -- C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL (Hewlett-Packard Co.)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Stopped]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Stopped]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Stopped]) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LVPrcSrv [Auto | Stopped]) -- c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVSrvLauncher [Auto | Stopped]) -- C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (Net Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (npggsvc [On_Demand | Stopped]) -- C:\WINDOWS\system32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (nTuneService [Auto | Stopped]) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
SRV - (NVSvc [Auto | Stopped]) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (Pml Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)
SRV - (PnkBstrA [Auto | Stopped]) -- C:\WINDOWS\system32\PnkBstrA.exe ()
SRV - (PnkBstrB [Auto | Stopped]) -- C:\WINDOWS\system32\PnkBstrB.exe ()
SRV - (ProtexisLicensing [Auto | Stopped]) -- C:\WINDOWS\system32\PSIService.exe ()
SRV - (SABSVC [Auto | Stopped]) -- C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE (SuperAdBlocker.com)
SRV - (Symantec Core LC [On_Demand | Stopped]) -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation)
SRV - (TVersityMediaServer [Auto | Running]) -- C:\Program Files\TVersity\Media Server\MediaServer.exe ()
SRV - (usnjsvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service [Auto | Stopped]) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WLSetupSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [Auto | Running]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (ZuneBusEnum [Auto | Stopped]) -- c:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc [Auto | Stopped]) -- c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc [On_Demand | Stopped]) -- c:\WINDOWS\system32\ZuneWlanCfgSvc.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (atksgt [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\atksgt.sys ()
DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (ENTECH [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ENTECH.sys (EnTech Taiwan)
DRV - (FETNDIS [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\fetnd5.sys (VIA Technologies, Inc. )
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (giveio [Boot | Running]) -- C:\WINDOWS\system32\giveio.sys ()
DRV - (L8042Kbd [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys (Logitech, Inc.)
DRV - (L8042mou [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\L8042mou.sys (Logitech, Inc.)
DRV - (Lbd [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (LHidKe [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\LHidKE.Sys (Logitech, Inc.)
DRV - (LHidUsbK [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\LHidUsbK.Sys (Logitech, Inc.)
DRV - (lirsgt [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\lirsgt.sys ()
DRV - (LMouKE [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\LMouKE.sys (Logitech, Inc.)
DRV - (LVcKap [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\LVcKap.sys ()
DRV - (LVMVDrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\LVMVDrv.sys (Logitech Inc.)
DRV - (LVPr2Mon [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys ()
DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (NVR0Dev [On_Demand | Running]) -- C:\WINDOWS\nvoclock.sys (NVidia Corp.)
DRV - (pfc [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (PhilCam8116 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\CamDrO21.sys (Microsoft Corporation)
DRV - (ppsio2 [Auto | Running]) -- C:\WINDOWS\System32\drivers\ppsio2.sys ()
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (RivaTuner32 [On_Demand | Stopped]) -- D:\Program Files\RivaTuner v2.08\RivaTuner32.sys ()
DRV - (RTL8023xp [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (rtl8139 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (SABDIFSV [System | Stopped]) -- C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABDIFSV.SYS ()
DRV - (SABKUTIL [System | Running]) -- C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys ()
DRV - (SABProcEnum [On_Demand | Stopped]) -- C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABProcEnum.sys (SuperAdBlocker.com)
DRV - (SASDIFSV [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Stopped]) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (speedfan [Boot | Running]) -- C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (sptd [Boot | Running]) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (StillCam [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (Tcpip6 [System | Running]) -- C:\WINDOWS\system32\DRIVERS\tcpip6.sys (Microsoft Corporation)
DRV - (usbaudio [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (VIAudio [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\vinyl97.sys (VIA Technologies, Inc.)
DRV - (ViBus [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ViBus.sys (VIA Technologies, Inc.)
DRV - (videX32 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\videX32.sys (VIA Technologies, Inc.)
DRV - (ViPrt [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ViPrt.sys (VIA Technologies, Inc.)
DRV - (WMDrive [Auto | Running]) -- C:\WINDOWS\system32\drivers\WMDrive.sys ()
DRV - (X4HSX32 [Auto | Running]) -- C:\Program Files\GameTap\bin\Release\X4HSX32.Sys (Exent Technologies Ltd.)
DRV - (xnacc [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\xnacc.sys (Microsoft Corporation)
DRV - (zumbus [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\zumbus.sys (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p="
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: {1d5287d1-8a92-0001-1f31-1cec198018d8}:2.1.0.7
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.10
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090123.1
FF - prefs.js..extensions.enabledItems: iaplayer@instantaction.com:0.3.4.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.07061050
FF - prefs.js..extensions.enabledItems: {46868735-c3fa-47ce-8ce7-cce51a66aceb}:1.2
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:3.0.0
FF - prefs.js..extensions.enabledItems: en-US@dictionaries.addons.mozilla.org:3.0.3
FF - prefs.js..extensions.enabledItems: {3414F358-CBBD-4215-8320-ABAECC12AC25}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=ffds1&p="

FF - HKLM\software\mozilla\Firefox\Extensions\\{3414F358-CBBD-4215-8320-ABAECC12AC25}: C:\DOCUMENTS AND SETTINGS\JOHN CHRISTIAN\LOCAL SETTINGS\APPLICATION DATA\{3414F358-CBBD-4215-8320-ABAECC12AC25}\ [2009/01/05 03:05:00 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX [2009/05/04 14:00:08 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{1d5287d1-8a92-0001-1f31-1cec198018d8}: C:\PROGRAM FILES\AVG\AVG8\TOOLBARFF [2009/05/04 14:00:09 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/05/23 19:42:24 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/06/14 17:07:04 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/06/12 00:16:16 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/06/14 17:07:38 | 00,000,000 | ---D | M]

[2008/06/27 07:34:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Extensions
[2008/06/27 07:34:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/06/15 14:06:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions
[2009/04/23 19:19:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2008/06/27 08:11:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{46868735-c3fa-47ce-8ce7-cce51a66aceb}
[2008/02/01 12:50:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2007/08/07 01:12:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2008/06/30 10:35:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
[2009/06/14 18:44:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2008/06/27 07:48:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\en-US@dictionaries.addons.mozilla.org
[2008/01/31 20:30:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\iaplayer@instantaction.com
[2007/09/12 03:29:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\moveplayer@movenetworks.com
[2008/05/08 00:35:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\sp82nxrc.JC01\extensions
[2008/02/01 12:40:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\sp82nxrc.JC01\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2008/05/08 00:35:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\sp82nxrc.JC01\extensions\{991A772A-BA13-4c1d-A9EF-F897F31DEC7D}
[2008/12/12 14:23:54 | 00,002,158 | ---- | M] () -- C:\Documents and Settings\John Christian\Application Data\Mozilla\FireFox\Profiles\0c457zba.default\searchplugins\MySpace.xml
[2009/06/15 14:06:15 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/06/12 00:16:16 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/11/04 18:06:45 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2009/06/14 17:07:44 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2009/06/12 00:16:10 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/06/12 00:16:10 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2004/05/07 15:31:40 | 00,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\components\MSVCR71.DLL
[2006/11/07 12:58:44 | 00,139,264 | ---- | M] () -- C:\Program Files\mozilla firefox\components\SABFF20.DLL
[2009/05/11 22:01:14 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/05/11 22:01:14 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/05/11 22:01:14 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/05/11 22:01:14 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/05/11 22:01:14 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/05/11 22:01:14 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/05/11 22:01:14 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (786 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG Technologies CZ, s.r.o.)
O3 - HKLM\..\Toolbar: (Super Ad Blocker Toolbar) - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\sabtb.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG Technologies CZ, s.r.o.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKCU..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear (NVIDIA)
O4 - HKCU..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" (BitTorrent, Inc.)
O4 - Startup: C:\Documents and Settings\John Christian\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 157
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 26 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SABWinLogon: DllName - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL (SuperAdBlocker.com)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000D7} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSEHB.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/07/28 21:42:25 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{aa9a245e-2b88-11de-9032-00142a7c704f}\Shell - "" = AutoRun
O33 - MountPoints2\{aa9a245e-2b88-11de-9032-00142a7c704f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{aa9a245e-2b88-11de-9032-00142a7c704f}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found
O33 - MountPoints2\{b6b3b553-3d36-11dc-a3af-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{b6b3b553-3d36-11dc-a3af-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b6b3b553-3d36-11dc-a3af-806d6172696f}\Shell\AutoRun\command - "" = E:\FrameworkCheck.exe -- File not found
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/06/15 18:32:43 | 00,000,000 | ---D | M]
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[2099/01/01 12:00:00 | 00,011,168 | -H-- | C] () -- C:\WINDOWS\System32\tupigovi
[2009/06/15 18:07:21 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/06/15 17:12:01 | 00,000,767 | ---- | C] () -- C:\Documents and Settings\John Christian\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/06/15 17:11:52 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/06/15 16:40:15 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/06/15 16:29:12 | 00,001,720 | ---- | C] () -- C:\WINDOWS\System32\tmp.reg
[2009/06/15 16:28:21 | 00,289,144 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\VCCLSID.exe
[2009/06/15 16:28:21 | 00,288,417 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\SrchSTS.exe
[2009/06/15 16:28:21 | 00,135,168 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swreg.exe
[2009/06/15 16:28:21 | 00,087,552 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\VACFix.exe
[2009/06/15 16:28:21 | 00,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.exe
[2009/06/15 16:28:21 | 00,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.C.exe
[2009/06/15 16:28:21 | 00,082,432 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\404Fix.exe
[2009/06/15 16:28:21 | 00,080,384 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\o4Patch.exe
[2009/06/15 16:28:21 | 00,079,360 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swxcacls.exe
[2009/06/15 16:28:21 | 00,078,336 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\Agent.OMZ.Fix.exe
[2009/06/15 16:28:21 | 00,075,776 | ---- | C] () -- C:\WINDOWS\System32\WS2Fix.exe
[2009/06/15 16:28:21 | 00,053,248 | ---- | C] (http://www.beyondlogic.org) -- C:\WINDOWS\System32\Process.exe
[2009/06/15 16:28:21 | 00,051,200 | ---- | C] () -- C:\WINDOWS\System32\dumphive.exe
[2009/06/15 16:28:21 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\swsc.exe
[2009/06/15 13:41:50 | 00,981,586 | ---- | C] () -- C:\Documents and Settings\John Christian\My Documents\cc_20090615_134143.reg
[2009/06/15 05:42:28 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\93338746.ini
[2009/06/15 05:42:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\93338746
[2009/06/15 05:42:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\13328754
[2009/06/14 23:02:31 | 01,615,732 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\ProcessExplorer.zip
[2009/06/14 20:42:02 | 00,000,000 | ---D | C] -- C:\Program Files\ESET
[2009/06/14 19:58:14 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/06/14 19:58:14 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/06/14 19:58:14 | 00,155,136 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2009/06/14 19:58:14 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/06/14 19:58:14 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/06/14 19:58:14 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/06/14 19:58:14 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/06/14 19:58:14 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/06/14 19:57:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/06/14 19:57:29 | 00,000,000 | --SD | C] -- C:\ComboFix
[2009/06/14 19:57:24 | 00,389,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF1521.exe
[2009/06/14 19:56:19 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/06/14 19:28:32 | 00,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/06/14 19:28:29 | 00,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2009/06/14 17:06:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2009/06/12 14:10:30 | 04,613,370 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\heartbeats.mp3
[2009/06/11 22:26:13 | 00,215,383 | ---- | C] () -- C:\WINDOWS\System32\nvapps.xml
[2009/06/11 22:26:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\nview
[2009/06/11 16:59:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\John Christian\My Documents\Prototype
[2009/06/11 04:14:24 | 00,000,803 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Prototype™.lnk
[2009/06/10 03:01:00 | 00,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieproxy.dll
[2009/06/10 03:01:00 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpshims.dll
[2009/06/08 21:17:31 | 03,099,494 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\boss.bmp
[2009/06/05 21:02:27 | 00,000,000 | ---D | C] -- C:\Program Files\Realtek AC97
[2009/06/05 20:59:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/06/05 20:58:58 | 00,000,000 | ---D | C] -- C:\Program Files\PC Drivers HeadQuarters
[2009/06/05 17:30:08 | 00,001,407 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\i j j i.lnk
[2009/06/05 17:30:03 | 00,000,000 | ---D | C] -- C:\ijji
[2009/06/05 17:30:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\John Christian\Application Data\ijjigame
[2009/06/05 17:29:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ijjigame
[2009/06/05 17:06:13 | 00,710,064 | ---- | C] (NHN USA) -- C:\WINDOWS\System32\ijjiSetup.exe
[2009/06/05 17:06:13 | 00,157,152 | ---- | C] (NHN Corporation) -- C:\WINDOWS\System32\PubPlugin.dll
[2009/06/05 17:06:13 | 00,058,800 | ---- | C] (NHN USA Inc.) -- C:\WINDOWS\System32\ijjiProcessRestarter.exe
[2009/06/05 17:06:13 | 00,058,800 | ---- | C] (NHN USA Corp.) -- C:\WINDOWS\System32\ijjiPlugin2.dll
[2009/06/05 17:06:13 | 00,000,000 | ---D | C] -- C:\Program Files\NHN USA
[2009/06/05 15:22:40 | 00,001,341 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Huxley Lite.lnk
[2009/06/05 15:22:40 | 00,000,000 | ---D | C] -- C:\Program Files\HuxleyLite
[2009/06/05 03:17:47 | 21,148,51485 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\Huxley_Lite_Setup.zip
[2009/06/03 23:48:43 | 00,000,854 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\The Sims 3.lnk
[2009/06/03 23:26:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
[2009/06/03 23:26:23 | 00,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2009/06/03 23:25:34 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ZoneLabs
[2009/05/25 18:27:25 | 31,796,401 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\169_sc2_cs_pc2_101108_hr.mp4
[2009/05/24 22:40:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\John Christian\Application Data\Games
[2009/05/23 22:29:17 | 00,000,000 | ---D | C] -- C:\Program Files\USArmy
[2009/05/23 20:36:21 | 01,089,593 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/05/23 19:44:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AA3DeployClient
[2009/05/23 19:44:26 | 00,000,308 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\AA3Deploy.appref-ms
[2009/05/23 19:35:30 | 00,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel
[2009/05/21 18:51:48 | 00,041,808 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll
[2009/05/19 18:27:38 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft WSE
[2009/04/22 00:19:06 | 00,172,173 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2009/03/27 10:03:00 | 01,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2009/03/27 10:03:00 | 01,503,232 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2009/03/27 10:03:00 | 01,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2009/03/27 10:03:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2009/02/17 15:13:08 | 00,037,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\WMDrive.sys
[2009/02/07 01:33:58 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2008/12/19 02:52:42 | 00,000,061 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2008/11/10 02:26:10 | 00,000,004 | ---- | C] () -- C:\WINDOWS\System32\microday08.dll
[2008/11/10 02:26:07 | 00,000,070 | ---- | C] () -- C:\WINDOWS\System32\mypath0079.dll
[2008/11/10 02:26:07 | 00,000,034 | ---- | C] () -- C:\WINDOWS\System32\MTX0CI.dll
[2008/11/06 12:37:32 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/11/06 12:34:00 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2008/11/06 12:34:00 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2008/11/06 12:33:02 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/11/05 17:29:30 | 00,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys
[2008/10/07 10:13:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/08/21 15:05:01 | 00,000,056 | ---- | C] () -- C:\WINDOWS\kgt2k.INI
[2008/07/03 19:57:29 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2008/07/03 16:32:59 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2008/07/03 16:32:59 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2008/07/03 16:32:59 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2008/06/05 08:58:26 | 00,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008/04/10 12:52:08 | 00,662,016 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008/04/10 12:52:06 | 03,104,256 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2008/04/10 12:52:06 | 00,520,192 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2008/04/10 12:52:06 | 00,404,992 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2008/04/10 12:52:06 | 00,397,312 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
[2008/04/10 12:52:06 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll
[2008/04/10 12:52:06 | 00,167,936 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
[2008/04/10 12:52:06 | 00,143,360 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
[2008/04/10 12:52:06 | 00,135,168 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
[2008/04/10 12:52:06 | 00,122,880 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2008/04/10 12:52:06 | 00,118,784 | ---- | C] () -- C:\WINDOWS\System32\ff_realaac.dll
[2008/04/10 12:52:06 | 00,102,912 | ---- | C] () -- C:\WINDOWS\System32\ff_tremor.dll
[2008/04/10 12:52:06 | 00,054,784 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
[2008/04/10 12:52:06 | 00,038,400 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
[2008/04/10 12:52:06 | 00,026,624 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2008/04/10 12:50:40 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008/03/29 11:42:22 | 00,245,248 | ---- | C] () -- C:\WINDOWS\System32\dxr.dll
[2008/03/29 11:42:20 | 00,159,744 | ---- | C] () -- C:\WINDOWS\System32\mmfinfo.dll
[2008/03/29 11:42:14 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\avss.dll
[2008/03/29 11:42:08 | 00,148,992 | ---- | C] () -- C:\WINDOWS\System32\mkx.dll
[2008/03/29 11:42:04 | 00,141,312 | ---- | C] () -- C:\WINDOWS\System32\mp4.dll
[2008/03/29 11:42:04 | 00,108,032 | ---- | C] () -- C:\WINDOWS\System32\avi.dll
[2008/03/29 11:42:02 | 00,120,832 | ---- | C] () -- C:\WINDOWS\System32\ogm.dll
[2008/03/29 11:42:00 | 00,163,840 | ---- | C] () -- C:\WINDOWS\System32\ts.dll
[2008/03/29 11:41:54 | 00,097,280 | ---- | C] () -- C:\WINDOWS\System32\avs.dll
[2008/03/29 11:41:52 | 00,079,360 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll
[2008/03/29 11:41:52 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll
[2008/03/14 02:53:39 | 00,000,004 | ---- | C] () -- C:\WINDOWS\info147.sys
[2008/01/23 02:39:12 | 00,215,144 | ---- | C] () -- C:\WINDOWS\patchw32.dll
[2007/12/31 20:00:00 | 00,741,376 | ---- | C] () -- C:\WINDOWS\System32\audxlib.dll
[2007/12/31 20:00:00 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2007/12/31 20:00:00 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\ff_kernelDeint.dll
[2007/12/08 04:28:38 | 00,000,023 | ---- | C] () -- C:\WINDOWS\BlendSettings.ini
[2007/12/01 01:40:08 | 00,279,712 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2007/12/01 01:40:07 | 00,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2007/11/18 22:56:06 | 00,000,319 | ---- | C] () -- C:\WINDOWS\game.ini
[2007/10/13 05:30:20 | 00,000,137 | ---- | C] () -- C:\WINDOWS\System32\Registration.ini
[2007/10/01 23:37:38 | 00,032,768 | ---- | C] () -- C:\WINDOWS\System32\mf.dll
[2007/10/01 20:25:17 | 00,034,308 | ---- | C] () -- C:\WINDOWS\System32\bassmod.dll
[2007/08/27 19:51:31 | 00,000,077 | ---- | C] () -- C:\WINDOWS\mydebug.ini
[2007/08/27 19:31:47 | 00,023,200 | ---- | C] () -- C:\WINDOWS\System32\drivers\ppsio2.sys
[2007/08/27 19:30:46 | 00,001,020 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2007/08/27 19:30:46 | 00,000,090 | ---- | C] () -- C:\WINDOWS\calera.ini
[2007/08/27 19:30:39 | 00,269,312 | ---- | C] () -- C:\WINDOWS\System32\FPXIG.DLL
[2007/08/27 19:30:39 | 00,068,096 | ---- | C] () -- C:\WINDOWS\System32\IGFPX32P.DLL
[2007/08/27 19:30:39 | 00,065,024 | ---- | C] () -- C:\WINDOWS\System32\JPEGACC.DLL
[2007/08/27 19:30:27 | 00,101,376 | ---- | C] () -- C:\WINDOWS\System32\WELSOF32.DLL
[2007/08/10 10:13:09 | 00,138,920 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/08/03 00:09:08 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2007/07/29 17:43:52 | 00,685,816 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2007/07/28 22:58:45 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\YCRWin32.dll
[2007/06/28 14:54:10 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007/03/12 12:01:30 | 00,217,088 | ---- | C] () -- C:\WINDOWS\NVGfxOgl.dll
[2007/02/06 17:45:04 | 00,025,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/02/06 17:42:40 | 01,691,808 | ---- | C] () -- C:\WINDOWS\System32\drivers\Lvckap.sys
[2004/08/04 08:00:00 | 00,000,651 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/04 08:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\SYSTEM.INI
[2003/04/05 13:47:42 | 00,147,456 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2002/05/15 20:38:40 | 00,091,136 | ---- | C] () -- C:\WINDOWS\System32\mp4fil32.dll
[2002/05/04 10:19:00 | 00,049,152 | ---- | C] () -- C:\WINDOWS\System32\avisynthEx.dll
[1996/04/03 15:33:26 | 00,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys

========== Files - Modified Within 30 Days ==========

[2009/06/15 18:12:58 | 00,008,192 | -HS- | M] () -- C:\WINDOWS\Thumbs.db
[2009/06/15 18:00:34 | 00,215,383 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/06/15 18:00:34 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/06/15 18:00:15 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\John Christian\Local Settings\desktop.ini
[2009/06/15 18:00:07 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/06/15 17:59:59 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/06/15 17:56:48 | 00,492,248 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/06/15 17:56:48 | 00,435,260 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/06/15 17:56:48 | 00,068,156 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/06/15 17:17:24 | 37,139,497 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/06/15 17:17:24 | 00,077,549 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/06/15 17:12:01 | 00,000,767 | ---- | M] () -- C:\Documents and Settings\John Christian\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/06/15 16:31:44 | 00,001,720 | ---- | M] () -- C:\WINDOWS\System32\tmp.reg
[2009/06/15 13:58:19 | 00,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/06/15 13:42:29 | 00,981,586 | ---- | M] () -- C:\Documents and Settings\John Christian\My Documents\cc_20090615_134143.reg
[2009/06/15 13:37:06 | 00,000,651 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/06/15 13:37:06 | 00,000,227 | ---- | M] () -- C:\WINDOWS\SYSTEM.INI
[2009/06/15 13:37:06 | 00,000,211 | -HS- | M] () -- C:\boot.ini
[2009/06/15 05:42:28 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\93338746.ini
[2009/06/14 23:02:33 | 01,615,732 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\ProcessExplorer.zip
[2009/06/14 19:56:38 | 00,389,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF1521.exe
[2009/06/14 19:28:29 | 00,000,552 | ---- | M] () -- C:\WINDOWS\System32\d3d8caps.dat
[2009/06/13 19:19:31 | 00,001,407 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\i j j i.lnk
[2009/06/12 14:20:54 | 04,613,370 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\heartbeats.mp3
[2009/06/11 04:14:24 | 00,000,803 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Prototype™.lnk
[2009/06/10 21:23:45 | 00,386,888 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/06/08 22:17:20 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/06/08 21:17:32 | 03,099,494 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\boss.bmp
[2009/06/08 20:00:01 | 00,000,594 | ---- | M] () -- C:\WINDOWS\tasks\Norton Security Online - Run Full System Scan - John Christian.job
[2009/06/08 08:10:10 | 00,155,136 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2009/06/05 15:22:40 | 00,001,341 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Huxley Lite.lnk
[2009/06/05 04:36:36 | 21,148,51485 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\Huxley_Lite_Setup.zip
[2009/06/03 23:48:43 | 00,000,854 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\The Sims 3.lnk
[2009/06/03 23:37:54 | 00,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat
[2009/06/02 11:17:27 | 00,075,776 | ---- | M] () -- C:\WINDOWS\System32\WS2Fix.exe
[2009/06/01 12:51:12 | 23,635,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/05/31 22:17:35 | 00,015,688 | ---- | M] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/05/26 17:31:26 | 00,058,800 | ---- | M] (NHN USA Inc.) -- C:\WINDOWS\System32\ijjiProcessRestarter.exe
[2009/05/26 13:20:08 | 00,040,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/26 13:19:56 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/25 18:30:24 | 31,796,401 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\169_sc2_cs_pc2_101108_hr.mp4
[2009/05/23 19:44:26 | 00,000,308 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\AA3Deploy.appref-ms
[2009/05/21 18:51:48 | 00,041,808 | ---- | M] () -- C:\WINDOWS\System32\xfcodec.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 451 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >



QUOTE
OTL Extras logfile created on: 6/15/2009 6:34:02 PM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\John Christian\Desktop\Misc Desktops\AntiVirusAd
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.33 Gb Available Physical Memory | 66.58% Memory free
3.85 Gb Paging File | 3.34 Gb Available in Paging File | 86.76% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 279.46 Gb Total Space | 36.65 Gb Free Space | 13.11% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 30.09 Gb Free Space | 6.46% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JOHN
Current User Name: John Christian
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"10244:TCP" = 10244:TCP:LocalSubNet:Enabled:Zune Network Sharing Service
"10285:UDP" = 10285:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10286:UDP" = 10286:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10287:UDP" = 10287:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10288:UDP" = 10288:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10289:UDP" = 10289:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10244:TCP" = 10244:TCP:LocalSubNet:Enabled:Zune Network Sharing Service
"10285:UDP" = 10285:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10286:UDP" = 10286:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10287:UDP" = 10287:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10288:UDP" = 10288:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10289:UDP" = 10289:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"57909:TCP" = 57909:TCP:*:Disabled:Pando Media Booster
"57909:UDP" = 57909:UDP:*:Disabled:Pando Media Booster
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
%windir%\system32\drivers\svchost.exe:*:Enabled:svchost File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:uTorrent (BitTorrent, Inc.)
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.)
D:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty® 4 - Modern Warfare™ ()
C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test (Microsoft Corporation)
C:\Program Files\Xfire\xfire.exe:*:Enabled:Xfire (Xfire Inc.)
D:\Program Files\America's Army Deploy Client\AADeployClient.exe:*:Disabled:AADeployClient (US Army)
E:\bin\IA\Core\MDM_Util.exe:*:Enabled:MDM_Util File not found
D:\Program Files\Electronic Arts\Dead Space\Dead Space.exe:*:Enabled:Dead Space ™ ()
C:\Program Files\Steam\steam.exe:*:Enabled:Steam (Valve Corporation)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Disabled:Bonjour (Apple Inc.)
D:\Program Files\Ubisoft\Far Cry 2\bin\FarCry2.exe:*:Disabled:Far Cry 2 (Ubisoft Entertainment)
D:\Program Files\Ubisoft\Far Cry 2\bin\FC2Launcher.exe:*:Disabled:Far Cry 2 Updater (Ubisoft)
C:\Program Files\iTunes\iTunes.exe:*:Disabled:iTunes (Apple Inc.)
D:\Program Files\EA Games\Mirror's Edge\Binaries\MirrorsEdge.exe:*:Enabled:Mirror's Edge™ (EA Digital Illusions CE AB)
C:\Documents and Settings\John Christian\Desktop\base\MetalDrift.exe:*:Enabled:MetalDrift File not found
%windir%\system32\drivers\svchost.exe:*:Enabled:svchost File not found
C:\Program Files\Steam\steamapps\fanible\darwinia\darwinia.exe:*:Enabled:Darwinia File not found
C:\Program Files\TVersity\Media Server\MediaServer.exe:*:Enabled:TVersity Media Server ()
C:\WINDOWS\explorer.exe:*:Enabled:Windows Explorer (Microsoft Corporation)
C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox (Mozilla Corporation)
C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader (AOL LLC)
C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM (AOL LLC)
C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\MySpace\IM\MySpaceIM.exe:*:Enabled:MySpaceIM ()
C:\Program Files\SmartFTP Client\SmartFTP.exe:*:Enabled:SmartFTP Client 3.0 (SmartSoft Ltd.)
C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger (America Online, Inc.)
C:\Program Files\Steam\steamapps\common\left 4 dead\left4dead.exe:*:Enabled:Left 4 Dead ()
C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Disabled:Pando Media Booster ()
C:\Program Files\USArmy\America's Army 3\Binaries\AA3Game.exe:*:Enabled:AA3Game ()
C:\WINDOWS\Downloaded Program Files\PurpleBean.exe:*:Enabled:PurpleBean.exe ()
C:\Program Files\HuxleyLite\binaries\HuxleyMMOGame.exe:*:Enabled:Huxley: The Dystopia (WEBZEN)
D:\Program Files\Activision\Prototype\prototypef.exe:*:Enabled:Prototype™ (Activision)
C:\Program Files\NovaLogic\Delta Force Xtreme 2 BETA\UPDATE.EXE:*:Disabled:Delta Force Xtreme 2 BETA File not found
C:\Program Files\NovaLogic\Delta Force Xtreme 2 BETA\DFX2BETA.EXE:*:Disabled:Delta Force Xtreme 2 BETA File not found
D:\Program Files\Ubisoft\Far Cry 2\bin\FC2Editor.exe:*:Disabled:Editor (Ubisoft Entertainment)
C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Disabled:Nexon Game Manager (Nexon)
D:\Program Files\Combat Arms\NMService.exe:*:Disabled:Nexon Messenger Core File not found

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{0C180787-F8C8-42FD-A9D3-689BA44BEAAF}" = Corel Painter Essentials 3
"{001E7FB6-BB6B-4ED0-BEDC-B5404ED96D4E}" = DocProc
"{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}" = Zune Language Pack (FR)
"{01386D1F-ADE7-43B4-A4E9-312FC5BC726F}_is1" = SWF Opener
"{02DFF6B1-1654-411C-8D7B-FD6052EF016F}" = Apple Software Update
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{05B49229-22A2-4F88-842A-BBC2EBE1CCF6}" = Microsoft Games for Windows - LIVE Redistributable
"{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0C180787-F8C8-42FD-A9D3-689BA44BEAAF}" = Corel Painter Essentials 3
"{0CA38F52-F0FA-4B9F-8A36-EC8A9609FBBC}" = Halo 2 for Windows Vista
"{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{1632FD86-1BA4-4FC4-8B25-A8C655D63F68}" = Sid Meier's Pirates!
"{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1B0FBB9A-995D-47cd-87CD-13E68B676E4F}" = Mass Effect
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{1C6D9FD0-8BE2-4226-8D9F-4929CBC1C396}" = Camtasia Studio 4
"{1DCC7418-2089-4BDD-B321-3771956160FC}" = ijji Auto Installer
"{200A873B-977F-4063-9AD7-C333B069A571}" = HuxleyLite
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{245F6C7A-0C22-4DE0-8202-2AAA620A1D3A}" = Microsoft XNA Framework Redistributable 2.0
"{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.5.5
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 14
"{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg
"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}" = Logitech SetPoint
"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision
"{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty® 4 - Modern Warfare™ 1.4 Patch
"{3F64C088-9A45-41B3-8B99-71AFAB720A77}" = Sherlock Holmes versus Jack the Ripper DEMO
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{405ABBEB-8DF1-4174-86C0-DCB5E1C78F14}" = NetDeviceManager
"{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}" = Google Earth
"{415CDA53-9100-476F-A7B2-476691E117C7}" = HP Smart Web Printing
"{44B2E182-DD85-45FC-9F51-326B81D7C7F1}" = Fax
"{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}" = Bonjour
"{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply
"{4D243BA7-9AC4-46D1-90E5-EEB88974F501}" = Microsoft Games for Windows - LIVE
"{4D87DC92-C328-46EC-A7B4-9C88129DC696}" = Dead Space™
"{4F0C7CCF-5666-474B-B02E-AC514A95EC93}" = NVIDIA GAME System Software 2.8.1
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{5721A8EA-A30F-4F66-9046-3F40C43AE1DC}" = Driver Detective
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.6
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67E158AF-8856-4337-B483-EA21930786AF}" = GameTap
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{6D6204C8-6B1D-4FBA-ADA9-CB6DFF9BF80D}" = America's Army Deploy Client
"{6F23C1A3-9F62-470C-BD12-B83F04E67865}" = SmartFTP Client
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{730837D4-FF5E-48DB-BA49-33E732DFF0B3}" = PanoStandAlone
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"{7D2370AC-D8E6-4996-986A-19824F8A167C}" = Logitech QuickCam
"{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
"{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01
"{8503C901-85D7-4262-88D2-8D8B2A7B08B8}" = Call of Duty® 4 - Modern Warfare™ 1.5 Patch
"{870B0889-A92E-4230-A6A1-F739C1D140DD}" = Opera 9.25
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8865B208-4759-4308-8DB5-3C18D2F568E2}" = CrazyTalk for Skype
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty® 4 - Modern Warfare™ 1.6 Patch
"{8AB8D458-939E-403F-0097-9BA1C1F013D5}" = The Sims 2
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty® 4 - Modern Warfare™ 1.7 Patch
"{9322A850-9091-4D0E-B252-3E82EDA3D94A}" = Prototype™
"{93F54611-2701-454e-94AB-623F458D9E6B}" = DeviceDiscovery
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{949DBB22-2FB7-4de1-804C-23D495A988D8}" = CuteFTP 8 Home
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9DF0196F-B6B8-4C3A-8790-DE42AA530101}" = SPORE™
"{9E478F3F-7A7B-42C5-BE9C-40FC0E07665F}" = The Awakened
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A129D1F2-CAC4-4AD7-B26D-3C6411B87DCC}" = Psychonauts
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A7A34FC9-DF24-4A36-00AD-D4EFE94CC116}" = SimCity 4 Deluxe
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A81100000003}" = Adobe Reader 8.1.1
"{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver
"{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant
"{AEDBD563-24BB-4EE3-8366-A654DAC2D988}" = Mirror's Edge™
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
"{B041ABD7-4A10-482a-A525-577A7AAD8EC7}" = C6200_Help
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B300CF23-C754-4888-84DD-7AF097F06E05}" = HuxleyLite
"{B34E4B72-37C6-4f79-A5B3-008EEFC6EA8B}" = PS_AIO_02_Software_min
"{B44529FF-501E-47CD-A06D-223C161BE058}" = FinePixViewer Resource
"{B46AC30C-22D2-4610-B041-1DA7BB29EB57}" = HP Photosmart All-In-One Software 9.0
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B7E5D642-E74E-40a4-B5C7-6AB6EE916814}" = PS_AIO_02_ProductContext
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BC10649A-983B-494e-AD1F-DE0BF717D701}" = PS_AIO_02_Software
"{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter
"{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C06A7DAC-1708-417C-B694-28C84DFE2DF9}" = The Movies™ Stunts & Effects
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3B3AB03-8ABC-46CF-8CA9-DB5581E1F368}" = FinePix Studio
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty® 4 - Modern Warfare™
"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
"{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator
"{ECCA8FE7-767A-4C8A-9DAA-BAB60F877C41}" = Sins of a Solar Empire
"{EE4ACABF-531E-419A-9225-B8E0FA4955AF}" = Zune Language Pack (ES)
"{EE5B8E34-973C-4FBE-AC83-99F064009FC7}" = SpyHunter
"{EF6C4600-306D-4F6A-A119-C2A877D25B4A}" = iTunes
"{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager
"{F11ADC64-C89E-47F4-A0B3-3665FF859397}" = World in Conflict
"{F138762F-5A1F-4CF0-A5E1-1588EF6088A4}" = The Witcher Enhanced Edition
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F2835483-37F2-4123-B4FE-0E77D58447F2}" = Far Cry 2
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
"{F73459A3-36B8-42e4-A982-AAF06A44D508}" = C6200_doccd
"{F8BA8B13-856D-4DFB-A28F-7EC868142453}" = Super Ad Blocker
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status
"{FE54D686-ACC0-42db-A46B-987A5B6D8325}" = C6200
"{FF70513F-E3A7-402F-84FB-B7810A064BE2}" = Zune
"Acoustica Effects Pack" = Acoustica Effects Pack
"Acoustica Mixcraft 3.1" = Acoustica Mixcraft 3.1
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"aignesamdeadlink_is1" = AM-DeadLink 2.8.1
"AIM_6" = AIM 6
"AMP WinOFF" = AMP WinOFF
"Aquarius Soft PC Alarm Clock Professional" = Aquarius Soft PC Alarm Clock Professional
"AVG8Uninstall" = AVG Free 8.5
"AVI Codec Pack" = AVI Codec Pack
"Bink and Smacker" = Bink and Smacker
"BroadJump Client Foundation" = BroadJump Client Foundation
"CCleaner" = CCleaner (remove only)
"Conflict-2142 Map Installer 1.2.1" = Conflict-2142 Map Installer 1.2.1
"Diner Dash 2_is1" = Diner Dash 2
"Diner Dash Flo On The Go_is1" = Diner Dash Flo On The Go
"Diner Dash_is1" = Diner Dash
"DirectVobSub" = DirectVobSub (remove only)
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"ERUNT_is1" = ERUNT 1.1j
"ESET Online Scanner" = ESET Online Scanner v3
"ffdshow_is1" = ffdshow [rev 1723] [2007-12-24]
"FLVPlayer" = FLV Player 1.3.3
"Fraps" = Fraps
"HammerHead Rhythm Station" = HammerHead Rhythm Station
"Hidden Secrets The Nightmare_is1" = Hidden Secrets The Nightmare
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 9.0
"HP Photosmart Essential" = HP Photosmart Essential 2.01
"HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0
"HPOCR" = HP OCR Software 9.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{0556F885-2415-4666-B53E-33727E46AEA1}" = The Movies™ Stunts & Effects
"InstallShield_{1632FD86-1BA4-4FC4-8B25-A8C655D63F68}" = Sid Meier's Pirates!
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty® 4 - Modern Warfare™ 1.4 Patch
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"InstallShield_{8503C901-85D7-4262-88D2-8D8B2A7B08B8}" = Call of Duty® 4 - Modern Warfare™ 1.5 Multiplayer Patch
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty® 4 - Modern Warfare™ 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty® 4 - Modern Warfare™ 1.7 Patch
"InstallShield_{9322A850-9091-4D0E-B252-3E82EDA3D94A}" = Prototype™
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty® 4 - Modern Warfare™
"InstallShield_{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager
"IsoBuster_is1" = IsoBuster 2.1
"Magic ISO Maker v5.3 (build 0221)" = Magic ISO Maker v5.3 (build 0221)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Media Player - Codec Pack" = Media Player Codec Pack 3.1.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Mozilla Firefox (3.0.11)" = Mozilla Firefox (3.0.11)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MySpaceIM" = MySpaceIM
"Mystery Case Files - Huntsville" = Mystery Case Files - Huntsville (remove only)
"Mystery Case Files - Prime Suspects" = Mystery Case Files - Prime Suspects (remove only)
"Natural Mod" = Natural Mod
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OggDS" = Direct Show Ogg Vorbis Filter (remove only)
"OneTouch Version 3.0" = OneTouch Version 3.0
"OpenAL" = OpenAL
"PaperPort 7.01" = PaperPort 7.01
"PunkBusterSvc" = PunkBuster Services
"QcDrv" = Logitech® Camera Driver
"RealPlayer 6.0" = RealPlayer
"RivaTuner" = RivaTuner v2.08
"SBC.MCCInstall" = AT&T Self Support Tool
"Sins of a Solar Empire" = Sins of a Solar Empire
"Sins of a Solar Empirev1.15" = Sins of a Solar Empire
"SmartFTP Client 3.0 Setup Files" = SmartFTP Client 3.0 Setup Files (remove only)
"SpeedFan" = SpeedFan (remove only)
"SpywareBlaster_is1" = SpywareBlaster 4.1
"ST6UNST #1" = Hero Editor V0.95
"Steam App 1500" = Darwinia
"Steam App 500" = Left 4 Dead
"SystemRequirementsLab" = System Requirements Lab
"Task Killer" = Task Killer (remove only)
"Total Video Player 1.03_is1" = Total Video Player 1.03
"TVersity Codec Pack" = TVersity Codec Pack 1.2
"TVersity Media Server " = TVersity Media Server 1.0.0.11 RC7
"UltraISO_is1" = UltraISO Premium V8.63
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VideoLAN VLC media player 0.8.6c
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WIC" = Windows Imaging Component
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinMount3_is1" = WinMount V3.1.1219
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xbox_360_CC_Driver" = Xbox 360 Controller for Windows
"Xfire" = Xfire (remove only)
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XviD MPEG4 Video Codec v1.1.2" = XviD MPEG4 Video Codec v1.1.2 (remove only)
"Xvid_is1" = Xvid 1.1.3 final uninstall
"Yahoo! Applications" = AT&T Yahoo! Applications
"Yahoo! Toolbar" = Yahoo! Toolbar
"Zune" = Zune

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"2a4f70b48f669acd" = AA3Deploy
"Octoshape Streaming Services" = Octoshape Streaming Services
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/11/2009 9:01:42 PM | Computer Name = JOHN | Source = Application Error | ID = 1000
Description = Faulting application xfire.exe, version 1.0.0.13133, faulting module
msvcr71.dll, version 7.10.3052.4, fault address 0x00002f30.

Error - 6/11/2009 10:26:31 PM | Computer Name = JOHN | Source = MsiInstaller | ID = 1013
Description = Product: NVIDIA PhysX -- Installation terminated

Error - 6/13/2009 11:46:22 AM | Computer Name = JOHN | Source = Application Error | ID = 1000
Description = Faulting application xfire.exe, version 1.0.0.13133, faulting module
msvcr71.dll, version 7.10.3052.4, fault address 0x00002f30.

Error - 6/13/2009 6:47:09 PM | Computer Name = JOHN | Source = Application Error | ID = 1000
Description = Faulting application xfire.exe, version 1.0.0.13133, faulting module
msvcr71.dll, version 7.10.3052.4, fault address 0x00002f30.

Error - 6/15/2009 5:10:48 PM | Computer Name = JOHN | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 sysrestorepoint.exe, P2 1.3.0.0, P3 485da791,
P4 sysrestorepoint, P5 1.3.0.0, P6 485da791, P7 d, P8 ca, P9 system.invalidoperationexception,
P10 NIL.

Error - 6/15/2009 5:10:58 PM | Computer Name = JOHN | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 sysrestorepoint.exe, P2 1.3.0.0, P3 485da791,
P4 sysrestorepoint, P5 1.3.0.0, P6 485da791, P7 d, P8 ca, P9 system.invalidoperationexception,
P10 NIL.

Error - 6/15/2009 6:08:19 PM | Computer Name = JOHN | Source = Application Hang | ID = 1002
Description = Hanging application Rooter.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 6/15/2009 6:08:23 PM | Computer Name = JOHN | Source = Application Hang | ID = 1001
Description = Fault bucket 495547216.

Error - 6/15/2009 6:08:45 PM | Computer Name = JOHN | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 sysrestorepoint.exe, P2 1.3.0.0, P3 485da791,
P4 sysrestorepoint, P5 1.3.0.0, P6 485da791, P7 d, P8 ca, P9 system.invalidoperationexception,
P10 NIL.

Error - 6/15/2009 6:08:56 PM | Computer Name = JOHN | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 sysrestorepointooooo.exe, P2 1.3.0.0, P3 485da791,
P4 sysrestorepoint, P5 1.3.0.0, P6 485da791, P7 d, P8 ca, P9 system.invalidoperationexception,
P10 NIL.

[ System Events ]
Error - 6/15/2009 6:06:03 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7034
Description = The nTune Service service terminated unexpectedly. It has done this
1 time(s).

Error - 6/15/2009 6:06:06 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7031
Description = The .NET Runtime Optimization Service v2.0.50727_X86 service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 60000 milliseconds: Restart the service.

Error - 6/15/2009 6:06:08 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7034
Description = The Process Monitor service terminated unexpectedly. It has done
this 1 time(s).

Error - 6/15/2009 6:06:12 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7031
Description = The Zune Network Sharing Service service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in 0
milliseconds: Restart the service.

Error - 6/15/2009 6:06:13 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7031
Description = The Zune Bus Enumerator service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 0 milliseconds:
Restart the service.

Error - 6/15/2009 6:06:14 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7031
Description = The Zune Network Sharing Service service terminated unexpectedly.
It has done this 2 time(s). The following corrective action will be taken in 0
milliseconds: Restart the service.

Error - 6/15/2009 6:06:15 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7031
Description = The Zune Bus Enumerator service terminated unexpectedly. It has done
this 2 time(s). The following corrective action will be taken in 0 milliseconds:
Restart the service.

Error - 6/15/2009 6:06:16 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7034
Description = The Zune Network Sharing Service service terminated unexpectedly.
It has done this 3 time(s).

Error - 6/15/2009 6:06:17 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7034
Description = The Zune Bus Enumerator service terminated unexpectedly. It has done
this 3 time(s).

Error - 6/15/2009 6:06:18 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7034
Description = The Viewpoint Manager Service service terminated unexpectedly. It
has done this 1 time(s).


< End of report >


This post has been edited by jaysee: Jun 16 2009, 11:10 PM
Go to the top of the page
 
+Quote Post
Transience
post Jun 15 2009, 07:23 PM
Post #4


Unofficial Music Guru
Group Icon
Posts: 2,354
From: Massachusetts, USA
OS: Vista



Hi jaysee -

I see you're using or have in the past used p2p software such as uTorrent. Although p2p programs are not usually malware in their own right, oftentimes malware is installed alongside them. Even if the program is clean, people often upload infected files to be shared using these programs, and it is very easy to end up compromising your PC. It's your decision about whether or not you use p2p programs, you don't have to remove them to be deemed clean and I'll still give you help if you want to keep them. It's just important that you're aware of the risks. If you want to continue using p2p programs that's fine with me, all I ask is that you not download anything from them until you're clean so we aren't taking steps backwards here. To remove p2p programs if you wish to do so, uninstall them from the Add/Remove Programs (it's Programs and Features in Vista) menu of your Control Panel.

Please go to Add/Remove Programs in your Control Panel (Programs and Features if you are a Vista user). Select and remove the following if present, don't worry if they aren't:

Viewpoint Media Player - Viewpoint is an annoying media player that installs alongside many different things without your permission, not a good idea to keep it on your computer.

Next

OTL Fixes
  • Please double click on OTL to run it
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    CODE
    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090123.1
    FF - prefs.js..extensions.enabledItems: {3414F358-CBBD-4215-8320-ABAECC12AC25}:1.0
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2007/07/28 21:42:25 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O33 - MountPoints2\{aa9a245e-2b88-11de-9032-00142a7c704f}\Shell - "" = AutoRun
    O33 - MountPoints2\{aa9a245e-2b88-11de-9032-00142a7c704f}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{aa9a245e-2b88-11de-9032-00142a7c704f}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found
    O33 - MountPoints2\{b6b3b553-3d36-11dc-a3af-806d6172696f}\Shell - "" = AutoRun
    O33 - MountPoints2\{b6b3b553-3d36-11dc-a3af-806d6172696f}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{b6b3b553-3d36-11dc-a3af-806d6172696f}\Shell\AutoRun\command - "" = E:\FrameworkCheck.exe -- File not found
    O33 - MountPoints2\G\Shell - "" = AutoRun
    O33 - MountPoints2\G\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found

    :Files
    C:\DOCUMENTS AND SETTINGS\JOHN CHRISTIAN\LOCAL SETTINGS\APPLICATION DATA\{3414F358-CBBD-4215-8320-ABAECC12AC25}
    C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
    C:\WINDOWS\System32\tupigovi
    C:\Documents and Settings\All Users\Application Data\93338746.ini
    C:\Documents and Settings\All Users\Application Data\93338746
    C:\Documents and Settings\All Users\Application Data\13328754
    C:\WINDOWS\System32\d3d9caps.dat
    C:\WINDOWS\System32\d3d8caps.dat
    C:\WINDOWS\SxsCaPendDel

    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Then post a new OTL2 log.

Just need the fresh OTL log in your next reply.
Go to the top of the page
 
+Quote Post
jaysee
post Jun 16 2009, 08:39 PM
Post #5


Member
**
Posts: 25
OS: XP Pro



Uninstalled utorrent, and also Viewpoint Media Player. I didn't know if I was suppose to try or not, but Yahoo.com searches are still being redirected to spam, or fake search engines.

QUOTE
OTL logfile created on: 6/16/2009 10:49:24 PM - Run 2
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\John Christian\Desktop\Misc Desktops\AntiVirusAd
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.50 Gb Available Physical Memory | 75.00% Memory free
3.85 Gb Paging File | 3.48 Gb Available in Paging File | 90.50% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 279.46 Gb Total Space | 34.46 Gb Free Space | 12.33% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 30.68 Gb Free Space | 6.59% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JOHN
Current User Name: John Christian
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\TVersity\Media Server\MediaServer.exe ()
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Documents and Settings\John Christian\Desktop\Misc Desktops\AntiVirusAd\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe LM Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqcxs08 [Disabled | Stopped]) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc [Disabled | Stopped]) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (HPSLPSVC [Disabled | Stopped]) -- C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL (Hewlett-Packard Co.)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Stopped]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Stopped]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Stopped]) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LVPrcSrv [Auto | Stopped]) -- c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVSrvLauncher [Auto | Stopped]) -- C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (Net Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (npggsvc [On_Demand | Stopped]) -- C:\WINDOWS\system32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (nTuneService [Auto | Stopped]) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
SRV - (NVSvc [Auto | Stopped]) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (Pml Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)
SRV - (PnkBstrA [Auto | Stopped]) -- C:\WINDOWS\system32\PnkBstrA.exe ()
SRV - (PnkBstrB [Auto | Stopped]) -- C:\WINDOWS\system32\PnkBstrB.exe ()
SRV - (ProtexisLicensing [Auto | Stopped]) -- C:\WINDOWS\system32\PSIService.exe ()
SRV - (SABSVC [Auto | Stopped]) -- C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE (SuperAdBlocker.com)
SRV - (Symantec Core LC [On_Demand | Stopped]) -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation)
SRV - (TVersityMediaServer [Auto | Running]) -- C:\Program Files\TVersity\Media Server\MediaServer.exe ()
SRV - (usnjsvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WLSetupSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [Auto | Running]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (ZuneBusEnum [Auto | Stopped]) -- c:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc [Auto | Stopped]) -- c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc [On_Demand | Stopped]) -- c:\WINDOWS\system32\ZuneWlanCfgSvc.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (atksgt [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\atksgt.sys ()
DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (ENTECH [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ENTECH.sys (EnTech Taiwan)
DRV - (FETNDIS [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\fetnd5.sys (VIA Technologies, Inc. )
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (giveio [Boot | Running]) -- C:\WINDOWS\system32\giveio.sys ()
DRV - (L8042Kbd [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys (Logitech, Inc.)
DRV - (L8042mou [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\L8042mou.sys (Logitech, Inc.)
DRV - (Lbd [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (LHidKe [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\LHidKE.Sys (Logitech, Inc.)
DRV - (LHidUsbK [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\LHidUsbK.Sys (Logitech, Inc.)
DRV - (lirsgt [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\lirsgt.sys ()
DRV - (LMouKE [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\LMouKE.sys (Logitech, Inc.)
DRV - (LVcKap [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\LVcKap.sys ()
DRV - (LVMVDrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\LVMVDrv.sys (Logitech Inc.)
DRV - (LVPr2Mon [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys ()
DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (NVR0Dev [On_Demand | Running]) -- C:\WINDOWS\nvoclock.sys (NVidia Corp.)
DRV - (pfc [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (PhilCam8116 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\CamDrO21.sys (Microsoft Corporation)
DRV - (ppsio2 [Auto | Running]) -- C:\WINDOWS\System32\drivers\ppsio2.sys ()
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (RivaTuner32 [On_Demand | Stopped]) -- D:\Program Files\RivaTuner v2.08\RivaTuner32.sys ()
DRV - (RTL8023xp [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (rtl8139 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (SABDIFSV [System | Stopped]) -- C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABDIFSV.SYS ()
DRV - (SABKUTIL [System | Running]) -- C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys ()
DRV - (SABProcEnum [On_Demand | Stopped]) -- C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABProcEnum.sys (SuperAdBlocker.com)
DRV - (SASDIFSV [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Stopped]) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (speedfan [Boot | Running]) -- C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (sptd [Boot | Running]) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (StillCam [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (Tcpip6 [System | Running]) -- C:\WINDOWS\system32\DRIVERS\tcpip6.sys (Microsoft Corporation)
DRV - (usbaudio [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (VIAudio [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\vinyl97.sys (VIA Technologies, Inc.)
DRV - (ViBus [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ViBus.sys (VIA Technologies, Inc.)
DRV - (videX32 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\videX32.sys (VIA Technologies, Inc.)
DRV - (ViPrt [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ViPrt.sys (VIA Technologies, Inc.)
DRV - (WMDrive [Auto | Running]) -- C:\WINDOWS\system32\drivers\WMDrive.sys ()
DRV - (X4HSX32 [Auto | Running]) -- C:\Program Files\GameTap\bin\Release\X4HSX32.Sys (Exent Technologies Ltd.)
DRV - (xnacc [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\xnacc.sys (Microsoft Corporation)
DRV - (zumbus [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\zumbus.sys (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p="
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: {1d5287d1-8a92-0001-1f31-1cec198018d8}:2.1.0.7
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.10
FF - prefs.js..extensions.enabledItems: iaplayer@instantaction.com:0.3.4.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.07061050
FF - prefs.js..extensions.enabledItems: {46868735-c3fa-47ce-8ce7-cce51a66aceb}:1.2
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:3.0.0
FF - prefs.js..extensions.enabledItems: en-US@dictionaries.addons.mozilla.org:3.0.3
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11

FF - HKLM\software\mozilla\Firefox\Extensions\\{3414F358-CBBD-4215-8320-ABAECC12AC25}: C:\DOCUMENTS AND SETTINGS\JOHN CHRISTIAN\LOCAL SETTINGS\APPLICATION DATA\{3414F358-CBBD-4215-8320-ABAECC12AC25}\
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX [2009/05/04 14:00:08 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{1d5287d1-8a92-0001-1f31-1cec198018d8}: C:\PROGRAM FILES\AVG\AVG8\TOOLBARFF [2009/05/04 14:00:09 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/05/23 19:42:24 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/06/14 17:07:04 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/06/16 14:47:13 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/06/16 22:27:35 | 00,000,000 | ---D | M]

[2008/06/27 07:34:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Extensions
[2008/06/27 07:34:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/06/16 22:23:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions
[2009/04/23 19:19:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2008/06/27 08:11:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{46868735-c3fa-47ce-8ce7-cce51a66aceb}
[2008/02/01 12:50:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2007/08/07 01:12:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2008/06/30 10:35:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
[2008/06/27 07:48:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\en-US@dictionaries.addons.mozilla.org
[2008/01/31 20:30:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\iaplayer@instantaction.com
[2007/09/12 03:29:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\0c457zba.default\extensions\moveplayer@movenetworks.com
[2008/05/08 00:35:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\sp82nxrc.JC01\extensions
[2008/02/01 12:40:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\sp82nxrc.JC01\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2008/05/08 00:35:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\John Christian\Application Data\mozilla\Firefox\Profiles\sp82nxrc.JC01\extensions\{991A772A-BA13-4c1d-A9EF-F897F31DEC7D}
[2008/12/12 14:23:54 | 00,002,158 | ---- | M] () -- C:\Documents and Settings\John Christian\Application Data\Mozilla\FireFox\Profiles\0c457zba.default\searchplugins\MySpace.xml
[2009/06/16 14:57:25 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/06/12 00:16:16 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/11/04 18:06:45 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2009/06/14 17:07:44 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2009/06/12 00:16:10 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/06/12 00:16:10 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2004/05/07 15:31:40 | 00,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\components\MSVCR71.DLL
[2006/11/07 12:58:44 | 00,139,264 | ---- | M] () -- C:\Program Files\mozilla firefox\components\SABFF20.DLL
[2009/05/11 22:01:14 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/05/11 22:01:14 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/05/11 22:01:14 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/05/11 22:01:14 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/05/11 22:01:14 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/05/11 22:01:14 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/05/11 22:01:14 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (786 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG Technologies CZ, s.r.o.)
O3 - HKLM\..\Toolbar: (Super Ad Blocker Toolbar) - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\sabtb.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG Technologies CZ, s.r.o.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKCU..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear (NVIDIA)
O4 - Startup: C:\Documents and Settings\John Christian\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 157
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 26 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SABWinLogon: DllName - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL (SuperAdBlocker.com)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000D7} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSEHB.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/06/15 18:35:15 | 00,000,000 | ---D | M]
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[2009/06/16 22:18:50 | 00,000,000 | ---D | C] -- C:\_OTL
[2009/06/15 18:07:21 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/06/15 17:12:01 | 00,000,767 | ---- | C] () -- C:\Documents and Settings\John Christian\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/06/15 17:11:52 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/06/15 16:40:15 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/06/15 16:29:12 | 00,001,720 | ---- | C] () -- C:\WINDOWS\System32\tmp.reg
[2009/06/15 16:28:21 | 00,289,144 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\VCCLSID.exe
[2009/06/15 16:28:21 | 00,288,417 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\SrchSTS.exe
[2009/06/15 16:28:21 | 00,135,168 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swreg.exe
[2009/06/15 16:28:21 | 00,087,552 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\VACFix.exe
[2009/06/15 16:28:21 | 00,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.exe
[2009/06/15 16:28:21 | 00,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.C.exe
[2009/06/15 16:28:21 | 00,082,432 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\404Fix.exe
[2009/06/15 16:28:21 | 00,080,384 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\o4Patch.exe
[2009/06/15 16:28:21 | 00,079,360 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swxcacls.exe
[2009/06/15 16:28:21 | 00,078,336 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\Agent.OMZ.Fix.exe
[2009/06/15 16:28:21 | 00,075,776 | ---- | C] () -- C:\WINDOWS\System32\WS2Fix.exe
[2009/06/15 16:28:21 | 00,053,248 | ---- | C] (http://www.beyondlogic.org) -- C:\WINDOWS\System32\Process.exe
[2009/06/15 16:28:21 | 00,051,200 | ---- | C] () -- C:\WINDOWS\System32\dumphive.exe
[2009/06/15 16:28:21 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\swsc.exe
[2009/06/15 13:41:50 | 00,981,586 | ---- | C] () -- C:\Documents and Settings\John Christian\My Documents\cc_20090615_134143.reg
[2009/06/14 23:02:31 | 01,615,732 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\ProcessExplorer.zip
[2009/06/14 20:42:02 | 00,000,000 | ---D | C] -- C:\Program Files\ESET
[2009/06/14 19:58:14 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/06/14 19:58:14 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/06/14 19:58:14 | 00,155,136 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2009/06/14 19:58:14 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/06/14 19:58:14 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/06/14 19:58:14 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/06/14 19:58:14 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/06/14 19:58:14 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/06/14 19:57:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/06/14 19:57:29 | 00,000,000 | --SD | C] -- C:\ComboFix
[2009/06/14 19:57:24 | 00,389,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF1521.exe
[2009/06/14 19:56:19 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/06/14 17:06:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2009/06/12 14:10:30 | 04,613,370 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\heartbeats.mp3
[2009/06/11 22:26:13 | 00,215,383 | ---- | C] () -- C:\WINDOWS\System32\nvapps.xml
[2009/06/11 22:26:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\nview
[2009/06/11 16:59:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\John Christian\My Documents\Prototype
[2009/06/11 04:14:24 | 00,000,803 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Prototype™.lnk
[2009/06/10 03:01:00 | 00,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieproxy.dll
[2009/06/10 03:01:00 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpshims.dll
[2009/06/08 21:17:31 | 03,099,494 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\boss.bmp
[2009/06/05 21:02:27 | 00,000,000 | ---D | C] -- C:\Program Files\Realtek AC97
[2009/06/05 20:59:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/06/05 20:58:58 | 00,000,000 | ---D | C] -- C:\Program Files\PC Drivers HeadQuarters
[2009/06/05 17:30:08 | 00,001,407 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\i j j i.lnk
[2009/06/05 17:30:03 | 00,000,000 | ---D | C] -- C:\ijji
[2009/06/05 17:30:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\John Christian\Application Data\ijjigame
[2009/06/05 17:29:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ijjigame
[2009/06/05 17:06:13 | 00,710,064 | ---- | C] (NHN USA) -- C:\WINDOWS\System32\ijjiSetup.exe
[2009/06/05 17:06:13 | 00,157,152 | ---- | C] (NHN Corporation) -- C:\WINDOWS\System32\PubPlugin.dll
[2009/06/05 17:06:13 | 00,058,800 | ---- | C] (NHN USA Inc.) -- C:\WINDOWS\System32\ijjiProcessRestarter.exe
[2009/06/05 17:06:13 | 00,058,800 | ---- | C] (NHN USA Corp.) -- C:\WINDOWS\System32\ijjiPlugin2.dll
[2009/06/05 17:06:13 | 00,000,000 | ---D | C] -- C:\Program Files\NHN USA
[2009/06/05 15:22:40 | 00,001,341 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Huxley Lite.lnk
[2009/06/05 15:22:40 | 00,000,000 | ---D | C] -- C:\Program Files\HuxleyLite
[2009/06/05 03:17:47 | 21,148,51485 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\Huxley_Lite_Setup.zip
[2009/06/03 23:48:43 | 00,000,854 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\The Sims 3.lnk
[2009/06/03 23:26:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
[2009/06/03 23:26:23 | 00,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2009/06/03 23:25:34 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ZoneLabs
[2009/05/25 18:27:25 | 31,796,401 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\169_sc2_cs_pc2_101108_hr.mp4
[2009/05/24 22:40:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\John Christian\Application Data\Games
[2009/05/23 22:29:17 | 00,000,000 | ---D | C] -- C:\Program Files\USArmy
[2009/05/23 20:36:21 | 01,089,593 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/05/23 19:44:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AA3DeployClient
[2009/05/23 19:44:26 | 00,000,308 | ---- | C] () -- C:\Documents and Settings\John Christian\Desktop\AA3Deploy.appref-ms
[2009/05/21 18:51:48 | 00,041,808 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll
[2009/05/19 18:27:38 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft WSE
[2009/04/22 00:19:06 | 00,172,173 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2009/03/27 10:03:00 | 01,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2009/03/27 10:03:00 | 01,503,232 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2009/03/27 10:03:00 | 01,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2009/03/27 10:03:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2009/02/17 15:13:08 | 00,037,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\WMDrive.sys
[2009/02/07 01:33:58 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2008/12/19 02:52:42 | 00,000,061 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2008/11/10 02:26:10 | 00,000,004 | ---- | C] () -- C:\WINDOWS\System32\microday08.dll
[2008/11/10 02:26:07 | 00,000,070 | ---- | C] () -- C:\WINDOWS\System32\mypath0079.dll
[2008/11/10 02:26:07 | 00,000,034 | ---- | C] () -- C:\WINDOWS\System32\MTX0CI.dll
[2008/11/06 12:37:32 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/11/06 12:34:00 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2008/11/06 12:34:00 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2008/11/06 12:33:02 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/11/05 17:29:30 | 00,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys
[2008/10/07 10:13:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/08/21 15:05:01 | 00,000,056 | ---- | C] () -- C:\WINDOWS\kgt2k.INI
[2008/07/03 19:57:29 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2008/07/03 16:32:59 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2008/07/03 16:32:59 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2008/07/03 16:32:59 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2008/06/05 08:58:26 | 00,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008/04/10 12:52:08 | 00,662,016 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008/04/10 12:52:06 | 03,104,256 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2008/04/10 12:52:06 | 00,520,192 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2008/04/10 12:52:06 | 00,404,992 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2008/04/10 12:52:06 | 00,397,312 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
[2008/04/10 12:52:06 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll
[2008/04/10 12:52:06 | 00,167,936 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
[2008/04/10 12:52:06 | 00,143,360 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
[2008/04/10 12:52:06 | 00,135,168 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
[2008/04/10 12:52:06 | 00,122,880 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2008/04/10 12:52:06 | 00,118,784 | ---- | C] () -- C:\WINDOWS\System32\ff_realaac.dll
[2008/04/10 12:52:06 | 00,102,912 | ---- | C] () -- C:\WINDOWS\System32\ff_tremor.dll
[2008/04/10 12:52:06 | 00,054,784 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
[2008/04/10 12:52:06 | 00,038,400 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
[2008/04/10 12:52:06 | 00,026,624 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2008/04/10 12:50:40 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008/03/29 11:42:22 | 00,245,248 | ---- | C] () -- C:\WINDOWS\System32\dxr.dll
[2008/03/29 11:42:20 | 00,159,744 | ---- | C] () -- C:\WINDOWS\System32\mmfinfo.dll
[2008/03/29 11:42:14 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\avss.dll
[2008/03/29 11:42:08 | 00,148,992 | ---- | C] () -- C:\WINDOWS\System32\mkx.dll
[2008/03/29 11:42:04 | 00,141,312 | ---- | C] () -- C:\WINDOWS\System32\mp4.dll
[2008/03/29 11:42:04 | 00,108,032 | ---- | C] () -- C:\WINDOWS\System32\avi.dll
[2008/03/29 11:42:02 | 00,120,832 | ---- | C] () -- C:\WINDOWS\System32\ogm.dll
[2008/03/29 11:42:00 | 00,163,840 | ---- | C] () -- C:\WINDOWS\System32\ts.dll
[2008/03/29 11:41:54 | 00,097,280 | ---- | C] () -- C:\WINDOWS\System32\avs.dll
[2008/03/29 11:41:52 | 00,079,360 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll
[2008/03/29 11:41:52 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll
[2008/03/14 02:53:39 | 00,000,004 | ---- | C] () -- C:\WINDOWS\info147.sys
[2008/01/23 02:39:12 | 00,215,144 | ---- | C] () -- C:\WINDOWS\patchw32.dll
[2007/12/31 20:00:00 | 00,741,376 | ---- | C] () -- C:\WINDOWS\System32\audxlib.dll
[2007/12/31 20:00:00 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2007/12/31 20:00:00 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\ff_kernelDeint.dll
[2007/12/08 04:28:38 | 00,000,023 | ---- | C] () -- C:\WINDOWS\BlendSettings.ini
[2007/12/01 01:40:08 | 00,279,712 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2007/12/01 01:40:07 | 00,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2007/11/18 22:56:06 | 00,000,319 | ---- | C] () -- C:\WINDOWS\game.ini
[2007/10/13 05:30:20 | 00,000,137 | ---- | C] () -- C:\WINDOWS\System32\Registration.ini
[2007/10/01 23:37:38 | 00,032,768 | ---- | C] () -- C:\WINDOWS\System32\mf.dll
[2007/10/01 20:25:17 | 00,034,308 | ---- | C] () -- C:\WINDOWS\System32\bassmod.dll
[2007/08/27 19:51:31 | 00,000,077 | ---- | C] () -- C:\WINDOWS\mydebug.ini
[2007/08/27 19:31:47 | 00,023,200 | ---- | C] () -- C:\WINDOWS\System32\drivers\ppsio2.sys
[2007/08/27 19:30:46 | 00,001,020 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2007/08/27 19:30:46 | 00,000,090 | ---- | C] () -- C:\WINDOWS\calera.ini
[2007/08/27 19:30:39 | 00,269,312 | ---- | C] () -- C:\WINDOWS\System32\FPXIG.DLL
[2007/08/27 19:30:39 | 00,068,096 | ---- | C] () -- C:\WINDOWS\System32\IGFPX32P.DLL
[2007/08/27 19:30:39 | 00,065,024 | ---- | C] () -- C:\WINDOWS\System32\JPEGACC.DLL
[2007/08/27 19:30:27 | 00,101,376 | ---- | C] () -- C:\WINDOWS\System32\WELSOF32.DLL
[2007/08/10 10:13:09 | 00,138,920 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/08/03 00:09:08 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2007/07/29 17:43:52 | 00,685,816 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2007/07/28 22:58:45 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\YCRWin32.dll
[2007/06/28 14:54:10 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007/03/12 12:01:30 | 00,217,088 | ---- | C] () -- C:\WINDOWS\NVGfxOgl.dll
[2007/02/06 17:45:04 | 00,025,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/02/06 17:42:40 | 01,691,808 | ---- | C] () -- C:\WINDOWS\System32\drivers\Lvckap.sys
[2004/08/04 08:00:00 | 00,000,651 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/04 08:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\SYSTEM.INI
[2003/04/05 13:47:42 | 00,147,456 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2002/05/15 20:38:40 | 00,091,136 | ---- | C] () -- C:\WINDOWS\System32\mp4fil32.dll
[2002/05/04 10:19:00 | 00,049,152 | ---- | C] () -- C:\WINDOWS\System32\avisynthEx.dll
[1996/04/03 15:33:26 | 00,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys

========== Files - Modified Within 30 Days ==========

[2009/06/16 22:47:56 | 00,215,383 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/06/16 22:47:23 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/06/16 22:47:11 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\John Christian\Local Settings\desktop.ini
[2009/06/16 22:46:58 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/06/16 22:46:53 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/06/16 22:27:57 | 00,008,192 | -HS- | M] () -- C:\WINDOWS\Thumbs.db
[2009/06/16 17:53:07 | 37,160,237 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/06/16 17:53:07 | 00,078,361 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/06/15 22:17:08 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/06/15 20:00:00 | 00,000,594 | ---- | M] () -- C:\WINDOWS\tasks\Norton Security Online - Run Full System Scan - John Christian.job
[2009/06/15 17:56:48 | 00,492,248 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/06/15 17:56:48 | 00,435,260 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/06/15 17:56:48 | 00,068,156 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/06/15 17:12:01 | 00,000,767 | ---- | M] () -- C:\Documents and Settings\John Christian\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/06/15 16:31:44 | 00,001,720 | ---- | M] () -- C:\WINDOWS\System32\tmp.reg
[2009/06/15 13:42:29 | 00,981,586 | ---- | M] () -- C:\Documents and Settings\John Christian\My Documents\cc_20090615_134143.reg
[2009/06/15 13:37:06 | 00,000,651 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/06/15 13:37:06 | 00,000,227 | ---- | M] () -- C:\WINDOWS\SYSTEM.INI
[2009/06/15 13:37:06 | 00,000,211 | -HS- | M] () -- C:\boot.ini
[2009/06/14 23:02:33 | 01,615,732 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\ProcessExplorer.zip
[2009/06/14 19:56:38 | 00,389,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF1521.exe
[2009/06/13 19:19:31 | 00,001,407 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\i j j i.lnk
[2009/06/12 14:20:54 | 04,613,370 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\heartbeats.mp3
[2009/06/11 04:14:24 | 00,000,803 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Prototype™.lnk
[2009/06/10 21:23:45 | 00,386,888 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/06/08 21:17:32 | 03,099,494 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\boss.bmp
[2009/06/08 08:10:10 | 00,155,136 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2009/06/05 15:22:40 | 00,001,341 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Huxley Lite.lnk
[2009/06/05 04:36:36 | 21,148,51485 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\Huxley_Lite_Setup.zip
[2009/06/03 23:48:43 | 00,000,854 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\The Sims 3.lnk
[2009/06/03 23:37:54 | 00,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat
[2009/06/02 11:17:27 | 00,075,776 | ---- | M] () -- C:\WINDOWS\System32\WS2Fix.exe
[2009/06/01 12:51:12 | 23,635,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/05/31 22:17:35 | 00,015,688 | ---- | M] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/05/26 17:31:26 | 00,058,800 | ---- | M] (NHN USA Inc.) -- C:\WINDOWS\System32\ijjiProcessRestarter.exe
[2009/05/26 13:20:08 | 00,040,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/26 13:19:56 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/25 18:30:24 | 31,796,401 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\169_sc2_cs_pc2_101108_hr.mp4
[2009/05/23 19:44:26 | 00,000,308 | ---- | M] () -- C:\Documents and Settings\John Christian\Desktop\AA3Deploy.appref-ms
[2009/05/21 18:51:48 | 00,041,808 | ---- | M] () -- C:\WINDOWS\System32\xfcodec.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 451 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >


This post has been edited by jaysee: Jun 16 2009, 08:56 PM
Go to the top of the page
 
+Quote Post
jaysee
post Jun 16 2009, 08:53 PM
Post #6


Member
**
Posts: 25
OS: XP Pro



*OTL added
Go to the top of the page
 
+Quote Post
Transience
post Jun 17 2009, 07:07 AM
Post #7


Unofficial Music Guru
Group Icon
Posts: 2,354
From: Massachusetts, USA
OS: Vista



Let's give this a try:

Please download GooredFix from one of the locations below and save it to your Desktop
  • Download Mirror #1
  • Download Mirror #2
  • Double-click GooredFix.exe to run it.
  • Select 1. Find Goored (no fix) by typing 1 and pressing Enter.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).
Note: Do not run Option #2 yet.

- Dave

This post has been edited by Transience: Jun 17 2009, 07:08 AM
Go to the top of the page
 
+Quote Post
jaysee
post Jun 17 2009, 12:23 PM
Post #8


Member
**
Posts: 25
OS: XP Pro



Noticed that when I try to pick a link after a Yahoo.com search, first it gives me a long address with my related search topic, where it starts off with a site like "affiliatesite.com" or "nanna.org", and then it has a "Redirect", finally bringing me to the spam/fake page, like that of Toseeka (which I see is a common page that these take you to). So if I look in the back/forward button arrow tab on Firefox, it goes through something like the following after clicking a link
QUOTE
test - Yahoo! Search Results ==> affiliatesite.com/result?blahblahblah ==> Redirect ==> Spam site



Here's the Goored log:

QUOTE
GooredFix v1.92 by jpshortstuff
Log created at 14:22 on 17/06/2009 running Option #1 (John Christian)
Firefox version 3.0.11 (en-US)

=====Suspect Goored Entries=====

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.11\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.11\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{1d5287d1-8a92-0001-1f31-1cec198018d8}"="C:\Program Files\AVG\AVG8\ToolbarFF"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG8\Firefox"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{3414F358-CBBD-4215-8320-ABAECC12AC25}"="C:\Documents and Settings\John Christian\Local Settings\Application Data\{3414F358-CBBD-4215-8320-ABAECC12AC25}\" (Folder Missing)


This post has been edited by jaysee: Jun 17 2009, 02:01 PM
Go to the top of the page
 
+Quote Post
Transience
post Jun 18 2009, 08:17 AM
Post #9


Unofficial Music Guru
Group Icon
Posts: 2,354
From: Massachusetts, USA
OS: Vista



1. OTMoveIt3

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    CODE
    :Processes
    explorer.exe

    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
    "{3414F358-CBBD-4215-8320-ABAECC12AC25}"=-

    :Commands
    [Purity]
    [EmptyTemp]
    [Start Explorer]
    [Reboot]

  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.

    Then:

    Please click on any of the links below to download Combofix. When you are asked to select the location of the file, please change the name of the file from ComboFix.exe to Combo-Fix.exe, and then save it to your desktop.

    Link 1
    Link 2
    Link 3





    Notes:
    • Before running ComboFix, you should disable all Antivirus, Anti-Spyware, and Firewall applications so they don't interfere with its running. You can often do this just by right-clicking on the system tray icon and clicking "Disable" or similar. If you need further instructions for how to disable your program specifically, look here.
    • ComboFix will temporarily disconnect your machine from the internet and change your clock settings, this is normal and both will be restored before the program terminates.
    • Do not attempt to run any programs or click on ComboFix's window while it is running, just allow it to proceed uninterrupted aside from okaying any prompts. It may appear to be doing nothing at times, this is normal, don't worry.
    Next:
    • Double click on ComboFix.exe and follow the prompts.
    • As part of its process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    • Follow the prompts to allow ComboFix to download and install the Recovery Console, and when prompted, agree to the End-User License Agreement to install it.
    * Note: If the Recovery Console is already installed on your computer, ComboFix will ignore the installation routines and continue its malware removal procedures.



    Once the Recovery Console is installed using ComboFix, you should see the following message:



    Click on Yes, to continue scanning. The program will then scan for malware and perform various fixes. You may be asked to reboot, okay the prompt and allow your computer to reboot. Log in as normal and allow ComboFix to complete its run without doing anything else.

    When it's finished, the program's log will appear in notepad as well as saving itself to C:\ComboFix.txt. Please include the full contents of the log in your next reply.
  • Close OTMoveIt3

Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, navigate to the open C:\_OTMoveIt\MovedFiles folder. Open the newest .log file present in notepad and post its contents in your next reply.

Just need the logs from OTMI and CF in your next reply.

Cheers,
Dave
Go to the top of the page
 
+Quote Post
jaysee
post Jun 21 2009, 07:15 PM
Post #10


Member
**
Posts: 25
OS: XP Pro



I can't download OTMoveit3. It gives me a "404 Not Found" error page when I try.

This post has been edited by jaysee: Jun 21 2009, 07:16 PM
Go to the top of the page
 
+Quote Post
Transience
post Jun 22 2009, 08:27 AM
Post #11


Unofficial Music Guru
Group Icon
Posts: 2,354
From: Massachusetts, USA
OS: Vista



That's my fault, link is outdated, sorry about that. Let's do it this way instead:

1. Registry Fixes

We're going to use a registry file to make the some changes to your registry. Please copy the complete contents of the box below to a new notepad file (Start > Programs > Accessories > Notepad). Ensure that the code in notepad looks exactly as it does in the box, with no blank lines before the first line of text. Please click on File > Save. In the Save as type: box click the drop-down menu and change the save as type to All files. Then please save the file to your desktop, naming it fix.reg (this name is important and should not be changed).

CODE
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{3414F358-CBBD-4215-8320-ABAECC12AC25}"=-


Then run ComboFix per these instructions:

2. ComboFix

Please download and save ComboFix from one of these locations:

Link 1 | Link 2 | Link 3

* It is very important that ComboFix is saved directly to your desktop.

Notes:
  • Before running ComboFix, you should disable all Antivirus and Antispyware applications so they don't interfere. You can often do this just by right-clicking on the system tray icon and clicking "Disable" or similar. If you need further instructions for how to disable your programs, look here.
  • ComboFix will temporarily disconnect your machine from the internet and change your clock settings, this is normal and both will be restored before the program terminates.
  • Do not attempt to run any programs or click on ComboFix's window while it is running, just allow it to run uninterrupted aside from okaying any prompts. It may appear to be doing nothing at times, this is normal, don't worry.
Next:
  • Double click on ComboFix.exe and follow the prompts.
  • As part of its process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a serious problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Recovery Console, and when prompted, agree to the End-User License Agreement to install it.
* Note: If the Recovery Console is already installed on your computer, ComboFix will ignore the installation routines and continue its malware removal procedures.



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware. The program will scan for malware and then perform various fixes. You may be asked to reboot, okay the prompt and allow your computer to reboot. Log in as normal and allow ComboFix to complete its run without doing anything else.

When it's finished, the program's log will appear in notepad and save itself to C:\ComboFix.txt. Please include the full contents of the log in your next reply.

Cheers,
Dave
Go to the top of the page
 
+Quote Post
jaysee
post Jun 22 2009, 11:42 AM
Post #12


Member
**
Posts: 25
OS: XP Pro



Okay, cool. I believe this fixed the problem. At least, I just tried a few random searches on Yahoo and none of the links I clicked on redirected me.

Real quick, just a couple things.
1. The unsecapp.exe process. Just out of curiousity, what causes it to start running? I've looked it up, and everyone says it's fine, but I've never had it running in my processes before until fairly recently (although long before this infection, as far as I'm aware).
2. Should I go ahead and change all my passwords to be on the safe side (email, general accounts, etc)?

Thanks for all the help thus far!


QUOTE
ComboFix 09-06-21.01 - John Christian 06/22/2009 13:13.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1546 [GMT -4:00]
Running from: c:\documents and settings\John Christian\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Manson
c:\temp\1cb
c:\windows\Downloaded Program Files\PurpleBean.exe
c:\windows\system32\drivers\SKYNETeyabbiyu.sys
c:\windows\system32\L5
c:\windows\system32\SKYNETaubodjkl.dll
c:\windows\system32\SKYNETtobwwyll.dat
c:\windows\system32\SKYNETwsqttomq.dll
c:\windows\system32\SKYNETxfuwbimk.dat
C:\DBI.EXE
C:\Documents
c:\documents and settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\c.cgm
c:\program files\Manson\liser.dll
c:\program files\Manson\liser.exe
c:\temp\1cb\syscheck.log
c:\windows\patchw32.dll
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\AutoRun.inf
c:\windows\system32\comsa32.sys
c:\windows\system32\drivers\SKYNETeyabbiyu.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SKYNETaubodjkl.dll
c:\windows\system32\SKYNETtobwwyll.dat
c:\windows\system32\SKYNETwsqttomq.dll
c:\windows\system32\SKYNETxfuwbimk.dat
c:\windows\system32\sopidkc.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\tpsaxyd.exe
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\wiawow32.sys
c:\windows\system32\WS2Fix.exe

Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\winlogon.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_SKYNETixjoyqje
-------\Legacy_HwIOctl
-------\Legacy_Memctl
-------\Service_HwIOctl
-------\Service_Memctl


((((((((((((((((((((((((( Files Created from 2009-05-22 to 2009-06-22 )))))))))))))))))))))))))))))))
.

2009-06-22 16:08 . 2009-06-22 16:08 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-06-19 23:58 . 2009-06-19 23:58 -------- d-----w- c:\documents and settings\John Christian\Local Settings\Application Data\GHOSTBUSTERS ™
2009-06-17 23:28 . 2009-06-17 23:28 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-06-17 23:28 . 2009-06-17 23:28 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Mozilla
2009-06-17 02:18 . 2009-06-17 02:18 -------- d-----w- C:\_OTL
2009-06-15 22:07 . 2009-06-15 22:31 -------- d-----w- C:\Rooter$
2009-06-15 21:11 . 2009-06-15 21:12 -------- d-----w- c:\program files\ERUNT
2009-06-15 20:40 . 2009-06-15 20:40 -------- d-----w- c:\program files\Trend Micro
2009-06-15 10:02 . 2009-06-15 10:02 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-06-15 09:54 . 2009-06-15 09:54 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Yahoo!
2009-06-15 09:54 . 2009-06-15 10:02 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\AVGTOOLBAR
2009-06-15 00:42 . 2009-06-15 00:42 -------- d-----w- c:\program files\ESET
2009-06-14 22:12 . 2009-06-14 22:12 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-06-14 21:07 . 2009-06-14 21:07 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-14 21:06 . 2009-06-14 21:06 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-06-14 21:06 . 2009-06-14 21:06 152576 ----a-w- c:\documents and settings\John Christian\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-12 02:26 . 2009-06-12 02:26 -------- d-----w- c:\windows\nview
2009-06-11 22:29 . 2009-06-11 22:29 41808 ----a-w- c:\windows\system32\xfcodec.dll
2009-06-10 07:01 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-10 07:01 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-08 02:34 . 2009-06-13 23:19 2114851345 ----a-w- c:\documents and settings\John Christian\Application Data\ijjigame\HuxleyLiteSetup.exe
2009-06-06 01:02 . 2009-06-06 01:02 -------- d-----w- c:\program files\Realtek AC97
2009-06-06 00:59 . 2009-06-06 00:59 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-06-06 00:58 . 2009-06-06 00:58 -------- d-----w- c:\program files\PC Drivers HeadQuarters
2009-06-05 21:30 . 2009-06-08 23:26 -------- d-----w- c:\documents and settings\John Christian\Application Data\ijjigame
2009-06-05 21:30 . 2009-06-05 21:30 -------- d-----w- C:\ijji
2009-06-05 21:29 . 2009-06-05 21:30 558552 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\PLauncher.exe
2009-06-05 21:29 . 2009-06-03 21:48 779720 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\PurpleBean.exe
2009-06-05 21:29 . 2008-09-04 20:34 112048 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjiPrePLauncher.exe
2009-06-05 21:29 . 2008-08-28 16:50 480688 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjistarter2FxB.exe
2009-06-05 21:29 . 2008-08-28 16:50 83376 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjiPreStarter2FxB.exe
2009-06-05 21:29 . 2008-08-28 16:50 50608 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjiNotify2FxB.exe
2009-06-05 21:29 . 2009-06-05 21:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ijjigame
2009-06-05 21:29 . 2008-08-28 16:50 79280 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjiPreNotify2FxB.exe
2009-06-05 21:06 . 2009-06-05 21:06 -------- d-----w- c:\program files\NHN USA
2009-06-05 21:06 . 2009-05-26 21:31 58800 ----a-w- c:\windows\system32\ijjiProcessRestarter.exe
2009-06-05 21:06 . 2009-05-13 00:48 710064 ----a-w- c:\windows\system32\ijjiSetup.exe
2009-06-05 21:06 . 2008-06-12 03:01 58800 ----a-w- c:\windows\system32\ijjiPlugin2.dll
2009-06-05 21:06 . 2008-04-23 18:02 157152 ----a-w- c:\windows\system32\PubPlugin.dll
2009-06-05 19:22 . 2009-06-13 23:19 -------- d-----w- c:\program files\HuxleyLite
2009-06-04 03:26 . 2009-06-05 01:26 -------- d-----w- c:\documents and settings\All Users\Application Data\MailFrontier
2009-06-04 03:26 . 2009-06-04 03:37 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-06-04 03:25 . 2009-06-11 01:23 -------- d-----w- c:\windows\system32\ZoneLabs
2009-06-01 02:17 . 2009-06-01 02:17 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-06-01 02:17 . 2009-06-01 02:17 83808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-06-01 02:17 . 2009-06-01 02:17 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-06-01 02:17 . 2009-06-01 02:17 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-05-25 02:40 . 2009-05-25 18:11 -------- d-----w- c:\documents and settings\John Christian\Application Data\Games
2009-05-24 02:29 . 2009-05-24 02:29 -------- d-----w- c:\program files\USArmy
2009-05-23 23:44 . 2009-06-11 03:12 -------- d-----w- c:\documents and settings\All Users\Application Data\AA3DeployClient
2009-05-23 23:44 . 2009-06-11 02:07 -------- d-----w- c:\documents and settings\John Christian\Local Settings\Application Data\AA3DeployClient
2009-05-23 23:43 . 2009-06-17 05:54 -------- d-----w- c:\documents and settings\John Christian\Local Settings\Application Data\Deployment

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-22 09:12 . 2008-01-24 03:08 -------- d-----w- c:\documents and settings\John Christian\Application Data\Xfire
2009-06-22 08:53 . 2007-09-12 08:25 -------- d-----w- c:\program files\Steam
2009-06-21 18:01 . 2007-07-29 09:18 -------- d-s---w- c:\program files\Xfire
2009-06-21 06:43 . 2008-12-19 08:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-21 06:42 . 2009-01-05 07:31 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-20 21:07 . 2007-08-10 14:13 137888 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-06-20 21:07 . 2007-08-10 14:10 189288 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-06-19 20:57 . 2007-07-29 09:20 -------- d-----w- c:\program files\Atari
2009-06-19 19:56 . 2007-07-29 03:12 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-19 00:12 . 2009-05-14 11:03 117760 ----a-w- c:\documents and settings\John Christian\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-18 20:42 . 2008-12-19 08:26 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-06-17 23:29 . 2007-07-29 09:24 -------- d-----w- c:\program files\DivX
2009-06-17 15:27 . 2008-12-19 08:41 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 15:27 . 2008-12-19 08:41 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-17 06:10 . 2007-07-29 09:24 -------- d-----w- c:\program files\EA Games
2009-06-17 05:55 . 2008-10-14 23:04 -------- d-----w- c:\documents and settings\All Users\Application Data\America's Army Deploy Client
2009-06-17 02:27 . 2007-07-29 21:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-06-15 01:47 . 2009-04-25 18:55 -------- d-----w- c:\program files\Diner Dash 2
2009-06-14 23:42 . 2009-03-15 14:33 -------- d-----w- c:\documents and settings\John Christian\Application Data\AVGTOOLBAR
2009-06-14 23:05 . 2007-09-14 22:32 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-14 21:06 . 2007-07-29 09:41 -------- d-----w- c:\program files\Java
2009-06-12 02:26 . 2007-08-03 09:19 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-07 05:42 . 2007-08-09 05:21 -------- d-----w- c:\documents and settings\John Christian\Application Data\Audacity
2009-06-05 01:48 . 2007-07-29 09:37 -------- d-----w- c:\program files\Electronic Arts
2009-06-01 02:17 . 2009-03-09 02:26 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-05-25 17:38 . 2007-08-04 22:44 -------- d-----w- c:\documents and settings\John Christian\Application Data\Mozilla2
2009-05-24 23:08 . 2007-11-04 04:58 -------- d-----w- c:\program files\AGEIA Technologies
2009-05-24 02:25 . 2007-07-29 02:50 118288 ----a-w- c:\documents and settings\John Christian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-24 02:14 . 2008-08-23 17:44 -------- d-----w- c:\program files\MSBuild
2009-05-24 02:14 . 2008-08-23 17:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-19 22:27 . 2009-05-19 22:27 10134 ----a-r- c:\documents and settings\John Christian\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-05-19 22:27 . 2009-05-19 22:27 -------- d-----w- c:\program files\Microsoft WSE
2009-05-14 10:52 . 2009-03-15 14:33 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-05-13 05:15 . 2004-08-04 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2004-08-04 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-02 23:59 . 2009-05-02 23:59 -------- d-----w- c:\program files\NovaLogic
2009-05-02 12:29 . 2009-03-15 14:33 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-05-02 12:29 . 2009-03-15 14:33 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-02 12:29 . 2006-06-27 06:07 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-02 12:28 . 2009-03-15 14:33 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-01 21:02 . 2009-05-01 21:02 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx07.dll
2009-05-01 21:02 . 2009-05-01 21:02 815104 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-05-01 21:02 . 2009-05-01 21:02 811008 ----a-w- c:\windows\system32\divx_xx16.dll
2009-05-01 21:02 . 2009-05-01 21:02 802816 ----a-w- c:\windows\system32\divx_xx11.dll
2009-05-01 21:02 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\DivX.dll
2009-05-01 04:30 . 2009-05-01 04:30 1194528 ----a-w- c:\windows\system32\nvcplui.exe
2009-05-01 02:02 . 2009-05-01 02:02 1579630 ----a-w- c:\windows\system32\nvdata.bin
2009-05-01 02:02 . 2007-11-20 02:36 457248 ----a-w- c:\windows\system32\nvudisp.exe
2009-04-27 04:42 . 2007-11-20 02:35 457248 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-04-27 02:17 . 2009-04-27 02:17 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-04-27 02:17 . 2009-03-09 02:17 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-04-25 18:56 . 2009-04-21 01:55 -------- d-----w- c:\documents and settings\John Christian\Application Data\PlayFirst
2009-04-25 18:56 . 2009-04-21 01:55 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2009-04-25 18:33 . 2009-04-21 01:58 -------- d-----w- c:\program files\Diner Dash
2009-04-22 04:20 . 2009-04-22 04:20 14311680 ----a-w- c:\windows\system32\xlive.dll
2009-04-22 04:20 . 2009-04-22 04:20 13642496 ----a-w- c:\windows\system32\xlivefnt.dll
2009-04-17 12:26 . 2004-08-04 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-17 06:29 . 2009-04-17 06:29 1878984 ----a-w- c:\documents and settings\John Christian\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-04-15 14:51 . 2004-08-04 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-03 16:39 . 2009-04-03 16:39 70936 ----a-w- c:\windows\system32\PhysXLoader.dll
2009-03-28 06:49 . 2009-03-28 06:49 7040776 ----a-w- c:\documents and settings\John Christian\Application Data\MySpace\IM\Install\MSIMClientSetup.1.0.789.0-static-A.exe
2004-05-07 19:31 . 2007-08-03 09:20 348160 ----a-w- c:\program files\mozilla firefox\components\MSVCR71.DLL
2006-11-07 16:58 . 2007-08-03 09:20 139264 ----a-w- c:\program files\mozilla firefox\components\SABFF20.DLL
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

------- Sigcheck -------

[7] 2004-08-04 12:00 295424 B60C877D16D9C880B952FDA04ADF16E6 c:\windows\$NtServicePackUninstall$\termsrv.dll
[7] 2008-04-14 00:12 295424 FF3477C03BE7201C294C35F684B3479F c:\windows\ServicePackFiles\i386\termsrv.dll
[-] 2009-03-14 07:15 295424 63999D0ABD8DABFD76A9C07F6E104868 c:\windows\system32\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 81920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-22 518488]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-02 1947928]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"RivaTunerStartupDaemon"="d:\program files\RivaTuner v2.08\RivaTuner.exe" [2008-03-10 2691072]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-27 1657376]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]

c:\documents and settings\John Christian\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000D7}"= "c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABSEHB.DLL" [2006-11-07 77824]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SABWinLogon]
2007-05-14 17:20 176128 ----a-w- c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-31 09:06 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-02 12:29 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AT&T Self Support Tool.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AT&T Self Support Tool.lnk
backup=c:\windows\pss\AT&T Self Support Tool.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ExifLauncher2.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ExifLauncher2.lnk
backup=c:\windows\pss\ExifLauncher2.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^John Christian^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\John Christian\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^John Christian^Start Menu^Programs^Startup^Aquarius Soft PC Alarm Clock Pro.lnk]
path=c:\documents and settings\John Christian\Start Menu\Programs\Startup\Aquarius Soft PC Alarm Clock Pro.lnk
backup=c:\windows\pss\Aquarius Soft PC Alarm Clock Pro.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^John Christian^Start Menu^Programs^Startup^reminder-ScanSoft Product Registration.lnk]
path=c:\documents and settings\John Christian\Start Menu\Programs\Startup\reminder-ScanSoft Product Registration.lnk
backup=c:\windows\pss\reminder-ScanSoft Product Registration.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^John Christian^Start Menu^Programs^Startup^Sins of a Solar Empire Launcher.lnk]
path=c:\documents and settings\John Christian\Start Menu\Programs\Startup\Sins of a Solar Empire Launcher.lnk
backup=c:\windows\pss\Sins of a Solar Empire Launcher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"hpqcxs08"=3 (0x3)
"HPSLPSVC"=2 (0x2)
"hpqddsvc"=2 (0x2)
"ZuneWlanCfgSvc"=3 (0x3)
"ZuneNetworkSvc"=2 (0x2)
"ZuneBusEnum"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"d:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\Steam\\steam.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"d:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Program Files\\EA Games\\Mirror's Edge\\Binaries\\MirrorsEdge.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\USArmy\\America's Army 3\\Binaries\\AA3Game.exe"=
"c:\\Program Files\\HuxleyLite\\binaries\\HuxleyMMOGame.exe"=
"d:\\Program Files\\Activision\\Prototype\\prototypef.exe"=
"d:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\america's army 3\\Binaries\\AA3Game.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57909:TCP"= 57909:TCP:*:Disabled:Pando Media Booster
"57909:UDP"= 57909:UDP:*:Disabled:Pando Media Booster

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/8/2009 10:17 PM 64160]
R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [7/29/2007 3:34 AM 16896]
R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [7/29/2007 3:34 AM 52224]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/15/2009 10:33 AM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/15/2009 10:33 AM 108552]
R1 SABKUTIL;SABKUTIL;c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.SYS [2/20/2007 4:02 PM 32256]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12/4/2008 2:50 PM 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/4/2008 2:50 PM 55024]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/15/2009 10:33 AM 298776]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 5:34 PM 1003344]
R2 ppsio2;PPDevice;c:\windows\system32\drivers\ppsio2.sys [8/27/2007 7:31 PM 23200]
R2 WMDrive;WMDrive;c:\windows\system32\drivers\WMDrive.sys [2/17/2009 3:13 PM 37376]
S1 SABDIFSV;SABDIFSV;c:\program files\SuperAdBlocker.com\Super Ad Blocker\sabdifsv.sys [9/21/2005 11:17 AM 5632]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/4/2008 2:50 PM 7408]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-06-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 02:17]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-Winlj13.sys
SafeBoot-Winly67.sys
SafeBoot-Winnn86.sys


.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = 127.0.0.1
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-22 13:27
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1547161642-152049171-1801674531-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ec,46,bd,6d,c1,8a,a5,c5,3c,4d,bc,4f,7a,44,7e,ef,18,4d,c4,35,46,87,95,
05,56,d3,65,78,e2,22,6d,e2,bb,c0,9a,58,b5,86,dd,0c,82,19,c3,28,8b,56,e9,81,\
"??"=hex:80,40,06,d0,8e,ad,37,15,76,13,ef,74,08,8e,27,0f

[HKEY_USERS\S-1-5-21-1547161642-152049171-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:d7,cc,7d,6b,10,af,f5,7a,0e,82,a7,31,be,ca,81,d5,24,4f,46,37,ff,
58,66,af,9a,0c,87,a2,14,99,e2,a2,56,28,69,4a,e3,08,87,d1,f0,6a,67,03,9b,57,\
"rkeysecu"=hex:ce,13,31,c2,44,4f,e5,b0,9b,27,0f,62,37,7a,e0,d3

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ř•€|˙˙˙˙•€|ů•A~*]
"5E7CEC10DF0760D4F8DAFB12FDC06CCD"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{01CEC7E5-70FD-4D06-8FAD-BF21DF0CC6DC}\\Registered"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"NoChange"="1"
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
@=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(820)
c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(5716)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\nvsvc32.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\TVersity\Media Server\MediaServer.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2009-06-22 13:32 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-22 17:32

Pre-Run: 8,724,213,760 bytes free
Post-Run: 8,830,857,216 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

Current=3 Default=3 Failed=2 LastKnownGood=5 Sets=1,2,3,4,5
415 --- E O F --- 2009-06-11 01:21


This post has been edited by jaysee: Jun 22 2009, 11:52 AM
Go to the top of the page
 
+Quote Post
Transience
post Jun 23 2009, 04:49 AM
Post #13


Unofficial Music Guru
Group Icon
Posts: 2,354
From: Massachusetts, USA
OS: Vista



Glad the redirects are gone smile.gif.

QUOTE
1. The unsecapp.exe process. Just out of curiousity, what causes it to start running? I've looked it up, and everyone says it's fine, but I've never had it running in my processes before until fairly recently (although long before this infection, as far as I'm aware).

It's hard to say, it's a windows process, most likely one that wasn't used before but now one of your program needs it.

QUOTE
2. Should I go ahead and change all my passwords to be on the safe side (email, general accounts, etc)?

That's a good safety measure to take, but it's best to wait until we're positive you're clean (almost there biggrin.gif).

Please go to Add/Remove Programs in your Control Panel (Programs and Features if you are a Vista user). Select and remove the following if present, don't worry if they aren't:

Viewpoint Media Player (and anything else that says "Viewpoint") - Viewpoint is an annoying media player that installs alongside many different things without your permission, not a good idea to keep it on your computer.

One last script to get a couple minor things:

1. Run a ComboFix script
  • Copy the entire contents of the code box below to notepad (Start > Programs > Accessories > Notepad).
  • Click on File > Save and name the file CFScript.txt. This name is important and must not be changed.
  • Change the Save as Type to All Files.
  • Save it directly on your desktop.

CODE
KillAll::

Folder::
c:\windows\system32\config\systemprofile\PrivacIE

FCOPY::
c:\windows\ServicePackFiles\i386\termsrv.dll | c:\windows\system32\termsrv.dll

Extra::

SysRst::

Note: If you are not the topic starter, DO NOT download or run this script as it could cause irreversible damage to your computer.

Please note that the same procedure applies to running ComboFix this time as before - disable your protection programs beforehand, close all other programs, don't interrupt it for any reason etc.



Once the script is saved, refering to the picture above, drag CFScript.txt into ComboFix.exe. This will cause ComboFix to start again. Allow it to complete running, following any prompts. Once the program has completed the log should appear automatically, if it doesn't it can be found at C:\ComboFix.txt. Please post the contents of that log in your next reply.

This post has been edited by Transience: Jun 23 2009, 04:52 AM
Go to the top of the page
 
+Quote Post
jaysee
post Jun 23 2009, 12:56 PM
Post #14


Member
**
Posts: 25
OS: XP Pro



Went ahead and did the ComboFix, posted below. Worth mentioning, though, that last night I ended up getting a redirected page (I believe, unless it's some feature of FireFox3 I don't know about). Yahoo remains fine, and pages don't take me elsewhere, but when I was visiting just a regular site at one point, it redirected me to a page saying that it was blocked, and to "Click here to find out why". As soon as I went back and tried again, it worked as normal.

I ran a full scan with Malwarebytes while I slept and it found six or seven .dll and .exe, "Trojan / Downloaders", which I removed and then restarted my computer. Unfortunately I didn't save the report.

So all that happened before I did the ComboFix here today. Then, after I was done doing this second ComboFix run, AVG on it's own picked up the following (disguised as a svchost.exe process), which I removed:



Lastly, ever since I did the first ComboFix, I don't know if it's just a coincidence, but my internet has been very slow at times, most noticeable when loading videos or pictures.


QUOTE
ComboFix 09-06-22.0E - John Christian 06/23/2009 14:34.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1561 [GMT -4:00]
Running from: c:\documents and settings\John Christian\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\John Christian\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\config\systemprofile\PrivacIE
c:\windows\system32\config\systemprofile\PrivacIE\index.dat

.
--------------- FCopy ---------------

c:\windows\ServicePackFiles\i386\termsrv.dll --> c:\windows\system32\termsrv.dll
.
((((((((((((((((((((((((( Files Created from 2009-05-23 to 2009-06-23 )))))))))))))))))))))))))))))))
.

2009-06-22 16:08 . 2009-06-22 16:08 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-06-19 23:58 . 2009-06-19 23:58 -------- d-----w- c:\documents and settings\John Christian\Local Settings\Application Data\GHOSTBUSTERS ™
2009-06-17 23:28 . 2009-06-17 23:28 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-06-17 23:28 . 2009-06-17 23:28 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Mozilla
2009-06-17 02:18 . 2009-06-17 02:18 -------- d-----w- C:\_OTL
2009-06-15 22:07 . 2009-06-15 22:31 -------- d-----w- C:\Rooter$
2009-06-15 21:11 . 2009-06-15 21:12 -------- d-----w- c:\program files\ERUNT
2009-06-15 20:40 . 2009-06-15 20:40 -------- d-----w- c:\program files\Trend Micro
2009-06-15 09:54 . 2009-06-15 09:54 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Yahoo!
2009-06-15 09:54 . 2009-06-15 10:02 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\AVGTOOLBAR
2009-06-15 00:42 . 2009-06-15 00:42 -------- d-----w- c:\program files\ESET
2009-06-14 22:12 . 2009-06-14 22:12 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-06-14 21:07 . 2009-06-14 21:07 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-14 21:06 . 2009-06-14 21:06 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-06-14 21:06 . 2009-06-14 21:06 152576 ----a-w- c:\documents and settings\John Christian\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-12 02:26 . 2009-06-12 02:26 -------- d-----w- c:\windows\nview
2009-06-11 22:29 . 2009-06-11 22:29 41808 ----a-w- c:\windows\system32\xfcodec.dll
2009-06-10 07:01 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-10 07:01 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-08 02:34 . 2009-06-13 23:19 2114851345 ----a-w- c:\documents and settings\John Christian\Application Data\ijjigame\HuxleyLiteSetup.exe
2009-06-06 01:02 . 2009-06-06 01:02 -------- d-----w- c:\program files\Realtek AC97
2009-06-06 00:59 . 2009-06-06 00:59 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-06-06 00:58 . 2009-06-06 00:58 -------- d-----w- c:\program files\PC Drivers HeadQuarters
2009-06-05 21:30 . 2009-06-08 23:26 -------- d-----w- c:\documents and settings\John Christian\Application Data\ijjigame
2009-06-05 21:30 . 2009-06-05 21:30 -------- d-----w- C:\ijji
2009-06-05 21:29 . 2009-06-05 21:30 558552 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\PLauncher.exe
2009-06-05 21:29 . 2009-06-03 21:48 779720 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\PurpleBean.exe
2009-06-05 21:29 . 2008-09-04 20:34 112048 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjiPrePLauncher.exe
2009-06-05 21:29 . 2008-08-28 16:50 480688 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjistarter2FxB.exe
2009-06-05 21:29 . 2008-08-28 16:50 83376 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjiPreStarter2FxB.exe
2009-06-05 21:29 . 2008-08-28 16:50 50608 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjiNotify2FxB.exe
2009-06-05 21:29 . 2009-06-05 21:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ijjigame
2009-06-05 21:29 . 2008-08-28 16:50 79280 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ijjiPreNotify2FxB.exe
2009-06-05 21:06 . 2009-06-05 21:06 -------- d-----w- c:\program files\NHN USA
2009-06-05 21:06 . 2009-05-26 21:31 58800 ----a-w- c:\windows\system32\ijjiProcessRestarter.exe
2009-06-05 21:06 . 2009-05-13 00:48 710064 ----a-w- c:\windows\system32\ijjiSetup.exe
2009-06-05 21:06 . 2008-06-12 03:01 58800 ----a-w- c:\windows\system32\ijjiPlugin2.dll
2009-06-05 21:06 . 2008-04-23 18:02 157152 ----a-w- c:\windows\system32\PubPlugin.dll
2009-06-05 19:22 . 2009-06-13 23:19 -------- d-----w- c:\program files\HuxleyLite
2009-06-04 03:26 . 2009-06-05 01:26 -------- d-----w- c:\documents and settings\All Users\Application Data\MailFrontier
2009-06-04 03:26 . 2009-06-04 03:37 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-06-04 03:25 . 2009-06-11 01:23 -------- d-----w- c:\windows\system32\ZoneLabs
2009-06-01 02:17 . 2009-06-01 02:17 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-06-01 02:17 . 2009-06-01 02:17 83808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-06-01 02:17 . 2009-06-01 02:17 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-06-01 02:17 . 2009-06-01 02:17 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-05-25 02:40 . 2009-05-25 18:11 -------- d-----w- c:\documents and settings\John Christian\Application Data\Games

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-23 08:32 . 2008-01-24 03:08 -------- d-----w- c:\documents and settings\John Christian\Application Data\Xfire
2009-06-23 08:25 . 2007-09-12 08:25 -------- d-----w- c:\program files\Steam
2009-06-22 21:50 . 2007-09-14 22:32 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-21 18:01 . 2007-07-29 09:18 -------- d-s---w- c:\program files\Xfire
2009-06-21 06:43 . 2008-12-19 08:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-21 06:42 . 2009-01-05 07:31 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-20 21:07 . 2007-08-10 14:13 137888 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-06-20 21:07 . 2007-08-10 14:10 189288 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-06-19 20:57 . 2007-07-29 09:20 -------- d-----w- c:\program files\Atari
2009-06-19 19:56 . 2007-07-29 03:12 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-19 00:12 . 2009-05-14 11:03 117760 ----a-w- c:\documents and settings\John Christian\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-18 20:42 . 2008-12-19 08:26 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-06-17 23:29 . 2007-07-29 09:24 -------- d-----w- c:\program files\DivX
2009-06-17 15:27 . 2008-12-19 08:41 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 15:27 . 2008-12-19 08:41 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-17 06:10 . 2007-07-29 09:24 -------- d-----w- c:\program files\EA Games
2009-06-17 05:55 . 2008-10-14 23:04 -------- d-----w- c:\documents and settings\All Users\Application Data\America's Army Deploy Client
2009-06-17 02:27 . 2007-07-29 21:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-06-15 01:47 . 2009-04-25 18:55 -------- d-----w- c:\program files\Diner Dash 2
2009-06-14 23:42 . 2009-03-15 14:33 -------- d-----w- c:\documents and settings\John Christian\Application Data\AVGTOOLBAR
2009-06-14 21:06 . 2007-07-29 09:41 -------- d-----w- c:\program files\Java
2009-06-12 02:26 . 2007-08-03 09:19 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-11 03:12 . 2009-05-23 23:44 -------- d-----w- c:\documents and settings\All Users\Application Data\AA3DeployClient
2009-06-07 05:42 . 2007-08-09 05:21 -------- d-----w- c:\documents and settings\John Christian\Application Data\Audacity
2009-06-05 01:48 . 2007-07-29 09:37 -------- d-----w- c:\program files\Electronic Arts
2009-06-01 02:17 . 2009-03-09 02:26 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-05-25 17:38 . 2007-08-04 22:44 -------- d-----w- c:\documents and settings\John Christian\Application Data\Mozilla2
2009-05-24 23:08 . 2007-11-04 04:58 -------- d-----w- c:\program files\AGEIA Technologies
2009-05-24 02:29 . 2009-05-24 02:29 -------- d-----w- c:\program files\USArmy
2009-05-24 02:25 . 2007-07-29 02:50 118288 ----a-w- c:\documents and settings\John Christian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-24 02:14 . 2008-08-23 17:44 -------- d-----w- c:\program files\MSBuild
2009-05-24 02:14 . 2008-08-23 17:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-19 22:27 . 2009-05-19 22:27 10134 ----a-r- c:\documents and settings\John Christian\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-05-19 22:27 . 2009-05-19 22:27 -------- d-----w- c:\program files\Microsoft WSE
2009-05-14 10:52 . 2009-03-15 14:33 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-05-13 05:15 . 2004-08-04 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2004-08-04 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-02 23:59 . 2009-05-02 23:59 -------- d-----w- c:\program files\NovaLogic
2009-05-02 12:29 . 2009-03-15 14:33 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-05-02 12:29 . 2009-03-15 14:33 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-02 12:29 . 2006-06-27 06:07 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-02 12:28 . 2009-03-15 14:33 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-01 21:02 . 2009-05-01 21:02 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx07.dll
2009-05-01 21:02 . 2009-05-01 21:02 815104 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-05-01 21:02 . 2009-05-01 21:02 811008 ----a-w- c:\windows\system32\divx_xx16.dll
2009-05-01 21:02 . 2009-05-01 21:02 802816 ----a-w- c:\windows\system32\divx_xx11.dll
2009-05-01 21:02 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\DivX.dll
2009-05-01 04:30 . 2009-05-01 04:30 1194528 ----a-w- c:\windows\system32\nvcplui.exe
2009-05-01 02:02 . 2009-05-01 02:02 1579630 ----a-w- c:\windows\system32\nvdata.bin
2009-05-01 02:02 . 2007-11-20 02:36 457248 ----a-w- c:\windows\system32\nvudisp.exe
2009-04-27 04:42 . 2007-11-20 02:35 457248 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-04-27 02:17 . 2009-04-27 02:17 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-04-27 02:17 . 2009-03-09 02:17 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-04-25 18:56 . 2009-04-21 01:55 -------- d-----w- c:\documents and settings\John Christian\Application Data\PlayFirst
2009-04-25 18:56 . 2009-04-21 01:55 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2009-04-25 18:33 . 2009-04-21 01:58 -------- d-----w- c:\program files\Diner Dash
2009-04-22 04:20 . 2009-04-22 04:20 14311680 ----a-w- c:\windows\system32\xlive.dll
2009-04-22 04:20 . 2009-04-22 04:20 13642496 ----a-w- c:\windows\system32\xlivefnt.dll
2009-04-17 12:26 . 2004-08-04 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-17 06:29 . 2009-04-17 06:29 1878984 ----a-w- c:\documents and settings\John Christian\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-04-15 14:51 . 2004-08-04 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-03 16:39 . 2009-04-03 16:39 70936 ----a-w- c:\windows\system32\PhysXLoader.dll
2009-03-28 06:49 . 2009-03-28 06:49 7040776 ----a-w- c:\documents and settings\John Christian\Application Data\MySpace\IM\Install\MSIMClientSetup.1.0.789.0-static-A.exe
2004-05-07 19:31 . 2007-08-03 09:20 348160 ----a-w- c:\program files\mozilla firefox\components\MSVCR71.DLL
2006-11-07 16:58 . 2007-08-03 09:20 139264 ----a-w- c:\program files\mozilla firefox\components\SABFF20.DLL
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-06-22_17.28.05 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-23 18:44 . 2009-06-23 18:44 16384 c:\windows\temp\Perflib_Perfdata_794.dat
+ 2009-06-23 18:44 . 2009-06-23 18:44 16384 c:\windows\temp\Perflib_Perfdata_108.dat
+ 2007-07-29 01:35 . 2008-04-14 00:12 295424 c:\windows\system32\dllcache\termsrv.dll
+ 2009-06-23 18:18 . 2009-06-23 18:18 360448 c:\windows\ERDNT\AutoBackup\6-23-2009\Users\00000002\UsrClass.dat
+ 2009-06-23 18:18 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\6-23-2009\ERDNT.EXE
+ 2009-06-23 18:18 . 2009-06-23 18:18 19324928 c:\windows\ERDNT\AutoBackup\6-23-2009\Users\00000001\ntuser.dat
.
((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\32788r22fwjfw\pv.exe
03/02/2006 11:42 PM 73728 \RP639\A0137685.exe
03/02/2006 11:42 PM 73728 \RP639\A0137686.exe

C:\DBI.EXE
12/29/2004 01:57 AM 17505 \RP638\A0137444.EXE

04/13/2008 08:12 PM 26624 c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
04/13/2008 08:12 PM 26624 \RP634\A0136276.dll
04/13/2008 08:12 PM 26624 \RP639\A0137777.dll

c:\program files\Manson\liser.dll
06/22/2009 12:11 PM 24576 \RP638\A0137424.dll

c:\program files\Manson\liser.exe
06/22/2009 12:11 PM 61440 \RP638\A0137425.exe

06/12/2009 12:16 AM 17400 c:\program files\Mozilla Firefox\AccessibleMarshal.dll
05/11/2009 10:01 PM 17400 \RP634\A0136371.dll

06/12/2009 12:16 AM 23032 c:\program files\Mozilla Firefox\components\browserdirprovider.dll
05/11/2009 10:01 PM 23032 \RP634\A0136373.dll

06/12/2009 12:16 AM 134648 c:\program files\Mozilla Firefox\components\brwsrcmp.dll
05/11/2009 10:01 PM 134648 \RP634\A0136374.dll

06/12/2009 12:16 AM 185848 c:\program files\Mozilla Firefox\crashreporter.exe
05/11/2009 10:01 PM 185848 \RP634\A0136375.exe

06/12/2009 12:16 AM 307704 c:\program files\Mozilla Firefox\firefox.exe
05/11/2009 10:01 PM 307704 \RP634\A0136376.exe

06/12/2009 12:16 AM 233472 c:\program files\Mozilla Firefox\freebl3.dll
05/11/2009 10:01 PM 233472 \RP634\A0136377.dll

06/12/2009 12:16 AM 694056 c:\program files\Mozilla Firefox\js3250.dll
05/11/2009 10:01 PM 697336 \RP634\A0136378.dll

06/12/2009 12:16 AM 710136 c:\program files\Mozilla Firefox\mozcrt19.dll
05/11/2009 10:01 PM 710136 \RP634\A0136379.dll

06/12/2009 12:16 AM 198136 c:\program files\Mozilla Firefox\nspr4.dll
05/11/2009 10:01 PM 198136 \RP634\A0136380.dll

06/12/2009 12:16 AM 718328 c:\program files\Mozilla Firefox\nss3.dll
05/11/2009 10:01 PM 718328 \RP634\A0136381.dll

06/12/2009 12:16 AM 292344 c:\program files\Mozilla Firefox\nssckbi.dll
05/11/2009 10:01 PM 292344 \RP634\A0136382.dll

06/12/2009 12:16 AM 103928 c:\program files\Mozilla Firefox\nssdbm3.dll
05/11/2009 10:01 PM 103928 \RP634\A0136383.dll

06/12/2009 12:16 AM 87544 c:\program files\Mozilla Firefox\nssutil3.dll
05/11/2009 10:01 PM 87544 \RP634\A0136384.dll

06/12/2009 12:16 AM 20472 c:\program files\Mozilla Firefox\plc4.dll
05/11/2009 10:01 PM 20472 \RP634\A0136386.dll

06/12/2009 12:16 AM 17400 c:\program files\Mozilla Firefox\plds4.dll
05/11/2009 10:01 PM 17400 \RP634\A0136387.dll

06/12/2009 12:16 AM 65528 c:\program files\Mozilla Firefox\plugins\npnul32.dll
05/11/2009 10:01 PM 65528 \RP634\A0136388.dll

06/12/2009 12:16 AM 103928 c:\program files\Mozilla Firefox\smime3.dll
05/11/2009 10:01 PM 103928 \RP634\A0136389.dll

06/12/2009 12:16 AM 151552 c:\program files\Mozilla Firefox\softokn3.dll
05/11/2009 10:01 PM 151552 \RP634\A0136390.dll

06/12/2009 12:16 AM 435704 c:\program files\Mozilla Firefox\sqlite3.dll
05/11/2009 10:01 PM 395768 \RP634\A0136391.dll

06/12/2009 12:16 AM 136696 c:\program files\Mozilla Firefox\ssl3.dll
05/11/2009 10:01 PM 136696 \RP634\A0136392.dll

06/12/2009 12:16 AM 509544 c:\program files\Mozilla Firefox\uninstall\helper.exe
05/11/2009 10:01 PM 509544 \RP634\A0136393.exe

06/12/2009 12:16 AM 242168 c:\program files\Mozilla Firefox\updater.exe
05/11/2009 10:01 PM 242168 \RP634\A0136394.exe

06/12/2009 12:16 AM 17912 c:\program files\Mozilla Firefox\xpcom.dll
05/11/2009 10:01 PM 17912 \RP634\A0136395.dll

06/12/2009 12:16 AM 9777144 c:\program files\Mozilla Firefox\xul.dll
05/11/2009 10:01 PM 9756664 \RP634\A0136396.dll

06/23/2009 01:32 AM 206072 c:\program files\Steam\bin\FileSystem_Steam.dll
06/15/2009 09:03 PM 206072 \RP639\A0137590.dll

06/23/2009 01:32 AM 1336568 c:\program files\Steam\bin\friendsUI.dll
06/15/2009 09:03 PM 1340664 \RP639\A0137591.dll

06/23/2009 01:32 AM 546040 c:\program files\Steam\bin\mss32_s.dll
06/15/2009 09:03 PM 546040 \RP639\A0137592.dll

06/23/2009 01:32 AM 185592 c:\program files\Steam\bin\nattypeprobe.dll
06/15/2009 09:03 PM 185592 \RP639\A0137593.dll

06/23/2009 01:32 AM 2069752 c:\program files\Steam\bin\p2pcore.dll
06/15/2009 09:03 PM 2069752 \RP639\A0137594.dll

06/23/2009 01:32 AM 1213688 c:\program files\Steam\bin\p2pvoice.dll
06/15/2009 09:03 PM 1213688 \RP639\A0137595.dll

06/23/2009 01:32 AM 980216 c:\program files\Steam\bin\ServerBrowser.dll
06/15/2009 09:03 PM 980216 \RP639\A0137596.dll

06/23/2009 01:32 AM 711152 c:\program files\Steam\bin\SteamService.dll
06/15/2009 09:03 PM 711152 \RP639\A0137597.dll

06/23/2009 01:32 AM 316664 c:\program files\Steam\bin\SteamService.exe
06/15/2009 09:03 PM 316664 \RP639\A0137598.exe

06/23/2009 01:32 AM 201976 c:\program files\Steam\bin\vaudio_speex.dll
06/15/2009 09:03 PM 201976 \RP639\A0137599.dll

06/23/2009 01:32 AM 455928 c:\program files\Steam\bin\vgui2.dll
06/15/2009 09:03 PM 455928 \RP639\A0137600.dll

06/23/2009 01:32 AM 122864 c:\program files\Steam\CSERHelper.dll
06/15/2009 09:03 PM 122864 \RP639\A0137605.dll

06/23/2009 01:32 AM 1039192 c:\program files\Steam\dbghelp.dll
06/15/2009 09:03 PM 1039192 \RP639\A0137588.dll

06/23/2009 01:32 AM 242936 c:\program files\Steam\GameOverlayRenderer.dll
06/15/2009 09:03 PM 242936 \RP639\A0137609.dll

06/23/2009 01:32 AM 1082616 c:\program files\Steam\GameOverlayUI.exe
06/15/2009 09:03 PM 1078520 \RP639\A0137610.exe

06/23/2009 01:32 AM 551408 c:\program files\Steam\mss32_s.dll
06/15/2009 09:03 PM 551408 \RP639\A0137611.dll

06/23/2009 01:32 AM 2884856 c:\program files\Steam\Steam.dll
06/15/2009 09:03 PM 2884856 \RP639\A0137589.dll

06/23/2009 01:32 AM 3335416 c:\program files\Steam\steamclient.dll
06/15/2009 09:03 PM 3336688 \RP639\A0137606.dll

06/23/2009 01:32 AM 3093752 c:\program files\Steam\SteamUI.dll
06/15/2009 09:03 PM 3089656 \RP639\A0137587.dll

06/23/2009 01:32 AM 275704 c:\program files\Steam\tier0_s.dll
06/15/2009 09:03 PM 275704 \RP639\A0137607.dll

06/23/2009 01:32 AM 386296 c:\program files\Steam\vstdlib_s.dll
06/15/2009 09:03 PM 386296 \RP639\A0137608.dll

06/23/2009 01:32 AM 256496 c:\program files\Steam\WriteMiniDump.exe
06/15/2009 09:03 PM 256496 \RP639\A0137586.exe

c:\windows\LastGood.Tmp\system32\D3DCompiler_33.dll
03/12/2007 05:42 PM 1123696 \RP634\A0136278.dll

c:\windows\LastGood.Tmp\system32\D3DCompiler_34.dll
05/16/2007 05:45 PM 1124720 \RP634\A0136279.dll

c:\windows\LastGood.Tmp\system32\D3DCompiler_35.dll
07/19/2007 07:14 PM 1358192 \RP634\A0136280.dll

c:\windows\LastGood.Tmp\system32\D3DCompiler_36.dll
10/12/2007 04:14 PM 1374232 \RP634\A0136281.dll

c:\windows\LastGood.Tmp\system32\D3DCompiler_37.dll
03/05/2008 04:56 PM 1420824 \RP634\A0136282.dll

c:\windows\LastGood.Tmp\system32\D3DCompiler_38.dll
05/30/2008 03:11 PM 1491992 \RP634\A0136283.dll

c:\windows\LastGood.Tmp\system32\D3DCompiler_39.dll
07/10/2008 12:00 PM 1493528 \RP634\A0136284.dll

c:\windows\LastGood.Tmp\system32\D3DCompiler_40.dll
10/10/2008 05:52 AM 2036576 \RP634\A0136285.dll

c:\windows\LastGood.Tmp\system32\d3dx10_33.dll
03/15/2007 05:57 PM 443752 \RP634\A0136286.dll

c:\windows\LastGood.Tmp\system32\d3dx10_34.dll
05/16/2007 05:45 PM 443752 \RP634\A0136287.dll

c:\windows\LastGood.Tmp\system32\d3dx10_35.dll
07/19/2007 07:14 PM 444776 \RP634\A0136288.dll

c:\windows\LastGood.Tmp\system32\d3dx10_36.dll
10/02/2007 10:56 AM 444776 \RP634\A0136289.dll

c:\windows\LastGood.Tmp\system32\d3dx10_37.dll
02/06/2008 12:07 AM 462864 \RP634\A0136290.dll

c:\windows\LastGood.Tmp\system32\d3dx10_38.dll
05/30/2008 03:11 PM 467984 \RP634\A0136291.dll

c:\windows\LastGood.Tmp\system32\d3dx10_39.dll
07/10/2008 12:01 PM 467984 \RP634\A0136292.dll

c:\windows\LastGood.Tmp\system32\d3dx10_40.dll
10/10/2008 05:52 AM 452440 \RP634\A0136293.dll

c:\windows\LastGood.Tmp\system32\d3dx9_24.dll
02/05/2005 08:45 PM 2222800 \RP634\A0136294.dll

c:\windows\LastGood.Tmp\system32\d3dx9_25.dll
03/18/2005 06:19 PM 2337488 \RP634\A0136296.dll

c:\windows\LastGood.Tmp\system32\d3dx9_26.dll
05/26/2005 04:34 PM 2297552 \RP634\A0136297.dll

c:\windows\LastGood.Tmp\system32\d3dx9_27.dll
07/22/2005 08:59 PM 2319568 \RP634\A0136298.dll

c:\windows\LastGood.Tmp\system32\d3dx9_28.dll
12/05/2005 07:09 PM 2323664 \RP634\A0136299.dll

c:\windows\LastGood.Tmp\system32\d3dx9_29.dll
02/03/2006 09:43 AM 2332368 \RP634\A0136300.dll

c:\windows\LastGood.Tmp\system32\d3dx9_30.dll
03/31/2006 01:40 PM 2388176 \RP634\A0136301.dll

c:\windows\LastGood.Tmp\system32\d3dx9_31.dll
09/28/2006 05:05 PM 2414360 \RP634\A0136302.dll

c:\windows\LastGood.Tmp\system32\d3dx9_32.dll
11/29/2006 02:06 PM 3426072 \RP634\A0136303.dll

c:\windows\LastGood.Tmp\system32\d3dx9_33.dll
03/12/2007 05:42 PM 3495784 \RP634\A0136304.dll

c:\windows\LastGood.Tmp\system32\d3dx9_34.dll
05/16/2007 05:45 PM 3497832 \RP634\A0136305.dll

c:\windows\LastGood.Tmp\system32\d3dx9_35.dll
07/19/2007 07:14 PM 3727720 \RP634\A0136306.dll

c:\windows\LastGood.Tmp\system32\d3dx9_36.dll
10/12/2007 04:14 PM 3734536 \RP634\A0136307.dll

c:\windows\LastGood.Tmp\system32\D3DX9_37.dll
03/05/2008 04:56 PM 3786760 \RP634\A0136308.dll

c:\windows\LastGood.Tmp\system32\D3DX9_38.dll
05/30/2008 03:11 PM 3850760 \RP634\A0136309.dll

c:\windows\LastGood.Tmp\system32\D3DX9_39.dll
07/10/2008 12:00 PM 3851784 \RP634\A0136310.dll

c:\windows\LastGood.Tmp\system32\D3DX9_40.dll
10/10/2008 05:52 AM 4379984 \RP634\A0136311.dll

c:\windows\LastGood.Tmp\system32\DRIVERS\nv4_mini.sys
04/30/2009 10:02 PM 8055584 \RP634\A0136356.sys

c:\windows\LastGood.Tmp\system32\nv4_disp.dll
04/30/2009 10:02 PM 5896320 \RP634\A0136357.dll

c:\windows\LastGood.Tmp\system32\x3daudio1_0.dll
02/03/2006 09:41 AM 14032 \RP634\A0136312.dll

c:\windows\LastGood.Tmp\system32\x3daudio1_1.dll
03/05/2007 01:42 PM 15128 \RP634\A0136313.dll

c:\windows\LastGood.Tmp\system32\x3daudio1_2.dll
10/22/2007 04:37 AM 17928 \RP634\A0136314.dll

c:\windows\LastGood.Tmp\system32\X3DAudio1_3.dll
03/05/2008 05:00 PM 25608 \RP634\A0136315.dll

c:\windows\LastGood.Tmp\system32\X3DAudio1_4.dll
05/30/2008 03:17 PM 25608 \RP634\A0136316.dll

c:\windows\LastGood.Tmp\system32\X3DAudio1_5.dll
10/27/2008 11:04 AM 23376 \RP634\A0136317.dll

c:\windows\LastGood.Tmp\system32\xactengine2_0.dll
02/03/2006 09:42 AM 230096 \RP634\A0136318.dll

c:\windows\LastGood.Tmp\system32\xactengine2_1.dll
03/31/2006 01:39 PM 229584 \RP634\A0136319.dll

c:\windows\LastGood.Tmp\system32\xactengine2_10.dll
10/22/2007 04:39 AM 267272 \RP634\A0136320.dll

c:\windows\LastGood.Tmp\system32\xactengine2_2.dll
05/31/2006 08:24 AM 230168 \RP634\A0136321.dll

c:\windows\LastGood.Tmp\system32\xactengine2_3.dll
07/28/2006 10:30 AM 236824 \RP634\A0136322.dll

c:\windows\LastGood.Tmp\system32\xactengine2_4.dll
09/28/2006 05:05 PM 237848 \RP634\A0136323.dll

c:\windows\LastGood.Tmp\system32\xactengine2_5.dll
12/08/2006 01:02 PM 251672 \RP634\A0136324.dll

c:\windows\LastGood.Tmp\system32\xactengine2_6.dll
01/24/2007 04:27 PM 255848 \RP634\A0136325.dll

c:\windows\LastGood.Tmp\system32\xactengine2_7.dll
04/04/2007 07:55 PM 261480 \RP634\A0136326.dll

c:\windows\LastGood.Tmp\system32\xactengine2_8.dll
06/20/2007 09:46 PM 266088 \RP634\A0136327.dll

c:\windows\LastGood.Tmp\system32\xactengine2_9.dll
07/20/2007 01:57 AM 267112 \RP634\A0136328.dll

c:\windows\LastGood.Tmp\system32\xactengine3_0.dll
03/05/2008 05:03 PM 238088 \RP634\A0136329.dll

c:\windows\LastGood.Tmp\system32\xactengine3_1.dll
05/30/2008 03:18 PM 238088 \RP634\A0136330.dll

c:\windows\LastGood.Tmp\system32\xactengine3_2.dll
07/30/2008 07:20 AM 238088 \RP634\A0136331.dll

c:\windows\LastGood.Tmp\system32\xactengine3_3.dll
10/27/2008 11:04 AM 235856 \RP634\A0136332.dll

c:\windows\LastGood.Tmp\system32\XAPOFX1_0.dll
05/30/2008 03:17 PM 65032 \RP634\A0136333.dll

c:\windows\LastGood.Tmp\system32\XAPOFX1_1.dll
07/30/2008 07:20 AM 68616 \RP634\A0136334.dll

c:\windows\LastGood.Tmp\system32\XAPOFX1_2.dll
10/27/2008 11:04 AM 70992 \RP634\A0136335.dll

c:\windows\LastGood.Tmp\system32\XAudio2_0.dll
03/05/2008 05:03 PM 479752 \RP634\A0136336.dll

c:\windows\LastGood.Tmp\system32\XAudio2_1.dll
05/30/2008 03:19 PM 507400 \RP634\A0136337.dll

c:\windows\LastGood.Tmp\system32\XAudio2_2.dll
07/30/2008 07:20 AM 509448 \RP634\A0136338.dll

c:\windows\LastGood.Tmp\system32\XAudio2_3.dll
10/27/2008 11:04 AM 514384 \RP634\A0136339.dll

c:\windows\LastGood.Tmp\system32\xinput1_1.dll
03/31/2006 01:39 PM 62672 \RP634\A0136340.dll

c:\windows\LastGood.Tmp\system32\xinput1_2.dll
07/28/2006 10:30 AM 62744 \RP634\A0136341.dll

c:\windows\LastGood.Tmp\system32\xinput1_3.dll
04/04/2007 07:53 PM 81768 \RP634\A0136342.dll

c:\windows\LastGood.Tmp\system32\xinput9_1_0.dll
12/05/2005 07:07 PM 61136 \RP634\A0136343.dll

c:\windows\patchw32.dll
01/23/2008 02:39 AM 215144 \RP638\A0137466.dll

c:\windows\system32\404Fix.exe
08/18/2008 12:19 PM 82432 \RP638\A0137426.exe

c:\windows\system32\Agent.OMZ.Fix.exe
12/12/2008 01:57 AM 78336 \RP638\A0137427.exe

c:\windows\system32\comsa32.sys
06/21/2009 10:22 AM 8 \RP638\A0137429.sys

03/27/2009 10:03 AM 6186880 c:\windows\system32\dllcache\nv4_disp.dll
10/25/2007 05:17 PM 5767808 \RP634\A0136268.dll

03/27/2009 10:03 AM 6280416 c:\windows\system32\dllcache\nv4_mini.sys
04/30/2009 10:02 PM 8055584 \RP634\A0136267.sys

03/27/2009 10:03 AM 6280416 c:\windows\system32\drivers\nv4_mini.sys
04/30/2009 10:02 PM 8055584 \RP634\A0136347.sys

c:\windows\system32\drivers\rubj.sys
06/23/2009 02:12 PM 61440 \RP639\A0137675.sys

c:\windows\system32\dumphive.exe
07/31/2004 06:50 PM 51200 \RP638\A0137430.exe

c:\windows\system32\IEDFix.C.exe
11/29/2008 06:58 PM 82944 \RP638\A0137431.exe

c:\windows\system32\IEDFix.exe
05/18/2008 09:40 PM 82944 \RP638\A0137432.exe

03/27/2009 10:03 AM 436768 c:\windows\system32\keystone.exe
05/01/2009 12:31 AM 436768 \RP634\A0136253.exe

03/27/2009 10:03 AM 6186880 c:\windows\system32\nv4_disp.dll
04/30/2009 10:02 PM 5896320 \RP634\A0136348.dll

03/27/2009 10:03 AM 667648 c:\windows\system32\nvapi.dll
04/30/2009 10:02 PM 806912 \RP634\A0136266.dll

03/27/2009 10:03 AM 449056 c:\windows\system32\nvappbar.exe
05/01/2009 12:31 AM 449056 \RP634\A0136252.exe

03/27/2009 10:03 AM 139264 c:\windows\system32\nvcod.dll
04/30/2009 10:02 PM 143360 \RP634\A0136263.dll

03/27/2009 10:03 AM 139264 c:\windows\system32\nvcodins.dll
04/30/2009 10:02 PM 143360 \RP634\A0136264.dll

03/27/2009 10:03 AM 143360 c:\windows\system32\nvcolor.exe
05/01/2009 12:30 AM 143360 \RP634\A0136265.exe

03/27/2009 10:03 AM 13684736 c:\windows\system32\nvcpl.dll
05/01/2009 12:30 AM 13750272 \RP634\A0136257.dll

03/27/2009 10:03 AM 1560576 c:\windows\system32\nvcuda.dll
04/30/2009 10:02 PM 1720320 \RP634\A0136269.dll

c:\windows\system32\nvcuvenc.dll
04/30/2009 10:02 PM 1314816 \RP634\A0136271.dll

03/27/2009 10:03 AM 401408 c:\windows\system32\nvcuvid.dll
04/30/2009 10:02 PM 663552 \RP634\A0136270.dll

03/27/2009 10:03 AM 4710400 c:\windows\system32\nvdisps.dll
05/01/2009 12:30 AM 4014080 \RP634\A0136240.dll

03/27/2009 10:03 AM 1346080 c:\windows\system32\nvdspsch.exe
01/15/2009 09:19 AM 1346080 \RP634\A0136250.exe

03/27/2009 10:03 AM 3489792 c:\windows\system32\nvgames.dll
05/01/2009 12:30 AM 3510272 \RP634\A0136241.dll

03/27/2009 10:03 AM 1503232 c:\windows\system32\nview.dll
05/01/2009 12:31 AM 1507328 \RP634\A0136247.dll

03/27/2009 10:03 AM 229376 c:\windows\system32\nvmccs.dll
05/01/2009 12:30 AM 229376 \RP634\A0136258.dll

03/27/2009 10:03 AM 45056 c:\windows\system32\nvmccsrs.dll
01/15/2009 09:19 AM 45056 \RP634\A0136259.dll

03/27/2009 10:03 AM 188416 c:\windows\system32\nvmccss.dll
05/01/2009 12:30 AM 188416 \RP634\A0136242.dll

03/27/2009 10:03 AM 86016 c:\windows\system32\nvmctray.dll
05/01/2009 12:30 AM 86016 \RP634\A0136260.dll

03/27/2009 10:03 AM 1273856 c:\windows\system32\nvmobls.dll
05/01/2009 12:30 AM 1282048 \RP634\A0136243.dll

c:\windows\system32\nvnt4cpl.dll
10/07/2008 01:33 PM 286720 \RP634\A0136255.dll

03/27/2009 10:03 AM 9596928 c:\windows\system32\nvoglnt.dll
04/30/2009 10:02 PM 9994240 \RP634\A0136261.dll

03/27/2009 10:03 AM 466944 c:\windows\system32\nvshell.dll
05/01/2009 12:31 AM 466944 \RP634\A0136248.dll

03/27/2009 10:03 AM 163908 c:\windows\system32\nvsvc32.exe
05/01/2009 12:30 AM 168004 \RP634\A0136262.exe

03/27/2009 10:03 AM 3796992 c:\windows\system32\nvvitvs.dll
05/01/2009 12:30 AM 4038656 \RP634\A0136244.dll

03/27/2009 10:03 AM 81920 c:\windows\system32\nvwddi.dll
05/01/2009 12:30 AM 81920 \RP634\A0136254.dll

03/27/2009 10:03 AM 1724416 c:\windows\system32\nvwdmcpl.dll
05/01/2009 12:31 AM 1724416 \RP634\A0136249.dll

03/27/2009 10:03 AM 1101824 c:\windows\system32\nvwimg.dll
05/01/2009 12:31 AM 1101824 \RP634\A0136251.dll

03/27/2009 10:03 AM 2744320 c:\windows\system32\nvwss.dll
05/01/2009 12:30 AM 3117056 \RP634\A0136245.dll

03/27/2009 10:03 AM 1657376 c:\windows\system32\nwiz.exe
05/01/2009 12:31 AM 1657376 \RP634\A0136256.exe

c:\windows\system32\o4Patch.exe
09/20/2008 12:45 PM 80384 \RP638\A0137433.exe

c:\windows\system32\Process.exe
06/05/2003 09:13 PM 53248 \RP638\A0137434.exe

c:\windows\system32\SKYNETaubodjkl.dll
\RP638\A0137404.dll

c:\windows\system32\SKYNETwsqttomq.dll
\RP638\A0137403.dll

c:\windows\system32\sopidkc.exe
\RP638\A0137435.exe

c:\windows\system32\SrchSTS.exe
04/27/2006 05:49 PM 288417 \RP638\A0137436.exe

04/13/2008 08:12 PM 295424 c:\windows\system32\termsrv.dll
03/14/2009 03:15 AM 295424 \RP639\A0137762.dll

c:\windows\system32\tmp.reg
06/15/2009 04:31 PM 1720 \RP638\A0137437.reg

c:\windows\system32\tpsaxyd.exe
\RP638\A0137438.exe

c:\windows\system32\VACFix.exe
10/01/2008 03:51 PM 87552 \RP638\A0137439.exe

c:\windows\system32\VCCLSID.exe
09/06/2007 12:22 AM 289144 \RP638\A0137440.exe

c:\windows\system32\wiawow32.sys
06/20/2009 10:20 PM 65536 \RP638\A0137441.sys

04/13/2008 08:12 PM 507904 c:\windows\system32\winlogon.exe
03/14/2009 03:15 AM 507904 \RP638\A0137467.exe

c:\windows\system32\WS2Fix.exe
06/02/2009 11:17 AM 75776 \RP638\A0137442.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 81920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-22 518488]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-02 1947928]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"RivaTunerStartupDaemon"="d:\program files\RivaTuner v2.08\RivaTuner.exe" [2008-03-10 2691072]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-27 1657376]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]

c:\documents and settings\John Christian\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000D7}"= "c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABSEHB.DLL" [2006-11-07 77824]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SABWinLogon]
2007-05-14 17:20 176128 ----a-w- c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-31 09:06 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-02 12:29 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AT&T Self Support Tool.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AT&T Self Support Tool.lnk
backup=c:\windows\pss\AT&T Self Support Tool.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ExifLauncher2.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ExifLauncher2.lnk
backup=c:\windows\pss\ExifLauncher2.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^John Christian^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\John Christian\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^John Christian^Start Menu^Programs^Startup^Aquarius Soft PC Alarm Clock Pro.lnk]
path=c:\documents and settings\John Christian\Start Menu\Programs\Startup\Aquarius Soft PC Alarm Clock Pro.lnk
backup=c:\windows\pss\Aquarius Soft PC Alarm Clock Pro.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^John Christian^Start Menu^Programs^Startup^reminder-ScanSoft Product Registration.lnk]
path=c:\documents and settings\John Christian\Start Menu\Programs\Startup\reminder-ScanSoft Product Registration.lnk
backup=c:\windows\pss\reminder-ScanSoft Product Registration.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^John Christian^Start Menu^Programs^Startup^Sins of a Solar Empire Launcher.lnk]
path=c:\documents and settings\John Christian\Start Menu\Programs\Startup\Sins of a Solar Empire Launcher.lnk
backup=c:\windows\pss\Sins of a Solar Empire Launcher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"hpqcxs08"=3 (0x3)
"HPSLPSVC"=2 (0x2)
"hpqddsvc"=2 (0x2)
"ZuneWlanCfgSvc"=3 (0x3)
"ZuneNetworkSvc"=2 (0x2)
"ZuneBusEnum"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"d:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\Steam\\steam.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"d:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Program Files\\EA Games\\Mirror's Edge\\Binaries\\MirrorsEdge.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\USArmy\\America's Army 3\\Binaries\\AA3Game.exe"=
"c:\\Program Files\\HuxleyLite\\binaries\\HuxleyMMOGame.exe"=
"d:\\Program Files\\Activision\\Prototype\\prototypef.exe"=
"d:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\america's army 3\\Binaries\\AA3Game.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57909:TCP"= 57909:TCP:*:Disabled:Pando Media Booster
"57909:UDP"= 57909:UDP:*:Disabled:Pando Media Booster

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/8/2009 10:17 PM 64160]
R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [7/29/2007 3:34 AM 16896]
R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [7/29/2007 3:34 AM 52224]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/15/2009 10:33 AM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/15/2009 10:33 AM 108552]
R1 SABKUTIL;SABKUTIL;c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.SYS [2/20/2007 4:02 PM 32256]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12/4/2008 2:50 PM 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/4/2008 2:50 PM 55024]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/15/2009 10:33 AM 298776]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 5:34 PM 1003344]
R2 ppsio2;PPDevice;c:\windows\system32\drivers\ppsio2.sys [8/27/2007 7:31 PM 23200]
R2 WMDrive;WMDrive;c:\windows\system32\drivers\WMDrive.sys [2/17/2009 3:13 PM 37376]
S1 SABDIFSV;SABDIFSV;c:\program files\SuperAdBlocker.com\Super Ad Blocker\sabdifsv.sys [9/21/2005 11:17 AM 5632]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/4/2008 2:50 PM 7408]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-06-23 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 02:17]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = 127.0.0.1
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-23 14:45
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1547161642-152049171-1801674531-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ec,46,bd,6d,c1,8a,a5,c5,3c,4d,bc,4f,7a,44,7e,ef,18,4d,c4,35,46,87,95,
05,56,d3,65,78,e2,22,6d,e2,bb,c0,9a,58,b5,86,dd,0c,82,19,c3,28,8b,56,e9,81,\
"??"=hex:80,40,06,d0,8e,ad,37,15,76,13,ef,74,08,8e,27,0f

[HKEY_USERS\S-1-5-21-1547161642-152049171-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:d7,cc,7d,6b,10,af,f5,7a,0e,82,a7,31,be,ca,81,d5,24,4f,46,37,ff,
58,66,af,9a,0c,87,a2,14,99,e2,a2,56,28,69,4a,e3,08,87,d1,f0,6a,67,03,9b,57,\
"rkeysecu"=hex:ce,13,31,c2,44,4f,e5,b0,9b,27,0f,62,37,7a,e0,d3

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ř•€|˙˙˙˙•€|ů•A~*]
"5E7CEC10DF0760D4F8DAFB12FDC06CCD"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{01CEC7E5-70FD-4D06-8FAD-BF21DF0CC6DC}\\Registered"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"NoChange"="1"
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
@=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(820)
c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(6836)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABSEHB.DLL
c:\program files\SUPERAntiSpyware\SASSEH.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\nvsvc32.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\TVersity\Media Server\MediaServer.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\program files\Mozilla Firefox\firefox.exe
.
**************************************************************************
.
Completion time: 2009-06-23 14:51 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-23 18:51
ComboFix2.txt 2009-06-22 17:32

Pre-Run: 5,057,720,320 bytes free
Post-Run: 5,098,979,328 bytes free

Current=3 Default=3 Failed=2 LastKnownGood=5 Sets=1,2,3,4,5
719 --- E O F --- 2009-06-11 01:21


This post has been edited by jaysee: Jun 23 2009, 02:03 PM
Go to the top of the page
 
+Quote Post
Transience
post Jun 24 2009, 09:20 AM
Post #15


Unofficial Music Guru
Group Icon
Posts: 2,354
From: Massachusetts, USA
OS: Vista



Those AVG detections are just system restore backups nothing to worry about. The Firefox page problem doesn't sound like a malware redirect to me, but let me know if you get any more.

CF log looks in good shape, so let's run some final checks. Sorry you have to run MBAM again, but I really do want to make sure I get a look at a log of a full scan, not just the quick scan.

First we'll clean out your unnecessary temp files to speed up the scans:

TFC
  • Please download TFC to your desktop.
  • Save any work, then close all open windows.
  • Double-click TFC to run it, and allow the program to complete its run, which should not take more than a couple minutes.
  • You may or may not be prompted to reboot, if you are click "Yes" and allow the computer to reboot.
  • Close TFC when it has completed.


Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware from here.

Doubleclick mbam-setup.exe to install the program.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware at the end of setup, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Full Scan, then click Scan.
  • The scan is different from the quick scan and will take a fairly long time to finish (you can leave it to run and go do something else), please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to restart.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab.
  • Copy & Paste the entire report in your next reply.


Kaspersky Online Scan

Kaspersky online scanner uses Java technology to perform the scan. Because your Java is out of date, we need to update it first so that the scan will run without issues.

Update Java

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts. A log will appear (JavaRa.log), DO NOT post this log, I have no need for it.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

Scan
  1. Follow this link to the Kaspersky WebScanner
  2. Read through the requirements and privacy statement and click on Accept button.
  3. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  4. When the downloads have finished, click on Settings.
  5. Make sure the following is checked.
      Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  6. Click on My Computer under Scan.
  7. Once the scan is complete, it will display the results. Click on View Scan Report.
  8. You will see a list of infected items there. Click on Save Report As....
  9. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  10. Please post this log in your next reply.

So post back with the logs from MBAM and Kaspersky when you have them and give me an update on how the PC is running, and we should have you on your way smile.gif.

- Dave


Go to the top of the page
 
+Quote Post

2 Pages V   1 2 >
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

RSS Time is now: 8th November 2009 - 02:18 AM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising