i did everything you asked.
SDfix Report
SDFix: Version 1.101
Run by Sava on 03/09/2007 at 19:26
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
DomainService
ImagePath:
C:\WINDOWS\System32\uvbpjngl.exe /service
DomainService - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Service xpdx - Deleted after Reboot
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\system32\xpdx.sys - Deleted
Folder C:\Documents and Settings\All Users\Documents\Settings - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
C:\Program Files\Common Files\aolshare\shell\uk\shellext.dll
C:\Program Files\eRightSoft\SUPER\cygwin1.dll
C:\Program Files\eRightSoft\SUPER\cygz.dll
C:\Program Files\eRightSoft\SUPER\mencoder\14_43260.dll
C:\Program Files\eRightSoft\SUPER\mencoder\28_83260.dll
C:\Program Files\eRightSoft\SUPER\mencoder\atrc3260.dll
C:\Program Files\eRightSoft\SUPER\mencoder\cook3260.dll
C:\Program Files\eRightSoft\SUPER\mencoder\ddnt3260.dll
C:\Program Files\eRightSoft\SUPER\mencoder\dnet3260.dll
C:\Program Files\eRightSoft\SUPER\mencoder\drv13260.dll
C:\Program Files\eRightSoft\SUPER\mencoder\drv23260.dll
C:\Program Files\eRightSoft\SUPER\mencoder\drv33260.dll
C:\Program Files\eRightSoft\SUPER\mencoder\drv43260.dll
C:\Program Files\eRightSoft\SUPER\mencoder\dspr3260.dll
C:\Program Files\eRightSoft\SUPER\mencoder\ivvideo.dll
C:\Program Files\eRightSoft\SUPER\mencoder\qtmlClient.dll
C:\Program Files\eRightSoft\SUPER\mencoder\raac.dll
C:\Program Files\eRightSoft\SUPER\mencoder\rnco3260.dll
C:\Program Files\eRightSoft\SUPER\mencoder\rnlt3260.dll
C:\Program Files\eRightSoft\SUPER\mencoder\rv103260.dll
C:\Program Files\eRightSoft\SUPER\mencoder\rv203260.dll
C:\Program Files\eRightSoft\SUPER\mencoder\rv303260.dll
C:\Program Files\eRightSoft\SUPER\mencoder\rv403260.dll
C:\Program Files\eRightSoft\SUPER\mencoder\sipr3260.dll
C:\Program Files\eRightSoft\SUPER\mencoder\tokr3260.dll
C:\WINDOWS\system32\flvDX.dll
C:\Program Files\eRightSoft\SUPER\Setup.exe
C:\Program Files\Smart Projects\IsoBuster\Help\AHlp.exe
C:\Deckard\System Scanner\backup\DOCUME~1\Sava\LOCALS~1\Temp\$b17a2e8.tmp
C:\Documents and Settings\Administrator\Local Settings\Temp\$b17a2e8.tmp
C:\Program Files\InterActual\InterActual Player\iti564.tmp
C:\WINDOWS\system32\ttutv.tmp
Finished
VundoFix Txt
undoFix V6.5.7
Checking Java version...
Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.10
Java version is 1.5.0.11
Scan started at 20:28:42 02/09/2007
Listing files found while scanning....
C:\WINDOWS\System32\ddayv.dll
C:\WINDOWS\System32\vyadd.bak1
C:\WINDOWS\System32\vyadd.ini
C:\WINDOWS\System32\wlaotmwj.dll
Beginning removal...
Attempting to delete C:\WINDOWS\System32\ddayv.dll
C:\WINDOWS\System32\ddayv.dll Could not be deleted.
Attempting to delete C:\WINDOWS\System32\vyadd.bak1
C:\WINDOWS\System32\vyadd.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\System32\vyadd.ini
C:\WINDOWS\System32\vyadd.ini Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.5.7
Checking Java version...
Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.10
Java version is 1.5.0.11
Scan started at 20:36:53 02/09/2007
Listing files found while scanning....
No infected files were found.
Beginning removal...
VundoFix V6.5.7
Checking Java version...
Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.10
Java version is 1.5.0.11
Scan started at 06:48:48 03/09/2007
Listing files found while scanning....
No infected files were found.
Beginning removal...
VundoFix V6.5.7
Checking Java version...
Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.10
Java version is 1.5.0.11
Scan started at 19:42:56 03/09/2007
Listing files found while scanning....
No infected files were found.
Beginning removal...
Beginning removal...
OTMoveIt
C:\WINDOWS\System32\ttutv.ini2 moved successfully.
C:\WINDOWS\System32\ttutv.bak2 moved successfully.
C:\WINDOWS\System32\ttutv.bak1 moved successfully.
File/Folder C:\WINDOWS\System32\xpdx.sys not found.
File/Folder C:\WINDOWS\System32\yayyxxy.dll not found.
File/Folder C:\WINDOWS\System32\uvbpjngl.exe not found.
Created on 09/03/2007 19:57:57
DSS txt
Deckard's System Scanner v20070826.66
Run by Sava on 2007-09-03 20:00:33
Computer is in Normal Mode.
--------------------------------------------------------------------------------
Total Physical Memory: 511 MiB (512 MiB recommended).-- HijackThis (run as Sava.exe) ------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 20:00:46, on 03/09/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Prevx2\PXAgent.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Prevx2\PXConsole.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Sava\Desktop\OTMoveIt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Sava\Desktop\dss.exe
C:\DOCUME~1\Sava\Desktop\Sava.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant =
http://search.bearsh...ar.html?src=ssbR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://search.bearsh...ar.html?src=ssbR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://search.bearsh...ar.html?src=ssbR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
HTTP://WWW.SUPERHEROHYPE.COM/R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://uk.red.client...arch.yahoo.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspee.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: PopupBlockerBHO.CPopupBlockerBHO - {0D929918-C804-4756-B0AC-640EF3F061E9} - C:\Program Files\SmartPopupBlocker\PopupBlockerBHO.dll
O2 - BHO: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspee.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB2.05.0000.1082\en-gb\msntb.dll
O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspee.dll
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx2\PXConsole.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - Startup: OpenOffice.org 1.1.5.lnk = C:\Program Files\OpenOffice.org1.1.5\program\quickstart.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB2.05.0000.1082\en-gb\msntb.dll/search.htm
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB2.05.0001.1119\en-gb\msntabres.dll/229?be73083ee7ac479fa776bfb480fc3aba
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB2.05.0001.1119\en-gb\msntabres.dll/230?be73083ee7ac479fa776bfb480fc3aba
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O20 - Winlogon Notify: vtutt - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: PREVXAgent - Unknown owner - C:\Program Files\Prevx2\PXAgent.exe" -f (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\System32\UAService7.exe (file missing)
-- Files created between 2007-08-03 and 2007-09-03 -----------------------------
2007-09-03 19:25:03 0 d-------- C:\WINDOWS\ERUNT
2007-09-03 15:58:16 0 d-------- C:\Program Files\SmartPopupBlocker
2007-09-03 11:58:13 0 d-------- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\Application Data\Prevx
2007-09-03 11:27:02 0 d-------- C:\Documents and Settings\Sava\Application Data\Prevx
2007-09-03 11:26:00 0 d-------- C:\WINDOWS\LastGood
2007-09-03 11:25:00 0 d-------- C:\Documents and Settings\All Users\Application Data\Prevx
2007-09-03 11:24:59 0 d-------- C:\Program Files\Prevx2
2007-09-02 20:33:45 24576 --a------ C:\WINDOWS\System32\VundoFixSVC.exe <Not Verified; Atribune.org; Vundofix Service>
2007-09-02 20:28:42 0 d------c- C:\VundoFix Backups
2007-09-02 16:21:56 0 dr------- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\Start Menu
2007-09-02 16:21:56 0 dr-h----- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\SendTo
2007-09-02 16:21:56 0 dr-h----- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\Recent
2007-09-02 16:21:56 0 d--h----- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\PrintHood
2007-09-02 16:21:56 0 d--h----- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\NetHood
2007-09-02 16:21:56 0 d-------- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\Desktop
2007-09-02 16:21:56 0 d-------- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\Application Data\InterTrust
2007-09-02 16:21:56 0 d-------- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\Application Data\Identities
2007-09-02 16:21:56 0 d-------- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\Application Data\Help
2007-09-02 16:21:56 0 d-------- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\Application Data\CyberLink
2007-09-01 16:46:41 0 d-------- C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic
2007-08-31 17:51:25 0 d--h----- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\Templates
2007-08-31 17:51:25 0 dr------- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\My Documents
2007-08-31 17:51:25 0 d--h----- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\Local Settings
2007-08-31 17:51:25 0 dr------- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\Favorites
2007-08-31 17:51:25 0 d---s---- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\Cookies
2007-08-31 17:51:25 0 dr-h----- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\Application Data
2007-08-31 17:51:25 0 d-------- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\Application Data\Roxio
2007-08-31 17:51:25 0 d---s---- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\Application Data\Microsoft
2007-08-31 17:51:25 0 d-------- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\Application Data\Adobe
2007-08-31 17:51:24 1048576 --ah----- C:\Documents and Settings\Administrator.YOUR-92A7W51YBH.000\NTUSER.DAT
2007-08-31 13:56:10 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-08-31 13:34:48 0 d-------- C:\Documents and Settings\Sava\Application Data\WinTouch
2007-08-31 13:15:51 0 d-------- C:\Program Files\Spyware Doctor
2007-08-31 13:15:51 0 d-------- C:\Documents and Settings\Sava\Application Data\PC Tools
2007-08-31 12:37:17 0 d-------- C:\Documents and Settings\Sava\Application Data\Uniblue
2007-08-31 12:18:40 0 d-------- C:\Program Files\Debugging Tools for Windows
2007-08-31 11:52:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Grid Blue Memo Site
2007-08-27 19:23:27 0 d-------- C:\Documents and Settings\All Users\Application Data\SpeedBit
2007-08-27 19:23:22 0 d-------- C:\Documents and Settings\Sava\Application Data\SpeedBit
2007-08-27 19:22:39 0 d-------- C:\Program Files\SpeedOptimizer
2007-08-27 19:11:47 0 d-------- C:\Program Files\SpeedBit Video Accelerator
2007-08-27 19:11:46 0 d-------- C:\Program Files\AskPBar
2007-08-27 19:11:28 0 d-------- C:\Program Files\speed-bit
2007-08-27 19:09:10 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-08-27 19:08:53 50688 --a------ C:\WINDOWS\System32\wbhelp2.dll <Not Verified; Stardock.Net, Inc; WindowBlinds for Win32 x86 machines>
2007-08-27 19:08:52 0 d-------- C:\Program Files\DAP
2007-08-23 10:06:06 0 d-------- C:\Program Files\Lavasoft
2007-08-23 10:06:06 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-08-23 10:05:26 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-08-22 21:21:30 0 d------c- C:\Downloads
2007-08-22 21:13:07 0 d-------- C:\Program Files\XviD
2007-08-19 19:20:30 0 d-------- C:\Program Files\XviD(2)
2007-08-18 03:47:40 6553600 --a------ C:\Documents and Settings\Sava\ntuser.dat
2007-08-08 09:22:33 0 d-------- C:\Program Files\InterActual
-- Find3M Report ---------------------------------------------------------------
2007-09-03 19:39:49 0 d-------- C:\Program Files\OpenOffice.org1.1.5
2007-09-02 16:22:04 0 d-------- C:\Program Files\SoftwareOnline
2007-09-01 18:05:12 0 d-------- C:\Program Files\SoftwareRevenue.org
2007-09-01 17:59:08 0 d-------- C:\Program Files\LimeWire
2007-08-31 13:35:30 10 --a------ C:\Program Files\.autoreg
2007-08-27 20:02:54 0 d-------- C:\Program Files\CoreCodec
2007-08-27 20:02:15 0 d-------- C:\Documents and Settings\Sava\Application Data\MP3Rocket
2007-08-23 10:06:04 0 d-------- C:\Documents and Settings\Sava\Application Data\Lavasoft
2007-08-23 10:05:26 0 d-a------ C:\Program Files\Common Files
2007-08-22 21:13:07 0 d-------- C:\Program Files\DivX
2007-07-24 09:51:12 0 d-------- C:\Program Files\Java
2007-07-11 20:56:36 0 d-------- C:\Program Files\BearShare Applications
2007-07-11 20:51:22 0 d-------- C:\Program Files\Incomplete
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2ba521ac-b9b9-4433-ba45-dba2f02cba5a}]
31/07/2007 16:33 1391640 --a------ C:\Program Files\speed-bit\tbspee.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2BA521AC-B9B9-4433-BA45-DBA2F02CBA5A}"= C:\Program Files\speed-bit\tbspee.dll [31/07/2007 16:33 1391640]
[-HKEY_CLASSES_ROOT\CLSID\{2BA521AC-B9B9-4433-BA45-DBA2F02CBA5A}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PrevxOne"="C:\Program Files\Prevx2\PXConsole.exe" [29/08/2007 11:05]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [27/04/2007 09:41]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [12/10/2005 18:13]
"Free Download Manager"="C:\Program Files\Free Download Manager\fdm.exe" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [15/11/2004 16:18]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [03/05/2007 17:43]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" []
C:\Documents and Settings\Sava\Start Menu\Programs\Startup\
OpenOffice.org 1.1.5.lnk - C:\Program Files\OpenOffice.org1.1.5\program\quickstart.exe [12/07/2005 02:10:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtutt]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"= :\WINDOW
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Sava^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Sava\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Sava^Start Menu^Programs^Startup^Morpheus.lnk]
path=C:\Documents and Settings\Sava\Start Menu\Programs\Startup\Morpheus.lnk
backup=C:\WINDOWS\pss\Morpheus.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet Acceleration Patch]
C:\Documents and Settings\All Users\Start Menu\Programs\BitComet Acceleration Patch\BitComet Acceleration Patch.lnk
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey]
zHotkey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X5100 Series]
"C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ML1HelperStartUp]
C:\PROGRA~1\MIDNIG~1\ML1HEL~1.EXE /partner ML1
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Morpheus Download Booster]
C:\Program Files\Morpheus Download Booster\Morpheus Download Booster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]
rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
"C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioAudioCentral]
"C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
"C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioEngineUtility]
"C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunKistEM]
C:\Program Files\eMachines Bay Reader\shwiconem.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSave]
"C:\Program Files\Save\Save.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSearch]
"C:\Program Files\WhenUSearch\Search.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSearchWHSE]
"C:\Program Files\WhenUSearch\whse.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Workflow]
D:\Workflow.exe
-- End of Deckard's System Scanner: finished at 2007-09-03 20:01:17 ------------
i'm not getting the popups anymore