Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

kxvo.exe PLEASE HELP [RESOLVED]


  • This topic is locked This topic is locked

#376
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hi please use the Hosts expert program as instucted 2 posts prior if you did use that then let me know but I do not see evidence of it in your log.
Do that reboot and let me know if the browser still redirects.
  • 0

Advertisements


#377
amm007

amm007

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 265 posts
redirection still present. are we sure that the URL is a bad redirect?
  • 0

#378
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
It's not as long as you use opendns?
It is a legit website but let me know about that.
  • 0

#379
amm007

amm007

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 265 posts
i am redirected to opendns when i type random sites. most of the time, it replaces the cannot find server page.
  • 0

#380
amm007

amm007

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 265 posts
by the way, i do not use or subscribe to opendns either.
  • 0

#381
amm007

amm007

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 265 posts
by the way, i do not use or subscribe to opendns either.
  • 0

#382
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hi please visit this ink and see if that will help with your redirecions.
Please then post a new Rsit log.
Let me know how it goes.
  • 0

#383
amm007

amm007

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 265 posts
what link will i visit?
  • 0

#384
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
http://www.labnol.or...ss-bar-ie/2662/
Sorry.
  • 0

#385
amm007

amm007

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 265 posts
after following the directions from the link, the redirection is now gone.

Logfile of random's system information tool 1.04 (written by random/random)
Run by Ruberc at 2008-11-03 23:19:53
Microsoft Windows XP Professional Service Pack 3
System drive C: has 2 GB (9%) free of 20 GB
Total RAM: 502 MB (6% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:20:31 PM, on 11/3/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\DRIVERS\dcfssvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\QCONSVC.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\RunDll32.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Documents and Settings\Ruberc\Application Data\Smilebox\SmileboxTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ChikkaV4\ChikkaLauncher.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Documents and Settings\Ruberc\Desktop\RSIT.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Ruberc.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe"
O4 - HKCU\..\Run: [EPSON Stylus C90 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBZP.EXE /FU "C:\WINDOWS\TEMP\E_S250.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [SmileboxTray] "C:\Documents and Settings\Ruberc\Application Data\Smilebox\SmileboxTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Chessmaster Challenge\Images\stg_drm.ocx
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitd...can8/oscan8.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-sec...m/ols/fscax.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Chessmaster Challenge\Images\armhelper.ocx
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: dcfssvc (Dcfssvc) - Eastman Kodak Company - C:\WINDOWS\system32\DRIVERS\dcfssvc.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe

--
End of file - 7379 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\BMMTask.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2008-08-30 455960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-08-30 2055960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}]
EpsonToolBandKicker Class - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EE5D279F-081B-4404-994D-C6B60AAEBA6D} - EPSON Web-To-Page - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-08-30 2055960]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BMMGAG"=RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll []
"BLOG"=C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL [2005-04-20 208896]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-09-30 1234712]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"snpstd3"=C:\WINDOWS\vsnpstd3.exe [2006-09-19 827392]
"DAEMON Tools-1033"=C:\Program Files\D-Tools\daemon.exe [2004-03-12 81920]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"=C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE [2007-08-30 4670704]
"BitTorrent"=C:\Program Files\BitTorrent\bittorrent.exe [2008-09-27 634672]
"EPSON Stylus C90 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBZP.EXE [2006-09-27 139264]
"SmileboxTray"=C:\Documents and Settings\Ruberc\Application Data\Smilebox\SmileboxTray.exe [2008-10-16 254600]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
; C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
; C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-09-30 1234712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BMMLREF]
; C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BMMMONWND]
; rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer]
; C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EZEJMNAP]
; C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
; C:\WINDOWS\system32\hkcmd.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
; C:\WINDOWS\system32\igfxtray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
; C:\Program Files\iTunes\iTunesHelper.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
; C:\Program Files\MSN Messenger\MsnMsgr.Exe /background []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
; C:\WINDOWS\system32\NeroCheck.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
; C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
; C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QCTRAY]
; C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QCWLICON]
; C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
; C:\Program Files\QuickTime\qttask.exe -atboottime []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
; C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmileboxTray]
C:\Documents and Settings\Ruberc\Application Data\Smilebox\SmileboxTray.exe [2008-10-16 254600]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
; C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
; C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe [2008-03-25 144784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TP4EX]
; tp4ex.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPHOTKEY]
; C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPKMAPHELPER]
; C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrackPointSrv]
; tp4serv.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ruberc^Start Menu^Programs^Startup^Adobe Gamma.lnk]
C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE [2005-03-16 113664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="avgrsstx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2004-11-02 348160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\QConGina]
C:\WINDOWS\system32\QConGina.dll [2005-03-18 262144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tphotkey]
C:\WINDOWS\system32\tphklock.dll [2004-08-12 24576]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"NoDrives"=
"NoDriveAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\TDS_SCC\Worms 4 Mayhem\WORMS 4 MAYHEM.EXE"="C:\Program Files\TDS_SCC\Worms 4 Mayhem\WORMS 4 MAYHEM.EXE:*:Enabled:Worms 4 Mayhem"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
shell\AutoRun\command - F:\setup.exe


======List of files/folders created in the last 1 months======

2008-11-02 21:27:31 ----D---- C:\ConvertTemp
2008-11-02 21:10:57 ----D---- C:\Documents and Settings\Ruberc\Application Data\Samsung
2008-11-02 20:59:15 ----A---- C:\WINDOWS\system32\framedyn.dll
2008-11-02 20:58:30 ----A---- C:\WINDOWS\system32\msvcr71.dll
2008-11-02 20:54:35 ----D---- C:\WINDOWS\system32\Samsung_USB_Drivers
2008-11-02 20:53:41 ----D---- C:\Documents and Settings\Ruberc\Application Data\Shutterfly
2008-11-02 20:52:23 ----D---- C:\Program Files\Samsung
2008-11-02 20:50:23 ----D---- C:\Program Files\Shutterfly
2008-10-31 12:39:14 ----D---- C:\Documents and Settings\Ruberc\Application Data\Ahead
2008-10-31 12:21:06 ----D---- C:\Program Files\Nero
2008-10-29 00:18:44 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2008-10-27 22:13:17 ----D---- C:\WINDOWS\Prefetch
2008-10-27 21:43:18 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2008-10-27 21:43:10 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2008-10-27 21:42:57 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2008-10-27 21:42:49 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2008-10-27 21:42:40 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2008-10-27 21:42:29 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-10-27 21:42:21 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-10-27 21:42:12 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2008-10-27 21:42:02 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-10-27 21:41:55 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-10-27 21:41:48 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2008-10-27 21:41:36 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-10-27 21:41:29 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-10-27 21:41:22 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-10-27 21:41:13 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-10-27 21:41:05 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-10-27 21:31:43 ----D---- C:\WINDOWS\system32\scripting
2008-10-27 21:31:40 ----D---- C:\WINDOWS\l2schemas
2008-10-27 21:31:38 ----D---- C:\WINDOWS\system32\en
2008-10-27 21:31:37 ----D---- C:\WINDOWS\system32\bits
2008-10-27 21:25:54 ----D---- C:\WINDOWS\ServicePackFiles
2008-10-27 21:09:05 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-10-25 12:11:23 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
2008-10-21 14:25:23 ----SHD---- C:\RECYCLER
2008-10-21 09:34:24 ----D---- C:\WINDOWS\temp
2008-10-21 09:34:18 ----A---- C:\ComboFix.txt
2008-10-21 09:22:30 ----D---- C:\ComboFix
2008-10-21 09:20:45 ----A---- C:\Boot.bak
2008-10-21 09:20:30 ----D---- C:\cmdcons
2008-10-21 09:10:20 ----A---- C:\WINDOWS\NIRCMD.exe
2008-10-21 09:10:19 ----A---- C:\WINDOWS\zip.exe
2008-10-21 09:10:19 ----A---- C:\WINDOWS\VFIND.exe
2008-10-21 09:10:19 ----A---- C:\WINDOWS\SWXCACLS.exe
2008-10-21 09:10:19 ----A---- C:\WINDOWS\SWSC.exe
2008-10-21 09:10:19 ----A---- C:\WINDOWS\SWREG.exe
2008-10-21 09:10:19 ----A---- C:\WINDOWS\sed.exe
2008-10-21 09:10:19 ----A---- C:\WINDOWS\grep.exe
2008-10-21 09:10:19 ----A---- C:\WINDOWS\fdsv.exe
2008-10-21 09:09:50 ----D---- C:\WINDOWS\ERDNT
2008-10-21 09:09:50 ----D---- C:\Qoobox
2008-10-19 20:34:49 ----D---- C:\rsit
2008-10-16 08:58:23 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
2008-10-16 08:55:41 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2008-10-16 08:52:58 ----HDC---- C:\WINDOWS\$NtUninstallKB957095_0$
2008-10-16 08:29:44 ----HDC---- C:\WINDOWS\$NtUninstallKB954211_0$
2008-10-16 08:16:25 ----HDC---- C:\WINDOWS\$NtUninstallKB956841_0$

======List of files/folders modified in the last 1 months======

2008-11-03 23:18:43 ----D---- C:\Documents and Settings\Ruberc\Application Data\BitTorrent
2008-11-03 12:40:46 ----D---- C:\WINDOWS\system32\CatRoot2
2008-11-03 10:18:32 ----D---- C:\Program Files\Mozilla Firefox
2008-11-03 07:27:36 ----D---- C:\WINDOWS
2008-11-03 01:21:57 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-11-02 22:12:28 ----A---- C:\WINDOWS\NeroDigital.ini
2008-11-02 21:25:43 ----RSD---- C:\WINDOWS\Fonts
2008-11-02 21:19:35 ----D---- C:\WINDOWS\system32\drivers
2008-11-02 21:19:23 ----HD---- C:\WINDOWS\inf
2008-11-02 20:59:15 ----D---- C:\WINDOWS\system32
2008-11-02 20:54:14 ----SHD---- C:\WINDOWS\Installer
2008-11-02 20:52:23 ----D---- C:\Program Files
2008-11-02 20:52:10 ----HD---- C:\Program Files\InstallShield Installation Information
2008-11-02 20:30:00 ----D---- C:\Documents and Settings\Ruberc\Application Data\Smilebox
2008-10-31 12:42:50 ----D---- C:\Program Files\Common Files\Ahead
2008-10-31 11:52:08 ----D---- C:\Program Files\Ahead
2008-10-29 00:18:49 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-10-28 23:31:36 ----HD---- C:\WINDOWS\$hf_mig$
2008-10-27 22:17:15 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-27 22:16:57 ----A---- C:\WINDOWS\OEWABLog.txt
2008-10-27 22:13:30 ----A---- C:\WINDOWS\setuplog.txt
2008-10-27 22:12:29 ----D---- C:\WINDOWS\system32\Setup
2008-10-27 22:12:29 ----D---- C:\WINDOWS\ime
2008-10-27 22:12:28 ----D---- C:\WINDOWS\AppPatch
2008-10-27 22:12:27 ----D---- C:\WINDOWS\system32\wbem
2008-10-27 22:11:28 ----D---- C:\WINDOWS\security
2008-10-27 21:43:24 ----A---- C:\WINDOWS\imsins.BAK
2008-10-27 21:43:20 ----D---- C:\WINDOWS\system32\CatRoot
2008-10-27 21:41:15 ----D---- C:\Program Files\Messenger
2008-10-27 21:33:20 ----D---- C:\WINDOWS\WinSxS
2008-10-27 21:33:08 ----D---- C:\Program Files\Windows Media Player
2008-10-27 21:32:17 ----D---- C:\WINDOWS\system32\inetsrv
2008-10-27 21:32:16 ----D---- C:\WINDOWS\network diagnostic
2008-10-27 21:32:16 ----D---- C:\WINDOWS\Help
2008-10-27 21:31:46 ----D---- C:\WINDOWS\system32\usmt
2008-10-27 21:31:46 ----D---- C:\WINDOWS\system32\en-US
2008-10-27 21:31:37 ----D---- C:\WINDOWS\PeerNet
2008-10-27 21:31:37 ----D---- C:\Program Files\Movie Maker
2008-10-27 21:25:31 ----D---- C:\WINDOWS\system32\Restore
2008-10-27 21:25:31 ----D---- C:\WINDOWS\system32\npp
2008-10-27 21:25:30 ----D---- C:\WINDOWS\mui
2008-10-27 21:25:27 ----D---- C:\WINDOWS\msagent
2008-10-27 21:25:25 ----D---- C:\WINDOWS\srchasst
2008-10-27 21:25:23 ----D---- C:\Program Files\NetMeeting
2008-10-27 21:25:20 ----D---- C:\WINDOWS\system32\Com
2008-10-27 21:25:13 ----D---- C:\Program Files\Windows NT
2008-10-27 21:25:13 ----D---- C:\Program Files\Outlook Express
2008-10-27 21:25:03 ----D---- C:\Program Files\Common Files\System
2008-10-27 21:24:13 ----D---- C:\WINDOWS\system32\oobe
2008-10-27 21:24:08 ----D---- C:\WINDOWS\system
2008-10-27 21:19:34 ----RD---- C:\WINDOWS\Web
2008-10-27 21:16:46 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-10-27 21:09:01 ----D---- C:\WINDOWS\ehome
2008-10-25 10:22:59 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-21 09:29:01 ----A---- C:\WINDOWS\system.ini
2008-10-21 09:27:06 ----D---- C:\Program Files\Common Files
2008-10-21 09:20:45 ----RASH---- C:\boot.ini
2008-10-21 09:10:19 ----SHD---- C:\System Volume Information
2008-10-16 08:46:53 ----D---- C:\Program Files\Internet Explorer
2008-10-16 00:34:24 ----A---- C:\WINDOWS\system32\netapi32.dll
2008-10-14 08:42:18 ----D---- C:\Program Files\BitTorrent
2008-10-09 19:35:02 ----HD---- C:\$AVG8.VAULT$
2008-10-08 03:19:40 ----A---- C:\WINDOWS\system32\MRT.exe
2008-10-04 01:41:15 ----A---- C:\WINDOWS\system32\ieframe.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ANC;ANC; C:\WINDOWS\System32\drivers\ANC.SYS [2005-03-18 11520]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-08-30 97928]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2008-08-30 26824]
R1 DcCam;Kodak Camera Proxy; C:\WINDOWS\system32\DRIVERS\DcCam.sys [2000-06-08 29104]
R1 IBMTPCHK;IBMTPCHK; C:\WINDOWS\System32\drivers\IBMBLDID.SYS [2005-03-18 2432]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
R1 TPHKDRV;TPHKDRV; C:\WINDOWS\system32\drivers\TPHKDRV.sys [2004-09-06 16370]
R1 TPPWR;TPPWR; C:\WINDOWS\System32\drivers\Tppwr.sys [2005-04-20 16384]
R1 TSMAPIP;TSMAPIP; C:\WINDOWS\System32\drivers\TSMAPIP.SYS [2004-12-01 7168]
R2 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-08-30 76040]
R2 DCFS2k;DCFS2k; C:\WINDOWS\system32\DRIVERS\DCFS2k.sys [2000-05-29 35637]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2004-04-07 116176]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\System32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 DcLps;Legacy Polling Service; C:\WINDOWS\system32\DRIVERS\DcLps.sys [2000-06-08 8272]
R3 E100B;Intel® PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2003-09-17 145408]
R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2006-09-19 15664]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2004-11-10 1041664]
R3 HSFHWICH;HSFHWICH; C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys [2004-11-10 200448]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2004-11-02 773565]
R3 IBMPMDRV;IBMPMDRV; C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys [2004-11-05 12944]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-23 12160]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2004-06-23 266880]
R3 Tp4Track;IBM PS/2 TrackPoint Driver; C:\WINDOWS\system32\DRIVERS\tp4track.sys [2004-10-28 13904]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 w29n51;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows XP; C:\WINDOWS\system32\DRIVERS\w29n51.sys [2004-10-29 3222784]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2004-11-10 685184]
S1 Exportit;Exportit; C:\WINDOWS\system32\DRIVERS\exportit.sys [2000-06-27 115509]
S1 InCDPass;InCDPass; C:\WINDOWS\system32\drivers\InCDPass.sys []
S1 InCDRm;InCD Reader; C:\WINDOWS\system32\drivers\InCDRm.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 DcFpoint;DcFpoint; C:\WINDOWS\system32\DRIVERS\DcFpoint.sys [2000-06-08 61424]
S3 DcPTP;%DcPTP.SvcDesc%; C:\WINDOWS\system32\DRIVERS\DcPTP.sys [2000-06-08 47728]
S3 gmer;gmer; C:\WINDOWS\System32\DRIVERS\gmer.sys [2008-07-02 86097]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 Nokia USB Generic;Nokia USB Generic; C:\WINDOWS\system32\drivers\nmwcdc.sys [2005-02-15 6300]
S3 Nokia USB Modem;Nokia USB Modem; C:\WINDOWS\system32\drivers\nmwcdcm.sys [2005-02-15 9021]
S3 Nokia USB Phone Parent;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\nmwcd.sys [2005-02-17 140619]
S3 QCNDISIF;QCNDISIF; C:\WINDOWS\System32\drivers\qcndisif.SYS [2005-03-18 12288]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 SNPSTD3;USB PC Camera (SNPSTD3); C:\WINDOWS\system32\DRIVERS\snpstd3.sys [2007-03-27 10252544]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 ssm_bus;SAMSUNG Mobile USB Device II 1.0 driver (WDM); C:\WINDOWS\system32\DRIVERS\ssm_bus.sys [2005-08-30 58320]
S3 ssm_mdfl;SAMSUNG Mobile USB Modem II 1.0 Filter; C:\WINDOWS\system32\DRIVERS\ssm_mdfl.sys [2005-08-30 8336]
S3 ssm_mdm;SAMSUNG Mobile USB Modem II 1.0 Drivers; C:\WINDOWS\system32\DRIVERS\ssm_mdm.sys [2005-08-30 94000]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 TwoTrack;IBM PS/2 TrackPoint Filter Driver; C:\WINDOWS\System32\DRIVERS\TwoTrack.sys [2001-08-17 11520]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S4 InCDFs;InCD File System; C:\WINDOWS\system32\drivers\InCDFs.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-30 875288]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-30 231704]
R2 Dcfssvc;dcfssvc; C:\WINDOWS\system32\DRIVERS\dcfssvc.exe [2000-05-18 75324]
R2 IBMPMSVC;IBM PM Service; C:\WINDOWS\system32\ibmpmsvc.exe [2004-11-05 57344]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 QCONSVC;QCONSVC; C:\WINDOWS\System32\QCONSVC.EXE [2005-03-18 77824]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
R2 TpKmpSVC;IBM KCU Service; C:\WINDOWS\system32\TpKmpSVC.exe [2003-07-11 32768]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2007-11-25 72704]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2007-04-27 500800]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 Visual Studio Analyzer RPC bridge;Visual Studio Analyzer RPC bridge; C:\Program Files\Microsoft Visual Studio\Common\Tools\VS-Ent98\Vanalyzr\varpc.exe [1998-06-06 34036]

-----------------EOF-----------------
  • 0

Advertisements


#386
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
We can move on to the next computer if you are satisifed with this one now after doing the below this compute rwill be clean.
=====================
Please open up Notepad and copy all of the items in the code box below.
Change the "Save As Type" to "All Files". Save it as fixthis.reg on your Desktop.
REGEDIT4

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
Now double-click fixthis.reg.
A window will come up asking if you want to let it merge with the registry.
Click yes.
You can delete that file after it merges.
========================================
Cleanup:

Please download OT CLeanit from Here save it to your desktop.
Double click on OT Clean it to run it.
Then click on Clean up.
Restart your computer when prompted.
This will remove what tools we used.
===============
Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 10...allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u10-windows-i586-p.exe to install the newest version.

======================
Use a Firewall:

Install and use a firewall with outbound protection
While the firewall built into Windows XP is adequate to protect you from incoming attacks, it will not be much help in alerting you to programs already on your PC attempting to connect to remote servers
I therefore strongly recommend that you install one of the following free firewalls: Sunbelt Free Firewall or Zonealarm
See Bleepingcomputer's excellent tutorial to help using and understanding a firewall here
Note: You should only have one firewall installed at a time. Having more than one antivirus program installed at once is likely to cause conflicts and may well decrease your overall protection as well as seriously impairing the performance of your PC.


=============================
Delete\uninstall anything else that we have used.

System Restore
Then I will need you to reset your System Restore points.
The link below shows how to create a clean restore point.
How to Turn On and Turn Off System Restore in Windows XP
http://support.micro...kb/310405/en-us

If you are using Vista then see this link > http://www.bleepingc...143.html#manual
=====================================
After that your log is clean. :)

The following is a list of tools and utilities that I like to suggest to people.
You do not have to have all or any of them they are only suggestions.
This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.

Spybot Search & Destroy-Uber powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.

Spyware Blaster - Great prevention tool to keep nasties from installing on your system.

Spywareguard-Works as a Spyware "Shield" to protect your computer from getting malware in the first place.

Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.

Tony Klein article To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein.
  • 0

#387
amm007

amm007

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 265 posts
i have already done the clean up steps.i am just updating java at the moment.as for the third computer, i just opted to reformat it since there is not much of important files there. ill just observe this computer's performance for the next days. thanks a lot.. i might be joining the training for volunteers in my free time.
  • 0

#388
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Sounds good and let me know how it goes and we will wrap it up.
  • 0

#389
amm007

amm007

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 265 posts
i think the computer works perfectly well now...

btw, i would really like to join the training here..thanks! :)
  • 0

#390
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Ok sign up Here.

But it appears we are finnaly done with this one.
Thanks for sticking with it and safe surfing.

You are welcome :)


Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If your the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP