Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Want to know if my computer is infected [RESOLVED]


  • This topic is locked This topic is locked

#1
demoman

demoman

    Member

  • Member
  • PipPip
  • 11 posts
I have already done the ,"You must read this before posting a Hijack Log"

I did the scans nessesary and they had come up with multiple viruses and spyware.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:05:39 AM, on 3/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Documents and Settings\DEMOSSE\Desktop\Computer protection\Remove keylogger\Antispyware\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Mcafee\MWL\MWLGui.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Documents and Settings\DEMOSSE\Desktop\Computer protection\Remove keylogger\Antispyware\avgas.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Documents and Settings\DEMOSSE\Desktop\Computer protection\Remove keylogger\SUPER anti spyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Wireless 802.11g USB Adapter\ZDWlan.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mcafee\MWL\MwlSvc.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Documents and Settings\DEMOSSE\Desktop\Computer protection\Remove keylogger\Hijack this NEW\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.daemonsearch.com/intl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;*.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\SiteAdv.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - C:\Program Files\McAfee\MSK\mcapbho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll (file missing)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll (file missing)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\SiteAdv.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MWLExe] C:\Program Files\Mcafee\MWL\MWLGui.exe /Start
O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\DEMOSSE\Desktop\Computer protection\Remove keylogger\Antispyware\avgas.exe" /minimized
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uptodate] C:\WINDOWS\system32\autocxk.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Documents and Settings\DEMOSSE\Desktop\Computer protection\Remove keylogger\SUPER anti spyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [Magnify] Magnify.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [] OSK.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Wireless 802.11g USB Adapter.lnk = C:\Program Files\Wireless 802.11g USB Adapter\ZDWlan.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-au\msntabres.dll.mui/229?e781fe2fbd9044f786e03fc6d7c6a696
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-au\msntabres.dll.mui/230?e781fe2fbd9044f786e03fc6d7c6a696
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail....es/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zon...1/GAME_UNO1.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zon...nt.cab56907.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Documents and Settings\DEMOSSE\Desktop\Computer protection\Remove keylogger\SUPER anti spyware\SASWINLO.dll
O21 - SSODL: Midieng - {E21C7CF8-6F67-4519-9749-A9BDE2D1F94B} - C:\WINDOWS\system32\vgareg.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Documents and Settings\DEMOSSE\Desktop\Computer protection\Remove keylogger\Antispyware\guard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: MSSQL$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing)
O23 - Service: McAfee Wireless Network Security Service (MWLSvc) - McAfee, Inc. - C:\Program Files\Mcafee\MWL\MwlSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SQLAgent$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing)
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe (file missing)
O24 - Desktop Component 1: (no name) - http://www.google.com.au/

--
End of file - 14103 bytes


Thanks for help
hopefully this is enough
  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Still a few bits to remove

Download and save to your desktop OTCleanit we will use this later


Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O4 - HKCU\..\Run: [Uptodate] C:\WINDOWS\system32\autocxk.exe
O21 - SSODL: Midieng - {E21C7CF8-6F67-4519-9749-A9BDE2D1F94B} - C:\WINDOWS\system32\vgareg.dll (file missing)

Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.

THEN

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\WINDOWS\system32\autocxk.exe
    C:\WINDOWS\system32\vgareg.dll
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light blue bar) and choose Paste.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Purity
  • Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

FINALLY FOR NOW

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

  • 0

#3
demoman

demoman

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
thanks for help

here is the info you requested

a question: What do I do with the OTcleanit?

This is OTmoveit's log:

File/Folder C:\WINDOWS\system32\autocxk.exe not found.
File/Folder C:\WINDOWS\system32\vgareg.dll not found.
[Custom Input]
< Purity >
C:\WINDOWS\a?sembly moved successfully.
C:\WINDOWS\s?mbols moved successfully.
C:\WINDOWS\??stem moved successfully.
C:\WINDOWS\system32\?icrosoft moved successfully.
C:\WINDOWS\system32\?ymbols\?ymbols moved successfully.
C:\WINDOWS\system32\?ymbols moved successfully.
C:\Program Files\F?nts moved successfully.
C:\Program Files\M?crosoft moved successfully.
C:\Program Files\W?nSxS moved successfully.
C:\Program Files\Common Files\s?curity moved successfully.
C:\Program Files\Common Files\S?mantec moved successfully.
C:\Documents and Settings\DEMOSSE\Application Data\??mbols moved successfully.
C:\Documents and Settings\DEMOSSE\Application Data\s?stem moved successfully.
C:\Documents and Settings\DEMOSSE\Application Data\W?nSxS moved successfully.

OTMoveIt2 by OldTimer - Version 1.0.21 log created on 03172008_144251

This is the Main.txt from DSS:

Deckard's System Scanner v20071014.68
Run by DEMOSSE on 2008-03-17 14:45:08
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
13: 2008-03-17 04:45:13 UTC - RP719 - Deckard's System Scanner Restore Point
12: 2008-03-17 04:25:00 UTC - RP718 - Installed Styler
11: 2008-03-16 02:17:52 UTC - RP717 - Installed Battlefield 2 Patch v1.41
10: 2008-03-16 02:05:33 UTC - RP716 - Installed Battlefield 2: Deluxe Edition
9: 2008-03-16 02:02:08 UTC - RP715 - Removed Battlefield 2: Deluxe Edition


-- First Restore Point --
1: 2008-03-15 04:49:38 UTC - RP707 - Remove [bleep] restore


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as DEMOSSE.exe) ---------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:46:46 PM, on 3/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mcafee\MWL\MwlSvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Mcafee\MWL\MWLGui.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Wireless 802.11g USB Adapter\ZDWlan.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Documents and Settings\DEMOSSE\Desktop\Computer protection\Remove keylogger\dss.exe
C:\DOCUME~1\DEMOSSE\Desktop\COMPUT~1\REMOVE~1\HIJACK~3\DEMOSSE.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.daemonsearch.com/intl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;*.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\SiteAdv.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - C:\Program Files\McAfee\MSK\mcapbho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll (file missing)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll (file missing)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\SiteAdv.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MWLExe] C:\Program Files\Mcafee\MWL\MWLGui.exe /Start
O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [Magnify] Magnify.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [] OSK.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Styler.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Wireless 802.11g USB Adapter.lnk = C:\Program Files\Wireless 802.11g USB Adapter\ZDWlan.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-au\msntabres.dll.mui/229?e781fe2fbd9044f786e03fc6d7c6a696
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-au\msntabres.dll.mui/230?e781fe2fbd9044f786e03fc6d7c6a696
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail....es/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zon...1/GAME_UNO1.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zon...nt.cab56907.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: MSSQL$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing)
O23 - Service: McAfee Wireless Network Security Service (MWLSvc) - McAfee, Inc. - C:\Program Files\Mcafee\MWL\MwlSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SQLAgent$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing)
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe (file missing)
O24 - Desktop Component 1: (no name) - http://www.google.com.au/

--
End of file - 12906 bytes

-- HijackThis Fixed Entries (C:\DOCUME~1\DEMOSSE\Desktop\COMPUT~1\REMOVE~1\HIJACK~3\backups\) --------------------------------------------------------------------------------

backup-20080317-144050-674 O4 - HKCU\..\Run: [Uptodate] C:\WINDOWS\system32\autocxk.exe
backup-20080317-144050-807 O21 - SSODL: Midieng - {E21C7CF8-6F67-4519-9749-A9BDE2D1F94B} - C:\WINDOWS\system32\vgareg.dll (file missing)

-- File Associations -----------------------------------------------------------

.scr - AutoCADScriptFile - shell\open\command - "C:\WINDOWS\system32\notepad.exe" "%1"


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R0 prohlp02 (StarForce Protection Helper Driver v2) - c:\windows\system32\drivers\prohlp02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfhlp01 (StarForce Protection Helper Driver) - c:\windows\system32\drivers\sfhlp01.sys <Not Verified; Protection Technology; StarForce Protection System>
R1 prodrv06 (StarForce Protection Environment Driver v6) - c:\windows\system32\drivers\prodrv06.sys <Not Verified; Protection Technology; StarForce Protection System>
R1 StarOpen - c:\windows\system32\drivers\staropen.sys
R1 UBHelper - c:\windows\system32\drivers\ubhelper.sys
R3 AgereSoftModem (Agere Systems Soft Modem) - c:\windows\system32\drivers\agrsm.sys <Not Verified; Agere Systems; Agere SoftModem Driver>
R3 DNE (Deterministic Network Enhancer Miniport) - c:\windows\system32\drivers\dne2000.sys <Not Verified; Deterministic Networks, Inc.; >
R3 ezplay (VSO Software ezplay) - c:\windows\system32\drivers\ezplay.sys <Not Verified; VSO Software; ezplay driver>
R3 Maplom - c:\windows\system32\drivers\maplom.sys <Not Verified; SlySoft Inc.; Game Jackal>
R3 NTIDrvr (Upper Class Filter Driver) - c:\windows\system32\drivers\ntidrvr.sys <Not Verified; NewTech Infosystems, Inc.; >
R3 pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>

S2 int15.sys - x:\int15.sys (file missing)
S3 ASPI (Advanced SCSI Programming Interface Driver) - c:\windows\system32\drivers\aspi32.sys <Not Verified; Adaptec; Adaptec's ASPI Layer>
S3 dtscsi - c:\windows\system32\drivers\dtscsi.sys (file missing)
S3 RT73 (Belkin USB Network Adapter) - c:\windows\system32\drivers\rt73.sys <Not Verified; Ralink Technology, Corp.; Ralink 802.11 Wireless Adapters>
S3 ssm_bus (SAMSUNG Mobile USB Device II 1.0 driver (WDM)) - c:\windows\system32\drivers\ssm_bus.sys <Not Verified; MCCI; SAMSUNG Mobile USB Device II 1.0>
S3 ssm_mdfl (SAMSUNG Mobile USB Modem II 1.0 Filter) - c:\windows\system32\drivers\ssm_mdfl.sys <Not Verified; MCCI; SAMSUNG Mobile USB Modem II 1.0 Filter Driver>
S3 ssm_mdm (SAMSUNG Mobile USB Port II 1.0 Drivers) - c:\windows\system32\drivers\ssm_mdm.sys <Not Verified; MCCI; SAMSUNG Mobile USB Modem II 1.0>
S3 ZD1211U(ZyDAS) (ZyDAS ZD1211 IEEE 802.11b+g Wireless LAN Driver (USB)(ZyDAS)) - c:\windows\system32\drivers\zd1211u.sys <Not Verified; ZyDAS Technology Corporation; ZD1211 802.11b+g USB LAN Adapter>
S3 ZDBRGSYS (ZDBRGSYS NDIS Protocol Driver) - c:\windows\system32\zdbrgsys.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
S3 ZDPNDIS5 (ZDPNDIS5 NDIS Protocol Driver) - c:\windows\system32\zdpndis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>

S2 StyleXPService - "c:\program files\tgtsoft\stylexp\stylexpservice.exe" (file missing)
S3 gusvc (Google Updater Service) - "c:\program files\google\common\google updater\googleupdaterservice.exe" (file missing)
S3 MSSQL$SONY_MEDIAMGR - c:\program files\sony\shared plug-ins\media manager\mssql$sony_mediamgr\binn\sqlservr.exe -ssony_mediamgr (file missing)
S3 SQLAgent$SONY_MEDIAMGR - c:\program files\sony\shared plug-ins\media manager\mssql$sony_mediamgr\binn\sqlagent.exe -i sony_mediamgr (file missing)


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Cisco Systems VPN Adapter
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter
PNP Device ID: ROOT\NET\0000
Service: CVirtA

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Hamachi Network Interface
Device ID: ROOT\NET\0001
Manufacturer: LogMeIn, Inc.
Name: Hamachi Network Interface
PNP Device ID: ROOT\NET\0001
Service: hamachi


-- Scheduled Tasks -------------------------------------------------------------

2008-03-17 14:08:08 256 --a------ C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
2008-03-15 21:35:08 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2007-11-05 15:18:19 268 --a------ C:\WINDOWS\Tasks\McDefragTask.job
2007-11-05 15:18:18 360 --a------ C:\WINDOWS\Tasks\McQcTask.job


-- Files created between 2008-02-17 and 2008-03-17 -----------------------------

2008-03-17 14:29:10 0 d-------- C:\Documents and Settings\DEMOSSE\Application Data\Styler
2008-03-17 14:25:03 0 d-------- C:\Program Files\Styler
2008-03-16 22:37:28 0 d-------- C:\Program Files\Trillian
2008-03-16 22:36:10 0 d-------- C:\Program Files\Miranda IM
2008-03-15 19:56:31 0 d-------- C:\WINDOWS\system32\ActiveScan
2008-03-15 18:28:07 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-15 18:27:41 0 d-------- C:\Documents and Settings\DEMOSSE\Application Data\SUPERAntiSpyware.com
2008-03-15 14:56:08 0 d-------- C:\Documents and Settings\DEMOSSE\Application Data\Grisoft
2008-03-15 14:55:56 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-05 22:18:28 0 d-------- C:\Documents and Settings\LocalService\Application Data\McAfee
2008-03-01 18:54:00 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-01 18:53:54 0 d-------- C:\Program Files\Windows Live
2008-03-01 18:53:31 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-27 15:33:47 0 d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-02-23 21:43:11 0 d-------- C:\Program Files\iTunes
2008-02-23 21:41:11 0 d-------- C:\Program Files\QuickTime
2008-02-23 20:54:17 0 d-------- C:\Program Files\LimeWire
2008-02-17 17:26:45 0 d-------- C:\Sierra
2008-02-17 17:11:44 0 d-------- C:\Program Files\Disc2Phone
2008-02-17 16:51:49 0 d-------- C:\Documents and Settings\DEMOSSE\Application Data\Teleca
2008-02-17 16:51:17 0 d-------- C:\Documents and Settings\All Users\Application Data\Sony Ericsson
2008-02-17 16:51:12 0 d-------- C:\Program Files\Common Files\Teleca Shared
2008-02-17 16:51:04 0 d-------- C:\Program Files\Sony Ericsson
2008-02-17 16:51:04 0 d-------- C:\Documents and Settings\All Users\Application Data\Teleca


-- Find3M Report ---------------------------------------------------------------

2008-03-17 14:42:52 0 d-------- C:\Program Files\Common Files
2008-03-17 14:23:38 0 d-------- C:\Documents and Settings\DEMOSSE\Application Data\SiteAdvisor
2008-03-17 13:23:46 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-03-16 21:51:31 0 d-------- C:\Program Files\McAfee
2008-03-16 10:13:37 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-15 21:17:31 0 d-------- C:\Program Files\Wireless 802.11g USB Adapter
2008-03-15 21:17:18 0 d-------- C:\Program Files\Windows Live Toolbar
2008-03-15 21:17:01 0 d-------- C:\Program Files\Windows Live Favorites
2008-03-15 21:15:42 0 d-------- C:\Program Files\SiteAdvisor
2008-03-15 20:53:08 0 d-------- C:\Program Files\Common Files\Autodesk Shared
2008-03-15 20:51:48 0 d-------- C:\Program Files\Bonjour
2008-03-11 13:38:24 0 d-------- C:\Program Files\Java
2008-03-01 18:55:00 0 d-------- C:\Program Files\MSN Messenger
2008-02-25 17:53:13 0 d-------- C:\Documents and Settings\DEMOSSE\Application Data\McAfee
2008-02-23 21:43:27 0 d-------- C:\Program Files\iPod
2008-02-22 14:44:39 0 d--h----- C:\Documents and Settings\DEMOSSE\Application Data\Adobe
2008-02-17 17:26:06 0 d-------- C:\Program Files\Games
2008-02-17 17:21:22 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-02-07 21:52:57 0 d-------- C:\Documents and Settings\DEMOSSE\Application Data\Vso
2008-02-07 21:52:57 34 --a------ C:\Documents and Settings\DEMOSSE\Application Data\ezplay.log
2008-02-07 21:52:52 7861 --a------ C:\Documents and Settings\DEMOSSE\Application Data\ezplay.cat
2008-02-07 21:52:51 94208 --a------ C:\Documents and Settings\DEMOSSE\Application Data\ezplay.sys <Not Verified; VSO Software; ezplay driver>
2008-02-07 21:52:51 125 --a------ C:\Documents and Settings\DEMOSSE\Application Data\ezplay.ini
2008-02-07 21:52:51 1103 --a------ C:\Documents and Settings\DEMOSSE\Application Data\ezplay.inf
2008-02-07 21:52:50 34 --a------ C:\Documents and Settings\DEMOSSE\Application Data\pcouffin.log
2008-02-07 21:52:26 47360 --a------ C:\Documents and Settings\DEMOSSE\Application Data\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2008-02-07 21:52:26 7887 --a------ C:\Documents and Settings\DEMOSSE\Application Data\pcouffin.cat
2008-02-07 21:52:25 1144 --a------ C:\Documents and Settings\DEMOSSE\Application Data\pcouffin.inf
2008-02-07 21:52:23 0 d-------- C:\Program Files\VSO
2008-02-06 16:12:58 0 d-------- C:\Program Files\Apple Software Update
2008-01-28 08:57:57 0 dr-h----- C:\Documents and Settings\DEMOSSE\Application Data\SecuROM
2008-01-28 07:58:47 0 d-------- C:\Program Files\Alcohol Soft


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{377C180E-6F0E-4D4C-980F-F45BD3D40CF4}]
09/19/2007 06:15 AM 329032 --a------ C:\Program Files\McAfee\MSK\mcapbho.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [08/06/2005 07:56 AM]
"LaunchApp"="Alaunch" []
"SoundMan"="SOUNDMAN.EXE" [09/23/2005 02:42 AM C:\WINDOWS\soundman.exe]
"ntiMUI"="c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [05/12/2005 12:15 PM]
"@"="" []
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [08/11/2004 06:00 AM]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [08/11/2004 06:00 AM]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [08/11/2004 06:00 AM]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [08/11/2004 06:00 AM]
"AGRSMMSG"="AGRSMMSG.exe" [06/30/2004 03:06 AM C:\WINDOWS\AGRSMMSG.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [11/15/2005 04:03 PM]
"nwiz"="nwiz.exe" [11/15/2005 04:03 PM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [11/15/2005 04:03 PM C:\WINDOWS\system32\nvmctray.dll]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [11/01/2005 10:21 AM]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [11/01/2003 01:42 PM]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/10/2001 04:50 AM]
"RegistryMechanic"="" []
"MWLExe"="C:\Program Files\Mcafee\MWL\MWLGui.exe" [07/28/2007 09:32 AM]
"McAfee Backup"="C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" [01/16/2007 01:59 PM]
"MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [01/08/2007 11:22 AM]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [08/03/2007 10:33 PM]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [10/26/2005 04:17 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [01/31/2008 11:13 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [02/19/2008 01:10 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [01/31/2008 11:13 PM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/11/2004 06:00 AM]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [10/18/2006 08:05 PM]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe
"Magnify"=Magnify.exe
@=OSK.exe

C:\Documents and Settings\DEMOSSE\Start Menu\Programs\Startup\
Styler.lnk - C:\Documents and Settings\DEMOSSE\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [3/17/2008 2:25:05 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2/18/2007 4:01:16 PM]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [12/14/2004 10:44:06 PM]
Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe [3/27/2006 4:15:59 PM]
Wireless 802.11g USB Adapter.lnk - C:\Program Files\Wireless 802.11g USB Adapter\ZDWlan.exe [11/20/2004 4:34:00 AM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C0D0400F-D8F0-DCD2-B56C-B60C9D8B83AB}]
C:\WINDOWS\system32\autocxk.exe



-- End of Deckard's System Scanner: finished at 2008-03-17 14:47:21 ------------

AND THIS IS THE extra.txt from DSS:

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: AMD Athlon™ 64 Processor 3500+
Percentage of Memory in Use: 54%
Physical Memory (total/avail): 958.48 MiB / 437.13 MiB
Pagefile Memory (total/avail): 2313.33 MiB / 1794.91 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1928.57 MiB

C: is Fixed (NTFS) - 113.76 GiB total, 46.89 GiB free.
D: is Fixed (FAT32) - 114.22 GiB total, 35.96 GiB free.
E: is CDROM (UDF)
F: is CDROM (No Media)
G: is Removable (FAT)
I: is Removable (No Media)
J: is Removable (No Media)
K: is Removable (No Media)
L: is Removable (No Media)
Z: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - HDT722525DLA380 - 232.88 GiB - 3 partitions
\PARTITION0 - Unknown - 4.88 GiB
\PARTITION1 (bootable) - Installable File System - 113.76 GiB - C:
\PARTITION2 - Unknown - 114.25 GiB - D:

\\.\PHYSICALDRIVE1 - Generic 2.0 Reader-CF USB Device

\\.\PHYSICALDRIVE4 - Generic 2.0 Reader-MS USB Device

\\.\PHYSICALDRIVE3 - Generic 2.0 Reader-SD USB Device

\\.\PHYSICALDRIVE2 - Generic 2.0 Reader-SM/xD USB Device

\\.\PHYSICALDRIVE5 - Generic USB Flash Drive USB Device - 1011.91 MiB - 1 partition
\PARTITION0 (bootable) - Unknown - 1011.88 MiB - G:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
AUState says computer is ready and waiting.
Windows Internal Firewall is enabled.

FirstRunDisabled is set.
AntiVirusDisableNotify is set.
FirewallDisableNotify is set.

FW: McAfee Personal Firewall v (McAfee)
AV: McAfee VirusScan v (McAfee)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\fxsclnt.exe"="C:\\WINDOWS\\system32\\fxsclnt.exe:*:Enabled:Microsoft Fax Console"
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\AGE2_X1.ICD"="C:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\AGE2_X1.ICD:*:Enabled:Age of Empires II Expansion"
"C:\\Program Files\\Battlefield 2\\BF2.exe"="C:\\Program Files\\Battlefield 2\\BF2.exe:*:Enabled:Battlefield 2"
"G:\\Games\\FILES\\DOOM II\\DOOM95.EXE"="G:\\Games\\FILES\\DOOM II\\DOOM95.EXE:*:Enabled:doom95"
"H:\\Games\\Age of empires\\age2_x1.exe"="H:\\Games\\Age of empires\\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"C:\\Program Files\\GameSpy Arcade\\Aphex.exe"="C:\\Program Files\\GameSpy Arcade\\Aphex.exe:*:Enabled:GameSpy Arcade"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Sierra\\Empire Earth\\Empire Earth.exe"="C:\\Sierra\\Empire Earth\\Empire Earth.exe:*:Enabled:Empire Earth"
"C:\\Valve\\Condition Zero\\czero.exe"="C:\\Valve\\Condition Zero\\czero.exe:*:Enabled:Condition Zero Launcher"
"C:\\Program Files\\Crave\\Global Operations\\goserver.exe"="C:\\Program Files\\Crave\\Global Operations\\goserver.exe:*:Enabled:Global Operations Server"
"E:\\Valve\\Condition Zero\\czero.exe"="E:\\Valve\\Condition Zero\\czero.exe:*:Enabled:Condition Zero Launcher"
"H:\\StubInstaller.exe"="H:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"G:\\StuFf\\LimeWire\\LimeWire.exe"="G:\\StuFf\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\emp-css\\emp-css\\hl2.exe"="C:\\Program Files\\emp-css\\emp-css\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Games\\Valve\\Condition Zero\\czero.exe"="C:\\Program Files\\Games\\Valve\\Condition Zero\\czero.exe:*:Enabled:Condition Zero Launcher"
"C:\\Program Files\\Games\\Battlefield 2\\BF2.exe"="C:\\Program Files\\Games\\Battlefield 2\\BF2.exe:*:Enabled:BF2"
"C:\\Program Files\\Games\\emp-css\\emp-css\\hl2.exe"="C:\\Program Files\\Games\\emp-css\\emp-css\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Games\\Activision\\Call of Duty 2\\CoD2MP_s.exe"="C:\\Program Files\\Games\\Activision\\Call of Duty 2\\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\\Program Files\\Games\\EA GAMES\\BFV\\bfvietnam.exe"="C:\\Program Files\\Games\\EA GAMES\\BFV\\bfvietnam.exe:*:Enabled:bfvietnam"
"C:\\Program Files\\Games\\EA GAMES\\BFV C&C server\\BFVCC.exe"="C:\\Program Files\\Games\\EA GAMES\\BFV C&C server\\BFVCC.exe:*:Enabled:BFVCC"
"C:\\Program Files\\Games\\Crave\\Global Operations\\goserver.exe"="C:\\Program Files\\Games\\Crave\\Global Operations\\goserver.exe:*:Enabled:Global Operations Server"
"C:\\Program Files\\Games\\EA GAMES\\BFV\\bfvietnam_w32ded.exe"="C:\\Program Files\\Games\\EA GAMES\\BFV\\bfvietnam_w32ded.exe:*:Enabled:bfvietnam_w32ded"
"G:\\StuFf\\many things that are very interesting\\anz\\mobile\\copy\\phone\\stampler\\Usb\\mega-pac\\ipod\\camera\\resume\\pp\\lol\\progs\\cool stuff\\stuff\\LimeWire\\LimeWire.exe"="G:\\StuFf\\many things that are very interesting\\anz\\mobile\\copy\\phone\\stampler\\Usb\\mega-pac\\ipod\\camera\\resume\\pp\\lol\\progs\\cool stuff\\stuff\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Torrent101\\Torrent101.exe"="C:\\Program Files\\Torrent101\\Torrent101.exe:*:Enabled:Torrent P2P application"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Games\\Microsoft Games\\Age of Empires II\\age2_x1\\age2_x1.exe"="C:\\Program Files\\Games\\Microsoft Games\\Age of Empires II\\age2_x1\\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"C:\\Program Files\\BitComet\\BitComet.exe"="C:\\Program Files\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
"C:\\Program Files\\Activision\\Call of Duty\\CoDMP.exe"="C:\\Program Files\\Activision\\Call of Duty\\CoDMP.exe:*:Enabled:CoDMP"
"C:\\WINDOWS\\system32\\dplaysvr.exe"="C:\\WINDOWS\\system32\\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\\Program Files\\Games\\GameSpy Arcade\\Aphex.exe"="C:\\Program Files\\Games\\GameSpy Arcade\\Aphex.exe:*:Enabled:GameSpy Arcade"
"C:\\Program Files\\Games\\Activision\\Thps3\\Skate3.exe"="C:\\Program Files\\Games\\Activision\\Thps3\\Skate3.exe:*:Enabled:THPS3PC"
"G:\\Games\\Age of Empires 2\\age2_x1.exe"="G:\\Games\\Age of Empires 2\\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"C:\\Documents and Settings\\DEMOSSE\\Desktop\\Other icons\\LimeWire\\LimeWire.exe"="C:\\Documents and Settings\\DEMOSSE\\Desktop\\Other icons\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Games\\Steam\\Counter-Strike Source\\hl2.exe"="C:\\Program Files\\Games\\Steam\\Counter-Strike Source\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Games\\EA GAMES\\FIFA 07\\FIFI.exe"="C:\\Program Files\\Games\\EA GAMES\\FIFA 07\\FIFI.exe:*:Enabled:FIFI"
"M:\\LimeWire\\lime wire\\LimeWire\\LimeWire.exe"="M:\\LimeWire\\lime wire\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Games\\NFS Carbon\\nfsc.exe"="C:\\Program Files\\Games\\NFS Carbon\\nfsc.exe:*:Enabled:nfsc"
"D:\\Games\\FEAR\\FEAR.exe"="D:\\Games\\FEAR\\FEAR.exe:*:Enabled:FEAR"
"D:\\Games\\FIFA 07\\FIFA.exe"="D:\\Games\\FIFA 07\\FIFA.exe:*:Enabled:FIFA"
"D:\\Games\\Valve\\Condition Zero\\czero.exe"="D:\\Games\\Valve\\Condition Zero\\czero.exe:*:Enabled:Condition Zero Launcher"
"C:\\Documents and Settings\\DEMOSSE\\Desktop\\Other icons\\Age of Empires 2\\age2_x1.exe"="C:\\Documents and Settings\\DEMOSSE\\Desktop\\Other icons\\Age of Empires 2\\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"D:\\Games\\Microsoft Games\\AOE 3\\AOE3.exe"="D:\\Games\\Microsoft Games\\AOE 3\\AOE3.exe:*:Enabled:Age of Empires 3"
"C:\\Documents and Settings\\DEMOSSE\\My Documents\\LimeWire\\LimeWire.exe"="C:\\Documents and Settings\\DEMOSSE\\My Documents\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"D:\\Games\\Sierra\\Empire Earth\\EE.exe"="D:\\Games\\Sierra\\Empire Earth\\EE.exe:*:Enabled:EE"
"C:\\Program Files\\Counter-Strike 1.6\\hl.exe"="C:\\Program Files\\Counter-Strike 1.6\\hl.exe:*:Enabled:Half-Life Launcher"
"G:\\Games\\Counter-Strike 1.6\\cstrike.exe"="G:\\Games\\Counter-Strike 1.6\\cstrike.exe:*:Enabled:Counter-Strike Launcher"
"C:\\Program Files\\Counter-Strike 1.6\\hlds.exe"="C:\\Program Files\\Counter-Strike 1.6\\hlds.exe:*:Enabled:HLDS Launcher"
"C:\\Documents and Settings\\DEMOSSE\\Desktop\\Other icons\\LimeWirePro\\LimeWire.exe"="C:\\Documents and Settings\\DEMOSSE\\Desktop\\Other icons\\LimeWirePro\\LimeWire.exe:*:Enabled:LimeWire"
"D:\\Games\\AGE 2\\age2_x1\\age2_x1.exe"="D:\\Games\\AGE 2\\age2_x1\\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"D:\\Games\\DOOM II\\DOOM95.EXE"="D:\\Games\\DOOM II\\DOOM95.EXE:*:Enabled:doom95"
"D:\\Games\\Activision\\Call of Duty 2\\CoD2MP_s.exe"="D:\\Games\\Activision\\Call of Duty 2\\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\\Program Files\\Hamachi\\hamachi.exe"="C:\\Program Files\\Hamachi\\hamachi.exe:*:Enabled:Hamachi Client"
"D:\\Games\\Counter Strike 1.6\\hl.exe"="D:\\Games\\Counter Strike 1.6\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\Games\\CS 1.6 Bastino\\hl.exe"="D:\\Games\\CS 1.6 Bastino\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Program Files\\Counter-Strike 1.6\\cstrike.exe"="C:\\Program Files\\Counter-Strike 1.6\\cstrike.exe:*:Enabled:Counter-Strike Launcher"
"M:\\Games\\Counterstrike\\hl.exe"="M:\\Games\\Counterstrike\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\Games\\BF2\\bf2_w32ded.exe"="D:\\Games\\BF2\\bf2_w32ded.exe:*:Enabled:bf2_w32ded"
"D:\\Games\\CS 1.6\\hl.exe"="D:\\Games\\CS 1.6\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\Games\\Counter Strike 1.6\\cstrike.exe"="D:\\Games\\Counter Strike 1.6\\cstrike.exe:*:Enabled:Counter-Strike Launcher"
"M:\\Games\\Counterstrike lan version\\hl.exe"="M:\\Games\\Counterstrike lan version\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\Games\\Gamespy arcade\\Aphex.exe"="D:\\Games\\Gamespy arcade\\Aphex.exe:*:Enabled:GameSpy Arcade"
"D:\\Games\\EA GAMES\\BFV\\bfvietnam.exe"="D:\\Games\\EA GAMES\\BFV\\bfvietnam.exe:*:Enabled:bfvietnam"
"D:\\Games\\Counterstrike lan version\\hl.exe"="D:\\Games\\Counterstrike lan version\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\Games\\Counterstrike lan version\\cstrike.exe"="D:\\Games\\Counterstrike lan version\\cstrike.exe:*:Enabled:Counter-Strike Launcher"
"G:\\Games\\Counter-strike - Condition Zero\\czero.exe"="G:\\Games\\Counter-strike - Condition Zero\\czero.exe:*:Enabled:Condition Zero Launcher"
"M:\\Games\\Counter-Strike (0531-05340-5557)\\hl.exe"="M:\\Games\\Counter-Strike (0531-05340-5557)\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\Games\\Battlefield 2\\bf2_w32ded.exe"="D:\\Games\\Battlefield 2\\bf2_w32ded.exe:*:Enabled:bf2_w32ded"
"C:\\Documents and Settings\\DEMOSSE\\Local Settings\\Temp\\Rar$EX03.110\\Counter-Strike (0531-05340-5557)\\hl.exe"="C:\\Documents and Settings\\DEMOSSE\\Local Settings\\Temp\\Rar$EX03.110\\Counter-Strike (0531-05340-5557)\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\Games\\Couhnter 1.6\\hl.exe"="D:\\Games\\Couhnter 1.6\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\Games\\Battlefield 2\\Battlefield 2.exe"="D:\\Games\\Battlefield 2\\Battlefield 2.exe:*:Enabled:Battlefield 2"
"D:\\Battlefield 2\\BF2.exe"="D:\\Battlefield 2\\BF2.exe:*:Enabled:BF2"
"D:\\DDDD!! Battle field 2\\BF2.exe"="D:\\DDDD!! Battle field 2\\BF2.exe:*:Enabled:BF2"
"D:\\Games\\Valve\\Steam\\Steam.exe"="D:\\Games\\Valve\\Steam\\Steam.exe:*:Enabled:Steam"
"M:\\Games\\Halo\\halo.exe"="M:\\Games\\Halo\\halo.exe:*:Enabled:Halo"
"C:\\Documents and Settings\\DEMOSSE\\My Documents\\Torrent Downloads\\Counter-Strike 1.6 No Steam - FULL v23B.(vjpower studios apps)\\Counter-Strike 1.6 No Steam - FULL v23B.(vjpower studios apps)\\Hack proxy 1.2\\vjpower estudios\\hack proxy.exe"="C:\\Documents and Settings\\DEMOSSE\\My Documents\\Torrent Downloads\\Counter-Strike 1.6 No Steam - FULL v23B.(vjpower studios apps)\\Counter-Strike 1.6 No Steam - FULL v23B.(vjpower studios apps)\\Hack proxy 1.2\\vjpower estudios\\hack proxy.exe:*:Disabled:hacker proxy 1.2 "
"C:\\Documents and Settings\\DEMOSSE\\Desktop\\Other icons\\New Folder (2)\\Couhnter 1.6\\hl.exe"="C:\\Documents and Settings\\DEMOSSE\\Desktop\\Other icons\\New Folder (2)\\Couhnter 1.6\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\Games\\Halo\\halo.exe"="D:\\Games\\Halo\\halo.exe:*:Enabled:Halo"
"C:\\Program Files\\McAfee\\MWL\\MwlSvc.exe"="C:\\Program Files\\McAfee\\MWL\\MwlSvc.exe:*:Enabled:McAfee Wireless Network Security"
"C:\\Program Files\\McAfee\\MBK\\McAfeeDataBackup.exe"="C:\\Program Files\\McAfee\\MBK\\McAfeeDataBackup.exe:*:Enabled:McAfee Data Backup"
"C:\\Documents and Settings\\DEMOSSE\\Local Settings\\Temp\\Rar$EX07.625\\CS 1.6\\hl.exe"="C:\\Documents and Settings\\DEMOSSE\\Local Settings\\Temp\\Rar$EX07.625\\CS 1.6\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"="C:\\Program Files\\Common Files\\McAfee\
  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

a question: What do I do with the OTcleanit?

Now is the time to use it because..............

Now the best part of the day ----- Your log now appears clean :)

Double click OTcleanit and you should see a CleanUp! button, press that button, you may get prompted by your firewall that OTcleanit wants to contact the internet, allow this, a cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will delete all the tools you have downloaded plus itself


Now to get you off to a good start we will re-set your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your your restore point but this is my method:

1. Select Start > All Programs > Accessories > System tools > System Restore.
2. On the dialogue box that appears select Create a Restore Point
3. Click NEXT
4. Enter a name e.g. Clean
5. Click CREATE

You now have a clean restore point, to get rid of the bad ones:

1. Select Start > All Programs > Accessories > System tools > Disk Cleanup.
2. In the Drop down box that appears select your main drive e.g. C
3. Click OK
4. The System will do some calculation and the display a dialogue box with TABS
5. Select the More Options Tab.
6. At the bottom will be a system restore box with a CLEANUP button click this
7. Accept the Warning and select OK again, the program will close and you are done



Now that you are clean, to help protect your computer in the future I recommend that you get the following free program: It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit

To learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place?


Keep safe :)
  • 0

#5
demoman

demoman

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Thank you very much

i really appreciate what you have done

thanks again
  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP