Thank you for your fast response. I have done everything you've asked for and here are the logs. Also I did not find Pc Cleaner in my Add\Remove Program list.
NoLop LogFileNoLop! Log by Skate_Punk_21
Fix running from: C:\Documents and Settings\Florin\Desktop
[4/13/2008]
[6:40:20 PM]
---Infection Files Found/Removed---
C:\WINDOWS\tasks\A0054BE891E6FEB4.job
Beginning Removal...
Rebooting...
Removing Lop's Leftover Files/Folders...
Editing Registry...
**Fix Complete!**
---Listing AppData sub directories---
C:\Documents and Settings\All Users\Application Data\Adobe
C:\Documents and Settings\All Users\Application Data\Adobe Systems
C:\Documents and Settings\All Users\Application Data\Ahead
C:\Documents and Settings\All Users\Application Data\Apple
C:\Documents and Settings\All Users\Application Data\Apple Computer
C:\Documents and Settings\All Users\Application Data\Ati
C:\Documents and Settings\All Users\Application Data\Autodesk
C:\Documents and Settings\All Users\Application Data\Avg7 -- EMPTY Directory
C:\Documents and Settings\All Users\Application Data\Bvrp Software
C:\Documents and Settings\All Users\Application Data\Creative
C:\Documents and Settings\All Users\Application Data\Cyberlink
C:\Documents and Settings\All Users\Application Data\Enternhelp
C:\Documents and Settings\All Users\Application Data\Espionserverdata
C:\Documents and Settings\All Users\Application Data\Google Updater
C:\Documents and Settings\All Users\Application Data\Intuit Canada
C:\Documents and Settings\All Users\Application Data\Iwin Games
C:\Documents and Settings\All Users\Application Data\Kodak
C:\Documents and Settings\All Users\Application Data\Last.fm
C:\Documents and Settings\All Users\Application Data\Messenger Plus!
C:\Documents and Settings\All Users\Application Data\Microsoft
C:\Documents and Settings\All Users\Application Data\Microsoft Help
C:\Documents and Settings\All Users\Application Data\Msn6
C:\Documents and Settings\All Users\Application Data\Mumbojumbo
C:\Documents and Settings\All Users\Application Data\Nero
C:\Documents and Settings\All Users\Application Data\Netjet
C:\Documents and Settings\All Users\Application Data\Nikon
C:\Documents and Settings\All Users\Application Data\Noteborq -- EMPTY Directory
C:\Documents and Settings\All Users\Application Data\Nvidia
C:\Documents and Settings\All Users\Application Data\Nview_profiles -- EMPTY Directory
C:\Documents and Settings\All Users\Application Data\Oberon Media
C:\Documents and Settings\All Users\Application Data\Orbnetworks
C:\Documents and Settings\All Users\Application Data\Popcap
C:\Documents and Settings\All Users\Application Data\Sega
C:\Documents and Settings\All Users\Application Data\Subliminal Flash
C:\Documents and Settings\All Users\Application Data\Symantec
C:\Documents and Settings\All Users\Application Data\Temp -- EMPTY Directory
C:\Documents and Settings\All Users\Application Data\Trymedia
C:\Documents and Settings\All Users\Application Data\Ultima_t15
C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
C:\Documents and Settings\All Users\Application Data\Wlinstaller
C:\Documents and Settings\All Users\Application Data\Yahoo!
C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
C:\Documents and Settings\All Users\Application Data\{cd08d33b-f39b-4a65-944a-a36fe20fb7bc}
C:\Documents and Settings\Default User\Application Data\Apple Computer
C:\Documents and Settings\Default User\Application Data\Microsoft
C:\Documents and Settings\Florin\Application Data\4team
C:\Documents and Settings\Florin\Application Data\Adobe
C:\Documents and Settings\Florin\Application Data\Adobeum -- EMPTY Directory
C:\Documents and Settings\Florin\Application Data\Ahead
C:\Documents and Settings\Florin\Application Data\Apple Computer
C:\Documents and Settings\Florin\Application Data\Atari
C:\Documents and Settings\Florin\Application Data\Ati
C:\Documents and Settings\Florin\Application Data\Autodesk
C:\Documents and Settings\Florin\Application Data\Bittorrent
C:\Documents and Settings\Florin\Application Data\Converttemp -- EMPTY Directory
C:\Documents and Settings\Florin\Application Data\Copytrans
C:\Documents and Settings\Florin\Application Data\Creative
C:\Documents and Settings\Florin\Application Data\Cyberlink
C:\Documents and Settings\Florin\Application Data\Dev-cpp
C:\Documents and Settings\Florin\Application Data\Eltima Software
C:\Documents and Settings\Florin\Application Data\Frostwire
C:\Documents and Settings\Florin\Application Data\Google
C:\Documents and Settings\Florin\Application Data\Help -- EMPTY Directory
C:\Documents and Settings\Florin\Application Data\Identities
C:\Documents and Settings\Florin\Application Data\Installshield
C:\Documents and Settings\Florin\Application Data\Intertrust
C:\Documents and Settings\Florin\Application Data\Lavasoft
C:\Documents and Settings\Florin\Application Data\Limewire
C:\Documents and Settings\Florin\Application Data\Macromedia
C:\Documents and Settings\Florin\Application Data\Microsoft
C:\Documents and Settings\Florin\Application Data\Moyea
C:\Documents and Settings\Florin\Application Data\Mozilla
C:\Documents and Settings\Florin\Application Data\Musicip
C:\Documents and Settings\Florin\Application Data\Oberon Media
C:\Documents and Settings\Florin\Application Data\Opera -- EMPTY Directory
C:\Documents and Settings\Florin\Application Data\Rapidget
C:\Documents and Settings\Florin\Application Data\Ringtone
C:\Documents and Settings\Florin\Application Data\Samsung
C:\Documents and Settings\Florin\Application Data\Seven Zip
C:\Documents and Settings\Florin\Application Data\Sun
C:\Documents and Settings\Florin\Application Data\Synthfont
C:\Documents and Settings\Florin\Application Data\Talkback
C:\Documents and Settings\Florin\Application Data\Temporary
C:\Documents and Settings\Florin\Application Data\Tmprecenticons
C:\Documents and Settings\Florin\Application Data\Transrender -- EMPTY Directory
C:\Documents and Settings\Florin\Application Data\Vlc
C:\Documents and Settings\Florin\Application Data\Winamp
C:\Documents and Settings\Florin\Application Data\Xfire
C:\Documents and Settings\Florin\Application Data\Yahoo!
C:\Documents and Settings\Localservice\Application Data\Microsoft
C:\Documents and Settings\Localservice\Application Data\Mozilla
C:\Documents and Settings\Localservice\Application Data\Talkback
C:\Documents and Settings\Networkservice\Application Data\Microsoft
C:\Documents and Settings\Sorin_diana\Application Data\Adobe
C:\Documents and Settings\Sorin_diana\Application Data\Adobeum
C:\Documents and Settings\Sorin_diana\Application Data\Ahead
C:\Documents and Settings\Sorin_diana\Application Data\Apple Computer
C:\Documents and Settings\Sorin_diana\Application Data\Arcsoft
C:\Documents and Settings\Sorin_diana\Application Data\Atari
C:\Documents and Settings\Sorin_diana\Application Data\Ati
C:\Documents and Settings\Sorin_diana\Application Data\Autodesk
C:\Documents and Settings\Sorin_diana\Application Data\Creative
C:\Documents and Settings\Sorin_diana\Application Data\Cyberlink
C:\Documents and Settings\Sorin_diana\Application Data\Google
C:\Documents and Settings\Sorin_diana\Application Data\Help -- EMPTY Directory
C:\Documents and Settings\Sorin_diana\Application Data\Identities
C:\Documents and Settings\Sorin_diana\Application Data\Installshield
C:\Documents and Settings\Sorin_diana\Application Data\Intuit Canada
C:\Documents and Settings\Sorin_diana\Application Data\Iwin
C:\Documents and Settings\Sorin_diana\Application Data\Lavasoft
C:\Documents and Settings\Sorin_diana\Application Data\Leadertech
C:\Documents and Settings\Sorin_diana\Application Data\Macromedia
C:\Documents and Settings\Sorin_diana\Application Data\Mechsoft
C:\Documents and Settings\Sorin_diana\Application Data\Microsoft
C:\Documents and Settings\Sorin_diana\Application Data\Mozilla
C:\Documents and Settings\Sorin_diana\Application Data\Msn6
C:\Documents and Settings\Sorin_diana\Application Data\Musicip
C:\Documents and Settings\Sorin_diana\Application Data\Nikon
C:\Documents and Settings\Sorin_diana\Application Data\Oberon Media
C:\Documents and Settings\Sorin_diana\Application Data\Opera -- EMPTY Directory
C:\Documents and Settings\Sorin_diana\Application Data\Panasonic
C:\Documents and Settings\Sorin_diana\Application Data\Samsung
C:\Documents and Settings\Sorin_diana\Application Data\Screenshot Sender
C:\Documents and Settings\Sorin_diana\Application Data\Starware347
C:\Documents and Settings\Sorin_diana\Application Data\Sun
C:\Documents and Settings\Sorin_diana\Application Data\Talkback
C:\Documents and Settings\Sorin_diana\Application Data\Tmprecenticons
C:\Documents and Settings\Sorin_diana\Application Data\U3
C:\Documents and Settings\Sorin_diana\Application Data\Utorrent
C:\Documents and Settings\Sorin_diana\Application Data\Vlc
C:\Documents and Settings\Sorin_diana\Application Data\Whenu
C:\Documents and Settings\Sorin_diana\Application Data\Winamp
C:\Documents and Settings\Sorin_diana\Application Data\Xfire -- EMPTY Directory
C:\Documents and Settings\Sorin_diana\Application Data\Yahoo!
HijackThis Log File after NoLopLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:51:43 PM, on 4/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\Program Files\Creative\ShareDLL\Mediadet.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\WINDOWS\tsnp2std.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\vsnp2std.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Florin\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [bc4c2a6e] rundll32.exe "C:\WINDOWS\system32\tmvvqude.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.liv...m/quickadd.aspxO8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download linked FLV with GetFLV - C:\Program Files\GetFLV\iemenu\DownloadLinkFLV.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PacificPoker4 - {94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} - F:\PROGRA~1\PACIFI~1\pacificpoker.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -
http://www.creative....026/CTSUEng.cabO16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) -
http://messenger.zon...kr.cab56986.cabO16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) -
http://messenger.zon...wn.cab56986.cabO16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
http://messenger.zon...1/GAME_UNO1.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1156908970488O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1157302271718O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) -
http://appdirectory....ap/PhtPkMSN.cabO16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab56907.cabO16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative....15026/CTPID.cabO18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O21 - SSODL: qdnkewfa - {7FCF8B39-6002-427E-9BDA-C30E916746BD} - C:\WINDOWS\qdnkewfa.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
--
End of file - 12860 bytes
OTmoveIt log fileFile/Folder C:\Program Files\WhenUSearch not found.
File/Folder c:\docume~1\sebast~1\locals~1\temp\adxapie.sys not found.
File/Folder C:\WINDOWS\Tasks\A0054BE891E6FEB4.job not found.
Folder move failed. C:\WINDOWS\privacy_danger scheduled to be moved on reboot.
C:\Program Files\PC-Cleaner moved successfully.
C:\WINDOWS\system32\abgnqtux.exe moved successfully.
C:\WINDOWS\system32\wdalonoz.exe moved successfully.
C:\WINDOWS\system32\hhPsvyay.ini2 moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\yayvsPhh.dll
C:\WINDOWS\system32\yayvsPhh.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\yayvsPhh.dll scheduled to be moved on reboot.
C:\WINDOWS\apoxqwfv.exe moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\byXOiIca.dll
C:\WINDOWS\system32\byXOiIca.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\byXOiIca.dll scheduled to be moved on reboot.
C:\WINDOWS\.rk_save_32 moved successfully.
C:\Program Files\BITS ITCH TITLE moved successfully.
File/Folder C:\WINDOWS\qdnkewfa.dll not found.
< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\onlinevga >
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\onlinevga\\ deleted successfully.
< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSearch >
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSearch\\ deleted successfully.
< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSearchWHSE >
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSearchWHSE\\ deleted successfully.
< Purity >
OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04132008_190041
Files moved on Reboot...
Folder move failed. C:\WINDOWS\privacy_danger scheduled to be moved on reboot.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\yayvsPhh.dll
C:\WINDOWS\system32\yayvsPhh.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\yayvsPhh.dll scheduled to be moved on reboot.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\byXOiIca.dll
C:\WINDOWS\system32\byXOiIca.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\byXOiIca.dll scheduled to be moved on reboot.
CombFix logfileComboFix 08-04-13.1 - Florin 2008-04-13 19:10:41.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1427 [GMT -4:00]
Running from: C:\Documents and Settings\Florin\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Florin\Favorites\Error Cleaner.url
C:\Documents and Settings\Florin\Favorites\Privacy Protector.url
C:\Documents and Settings\Florin\Favorites\Spyware&Malware Protection.url
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\BrowserSearch\BrowserSearch.xml
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\BrowserSearch\BrowserSearch.xml.backup
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\Configurator\Configurator.xml
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\Configurator\Configurator.xml.backup
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\EntertainmentMarketingSP\EntertainmentMarketingSPOptions.xml
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\EntertainmentMarketingSP\EntertainmentMarketingSPOptions.xml.backup
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\ErrorSearch\ErrorSearchOptions.xml
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\ErrorSearch\ErrorSearchOptions.xml.backup
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\Games\GamesOptions.xml
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\Games\GamesOptions.xml.backup
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\JokeSearch\JokeSearchOptions.xml
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\JokeSearch\JokeSearchOptions.xml.backup
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\Layouts\ToolbarLayout.xml
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\Layouts\ToolbarLayout.xml.backup
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\Manager\ManagerOptions.xml
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\Manager\ManagerOptions.xml.backup
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\Movies\MoviesOptions.xml
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\Movies\MoviesOptions.xml.backup
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\Pranks\PranksOptions.xml
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\Pranks\PranksOptions.xml.backup
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\RelatedSearch\RelatedSearchOptions.xml
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\RelatedSearch\RelatedSearchOptions.xml.backup
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\SearchAssistPlus\SearchAssistPlusOptions.xml
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\SearchAssistPlus\SearchAssistPlusOptions.xml.backup
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\SearchMatch\SearchMatchOptions.xml
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\SearchMatch\SearchMatchOptions.xml.backup
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\Toolbar\TBProductsOptions.xml
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\Toolbar\TBProductsOptions.xml.backup
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\ToolbarLogo\ToolbarLogoOptions.xml
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\ToolbarLogo\ToolbarLogoOptions.xml.backup
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\ToolbarSearch\ToolbarSearchOptions.xml
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\ToolbarSearch\ToolbarSearchOptions.xml.backup
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\TravelSearch\TravelSearchOptions.xml
C:\Documents and Settings\Sorin_Diana\Application Data\Starware347\TravelSearch\TravelSearchOptions.xml.backup
C:\Documents and Settings\Sorin_Diana\Desktop\Error Cleaner.url
C:\Documents and Settings\Sorin_Diana\Desktop\Privacy Protector.url
C:\Documents and Settings\Sorin_Diana\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\Sorin_Diana\Favorites\Error Cleaner.url
C:\Documents and Settings\Sorin_Diana\Favorites\Privacy Protector.url
C:\Documents and Settings\Sorin_Diana\Favorites\Spyware&Malware Protection.url
C:\WINDOWS\rs.txt
C:\WINDOWS\system32\byXOiIca.dll
C:\WINDOWS\system32\eduqvvmt.ini
C:\WINDOWS\system32\hhPsvyay.ini
C:\WINDOWS\system32\hhPsvyay.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\tmvvqude.dll
C:\WINDOWS\system32\yayvsPhh.dll
.
((((((((((((((((((((((((( Files Created from 2008-03-13 to 2008-04-13 )))))))))))))))))))))))))))))))
.
2008-04-13 18:57 . 2008-04-13 18:57 <DIR> d-------- C:\Program Files\ERUNT
2008-04-13 18:43 . 2008-04-13 18:44 <DIR> d-------- C:\NoLopBackups
2008-04-13 13:16 . 2008-04-13 13:16 <DIR> d-------- C:\Deckard
2008-04-13 13:14 . 2008-04-13 13:14 <DIR> d-------- C:\_OTMoveIt
2008-04-13 10:21 . 2008-04-13 10:21 <DIR> d-------- C:\Program Files\Alwil Software
2008-04-13 10:15 . 2008-04-13 10:14 230,776 --a------ C:\aswclear.exe
2008-04-13 09:32 . 2008-04-13 09:32 2,218,368 --a------ C:\AROTrial.exe
2008-04-12 16:11 . 2008-04-12 16:11 <DIR> d-------- C:\WINDOWS\privacy_danger
2008-04-12 13:54 . 2008-04-13 13:04 1,134 --ahs---- C:\WINDOWS\system32\uanjaogs.ini
2008-04-12 08:05 . 2008-04-12 08:05 <DIR> d-------- C:\Documents and Settings\Florin\Application Data\Ahead
2008-04-12 07:57 . 2008-04-12 07:57 <DIR> d-------- C:\Program Files\GetFLV
2008-04-12 07:57 . 2008-04-04 07:18 1,462,272 --a------ C:\WINDOWS\system32\vbsgf.dat
2008-04-12 07:53 . 2007-06-29 10:55 577,536 --a------ C:\WINDOWS\system32\audiocodec.dll
2008-04-12 07:53 . 2007-06-29 10:55 282,624 --a------ C:\WINDOWS\system32\4codedecoder.dll
2008-04-12 07:53 . 2007-06-29 10:55 233,472 --a------ C:\WINDOWS\system32\dllzaac.dll
2008-04-12 07:53 . 2007-06-29 10:55 217,088 --a------ C:\WINDOWS\system32\mp4filelib.dll
2008-04-12 07:53 . 2007-06-29 10:55 57,344 --a------ C:\WINDOWS\system32\streamio.dll
2008-04-11 22:10 . 2008-04-13 09:46 <DIR> d-------- C:\Documents and Settings\Sorin_Diana\Application Data\TmpRecentIcons
2008-04-11 18:36 . 2008-04-12 10:09 <DIR> d-------- C:\Documents and Settings\Florin\Application Data\TmpRecentIcons
2008-04-11 17:03 . 2008-04-11 17:03 <DIR> d-------- C:\Program Files\SourceTec
2008-04-11 17:03 . 2007-02-05 12:00 761,856 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-04-11 17:03 . 2007-02-05 12:00 135,168 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-04-11 17:03 . 2008-04-11 17:03 37 --a------ C:\WINDOWS\SWFConverter.INI
2008-04-11 17:00 . 2008-04-12 09:07 714 --ahs---- C:\WINDOWS\system32\uwcpxadx.ini
2008-04-11 16:56 . 2008-04-11 16:56 <DIR> d-------- C:\Program Files\Swf2Avi
2008-04-11 16:52 . 2008-04-11 16:52 <DIR> d-------- C:\Program Files\Xilisoft
2008-04-11 16:49 . 2008-04-12 00:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\noteborq
2008-04-11 16:41 . 2008-04-11 16:41 <DIR> d-------- C:\Program Files\Moyea
2008-04-11 16:37 . 2008-04-11 16:37 <DIR> d-------- C:\Documents and Settings\Florin\Application Data\Moyea
2008-04-11 16:32 . 2008-04-11 16:32 <DIR> d-------- C:\Documents and Settings\Florin\Application Data\Eltima Software
2008-04-09 07:23 . 2008-04-13 19:21 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-09 07:23 . 2008-04-09 07:23 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-08 17:51 . 2008-04-08 17:51 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-08 17:50 . 2008-04-08 17:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-31 17:47 . 2008-03-31 17:47 <DIR> d-------- C:\Program Files\Common Files\Scanner
2008-03-31 17:47 . 2008-04-12 08:42 <DIR> d-------- C:\Program Files\CA Yahoo! Anti-Spy
2008-03-28 23:37 . 2008-03-28 23:37 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-03-28 23:37 . 2008-03-28 23:37 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-03-28 09:05 . 2008-03-28 09:05 <DIR> d-------- C:\Program Files\MSECache
2008-03-26 18:00 . 2008-03-26 18:00 1,816 --a------ C:\WINDOWS\TSearch.INI
2008-03-26 08:17 . 2008-03-26 08:17 145 --a------ C:\WINDOWS\?????????????????????????????????i
2008-03-25 23:46 . 2008-03-25 23:48 <DIR> d-------- C:\Documents and Settings\Sorin_Diana\Application Data\Winamp
2008-03-25 09:02 . 2008-03-25 16:47 <DIR> d-------- C:\Documents and Settings\Florin\Application Data\Winamp
2008-03-23 11:07 . 2008-03-23 11:19 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-03-17 15:51 . 2008-04-13 19:20 3,375,934 --a------ C:\WINDOWS\{00000004-00000000-00000008-00001102-00000002-80641102}.CDF
2008-03-17 15:51 . 2008-04-13 19:20 3,375,934 --a------ C:\WINDOWS\{00000004-00000000-00000008-00001102-00000002-80641102}.BAK
2008-03-17 08:35 . 2008-04-13 19:18 29,808 --a------ C:\WINDOWS\system32\BMXCtrlState-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx
2008-03-17 08:35 . 2008-04-13 19:18 29,808 --a------ C:\WINDOWS\system32\BMXBkpCtrlState-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx
2008-03-17 08:35 . 2008-04-13 19:18 17,500 --a------ C:\WINDOWS\system32\BMXStateBkp-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx
2008-03-17 08:35 . 2008-04-13 19:18 17,500 --a------ C:\WINDOWS\system32\BMXState-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx
2008-03-17 08:35 . 2008-04-13 19:18 24 --a------ C:\WINDOWS\system32\DVCStateBkp-{00000004-00000000-00000008-00001102-00000002-80641102}.dat
2008-03-17 08:35 . 2008-04-13 19:18 24 --a------ C:\WINDOWS\system32\DVCState-{00000004-00000000-00000008-00001102-00000002-80641102}.dat
2008-03-16 03:15 . 2008-03-16 03:15 136,496 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-03-16 03:15 . 2007-12-18 20:06 91,008 --a------ C:\WINDOWS\system32\drivers\SysPlant.sys
2008-03-16 03:15 . 2008-03-16 03:15 60,808 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-03-16 03:15 . 2008-03-16 03:15 10,652 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-03-16 03:15 . 2008-03-16 03:15 806 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-03-16 03:11 . 2008-03-16 03:15 <DIR> d-------- C:\Program Files\Symantec
2008-03-16 03:11 . 2008-03-16 03:17 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-03-16 03:11 . 2008-03-16 03:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-16 03:04 . 2008-03-16 03:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-03-16 02:37 . 2004-08-04 08:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-03-16 02:36 . 2004-08-04 08:00 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll
2008-03-16 02:33 . 2008-03-16 02:33 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-03-16 02:32 . 2004-08-04 08:00 16,384 --a--c--- C:\WINDOWS\system32\dllcache\isignup.exe
2008-03-16 02:32 . 2008-03-16 02:32 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-03-16 02:32 . 2008-03-16 02:32 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-03-16 02:32 . 2008-03-16 02:32 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-03-16 02:32 . 2008-03-16 02:32 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2008-03-16 02:32 . 2008-03-16 02:32 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-03-16 02:18 . 2004-08-04 08:00 2,012,670 --a--c--- C:\WINDOWS\system32\dllcache\NT5.CAT
2008-03-16 02:18 . 2004-08-04 08:00 1,086,058 -ra------ C:\WINDOWS\SET103.tmp
2008-03-16 02:18 . 2004-08-04 08:00 1,042,903 --a--c--- C:\WINDOWS\system32\dllcache\SP2.CAT
2008-03-16 02:18 . 2004-08-04 08:00 1,042,903 -ra------ C:\WINDOWS\SET101.tmp
2008-03-16 02:18 . 2004-08-04 08:00 502,724 --a--c--- C:\WINDOWS\system32\dllcache\NT5INF.CAT
2008-03-16 02:18 . 2004-08-04 08:00 13,753 -ra------ C:\WINDOWS\SET10B.tmp
2008-03-16 01:42 . 2008-03-16 01:42 <DIR> d-------- C:\Program Files\Subliminal Flash
2008-03-16 01:42 . 2008-03-16 01:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Subliminal Flash
2008-03-16 01:38 . 2008-03-16 01:38 <DIR> d-------- C:\Program Files\Subliminal Images
2008-03-15 20:41 . 2008-03-15 23:27 <DIR> d-------- C:\Documents and Settings\Sorin_Diana\Application Data\Ahead
2008-03-15 20:40 . 2008-03-15 20:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-03-15 20:37 . 2008-03-15 20:37 <DIR> d-------- C:\Program Files\Nero
2008-03-15 20:37 . 2008-03-15 20:43 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-03-15 20:37 . 2008-03-15 20:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-12 11:52 --------- d-----w C:\Program Files\Eltima Software
2008-04-11 12:29 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-11 03:38 --------- d-----w C:\Documents and Settings\Sorin_Diana\Application Data\U3
2008-04-09 19:54 --------- d-----w C:\Program Files\iTunes
2008-04-09 19:53 --------- d-----w C:\Program Files\iPod
2008-04-09 19:52 --------- d-----w C:\Program Files\QuickTime
2008-04-08 21:52 --------- d-----w C:\Program Files\MSN Messenger
2008-04-08 21:51 --------- d-----w C:\Program Files\Windows Live
2008-04-04 23:01 --------- d-----w C:\Documents and Settings\Florin\Application Data\FrostWire
2008-03-30 15:40 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-03-30 15:40 --------- d-----w C:\Program Files\Circle Developement
2008-03-30 06:15 --------- d-----w C:\Documents and Settings\Sorin_Diana\Application Data\MSN6
2008-03-27 03:25 --------- d-----w C:\Program Files\Winamp
2008-03-25 20:15 50,536 ----a-w C:\WINDOWS\system32\drivers\WpsHelper.sys
2008-03-25 13:03 --------- d-----w C:\Program Files\Winamp Toolbar
2008-03-21 18:44 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-17 11:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-16 09:18 --------- d-----w C:\Program Files\DAEMON Tools
2008-03-16 00:25 --------- d-----w C:\Program Files\Ahead
2008-03-10 04:08 --------- d-----w C:\Program Files\QuickTax 2007
2008-03-10 00:29 --------- d-----w C:\Program Files\Common Files\AnswerWorks 4.0
2008-03-10 00:29 --------- d-----w C:\Documents and Settings\Sorin_Diana\Application Data\Intuit Canada
2008-03-10 00:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Intuit Canada
2008-02-28 23:09 --------- d-----w C:\Program Files\AoA Audio Extractor
2008-02-28 22:57 --------- d-----w C:\Program Files\FLV Player
2008-02-28 21:50 --------- d-----w C:\Documents and Settings\Florin\Application Data\CopyTrans
2008-02-21 00:27 --------- d-----w C:\Program Files\EasyRecorder
2008-02-09 15:21 720,896 ----a-w C:\WINDOWS\iun6002.exe
2007-12-02 22:04 20 ---h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2007-12-02 22:04 20 ---h--w C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
2007-03-08 03:22 67,922 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_03_07_19_52_04_small.dmp.zip
2007-02-25 03:39 15,230,483 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_02_24_09_05_58_full.dmp.zip
2007-02-13 11:32 65,046 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_02_12_08_00_29_small.dmp.zip
2007-02-13 11:32 64,631 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_02_12_08_11_30_small.dmp.zip
2007-01-16 20:44 60,757 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_01_16_15_39_38_small.dmp.zip
2007-01-16 20:44 60,142 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_01_16_15_39_45_small.dmp.zip
2006-12-27 00:53 126,848 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_12_26_14_02_26_small.dmp.zip
2006-11-02 21:14 131,279 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_11_02_16_06_46_small.dmp.zip
2006-10-22 19:53 7,988 ----a-w C:\Program Files\install.log
2006-10-22 03:41 2,983 ----a-w C:\Program Files\install_wizard.log
2006-10-20 23:29 88,254 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_10_20_16_26_15_small.dmp.zip
2006-10-20 23:29 107,868 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_10_20_16_26_29_small.dmp.zip
2004-10-01 19:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-12-13 12:49 1185120 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2007-12-13 12:49 1185120]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-12-13 12:49 1185120]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00 15360]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2006-11-30 22:49 4662776]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WINDVDPatch"="CTHELPER.EXE" [2002-07-02 18:56 24576 C:\WINDOWS\system32\CTHELPER.EXE]
"Disc Detector"="C:\Program Files\Creative\ShareDLL\CtNotify.exe" [2001-12-26 02:00 191488]
"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 16:49 77824]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00 90112]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2006-01-13 20:13 172032]
"EPSON Stylus Photo R200 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.exe" [2003-07-08 03:00 99840]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 13:35 90112]
"tsnp2std"="C:\WINDOWS\tsnp2std.exe" [2007-01-05 18:12 258048]
"snp2std"="C:\WINDOWS\vsnp2std.exe" [2006-09-15 14:21 675840]
"SoundMan"="SOUNDMAN.EXE" [2005-08-17 18:39 90112 C:\WINDOWS\soundman.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-11-09 16:15 115560]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-01-15 18:54 37376]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [ ]
C:\Documents and Settings\Sorin_Diana\Start Menu\Programs\Startup\
Last.fm Helper.lnk - C:\Program Files\Last.fm\LastFMHelper.exe [2007-06-28 22:14:11 106496]
C:\Documents and Settings\Florin\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE [2005-10-20 12:04:08 38912]
Last.fm Helper.lnk - C:\Program Files\Last.fm\LastFMHelper.exe [2007-06-28 22:14:11 106496]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byXOiIca]
byXOiIca.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antvirus]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Last.fm Helper.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Last.fm Helper.lnk
backup=C:\WINDOWS\pss\Last.fm Helper.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^LUMIX Simple Viewer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\LUMIX Simple Viewer.lnk
backup=C:\WINDOWS\pss\LUMIX Simple Viewer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk
backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Sorin_Diana^Start Menu^Programs^Startup^Last.fm Helper.lnk]
path=C:\Documents and Settings\Sorin_Diana\Start Menu\Programs\Startup\Last.fm Helper.lnk
backup=C:\WINDOWS\pss\Last.fm Helper.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
--a------ 2006-01-12 21:52 483328 C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
-ra------ 2007-08-30 06:32 61440 C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.2\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Version Cue CS2]
--a------ 2005-04-04 18:58 856064 C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msc