Hello
Ltangelic,
Sorry for the delay, there was a power outage in the area due to severe weather conditions.
I'm glad to say there is some considerable progress. I found the following files on my computer:
C:\WINDOWS\system32\buvexano.exe
C:\WINDOWS\system32\nwlypavs.exe
C:\WINDOWS\system32\StHP10a2.exe
C:\WINDOWS\system32\YsS6tem0.exe
C:\WINDOWS\system32\YsS6tem0.exe_
C:\WINDOWS\system32\ActiveScan\pskavs.dll
C:\Documents and Settings\All Users\Application Data\zoxsbmjy\xmpwlsho.exe
C:\Downloads\avitompeg15.exe
These were all from the same source, wherever the virus came from, and I removed them all successfuly. Prior to my posting of the HJT log, I noticed the process "YsS6tem0.exe" wouldn't close, and I googled it but found nothing, so it was obviously not a system file. I used
Jotti's malware scan and the results are as follows (prior to my removing of the above):
2008 05:52:08 (GMT)
A-Squared Found nothing
AntiVir Found TR/Crypt.ULPM.Gen
ArcaVir Found nothing
Avast Found Win32:Trojan-gen {Other}
AVG Antivirus Found Generic10.AOWW
BitDefender Found nothing
ClamAV Found Trojan.Spy-41149
CPsecure Found nothing
Dr.Web Found Trojan.Click.19260
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found Trojan-GameThief.Win32.OnLineGames.arxy
Fortinet Found W32/OnLineGames.ARXY!tr.pws
Ikarus Found Trojan.Crypt.ULPM
Kaspersky Anti-Virus Found Trojan-GameThief.Win32.OnLineGames.arxy
NOD32 Found probably unknown NewHeur_PE (probable variant)
Norman Virus Control Found W32/DLoader.HSQD
Panda Antivirus Found Generic
Sophos Antivirus Found Mal/EncPk-F
VirusBuster Found nothing
VBA32 Found Trojan-PSW.Win32.OnLineGames.arxy
Here are the results for Deckard's system scanner:(The extra.txt file is attached)
Deckard's System Scanner v20071014.68
Run by Administrator on 2008-06-28 16:12:01
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 1 Restore Point(s) --
1: 2008-06-28 21:12:16 UTC - RP202 - Deckard's System Scanner Restore Point
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 510 MiB (512 MiB recommended).-- HijackThis (run as Administrator.exe) ---------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:14:21 PM, on 6/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.5.0_12\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Administrator\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Administrator.exe
C:\WINDOWS\system32\notepad.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 222.190.118.27:8080
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Avira AntiVir Personal Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 3960 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080401-134307-493 O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
backup-20080401-134523-207 O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
backup-20080402-130318-548 O4 - HKLM\..\Policies\Explorer\Run: [9goXcGXZAM] C:\Documents and Settings\All Users\Application Data\zoxsbmjy\xmpwlsho.exe
backup-20080402-130327-848 O4 - HKCU\..\Run: [vgiauuwe] C:\WINDOWS\system32\nwlypavs.exe
backup-20080402-130546-380 O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
backup-20080402-130558-272 O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
backup-20080402-150507-247 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
backup-20080402-150507-257 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896backup-20080402-150507-340 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157backup-20080402-150507-432 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896backup-20080625-031407-146 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
backup-20080625-031407-321 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
backup-20080625-031407-478 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
backup-20080625-031407-925 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
backup-20080625-031514-875 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
backup-20080625-031526-901 O2 - BHO: adsonmedia browser optimizer - {94cc7750-5b38-44fe-84c6-5d6aca55925d} - C:\WINDOWS\system32\{3ed62066-a709-5363-e318-6cdafed8b076}.dll
backup-20080625-031541-212 F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
-- File Associations -----------------------------------------------------------
.reg - regfile - shell\open\command - regedit.exe"%1" %*.scr - scrfile - shell\open\command - "%1" %*-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
S1 InCDPass - c:\windows\system32\drivers\incdpass.sys (file missing)
S1 InCDRm (InCD Reader) - c:\windows\system32\drivers\incdrm.sys (file missing)
S2 zntport (NTPort Library Driver) - c:\windows\system32\zntport.sys (file missing)
S3 catchme - c:\docume~1\admini~1\locals~1\temp\catchme.sys (file missing)
S4 InCDFs (InCD File System) - c:\windows\system32\drivers\incdfs.sys (file missing)
S4 VFILT (Outpost Firewall Kernel Driver) - c:\progra~1\agnitum\outpos~1.0\kernel\2000\filtnt.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 AntiVirScheduler (Avira AntiVir Personal Free Antivirus Scheduler) - "c:\program files\avira\antivir personaledition classic\sched.exe" <Not Verified; Avira GmbH; AntiVir Workstation>
S2 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>
S3 ServiceLayer - "c:\program files\pc connectivity solution\servicelayer.exe" <Not Verified; Nokia.; PC Connectivity Solution>
S4 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-06-28 16:00:00 350 --a------ C:\WINDOWS\Tasks\At41.job
2008-06-28 16:00:00 350 --a------ C:\WINDOWS\Tasks\At17.job
2008-06-28 15:32:02 350 --a------ C:\WINDOWS\Tasks\At39.job
2008-06-28 15:00:10 350 --a------ C:\WINDOWS\Tasks\At40.job
2008-06-28 15:00:02 350 --a------ C:\WINDOWS\Tasks\At16.job
2008-06-28 14:00:02 350 --a------ C:\WINDOWS\Tasks\At15.job
2008-06-28 13:16:06 350 --a------ C:\WINDOWS\Tasks\At25.job
2008-06-28 03:00:10 350 --a------ C:\WINDOWS\Tasks\At28.job
2008-06-28 03:00:02 350 --a------ C:\WINDOWS\Tasks\At4.job
2008-06-28 02:00:10 350 --a------ C:\WINDOWS\Tasks\At27.job
2008-06-28 02:00:01 350 --a------ C:\WINDOWS\Tasks\At3.job
2008-06-28 01:00:10 350 --a------ C:\WINDOWS\Tasks\At26.job
2008-06-28 01:00:01 350 --a------ C:\WINDOWS\Tasks\At2.job
2008-06-28 00:22:01 350 --a------ C:\WINDOWS\Tasks\At1.job
2008-06-27 15:45:54 350 --a------ C:\WINDOWS\Tasks\At36.job
2008-06-26 17:00:10 350 --a------ C:\WINDOWS\Tasks\At42.job
2008-06-26 17:00:02 350 --a------ C:\WINDOWS\Tasks\At18.job
2008-06-26 13:00:10 350 --a------ C:\WINDOWS\Tasks\At38.job
2008-06-26 13:00:01 350 --a------ C:\WINDOWS\Tasks\At14.job
2008-06-26 12:00:10 350 --a------ C:\WINDOWS\Tasks\At37.job
2008-06-26 12:00:01 350 --a------ C:\WINDOWS\Tasks\At13.job
2008-06-26 11:00:02 350 --a------ C:\WINDOWS\Tasks\At12.job
2008-06-26 10:05:55 350 --a------ C:\WINDOWS\Tasks\At44.job
2008-06-25 23:00:10 350 --a------ C:\WINDOWS\Tasks\At48.job
2008-06-25 23:00:02 350 --a------ C:\WINDOWS\Tasks\At24.job
2008-06-25 22:00:10 350 --a------ C:\WINDOWS\Tasks\At47.job
2008-06-25 22:00:01 350 --a------ C:\WINDOWS\Tasks\At23.job
2008-06-25 21:00:10 350 --a------ C:\WINDOWS\Tasks\At46.job
2008-06-25 21:00:02 350 --a------ C:\WINDOWS\Tasks\At22.job
2008-06-25 20:00:10 350 --a------ C:\WINDOWS\Tasks\At45.job
2008-06-25 20:00:02 350 --a------ C:\WINDOWS\Tasks\At21.job
2008-06-25 19:00:01 350 --a------ C:\WINDOWS\Tasks\At20.job
2008-06-25 04:00:10 350 --a------ C:\WINDOWS\Tasks\At29.job
2008-06-25 04:00:01 350 --a------ C:\WINDOWS\Tasks\At5.job
2008-06-25 02:13:57 350 --a------ C:\WINDOWS\Tasks\At43.job
2008-06-25 02:13:57 350 --a------ C:\WINDOWS\Tasks\At35.job
2008-06-25 02:13:57 350 --a------ C:\WINDOWS\Tasks\At34.job
2008-06-25 02:13:57 350 --a------ C:\WINDOWS\Tasks\At33.job
2008-06-25 02:13:57 350 --a------ C:\WINDOWS\Tasks\At32.job
2008-06-25 02:13:57 350 --a------ C:\WINDOWS\Tasks\At31.job
2008-06-25 02:13:57 350 --a------ C:\WINDOWS\Tasks\At30.job
2008-06-24 18:00:01 350 --a------ C:\WINDOWS\Tasks\At19.job
2008-06-24 01:00:32 350 --a------ C:\WINDOWS\Tasks\At9.job
2008-06-24 01:00:32 350 --a------ C:\WINDOWS\Tasks\At8.job
2008-06-24 01:00:32 350 --a------ C:\WINDOWS\Tasks\At7.job
2008-06-24 01:00:32 350 --a------ C:\WINDOWS\Tasks\At6.job
2008-06-24 01:00:32 350 --a------ C:\WINDOWS\Tasks\At11.job
2008-06-24 01:00:32 350 --a------ C:\WINDOWS\Tasks\At10.job
-- Files created between 2008-05-28 and 2008-06-28 -----------------------------
2008-06-28 15:21:18 0 d-------- C:\Program Files\Avira
2008-06-28 15:21:18 0 d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-06-26 12:05:34 0 d-------- C:\Program Files\Pawsoft
2008-06-25 21:20:03 0 d-------- C:\Documents and Settings\NetworkService\Application Data\Macromedia
2008-06-25 19:59:36 0 d-------- C:\Documents and Settings\Islam\Application Data\Macromedia
2008-06-25 19:58:05 0 d-------- C:\Documents and Settings\Islam\Application Data\Adobe
2008-06-25 12:54:57 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-06-25 03:03:17 0 d-------- C:\Documents and Settings\NetworkService\Application Data\Adobe
2008-06-25 03:00:12 0 dr------- C:\Documents and Settings\NetworkService\Favorites
2008-06-25 02:13:57 20480 --a------ C:\WINDOWS\system32\UoO6pai0.dll
2008-06-20 21:04:35 0 d-------- C:\Program Files\PowerISO
2008-06-12 01:28:49 56108 --a------ C:\WINDOWS\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
2008-06-11 23:03:40 0 d-------- C:\Program Files\Counter Strike Condition Zero
2008-06-11 23:02:03 6 --a------ C:\Documents and Settings\Administrator\MK3NAME.DAT
2008-06-11 23:02:03 2 --a------ C:\Documents and Settings\Administrator\MK3.DAT
2008-06-02 17:06:30 0 d-------- C:\WINDOWS\system32\Adobe
-- Find3M Report ---------------------------------------------------------------
2008-06-28 15:36:42 0 d-------- C:\Program Files\Java
2008-06-26 01:10:07 0 d-------- C:\Documents and Settings\Administrator\Application Data\Move Networks
2008-06-23 16:26:36 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2008-06-18 23:57:38 0 d-------- C:\Program Files\Messenger
2008-06-18 23:48:12 0 d-------- C:\Program Files\Windows Live
2008-06-15 02:31:06 0 d-------- C:\Program Files\Nokia
2008-06-15 02:31:06 0 d-------- C:\Program Files\Common Files\Nokia
2008-06-11 01:03:08 0 d-------- C:\Program Files\Common Files\Adobe
2008-04-03 21:40:32 1394 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-28 23:19:34 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [09/20/2005 09:32 AM]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [02/12/2008 10:06 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [02/16/2007 10:54 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [03/25/2008 04:28 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/03/2004 05:56 PM]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [04/12/2007 01:43 AM]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{650CA63D-4A01-4BF8-A608-9B1EBB36292E}"= C:\WINDOWS\system32\UoO6pai0.dll [06/27/2008 04:10 PM 20480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll,
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM\aim.exe -cnetwait.odl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
"C:\Program Files\BitTorrent_DNA\dna.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1140464654\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Access]
C:\Program Files\Media Access\MediaAccK.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
"C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
*Newly Created Service* - SSMDRV
-- Hosts -----------------------------------------------------------------------
127.0.0.1 localhost
-- End of Deckard's System Scanner: finished at 2008-06-28 16:14:57 ------------The problem of the inactive window no longer occurs, and I've monitored the running processes. "iexplore.exe" no longer comes up temporarily.
As for my Hosts files and the ATF cleaner, I have both, and a folder with some other G2G programs; I run CCleaner daily as I use the computer often.
Thanks, and if there are any other problems with the logs I posted above, take your time in responding.
Suli
PS: Thanks for the best wishes, I completed reading the majority of the tutorials and will start on the PLs soon.
Edited by MatrixEquilibrium, 28 June 2008 - 03:32 PM.