Tried cleaning multiple times, need some custom help please [Closed] - Geeks to Go Forums

Jump to content

Log in Register Register Malware removal guide How it works

Tried cleaning multiple times, need some custom help please [Closed] avast blocking v1.adwarefeed, unable to update antivirus detects, etc.

#1 theweauction

  • Group: Member
  • Posts: 3
  • Joined: 18-September 09

Posted 18 September 2009 - 08:18 PM

Hello my name is Andy I've ran the basic guide here and double checked hoping for some miracles. So some details, I've ran Temp File Cleaner, tried SysRestorePoint but it runs into an application error of initialize property (0xc000007b). When i did a ERU backup Avast said it found a sample of Win32Vitro in the .exe so my registry needs help. Malwarebytes update times out with the error 732 unable to connect but the last time i updated was 9/14/2009, also after running it doesn't find anything. I had AVG originally but i couldnt update that so i tried AntiVir and I couldn't completely install that so i'm using Avast. Also rootrepeal starts to scan but 30 seconds in it causes my harddrive to have a continuous load and my mouse begins to stutter, I wiat but it just locks up. Following are my OTL logs. I hope I did all this right. Any help is very greatly appreciated, thanks in advance!

OTL logfile created on: 9/18/2009 9:59:04 PM - Run 1
OTL by OldTimer - Version 3.0.14.0 Folder = C:\Documents and Settings\Andy\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.37 Gb Available Physical Memory | 68.54% Memory free
3.85 Gb Paging File | 3.27 Gb Available in Paging File | 85.12% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 127.99 Gb Total Space | 6.37 Gb Free Space | 4.98% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 259.64 Gb Total Space | 38.77 Gb Free Space | 14.93% Space Free | Partition Type: NTFS
Drive F: | 78.13 Gb Total Space | 30.02 Gb Free Space | 38.43% Space Free | Partition Type: NTFS
Drive G: | 465.76 Gb Total Space | 450.16 Gb Free Space | 96.65% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ANDYS
Current User Name: Andy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2008/07/07 08:15:18 | 00,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
PRC - [2009/08/17 11:58:55 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/08/17 12:07:17 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2008/04/13 20:12:19 | 01,054,208 | ---- | M] (Microsoft Corporation) -- C:\windows\Explorer.EXE
PRC - [2007/01/30 22:54:36 | 16,139,264 | R--- | M] (Realtek Semiconductor Corp.) -- C:\windows\RTHDCPL.EXE
PRC - [2007/04/20 08:59:30 | 01,169,720 | ---- | M] (Maxtor) -- C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe
PRC - [2007/08/31 13:01:22 | 01,037,736 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft IntelliPoint\ipoint.exe
PRC - [2009/09/08 21:09:42 | 00,305,440 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/07/31 15:23:21 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/08/17 12:07:23 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/03/05 16:07:20 | 02,280,960 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/01/10 22:54:36 | 00,115,712 | ---- | M] (KaaKoon) -- C:\Program Files\HotSwap!\HotSwap!.EXE
PRC - [2007/08/31 12:58:52 | 00,357,800 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
PRC - [2009/08/29 02:00:12 | 00,987,136 | ---- | M] () -- C:\Documents and Settings\Andy\Local Settings\Apps\F.lux\flux.exe
PRC - [2008/05/02 02:44:08 | 00,805,392 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe
PRC - [2008/09/29 02:38:26 | 00,752,128 | ---- | M] (Realtime Soft Ltd) -- C:\Program Files\UltraMon\UltraMon.exe
PRC - [2008/09/29 01:02:38 | 00,327,168 | ---- | M] (Realtime Soft Ltd) -- C:\Program Files\UltraMon\UltraMonTaskbar.exe
PRC - [2008/05/02 02:40:56 | 00,076,304 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
PRC - [2009/08/28 19:42:54 | 00,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2009/07/31 15:23:19 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2007/09/04 20:25:44 | 00,151,552 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
PRC - [2009/02/09 14:18:00 | 00,184,320 | ---- | M] (NVIDIA Corporation) -- C:\windows\System32\nvsvc32.exe
PRC - [2008/11/24 20:35:32 | 00,066,872 | ---- | M] () -- C:\windows\System32\PnkBstrA.exe
PRC - [2008/08/06 11:34:02 | 00,216,032 | ---- | M] () -- C:\Program Files\Macrium\Reflect\ReflectService.exe
PRC - [2008/03/13 11:24:00 | 00,135,168 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
PRC - [2007/01/04 17:38:08 | 00,045,056 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2009/08/17 12:07:01 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/08/17 12:04:21 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009/09/08 21:09:30 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/09/18 20:37:08 | 00,535,552 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Andy\My Documents\Downloads\OTL.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/07/07 08:15:18 | 00,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice [Auto | Running])
SRV - File not found -- -- (AcrSch2Svc [Auto | Stopped])
SRV - [2008/05/09 13:17:37 | 00,093,184 | ---- | M] (Adobe Systems) -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service [On_Demand | Stopped])
SRV - [2008/09/24 08:20:05 | 00,304,528 | ---- | M] (Protection Technology) -- C:\windows\System32\appdrvrem01.exe -- (appdrvrem01 [Auto | Stopped])
SRV - [2009/08/28 19:42:54 | 00,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2008/07/25 12:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2009/08/17 11:58:55 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
SRV - [2009/08/17 12:07:17 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
SRV - [2009/08/17 12:07:01 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
SRV - [2009/08/17 12:04:21 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
SRV - [2009/08/15 14:15:43 | 00,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe -- (avg8emc [Auto | Stopped])
SRV - [2009/08/15 14:15:34 | 00,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd [Auto | Stopped])
SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2008/07/25 12:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2009/08/22 18:32:16 | 00,655,624 | ---- | M] (Acresso Software Inc.) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service [On_Demand | Stopped])
SRV - [2008/07/29 22:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/04/13 20:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\windows\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [On_Demand | Stopped])
SRV - [2005/04/04 01:41:10 | 00,090,112 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2008/07/29 20:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2009/09/08 21:09:30 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2009/07/31 15:23:19 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2008/05/02 02:42:06 | 00,121,360 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ [On_Demand | Stopped])
SRV - [2008/07/29 20:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - File not found -- -- (Net_Login [Auto | Stopped])
SRV - [2007/09/04 20:25:44 | 00,151,552 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe -- (nTuneService [Auto | Running])
SRV - [2009/02/09 14:18:00 | 00,184,320 | ---- | M] (NVIDIA Corporation) -- C:\windows\System32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2004/03/18 16:55:48 | 00,086,016 | ---- | M] (HP) -- C:\windows\System32\HPZipm12.exe -- (Pml Driver HPZ12 [On_Demand | Stopped])
SRV - [2008/11/24 20:35:32 | 00,066,872 | ---- | M] () -- C:\windows\System32\PnkBstrA.exe -- (PnkBstrA [Auto | Running])
SRV - [2008/08/06 11:34:02 | 00,216,032 | ---- | M] () -- C:\Program Files\Macrium\Reflect\ReflectService.exe -- (ReflectService [Auto | Running])
SRV - [2007/05/14 12:54:36 | 00,272,024 | ---- | M] () -- C:\Program Files\CyberLink\Shared files\RichVideo.exe -- (RichVideo [On_Demand | Stopped])
SRV - [2007/11/15 16:30:48 | 00,092,792 | ---- | M] (CACE Technologies) -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd [On_Demand | Stopped])
SRV - [2008/04/13 20:11:54 | 00,761,856 | ---- | M] (Maxthon International ltd.) -- C:\windows\System32\trkwks.dll -- (TrkWks [Auto | Running])
SRV - [2005/01/28 14:44:28 | 00,059,392 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\wdfmgr.exe -- (UMWdf [On_Demand | Stopped])
SRV - [2008/03/13 11:24:00 | 00,135,168 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe -- (UpdateCenterService [Auto | Running])
SRV - [2007/01/04 17:38:08 | 00,045,056 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service [Auto | Running])
SRV - [2006/10/18 21:05:24 | 00,933,888 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 8E 7B AB 86 9B 11 CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "IMDb"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {c4d362ec-1cff-4ca0-9031-99a8fad7995a}:1.10.2009073101
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}:6.0.16
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: webnotestoolbar@webnotes.net:1.1
FF - prefs.js..extensions.enabledItems: {3B34F143-7D2A-4B01-B210-F772A0DCBCA0}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3
FF - prefs.js..extensions.enabledItems: {36C13C8F-54F1-412e-8177-2E411719162D}:4.0.1

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/09/15 01:41:07 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/07/26 18:32:12 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2008/11/24 02:59:46 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/14 19:12:59 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/09/14 19:14:02 | 00,000,000 | ---D | M]

[2008/08/27 21:32:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\mozilla\Extensions
[2008/08/27 21:32:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/09/18 21:33:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\mozilla\Firefox\Profiles\9u8el4o1.default\extensions
[2009/07/26 19:51:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\mozilla\Firefox\Profiles\9u8el4o1.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/07/26 17:44:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\mozilla\Firefox\Profiles\9u8el4o1.default\extensions\{36C13C8F-54F1-412e-8177-2E411719162D}
[2009/08/11 00:59:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\mozilla\Firefox\Profiles\9u8el4o1.default\extensions\{c4d362ec-1cff-4ca0-9031-99a8fad7995a}
[2009/04/27 00:37:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\mozilla\Firefox\Profiles\9u8el4o1.default\extensions\webnotestoolbar@webnotes.net
[2008/06/20 09:20:50 | 00,000,908 | ---- | M] () -- C:\Documents and Settings\Andy\Application Data\Mozilla\FireFox\Profiles\9u8el4o1.default\searchplugins\imdb.xml
[2009/09/18 21:33:42 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/02/06 02:38:33 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{3B34F143-7D2A-4B01-B210-F772A0DCBCA0}
[2009/09/09 23:05:51 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/12/07 02:52:48 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008/03/09 02:01:48 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/07/13 16:50:04 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2008/11/24 02:59:56 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2008/12/04 15:22:49 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/04/06 15:43:20 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/06/11 03:33:51 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2009/08/10 22:51:07 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
[2009/09/15 00:18:40 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
[2009/09/09 23:05:45 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/09/09 23:05:45 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/07/31 15:23:11 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2007/11/20 15:37:22 | 01,334,576 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll
[2009/09/09 23:05:47 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2007/05/10 23:52:34 | 00,095,864 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2009/09/14 19:14:01 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/09/14 19:14:01 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/09/14 19:14:02 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/09/14 19:14:02 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/09/14 19:14:02 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/09/14 19:14:02 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/09/14 19:14:02 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2007/04/16 13:07:12 | 00,180,293 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2009/07/15 14:10:00 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/07/15 14:10:00 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/07/15 14:10:00 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/07/15 14:10:00 | 00,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/07/15 14:10:00 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/07/15 14:10:00 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml

O1 HOSTS File: (330975 bytes) - C:\windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 11336 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {0B8D6118-C605-47B8-9159-466CB1AA1099} - No CLSID value found.
O2 - BHO: (no name) - {20655162-E6A5-4A48-8846-11218FAAF943} - No CLSID value found.
O2 - BHO: (no name) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - No CLSID value found.
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {F775DC26-396A-4FB7-8772-ACAFA76690F6} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Alcmtr] C:\windows\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MaxBlastMonitor.exe] C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe (Maxtor)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\windows\System32\nwiz.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [RTHDCPL] C:\windows\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SkyTel] C:\windows\SkyTel.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [USB2Check] C:\windows\System32\PCLECoInst.DLL (Pinnacle Systems)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [F.lux] C:\Documents and Settings\Andy\Local Settings\Apps\F.lux\flux.exe ()
O4 - HKCU..\Run: [HotSwap! Applet] C:\Program Files\HotSwap!\HotSwap!.EXE (KaaKoon)
O4 - HKCU..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\WECPUpdate.exe (MediaCodec.Org)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\UltraMon.lnk = C:\windows\Installer\{CC15A5FC-B6D3-4A2D-8A26-D8F2702A3C00}\IcoUltraMon.ico ()
O4 - Startup: C:\Documents and Settings\Andy\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: &D&ownload &with BitComet - Reg Error: Value error. File not found
O8 - Extra context menu item: &D&ownload all video with BitComet - Reg Error: Value error. File not found
O8 - Extra context menu item: &D&ownload all with BitComet - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\windows\bdoscandel.exe ()
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - F:\Old Drive ©\Program Files\AIM\aim.exe File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\windows\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\windows\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 72 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/...can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDownlo...iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\hebedogu.dll) - C:\windows\System32\hebedogu.dll File not found
O20 - AppInit_DLLs: (c:\windows\system32\) - C:\windows\System32 [2009/09/18 21:26:59 | 00,000,000 | ---D | M]
O20 - AppInit_DLLs: (c:\windows\system32\huyerifi.dll) - C:\windows\System32\huyerifi.dll File not found
O20 - AppInit_DLLs: (c:\windows\system32\) - C:\windows\System32 [2009/09/18 21:26:59 | 00,000,000 | ---D | M]
O20 - AppInit_DLLs: (c:\windows\system32\) - C:\windows\System32 [2009/09/18 21:26:59 | 00,000,000 | ---D | M]
O20 - AppInit_DLLs: (jcjmqp.dll) - File not found
O20 - AppInit_DLLs: (dceuki.dll) - File not found
O20 - AppInit_DLLs: (gayujoje.dll) - File not found
O20 - AppInit_DLLs: (zotemiso.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\hgGyyaAT: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
O20 - Winlogon\Notify\pMDVllJy: DllName - pMDVllJy.dll - File not found
O20 - Winlogon\Notify\ssqQgDsT: DllName - ssqQgDsT.dll - File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O30 - LSA: Authentication Packages - (relog_ap) - C:\windows\System32\relog_ap.dll (Acronis)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/01/22 16:28:59 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{01ca0571-351f-11de-b736-00044b0429b5}\Shell - "" = AutoRun
O33 - MountPoints2\{01ca0571-351f-11de-b736-00044b0429b5}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c78d1af6-53bd-11de-b75c-00044b0429b5}\Shell - "" = AutoRun
O33 - MountPoints2\{c78d1af6-53bd-11de-b75c-00044b0429b5}\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\windows\System32\lsdelete.exe ()

NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: TrkWks - C:\windows\System32\trkwks.dll (Maxthon International ltd.)
NetSvcs: Wmi - C:\windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - C:\windows\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)

========== Files/Folders - Created Within 14 Days ==========

[2099/01/01 12:00:00 | 00,006,456 | ---- | C] () -- C:\windows\System32\satonite
[2009/09/18 21:40:19 | 00,000,000 | ---D | C] -- C:\windows\ERDNT
[2009/09/18 21:39:28 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/09/17 22:04:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Andy\Application Data\AVG8
[2009/09/16 02:10:34 | 00,000,000 | -H-D | C] -- C:\$AVG8.VAULT$
[2009/09/15 21:09:33 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\windows\System32\AvastSS.scr
[2009/09/15 21:09:33 | 00,051,376 | ---- | C] (ALWIL Software) -- C:\windows\System32\drivers\aswTdi.sys
[2009/09/15 21:09:33 | 00,026,944 | ---- | C] (ALWIL Software) -- C:\windows\System32\drivers\aavmker4.sys
[2009/09/15 21:09:33 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\windows\System32\drivers\aswRdr.sys
[2009/09/15 21:09:33 | 00,001,709 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/09/15 21:09:32 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\windows\System32\drivers\aswSP.sys
[2009/09/15 21:09:32 | 00,094,160 | ---- | C] (ALWIL Software) -- C:\windows\System32\drivers\aswmon2.sys
[2009/09/15 21:09:32 | 00,093,392 | ---- | C] (ALWIL Software) -- C:\windows\System32\drivers\aswmon.sys
[2009/09/15 21:09:32 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\windows\System32\drivers\aswFsBlk.sys
[2009/09/15 21:09:20 | 01,279,456 | ---- | C] (ALWIL Software) -- C:\windows\System32\aswBoot.exe
[2009/09/15 21:09:20 | 00,380,928 | ---- | C] () -- C:\windows\System32\actskin4.ocx
[2009/09/15 08:55:01 | 00,000,003 | ---- | C] () -- C:\windows\System32\hfsd
[2009/09/15 02:09:34 | 00,000,000 | ---D | C] -- C:\windows\BDOSCAN8
[2009/09/15 01:41:07 | 00,000,000 | ---D | C] -- C:\windows\System32\drivers\Avg
[2009/09/15 01:40:52 | 00,000,000 | ---D | C] -- C:\Program Files\AVG
[2009/09/15 01:02:35 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2009/09/15 00:35:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
[2009/09/15 00:22:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/09/15 00:22:26 | 00,000,780 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/09/15 00:22:22 | 00,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2009/09/15 00:22:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Andy\Application Data\SUPERAntiSpyware.com
[2009/09/15 00:16:13 | 00,000,440 | ---- | C] () -- C:\windows\tasks\ParetoLogic Registration.job
[2009/09/15 00:15:58 | 00,715,040 | -HS- | C] () -- C:\windows\System32\drivers\fidbox.dat
[2009/09/15 00:15:58 | 00,046,368 | -HS- | C] () -- C:\windows\System32\drivers\fidbox2.dat
[2009/09/15 00:15:58 | 00,013,784 | -HS- | C] () -- C:\windows\System32\drivers\fidbox.idx
[2009/09/15 00:15:58 | 00,006,464 | -HS- | C] () -- C:\windows\System32\drivers\fidbox2.idx
[2009/09/15 00:15:36 | 00,000,985 | ---- | C] () -- C:\rollback.ini
[2009/09/15 00:09:32 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\ParetoLogic
[2009/09/15 00:09:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Virus PLUS
[2009/09/15 00:09:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/09/14 21:23:52 | 00,000,762 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Diablo II.lnk
[2009/09/14 21:23:52 | 00,000,000 | ---D | C] -- C:\Program Files\Diablo II
[2009/09/14 19:15:26 | 00,000,000 | ---D | C] -- C:\Program Files\iPod
[2009/09/14 19:15:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/09/14 17:49:48 | 00,000,000 | R--D | C] -- C:\windows\AsDmiHtm
[2009/09/14 17:49:08 | 00,001,746 | ---- | C] () -- C:\windows\Language_trs.ini
[2009/09/14 17:49:02 | 00,016,285 | ---- | C] () -- C:\windows\Ascd_tmp.ini
[2009/09/14 17:49:02 | 00,010,296 | ---- | C] () -- C:\windows\System32\drivers\ASUSHWIO.SYS
[2009/09/14 02:36:48 | 00,077,248 | ---- | C] () -- C:\windows\War3Unin.dat
[2009/09/14 02:36:47 | 00,159,744 | ---- | C] (Blizzard Entertainment) -- C:\windows\War3Unin.exe
[2009/09/14 02:36:47 | 00,002,829 | ---- | C] () -- C:\windows\War3Unin.pif
[2009/09/14 02:10:43 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Blizzard Entertainment
[2009/09/11 00:30:46 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Andy\Application Data\HDRsoft
[2009/09/11 00:28:20 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Andy\Desktop\HDR Pictures
[2009/09/11 00:22:57 | 00,001,643 | ---- | C] () -- C:\Documents and Settings\Andy\Desktop\Photomatix Pro 3.lnk
[2009/09/11 00:22:55 | 00,000,000 | ---D | C] -- C:\Program Files\PhotomatixPro3
[2009/09/10 19:13:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Andy\Desktop\Bowen Hall Pics

========== Files - Modified Within 14 Days ==========

[2009/09/18 22:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At71.job
[2009/09/18 22:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At47.job
[2009/09/18 22:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At23.job
[2009/09/18 21:26:59 | 00,441,124 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2009/09/18 21:26:59 | 00,071,060 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2009/09/18 21:26:58 | 00,521,942 | ---- | M] () -- C:\windows\System32\PerfStringBackup.INI
[2009/09/18 21:22:30 | 00,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT
[2009/09/18 21:22:08 | 00,002,299 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\UltraMon.lnk
[2009/09/18 21:22:04 | 00,204,007 | ---- | M] () -- C:\windows\System32\nvapps.xml
[2009/09/18 21:21:19 | 00,002,048 | --S- | M] () -- C:\windows\bootstat.dat
[2009/09/18 21:00:38 | 06,476,182 | -H-- | M] () -- C:\Documents and Settings\Andy\Local Settings\Application Data\IconCache.db
[2009/09/18 21:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At70.job
[2009/09/18 21:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At46.job
[2009/09/18 21:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At22.job
[2009/09/18 03:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At52.job
[2009/09/18 03:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At4.job
[2009/09/18 03:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At28.job
[2009/09/17 21:57:02 | 00,000,284 | ---- | M] () -- C:\windows\tasks\AppleSoftwareUpdate.job
[2009/09/17 20:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At69.job
[2009/09/17 20:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At45.job
[2009/09/17 20:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At21.job
[2009/09/17 19:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At68.job
[2009/09/17 19:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At44.job
[2009/09/17 19:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At20.job
[2009/09/17 18:37:07 | 00,000,440 | ---- | M] () -- C:\windows\tasks\ParetoLogic Registration.job
[2009/09/17 18:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At67.job
[2009/09/17 18:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At43.job
[2009/09/17 18:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At19.job
[2009/09/17 17:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At66.job
[2009/09/17 17:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At42.job
[2009/09/17 17:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At18.job
[2009/09/17 16:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At65.job
[2009/09/17 16:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At41.job
[2009/09/17 16:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At17.job
[2009/09/17 15:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At64.job
[2009/09/17 15:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At40.job
[2009/09/17 15:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At16.job
[2009/09/17 14:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At63.job
[2009/09/17 14:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At39.job
[2009/09/17 14:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At15.job
[2009/09/17 13:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At62.job
[2009/09/17 13:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At38.job
[2009/09/17 13:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At14.job
[2009/09/17 12:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At61.job
[2009/09/17 12:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At37.job
[2009/09/17 12:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At13.job
[2009/09/17 11:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At60.job
[2009/09/17 11:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At36.job
[2009/09/17 11:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At12.job
[2009/09/17 10:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At59.job
[2009/09/17 10:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At35.job
[2009/09/17 10:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At11.job
[2009/09/17 09:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At58.job
[2009/09/17 09:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At34.job
[2009/09/17 09:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At10.job
[2009/09/17 08:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At9.job
[2009/09/17 08:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At57.job
[2009/09/17 08:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At33.job
[2009/09/17 07:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At8.job
[2009/09/17 07:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At56.job
[2009/09/17 07:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At32.job
[2009/09/17 06:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At7.job
[2009/09/17 06:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At55.job
[2009/09/17 06:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At31.job
[2009/09/17 05:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At6.job
[2009/09/17 05:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At54.job
[2009/09/17 05:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At30.job
[2009/09/17 04:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At53.job
[2009/09/17 04:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At5.job
[2009/09/17 04:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At29.job
[2009/09/17 02:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At51.job
[2009/09/17 02:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At3.job
[2009/09/17 02:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At27.job
[2009/09/17 01:54:15 | 00,012,598 | ---- | M] () -- C:\windows\System32\wpa.dbl
[2009/09/16 01:11:44 | 00,330,975 | R--- | M] () -- C:\windows\System32\drivers\etc\hosts
[2009/09/16 01:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At50.job
[2009/09/16 01:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At26.job
[2009/09/16 01:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At2.job
[2009/09/15 21:09:33 | 00,001,709 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/09/15 21:09:32 | 00,002,626 | ---- | M] () -- C:\windows\System32\CONFIG.NT
[2009/09/15 08:55:01 | 00,000,003 | ---- | M] () -- C:\windows\System32\hfsd
[2009/09/15 02:01:08 | 00,715,040 | -HS- | M] () -- C:\windows\System32\drivers\fidbox.dat
[2009/09/15 02:01:08 | 00,046,368 | -HS- | M] () -- C:\windows\System32\drivers\fidbox2.dat
[2009/09/15 02:01:08 | 00,013,784 | -HS- | M] () -- C:\windows\System32\drivers\fidbox.idx
[2009/09/15 02:01:08 | 00,006,464 | -HS- | M] () -- C:\windows\System32\drivers\fidbox2.idx
[2009/09/15 00:53:22 | 00,330,975 | R--- | M] () -- C:\windows\System32\drivers\etc\hosts.20090916-011144.backup
[2009/09/15 00:39:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At49.job
[2009/09/15 00:34:27 | 00,000,985 | ---- | M] () -- C:\rollback.ini
[2009/09/15 00:33:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At25.job
[2009/09/15 00:25:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At1.job
[2009/09/15 00:22:26 | 00,000,780 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/09/14 23:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At72.job
[2009/09/14 23:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At48.job
[2009/09/14 23:00:00 | 00,000,350 | ---- | M] () -- C:\windows\tasks\At24.job
[2009/09/14 21:44:35 | 00,000,762 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Diablo II.lnk
[2009/09/14 17:49:20 | 00,016,285 | ---- | M] () -- C:\windows\Ascd_tmp.ini
[2009/09/14 17:49:08 | 00,001,746 | ---- | M] () -- C:\windows\Language_trs.ini
[2009/09/14 02:45:40 | 00,077,248 | ---- | M] () -- C:\windows\War3Unin.dat
[2009/09/14 02:40:05 | 00,159,744 | ---- | M] (Blizzard Entertainment) -- C:\windows\War3Unin.exe
[2009/09/14 02:40:05 | 00,002,829 | ---- | M] () -- C:\windows\War3Unin.pif
[2009/09/14 02:29:02 | 00,000,382 | ---- | M] () -- C:\windows\tasks\SmartDefrag.job
[2009/09/11 00:22:57 | 00,001,643 | ---- | M] () -- C:\Documents and Settings\Andy\Desktop\Photomatix Pro 3.lnk
[2009/09/10 14:54:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys
[2009/09/10 14:53:50 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys

========== LOP Check ==========

[2009/09/15 00:39:22 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/09/14 19:16:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/06/15 05:40:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2DBoy
[2002/08/23 22:45:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore
[2007/12/01 20:31:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Acronis
[2007/12/04 20:39:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CyberLink
[2009/06/22 21:03:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2009/08/22 19:17:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2008/05/25 18:04:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grisoft
[2007/12/10 23:12:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LogiShrd
[2009/03/20 20:31:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Macrium
[2007/12/01 22:10:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Maxtor
[2009/04/06 01:31:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Minnetonka Audio Software
[2009/09/15 01:49:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/09/15 00:09:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Virus PLUS
[2009/04/16 23:35:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
[2009/04/16 23:35:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle Studio Plus
[2009/03/25 17:01:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle Studio Ultimate
[2009/06/26 22:08:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap Games
[2008/10/04 05:03:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ranczcly
[2008/04/20 20:30:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SlySoft
[2009/04/16 23:35:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Studio 12
[2009/09/18 21:22:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/01/05 02:02:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia
[2002/08/23 22:45:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/09/17 22:04:22 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\Andy\Application Data
[2007/12/02 21:54:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\acccore
[2008/10/01 11:23:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\Ahead
[2007/12/02 00:24:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\Aim
[2009/01/11 20:00:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\Audacity
[2007/12/29 23:26:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\Bioshock
[2009/05/05 16:59:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\Braid
[2008/03/05 11:47:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\BSplayer PRO
[2009/05/05 13:46:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\Crayon Physics Deluxe
[2007/12/04 20:41:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\CyberLink
[2008/05/09 12:55:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\DAEMON Tools
[2009/06/12 03:22:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\Download Manager
[2009/05/02 02:07:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\DVD Shrink
[2009/08/24 21:53:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\FileZilla
[2009/09/02 00:37:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\GetRightToGo
[2008/04/18 02:31:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\Hamachi
[2009/09/11 00:30:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\HDRsoft
[2009/04/26 21:27:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\IObit
[2008/11/14 03:06:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\Leadertech
[2008/12/01 01:03:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\Move Networks
[2009/02/17 01:01:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\OpenOffice.org
[2009/04/17 00:19:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\proDAD
[2007/12/12 18:27:55 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Andy\Application Data\SecuROM
[2009/03/13 23:55:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\SystemRequirementsLab
[2009/09/02 00:46:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\Turbine
[2009/07/05 21:51:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\U3
[2009/05/03 22:10:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\Ventrilo
[2007/12/18 01:48:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\Viewpoint
[2009/08/18 03:08:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\Vso
[2009/03/28 16:27:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\XRay Engine
[2009/09/17 21:57:02 | 00,000,284 | ---- | M] () -- C:\windows\Tasks\AppleSoftwareUpdate.job
[2009/09/15 00:25:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At1.job
[2009/09/17 09:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At10.job
[2009/09/17 10:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At11.job
[2009/09/17 11:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At12.job
[2009/09/17 12:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At13.job
[2009/09/17 13:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At14.job
[2009/09/17 14:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At15.job
[2009/09/17 15:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At16.job
[2009/09/17 16:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At17.job
[2009/09/17 17:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At18.job
[2009/09/17 18:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At19.job
[2009/09/16 01:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At2.job
[2009/09/17 19:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At20.job
[2009/09/17 20:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At21.job
[2009/09/18 21:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At22.job
[2009/09/18 22:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At23.job
[2009/09/14 23:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At24.job
[2009/09/15 00:33:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At25.job
[2009/09/16 01:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At26.job
[2009/09/17 02:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At27.job
[2009/09/18 03:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At28.job
[2009/09/17 04:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At29.job
[2009/09/17 02:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At3.job
[2009/09/17 05:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At30.job
[2009/09/17 06:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At31.job
[2009/09/17 07:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At32.job
[2009/09/17 08:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At33.job
[2009/09/17 09:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At34.job
[2009/09/17 10:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At35.job
[2009/09/17 11:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At36.job
[2009/09/17 12:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At37.job
[2009/09/17 13:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At38.job
[2009/09/17 14:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At39.job
[2009/09/18 03:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At4.job
[2009/09/17 15:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At40.job
[2009/09/17 16:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At41.job
[2009/09/17 17:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At42.job
[2009/09/17 18:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At43.job
[2009/09/17 19:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At44.job
[2009/09/17 20:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At45.job
[2009/09/18 21:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At46.job
[2009/09/18 22:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At47.job
[2009/09/14 23:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At48.job
[2009/09/15 00:39:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At49.job
[2009/09/17 04:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At5.job
[2009/09/16 01:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At50.job
[2009/09/17 02:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At51.job
[2009/09/18 03:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At52.job
[2009/09/17 04:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At53.job
[2009/09/17 05:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At54.job
[2009/09/17 06:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At55.job
[2009/09/17 07:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At56.job
[2009/09/17 08:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At57.job
[2009/09/17 09:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At58.job
[2009/09/17 10:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At59.job
[2009/09/17 05:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At6.job
[2009/09/17 11:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At60.job
[2009/09/17 12:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At61.job
[2009/09/17 13:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At62.job
[2009/09/17 14:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At63.job
[2009/09/17 15:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At64.job
[2009/09/17 16:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At65.job
[2009/09/17 17:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At66.job
[2009/09/17 18:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At67.job
[2009/09/17 19:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At68.job
[2009/09/17 20:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At69.job
[2009/09/17 06:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At7.job
[2009/09/18 21:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At70.job
[2009/09/18 22:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At71.job
[2009/09/14 23:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At72.job
[2009/09/17 07:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At8.job
[2009/09/17 08:00:00 | 00,000,350 | ---- | M] () -- C:\windows\Tasks\At9.job
[2001/08/18 08:00:00 | 00,000,065 | RH-- | M] () -- C:\windows\Tasks\desktop.ini
[2009/09/17 18:37:07 | 00,000,440 | ---- | M] () -- C:\windows\Tasks\ParetoLogic Registration.job
[2009/09/18 21:22:30 | 00,000,006 | -H-- | M] () -- C:\windows\Tasks\SA.DAT
[2009/09/14 02:29:02 | 00,000,382 | ---- | M] () -- C:\windows\Tasks\SmartDefrag.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >

< %systemroot%\system32\eventlog.dll >
[2008/04/13 20:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\windows\system32\eventlog.dll

< %systemroot%\system32\scecli.dll >
[2008/04/13 20:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) -- C:\windows\system32\scecli.dll

< %systemroot%\netlogon.dll >

< %systemroot%\system32\cngaudit.dll >

< %systemroot%\system32\sceclt.dll >

< %systemroot%\ntelogon.dll >

< %systemroot%\system32\logevent.dll >

========== Alternate Data Streams ==========

@Alternate Data Stream - 498 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:51F9B1F4
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A73B0434
< End of report >



OTL Extras logfile created on: 9/18/2009 9:59:04 PM - Run 1
OTL by OldTimer - Version 3.0.14.0 Folder = C:\Documents and Settings\Andy\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.37 Gb Available Physical Memory | 68.54% Memory free
3.85 Gb Paging File | 3.27 Gb Available in Paging File | 85.12% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 127.99 Gb Total Space | 6.37 Gb Free Space | 4.98% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 259.64 Gb Total Space | 38.77 Gb Free Space | 14.93% Space Free | Partition Type: NTFS
Drive F: | 78.13 Gb Total Space | 30.02 Gb Free Space | 38.43% Space Free | Partition Type: NTFS
Drive G: | 465.76 Gb Total Space | 450.16 Gb Free Space | 96.65% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ANDYS
Current User Name: Andy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.inf [@ = inffile] -- Reg Error: Key error. File not found
.ini [@ = inifile] -- C:\windows\notepad.exe (Microsoft Corporation)
.js [@ = JSFile] -- Reg Error: Key error. File not found
.jse [@ = JSEFile] -- Reg Error: Key error. File not found
.txt [@ = txtfile] -- C:\windows\notepad.exe (Microsoft Corporation)
.vbe [@ = VBEFile] -- Reg Error: Value error. File not found
.vbs [@ = VBSFile] -- Reg Error: Key error. File not found
.wsf [@ = WSFFile] -- Reg Error: Key error. File not found
.wsh [@ = WSHFile] -- Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- Reg Error: Key error.
batfile [open] -- "%1" %* File not found
batfile [print] -- Reg Error: Key error.
chm.file [open] -- "C:\WINDOWS\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- Reg Error: Key error.
cmdfile [open] -- "%1" %* File not found
cmdfile [print] -- Reg Error: Key error.
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [open] -- Reg Error: Key error.
inffile [print] -- Reg Error: Key error.
inifile [open] -- notepad.exe %1 (Microsoft Corporation)
inifile [print] -- Reg Error: Key error.
jsfile [edit] -- Reg Error: Key error.
jsfile [open] -- Reg Error: Key error.
jsfile [print] -- Reg Error: Key error.
jsefile [edit] -- Reg Error: Key error.
jsefile [open] -- Reg Error: Key error.
jsefile [print] -- Reg Error: Key error.
piffile [open] -- "%1" %* File not found
regfile [edit] -- Reg Error: Key error.
regfile [merge] -- Reg Error: Key error.
regfile [print] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- notepad.exe %1 (Microsoft Corporation)
txtfile [print] -- Reg Error: Key error.
txtfile [printto] -- Reg Error: Key error.
vbefile [edit] -- Reg Error: Key error.
vbefile [open] -- Reg Error: Value error.
vbefile [print] -- Reg Error: Key error.
vbsfile [edit] -- Reg Error: Key error.
vbsfile [open] -- Reg Error: Key error.
vbsfile [print] -- Reg Error: Key error.
wsffile [edit] -- Reg Error: Key error.
wsffile [open] -- Reg Error: Key error.
wsffile [print] -- Reg Error: Key error.
wshfile [open] -- Reg Error: Key error.
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"19878:TCP" = 19878:TCP:*:Enabled:BitComet 19878 TCP
"19878:UDP" = 19878:UDP:*:Enabled:BitComet 19878 UDP
"6112:TCP" = 6112:TCP:*:Enabled:EuroBattlenet
"6112:UDP" = 6112:UDP:*:Enabled:EuroBattlenet
"6113:TCP" = 6113:TCP:*:Enabled:EuroBattlenet
"6114:TCP" = 6114:TCP:*:Enabled:EuroBattlenet
"6115:TCP" = 6115:TCP:*:Enabled:EuroBattlenet
"6116:TCP" = 6116:TCP:*:Enabled:EuroBattlenet
"6117:TCP" = 6117:TCP:*:Enabled:EuroBattlenet
"6118:TCP" = 6118:TCP:*:Enabled:EuroBattlenet
"6119:TCP" = 6119:TCP:*:Enabled:EuroBattlenet
"6113:UDP" = 6113:UDP:*:Enabled:EuroBattlenet
"6114:UDP" = 6114:UDP:*:Enabled:EuroBattlenet
"6115:UDP" = 6115:UDP:*:Enabled:EuroBattlenet
"6116:UDP" = 6116:UDP:*:Enabled:EuroBattlenet
"6117:UDP" = 6117:UDP:*:Enabled:EuroBattlenet
"6118:UDP" = 6118:UDP:*:Enabled:EuroBattlenet
"6119:UDP" = 6119:UDP:*:Enabled:EuroBattlenet
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Steam\SteamApps\lordfogsworth\team fortress 2\hl2.exe" = C:\Program Files\Steam\SteamApps\lordfogsworth\team fortress 2\hl2.exe:*:Enabled:hl2 -- File not found
"C:\Program Files\Steam\steamapps\lordfogsworth\source sdk base\hl2.exe" = C:\Program Files\Steam\steamapps\lordfogsworth\source sdk base\hl2.exe:*:Enabled:hl2 -- File not found
"C:\Program Files\BitComet\BitComet.exe" = C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client -- File not found
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader -- (AOL LLC)
"C:\Program Files\Steam\steamapps\lordfogsworth\counter-strike source\hl2.exe" = C:\Program Files\Steam\steamapps\lordfogsworth\counter-strike source\hl2.exe:*:Enabled:hl2 -- File not found
"C:\WINDOWS\system32\PnkBstrA.exe" = C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA -- ()
"C:\WINDOWS\system32\PnkBstrB.exe" = C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB -- ()
"C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" = C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe:*:Enabled:CyberLink PowerDVD -- (CyberLink Corp.)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM -- (AOL LLC)
"C:\Program Files\Steam\steamapps\lordfogsworth\day of defeat source\hl2.exe" = C:\Program Files\Steam\steamapps\lordfogsworth\day of defeat source\hl2.exe:*:Enabled:hl2 -- File not found
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam -- (Valve Corporation)
"C:\Program Files\Warcraft III\Warcraft III.exe" = C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III -- (Blizzard Entertainment)
"C:\Program Files\Soulseek\slsk.exe" = C:\Program Files\Soulseek\slsk.exe:*:Enabled:SoulSeek -- ()
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Warcraft III\euroloader.exe" = C:\Program Files\Warcraft III\euroloader.exe:*:Enabled:euroloader -- File not found
"C:\Program Files\Pinnacle\Studio 12\Programs\RM.exe" = C:\Program Files\Pinnacle\Studio 12\Programs\RM.exe:*:Enabled:Render Manager -- (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe" = C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe:*:Enabled:Studio -- (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 12\Programs\umi.exe" = C:\Program Files\Pinnacle\Studio 12\Programs\umi.exe:*:Enabled:umi -- (Pinnacle Systems)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Program Files\Garena\Garena.exe" = C:\Program Files\Garena\Garena.exe:*:Enabled:Garena -- (Garena Interactive PTE LTD)
"C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe" = C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe:*:Enabled:Nero ShowTime -- (Nero AG)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)
"C:\Program Files\Steam\steamapps\common\left 4 dead\left4dead.exe" = C:\Program Files\Steam\steamapps\common\left 4 dead\left4dead.exe:*:Enabled:Left 4 Dead -- File not found
"C:\Program Files\Steam\steamapps\lordfogsworth\source sdk base 2007\hl2.exe" = C:\Program Files\Steam\steamapps\lordfogsworth\source sdk base 2007\hl2.exe:*:Enabled:hl2 -- File not found
"C:\Program Files\Adobe\Adobe After Effects CS4\Support Files\AfterFX.exe" = C:\Program Files\Adobe\Adobe After Effects CS4\Support Files\AfterFX.exe:*:Enabled:Adobe After Effects CS4 -- (Adobe Systems Incorporated)
"C:\Program Files\GoFTP\GoFTP.exe" = C:\Program Files\GoFTP\GoFTP.exe:*:Enabled:GoFTP -- File not found
"C:\Documents and Settings\Andy\Desktop\DOTA FILES\GoFTP.exe" = C:\Documents and Settings\Andy\Desktop\DOTA FILES\GoFTP.exe:*:Enabled:GoFTP -- File not found
"C:\Program Files\Turbine\Dungeons & Dragons Online - Stormreach\dndclient.exe" = C:\Program Files\Turbine\Dungeons & Dragons Online - Stormreach\dndclient.exe:*:Enabled:dndclient -- (Turbine, Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\WINDOWS\Temp\VRTB.tmp" = C:\WINDOWS\Temp\VRTB.tmp:*:Enabled:installer -- File not found
"C:\windows\TEMP\VRT4.tmp" = C:\windows\TEMP\VRT4.tmp:*:Enabled:installer -- File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{14F06853-8A15-4731-BBDC-C9B40A866A63}" = Virtual VCR
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1B779CC7-5F25-29B3-5150-AF44A6201033}" = Nero 7 Demo
"{1CB92574-96F2-467B-B793-5CEB35C40C29}" = Image Resizer Powertoy for Windows XP
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{262BF2CD-601D-4F43-919C-4B00B1D1F338}" = Boris Graffiti
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java™ 6 Update 16
"{26A24AE4-039D-4CA4-87B4-2F83216013F0}" = Java™ 6 Update 13
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2F750C77-1FEC-44F9-88CC-2CE322EBD61E}" = Microsoft Games for Windows - LIVE Redistributable
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3
"{411F3ABA-2AB5-4799-AA19-6ADF0A8F7424}" = Adobe Setup
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets
"{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
"{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}" = Sony USB Driver
"{5EB90C06-964F-4195-B83E-BD7E55C88415}" = Pinnacle Video Driver
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6F69C969-2942-4E7B-B594-75B37664B8BA}" = NVIDIA System Update
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{786C5747-1437-443D-B06E-79A00FE45110}" = Adobe Stock Photos 1.0
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{81A60A13-224D-4637-8203-3EAC03B121A4}" = Maxtor MaxBlast
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{88742616-A6E9-4C7E-9665-B625799541FB}" = Wireless-G PCI Adapter
"{8BC826C5-DFBF-4E3E-AF23-3A88F8BE6AC9}" = LG Download VX8500 DLL
"{8C5FAD77-F678-4758-A296-C12F08D179E0}" = Microsoft IntelliPoint 6.2
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8EDBA74D-0686-4C99-BFDD-F894678E5102}" = Adobe Common File Installer
"{8FFC924C-ED06-44CB-8867-3CA778ECE903}" = Adobe Help Center 2.0
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{9580813D-94B1-4C28-9426-A441E2BB29A5}" = Counter-Strike: Source
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-A81100000003}" = Adobe Reader 8.1.1
"{AE3D38A6-13B1-40B3-9423-D1FA9982FB6A}" = Adobe Bridge 1.0
"{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
"{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BB406CEB-6207-4512-9BB2-89950DC9D6B6}_is1" = ConvertXtoDVD 2.1.14.223
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BC5484A4-33AF-457B-9EAE-E65E3561DCFD}" = Macrium Reflect - Free Edition
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1212AE3-DBB9-4365-8473-F8ABC7B06BBB}" = Pinnacle Instant DVD Recorder
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C9E4932C-8417-4E4C-A0E3-EE534810AB4D}" = ClearType Tuning Control Panel Applet
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC15A5FC-B6D3-4A2D-8A26-D8F2702A3C00}" = UltraMon
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D041EB9E-890A-4098-8F94-51DA194AC72A}" = Pinnacle Studio 12
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D1860E6E-520E-4380-8433-E58E8F88B473}" = Pinnacle Studio 12 Ultimate Plugins
"{D29FBBC1-5DA2-47AC-83CB-C234292F0C50}" = LGDownload Version 1.6
"{DD1865F0-AD73-40FB-B23E-1822E02396FF}" = NVIDIA PhysX
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E2B64929-B616-4235-B10E-D26D686296F9}" = GiPo@FileUtilities 3.2
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{E9CFBE78-ED91-4FCF-9E6F-210E477E527D}" = NVIDIA System Monitor
"{EC2A8F27-4FBF-4E41-B27B-FE822511B761}" = iTunes
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1CBC6F7-D82D-4DC5-B81C-9A14F418593A}_is1" = WC3Banlist
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FA17A726-B229-4116-B793-A2AB1A4EAE2E}" = Adobe Premiere Pro 2.0
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1" = BitPim 0.9.10
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup
"15b35190-c6f9-11d9-9669-0800200c9a66_is1" = DUNGEONS & DRAGONS ONLINE™: Stormreach™ v01.08.00.8106
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Premiere Pro 2.0" = Adobe Premiere Pro 2.0
"Adobe_3dcb365ab9e01871fb8c6f27b0ea079" = Adobe After Effects CS4
"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"AIM_6" = AIM 6
"AnyDVD" = AnyDVD
"Audacity_is1" = Audacity 1.2.6
"avast!" = avast! Antivirus
"CCleaner" = CCleaner (remove only)
"CobBackup9" = Cobian Backup 9
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"ERUNT_is1" = ERUNT 1.1j
"Gadwin PrintScreen" = Gadwin PrintScreen
"Garena" = Garena
"Hamachi" = Hamachi 1.0.2.5
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"INI_FCFG_V03.14A05_is1" = INI_FCFG_V03.14A05
"InstallShield_{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD Ultra
"InstallShield_{6F69C969-2942-4E7B-B594-75B37664B8BA}" = NVIDIA System Update
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"InstallShield_{C4E2A4A7-B623-40CB-8EEA-72F577E49D56}" = Vampire - The Masquerade Bloodlines
"InstallShield_{E9CFBE78-ED91-4FCF-9E6F-210E477E527D}" = NVIDIA System Monitor
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.7.0 (Full)
"LG USB Drivers" = LG USB Drivers
"Magic Bullet Looks Studio" = Magic Bullet Looks Studio
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.3)" = Mozilla Firefox (3.5.3)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PE Builder_is1" = PE Builder 3.1.10a
"PeerGuardian_is1" = PeerGuardian 2.0
"PhotomatixPro3Betax32_is1" = Photomatix Pro version 3.2
"PowerISO" = PowerISO
"proDAD-Vitascene-1.0" = proDAD Vitascene 1.0
"RivaTuner" = RivaTuner v2.0 Final Release
"Smart Defrag_is1" = Smart Defrag 1.20
"Soulseek" = SoulSeek Client 156c
"SpywareBlaster_is1" = SpywareBlaster 4.2
"stax-Pinnacle_is1" = SureThing Express Labeler
"Steam App 215" = Source SDK Base
"Steam App 218" = Source SDK Base - Orange Box
"Steam App 440" = Team Fortress 2
"Steam App 500" = Left 4 Dead
"SystemRequirementsLab" = System Requirements Lab
"Trapcode Starglow" = Trapcode Starglow
"Tweak UI 2.10" = Tweak UI
"ViewpointMediaPlayer" = Viewpoint Media Player
"Winamp" = Winamp
"Windows Essentials Media Codec Pack" = Windows Essentials Media Codec Pack 2.3
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"FileZilla Client" = FileZilla Client 3.2.7.1
"Flux" = F.lux
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/15/2009 7:21:05 AM | Computer Name = ANDYS | Source = nview_info | ID = 11141121
Description =

Error - 9/15/2009 7:21:08 AM | Computer Name = ANDYS | Source = nview_info | ID = 11141121
Description =

Error - 9/15/2009 7:40:24 AM | Computer Name = ANDYS | Source = nview_info | ID = 11141121
Description =

Error - 9/15/2009 9:10:34 AM | Computer Name = ANDYS | Source = Application Error | ID = 1000
Description = Faulting application mbam.exe, version 1.41.0.0, faulting module unknown,
version 0.0.0.0, fault address 0x10078920.

Error - 9/15/2009 9:10:34 AM | Computer Name = ANDYS | Source = Application Error | ID = 1000
Description = Faulting application rthdcpl.exe, version 2.1.2.0, faulting module
unknown, version 0.0.0.0, fault address 0x10078920.

Error - 9/15/2009 9:10:35 AM | Computer Name = ANDYS | Source = Microsoft IntelliPoint | ID = 1000
Description =

Error - 9/16/2009 1:09:12 AM | Computer Name = ANDYS | Source = Application Error | ID = 1000
Description = Faulting application spybotsd.exe, version 1.6.2.46, faulting module
spybotsd.exe, version 1.6.2.46, fault address 0x000049ee.

Error - 9/16/2009 1:10:07 AM | Computer Name = ANDYS | Source = Application Error | ID = 1000
Description = Faulting application spybotsd.exe, version 1.6.2.46, faulting module
unknown, version 0.0.0.0, fault address 0x71356800.

Error - 9/16/2009 1:49:33 AM | Computer Name = ANDYS | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 800706BF from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 9/18/2009 8:20:51 PM | Computer Name = ANDYS | Source = Application Error | ID = 1000
Description = Faulting application spybotsd.exe, version 1.6.2.46, faulting module
spybotsd.exe, version 1.6.2.46, fault address 0x000049ee.

[ System Events ]
Error - 9/18/2009 9:51:55 PM | Computer Name = ANDYS | Source = nvgts | ID = 262149
Description = A parity error was detected on \Device\Scsi\nvgts1.

Error - 9/18/2009 9:51:55 PM | Computer Name = ANDYS | Source = nvgts | ID = 262149
Description = A parity error was detected on \Device\Scsi\nvgts1.

Error - 9/18/2009 9:51:55 PM | Computer Name = ANDYS | Source = nvgts | ID = 262149
Description = A parity error was detected on \Device\Scsi\nvgts1.

Error - 9/18/2009 9:51:55 PM | Computer Name = ANDYS | Source = nvgts | ID = 262149
Description = A parity error was detected on \Device\Scsi\nvgts1.

Error - 9/18/2009 9:51:55 PM | Computer Name = ANDYS | Source = nvgts | ID = 262149
Description = A parity error was detected on \Device\Scsi\nvgts1.

Error - 9/18/2009 9:51:55 PM | Computer Name = ANDYS | Source = nvgts | ID = 262149
Description = A parity error was detected on \Device\Scsi\nvgts1.

Error - 9/18/2009 9:51:55 PM | Computer Name = ANDYS | Source = nvgts | ID = 262149
Description = A parity error was detected on \Device\Scsi\nvgts1.

Error - 9/18/2009 10:00:00 PM | Computer Name = ANDYS | Source = Schedule | ID = 7901
Description = The At23.job command failed to start due to the following error: %%2147942402

Error - 9/18/2009 10:00:00 PM | Computer Name = ANDYS | Source = Schedule | ID = 7901
Description = The At47.job command failed to start due to the following error: %%2147942402

Error - 9/18/2009 10:00:00 PM | Computer Name = ANDYS | Source = Schedule | ID = 7901
Description = The At71.job command failed to start due to the following error: %%2147942402


< End of report >

#2 heir

  • Group: Malware Removal
  • Posts: 5,427
  • Joined: 19-February 08

Posted 19 September 2009 - 03:18 AM

Hello theweauction !

Welcome to the site! :) My nickname is heir and I'll be helping clean up your computer. :)

Before we proceed to clean your computer from malware, let's go over some points that will help both me and you, and prevent causing damage to your computer:
  • To make sure that you receive an email when I reply to this topic, please click here and check that this topic is listed under Malware Removal and Spyware Removal.
  • Please don't be afraid to ask questions! No question is considered dumb here. It's better to be safe than sorry!
  • When posting logs, please ensure Wordwrap is turned off in Notepad (to check, open Notepad in the menubar click on Format and make sure that Word Wrap is unchecked)
  • Please follow the steps exactly in the same order posted. If you can't perform a certain step, or you're unsure on what to do, please stop and let me know.
  • NEVER fix anything in HijackThis or other programs on your own! This can be very dangerous and cause harm to your system. If you see a certain entry or program you're unsure about, please don't hesitate to ask!
  • Make sure you reply to this thread using the Add Reply button: Posted Image


Please read my posts completely before following the instructions.
It may be easier for you if you copy and paste a post to a new text document or print it for reference later.
This is required when you won't have access to Internet.

Step 1.
MBAM:

Please download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Step 2.
Lop S&D:

Disable resident protections (Antivirus...); you'll re-enable them after the scan

Download Lop S&D < here and save it to the desktop

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)

Step 3.
Things I would like to see in your reply:

  • The content of the report from MBAM in step 1.
  • The content of C:\lopR.txt from step 2.


#3 theweauction

  • Group: Member
  • Posts: 3
  • Joined: 18-September 09

Posted 19 September 2009 - 07:26 PM

Malwarebytes' Anti-Malware 1.41
Database version: 2798
Windows 5.1.2600 Service Pack 3

9/19/2009 9:18:42 PM
mbam-log-2009-09-19 (21-18-42).txt

Scan type: Quick Scan
Objects scanned: 97568
Time elapsed: 3 minute(s), 59 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)






--------------------\\ Lop S&D 4.2.5-0 XP/Vista


"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( Sat 09/19/2009|21:22 )

--------------------\\ Listing folders in APPLIC~1

[04/22/2008|04:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Grisoft
[09/15/2009|12:38] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Microsoft

[09/14/2009|07:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> {755AC846-7372-4AC8-8550-C52491DAA8BD}
[06/15/2009|05:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> 2DBoy
[08/23/2002|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> acccore
[12/01/2007|08:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Acronis
[08/22/2009|11:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe
[05/09/2008|01:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe Systems
[08/23/2002|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> AOL
[12/02/2007|09:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> AOL OCP
[12/09/2007|08:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple
[12/09/2007|08:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple Computer
[09/15/2009|01:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> avg8
[09/15/2009|12:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Avira
[12/04/2007|08:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> CyberLink
[06/22/2009|09:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> DVD Shrink
[08/22/2009|07:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> FLEXnet
[05/25/2008|06:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Grisoft
[08/18/2008|04:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Lavasoft
[12/10/2007|11:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> LogiShrd
[12/10/2007|11:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Logitech
[03/20/2009|08:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Macrium
[01/11/2009|09:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Malwarebytes
[12/01/2007|10:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Maxtor
[04/19/2009|07:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft
[04/06/2009|01:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Minnetonka Audio Software
[12/14/2007|01:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> nView_Profiles
[09/15/2009|01:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> ParetoLogic
[09/15/2009|12:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> ParetoLogic Anti-Virus PLUS
[04/16/2009|11:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Pinnacle
[04/16/2009|11:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Pinnacle Studio Plus
[03/25/2009|05:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Pinnacle Studio Ultimate
[06/26/2009|10:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> PopCap Games
[10/04/2008|05:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> ranczcly
[03/26/2009|11:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Realtime Soft
[03/25/2009|05:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Skype
[04/20/2008|08:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> SlySoft
[09/17/2009|06:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Spybot - Search & Destroy
[04/16/2009|11:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Studio 12
[09/15/2009|12:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> SUPERAntiSpyware.com
[09/19/2009|09:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> TEMP
[01/05/2008|02:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Trymedia
[08/23/2002|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Viewpoint
[11/29/2007|09:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage

[12/02/2007|09:54] C:\DOCUME~1\Andy\APPLIC~1\<DIR> acccore
[08/23/2009|07:00] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Adobe
[10/01/2008|11:23] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Ahead
[12/02/2007|12:24] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Aim
[09/14/2009|07:38] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Apple Computer
[01/11/2009|08:00] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Audacity
[09/17/2009|10:04] C:\DOCUME~1\Andy\APPLIC~1\<DIR> AVG8
[12/29/2007|11:26] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Bioshock
[05/05/2009|04:59] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Braid
[03/05/2008|11:47] C:\DOCUME~1\Andy\APPLIC~1\<DIR> BSplayer PRO
[05/05/2009|01:46] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Crayon Physics Deluxe
[12/04/2007|08:41] C:\DOCUME~1\Andy\APPLIC~1\<DIR> CyberLink
[05/09/2008|12:55] C:\DOCUME~1\Andy\APPLIC~1\<DIR> DAEMON Tools
[04/16/2009|11:55] C:\DOCUME~1\Andy\APPLIC~1\<DIR> DivX
[06/12/2009|03:22] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Download Manager
[05/02/2009|02:07] C:\DOCUME~1\Andy\APPLIC~1\<DIR> DVD Shrink
[08/24/2009|09:53] C:\DOCUME~1\Andy\APPLIC~1\<DIR> FileZilla
[09/02/2009|12:37] C:\DOCUME~1\Andy\APPLIC~1\<DIR> GetRightToGo
[04/18/2008|02:31] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Hamachi
[09/11/2009|12:30] C:\DOCUME~1\Andy\APPLIC~1\<DIR> HDRsoft
[11/29/2007|07:32] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Identities
[12/10/2007|11:08] C:\DOCUME~1\Andy\APPLIC~1\<DIR> InstallShield
[04/26/2009|09:27] C:\DOCUME~1\Andy\APPLIC~1\<DIR> IObit
[11/14/2008|03:06] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Leadertech
[12/10/2007|11:11] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Logitech
[11/29/2007|08:23] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Macromedia
[01/11/2009|09:02] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Malwarebytes
[11/30/2007|03:28] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Media Player Classic
[09/15/2009|12:38] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Microsoft
[12/01/2008|01:03] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Move Networks
[09/02/2009|01:04] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Mozilla
[02/17/2009|01:01] C:\DOCUME~1\Andy\APPLIC~1\<DIR> OpenOffice.org
[04/17/2009|12:19] C:\DOCUME~1\Andy\APPLIC~1\<DIR> proDAD
[03/26/2009|11:15] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Realtime Soft
[12/12/2007|06:27] C:\DOCUME~1\Andy\APPLIC~1\<DIR> SecuROM
[07/01/2009|08:13] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Skype
[12/07/2007|02:53] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Sun
[09/15/2009|12:22] C:\DOCUME~1\Andy\APPLIC~1\<DIR> SUPERAntiSpyware.com
[03/13/2009|11:55] C:\DOCUME~1\Andy\APPLIC~1\<DIR> SystemRequirementsLab
[09/02/2009|12:46] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Turbine
[07/05/2009|09:51] C:\DOCUME~1\Andy\APPLIC~1\<DIR> U3
[05/03/2009|10:10] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Ventrilo
[12/18/2007|01:48] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Viewpoint
[08/18/2009|03:08] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Vso
[08/18/2009|03:34] C:\DOCUME~1\Andy\APPLIC~1\<DIR> Winamp
[12/03/2007|05:21] C:\DOCUME~1\Andy\APPLIC~1\<DIR> WinRAR
[03/28/2009|04:27] C:\DOCUME~1\Andy\APPLIC~1\<DIR> XRay Engine

[04/22/2008|05:07] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> DivX
[12/04/2007|10:07] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft

[09/15/2009|12:38] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft

[08/17/2008|02:48] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Macromedia
[09/15/2009|12:38] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft

--------------------\\ Scheduled Tasks located in C:\windows\Tasks

[09/17/2009 06:37 PM][--a------] C:\windows\tasks\ParetoLogic Registration.job
[09/14/2009 02:29 AM][--a------] C:\windows\tasks\SmartDefrag.job
[09/17/2009 09:57 PM][--a------] C:\windows\tasks\AppleSoftwareUpdate.job
[09/18/2009 11:00 PM][--a------] C:\windows\tasks\At48.job
[09/18/2009 09:00 PM][--a------] C:\windows\tasks\At46.job
[09/17/2009 08:00 PM][--a------] C:\windows\tasks\At45.job
[09/17/2009 07:00 PM][--a------] C:\windows\tasks\At44.job
[09/18/2009 10:00 PM][--a------] C:\windows\tasks\At47.job
[09/17/2009 06:00 PM][--a------] C:\windows\tasks\At43.job
[09/17/2009 05:00 PM][--a------] C:\windows\tasks\At42.job
[09/17/2009 04:00 PM][--a------] C:\windows\tasks\At41.job
[09/17/2009 12:00 PM][--a------] C:\windows\tasks\At37.job
[09/17/2009 02:00 PM][--a------] C:\windows\tasks\At39.job
[09/17/2009 03:00 PM][--a------] C:\windows\tasks\At40.job
[09/17/2009 01:00 PM][--a------] C:\windows\tasks\At38.job
[09/19/2009 09:00 AM][--a------] C:\windows\tasks\At34.job
[09/17/2009 11:00 AM][--a------] C:\windows\tasks\At36.job
[09/19/2009 10:00 AM][--a------] C:\windows\tasks\At35.job
[09/19/2009 08:00 AM][--a------] C:\windows\tasks\At33.job
[09/19/2009 07:00 AM][--a------] C:\windows\tasks\At32.job
[09/17/2009 06:00 AM][--a------] C:\windows\tasks\At31.job
[09/17/2009 05:00 AM][--a------] C:\windows\tasks\At30.job
[09/17/2009 02:00 AM][--a------] C:\windows\tasks\At27.job
[09/18/2009 03:00 AM][--a------] C:\windows\tasks\At28.job
[09/17/2009 04:00 AM][--a------] C:\windows\tasks\At29.job
[09/19/2009 12:33 AM][--a------] C:\windows\tasks\At25.job
[09/16/2009 01:00 AM][--a------] C:\windows\tasks\At26.job
[09/18/2009 11:00 PM][--a------] C:\windows\tasks\At24.job
[09/18/2009 09:00 PM][--a------] C:\windows\tasks\At22.job
[09/17/2009 08:00 PM][--a------] C:\windows\tasks\At21.job
[09/18/2009 10:00 PM][--a------] C:\windows\tasks\At23.job
[09/17/2009 06:00 PM][--a------] C:\windows\tasks\At19.job
[09/17/2009 05:00 PM][--a------] C:\windows\tasks\At18.job
[09/17/2009 07:00 PM][--a------] C:\windows\tasks\At20.job
[09/17/2009 04:00 PM][--a------] C:\windows\tasks\At17.job
[09/17/2009 02:00 PM][--a------] C:\windows\tasks\At15.job
[09/17/2009 03:00 PM][--a------] C:\windows\tasks\At16.job
[09/17/2009 01:00 PM][--a------] C:\windows\tasks\At14.job
[09/17/2009 12:00 PM][--a------] C:\windows\tasks\At13.job
[09/17/2009 11:00 AM][--a------] C:\windows\tasks\At12.job
[09/19/2009 10:00 AM][--a------] C:\windows\tasks\At11.job
[09/19/2009 09:00 AM][--a------] C:\windows\tasks\At10.job
[09/17/2009 05:00 AM][--a------] C:\windows\tasks\At6.job
[09/17/2009 06:00 AM][--a------] C:\windows\tasks\At7.job
[09/19/2009 07:00 AM][--a------] C:\windows\tasks\At8.job
[09/19/2009 08:00 AM][--a------] C:\windows\tasks\At9.job
[09/17/2009 04:00 AM][--a------] C:\windows\tasks\At5.job
[09/18/2009 03:00 AM][--a------] C:\windows\tasks\At4.job
[09/17/2009 02:00 AM][--a------] C:\windows\tasks\At3.job
[09/16/2009 01:00 AM][--a------] C:\windows\tasks\At2.job
[09/19/2009 12:25 AM][--a------] C:\windows\tasks\At1.job
[09/19/2009 09:13 PM][--ah-----] C:\windows\tasks\SA.DAT
[08/18/2001 08:00 AM][-rah-----] C:\windows\tasks\desktop.ini
[09/18/2009 11:00 PM][--a------] C:\windows\tasks\At72.job
[09/18/2009 10:00 PM][--a------] C:\windows\tasks\At71.job
[09/18/2009 09:00 PM][--a------] C:\windows\tasks\At70.job
[09/17/2009 07:00 PM][--a------] C:\windows\tasks\At68.job
[09/17/2009 08:00 PM][--a------] C:\windows\tasks\At69.job
[09/17/2009 06:00 PM][--a------] C:\windows\tasks\At67.job
[09/17/2009 05:00 PM][--a------] C:\windows\tasks\At66.job
[09/17/2009 04:00 PM][--a------] C:\windows\tasks\At65.job
[09/17/2009 03:00 PM][--a------] C:\windows\tasks\At64.job
[09/17/2009 01:00 PM][--a------] C:\windows\tasks\At62.job
[09/17/2009 12:00 PM][--a------] C:\windows\tasks\At61.job
[09/17/2009 02:00 PM][--a------] C:\windows\tasks\At63.job
[09/17/2009 11:00 AM][--a------] C:\windows\tasks\At60.job
[09/19/2009 09:00 AM][--a------] C:\windows\tasks\At58.job
[09/19/2009 10:00 AM][--a------] C:\windows\tasks\At59.job
[09/19/2009 07:00 AM][--a------] C:\windows\tasks\At56.job
[09/19/2009 08:00 AM][--a------] C:\windows\tasks\At57.job
[09/17/2009 05:00 AM][--a------] C:\windows\tasks\At54.job
[09/17/2009 06:00 AM][--a------] C:\windows\tasks\At55.job
[09/17/2009 04:00 AM][--a------] C:\windows\tasks\At53.job
[09/18/2009 03:00 AM][--a------] C:\windows\tasks\At52.job
[09/17/2009 02:00 AM][--a------] C:\windows\tasks\At51.job
[09/19/2009 12:39 AM][--a------] C:\windows\tasks\At49.job
[09/16/2009 01:00 AM][--a------] C:\windows\tasks\At50.job

--------------------\\ Listing Folders in C:\Program Files

[08/22/2009|06:41] C:\Program Files\<DIR> Adobe
[08/22/2009|06:38] C:\Program Files\<DIR> Adobe Media Player
[02/23/2009|02:52] C:\Program Files\<DIR> AGEIA Technologies
[05/02/2009|02:07] C:\Program Files\<DIR> AIM6
[09/15/2009|01:02] C:\Program Files\<DIR> Alwil Software
[12/26/2008|02:00] C:\Program Files\<DIR> Apple Software Update
[01/11/2009|08:34] C:\Program Files\<DIR> Audacity
[09/15/2009|01:40] C:\Program Files\<DIR> AVG
[09/15/2009|01:50] C:\Program Files\<DIR> BitComet
[01/11/2009|08:01] C:\Program Files\<DIR> BitPim
[09/14/2009|07:14] C:\Program Files\<DIR> Bonjour
[04/17/2009|12:18] C:\Program Files\<DIR> Boris FX, Inc
[04/28/2009|11:51] C:\Program Files\<DIR> CCleaner
[09/14/2009|10:04] C:\Program Files\<DIR> Cobian Backup 9
[09/15/2009|12:09] C:\Program Files\<DIR> Common Files
[11/29/2007|07:26] C:\Program Files\<DIR> ComPlus Applications
[08/22/2009|12:17] C:\Program Files\<DIR> Crayon Physics Deluxe
[07/28/2009|05:44] C:\Program Files\<DIR> CyberLink
[08/22/2002|09:13] C:\Program Files\<DIR> DAEMON Tools Lite
[09/24/2008|12:02] C:\Program Files\<DIR> Deep Silver
[09/18/2009|08:56] C:\Program Files\<DIR> Diablo II
[12/11/2007|02:39] C:\Program Files\<DIR> DivX
[02/19/2008|01:39] C:\Program Files\<DIR> Dofus
[12/07/2007|08:38] C:\Program Files\<DIR> DVD Decrypter
[12/09/2007|08:26] C:\Program Files\<DIR> DVD Shrink
[09/18/2009|09:39] C:\Program Files\<DIR> ERUNT
[04/14/2009|01:44] C:\Program Files\<DIR> Essentials Codec Pack
[08/24/2009|09:41] C:\Program Files\<DIR> FileZilla FTP Client
[02/01/2008|08:32] C:\Program Files\<DIR> Gadwin Systems
[09/14/2009|02:46] C:\Program Files\<DIR> Garena
[03/21/2009|12:20] C:\Program Files\<DIR> GiPo@Utilities
[04/23/2008|06:58] C:\Program Files\<DIR> Grisoft
[04/10/2008|12:08] C:\Program Files\<DIR> Hamachi
[07/28/2009|03:41] C:\Program Files\<DIR> Hewlett-Packard
[02/23/2009|07:02] C:\Program Files\<DIR> HotSwap!
[07/15/2009|10:53] C:\Program Files\<DIR> HP
[02/20/2009|07:39] C:\Program Files\<DIR> initio
[07/28/2009|05:44] C:\Program Files\<DIR> InstallShield Installation Information
[07/30/2009|11:26] C:\Program Files\<DIR> Internet Explorer
[04/25/2009|08:43] C:\Program Files\<DIR> IObit
[09/14/2009|07:15] C:\Program Files\<DIR> iPod
[09/14/2009|07:16] C:\Program Files\<DIR> iTunes
[09/15/2009|12:18] C:\Program Files\<DIR> Java
[07/27/2009|05:24] C:\Program Files\<DIR> JRE
[05/02/2009|02:07] C:\Program Files\<DIR> K-Lite Codec Pack
[08/26/2008|08:36] C:\Program Files\<DIR> Lavasoft
[01/11/2009|08:02] C:\Program Files\<DIR> LG Drivers
[12/10/2007|11:08] C:\Program Files\<DIR> Logitech
[04/17/2009|12:19] C:\Program Files\<DIR> LooksBuilderSE
[03/20/2009|08:29] C:\Program Files\<DIR> Macrium
[09/15/2009|02:04] C:\Program Files\<DIR> Malwarebytes' Anti-Malware
[11/29/2007|08:03] C:\Program Files\<DIR> Maxtor
[08/14/2008|05:11] C:\Program Files\<DIR> Messenger
[11/29/2007|07:28] C:\Program Files\<DIR> microsoft frontpage
[11/29/2007|09:23] C:\Program Files\<DIR> Microsoft IntelliPoint
[05/25/2008|07:02] C:\Program Files\<DIR> Movie Maker
[09/19/2009|09:15] C:\Program Files\<DIR> Mozilla Firefox
[02/23/2009|02:14] C:\Program Files\<DIR> MSBuild
[11/29/2007|07:25] C:\Program Files\<DIR> MSN
[11/29/2007|07:25] C:\Program Files\<DIR> MSN Gaming Zone
[01/04/2008|10:02] C:\Program Files\<DIR> MSXML 4.0
[11/29/2007|09:23] C:\Program Files\<DIR> MSXML 6.0
[02/22/2009|05:42] C:\Program Files\<DIR> NavNet
[12/10/2007|03:33] C:\Program Files\<DIR> Nero
[09/14/2009|10:16] C:\Program Files\<DIR> NetMeeting
[04/24/2008|07:11] C:\Program Files\<DIR> NVIDIA Corporation
[12/07/2007|04:04] C:\Program Files\<DIR> NVIDIA nTune Performance Application
[11/29/2007|07:25] C:\Program Files\<DIR> Online Services
[07/27/2009|05:24] C:\Program Files\<DIR> OpenOffice.org 3
[09/14/2009|10:18] C:\Program Files\<DIR> Outlook Express
[09/13/2009|07:30] C:\Program Files\<DIR> PeerGuardian2
[09/16/2009|03:17] C:\Program Files\<DIR> PhotomatixPro3
[04/17/2009|12:16] C:\Program Files\<DIR> Pinnacle
[11/06/2008|06:48] C:\Program Files\<DIR> PowerISO
[04/17/2009|12:19] C:\Program Files\<DIR> proDAD
[09/14/2009|07:14] C:\Program Files\<DIR> QuickTime
[04/01/2009|10:13] C:\Program Files\<DIR> Rapid Backup
[04/23/2008|08:40] C:\Program Files\<DIR> Realtek
[02/23/2009|02:13] C:\Program Files\<DIR> Reference Assemblies
[06/26/2009|10:33] C:\Program Files\<DIR> ReflexiveArcade
[01/09/2008|05:16] C:\Program Files\<DIR> RivaTuner v2.0 Final Release
[02/05/2009|06:11] C:\Program Files\<DIR> Seagate
[03/25/2009|09:08] C:\Program Files\<DIR> Skype
[03/10/2009|01:48] C:\Program Files\<DIR> SlySoft
[03/30/2008|03:46] C:\Program Files\<DIR> Soulseek
[09/16/2009|01:46] C:\Program Files\<DIR> Spybot - Search & Destroy
[09/15/2009|02:04] C:\Program Files\<DIR> SpywareBlaster
[08/26/2009|12:39] C:\Program Files\<DIR> Steam
[09/18/2009|08:43] C:\Program Files\<DIR> SUPERAntiSpyware
[04/22/2009|06:58] C:\Program Files\<DIR> SureThing Express Labeler
[03/13/2009|11:55] C:\Program Files\<DIR> SystemRequirementsLab
[09/02/2009|12:28] C:\Program Files\<DIR> Turbine
[09/14/2009|10:23] C:\Program Files\<DIR> UltraMon
[11/29/2007|07:32] C:\Program Files\<DIR> Uninstall Information
[01/21/2008|11:12] C:\Program Files\<DIR> Ventrilo
[12/02/2007|09:52] C:\Program Files\<DIR> Viewpoint
[05/02/2009|02:07] C:\Program Files\<DIR> Virtual VCR
[12/18/2007|10:44] C:\Program Files\<DIR> vso
[09/19/2009|01:11] C:\Program Files\<DIR> Warcraft III
[05/05/2008|09:07] C:\Program Files\<DIR> WC3Banlist
[01/30/2008|02:59] C:\Program Files\<DIR> Webteh
[11/30/2007|03:18] C:\Program Files\<DIR> Winamp
[07/26/2009|06:28] C:\Program Files\<DIR> Windows Live SkyDrive
[09/15/2009|03:19] C:\Program Files\<DIR> Windows Media Connect 2
[09/15/2009|03:19] C:\Program Files\<DIR> Windows Media Player
[05/25/2008|07:01] C:\Program Files\<DIR> Windows NT
[04/22/2008|10:32] C:\Program Files\<DIR> WindowsUpdate
[02/26/2009|08:01] C:\Program Files\<DIR> WinPcap
[09/16/2009|03:17] C:\Program Files\<DIR> WinRAR
[09/14/2009|10:24] C:\Program Files\<DIR> WMPCI54G WLAN Monitor
[11/29/2007|07:28] C:\Program Files\<DIR> xerox
[10/04/2008|05:48] C:\Program Files\<DIR> xsbbbfg
[12/10/2007|03:31] C:\Program Files\<DIR> Yahoo!
[08/22/2009|12:12] C:\Program Files\<DIR> Zombie Shooter

--------------------\\ Listing Folders in C:\Program Files\Common Files

[08/22/2009|06:40] C:\Program Files\Common Files\<DIR> Adobe
[08/22/2009|06:36] C:\Program Files\Common Files\<DIR> Adobe AIR
[05/09/2008|01:17] C:\Program Files\Common Files\<DIR> Adobe Systems Shared
[12/10/2007|03:38] C:\Program Files\Common Files\<DIR> Ahead
[12/02/2007|09:52] C:\Program Files\Common Files\<DIR> AOL
[09/14/2009|07:15] C:\Program Files\Common Files\<DIR> Apple
[09/14/2009|09:27] C:\Program Files\Common Files\<DIR> Blizzard Entertainment
[06/08/2008|10:54] C:\Program Files\Common Files\<DIR> Canon
[12/12/2007|06:19] C:\Program Files\Common Files\<DIR> DirectX
[03/21/2009|12:20] C:\Program Files\Common Files\<DIR> Gibinsoft Shared
[12/02/2007|08:55] C:\Program Files\Common Files\<DIR> InstallShield
[12/07/2007|02:50] C:\Program Files\Common Files\<DIR> Java
[12/10/2007|11:09] C:\Program Files\Common Files\<DIR> Logishrd
[05/12/2008|09:04] C:\Program Files\Common Files\<DIR> Macrovision Shared
[11/29/2007|08:03] C:\Program Files\Common Files\<DIR> Maxtor
[11/30/2007|04:35] C:\Program Files\Common Files\<DIR> Microsoft Shared
[11/29/2007|07:26] C:\Program Files\Common Files\<DIR> MSSoap
[11/30/2007|03:24] C:\Program Files\Common Files\<DIR> ODBC
[09/15/2009|01:49] C:\Program Files\Common Files\<DIR> ParetoLogic
[04/16/2009|11:35] C:\Program Files\Common Files\<DIR> Pegasus Imaging
[04/16/2009|11:40] C:\Program Files\Common Files\<DIR> Pinnacle
[03/26/2009|11:15] C:\Program Files\Common Files\<DIR> Realtime Soft
[11/29/2007|07:26] C:\Program Files\Common Files\<DIR> Services
[11/30/2007|03:24] C:\Program Files\Common Files\<DIR> SpeechEngines
[04/16/2009|10:55] C:\Program Files\Common Files\<DIR> SureThing Shared
[05/25/2008|07:01] C:\Program Files\Common Files\<DIR> System
[09/15/2009|12:22] C:\Program Files\Common Files\<DIR> Wise Installation Wizard
[04/16/2009|11:35] C:\Program Files\Common Files\<DIR> Yahoo!

--------------------\\ Process

( 52 Processes )

... OK !

--------------------\\ Searching with S_Lop

No Lop folder found !

--------------------\\ Searching for Lop Files - Folders

No Lop folder found !

--------------------\\ Searching within the Registry

..... OK !

--------------------\\ Checking the Hosts file

Hosts file CLEAN


--------------------\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-19 21:23:25
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Searching for other infections

C:\windows\Tasks\At1.job
C:\windows\Tasks\At10.job
C:\windows\Tasks\At11.job
C:\windows\Tasks\At12.job
C:\windows\Tasks\At13.job
C:\windows\Tasks\At14.job
C:\windows\Tasks\At15.job
C:\windows\Tasks\At16.job
C:\windows\Tasks\At17.job
C:\windows\Tasks\At18.job
C:\windows\Tasks\At19.job
C:\windows\Tasks\At2.job
C:\windows\Tasks\At20.job
C:\windows\Tasks\At21.job
C:\windows\Tasks\At22.job
C:\windows\Tasks\At23.job
C:\windows\Tasks\At24.job
C:\windows\Tasks\At25.job
C:\windows\Tasks\At26.job
C:\windows\Tasks\At27.job
C:\windows\Tasks\At28.job
C:\windows\Tasks\At29.job
C:\windows\Tasks\At3.job
C:\windows\Tasks\At30.job
C:\windows\Tasks\At31.job
C:\windows\Tasks\At32.job
C:\windows\Tasks\At33.job
C:\windows\Tasks\At34.job
C:\windows\Tasks\At35.job
C:\windows\Tasks\At36.job
C:\windows\Tasks\At37.job
C:\windows\Tasks\At38.job
C:\windows\Tasks\At39.job
C:\windows\Tasks\At4.job
C:\windows\Tasks\At40.job
C:\windows\Tasks\At41.job
C:\windows\Tasks\At42.job
C:\windows\Tasks\At43.job
C:\windows\Tasks\At44.job
C:\windows\Tasks\At45.job
C:\windows\Tasks\At46.job
C:\windows\Tasks\At47.job
C:\windows\Tasks\At48.job
C:\windows\Tasks\At49.job
C:\windows\Tasks\At5.job
C:\windows\Tasks\At50.job
C:\windows\Tasks\At51.job
C:\windows\Tasks\At52.job
C:\windows\Tasks\At53.job
C:\windows\Tasks\At54.job
C:\windows\Tasks\At55.job
C:\windows\Tasks\At56.job
C:\windows\Tasks\At57.job
C:\windows\Tasks\At58.job
C:\windows\Tasks\At59.job
C:\windows\Tasks\At6.job
C:\windows\Tasks\At60.job
C:\windows\Tasks\At61.job
C:\windows\Tasks\At62.job
C:\windows\Tasks\At63.job
C:\windows\Tasks\At64.job
C:\windows\Tasks\At65.job
C:\windows\Tasks\At66.job
C:\windows\Tasks\At67.job
C:\windows\Tasks\At68.job
C:\windows\Tasks\At69.job
C:\windows\Tasks\At7.job
C:\windows\Tasks\At70.job
C:\windows\Tasks\At71.job
C:\windows\Tasks\At72.job
C:\windows\Tasks\At8.job
C:\windows\Tasks\At9.job

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\Andy\My Documents\My Music\iTunes\iTunes Music\Mastodon\Crack the Skye
C:\DOCUME~1\Andy\My Documents\My Music\iTunes\iTunes Music\Mastodon\Crack the Skye\01 Oblivion.mp3
C:\DOCUME~1\Andy\My Documents\My Music\iTunes\iTunes Music\Mastodon\Crack the Skye\02 Divinations.mp3
C:\DOCUME~1\Andy\My Documents\My Music\iTunes\iTunes Music\Mastodon\Crack the Skye\03 Quintessence.mp3
C:\DOCUME~1\Andy\My Documents\My Music\iTunes\iTunes Music\Mastodon\Crack the Skye\04 The Czar.mp3
C:\DOCUME~1\Andy\My Documents\My Music\iTunes\iTunes Music\Mastodon\Crack the Skye\05 Ghost of Karelia.mp3
C:\DOCUME~1\Andy\My Documents\My Music\iTunes\iTunes Music\Mastodon\Crack the Skye\06 Crack the Skye.mp3
C:\DOCUME~1\Andy\My Documents\My Music\iTunes\iTunes Music\Mastodon\Crack the Skye\07 The Last Baron.mp3
C:\DOCUME~1\Andy\My Documents\My Music\iTunes\iTunes Music\Mastodon\Crack the Skye\08 Oblivion (Instrumental).mp3
C:\DOCUME~1\Andy\My Documents\My Music\iTunes\iTunes Music\Mastodon\Crack the Skye\09 Divinations (Instrumental).mp3
C:\DOCUME~1\Andy\My Documents\My Music\iTunes\iTunes Music\The Spinto Band\Nice And Nicely Done\06 Crack The Whip.mp3


[F:50][D:6]-> C:\DOCUME~1\Andy\LOCALS~1\Temp
[F:17][D:0]-> C:\DOCUME~1\Andy\Cookies
[F:24][D:4]-> C:\DOCUME~1\Andy\LOCALS~1\TEMPOR~1\content.IE5
[F:1][D:1]-> C:\$Recycle.Bin

1 - "C:\Lop SD\LopR_1.txt" - Sat 09/19/2009|21:24 - Option : [1]

--------------------\\ Scan completed at 21:24:57

#4 heir

  • Group: Malware Removal
  • Posts: 5,427
  • Joined: 19-February 08

Posted 20 September 2009 - 12:12 AM

Let's remove some then.

Step 1.
Uninstall unwanted software:

Please go to Start > Control Panel > Add/Remove Programs and remove the following (if present):

BitComet
SoulSeek Client 156c

Viewpoint Media Player


Optional removals
SoulSeek, BitComet and P2P programs in general are legal themselves, but much of the content downloaded with them is downloaded illegally. They are also a great way to infect yourself with malware.
It's up to you if you want to remove the above programs, however I recommend you do.


Step 2.
OTL-fix:

Run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - [2009/08/29 02:00:12 | 00,987,136 | ---- | M] () -- C:\Documents and Settings\Andy\Local Settings\Apps\F.lux\flux.exe
    PRC - [2007/01/04 17:38:08 | 00,045,056 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe
    SRV - [2007/01/04 17:38:08 | 00,045,056 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service [Auto | Running])
    O2 - BHO: (no name) - {0B8D6118-C605-47B8-9159-466CB1AA1099} - No CLSID value found.
    O2 - BHO: (no name) - {20655162-E6A5-4A48-8846-11218FAAF943} - No CLSID value found.
    O2 - BHO: (no name) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - No CLSID value found.
    O2 - BHO: (no name) - {F775DC26-396A-4FB7-8772-ACAFA76690F6} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
    O4 - HKCU..\Run: [F.lux] C:\Documents and Settings\Andy\Local Settings\Apps\F.lux\flux.exe ()
    O20 - AppInit_DLLs: (C:\WINDOWS\system32\hebedogu.dll) - C:\windows\System32\hebedogu.dll File not found
    O20 - AppInit_DLLs: (c:\windows\system32\huyerifi.dll) - C:\windows\System32\huyerifi.dll File not found
    O20 - AppInit_DLLs: (jcjmqp.dll) - File not found
    O20 - AppInit_DLLs: (dceuki.dll) - File not found
    O20 - AppInit_DLLs: (gayujoje.dll) - File not found
    O20 - AppInit_DLLs: (zotemiso.dll) - File not found
    O20 - Winlogon\Notify\hgGyyaAT: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
    O20 - Winlogon\Notify\pMDVllJy: DllName - pMDVllJy.dll - File not found
    O20 - Winlogon\Notify\ssqQgDsT: DllName - ssqQgDsT.dll - File not found
    O33 - MountPoints2\{01ca0571-351f-11de-b736-00044b0429b5}\Shell - "" = AutoRun
    O33 - MountPoints2\{01ca0571-351f-11de-b736-00044b0429b5}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{c78d1af6-53bd-11de-b75c-00044b0429b5}\Shell - "" = AutoRun
    O33 - MountPoints2\{c78d1af6-53bd-11de-b75c-00044b0429b5}\Shell\AutoRun - "" = Auto&Play
    [2002/08/23 22:45:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
    [2007/12/18 01:48:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Andy\Application Data\Viewpoint
    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Program Files\BitComet\BitComet.exe"=-
    "C:\Program Files\Soulseek\slsk.exe"=-
    :Files
    C:\windows\tasks\At*.job
    C:\Program Files\Viewpoint
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]


  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL fixlog


Step 3.
Things I would like to see in your reply:

  • Which P2P softwares were uninstalled in step 1.
  • The conten of the fixlog from OTL in step 2.
  • Information on how your computer is running now.


#5 theweauction

  • Group: Member
  • Posts: 3
  • Joined: 18-September 09

Posted 23 September 2009 - 06:22 PM

Sorry in the delay of posting.

Well I went in and unistalled soulseek and viewpoint, bitcomet was already uninstalled.
Here is the log:

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named flux.exe was found!
No active process named ViewpointService.exe was found!
Service\Driver Viewpoint Manager Service not found.
Service\Driver Viewpoint Manager Service not found.
File C:\Program Files\Viewpoint\Common\ViewpointService.exe not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0B8D6118-C605-47B8-9159-466CB1AA1099}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B8D6118-C605-47B8-9159-466CB1AA1099}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{20655162-E6A5-4A48-8846-11218FAAF943}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20655162-E6A5-4A48-8846-11218FAAF943}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F775DC26-396A-4FB7-8772-ACAFA76690F6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F775DC26-396A-4FB7-8772-ACAFA76690F6}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\F.lux deleted successfully.
C:\Documents and Settings\Andy\Local Settings\Apps\F.lux\flux.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\WINDOWS\system32\hebedogu.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\huyerifi.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:jcjmqp.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:dceuki.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:gayujoje.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:zotemiso.dll deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\hgGyyaAT\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pMDVllJy\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqQgDsT\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{01ca0571-351f-11de-b736-00044b0429b5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01ca0571-351f-11de-b736-00044b0429b5}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{01ca0571-351f-11de-b736-00044b0429b5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01ca0571-351f-11de-b736-00044b0429b5}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c78d1af6-53bd-11de-b75c-00044b0429b5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c78d1af6-53bd-11de-b75c-00044b0429b5}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c78d1af6-53bd-11de-b75c-00044b0429b5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c78d1af6-53bd-11de-b75c-00044b0429b5}\ not found.
C:\Documents and Settings\All Users\Application Data\Viewpoint moved successfully.
Folder C:\Documents and Settings\Andy\Application Data\Viewpoint\ not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\BitComet\BitComet.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Soulseek\slsk.exe deleted successfully.
========== FILES ==========
C:\windows\tasks\At1.job moved successfully.
C:\windows\tasks\At10.job moved successfully.
C:\windows\tasks\At11.job moved successfully.
C:\windows\tasks\At12.job moved successfully.
C:\windows\tasks\At13.job moved successfully.
C:\windows\tasks\At14.job moved successfully.
C:\windows\tasks\At15.job moved successfully.
C:\windows\tasks\At16.job moved successfully.
C:\windows\tasks\At17.job moved successfully.
C:\windows\tasks\At18.job moved successfully.
C:\windows\tasks\At19.job moved successfully.
C:\windows\tasks\At2.job moved successfully.
C:\windows\tasks\At20.job moved successfully.
C:\windows\tasks\At21.job moved successfully.
C:\windows\tasks\At22.job moved successfully.
C:\windows\tasks\At23.job moved successfully.
C:\windows\tasks\At24.job moved successfully.
C:\windows\tasks\At25.job moved successfully.
C:\windows\tasks\At26.job moved successfully.
C:\windows\tasks\At27.job moved successfully.
C:\windows\tasks\At28.job moved successfully.
C:\windows\tasks\At29.job moved successfully.
C:\windows\tasks\At3.job moved successfully.
C:\windows\tasks\At30.job moved successfully.
C:\windows\tasks\At31.job moved successfully.
C:\windows\tasks\At32.job moved successfully.
C:\windows\tasks\At33.job moved successfully.
C:\windows\tasks\At34.job moved successfully.
C:\windows\tasks\At35.job moved successfully.
C:\windows\tasks\At36.job moved successfully.
C:\windows\tasks\At37.job moved successfully.
C:\windows\tasks\At38.job moved successfully.
C:\windows\tasks\At39.job moved successfully.
C:\windows\tasks\At4.job moved successfully.
C:\windows\tasks\At40.job moved successfully.
C:\windows\tasks\At41.job moved successfully.
C:\windows\tasks\At42.job moved successfully.
C:\windows\tasks\At43.job moved successfully.
C:\windows\tasks\At44.job moved successfully.
C:\windows\tasks\At45.job moved successfully.
C:\windows\tasks\At46.job moved successfully.
C:\windows\tasks\At47.job moved successfully.
C:\windows\tasks\At48.job moved successfully.
C:\windows\tasks\At49.job moved successfully.
C:\windows\tasks\At5.job moved successfully.
C:\windows\tasks\At50.job moved successfully.
C:\windows\tasks\At51.job moved successfully.
C:\windows\tasks\At52.job moved successfully.
C:\windows\tasks\At53.job moved successfully.
C:\windows\tasks\At54.job moved successfully.
C:\windows\tasks\At55.job moved successfully.
C:\windows\tasks\At56.job moved successfully.
C:\windows\tasks\At57.job moved successfully.
C:\windows\tasks\At58.job moved successfully.
C:\windows\tasks\At59.job moved successfully.
C:\windows\tasks\At6.job moved successfully.
C:\windows\tasks\At60.job moved successfully.
C:\windows\tasks\At61.job moved successfully.
C:\windows\tasks\At62.job moved successfully.
C:\windows\tasks\At63.job moved successfully.
C:\windows\tasks\At64.job moved successfully.
C:\windows\tasks\At65.job moved successfully.
C:\windows\tasks\At66.job moved successfully.
C:\windows\tasks\At67.job moved successfully.
C:\windows\tasks\At68.job moved successfully.
C:\windows\tasks\At69.job moved successfully.
C:\windows\tasks\At7.job moved successfully.
C:\windows\tasks\At70.job moved successfully.
C:\windows\tasks\At71.job moved successfully.
C:\windows\tasks\At72.job moved successfully.
C:\windows\tasks\At8.job moved successfully.
C:\windows\tasks\At9.job moved successfully.
File\Folder C:\Program Files\Viewpoint not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Andy
->Temp folder emptied: 6976663 bytes
File delete failed. C:\Documents and Settings\Andy\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 679455 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 75710123 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
File delete failed. C:\windows\temp\_av_proI.tm~a04004\setup.lok scheduled to be deleted on reboot.
File delete failed. C:\windows\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\windows\temp\Perflib_Perfdata_6f8.dat scheduled to be deleted on reboot.
Windows Temp folder emptied: 155289 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 79.78 mb


OTL by OldTimer - Version 3.0.14.0 log created on 09232009_200152

Files\Folders moved on Reboot...
C:\windows\temp\_av_proI.tm~a04004\setup.lok moved successfully.
File\Folder C:\windows\temp\_avast4_\Webshlock.txt not found!
C:\windows\temp\Perflib_Perfdata_6f8.dat moved successfully.

Registry entries deleted on Reboot...



I still get Avast warning me of a possible trojan trying to connect to and ad1 website. Also I couldn't install AntiVir either.

#6 heir

  • Group: Malware Removal
  • Posts: 5,427
  • Joined: 19-February 08

Posted 24 September 2009 - 01:13 PM

Quote

Also I couldn't install AntiVir either.
No need to install Antivir as you have avast installed already.



Step 1.
OTL-fix

Run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    :Files
    [09/15/2009|01:50] C:\Program Files\BitComet
    [03/30/2008|03:46] C:\Program Files\Soulseek
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]


  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL fixlog


Step 2.
Scan with MBAM:

Please download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Step 3.
Scan with Kaspersky Online Scanner:

Please do an online scan with Kaspersky Online Scanner

Kaspersky online scanner uses JAVA tecnology to perform the scan. If you do not have the latest JAVA version, follow the instrutions below under Upgrading Java, to download and install the latest vesion.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure the following is checked.
      Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases

  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.


Upgrading Java:

Posted Image Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

Upgrading Java:
  • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 16.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u16-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u16-windows-i586-p.exe and select "Run as an Administrator.")


Step 4.
Things I would like to see in your reply:

  • The content of the fixlog from OTL from Step 1.
  • The content of the report from MBAM from Step 2.
  • The content of the report from Kaspersky Online Scanner from Step 3.


#7 heir

  • Group: Malware Removal
  • Posts: 5,427
  • Joined: 19-February 08

Posted 01 October 2009 - 07:35 PM

Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.

Share this topic: