Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Unable to do much of anything... [Solved]


  • This topic is locked This topic is locked

#16
Wafflemonger

Wafflemonger

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 548 posts
Here are the logs you requested sir ^^:

info.txt logfile of random's system information tool 1.06 2009-06-18 11:54:56

======Uninstall list======

-->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\windows\UNNeroMediaHome.exe /UNINSTALL
-->C:\windows\UNNeroShowTime.exe /UNINSTALL
-->C:\windows\UNNeroVision.exe /UNINSTALL
-->C:\windows\UNRecode.exe /UNINSTALL
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acrobat.com-->MsiExec.exe /X{287ECFA4-719A-2143-A09B-D6A12DE54E40}
Ad-Aware-->"C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE
Ad-Aware-->C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.1-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81000000003}
Adobe Reader 9.1.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A91000000001}
Adobe Shockwave Player 11.5-->"C:\windows\system32\Adobe\Shockwave 11\uninstaller.exe"
Adobe® Photoshop® Album Starter Edition 3.2-->MsiExec.exe /I{A654A805-41D9-40C7-AA46-4AF04F044D61}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
AVS4YOU Software Navigator 1.2-->"C:\Program Files\AVS4YOU\AVSSoftwareNavigator\unins000.exe"
Belkin Wireless G Desktop Card Driver and Utility-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CBD63CE3-F31F-4FF8-93BB-CFE3988B4624}\setup.exe" -l0x9 REMOVE
Belkin Wireless G Desktop Card Software-->C:\Program Files\InstallShield Installation Information\{E8ADC69C-4F11-483B-A3C9-B42E6A451CD2}\SETUP.EXE -v"ISSCRIPTCMDLINE=\"-d -zREMOVE\"" -l0x0009 -removeonly
CardRd81-->MsiExec.exe /I{54C8FE84-89C4-40E8-976C-439EB0729BD6}
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
CCScore-->MsiExec.exe /I{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}
Coupon Printer for Windows-->"C:\Program Files\Coupons\uninstall.exe" "/U:C:\Program Files\Coupons\Uninstall\uninstall.xml"
Coupon Printer-->"C:\Program Files\Coupon Printer\uninstall.exe" "/U:C:\Program Files\Coupon Printer\Uninstall\uninstall.xml"
COWON Media Center - jetAudio Basic-->C:\Program Files\InstallShield Installation Information\{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}\setup.exe -runfromtemp -l0x0009 -removeonly
CR2-->MsiExec.exe /I{432C3720-37BF-4BD7-8E49-F38E090246D0}
Critical Update for Windows Media Player 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
Digital Locker Assistant-->MsiExec.exe /I{D01653EF-9F9F-41D6-B879-654A6BF5892C}
DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5.0.2.5-->"C:\Program Files\DVDFab 5\unins000.exe"
DVDFab HD Decrypter 4.0.5.0-->"C:\Program Files\DVDFab HD Decrypter 4\unins000.exe"
EPSON Printer Software-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
ERUNT 1.1j-->"C:\Program Files\ERUNT\unins000.exe"
ESSBrwr-->MsiExec.exe /I{643EAE81-920C-4931-9F0B-4B343B225CA6}
ESSCDBK-->MsiExec.exe /I{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}
ESScore-->MsiExec.exe /I{42938595-0D83-404D-9F73-F8177FDD531A}
ESSgui-->MsiExec.exe /I{91517631-A9F3-4B7C-B482-43E0068FD55A}
ESSini-->MsiExec.exe /I{8E92D746-CD9F-4B90-9668-42B74C14F765}
ESSPCD-->MsiExec.exe /I{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}
ESSPDock-->MsiExec.exe /I{FCDB1C92-03C6-4C76-8625-371224256091}
ESSSONIC-->MsiExec.exe /I{073F22CE-9A5B-4A40-A604-C7270AC6BF34}
ESSTOOLS-->MsiExec.exe /I{8A502E38-29C9-49FA-BCFA-D727CA062589}
essvatgt-->MsiExec.exe /I{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}
Eyewitness News Alert-->C:\WINDOWS\wnUninstall.exe "Eyewitness News Alert"
Family Tree Maker-->C:\FTW\uninstal.exe
filehippo.com Update Checker-->"C:\Program Files\filehippo.com\uninstall.exe"
FTDI USB Serial Converter Drivers-->C:\WINDOWS\system32\ftdiunin.exe C:\WINDOWS\system32\ftdiun2k.ini
getPlus® for Adobe-->"C:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1
Glary Registry Repair 3.0-->"C:\Program Files\Glary Registry Repair\unins000.exe"
Google Earth Plugin-->MsiExec.exe /I{CFA3D1B0-415C-11DE-8251-005056806466}
Google Earth-->MsiExec.exe /X{CC016F21-3970-11DE-B878-005056806466}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Homescan Internet Transporter-->C:\Program Files\InstallShield Installation Information\{92BF38A8-5616-4209-87A3-D910B45A1D98}\setup.exe -runfromtemp -l0x0009 -uninst -removeonly
Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Intel® Extreme Graphics Driver-->RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562
Java™ 6 Update 14-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216014FF}
kgcbase-->MsiExec.exe /I{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}
LimeWire 5.2.2-->"C:\Program Files\LimeWire\uninstall.exe"
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office 2000 Premium-->MsiExec.exe /I{00000409-78E1-11D2-B60F-006097C998E7}
Microsoft Reader-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B6F7DBE7-2FE2-458F-A738-B10832746036}\Setup.exe" -L0x9
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (3.0.11)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Nero 7 Essentials-->MsiExec.exe /X{B28B351F-1232-46EA-85EF-B8EA91641033}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
netbrdg-->MsiExec.exe /I{4537EA4B-F603-4181-89FB-2953FC695AB1}
OfotoXMI-->MsiExec.exe /I{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}
OpenOffice.org Installer 1.0-->MsiExec.exe /X{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}
PhotoStreamer 2-->"C:\Documents and Settings\All Users\Application Data\{BA892C10-A262-42D0-B6AD-2ADE4916F871}\PhotoStreamer2Setup.exe" REMOVE=TRUE MODIFY=FALSE
PRECISION 801-->MsiExec.exe /X{44E75850-B838-43D2-8F37-84D3FB71FF6E}
QuickTime-->MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x9 -removeonly
RegScrubXP 3.25-->"C:\Program Files\RegScrubXP\unins000.exe"
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB969897)-->"C:\windows\ie8updates\KB969897-IE8\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 9 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961501)-->"C:\windows\$NtUninstallKB961501$\spuninst\spuninst.exe"
Security Update for Windows XP (KB968537)-->"C:\windows\$NtUninstallKB968537$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969898)-->"C:\windows\$NtUninstallKB969898$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970238)-->"C:\windows\$NtUninstallKB970238$\spuninst\spuninst.exe"
SFR-->MsiExec.exe /I{DB02F716-6275-42E9-B8D2-83BA2BF5100B}
SFR2-->MsiExec.exe /I{A0AF08BA-3630-4505-BFB2-A41F3837B0D0}
SHASTA-->MsiExec.exe /I{605A4E39-613C-4A12-B56F-DEFBE6757237}
skin0001-->MsiExec.exe /I{5316DFC9-CE99-4458-9AB3-E8726EDE0210}
SKINXSDK-->MsiExec.exe /I{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}
SoftK56 Data Fax Voice Speakerphone CARP-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F00&SUBSYS_200414F1\HXFSETUP.EXE -U -IVEN_14F1&DEV_2F00&SUBSYS_200414F1
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SpywareBlaster 4.2-->"C:\Program Files\SpywareBlaster\unins000.exe"
staticcr-->MsiExec.exe /I{8943CE61-53BD-475E-90E1-A580869E98A2}
SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
SwiftKit-->C:\Program Files\SwiftKit\Uninstall.exe
TeamViewer 4-->C:\Program Files\TeamViewer\Version4\uninstall.exe
tooltips-->MsiExec.exe /I{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}
TuneUp Utilities 2009-->MsiExec.exe /I{55A29068-F2CE-456C-9148-C869879E2357}
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Ventrilo Client-->MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
Video Converter 3-->C:\Program Files\Xilisoft\Video Converter 3\Uninstall.exe
Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\windows\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
VLC media player 1.0.0-rc3-->C:\Program Files\VideoLAN\VLC\uninstall.exe
VPRINTOL-->MsiExec.exe /I{999D43F4-9709-4887-9B1A-83EBB15A8370}
Wal-Mart Digital Photo Manager-->MsiExec.exe /X{C94C253C-069F-4C02-8E5B-C1D056827643}
Windows Driver Package - Camera Maker (MR97310_VGA_DUAL_CAMERA) Image 03/30/2004 2.0.0.0-->C:\WINDOWS\system32\DRVSTORE\f1490bc41e7d27129cb157cba768cf63b89e7752\DPInst.exe /u mr97310v_d627f051ae9bfa697d2ded113879197412f3f2b1
Windows Essentials Media Codec Pack 2.3c-->C:\Program Files\Essentials Codec Pack\uninst.exe
Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinZip 12.0-->MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240B7}
WIRELESS-->MsiExec.exe /I{F9593CFB-D836-49BC-BFF1-0E669A411D9F}
Yahoo! Browser Services-->C:\PROGRA~1\Yahoo!\Common\UNIN_Y~1.EXE /S

=====HijackThis Backups=====

O3 - Toolbar: (no name) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - (no file) [2009-06-09]
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file) [2009-06-09]
O3 - Toolbar: (no name) - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - (no file) [2009-06-09]
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfar...etup1.0.1.0.cab [2009-06-09]

======Hosts File======

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com

======Security center information======

AV: ThreatFire
AV: avast! antivirus 4.8.1335 [VPS 090617-0]

======System event log======

Computer Name: HOME
Event Code: 7034
Message: The avast! Web Scanner service terminated unexpectedly. It has done this 1 time(s).

Record Number: 26
Source Name: Service Control Manager
Time Written: 20090617210217.000000-240
Event Type: error
User:

Computer Name: HOME
Event Code: 7023
Message: The avast! Mail Scanner service terminated with the following error:
Cannot create a file when that file already exists.


Record Number: 19
Source Name: Service Control Manager
Time Written: 20090617205445.000000-240
Event Type: error
User:

Computer Name: HOME
Event Code: 7000
Message: The avast! Mail Scanner service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.


Record Number: 10
Source Name: Service Control Manager
Time Written: 20090617205345.000000-240
Event Type: error
User:

Computer Name: HOME
Event Code: 7009
Message: Timeout (30000 milliseconds) waiting for the avast! Mail Scanner service to connect.

Record Number: 9
Source Name: Service Control Manager
Time Written: 20090617205345.000000-240
Event Type: error
User:

Computer Name: HOME
Event Code: 7023
Message: The HID Input Service service terminated with the following error:
The system cannot find the file specified.


Record Number: 5
Source Name: Service Control Manager
Time Written: 20090617205334.000000-240
Event Type: error
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 1 Stepping 3, GenuineIntel
"PROCESSOR_REVISION"=0103
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO
"CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

-----------------EOF-----------------


Logfile of random's system information tool 1.06 (written by random/random)
Run by Janet at 2009-06-18 12:47:59
Microsoft Windows XP Professional Service Pack 3
System drive C: has 38 GB (33%) free of 114 GB
Total RAM: 375 MB (34% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:49:00 PM, on 6/18/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\windows\System32\svchost.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\filehippo.com\UpdateChecker.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\windows\System32\svchost.exe
C:\windows\System32\TUProgSt.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\TeamViewer\Version4\TeamViewer.exe
C:\Documents and Settings\Janet\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Janet.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cm.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.c...spx?tb_id=60341
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.c...aspx?TbId=60341
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [filehippo.com] "C:\Program Files\filehippo.com\UpdateChecker.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: www.safer-networking.org
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide....ageUploader.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadbl...ivex/sabspx.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.ado...obat/nos/gp.cab
O16 - DPF: {D8AA889B-2C65-47C3-8C16-3DCD4EF76A47} - http://rms2.invokeso...1450/MILive.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcp.../pcpitstop2.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Update Service (gupdate1c9ec3811168202) (gupdate1c9ec3811168202) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\windows\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\windows\System32\TUProgSt.exe

--
End of file - 7625 bytes

======Scheduled tasks folder======

C:\windows\tasks\1-Click Maintenance.job
C:\windows\tasks\Ad-Aware Update (Weekly).job
C:\windows\tasks\AppleSoftwareUpdate.job
C:\windows\tasks\GoogleUpdateTaskMachine.job
C:\windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
C:\windows\tasks\User_Feed_Synchronization-{06206F48-BC9B-451C-B31E-EC15954979E3}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2009-02-27 61816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
Yahoo! IE Services Button - C:\Program Files\Yahoo!\Common\yiesrvc.dll [2007-12-12 222448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{69A87B7D-DE56-4136-9655-716BA50C19C7}]
&Google Web Accelerator Helper - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll [2007-07-09 311296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-06-09 41368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-06-09 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - Google Web Accelerator - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll [2007-07-09 311296]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-02-05 81000]
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2009-03-09 515416]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\windows\system32\ctfmon.exe [2008-04-13 15360]
"filehippo.com"=C:\Program Files\filehippo.com\UpdateChecker.exe [2009-04-06 146944]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2009-05-26 1830128]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe [2007-03-09 63712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2007-10-10 39792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CARPService]
C:\windows\system32\carpserv.exe [2001-12-22 4608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX5400]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE [2003-05-26 99840]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe [2004-01-16 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\system32\igfxtray.exe [2004-01-16 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MegaPanel]
C:\Program Files\ACNielsen\Homescan Internet Transporter\HSTrans.exe [2006-05-11 2064384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2006-01-12 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2009-05-26 413696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Belkin Wireless G Desktop Card Client Utility.lnk]
C:\PROGRA~1\Belkin\PCIF5D~1\WIRELE~1\BELKIN~1.EXE [2006-08-14 1556480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
C:\DOCUME~1\Janet\MYDOCU~1\KODAKE~1\bin\EASYSH~1.EXE [2007-09-19 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~2\Office\OSA9.EXE [1999-02-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Google Web Accelerator.lnk]
C:\PROGRA~1\Google\WEBACC~1\GOOGLE~2.EXE [2007-07-09 1134592]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Janet^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Janet^Start Menu^Programs^Startup^MP3 Rocket (Minimized).lnk]
[]

C:\Documents and Settings\Janet\Start Menu\Programs\Startup
ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2008-12-22 356352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxsrvc.dll [2004-01-16 335872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\windows\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\windows\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoViewOnDrive"=0
"NoLogoff"=0
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\WINDOWS\system32\spool\drivers\w32x86\3\SAGENT4.EXE"="C:\WINDOWS\system32\spool\drivers\w32x86\3\SAGENT4.EXE:*:Enabled:SAgent4"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Documents and Settings\Janet\My Documents\Kodak EasyShare software\bin\EasyShare.exe"="C:\Documents and Settings\Janet\My Documents\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Belkin\PCI F5D700F\Wireless Utility\Belkinwcui.exe"="C:\Program Files\Belkin\PCI F5D700F\Wireless Utility\Belkinwcui.exe:*:Enabled:Belkin Wireless G Desktop Card Cleint Utility"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe"="C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe:*:Enabled:Nero Home"
"C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe"="C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup"
"C:\Program Files\TeamViewer\Version4\TeamViewer.exe"="C:\Program Files\TeamViewer\Version4\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application"
"C:\Program Files\Ventrilo\Ventrilo.exe"="C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware"
"C:\Documents and Settings\Janet\Desktop\spybotsd162.exe"="C:\Documents and Settings\Janet\Desktop\spybotsd162.exe:*:Enabled:spybotsd162"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2009-06-18 11:53:35 ----DC---- C:\rsit
2009-06-18 02:59:11 ----A---- C:\Program Files\Shockwave_Installer_Slim.exe
2009-06-18 02:33:50 ----A---- C:\Program Files\install_flash_player.exe
2009-06-17 00:07:59 ----DC---- C:\Documents and Settings\All Users\Application Data\Google
2009-06-16 17:41:42 ----A---- C:\Program Files\utorrent.exe
2009-06-16 14:52:53 ----A---- C:\windows\SchedLgU.Txt
2009-06-16 10:59:08 ----A---- C:\Program Files\Setup-349cc72_02018-4.exe
2009-06-16 10:46:06 ----D---- C:\Program Files\Common Files\Uninstall
2009-06-16 10:45:37 ----D---- C:\Program Files\PAV
2009-06-16 04:25:40 ----D---- C:\Program Files\Mozilla Firefox
2009-06-15 04:22:29 ----AC---- C:\Rooter.txt
2009-06-14 17:05:17 ----DC---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-14 17:04:51 ----D---- C:\Program Files\SUPERAntiSpyware
2009-06-14 17:04:50 ----DC---- C:\Documents and Settings\Janet\Application Data\SUPERAntiSpyware.com
2009-06-14 15:47:32 ----A---- C:\windows\wininit.ini
2009-06-14 14:55:39 ----DC---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-14 14:55:39 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-06-14 01:24:49 ----HDC---- C:\windows\$NtUninstallKB961501$
2009-06-14 01:24:31 ----HDC---- C:\windows\$NtUninstallKB969898$
2009-06-14 01:21:07 ----HDC---- C:\windows\$NtUninstallKB970238$
2009-06-14 01:20:32 ----HDC---- C:\windows\$NtUninstallKB968537$
2009-06-13 20:48:15 ----DC---- C:\Documents and Settings\Janet\Application Data\vlc
2009-06-13 11:02:48 ----A---- C:\Program Files\GoogleEarthPluginSetup.exe
2009-06-13 09:17:23 ----A---- C:\Program Files\GoogleToolbarInstaller_en_signed.exe
2009-06-13 09:10:55 ----DC---- C:\Documents and Settings\All Users\Application Data\Apple Computer
2009-06-13 09:09:49 ----D---- C:\Program Files\Apple Software Update
2009-06-13 09:09:48 ----DC---- C:\Documents and Settings\All Users\Application Data\Apple
2009-06-13 09:08:28 ----A---- C:\Program Files\QuickTimeInstaller.exe
2009-06-13 08:58:43 ----AC---- C:\Bug.txt
2009-06-13 08:58:20 ----DC---- C:\32788R22FWJFW
2009-06-12 23:37:42 ----AC---- C:\ComboFix.txt
2009-06-12 21:19:24 ----A---- C:\windows\zip.exe
2009-06-12 21:19:24 ----A---- C:\windows\SWXCACLS.exe
2009-06-12 21:19:24 ----A---- C:\windows\SWSC.exe
2009-06-12 21:19:24 ----A---- C:\windows\SWREG.exe
2009-06-12 21:19:24 ----A---- C:\windows\sed.exe
2009-06-12 21:19:24 ----A---- C:\windows\PEV.exe
2009-06-12 21:19:24 ----A---- C:\windows\NIRCMD.exe
2009-06-12 21:19:24 ----A---- C:\windows\grep.exe
2009-06-12 21:18:57 ----A---- C:\windows\system32\CF15232.exe
2009-06-12 18:56:27 ----DC---- C:\Qoobox
2009-06-12 18:34:44 ----DC---- C:\_OTL
2009-06-12 17:49:57 ----DC---- C:\Documents and Settings\Janet\Application Data\COWON
2009-06-12 17:13:16 ----D---- C:\Program Files\Common Files\COWON
2009-06-12 17:13:07 ----D---- C:\Program Files\JetAudio
2009-06-12 17:10:14 ----A---- C:\Program Files\JAD7_BASIC.exe
2009-06-12 12:03:02 ----A---- C:\Program Files\SUPERsetup.exe
2009-06-12 11:30:08 ----A---- C:\Program Files\vlc-1.0.0-rc3-win32.exe
2009-06-12 11:24:21 ----A---- C:\Program Files\utorrent-1.8.3-beta-15619.upx.exe
2009-06-12 11:02:20 ----A---- C:\Program Files\GoogleEarth-Win-Plus-5.0.11733.9347.exe
2009-06-12 10:39:23 ----A---- C:\Program Files\Firefox Setup 3.5 Beta 99.exe
2009-06-12 10:17:17 ----A---- C:\Program Files\SpywareTerminatorSetup.exe
2009-06-12 10:13:44 ----A---- C:\Program Files\Shockwave_Installer_Full.exe
2009-06-12 08:39:49 ----A---- C:\Program Files\mbam-setup.exe
2009-06-12 08:37:29 ----A---- C:\Program Files\LimeWireWin.exe
2009-06-12 08:35:06 ----A---- C:\Program Files\install_flash_player_10.exe
2009-06-12 08:33:24 ----A---- C:\Program Files\Firefox Setup 3.0.11.exe
2009-06-12 08:30:24 ----A---- C:\Program Files\AdobeAIRInstaller.exe
2009-06-12 08:26:16 ----HDC---- C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-12 08:25:57 ----D---- C:\Program Files\Lavasoft
2009-06-12 08:22:44 ----A---- C:\Program Files\Ad-AwareAE.exe
2009-06-12 08:14:35 ----D---- C:\Program Files\filehippo.com
2009-06-12 08:14:00 ----A---- C:\Program Files\FHSetup.exe
2009-06-09 17:20:55 ----D---- C:\windows\ERDNT
2009-06-09 17:20:38 ----D---- C:\Program Files\ERUNT
2009-06-09 17:07:40 ----DC---- C:\Rooter$
2009-06-09 16:58:38 ----DC---- C:\Documents and Settings\Janet\Application Data\Malwarebytes
2009-06-09 16:58:26 ----DC---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-06-09 16:58:25 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-06-09 16:50:39 ----D---- C:\Program Files\Trend Micro
2009-06-09 16:47:57 ----D---- C:\Program Files\SpywareBlaster
2009-06-09 02:58:09 ----A---- C:\windows\system32\TUProgSt.exe
2009-06-09 02:58:05 ----A---- C:\windows\system32\uxtuneup.dll
2009-06-09 02:58:02 ----A---- C:\windows\system32\TuneUpDefragService.exe
2009-06-09 02:57:48 ----DC---- C:\Documents and Settings\Janet\Application Data\TuneUp Software
2009-06-09 02:56:25 ----DC---- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2009-06-09 02:56:16 ----D---- C:\Program Files\TuneUp Utilities 2009
2009-06-09 02:55:25 ----SHDC---- C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-06-09 01:24:23 ----A---- C:\windows\system32\aswBoot.exe
2009-06-09 01:24:19 ----D---- C:\Program Files\Alwil Software
2009-06-09 01:09:45 ----A---- C:\windows\system32\javaws.exe
2009-06-09 01:09:45 ----A---- C:\windows\system32\javaw.exe
2009-06-09 01:09:45 ----A---- C:\windows\system32\java.exe
2009-06-09 01:09:19 ----D---- C:\Program Files\Java
2009-06-08 23:56:44 ----D---- C:\Program Files\Ventrilo
2009-06-08 23:56:42 ----A---- C:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2009-06-08 23:53:36 ----DC---- C:\Documents and Settings\Janet\Application Data\TeamViewer
2009-06-08 23:53:21 ----D---- C:\Program Files\TeamViewer
2009-06-06 13:16:55 ----A---- C:\windows\system32\ChCfg.exe
2009-06-06 13:15:42 ----D---- C:\Program Files\Realtek AC97
2009-06-06 13:15:39 ----A---- C:\windows\system32\RTLCPL.exe
2009-06-06 13:15:37 ----A---- C:\windows\soundman.exe
2009-06-06 13:15:36 ----A---- C:\windows\system32\RtlCPAPI.dll
2009-06-06 13:14:57 ----A---- C:\Program Files\WDM_A406.exe
2009-06-06 13:07:34 ----A---- C:\Program Files\ccsetup220.exe
2009-05-27 10:03:55 ----DC---- C:\Documents and Settings\Janet\Application Data\DNA
2009-05-27 10:03:55 ----D---- C:\Program Files\DNA
2009-05-25 18:34:08 ----DC---- C:\divx
2009-05-25 17:29:01 ----N---- C:\windows\system32\spmsg.dll
2009-05-25 17:04:49 ----D---- C:\Program Files\Glary Registry Repair
2009-05-24 19:43:25 ----DC---- C:\Documents and Settings\Janet\Application Data\DivX
2009-05-24 19:43:22 ----DC---- C:\Documents and Settings\Janet\Application Data\Media Player Classic
2009-05-24 19:25:07 ----D---- C:\Program Files\Essentials Codec Pack
2009-05-24 18:32:47 ----HD---- C:\windows\PIF
2009-05-24 13:54:05 ----DC---- C:\Temp
2009-05-24 13:48:22 ----D---- C:\Program Files\Xilisoft
2009-05-23 00:34:51 ----DC---- C:\Documents and Settings\Janet\Application Data\dvdcss
2009-05-23 00:31:37 ----D---- C:\Program Files\VideoLAN
2009-05-21 22:43:16 ----DC---- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2009-05-21 17:20:59 ----DC---- C:\Documents and Settings\All Users\Application Data\LightScribe
2009-05-20 15:36:49 ----DC---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-05-20 14:23:57 ----D---- C:\Program Files\Common Files\LightScribe
2009-05-20 14:17:30 ----DC---- C:\Documents and Settings\All Users\Application Data\Nero
2009-05-20 14:17:29 ----D---- C:\Program Files\Nero
2009-05-20 13:34:03 ----DC---- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2009-05-19 21:16:09 ----DC---- C:\Documents and Settings\All Users\Application Data\Eyewitness News Alert

======List of files/folders modified in the last 1 months======

2009-06-18 12:07:27 ----D---- C:\windows\Temp
2009-06-18 12:00:55 ----D---- C:\windows\system32\CatRoot2
2009-06-18 11:59:07 ----D---- C:\WINDOWS
2009-06-18 11:57:03 ----D---- C:\windows\system32
2009-06-18 11:56:00 ----D---- C:\windows\Prefetch
2009-06-18 11:48:11 ----ADC---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-06-18 02:59:22 ----D---- C:\Program Files
2009-06-17 20:47:40 ----D---- C:\Program Files\DivX
2009-06-17 14:27:35 ----AC---- C:\windows\NeroDigital.ini
2009-06-17 08:56:48 ----D---- C:\Program Files\Google
2009-06-17 00:07:19 ----SHD---- C:\windows\Installer
2009-06-16 19:59:20 ----D---- C:\windows\Help
2009-06-16 17:43:26 ----DC---- C:\Documents and Settings\Janet\Application Data\uTorrent
2009-06-16 16:59:55 ----D---- C:\windows\system32\drivers
2009-06-16 11:21:59 ----SD---- C:\windows\Tasks
2009-06-16 10:47:18 ----RSHDC---- C:\windows\system32\dllcache
2009-06-16 10:46:06 ----D---- C:\Program Files\Common Files
2009-06-16 09:43:15 ----D---- C:\windows\network diagnostic
2009-06-16 03:53:15 ----D---- C:\windows\system32\Macromed
2009-06-15 23:39:24 ----SD---- C:\windows\Downloaded Program Files
2009-06-15 23:39:16 ----HD---- C:\windows\inf
2009-06-15 16:30:19 ----D---- C:\windows\Debug
2009-06-14 17:04:01 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-06-14 15:47:29 ----D---- C:\windows\Cache
2009-06-14 01:25:15 ----D---- C:\Program Files\Internet Explorer
2009-06-14 01:25:04 ----D---- C:\windows\ie8updates
2009-06-14 01:24:58 ----HD---- C:\windows\$hf_mig$
2009-06-13 09:21:11 ----D---- C:\Program Files\LimeWire
2009-06-13 09:11:59 ----D---- C:\Program Files\QuickTime
2009-06-12 22:46:43 ----AC---- C:\windows\system.ini
2009-06-12 21:29:16 ----D---- C:\windows\system32\config
2009-06-12 21:25:14 ----D---- C:\windows\AppPatch
2009-06-12 21:10:56 ----DC---- C:\Documents and Settings\All Users\Application Data\PC Tools
2009-06-12 17:13:03 ----HD---- C:\Program Files\InstallShield Installation Information
2009-06-12 11:21:34 ----D---- C:\Documents and Settings\Janet\Application Data\LimeWire
2009-06-12 08:31:01 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-06-12 08:28:00 ----DC---- C:\windows\system32\DRVSTORE
2009-06-12 08:25:57 ----DC---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-06-12 08:25:48 ----D---- C:\windows\WinSxS
2009-06-09 23:19:09 ----SHD---- C:\System Volume Information
2009-06-09 23:19:09 ----D---- C:\windows\system32\Restore
2009-06-09 03:18:16 ----A---- C:\windows\RTacDbg.txt
2009-06-09 03:03:06 ----D---- C:\Program Files\Yahoo!
2009-06-09 02:06:20 ----SHD---- C:\RECYCLER
2009-06-09 01:09:26 ----A---- C:\windows\system32\deploytk.dll
2009-06-09 00:22:28 ----D---- C:\Program Files\SwiftKit
2009-06-08 23:55:02 ----DC---- C:\Documents and Settings\All Users\Application Data\SwiftKit
2009-06-08 12:23:17 ----D---- C:\Program Files\Common Files\Eyewitness News Alert
2009-06-07 14:36:40 ----D---- C:\Program Files\RegScrubXP
2009-06-06 16:42:12 ----SD---- C:\Documents and Settings\Janet\Application Data\Microsoft
2009-06-06 14:15:27 ----D---- C:\Program Files\Grisoft
2009-06-06 13:16:23 ----D---- C:\windows\system32\ReinstallBackups
2009-06-06 13:08:59 ----D---- C:\Program Files\CCleaner
2009-06-06 13:02:52 ----D---- C:\windows\Minidump
2009-06-06 00:55:02 ----RSD---- C:\windows\assembly
2009-06-01 09:51:14 ----AC---- C:\windows\system32\MRT.exe
2009-05-31 12:50:40 ----AC---- C:\windows\system32\results.txt
2009-05-25 18:10:46 ----D---- C:\windows\system32\CatRoot
2009-05-22 21:41:59 ----DC---- C:\Documents and Settings\Janet\Application Data\Ahead
2009-05-20 14:23:24 ----D---- C:\Program Files\Common Files\Ahead
2009-05-19 23:12:23 ----D---- C:\Program Files\Ahead
2009-05-19 23:04:54 ----D---- C:\Program Files\Vuze
2009-05-19 21:15:45 ----DC---- C:\Documents and Settings\All Users\Application Data\Kodak

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\windows\system32\drivers\Aavmker4.sys [2009-02-05 26944]
R1 aswSP;avast! Self Protection; C:\windows\system32\drivers\aswSP.sys [2009-02-05 114768]
R1 aswTdi;avast! Network Shield Support; C:\windows\system32\drivers\aswTdi.sys [2009-02-05 51376]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.5.0; C:\windows\system32\DRIVERS\AegisP.sys [2009-05-31 21035]
R2 aswFsBlk;aswFsBlk; C:\windows\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
R2 aswMon2;avast! Standard Shield Support; C:\windows\system32\drivers\aswMon2.sys [2009-02-05 94032]
R2 mdmxsdk;mdmxsdk; C:\windows\system32\DRIVERS\mdmxsdk.sys [2001-10-21 9855]
R2 StreamDispatcher;StreamDispatcher; C:\windows\system32\DRIVERS\strmdisp.sys [2001-12-22 33548]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\windows\system32\drivers\ALCXWDM.SYS [2008-09-24 4122368]
R3 als4k;Avance Audio Miniport Driver (WDM); C:\windows\system32\drivers\als4000.sys [2001-10-22 28919]
R3 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr.sys [2009-02-05 23152]
R3 Belkin700F;Belkin Wireless G Desktop Card Service v7; C:\windows\system32\DRIVERS\BLKWGDv7.sys [2006-10-19 303616]
R3 HidUsb;Microsoft HID Class Driver; C:\windows\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DP;HSF_DP; C:\windows\system32\DRIVERS\HSF_DP.sys [2001-12-22 1171488]
R3 HSFHWBS2;HSFHWBS2; C:\windows\system32\DRIVERS\HSFHWBS2.sys [2001-12-22 160083]
R3 ialm;ialm; C:\windows\system32\DRIVERS\ialmnt5.sys [2004-01-16 666109]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\windows\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Mouse HID Driver; C:\windows\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 pcouffin;VSO Software pcouffin; C:\windows\System32\Drivers\pcouffin.sys [2008-06-03 47360]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\windows\System32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\windows\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\windows\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\windows\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 winachsf;winachsf; C:\windows\system32\DRIVERS\HSF_CNXT.sys [2001-12-22 591536]
S1 kbdhid;Keyboard HID Driver; C:\windows\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S3 catchme;catchme; \??\C:\DOCUME~1\Janet\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\windows\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 FTDIBUS;USB Serial Converter Driver; C:\windows\system32\drivers\ftdibus.sys [2005-12-19 28449]
S3 FTSER2K;USB Serial Port Driver; C:\windows\system32\drivers\ftser2k.sys [2005-12-19 60572]
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera; C:\windows\system32\DRIVERS\mr97310v.sys [2004-03-30 118106]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\windows\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\windows\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\windows\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 SABProcEnum;SABProcEnum; \??\C:\Program Files\Internet Explorer\SABProcEnum.sys []
S3 sermouse;Serial Mouse Driver; C:\windows\System32\DRIVERS\sermouse.sys [2001-08-17 17664]
S3 SjyPkt;SjyPkt; \??\C:\windows\System32\Drivers\SjyPkt.sys []
S3 SLIP;BDA Slip De-Framer; C:\windows\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\windows\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 TVICHW32;TVICHW32; \??\C:\windows\system32\DRIVERS\TVICHW32.SYS []
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\windows\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\windows\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Usbscan; C:\windows\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\windows\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; C:\windows\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\windows\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\windows\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\windows\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-02-05 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-02-05 138680]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-06-09 152984]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-09 951632]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-12-14 61440]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; C:\windows\System32\TUProgSt.exe [2009-06-09 604416]
R2 UxTuneUp;TuneUp Theme Extension; C:\windows\System32\svchost.exe [2008-04-13 14336]
R2 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\windows\system32\svchost.exe [2008-04-13 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-02-05 254040]
S2 gupdate1c9ec3811168202;Google Update Service (gupdate1c9ec3811168202); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-06-13 133104]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-02-05 352920]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 getPlus® Helper;getPlus® Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2009-03-03 33176]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\windows\System32\TuneUpDefragService.exe [2009-06-09 361216]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2006-12-23 262144]

-----------------EOF-----------------


EDIT: I've noticed multiple times that the Threatfire anti virus is still on my computer even though i've uninstalled it and removed it from program files. Any help on removing it permanently would be appreciated.

Edited by Wafflemonger, 18 June 2009 - 11:04 AM.

  • 0

Advertisements


#17
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Hi Wafflemonger,


I do not see any sign of ThreatFire either.


Spybot Search & Destroy TeaTimer
  • Launch Spybot Search & Destroy Posted Image
  • In the Menu, Select Mode and choose Advanced Mode
  • Click Yes in the confirmation dialogue box
  • click on Tools to expand the menu. Make sure that Resident is checked and then click Resident in the left pane.
  • In the right pane uncheck Resident "Tea timer" (Protection of over-all system settings) to disable it.
  • Uncheck the TeaTimer box and OK any prompts.
  • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
  • Exit Spybot S&D when done.
  • (Once you are clean, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]


Step #1

Run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60341
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60341
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done



Step #2

You are using peer-to-peer programs, specifically LimeWire.
These are what we call an optional removal. However, anytime you are running any type of peer-to-peer application, you are more prone to infection by malware, and this is probably how you became infected in the first place. The choice to remove them is entirely up to you, but I would strongly recommend that you do.
If you do not want to, please at least refrain from using any peer-to-peer programs for the remainder of my fix.
Below I listed LimeWire for removal, if you do not wish to remove it, skip removing it below.



Please go to Start > Control Panel > Add/Remove Programs and remove the following (if present):


Adobe Reader 8.1.1
LimeWire 5.2.2



Step #3

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :dir
    C:\32788R22FWJFW
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


Step #4

Disable resident protections (Antivirus...); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
  • 0

#18
Wafflemonger

Wafflemonger

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 548 posts
I don't know if you wanted this but:

========== OTL ==========
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\Janet\Local Settings\temp\~DF13E0.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Janet\Local Settings\temp\~DF13F2.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Janet\Local Settings\temp\~DF18EA.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Janet\Local Settings\temp\~DF18FC.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Janet\Local Settings\temp\~DF1B14.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Janet\Local Settings\temp\~DF1B26.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\windows\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\windows\temp\Perflib_Perfdata_284.dat scheduled to be deleted on reboot.
File delete failed. C:\windows\temp\Perflib_Perfdata_7f4.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTL by OldTimer - Version 2.1.1.0 log created on 06182009_193048

Files moved on Reboot...
File C:\Documents and Settings\Janet\Local Settings\temp\~DF13E0.tmp not found!
File C:\Documents and Settings\Janet\Local Settings\temp\~DF13F2.tmp not found!
File C:\Documents and Settings\Janet\Local Settings\temp\~DF18EA.tmp not found!
File C:\Documents and Settings\Janet\Local Settings\temp\~DF18FC.tmp not found!
File C:\Documents and Settings\Janet\Local Settings\temp\~DF1B14.tmp not found!
File C:\Documents and Settings\Janet\Local Settings\temp\~DF1B26.tmp not found!
File move failed. C:\windows\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
C:\windows\temp\Perflib_Perfdata_284.dat moved successfully.
File C:\windows\temp\Perflib_Perfdata_7f4.dat not found!

Registry entries deleted on Reboot...

And when i try to remove the adobe 8.1.1 i get this:

Posted Image


SystemLook v1.0 by jpshortstuff (22.05.09)
Log created at 19:53 on 18/06/2009 by Janet (Administrator - Elevation successful)

========== dir ==========

C:\32788R22FWJFW - Parameters: "(none)"

---Files---
NirCmd.cfexe --a--c 31232 bytes [12:58 13/06/2009] [16:56 20/04/2009]

---Folders---
None found.

-=End Of File=-



--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel® Celeron® CPU 1.70GHz )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Janet ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1335 [VPS 090618-0] 4.8.1335 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:111 Go (Free:37 Go)
D:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( Thu 06/18/2009|19:57 )

--------------------\\ Listing folders in APPLIC~1

[06/09/2009|02:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> {55A29068-F2CE-456C-9148-C869879E2357}
[06/12/2009|08:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> {7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[02/25/2008|11:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> {BA892C10-A262-42D0-B6AD-2ADE4916F871}
[05/04/2009|11:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> ~0
[06/12/2009|08:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe
[06/13/2009|09:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple
[06/13/2009|09:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple Computer
[05/21/2009|10:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> DVD Shrink
[05/19/2009|09:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Eyewitness News Alert
[06/17/2009|12:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Google
[05/19/2009|09:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Kodak
[06/12/2009|08:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Lavasoft
[05/21/2009|05:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> LightScribe
[06/09/2009|04:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Malwarebytes
[07/25/2007|05:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft
[12/29/2007|06:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> NCH Swift Sound
[05/20/2009|02:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Nero
[05/15/2009|10:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> NOS
[05/20/2009|01:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> PC Drivers HeadQuarters
[06/12/2009|09:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> PC Tools
[07/01/2008|11:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> PCPitstop
[01/03/2008|10:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> QuickTime
[04/23/2009|12:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Skype
[10/01/2007|09:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> SpinTop Games
[06/15/2009|06:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Spybot - Search & Destroy
[06/14/2009|05:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> SUPERAntiSpyware.com
[06/08/2009|11:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> SwiftKit
[06/18/2009|11:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> TEMP
[10/01/2007|08:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Trymedia
[06/09/2009|02:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> TuneUp Software
[07/23/2007|12:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage
[03/09/2009|04:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> WinZip
[05/08/2009|07:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Yahoo!

[07/21/2007|04:07] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft

[05/15/2009|10:41] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Adobe
[05/22/2009|09:41] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Ahead
[08/23/2007|12:06] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Apple Computer
[05/18/2009|09:40] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Azureus
[05/17/2009|12:24] C:\DOCUME~1\Janet\APPLIC~1\<DIR> com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[06/12/2009|05:49] C:\DOCUME~1\Janet\APPLIC~1\<DIR> COWON
[12/18/2007|01:29] C:\DOCUME~1\Janet\APPLIC~1\<DIR> DeepBurner
[08/12/2007|06:54] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Digital Album Organizer
[05/25/2009|06:27] C:\DOCUME~1\Janet\APPLIC~1\<DIR> DivX
[02/23/2008|11:27] C:\DOCUME~1\Janet\APPLIC~1\<DIR> DMCache
[06/09/2009|03:18] C:\DOCUME~1\Janet\APPLIC~1\<DIR> DNA
[05/27/2009|07:12] C:\DOCUME~1\Janet\APPLIC~1\<DIR> dvdcss
[01/12/2008|09:53] C:\DOCUME~1\Janet\APPLIC~1\<DIR> EPSON
[05/03/2008|10:03] C:\DOCUME~1\Janet\APPLIC~1\<DIR> FrostWire
[11/23/2007|01:53] C:\DOCUME~1\Janet\APPLIC~1\<DIR> GlarySoft
[10/27/2007|02:23] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Google
[08/04/2007|05:00] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Help
[07/21/2007|04:21] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Identities
[07/24/2007|09:55] C:\DOCUME~1\Janet\APPLIC~1\<DIR> InstallShield
[02/25/2008|06:25] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Leadertech
[06/12/2009|11:21] C:\DOCUME~1\Janet\APPLIC~1\<DIR> LimeWire
[08/14/2007|07:11] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Macromedia
[06/09/2009|04:58] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Malwarebytes
[05/24/2009|07:44] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Media Player Classic
[06/06/2009|04:42] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Microsoft
[07/23/2007|02:50] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Microsoft Web Folders
[01/03/2008|05:44] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Move Networks
[08/11/2007|09:20] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Movie Label
[09/01/2008|10:53] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Mozilla
[05/02/2009|12:03] C:\DOCUME~1\Janet\APPLIC~1\<DIR> MP3Rocket
[12/29/2007|06:17] C:\DOCUME~1\Janet\APPLIC~1\<DIR> NCH Swift Sound
[12/30/2007|07:25] C:\DOCUME~1\Janet\APPLIC~1\<DIR> PhotoWorks
[02/27/2008|08:06] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Real
[01/23/2008|05:11] C:\DOCUME~1\Janet\APPLIC~1\<DIR> RipIt4Me
[12/30/2007|07:24] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Seven Zip
[03/06/2009|05:02] C:\DOCUME~1\Janet\APPLIC~1\<DIR> skypePM
[02/26/2008|12:13] C:\DOCUME~1\Janet\APPLIC~1\<DIR> SlickRun
[08/05/2007|02:33] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Snapfish
[07/25/2007|06:18] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Sun
[06/14/2009|05:04] C:\DOCUME~1\Janet\APPLIC~1\<DIR> SUPERAntiSpyware.com
[06/14/2009|08:10] C:\DOCUME~1\Janet\APPLIC~1\<DIR> TeamViewer
[06/09/2009|02:57] C:\DOCUME~1\Janet\APPLIC~1\<DIR> TuneUp Software
[01/29/2008|11:27] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Uniblue
[06/18/2009|02:18] C:\DOCUME~1\Janet\APPLIC~1\<DIR> uTorrent
[03/03/2009|03:27] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Ventrilo
[06/18/2009|03:29] C:\DOCUME~1\Janet\APPLIC~1\<DIR> vlc
[07/31/2007|07:34] C:\DOCUME~1\Janet\APPLIC~1\<DIR> VombaNetwork
[06/03/2008|06:58] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Vso
[08/12/2007|06:49] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Wal-Mart Digital Photo Manager
[08/11/2007|06:26] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Wal-Mart Digital Photo Viewer
[06/03/2008|04:48] C:\DOCUME~1\Janet\APPLIC~1\<DIR> Yahoo!

[07/08/2008|03:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft
[03/06/2008|12:16] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Mozilla

[05/25/2009|05:39] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Adobe
[05/25/2009|05:38] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Google
[06/06/2009|04:42] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft
[05/25/2009|05:38] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Yahoo!

--------------------\\ Scheduled Tasks located in C:\windows\Tasks

[06/16/2009 11:21 AM][--a------] C:\windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[06/18/2009 07:34 PM][--a------] C:\windows\tasks\GoogleUpdateTaskMachine.job
[06/17/2009 09:08 AM][--a------] C:\windows\tasks\AppleSoftwareUpdate.job
[06/15/2009 08:28 AM][--a------] C:\windows\tasks\Ad-Aware Update (Weekly).job
[06/18/2009 07:35 PM][--a------] C:\windows\tasks\1-Click Maintenance.job
[06/18/2009 02:23 PM][--ah-c---] C:\windows\tasks\User_Feed_Synchronization-{06206F48-BC9B-451C-B31E-EC15954979E3}.job
[06/18/2009 07:34 PM][--ah-c---] C:\windows\tasks\SA.DAT
[08/23/2001 08:00 AM][-r-h-c---] C:\windows\tasks\desktop.ini

--------------------\\ Listing Folders in C:\Program Files

[05/15/2009|10:49] C:\Program Files\<DIR> 3D Relief Screensaver
[04/29/2008|01:55] C:\Program Files\<DIR> ACNielsen
[05/15/2009|10:45] C:\Program Files\<DIR> Adobe
[05/19/2009|11:12] C:\Program Files\<DIR> Ahead
[06/09/2009|01:24] C:\Program Files\<DIR> Alwil Software
[06/13/2009|09:09] C:\Program Files\<DIR> Apple Software Update
[01/22/2008|09:30] C:\Program Files\<DIR> Astonsoft
[01/29/2008|02:32] C:\Program Files\<DIR> AvRack
[06/21/2008|10:46] C:\Program Files\<DIR> AVS4YOU
[08/01/2007|06:32] C:\Program Files\<DIR> Belkin
[01/14/2008|01:10] C:\Program Files\<DIR> BitComet
[06/08/2008|07:26] C:\Program Files\<DIR> Burn4Free Toolbar
[06/06/2009|01:08] C:\Program Files\<DIR> CCleaner
[06/16/2009|10:46] C:\Program Files\<DIR> Common Files
[07/21/2007|04:04] C:\Program Files\<DIR> ComPlus Applications
[07/24/2007|09:42] C:\Program Files\<DIR> CONEXANT
[02/26/2008|12:02] C:\Program Files\<DIR> Coupon Printer
[04/23/2009|12:53] C:\Program Files\<DIR> Coupons
[07/01/2008|11:59] C:\Program Files\<DIR> Digital Locker Assistant
[06/17/2009|08:47] C:\Program Files\<DIR> DivX
[06/09/2009|02:43] C:\Program Files\<DIR> DNA
[05/13/2009|05:00] C:\Program Files\<DIR> DVD Shrink
[06/03/2008|06:57] C:\Program Files\<DIR> DVDFab 5
[01/22/2008|07:22] C:\Program Files\<DIR> DVDFab HD Decrypter 4
[09/18/2007|01:13] C:\Program Files\<DIR> epson
[06/09/2009|05:20] C:\Program Files\<DIR> ERUNT
[05/24/2009|07:26] C:\Program Files\<DIR> Essentials Codec Pack
[06/12/2009|08:14] C:\Program Files\<DIR> filehippo.com
[07/01/2008|05:30] C:\Program Files\<DIR> FrostWire
[05/25/2009|05:04] C:\Program Files\<DIR> Glary Registry Repair
[06/17/2009|08:56] C:\Program Files\<DIR> Google
[06/06/2009|02:15] C:\Program Files\<DIR> Grisoft
[04/12/2008|05:00] C:\Program Files\<DIR> HOTLLAMA Media
[06/12/2009|05:13] C:\Program Files\<DIR> InstallShield Installation Information
[07/23/2007|01:29] C:\Program Files\<DIR> Intel
[12/19/2007|06:30] C:\Program Files\<DIR> InterActual
[06/14/2009|01:25] C:\Program Files\<DIR> Internet Explorer
[06/09/2009|01:09] C:\Program Files\<DIR> Java
[06/12/2009|05:14] C:\Program Files\<DIR> JetAudio
[02/26/2008|12:02] C:\Program Files\<DIR> Kodak
[06/12/2009|08:25] C:\Program Files\<DIR> Lavasoft
[06/13/2009|09:21] C:\Program Files\<DIR> LimeWire
[06/18/2009|02:14] C:\Program Files\<DIR> Malwarebytes' Anti-Malware
[02/26/2008|12:02] C:\Program Files\<DIR> Mars
[08/19/2008|06:06] C:\Program Files\<DIR> Messenger
[01/01/2008|10:25] C:\Program Files\<DIR> Microsoft CAPICOM 2.1.0.2
[07/23/2007|02:50] C:\Program Files\<DIR> microsoft frontpage
[07/23/2007|02:50] C:\Program Files\<DIR> Microsoft Office
[05/17/2009|02:26] C:\Program Files\<DIR> Microsoft Reader
[08/19/2008|05:15] C:\Program Files\<DIR> Movie Maker
[06/18/2009|05:01] C:\Program Files\<DIR> Mozilla Firefox
[08/19/2008|05:15] C:\Program Files\<DIR> msn
[07/21/2007|04:03] C:\Program Files\<DIR> MSN Gaming Zone
[08/20/2007|04:36] C:\Program Files\<DIR> MSXML 4.0
[05/20/2008|09:50] C:\Program Files\<DIR> mypoints
[01/28/2008|09:08] C:\Program Files\<DIR> NCH Swift Sound
[05/20/2009|02:17] C:\Program Files\<DIR> Nero
[08/19/2008|05:10] C:\Program Files\<DIR> NetMeeting
[05/15/2009|10:28] C:\Program Files\<DIR> NOS
[03/21/2008|02:12] C:\Program Files\<DIR> Online Services
[08/19/2008|05:10] C:\Program Files\<DIR> Outlook Express
[06/16/2009|04:54] C:\Program Files\<DIR> PAV
[02/26/2008|12:02] C:\Program Files\<DIR> PhotoWorks
[06/13/2009|09:11] C:\Program Files\<DIR> QuickTime
[06/06/2009|01:15] C:\Program Files\<DIR> Realtek AC97
[07/24/2007|04:21] C:\Program Files\<DIR> Realtek Sound Manager
[05/09/2009|10:36] C:\Program Files\<DIR> Registry Mechanic
[01/27/2008|05:08] C:\Program Files\<DIR> Registry Repair
[05/08/2009|03:59] C:\Program Files\<DIR> Registry_Cleaner_Pro
[06/07/2009|02:36] C:\Program Files\<DIR> RegScrubXP
[02/27/2008|08:04] C:\Program Files\<DIR> SlickRun
[06/21/2008|10:23] C:\Program Files\<DIR> Speeditup Free
[06/16/2009|12:55] C:\Program Files\<DIR> Spybot - Search & Destroy
[06/18/2009|11:47] C:\Program Files\<DIR> SpywareBlaster
[07/23/2008|10:20] C:\Program Files\<DIR> Sun
[06/14/2009|05:04] C:\Program Files\<DIR> SUPERAntiSpyware
[06/09/2009|12:22] C:\Program Files\<DIR> SwiftKit
[01/25/2008|08:23] C:\Program Files\<DIR> SymplisIT
[06/08/2009|11:53] C:\Program Files\<DIR> TeamViewer
[03/06/2008|01:00] C:\Program Files\<DIR> The Weather Channel FW
[11/16/2007|03:30] C:\Program Files\<DIR> ToniArts
[06/09/2009|04:50] C:\Program Files\<DIR> Trend Micro
[06/09/2009|02:58] C:\Program Files\<DIR> TuneUp Utilities 2009
[07/24/2007|09:34] C:\Program Files\<DIR> UIU
[07/21/2007|04:21] C:\Program Files\<DIR> Uninstall Information
[05/17/2009|09:22] C:\Program Files\<DIR> uTorrent
[06/08/2009|11:56] C:\Program Files\<DIR> Ventrilo
[05/23/2009|12:31] C:\Program Files\<DIR> VideoLAN
[05/19/2009|11:04] C:\Program Files\<DIR> Vuze
[02/26/2008|12:02] C:\Program Files\<DIR> Wal-Mart
[08/25/2007|06:02] C:\Program Files\<DIR> Windows Media Connect 2
[08/19/2008|05:10] C:\Program Files\<DIR> Windows Media Player
[08/19/2008|05:10] C:\Program Files\<DIR> Windows NT
[07/23/2007|11:35] C:\Program Files\<DIR> WindowsUpdate
[03/09/2009|04:25] C:\Program Files\<DIR> WinZip
[07/21/2007|04:08] C:\Program Files\<DIR> xerox
[05/24/2009|01:48] C:\Program Files\<DIR> Xilisoft
[06/09/2009|03:03] C:\Program Files\<DIR> Yahoo!

--------------------\\ Listing Folders in C:\Program Files\Common Files

[02/25/2008|11:59] C:\Program Files\Common Files\<DIR> Adobe
[06/12/2009|08:31] C:\Program Files\Common Files\<DIR> Adobe AIR
[05/20/2009|02:23] C:\Program Files\Common Files\<DIR> Ahead
[06/21/2008|10:46] C:\Program Files\Common Files\<DIR> AVSMedia
[06/12/2009|05:14] C:\Program Files\Common Files\<DIR> COWON
[07/23/2007|02:52] C:\Program Files\Common Files\<DIR> Designer
[08/15/2007|11:10] C:\Program Files\Common Files\<DIR> Download Manager
[01/03/2008|05:39] C:\Program Files\Common Files\<DIR> DVDVideoSoft
[06/08/2009|12:23] C:\Program Files\Common Files\<DIR> Eyewitness News Alert
[02/26/2008|12:02] C:\Program Files\Common Files\<DIR> HP
[01/29/2008|02:31] C:\Program Files\Common Files\<DIR> InstallShield
[01/03/2008|11:17] C:\Program Files\Common Files\<DIR> Kodak
[05/20/2009|02:24] C:\Program Files\Common Files\<DIR> LightScribe
[05/17/2009|02:25] C:\Program Files\Common Files\<DIR> Microsoft Shared
[07/21/2007|04:05] C:\Program Files\Common Files\<DIR> MSSoap
[07/21/2007|11:43] C:\Program Files\Common Files\<DIR> ODBC
[02/27/2008|08:06] C:\Program Files\Common Files\<DIR> Real
[07/21/2007|04:05] C:\Program Files\Common Files\<DIR> Services
[07/21/2007|11:43] C:\Program Files\Common Files\<DIR> SpeechEngines
[03/02/2008|04:22] C:\Program Files\Common Files\<DIR> SWF Studio
[01/22/2008|09:27] C:\Program Files\Common Files\<DIR> Symantec Shared
[08/19/2008|05:10] C:\Program Files\Common Files\<DIR> System
[06/16/2009|10:46] C:\Program Files\Common Files\<DIR> Uninstall
[06/14/2009|05:04] C:\Program Files\Common Files\<DIR> Wise Installation Wizard

--------------------\\ Process

( 44 Processes )

... OK !

--------------------\\ Searching with S_Lop

No Lop folder found !

--------------------\\ Searching for Lop Files - Folders

C:\DOCUME~1\Janet\Cookies\janet@adultfriendfinder[1].txt

--------------------\\ Searching within the Registry

..... OK !

--------------------\\ Checking the Hosts file

Hosts file CLEAN


--------------------\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-18 20:04:56
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Searching for other infections


No other infections found !

[F:1][D:2]-> C:\DOCUME~1\Janet\LOCALS~1\Temp
[F:92][D:0]-> C:\DOCUME~1\Janet\Cookies
[F:33][D:4]-> C:\DOCUME~1\Janet\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Thu 06/18/2009|20:07 - Option : [1]

--------------------\\ Scan completed at 20:07:47
  • 0

#19
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
How is your computer running?


Download RootRepeal.zip and unzip it to your Desktop.
  • Double click RootRepeal.exe to start the program
  • Click on the Report tab at the bottom of the program window
  • Click the Scan button
  • In the Select Scan dialog, check:
    • Drivers
    • Files
    • Processes
    • SSDT
    • Stealth Objects
    • Hidden Services
  • Click the OK button
  • In the next dialog, select all drives showing
  • Click OK to start the scan

    Note: The scan can take some time. DO NOT run any other programs while the scan is running

  • When the scan is complete, the Save Report button will become available
  • Click this and save the report to your Desktop as RootRepeal.txt
  • Go to File, then Exit to close the program
If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on Posted Image to insert the attachment into your post



Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.

  • 0

#20
Wafflemonger

Wafflemonger

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 548 posts
When i ran the first program i g ot this error:

could not read the boot sector. try adjusting the disk access level int he options dialog

And the second one (the virus scan) there was no mentioning of a log anywhere but at the bottom it said "No virus found"

Edited by Wafflemonger, 19 June 2009 - 09:11 PM.

  • 0

#21
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Lets try this:


Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<--- ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.
  • 0

#22
Wafflemonger

Wafflemonger

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 548 posts
Please give me a day or so to complete the requested i'm kinda busy with something i will get back to you.
  • 0

#23
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Ok, Thanks for letting me know :)
  • 0

#24
Wafflemonger

Wafflemonger

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 548 posts
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-26 11:23:19
Windows 5.1.2600 Service Pack 3


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xEC8BA6B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xEC8BA574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xEC8BAA52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xEC8BA14C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xEC8BA64E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xEC8BA08C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xEC8BA0F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xEC8BA76E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xEC8BA72E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xEC8BA8AE]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xEC99CDF0]

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\windows\system32\services.exe[964] @ C:\windows\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\windows\system32\services.exe[964] @ C:\windows\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeSniffers\VideoFilesContentSniffer@RelPattern *.asf?*.avi?*.divx?*.mov?*.mpeg?*.mpg?*.ogm?*.qt?*.rm?*.wmv?*.mkv?*.vob?*.m1v?*.m2v?*.swf?*.fli?*.flc?*.flic?*.dat?*.mp4?*.mpe?*.3gp?*.3g2?*.ts?*.tp?*.trp?*.k3g?*.flv?*.mpg?VIDEO\*.mpg?*.mpe
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}@scansk 0x2D 0xAE 0x38 0x0B ...
Reg HKLM\SOFTWARE\Classes\CLSID\{dd7b763d-e7f1-46a6-8d42-5d8b3599ca37}@Model 293
Reg HKLM\SOFTWARE\Classes\CLSID\{dd7b763d-e7f1-46a6-8d42-5d8b3599ca37}@Therad 42

---- EOF - GMER 1.0.15 ----


There it is, sorry for the very late response.

Edited by Wafflemonger, 26 June 2009 - 09:37 AM.

  • 0

#25
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
No worries :)


Launch Malwarebytes' Anti-Malware
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
  • 0

Advertisements


#26
Wafflemonger

Wafflemonger

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 548 posts
Malwarebytes' Anti-Malware 1.38
Database version: 2340
Windows 5.1.2600 Service Pack 3

6/26/2009 7:45:56 PM
mbam-log-2009-06-26 (19-45-56).txt

Scan type: Quick Scan
Objects scanned: 84200
Time elapsed: 10 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 14
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f5078f1b-c551-11d3-89b9-0000f81fe221} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f5078f1c-c551-11d3-89b9-0000f81fe221} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f5078f1d-c551-11d3-89b9-0000f81fe221} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f5078f1e-c551-11d3-89b9-0000f81fe221} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f5078f1f-c551-11d3-89b9-0000f81fe221} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f5078f20-c551-11d3-89b9-0000f81fe221} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f5078f21-c551-11d3-89b9-0000f81fe221} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f5078f22-c551-11d3-89b9-0000f81fe221} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f5078f25-c551-11d3-89b9-0000f81fe221} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f5078f26-c551-11d3-89b9-0000f81fe221} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f5078f28-c551-11d3-89b9-0000f81fe221} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f5078f29-c551-11d3-89b9-0000f81fe221} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f6d90f10-9c73-11d3-b32e-00c04f990bb4} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\msxml2.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
  • 0

#27
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
I see you have already ran RSIT, so please run random's system information tool (RSIT) again and post the log.
  • 0

#28
Wafflemonger

Wafflemonger

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 548 posts
Logfile of random's system information tool 1.06 (written by random/random)
Run by Janet at 2009-06-28 23:04:58
Microsoft Windows XP Professional Service Pack 3
System drive C: has 43 GB (38%) free of 114 GB
Total RAM: 375 MB (30% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:06:08 PM, on 6/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\windows\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\windows\System32\svchost.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\windows\System32\svchost.exe
C:\windows\System32\TUProgSt.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\TeamViewer\Version4\TeamViewer.exe
C:\Documents and Settings\Janet\Desktop\RSIT.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Program Files\Trend Micro\HijackThis\Janet.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cm.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.c...spx?tb_id=60341
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.c...aspx?TbId=60341
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: www.safer-networking.org
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide....ageUploader.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadbl...ivex/sabspx.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.ado...obat/nos/gp.cab
O16 - DPF: {D8AA889B-2C65-47C3-8C16-3DCD4EF76A47} - http://rms2.invokeso...1450/MILive.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcp.../pcpitstop2.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Update Service (gupdate1c9ec3811168202) (gupdate1c9ec3811168202) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\windows\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\windows\System32\TUProgSt.exe

--
End of file - 7867 bytes

======Scheduled tasks folder======

C:\windows\tasks\1-Click Maintenance.job
C:\windows\tasks\Ad-Aware Update (Weekly).job
C:\windows\tasks\AppleSoftwareUpdate.job
C:\windows\tasks\GoogleUpdateTaskMachine.job
C:\windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
C:\windows\tasks\User_Feed_Synchronization-{06206F48-BC9B-451C-B31E-EC15954979E3}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2009-02-27 61816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
Yahoo! IE Services Button - C:\Program Files\Yahoo!\Common\yiesrvc.dll [2007-12-12 222448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{69A87B7D-DE56-4136-9655-716BA50C19C7}]
&Google Web Accelerator Helper - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll [2007-07-09 311296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-06-09 41368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-06-09 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - Google Web Accelerator - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll [2007-07-09 311296]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-02-05 81000]
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2009-03-09 515416]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2009-06-17 414992]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\windows\system32\ctfmon.exe [2008-04-13 15360]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2009-06-26 1830128]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe [2007-03-09 63712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2007-10-10 39792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CARPService]
C:\windows\system32\carpserv.exe [2001-12-22 4608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX5400]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE [2003-05-26 99840]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe [2004-01-16 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\system32\igfxtray.exe [2004-01-16 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MegaPanel]
C:\Program Files\ACNielsen\Homescan Internet Transporter\HSTrans.exe [2006-05-11 2064384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2006-01-12 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2009-05-26 413696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Belkin Wireless G Desktop Card Client Utility.lnk]
C:\PROGRA~1\Belkin\PCIF5D~1\WIRELE~1\BELKIN~1.EXE [2006-08-14 1556480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
C:\DOCUME~1\Janet\MYDOCU~1\KODAKE~1\bin\EASYSH~1.EXE [2007-09-19 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~2\Office\OSA9.EXE [1999-02-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Google Web Accelerator.lnk]
C:\PROGRA~1\Google\WEBACC~1\GOOGLE~2.EXE [2007-07-09 1134592]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Janet^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Janet^Start Menu^Programs^Startup^MP3 Rocket (Minimized).lnk]
[]

C:\Documents and Settings\Janet\Start Menu\Programs\Startup
ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2008-12-22 356352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxsrvc.dll [2004-01-16 335872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\windows\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\windows\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoViewOnDrive"=0
"NoLogoff"=0
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\WINDOWS\system32\spool\drivers\w32x86\3\SAGENT4.EXE"="C:\WINDOWS\system32\spool\drivers\w32x86\3\SAGENT4.EXE:*:Enabled:SAgent4"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Documents and Settings\Janet\My Documents\Kodak EasyShare software\bin\EasyShare.exe"="C:\Documents and Settings\Janet\My Documents\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Belkin\PCI F5D700F\Wireless Utility\Belkinwcui.exe"="C:\Program Files\Belkin\PCI F5D700F\Wireless Utility\Belkinwcui.exe:*:Enabled:Belkin Wireless G Desktop Card Cleint Utility"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\TeamViewer\Version4\TeamViewer.exe"="C:\Program Files\TeamViewer\Version4\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application"
"C:\Program Files\Ventrilo\Ventrilo.exe"="C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware"
"C:\Documents and Settings\Janet\Desktop\spybotsd162.exe"="C:\Documents and Settings\Janet\Desktop\spybotsd162.exe:*:Enabled:spybotsd162"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2009-06-23 16:45:01 ----AD---- C:\Program Files\advrcntr2
2009-06-23 16:43:25 ----A---- C:\Program Files\advrcntr2.exe
2009-06-23 16:24:36 ----A---- C:\Program Files\registryboosterplc.exe
2009-06-22 21:20:23 ----A---- C:\Program Files\WGAPluginInstall.exe
2009-06-21 19:46:14 ----DC---- C:\Documents and Settings\Janet\Application Data\Nero
2009-06-21 19:43:53 ----DC---- C:\Documents and Settings\All Users\Application Data\Nero
2009-06-21 19:43:52 ----D---- C:\Program Files\Common Files\Nero
2009-06-21 14:31:18 ----DC---- C:\Documents and Settings\Janet\Application Data\Canneverbe_Limited
2009-06-21 14:30:46 ----D---- C:\Program Files\CDBurnerXP
2009-06-21 14:26:30 ----A---- C:\Program Files\cdbxp_setup_4.2.4.1351.exe
2009-06-20 03:37:58 ----A---- C:\Program Files\wrar39b3.exe
2009-06-19 21:21:24 ----DC---- C:\Documents and Settings\Janet\Application Data\WinRAR
2009-06-19 21:19:02 ----D---- C:\Program Files\WinRAR
2009-06-19 14:38:18 ----D---- C:\Program Files\sherlock2.0
2009-06-19 11:37:12 ----A---- C:\Program Files\AVSSystemInfo.exe
2009-06-19 10:51:27 ----DC---- C:\Documents and Settings\Janet\Application Data\AVS4YOU
2009-06-19 10:48:32 ----A---- C:\windows\system32\mfc70.dll
2009-06-19 10:40:42 ----DC---- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2009-06-19 10:10:23 ----A---- C:\Program Files\wmpfirefoxplugin.exe
2009-06-19 07:50:02 ----A---- C:\Program Files\flashplayer_10_ax_debug.exe
2009-06-18 19:57:24 ----AC---- C:\lopR.txt
2009-06-18 19:55:01 ----DC---- C:\Lop SD
2009-06-18 14:41:21 ----DC---- C:\Documents and Settings\Janet\Application Data\vlc
2009-06-18 14:23:30 ----A---- C:\Program Files\vlc-1.0.0-rc4-win32.exe
2009-06-18 11:53:35 ----DC---- C:\rsit
2009-06-18 02:33:50 ----A---- C:\Program Files\install_flash_player.exe
2009-06-17 00:07:59 ----DC---- C:\Documents and Settings\All Users\Application Data\Google
2009-06-16 17:41:42 ----A---- C:\Program Files\utorrent.exe
2009-06-16 14:52:53 ----A---- C:\windows\SchedLgU.Txt
2009-06-16 10:59:08 ----A---- C:\Program Files\Setup-349cc72_02018-4.exe
2009-06-16 10:46:06 ----D---- C:\Program Files\Common Files\Uninstall
2009-06-16 10:45:37 ----D---- C:\Program Files\PAV
2009-06-16 04:25:40 ----D---- C:\Program Files\Mozilla Firefox
2009-06-15 04:22:29 ----AC---- C:\Rooter.txt
2009-06-14 17:05:17 ----DC---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-14 17:04:51 ----D---- C:\Program Files\SUPERAntiSpyware
2009-06-14 17:04:50 ----DC---- C:\Documents and Settings\Janet\Application Data\SUPERAntiSpyware.com
2009-06-14 15:47:32 ----A---- C:\windows\wininit.ini
2009-06-14 14:55:39 ----DC---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-14 14:55:39 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-06-14 01:24:49 ----HDC---- C:\windows\$NtUninstallKB961501$
2009-06-14 01:24:31 ----HDC---- C:\windows\$NtUninstallKB969898$
2009-06-14 01:21:07 ----HDC---- C:\windows\$NtUninstallKB970238$
2009-06-14 01:20:32 ----HDC---- C:\windows\$NtUninstallKB968537$
2009-06-13 11:02:48 ----A---- C:\Program Files\GoogleEarthPluginSetup.exe
2009-06-13 09:17:23 ----A---- C:\Program Files\GoogleToolbarInstaller_en_signed.exe
2009-06-13 09:10:55 ----DC---- C:\Documents and Settings\All Users\Application Data\Apple Computer
2009-06-13 09:09:49 ----D---- C:\Program Files\Apple Software Update
2009-06-13 09:09:48 ----DC---- C:\Documents and Settings\All Users\Application Data\Apple
2009-06-13 09:08:28 ----A---- C:\Program Files\QuickTimeInstaller.exe
2009-06-13 08:58:43 ----AC---- C:\Bug.txt
2009-06-13 08:58:20 ----DC---- C:\32788R22FWJFW
2009-06-12 23:37:42 ----AC---- C:\ComboFix.txt
2009-06-12 21:19:24 ----A---- C:\windows\zip.exe
2009-06-12 21:19:24 ----A---- C:\windows\SWXCACLS.exe
2009-06-12 21:19:24 ----A---- C:\windows\SWSC.exe
2009-06-12 21:19:24 ----A---- C:\windows\SWREG.exe
2009-06-12 21:19:24 ----A---- C:\windows\sed.exe
2009-06-12 21:19:24 ----A---- C:\windows\PEV.exe
2009-06-12 21:19:24 ----A---- C:\windows\NIRCMD.exe
2009-06-12 21:19:24 ----A---- C:\windows\grep.exe
2009-06-12 21:18:57 ----A---- C:\windows\system32\CF15232.exe
2009-06-12 18:56:27 ----DC---- C:\Qoobox
2009-06-12 18:34:44 ----DC---- C:\_OTL
2009-06-12 17:49:57 ----DC---- C:\Documents and Settings\Janet\Application Data\COWON
2009-06-12 17:13:16 ----D---- C:\Program Files\Common Files\COWON
2009-06-12 17:13:07 ----D---- C:\Program Files\JetAudio
2009-06-12 17:10:14 ----A---- C:\Program Files\JAD7_BASIC.exe
2009-06-12 12:03:02 ----A---- C:\Program Files\SUPERsetup.exe
2009-06-12 11:30:08 ----A---- C:\Program Files\vlc-1.0.0-rc3-win32.exe
2009-06-12 11:24:21 ----A---- C:\Program Files\utorrent-1.8.3-beta-15619.upx.exe
2009-06-12 11:02:20 ----A---- C:\Program Files\GoogleEarth-Win-Plus-5.0.11733.9347.exe
2009-06-12 10:39:23 ----A---- C:\Program Files\Firefox Setup 3.5 Beta 99.exe
2009-06-12 10:17:17 ----A---- C:\Program Files\SpywareTerminatorSetup.exe
2009-06-12 10:13:44 ----A---- C:\Program Files\Shockwave_Installer_Full.exe
2009-06-12 08:39:49 ----A---- C:\Program Files\mbam-setup.exe
2009-06-12 08:37:29 ----A---- C:\Program Files\LimeWireWin.exe
2009-06-12 08:35:06 ----A---- C:\Program Files\install_flash_player_10.exe
2009-06-12 08:33:24 ----A---- C:\Program Files\Firefox Setup 3.0.11.exe
2009-06-12 08:30:24 ----A---- C:\Program Files\AdobeAIRInstaller.exe
2009-06-12 08:26:16 ----HDC---- C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-12 08:25:57 ----D---- C:\Program Files\Lavasoft
2009-06-12 08:22:44 ----A---- C:\Program Files\Ad-AwareAE.exe
2009-06-12 08:14:00 ----A---- C:\Program Files\FHSetup.exe
2009-06-09 17:20:55 ----D---- C:\windows\ERDNT
2009-06-09 17:20:38 ----D---- C:\Program Files\ERUNT
2009-06-09 17:07:40 ----DC---- C:\Rooter$
2009-06-09 16:58:38 ----DC---- C:\Documents and Settings\Janet\Application Data\Malwarebytes
2009-06-09 16:58:26 ----DC---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-06-09 16:58:25 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-06-09 16:50:39 ----D---- C:\Program Files\Trend Micro
2009-06-09 16:47:57 ----D---- C:\Program Files\SpywareBlaster
2009-06-09 02:58:09 ----A---- C:\windows\system32\TUProgSt.exe
2009-06-09 02:58:05 ----A---- C:\windows\system32\uxtuneup.dll
2009-06-09 02:58:02 ----A---- C:\windows\system32\TuneUpDefragService.exe
2009-06-09 02:57:48 ----DC---- C:\Documents and Settings\Janet\Application Data\TuneUp Software
2009-06-09 02:56:25 ----DC---- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2009-06-09 02:56:16 ----D---- C:\Program Files\TuneUp Utilities 2009
2009-06-09 02:55:25 ----SHDC---- C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-06-09 01:24:23 ----A---- C:\windows\system32\aswBoot.exe
2009-06-09 01:24:19 ----D---- C:\Program Files\Alwil Software
2009-06-09 01:09:45 ----A---- C:\windows\system32\javaws.exe
2009-06-09 01:09:45 ----A---- C:\windows\system32\javaw.exe
2009-06-09 01:09:45 ----A---- C:\windows\system32\java.exe
2009-06-09 01:09:19 ----D---- C:\Program Files\Java
2009-06-08 23:56:44 ----D---- C:\Program Files\Ventrilo
2009-06-08 23:56:42 ----A---- C:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2009-06-08 23:53:36 ----DC---- C:\Documents and Settings\Janet\Application Data\TeamViewer
2009-06-08 23:53:21 ----D---- C:\Program Files\TeamViewer
2009-06-06 13:16:55 ----A---- C:\windows\system32\ChCfg.exe
2009-06-06 13:15:42 ----D---- C:\Program Files\Realtek AC97
2009-06-06 13:15:39 ----A---- C:\windows\system32\RTLCPL.exe
2009-06-06 13:15:37 ----A---- C:\windows\soundman.exe
2009-06-06 13:15:36 ----A---- C:\windows\system32\RtlCPAPI.dll
2009-06-06 13:14:57 ----A---- C:\Program Files\WDM_A406.exe
2009-06-06 13:07:34 ----A---- C:\Program Files\ccsetup220.exe

======List of files/folders modified in the last 1 months======

2009-06-28 23:06:16 ----D---- C:\windows\Temp
2009-06-28 23:05:04 ----D---- C:\windows\Prefetch
2009-06-28 14:50:10 ----D---- C:\windows\system32\CatRoot2
2009-06-26 19:48:03 ----D---- C:\windows\system32\drivers
2009-06-26 19:48:03 ----D---- C:\windows\system32
2009-06-26 19:46:11 ----RSHDC---- C:\windows\system32\dllcache
2009-06-26 10:30:24 ----D---- C:\WINDOWS
2009-06-25 14:15:47 ----SD---- C:\windows\Tasks
2009-06-25 04:36:00 ----D---- C:\Program Files\RegScrubXP
2009-06-25 04:29:47 ----D---- C:\windows\Debug
2009-06-24 15:09:49 ----D---- C:\Program Files
2009-06-24 15:00:19 ----AC---- C:\windows\NeroDigital.ini
2009-06-23 21:18:05 ----D---- C:\Program Files\DivX
2009-06-23 17:52:32 ----SHD---- C:\windows\Installer
2009-06-23 17:52:01 ----D---- C:\Program Files\Google
2009-06-23 16:33:40 ----HDC---- C:\Documents and Settings\All Users\Application Data\~0
2009-06-22 15:46:21 ----DC---- C:\Documents and Settings\Janet\Application Data\uTorrent
2009-06-22 13:33:26 ----DC---- C:\DVD_VIDEO
2009-06-21 21:20:00 ----D---- C:\epson
2009-06-21 19:44:36 ----D---- C:\Program Files\Nero
2009-06-21 19:43:52 ----D---- C:\Program Files\Common Files
2009-06-21 13:38:36 ----D---- C:\windows\network diagnostic
2009-06-20 15:18:46 ----DC---- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2009-06-20 15:15:04 ----D---- C:\Program Files\DVD Shrink
2009-06-20 14:56:47 ----D---- C:\Program Files\Common Files\Ahead
2009-06-20 09:12:14 ----HD---- C:\windows\inf
2009-06-19 23:17:32 ----D---- C:\windows\system32\Macromed
2009-06-19 16:22:38 ----D---- C:\Program Files\AVS4YOU
2009-06-19 12:31:12 ----DC---- C:\Documents and Settings\Janet\Application Data\Yahoo!
2009-06-19 10:51:09 ----D---- C:\Program Files\Common Files\AVSMedia
2009-06-19 10:49:29 ----RSD---- C:\windows\Fonts
2009-06-19 07:53:27 ----SD---- C:\windows\Downloaded Program Files
2009-06-18 11:48:11 ----ADC---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-06-16 19:59:20 ----D---- C:\windows\Help
2009-06-14 17:04:01 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-06-14 15:47:29 ----D---- C:\windows\Cache
2009-06-14 01:25:15 ----D---- C:\Program Files\Internet Explorer
2009-06-14 01:25:04 ----D---- C:\windows\ie8updates
2009-06-14 01:24:58 ----HD---- C:\windows\$hf_mig$
2009-06-13 09:21:11 ----D---- C:\Program Files\LimeWire
2009-06-13 09:11:59 ----D---- C:\Program Files\QuickTime
2009-06-12 22:46:43 ----AC---- C:\windows\system.ini
2009-06-12 21:29:16 ----D---- C:\windows\system32\config
2009-06-12 21:25:14 ----D---- C:\windows\AppPatch
2009-06-12 21:10:56 ----DC---- C:\Documents and Settings\All Users\Application Data\PC Tools
2009-06-12 17:13:03 ----HD---- C:\Program Files\InstallShield Installation Information
2009-06-12 11:21:34 ----D---- C:\Documents and Settings\Janet\Application Data\LimeWire
2009-06-12 08:31:18 ----DC---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-06-12 08:31:01 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-06-12 08:28:00 ----DC---- C:\windows\system32\DRVSTORE
2009-06-12 08:25:57 ----DC---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-06-12 08:25:48 ----D---- C:\windows\WinSxS
2009-06-09 23:19:09 ----SHD---- C:\System Volume Information
2009-06-09 23:19:09 ----D---- C:\windows\system32\Restore
2009-06-09 03:18:16 ----A---- C:\windows\RTacDbg.txt
2009-06-09 03:18:14 ----DC---- C:\Documents and Settings\Janet\Application Data\DNA
2009-06-09 03:03:06 ----D---- C:\Program Files\Yahoo!
2009-06-09 02:43:33 ----D---- C:\Program Files\DNA
2009-06-09 02:06:20 ----SHD---- C:\RECYCLER
2009-06-09 01:09:26 ----A---- C:\windows\system32\deploytk.dll
2009-06-09 00:22:28 ----D---- C:\Program Files\SwiftKit
2009-06-08 23:55:02 ----DC---- C:\Documents and Settings\All Users\Application Data\SwiftKit
2009-06-08 12:23:17 ----D---- C:\Program Files\Common Files\Eyewitness News Alert
2009-06-06 16:42:12 ----SD---- C:\Documents and Settings\Janet\Application Data\Microsoft
2009-06-06 14:15:27 ----D---- C:\Program Files\Grisoft
2009-06-06 13:16:23 ----D---- C:\windows\system32\ReinstallBackups
2009-06-06 13:08:59 ----D---- C:\Program Files\CCleaner
2009-06-06 13:02:52 ----D---- C:\windows\Minidump
2009-06-06 00:55:02 ----RSD---- C:\windows\assembly
2009-05-31 12:50:40 ----AC---- C:\windows\system32\results.txt

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\windows\system32\drivers\Aavmker4.sys [2009-02-05 26944]
R1 aswSP;avast! Self Protection; C:\windows\system32\drivers\aswSP.sys [2009-02-05 114768]
R1 aswTdi;avast! Network Shield Support; C:\windows\system32\drivers\aswTdi.sys [2009-02-05 51376]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.5.0; C:\windows\system32\DRIVERS\AegisP.sys [2009-05-31 21035]
R2 aswFsBlk;aswFsBlk; C:\windows\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
R2 aswMon2;avast! Standard Shield Support; C:\windows\system32\drivers\aswMon2.sys [2009-02-05 94032]
R2 mdmxsdk;mdmxsdk; C:\windows\system32\DRIVERS\mdmxsdk.sys [2001-10-21 9855]
R2 StreamDispatcher;StreamDispatcher; C:\windows\system32\DRIVERS\strmdisp.sys [2001-12-22 33548]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\windows\system32\drivers\ALCXWDM.SYS [2008-09-24 4122368]
R3 als4k;Avance Audio Miniport Driver (WDM); C:\windows\system32\drivers\als4000.sys [2001-10-22 28919]
R3 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr.sys [2009-02-05 23152]
R3 Belkin700F;Belkin Wireless G Desktop Card Service v7; C:\windows\system32\DRIVERS\BLKWGDv7.sys [2006-10-19 303616]
R3 HidUsb;Microsoft HID Class Driver; C:\windows\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\windows\system32\DRIVERS\ialmnt5.sys [2004-01-16 666109]
R3 MBAMProtector;MBAMProtector; \??\C:\windows\system32\drivers\mbam.sys []
R3 mouhid;Mouse HID Driver; C:\windows\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 pcouffin;VSO Software pcouffin; C:\windows\System32\Drivers\pcouffin.sys [2008-06-03 47360]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\windows\System32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\windows\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\windows\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\windows\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 kbdhid;Keyboard HID Driver; C:\windows\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S3 CCDECODE;Closed Caption Decoder; C:\windows\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 FTDIBUS;USB Serial Converter Driver; C:\windows\system32\drivers\ftdibus.sys [2005-12-19 28449]
S3 FTSER2K;USB Serial Port Driver; C:\windows\system32\drivers\ftser2k.sys [2005-12-19 60572]
S3 HSF_DP;HSF_DP; C:\windows\system32\DRIVERS\HSF_DP.sys [2001-12-22 1171488]
S3 HSFHWBS2;HSFHWBS2; C:\windows\system32\DRIVERS\HSFHWBS2.sys [2001-12-22 160083]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\windows\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera; C:\windows\system32\DRIVERS\mr97310v.sys [2004-03-30 118106]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\windows\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\windows\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\windows\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 SABProcEnum;SABProcEnum; \??\C:\Program Files\Internet Explorer\SABProcEnum.sys []
S3 sermouse;Serial Mouse Driver; C:\windows\System32\DRIVERS\sermouse.sys [2001-08-17 17664]
S3 SjyPkt;SjyPkt; \??\C:\windows\System32\Drivers\SjyPkt.sys []
S3 SLIP;BDA Slip De-Framer; C:\windows\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\windows\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 TVICHW32;TVICHW32; \??\C:\windows\system32\DRIVERS\TVICHW32.SYS []
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\windows\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\windows\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Usbscan; C:\windows\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\windows\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 winachsf;winachsf; C:\windows\system32\DRIVERS\HSF_CNXT.sys [2001-12-22 591536]
S3 WpdUsb;WpdUsb; C:\windows\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\windows\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\windows\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\windows\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-02-05 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-02-05 138680]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-06-09 152984]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-09 951632]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-12-14 61440]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2009-06-17 195856]
R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2008-10-20 71096]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; C:\windows\System32\TUProgSt.exe [2009-06-09 604416]
R2 UxTuneUp;TuneUp Theme Extension; C:\windows\System32\svchost.exe [2008-04-13 14336]
R2 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\windows\system32\svchost.exe [2008-04-13 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-02-05 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-02-05 352920]
S2 gupdate1c9ec3811168202;Google Update Service (gupdate1c9ec3811168202); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-06-13 133104]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 getPlus® Helper;getPlus® Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2009-03-03 33176]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\windows\System32\TuneUpDefragService.exe [2009-06-09 361216]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe []

-----------------EOF-----------------

There's the log, once again sorry for the late response.
  • 0

#29
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Hi Wafflemonger,

How is your computer running?
  • 0

#30
Wafflemonger

Wafflemonger

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 548 posts
It's running a lot better now thank you!
  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP