This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] After Removing Some Trojans I am now unable to connect t

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Actually I can't connect to the internet unless I am in safe mode. I've run Norman Malware, AVG, Malwarebytes, Superantispyware with the latest updates (Martch 11th) and all scans come up clean. Unsure of what to do now as my searches seem to bring up only unique solutions for each individual. Thanks in advance for any assistance. I've attached the HijackThis log file run is safe mode.

RMH

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:11:49 AM, on 3/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TELUS_McciTrayApp] C:\Program Files\TELUS\TELUS Support Centre\bin\McciTrayApp.exe
O4 - HKLM\..\Run: [TEPA.exe] "C:\Program Files\TELUS\eProtect Advisor\TEPA.exe" /AUTORUN
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [e7c3htdnpvp] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wfzv9w.exe
O4 - HKCU\..\Run: [h0gq8ozqegvo6fmzm4dle85asrpwlmte4d3e7jyvvpttf] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cjb6j4.exe
O4 - HKCU\..\Run: [d9cpa5nzw] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\eqor2qej.exe
O4 - HKCU\..\Run: [cuac1n219mwsmtt4ynhserwlomv] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\m6qs7nk.exe
O4 - HKCU\..\Run: [iroc5eqi1b1blryh3m8pfu6ylq0oe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nu5oojrvz7jas.exe
O4 - HKCU\..\Run: [v4y6q5r4g3] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ttidhr21f.exe
O4 - HKCU\..\Run: [v1jd00uta8v5nlji18yjl0] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cbflalcv14.exe
O4 - HKCU\..\Run: [uwwwzhjwodf7n21xf] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\i57c4w3l.exe
O4 - HKCU\..\Run: [btvj4ad93itqsjnkux7g5l0bah1mapy] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\anxgtii.exe
O4 - HKCU\..\Run: [gzcey3gahn6midnwv5c7wrkkvg8wlsj5e] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\h4rt95.exe
O4 - HKCU\..\Run: [jiehq417w0fqsvz94pdqcwucwjx] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\baq3mo9.exe
O4 - HKCU\..\Run: [zx2889vn5h35kd4kgk5c] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cbq4jlawnizc.exe
O4 - HKCU\..\Run: [vmm30b9coxd7cgjwggxa2f07xsjh25uxifazh] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xrjteldvw4zz.exe
O4 - HKCU\..\Run: [sgy4fclhw] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\g4dz8k3cc.exe
O4 - HKCU\..\Run: [kyi5epng5zmpl0otskgm4qgpvusskc9o4ept9ivbtvjj7ufgh5] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\st648ljsrn29e.exe
O4 - HKCU\..\Run: [sey0kbz2yfcgh18ox095xf7nvs9ilw] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\t34i6kaslnso.exe
O4 - HKCU\..\Run: [rg7ru25x4aoun22cbcyr1vq5fwxfd3bsp91c81y3o9ye] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\h5rhsvhb36mgt.exe
O4 - HKCU\..\Run: [kzrltkbvzmqefqfwylxfj] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ifwfjv.exe
O4 - HKCU\..\Run: [j71np70c8tjhi422tkextkvmq] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\t3fif3.exe
O4 - HKCU\..\Run: [b9psbsyod1fbzireviuae3oqfb7bocx9m24jup78rdvp2qkxu] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\gvt3uw.exe
O4 - HKCU\..\Run: [h5u2pq3ry5q9jab555yifycoanw967] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\lba2f9nhx.exe
O4 - HKCU\..\Run: [qxqn7w603vgvmbllktdu6v5yfysn] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qjyv828y8.exe
O4 - HKCU\..\Run: [ip9o1kh7vrd82su6] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jbte55oes.exe
O4 - HKCU\..\Run: [e4vy7bbqbf0kuhmbkvdh9q5jgmk0a2by6avr15vm0r2whfm9] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cy5wcazgcb.exe
O4 - HKCU\..\Run: [nz2xio5vr724xz9zna846] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jgchemcb.exe
O4 - HKCU\..\Run: [yl5a0y0eavf1r52fbnz11t245f6lmi0iyaxrxbnz4uzyqa] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\uqbgwqmysn5.exe
O4 - HKCU\..\Run: [a33l1g0rk5c91jyqsf3er06slj167h86tfdtwxp6dfu] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\n15fabs.exe
O4 - HKCU\..\Run: [j7g843tqocefx4nzi9] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ftumrb7cba.exe
O4 - HKCU\..\Run: [r03gpaup0u0] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qhlpx4pw.exe
O4 - HKCU\..\Run: [wor1zu29t8nkhtpw8kynt0f] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cdp01o6ajmk.exe
O4 - HKCU\..\Run: [j95ao9ygvdm99hpf4ey9ffgldnwvuuagqk8h4ybkikznn] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hsc9v18un.exe
O4 - HKCU\..\Run: [yjdgixolohvqmhuf0iu13f2zlmi2fla9mxn3tz] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ihvu1fe0042yp.exe
O4 - HKCU\..\Run: [o8374sy3v83rfacivlqs5s1gzs] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jdw939p1.exe
O4 - HKCU\..\Run: [anvwjasmvf08yr32jn23yvtg36l4og] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ua3st1frdn5h.exe
O4 - HKCU\..\Run: [bpu7rpn3qnn] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xutfoxdpiz4e.exe
O4 - HKCU\..\Run: [wj5f24ptvu9k1uq8vvfnn4j131] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\zq48bs8ktbfh.exe
O4 - HKCU\..\Run: [g3yi6r241z436i8bd3vb] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\swgqixjmdzmfy.exe
O4 - HKCU\..\Run: [c2zsrxs4js6nou8xcs5zrr2tuw2f6afr7knuk0ox73akku] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\o3ickf.exe
O4 - HKCU\..\Run: [dwqqu5fvvxadig] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\blwpep8b4zlwc.exe
O4 - HKCU\..\Run: [e8ntuv55dw013ouuuiwnv] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xxhepo58aielz.exe
O4 - HKCU\..\Run: [dicwqis0gl] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\oj7k7u.exe
O4 - HKCU\..\Run: [k7x5vpi7wn27zg7z] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\vixmq6zbyoc5.exe
O4 - HKCU\..\Run: [zq6186sg3mx5gvzp] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\crzayy.exe
O4 - HKCU\..\Run: [i90d1q9lxqv2fi8oxsdzh4vyqgv9vru0dr52pv0dynsah0n1p] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\un6bx3.exe
O4 - HKCU\..\Run: [cdzdlet85tog5gcnl4z9r67] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\quf0935p5.exe
O4 - HKCU\..\Run: [fyd3g5gr6me7n77flh7eunxp43hh] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fla1s9kdviat.exe
O4 - HKCU\..\Run: [k1infzuu7w1fursznntre8o] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\advpnbg.exe
O4 - HKCU\..\Run: [u6y13sd1t0ued2xxppvq4ckxi2du] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hqjqgp.exe
O4 - HKCU\..\Run: [ohne47dfrh8j2kcbq43a0m18369xq4f2yv3mwgu8oo7g7f] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\pgvqqij3njm97.exe
O4 - HKCU\..\Run: [x308bkrolbzv6rc3jzab22czrc4prsl6sohod] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\dt6j73cmvdel.exe
O4 - HKCU\..\Run: [waa6hw2b6i0lr76kfdoc7s0fco5vjrkgzurtpocjvp] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\b937in1ujjps.exe
O4 - HKCU\..\Run: [vtcande3kqw5qkrq] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\haakicmp3p9t.exe
O4 - HKCU\..\Run: [m2rb91krw9] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\g7c2sd5.exe
O4 - HKCU\..\Run: [fupkv27s63173pe60] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tl6kjkmbfzt.exe
O4 - HKCU\..\Run: [bdeq4w34lgmikeuaw749u] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sh56l52vs.exe
O4 - HKCU\..\Run: [s0x7vrd0xfpaj541nxuq3xmjodts241sg1f] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qrbuc8aqgltg.exe
O4 - HKCU\..\Run: [dpi7urm225rdw70xa8csr9jxxjg1jsu4wl8lwyr] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cuac40agxw3.exe
O4 - HKCU\..\Run: [vhz59wczobgk] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\i3y2lt5n.exe
O4 - HKCU\..\Run: [tsxrrnpgzt613y9ad] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nzmbf5.exe
O4 - HKCU\..\Run: [kc9rzv3jg46ss7y4s9xq96e27rohyn8ss2twdnhs17z] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hn14ytof.exe
O4 - HKCU\..\Run: [o7gudzvgdvyp4wcglaloqchsy] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cd8jnl.exe
O4 - HKCU\..\Run: [n9btovjageuvt7uerpegtt3sxdfkcze43] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ybv7ie.exe
O4 - HKCU\..\Run: [ebwevln43p6wgmync4qkiwimvhj359rx8y79x0tu7by] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\a1v9nj.exe
O4 - HKCU\..\Run: [xi9kbhxra01i6wbz2] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fx0o70kh4.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [c43x559d6csnw6c9oij] C:\WINDOWS\TEMP\yk7n10p72.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [gwhhv3idexbbuk0izkiq5cu5n32zqt775vj6jr] C:\WINDOWS\TEMP\tbm5guhz2.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [qog9arnn69iuswu14nnq40mlfpkgb4xazzr5x8c7x] C:\WINDOWS\TEMP\yvff7804wv.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [rpemb5f06hhq0qxvvzkbes7huag4779gsimdurkj3ub2ol05s1] C:\WINDOWS\TEMP\heylpco.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [vdy24kleokezye6lqt7] C:\WINDOWS\TEMP\j414p2wrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Startup: winlogon.lnk = ?
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - http://www.eversoft.co.kr/vmpinstaller/ins…e_lns4695d.html
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/…trolLite_EN.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab
O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} (Webshots Multiple Media Uploader - Container) - http://community.webshots.com/html/atx/wsaxcontrol.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {9AD9B5EB-F9E0-47D4-B20F-C29D58C6F5E1} (IndeXMap Class) - http://alta.registries.gov.ab.ca/SpinII/cabs/WayToIndex.CAB
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://66.242.36.104/app/view22RTE.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter hijack: text/html - {4683b2ef-765e-484d-a516-7644da09ebe5} - C:\WINDOWS\system32\msiebbar.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

–
End of file - 16179 bytes
hello

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    msconfig
    safebootminimal
    safebootnetwork
    activex
    %systemroot%\System32\antiwpa.dll
    %systemroot%\SYSTEM32\wpa.dll
    %systemroot%\setup\scripts\biestart.exe
    %systemroot%\system32\drivers\royal.sys
    %systemroot%\system32\serauth1.dll
    %systemroot%\system32\serauth2.dll
    %systemroot%\system32\sysaudio.sys
    %systemroot%\system32\wdmaud.sys
    %systemroot%\system32\aeaudio.sys

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
When I run the program all that it gice for an output is the OTlistlt.txt. I'm running in safe mode if that makes a difference. posted below is the OTlistlt.txt contents, Thanks.

OTListIt logfile created on: 3/12/2009 6:50:38 PM - Run 2
OTListIt2 by OldTimer - Version 2.0.3.5 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.72 Gb Available Physical Memory | 85.83% Memory free
3.85 Gb Paging File | 3.73 Gb Available in Paging File | 96.86% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 55.27 Gb Free Space | 18.54% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: IANCE-3FA06CAA9
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Documents and Settings\Administrator\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aawservice [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
SRV - (Apple Mobile Device [Auto | Stopped]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (ATKKeyboardService [Auto | Stopped]) – C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)
SRV - (Automatic LiveUpdate Scheduler [Auto | Stopped]) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (avg8wd [Auto | Stopped]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Auto | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (ccEvtMgr [Disabled | Stopped]) – File not found
SRV - (ccSetMgr [Auto | Stopped]) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CLTNetCnService [Auto | Stopped]) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (comHost [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Stopped]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LiveUpdate [On_Demand | Stopped]) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (LiveUpdate Notice [Auto | Stopped]) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (MDM [Auto | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NMIndexingService [Disabled | Stopped]) – File not found
SRV - (NVSvc [Auto | Stopped]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Symantec Core LC [Auto | Stopped]) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [Auto | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AsIO [System | Stopped]) – C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (asuskbnt [System | Stopped]) – C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (atksgt [Auto | Stopped]) – C:\WINDOWS\system32\DRIVERS\atksgt.sys ()
DRV - (AvgLdx86 [System | Stopped]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Stopped]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (COH_Mon [On_Demand | Stopped]) – C:\WINDOWS\system32\Drivers\COH_Mon.sys (Symantec Corporation)
DRV - (CO_Mon [Auto | Stopped]) – C:\WINDOWS\system32\drivers\CO_Mon.sys (Symantec Corporation)
DRV - (eeCtrl [System | Stopped]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EIO [Auto | Stopped]) – C:\WINDOWS\system32\drivers\EIO.sys (ASUSTeK Computer Inc.)
DRV - (ENTECH [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ENTECH.sys (EnTech Taiwan)
DRV - (EraserUtilRebootDrv [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (fab2e477 [System | Stopped]) – C:\WINDOWS\System32\drivers\fab2e477.sys ()
DRV - (gameenum [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (grmnusb [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\grmnusb.sys (GARMIN Corp.)
DRV - (idrmkl [On_Demand | Stopped]) – C:\Documents and Settings\Administrator\Local Settings\Temp\idrmkl.sys ()
DRV - (jcuptzlq [Boot | Stopped]) – C:\WINDOWS\system32\drivers\jcuptzlq.sys ()
DRV - (lirsgt [Auto | Stopped]) – C:\WINDOWS\system32\DRIVERS\lirsgt.sys ()
DRV - (motmodem [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\motmodem.sys (Motorola)
DRV - (ms_mpu401 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (MTsensor [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ASACPI.sys ()
DRV - (NAVENG [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080825.034\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080825.034\NAVEX15.SYS (Symantec Corporation)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nvnetbus.sys (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (RT73 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\Dr71WU.sys (Ralink Technology, Corp.)
DRV - (SASDIFSV [System | Stopped]) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Stopped]) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Stopped]) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Secdrv [Auto | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sfdrv01 [Boot | Running]) – C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02 [Boot | Running]) – C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (sfsync02 [Boot | Running]) – C:\WINDOWS\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (SI3132 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\SI3132.sys (Silicon Image, Inc.)
DRV - (SiFilter [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (SiRemFil [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\SiRemFil.sys (Silicon Image, Inc.)
DRV - (SPBBCDrv [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SRTSP [System | Stopped]) – C:\WINDOWS\System32\Drivers\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\SRTSPL.SYS (Symantec Corporation)
DRV - (SRTSPX [System | Stopped]) – C:\WINDOWS\System32\Drivers\SRTSPX.SYS (Symantec Corporation)
DRV - (SYMDNS [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (SymEvent [On_Demand | Stopped]) – C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMFW [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMIDS [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\SYMIDS.SYS (Symantec Corporation)
DRV - (SYMIDSCO [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SymcData\ipsdefs\20080825.001\SymIDSCo.sys (Symantec Corporation)
DRV - (SymIM [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\SymIM.sys (Symantec Corporation)
DRV - (SymIMMP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\SymIM.sys (Symantec Corporation)
DRV - (symlcbrd [Auto | Stopped]) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (SYMNDIS [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMREDRV [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMTDI [System | Stopped]) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (USBCCID [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\usbccid.sys (Microsoft Corporation)
DRV - (yukonwxp [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\yk51x86.sys (Marvell)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - presf.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://drudgereport.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - HKLM\software\mozilla\Firefox\extensions\\[removed] -> %ProgramFiles%\JAVA\JRE6\LIB\DEPLOY\JQS\FF [C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF] -> [2008/12/20 04:27:44 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71} -> %ProgramFiles%\AVG\AVG8\FIREFOX [C:\PROGRAM FILES\AVG\AVG8\FIREFOX] -> [2009/03/08 16:15:22 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components -> %ProgramFiles%\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2009/03/07 15:09:46 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins -> %ProgramFiles%\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2009/03/07 15:09:40 00,000,000 | —D | M]
FF - C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions [2009/03/07 15:10:19 00,000,000 | —D | M]
FF - C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/03/07 15:10:19 00,000,000 | —D | M]
FF - C:\Documents and Settings\Administrator\Application Data\mozilla\Firefox\Profiles\n09x3eqj.default\extensions [2009/03/07 15:11:54 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions [2009/03/09 02:45:01 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2006/11/08 02:13:12 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/03/07 15:09:41 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} [2007/06/16 21:19:58 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} [2007/07/25 17:45:42 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [2007/10/05 01:01:10 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [2008/06/18 00:28:00 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [2008/08/10 13:16:15 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [2008/12/20 04:28:01 00,000,000 | —D | M]

O1 HOSTS File: (646 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install ()
O4 - HKLM..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe" (Symantec Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe (Enigma Software Group USA, LLC.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TELUS_McciTrayApp] C:\Program Files\TELUS\TELUS Support Centre\bin\McciTrayApp.exe File not found
O4 - HKLM..\Run: [TEPA.exe] "C:\Program Files\TELUS\eProtect Advisor\TEPA.exe" /AUTORUN File not found
O4 - HKLM..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u File not found
O4 - HKCU..\Run: [a33l1g0rk5c91jyqsf3er06slj167h86tfdtwxp6dfu] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\n15fabs.exe ()
O4 - HKCU..\Run: [anvwjasmvf08yr32jn23yvtg36l4og] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ua3st1frdn5h.exe ()
O4 - HKCU..\Run: [b9psbsyod1fbzireviuae3oqfb7bocx9m24jup78rdvp2qkxu] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\gvt3uw.exe ()
O4 - HKCU..\Run: [bdeq4w34lgmikeuaw749u] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sh56l52vs.exe ()
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" File not found
O4 - HKCU..\Run: [bpu7rpn3qnn] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xutfoxdpiz4e.exe ()
O4 - HKCU..\Run: [btvj4ad93itqsjnkux7g5l0bah1mapy] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\anxgtii.exe ()
O4 - HKCU..\Run: [c2zsrxs4js6nou8xcs5zrr2tuw2f6afr7knuk0ox73akku] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\o3ickf.exe ()
O4 - HKCU..\Run: [cdzdlet85tog5gcnl4z9r67] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\quf0935p5.exe ()
O4 - HKCU..\Run: [cuac1n219mwsmtt4ynhserwlomv] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\m6qs7nk.exe ()
O4 - HKCU..\Run: [d9cpa5nzw] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\eqor2qej.exe ()
O4 - HKCU..\Run: [dicwqis0gl] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\oj7k7u.exe ()
O4 - HKCU..\Run: [dpi7urm225rdw70xa8csr9jxxjg1jsu4wl8lwyr] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cuac40agxw3.exe ()
O4 - HKCU..\Run: [dwqqu5fvvxadig] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\blwpep8b4zlwc.exe ()
O4 - HKCU..\Run: [e4vy7bbqbf0kuhmbkvdh9q5jgmk0a2by6avr15vm0r2whfm9] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cy5wcazgcb.exe ()
O4 - HKCU..\Run: [e7c3htdnpvp] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wfzv9w.exe ()
O4 - HKCU..\Run: [e8ntuv55dw013ouuuiwnv] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xxhepo58aielz.exe ()
O4 - HKCU..\Run: [ebwevln43p6wgmync4qkiwimvhj359rx8y79x0tu7by] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\a1v9nj.exe ()
O4 - HKCU..\Run: [fupkv27s63173pe60] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tl6kjkmbfzt.exe ()
O4 - HKCU..\Run: [fyd3g5gr6me7n77flh7eunxp43hh] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fla1s9kdviat.exe ()
O4 - HKCU..\Run: [g3yi6r241z436i8bd3vb] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\swgqixjmdzmfy.exe ()
O4 - HKCU..\Run: [gzcey3gahn6midnwv5c7wrkkvg8wlsj5e] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\h4rt95.exe ()
O4 - HKCU..\Run: [h0gq8ozqegvo6fmzm4dle85asrpwlmte4d3e7jyvvpttf] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cjb6j4.exe ()
O4 - HKCU..\Run: [h5u2pq3ry5q9jab555yifycoanw967] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\lba2f9nhx.exe ()
O4 - HKCU..\Run: [i90d1q9lxqv2fi8oxsdzh4vyqgv9vru0dr52pv0dynsah0n1p] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\un6bx3.exe ()
O4 - HKCU..\Run: [ip9o1kh7vrd82su6] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jbte55oes.exe ()
O4 - HKCU..\Run: [iroc5eqi1b1blryh3m8pfu6ylq0oe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nu5oojrvz7jas.exe ()
O4 - HKCU..\Run: [j71np70c8tjhi422tkextkvmq] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\t3fif3.exe ()
O4 - HKCU..\Run: [j7g843tqocefx4nzi9] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ftumrb7cba.exe ()
O4 - HKCU..\Run: [j95ao9ygvdm99hpf4ey9ffgldnwvuuagqk8h4ybkikznn] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hsc9v18un.exe ()
O4 - HKCU..\Run: [jiehq417w0fqsvz94pdqcwucwjx] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\baq3mo9.exe ()
O4 - HKCU..\Run: [k1infzuu7w1fursznntre8o] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\advpnbg.exe ()
O4 - HKCU..\Run: [k7x5vpi7wn27zg7z] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\vixmq6zbyoc5.exe ()
O4 - HKCU..\Run: [kc9rzv3jg46ss7y4s9xq96e27rohyn8ss2twdnhs17z] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hn14ytof.exe ()
O4 - HKCU..\Run: [kyi5epng5zmpl0otskgm4qgpvusskc9o4ept9ivbtvjj7ufgh5] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\st648ljsrn29e.exe ()
O4 - HKCU..\Run: [kzrltkbvzmqefqfwylxfj] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ifwfjv.exe ()
O4 - HKCU..\Run: [m2rb91krw9] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\g7c2sd5.exe ()
O4 - HKCU..\Run: [n9btovjageuvt7uerpegtt3sxdfkcze43] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ybv7ie.exe ()
O4 - HKCU..\Run: [nz2xio5vr724xz9zna846] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jgchemcb.exe ()
O4 - HKCU..\Run: [o7gudzvgdvyp4wcglaloqchsy] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cd8jnl.exe ()
O4 - HKCU..\Run: [o8374sy3v83rfacivlqs5s1gzs] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jdw939p1.exe ()
O4 - HKCU..\Run: [ohne47dfrh8j2kcbq43a0m18369xq4f2yv3mwgu8oo7g7f] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\pgvqqij3njm97.exe ()
O4 - HKCU..\Run: [qxqn7w603vgvmbllktdu6v5yfysn] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qjyv828y8.exe ()
O4 - HKCU..\Run: [r03gpaup0u0] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qhlpx4pw.exe ()
O4 - HKCU..\Run: [rg7ru25x4aoun22cbcyr1vq5fwxfd3bsp91c81y3o9ye] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\h5rhsvhb36mgt.exe ()
O4 - HKCU..\Run: [s0x7vrd0xfpaj541nxuq3xmjodts241sg1f] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qrbuc8aqgltg.exe ()
O4 - HKCU..\Run: [sey0kbz2yfcgh18ox095xf7nvs9ilw] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\t34i6kaslnso.exe ()
O4 - HKCU..\Run: [sgy4fclhw] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\g4dz8k3cc.exe ()
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [tsxrrnpgzt613y9ad] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nzmbf5.exe ()
O4 - HKCU..\Run: [u6y13sd1t0ued2xxppvq4ckxi2du] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hqjqgp.exe ()
O4 - HKCU..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1 (Adobe Systems Incorporated)
O4 - HKCU..\Run: [uwwwzhjwodf7n21xf] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\i57c4w3l.exe ()
O4 - HKCU..\Run: [v1jd00uta8v5nlji18yjl0] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cbflalcv14.exe ()
O4 - HKCU..\Run: [v4y6q5r4g3] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ttidhr21f.exe ()
O4 - HKCU..\Run: [vhz59wczobgk] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\i3y2lt5n.exe ()
O4 - HKCU..\Run: [vmm30b9coxd7cgjwggxa2f07xsjh25uxifazh] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xrjteldvw4zz.exe ()
O4 - HKCU..\Run: [vtcande3kqw5qkrq] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\haakicmp3p9t.exe ()
O4 - HKCU..\Run: [waa6hw2b6i0lr76kfdoc7s0fco5vjrkgzurtpocjvp] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\b937in1ujjps.exe ()
O4 - HKCU..\Run: [wj5f24ptvu9k1uq8vvfnn4j131] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\zq48bs8ktbfh.exe ()
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - HKCU..\Run: [wor1zu29t8nkhtpw8kynt0f] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cdp01o6ajmk.exe ()
O4 - HKCU..\Run: [x308bkrolbzv6rc3jzab22czrc4prsl6sohod] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\dt6j73cmvdel.exe ()
O4 - HKCU..\Run: [xi9kbhxra01i6wbz2] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fx0o70kh4.exe ()
O4 - HKCU..\Run: [yjdgixolohvqmhuf0iu13f2zlmi2fla9mxn3tz] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ihvu1fe0042yp.exe ()
O4 - HKCU..\Run: [yl5a0y0eavf1r52fbnz11t245f6lmi0iyaxrxbnz4uzyqa] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\uqbgwqmysn5.exe ()
O4 - HKCU..\Run: [zq6186sg3mx5gvzp] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\crzayy.exe ()
O4 - HKCU..\Run: [zx2889vn5h35kd4kgk5c] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cbq4jlawnizc.exe ()
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\winlogon.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoAdminPage = 1
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} http://www.eversoft.co.kr/vmpinstaller/ins…e_lns4695d.html (MetaStreamCtl Class)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://downloadcenter.samsung.com/content/…trolLite_EN.cab (DjVuCtl Class)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} http://community.webshots.com/html/atx/wsaxcontrol.cab (Webshots Multiple Media Uploader - Container)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9AD9B5EB-F9E0-47D4-B20F-C29D58C6F5E1} http://alta.registries.gov.ab.ca/SpinII/cabs/WayToIndex.CAB (IndeXMap Class)
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} http://66.242.36.104/app/view22RTE.cab (View22RTE Class)
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} http://www.systemrequirementslab.com/sysreqlab.cab (System Requirements Lab Class)
O16 - DPF: {CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.3.1_18)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O29 - HKLM SecurityProviders - ( digeste.dll) - File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{91634c50-4950-11dc-aac1-0018f3272aea}\Shell\Auto\command - "" = F:\tel.xls.exe – File not found
O33 - MountPoints2\{91634c50-4950-11dc-aac1-0018f3272aea}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{cd96e6d8-521b-11db-8a65-0018f3272aea}\Shell\AutoRun\command - "" = setupSNK.exe

========== Files/Folders - Created Within 30 Days ==========

[15 C:\WINDOWS\*.tmp files]
[2009/03/12 18:44:37 | 00,497,664 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTListIt2.exe
[2009/03/12 01:18:20 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/03/12 01:17:47 | 00,000,611 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\NTREGOPT.lnk
[2009/03/12 01:17:47 | 00,000,592 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\ERUNT.lnk
[2009/03/12 01:17:47 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/03/12 01:16:28 | 00,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Administrator\My Documents\erunt_setup.exe
[2009/03/12 01:11:32 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\HIjackthis Log March11
[2009/03/12 00:52:04 | 00,001,734 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\HijackThis.lnk
[2009/03/12 00:52:04 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/12 00:51:48 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Administrator\My Documents\HJTInstall.exe
[2009/03/12 00:49:28 | 16,434,584 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\jre-6u12-windows-i586-p-s.exe
[2009/03/11 19:15:11 | 00,313,975 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\After virus scan and removal can't connect to the internet.mht
[2009/03/11 19:13:29 | 00,027,742 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Malwarebytes Forum No internet access after removing Trojan_Agent.mht
[2009/03/11 19:05:34 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\av11th
[2009/03/10 21:40:22 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/03/10 21:40:17 | 00,000,780 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/03/10 21:40:16 | 00,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2009/03/10 21:40:16 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
[2009/03/10 21:38:45 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\udats 10
[2009/03/10 21:33:34 | 00,103,624 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\BleepingComputer_com svchost_exe, exception breakpoint, soxpeca, mabidwe.mht
[2009/03/10 21:30:45 | 01,529,241 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\SDFix.exe
[2009/03/10 21:27:54 | 06,018,080 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\SUPERAntiSpywarePro.exe
[2009/03/10 21:12:41 | 00,000,000 | —D | C] – C:\myRTVAULT
[2009/03/10 18:26:28 | 00,000,899 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SpyHunter.lnk
[2009/03/10 18:26:23 | 00,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2009/03/09 23:30:12 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2009/03/09 23:26:41 | 06,068,768 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\SUPERAntiSpyware.exe
[2009/03/09 23:20:52 | 35,257,400 | —- | C] (Norman ASA) – C:\Documents and Settings\Administrator\My Documents\Norman_Malware_Cleaner.exe
[2009/03/09 23:15:51 | 02,132,416 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\My Documents\mbam-rules.exe
[2009/03/09 23:05:11 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/09 23:05:11 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/09 23:05:08 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/09 23:05:07 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/03/09 23:05:07 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/03/09 22:51:16 | 02,876,720 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\My Documents\helppppp.exe
[2009/03/09 22:45:19 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\thdzifan
[2009/03/09 22:45:19 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\thdzifan
[2009/03/09 03:01:49 | 09,764,072 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\SpyHunter-Scanner-Install.exe
[2009/03/09 02:57:59 | 00,374,274 | —- | C] (miekiemoes © 2005 ) – C:\Documents and Settings\Administrator\Desktop\LQfix.exe
[2009/03/09 02:20:13 | 09,764,072 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\SpyHunter-Scanner-Install.exe
[2009/03/09 02:15:15 | 00,446,464 | —- | C] (Proland Software) – C:\Documents and Settings\Administrator\My Documents\cleanpakes.exe
[2009/03/09 02:09:10 | 00,000,000 | —D | C] – C:\WINDOWS\BDOSCAN8
[2009/03/08 19:54:40 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\avg
[2009/03/08 16:16:39 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/03/08 16:15:38 | 00,010,520 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/03/08 16:15:38 | 00,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/03/08 16:15:37 | 00,325,640 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/03/08 16:15:37 | 00,107,912 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/03/08 16:15:36 | 00,027,656 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/03/08 16:15:32 | 33,987,075 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/03/08 16:15:32 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/03/08 16:15:32 | 00,401,372 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/03/08 16:15:32 | 00,033,349 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/03/08 16:15:32 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2009/03/08 16:15:22 | 00,000,000 | —D | C] – C:\Program Files\AVG
[2009/03/08 16:15:22 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/03/08 16:14:15 | 62,270,256 | —- | C] (AVG Technologies) – C:\Documents and Settings\Administrator\My Documents\avg_free_stf_en_85_278a1439.exe
[2009/03/08 14:37:37 | 00,000,434 | —- | C] () – C:\WINDOWS\tasks\At1.job
[2009/03/08 14:37:27 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\fab2e477.sys
[2009/03/08 14:37:16 | 00,000,002 | —- | C] () – C:\-535435166
[2009/03/07 15:09:53 | 00,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/03/07 15:08:50 | 07,522,240 | —- | C] (Mozilla) – C:\Documents and Settings\Administrator\Desktop\Firefox Setup 3.0.7.exe
[2009/03/07 13:06:42 | 00,011,776 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\New Microsoft Excel Worksheet (3).xls
[2009/02/25 22:42:05 | 00,213,024 | —- | C] () – C:\WINDOWS\System32\drivers\str.sys
[2009/02/20 19:06:35 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SWiSHMax2WorkFolder
[2009/02/20 18:59:13 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\Feb20 Adds
[2009/02/20 18:38:06 | 00,002,235 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Souther Agri Services.swf
[2009/02/20 18:22:45 | 00,018,012 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Souther Agri Services.sbk
[2009/02/20 18:22:45 | 00,016,332 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Souther Agri Services.swi
[2009/02/20 18:12:15 | 00,002,071 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\basic add.swi
[2009/02/20 14:15:36 | 02,978,693 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\PowerPoint Backgrounds.zip
[2009/02/20 00:20:10 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\PowerPoint Backgrounds
[2009/02/19 23:46:26 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2009/02/19 23:27:00 | 00,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_motmodem_01005.Wdf
[2009/02/19 23:26:58 | 00,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2009/02/19 23:26:50 | 01,327,601 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\KRZR_K1m_UG_updated.pdf
[2009/02/19 13:03:34 | 00,579,464 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\SymNeti.dll
[2009/02/19 13:03:26 | 00,207,240 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\SymRedir.dll
[2009/02/19 12:31:42 | 00,031,280 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SymIM.sys
[2009/02/19 12:31:42 | 00,009,844 | —- | C] () – C:\WINDOWS\System32\drivers\SymRedir.cat
[2009/02/19 12:31:42 | 00,001,611 | —- | C] () – C:\WINDOWS\System32\drivers\SymRedir.inf
[2009/02/19 12:31:18 | 00,041,008 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symndisv.sys
[2009/02/19 12:31:16 | 00,184,496 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symtdi.sys
[2009/02/19 12:31:16 | 00,096,560 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symfw.sys
[2009/02/19 12:31:16 | 00,038,576 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symids.sys
[2009/02/19 12:31:16 | 00,037,424 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symndis.sys
[2009/02/19 12:31:16 | 00,022,320 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symredrv.sys
[2009/02/19 12:31:16 | 00,013,616 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symdns.sys
[2009/02/16 20:01:18 | 00,004,344 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\BayerCropFeb2009.swf
[2009/02/16 18:13:51 | 00,015,567 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\unfucked.swi
[2009/02/16 18:13:51 | 00,012,838 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\unfucked.sbk
[2009/02/16 18:11:22 | 00,016,439 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\######.swi
[2009/02/16 17:32:05 | 00,110,608 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Taber Small Engine Repair.sbk
[2009/02/16 17:12:39 | 00,005,668 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\exp.sbk
[2009/02/16 17:12:39 | 00,003,456 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\exp.swi
[2009/02/16 17:11:08 | 00,002,079 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\4x8template.swi
[2009/02/16 17:00:38 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\adds Feb16
[2009/02/16 04:14:13 | 00,015,864 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\eye edit copy2.png
[2009/02/16 04:12:33 | 00,010,040 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\eye edit copy.png
[2009/02/16 04:02:33 | 00,136,853 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\eyee.sbk
[2009/02/16 03:53:58 | 00,010,976 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\eyeballs-small.png
[2009/02/16 03:53:54 | 00,007,927 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\eyeball-small.png
[2009/02/14 01:54:30 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\BiGboys
[2009/02/14 01:44:40 | 00,430,273 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\10540 BB Sign- Rick Kawa- Feb.pdf
[2009/02/11 19:22:26 | 00,248,120 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\attachment.jpg

========== Files - Modified Within 30 Days ==========

[5 C:\WINDOWS\System32\*.tmp files]
[15 C:\WINDOWS\*.tmp files]
[2009/03/12 18:44:39 | 00,497,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTListIt2.exe
[2009/03/12 01:17:47 | 00,000,611 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\NTREGOPT.lnk
[2009/03/12 01:17:47 | 00,000,592 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\ERUNT.lnk
[2009/03/12 01:16:31 | 00,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Administrator\My Documents\erunt_setup.exe
[2009/03/12 00:52:04 | 00,001,734 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\HijackThis.lnk
[2009/03/12 00:51:50 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Administrator\My Documents\HJTInstall.exe
[2009/03/12 00:49:28 | 16,434,584 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\jre-6u12-windows-i586-p-s.exe
[2009/03/11 23:32:25 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/11 23:31:43 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/03/11 23:30:24 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/11 19:22:10 | 33,987,075 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/03/11 19:19:19 | 00,092,010 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/03/11 19:18:58 | 00,000,434 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2009/03/11 19:15:14 | 00,313,975 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\After virus scan and removal can't connect to the internet.mht
[2009/03/11 19:13:29 | 00,027,742 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Malwarebytes Forum No internet access after removing Trojan_Agent.mht
[2009/03/10 21:40:17 | 00,000,780 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/03/10 21:39:35 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/03/10 21:39:35 | 00,401,372 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/03/10 21:39:35 | 00,033,349 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/03/10 21:33:35 | 00,103,624 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\BleepingComputer_com svchost_exe, exception breakpoint, soxpeca, mabidwe.mht
[2009/03/10 21:30:51 | 01,529,241 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\SDFix.exe
[2009/03/10 21:27:54 | 06,018,080 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\SUPERAntiSpywarePro.exe
[2009/03/10 18:26:28 | 00,000,899 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SpyHunter.lnk
[2009/03/09 23:33:18 | 35,257,400 | —- | M] (Norman ASA) – C:\Documents and Settings\Administrator\My Documents\Norman_Malware_Cleaner.exe
[2009/03/09 23:26:41 | 06,068,768 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\SUPERAntiSpyware.exe
[2009/03/09 23:15:59 | 02,132,416 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\My Documents\mbam-rules.exe
[2009/03/09 23:05:11 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/09 22:51:27 | 02,876,720 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\My Documents\helppppp.exe
[2009/03/09 03:01:49 | 09,764,072 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\SpyHunter-Scanner-Install.exe
[2009/03/09 02:58:00 | 00,374,274 | —- | M] (miekiemoes © 2005 ) – C:\Documents and Settings\Administrator\Desktop\LQfix.exe
[2009/03/09 02:20:13 | 09,764,072 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\SpyHunter-Scanner-Install.exe
[2009/03/09 02:15:17 | 00,446,464 | —- | M] (Proland Software) – C:\Documents and Settings\Administrator\My Documents\cleanpakes.exe
[2009/03/08 21:23:54 | 00,006,456 | -H– | M] () – C:\WINDOWS\System32\sepinose
[2009/03/08 16:15:38 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/03/08 16:15:38 | 00,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/03/08 16:15:37 | 00,325,640 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/03/08 16:15:37 | 00,107,912 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/03/08 16:15:36 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/03/08 16:14:23 | 62,270,256 | —- | M] (AVG Technologies) – C:\Documents and Settings\Administrator\My Documents\avg_free_stf_en_85_278a1439.exe
[2009/03/08 15:15:04 | 00,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/03/08 15:15:04 | 00,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2009/03/08 15:08:38 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\fab2e477.sys
[2009/03/08 14:42:26 | 00,481,352 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/08 14:42:26 | 00,408,792 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/08 14:42:26 | 00,064,314 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/08 14:39:09 | 00,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/03/08 14:39:09 | 00,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2009/03/08 14:37:18 | 00,000,002 | —- | M] () – C:\-535435166
[2009/03/08 14:37:14 | 00,014,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\svchost.exe
[2009/03/08 14:37:14 | 00,014,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\svchost.exe
[2009/03/08 14:36:56 | 00,102,400 | -HS- | M] () – C:\WINDOWS\System32\wifufulu.dll
[2009/03/08 02:25:50 | 00,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/03/08 02:25:50 | 00,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/03/08 02:23:26 | 00,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/03/08 02:23:26 | 00,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/03/08 02:22:08 | 00,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/03/08 02:22:08 | 00,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/03/08 02:21:41 | 00,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/03/08 02:21:41 | 00,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2009/03/08 02:21:14 | 00,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/03/08 02:21:14 | 00,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2009/03/08 02:19:27 | 00,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/03/08 02:19:27 | 00,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2009/03/08 02:19:00 | 00,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/03/08 02:19:00 | 00,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2009/03/08 02:18:33 | 00,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2009/03/08 02:18:33 | 00,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2009/03/08 02:18:03 | 00,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/03/08 02:18:03 | 00,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2009/03/08 02:17:34 | 00,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/03/08 02:17:34 | 00,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/03/08 02:17:06 | 00,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/03/08 02:17:05 | 00,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/03/08 02:15:35 | 00,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/03/08 02:15:35 | 00,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/03/08 02:15:07 | 00,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/03/08 02:15:07 | 00,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/03/08 02:14:38 | 00,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/03/08 02:14:38 | 00,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/03/08 02:14:09 | 00,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/03/08 02:14:09 | 00,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2009/03/08 02:13:38 | 00,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/03/08 02:13:38 | 00,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2009/03/08 02:13:09 | 00,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/03/08 02:13:09 | 00,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2009/03/08 02:12:40 | 00,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/03/08 02:12:40 | 00,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2009/03/07 18:11:06 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/03/07 15:09:53 | 00,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/03/07 15:08:50 | 07,522,240 | —- | M] (Mozilla) – C:\Documents and Settings\Administrator\Desktop\Firefox Setup 3.0.7.exe
[2009/03/07 13:06:48 | 00,011,776 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\New Microsoft Excel Worksheet (3).xls
[2009/03/02 21:00:08 | 00,000,638 | —- | M] () – C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Administrator.job
[2009/02/27 19:55:49 | 00,213,024 | —- | M] () – C:\WINDOWS\System32\drivers\str.sys
[2009/02/20 18:43:13 | 00,002,235 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Souther Agri Services.swf
[2009/02/20 18:42:43 | 00,016,332 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Souther Agri Services.swi
[2009/02/20 18:38:41 | 00,018,012 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Souther Agri Services.sbk
[2009/02/20 18:12:15 | 00,002,071 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\basic add.swi
[2009/02/20 14:15:40 | 02,978,693 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\PowerPoint Backgrounds.zip
[2009/02/19 23:27:00 | 00,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_motmodem_01005.Wdf
[2009/02/19 23:26:58 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/02/19 23:26:58 | 00,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2009/02/19 23:26:57 | 01,327,601 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\KRZR_K1m_UG_updated.pdf
[2009/02/19 13:03:34 | 00,579,464 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\SymNeti.dll
[2009/02/19 13:03:26 | 00,207,240 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\SymRedir.dll
[2009/02/19 12:31:42 | 00,031,280 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SymIM.sys
[2009/02/19 12:31:42 | 00,009,844 | —- | M] () – C:\WINDOWS\System32\drivers\SymRedir.cat
[2009/02/19 12:31:42 | 00,001,611 | —- | M] () – C:\WINDOWS\System32\drivers\SymRedir.inf
[2009/02/19 12:31:18 | 00,041,008 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symndisv.sys
[2009/02/19 12:31:16 | 00,184,496 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symtdi.sys
[2009/02/19 12:31:16 | 00,096,560 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symfw.sys
[2009/02/19 12:31:16 | 00,038,576 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symids.sys
[2009/02/19 12:31:16 | 00,037,424 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symndis.sys
[2009/02/19 12:31:16 | 00,022,320 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symredrv.sys
[2009/02/19 12:31:16 | 00,013,616 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symdns.sys
[2009/02/16 20:01:18 | 00,004,344 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\BayerCropFeb2009.swf
[2009/02/16 19:13:56 | 00,015,567 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\unfucked.swi
[2009/02/16 19:10:25 | 00,012,838 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\unfucked.sbk
[2009/02/16 18:13:40 | 00,003,557 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\4x8template.swi
[2009/02/16 18:11:22 | 00,016,439 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\######.swi
[2009/02/16 17:43:55 | 00,136,853 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\eyee.sbk
[2009/02/16 17:32:05 | 00,110,608 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Taber Small Engine Repair.sbk
[2009/02/16 17:16:58 | 00,003,456 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\exp.swi
[2009/02/16 17:12:39 | 00,005,668 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\exp.sbk
[2009/02/16 17:11:08 | 00,002,079 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\4x8template.swi
[2009/02/16 04:14:24 | 00,331,776 | -HS- | M] () – C:\Documents and Settings\Administrator\Desktop\Thumbs.db
[2009/02/16 04:14:16 | 00,015,864 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\eye edit copy2.png
[2009/02/16 04:12:35 | 00,010,040 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\eye edit copy.png
[2009/02/16 03:53:35 | 00,010,976 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\eyeballs-small.png
[2009/02/16 03:53:35 | 00,007,927 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\eyeball-small.png
[2009/02/14 01:44:40 | 00,430,273 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\10540 BB Sign- Rick Kawa- Feb.pdf
[2009/02/11 19:21:48 | 00,248,120 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\attachment.jpg
[2009/02/11 10:19:42 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/02/11 10:19:34 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys

========== LOP Check ==========

[2009/03/10 21:40:16 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Administrator\Application Data
[2008/09/12 00:20:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ACD Systems
[2008/04/03 21:44:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Adobe
[2008/05/16 20:21:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\AdobeUM
[2009/03/08 15:48:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Apple Computer
[2008/12/17 03:40:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Azureus
[2006/09/01 14:01:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\BitTorrent
[2006/09/06 00:24:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Canon
[2008/03/27 13:38:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ContentGuard
[2006/10/04 02:41:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\CyberLink
[2006/10/20 12:45:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\DivX
[2007/12/31 15:50:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\GetRightToGo
[2007/01/18 21:59:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Google
[2008/03/30 01:22:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Help
[2006/09/29 01:33:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ICAClient
[2006/08/21 16:05:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Identities
[2007/03/03 20:00:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\InstallShield
[2007/08/12 21:52:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Lavasoft
[2006/08/27 23:52:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Leadertech
[2006/08/30 02:15:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Macromedia
[2009/03/09 23:30:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2008/09/08 20:44:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Media Player Classic
[2009/02/19 23:52:22 | 00,000,000 | –SD | M] – C:\Documents and Settings\Administrator\Application Data\Microsoft
[2008/08/31 17:23:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Motive
[2009/03/07 15:10:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla
[2006/08/28 00:23:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\My Games
[2008/09/08 20:44:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Real
[2006/11/29 23:48:11 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Administrator\Application Data\SecuROM
[2007/02/24 22:18:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Sun
[2009/03/10 21:40:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
[2008/04/27 23:09:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Symantec
[2009/01/27 20:47:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\TeamViewer
[2008/08/31 17:26:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\TELUS
[2009/03/09 22:45:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\thdzifan
[2007/06/10 22:38:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Viewpoint
[2008/09/24 20:25:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\vlc
[2009/03/10 21:40:22 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/12/07 20:19:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/09/11 22:57:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ACD Systems
[2007/07/15 20:55:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/09/24 18:15:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2006/09/22 21:45:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/03/10 00:21:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2006/09/23 14:28:36 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2006/10/04 02:41:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2009/03/10 21:46:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2008/05/12 07:04:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/03/09 23:05:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/04/20 18:51:54 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/08/31 17:27:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2006/08/24 16:21:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NVIDIA
[2006/08/24 17:36:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\nView_Profiles
[2009/02/19 23:46:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2006/08/27 17:22:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\POPWWPROFILES
[2008/09/08 20:44:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Real
[2009/03/10 21:40:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/02/20 19:06:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SWiSHMax2WorkFolder
[2009/02/14 15:56:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2007/12/31 15:54:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tages
[2008/08/31 17:26:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TELUS
[2007/06/10 22:38:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/08/24 17:09:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/03/07 18:11:06 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2009/03/11 19:18:58 | 00,000,434 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2004/08/04 06:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/03/02 21:00:08 | 00,000,638 | —- | M] () – C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Administrator.job
[2009/03/11 23:30:24 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Custom Scans ==========



========== Net Services ==========

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\NetSvcs

6to4 - -
AppMgmt - C:\WINDOWS\System32\appmgmts.dll - (Microsoft Corporation)
AudioSrv - C:\WINDOWS\System32\audiosrv.dll - (Microsoft Corporation)
Browser - C:\WINDOWS\System32\browser.dll - (Microsoft Corporation)
CryptSvc - C:\WINDOWS\System32\cryptsvc.dll - (Microsoft Corporation)
DMServer - C:\WINDOWS\System32\dmserver.dll - (Microsoft Corp.)
DHCP - C:\WINDOWS\System32\dhcpcsvc.dll - (Microsoft Corporation)
ERSvc - C:\WINDOWS\System32\ersvc.dll - (Microsoft Corporation)
EventSystem - C:\WINDOWS\system32\es.dll - (Microsoft Corporation)
FastUserSwitchingCompatibility - C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation)
HidServ - C:\WINDOWS\System32\hidserv.dll - (Microsoft Corporation)
Ias - -
Iprip - -
jjnmobrd - -
Irmon - -
LanmanServer - C:\WINDOWS\System32\srvsvc.dll - (Microsoft Corporation)
LanmanWorkstation - C:\WINDOWS\System32\wkssvc.dll - (Microsoft Corporation)
Messenger - C:\WINDOWS\System32\msgsvc.dll - (Microsoft Corporation)
Netman - C:\WINDOWS\System32\netman.dll - (Microsoft Corporation)
Nla - C:\WINDOWS\System32\mswsock.dll - (Microsoft Corporation)
Ntmssvc - C:\WINDOWS\system32\ntmssvc.dll - (Microsoft Corporation)
NWCWorkstation - -
Nwsapagent - -
Rasauto - C:\WINDOWS\System32\rasauto.dll - (Microsoft Corporation)
Rasman - C:\WINDOWS\System32\rasmans.dll - (Microsoft Corporation)
Remoteaccess - C:\WINDOWS\System32\mprdim.dll - (Microsoft Corporation)
Schedule - C:\WINDOWS\system32\schedsvc.dll - (Microsoft Corporation)
Seclogon - C:\WINDOWS\System32\seclogon.dll - (Microsoft Corporation)
SENS - C:\WINDOWS\system32\sens.dll - (Microsoft Corporation)
Sharedaccess - C:\WINDOWS\System32\ipnathlp.dll - (Microsoft Corporation)
SRService - C:\WINDOWS\system32\srsvc.dll - (Microsoft Corporation)
Tapisrv - C:\WINDOWS\System32\tapisrv.dll - (Microsoft Corporation)
Themes - C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation)
TrkWks - C:\WINDOWS\system32\trkwks.dll - (Microsoft Corporation)
W32Time - C:\WINDOWS\system32\w32time.dll - (Microsoft Corporation)
WZCSVC - C:\WINDOWS\System32\wzcsvc.dll - (Microsoft Corporation)
Wmi - C:\WINDOWS\System32\advapi32.dll - (Microsoft Corporation)
WmdmPmSp - -
winmgmt - C:\WINDOWS\system32\wbem\WMIsvc.dll - (Microsoft Corporation)
wscsvc - C:\WINDOWS\system32\wscsvc.dll - (Microsoft Corporation)
xmlprov - C:\WINDOWS\System32\xmlprov.dll - (Microsoft Corporation)
BITS - C:\WINDOWS\system32\qmgr.dll - (Microsoft Corporation)
wuauserv - C:\WINDOWS\system32\wuauserv.dll - (Microsoft Corporation)
ShellHWDetection - C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation)
helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
WmdmPmSN - C:\WINDOWS\system32\MsPMSNSv.dll - (Microsoft Corporation)
napagent - C:\WINDOWS\System32\qagentrt.dll - (Microsoft Corporation)
hkmsvc - C:\WINDOWS\System32\kmsvc.dll - (Microsoft Corporation)

======= End Net Services =========



========== Disabled MS Config ==========

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\

C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk - %CommonProgramFiles%\Adobe\Calibration\Adobe Gamma Loader.exe - (Adobe Systems, Inc.)
C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk - %ProgramFiles%\Adobe\Acrobat 7.0\Reader\reader_sl.exe - (Adobe Systems Incorporated)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\

ASUS SmartDoctor hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\ASUS\SmartDoctor\SmartDoctor.exe -> (ASUSTeK Inc.)
BitTorrent hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\BitTorrent\bittorrent.exe -> File not found
iTunesHelper hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\iTunes\iTunesHelper.exe -> (Apple Inc.)
Launch Ai Booster hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\ASUS\Ai Booster\OverClk.exe -> ()
Logitech.StreamPoint.Host hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Logitech\StreamPoint\StreamPoint.exe -> (Logitech Inc.)
Steam hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Valve\Steam\Steam.exe -> (Valve Corporation)
winlogon hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\BitTorrent\bittorrent.exe -> File not found
Zinio DLM hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Zinio\ZinioReader.exe -> (Zinio Systems, Inc.)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state

"system.ini" - 0
"win.ini" - 0
"bootini" - 0
"services" - 0
"startup" - 2


========== SafeBoot-Minimal Settings ==========

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\

aawservice - %ProgramFiles%\Lavasoft\Ad-Aware 2007\aawservice.exe - (Lavasoft)
AppMgmt - %SystemRoot%\System32\appmgmts.dll - (Microsoft Corporation)
Base - Driver Group
Boot Bus Extender - Driver Group
Boot file system - Driver Group
CryptSvc - %SystemRoot%\System32\cryptsvc.dll - (Microsoft Corporation)
DcomLaunch - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
dmadmin - %SystemRoot%\System32\dmadmin.exe - (Microsoft Corp., Veritas Software)
dmboot.sys - %SystemRoot%\System32\drivers\dmboot.sys - (Microsoft Corp., Veritas Software)
dmio.sys - %SystemRoot%\System32\drivers\dmio.sys - (Microsoft Corp., Veritas Software)
dmload.sys - %SystemRoot%\System32\drivers\dmload.sys - (Microsoft Corp., Veritas Software.)
dmserver - %SystemRoot%\System32\dmserver.dll - (Microsoft Corp.)
EventLog - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
File system - Driver Group
Filter - Driver Group
HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
Netlogon - %SystemRoot%\system32\lsass.exe - (Microsoft Corporation)
PCI Configuration - Driver Group
PlugPlay - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
PNP Filter - Driver Group
Primary disk - Driver Group
RpcSs - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
SCSI Class - Driver Group
sermouse.sys - Driver
sr.sys - %SystemRoot%\system32\DRIVERS\sr.sys - (Microsoft Corporation)
SRService - %SystemRoot%\system32\srsvc.dll - (Microsoft Corporation)
System Bus Extender - Driver Group
vds - Service
vga.sys - Driver
vgasave.sys - %SystemRoot%\System32\drivers\vga.sys - (Microsoft Corporation)
WinMgmt - %SystemRoot%\system32\wbem\WMIsvc.dll - (Microsoft Corporation)
{36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
{4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
{4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
{4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
{4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
{4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
{4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
{4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
{4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
{4D36E97D-E325-11CE-BFC1-08002BE10318} - System
{4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
{533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
{71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

======= End SafeBoot-Minimal =========



========== SafeBoot-Network Settings ==========

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\

aawservice - %ProgramFiles%\Lavasoft\Ad-Aware 2007\aawservice.exe - (Lavasoft)
AFD - %SystemRoot%\System32\drivers\afd.sys - (Microsoft Corporation)
AppMgmt - %SystemRoot%\System32\appmgmts.dll - (Microsoft Corporation)
Base - Driver Group
Boot Bus Extender - Driver Group
Boot file system - Driver Group
Browser - %SystemRoot%\System32\browser.dll - (Microsoft Corporation)
CryptSvc - %SystemRoot%\System32\cryptsvc.dll - (Microsoft Corporation)
DcomLaunch - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
Dhcp - %SystemRoot%\System32\dhcpcsvc.dll - (Microsoft Corporation)
dmadmin - %SystemRoot%\System32\dmadmin.exe - (Microsoft Corp., Veritas Software)
dmboot.sys - %SystemRoot%\System32\drivers\dmboot.sys - (Microsoft Corp., Veritas Software)
dmio.sys - %SystemRoot%\System32\drivers\dmio.sys - (Microsoft Corp., Veritas Software)
dmload.sys - %SystemRoot%\System32\drivers\dmload.sys - (Microsoft Corp., Veritas Software.)
dmserver - %SystemRoot%\System32\dmserver.dll - (Microsoft Corp.)
DnsCache - %SystemRoot%\System32\dnsrslvr.dll - (Microsoft Corporation)
EventLog - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
File system - Driver Group
Filter - Driver Group
HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
ip6fw.sys - %SystemRoot%\system32\drivers\ip6fw.sys - (Microsoft Corporation)
ipnat.sys - %SystemRoot%\system32\DRIVERS\ipnat.sys - (Microsoft Corporation)
LanmanServer - %SystemRoot%\System32\srvsvc.dll - (Microsoft Corporation)
LanmanWorkstation - %SystemRoot%\System32\wkssvc.dll - (Microsoft Corporation)
LmHosts - %SystemRoot%\System32\lmhsvc.dll - (Microsoft Corporation)
Messenger - %SystemRoot%\System32\msgsvc.dll - (Microsoft Corporation)
NDIS - %SystemRoot%\System32\drivers\ndis.sys - (Microsoft Corporation)
NDIS Wrapper - Driver Group
Ndisuio - %SystemRoot%\system32\DRIVERS\ndisuio.sys - (Microsoft Corporation)
NetBIOS - %SystemRoot%\system32\DRIVERS\netbios.sys - (Microsoft Corporation)
NetBIOSGroup - Driver Group
NetBT - %SystemRoot%\system32\DRIVERS\netbt.sys - (Microsoft Corporation)
NetDDEGroup - Driver Group
Netlogon - %SystemRoot%\system32\lsass.exe - (Microsoft Corporation)
NetMan - %SystemRoot%\System32\netman.dll - (Microsoft Corporation)
Network - Driver Group
NetworkProvider - Driver Group
NtLmSsp - %SystemRoot%\system32\lsass.exe - (Microsoft Corporation)
PCI Configuration - Driver Group
PlugPlay - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
PNP Filter - Driver Group
PNP_TDI - Driver Group
Primary disk - Driver Group
rdpcdd.sys - %SystemRoot%\System32\DRIVERS\RDPCDD.sys - (Microsoft Corporation)
rdpdd.sys - %SystemRoot%\System32\rdpdd.dll - (Microsoft Corporation)
rdpwd.sys - %SystemRoot%\System32\drivers\rdpwd.sys - (Microsoft Corporation)
rdsessmgr - %SystemRoot%\system32\sessmgr.exe - (Microsoft Corporation)
RpcSs - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
SCSI Class - Driver Group
sermouse.sys - Driver
SharedAccess - %SystemRoot%\System32\ipnathlp.dll - (Microsoft Corporation)
sr.sys - %SystemRoot%\system32\DRIVERS\sr.sys - (Microsoft Corporation)
SRService - %SystemRoot%\system32\srsvc.dll - (Microsoft Corporation)
Streams Drivers - Driver Group
System Bus Extender - Driver Group
Tcpip - %SystemRoot%\system32\DRIVERS\tcpip.sys - (Microsoft Corporation)
TDI - Driver Group
tdpipe.sys - %SystemRoot%\System32\drivers\tdpipe.sys - (Microsoft Corporation)
tdtcp.sys - %SystemRoot%\System32\drivers\tdtcp.sys - (Microsoft Corporation)
termservice - %SystemRoot%\System32\termsrv.dll - (Microsoft Corporation)
vga.sys - Driver
vgasave.sys - %SystemRoot%\System32\drivers\vga.sys - (Microsoft Corporation)
WinMgmt - %SystemRoot%\system32\wbem\WMIsvc.dll - (Microsoft Corporation)
WZCSVC - %SystemRoot%\System32\wzcsvc.dll - (Microsoft Corporation)
{1a3e09be-1e45-494b-9174-d7385b45bbf5} - Reg Error: Value error.
{36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
{4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
{4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
{4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
{4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
{4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
{4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
{4D36E972-E325-11CE-BFC1-08002BE10318} - Net
{4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
{4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
{4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
{4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
{4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
{4D36E97D-E325-11CE-BFC1-08002BE10318} - System
{4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
{71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

======= End SafeBoot-Network =========



========== ActiveX Components ==========

{03F998B2-0E00-11D3-A498-00104B6EB52E}: Viewpoint Media Player
{08B0E5C0-4FCB-11CF-AAA5-00401C608500}: Java (Sun)
{0e8d0700-75df-11d3-8b4a-0008c7450c4a}: LizardTech DjVu Activex Control
{10072CEC-8CC1-11D1-986E-00A0C955B42F}: Vector Graphics Rendering (VML)
{1325db73-d9f1-48f8-8895-6d814ec58889}: Security Update for Windows XP (KB913433)
{1B00725B-C455-4DE6-BFB6-AD540AD427CD}: Viewpoint Media Player
{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}: NetShow
{22d6f312-b0f6-11d0-94ab-0080c74c7e95}: Microsoft Windows Media Player 6.4
{233C1507-6A77-46A4-9443-F871F945D258}: Adobe Shockwave Director 10.2
{283807B5-2C60-11D0-A31D-00AA00B92C03}: DirectAnimation
{2A202491-F00D-11cf-87CC-0020AFEECF20}: Adobe Shockwave Director 10.2
{2C7339CF-2B09-4501-B3F3-F3508C9228ED}: %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
{36f8ec70-c29a-11d1-b5c7-0000f8051515}: Dynamic HTML Data Binding for Java
{3af36230-a269-11d1-b5bf-0000f8051515}: Offline Browsing Pack
{3bf42070-b3b1-11d1-b5c5-0000f8051515}: Uniscribe
{411EDCF7-755D-414E-A74B-3DCD6583F589}: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
{4278c270-a269-11d1-b5bf-0000f8051515}: Advanced Authoring
{44BBA840-CC51-11CF-AAFA-00AA00B6015C}: "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
{44BBA842-CC51-11CF-AAFA-00AA00B6015B}: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
{44BBA848-CC51-11CF-AAFA-00AA00B6015C}: DirectShow
{44BBA855-CC51-11CF-AAFA-00AA00B6015F}: DirectDrawEx
{45ea75a0-a269-11d1-b5bf-0000f8051515}: Internet Explorer Help
{4f216970-c90c-11d1-b5c7-0000f8051515}: DirectAnimation Java Classes
{4f645220-306d-11d2-995d-00c04f98bbc9}: Microsoft Windows Script 5.6
{5945c046-1e7d-11d1-bc44-00c04fd912be}: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
{5A8D6EE0-3E18-11D0-821E-444553540000}: ICW
{5fd399c0-a70a-11d1-9948-00c04f98bbc9}: Internet Explorer Setup Tools
{630b1da0-b465-11d1-9948-00c04f98bbc9}: Browsing Enhancements
{6BF52A52-394A-11d3-B153-00C04F79FAA6}: Microsoft Windows Media Player
{6fab99d0-bab8-11d1-994a-00c04f98bbc9}: MSN Site Access
{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}: .NET Framework
{73FA19D0-2D75-11D2-995D-00C04F98BBC9}: Web Folders
{7790769C-0471-11d2-AF11-00C04FA35D02}: "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
{89820200-ECBD-11cf-8B85-00AA005B4340}: regsvr32.exe /s /n /i:U shell32.dll
{89820200-ECBD-11cf-8B85-00AA005B4383}: C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
{89B4C1CD-B018-4511-B0A1-5476DBF70820}: c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
{8D1D0E9A-C799-4D28-9E29-0061D1E66E43}: Microsoft .NET Framework 1.1 Hotfix (KB928366)
{9381D8F2-0288-11D0-9501-00AA00B911A5}: Dynamic HTML Data Binding
{B508B3F1-A24A-32C0-B310-85786919EF28}: .NET Framework
{C9E9A340-D1F1-11D0-821E-444553540600}: Internet Explorer Core Fonts
{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}: .NET Framework
{CC2A9BA0-3BDD-11D0-821E-444553540000}: Task Scheduler
{CDD7975E-60F8-41d5-8149-19E51D6F71D0}: Windows Movie Maker v2.1
{D27CDB6E-AE6D-11cf-96B8-444553540000}: Adobe Flash Player
{de5aed00-a4bf-11d1-9948-00c04f98bbc9}: HTML Help
{E92B03AB-B707-11d2-9CBD-0000F87A369E}: Active Directory Service Interface
<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}: C:\WINDOWS\system32\ieudinit.exe
>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}: C:\WINDOWS\inf\unregmp2.exe /ShowWMP
>{26923b43-4d38-484f-9b9e-de460746276c}: %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
>{60B49E34-C7CC-11D0-8953-00A0C90347FF}: RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS: RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}: %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

======= End ActiveX =========


< %systemroot%\System32\antiwpa.dll >

< %systemroot%\SYSTEM32\wpa.dll >

< %systemroot%\setup\scripts\biestart.exe >

< %systemroot%\system32\drivers\royal.sys >

< %systemroot%\system32\serauth1.dll >

< %systemroot%\system32\serauth2.dll >

< %systemroot%\system32\sysaudio.sys >

< %systemroot%\system32\wdmaud.sys >

< %systemroot%\system32\aeaudio.sys >

========== Alternate Data Streams ==========

@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Administrator\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Administrator\Desktop\Thumbs.db:encryptable
< End of report >
hello

Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
    DRV - (fab2e477 [System | Stopped]) – C:\WINDOWS\System32\drivers\fab2e477.sys ()
    DRV - (idrmkl [On_Demand | Stopped]) – C:\Documents and Settings\Administrator\Local Settings\Temp\idrmkl.sys ()
    DRV - (jcuptzlq [Boot | Stopped]) – C:\WINDOWS\system32\drivers\jcuptzlq.sys ()
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
    O4 - HKCU..\Run: [a33l1g0rk5c91jyqsf3er06slj167h86tfdtwxp6dfu] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\n15fabs.exe ()
    O4 - HKCU..\Run: [anvwjasmvf08yr32jn23yvtg36l4og] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ua3st1frdn5h.exe ()
    O4 - HKCU..\Run: [b9psbsyod1fbzireviuae3oqfb7bocx9m24jup78rdvp2qkxu] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\gvt3uw.exe ()
    O4 - HKCU..\Run: [bdeq4w34lgmikeuaw749u] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sh56l52vs.exe ()
    O4 - HKCU..\Run: [bpu7rpn3qnn] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xutfoxdpiz4e.exe ()
    O4 - HKCU..\Run: [btvj4ad93itqsjnkux7g5l0bah1mapy] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\anxgtii.exe ()
    O4 - HKCU..\Run: [c2zsrxs4js6nou8xcs5zrr2tuw2f6afr7knuk0ox73akku] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\o3ickf.exe ()
    O4 - HKCU..\Run: [cdzdlet85tog5gcnl4z9r67] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\quf0935p5.exe ()
    O4 - HKCU..\Run: [cuac1n219mwsmtt4ynhserwlomv] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\m6qs7nk.exe ()
    O4 - HKCU..\Run: [d9cpa5nzw] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\eqor2qej.exe ()
    O4 - HKCU..\Run: [dicwqis0gl] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\oj7k7u.exe ()
    O4 - HKCU..\Run: [dpi7urm225rdw70xa8csr9jxxjg1jsu4wl8lwyr] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cuac40agxw3.exe ()
    O4 - HKCU..\Run: [dwqqu5fvvxadig] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\blwpep8b4zlwc.exe ()
    O4 - HKCU..\Run: [e4vy7bbqbf0kuhmbkvdh9q5jgmk0a2by6avr15vm0r2whfm9] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cy5wcazgcb.exe ()
    O4 - HKCU..\Run: [e7c3htdnpvp] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wfzv9w.exe ()
    O4 - HKCU..\Run: [e8ntuv55dw013ouuuiwnv] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xxhepo58aielz.exe ()
    O4 - HKCU..\Run: [ebwevln43p6wgmync4qkiwimvhj359rx8y79x0tu7by] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\a1v9nj.exe ()
    O4 - HKCU..\Run: [fupkv27s63173pe60] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tl6kjkmbfzt.exe ()
    O4 - HKCU..\Run: [fyd3g5gr6me7n77flh7eunxp43hh] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fla1s9kdviat.exe ()
    O4 - HKCU..\Run: [g3yi6r241z436i8bd3vb] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\swgqixjmdzmfy.exe ()
    O4 - HKCU..\Run: [gzcey3gahn6midnwv5c7wrkkvg8wlsj5e] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\h4rt95.exe ()
    O4 - HKCU..\Run: [h0gq8ozqegvo6fmzm4dle85asrpwlmte4d3e7jyvvpttf] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cjb6j4.exe ()
    O4 - HKCU..\Run: [h5u2pq3ry5q9jab555yifycoanw967] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\lba2f9nhx.exe ()
    O4 - HKCU..\Run: [i90d1q9lxqv2fi8oxsdzh4vyqgv9vru0dr52pv0dynsah0n1p] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\un6bx3.exe ()
    O4 - HKCU..\Run: [ip9o1kh7vrd82su6] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jbte55oes.exe ()
    O4 - HKCU..\Run: [iroc5eqi1b1blryh3m8pfu6ylq0oe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nu5oojrvz7jas.exe ()
    O4 - HKCU..\Run: [j71np70c8tjhi422tkextkvmq] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\t3fif3.exe ()
    O4 - HKCU..\Run: [j7g843tqocefx4nzi9] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ftumrb7cba.exe ()
    O4 - HKCU..\Run: [j95ao9ygvdm99hpf4ey9ffgldnwvuuagqk8h4ybkikznn] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hsc9v18un.exe ()
    O4 - HKCU..\Run: [jiehq417w0fqsvz94pdqcwucwjx] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\baq3mo9.exe ()
    O4 - HKCU..\Run: [k1infzuu7w1fursznntre8o] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\advpnbg.exe ()
    O4 - HKCU..\Run: [k7x5vpi7wn27zg7z] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\vixmq6zbyoc5.exe ()
    O4 - HKCU..\Run: [kc9rzv3jg46ss7y4s9xq96e27rohyn8ss2twdnhs17z] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hn14ytof.exe ()
    O4 - HKCU..\Run: [kyi5epng5zmpl0otskgm4qgpvusskc9o4ept9ivbtvjj7ufgh5] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\st648ljsrn29e.exe ()
    O4 - HKCU..\Run: [kzrltkbvzmqefqfwylxfj] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ifwfjv.exe ()
    O4 - HKCU..\Run: [m2rb91krw9] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\g7c2sd5.exe ()
    O4 - HKCU..\Run: [n9btovjageuvt7uerpegtt3sxdfkcze43] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ybv7ie.exe ()
    O4 - HKCU..\Run: [nz2xio5vr724xz9zna846] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jgchemcb.exe ()
    O4 - HKCU..\Run: [o7gudzvgdvyp4wcglaloqchsy] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cd8jnl.exe ()
    O4 - HKCU..\Run: [o8374sy3v83rfacivlqs5s1gzs] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jdw939p1.exe ()
    O4 - HKCU..\Run: [ohne47dfrh8j2kcbq43a0m18369xq4f2yv3mwgu8oo7g7f] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\pgvqqij3njm97.exe ()
    O4 - HKCU..\Run: [qxqn7w603vgvmbllktdu6v5yfysn] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qjyv828y8.exe ()
    O4 - HKCU..\Run: [r03gpaup0u0] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qhlpx4pw.exe ()
    O4 - HKCU..\Run: [rg7ru25x4aoun22cbcyr1vq5fwxfd3bsp91c81y3o9ye] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\h5rhsvhb36mgt.exe ()
    O4 - HKCU..\Run: [s0x7vrd0xfpaj541nxuq3xmjodts241sg1f] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qrbuc8aqgltg.exe ()
    O4 - HKCU..\Run: [sey0kbz2yfcgh18ox095xf7nvs9ilw] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\t34i6kaslnso.exe ()
    O4 - HKCU..\Run: [sgy4fclhw] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\g4dz8k3cc.exe ()
    O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
    O4 - HKCU..\Run: [tsxrrnpgzt613y9ad] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nzmbf5.exe ()
    O4 - HKCU..\Run: [u6y13sd1t0ued2xxppvq4ckxi2du] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hqjqgp.exe ()
    O4 - HKCU..\Run: [uwwwzhjwodf7n21xf] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\i57c4w3l.exe ()
    O4 - HKCU..\Run: [v1jd00uta8v5nlji18yjl0] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cbflalcv14.exe ()
    O4 - HKCU..\Run: [v4y6q5r4g3] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ttidhr21f.exe ()
    O4 - HKCU..\Run: [vhz59wczobgk] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\i3y2lt5n.exe ()
    O4 - HKCU..\Run: [vmm30b9coxd7cgjwggxa2f07xsjh25uxifazh] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xrjteldvw4zz.exe ()
    O4 - HKCU..\Run: [vtcande3kqw5qkrq] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\haakicmp3p9t.exe ()
    O4 - HKCU..\Run: [waa6hw2b6i0lr76kfdoc7s0fco5vjrkgzurtpocjvp] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\b937in1ujjps.exe ()
    O4 - HKCU..\Run: [wj5f24ptvu9k1uq8vvfnn4j131] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\zq48bs8ktbfh.exe ()
    O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
    O4 - HKCU..\Run: [wor1zu29t8nkhtpw8kynt0f] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cdp01o6ajmk.exe ()
    O4 - HKCU..\Run: [x308bkrolbzv6rc3jzab22czrc4prsl6sohod] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\dt6j73cmvdel.exe ()
    O4 - HKCU..\Run: [xi9kbhxra01i6wbz2] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fx0o70kh4.exe ()
    O4 - HKCU..\Run: [yjdgixolohvqmhuf0iu13f2zlmi2fla9mxn3tz] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ihvu1fe0042yp.exe ()
    O4 - HKCU..\Run: [yl5a0y0eavf1r52fbnz11t245f6lmi0iyaxrxbnz4uzyqa] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\uqbgwqmysn5.exe ()
    O4 - HKCU..\Run: [zq6186sg3mx5gvzp] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\crzayy.exe ()
    O4 - HKCU..\Run: [zx2889vn5h35kd4kgk5c] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cbq4jlawnizc.exe ()
    O29 - HKLM SecurityProviders - ( digeste.dll) - File not found
    O33 - MountPoints2\{91634c50-4950-11dc-aac1-0018f3272aea}\Shell\Auto\command - "" = F:\tel.xls.exe – File not found
    O33 - MountPoints2\{91634c50-4950-11dc-aac1-0018f3272aea}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{cd96e6d8-521b-11db-8a65-0018f3272aea}\Shell\AutoRun\command - "" = setupSNK.exe
    [2009/03/08 14:37:37 | 00,000,434 | —- | C] () – C:\WINDOWS\tasks\At1.job
    [2009/03/08 14:37:27 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\fab2e477.sys
    [2009/03/08 14:37:16 | 00,000,002 | —- | C] () – C:\-535435166
    [2009/03/09 22:45:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\thdzifan
    
    :Services
    
    :Reg
    
    :Files
    C:\WINDOWS\tasks\At*.job
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )
I know its a long shot but who ever you are helping me if you are ever in calgary msg me and i'll buy you a beer or 2 :)
New OTListlt Log:

OTListIt logfile created on: 3/14/2009 12:27:09 AM - Run 5
OTListIt2 by OldTimer - Version 2.0.3.5 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.68 Gb Available Physical Memory | 84.17% Memory free
3.85 Gb Paging File | 3.71 Gb Available in Paging File | 96.25% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 62.17 Gb Free Space | 20.86% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: IANCE-3FA06CAA9
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Administrator\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aawservice [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
SRV - (Apple Mobile Device [Auto | Stopped]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (ATKKeyboardService [Auto | Stopped]) – C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)
SRV - (Automatic LiveUpdate Scheduler [Auto | Stopped]) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (avg8wd [Auto | Stopped]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Auto | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (ccEvtMgr [Disabled | Stopped]) – File not found
SRV - (ccSetMgr [Auto | Stopped]) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CLTNetCnService [Auto | Stopped]) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (comHost [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Stopped]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LiveUpdate [On_Demand | Stopped]) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (LiveUpdate Notice [Auto | Stopped]) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (MDM [Auto | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NMIndexingService [Disabled | Stopped]) – File not found
SRV - (NVSvc [Auto | Stopped]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Symantec Core LC [Auto | Stopped]) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [Auto | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AsIO [System | Stopped]) – C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (asuskbnt [System | Stopped]) – C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (atksgt [Auto | Stopped]) – C:\WINDOWS\system32\DRIVERS\atksgt.sys ()
DRV - (AvgLdx86 [System | Stopped]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Stopped]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (COH_Mon [On_Demand | Stopped]) – C:\WINDOWS\system32\Drivers\COH_Mon.sys (Symantec Corporation)
DRV - (CO_Mon [Auto | Stopped]) – C:\WINDOWS\system32\drivers\CO_Mon.sys (Symantec Corporation)
DRV - (eeCtrl [System | Stopped]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EIO [Auto | Stopped]) – C:\WINDOWS\system32\drivers\EIO.sys (ASUSTeK Computer Inc.)
DRV - (ENTECH [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ENTECH.sys (EnTech Taiwan)
DRV - (EraserUtilRebootDrv [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (fab2e477 [System | Stopped]) – C:\WINDOWS\System32\drivers\fab2e477.sys ()
DRV - (gameenum [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (grmnusb [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\grmnusb.sys (GARMIN Corp.)
DRV - (jcuptzlq [Boot | Stopped]) – C:\WINDOWS\system32\drivers\jcuptzlq.sys ()
DRV - (lirsgt [Auto | Stopped]) – C:\WINDOWS\system32\DRIVERS\lirsgt.sys ()
DRV - (motmodem [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\motmodem.sys (Motorola)
DRV - (ms_mpu401 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (MTsensor [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ASACPI.sys ()
DRV - (NAVENG [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080825.034\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080825.034\NAVEX15.SYS (Symantec Corporation)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nvnetbus.sys (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (RT73 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\Dr71WU.sys (Ralink Technology, Corp.)
DRV - (SASDIFSV [System | Stopped]) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Stopped]) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Stopped]) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Secdrv [Auto | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sfdrv01 [Boot | Running]) – C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02 [Boot | Running]) – C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (sfsync02 [Boot | Running]) – C:\WINDOWS\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (SI3132 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\SI3132.sys (Silicon Image, Inc.)
DRV - (SiFilter [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (SiRemFil [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\SiRemFil.sys (Silicon Image, Inc.)
DRV - (SPBBCDrv [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SRTSP [System | Stopped]) – C:\WINDOWS\System32\Drivers\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\SRTSPL.SYS (Symantec Corporation)
DRV - (SRTSPX [System | Stopped]) – C:\WINDOWS\System32\Drivers\SRTSPX.SYS (Symantec Corporation)
DRV - (SYMDNS [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (SymEvent [On_Demand | Stopped]) – C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMFW [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMIDS [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\SYMIDS.SYS (Symantec Corporation)
DRV - (SYMIDSCO [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SymcData\ipsdefs\20080825.001\SymIDSCo.sys (Symantec Corporation)
DRV - (SymIM [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\SymIM.sys (Symantec Corporation)
DRV - (SymIMMP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\SymIM.sys (Symantec Corporation)
DRV - (symlcbrd [Auto | Stopped]) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (SYMNDIS [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMREDRV [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMTDI [System | Stopped]) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (USBCCID [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\usbccid.sys (Microsoft Corporation)
DRV - (yukonwxp [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\yk51x86.sys (Marvell)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - presf.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://drudgereport.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - HKLM\software\mozilla\Firefox\extensions\\[removed] -> %ProgramFiles%\JAVA\JRE6\LIB\DEPLOY\JQS\FF [C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF] -> [2008/12/20 04:27:44 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71} -> %ProgramFiles%\AVG\AVG8\FIREFOX [C:\PROGRAM FILES\AVG\AVG8\FIREFOX] -> [2009/03/08 16:15:22 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components -> %ProgramFiles%\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2009/03/07 15:09:46 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins -> %ProgramFiles%\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2009/03/07 15:09:40 00,000,000 | —D | M]
FF - C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions [2009/03/07 15:10:19 00,000,000 | —D | M]
FF - C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/03/07 15:10:19 00,000,000 | —D | M]
FF - C:\Documents and Settings\Administrator\Application Data\mozilla\Firefox\Profiles\n09x3eqj.default\extensions [2009/03/07 15:11:54 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions [2009/03/09 02:45:01 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2006/11/08 02:13:12 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/03/07 15:09:41 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} [2007/06/16 21:19:58 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} [2007/07/25 17:45:42 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [2007/10/05 01:01:10 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [2008/06/18 00:28:00 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [2008/08/10 13:16:15 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [2008/12/20 04:28:01 00,000,000 | —D | M]

O1 HOSTS File: (646 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install ()
O4 - HKLM..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe" (Symantec Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe (Enigma Software Group USA, LLC.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TELUS_McciTrayApp] C:\Program Files\TELUS\TELUS Support Centre\bin\McciTrayApp.exe File not found
O4 - HKLM..\Run: [TEPA.exe] "C:\Program Files\TELUS\eProtect Advisor\TEPA.exe" /AUTORUN File not found
O4 - HKLM..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u File not found
O4 - HKCU..\Run: [a33l1g0rk5c91jyqsf3er06slj167h86tfdtwxp6dfu] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\n15fabs.exe File not found
O4 - HKCU..\Run: [anvwjasmvf08yr32jn23yvtg36l4og] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ua3st1frdn5h.exe File not found
O4 - HKCU..\Run: [b9psbsyod1fbzireviuae3oqfb7bocx9m24jup78rdvp2qkxu] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\gvt3uw.exe File not found
O4 - HKCU..\Run: [bdeq4w34lgmikeuaw749u] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sh56l52vs.exe File not found
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" File not found
O4 - HKCU..\Run: [bpu7rpn3qnn] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xutfoxdpiz4e.exe File not found
O4 - HKCU..\Run: [btvj4ad93itqsjnkux7g5l0bah1mapy] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\anxgtii.exe File not found
O4 - HKCU..\Run: [c2zsrxs4js6nou8xcs5zrr2tuw2f6afr7knuk0ox73akku] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\o3ickf.exe File not found
O4 - HKCU..\Run: [cdzdlet85tog5gcnl4z9r67] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\quf0935p5.exe File not found
O4 - HKCU..\Run: [cuac1n219mwsmtt4ynhserwlomv] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\m6qs7nk.exe File not found
O4 - HKCU..\Run: [d9cpa5nzw] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\eqor2qej.exe File not found
O4 - HKCU..\Run: [dicwqis0gl] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\oj7k7u.exe File not found
O4 - HKCU..\Run: [dpi7urm225rdw70xa8csr9jxxjg1jsu4wl8lwyr] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cuac40agxw3.exe File not found
O4 - HKCU..\Run: [dwqqu5fvvxadig] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\blwpep8b4zlwc.exe File not found
O4 - HKCU..\Run: [e4vy7bbqbf0kuhmbkvdh9q5jgmk0a2by6avr15vm0r2whfm9] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cy5wcazgcb.exe File not found
O4 - HKCU..\Run: [e7c3htdnpvp] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wfzv9w.exe File not found
O4 - HKCU..\Run: [e8ntuv55dw013ouuuiwnv] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xxhepo58aielz.exe File not found
O4 - HKCU..\Run: [ebwevln43p6wgmync4qkiwimvhj359rx8y79x0tu7by] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\a1v9nj.exe File not found
O4 - HKCU..\Run: [fupkv27s63173pe60] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tl6kjkmbfzt.exe File not found
O4 - HKCU..\Run: [fyd3g5gr6me7n77flh7eunxp43hh] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fla1s9kdviat.exe File not found
O4 - HKCU..\Run: [g3yi6r241z436i8bd3vb] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\swgqixjmdzmfy.exe File not found
O4 - HKCU..\Run: [gzcey3gahn6midnwv5c7wrkkvg8wlsj5e] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\h4rt95.exe File not found
O4 - HKCU..\Run: [h0gq8ozqegvo6fmzm4dle85asrpwlmte4d3e7jyvvpttf] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cjb6j4.exe File not found
O4 - HKCU..\Run: [h5u2pq3ry5q9jab555yifycoanw967] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\lba2f9nhx.exe File not found
O4 - HKCU..\Run: [i90d1q9lxqv2fi8oxsdzh4vyqgv9vru0dr52pv0dynsah0n1p] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\un6bx3.exe File not found
O4 - HKCU..\Run: [ip9o1kh7vrd82su6] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jbte55oes.exe File not found
O4 - HKCU..\Run: [iroc5eqi1b1blryh3m8pfu6ylq0oe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nu5oojrvz7jas.exe File not found
O4 - HKCU..\Run: [j71np70c8tjhi422tkextkvmq] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\t3fif3.exe File not found
O4 - HKCU..\Run: [j7g843tqocefx4nzi9] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ftumrb7cba.exe File not found
O4 - HKCU..\Run: [j95ao9ygvdm99hpf4ey9ffgldnwvuuagqk8h4ybkikznn] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hsc9v18un.exe File not found
O4 - HKCU..\Run: [jiehq417w0fqsvz94pdqcwucwjx] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\baq3mo9.exe File not found
O4 - HKCU..\Run: [k1infzuu7w1fursznntre8o] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\advpnbg.exe File not found
O4 - HKCU..\Run: [k7x5vpi7wn27zg7z] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\vixmq6zbyoc5.exe File not found
O4 - HKCU..\Run: [kc9rzv3jg46ss7y4s9xq96e27rohyn8ss2twdnhs17z] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hn14ytof.exe File not found
O4 - HKCU..\Run: [kyi5epng5zmpl0otskgm4qgpvusskc9o4ept9ivbtvjj7ufgh5] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\st648ljsrn29e.exe File not found
O4 - HKCU..\Run: [kzrltkbvzmqefqfwylxfj] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ifwfjv.exe File not found
O4 - HKCU..\Run: [m2rb91krw9] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\g7c2sd5.exe File not found
O4 - HKCU..\Run: [n9btovjageuvt7uerpegtt3sxdfkcze43] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ybv7ie.exe File not found
O4 - HKCU..\Run: [nz2xio5vr724xz9zna846] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jgchemcb.exe File not found
O4 - HKCU..\Run: [o7gudzvgdvyp4wcglaloqchsy] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cd8jnl.exe File not found
O4 - HKCU..\Run: [o8374sy3v83rfacivlqs5s1gzs] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jdw939p1.exe File not found
O4 - HKCU..\Run: [ohne47dfrh8j2kcbq43a0m18369xq4f2yv3mwgu8oo7g7f] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\pgvqqij3njm97.exe File not found
O4 - HKCU..\Run: [qxqn7w603vgvmbllktdu6v5yfysn] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qjyv828y8.exe File not found
O4 - HKCU..\Run: [r03gpaup0u0] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qhlpx4pw.exe File not found
O4 - HKCU..\Run: [rg7ru25x4aoun22cbcyr1vq5fwxfd3bsp91c81y3o9ye] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\h5rhsvhb36mgt.exe File not found
O4 - HKCU..\Run: [s0x7vrd0xfpaj541nxuq3xmjodts241sg1f] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qrbuc8aqgltg.exe File not found
O4 - HKCU..\Run: [sey0kbz2yfcgh18ox095xf7nvs9ilw] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\t34i6kaslnso.exe File not found
O4 - HKCU..\Run: [sgy4fclhw] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\g4dz8k3cc.exe File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [tsxrrnpgzt613y9ad] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nzmbf5.exe File not found
O4 - HKCU..\Run: [u6y13sd1t0ued2xxppvq4ckxi2du] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hqjqgp.exe File not found
O4 - HKCU..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1 (Adobe Systems Incorporated)
O4 - HKCU..\Run: [uwwwzhjwodf7n21xf] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\i57c4w3l.exe File not found
O4 - HKCU..\Run: [v1jd00uta8v5nlji18yjl0] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cbflalcv14.exe File not found
O4 - HKCU..\Run: [v4y6q5r4g3] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ttidhr21f.exe File not found
O4 - HKCU..\Run: [vhz59wczobgk] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\i3y2lt5n.exe File not found
O4 - HKCU..\Run: [vmm30b9coxd7cgjwggxa2f07xsjh25uxifazh] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xrjteldvw4zz.exe File not found
O4 - HKCU..\Run: [vtcande3kqw5qkrq] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\haakicmp3p9t.exe File not found
O4 - HKCU..\Run: [waa6hw2b6i0lr76kfdoc7s0fco5vjrkgzurtpocjvp] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\b937in1ujjps.exe File not found
O4 - HKCU..\Run: [wj5f24ptvu9k1uq8vvfnn4j131] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\zq48bs8ktbfh.exe File not found
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - HKCU..\Run: [wor1zu29t8nkhtpw8kynt0f] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cdp01o6ajmk.exe File not found
O4 - HKCU..\Run: [x308bkrolbzv6rc3jzab22czrc4prsl6sohod] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\dt6j73cmvdel.exe File not found
O4 - HKCU..\Run: [xi9kbhxra01i6wbz2] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fx0o70kh4.exe File not found
O4 - HKCU..\Run: [yjdgixolohvqmhuf0iu13f2zlmi2fla9mxn3tz] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ihvu1fe0042yp.exe File not found
O4 - HKCU..\Run: [yl5a0y0eavf1r52fbnz11t245f6lmi0iyaxrxbnz4uzyqa] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\uqbgwqmysn5.exe File not found
O4 - HKCU..\Run: [zq6186sg3mx5gvzp] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\crzayy.exe File not found
O4 - HKCU..\Run: [zx2889vn5h35kd4kgk5c] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cbq4jlawnizc.exe File not found
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\winlogon.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoAdminPage = 1
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} http://www.eversoft.co.kr/vmpinstaller/ins…e_lns4695d.html (MetaStreamCtl Class)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://downloadcenter.samsung.com/content/…trolLite_EN.cab (DjVuCtl Class)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} http://community.webshots.com/html/atx/wsaxcontrol.cab (Webshots Multiple Media Uploader - Container)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9AD9B5EB-F9E0-47D4-B20F-C29D58C6F5E1} http://alta.registries.gov.ab.ca/SpinII/cabs/WayToIndex.CAB (IndeXMap Class)
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} http://66.242.36.104/app/view22RTE.cab (View22RTE Class)
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} http://www.systemrequirementslab.com/sysreqlab.cab (System Requirements Lab Class)
O16 - DPF: {CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.3.1_18)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O29 - HKLM SecurityProviders - ( digeste.dll) - File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{91634c50-4950-11dc-aac1-0018f3272aea}\Shell\Auto\command - "" = F:\tel.xls.exe – File not found
O33 - MountPoints2\{91634c50-4950-11dc-aac1-0018f3272aea}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{cd96e6d8-521b-11db-8a65-0018f3272aea}\Shell\AutoRun\command - "" = setupSNK.exe

========== Files/Folders - Created Within 30 Days ==========

[15 C:\WINDOWS\*.tmp files]
[2009/03/14 00:22:42 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/03/12 18:44:37 | 00,497,664 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTListIt2.exe
[2009/03/12 01:18:20 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/03/12 01:17:47 | 00,000,611 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\NTREGOPT.lnk
[2009/03/12 01:17:47 | 00,000,592 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\ERUNT.lnk
[2009/03/12 01:17:47 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/03/12 01:16:28 | 00,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Administrator\My Documents\erunt_setup.exe
[2009/03/12 01:11:32 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\HIjackthis Log March11
[2009/03/12 00:52:04 | 00,001,734 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\HijackThis.lnk
[2009/03/12 00:52:04 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/12 00:51:48 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Administrator\My Documents\HJTInstall.exe
[2009/03/12 00:49:28 | 16,434,584 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\jre-6u12-windows-i586-p-s.exe
[2009/03/11 19:15:11 | 00,313,975 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\After virus scan and removal can't connect to the internet.mht
[2009/03/11 19:13:29 | 00,027,742 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Malwarebytes Forum No internet access after removing Trojan_Agent.mht
[2009/03/11 19:05:34 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\av11th
[2009/03/10 21:40:22 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/03/10 21:40:17 | 00,000,780 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/03/10 21:40:16 | 00,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2009/03/10 21:40:16 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
[2009/03/10 21:38:45 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\udats 10
[2009/03/10 21:33:34 | 00,103,624 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\BleepingComputer_com svchost_exe, exception breakpoint, soxpeca, mabidwe.mht
[2009/03/10 21:30:45 | 01,529,241 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\SDFix.exe
[2009/03/10 21:27:54 | 06,018,080 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\SUPERAntiSpywarePro.exe
[2009/03/10 21:12:41 | 00,000,000 | —D | C] – C:\myRTVAULT
[2009/03/10 18:26:28 | 00,000,899 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SpyHunter.lnk
[2009/03/10 18:26:23 | 00,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2009/03/09 23:30:12 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2009/03/09 23:26:41 | 06,068,768 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\SUPERAntiSpyware.exe
[2009/03/09 23:20:52 | 35,257,400 | —- | C] (Norman ASA) – C:\Documents and Settings\Administrator\My Documents\Norman_Malware_Cleaner.exe
[2009/03/09 23:15:51 | 02,132,416 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\My Documents\mbam-rules.exe
[2009/03/09 23:05:11 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/09 23:05:11 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/09 23:05:08 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/09 23:05:07 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/03/09 23:05:07 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/03/09 22:51:16 | 02,876,720 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\My Documents\helppppp.exe
[2009/03/09 22:45:19 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\thdzifan
[2009/03/09 22:45:19 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\thdzifan
[2009/03/09 03:01:49 | 09,764,072 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\SpyHunter-Scanner-Install.exe
[2009/03/09 02:57:59 | 00,374,274 | —- | C] (miekiemoes © 2005 ) – C:\Documents and Settings\Administrator\Desktop\LQfix.exe
[2009/03/09 02:20:13 | 09,764,072 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\SpyHunter-Scanner-Install.exe
[2009/03/09 02:15:15 | 00,446,464 | —- | C] (Proland Software) – C:\Documents and Settings\Administrator\My Documents\cleanpakes.exe
[2009/03/09 02:09:10 | 00,000,000 | —D | C] – C:\WINDOWS\BDOSCAN8
[2009/03/08 19:54:40 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\avg
[2009/03/08 16:16:39 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/03/08 16:15:38 | 00,010,520 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/03/08 16:15:38 | 00,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/03/08 16:15:37 | 00,325,640 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/03/08 16:15:37 | 00,107,912 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/03/08 16:15:36 | 00,027,656 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/03/08 16:15:32 | 33,987,075 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/03/08 16:15:32 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/03/08 16:15:32 | 00,401,372 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/03/08 16:15:32 | 00,033,349 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/03/08 16:15:32 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2009/03/08 16:15:22 | 00,000,000 | —D | C] – C:\Program Files\AVG
[2009/03/08 16:15:22 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/03/08 16:14:15 | 62,270,256 | —- | C] (AVG Technologies) – C:\Documents and Settings\Administrator\My Documents\avg_free_stf_en_85_278a1439.exe
[2009/03/08 14:37:27 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\fab2e477.sys
[2009/03/08 14:37:16 | 00,000,002 | —- | C] () – C:\-535435166
[2009/03/07 15:09:53 | 00,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/03/07 15:08:50 | 07,522,240 | —- | C] (Mozilla) – C:\Documents and Settings\Administrator\Desktop\Firefox Setup 3.0.7.exe
[2009/03/07 13:06:42 | 00,011,776 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\New Microsoft Excel Worksheet (3).xls
[2009/02/25 22:42:05 | 00,213,024 | —- | C] () – C:\WINDOWS\System32\drivers\str.sys
[2009/02/20 19:06:35 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SWiSHMax2WorkFolder
[2009/02/20 18:59:13 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\Feb20 Adds
[2009/02/20 18:38:06 | 00,002,235 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Souther Agri Services.swf
[2009/02/20 18:22:45 | 00,018,012 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Souther Agri Services.sbk
[2009/02/20 18:22:45 | 00,016,332 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Souther Agri Services.swi
[2009/02/20 18:12:15 | 00,002,071 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\basic add.swi
[2009/02/20 14:15:36 | 02,978,693 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\PowerPoint Backgrounds.zip
[2009/02/20 00:20:10 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\PowerPoint Backgrounds
[2009/02/19 23:46:26 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2009/02/19 23:27:00 | 00,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_motmodem_01005.Wdf
[2009/02/19 23:26:58 | 00,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2009/02/19 23:26:50 | 01,327,601 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\KRZR_K1m_UG_updated.pdf
[2009/02/19 13:03:34 | 00,579,464 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\SymNeti.dll
[2009/02/19 13:03:26 | 00,207,240 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\SymRedir.dll
[2009/02/19 12:31:42 | 00,031,280 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SymIM.sys
[2009/02/19 12:31:42 | 00,009,844 | —- | C] () – C:\WINDOWS\System32\drivers\SymRedir.cat
[2009/02/19 12:31:42 | 00,001,611 | —- | C] () – C:\WINDOWS\System32\drivers\SymRedir.inf
[2009/02/19 12:31:18 | 00,041,008 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symndisv.sys
[2009/02/19 12:31:16 | 00,184,496 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symtdi.sys
[2009/02/19 12:31:16 | 00,096,560 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symfw.sys
[2009/02/19 12:31:16 | 00,038,576 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symids.sys
[2009/02/19 12:31:16 | 00,037,424 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symndis.sys
[2009/02/19 12:31:16 | 00,022,320 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symredrv.sys
[2009/02/19 12:31:16 | 00,013,616 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symdns.sys
[2009/02/16 20:01:18 | 00,004,344 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\BayerCropFeb2009.swf
[2009/02/16 18:13:51 | 00,015,567 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\unfucked.swi
[2009/02/16 18:13:51 | 00,012,838 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\unfucked.sbk
[2009/02/16 18:11:22 | 00,016,439 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\######.swi
[2009/02/16 17:32:05 | 00,110,608 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Taber Small Engine Repair.sbk
[2009/02/16 17:12:39 | 00,005,668 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\exp.sbk
[2009/02/16 17:12:39 | 00,003,456 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\exp.swi
[2009/02/16 17:11:08 | 00,002,079 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\4x8template.swi
[2009/02/16 17:00:38 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\adds Feb16
[2009/02/16 04:14:13 | 00,015,864 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\eye edit copy2.png
[2009/02/16 04:12:33 | 00,010,040 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\eye edit copy.png
[2009/02/16 04:02:33 | 00,136,853 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\eyee.sbk
[2009/02/16 03:53:58 | 00,010,976 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\eyeballs-small.png
[2009/02/16 03:53:54 | 00,007,927 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\eyeball-small.png
[2009/02/14 01:54:30 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\BiGboys
[2009/02/14 01:44:40 | 00,430,273 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\10540 BB Sign- Rick Kawa- Feb.pdf

========== Files - Modified Within 30 Days ==========

[5 C:\WINDOWS\System32\*.tmp files]
[15 C:\WINDOWS\*.tmp files]
[2009/03/14 00:25:53 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/14 00:25:05 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/03/12 18:44:39 | 00,497,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTListIt2.exe
[2009/03/12 01:17:47 | 00,000,611 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\NTREGOPT.lnk
[2009/03/12 01:17:47 | 00,000,592 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\ERUNT.lnk
[2009/03/12 01:16:31 | 00,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Administrator\My Documents\erunt_setup.exe
[2009/03/12 00:52:04 | 00,001,734 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\HijackThis.lnk
[2009/03/12 00:51:50 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Administrator\My Documents\HJTInstall.exe
[2009/03/12 00:49:28 | 16,434,584 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\jre-6u12-windows-i586-p-s.exe
[2009/03/11 23:30:24 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/11 19:22:10 | 33,987,075 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/03/11 19:19:19 | 00,092,010 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/03/11 19:15:14 | 00,313,975 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\After virus scan and removal can't connect to the internet.mht
[2009/03/11 19:13:29 | 00,027,742 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Malwarebytes Forum No internet access after removing Trojan_Agent.mht
[2009/03/10 21:40:17 | 00,000,780 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/03/10 21:39:35 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/03/10 21:39:35 | 00,401,372 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/03/10 21:39:35 | 00,033,349 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/03/10 21:33:35 | 00,103,624 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\BleepingComputer_com svchost_exe, exception breakpoint, soxpeca, mabidwe.mht
[2009/03/10 21:30:51 | 01,529,241 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\SDFix.exe
[2009/03/10 21:27:54 | 06,018,080 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\SUPERAntiSpywarePro.exe
[2009/03/10 18:26:28 | 00,000,899 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SpyHunter.lnk
[2009/03/09 23:33:18 | 35,257,400 | —- | M] (Norman ASA) – C:\Documents and Settings\Administrator\My Documents\Norman_Malware_Cleaner.exe
[2009/03/09 23:26:41 | 06,068,768 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\SUPERAntiSpyware.exe
[2009/03/09 23:15:59 | 02,132,416 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\My Documents\mbam-rules.exe
[2009/03/09 23:05:11 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/09 22:51:27 | 02,876,720 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\My Documents\helppppp.exe
[2009/03/09 03:01:49 | 09,764,072 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\SpyHunter-Scanner-Install.exe
[2009/03/09 02:58:00 | 00,374,274 | —- | M] (miekiemoes © 2005 ) – C:\Documents and Settings\Administrator\Desktop\LQfix.exe
[2009/03/09 02:20:13 | 09,764,072 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\SpyHunter-Scanner-Install.exe
[2009/03/09 02:15:17 | 00,446,464 | —- | M] (Proland Software) – C:\Documents and Settings\Administrator\My Documents\cleanpakes.exe
[2009/03/08 21:23:54 | 00,006,456 | -H– | M] () – C:\WINDOWS\System32\sepinose
[2009/03/08 16:15:38 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/03/08 16:15:38 | 00,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/03/08 16:15:37 | 00,325,640 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/03/08 16:15:37 | 00,107,912 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/03/08 16:15:36 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/03/08 16:14:23 | 62,270,256 | —- | M] (AVG Technologies) – C:\Documents and Settings\Administrator\My Documents\avg_free_stf_en_85_278a1439.exe
[2009/03/08 15:15:04 | 00,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/03/08 15:15:04 | 00,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2009/03/08 15:08:38 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\fab2e477.sys
[2009/03/08 14:42:26 | 00,481,352 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/08 14:42:26 | 00,408,792 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/08 14:42:26 | 00,064,314 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/08 14:39:09 | 00,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/03/08 14:39:09 | 00,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2009/03/08 14:37:18 | 00,000,002 | —- | M] () – C:\-535435166
[2009/03/08 14:37:14 | 00,014,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\svchost.exe
[2009/03/08 14:37:14 | 00,014,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\svchost.exe
[2009/03/08 14:36:56 | 00,102,400 | -HS- | M] () – C:\WINDOWS\System32\wifufulu.dll
[2009/03/08 02:25:50 | 00,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/03/08 02:25:50 | 00,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/03/08 02:23:26 | 00,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/03/08 02:23:26 | 00,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/03/08 02:22:08 | 00,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/03/08 02:22:08 | 00,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/03/08 02:21:41 | 00,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/03/08 02:21:41 | 00,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2009/03/08 02:21:14 | 00,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/03/08 02:21:14 | 00,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2009/03/08 02:19:27 | 00,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/03/08 02:19:27 | 00,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2009/03/08 02:19:00 | 00,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/03/08 02:19:00 | 00,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2009/03/08 02:18:33 | 00,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2009/03/08 02:18:33 | 00,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2009/03/08 02:18:03 | 00,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/03/08 02:18:03 | 00,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2009/03/08 02:17:34 | 00,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/03/08 02:17:34 | 00,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/03/08 02:17:06 | 00,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/03/08 02:17:05 | 00,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/03/08 02:15:35 | 00,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/03/08 02:15:35 | 00,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/03/08 02:15:07 | 00,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/03/08 02:15:07 | 00,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/03/08 02:14:38 | 00,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/03/08 02:14:38 | 00,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/03/08 02:14:09 | 00,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/03/08 02:14:09 | 00,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2009/03/08 02:13:38 | 00,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/03/08 02:13:38 | 00,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2009/03/08 02:13:09 | 00,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/03/08 02:13:09 | 00,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2009/03/08 02:12:40 | 00,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/03/08 02:12:40 | 00,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2009/03/07 18:11:06 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/03/07 15:09:53 | 00,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/03/07 15:08:50 | 07,522,240 | —- | M] (Mozilla) – C:\Documents and Settings\Administrator\Desktop\Firefox Setup 3.0.7.exe
[2009/03/07 13:06:48 | 00,011,776 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\New Microsoft Excel Worksheet (3).xls
[2009/03/02 21:00:08 | 00,000,638 | —- | M] () – C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Administrator.job
[2009/02/27 19:55:49 | 00,213,024 | —- | M] () – C:\WINDOWS\System32\drivers\str.sys
[2009/02/20 18:43:13 | 00,002,235 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Souther Agri Services.swf
[2009/02/20 18:42:43 | 00,016,332 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Souther Agri Services.swi
[2009/02/20 18:38:41 | 00,018,012 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Souther Agri Services.sbk
[2009/02/20 18:12:15 | 00,002,071 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\basic add.swi
[2009/02/20 14:15:40 | 02,978,693 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\PowerPoint Backgrounds.zip
[2009/02/19 23:27:00 | 00,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_motmodem_01005.Wdf
[2009/02/19 23:26:58 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/02/19 23:26:58 | 00,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2009/02/19 23:26:57 | 01,327,601 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\KRZR_K1m_UG_updated.pdf
[2009/02/19 13:03:34 | 00,579,464 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\SymNeti.dll
[2009/02/19 13:03:26 | 00,207,240 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\SymRedir.dll
[2009/02/19 12:31:42 | 00,031,280 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SymIM.sys
[2009/02/19 12:31:42 | 00,009,844 | —- | M] () – C:\WINDOWS\System32\drivers\SymRedir.cat
[2009/02/19 12:31:42 | 00,001,611 | —- | M] () – C:\WINDOWS\System32\drivers\SymRedir.inf
[2009/02/19 12:31:18 | 00,041,008 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symndisv.sys
[2009/02/19 12:31:16 | 00,184,496 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symtdi.sys
[2009/02/19 12:31:16 | 00,096,560 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symfw.sys
[2009/02/19 12:31:16 | 00,038,576 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symids.sys
[2009/02/19 12:31:16 | 00,037,424 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symndis.sys
[2009/02/19 12:31:16 | 00,022,320 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symredrv.sys
[2009/02/19 12:31:16 | 00,013,616 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\symdns.sys
[2009/02/16 20:01:18 | 00,004,344 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\BayerCropFeb2009.swf
[2009/02/16 19:13:56 | 00,015,567 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\unfucked.swi
[2009/02/16 19:10:25 | 00,012,838 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\unfucked.sbk
[2009/02/16 18:13:40 | 00,003,557 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\4x8template.swi
[2009/02/16 18:11:22 | 00,016,439 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\######.swi
[2009/02/16 17:43:55 | 00,136,853 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\eyee.sbk
[2009/02/16 17:32:05 | 00,110,608 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Taber Small Engine Repair.sbk
[2009/02/16 17:16:58 | 00,003,456 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\exp.swi
[2009/02/16 17:12:39 | 00,005,668 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\exp.sbk
[2009/02/16 17:11:08 | 00,002,079 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\4x8template.swi
[2009/02/16 04:14:24 | 00,331,776 | -HS- | M] () – C:\Documents and Settings\Administrator\Desktop\Thumbs.db
[2009/02/16 04:14:16 | 00,015,864 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\eye edit copy2.png
[2009/02/16 04:12:35 | 00,010,040 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\eye edit copy.png
[2009/02/16 03:53:35 | 00,010,976 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\eyeballs-small.png
[2009/02/16 03:53:35 | 00,007,927 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\eyeball-small.png
[2009/02/14 01:44:40 | 00,430,273 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\10540 BB Sign- Rick Kawa- Feb.pdf

========== Alternate Data Streams ==========

@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Administrator\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Administrator\Desktop\Thumbs.db:encryptable
< End of report >
Don't thank me just yet, I think you may have to reformat this one :(

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:

    • C:\WINDOWS\system32\lsass.exe
  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


Repeat it for this file

C:\WINDOWS\system32\svchost.exe
This is for the 1st file:lsass.exe


VirSCAN.org Scanned Report :
Scanned time : 2009/03/14 16:07:33 (MDT)
Scanner results: All Scanners reported not find malware!
File Name : lsass.exe
File Size : 13312 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : bf2466b3e18e970d8a976fb95fc1ca85
SHA1 : de5a73cbb5f51f64c53fb4277ef2c23e70db123f
Online report : http://virscan.org/report/c517512546297bbc…e0dff031ee.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090313162836 2009-03-13 2.76 -
AhnLab V3 2009.03.14.00 2009.03.14 2009-03-14 1.09 -
AntiVir 7.9.0.114 7.1.2.171 2009-03-13 1.91 -
Antiy 2.0.18 20090314.2215997 2009-03-14 0.12 -
Authentium 5.1.1 200903141844 2009-03-14 1.09 -
AVAST! 3.0.1 090314-0 2009-03-14 0.87 -
AVG 7.5.52.442 270.11.13/2001 2009-03-14 1.95 -
BitDefender 7.81008.2793145 7.24182 2009-03-15 2.55 -
CA (VET) 9.0.0.143 31.6.6395 2009-03-13 5.20 -
ClamAV 0.94.2 9108 2009-03-15 0.01 -
Comodo 3.8 1056 2009-03-14 0.59 -
CP Secure 1.1.0.715 2009.03.14 2009-03-14 7.46 -
Dr.Web 4.44.0.9170 2009.03.14 2009-03-14 4.22 -
F-Prot 4.4.4.56 20090314 2009-03-14 1.08 -
F-Secure 5.51.6100 2009.03.14.02 2009-03-14 4.84 -
Fortinet 2.81-3.117 10.159 2009-03-14 0.17 -
GData 19.3938/19.261 20090314 2009-03-14 3.34 -
ViRobot 20090313 2009.03.13 2009-03-13 0.41 -
Ikarus T3.1.01.45 2009.03.14.72427 2009-03-14 4.28 -
JiangMin 11.0.706 2009.03.14 2009-03-14 1.57 -
Kaspersky 5.5.10 2009.03.14 2009-03-14 0.05 -
KingSoft 2009.2.5.15 2009.3.14.21 2009-03-14 0.65 -
McAfee 5.3.00 5553 2009-03-14 2.69 -
Microsoft 1.4405 2009.03.14 2009-03-14 4.47 -
mks_vir 2.01 2009.03.13 2009-03-13 2.77 -
Norman 6.00.06 6.00.00 2009-03-13 8.01 -
Panda 9.05.01 2009.03.14 2009-03-14 1.59 -
Trend Micro 8.700-1004 5.896.32 2009-03-14 0.03 -
Quick Heal 10.00 2009.03.14 2009-03-14 0.94 -
Rising 20.0 21.20.52.00 2009-03-14 0.79 -
Sophos 2.84.1 4.39 2009-03-15 2.19 -
Sunbelt 5040 5040 2009-03-13 0.55 -
Symantec 1.3.0.24 20090314.003 2009-03-14 0.05 -
nProtect 20090314.01 3332311 2009-03-14 4.19 -
The Hacker [removed] v00281 2009-03-13 0.56 -
VBA32 3.12.10.1 20090313.1825 2009-03-13 1.73 -
VirusBuster 4.5.11.10 10.102.10/978783 2009-03-14 1.22 -

The second file:svchost.exe
VirSCAN.org Scanned Report :
Scanned time : 2009/03/14 16:12:10 (MDT)
Scanner results: All Scanners reported not find malware!
File Name : svchost.exe
File Size : 14336 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 27c6d03bcdb8cfeb96b716f3d8be3e18
SHA1 : 49083ae3725a0488e0a8fbbe1335c745f70c4667
Online report : http://virscan.org/report/414f0937af722b5d…0267c88c60.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090313162836 2009-03-13 2.56 -
AhnLab V3 2009.03.14.00 2009.03.14 2009-03-14 1.15 -
AntiVir 7.9.0.114 7.1.2.171 2009-03-13 1.94 -
Antiy 2.0.18 20090314.2215997 2009-03-14 0.12 -
Authentium 5.1.1 200903141844 2009-03-14 1.08 -
AVAST! 3.0.1 090314-0 2009-03-14 0.00 -
AVG 7.5.52.442 270.11.13/2001 2009-03-14 1.94 -
BitDefender 7.81008.2793145 7.24182 2009-03-15 2.56 -
CA (VET) 9.0.0.143 31.6.6395 2009-03-13 2.45 -
ClamAV 0.94.2 9108 2009-03-15 0.01 -
Comodo 3.8 1056 2009-03-14 0.53 -
CP Secure 1.1.0.715 2009.03.14 2009-03-14 7.42 -
Dr.Web 4.44.0.9170 2009.03.14 2009-03-14 4.21 -
F-Prot 4.4.4.56 20090314 2009-03-14 1.07 -
F-Secure 5.51.6100 2009.03.14.02 2009-03-14 4.83 -
Fortinet 2.81-3.117 10.159 2009-03-14 0.18 -
GData 19.3938/19.261 20090314 2009-03-14 3.30 -
ViRobot 20090313 2009.03.13 2009-03-13 0.40 -
Ikarus T3.1.01.45 2009.03.14.72427 2009-03-14 4.29 -
JiangMin 11.0.706 2009.03.14 2009-03-14 1.57 -
Kaspersky 5.5.10 2009.03.14 2009-03-14 0.04 -
KingSoft 2009.2.5.15 2009.3.14.21 2009-03-14 0.70 -
McAfee 5.3.00 5553 2009-03-14 2.69 -
Microsoft 1.4405 2009.03.14 2009-03-14 4.57 -
mks_vir 2.01 2009.03.13 2009-03-13 2.67 -
Norman 6.00.06 6.00.00 2009-03-13 8.01 -
Panda 9.05.01 2009.03.14 2009-03-14 1.61 -
Trend Micro 8.700-1004 5.896.32 2009-03-14 0.03 -
Quick Heal 10.00 2009.03.14 2009-03-14 0.94 -
Rising 20.0 21.20.52.00 2009-03-14 0.80 -
Sophos 2.84.1 4.39 2009-03-15 2.06 -
Sunbelt 5040 5040 2009-03-13 0.61 -
Symantec 1.3.0.24 20090314.003 2009-03-14 0.05 -
nProtect 20090314.01 3332311 2009-03-14 4.11 -
The Hacker [removed] v00281 2009-03-13 0.58 -
VBA32 3.12.10.1 20090313.1825 2009-03-13 1.74 -
VirusBuster 4.5.11.10 10.102.10/978783 2009-03-14 1.21 -
hello

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
So I ran the ATF Cleaner Then I did a full scan by Malwarebytes' Anti-Malware with recent updates (checked wrong box, sorry) It found a few new things and I rebooted, Log is attached: alwarebytes' Anti-Malware 1.34 Database version: 1851 Windows 5.1.2600 Service Pack 3 3/15/2009 12:37:12 PM mbam-log-2009-03-15 (12-37-12).txt Scan type: Full Scan (A:\|C:\|D:\|) Objects scanned: 244385 Time elapsed: 34 minute(s), 47 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 3 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UACd.sys (Trojan.Agent) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Hijack.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Hijack.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Hijack.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Ran the quick scan which came back clean log is attached: Malwarebytes' Anti-Malware 1.34 Database version: 1852 Windows 5.1.2600 Service Pack 3 3/15/2009 12:48:45 PM mbam-log-2009-03-15 (12-48-45).txt Scan type: Quick Scan Objects scanned: 78313 Time elapsed: 2 minute(s), 10 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) I cannot seem to run the Kapersky program. When I access the program online it tells me that I need java 1.5 installed. I go to the java website and install the latest version and then check it and the java website says I have the latest version. I tried to download the full trial version of Kapersky but when I install it there is an error message that says I need to remove ALWIL Software Avast 4.0??? which is not in my control panel/addremove programs list or start all programs???? :( Also I can now work our of normal mode and access the internet, is this ok or should I still be running out of safe mode?
give this a whirl

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
Completed the "Combo Fix". It told me that I had Norton running but like the program that was giving me trouble with Kapersky Norton is not in the task bar/Start menu/or in add remove programs?????


ComboFix 09-03-15.01 - Administrator 2009-03-15 18:27:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1577 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning enabled* (Outdated)
FW: Norton Internet Security *enabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\Start Menu\Programs\Startup\winlogon.lnk
c:\windows\config.ini
c:\windows\IE4 Error Log.txt
c:\windows\system32\anqasi\winlogon.ini
c:\windows\system32\drivers\str.sys
c:\windows\wiaserviv.log

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_icf


((((((((((((((((((((((((( Files Created from 2009-02-16 to 2009-03-16 )))))))))))))))))))))))))))))))
.

2009-03-15 13:17 . 2009-03-15 13:17 d——– c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-03-14 00:22 . 2009-03-14 00:22 d——– C:\_OTListIt
2009-03-12 01:17 . 2009-03-12 01:17 d——– c:\program files\ERUNT
2009-03-12 00:52 . 2009-03-12 00:52 d——– c:\program files\Trend Micro
2009-03-10 21:40 . 2009-03-15 13:24 d——– c:\program files\SUPERAntiSpyware
2009-03-10 21:40 . 2009-03-10 21:40 d——– c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-03-10 21:40 . 2009-03-15 13:24 d——– c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-03-10 21:12 . 2009-03-10 21:12 d——– C:\myRTVAULT
2009-03-10 18:26 . 2009-03-15 13:18 d——– c:\program files\Enigma Software Group
2009-03-09 23:30 . 2009-03-09 23:30 d——– c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-03-09 23:05 . 2009-03-09 23:27 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-09 23:05 . 2009-03-09 23:05 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-09 23:05 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-09 23:05 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-03-09 22:45 . 2009-03-09 22:45 d——– c:\documents and settings\Administrator\Application Data\thdzifan
2009-03-09 02:09 . 2009-03-09 02:10 d——– c:\windows\BDOSCAN8
2009-03-08 16:15 . 2009-03-08 16:15 d——– c:\program files\AVG
2009-03-08 16:15 . 2009-03-15 13:41 d——– c:\documents and settings\All Users\Application Data\avg8
2009-03-08 14:37 . 2009-03-08 14:37 2 –a—— C:\-535435166
2009-03-08 14:37 . 2009-03-08 15:08 0 –a—— c:\windows\system32\drivers\fab2e477.sys
2009-02-19 23:46 . 2009-02-19 23:46 d——– c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-02-19 23:27 . 2009-02-19 23:27 0 –ah—– c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2009-02-19 23:26 . 2009-02-19 23:26 0 –ah—– c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-15 20:00 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-03-15 20:00 ——— d—–w c:\documents and settings\All Users\Application Data\Symantec
2009-03-15 19:57 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2009-03-15 18:59 ——— d—–w c:\program files\Java
2009-03-11 03:46 ——— d—–w c:\program files\Google
2009-03-11 01:43 1,428 —-a-w c:\program files\wtpqza.txt
2009-03-08 21:48 ——— d—–w c:\documents and settings\Administrator\Application Data\Apple Computer
2009-02-06 19:16 ——— d—–w c:\program files\Ahead
2009-02-06 19:06 ——— d—–w c:\program files\Swf2Avi
2009-01-31 23:57 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-28 02:47 ——— d—–w c:\documents and settings\Administrator\Application Data\TeamViewer
2009-01-28 02:46 ——— d—–w c:\program files\TeamViewer3
2009-01-28 02:46 ——— d—–w c:\program files\TeamViewer
2004-10-01 21:00 40,960 —-a-w c:\program files\Uninstall_CDS.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-15 148888]
"SoundMan"="SOUNDMAN.EXE" [2005-08-17 c:\windows\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2008-05-16 c:\windows\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS SmartDoctor]
–a—— 2006-05-15 12:31 1081344 c:\program files\Asus\SmartDoctor\SmartDoctor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-11-20 14:20 290088 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch Ai Booster]
–a—— 2006-07-06 17:19 3711488 c:\program files\Asus\Ai Booster\OverClk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech.StreamPoint.Host]
–a—— 2007-04-26 13:26 56080 c:\program files\Logitech\StreamPoint\StreamPoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
–a—— 2006-08-24 17:26 1249280 c:\program files\Valve\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zinio DLM]
–a—— 2007-05-04 14:52 3756102 c:\program files\Zinio\ZinioReader.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

S0 jcuptzlq;jcuptzlq;c:\windows\system32\drivers\jcuptzlq.sys [2004-08-04 23424]
S0 miojwt;miojwt;c:\windows\system32\drivers\txdseasq.sys –> c:\windows\system32\drivers\txdseasq.sys [?]
S1 fab2e477;fab2e477;c:\windows\system32\drivers\fab2e477.sys [2009-03-08 0]
S2 yfpnwetfbrslq;yfpnwetfbrslq;\??\c:\windows\system32\drivers\syzzdkv.sys –> c:\windows\system32\drivers\syzzdkv.sys [?]
S3 idrmkl;idrmkl;\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\idrmkl.sys –> c:\docume~1\ADMINI~1\LOCALS~1\Temp\idrmkl.sys [?]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
jjnmobrd

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd96e6d8-521b-11db-8a65-0018f3272aea}]
\Shell\AutoRun\command - setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder

2009-03-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
HKLM-Run-TELUS_McciTrayApp - c:\program files\TELUS\TELUS Support Centre\bin\McciTrayApp.exe
HKLM-Run-TEPA.exe - c:\program files\TELUS\eProtect Advisor\TEPA.exe
HKU-Default-Run-c43x559d6csnw6c9oij - c:\windows\TEMP\yk7n10p72.exe
HKU-Default-Run-gwhhv3idexbbuk0izkiq5cu5n32zqt775vj6jr - c:\windows\TEMP\tbm5guhz2.exe
HKU-Default-Run-qog9arnn69iuswu14nnq40mlfpkgb4xazzr5x8c7x - c:\windows\TEMP\yvff7804wv.exe
HKU-Default-Run-rpemb5f06hhq0qxvvzkbes7huag4779gsimdurkj3ub2ol05s1 - c:\windows\TEMP\heylpco.exe
HKU-Default-Run-vdy24kleokezye6lqt7 - c:\windows\TEMP\j414p2wrd.exe
MSConfigStartUp-BitTorrent - c:\program files\BitTorrent\bittorrent.exe
MSConfigStartUp-winlogon - c:\program files\BitTorrent\bittorrent.exe


.
——- Supplementary Scan ——-
.
uStart Page = www.drudgereport.com/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n09x3eqj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://drudgereport.com/
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-15 18:31:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\SAVRT]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\SNDSrvc]
"ImagePath"="-"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-602162358-842925246-725345543-500\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ec,90,51,28,af,07,48,0a,7f,26,c4,ac,b3,ff,44,42,18,e9,d5,5e,8c,8d,02,
be,1e,8c,9e,ae,ba,6d,ab,fe,1f,e2,f2,5e,86,34,8b,b9,cf,41,28,5c,1c,ce,88,dc,\
"??"=hex:30,19,66,15,31,91,c7,d4,90,dc,e8,a6,b9,c9,30,ea

[HKEY_LOCAL_MACHINE\System\ControlSet003\Enum\DISPLAY\Default_Monitor\7&146ba760&0&11337799&04&00\LogConf]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\System\ControlSet003\Enum\DISPLAY\Default_Monitor\7&1c439a37&0&11337799&03&00\LogConf]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\System\ControlSet003\Enum\DISPLAY\EPIA790\7&146ba760&0&11335577&04&00\LogConf]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\System\ControlSet003\Enum\DISPLAY\GWY088A\7&146ba760&0&11335587&04&00\LogConf]
@DACL=(02 0000)
.
———————— Other Running Processes ————————
.
c:\windows\system32\scardsvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\ATKKBService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-03-15 18:35:29 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-16 00:35:27

Pre-Run: 67,503,050,752 bytes free
Post-Run: 67,426,234,368 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
217 — E O F — 2009-02-25 06:21:08
hello

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
c:\windows\system32\drivers\jcuptzlq.sys
c:\windows\system32\drivers\txdseasq.sys
c:\windows\system32\drivers\fab2e477.sys
c:\windows\system32\drivers\syzzdkv.sys
c:\docume~1\ADMINI~1\LOCALS~1\Temp\idrmkl.sys
C:\-535435166
c:\windows\system32\drivers\fab2e477.sys
c:\program files\wtpqza.txt
Folder::

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd96e6d8-521b-11db-8a65-0018f3272aea}]

Driver::
jcuptzlq
miojwt
fab2e477
yfpnwetfbrslq
idrmkl

KillAll::

NetSvc::
jjnmobrd


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
ComboFix 09-03-15.01 - Administrator 2009-03-16 19:06:30.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1587 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning enabled* (Outdated)
FW: Norton Internet Security *enabled*
* Created a new restore point

FILE ::
C:\-535435166
c:\docume~1\ADMINI~1\LOCALS~1\Temp\idrmkl.sys
c:\program files\wtpqza.txt
c:\windows\system32\drivers\fab2e477.sys
c:\windows\system32\drivers\jcuptzlq.sys
c:\windows\system32\drivers\syzzdkv.sys
c:\windows\system32\drivers\txdseasq.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\-535435166
c:\program files\wtpqza.txt
c:\windows\system32\drivers\fab2e477.sys
c:\windows\system32\drivers\jcuptzlq.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_IDRMKL
——-\Legacy_JCUPTZLQ
——-\Legacy_YFPNWETFBRSLQ
——-\Service_fab2e477
——-\Service_idrmkl
——-\Service_jcuptzlq
——-\Service_miojwt
——-\Service_yfpnwetfbrslq


((((((((((((((((((((((((( Files Created from 2009-02-17 to 2009-03-17 )))))))))))))))))))))))))))))))
.

2009-03-15 13:17 . 2009-03-15 13:17 d——– c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-03-14 00:22 . 2009-03-14 00:22 d——– C:\_OTListIt
2009-03-12 01:17 . 2009-03-12 01:17 d——– c:\program files\ERUNT
2009-03-12 00:52 . 2009-03-12 00:52 d——– c:\program files\Trend Micro
2009-03-10 21:40 . 2009-03-15 13:24 d——– c:\program files\SUPERAntiSpyware
2009-03-10 21:40 . 2009-03-10 21:40 d——– c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-03-10 21:40 . 2009-03-15 13:24 d——– c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-03-10 21:12 . 2009-03-10 21:12 d——– C:\myRTVAULT
2009-03-10 18:26 . 2009-03-15 13:18 d——– c:\program files\Enigma Software Group
2009-03-09 23:30 . 2009-03-09 23:30 d——– c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-03-09 23:05 . 2009-03-09 23:27 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-09 23:05 . 2009-03-09 23:05 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-09 23:05 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-09 23:05 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-03-09 22:45 . 2009-03-09 22:45 d——– c:\documents and settings\Administrator\Application Data\thdzifan
2009-03-09 02:09 . 2009-03-09 02:10 d——– c:\windows\BDOSCAN8
2009-03-08 16:15 . 2009-03-08 16:15 d——– c:\program files\AVG
2009-03-08 16:15 . 2009-03-15 13:41 d——– c:\documents and settings\All Users\Application Data\avg8
2009-02-19 23:46 . 2009-02-19 23:46 d——– c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-02-19 23:27 . 2009-02-19 23:27 0 –ah—– c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2009-02-19 23:26 . 2009-02-19 23:26 0 –ah—– c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-15 20:00 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-03-15 20:00 ——— d—–w c:\documents and settings\All Users\Application Data\Symantec
2009-03-15 19:57 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2009-03-15 18:59 ——— d—–w c:\program files\Java
2009-03-11 03:46 ——— d—–w c:\program files\Google
2009-03-08 21:48 ——— d—–w c:\documents and settings\Administrator\Application Data\Apple Computer
2009-02-06 19:16 ——— d—–w c:\program files\Ahead
2009-02-06 19:06 ——— d—–w c:\program files\Swf2Avi
2009-01-31 23:57 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-28 02:47 ——— d—–w c:\documents and settings\Administrator\Application Data\TeamViewer
2009-01-28 02:46 ——— d—–w c:\program files\TeamViewer3
2009-01-28 02:46 ——— d—–w c:\program files\TeamViewer
2004-10-01 21:00 40,960 —-a-w c:\program files\Uninstall_CDS.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-03-15_18.34.57.10 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-17 01:09:27 16,384 —-atw c:\windows\temp\Perflib_Perfdata_6b4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-15 148888]
"SoundMan"="SOUNDMAN.EXE" [2005-08-17 c:\windows\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2008-05-16 c:\windows\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS SmartDoctor]
–a—— 2006-05-15 12:31 1081344 c:\program files\Asus\SmartDoctor\SmartDoctor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-11-20 14:20 290088 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch Ai Booster]
–a—— 2006-07-06 17:19 3711488 c:\program files\Asus\Ai Booster\OverClk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech.StreamPoint.Host]
–a—— 2007-04-26 13:26 56080 c:\program files\Logitech\StreamPoint\StreamPoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
–a—— 2006-08-24 17:26 1249280 c:\program files\Valve\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zinio DLM]
–a—— 2007-05-04 14:52 3756102 c:\program files\Zinio\ZinioReader.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

.
Contents of the 'Scheduled Tasks' folder

2009-03-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = www.drudgereport.com/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n09x3eqj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://drudgereport.com/
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-16 19:10:39
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\SAVRT]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\SNDSrvc]
"ImagePath"="-"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-602162358-842925246-725345543-500\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ec,90,51,28,af,07,48,0a,7f,26,c4,ac,b3,ff,44,42,18,e9,d5,5e,8c,8d,02,
be,1e,8c,9e,ae,ba,6d,ab,fe,1f,e2,f2,5e,86,34,8b,b9,cf,41,28,5c,1c,ce,88,dc,\
"??"=hex:30,19,66,15,31,91,c7,d4,90,dc,e8,a6,b9,c9,30,ea

[HKEY_LOCAL_MACHINE\System\ControlSet003\Enum\DISPLAY\Default_Monitor\7&146ba760&0&11337799&04&00\LogConf]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\System\ControlSet003\Enum\DISPLAY\Default_Monitor\7&1c439a37&0&11337799&03&00\LogConf]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\System\ControlSet003\Enum\DISPLAY\EPIA790\7&146ba760&0&11335577&04&00\LogConf]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\System\ControlSet003\Enum\DISPLAY\GWY088A\7&146ba760&0&11335587&04&00\LogConf]
@DACL=(02 0000)
.
———————— Other Running Processes ————————
.
c:\windows\system32\scardsvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\ATKKBService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-03-16 19:14:27 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-17 01:14:24
ComboFix2.txt 2009-03-16 00:35:30

Pre-Run: 67,352,764,416 bytes free
Post-Run: 67,384,950,784 bytes free

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
206 — E O F — 2009-02-25 06:21:08
hello

Please download OTMoveIt3 by OldTimer
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    c:\documents and settings\Administrator\Application Data\thdzifan
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Download RootRepeal.zip and unzip it to your Desktop.
  • Double click RootRepeal.exe to start the program
  • Click on the Report tab at the bottom of the program window
  • Click the Scan button
  • In the Select Scan dialog, check:
    • Drivers
    • Files
    • Processes
    • SSDT
    • Stealth Objects
    • Hidden Services
  • Click the OK button
  • In the next dialog, select all drives showing
  • Click OK to start the scan

    Note: The scan can take some time. DO NOT run any other programs while the scan is running

  • When the scan is complete, the Save Report button will become available
  • Click this and save the report to your Desktop as RootRepeal.txt
If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI