This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Userinit Infected Swizzor aswell as multiple problems

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:pullhair:

I am loosing My mind .. after Antispyware 2009 removal I have had one thing after another.. I am currently running AVG yet I cannot access IE (pages will not load) yet I do have access to the Net. This was also true on Firfox But after removal and reinstall I have access via Firefox ( I hate IE but with most updates and installations its Necessary)

I have seen most Do a hijackthis log in posts so I have downloaded and am uploading aswell…

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:20:38 AM, on 3/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:7070
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKUS\S-1-5-21-2588003286-1639580014-1869957976-500\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Administrator')
O4 - HKUS\S-1-5-21-2588003286-1639580014-1869957976-500\..\RunOnce: [NeroHomeFirstStart] C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe (User 'Administrator')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: Suitcase Startup.lnk = ?
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.moove.com
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.0.6.2.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll orvvvu.dll xzalbd.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: khfDstUo - khfDstUo.dll (file missing)
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe

–
End of file - 12920 bytes
Hi there,

Welcome to WTT.

Please download ATF Cleaner by Atribune.Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Download Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have installed Windows). Post that in your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Download OTListIt2.exe and save it to your desktop
  • Double click OTListIt2.exe to run the program
  • Put a checkmark into Scan All Users
  • In the Output box, make sure that Minimal Output is selected
  • In Extra Registry check Use SafeList
  • In the File Age drop down menu, select 60 Days
  • Click the Run Scan button
When the scan is complete, a log will open named OTListIt.Txt another log will also be produced but will be minimised, named Extras.Txt Both these logs will be saved to your desktop.

Please post the contents of both logs in your next reply.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


So in your next reply, please include the following logs:
  • The contents of the MBAM log
  • The contents of Rooter.txt
  • The contents of bothe OTListIt logs
Please make a separate post for each log.

Regards,
RatHat
thanks I am running MBAM right now though due to IE not working I cant run updates for it… Will post logs soon as Finished :pullhair: MBAM Malwarebytes' Anti-Malware 1.33 Database version: 1705 Windows 5.1.2600 Service Pack 3 3/14/2009 8:29:59 PM mbam-log-2009-03-14 (20-29-54).txt Scan type: Quick Scan Objects scanned: 64141 Time elapsed: 9 minute(s), 49 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\userinit.exe -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\userinit.exe -> No action taken. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Microsoft Windows XP Professional (5.1.2600) Service Pack 3

C:\ [Fixed] - NTFS - (Total:229749 Mo/Free:3184 Mo)
D:\ [Fixed] - FAT32 - (Total:8706 Mo/Free:1156 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
F:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
G:\ [Removable] (Total:0 Mo/Free:0 Mo)
H:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
I:\ [Removable] (Total:0 Mo/Free:0 Mo)
J:\ [Removable] (Total:0 Mo/Free:0 Mo)
K:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
L:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
M:\ [Removable] (Total:0 Mo/Free:0 Mo)

Sat 03/14/2009|21:00

———————-\\ Processes..

–Locked– [System Process]
———- System
———- \SystemRoot\System32\smss.exe
———- \??\C:\WINDOWS\system32\csrss.exe
———- \??\C:\WINDOWS\system32\winlogon.exe
———- C:\WINDOWS\system32\services.exe
———- C:\WINDOWS\system32\lsass.exe
———- C:\WINDOWS\system32\Ati2evxx.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\Ati2evxx.exe
———- C:\WINDOWS\system32\spoolsv.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
———- C:\WINDOWS\arservice.exe
———- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
———- C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
———- C:\Program Files\Java\jre6\bin\jusched.exe
———- C:\WINDOWS\system32\ctfmon.exe
———- C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe
———- C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
———- C:\Program Files\Bonjour\mDNSResponder.exe
———- C:\WINDOWS\eHome\ehRecvr.exe
———- C:\WINDOWS\eHome\ehSched.exe
———- C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
———- C:\Program Files\Java\jre6\bin\jqs.exe
———- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
———- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
———- C:\PROGRA~1\AVG\AVG8\avgrsx.exe
———- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
———- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
———- C:\WINDOWS\system32\PSIService.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
———- C:\WINDOWS\system32\dllhost.exe
———- C:\WINDOWS\system32\wbem\unsecapp.exe
———- C:\WINDOWS\System32\alg.exe
———- C:\WINDOWS\system32\wbem\wmiprvse.exe
———- C:\HP\KBD\KBD.EXE
———- C:\WINDOWS\ALCXMNTR.EXE
———- c:\windows\system\hpsysdrv.exe
———- C:\WINDOWS\system32\rundll32.exe
———- C:\WINDOWS\explorer.exe
———- C:\Documents and Settings\HP_Administrator\Desktop\fraps\fraps.exe
———- C:\Program Files\Mozilla Firefox\firefox.exe
———- C:\WINDOWS\system32\cmd.exe
———- C:\Rooter$\RK.exe

———————-\\ Search..

==> VUNDO <==

———————-\\ ROOTKIT !!

HKLM\SYSTEM\ControlSet001\Services\seneka
HKLM\SYSTEM\ControlSet002\Services\seneka
HKLM\SYSTEM\CurrentControlSet\Services\seneka

———————-\\ Cracks & Keygens..

C:\DOCUME~1\HP_ADM~1\Desktop\downloads\Limewire Lime Wire Pro v.4.8.1 Cracked with Java Runtime Environment.zip
C:\DOCUME~1\HP_ADM~1\My Documents\brushes\brushes\brushesps7\vered_cracked_wall_ps7_brush.zip
C:\DOCUME~1\ALLUSE~1\Documents\Plant Tycoon [+ crack].zip
C:\DOCUME~1\ALLUSE~1\Documents\Files\2008\Corel Paint Shop Pro Photo X2 with Crack\Readme.txt
C:\DOCUME~1\ALLUSE~1\Documents\Files\2008\Corel Paint Shop Pro Photo X2 with Crack\pspx2\installer.exe
C:\DOCUME~1\ALLUSE~1\Documents\Files\2008\Corel Paint Shop Pro Photo X2 with Crack\pspx2\msi31.exe
C:\DOCUME~1\ALLUSE~1\Documents\Files\2008\Corel Paint Shop Pro Photo X2 with Crack\pspx2\setup.exe
C:\DOCUME~1\ALLUSE~1\Documents\Files\2008\Corel Paint Shop Pro Photo X2 with Crack\pspx2\Crack\Corel Paint Shop Pro Photo.exe
C:\DOCUME~1\ALLUSE~1\Documents\Files\2008\Julia reformat July 17, 2008\Reformat\Downloads to Keep\Removed from Steves Computer\Palm4Steve\For Palm\TealPaint__Keygen\imagemgr.exe
C:\DOCUME~1\ALLUSE~1\Documents\Files\2008\Julia reformat July 17, 2008\Reformat\Downloads to Keep\Removed from Steves Computer\Palm4Steve\For Palm\TealPaint__Keygen\picutil.exe
C:\DOCUME~1\ALLUSE~1\Documents\Files\2008\Julia reformat July 17, 2008\Reformat\Downloads to Keep\Removed from Steves Computer\Palm4Steve\For Palm\TealPaint__Keygen\register.txt
C:\DOCUME~1\ALLUSE~1\Documents\Files\2008\Julia reformat July 17, 2008\Reformat\Downloads to Keep\Removed from Steves Computer\Palm4Steve\For Palm\TealPaint__Keygen\TPSetup.exe
C:\DOCUME~1\ALLUSE~1\Documents\Files\2008\Julia reformat July 17, 2008\Reformat\Downloads to Keep\Removed from Steves Computer\pspx2\Crack\Corel Paint Shop Pro Photo.exe
C:\DOCUME~1\ALLUSE~1\Documents\Files\2008\Julia reformat July 17, 2008\Reformat\Scrapbooking and Clipart\Scrapbooking\Zipped Scrapbooking Done\christmas_on_crack.zip
C:\DOCUME~1\ALLUSE~1\Documents\Files\2008\Need to Sort\Bigfish Games - Virtual Villagers - The Secret City + Adnan_Boy 2008 + Precracked\PLEASE SEED.txt
C:\DOCUME~1\ALLUSE~1\Documents\Files\2008\Need to Sort\Bigfish Games - Virtual Villagers - The Secret City + Adnan_Boy 2008 + Precracked\Torrent downloaded from Demonoid.com.txt
C:\DOCUME~1\ALLUSE~1\Documents\Files\2008\Need to Sort\Bigfish Games - Virtual Villagers - The Secret City + Adnan_Boy 2008 + Precracked\Virtual Villagers - The Secret City.exe
C:\DOCUME~1\ALLUSE~1\Documents\Files\2008\Need to Sort\go binder\gobinder.v2005\gobinder.v2005.crack.exe
C:\DOCUME~1\ALLUSE~1\Documents\Files\2008\Programs to Keep\Mindjet MindManager Pro v7.0.429\keygen.exe
C:\DOCUME~1\ALLUSE~1\Documents\Files\2008\Programs to Keep\off07\Crack.txt
C:\DOCUME~1\ALLUSE~1\Documents\Files\2008\Programs to Keep\Penguins [ Indian Boy 2007 ]\Penguins Crack\penguins-WT.exe


1 - "C:\Rooter$\Rooter_1.txt" - Sat 03/14/2009|21:02

———————-\\ Scan completed at 21:02
OTListIt logfile created on: 3/14/2009 9:21:12 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.3.8 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.48 Mb Total Physical Memory | 491.97 Mb Available Physical Memory | 51.33% Memory free
2.26 Gb Paging File | 1.75 Gb Available in Paging File | 77.40% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.37 Gb Total Space | 3.11 Gb Free Space | 1.38% Space Free | Partition Type: NTFS
Drive D: | 8.50 Gb Total Space | 1.13 Gb Free Space | 13.28% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TEKNIQ
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 60 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\HP\HP Software Update\HPwuSchd2.exe (Hewlett-Packard Co.)
PRC - C:\WINDOWS\arservice.exe (Microsoft)
PRC - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe (TuneUp Software GmbH)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Computer, Inc.)
PRC - C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe (DataViz, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\PSIService.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\HP\KBD\KBD.EXE (Hewlett-Packard Company)
PRC - C:\WINDOWS\ALCXMNTR.EXE (Realtek Semiconductor Corp.)
PRC - c:\windows\system\hpsysdrv.exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\HP_Administrator\Desktop\fraps\fraps.exe (Beepa P/L)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\HP_Administrator\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe Version Cue CS3 [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (Adobe Systems Incorporated)
SRV - (ARSVC [Auto | Running]) – C:\WINDOWS\arservice.exe (Microsoft)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Computer, Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ehRecvr [Auto | Running]) – C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [Auto | Running]) – C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Stopped]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (LVCOMSer [Auto | Running]) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (LVPrcSrv [Auto | Running]) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (McrdSvc [Auto | Stopped]) – C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (MHN [On_Demand | Stopped]) – C:\WINDOWS\System32\mhn.dll (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service [On_Demand | Stopped]) – C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (NBService [On_Demand | Stopped]) – C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (Nero AG)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Boot | Stopped]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (ProtexisLicensing [Auto | Running]) – C:\WINDOWS\system32\PSIService.exe ()
SRV - (TabletServicePen [Auto | Stopped]) – C:\WINDOWS\system32\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (UxTuneUp [Auto | Running]) – C:\WINDOWS\System32\uxtuneup.dll (TuneUp Software GmbH)
SRV - (WLSetupSvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (sdAuxService [On_Demand | Stopped]) – C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (sdCoreService [On_Demand | Stopped]) – C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AmdK8 [System | Running]) – C:\WINDOWS\system32\DRIVERS\AmdK8.sys (Advanced Micro Devices)
DRV - (ASPI32 [System | Running]) – C:\WINDOWS\System32\drivers\Aspi32.sys (Adaptec)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (bb-run [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\bb-run.sys (Promise Technology, Inc.)
DRV - (dtscsi [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\dtscsi.sys ()
DRV - (ftsata2 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ftsata2.sys (Promise Technology, Inc.)
DRV - (HPZid412 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys (HP)
DRV - (HSFHWBS2 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (iaStor [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (LVPr2Mon [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys ()
DRV - (LVUSBSta [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\LVUSBSta.sys (Logitech Inc.)
DRV - (mcdbus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\mcdbus.sys (MagicISO, Inc.)
DRV - (MCSTRM [Auto | Running]) – C:\WINDOWS\System32\drivers\mcstrm.sys (RealNetworks, Inc.)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (PalmUSBD [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (PenClass [Boot | Running]) – C:\WINDOWS\system32\Drivers\PenClass.sys (Wacom Technology Corporation)
DRV - (PID_0928 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\LV561AV.SYS (Logitech Inc.)
DRV - (Ps2 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\PS2.sys (Hewlett-Packard Company)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (RTL8023xp [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (rtl8139 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (SCDEmu [System | Running]) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sptd [Boot | Running]) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (tffsport [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\tffsport.sys (M-Systems)
DRV - (wacmoumonitor [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\wacmoumonitor.sys (Wacom Technology)
DRV - (wacommousefilter [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys (Wacom Technology)
DRV - (wacomvhid [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\wacomvhid.sys (Wacom Technology)
DRV - (WacomVKHid [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\WacomVKHid.sys (Wacom Technology)
DRV - (WIBUKEY [Auto | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\WibuKey.sys (WIBU-SYSTEMS AG)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (PCTCore [Boot | Running]) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://ll-tek-ll.deviantart.com/"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:0.5.9
FF - prefs.js..extensions.enabledItems: {94C030E5-CEF2-4C67-AE5A-D99F805C1D5B}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - prefs.js..extensions.enabledItems: [removed]:3.1
FF - prefs.js..extensions.enabledItems: [removed]:0.6.20090117
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX [2009/02/01 17:53:34 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{1d5287d1-8a92-0001-1f31-1cec198018d8}: C:\PROGRAM FILES\AVG\AVG8\TOOLBARFF [2009/02/01 17:53:34 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008/11/23 08:18:37 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{94C030E5-CEF2-4C67-AE5A-D99F805C1D5B}: C:\DOCUMENTS AND SETTINGS\HP_ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\{94C030E5-CEF2-4C67-AE5A-D99F805C1D5B}\ [2009/01/29 14:15:11 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/14 07:01:22 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/09 20:31:21 | 00,000,000 | —D | M]
[2009/01/29 21:21:00 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\mozilla\Extensions
[2009/01/29 21:21:00 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/03/14 05:19:40 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\mozilla\Firefox\Profiles\cvhw8qw6.default\extensions
[2009/02/22 02:30:06 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\mozilla\Firefox\Profiles\cvhw8qw6.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2009/01/29 22:09:20 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\mozilla\Firefox\Profiles\cvhw8qw6.default\extensions\[removed]
[2009/01/29 22:04:06 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\mozilla\Firefox\Profiles\cvhw8qw6.default\extensions\[removed]
[2009/03/14 05:19:40 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/03/05 05:50:10 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/03/23 23:44:54 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/07/23 06:34:44 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2008/11/23 08:18:50 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2008/12/14 16:00:30 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/03/05 05:49:57 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/05 05:49:57 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll

O1 HOSTS File: (256715 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 8926 more lines…
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe [2008/04/07 10:09:25 | 00,000,000 | —D | M]
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C6BB606F-232D-4957-8AFF-7D4F4A220F67} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE (Microsoft)
O4 - HKLM..\Run: [ATICustomerCare] "C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe" (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe (Hewlett-Packard)
O4 - HKLM..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start (Macrovision Corporation)
O4 - HKLM..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe (Enigma Software Group USA, LLC.)
O4 - HKLM..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H (PC Tools)
O4 - HKCU..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe" autostart (TuneUp Software GmbH)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe (DataViz, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Suitcase Startup.lnk = C:\Program Files\Extensis\Suitcase 9.2\Suitcase.exe (Extensis Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe (Wacom Technology, Corp.)
O4 - Startup: C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\PowerReg Scheduler.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMorePrograms = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetFolders = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O8 - Extra context menu item: &D;&ownload; &with; BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D;&ownload; all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D;&ownload; all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O15 - HKLM\..Trusted Domains: 43 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: moove.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: 42 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.0.6.2.cab (DownloadManager Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (orvvvu.dll) - File not found
O20 - AppInit_DLLs: (xzalbd.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe ()
O20 - HKLM Winlogon: UIHost - (C:\Documents) - File not found
O20 - HKLM Winlogon: UIHost - (and) - File not found
O20 - HKLM Winlogon: UIHost - (Settings\All) - File not found
O20 - HKLM Winlogon: UIHost - (Users\Application) - File not found
O20 - HKLM Winlogon: UIHost - (Data\TuneUp) - File not found
O20 - HKLM Winlogon: UIHost - (Software\TuneUp) - File not found
O20 - HKLM Winlogon: UIHost - (Utilities\WinStyler\tu_logonui.exe) - File not found
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\khfDstUo: DllName - khfDstUo.dll - File not found
O21 - SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - C:\Program Files\Common Files\Stardock\MCPCore.dll File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\vtUooLbY) - File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - D:\AUTOEXEC.BAT () - [ FAT32 ]
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play;

========== Files/Folders - Created Within 60 Days ==========

[1 C:\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/03/14 20:21:53 | 00,498,176 | —- | C] (OldTimer Tools) – C:\DOCUME~1\HP_ADM~1\Desktop\OTListIt2.exe
[2009/03/14 20:19:34 | 00,000,000 | —D | C] – C:\Rooter$
[2009/03/14 20:19:15 | 00,267,612 | —- | C] () – C:\DOCUME~1\HP_ADM~1\Desktop\Rooter.exe
[2009/03/14 19:55:29 | 26,333,068 | —- | C] () – C:\DOCUME~1\HP_ADM~1\Desktop\Steampunk_Circus_Doll_Pack_4_by_mizzd_stock.zip
[2009/03/14 19:55:18 | 17,390,628 | —- | C] () – C:\DOCUME~1\HP_ADM~1\Desktop\Steampunk_Circus_Doll_Pack_5_by_mizzd_stock.zip
[2009/03/14 09:13:53 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\226532f.dll
[2009/03/14 09:13:53 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\1dbaadec.dll
[2009/03/14 08:42:41 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\2415e5d5.dll
[2009/03/14 08:42:41 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\16616da4.dll
[2009/03/14 08:05:26 | 00,001,745 | —- | C] () – C:\DOCUME~1\HP_ADM~1\Desktop\HijackThis.lnk
[2009/03/14 08:05:24 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/14 07:33:21 | 00,159,600 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctgntdi.sys
[2009/03/14 07:32:52 | 00,130,424 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2009/03/14 07:32:51 | 00,073,840 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2009/03/14 07:32:37 | 00,001,648 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\Spyware Doctor.lnk
[2009/03/14 07:32:35 | 00,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2009/03/14 07:32:34 | 00,064,392 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctplsg.sys
[2009/03/14 07:32:29 | 00,000,000 | —D | C] – C:\Program Files\Spyware Doctor
[2009/03/14 07:32:29 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\PC Tools
[2009/03/14 07:32:29 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2009/03/14 07:32:25 | 00,000,749 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\Registry Mechanic.lnk
[2009/03/14 07:32:21 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\STKIT432.DLL
[2009/03/14 07:32:19 | 00,000,000 | —D | C] – C:\Program Files\Registry Mechanic
[2009/03/14 07:31:02 | 23,608,320 | —- | C] (PC Tools ) – C:\DOCUME~1\HP_ADM~1\Desktop\sdsetup.exe
[2009/03/14 06:47:40 | 00,000,910 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\SpyHunter.lnk
[2009/03/14 06:47:25 | 00,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2009/03/14 06:45:14 | 09,772,784 | —- | C] () – C:\DOCUME~1\HP_ADM~1\Desktop\SpyHunter-Scanner-ri-Install.exe
[2009/03/14 05:44:06 | 09,170,103 | —- | C] () – C:\DOCUME~1\HP_ADM~1\Desktop\Package___Cosmos___7_by_resurgere.zip
[2009/03/14 05:29:36 | 00,015,688 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/03/14 05:29:31 | 00,000,106 | -H– | C] () – C:\aaw7boot.cmd
[2009/03/13 11:35:44 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/03/13 11:35:41 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/03/13 11:31:52 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/03/13 11:31:51 | 00,000,878 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\Ad-Aware.lnk
[2009/03/13 05:48:26 | 40,540,552 | —- | C] () – C:\DOCUME~1\HP_ADM~1\Desktop\West_Of_Eden_Pack_by_flordelys_stock.zip
[2009/03/13 05:48:18 | 03,976,060 | —- | C] () – C:\DOCUME~1\HP_ADM~1\Desktop\West_Of_Eden_Variation_by_flordelys_stock.zip
[2009/03/12 22:50:34 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Xfire
[2009/03/12 22:50:32 | 00,000,649 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\Xfire.lnk
[2009/03/12 22:50:29 | 00,000,000 | —D | C] – C:\Program Files\Xfire
[2009/03/12 17:45:29 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\19925568.dll
[2009/03/12 17:45:29 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\18271a04.dll
[2009/03/11 01:30:09 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\cf7dbaa.dll
[2009/03/11 01:30:08 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\e8bb643.dll
[2009/03/09 20:35:47 | 00,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2009/03/09 20:23:22 | 01,931,136 | —- | C] () – C:\DOCUME~1\HP_ADM~1\Desktop\3D_object___wings4_by_AzurylipfesStock.rar
[2009/03/09 20:23:13 | 01,077,645 | —- | C] () – C:\DOCUME~1\HP_ADM~1\Desktop\3D_object___wings3_by_AzurylipfesStock.rar
[2009/03/08 22:47:21 | 21,691,996 | —- | C] () – C:\DOCUME~1\HP_ADM~1\Desktop\Scene_Sunshine_by_kime_stock.zip
[2009/03/08 22:47:03 | 11,064,022 | —- | C] () – C:\DOCUME~1\HP_ADM~1\Desktop\Scene_Heels_2_by_kime_stock.zip
[2009/03/08 22:46:53 | 11,774,306 | —- | C] () – C:\DOCUME~1\HP_ADM~1\Desktop\Scene_Heels_by_kime_stock.zip
[2009/03/08 22:46:36 | 16,259,267 | —- | C] () – C:\DOCUME~1\HP_ADM~1\Desktop\Scene_Perspective_2_by_kime_stock.zip
[2009/03/08 13:24:28 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\3cfba05.dll
[2009/03/08 13:24:27 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\433702c.dll
[2009/03/08 08:55:54 | 35,436,880 | —- | C] () – C:\DOCUME~1\HP_ADM~1\Desktop\Grunge_texture_PACK_by_gsdark_stock.zip
[2009/03/07 13:55:52 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/03/07 13:55:52 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/03/07 08:05:08 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\1f8c8c9.dll
[2009/03/07 08:05:08 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\12685e6a.dll
[2009/03/06 18:50:38 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\9055298.dll
[2009/03/06 18:50:37 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\4e0598b.dll
[2009/03/06 18:27:41 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\7525b70.dll
[2009/03/06 18:27:40 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\151565bc.dll
[2009/03/06 18:16:13 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\ATI
[2009/03/06 18:16:13 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ATI
[2009/03/06 18:16:13 | 00,000,000 | —D | C] – C:\DOCUME~1\HP_ADM~1\Local Settings\Application Data\ATI
[2009/03/06 18:15:16 | 00,000,000 | —D | C] – C:\WTablet
[2009/03/06 18:14:04 | 00,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2009/03/06 18:12:02 | 00,000,000 | —D | C] – C:\Program Files\ATI
[2009/03/06 18:09:32 | 00,000,000 | —D | C] – C:\NGM
[2009/03/06 18:09:23 | 00,593,920 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2009/03/06 18:07:51 | 00,000,000 | —D | C] – C:\ATI
[2009/03/03 10:57:56 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie7
[2009/03/03 04:31:07 | 00,000,000 | —D | C] – C:\DOCUME~1\HP_ADM~1\Desktop\fraps
[2009/03/02 02:13:53 | 03,495,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_33.dll
[2009/02/26 15:26:25 | 00,000,000 | —D | C] – C:\DOCUME~1\HP_ADM~1\My Documents\Sceencaps-CA
[2009/02/26 13:47:56 | 00,042,320 | —- | C] () – C:\WINDOWS\System32\xfcodec.dll
[2009/02/25 11:06:16 | 00,000,000 | —D | C] – C:\Program Files\Common Files\INCA Shared
[2009/02/25 10:46:43 | 00,000,000 | —D | C] – C:\Program Files\G4box
[2009/02/06 02:59:22 | 00,000,447 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\12Sky.lnk
[2009/02/06 02:59:22 | 00,000,000 | —D | C] – C:\AeriaGames
[2009/02/04 21:55:17 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\e0bf750.dll
[2009/02/04 21:55:17 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\34165fe.dll
[2009/02/03 23:44:03 | 00,155,648 | —- | C] (ATI Technologies, Inc.) – C:\WINDOWS\System32\Oemdspif.dll
[2009/02/03 23:13:29 | 00,121,808 | —- | C] () – C:\WINDOWS\System32\ativvaxx.cap
[2009/02/03 23:13:21 | 03,107,788 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2009/02/03 23:13:21 | 00,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2009/02/03 20:12:25 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\1e706c7a.dll
[2009/02/03 20:12:25 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\1768c65.dll
[2009/02/03 04:25:45 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\91075f4.dll
[2009/02/03 04:25:44 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\2a040853.dll
[2009/02/02 23:34:06 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\7d01aa.dll
[2009/02/02 23:34:06 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\5a27420.dll
[2009/02/02 22:04:21 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\7e8ff70.dll
[2009/02/02 22:04:21 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\139f1362.dll
[2009/02/02 20:57:43 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\ead6c6b.dll
[2009/02/02 20:57:43 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\3af3962.dll
[2009/02/01 17:59:02 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\dee2a10.dll
[2009/02/01 17:59:01 | 00,082,432 | -H– | C] (Microsoft Corporation) – C:\WINDOWS\System32\5ff2470.dll
[2009/01/29 21:20:48 | 00,001,613 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\Mozilla Firefox.lnk
[2009/01/29 17:34:31 | 00,000,059 | —- | C] () – C:\WINDOWS\System32\senekafuucrlov.dat
[2009/01/29 17:34:29 | 00,000,889 | —- | C] () – C:\WINDOWS\System32\senekaswewfvma.dat
[2009/01/29 17:29:29 | 00,000,217 | —- | C] () – C:\WINDOWS\System32\senekauwixtylq.dat
[2009/01/29 17:12:54 | 00,000,000 | —D | C] – C:\Program Files\System
[2009/01/29 17:09:47 | 10,051,13344 | -HS- | C] () – C:\hiberfil.sys
[2009/01/29 16:56:31 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\stu2.exe
[2009/01/29 14:15:10 | 00,000,000 | —D | C] – C:\DOCUME~1\HP_ADM~1\Local Settings\Application Data\{94C030E5-CEF2-4C67-AE5A-D99F805C1D5B}
[2009/01/29 13:52:47 | 00,000,059 | —- | C] () – C:\WINDOWS\System32\senekamepfrlmw.dat
[2009/01/29 13:52:34 | 00,001,104 | —- | C] () – C:\WINDOWS\jpbdzsat
[2009/01/29 13:47:44 | 00,003,925 | —- | C] () – C:\WINDOWS\System32\senekajctgnvig.dat
[2009/01/26 20:20:27 | 00,000,000 | —D | C] – C:\DOCUME~1\ALLUSE~1\Documents\Pictures

========== Files - Modified Within 60 Days ==========

[1 C:\*.tmp files]
[14 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/03/14 20:21:53 | 00,498,176 | —- | M] (OldTimer Tools) – C:\DOCUME~1\HP_ADM~1\Desktop\OTListIt2.exe
[2009/03/14 20:19:16 | 00,267,612 | —- | M] () – C:\DOCUME~1\HP_ADM~1\Desktop\Rooter.exe
[2009/03/14 19:57:26 | 26,333,068 | —- | M] () – C:\DOCUME~1\HP_ADM~1\Desktop\Steampunk_Circus_Doll_Pack_4_by_mizzd_stock.zip
[2009/03/14 19:56:14 | 17,390,628 | —- | M] () – C:\DOCUME~1\HP_ADM~1\Desktop\Steampunk_Circus_Doll_Pack_5_by_mizzd_stock.zip
[2009/03/14 08:31:50 | 34,058,980 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/03/14 08:05:26 | 00,001,745 | —- | M] () – C:\DOCUME~1\HP_ADM~1\Desktop\HijackThis.lnk
[2009/03/14 07:32:37 | 00,001,648 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\Spyware Doctor.lnk
[2009/03/14 07:32:25 | 00,000,749 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\Registry Mechanic.lnk
[2009/03/14 07:31:27 | 23,608,320 | —- | M] (PC Tools ) – C:\DOCUME~1\HP_ADM~1\Desktop\sdsetup.exe
[2009/03/14 06:47:40 | 00,000,910 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\SpyHunter.lnk
[2009/03/14 06:45:23 | 09,772,784 | —- | M] () – C:\DOCUME~1\HP_ADM~1\Desktop\SpyHunter-Scanner-ri-Install.exe
[2009/03/14 06:00:01 | 00,000,332 | —- | M] () – C:\WINDOWS\tasks\xmjsuztu.job
[2009/03/14 05:44:18 | 09,170,103 | —- | M] () – C:\DOCUME~1\HP_ADM~1\Desktop\Package___Cosmos___7_by_resurgere.zip
[2009/03/14 05:29:31 | 00,000,106 | -H– | M] () – C:\aaw7boot.cmd
[2009/03/14 05:29:17 | 00,000,186 | —- | M] () – C:\WINDOWS\System\hpsysdrv.DAT
[2009/03/14 05:25:56 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/14 05:24:44 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/14 05:24:39 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/03/14 05:24:35 | 10,051,13344 | -HS- | M] () – C:\hiberfil.sys
[2009/03/13 17:18:42 | 00,000,412 | —- | M] () – C:\WINDOWS\tasks\1-Click Maintenance.job
[2009/03/13 11:35:45 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/03/13 11:35:17 | 00,015,688 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2009/03/13 11:34:59 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/03/13 11:31:51 | 00,000,878 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\Ad-Aware.lnk
[2009/03/13 11:18:57 | 00,410,904 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/13 11:18:57 | 00,065,248 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/13 11:18:56 | 00,483,988 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/13 05:49:14 | 40,540,552 | —- | M] () – C:\DOCUME~1\HP_ADM~1\Desktop\West_Of_Eden_Pack_by_flordelys_stock.zip
[2009/03/13 05:48:34 | 03,976,060 | —- | M] () – C:\DOCUME~1\HP_ADM~1\Desktop\West_Of_Eden_Variation_by_flordelys_stock.zip
[2009/03/13 04:58:30 | 00,037,735 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/03/12 23:30:14 | 00,075,264 | —- | M] () – C:\DOCUME~1\HP_ADM~1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/12 22:50:32 | 00,000,649 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\Xfire.lnk
[2009/03/09 20:23:24 | 01,931,136 | —- | M] () – C:\DOCUME~1\HP_ADM~1\Desktop\3D_object___wings4_by_AzurylipfesStock.rar
[2009/03/09 20:23:16 | 01,077,645 | —- | M] () – C:\DOCUME~1\HP_ADM~1\Desktop\3D_object___wings3_by_AzurylipfesStock.rar
[2009/03/08 22:50:32 | 21,691,996 | —- | M] () – C:\DOCUME~1\HP_ADM~1\Desktop\Scene_Sunshine_by_kime_stock.zip
[2009/03/08 22:49:51 | 16,259,267 | —- | M] () – C:\DOCUME~1\HP_ADM~1\Desktop\Scene_Perspective_2_by_kime_stock.zip
[2009/03/08 22:48:28 | 11,064,022 | —- | M] () – C:\DOCUME~1\HP_ADM~1\Desktop\Scene_Heels_2_by_kime_stock.zip
[2009/03/08 22:48:27 | 11,774,306 | —- | M] () – C:\DOCUME~1\HP_ADM~1\Desktop\Scene_Heels_by_kime_stock.zip
[2009/03/08 08:59:13 | 35,436,880 | —- | M] () – C:\DOCUME~1\HP_ADM~1\Desktop\Grunge_texture_PACK_by_gsdark_stock.zip
[2009/03/07 13:55:52 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/03/07 13:55:52 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/03/06 18:14:04 | 00,000,000 | —- | M] () – C:\WINDOWS\ativpsrm.bin
[2009/03/06 16:45:06 | 00,130,424 | —- | M] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2009/03/03 11:19:23 | 00,000,087 | -HS- | M] () – C:\DOCUME~1\HP_ADM~1\My Documents\desktop.ini
[2009/03/03 11:00:07 | 00,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/03/01 08:04:46 | 00,001,508 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\Combat Arms.lnk
[2009/02/26 13:47:56 | 00,042,320 | —- | M] () – C:\WINDOWS\System32\xfcodec.dll
[2009/02/25 13:31:16 | 01,590,568 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/02/23 08:44:32 | 00,401,372 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/02/06 02:59:22 | 00,000,447 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\12Sky.lnk
[2009/02/03 23:44:16 | 00,196,608 | —- | M] (ATI Technologies, Inc.) – C:\WINDOWS\System32\atipdlxx.dll
[2009/02/03 23:44:03 | 00,155,648 | —- | M] (ATI Technologies, Inc.) – C:\WINDOWS\System32\Oemdspif.dll
[2009/02/03 23:43:55 | 00,026,112 | —- | M] (ATI Technologies, Inc.) – C:\WINDOWS\System32\Ati2mdxx.exe
[2009/02/03 23:43:45 | 00,043,520 | —- | M] (ATI Technologies, Inc.) – C:\WINDOWS\System32\ati2edxx.dll
[2009/02/03 23:13:29 | 00,121,808 | —- | M] () – C:\WINDOWS\System32\ativvaxx.cap
[2009/02/03 23:13:21 | 03,107,788 | —- | M] () – C:\WINDOWS\System32\ativva5x.dat
[2009/02/03 23:13:21 | 00,887,724 | —- | M] () – C:\WINDOWS\System32\ativva6x.dat
[2009/02/03 22:05:00 | 00,593,920 | —- | M] () – C:\WINDOWS\System32\ati2sgag.exe
[2009/01/31 19:49:01 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/01/31 19:49:01 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/01/31 19:49:01 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/01/29 21:20:48 | 00,001,613 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\Mozilla Firefox.lnk
[2009/01/29 17:34:31 | 00,000,889 | —- | M] () – C:\WINDOWS\System32\senekaswewfvma.dat
[2009/01/29 17:34:31 | 00,000,059 | —- | M] () – C:\WINDOWS\System32\senekafuucrlov.dat
[2009/01/29 17:29:29 | 00,000,217 | —- | M] () – C:\WINDOWS\System32\senekauwixtylq.dat
[2009/01/29 17:28:32 | 00,001,104 | —- | M] () – C:\WINDOWS\jpbdzsat
[2009/01/29 17:17:29 | 00,003,925 | —- | M] () – C:\WINDOWS\System32\senekajctgnvig.dat
[2009/01/29 17:17:29 | 00,000,059 | —- | M] () – C:\WINDOWS\System32\senekamepfrlmw.dat
[2009/01/29 16:54:35 | 00,008,704 | —- | M] () – C:\WINDOWS\System32\userinit.exe
[2009/01/14 17:11:32 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/14 17:11:28 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A11F741D
@Alternate Data Stream - 512 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 0 bytes -> C:\WINDOWS\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\DOCUME~1\HP_ADM~1\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\DOCUME~1\ALLUSE~1\Documents\Thumbs.db:encryptable
< End of report >
Extras List


OTListIt Extras logfile created on: 3/14/2009 9:21:12 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.3.8 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.48 Mb Total Physical Memory | 491.97 Mb Available Physical Memory | 51.33% Memory free
2.26 Gb Paging File | 1.75 Gb Available in Paging File | 77.40% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.37 Gb Total Space | 3.11 Gb Free Space | 1.38% Space Free | Partition Type: NTFS
Drive D: | 8.50 Gb Total Space | 1.13 Gb Free Space | 13.28% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TEKNIQ
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 60 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.js [@ = jsfile] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe (Nexon)
C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe (Nexon)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe (Nexon)
C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe (Nexon)
C:\Nexon\Combat Arms\NMService.exe:*:Enabled:Nexon Messenger Core (Nexon Corp.)
C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary (Sun Microsystems, Inc.)
C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client (www.BitComet.com)
C:\Program Files\AeriaGames\ProjectTorque\ProjectTorque.bin:*:Enabled:Project Torque (Invictus Games Ltd.)
C:\AeriaGames\12Sky\TwelveSky.exe:*:Enabled:TwelveSky ()
C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager (Nexon)
C:\NGM\NGM.exe:*:Enabled:Nexon Game Manager (Nexon)
C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire (Xfire Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00060000-0000-1004-8002-0000C06B5161}" = WIBU-KEY Setup (WIBU-KEY Remove)
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{0224CACC-994D-45F8-B973-D65056EA9C2F}" = Adobe XMP DVA Panels CS3
"{0327FA9D-975C-448C-A086-577D57BB25B8}" = Adobe Soundbooth CS3 Codecs
"{03CE1BCB-03F5-4C6A-B37E-69799AA3C544}" = SpyHunter
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0AD84416-63A4-4CF3-BDDF-8FA866711FB0}" = Civilization III
"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{11051835-560C-9E8F-C9B5-C376F4A46580}" = Catalyst Control Center Graphics Previews Common
"{16D354E4-63D4-B300-AFBC-8D22A94CE6D6}" = ccc-utility
"{172975EB-9465-4861-95B5-C7BB6D3DE62A}" = DocumentViewer
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{193EAFD0-1BAF-4FB4-B18F-79D5D6A4B285}" = Adobe After Effects CS3 Presets
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{1C2CD847-D196-079D-E004-C1D82B57E3A7}" = Catalyst Control Center Graphics Full Existing
"{1D58229F-C505-45CA-8223-F35F3A34B963}" = Adobe Version Cue CS3 Server {ko_KR}
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java™ 6 Update 11
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{291B3A3B-F808-45B8-8113-DF232FCB6C82}" = Microsoft .NET Compact Framework 3.5
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}" = HP Deskjet Printer Preload
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{2EFFFC71-1E66-454E-A6E6-CEEC800B96D2}" = Adobe Flash Video Encoder
"{2F351A97-7BAC-4045-80A4-3527805E1033}" = Nero 7 Demo
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{3248F0A8-6813-11D6-A77B-00B0D0150010}" = J2SE Runtime Environment 5.0 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0150050}" = J2SE Runtime Environment 5.0 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{33D6CC28-9F75-4d1b-A11D-98895B3A3729}" = HP Photosmart 330,380,420,470,7800,8000,8200 Series
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{37E9E443-FA8E-095F-CF2A-90A18B0B206B}" = CCC Help English
"{382E94C0-6E22-44e4-B003-8EB31DFE296F}" = cp_LightScribeConfig
"{3AF8FCCD-F51A-4014-9002-F195E1CBC876}" = Logitech QuickCam
"{3BA95526-6AE0-4B87-A62D-17187EF565FC}" = HP Boot Optimizer
"{3C0BAFCA-BDB8-492B-8845-DC0A4B4C1823}" = HPDeskjet5400Series
"{3E386744-10FA-44b2-98C9-DF7A270DECB3}" = HP PSC & OfficeJet 5.3.A
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{4235A9E5-EEFF-42E7-BEC9-9D421DD10ECB}" = 12Sky
"{4458C442-7376-4CF9-AF58-E8CEA6722363}" = Adobe Setup
"{448A1BF6-B110-5C4B-2220-30F5ECE6DD83}" = Catalyst Control Center Core Implementation
"{45235788-142C-44BE-8A4D-DDE9A84492E5}" = AGEIA PhysX v7.09.13
"{485ACF57-F364-440A-8496-E1E81C8FA1AA}" = Adobe Premiere Pro CS3 Third Party Content
"{4F3C8CEE-89D6-891E-D728-80A8CF0DCB32}" = ccc-core-preinstall
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{50F102CA-4BE2-41A9-9810-5BB05EB91B9A}" = Adobe Premiere Pro CS3 Functional Content
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{54B2EAD9-A110-43F7-B010-2859A1BD2AFE}" = Adobe Encore CS3
"{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy
"{567C23E1-7580-4185-B8C2-30805677297C}" = NewCopy_CDA
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{58DCEEE5-532E-44F4-B1D7-A146EF9E9FDA}" = Adobe Premiere Pro CS3
"{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{5FE5135B-2B27-4E78-BA01-AEAC7826AD86}" = Extensis Suitcase 9.2.1
"{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}" = Adobe Setup
"{654870E9-EF38-D3B3-328C-ABA367163D15}" = Catalyst Control Center Graphics Full New
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6B52140A-F189-4945-BFFC-DB3F00B8C589}" = Adobe Flash CS3
"{6B708481-748A-4EB4-97C1-CD386244FF77}" = Adobe MotionPicture Color Files
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}" = AHV content for Acrobat and Flash
"{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}" = Adobe Color Common Settings
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{72736F5F-520D-472A-88CC-7B02872FD34E}" = ATI Catalyst Registration
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{755EC5E3-FD51-46bd-A57F-7A2D56FBF061}" = PSTAPlugin
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{769A295C-DCF4-41d6-AFBA-7D9394B23AFE}" = PSPrinters08
"{77D2A9D3-5800-43E3-B274-87841BC87DB2}" = Adobe ExtendScript Toolkit 2
"{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware
"{7ACFB90E-8FD0-4397-AD3A-5195412623A3}" = Adobe Help Viewer CS3
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7C10F5C7-F00F-4BD3-A110-C7D240D2DD25}" = Adobe Dreamweaver CS3
"{7DFC1012-D346-46CE-B03E-FF79125AE029}" = Adobe Fireworks CS3
"{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}" = Adobe Video Profiles
"{8718DC03-D066-4957-94E5-50C3C5042E8E}" = Adobe Creative Suite 3 Master Collection
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8AE03988-8C8C-40EE-BDC7-76781BEF1B1D}" = Adobe Setup
"{8CD8CCC0-3C5C-DF21-DAC3-D5834E803F1E}" = Catalyst Control Center Graphics Light
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{8F6A89F1-F04A-6FD8-1802-D7D5BAE382E1}" = ccc-core-static
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90170409-6000-11D3-8CFE-0050048383C9}" = Microsoft FrontPage 2002
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{91477C6F-EC7C-4BFC-BBE1-E45908019DED}" = LightScribe 1.4.52.1
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{929408E6-D265-4174-805F-81D1D914E2A4}" = QuickTime
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3455242-DAE0-4523-8242-FD82706ABF4B}" = CameraDrivers
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A6B23EFA-6590-482C-A11F-5ACE1B91F5B9}" = Adobe Soundbooth CS3
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{AB18B0BA-A08F-48B8-8D0E-AA9DDDCA22EA}" = CuteFTP 6 Professional
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-1033-0000-7760-000000000003}" = Adobe Acrobat 8 Professional
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}" = Windows Live Sign-in Assistant
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B276997E-4367-4b1b-A39C-4CAE7464337A}" = AiO_Scan_CDA
"{B3B20D3D-92F9-5EBA-B557-CECA02984F05}" = Catalyst Control Center HydraVision Full
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4D279F1-4309-49cc-A4B5-3A0D2E59C7B5}" = PanoStandAlone
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B60E7826-F117-4d26-8165-D2DC5A494AB0}" = Fax_CDA
"{B64E3AFC-59EF-4f18-BF11-E751462450D3}" = AiOSoftwareNPI
"{B671CBFD-4109-4D35-9252-3062D3CCB7B2}" = Adobe SING CS3
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}" = Adobe BridgeTalk Plugin CS3
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B8B7A4D8-80E1-4DAE-BD33-7FD535BA3931}" = Adobe Encore CS3 Codecs
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BBF51613-ACF3-4B1C-86E8-AD15BB431037}" = Tribes Vengeance
"{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3
"{BF7BE540-A2D9-41C1-AFD3-1842CEE0B16C}" = Documents To Go
"{C104580B-1C79-4d73-9BF0-CA0B184296A4}" = cp_LightScribePlugin
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{C5BD220A-EFE8-48A5-B70E-9503D535FACE}" = Adobe WAS CS3
"{C83A12B9-B31B-461A-BBD4-CE9B988094F1}" = HP Photosmart Cameras 5.0
"{C8BB4912-12D9-42AE-B571-E580D8CD1B5B}" = TuneUp Utilities 2007
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB3F8375-B600-4B9F-83C9-238ED1E583FD}" = Adobe InDesign CS3
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D3B1C799-CB73-42DE-BA0F-2344793A095C}" = Catalyst Control Center - Branding
"{D518592A-0F1E-40ca-BECB-3D3F026C6B0D}" = CameraDrivers
"{D5A31AB1-345D-47C7-A87B-036A669F6DF1}" = Adobe XMP Panels CS3
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{DFB0FED6-0010-4E9B-A402-E513F2459161}" = muvee autoProducer unPlugged 1.2
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E7137AFD-4E43-47A6-BDC7-533808F72B36}" = muvee autoProducer 4.5
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}" = Adobe InDesign CS3 Icon Handler
"{EB0202F7-016A-410C-ADE4-40F848CCC661}" = Adobe After Effects CS3
"{EB57A16E-500D-43d7-85B9-FBE279EBBA6E}" = HP Deskjet 5400 series
"{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}" = HP Software Update
"{F0601E2E-8FB3-1C63-F72D-54EB2F908767}" = Skins
"{F08E8D2E-F132-4742-9C87-D5FF223A016A}" = Adobe Illustrator CS3
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F80239D8-7811-4D5E-B033-0D0BBFE32920}" = HP DigitalMedia Archive
"{FC9E08AA-CD59-4C59-BEF9-87E05B9E37D7}" = Adobe Contribute CS3
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FF8157AA-F640-45BD-B7C2-BAA1016B267A}" = palmOne
"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2
"Adobe_4dcfd9b7e901b57f81f667144603236" = Add or Remove Adobe Creative Suite 3 Master Collection
"Adobe_6c8e2cb4fd241c55406016127a6ab2e" = Adobe Color Common Settings
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"AVG8Uninstall" = AVG Free 8.0
"BitComet" = BitComet 1.06
"CamStudio" = CamStudio
"Camtasia" = Camtasia
"Combat Arms" = Combat Arms
"DAZ|Studio" = DAZ|Studio [removed]
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DVD Shrink_is1" = DVD Shrink 3.2
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FLV Player" = FLV Player 2.0, build 24
"Fraps" = Fraps (remove only)
"HijackThis" = HijackThis 2.0.2
"HP Document Viewer" = HP Document Viewer 5.3
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"HPOOVClient-9972322 Uninstaller" = Updates from HP (remove only)
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{929408E6-D265-4174-805F-81D1D914E2A4}" = QuickTime
"InstallShield_{AB18B0BA-A08F-48B8-8D0E-AA9DDDCA22EA}" = CuteFTP 6 Professional
"InstallShield_{BBF51613-ACF3-4B1C-86E8-AD15BB431037}" = Tribes Vengeance
"LHTTSENG" = L&H TTS3000 British English
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Magic ISO Maker v5.4 (build 0239)" = Magic ISO Maker v5.4 (build 0239)
"MagicDisc 2.5.79" = MagicDisc 2.5.79
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox (3.0.7)" = Mozilla Firefox (3.0.7)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero PhotoShow Express" = Nero PhotoShow Express
"NeroVision!UninstallKey" = NeroVision Express 2
"Nitto 1320 Legends_is1" = Nitto 1320 Legends Public Beta 0.9.10.1
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NMPUninstallKey" = Nero Media Player
"NoteTab Light_is1" = NoteTab Light (Remove only)
"NVEContent!UninstallKey" = NeroVision Express 2 Content
"PC-Doctor 5 for Windows" = PC-Doctor 5 for Windows
"Pen Tablet Driver" = Pen Tablet
"penPalette 1.0" = penPalette 1.0
"PowerISO" = PowerISO
"Project Torque" = Project Torque
"PS2" = PS2
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"Registry Mechanic_is1" = Registry Mechanic 8.0
"Spyware Doctor" = Spyware Doctor 6.0
"Winamp" = Winamp
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Pixie" = Pixie 3.1 (remove only)

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/12/2009 5:13:39 PM | Computer Name = TEKNIQ | Source = Application Error | ID = 1000
Description = Faulting application moviemk.exe, version 2.1.4026.0, faulting module
arcspl.ax, version 2.4.1.12, fault address 0x00002305.

Error - 3/12/2009 5:14:24 PM | Computer Name = TEKNIQ | Source = Application Error | ID = 1000
Description = Faulting application moviemk.exe, version 2.1.4026.0, faulting module
arcspl.ax, version 2.4.1.12, fault address 0x00002305.

Error - 3/12/2009 5:19:10 PM | Computer Name = TEKNIQ | Source = Application Error | ID = 1000
Description = Faulting application moviemk.exe, version 2.1.4026.0, faulting module
arcspl.ax, version 2.4.1.12, fault address 0x00002305.

Error - 3/13/2009 6:27:12 AM | Computer Name = TEKNIQ | Source = Application Error | ID = 1000
Description = Faulting application engine.exe, version 0.0.0.0, faulting module
, version 0.0.0.0, fault address 0x00000000.

Error - 3/13/2009 12:32:34 PM | Computer Name = TEKNIQ | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

Error - 3/14/2009 6:30:03 AM | Computer Name = TEKNIQ | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established

Error - 3/14/2009 6:30:04 AM | Computer Name = TEKNIQ | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 3/14/2009 6:30:04 AM | Computer Name = TEKNIQ | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 3/14/2009 6:30:05 AM | Computer Name = TEKNIQ | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 3/14/2009 8:18:59 AM | Computer Name = TEKNIQ | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module explorer.exe, version 6.0.2900.5512, fault address 0x00011900.

[ System Events ]
Error - 3/8/2009 3:54:39 PM | Computer Name = TEKNIQ | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 3/13/2009 12:14:44 PM | Computer Name = TEKNIQ | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%2

Error - 3/13/2009 12:14:44 PM | Computer Name = TEKNIQ | Source = Service Control Manager | ID = 7001
Description = The Media Center Extender Service service depends on the SSDP Discovery
Service service which failed to start because of the following error: %%1058

Error - 3/14/2009 6:09:18 AM | Computer Name = TEKNIQ | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%2

Error - 3/14/2009 6:09:18 AM | Computer Name = TEKNIQ | Source = Service Control Manager | ID = 7001
Description = The Media Center Extender Service service depends on the SSDP Discovery
Service service which failed to start because of the following error: %%1058

Error - 3/14/2009 6:09:18 AM | Computer Name = TEKNIQ | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
iaStor IntelIde ViaIde

Error - 3/14/2009 6:25:53 AM | Computer Name = TEKNIQ | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%2

Error - 3/14/2009 6:25:53 AM | Computer Name = TEKNIQ | Source = Service Control Manager | ID = 7001
Description = The Media Center Extender Service service depends on the SSDP Discovery
Service service which failed to start because of the following error: %%1058

Error - 3/14/2009 8:47:01 AM | Computer Name = TEKNIQ | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 3/14/2009 8:47:01 AM | Computer Name = TEKNIQ | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}


< End of report >
Please download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. If you are unsure of how to disable these programs, please refer to this page for details.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply.

Note: If you are unsure about anything, a very good Combofix tutorial can be found here.
ComboFix 09-03-13.02 - HP_Administrator 2009-03-14 21:56:55.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.456 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\HP_Administrator\Local Settings\Temporary Internet Files\fbk.sts
C:\install.exe
c:\program files\system\smss.exe.assembly
c:\windows\IE4 Error Log.txt
c:\windows\system32\404Fix.exe
c:\windows\system32\cemetrix.dll
c:\windows\system32\dumphive.exe
c:\windows\system32\hQWyayxx.ini
c:\windows\system32\hQWyayxx.ini2
c:\windows\system32\IEDFix.exe
c:\windows\system32\ncklugyc.ini
c:\windows\system32\Process.exe
c:\windows\system32\senekafuucrlov.dat
c:\windows\system32\senekajctgnvig.dat
c:\windows\system32\senekamepfrlmw.dat
c:\windows\system32\senekaswewfvma.dat
c:\windows\system32\senekauwixtylq.dat
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\wllmtgbk.ini
c:\windows\system32\WS2Fix.exe

—– BITS: Possible infected sites —–

hxxp://b9n.org
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\userinit.exe


.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_LANMANDRV
——-\Legacy_NFR.SYS
——-\Service_seneka


((((((((((((((((((((((((( Files Created from 2009-02-15 to 2009-03-15 )))))))))))))))))))))))))))))))
.

2009-03-14 20:19 . 2009-03-14 21:02 d——– C:\Rooter$
2009-03-14 08:05 . 2009-03-14 08:05 d——– c:\program files\Trend Micro
2009-03-14 07:33 . 2008-12-11 08:38 159,600 –a—— c:\windows\system32\drivers\pctgntdi.sys
2009-03-14 07:32 . 2009-03-14 07:40 d——– c:\program files\Spyware Doctor
2009-03-14 07:32 . 2009-03-14 07:34 d——– c:\program files\Common Files\PC Tools
2009-03-14 07:32 . 2009-03-14 07:32 d——– c:\documents and settings\HP_Administrator\Application Data\PC Tools
2009-03-14 07:32 . 2009-03-14 07:32 d——– c:\documents and settings\All Users\Application Data\PC Tools
2009-03-14 07:32 . 2009-03-06 16:45 130,424 –a—— c:\windows\system32\drivers\PCTCore.sys
2009-03-14 07:32 . 2008-12-18 12:16 73,840 –a—— c:\windows\system32\drivers\PCTAppEvent.sys
2009-03-14 07:32 . 2008-12-10 12:36 64,392 –a—— c:\windows\system32\drivers\pctplsg.sys
2009-03-14 06:47 . 2009-03-14 06:47 d——– c:\program files\Enigma Software Group
2009-03-14 05:29 . 2009-03-13 11:35 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-03-13 11:35 . 2009-03-13 11:34 64,160 –a—— c:\windows\system32\drivers\Lbd.sys
2009-03-13 11:31 . 2009-03-13 11:31 d–h-c— c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-03-12 22:59 . 2009-03-12 22:59 d——– c:\documents and settings\NetworkService\Application Data\Xfire
2009-03-12 22:50 . 2009-03-12 22:59 d——– c:\program files\Xfire
2009-03-12 22:50 . 2009-03-12 23:22 d——– c:\documents and settings\HP_Administrator\Application Data\Xfire
2009-03-12 17:45 . 2008-04-13 19:12 82,432 —h—t- c:\windows\system32\19925568.dll
2009-03-12 17:45 . 2008-04-13 19:12 82,432 —h—t- c:\windows\system32\18271a04.dll
2009-03-11 01:30 . 2008-04-13 19:12 82,432 —h—t- c:\windows\system32\e8bb643.dll
2009-03-11 01:30 . 2008-04-13 19:12 82,432 —h—t- c:\windows\system32\cf7dbaa.dll
2009-03-09 20:35 . 2009-03-09 20:35 d——– c:\program files\Reference Assemblies
2009-03-08 13:24 . 2008-04-13 19:12 82,432 —h—t- c:\windows\system32\433702c.dll
2009-03-08 13:24 . 2008-04-13 19:12 82,432 —h—t- c:\windows\system32\3cfba05.dll
2009-03-07 13:55 . 2009-03-07 13:55 54,156 –ah—– c:\windows\QTFont.qfn
2009-03-07 13:55 . 2009-03-07 13:55 1,409 –a—— c:\windows\QTFont.for
2009-03-07 08:05 . 2008-04-13 19:12 82,432 —h—t- c:\windows\system32\1f8c8c9.dll
2009-03-07 08:05 . 2008-04-13 19:12 82,432 —h—t- c:\windows\system32\12685e6a.dll
2009-03-06 18:50 . 2008-04-13 19:12 82,432 —h—t- c:\windows\system32\9055298.dll
2009-03-06 18:50 . 2008-04-13 19:12 82,432 —h—t- c:\windows\system32\4e0598b.dll
2009-03-06 18:27 . 2008-04-13 19:12 82,432 —h—t- c:\windows\system32\7525b70.dll
2009-03-06 18:27 . 2008-04-13 19:12 82,432 —h—t- c:\windows\system32\151565bc.dll
2009-03-06 18:16 . 2009-03-06 18:16 d——– c:\documents and settings\HP_Administrator\Application Data\ATI
2009-03-06 18:16 . 2009-03-06 18:16 d——– c:\documents and settings\All Users\Application Data\ATI
2009-03-06 18:15 . 2009-03-06 18:15 d——– C:\WTablet
2009-03-06 18:14 . 2009-03-06 18:14 0 –a—— c:\windows\ativpsrm.bin
2009-03-06 18:12 . 2009-03-14 07:51 d——– c:\program files\ATI
2009-03-06 18:09 . 2009-03-06 18:09 d——– C:\NGM
2009-03-06 18:09 . 2009-02-03 22:05 593,920 ——— c:\windows\system32\ati2sgag.exe
2009-03-06 18:07 . 2009-03-06 18:07 d——– C:\ATI
2009-03-02 02:13 . 2007-03-12 17:42 3,495,784 –a—— c:\windows\system32\d3dx9_33.dll
2009-02-26 13:47 . 2009-02-26 13:47 42,320 –a—— c:\windows\system32\xfcodec.dll
2009-02-25 11:06 . 2009-02-25 11:06 d——– c:\program files\Common Files\INCA Shared
2009-02-25 10:46 . 2009-02-25 10:46 d——– c:\program files\G4box
2009-02-24 06:11 . 2009-02-24 06:11 d——– c:\documents and settings\LocalService\Application Data\Xfire

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-15 03:05 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-15 03:04 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\WTablet
2009-03-15 02:57 ——— d—–w c:\program files\System
2009-03-14 10:29 ——— d—–w c:\program files\Common Files\Stardock
2009-03-13 16:31 ——— d—–w c:\program files\Lavasoft
2009-03-13 16:31 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-03-13 12:28 ——— d—–w c:\program files\Nitto 1320 Legends
2009-03-10 01:35 ——— d—–w c:\program files\Microsoft.NET
2009-03-08 17:20 ——— d—–w c:\program files\Windows Desktop Search
2009-03-06 23:10 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-06 23:10 ——— d—–w c:\program files\ATI Technologies
2009-03-03 15:52 ——— d—–w c:\program files\DivX
2009-02-17 12:08 ——— d—–w c:\program files\CamStudio
2009-02-04 07:27 3,488,768 —-a-w c:\windows\system32\drivers\ati2mtag.sys
2009-02-04 03:52 53,248 —-a-w c:\windows\system32\drivers\ati2erec.dll
2009-02-01 22:54 ——— d—–w c:\documents and settings\LocalService\Application Data\WTablet
2009-02-01 00:49 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-02-01 00:49 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-01-30 01:23 ——— d—–w c:\program files\Yahoo!
2009-01-30 01:23 ——— d—–w c:\program files\Opera
2009-01-29 22:00 ——— d—–w c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-01-19 00:32 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-01-18 01:30 ——— d—–w c:\documents and settings\All Users\Application Data\FLEXnet
2008-07-30 03:30 15,360 –sh–w c:\documents and settings\HP_Administrator\SetupDL.exe
2007-06-07 18:45 80 –sh–r c:\windows\system32\FF553558F8.dll
2006-09-16 19:25 848 –sha-w c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"TuneUp MemOptimizer"="c:\program files\TuneUp Utilities 2007\MemOptimizer.exe" [2006-12-19 310792]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-09-21 1605740]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-03-20 213936]
"ISUSScheduler"="c:\program files\common files\installshield\updateservice\issch.exe" [2006-03-20 86960]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-31 1601304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-03 61440]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2007-10-04 307200]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-13 515416]
"SpyHunter Security Suite"="c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2009-01-13 864256]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 c:\windows\arpwrmsg.exe]

c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2005-11-22 27136]

c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
PowerReg Scheduler.exe [2008-03-02 256000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
DataViz Inc Messenger.lnk - c:\program files\Common Files\DataViz\DvzIncMsgr.exe [2007-02-16 28672]
HotSync Manager.lnk - c:\program files\palmOne\Hotsync.exe [2004-06-09 471040]
Suitcase Startup.lnk - c:\program files\Extensis\Suitcase 9.2\Suitcase.exe [2006-02-11 3145728]
TabUserW.exe.lnk - c:\windows\system32\WTablet\TabUserW.exe [2006-06-09 114688]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\documents and settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-31 19:49 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
–a—— 2005-11-08 17:00 128920 c:\program files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-02-17 04:10 155648 c:\program files\QuickTime\qttask.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"PhotoShow Deluxe Media Manager"=c:\progra~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
"BitComet"="c:\program files\BitComet\BitComet.exe" /tray

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PCDrSmartMonitor"="c:\program files\PC-Doctor 5 for Windows\PcdSmartMonitor.exe" -r
"Adobe_ID0EYTHM"=c:\progra~1\COMMON~1\Adobe\ADOBEV~2\Server\bin\VERSIO~2.EXE
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" /hide
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\AeriaGames\\ProjectTorque\\ProjectTorque.bin"=
"c:\\AeriaGames\\12Sky\\TwelveSky.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\NGM\\NGM.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-03-13 64160]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-03-14 130424]
R0 tffsport;M-Systems DiskOnChip 2000;c:\windows\system32\drivers\tffsport.sys [2006-11-24 149376]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-07-30 325128]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-30 298264]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2008-12-16 2749736]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2008-12-16 15656]
S0 gbbc;gbbc;c:\windows\system32\drivers\nrmtno.sys –> c:\windows\system32\drivers\nrmtno.sys [?]
S0 kogu;kogu;c:\windows\system32\drivers\sgpojol.sys –> c:\windows\system32\drivers\sgpojol.sys [?]
S0 qaon;qaon;c:\windows\system32\drivers\kznvhgu.sys –> c:\windows\system32\drivers\kznvhgu.sys [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 951632]
S3 idrmkl;idrmkl;\??\c:\docume~1\HP_ADM~1\LOCALS~1\Temp\idrmkl.sys –> c:\docume~1\HP_ADM~1\LOCALS~1\Temp\idrmkl.sys [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-03-14 348752]

— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
.
Contents of the 'Scheduled Tasks' folder

2009-03-13 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 16:53]

2009-03-13 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-13 11:34]

2009-03-15 c:\windows\Tasks\xmjsuztu.job
- c:\windows\system32\efcDWpPF.dll []
.
- - - - ORPHANS REMOVED - - - -

Notify-khfDstUo - khfDstUo.dll
SafeBoot-Winyg28.sys
MSConfigStartUp-dvd43 - c:\program files\dvd43\dvd43_tray.exe
MSConfigStartUp-Skype - c:\program files\Skype\Phone\Skype.exe
MSConfigStartUp-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe


.
——- Supplementary Scan ——-
.
uStart Page =
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local;
uInternet Settings,ProxyServer = http=127.0.0.1:7070
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: moove.com
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\cvhw8qw6.default\
FF - prefs.js: browser.startup.homepage - hxxp://ll-tek-ll.deviantart.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-14 22:05:13
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-2588003286-1639580014-1869957976-1008\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{CA956ACF-856B-6AFE-8641-78586BBA40CC}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iabbgjeidhiookfepd"=hex:6a,61,6e,62,68,6f,65,64,69,6b,67,61,62,65,70,68,70,68,
6d,63,00,00
"hapaagcimdlafeij"=hex:6a,61,6e,62,68,6f,65,64,69,6b,67,61,62,65,70,68,70,68,
6d,63,00,ff
"ianpgmidglgcnhmbgn"=hex:63,61,67,62,69,70,00,7c
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(712)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\WINSPOOL.DRV
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\arservice.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\logishrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\PSIService.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\WTablet\Pen_TabletUser.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Common Files\logishrd\LVCOMSER\LVComSer.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\hp\KBD\kbd.exe
.
**************************************************************************
.
Completion time: 2009-03-14 22:17:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-15 03:17:01

Pre-Run: 3,152,060,416 bytes free
Post-Run: 2,885,218,304 bytes free

316 — E O F — 2009-01-14 09:07:52
Hi there,

See all those crack files listed in Post 5? Delete them all as they are likely to be infected.



1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:


File::
c:\windows\Tasks\xmjsuztu.job

KILLALL::

Registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BitComet"=-

RegLockDel::
[HKEY_USERS\S-1-5-21-2588003286-1639580014-1869957976-1008\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{CA956ACF-856B-6AFE-8641-78586BBA40CC}*]

Driver::
gbbc
kogu
qaon

Collect::[4]
c:\windows\system32\19925568.dll
c:\windows\system32\18271a04.dll
c:\windows\system32\e8bb643.dll
c:\windows\system32\cf7dbaa.dll
c:\windows\system32\433702c.dll
c:\windows\system32\3cfba05.dll
c:\windows\system32\1f8c8c9.dll
c:\windows\system32\12685e6a.dll
c:\windows\system32\9055298.dll
c:\windows\system32\4e0598b.dll
c:\windows\system32\7525b70.dll
c:\windows\system32\151565bc.dll
c:\windows\system32\drivers\nrmtno.sys
c:\windows\system32\drivers\sgpojol.sys
c:\windows\system32\drivers\kznvhgu.sys
c:\windows\system32\efcDWpPF.dll


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

5. After reboot, (in case it asks to reboot), please post the Combofix.txt report into your next reply.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Please run an online scan with Kaspersky WebScanner.
Note: You must disable your Anti Virus program during the scan. If you are unsure of how to disable these programs, please refer to this page for details.


  • Click the Accept button.

    You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded and updated click on My Computer in the Scan settings
    • This will start the scan of your system.
    • The scan will take a while so be patient and let it run until it is complete.
    • Now click on the View scan report link:
  • Click the Save report as button
  • Under Save as type, choose Text file (*.txt)
  • Save the file to your desktop as Kaspersky.txt
  • Copy and paste that information in your next post.
ComboFix 09-03-13.02 - HP_Administrator 2009-03-15 3:08:16.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.471 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\HP_Administrator\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
c:\windows\Tasks\xmjsuztu.job
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\12685e6a.dll
c:\windows\system32\151565bc.dll
c:\windows\system32\18271a04.dll
c:\windows\system32\19925568.dll
c:\windows\system32\1f8c8c9.dll
c:\windows\system32\3cfba05.dll
c:\windows\system32\433702c.dll
c:\windows\system32\4e0598b.dll
c:\windows\system32\7525b70.dll
c:\windows\system32\9055298.dll
c:\windows\system32\cf7dbaa.dll
c:\windows\system32\e8bb643.dll
c:\windows\Tasks\xmjsuztu.job

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_gbbc
——-\Service_kogu
——-\Service_qaon


((((((((((((((((((((((((( Files Created from 2009-02-15 to 2009-03-15 )))))))))))))))))))))))))))))))
.

2009-03-15 03:05 . 2009-03-15 03:07 d——– C:\50d405b0c9dd102b2c
2009-03-15 03:01 . 2009-03-15 03:01 d——– c:\program files\Microsoft Visual Studio 8
2009-03-14 20:19 . 2009-03-14 21:02 d——– C:\Rooter$
2009-03-14 08:05 . 2009-03-14 08:05 d——– c:\program files\Trend Micro
2009-03-14 07:33 . 2008-12-11 08:38 159,600 –a—— c:\windows\system32\drivers\pctgntdi.sys
2009-03-14 07:32 . 2009-03-14 07:40 d——– c:\program files\Spyware Doctor
2009-03-14 07:32 . 2009-03-14 07:34 d——– c:\program files\Common Files\PC Tools
2009-03-14 07:32 . 2009-03-14 07:32 d——– c:\documents and settings\HP_Administrator\Application Data\PC Tools
2009-03-14 07:32 . 2009-03-14 07:32 d——– c:\documents and settings\All Users\Application Data\PC Tools
2009-03-14 07:32 . 2009-03-06 16:45 130,424 –a—— c:\windows\system32\drivers\PCTCore.sys
2009-03-14 07:32 . 2008-12-18 12:16 73,840 –a—— c:\windows\system32\drivers\PCTAppEvent.sys
2009-03-14 07:32 . 2008-12-10 12:36 64,392 –a—— c:\windows\system32\drivers\pctplsg.sys
2009-03-14 06:47 . 2009-03-14 06:47 d——– c:\program files\Enigma Software Group
2009-03-14 05:29 . 2009-03-13 11:35 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-03-13 11:35 . 2009-03-13 11:34 64,160 –a—— c:\windows\system32\drivers\Lbd.sys
2009-03-13 11:31 . 2009-03-13 11:31 d–h-c— c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-03-12 22:59 . 2009-03-12 22:59 d——– c:\documents and settings\NetworkService\Application Data\Xfire
2009-03-12 22:50 . 2009-03-12 22:59 d——– c:\program files\Xfire
2009-03-12 22:50 . 2009-03-12 23:22 d——– c:\documents and settings\HP_Administrator\Application Data\Xfire
2009-03-09 20:35 . 2009-03-09 20:35 d——– c:\program files\Reference Assemblies
2009-03-07 13:55 . 2009-03-07 13:55 54,156 –ah—– c:\windows\QTFont.qfn
2009-03-07 13:55 . 2009-03-07 13:55 1,409 –a—— c:\windows\QTFont.for
2009-03-06 18:16 . 2009-03-06 18:16 d——– c:\documents and settings\HP_Administrator\Application Data\ATI
2009-03-06 18:16 . 2009-03-06 18:16 d——– c:\documents and settings\All Users\Application Data\ATI
2009-03-06 18:15 . 2009-03-06 18:15 d——– C:\WTablet
2009-03-06 18:14 . 2009-03-06 18:14 0 –a—— c:\windows\ativpsrm.bin
2009-03-06 18:12 . 2009-03-14 07:51 d——– c:\program files\ATI
2009-03-06 18:09 . 2009-03-06 18:09 d——– C:\NGM
2009-03-06 18:09 . 2009-02-03 22:05 593,920 ——— c:\windows\system32\ati2sgag.exe
2009-03-06 18:07 . 2009-03-06 18:07 d——– C:\ATI
2009-03-02 02:13 . 2007-03-12 17:42 3,495,784 –a—— c:\windows\system32\d3dx9_33.dll
2009-02-26 13:47 . 2009-02-26 13:47 42,320 –a—— c:\windows\system32\xfcodec.dll
2009-02-25 11:06 . 2009-02-25 11:06 d——– c:\program files\Common Files\INCA Shared
2009-02-25 10:46 . 2009-02-25 10:46 d——– c:\program files\G4box
2009-02-24 06:11 . 2009-02-24 06:11 d——– c:\documents and settings\LocalService\Application Data\Xfire

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-15 08:16 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-15 08:15 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\WTablet
2009-03-15 08:02 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-15 02:57 ——— d—–w c:\program files\System
2009-03-14 10:29 ——— d—–w c:\program files\Common Files\Stardock
2009-03-13 16:31 ——— d—–w c:\program files\Lavasoft
2009-03-13 16:31 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-03-13 12:28 ——— d—–w c:\program files\Nitto 1320 Legends
2009-03-10 01:35 ——— d—–w c:\program files\Microsoft.NET
2009-03-08 17:20 ——— d—–w c:\program files\Windows Desktop Search
2009-03-06 23:10 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-06 23:10 ——— d—–w c:\program files\ATI Technologies
2009-03-03 15:52 ——— d—–w c:\program files\DivX
2009-02-17 12:08 ——— d—–w c:\program files\CamStudio
2009-02-04 07:27 3,488,768 —-a-w c:\windows\system32\drivers\ati2mtag.sys
2009-02-04 03:52 53,248 —-a-w c:\windows\system32\drivers\ati2erec.dll
2009-02-01 22:54 ——— d—–w c:\documents and settings\LocalService\Application Data\WTablet
2009-02-01 00:49 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-02-01 00:49 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-01-30 01:23 ——— d—–w c:\program files\Yahoo!
2009-01-30 01:23 ——— d—–w c:\program files\Opera
2009-01-29 22:00 ——— d—–w c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-01-19 00:32 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-01-18 01:30 ——— d—–w c:\documents and settings\All Users\Application Data\FLEXnet
2008-07-30 03:30 15,360 –sh–w c:\documents and settings\HP_Administrator\SetupDL.exe
2007-06-07 18:45 80 –sh–r c:\windows\system32\FF553558F8.dll
2006-09-16 19:25 848 –sha-w c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-03-14_22.15.25.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-09 11:08:53 1,847,552 —-a-w c:\windows\$hf_mig$\KB958690\SP3QFE\win32k.sys
+ 2008-07-09 07:38:24 17,272 —-a-w c:\windows\$hf_mig$\KB958690\spmsg.dll
+ 2008-07-09 07:38:25 231,288 —-a-w c:\windows\$hf_mig$\KB958690\spuninst.exe
+ 2008-07-09 07:38:24 26,488 —-a-w c:\windows\$hf_mig$\KB958690\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 —-a-w c:\windows\$hf_mig$\KB958690\update\update.exe
+ 2008-07-09 07:38:37 382,840 —-a-w c:\windows\$hf_mig$\KB958690\update\updspapi.dll
+ 2008-12-05 06:58:08 144,896 —-a-w c:\windows\$hf_mig$\KB960225\SP3QFE\schannel.dll
+ 2007-11-30 11:18:51 17,272 —-a-w c:\windows\$hf_mig$\KB960225\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\windows\$hf_mig$\KB960225\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\windows\$hf_mig$\KB960225\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 —-a-w c:\windows\$hf_mig$\KB960225\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB960225\update\updspapi.dll
+ 2008-06-17 19:04:34 8,461,824 —-a-w c:\windows\$hf_mig$\KB967715\SP3QFE\shell32.dll
+ 2008-07-09 07:38:24 17,272 —-a-w c:\windows\$hf_mig$\KB967715\spmsg.dll
+ 2008-07-09 07:38:25 231,288 —-a-w c:\windows\$hf_mig$\KB967715\spuninst.exe
+ 2008-07-09 07:38:24 26,488 —-a-w c:\windows\$hf_mig$\KB967715\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 —-a-w c:\windows\$hf_mig$\KB967715\update\update.exe
+ 2008-07-09 07:38:37 382,840 —-a-w c:\windows\$hf_mig$\KB967715\update\updspapi.dll
+ 2007-08-14 00:39:00 123,904 -c—-w c:\windows\ie7updates\KB961260-IE7\advpack.dll
+ 2007-08-14 00:35:46 346,624 -c—-w c:\windows\ie7updates\KB961260-IE7\dxtmsft.dll
+ 2007-08-14 00:35:38 214,528 -c—-w c:\windows\ie7updates\KB961260-IE7\dxtrans.dll
+ 2007-08-14 00:54:10 131,584 -c—-w c:\windows\ie7updates\KB961260-IE7\extmgr.dll
+ 2007-08-14 00:36:26 61,952 -c—-w c:\windows\ie7updates\KB961260-IE7\icardie.dll
+ 2007-08-14 00:39:06 54,784 -c—-w c:\windows\ie7updates\KB961260-IE7\ie4uinit.exe
+ 2007-08-14 00:39:26 152,064 -c—-w c:\windows\ie7updates\KB961260-IE7\ieakeng.dll
+ 2007-08-14 00:39:54 229,376 -c—-w c:\windows\ie7updates\KB961260-IE7\ieaksie.dll
+ 2007-08-13 23:56:54 161,792 -c—-w c:\windows\ie7updates\KB961260-IE7\ieakui.dll
+ 2007-02-12 22:10:12 2,451,312 -c—-w c:\windows\ie7updates\KB961260-IE7\ieapfltr.dat
+ 2007-07-11 18:27:48 383,488 -c—-w c:\windows\ie7updates\KB961260-IE7\ieapfltr.dll
+ 2007-08-14 00:39:50 382,976 -c—-w c:\windows\ie7updates\KB961260-IE7\iedkcs32.dll
+ 2007-08-14 00:54:10 6,049,280 -c—-w c:\windows\ie7updates\KB961260-IE7\ieframe.dll
+ 2007-08-14 00:39:10 43,008 -c—-w c:\windows\ie7updates\KB961260-IE7\iernonce.dll
+ 2007-08-14 00:34:04 266,752 -c—-w c:\windows\ie7updates\KB961260-IE7\iertutil.dll
+ 2007-08-14 00:39:10 13,312 -c—-w c:\windows\ie7updates\KB961260-IE7\ieudinit.exe
+ 2007-08-14 00:43:56 622,080 -c—-w c:\windows\ie7updates\KB961260-IE7\iexplore.exe
+ 2007-08-14 00:54:10 27,136 -c—-w c:\windows\ie7updates\KB961260-IE7\jsproxy.dll
+ 2007-08-14 00:54:10 458,752 -c—-w c:\windows\ie7updates\KB961260-IE7\msfeeds.dll
+ 2007-08-14 00:54:10 50,688 -c—-w c:\windows\ie7updates\KB961260-IE7\msfeedsbs.dll
+ 2007-08-14 00:54:12 3,578,368 -c—-w c:\windows\ie7updates\KB961260-IE7\mshtml.dll
+ 2007-08-14 00:54:10 475,648 -c—-w c:\windows\ie7updates\KB961260-IE7\mshtmled.dll
+ 2007-08-14 00:44:26 192,000 -c—-w c:\windows\ie7updates\KB961260-IE7\msrating.dll
+ 2007-08-14 00:54:10 670,720 -c—-w c:\windows\ie7updates\KB961260-IE7\mstime.dll
+ 2007-08-14 00:44:06 101,376 -c—-w c:\windows\ie7updates\KB961260-IE7\occache.dll
+ 2007-08-14 00:36:12 44,544 -c—-w c:\windows\ie7updates\KB961260-IE7\pngfilt.dll
+ 2007-03-06 01:22:41 213,216 -c—-w c:\windows\ie7updates\KB961260-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w c:\windows\ie7updates\KB961260-IE7\spuninst\updspapi.dll
+ 2007-08-14 00:44:30 105,984 -c—-w c:\windows\ie7updates\KB961260-IE7\url.dll
+ 2007-08-14 00:54:10 1,162,240 -c—-w c:\windows\ie7updates\KB961260-IE7\urlmon.dll
+ 2007-08-14 00:54:10 231,424 -c—-w c:\windows\ie7updates\KB961260-IE7\webcheck.dll
+ 2007-08-14 00:54:10 818,688 -c—-w c:\windows\ie7updates\KB961260-IE7\wininet.dll
- 2009-01-14 09:06:56 1,165,584 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-03-15 08:01:55 1,165,584 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2009-01-14 09:06:57 20,240 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-03-15 08:01:57 20,240 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2009-01-14 09:06:57 159,504 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2009-03-15 08:01:56 159,504 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2009-01-14 09:06:57 184,080 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-03-15 08:01:56 184,080 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2009-01-14 09:06:57 217,864 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2009-03-15 08:01:57 217,864 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2009-01-14 09:06:57 18,704 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-03-15 08:01:57 18,704 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-01-14 09:06:58 35,088 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-03-15 08:01:58 35,088 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2009-01-14 09:06:57 845,584 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2009-03-15 08:01:56 845,584 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2009-01-14 09:06:57 922,384 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-03-15 08:01:56 922,384 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2009-01-14 09:06:57 272,648 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2009-03-15 08:01:57 272,648 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2009-01-14 09:06:57 888,080 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-03-15 08:01:57 888,080 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2009-01-14 09:06:57 1,172,240 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-03-15 08:01:55 1,172,240 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2007-08-14 00:39:00 123,904 —-a-w c:\windows\system32\advpack.dll
+ 2008-12-20 23:15:11 124,928 —-a-w c:\windows\system32\advpack.dll
- 2007-08-14 00:39:00 123,904 ——w c:\windows\system32\dllcache\advpack.dll
+ 2008-12-20 23:15:11 124,928 ——w c:\windows\system32\dllcache\advpack.dll
- 2007-08-14 00:35:46 346,624 ——w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 ——w c:\windows\system32\dllcache\dxtmsft.dll
- 2007-08-14 00:35:38 214,528 ——w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-12-20 23:15:13 214,528 ——w c:\windows\system32\dllcache\dxtrans.dll
- 2007-08-14 00:54:10 131,584 ——w c:\windows\system32\dllcache\extmgr.dll
+ 2008-12-20 23:15:13 133,120 ——w c:\windows\system32\dllcache\extmgr.dll
- 2007-12-07 02:21:45 63,488 ——w c:\windows\system32\dllcache\icardie.dll
+ 2008-12-20 23:15:13 63,488 ——w c:\windows\system32\dllcache\icardie.dll
- 2007-08-14 00:39:06 54,784 ——w c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-12-19 09:10:15 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
- 2007-08-14 00:39:26 152,064 ——w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 ——w c:\windows\system32\dllcache\ieakeng.dll
- 2007-08-14 00:39:54 229,376 ——w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 ——w c:\windows\system32\dllcache\ieaksie.dll
- 2007-08-13 23:56:54 161,792 —-a-w c:\windows\system32\dllcache\ieakui.dll
+ 2008-12-19 05:23:56 161,792 —-a-w c:\windows\system32\dllcache\ieakui.dll
- 2007-12-07 02:21:45 383,488 ——w c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-12-20 23:15:15 383,488 ——w c:\windows\system32\dllcache\ieapfltr.dll
- 2007-08-14 00:39:50 382,976 ——w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 ——w c:\windows\system32\dllcache\iedkcs32.dll
- 2007-12-07 02:21:46 6,066,176 ——w c:\windows\system32\dllcache\ieframe.dll
+ 2008-12-20 23:15:21 6,066,688 ——w c:\windows\system32\dllcache\ieframe.dll
- 2007-08-14 00:39:10 43,008 ——w c:\windows\system32\dllcache\iernonce.dll
+ 2008-12-20 23:15:21 44,544 ——w c:\windows\system32\dllcache\iernonce.dll
- 2007-12-07 02:21:46 267,776 ——w c:\windows\system32\dllcache\iertutil.dll
+ 2008-12-20 23:15:22 267,776 ——w c:\windows\system32\dllcache\iertutil.dll
- 2007-12-06 11:00:58 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
+ 2008-12-19 09:10:15 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
- 2007-08-14 00:43:56 622,080 ——w c:\windows\system32\dllcache\iexplore.exe
+ 2008-12-19 05:25:25 634,024 ——w c:\windows\system32\dllcache\iexplore.exe
- 2007-08-14 00:54:10 27,136 ——w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-12-20 23:15:23 27,648 ——w c:\windows\system32\dllcache\jsproxy.dll
- 2007-12-07 02:21:47 459,264 ——w c:\windows\system32\dllcache\msfeeds.dll
+ 2008-12-20 23:15:23 459,264 ——w c:\windows\system32\dllcache\msfeeds.dll
- 2007-12-07 02:21:47 52,224 ——w c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 ——w c:\windows\system32\dllcache\msfeedsbs.dll
- 2007-08-14 00:54:12 3,578,368 —-a-w c:\windows\system32\dllcache\mshtml.dll
+ 2009-01-17 02:35:14 3,594,752 —-a-w c:\windows\system32\dllcache\mshtml.dll
- 2007-08-14 00:54:10 475,648 ——w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 ——w c:\windows\system32\dllcache\mshtmled.dll
- 2007-08-14 00:44:26 192,000 ——w c:\windows\system32\dllcache\msrating.dll
+ 2008-12-20 23:15:31 193,024 ——w c:\windows\system32\dllcache\msrating.dll
- 2007-08-14 00:54:10 670,720 ——w c:\windows\system32\dllcache\mstime.dll
+ 2008-12-20 23:15:32 671,232 ——w c:\windows\system32\dllcache\mstime.dll
- 2007-08-14 00:44:06 101,376 ——w c:\windows\system32\dllcache\occache.dll
+ 2008-12-20 23:15:38 102,912 ——w c:\windows\system32\dllcache\occache.dll
- 2007-08-14 00:36:12 44,544 ——w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 ——w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-12-05 06:54:55 144,896 ——w c:\windows\system32\dllcache\schannel.dll
+ 2008-06-17 19:02:19 8,461,312 ——w c:\windows\system32\dllcache\shell32.dll
- 2007-08-14 00:44:30 105,984 ——w c:\windows\system32\dllcache\url.dll
+ 2008-12-20 23:15:39 105,984 ——w c:\windows\system32\dllcache\url.dll
- 2007-08-14 00:54:10 1,162,240 —-a-w c:\windows\system32\dllcache\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 —-a-w c:\windows\system32\dllcache\urlmon.dll
- 2007-08-14 00:54:10 231,424 ——w c:\windows\system32\dllcache\webcheck.dll
+ 2008-12-20 23:15:40 233,472 ——w c:\windows\system32\dllcache\webcheck.dll
- 2008-09-15 12:12:56 1,846,400 ——w c:\windows\system32\dllcache\win32k.sys
+ 2009-02-09 11:13:27 1,846,784 ——w c:\windows\system32\dllcache\win32k.sys
- 2007-08-14 00:54:10 818,688 —-a-w c:\windows\system32\dllcache\wininet.dll
+ 2008-12-20 23:15:41 826,368 —-a-w c:\windows\system32\dllcache\wininet.dll
- 2007-06-12 04:51:12 10,834,944 —-a-w c:\windows\system32\dllcache\wmp.dll
+ 2008-11-11 23:34:42 10,838,016 —-a-w c:\windows\system32\dllcache\wmp.dll
- 2007-08-14 00:35:46 346,624 —-a-w c:\windows\system32\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 —-a-w c:\windows\system32\dxtmsft.dll
- 2007-08-14 00:35:38 214,528 —-a-w c:\windows\system32\dxtrans.dll
+ 2008-12-20 23:15:13 214,528 —-a-w c:\windows\system32\dxtrans.dll
- 2007-08-14 00:54:10 131,584 —-a-w c:\windows\system32\extmgr.dll
+ 2008-12-20 23:15:13 133,120 —-a-w c:\windows\system32\extmgr.dll
- 2009-02-25 18:31:16 1,590,568 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-03-15 08:14:52 1,590,568 —-a-w c:\windows\system32\FNTCACHE.DAT
- 2007-08-14 00:36:26 61,952 ——w c:\windows\system32\icardie.dll
+ 2008-12-20 23:15:13 63,488 —-a-w c:\windows\system32\icardie.dll
- 2007-08-14 00:39:06 54,784 —-a-w c:\windows\system32\ie4uinit.exe
+ 2008-12-19 09:10:15 70,656 —-a-w c:\windows\system32\ie4uinit.exe
- 2007-08-14 00:39:26 152,064 —-a-w c:\windows\system32\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 —-a-w c:\windows\system32\ieakeng.dll
- 2007-08-14 00:39:54 229,376 —-a-w c:\windows\system32\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 —-a-w c:\windows\system32\ieaksie.dll
- 2007-08-13 23:56:54 161,792 —-a-w c:\windows\system32\ieakui.dll
+ 2008-12-19 05:23:56 161,792 —-a-w c:\windows\system32\ieakui.dll
- 2007-02-12 22:10:12 2,451,312 ——w c:\windows\system32\ieapfltr.dat
+ 2007-04-17 09:32:38 2,455,488 —-a-w c:\windows\system32\ieapfltr.dat
- 2007-07-11 18:27:48 383,488 ——w c:\windows\system32\ieapfltr.dll
+ 2008-12-20 23:15:15 383,488 —-a-w c:\windows\system32\ieapfltr.dll
- 2007-08-14 00:39:50 382,976 —-a-w c:\windows\system32\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 —-a-w c:\windows\system32\iedkcs32.dll
- 2007-08-14 00:54:10 6,049,280 ——w c:\windows\system32\ieframe.dll
+ 2008-12-20 23:15:21 6,066,688 —-a-w c:\windows\system32\ieframe.dll
- 2007-08-14 00:39:10 43,008 —-a-w c:\windows\system32\iernonce.dll
+ 2008-12-20 23:15:21 44,544 —-a-w c:\windows\system32\iernonce.dll
- 2007-08-14 00:34:04 266,752 ——w c:\windows\system32\iertutil.dll
+ 2008-12-20 23:15:22 267,776 —-a-w c:\windows\system32\iertutil.dll
- 2007-08-14 00:39:10 13,312 —-a-w c:\windows\system32\ieudinit.exe
+ 2008-12-19 09:10:15 13,824 —-a-w c:\windows\system32\ieudinit.exe
- 2007-08-14 00:54:10 27,136 —-a-w c:\windows\system32\jsproxy.dll
+ 2008-12-20 23:15:23 27,648 —-a-w c:\windows\system32\jsproxy.dll
- 2009-01-10 01:35:28 20,853,704 —-a-w c:\windows\system32\MRT.exe
+ 2009-02-25 17:55:00 24,768,960 —-a-w c:\windows\system32\MRT.exe
- 2007-08-14 00:54:10 458,752 ——w c:\windows\system32\msfeeds.dll
+ 2008-12-20 23:15:23 459,264 —-a-w c:\windows\system32\msfeeds.dll
- 2007-08-14 00:54:10 50,688 ——w c:\windows\system32\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
- 2007-08-14 00:54:12 3,578,368 —-a-w c:\windows\system32\mshtml.dll
+ 2009-01-17 02:35:14 3,594,752 —-a-w c:\windows\system32\mshtml.dll
- 2007-08-14 00:54:10 475,648 —-a-w c:\windows\system32\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 —-a-w c:\windows\system32\mshtmled.dll
- 2007-08-14 00:44:26 192,000 —-a-w c:\windows\system32\msrating.dll
+ 2008-12-20 23:15:31 193,024 —-a-w c:\windows\system32\msrating.dll
- 2007-08-14 00:54:10 670,720 —-a-w c:\windows\system32\mstime.dll
+ 2008-12-20 23:15:32 671,232 —-a-w c:\windows\system32\mstime.dll
- 2007-08-14 00:44:06 101,376 —-a-w c:\windows\system32\occache.dll
+ 2008-12-20 23:15:38 102,912 —-a-w c:\windows\system32\occache.dll
- 2007-08-14 00:36:12 44,544 —-a-w c:\windows\system32\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 —-a-w c:\windows\system32\pngfilt.dll
- 2008-04-14 00:12:05 144,384 —-a-w c:\windows\system32\schannel.dll
+ 2008-12-05 06:54:55 144,896 —-a-w c:\windows\system32\schannel.dll
- 2008-04-14 00:12:05 8,461,312 —-a-w c:\windows\system32\shell32.dll
+ 2008-06-17 19:02:19 8,461,312 —-a-w c:\windows\system32\shell32.dll
- 2007-11-30 12:39:22 17,272 ——w c:\windows\system32\spmsg.dll
+ 2007-11-30 11:18:51 17,272 ——w c:\windows\system32\spmsg.dll
- 2007-08-11 03:46:18 26,488 —-a-w c:\windows\system32\spupdsvc.exe
+ 2007-07-27 14:41:38 26,488 —-a-w c:\windows\system32\spupdsvc.exe
- 2007-08-14 00:44:30 105,984 —-a-w c:\windows\system32\url.dll
+ 2008-12-20 23:15:39 105,984 —-a-w c:\windows\system32\url.dll
- 2007-08-14 00:54:10 1,162,240 —-a-w c:\windows\system32\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 —-a-w c:\windows\system32\urlmon.dll
- 2007-08-14 00:54:10 231,424 —-a-w c:\windows\system32\webcheck.dll
+ 2008-12-20 23:15:40 233,472 —-a-w c:\windows\system32\webcheck.dll
- 2008-09-15 12:12:56 1,846,400 —-a-w c:\windows\system32\win32k.sys
+ 2009-02-09 11:13:27 1,846,784 —-a-w c:\windows\system32\win32k.sys
- 2007-08-14 00:54:10 818,688 —-a-w c:\windows\system32\wininet.dll
+ 2008-12-20 23:15:41 826,368 —-a-w c:\windows\system32\wininet.dll
- 2007-06-12 04:51:12 10,834,944 —-a-w c:\windows\system32\wmp.dll
+ 2008-11-11 23:34:42 10,838,016 —-a-w c:\windows\system32\wmp.dll
+ 2009-03-15 08:14:57 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_1f4.dat
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"TuneUp MemOptimizer"="c:\program files\TuneUp Utilities 2007\MemOptimizer.exe" [2006-12-19 310792]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-09-21 1605740]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-03-20 213936]
"ISUSScheduler"="c:\program files\common files\installshield\updateservice\issch.exe" [2006-03-20 86960]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-31 1601304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-03 61440]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2007-10-04 307200]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-13 515416]
"SpyHunter Security Suite"="c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2009-01-13 864256]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 c:\windows\arpwrmsg.exe]

c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2005-11-22 27136]

c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
PowerReg Scheduler.exe [2008-03-02 256000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
DataViz Inc Messenger.lnk - c:\program files\Common Files\DataViz\DvzIncMsgr.exe [2007-02-16 28672]
HotSync Manager.lnk - c:\program files\palmOne\Hotsync.exe [2004-06-09 471040]
Suitcase Startup.lnk - c:\program files\Extensis\Suitcase 9.2\Suitcase.exe [2006-02-11 3145728]
TabUserW.exe.lnk - c:\windows\system32\WTablet\TabUserW.exe [2006-06-09 114688]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\documents and settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-31 19:49 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
–a—— 2005-11-08 17:00 128920 c:\program files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-02-17 04:10 155648 c:\program files\QuickTime\qttask.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"PhotoShow Deluxe Media Manager"=c:\progra~1\Ahead\Ahead\data\Xtras\mssysmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PCDrSmartMonitor"="c:\program files\PC-Doctor 5 for Windows\PcdSmartMonitor.exe" -r
"Adobe_ID0EYTHM"=c:\progra~1\COMMON~1\Adobe\ADOBEV~2\Server\bin\VERSIO~2.EXE
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" /hide
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\AeriaGames\\ProjectTorque\\ProjectTorque.bin"=
"c:\\AeriaGames\\12Sky\\TwelveSky.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\NGM\\NGM.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-03-13 64160]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-03-14 130424]
R0 tffsport;M-Systems DiskOnChip 2000;c:\windows\system32\drivers\tffsport.sys [2006-11-24 149376]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-07-30 325128]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-30 298264]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 951632]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2008-12-16 2749736]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2008-12-16 15656]
S3 idrmkl;idrmkl;\??\c:\docume~1\HP_ADM~1\LOCALS~1\Temp\idrmkl.sys –> c:\docume~1\HP_ADM~1\LOCALS~1\Temp\idrmkl.sys [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-03-14 348752]

— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
.
Contents of the 'Scheduled Tasks' folder

2009-03-13 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 16:53]

2009-03-13 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-13 11:34]
.
.
——- Supplementary Scan ——-
.
uStart Page =
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local;
uInternet Settings,ProxyServer = http=127.0.0.1:7070
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: moove.com
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\cvhw8qw6.default\
FF - prefs.js: browser.startup.homepage - hxxp://ll-tek-ll.deviantart.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-15 03:15:12
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-2588003286-1639580014-1869957976-1008\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{CA956ACF-856B-6AFE-8641-78586BBA40CC}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iabbgjeidhiookfepd"=hex:6a,61,6e,62,68,6f,65,64,69,6b,67,61,62,65,70,68,70,68,
6d,63,00,00
"hapaagcimdlafeij"=hex:6a,61,6e,62,68,6f,65,64,69,6b,67,61,62,65,70,68,70,68,
6d,63,00,ff
"ianpgmidglgcnhmbgn"=hex:63,61,67,62,69,70,00,7c
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(704)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\arservice.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\logishrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\PSIService.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\WTablet\Pen_TabletUser.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Common Files\logishrd\LVCOMSER\LVComSer.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2009-03-15 3:25:40 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-15 08:25:36
ComboFix2.txt 2009-03-15 03:17:07

Pre-Run: 2,536,792,064 bytes free
Post-Run: 2,541,768,704 bytes free

502 — E O F — 2009-03-15 08:06:32
Sorry for the wait ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Monday, March 16, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Sunday, March 15, 2009 23:17:09 Records in database: 1910408 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ K:\ L:\ M:\ Scan statistics: Files scanned: 357023 Threat name: 4 Infected objects: 7 Suspicious objects: 0 Duration of the scan: 05:12:26 File name / Threat name / Threats count C:\Documents and Settings\All Users\Documents\Files\2008\Julia reformat July 17, 2008\Reformat\Downloads to Keep\MISC\New Folder\Virtual Village 3 don't need but one has saved game\VirtualVillagersTheSecretCitySetup.exe Infected: Trojan-Downloader.Win32.Agent.bfrf 1 C:\Documents and Settings\All Users\Documents\Pictures\New Folder\VirtualVillagersTheSecretCitySetup.exe Infected: Trojan-Downloader.Win32.Agent.bfrf 1 C:\Documents and Settings\HP_Administrator\SmitfraudFix\IEDFix.exe Infected: Hoax.Win32.Renos.dws 1 C:\Program Files\Opera\SmitfraudFix\IEDFix.exe Infected: Hoax.Win32.Renos.dws 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\cemetrix.dll.vir Infected: not-a-virus:AdWare.Win32.Marketscore.a 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\IEDFix.exe.vir Infected: Hoax.Win32.Renos.dws 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\userinit.exe.vir Infected: Trojan-Downloader.Win32.Injecter.btn 1 The selected area was scanned.
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\Documents and Settings\All Users\Documents\Files\2008\Julia reformat July 17, 2008\Reformat\Downloads to Keep\MISC\New Folder\Virtual Village 3 don't need but one has saved game\VirtualVillagersTheSecretCitySetup.exe
C:\Documents and Settings\All Users\Documents\Pictures\New Folder\VirtualVillagersTheSecretCitySetup.exe

KILLALL::

Driver::
idrmkl

RegNull::
[HKEY_USERS\S-1-5-21-2588003286-1639580014-1869957976-1008\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{CA956ACF-856B-6AFE-8641-78586BBA40CC}*]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

5. After reboot, (in case it asks to reboot), please post the Combofix.txt report into your next reply.

I will be away for a couple of days, so Tomk, a very experienced staff member, will check your log and continue to assist you until I get back.

Regards,
RatHat
ComboFix 09-03-13.02 - HP_Administrator 2009-03-16 0:34:09.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.444 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\HP_Administrator\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
c:\documents and settings\All Users\Documents\Files\2008\Julia reformat July 17, 2008\Reformat\Downloads to Keep\MISC\New Folder\Virtual Village 3 don't need but one has saved game\VirtualVillagersTheSecretCitySetup.exe
c:\documents and settings\All Users\Documents\Pictures\New Folder\VirtualVillagersTheSecretCitySetup.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Documents\Files\2008\Julia reformat July 17, 2008\Reformat\Downloads to Keep\MISC\New Folder\Virtual Village 3 don't need but one has saved game\VirtualVillagersTheSecretCitySetup.exe
c:\documents and settings\All Users\Documents\Pictures\New Folder\VirtualVillagersTheSecretCitySetup.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_IDRMKL
——-\Service_idrmkl


((((((((((((((((((((((((( Files Created from 2009-02-16 to 2009-03-16 )))))))))))))))))))))))))))))))
.

2009-03-15 03:05 . 2009-03-15 03:07 d——– C:\50d405b0c9dd102b2c
2009-03-15 03:01 . 2009-03-15 03:01 d——– c:\program files\Microsoft Visual Studio 8
2009-03-14 20:19 . 2009-03-14 21:02 d——– C:\Rooter$
2009-03-14 08:05 . 2009-03-14 08:05 d——– c:\program files\Trend Micro
2009-03-14 07:33 . 2008-12-11 08:38 159,600 –a—— c:\windows\system32\drivers\pctgntdi.sys
2009-03-14 07:32 . 2009-03-14 07:40 d——– c:\program files\Spyware Doctor
2009-03-14 07:32 . 2009-03-14 07:34 d——– c:\program files\Common Files\PC Tools
2009-03-14 07:32 . 2009-03-14 07:32 d——– c:\documents and settings\HP_Administrator\Application Data\PC Tools
2009-03-14 07:32 . 2009-03-14 07:32 d——– c:\documents and settings\All Users\Application Data\PC Tools
2009-03-14 07:32 . 2009-03-06 16:45 130,424 –a—— c:\windows\system32\drivers\PCTCore.sys
2009-03-14 07:32 . 2008-12-18 12:16 73,840 –a—— c:\windows\system32\drivers\PCTAppEvent.sys
2009-03-14 07:32 . 2008-12-10 12:36 64,392 –a—— c:\windows\system32\drivers\pctplsg.sys
2009-03-14 06:47 . 2009-03-14 06:47 d——– c:\program files\Enigma Software Group
2009-03-14 05:29 . 2009-03-13 11:35 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-03-13 11:35 . 2009-03-13 11:34 64,160 –a—— c:\windows\system32\drivers\Lbd.sys
2009-03-13 11:31 . 2009-03-13 11:31 d–h-c— c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-03-12 22:59 . 2009-03-12 22:59 d——– c:\documents and settings\NetworkService\Application Data\Xfire
2009-03-12 22:50 . 2009-03-12 22:59 d——– c:\program files\Xfire
2009-03-12 22:50 . 2009-03-12 23:22 d——– c:\documents and settings\HP_Administrator\Application Data\Xfire
2009-03-09 20:35 . 2009-03-09 20:35 d——– c:\program files\Reference Assemblies
2009-03-07 13:55 . 2009-03-07 13:55 54,156 –ah—– c:\windows\QTFont.qfn
2009-03-07 13:55 . 2009-03-07 13:55 1,409 –a—— c:\windows\QTFont.for
2009-03-06 18:16 . 2009-03-06 18:16 d——– c:\documents and settings\HP_Administrator\Application Data\ATI
2009-03-06 18:16 . 2009-03-06 18:16 d——– c:\documents and settings\All Users\Application Data\ATI
2009-03-06 18:15 . 2009-03-06 18:15 d——– C:\WTablet
2009-03-06 18:14 . 2009-03-06 18:14 0 –a—— c:\windows\ativpsrm.bin
2009-03-06 18:09 . 2009-03-06 18:09 d——– C:\NGM
2009-03-06 18:09 . 2009-02-03 22:05 593,920 ——— c:\windows\system32\ati2sgag.exe
2009-03-06 18:07 . 2009-03-06 18:07 d——– C:\ATI
2009-03-02 02:13 . 2007-03-12 17:42 3,495,784 –a—— c:\windows\system32\d3dx9_33.dll
2009-02-26 13:47 . 2009-02-26 13:47 42,320 –a—— c:\windows\system32\xfcodec.dll
2009-02-25 11:06 . 2009-02-25 11:06 d——– c:\program files\Common Files\INCA Shared
2009-02-25 10:46 . 2009-02-25 10:46 d——– c:\program files\G4box
2009-02-24 06:11 . 2009-02-24 06:11 d——– c:\documents and settings\LocalService\Application Data\Xfire

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-16 05:41 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-16 05:40 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\WTablet
2009-03-15 08:02 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-15 02:57 ——— d—–w c:\program files\System
2009-03-14 10:29 ——— d—–w c:\program files\Common Files\Stardock
2009-03-13 16:31 ——— d—–w c:\program files\Lavasoft
2009-03-13 16:31 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-03-13 12:28 ——— d—–w c:\program files\Nitto 1320 Legends
2009-03-10 01:35 ——— d—–w c:\program files\Microsoft.NET
2009-03-08 17:20 ——— d—–w c:\program files\Windows Desktop Search
2009-03-06 23:10 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-06 23:10 ——— d—–w c:\program files\ATI Technologies
2009-03-03 15:52 ——— d—–w c:\program files\DivX
2009-02-17 12:08 ——— d—–w c:\program files\CamStudio
2009-02-04 07:27 3,488,768 —-a-w c:\windows\system32\drivers\ati2mtag.sys
2009-02-04 03:52 53,248 —-a-w c:\windows\system32\drivers\ati2erec.dll
2009-02-01 22:54 ——— d—–w c:\documents and settings\LocalService\Application Data\WTablet
2009-02-01 00:49 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-02-01 00:49 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-01-30 01:23 ——— d—–w c:\program files\Yahoo!
2009-01-30 01:23 ——— d—–w c:\program files\Opera
2009-01-29 22:00 ——— d—–w c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-01-19 00:32 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-01-18 01:30 ——— d—–w c:\documents and settings\All Users\Application Data\FLEXnet
2008-07-30 03:30 15,360 –sh–w c:\documents and settings\HP_Administrator\SetupDL.exe
2007-06-07 18:45 80 –sh–r c:\windows\system32\FF553558F8.dll
2006-09-16 19:25 848 –sha-w c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( SnapShot_2009-03-15_ 3.24.14.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-16 05:40:21 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_5b8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"TuneUp MemOptimizer"="c:\program files\TuneUp Utilities 2007\MemOptimizer.exe" [2006-12-19 310792]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-09-21 1605740]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-03-20 213936]
"ISUSScheduler"="c:\program files\common files\installshield\updateservice\issch.exe" [2006-03-20 86960]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-31 1601304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-03 61440]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-13 515416]
"SpyHunter Security Suite"="c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2009-01-13 864256]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 c:\windows\arpwrmsg.exe]

c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2005-11-22 27136]

c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
PowerReg Scheduler.exe [2008-03-02 256000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
DataViz Inc Messenger.lnk - c:\program files\Common Files\DataViz\DvzIncMsgr.exe [2007-02-16 28672]
HotSync Manager.lnk - c:\program files\palmOne\Hotsync.exe [2004-06-09 471040]
Suitcase Startup.lnk - c:\program files\Extensis\Suitcase 9.2\Suitcase.exe [2006-02-11 3145728]
TabUserW.exe.lnk - c:\windows\system32\WTablet\TabUserW.exe [2006-06-09 114688]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\documents and settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-31 19:49 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
–a—— 2005-11-08 17:00 128920 c:\program files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-02-17 04:10 155648 c:\program files\QuickTime\qttask.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"PhotoShow Deluxe Media Manager"=c:\progra~1\Ahead\Ahead\data\Xtras\mssysmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PCDrSmartMonitor"="c:\program files\PC-Doctor 5 for Windows\PcdSmartMonitor.exe" -r
"Adobe_ID0EYTHM"=c:\progra~1\COMMON~1\Adobe\ADOBEV~2\Server\bin\VERSIO~2.EXE
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" /hide
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\AeriaGames\\ProjectTorque\\ProjectTorque.bin"=
"c:\\AeriaGames\\12Sky\\TwelveSky.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\NGM\\NGM.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-03-13 64160]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-03-14 130424]
R0 tffsport;M-Systems DiskOnChip 2000;c:\windows\system32\drivers\tffsport.sys [2006-11-24 149376]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-07-30 325128]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-30 298264]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 951632]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2008-12-16 2749736]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2008-12-16 15656]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-03-14 348752]

— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
.
Contents of the 'Scheduled Tasks' folder

2009-03-13 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 16:53]

2009-03-13 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-13 11:34]
.
.
——- Supplementary Scan ——-
.
uStart Page =
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local;
uInternet Settings,ProxyServer = http=127.0.0.1:7070
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: moove.com
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\cvhw8qw6.default\
FF - prefs.js: browser.startup.homepage - hxxp://ll-tek-ll.deviantart.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-16 00:40:39
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(704)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\arservice.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\logishrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\PSIService.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\WTablet\Pen_TabletUser.exe
c:\windows\system32\dllhost.exe
c:\program files\Common Files\logishrd\LVCOMSER\LVComSer.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\system32\msiexec.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\hp\KBD\kbd.exe
.
**************************************************************************
.
Completion time: 2009-03-16 0:51:13 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-16 05:51:09
ComboFix2.txt 2009-03-15 08:25:43
ComboFix3.txt 2009-03-15 03:17:07

Pre-Run: 3,431,825,408 bytes free
Post-Run: 3,487,088,640 bytes free

263 — E O F — 2009-03-15 08:06:32

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI