This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Desktop background picture disabled

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi SpySentinel I have uninstalled the Ask toolbar,at the moment l dont seem to find anything that might have installed without me knowing. I downloaded the OTMoveit3 and below is the report: ========== PROCESSES ========== Process explorer.exe killed successfully. ========== FILES ========== C:\Program Files\AskTBar\PopSwatr\History moved successfully. C:\Program Files\AskTBar\PopSwatr moved successfully. C:\Program Files\AskTBar\bar\Settings moved successfully. C:\Program Files\AskTBar\bar\History moved successfully. C:\Program Files\AskTBar\bar moved successfully. C:\Program Files\AskTBar moved successfully. C:\NeroUltraKeygen.exe moved successfully. ========== COMMANDS ========== File delete failed. C:\Users\Toshiba\AppData\Local\Temp\~DFF39A.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Windows\temp\TMP00000065DE2230456BB243DA scheduled to be deleted on reboot. Windows Temp folder emptied. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.10.0 log created on 04082009_155952
Hi Ldee247, I have some good news for you.


Your logs look clean, Great Job :thumbup:

Now for some cleanup..
Please download OTCleanIt and save it to Desktop.
  • Please make sure you are connecting to the Internet
  • Double-click OTCleanIt.exe
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

    Disabling System Restore
    WARNING: By disabling system restore you will delete all stored restore points and shadow copies of documents on your computer.
    To disable System Restore you would follow these steps:
    • Click on the Start button to open Start Menu.
    • Click on Control Panel
    • Click on System and Maintenance
    • Click on System
    • Click on System Protection in the left-hand task list.
    • Uncheck the checkboxes next to each hard drive listed under the Create restore points automatically on the selected disks: section. When you uncheck a disk you will be presented with the following screen.
    • You should click on the Turn System Protection Off button.
    • Press the Apply button and then the OK button.
    System Restore is now disabled.

    Enabling System Restore
    By default System Restore is enabled on Windows Vista. To enable System Restore:
    • Click on the Start button
    • Click on the Control Panel menu option.
    • Click on System and Maintenance
    • Click on System
    • Click on System Protection in the left-hand task list.
    • Put a checkmark in the checkboxes next to each hard drive listed under the Create restore points automatically on the selected disks: section.
    • Press the Apply button and then the OK button.
    System Restore is now enabled again.

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

  • Install SpywareGuard - SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program or there will be a conflict.

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

here are some additional utilities that will enhance your safety

  • McAfee Site Advisor <= McAfee Site Advisor protects your browser against malicious sites and warns you when you go to one.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Winpatrol <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
    Using Winpatrol to protect your computer from malicious software
Hi SpySentinel According to the last post you sent me l have done all you requested,but now the computer seem to behaving so funny it has become even much more slower than before, the internet is taking long to upload and when l'm on internet the web pages are freezing and all of a sudden the internet shuts down.some mouse click commands are not responding when you try to close web pages… Can you help dont seem to know whats gone wrong…????? Thanks Ldee247
Hi Ldee247 , it does not seem to be related to malware at all, because all of your logs are clean.

What I can have you do is run ComboFix to see if there is an infection still, but if that comes back clean the problem is not malware related and I can send you over to a Tech who can help fix your computer.


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Hi SpySentinel

I downloaded COMBO FIX and followed the onscreen prompts until a log file report was generated which l copied and pasted below:


ComboFix 09-04-04.01 - Toshiba 2009-04-10 14:44:54.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1014.149 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: PCguard Anti-Virus *On-access scanning disabled* (Updated)
FW: PCguard Firewall *enabled*
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-03-10 to 2009-04-10 )))))))))))))))))))))))))))))))
.

2009-04-10 14:26 . 2006-03-03 00:42 73,728 –a—— C:\pv.exe
2009-04-09 13:21 . 2009-04-09 13:21 d——– c:\users\All Users\SiteAdvisor
2009-04-09 13:21 . 2009-04-09 13:21 d——– c:\programdata\SiteAdvisor
2009-04-09 13:17 . 2009-04-09 13:17 d——– c:\program files\Common Files\McAfee
2009-04-09 13:16 . 2009-04-09 13:16 d——– c:\users\All Users\Yahoo! Companion
2009-04-09 13:16 . 2009-04-09 13:17 d——– c:\users\All Users\McAfee
2009-04-09 13:16 . 2009-04-09 13:16 d——– c:\programdata\Yahoo! Companion
2009-04-09 13:16 . 2009-04-09 13:17 d——– c:\programdata\McAfee
2009-04-09 13:16 . 2009-04-09 14:14 d——– c:\program files\McAfee
2009-04-09 13:13 . 2009-04-09 13:16 d——– c:\program files\SpywareGuard
2009-04-09 13:09 . 2009-04-09 13:09 d——– c:\program files\SpywareBlaster
2009-04-09 09:30 . 2008-06-20 02:14 781,344 –a—— c:\windows\System32\PresentationNative_v0300.dll
2009-04-09 09:30 . 2008-06-20 02:14 622,080 –a—— c:\windows\System32\icardagt.exe
2009-04-09 09:30 . 2008-06-20 02:14 326,160 –a—— c:\windows\System32\PresentationHost.exe
2009-04-09 09:30 . 2008-06-20 02:14 105,016 –a—— c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-04-09 09:30 . 2008-06-20 02:14 97,800 –a—— c:\windows\System32\infocardapi.dll
2009-04-09 09:30 . 2008-06-20 02:14 43,544 –a—— c:\windows\System32\PresentationHostProxy.dll
2009-04-09 09:30 . 2008-06-20 02:14 37,384 –a—— c:\windows\System32\infocardcpl.cpl
2009-04-09 09:30 . 2008-06-20 02:14 11,264 –a—— c:\windows\System32\icardres.dll
2009-04-09 09:20 . 2008-07-27 19:03 96,760 –a—— c:\windows\System32\dfshim.dll
2009-04-09 09:19 . 2008-07-27 19:03 282,112 –a—— c:\windows\System32\mscoree.dll
2009-04-09 09:19 . 2008-07-27 19:03 158,720 –a—— c:\windows\System32\mscorier.dll
2009-04-09 09:19 . 2008-07-27 19:03 83,968 –a—— c:\windows\System32\mscories.dll
2009-04-09 09:19 . 2008-07-27 19:03 41,984 –a—— c:\windows\System32\netfxperf.dll
2009-04-08 15:59 . 2009-04-08 15:59 d——– C:\_OTMoveIt
2009-04-05 19:21 . 2009-04-09 13:23 d——– c:\program files\watch-football.net
2009-03-27 15:28 . 2009-03-27 15:28 607,640 –a—— c:\users\Toshiba\jre-6u13-windows-i586-p-iftw.exe
2009-03-27 14:58 . 2009-03-27 15:28 d——– c:\users\Toshiba\.SunDownloadManager
2009-03-26 20:01 . 2009-03-26 20:01 d——– c:\users\Toshiba\AppData\Roaming\Nero
2009-03-26 15:36 . 2009-03-26 15:36 d——– c:\users\All Users\SUPERAntiSpyware.com
2009-03-26 15:36 . 2009-03-26 15:36 d——– c:\programdata\SUPERAntiSpyware.com
2009-03-26 15:35 . 2009-03-26 15:35 d——– c:\users\Toshiba\AppData\Roaming\SUPERAntiSpyware.com
2009-03-26 15:35 . 2009-03-27 16:25 d——– c:\program files\SUPERAntiSpyware
2009-03-26 15:33 . 2009-03-26 15:33 d——– c:\program files\Common Files\Wise Installation Wizard
2009-03-26 13:42 . 2009-03-27 08:58 156,629,198 –a—— c:\windows\MEMORY.DMP
2009-03-25 09:51 . 2009-03-25 09:51 d——– C:\OutputFolder
2009-03-25 09:48 . 2009-03-25 09:49 d——– c:\users\Toshiba\AppData\Roaming\GetRightToGo
2009-03-23 18:21 . 2009-03-23 18:58 d——– C:\VideoToDVD
2009-03-23 08:26 . 2002-05-19 02:57 944,797 –a—— c:\program files\wrar300.exe
2009-03-23 01:39 . 2009-03-23 01:40 d——– c:\program files\Ares
2009-03-20 19:11 . 2009-03-20 19:11 d——– c:\program files\ToggleEN
2009-03-20 19:11 . 2009-03-20 19:11 d——– c:\program files\Conduit
2009-03-20 18:32 . 2009-03-20 18:55 d-ahs—- c:\users\Public\DRM
2009-03-18 21:07 . 2009-03-18 21:07 d——– C:\_OTListIt
2009-03-18 20:13 . 2009-03-25 18:30 1,423 –a—— c:\windows\System32\SHORTCUT.INI
2009-03-18 19:42 . 2009-03-25 19:40 132 –a—— c:\windows\System32\REMOTEDEVICE.INI
2009-03-18 19:36 . 2009-04-10 14:33 5,982 –a—— c:\windows\System32\LOCALSERVICE.INI
2009-03-18 19:36 . 2009-03-25 19:33 99 –a—— c:\windows\System32\LOCALDEVICE.INI
2009-03-18 19:32 . 2009-03-18 19:32 0 –a—— c:\windows\System32\BSPRINT.INI
2009-03-18 17:02 . 2001-07-06 14:41 569,344 -ra—— c:\windows\System32\imagr5.dll
2009-03-18 17:02 . 2001-07-06 12:44 544,768 -ra—— c:\windows\System32\imagx5.dll
2009-03-18 17:02 . 2001-07-06 18:24 283,920 -ra—— c:\windows\System32\ImagXpr5.dll
2009-03-18 17:02 . 2000-06-26 11:45 106,496 -ra—— c:\windows\System32\TwnLib20.dll
2009-03-18 17:02 . 2001-06-26 08:15 38,912 -ra—— c:\windows\System32\picn20.dll
2009-03-17 17:50 . 2009-03-17 17:50 125,425 –a—— c:\users\Toshiba\WindowsXP-KB835935-SP2-ENU.exe
2009-03-17 15:11 . 2009-02-15 01:17 331,776 –a—— C:\Interop.WMPLib.dll
2009-03-17 15:11 . 2009-02-15 01:17 61,440 –a—— C:\AxInterop.WMPLib.dll
2009-03-12 23:07 . 2009-03-12 23:07 d——– c:\users\All Users\InterVideo
2009-03-12 23:07 . 2009-03-12 23:07 d——– c:\programdata\InterVideo
2009-03-12 09:44 . 2009-03-12 09:44 0 –a—— C:\OrbPVR.db
2009-03-11 09:02 . 2008-12-16 04:29 8,147,456 –a—— c:\windows\System32\wmploc.DLL
2009-03-11 09:02 . 2009-02-09 04:10 2,033,152 –a—— c:\windows\System32\win32k.sys
2009-03-11 09:02 . 2008-11-27 05:43 268,288 –a—— c:\windows\System32\schannel.dll
2009-03-11 09:02 . 2008-12-16 06:31 7,680 –a—— c:\windows\System32\spwmp.dll
2009-03-11 09:02 . 2008-12-16 06:31 4,096 –a—— c:\windows\System32\msdxm.ocx
2009-03-11 09:02 . 2008-12-16 06:31 4,096 –a—— c:\windows\System32\dxmasf.dll
2009-03-10 14:24 . 2009-03-10 14:26 d——– c:\users\All Users\WinZip
2009-03-10 14:24 . 2009-03-10 14:26 d——– c:\programdata\WinZip

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-10 13:51 ——— d—–w c:\programdata\Kontiki
2009-04-10 13:34 ——— d—–w c:\program files\Winamp Remote
2009-04-10 09:56 ——— d—–w c:\programdata\Google Updater
2009-04-09 12:16 ——— d—–w c:\program files\Yahoo!
2009-03-27 14:34 ——— d—–w c:\program files\Java
2009-03-27 09:27 ——— d—–w c:\programdata\NOS
2009-03-27 09:22 ——— d—–w c:\program files\NOS
2009-03-26 16:56 ——— d—–w c:\users\Toshiba\AppData\Roaming\Winamp
2009-03-26 16:56 ——— d—–w c:\programdata\Ulead Systems
2009-03-25 17:23 ——— d—–w c:\users\Toshiba\AppData\Roaming\Skype
2009-03-25 16:11 ——— d—–w c:\users\Toshiba\AppData\Roaming\skypePM
2009-03-25 07:51 ——— d—a-w c:\programdata\TEMP
2009-03-23 18:10 ——— d—–w c:\program files\Kontiki
2009-03-18 16:55 ——— d—–w c:\programdata\Bluetooth
2009-03-18 15:52 ——— d—–w c:\programdata\Nero
2009-03-18 08:46 ——— d—–w c:\users\Toshiba\AppData\Roaming\LimeWire
2009-03-12 08:04 ——— d—–w c:\program files\Windows Mail
2009-03-12 07:59 ——— d—–w c:\programdata\Microsoft Help
2009-03-11 19:46 ——— d—–w c:\users\Toshiba\AppData\Roaming\Ulead Systems
2009-03-09 05:19 410,984 —-a-w c:\windows\System32\deploytk.dll
2009-02-27 16:45 9,728 —-a-w c:\windows\System32\BsMonUI.dll
2009-02-27 16:45 57,430 —-a-w c:\windows\System32\btfunc.dll
2009-02-27 16:45 405,589 —-a-w c:\windows\System32\BsUI.dll
2009-02-27 16:45 18,432 —-a-w c:\windows\System32\BsMonSvr.dll
2009-02-27 16:44 622,693 —-a-w c:\windows\System32\BSShell.dll
2009-02-27 16:44 53,248 —-a-w c:\windows\System32\HtmPrintHelper.dll
2009-02-27 16:44 278,647 —-a-w c:\windows\System32\outlookAddin.dll
2009-02-27 16:44 114,774 —-a-w c:\windows\System32\versit.dll
2009-02-27 16:43 94,314 —-a-w c:\windows\System32\BsHelpCSps.dll
2009-02-27 16:43 557,142 —-a-w c:\windows\System32\Bscdlg.dll
2009-02-27 16:43 553,075 —-a-w c:\windows\System32\BlueSoleilCSps.dll
2009-02-27 16:43 151,642 —-a-w c:\windows\System32\BsCommon.dll
2009-02-27 16:43 114,788 —-a-w c:\windows\System32\BsProfileFunc.dll
2009-02-27 16:41 98,403 —-a-w c:\windows\System32\Bs2Res.dll
2009-02-27 16:41 28,766 —-a-w c:\windows\System32\PlayerCtrl.dll
2009-02-27 16:41 241,748 —-a-w c:\windows\System32\BsSDK.dll
2009-02-27 16:41 122,976 —-a-w c:\windows\System32\BsMobileSDK.dll
2009-02-27 16:40 28,760 —-a-w c:\windows\System32\BsTrace.dll
2009-02-27 16:40 28,672 —-a-w c:\windows\System32\BsMobileCSps.dll
2009-02-24 08:20 ——— d—–w c:\program files\Veetle
2009-02-17 20:37 ——— d—–w c:\program files\Google
2009-02-14 23:20 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-02-11 10:19 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 10:19 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-02-10 17:43 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-10 16:56 ——— d—–w c:\program files\Microsoft Games
2009-02-10 16:43 ——— d—–w c:\program files\Common Files\SWF Studio
2009-01-15 06:11 827,392 —-a-w c:\windows\System32\wininet.dll
2008-08-08 13:56 174 –sha-w c:\program files\desktop.ini
2002-05-19 02:48 102 —-a-w c:\program files\Readme.txt
2002-05-15 00:37 473 —-a-w c:\program files\rarreg.key
2008-06-30 12:44 324,976 —-a-w c:\program files\mozilla firefox\components\coFFPlgn.dll
2008-08-13 23:01 122,880 —-a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2008-04-07 07:41 67,696 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2008-04-07 07:41 54,376 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-04-07 07:41 34,952 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-04-07 07:41 46,720 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-04-07 07:41 172,144 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
2008-04-02 09:29 16,384 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-04-02 09:29 32,768 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-04-02 09:29 16,384 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2008-05-11 20:17 16,384 –sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-05-11 20:17 32,768 –sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-05-11 20:17 16,384 –sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2008-07-16 1266992]
"{038cb5c7-48ea-4af9-94e0-a1646542e62b}"= "c:\program files\ToggleEN\tbTogg.dll" [2009-02-16 1882136]

[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]

[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
2009-02-16 16:44 1882136 –a—— c:\program files\ToggleEN\tbTogg.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{038cb5c7-48ea-4af9-94e0-a1646542e62b}"= "c:\program files\ToggleEN\tbTogg.dll" [2009-02-16 1882136]
"{829db392-4699-433f-b952-5ae235e3259d}"= "c:\program files\watch-football.net\tbwatc.dll" [2006-09-13 1117208]

[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]

[HKEY_CLASSES_ROOT\clsid\{829db392-4699-433f-b952-5ae235e3259d}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{038CB5C7-48EA-4AF9-94E0-A1646542E62B}"= "c:\program files\ToggleEN\tbTogg.dll" [2009-02-16 1882136]
"{829DB392-4699-433F-B952-5AE235E3259D}"= "c:\program files\watch-football.net\tbwatc.dll" [2006-09-13 1117208]

[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]

[HKEY_CLASSES_ROOT\clsid\{829db392-4699-433f-b952-5ae235e3259d}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"kdx"="c:\program files\Kontiki\KHost.exe" [2009-01-02 1041960]
"ares"="c:\program files\Ares\Ares.exe" [2009-02-03 1004544]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-03-27 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-22 894248]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Ulead AutoDetector"="c:\program files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe" [2003-11-18 45056]
"Ulead Photo Express Calendar Checker"="c:\program files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe" [2004-01-12 69632]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-08-14 29744]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"4oD"="c:\program files\Kontiki\KHost.exe" [2009-01-02 1041960]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"Broadbandadvisor.exe"="c:\program files\Virgin Broadband\advisor\Broadbandadvisor.exe" [2007-08-07 2061552]
"PCguard"="c:\program files\Virgin Broadband\PCguard\Rps.exe" [2007-09-05 310000]
"-FreedomNeedsReboot"="c:\program files\Virgin Broadband\PCguard\ZkRunOnceR.exe" [2007-09-05 13552]
"Wireless Manager"="c:\program files\Virgin Broadband Wireless\Wireless Manager.exe" [2008-05-26 585728]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-04 36352]
"BtTray"="c:\program files\IVT Corporation\BlueSoleil\BtTray.exe" [2009-02-27 278016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 c:\windows\RtHDVCpl.exe]
"Skytel"="Skytel.exe" [2007-06-15 c:\windows\SkyTel.exe]
"NDSTray.exe"="NDSTray.exe" [BU]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

c:\users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-08-29 360448]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-05-14 113664]
RAMASST.lnk - c:\windows\System32\RAMASST.exe [2008-05-14 155648]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-01-14 525664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 12:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{657E2790-7A68-44EB-B717-9C7D89E33040}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{A962E0D5-562C-4EAC-AAFE-0E98951BA33B}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{CEFB1A4C-4196-4ED5-91C3-5C51C40DE9B4}c:\\program files\\bitdownload\\bitdownload.exe"= UDP:c:\program files\bitdownload\bitdownload.exe:BitDownload
"UDP Query User{1CC5647E-7BDA-4D2A-AB89-F56532495045}c:\\program files\\bitdownload\\bitdownload.exe"= TCP:c:\program files\bitdownload\bitdownload.exe:BitDownload
"TCP Query User{D504B23E-0E79-4B5C-AFCF-4641A3D69675}c:\\program files\\bitdownload\\bitdownload.exe"= UDP:c:\program files\bitdownload\bitdownload.exe:BitDownload
"UDP Query User{C3130EC2-65C1-43C6-9FBC-F468FBAE2615}c:\\program files\\bitdownload\\bitdownload.exe"= TCP:c:\program files\bitdownload\bitdownload.exe:BitDownload
"TCP Query User{A7917DA3-A0B0-4C21-90C8-E97714F157DE}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{3F8F07C5-BDA2-412B-8797-536CE8806ACB}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"{3302937E-EB92-434D-95B7-1F9BD18757A3}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{A0F47E87-3668-4BC3-94AA-4E2C9B97F7DF}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{21BAEA41-560D-4D76-8850-D53ADFEA00D9}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{49EBA0A9-AE2D-4AD4-993D-6FA3DBDB7614}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{1500C895-2326-446F-B23A-F1FC1C4121C2}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EAA97DAB-8AA3-40AC-8B4B-D9685020FD1F}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{3B505F01-FA9C-4F03-B2E8-9FC2863D93F8}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{16057D6C-BF53-4B22-84D3-645A320C0600}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{62292CD1-4D2F-4367-9564-8521D8B80926}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{0AF14551-7353-4166-8898-99D989DE9993}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{8A84FF83-3AEE-47A4-A398-3FC562E7937E}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{35498E36-7575-493B-A961-D4DCF78CB456}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{33801AA8-3FF6-43EE-88AB-2F495AAC7CD3}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{B5845C2E-1AD1-45F2-AE7A-B7F5246752E3}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{0420E385-645D-41E1-A1EC-33F9B7E8F205}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"{ECD2DBEB-DF81-4DFF-B6C7-0F6C9C87621C}"= UDP:c:\program files\McAfee\Common Framework\FrameworkService.exe:McAfee Framework Service
"{A6698BAD-28C3-4629-9B83-053A8B56FEB1}"= TCP:c:\program files\McAfee\Common Framework\FrameworkService.exe:McAfee Framework Service
"{0BC1ACC5-2F22-4C15-8A52-3DC35DFA08E5}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{61568BDD-5D2D-481D-AC5A-5BCF5BB34FE4}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil_.exe:BlueSoleil
"{3448B3C0-6CAB-448F-AAC6-7788071EF9A6}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil_.exe:BlueSoleil
"{C0BDE073-1A9F-43FD-AE21-7D3C9F06F284}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{8AEE36D9-5F73-42B3-8F1E-4E64D6BFEA80}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{6EC89285-C9FB-4655-A203-461C21F05B3E}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{396E548D-C287-4325-B138-F83E16969CF1}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{CCF289AB-27EA-4114-9A5E-A0FFAEF3ED70}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{C50C5BAD-1289-4BC6-B15B-BF917681CA4C}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"{CF46C3AB-633C-4F5C-BF6B-9D2E6A3B0482}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"{63988533-9DCB-4ECE-9B45-49DB5D5D7889}"= Disabled:UDP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{FA0559D9-B3AB-4A88-B272-0B2C1F3CE9A8}"= Disabled:TCP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{13AD6692-36FF-4789-BED0-168807376B51}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil_.exe:BlueSoleil
"{BA8047FC-9E9C-407E-A6DC-66B012E6DEC9}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil_.exe:BlueSoleil
"{91B58C53-162A-49EF-9B25-468AC87FDF74}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{0262F07B-B541-4E5F-B634-C3B150B0575A}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{684B9D67-DE81-4995-BC52-5B13CE1EFC86}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{88FD7088-EE74-4F50-A8F5-A3FD8A01DDF1}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= UDP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"UDP Query User{31DB0BAB-4476-42DE-A513-1680A5ACCC2A}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= TCP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"TCP Query User{D92E2C82-9699-42CA-AD78-94DAA118103A}c:\\users\\toshiba\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= UDP:c:\users\toshiba\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe
"UDP Query User{48EEA5F2-41E0-4DC4-AE75-D8DB8F2F90AF}c:\\users\\toshiba\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= TCP:c:\users\toshiba\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe
"{2C390D6A-CECB-4C3D-AB36-3751ECBFB915}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{9151333D-0FC9-41C4-B8B1-FEBC2C73B2C9}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"TCP Query User{68BF232E-B7C0-468C-8F44-8675C91DEB1E}c:\\program files\\kontiki\\khost.exe"= UDP:c:\program files\kontiki\khost.exe:Delivery Manager
"UDP Query User{B1B62B52-665E-4945-A5CF-D80988D6188B}c:\\program files\\kontiki\\khost.exe"= TCP:c:\program files\kontiki\khost.exe:Delivery Manager
"{385D04FD-A628-4000-84A3-CA059562196C}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{105EDC7E-9F7E-44DF-80EB-89C432E2F968}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"TCP Query User{D7CE99D2-2697-4811-9001-B6721FE16EA8}c:\\program files\\webmediaplayer\\webmediaplayer.exe"= UDP:c:\program files\webmediaplayer\webmediaplayer.exe:WebMediaPlayer
"UDP Query User{BA24DC06-2CDC-40B4-A009-4EC768664BDD}c:\\program files\\webmediaplayer\\webmediaplayer.exe"= TCP:c:\program files\webmediaplayer\webmediaplayer.exe:WebMediaPlayer
"{D85F615F-9C05-41A4-B0B6-5E6C6B371F84}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{99EAC962-86A6-4245-B053-45432C0E6EA1}c:\\program files\\tvuplayer\\tvuplayer.exe"= UDP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"UDP Query User{2A4773D4-61F7-426D-95F7-001EEB626995}c:\\program files\\tvuplayer\\tvuplayer.exe"= TCP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"{E97C5382-0215-4F61-AC12-4C4596BB66FC}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{D5DA6B19-6CF5-41C3-B191-62D5BD2CF5A3}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{C3D7987C-5625-4CEA-A234-CD77493C0A30}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{9B202BBF-E1FC-4FC8-BDB1-616E2F3FE4C0}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{3C960676-35A5-463A-B79A-FD6DAAA9A0DB}c:\\users\\toshiba\\appdata\\local\\octoshape\\octoshape streaming services\\octoshapeclient.exe"= UDP:c:\users\toshiba\appdata\local\octoshape\octoshape streaming services\octoshapeclient.exe:octoshapeclient.exe
"UDP Query User{C361EC20-DA38-4BC0-9DA6-C97A99F6BD55}c:\\users\\toshiba\\appdata\\local\\octoshape\\octoshape streaming services\\octoshapeclient.exe"= TCP:c:\users\toshiba\appdata\local\octoshape\octoshape streaming services\octoshapeclient.exe:octoshapeclient.exe
"{4AB6ED73-3206-493E-A141-543F6DD8057C}"= UDP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
"{82ED0535-46FB-4036-9255-B16031FAF02C}"= TCP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
"{D04923DC-1088-42AB-8C56-864FB88B912E}"= UDP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
"{00E84E16-6DC3-4411-B503-65254394FF1E}"= TCP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
"{479C9AF8-907B-4976-81F6-2A1E0F1909F8}"= UDP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
"{84CCFC95-731D-403C-8493-9E496EC7E9FB}"= TCP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
"TCP Query User{69BB1901-52FB-49DE-9BDB-FB3D4105587C}c:\\program files\\tvuplayer\\tvuplayer.exe"= UDP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"UDP Query User{C6F91E58-A4AD-4996-8F87-3A25ADED90D0}c:\\program files\\tvuplayer\\tvuplayer.exe"= TCP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"{E67A5491-1BD7-42B6-B5C6-7584817ED5F0}"= UDP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{360883DE-FA6F-4C12-A09D-A4D56630657E}"= TCP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{E9ECFC1D-5062-4BBD-8CF4-FF1FDCD66CB7}"= UDP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{5274B3E7-BAAA-4461-BC2B-6C2CD17A88BD}"= TCP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{4B16DD7B-B423-488B-B679-B848BE8806D5}"= UDP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{3B861E98-1843-45B1-A534-9AA1720B76B9}"= TCP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{A56ADD76-0293-45AE-B683-5021261EC50B}"= UDP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{2A83CE77-4517-4C3F-8E40-E6A63FD93EC3}"= TCP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{79F6EB85-8791-49FF-A114-E34DA4FC5B1F}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{3225AA82-1FF7-4B83-94F9-5B8C4E15F69F}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{18DA592B-E9BC-4A77-A4C7-914601121A40}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{EFF7B652-70AE-495E-8A34-8DF20BF66051}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
"TCP Query User{6EF6BD60-74A9-4C99-AA32-29142052AF9D}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{107D3784-ACC0-415D-90A9-9A5386B33865}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows

R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\System32\drivers\BtHidBus.sys [2009-01-08 20744]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-02-17 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-02-17 55024]
R2 BsMobileCS;BsMobileCS;c:\program files\IVT Corporation\BlueSoleil\BsMobileCS.exe [2009-02-27 143467]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-04-09 210216]
R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\System32\drivers\btnetBus.sys [2008-12-07 30088]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\System32\drivers\IvtBtBus.sys [2008-07-02 26248]
R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\System32\drivers\RTL8187B.sys [2008-08-12 339456]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2009-03-27 33176]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-08-05 29744]
S3 Radialpoint Security Services;Virgin Broadband PCguard;c:\windows\System32\dllhost.exe [2006-11-02 7168]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder

2008-08-17 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]

2009-04-10 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 08:47]

2009-04-10 c:\windows\Tasks\User_Feed_Synchronization-{3F837391-37B4-4652-8F63-A24909EEA1FE}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 08:33]

2009-04-10 c:\windows\Tasks\User_Feed_Synchronization-{99FB82D8-7D7F-4B02-B9E1-3BB97C159D41}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 08:33]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p;=%s
IE: &Search;
IE: &Winamp; Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Windows; Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send by Bluetooth - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tsinfo.htm
IE: Send via &Message;… - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tssms.htm
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - http://rover.ebay.com/rover/1/710-44557-9400-3/4
IE: {{8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/redire…1&site;=home
FF - ProfilePath -

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.hideGoButton", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver;={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&features;=TrustRank&client;={moz:client}&appver;={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?");
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-10 14:50:26
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(5100)
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\windows\system32\BsMobileSDK.dll
c:\windows\system32\BsLangInDepRes.dll
c:\windows\system32\Bs2Res.dll
.
Completion time: 2009-04-10 14:54:37
ComboFix-quarantined-files.txt 2009-04-10 13:54:30
ComboFix2.txt 2008-11-23 19:59:11
ComboFix3.txt 2008-09-13 19:24:19

Pre-Run: 20,191,776,768 bytes free
Post-Run: 20,063,526,912 bytes free

397 — E O F — 2009-04-09 08:38:30



Will be waiting to hear from your next response

Thanks for your cooperation

Ldee247

Thanks for your cooperation

Ldee247


No problem :thumbup:

Your log looks clean, so your computers slowness may be related to a tech issue. My best bet would be for you to post in the Tech Forum, and if that does not fix it, send me a PM and I will re open this topic and we can go from there.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI