This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Redirect virus

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I doubt im the only one to have this atm, all IE or other searches bounce through 5 or 6 other sites, Ask.com,Ebay, random advertisemnets and porn. No software seems to find it, and im not tech enuf to find it myself. any help/advice would be gratefully recieved.
(additional) Also cannot update any antivirus software now :(

I enclose my Hijackthis log here :-


Scan saved at 14:06:16, on 24/03/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gooogle.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [btbb_McciTrayApp] "C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: eBay.co.uk - Buy It Sell It Love It - {76577871-04EC-495E-A12B-91F7C3600AFA} - http://rover.ebay.com/rover/1/710-44557-9400-3/4 (file missing)
O9 - Extra button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/redire…1&site=home (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: PacificPoker4 - {94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} - C:\PROGRA~1\PACIFI~1\pacificpoker.exe (file missing)
O13 - Gopher Prefix:
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://static.photobox.co.uk/sg/common/uploader_uni.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5F973031-C962-4AE0-B2C2-BA5B8E2E48C8}: NameServer = 85.255.112.180,85.255.112.173
O17 - HKLM\System\CCS\Services\Tcpip\..\{8359E2C3-E176-45BF-8920-6014C45D6B46}: NameServer = 85.255.112.180,85.255.112.173
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.180,85.255.112.173
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.112.180,85.255.112.173
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.180,85.255.112.173
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

–
End of file - 11909 bytes
Hello curiouslyyellow and welcome to the forums here at WTT!

:welcome:

First, use Use ATF Cleaner to remove temp files,
cookies, cache, ect…

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I would also like you to run a couple of other scans.

Download Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have installed Windows). Post that in your next reply.
Please post back with
  • Rooter log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
First thanks for the sppedy reply :) Right i ran the ATF scan,downloaded and installed Malwarebytes, but when i run malwarebytes nothing happens,even from the first install, no updates , no program?? Any ideas,or should i run any othe the other prgrams in the list first? Thanks again for your time
KK this is from Rooter

Microsoft Windows Vista Home Edition (6.0.6001) Service Pack 1

C:\ [Fixed] - NTFS - (Total:57235 Mo/Free:1733 Mo)
E:\ [Fixed] - NTFS - (Total:55735 Mo/Free:2908 Mo)
F:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)

25/03/2009|19:16

———————-\\ Processes..

–Locked– [System Process]
–Locked– System
———- \SystemRoot\System32\smss.exe
———- C:\Windows\system32\csrss.exe
———- C:\Windows\system32\wininit.exe
———- C:\Windows\system32\csrss.exe
———- C:\Windows\system32\services.exe
———- C:\Windows\system32\lsass.exe
———- C:\Windows\system32\lsm.exe
———- C:\Windows\system32\winlogon.exe
———- C:\Windows\system32\svchost.exe
———- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
———- C:\Windows\system32\svchost.exe
———- C:\Windows\System32\svchost.exe
———- C:\Windows\system32\Ati2evxx.exe
———- C:\Windows\System32\svchost.exe
———- C:\Windows\System32\svchost.exe
———- C:\Windows\system32\svchost.exe
–Locked– audiodg.exe
———- C:\Windows\system32\SLsvc.exe
———- C:\Windows\system32\svchost.exe
———- C:\Windows\system32\Ati2evxx.exe
———- C:\Windows\system32\svchost.exe
———- C:\Windows\System32\spoolsv.exe
———- C:\Windows\system32\svchost.exe
———- C:\Windows\system32\agrsmsvc.exe
———- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
———- C:\Program Files\Bonjour\mDNSResponder.exe
———- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
———- C:\Windows\system32\svchost.exe
———- C:\Program Files\Kontiki\KService.exe
———- C:\Program Files\Common Files\Motive\McciCMService.exe
———- C:\Windows\System32\svchost.exe
———- C:\Windows\System32\svchost.exe
———- C:\Windows\system32\svchost.exe
———- C:\Windows\system32\svchost.exe
———- C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
———- C:\Windows\system32\TODDSrv.exe
———- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
———- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
———- C:\Windows\System32\svchost.exe
———- C:\Windows\system32\SearchIndexer.exe
———- C:\Windows\system32\taskeng.exe
———- C:\Windows\system32\Dwm.exe
———- C:\Windows\Explorer.EXE
———- C:\Program Files\Windows Defender\MSASCui.exe
———- C:\Windows\RtHDVCpl.exe
———- C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
———- C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
———- C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
———- C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
———- C:\Windows\system32\taskeng.exe
———- C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
———- C:\Program Files\Microsoft IntelliPoint\ipoint.exe
———- C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
———- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
———- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
———- C:\Program Files\iTunes\iTunesHelper.exe
———- C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe
———- C:\Windows\ehome\ehtray.exe
———- C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
———- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
———- C:\Program Files\Windows Media Player\wmpnscfg.exe
———- C:\Program Files\Synaptics\SynTP\SynToshiba.exe
———- C:\Program Files\Windows Media Player\wmpnetwk.exe
———- C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
———- C:\Program Files\iPod\bin\iPodService.exe
———- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
———- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
———- C:\Program Files\Internet Explorer\iexplore.exe
———- C:\Windows\system32\SearchProtocolHost.exe
———- C:\Windows\system32\SearchFilterHost.exe
———- C:\Windows\system32\DllHost.exe
———- C:\Users\Natalie\Desktop\Rooter.exe
———- C:\Windows\system32\cmd.exe
———- C:\Rooter$\RK.exe

———————-\\ Search..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.180,85.255.112.173
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.180,85.255.112.173
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.180,85.255.112.173
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{5F973031-C962-4AE0-B2C2-BA5B8E2E48C8}]
NameServer REG_SZ 85.255.112.180,85.255.112.173
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{8359E2C3-E176-45BF-8920-6014C45D6B46}]
NameServer REG_SZ 85.255.112.180,85.255.112.173
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\..\{5F973031-C962-4AE0-B2C2-BA5B8E2E48C8}]
NameServer REG_SZ 85.255.112.180,85.255.112.173
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\..\{8359E2C3-E176-45BF-8920-6014C45D6B46}]
NameServer REG_SZ 85.255.112.180,85.255.112.173
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{5F973031-C962-4AE0-B2C2-BA5B8E2E48C8}]
NameServer REG_SZ 85.255.112.180,85.255.112.173
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{8359E2C3-E176-45BF-8920-6014C45D6B46}]
NameServer REG_SZ 85.255.112.180,85.255.112.173
==> WAREOUT <==

———————-\\ ROOTKIT !!


———————-\\ Cracks & Keygens..

C:\Users\Natalie\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\THE SIMS 2 COMPLETE COLLECTION patched and cracked plus BONUS CONTENT!\thesims2completecollection.rar.bc!
C:\Users\Natalie\Desktop\AVG Anti-Virus v8.0.164 PRO+Keygen\avg_avwt_stf_en_8_164a1354.exe
C:\Users\Natalie\Desktop\AVG Anti-Virus v8.0.164 PRO+Keygen\Keygen.exe
C:\Users\Natalie\Music\AVG Anti-Virus v8.0.164 PRO+Keygen.rar
C:\Users\Natalie\Music\Microsoft Office Publisher 2007 Corporate Crack.zip
C:\Users\Natalie\Music\Limewire Downloads\Limewire Lime Wire Pro v.4.10.0.1 Cracked with Java Runtime Environment\Java Runtime Environment.exe
C:\Users\Natalie\Music\Limewire Downloads\Limewire Lime Wire Pro v.4.10.0.1 Cracked with Java Runtime Environment\LimeWireWin.exe
C:\Users\Natalie\WinRAR\KeyGen.txt
C:\Users\Natalie\WinRAR\RAR Password Cracker v4.11
C:\Users\Natalie\WinRAR\RAR Password Cracker v4.11\Readme.txt


1 - "C:\Rooter$\Rooter_1.txt" - 25/03/2009|19:17

———————-\\ Scan completed at 19:17
And this is OTList.txt

OTListIt logfile created on: 25/03/2009 19:21:12 - Run 1
OTListIt2 by OldTimer - Version 2.0.7.2 Folder = C:\Users\Natalie\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.87 Gb Total Physical Memory | 1.22 Gb Available Physical Memory | 65.27% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): c:\pagefile.sys 0 0;e:\pagefile.sys 4000 6000;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 5.69 Gb Free Space | 10.18% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 54.43 Gb Total Space | 34.84 Gb Free Space | 64.01% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: NATALIE-PC
Current User Name: Natalie
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
PRC - C:\Windows\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Windows\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Windows\system32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
PRC - C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
PRC - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\system32\TODDSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Utilities\KeNotify.exe ()
PRC - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE (ATI Technologies Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe (Motive Communications, Inc.)
PRC - C:\Windows\ehome\ehtray.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynToshiba.exe (Synaptics, Inc.)
PRC - C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Synaptics, Inc.)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Users\Natalie\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (AgereModemAudio [Auto | Running]) – C:\Windows\system32\agrsmsvc.exe (Agere Systems)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Ati External Event Utility [Auto | Running]) – C:\Windows\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (CFSvcs [Auto | Running]) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [Auto | Running]) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (hpqcxs08 [On_Demand | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc [Auto | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (KService [Auto | Running]) – C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (McciCMService [Auto | Running]) – C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
SRV - (Net Driver HPZ12 [Auto | Running]) – C:\Windows\system32\HPZinw12.dll (Hewlett-Packard)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Auto | Running]) – C:\Windows\system32\HPZipm12.dll (Hewlett-Packard)
SRV - (TNaviSrv [Auto | Running]) – C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv [Auto | Running]) – C:\Windows\system32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (TosCoSrv [Auto | Running]) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (TOSHIBA Bluetooth Service [Auto | Stopped]) – File not found
SRV - (UleadBurningHelper [Auto | Running]) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (WLSetupSvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Running]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (61883 [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\61883.sys (Microsoft Corporation)
DRV - (adp94xx [Disabled | Stopped]) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Disabled | Stopped]) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (AgereSoftModem [On_Demand | Running]) – C:\Windows\system32\DRIVERS\AGRSM.sys (Agere Systems)
DRV - (aic78xx [Disabled | Stopped]) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Disabled | Stopped]) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ApfiltrService [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (arc [Disabled | Stopped]) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Disabled | Stopped]) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (athr [On_Demand | Running]) – C:\Windows\system32\DRIVERS\athr.sys (Atheros Communications, Inc.)
DRV - (atikmdag [On_Demand | Running]) – C:\Windows\system32\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV - (Avc [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\avc.sys (Microsoft Corporation)
DRV - (BrFiltLo [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [Disabled | Stopped]) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (cmdide [Disabled | Stopped]) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (CplIR [Disabled | Stopped]) – C:\Windows\system32\DRIVERS\CplIR.SYS (COMPAL ELECTRONIC INC.)
DRV - (E1G60 [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (elxstor [Disabled | Stopped]) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\Windows\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HpCISSs [Disabled | Stopped]) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (iaStorV [Disabled | Stopped]) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (iirsp [Disabled | Stopped]) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (IntcAzAudAddService [On_Demand | Running]) – C:\Windows\system32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (iteatapi [Disabled | Stopped]) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Disabled | Stopped]) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (KR10I [Disabled | Stopped]) – C:\Windows\system32\drivers\kr10i.sys (TOSHIBA CORPORATION)
DRV - (KR10N [Disabled | Stopped]) – C:\Windows\system32\drivers\kr10n.sys (TOSHIBA CORPORATION)
DRV - (LPCFilter [Boot | Running]) – C:\Windows\system32\DRIVERS\LPCFilter.sys (COMPAL ELECTRONIC INC.)
DRV - (LSI_FC [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (megasas [Disabled | Stopped]) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Mraid35x [Disabled | Stopped]) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (MREMP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MSDV [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\msdv.sys (Microsoft Corporation)
DRV - (nfrd960 [Disabled | Stopped]) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (ntrigdigi [Disabled | Stopped]) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (nvraid [Disabled | Stopped]) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor [Disabled | Stopped]) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (ql2300 [Disabled | Stopped]) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Disabled | Stopped]) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (RTL8169 [On_Demand | Running]) – C:\Windows\system32\DRIVERS\Rtlh86.sys (Realtek Corporation )
DRV - (secdrv [Auto | Running]) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid2 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (SiSRaid4 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (sptd [Boot | Running]) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (Symc8xx [Disabled | Stopped]) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_hi [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (SynTP [On_Demand | Running]) – C:\Windows\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (tdcmdpst [On_Demand | Running]) – C:\Windows\system32\DRIVERS\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (tifm21 [On_Demand | Running]) – C:\Windows\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (tosrfec [Disabled | Stopped]) – C:\Windows\system32\DRIVERS\tosrfec.sys (TOSHIBA Corporation)
DRV - (tos_sps32 [Boot | Running]) – C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation)
DRV - (TVALZ [Boot | Running]) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (uliahci [Disabled | Stopped]) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\Windows\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (viaide [Disabled | Stopped]) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (vsmraid [Disabled | Stopped]) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://gooogle.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [btbb_McciTrayApp] "C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe" (Motive Communications, Inc.)
O4 - HKLM..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto (Interactive Digital Media)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [HWSetup] \HWSetup.exe hwSetUP File not found
O4 - HKLM..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RtHDVCpl] RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL (TOSHIBA)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup (TOSHIBA)
O4 - HKLM..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe (Toshiba)
O4 - HKLM..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE (TOSHIBA Corporation)
O4 - HKLM..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide (Microsoft Corporation)
O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: eBay.co.uk - Buy It Sell It Love It - {76577871-04EC-495E-A12B-91F7C3600AFA} - File not found
O9 - Extra Button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} - File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: PacificPoker4 - {94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} - C:\PROGRA~1\PACIFI~1\pacificpoker.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} http://ax.emsisoft.com/asquared.cab (a-squared Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} http://static.photobox.co.uk/sg/common/uploader_uni.cab (PB_Uploader Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.180,85.255.112.173
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{5F973031-C962-4AE0-B2C2-BA5B8E2E48C8}\\NameServer = 85.255.112.180,85.255.112.173
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{8359E2C3-E176-45BF-8920-6014C45D6B46}\\NameServer = 85.255.112.180,85.255.112.173
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\autoexec.bat () - [ NTFS ]
O33 - MountPoints2\{5ca9bde6-5d6d-11dc-9b3e-806e6f6e6963}\Shell\AutoRun\command - "" = F:\Setup.exe – File not found
O33 - MountPoints2\{5ca9bde6-5d6d-11dc-9b3e-806e6f6e6963}\Shell\BTHomeHub\command - "" = F:\Setup.exe – File not found
O33 - MountPoints2\{f3281409-1859-11dd-867f-001b383ed31f}\Shell - "" = AutoRun
O33 - MountPoints2\{f3281409-1859-11dd-867f-001b383ed31f}\Shell\AutoRun\command - "" = D:\Setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\Windows\*.tmp files]
[1 C:\Users\Natalie\Documents\*.tmp files]
[2 C:\Users\Natalie\Desktop\*.tmp files]
[2009/03/25 19:20:19 | 00,498,688 | —- | C] (OldTimer Tools) – C:\Users\Natalie\Desktop\OTListIt2.exe
[2009/03/25 19:16:48 | 00,000,000 | —D | C] – C:\Rooter$
[2009/03/25 19:16:43 | 00,267,612 | —- | C] () – C:\Users\Natalie\Desktop\Rooter.exe
[2009/03/25 17:12:56 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/03/25 17:12:56 | 00,000,823 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/25 17:12:54 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/03/25 17:12:52 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2009/03/25 17:12:12 | 02,876,728 | —- | C] (Malwarebytes Corporation ) – C:\Users\Natalie\Desktop\mbam-setup.exe
[2009/03/24 16:29:45 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/03/24 15:37:15 | 00,216,064 | —- | C] () – C:\Users\Natalie\Desktop\MuddybootsApplication_Form.doc
[2009/03/24 15:29:44 | 00,014,248 | —- | C] () – C:\Users\Natalie\Desktop\sign.jpg
[2009/03/24 14:05:36 | 00,001,879 | —- | C] () – C:\Users\Natalie\Desktop\HijackThis.lnk
[2009/03/24 14:05:34 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/24 14:05:09 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Users\Natalie\Desktop\HJTInstall.exe
[2009/03/24 13:50:02 | 00,010,520 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll.install_backup
[2009/03/24 13:49:36 | 00,000,000 | —D | C] – C:\Program Files\AVG
[2009/03/24 13:11:48 | 00,000,000 | —D | C] – C:\Users\Natalie\Desktop\AVG Anti-Virus v8.0.164 PRO+Keygen
[2009/03/23 18:13:16 | 00,000,000 | —D | C] – C:\Windows\System32\Service
[2009/03/23 10:34:58 | 00,216,064 | —- | C] () – C:\Users\Natalie\Desktop\MuddybootsApplication_FormProtected.doc
[2009/03/22 10:55:52 | 00,260,503 | —- | C] () – C:\Users\Natalie\Desktop\9c7177069efef10f45d82a95dda04858.jpg
[2009/03/22 10:53:37 | 00,041,325 | —- | C] () – C:\Users\Natalie\Desktop\54%20Sweet%20Stitches%20Tattoo.jpg
[2009/03/22 10:53:13 | 00,016,216 | —- | C] () – C:\Users\Natalie\Desktop\tattoo_illusion.jpg
[2009/03/22 10:47:05 | 00,029,629 | —- | C] () – C:\Users\Natalie\Desktop\butterfly_tattoo.jpg
[2009/03/21 18:34:41 | 00,244,586 | —- | C] () – C:\Users\Natalie\Desktop\view.pdf
[2009/03/21 18:31:56 | 00,025,497 | —- | C] () – C:\Users\Natalie\Desktop\Postgraduate%281%29.pdf
[2009/03/21 18:22:41 | 00,030,749 | —- | C] () – C:\Users\Natalie\Desktop\MA%20Application%20Form%202009-2010.pdf
[2009/03/21 16:26:55 | 00,028,160 | —- | C] () – C:\Users\Natalie\Documents\Personal Statement 3choice.doc
[2009/03/21 12:26:31 | 00,028,160 | —- | C] () – C:\Users\Natalie\Documents\Personal Statement (Not finished).doc
[2009/03/21 12:23:18 | 00,027,136 | —- | C] () – C:\Users\Natalie\Documents\Research Degree.doc
[2009/03/20 21:53:23 | 00,028,160 | —- | C] () – C:\Users\Natalie\Desktop\PERSONAL STATE MENT-DIGITAL THEATRE DESIGN.doc
[2009/03/20 21:42:36 | 00,011,978 | —- | C] () – C:\Users\Natalie\Desktop\PERSONAL STATE MENT.docx
[2009/03/20 17:18:18 | 00,000,000 | —D | C] – C:\Users\Public\Desktop\TrendMicro_TIS_17.00_en-US_32-bit
[2009/03/20 17:01:45 | 66,644,872 | —- | C] (Trend Micro Inc.) – C:\Users\Public\Desktop\TrendMicro_TIS_17.00_en-US_32-bit.exe
[2009/03/20 16:51:55 | 00,000,000 | —D | C] – C:\Windows\Sun
[2009/03/19 20:16:42 | 00,244,586 | —- | C] () – C:\Users\Natalie\Desktop\APPLICATION.pdf
[2009/03/19 10:03:36 | 00,028,672 | —- | C] () – C:\Users\Natalie\Desktop\MARKET.doc
[2009/03/18 09:21:16 | 00,000,000 | —D | C] – C:\Users\Natalie\AppData\Local\Mozilla
[2009/03/17 13:44:42 | 00,078,487 | —- | C] () – C:\Users\Natalie\Documents\fashion presentation.pptx
[2009/03/12 19:28:06 | 00,000,000 | —D | C] – C:\Program Files\Alwil Software
[2009/03/12 12:05:47 | 00,015,155 | —- | C] () – C:\Users\Natalie\Documents\Fashion Presentation.docx
[2009/03/11 18:34:18 | 62,270,256 | —- | C] (AVG Technologies) – C:\Users\Natalie\Desktop\avg_free.exe
[2009/03/11 17:49:59 | 00,000,000 | R-SD | C] – C:\Users\Natalie\Documents\My Stationery
[2009/03/11 09:44:54 | 00,000,000 | —D | C] – C:\Program Files\Conduit
[2009/03/11 09:43:53 | 00,000,000 | —D | C] – C:\RECYCLER
[2009/03/11 09:12:11 | 00,268,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\schannel.dll
[2009/03/11 09:12:06 | 02,033,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2009/03/10 18:20:18 | 00,000,000 | —D | C] – C:\Users\Natalie\AppData\Roaming\Motive
[2009/03/07 16:56:23 | 00,097,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2009/03/07 16:56:22 | 00,105,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/03/07 16:56:21 | 00,622,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2009/03/07 16:56:21 | 00,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2009/03/07 16:56:21 | 00,037,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2009/03/07 16:56:21 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2009/03/07 16:56:19 | 00,781,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2009/03/07 16:56:16 | 00,326,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2009/03/07 16:47:02 | 00,096,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfshim.dll
[2009/03/07 16:46:58 | 00,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscoree.dll
[2009/03/07 16:46:56 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2009/03/07 16:46:37 | 00,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2009/03/07 16:46:32 | 00,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2009/03/07 16:44:23 | 10,622,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmp.dll
[2009/03/07 16:44:22 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwmp.dll
[2009/03/07 16:44:22 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdxm.ocx
[2009/03/07 16:44:22 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxmasf.dll
[2009/03/07 16:44:21 | 08,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2009/03/05 19:26:46 | 00,401,920 | —- | C] () – C:\Users\Natalie\Desktop\THEATRE SHOW REEL.MSWMM
[2009/03/05 18:35:10 | 00,057,856 | —- | C] () – C:\Users\Natalie\Desktop\THEATRE DESIGN CV.doc
[2009/03/03 23:15:43 | 00,000,000 | —D | C] – C:\Users\Natalie\Desktop\101KC743
[2009/03/03 22:29:04 | 00,000,000 | —D | C] – C:\Windows\BTV.0001
[2009/03/03 22:19:10 | 00,000,000 | —D | C] – C:\Users\Natalie\Desktop\gentlemens night
[2009/03/03 18:14:20 | 00,000,000 | —D | C] – C:\ProgramData\Yahoo! Companion
[2009/03/03 18:11:09 | 00,000,000 | —D | C] – C:\Program Files\Yahoo!
[2009/03/03 18:10:35 | 00,095,616 | —- | C] (British Telecommunications Plc) – C:\Windows\System32\BTEmailConfig.dll
[2009/03/03 18:10:28 | 00,000,000 | —D | C] – C:\Windows\BTV.0000
[2009/03/03 18:10:23 | 00,001,232 | —- | C] () – C:\Users\Natalie\Desktop\BT Broadband Desktop Help.lnk
[2009/03/03 18:08:40 | 00,000,000 | —D | C] – C:\ProgramData\Motive
[2009/03/03 18:08:29 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Motive
[2009/03/03 18:08:22 | 00,000,000 | —D | C] – C:\Program Files\BT Broadband Desktop Help
[2009/03/03 18:08:20 | 00,001,837 | —- | C] () – C:\Users\Public\Desktop\BT Yahoo! Online.LNK
[2009/03/03 18:08:19 | 00,001,959 | —- | C] () – C:\Users\Public\Desktop\BT Broadband Life.LNK
[2009/03/03 18:08:17 | 00,000,000 | —D | C] – C:\Program Files\BTHomeHub
[2009/02/24 21:21:14 | 00,061,952 | —- | C] () – C:\Users\Natalie\Desktop\Natalie THEATRE CV.doc

========== Files - Modified Within 30 Days ==========

[1 C:\Windows\*.tmp files]
[1 C:\Users\Natalie\Documents\*.tmp files]
[2 C:\Users\Natalie\Desktop\*.tmp files]
[2009/03/25 19:20:27 | 00,498,688 | —- | M] (OldTimer Tools) – C:\Users\Natalie\Desktop\OTListIt2.exe
[2009/03/25 19:16:48 | 00,267,612 | —- | M] () – C:\Users\Natalie\Desktop\Rooter.exe
[2009/03/25 19:11:45 | 00,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/03/25 19:11:45 | 00,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/03/25 19:11:41 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/03/25 19:11:35 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/03/25 19:11:30 | 20,112,17920 | -HS- | M] () – C:\hiberfil.sys
[2009/03/25 19:10:22 | 02,184,838 | -H– | M] () – C:\Users\Natalie\AppData\Local\IconCache.db
[2009/03/25 17:12:56 | 00,000,823 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/25 17:12:19 | 02,876,728 | —- | M] (Malwarebytes Corporation ) – C:\Users\Natalie\Desktop\mbam-setup.exe
[2009/03/25 15:13:22 | 00,000,422 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{65A6F496-72F7-4965-973E-EC5A7717B4FC}.job
[2009/03/24 15:37:18 | 00,216,064 | —- | M] () – C:\Users\Natalie\Desktop\MuddybootsApplication_Form.doc
[2009/03/24 15:30:44 | 00,216,064 | —- | M] () – C:\Users\Natalie\Desktop\MuddybootsApplication_FormProtected.doc
[2009/03/24 15:29:44 | 00,014,248 | —- | M] () – C:\Users\Natalie\Desktop\sign.jpg
[2009/03/24 14:05:36 | 00,001,879 | —- | M] () – C:\Users\Natalie\Desktop\HijackThis.lnk
[2009/03/24 14:05:28 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Users\Natalie\Desktop\HJTInstall.exe
[2009/03/24 13:50:02 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll.install_backup
[2009/03/23 22:19:10 | 00,002,595 | —- | M] () – C:\Users\Natalie\Desktop\PowerPoint 2007.lnk
[2009/03/22 10:55:42 | 00,260,503 | —- | M] () – C:\Users\Natalie\Desktop\9c7177069efef10f45d82a95dda04858.jpg
[2009/03/22 10:53:27 | 00,041,325 | —- | M] () – C:\Users\Natalie\Desktop\54%20Sweet%20Stitches%20Tattoo.jpg
[2009/03/22 10:53:00 | 00,016,216 | —- | M] () – C:\Users\Natalie\Desktop\tattoo_illusion.jpg
[2009/03/22 10:46:52 | 00,029,629 | —- | M] () – C:\Users\Natalie\Desktop\butterfly_tattoo.jpg
[2009/03/21 18:34:41 | 00,244,586 | —- | M] () – C:\Users\Natalie\Desktop\view.pdf
[2009/03/21 18:31:56 | 00,025,497 | —- | M] () – C:\Users\Natalie\Desktop\Postgraduate%281%29.pdf
[2009/03/21 18:22:41 | 00,030,749 | —- | M] () – C:\Users\Natalie\Desktop\MA%20Application%20Form%202009-2010.pdf
[2009/03/21 16:26:57 | 00,028,160 | —- | M] () – C:\Users\Natalie\Documents\Personal Statement 3choice.doc
[2009/03/21 16:26:26 | 00,028,160 | —- | M] () – C:\Users\Natalie\Documents\Personal Statement (Not finished).doc
[2009/03/21 15:39:14 | 15,969,3064 | —- | M] () – C:\Windows\MEMORY.DMP
[2009/03/21 12:23:20 | 00,027,136 | —- | M] () – C:\Users\Natalie\Documents\Research Degree.doc
[2009/03/21 12:04:00 | 00,002,627 | —- | M] () – C:\Users\Natalie\Desktop\Microsoft Office Word 2007.lnk
[2009/03/20 21:53:24 | 00,028,160 | —- | M] () – C:\Users\Natalie\Desktop\PERSONAL STATE MENT-DIGITAL THEATRE DESIGN.doc
[2009/03/20 21:53:01 | 00,011,978 | —- | M] () – C:\Users\Natalie\Desktop\PERSONAL STATE MENT.docx
[2009/03/20 17:17:58 | 66,644,872 | —- | M] (Trend Micro Inc.) – C:\Users\Public\Desktop\TrendMicro_TIS_17.00_en-US_32-bit.exe
[2009/03/19 20:16:42 | 00,244,586 | —- | M] () – C:\Users\Natalie\Desktop\APPLICATION.pdf
[2009/03/19 10:14:07 | 00,028,672 | —- | M] () – C:\Users\Natalie\Desktop\MARKET.doc
[2009/03/17 19:30:46 | 00,078,487 | —- | M] () – C:\Users\Natalie\Documents\fashion presentation.pptx
[2009/03/12 19:28:37 | 00,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2009/03/12 19:18:44 | 00,015,155 | —- | M] () – C:\Users\Natalie\Documents\Fashion Presentation.docx
[2009/03/11 18:34:37 | 62,270,256 | —- | M] (AVG Technologies) – C:\Users\Natalie\Desktop\avg_free.exe
[2009/03/11 11:36:10 | 00,405,016 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2009/03/07 12:03:25 | 00,011,264 | —- | M] () – C:\Users\Natalie\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/05 19:26:47 | 00,401,920 | —- | M] () – C:\Users\Natalie\Desktop\THEATRE SHOW REEL.MSWMM
[2009/03/05 18:35:11 | 00,057,856 | —- | M] () – C:\Users\Natalie\Desktop\THEATRE DESIGN CV.doc
[2009/03/03 22:28:57 | 00,001,959 | —- | M] () – C:\Users\Public\Desktop\BT Broadband Life.LNK
[2009/03/03 22:28:57 | 00,001,837 | —- | M] () – C:\Users\Public\Desktop\BT Yahoo! Online.LNK
[2009/03/03 18:10:23 | 00,001,232 | —- | M] () – C:\Users\Natalie\Desktop\BT Broadband Desktop Help.lnk
[2009/02/24 21:21:15 | 00,061,952 | —- | M] () – C:\Users\Natalie\Desktop\Natalie THEATRE CV.doc

========== LOP Check ==========

[2008/01/19 23:57:59 | 00,000,258 | —- | M] () – C:\Windows\Tasks\Check Updates for Windows Live Toolbar.job
[2009/03/25 19:11:41 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/03/25 19:10:31 | 00,032,622 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2009/03/25 15:13:22 | 00,000,422 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{65A6F496-72F7-4965-973E-EC5A7717B4FC}.job

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 166 bytes -> C:\ProgramData\TEMP:ECF54A0E
< End of report >
And Extras.txt

OTListIt Extras logfile created on: 25/03/2009 19:21:12 - Run 1
OTListIt2 by OldTimer - Version 2.0.7.2 Folder = C:\Users\Natalie\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.87 Gb Total Physical Memory | 1.22 Gb Available Physical Memory | 65.27% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): c:\pagefile.sys 0 0;e:\pagefile.sys 4000 6000;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 5.69 Gb Free Space | 10.18% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 54.43 Gb Total Space | 34.84 Gb Free Space | 64.01% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: NATALIE-PC
Current User Name: Natalie
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" =
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"DisableNotifications" = 0
"EnableFirewall" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{003B5184-F3DF-AF76-CB17-D35B7BB46B81}" = CCC Help Japanese
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{0E4BC542-9CFD-4E97-B586-9F1E5516E7B9}" = Microsoft IntelliPoint 6.1
"{0F4F4815-76AD-4B26-8763-72F3344041C2}" = TOSHIBA Manuals
"{0F6932CF-E642-5A7A-8194-3F7443188287}" = CCC Help Turkish
"{103A43D9-9ED8-E78D-7BF1-E536DFE6FC9F}" = Catalyst Control Center Localization Greek
"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"{12887AF2-AE16-34CC-E85C-637DF6911C8C}" = Catalyst Control Center Localization Turkish
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{13614186-B0A0-AA21-F75A-2097F9167DB8}" = CCC Help Portuguese
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{177B615E-47B1-C1C4-6F3B-7D6FEB8D4564}" = CCC Help Thai
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{184E7118-0295-43C4-B72C-1D54AA75AAF7}" = Windows Live Mail
"{1AE3E621-E0C0-4aa1-B10B-B3E353A8D110}" = c3100_Help
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{2290A680-4083-410A-ADCC-7092C67FC052}" = Toshiba Online Product Information
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26210745-925C-8AE4-F3B9-5FA737A1F6F2}" = CCC Help Russian
"{2768CDA5-57DA-59D4-884F-A0F8A5B36D3E}" = CCC Help Finnish
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{282E5AB2-8E47-4571-B6FA-6B512555B557}" = HP Photosmart.All-In-One Driver Software 8.0 .A
"{29DC966A-DA3E-3ED4-68E7-6D3D9A055B42}" = Catalyst Control Center Localization Korean
"{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}" = Windows Live Photo Gallery
"{2E7A9DDC-E062-0074-08AB-DE7D1B431F75}" = Catalyst Control Center Localization Chinese Traditional
"{2FAE3800-CC47-C556-C57F-A91851BF7854}" = CCC Help French
"{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{33824DAC-3F98-0BB6-56D5-7DE1A3CCC068}" = Catalyst Control Center Localization German
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{3621A2DF-0870-FE7E-674F-1DBCB18C5D22}" = ccc-utility
"{3F11CE8A-388B-0D3A-DF6F-061F23A13D26}" = CCC Help Korean
"{4160DC5B-4C56-D0C3-C5FD-F5BDAD3C882B}" = ATI Catalyst Install Manager
"{41DD15BE-811D-7DEF-19A9-30AF18F75EFF}" = Catalyst Control Center Localization Thai
"{4377F918-E6C9-4ECA-A7F5-754B310B7ED8}" = Sid Meier's Civilization 4
"{44F5A980-8A6B-4aca-8D85-EFCE5D67D379}" = AIO_CDA_ProductContext
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"{52F368DE-06BD-E116-9233-D1DE207BDFE6}" = CCC Help Dutch
"{53BABC75-1DC1-479B-224B-1EB9E18A799B}" = CCC Help German
"{56797214-1A4C-052E-1ECE-B00308BF3362}" = CCC Help Chinese Standard
"{572D71E9-5102-74B3-5D22-DEDF911F7FE5}" = CCC Help Italian
"{582D2A53-F426-4C5E-A2E6-43C1AB36B907}" = Safari
"{5980B928-1C95-4B3E-957B-B02D8147FF9E}" = Desktop SMS
"{5BA0C9F0-3B01-91A3-6922-4DCF943D9CBE}" = CCC Help English
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{6080CE3C-2CB3-2FA3-1CE2-3350B06664BC}" = CCC Help Swedish
"{611E35B8-7F46-DDBB-CC4F-FAAED6C054FF}" = Catalyst Control Center Localization Spanish
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{678F1F2D-F214-08D4-67FB-AC04316C4940}" = ccc-core-static
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A0B868C-89BE-ACF1-8C0A-CC88878A9E46}" = Catalyst Control Center Localization Russian
"{6C4734CF-A10C-DFF4-5565-457F33849862}" = Catalyst Control Center Localization Swedish
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6DECCD60-782D-7B14-22DE-FB8D6EA46433}" = CCC Help Polish
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{715044AC-B95E-4CD0-9B0C-CEDDB422F93B}" = CCC Help Czech
"{724A8BEC-B350-1C76-C580-959AEA487108}" = Catalyst Control Center Localization Japanese
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}" = TOSHIBA ConfigFree
"{7994AA46-4BA6-4349-1606-1DF4148CE05B}" = CCC Help Hungarian
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{7AFBAC39-F6A8-9F8D-6A6D-F134F7E34B6E}" = Catalyst Control Center Localization Danish
"{845D19A7-0BBF-12DF-87CF-F5D468930EA6}" = Catalyst Control Center Localization Czech
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90BF970B-3335-CFD5-711C-9FE0310A97C0}" = CCC Help Greek
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{91130409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Small Business
"{9176251A-4CC1-4DDB-B343-B487195EB397}" = Windows Live Writer
"{926593ED-3962-4630-7CE3-34FF1B4ACCF3}" = Catalyst Control Center Localization Finnish
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{9EB0D4D4-87A5-52F5-C59C-159F81BED0E6}" = Catalyst Control Center Graphics Previews Vista
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{A6D4234C-CB02-4048-AC3E-AD09404FA35A}" = Emdedded IR Driver
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A91383E9-0311-DB40-6AF6-3F9E80F83E84}" = Catalyst Control Center Localization Portuguese
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB61E316-F10B-43eb-B47F-42095835F9CC}" = C3100
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{AF1C9345-B53D-4110-BFBF-A0DD83AEAB83}" = AIO_CDA_Software
"{B1211E68-4DA2-7942-BE75-14272A8C1EA9}" = Catalyst Control Center Localization Dutch
"{B1F8FA80-EFA5-EC12-AD36-F5266EF90B61}" = CCC Help Danish
"{B4369E44-8703-E769-A711-40EE5000AC2C}" = Catalyst Control Center Core Implementation
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B7DE7B5E-4A2B-B709-E133-EC74C81E654A}" = Catalyst Control Center Graphics Full New
"{B87A3B9F-7632-E053-2148-8EDD1A787B78}" = Catalyst Control Center Localization Chinese Standard
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C7EA6173-A2B8-D45E-A0EE-74F8D2C58D30}" = Catalyst Control Center Localization Hungarian
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}" = Sid Meier's Civilization 4
"{D1C3920F-1DC3-A2FA-BF5E-7497B5EF072E}" = Catalyst Control Center Localization Norwegian
"{D466F3D9-510C-4729-B7D4-2E70490E4CDF}" = BBC iPlayer Download Manager
"{D5A145FC-D00C-4F1A-9119-EB4D9D659750}" = Windows Live Toolbar
"{D95AAA04-9BEF-54B3-CD70-348AC1155DAB}" = Catalyst Control Center Graphics Full Existing
"{D9C7C58C-AC51-EDBF-CF22-E4E1B93ED50D}" = Skins
"{DA898F5C-4C85-4CF4-825B-E05D07DC39DD}" = BT Email Configuration Tool
"{DB780B85-B4B5-4864-A49C-9B706B169C93}" = TIPCI
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{DDC4619D-1DC8-C2A7-4968-45586F237131}" = CCC Help Norwegian
"{E015B7D9-01AD-FE29-052A-489F4F29ED7F}" = Catalyst Control Center Graphics Light
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E7511B20-2857-3F50-1B84-F0F32C519FE1}" = CCC Help Chinese Traditional
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB5BE9DE-6025-6227-0C25-AE5C852EC479}" = Catalyst Control Center Localization Polish
"{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}" = TOSHIBA SD Memory Utilities
"{EC28331A-FF2B-6D66-D8A0-32C706AEA120}" = CCC Help Spanish
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{F2B27034-6059-0549-F01A-4BD9865521B1}" = Catalyst Control Center Localization French
"{F958CA02-BB40-4007-894B-258729456EE4}" = QuickTime
"{FBE6B550-A93E-AA46-1DBB-421EC319E2DA}" = Catalyst Control Center Localization Italian
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"ATI Uninstaller" = ATI Uninstaller
"BBC iPlayer Download Manager" = BBC iPlayer Download Manager
"BT Broadband Desktop Help" = BT Broadband Desktop Help
"BTHomeHub" = BTHomeHub
"CleanMyPC - Registry Cleaner_is1" = CleanMyPC - Registry Cleaner
"Easy Desktop Publisher" = Easy Desktop Publisher
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"InstallShield_{A6D4234C-CB02-4048-AC3E-AD09404FA35A}" = Emdedded IR Driver
"InstallShield_{DB780B85-B4B5-4864-A49C-9B706B169C93}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"LimeWire" = LimeWire PRO 4.10.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"myphotobook" = myphotobook 3.1
"Shop for HP Supplies" = Shop for HP Supplies
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Windows Live Toolbar" = Windows Live Toolbar
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinRAR archiver" = WinRAR archiver
"World of Warcraft" = World of Warcraft
"Yahoo! Applications" = BT Yahoo! Applications
"Yahoo! Toolbar" = Yahoo! Toolbar
"Zoo Tycoon 1.0" = Microsoft Zoo Tycoon

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 14/10/2008 07:28:38 | Computer Name = Natalie-PC | Source = Application Error | ID = 1000
Description = Faulting application ccApp.exe, version 106.2.0.21, time stamp 0x45a467ef,
faulting module NSCWSCR2.DLL, version 2007.4.0.2, time stamp 0x468eb2ed, exception
code 0xc0000005, fault offset 0x0001ca18, process id 0x71c, application start time
0x01c92defd04b4106.

Error - 14/10/2008 15:57:57 | Computer Name = Natalie-PC | Source = Application Error | ID = 1000
Description = Faulting application ccApp.exe, version 106.2.0.21, time stamp 0x45a467ef,
faulting module NSCWSCR2.DLL, version 2007.4.0.2, time stamp 0x468eb2ed, exception
code 0xc0000005, fault offset 0x0001ca18, process id 0x2cc, application start time
0x01c92e370b43b042.

Error - 14/10/2008 17:30:31 | Computer Name = Natalie-PC | Source = EventSystem | ID = 4621
Description =

Error - 15/10/2008 06:04:35 | Computer Name = Natalie-PC | Source = Application Error | ID = 1000
Description = Faulting application ccApp.exe, version 106.2.0.21, time stamp 0x45a467ef,
faulting module NSCWSCR2.DLL, version 2007.4.0.2, time stamp 0x468eb2ed, exception
code 0xc0000005, fault offset 0x0001ca18, process id 0xc8c, application start time
0x01c92ead32449994.

Error - 15/10/2008 13:39:09 | Computer Name = Natalie-PC | Source = Application Error | ID = 1000
Description = Faulting application ccApp.exe, version 106.2.0.21, time stamp 0x45a467ef,
faulting module NSCWSCR2.DLL, version 2007.4.0.2, time stamp 0x468eb2ed, exception
code 0xc0000005, fault offset 0x0001ca18, process id 0xd34, application start time
0x01c92eecca8ffb37.

Error - 15/10/2008 17:03:42 | Computer Name = Natalie-PC | Source = EventSystem | ID = 4621
Description =

Error - 15/10/2008 17:27:10 | Computer Name = Natalie-PC | Source = Application Error | ID = 1000
Description = Faulting application ccApp.exe, version 106.2.0.21, time stamp 0x45a467ef,
faulting module NSCWSCR2.DLL, version 2007.4.0.2, time stamp 0x468eb2ed, exception
code 0xc0000005, fault offset 0x0001ca18, process id 0xf4c, application start time
0x01c92f0cab166bdb.

Error - 15/10/2008 18:18:54 | Computer Name = Natalie-PC | Source = EventSystem | ID = 4621
Description =

Error - 16/10/2008 01:48:20 | Computer Name = Natalie-PC | Source = Application Error | ID = 1000
Description = Faulting application ccApp.exe, version 106.2.0.21, time stamp 0x45a467ef,
faulting module NSCWSCR2.DLL, version 2007.4.0.2, time stamp 0x468eb2ed, exception
code 0xc0000005, fault offset 0x0001ca18, process id 0x960, application start time
0x01c92f528ecf84e7.

Error - 16/10/2008 02:13:02 | Computer Name = Natalie-PC | Source = Application Error | ID = 1000
Description = Faulting application ccApp.exe, version 106.2.0.21, time stamp 0x45a467ef,
faulting module NSCWSCR2.DLL, version 2007.4.0.2, time stamp 0x468eb2ed, exception
code 0xc0000005, fault offset 0x0001ca18, process id 0xf20, application start time
0x01c92f55faaccd7b.

[ Media Center Events ]
Error - 23/09/2007 10:06:32 | Computer Name = Natalie-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 25/05/2008 10:28:25 | Computer Name = Natalie-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

[ OSession Events ]
Error - 11/02/2008 21:12:41 | Computer Name = Natalie-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
lasted 10570 seconds with 9240 seconds of active time. This session ended with
a crash.

Error - 13/06/2008 18:45:33 | Computer Name = Natalie-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 1945
seconds with 660 seconds of active time. This session ended with a crash.

Error - 13/06/2008 19:12:20 | Computer Name = Natalie-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 1101
seconds with 120 seconds of active time. This session ended with a crash.

Error - 22/09/2008 18:07:45 | Computer Name = Natalie-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6300.5000, Microsoft Office Version: 12.0.6215.1000. This session
lasted 283 seconds with 120 seconds of active time. This session ended with a crash.

Error - 22/09/2008 18:14:50 | Computer Name = Natalie-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6300.5000, Microsoft Office Version: 12.0.6215.1000. This session
lasted 225 seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 25/03/2009 11:10:10 | Computer Name = Natalie-PC | Source = HTTP | ID = 15016
Description =

Error - 25/03/2009 11:11:42 | Computer Name = Natalie-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 25/03/2009 11:11:42 | Computer Name = Natalie-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 25/03/2009 15:06:46 | Computer Name = Natalie-PC | Source = HTTP | ID = 15016
Description =

Error - 25/03/2009 15:08:18 | Computer Name = Natalie-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 25/03/2009 15:08:18 | Computer Name = Natalie-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 25/03/2009 15:10:25 | Computer Name = Natalie-PC | Source = DCOM | ID = 10010
Description =

Error - 25/03/2009 15:11:42 | Computer Name = Natalie-PC | Source = HTTP | ID = 15016
Description =

Error - 25/03/2009 15:13:12 | Computer Name = Natalie-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 25/03/2009 15:13:12 | Computer Name = Natalie-PC | Source = Service Control Manager | ID = 7000
Description =


< End of report >
First, before we fix anything, I need to advise you of something. This site does not support the use of cracks, keygens, or P2P use. Before we move forward I need you to remove those items, and uninstall Limewire. If you're not okay with this that's your choice. But if you want our help, this is needed. By the way, that is most likely how you were infected in the first place.

Using Add or Remove Programs, uninstall Limewire.

Next,
Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :processes
    explorer.exe
    
    :files
    C:\Users\Natalie\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\THE SIMS 2 COMPLETE COLLECTION patched and cracked plus BONUS CONTENT!
    C:\Users\Natalie\Desktop\AVG Anti-Virus v8.0.164 PRO+Keygen\avg_avwt_stf_en_8_164a1354.exe
    C:\Users\Natalie\Desktop\AVG Anti-Virus v8.0.164 PRO+Keygen\Keygen.exe
    C:\Users\Natalie\Music\AVG Anti-Virus v8.0.164 PRO+Keygen.rar
    C:\Users\Natalie\Music\Microsoft Office Publisher 2007 Corporate Crack.zip
    C:\Users\Natalie\Music\Limewire Downloads
    C:\Users\Natalie\WinRAR\KeyGen.txt
    C:\Users\Natalie\WinRAR\RAR Password Cracker v4.11
    
    :commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

We are going to use HJT to create a list of your currently installed programs.1. Open HijackThis and click on the Config… button in the "Other stuff" section (lower right hand corner).
2. Click on the Misc Tools button.
3. Click on the Open Uninstall Manager… button.
4. Click on the Save list… button.
5. Save the file uninstall_list.txt to a convinient location. This should open Notepad with the list.
6. Please Copy and Paste the list into your next reply.
KK heres Uninstall_list.txt 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 32 Bit HP CIO Components Installer Activation Assistant for the 2007 Microsoft Office suites Adobe Flash Player 10 ActiveX Adobe Photoshop 7.0 Adobe Reader 8.1.3 Adobe Shockwave Player 11 ALPS Touch Pad Driver Apple Mobile Device Support Apple Software Update Atheros Driver Installation Program ATI Uninstaller BBC iPlayer Download Manager Bluetooth Stack for Windows by Toshiba Bonjour BT Broadband Desktop Help BT Email Configuration Tool BT Yahoo! Applications BTHomeHub CD/DVD Drive Acoustic Silencer Desktop SMS DVD MovieFactory for TOSHIBA Easy Desktop Publisher Emdedded IR Driver Google Earth Google Toolbar for Internet Explorer Google Toolbar for Internet Explorer Highlight Viewer (Windows Live Toolbar) HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Customer Participation Program 8.0 HP Imaging Device Functions 8.0 HP OCR Software 8.0 HP Photosmart Essential HP Photosmart.All-In-One Driver Software 8.0 .A HP Solution Center 8.0 HP Update iTunes Java™ SE Runtime Environment 6 Malwarebytes' Anti-Malware Map Button (Windows Live Toolbar) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 Microsoft Office Excel MUI (English) 2007 Microsoft Office Home and Student 2007 Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Office XP Small Business Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 Redistributable Microsoft Works Microsoft Zoo Tycoon MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB941833) MSXML 4.0 SP2 (KB954430) myphotobook 3.1 QuickTime Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista Realtek High Definition Audio Driver Safari Security Update for 2007 Microsoft Office System (KB951550) Security Update for 2007 Microsoft Office System (KB951944) Security Update for 2007 Microsoft Office System (KB958439) Security Update for CAPICOM (KB931906) Security Update for CAPICOM (KB931906) Security Update for Microsoft Office Excel 2007 (KB958437) Security Update for Microsoft Office OneNote 2007 (KB950130) Security Update for Microsoft Office PowerPoint 2007 (KB951338) Security Update for Microsoft Office system 2007 (KB954326) Security Update for Microsoft Office system 2007 (KB956828) Security Update for Microsoft Office Word 2007 (KB956358) Security Update for Visio 2007 (KB947590) Security Update for Windows Media Encoder (KB954156) Shop for HP Supplies Sid Meier's Civilization 4 Smart Menus (Windows Live Toolbar) Synaptics Pointing Device Driver Texas Instruments PCIxx21/x515/xx12 drivers. TOSHIBA Assist TOSHIBA ConfigFree TOSHIBA Disc Creator TOSHIBA DVD PLAYER TOSHIBA Extended Tiles for Windows Mobility Center TOSHIBA Flash Cards Support Utility TOSHIBA Hardware Setup TOSHIBA Manuals Toshiba Online Product Information TOSHIBA SD Memory Utilities TOSHIBA Software Modem TOSHIBA Supervisor Password TOSHIBA Value Added Package Update for Microsoft Office 2007 Help for Common Features (KB957244) Update for Microsoft Office Excel 2007 Help (KB957242) Update for Microsoft Office OneNote 2007 Help (KB957245) Update for Microsoft Office PowerPoint 2007 Help (KB957247) Update for Microsoft Office Word 2007 Help (KB957252) Update for Microsoft Script Editor Help (KB957253) Update for Office 2007 (KB946691) Windows Live Favorites for Windows Live Toolbar Windows Live installer Windows Live Mail Windows Live Messenger Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Toolbar Windows Live Toolbar Windows Live Toolbar Extension (Windows Live Toolbar) Windows Live Writer Windows Media Encoder 9 Series Windows Media Encoder 9 Series WinRAR archiver World of Warcraft
Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply. Please also post an updated HijackThis log and let me know how it's running.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
KK heres the Combo fix log

ComboFix 09-03-25.02 - Natalie 2009-03-26 8:36:51.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1917.1061 [GMT 0:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-9-3-75-100017650-100004608-100028882-1948.com
c:\users\Natalie\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1170.tmp
c:\users\Natalie\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccBD6D.tmp
c:\users\Natalie\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE929.tmp
c:\users\Natalie\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccEE1.tmp
c:\users\Natalie\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccFB53.tmp
c:\users\Natalie\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccFEA.tmp
c:\users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Download programs.url
c:\users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games.url
c:\users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Translator.url
c:\users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Videos.url
c:\users\Natalie\Desktop\Games.url
c:\users\Natalie\Desktop\Videos.url
c:\users\Natalie\FAVORI~1\Download programs.url
c:\users\Natalie\FAVORI~1\Games.url
c:\users\Natalie\FAVORI~1\Translator.url
c:\users\Natalie\FAVORI~1\Videos.url
c:\users\Natalie\Favorites\Download programs.url
c:\users\Natalie\Favorites\Games.url
c:\users\Natalie\Favorites\Translator.url
c:\users\Natalie\Favorites\Videos.url
c:\windows\system32\drivers\gaopdxcvowtfqvcepnnlspxriwdvebmmnjteux.sys
c:\windows\system32\gaopdxjhxfqvdtxouoiqjpghkiybwxwdnmqpig.dll
e:\recycler\S-9-3-75-100017650-100004608-100028882-1948.com

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_gaopdxserv.sys


((((((((((((((((((((((((( Files Created from 2009-02-26 to 2009-03-26 )))))))))))))))))))))))))))))))
.

2009-03-25 19:16 . 2009-03-25 20:07 d——– C:\Rooter$
2009-03-25 17:12 . 2009-03-25 17:12 d——– c:\users\All Users\Malwarebytes
2009-03-25 17:12 . 2009-03-25 17:12 d——– c:\programdata\Malwarebytes
2009-03-25 17:12 . 2009-02-11 10:19 38,496 –a—— c:\windows\System32\drivers\mbamswissarmy.sys
2009-03-25 17:12 . 2009-02-11 10:19 15,504 –a—— c:\windows\System32\drivers\mbam.sys
2009-03-24 16:29 . 2009-03-25 17:12 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-24 14:05 . 2009-03-24 14:05 d——– c:\program files\Trend Micro
2009-03-24 13:50 . 2009-03-24 13:50 10,520 –a—— c:\windows\System32\avgrsstx.dll.install_backup
2009-03-24 13:49 . 2009-03-25 03:28 d——– c:\program files\AVG
2009-03-23 18:13 . 2009-03-23 18:13 d——– c:\windows\System32\Service
2009-03-20 16:51 . 2009-03-20 16:51 d——– c:\windows\Sun
2009-03-12 19:28 . 2009-03-12 19:28 d——– c:\program files\Alwil Software
2009-03-11 09:44 . 2009-03-12 20:05 d——– c:\program files\Conduit
2009-03-11 09:12 . 2009-02-09 03:10 2,033,152 –a—— c:\windows\System32\win32k.sys
2009-03-11 09:12 . 2008-11-27 04:43 268,288 –a—— c:\windows\System32\schannel.dll
2009-03-10 18:20 . 2009-03-20 20:20 d——– c:\users\Natalie\AppData\Roaming\Motive
2009-03-07 16:56 . 2008-06-20 01:14 781,344 –a—— c:\windows\System32\PresentationNative_v0300.dll
2009-03-07 16:56 . 2008-06-20 01:14 622,080 –a—— c:\windows\System32\icardagt.exe
2009-03-07 16:56 . 2008-06-20 01:14 326,160 –a—— c:\windows\System32\PresentationHost.exe
2009-03-07 16:56 . 2008-06-20 01:14 105,016 –a—— c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-03-07 16:56 . 2008-06-20 01:14 97,800 –a—— c:\windows\System32\infocardapi.dll
2009-03-07 16:56 . 2008-06-20 01:14 43,544 –a—— c:\windows\System32\PresentationHostProxy.dll
2009-03-07 16:56 . 2008-06-20 01:14 37,384 –a—— c:\windows\System32\infocardcpl.cpl
2009-03-07 16:56 . 2008-06-20 01:14 11,264 –a—— c:\windows\System32\icardres.dll
2009-03-07 16:47 . 2008-07-27 18:03 96,760 –a—— c:\windows\System32\dfshim.dll
2009-03-07 16:46 . 2008-07-27 18:03 282,112 –a—— c:\windows\System32\mscoree.dll
2009-03-07 16:46 . 2008-07-27 18:03 158,720 –a—— c:\windows\System32\mscorier.dll
2009-03-07 16:46 . 2008-07-27 18:03 83,968 –a—— c:\windows\System32\mscories.dll
2009-03-07 16:46 . 2008-07-27 18:03 41,984 –a—— c:\windows\System32\netfxperf.dll
2009-03-07 16:44 . 2008-12-16 03:29 8,147,456 –a—— c:\windows\System32\wmploc.DLL
2009-03-07 16:44 . 2008-12-16 05:31 7,680 –a—— c:\windows\System32\spwmp.dll
2009-03-07 16:44 . 2008-12-16 05:31 4,096 –a—— c:\windows\System32\msdxm.ocx
2009-03-07 16:44 . 2008-12-16 05:31 4,096 –a—— c:\windows\System32\dxmasf.dll
2009-03-03 22:29 . 2009-03-03 22:29 d——– c:\windows\BTV.0001
2009-03-03 18:14 . 2009-03-03 18:14 d——– c:\users\All Users\Yahoo! Companion
2009-03-03 18:14 . 2009-03-03 18:14 d——– c:\programdata\Yahoo! Companion
2009-03-03 18:11 . 2009-03-03 18:11 d——– c:\program files\Yahoo!
2009-03-03 18:10 . 2009-03-03 18:10 d——– c:\windows\BTV.0000
2009-03-03 18:10 . 2008-12-09 20:54 95,616 ——— c:\windows\System32\BTEmailConfig.dll
2009-03-03 18:08 . 2009-03-10 18:20 d——– c:\users\All Users\Motive
2009-03-03 18:08 . 2009-03-10 18:20 d——– c:\programdata\Motive
2009-03-03 18:08 . 2009-03-03 18:08 d——– c:\program files\Common Files\Motive
2009-03-03 18:08 . 2009-03-03 18:08 d——– c:\program files\BTHomeHub
2009-03-03 18:08 . 2009-03-03 18:08 d——– c:\program files\BT Broadband Desktop Help

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-26 08:40 ——— d—–w c:\programdata\Kontiki
2009-03-25 20:44 ——— d—a-w c:\programdata\TEMP
2009-03-25 20:09 ——— d—–w c:\program files\LimeWire
2009-03-11 14:45 ——— d—–w c:\program files\BitLord
2009-03-11 11:34 ——— d—–w c:\program files\Windows Mail
2009-03-03 18:10 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-03 17:57 ——— d—–w c:\program files\Microsoft Silverlight
2009-01-15 06:11 827,392 —-a-w c:\windows\System32\wininet.dll
2008-08-20 16:08 24,316 —-a-w c:\users\Natalie\ptrn_a4.zip
2008-07-03 21:24 174 –sha-w c:\program files\desktop.ini
2008-02-15 14:36 114,008 —-a-w c:\users\Natalie\AppData\Roaming\GDIPFONTCACHEV1.DAT
2007-12-31 14:21 2,023,300 —-a-w c:\users\Natalie\PhotoBox UK 3.2.5.exe
2007-11-19 23:54 76,061,677 —-a-w c:\users\Natalie\jpeg.zip
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-09-12 171448]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 411192]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-05-23 509496]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-22 538744]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-06 34352]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-22 438272]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-04-02 577536]
"Desktop SMS"="c:\program files\IDM\Desktop SMS\DesktopSMS.exe" [2007-01-19 1507328]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2006-09-11 180224]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaRegistration.exe" [2007-05-04 571024]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-06-20 1316136]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"btbb_McciTrayApp"="c:\program files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe" [2008-09-11 1517056]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-25 c:\windows\RtHDVCpl.exe]

c:\users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-12-21 113664]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\vio\dvacm.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{6F1DF044-BC47-4E05-8A1D-B3071F4CE1B9}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9571BD14-5692-4ED1-90F1-93248782870D}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{DC0AA9E5-F248-47A7-A6B5-1D19DE8781A4}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{F5F9A6B7-2C0F-49D6-9194-93C91F620F1B}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{80DB277A-D739-4656-AEA8-0030694C6FC0}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{4D3A0904-45EF-481C-A697-9BE313C48888}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-2.4.3-to-3.0.2-enGB-Win-Final-downloader.exe:Blizzard Downloader
"{D7762868-8A90-4BA1-9441-E989BA41CCF6}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-2.4.3-to-3.0.2-enGB-Win-Final-downloader.exe:Blizzard Downloader
"{6A2C6449-5064-42E9-8C3D-36FC6658BEE7}"= UDP:3724:Blizzard Downloader: 3724
"{AE71889E-DDC3-4745-BECF-656DB990FB63}"= UDP:c:\users\Natalie\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool
"{72AD860E-2101-4F33-B160-00A0E40380D1}"= TCP:c:\users\Natalie\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool
"{A65BBCFE-E03D-4E71-8E29-448D708051DC}"= UDP:c:\program files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:Sid Meier's Civilization 4
"{B38187A6-A77F-4B27-ABF9-E4F177FE8A4D}"= TCP:c:\program files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:Sid Meier's Civilization 4
"{2E3FF2FF-B5DC-4896-BE5A-A704DAD60336}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{3830CA7C-BE32-41D3-8CEB-4CD7CB1E3D51}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{D00D20CA-5898-42F0-AAE1-B89DEA9C74E7}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{403DAA9F-E100-4916-AE5A-95F1145635D1}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{29D2DA82-AD1A-493E-BB77-02CB7BB534BE}c:\\users\\natalie\\appdata\\local\\temp\\blizzard launcher temporary - 441898f0\\launcher.exe"= UDP:c:\users\natalie\appdata\local\temp\blizzard launcher temporary - 441898f0\launcher.exe:launcher.exe
"UDP Query User{BD596E6E-603C-4F65-87A1-2C839BC93768}c:\\users\\natalie\\appdata\\local\\temp\\blizzard launcher temporary - 441898f0\\launcher.exe"= TCP:c:\users\natalie\appdata\local\temp\blizzard launcher temporary - 441898f0\launcher.exe:launcher.exe
"TCP Query User{722CA873-1C83-47F3-BF56-7D4F1AD68363}c:\\users\\natalie\\appdata\\local\\temp\\blizzard launcher temporary - 12fa35f8\\launcher.exe"= UDP:c:\users\natalie\appdata\local\temp\blizzard launcher temporary - 12fa35f8\launcher.exe:launcher.exe
"UDP Query User{FFF94CD5-14DB-42EA-AB77-FC58A922DB47}c:\\users\\natalie\\appdata\\local\\temp\\blizzard launcher temporary - 12fa35f8\\launcher.exe"= TCP:c:\users\natalie\appdata\local\temp\blizzard launcher temporary - 12fa35f8\launcher.exe:launcher.exe
"{91383C82-0565-4AFC-A249-635A65938EE7}"= UDP:f:\x86\IbisCont.exe:BT Home Hub 2.0
"{1C82C6C3-B998-42C0-9C35-8FAAC49B6D28}"= TCP:f:\x86\IbisCont.exe:BT Home Hub 2.0
"TCP Query User{79271E04-A53D-40FA-B4B3-ECFC58F4C4C6}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{684C2F80-0134-4837-B611-1D070A0C273F}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

S4 CplIR;Embedded IR Driver;c:\windows\System32\drivers\CplIR.sys [2007-03-06 14848]

— Other Services/Drivers In Memory —

*Deregistered* - sptd

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ca9bde6-5d6d-11dc-9b3e-806e6f6e6963}]
\shell\AutoRun\command - F:\Setup.exe
\shell\BTHomeHub\command - F:\Setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f3281409-1859-11dd-867f-001b383ed31f}]
\shell\AutoRun\command - D:\Setup.exe
.
Contents of the 'Scheduled Tasks' folder

2008-01-19 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]

2009-03-25 c:\windows\Tasks\User_Feed_Synchronization-{65A6F496-72F7-4965-973E-EC5A7717B4FC}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 07:33]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-HWSetup - \HWSetup.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://gooogle.com/
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - http://rover.ebay.com/rover/1/710-44557-9400-3/4
IE: {{8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/redire…1&site;=home
IE: {{94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} - c:\progra~1\PACIFI~1\pacificpoker.exe
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-26 08:41:23
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************
.
Completion time: 2009-03-26 8:43:47
ComboFix-quarantined-files.txt 2009-03-26 08:43:45

Pre-Run: 6,595,964,928 bytes free
Post-Run: 6,596,366,336 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
223 — E O F — 2009-03-11 11:31:32
And Hijackthis also

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:53:26, on 26/03/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gooogle.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [btbb_McciTrayApp] "C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: eBay.co.uk - Buy It Sell It Love It - {76577871-04EC-495E-A12B-91F7C3600AFA} - http://rover.ebay.com/rover/1/710-44557-9400-3/4 (file missing)
O9 - Extra button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/redire…1&site=home (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: PacificPoker4 - {94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} - C:\PROGRA~1\PACIFI~1\pacificpoker.exe (file missing)
O13 - Gopher Prefix:
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://static.photobox.co.uk/sg/common/uploader_uni.cab
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

–
End of file - 9888 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI