This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser Hijacker

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HI,
I hope some one can help. Both Firefox and Internet explorer often jump pass the page I want to go to, if you then press back arrow you get the page (more often than not, but not always), you wanted. Both browsers don't like being directed to any site which is about using Hijackthis.When trying once both browsers would not connect to the internet, althouh IE now does.

The AVG antivirus software can't update (no connection to the server it says), and I have tied switching off the firewall, but it makes no difference.Spybot can't connect to update either. Outlook express is working fine.

I have run a full scan in antivirus and spybot in both ordinary and safe mode and nothing has been found. I have also run to on-line scans (Pandasoft and Kapapski ), but again nothing found.

I tried to remove the Firefox programme in add/remove programmmes, in both ordinary and safe mode but it won't delete. I did a find all file and folders for Firefox and deleted them all, then downloaded the latest Firefox, its still Hijacked and the strange thing, all my saved favourites were still in the bbokmarks, eveb though I had deleted all Fire fox file before I downloaded/installed the new versions.

The hijackthis log is the following:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:05:04, on 28/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Novell\XTAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Novell\ZENworks\nalntsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe
C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe
C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Novell\ZENworks\wm.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Samsung\DisplayManager\DisplayManager.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
C:\WINDOWS\system32\iprntctl.exe
C:\WINDOWS\system32\iprntlgn.exe
C:\WINDOWS\system32\dpmw32.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
O1 - Hosts: 147.197.7.82 zenwsimport
O1 - Hosts: 147.197.7.36 DS1 #added by ACU setup
O1 - Hosts: 147.197.7.38 DS2 #added by ACU setup
O1 - Hosts: 147.197.7.52 DS3 #added by ACU setup
O1 - Hosts: 147.197.7.54 DS4 #added by ACU setup
O1 - Hosts: 147.197.7.38 U-HERTS #added by ACU setup
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Google plugin - {684EE1DB-CD52-4ca9-9CCF-93D5F6B419BA} - kmsvc32.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - (no file)
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [RestoreIT!] "C:\Program Files\Phoenix Technologies Ltd\RecoverPro_XP\VBPTASK.EXE" VBStart
O4 - HKLM\..\Run: [DisplayManager] C:\Program Files\Samsung\DisplayManager\DisplayManager.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
O4 - HKLM\..\Run: [iPrint Tray] C:\WINDOWS\system32\iprntctl.exe TRAY_ICON
O4 - HKLM\..\Run: [iPrint Event Monitor] C:\WINDOWS\system32\iprntlgn.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\system32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_1_0 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ChkDisk.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI69DF~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Novell delivered applications - {C1994287-422F-47aa-8E5E-6323E210A125} - C:\Program Files\Novell\ZENworks\AxNalServer.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.co.uk/scan_uk/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4AE66722-3678-49D2-B956-C59100B9D5E3}: Domain = herts.ac.uk
O17 - HKLM\System\CCS\Services\Tcpip\..\{4AE66722-3678-49D2-B956-C59100B9D5E3}: NameServer = 147.197.200.2,147.197.200.44
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = herts.ac.uk
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = herts.ac.uk
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\system32\cusrvc.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
O23 - Service: Google Update Service (gupdate1c99396c91d592) (gupdate1c99396c91d592) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\Program Files\Novell\ZENworks\nalntsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Novell ZENworks Remote Management Agent (Remote Management Agent) - Novell, Inc. - C:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe
O23 - Service: Samsung Update Plus - Unknown owner - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
O23 - Service: SNM WLAN Service - Unknown owner - C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe
O23 - Service: SRS PostInstaller Service (SRS_PostInstaller) - SRS Labs, Inc. - C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Novell XTier Agent Services (XTAgent) - Novell, Inc. - C:\WINDOWS\System32\Novell\XTAgent.exe
O23 - Service: Workstation Manager (ZFDWM) - Novell, Inc. - C:\Program Files\Novell\ZENworks\wm.exe

–
End of file - 11837 bytes

Hopefully someone will know what this is, and how to remove it…

Thanks,

Mick

Sorry I should also of mentioned that I tried to do a restore to an ealrier date, and the computer won't let me do that either …however as it always seems to be with computers, it doesn't say why!!

Thanks…

Mick
Hi and :welcome:

Firstly,

Is this a business machine?
If it is, you should perhaps refer this matter to your IT department, as sometimes Company Policy prevents third party intervention.

WTT cannot be held liable for changes made to this machine if it is used for business purposes.

If it is your personal machine that you use sometimes for business then I can help you clean it.

IMPORTANT
You should know that a file on this machine is referred to as a 'backdoor password stealer'.
Your personal information and your identity may have already been compromised.
If you have used this machine for online banking, I suggest you do the following immediately:
*Call all of your banks, credit card companies, financial institutions and inform them that your personal information may have been compromised and to put a watch on your accounts or change all your account numbers.

FROM AN UNINFECTED MACHINE

*Change ALL your on-line passwords for email, banks, financial accounts, PayPal, eBay, on-line companies, any on-line forums, groups or games you belong to.
DO NOT change your passwords from this computer as the attacker will be able to get all the new passwords and transaction records.

If you wish to have me attempt to clean this machine I will be happy to do so but I cannot guarantee that even after cleaning, your machine will be completely trustworthy again.
The only way to be certain is to do a complete reformat and reinstall of your operating system.
Please let me know what you decide to do.

If you decide to continue with cleaning then please do the following:



Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
HI… Thanks very much for your help. The laptop was a business one, but was given to me as part of my severance package, so no I can't take it in to the IT dept ..mores the pity!!. Yes I would like to try and clean it if you can help. The laptop wont now let me connect on either Firefox or IE, since I tried to download the ComboFix, so I'm having to do it on my desktop PC and move things across, so please bear with me. One I have put ComboFix on my laptop I'll paste the details back up here, and hopefully we can make a start getting rid of this 'thing', it the worse I have ever come across in terms of what it does and how it blocks you getting fixes!!. Once again thanks very much… Best Regards, Mick.
Hi, I've added the ComboFix onto the laptop, having downloaded it on my desktop. When you double click on it a small bluebar runs along as if its installing, the eggtimer flashes a few time and then nothing. Could it be that the Backddor password stealer is stopping from opening?… I'd be really grateful for some advice on what to next :pullhair: Regards, Mick
Yes it could be an issue,

Lets try another tactic…

Please do this

(you should be able to accomplish this download from your own computer as the tool is renamed and shouldn't be recognized by the infection)

If you are still unable to access the net, download the program to a different computer - rename it first - then transfer the renamed program over.)

Please download ComboFix from Here or Here to your Desktop.
**Note:  In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    [external image: Posted Image]

    [external image: Posted Image]
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.  
  • Please post the "C:\Combo-Fix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
Hi… I've tried that, and managed to save it a Combo - Fix.exe but it still just flashes the blue loading bar, and the egg timer flashes up but it fails to load. Regards, Mick
Hi

OK, then please do this,

we are going to have to do a manual removal

first lets clean up Combo fix

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]

Next


  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt.
    Note:These logs can be located in the OTListIt2. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Hi…

Yes done that. The attached is the OListlt2
OTListIt logfile created on: 29/03/2009 16:32:14 - Run 1
OTListIt2 by OldTimer - Version 2.0.7.2 Folder = E:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.50 Gb Total Physical Memory | 0.85 Gb Available Physical Memory | 56.78% Memory free
2.85 Gb Paging File | 2.37 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 101.26 Gb Total Space | 79.49 Gb Free Space | 78.51% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 963.70 Mb Total Space | 957.58 Mb Free Space | 99.36% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SEC-SECQMR-LAP
Current User Name: secqmr
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\System32\Novell\XTAgent.exe (Novell, Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
PRC - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe (F-Secure Corp.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Novell\ZENworks\nalntsrv.exe (Novell, Inc.)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe (Novell, Inc.)
PRC - C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe ()
PRC - C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe (SRS Labs, Inc.)
PRC - C:\Program Files\Novell\ZENworks\wm.exe (Novell, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\WINDOWS\AGRSMMSG.exe (Agere Systems)
PRC - C:\Program Files\Samsung\DisplayManager\DisplayManager.exe (SAMSUNG)
PRC - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe ()
PRC - C:\WINDOWS\system32\iprntctl.exe (Novell, Inc.)
PRC - C:\WINDOWS\system32\iprntlgn.exe (Novell, Inc.)
PRC - C:\WINDOWS\system32\dpmw32.exe (Novell, Inc.)
PRC - C:\WINDOWS\system32\NWTRAY.EXE (Novell, Inc.)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
PRC - E:\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (BackWeb Plug-in - 7681197 [Disabled | Stopped]) – C:\Program Files\F-Secure\BackWeb\7681197\program\ServiceWrapper-7681197.exe (F-Secure Automatic Update)
SRV - (btwdins [Auto | Running]) – C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (cusrvc [On_Demand | Stopped]) – C:\WINDOWS\system32\cusrvc.exe (Novell, Inc.)
SRV - (dsNcService [Auto | Running]) – C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
SRV - (F-Secure Network Request Broker [Disabled | Stopped]) – C:\Program Files\F-Secure\Common\FNRB32.EXE (F-Secure Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (fsbwsys [Auto | Running]) – C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe (F-Secure Corp.)
SRV - (FSMA [Disabled | Stopped]) – C:\Program Files\F-Secure\Common\FSMA32.EXE (F-Secure Corporation)
SRV - (gupdate1c99396c91d592 [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NALNTSERVICE [Auto | Running]) – C:\Program Files\Novell\ZENworks\nalntsrv.exe (Novell, Inc.)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Remote Management Agent [Auto | Running]) – C:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe (Novell, Inc.)
SRV - (Samsung Update Plus [Auto | Stopped]) – C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe ()
SRV - (SNM WLAN Service [Auto | Running]) – C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe ()
SRV - (SRS_PostInstaller [Auto | Running]) – C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe (SRS Labs, Inc.)
SRV - (vsmon [Auto | Running]) – C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (XTAgent [Auto | Running]) – C:\WINDOWS\System32\Novell\XTAgent.exe (Novell, Inc.)
SRV - (ZFDWM [Auto | Running]) – C:\Program Files\Novell\ZENworks\wm.exe (Novell, Inc.)

========== Driver Services (SafeList) ==========

DRV - (ADIHdAudAddService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (AEAudioService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\AEAudio.sys (Andrea Electronics Corporation)
DRV - (AgereSoftModem [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\AGRSM.sys (Agere Systems)
DRV - (amdagp [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (b57w2k [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (bcm4sbxp [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BlankScr [Auto | Running]) – C:\WINDOWS\System32\drivers\blankscr.sys (Novell Inc.)
DRV - (btaudio [On_Demand | Running]) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTKRNL [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\btkrnl.sys (Broadcom Corporation.)
DRV - (BTWUSB [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\btwusb.sys (Broadcom Corporation.)
DRV - (CmdIde [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DOSMEMIO [Auto | Running]) – C:\WINDOWS\system32\MEMIO.SYS ()
DRV - (dsNcAdpt [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys (Juniper Networks)
DRV - (FBAPI [Auto | Running]) – C:\WINDOWS\system32\drivers\FBAPI.sys ()
DRV - (HdAudAddService [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\HdAudio.sys (Windows ® Server 2003 DDK provider)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (ialm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (mraid35x [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (NETw3x32 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\NETw3x32.sys (Intel® Corporation)
DRV - (NetwareWorkstation [Auto | Running]) – C:\WINDOWS\system32\NetWare\nwfs.sys (Novell, Inc.)
DRV - (NICM [Boot | Running]) – C:\WINDOWS\system32\drivers\nicm.sys (Novell, Inc.)
DRV - (nipplpt2 [System | Running]) – C:\WINDOWS\system32\drivers\nipplpt.sys ()
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (NWDHCP [Auto | Running]) – C:\WINDOWS\system32\NetWare\nwdhcp.sys (Novell, Inc.)
DRV - (NWDNS [On_Demand | Running]) – C:\WINDOWS\system32\NetWare\nwdns.sys (Novell, Inc.)
DRV - (NWFILTER [Boot | Running]) – C:\WINDOWS\system32\NetWare\nwfilter.sys (Novell, Inc.)
DRV - (NWHOST [On_Demand | Running]) – C:\WINDOWS\system32\NetWare\NWHOST.sys (Novell, Inc.)
DRV - (NWSAP [On_Demand | Stopped]) – C:\WINDOWS\system32\NetWare\NWSAP.sys ()
DRV - (NWSIPX32 [Auto | Stopped]) – C:\WINDOWS\system32\NetWare\nwsipx32.sys (Novell, Inc.)
DRV - (NWSLP [On_Demand | Running]) – C:\WINDOWS\system32\NetWare\nwslp.sys (Novell, Inc.)
DRV - (NWSNS [On_Demand | Running]) – C:\WINDOWS\system32\NetWare\NWSNS.sys (Novell, Inc.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ql1080 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (RESMGR [Auto | Running]) – C:\WINDOWS\system32\NetWare\resmgr.sys (Novell, Inc.)
DRV - (rimmptsk [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\rimmptsk.sys (REDC)
DRV - (rimsptsk [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\rimsptsk.sys (REDC)
DRV - (RimVSerPort [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\RimSerial.sys (Research in Motion Ltd)
DRV - (rismxdp [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\rixdptsk.sys (REDC)
DRV - (RITCPT [Boot | Running]) – C:\WINDOWS\System32\drivers\RITCPT.SYS ()
DRV - (ROOTMODEM [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Sparrow [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (srescan [Boot | Running]) – C:\WINDOWS\system32\ZoneLabs\srescan.sys (Check Point Software Technologies LTD)
DRV - (SRVLOC [Auto | Running]) – C:\WINDOWS\system32\NetWare\srvloc.sys (Novell, Inc.)
DRV - (SSB2413 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\SSB2413.sys (Atheros Communications, Inc.)
DRV - (symc810 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (SynTP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (ultra [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (vsdatant [System | Running]) – C:\WINDOWS\System32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (wowfilter [On_Demand | Running]) – C:\WINDOWS\system32\drivers\wowfilter.sys ()

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.ntlworld.com"
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/27 20:23:58 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/27 20:23:58 | 00,000,000 | —D | M]

[2008/08/26 18:24:33 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\mozilla\Extensions
[2008/08/26 18:24:33 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/01/01 15:40:56 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\mozilla\Firefox\Profiles\kbs9bkyr.default\extensions
[2009/03/27 20:24:17 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/03/27 20:23:58 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/26 20:11:21 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/26 20:11:22 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/03/26 19:56:22 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/03/26 19:56:22 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/03/26 19:56:22 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/03/26 19:56:22 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/03/26 19:56:22 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/03/26 19:56:22 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/03/26 19:56:22 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (305864 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 147.197.7.82 zenwsimport
O1 - Hosts: 147.197.7.36 DS1 #added by ACU setup
O1 - Hosts: 147.197.7.38 DS2 #added by ACU setup
O1 - Hosts: 147.197.7.52 DS3 #added by ACU setup
O1 - Hosts: 147.197.7.54 DS4 #added by ACU setup
O1 - Hosts: 147.197.7.38 U-HERTS #added by ACU setup
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 10520 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Google plugin) - {684EE1DB-CD52-4ca9-9CCF-93D5F6B419BA} - File not found
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Ask Toolbar BHO) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {FE063DB9-4EC0-403E-8DD8-394C54984B2C} - Reg Error: Value error. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AGRSMMSG] AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe ()
O4 - HKLM..\Run: [DisplayManager] C:\Program Files\Samsung\DisplayManager\DisplayManager.exe (SAMSUNG)
O4 - HKLM..\Run: [iPrint Event Monitor] C:\WINDOWS\system32\iprntlgn.exe (Novell, Inc.)
O4 - HKLM..\Run: [iPrint Tray] C:\WINDOWS\system32\iprntctl.exe TRAY_ICON (Novell, Inc.)
O4 - HKLM..\Run: [NDPS] C:\WINDOWS\system32\dpmw32.exe (Novell, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NWTRAY] NWTRAY.EXE (Novell, Inc.)
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [RestoreIT!] "C:\Program Files\Phoenix Technologies Ltd\RecoverPro_XP\VBPTASK.EXE" VBStart (FarStone Tech. Inc.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_1_0 -reboot 1 (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: CompatibleRUPSecurity = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI69DF~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Novell delivered applications - {C1994287-422F-47aa-8E5E-6323E210A125} - C:\Program Files\Novell\ZENworks\AxNalServer.dll (Novell, Inc)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [Novell Directory Services Name Provider] - C:\WINDOWS\system32\netware\NWWS2NDS.DLL (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [Novell IPX/SPX SAP Name Provider] - C:\WINDOWS\system32\netware\NWWS2SAP.DLL (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [Novell SLP Provider] - C:\WINDOWS\system32\netware\NWWS2SLP.DLL (Novell, Inc.)
O15 - HKLM\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 55 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://www.bitdefender.co.uk/scan_uk/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{4AE66722-3678-49D2-B956-C59100B9D5E3}\\Domain = herts.ac.uk
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{4AE66722-3678-49D2-B956-C59100B9D5E3}\\NameServer = 147.197.200.2,147.197.200.44
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: System - (ziswin.exe) - C:\WINDOWS\system32\ziswin.exe (Novell)
O20 - HKLM Winlogon: GinaDLL - (NWGINA.DLL) - C:\WINDOWS\system32\NWGINA.DLL (Novell, Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\NetIdentity Notification: DllName - C:\WINDOWS\system32\Novell\XtNotify.dll - C:\WINDOWS\system32\Novell\XtNotify.dll (Novell, Inc.)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {763370C4-268E-4308-A60C-D8DA0342BE32} - C:\Program Files\Novell\ZENworks\NalShell.dll (Novell, Inc)
O30 - LSA: Authentication Packages - (nwv1_0) - C:\WINDOWS\System32\nwv1_0.dll (Novell, Inc.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{9e6745b3-0d82-11dc-ad17-001b7735fb1b}\Shell\AutoRun\command - "" = a.txt
O33 - MountPoints2\{9e6745b5-0d82-11dc-ad17-001b7735fb1b}\Shell\Auto\command - "" = tel.xls.exe
O33 - MountPoints2\{9e6745b5-0d82-11dc-ad17-001b7735fb1b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9e6745b7-0d82-11dc-ad17-001b7735fb1b}\Shell\AutoRun\command - "" = a.txt
O34 - HKLM BootExecute: (autocheck autochk *) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/03/29 16:20:23 | 00,000,000 | —D | C] – C:\32788R22FWJFW
[2009/03/29 16:19:07 | 00,000,284 | —- | C] () – C:\Documents and Settings\secqmr\Desktop\Shortcut to Combo - Fix.exe.lnk
[2009/03/28 10:30:45 | 00,000,060 | —- | C] () – C:\_.bat
[2009/03/28 08:40:04 | 00,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[2009/03/27 20:24:03 | 00,001,608 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/03/27 20:23:57 | 00,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2009/03/27 18:32:09 | 00,000,000 | —D | C] – C:\WINDOWS\BDOSCAN8
[2009/03/27 17:35:14 | 00,000,000 | —D | C] – C:\WINDOWS\CSC
[2009/03/26 21:40:25 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/09 20:24:42 | 04,568,726 | —- | C] () – C:\Documents and Settings\secqmr\Desktop\homeremedysecrets.pdf
[2009/03/08 17:08:37 | 00,000,886 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
[2009/03/08 16:33:14 | 00,003,658 | —- | C] () – C:\WINDOWS\System32\tmp.reg
[2009/03/08 16:32:30 | 00,082,944 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\IEDFix.C.exe
[2009/03/08 16:32:30 | 00,080,384 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\o4Patch.exe
[2009/03/08 16:32:30 | 00,078,336 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\Agent.OMZ.Fix.exe
[2009/03/08 16:32:29 | 00,087,552 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\VACFix.exe
[2009/03/08 16:32:29 | 00,082,944 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\IEDFix.exe
[2009/03/08 16:32:29 | 00,082,432 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\404Fix.exe
[2009/03/08 16:32:28 | 00,289,144 | —- | C] (S!Ri) – C:\WINDOWS\System32\VCCLSID.exe
[2009/03/08 16:32:28 | 00,025,600 | —- | C] () – C:\WINDOWS\System32\WS2Fix.exe
[2009/03/08 16:32:27 | 00,288,417 | —- | C] (S!Ri) – C:\WINDOWS\System32\SrchSTS.exe
[2009/03/08 16:32:27 | 00,079,360 | —- | C] (SteelWerX) – C:\WINDOWS\System32\swxcacls.exe
[2009/03/08 16:32:27 | 00,051,200 | —- | C] () – C:\WINDOWS\System32\dumphive.exe
[2009/03/08 16:32:26 | 00,135,168 | —- | C] (SteelWerX) – C:\WINDOWS\System32\swreg.exe
[2009/03/08 16:32:26 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\swsc.exe
[2009/03/08 16:32:25 | 00,053,248 | —- | C] (http://www.beyondlogic.org) – C:\WINDOWS\System32\Process.exe
[2009/03/08 13:31:44 | 00,001,152 | —- | C] () – C:\WINDOWS\System32\windrv.sys
[2009/03/08 13:30:31 | 00,000,000 | —D | C] – C:\Documents and Settings\secqmr\Application Data\GetRightToGo
[2009/03/08 13:13:00 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/03/05 19:59:11 | 00,059,392 | —- | C] () – C:\WINDOWS\System32\inform.dat
[2009/03/05 19:59:11 | 00,014,119 | —- | C] () – C:\WINDOWS\System32\wh
[2009/03/02 20:08:10 | 00,000,000 | —D | C] – C:\WINDOWS\Temporary Internet Files
[2009/03/02 20:08:10 | 00,000,000 | —D | C] – C:\WINDOWS\Recent
[2009/03/02 20:08:10 | 00,000,000 | —D | C] – C:\WINDOWS\History
[2009/03/02 20:08:10 | 00,000,000 | —D | C] – C:\WINDOWS\Cookies

========== Files - Modified Within 30 Days ==========

[2009/03/29 16:19:07 | 00,000,284 | —- | M] () – C:\Documents and Settings\secqmr\Desktop\Shortcut to Combo - Fix.exe.lnk
[2009/03/29 16:03:44 | 00,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
[2009/03/29 15:49:49 | 00,000,304 | —- | M] () – C:\WINDOWS\system.ini
[2009/03/29 08:21:04 | 00,000,000 | —- | M] () – C:\Documents and Settings\secqmr\Local Settings\Application Data\prvlcl.dat
[2009/03/29 08:00:09 | 00,555,756 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/29 08:00:09 | 00,466,140 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/29 08:00:09 | 00,079,608 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/29 07:58:40 | 00,043,616 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/03/29 07:58:27 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/29 07:33:53 | 00,350,193 | —- | M] () – C:\WINDOWS\System32\vsconfig.xml
[2009/03/29 07:32:53 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/29 07:32:46 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/03/28 23:27:00 | 09,259,034 | -H– | M] () – C:\Documents and Settings\secqmr\Local Settings\Application Data\IconCache.db
[2009/03/28 10:30:48 | 00,000,060 | —- | M] () – C:\_.bat
[2009/03/27 20:24:03 | 00,001,608 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/03/26 21:01:41 | 00,069,624 | —- | M] () – C:\Documents and Settings\secqmr\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/26 20:26:55 | 34,098,246 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/03/26 20:26:53 | 00,325,640 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/03/26 20:26:53 | 00,107,912 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/03/26 20:26:53 | 00,037,975 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/03/26 20:26:45 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/03/25 20:53:12 | 00,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2009/03/25 18:55:26 | 00,305,864 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/03/24 21:05:31 | 00,001,457 | —- | M] () – C:\Documents and Settings\secqmr\Application Data\mainhst.zgh
[2009/03/23 18:32:28 | 00,004,608 | —- | M] () – C:\Documents and Settings\secqmr\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/22 22:09:37 | 00,000,026 | —- | M] () – C:\WINDOWS\Zone.Identifier
[2009/03/18 20:44:08 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/03/18 18:55:11 | 00,305,062 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090325-175526.backup
[2009/03/18 18:50:18 | 00,270,192 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/13 20:12:31 | 00,304,810 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090318-175511.backup
[2009/03/09 20:25:45 | 04,568,726 | —- | M] () – C:\Documents and Settings\secqmr\Desktop\homeremedysecrets.pdf
[2009/03/08 17:08:37 | 00,000,886 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
[2009/03/08 16:44:50 | 00,003,658 | —- | M] () – C:\WINDOWS\System32\tmp.reg
[2009/03/08 16:44:45 | 00,304,456 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090313-191231.backup
[2009/03/08 13:31:44 | 00,001,152 | —- | M] () – C:\WINDOWS\System32\windrv.sys
[2009/03/08 12:46:43 | 00,000,694 | —- | M] () – C:\WINDOWS\win.ini
[2009/03/08 12:46:43 | 00,000,211 | RHS- | M] () – C:\boot.ini
[2009/03/05 19:59:11 | 00,059,392 | —- | M] () – C:\WINDOWS\System32\inform.dat
[2009/03/05 19:59:11 | 00,014,119 | —- | M] () – C:\WINDOWS\System32\wh
[2009/03/02 21:53:20 | 00,001,548 | —- | M] () – C:\Documents and Settings\secqmr\Desktop\CCleaner.lnk

========== LOP Check ==========

[2009/03/26 20:25:41 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/09/24 18:52:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/06/21 02:51:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ahead
[2009/03/26 20:26:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2007/06/21 03:00:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/04/24 21:29:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2009/03/28 08:39:55 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2009/03/17 22:09:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2008/09/25 18:41:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NOS
[2008/01/09 12:31:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\nView_Profiles
[2009/03/29 15:44:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/03/26 22:26:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/06/20 09:12:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/03/26 22:26:02 | 00,000,000 | RH-D | M] – C:\Documents and Settings\secqmr\Application Data
[2008/09/24 18:54:27 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Adobe
[2009/01/17 10:00:46 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\AdobeUM
[2008/02/17 13:13:22 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Ahead
[2009/01/15 19:58:16 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\CyberLink
[2007/06/21 04:28:03 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\F-Secure
[2009/03/08 13:31:30 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\GetRightToGo
[2007/12/09 17:05:59 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Google
[2009/01/22 18:31:25 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Help
[2005/09/10 21:10:36 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Identities
[2009/01/18 12:42:55 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\IObit
[2008/08/28 18:15:44 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Juniper Networks
[2007/11/10 08:46:45 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Macromedia
[2009/01/22 20:39:28 | 00,000,000 | –SD | M] – C:\Documents and Settings\secqmr\Application Data\Microsoft
[2008/08/26 18:24:33 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Mozilla
[2009/01/13 20:58:20 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Software Informer
[2007/06/21 02:38:14 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Sun
[2007/06/20 13:48:04 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Windows Desktop Search
[2008/11/18 20:21:00 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\ZipGenius
[2004/08/04 13:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/03/29 16:03:44 | 00,000,882 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachine.job
[2009/03/29 07:32:53 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/02/25 21:23:35 | 00,000,386 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag.job

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >

Hope that is what you need?..
I think this is second of the two reports:

OTListIt logfile created on: 29/03/2009 16:32:14 - Run 1
OTListIt2 by OldTimer - Version 2.0.7.2 Folder = E:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.50 Gb Total Physical Memory | 0.85 Gb Available Physical Memory | 56.78% Memory free
2.85 Gb Paging File | 2.37 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 101.26 Gb Total Space | 79.49 Gb Free Space | 78.51% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 963.70 Mb Total Space | 957.58 Mb Free Space | 99.36% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SEC-SECQMR-LAP
Current User Name: secqmr
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\System32\Novell\XTAgent.exe (Novell, Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
PRC - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe (F-Secure Corp.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Novell\ZENworks\nalntsrv.exe (Novell, Inc.)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe (Novell, Inc.)
PRC - C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe ()
PRC - C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe (SRS Labs, Inc.)
PRC - C:\Program Files\Novell\ZENworks\wm.exe (Novell, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\WINDOWS\AGRSMMSG.exe (Agere Systems)
PRC - C:\Program Files\Samsung\DisplayManager\DisplayManager.exe (SAMSUNG)
PRC - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe ()
PRC - C:\WINDOWS\system32\iprntctl.exe (Novell, Inc.)
PRC - C:\WINDOWS\system32\iprntlgn.exe (Novell, Inc.)
PRC - C:\WINDOWS\system32\dpmw32.exe (Novell, Inc.)
PRC - C:\WINDOWS\system32\NWTRAY.EXE (Novell, Inc.)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
PRC - E:\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (BackWeb Plug-in - 7681197 [Disabled | Stopped]) – C:\Program Files\F-Secure\BackWeb\7681197\program\ServiceWrapper-7681197.exe (F-Secure Automatic Update)
SRV - (btwdins [Auto | Running]) – C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (cusrvc [On_Demand | Stopped]) – C:\WINDOWS\system32\cusrvc.exe (Novell, Inc.)
SRV - (dsNcService [Auto | Running]) – C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
SRV - (F-Secure Network Request Broker [Disabled | Stopped]) – C:\Program Files\F-Secure\Common\FNRB32.EXE (F-Secure Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (fsbwsys [Auto | Running]) – C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe (F-Secure Corp.)
SRV - (FSMA [Disabled | Stopped]) – C:\Program Files\F-Secure\Common\FSMA32.EXE (F-Secure Corporation)
SRV - (gupdate1c99396c91d592 [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NALNTSERVICE [Auto | Running]) – C:\Program Files\Novell\ZENworks\nalntsrv.exe (Novell, Inc.)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Remote Management Agent [Auto | Running]) – C:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe (Novell, Inc.)
SRV - (Samsung Update Plus [Auto | Stopped]) – C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe ()
SRV - (SNM WLAN Service [Auto | Running]) – C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe ()
SRV - (SRS_PostInstaller [Auto | Running]) – C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe (SRS Labs, Inc.)
SRV - (vsmon [Auto | Running]) – C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (XTAgent [Auto | Running]) – C:\WINDOWS\System32\Novell\XTAgent.exe (Novell, Inc.)
SRV - (ZFDWM [Auto | Running]) – C:\Program Files\Novell\ZENworks\wm.exe (Novell, Inc.)

========== Driver Services (SafeList) ==========

DRV - (ADIHdAudAddService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (AEAudioService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\AEAudio.sys (Andrea Electronics Corporation)
DRV - (AgereSoftModem [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\AGRSM.sys (Agere Systems)
DRV - (amdagp [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (b57w2k [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (bcm4sbxp [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BlankScr [Auto | Running]) – C:\WINDOWS\System32\drivers\blankscr.sys (Novell Inc.)
DRV - (btaudio [On_Demand | Running]) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTKRNL [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\btkrnl.sys (Broadcom Corporation.)
DRV - (BTWUSB [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\btwusb.sys (Broadcom Corporation.)
DRV - (CmdIde [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DOSMEMIO [Auto | Running]) – C:\WINDOWS\system32\MEMIO.SYS ()
DRV - (dsNcAdpt [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys (Juniper Networks)
DRV - (FBAPI [Auto | Running]) – C:\WINDOWS\system32\drivers\FBAPI.sys ()
DRV - (HdAudAddService [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\HdAudio.sys (Windows ® Server 2003 DDK provider)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (ialm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (mraid35x [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (NETw3x32 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\NETw3x32.sys (Intel® Corporation)
DRV - (NetwareWorkstation [Auto | Running]) – C:\WINDOWS\system32\NetWare\nwfs.sys (Novell, Inc.)
DRV - (NICM [Boot | Running]) – C:\WINDOWS\system32\drivers\nicm.sys (Novell, Inc.)
DRV - (nipplpt2 [System | Running]) – C:\WINDOWS\system32\drivers\nipplpt.sys ()
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (NWDHCP [Auto | Running]) – C:\WINDOWS\system32\NetWare\nwdhcp.sys (Novell, Inc.)
DRV - (NWDNS [On_Demand | Running]) – C:\WINDOWS\system32\NetWare\nwdns.sys (Novell, Inc.)
DRV - (NWFILTER [Boot | Running]) – C:\WINDOWS\system32\NetWare\nwfilter.sys (Novell, Inc.)
DRV - (NWHOST [On_Demand | Running]) – C:\WINDOWS\system32\NetWare\NWHOST.sys (Novell, Inc.)
DRV - (NWSAP [On_Demand | Stopped]) – C:\WINDOWS\system32\NetWare\NWSAP.sys ()
DRV - (NWSIPX32 [Auto | Stopped]) – C:\WINDOWS\system32\NetWare\nwsipx32.sys (Novell, Inc.)
DRV - (NWSLP [On_Demand | Running]) – C:\WINDOWS\system32\NetWare\nwslp.sys (Novell, Inc.)
DRV - (NWSNS [On_Demand | Running]) – C:\WINDOWS\system32\NetWare\NWSNS.sys (Novell, Inc.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ql1080 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (RESMGR [Auto | Running]) – C:\WINDOWS\system32\NetWare\resmgr.sys (Novell, Inc.)
DRV - (rimmptsk [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\rimmptsk.sys (REDC)
DRV - (rimsptsk [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\rimsptsk.sys (REDC)
DRV - (RimVSerPort [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\RimSerial.sys (Research in Motion Ltd)
DRV - (rismxdp [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\rixdptsk.sys (REDC)
DRV - (RITCPT [Boot | Running]) – C:\WINDOWS\System32\drivers\RITCPT.SYS ()
DRV - (ROOTMODEM [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Sparrow [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (srescan [Boot | Running]) – C:\WINDOWS\system32\ZoneLabs\srescan.sys (Check Point Software Technologies LTD)
DRV - (SRVLOC [Auto | Running]) – C:\WINDOWS\system32\NetWare\srvloc.sys (Novell, Inc.)
DRV - (SSB2413 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\SSB2413.sys (Atheros Communications, Inc.)
DRV - (symc810 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (SynTP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (ultra [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (vsdatant [System | Running]) – C:\WINDOWS\System32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (wowfilter [On_Demand | Running]) – C:\WINDOWS\system32\drivers\wowfilter.sys ()

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.ntlworld.com"
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/27 20:23:58 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/27 20:23:58 | 00,000,000 | —D | M]

[2008/08/26 18:24:33 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\mozilla\Extensions
[2008/08/26 18:24:33 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/01/01 15:40:56 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\mozilla\Firefox\Profiles\kbs9bkyr.default\extensions
[2009/03/27 20:24:17 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/03/27 20:23:58 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/26 20:11:21 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/26 20:11:22 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/03/26 19:56:22 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/03/26 19:56:22 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/03/26 19:56:22 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/03/26 19:56:22 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/03/26 19:56:22 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/03/26 19:56:22 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/03/26 19:56:22 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (305864 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 147.197.7.82 zenwsimport
O1 - Hosts: 147.197.7.36 DS1 #added by ACU setup
O1 - Hosts: 147.197.7.38 DS2 #added by ACU setup
O1 - Hosts: 147.197.7.52 DS3 #added by ACU setup
O1 - Hosts: 147.197.7.54 DS4 #added by ACU setup
O1 - Hosts: 147.197.7.38 U-HERTS #added by ACU setup
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 10520 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Google plugin) - {684EE1DB-CD52-4ca9-9CCF-93D5F6B419BA} - File not found
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Ask Toolbar BHO) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {FE063DB9-4EC0-403E-8DD8-394C54984B2C} - Reg Error: Value error. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AGRSMMSG] AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe ()
O4 - HKLM..\Run: [DisplayManager] C:\Program Files\Samsung\DisplayManager\DisplayManager.exe (SAMSUNG)
O4 - HKLM..\Run: [iPrint Event Monitor] C:\WINDOWS\system32\iprntlgn.exe (Novell, Inc.)
O4 - HKLM..\Run: [iPrint Tray] C:\WINDOWS\system32\iprntctl.exe TRAY_ICON (Novell, Inc.)
O4 - HKLM..\Run: [NDPS] C:\WINDOWS\system32\dpmw32.exe (Novell, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NWTRAY] NWTRAY.EXE (Novell, Inc.)
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [RestoreIT!] "C:\Program Files\Phoenix Technologies Ltd\RecoverPro_XP\VBPTASK.EXE" VBStart (FarStone Tech. Inc.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_1_0 -reboot 1 (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: CompatibleRUPSecurity = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI69DF~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Novell delivered applications - {C1994287-422F-47aa-8E5E-6323E210A125} - C:\Program Files\Novell\ZENworks\AxNalServer.dll (Novell, Inc)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [Novell Directory Services Name Provider] - C:\WINDOWS\system32\netware\NWWS2NDS.DLL (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [Novell IPX/SPX SAP Name Provider] - C:\WINDOWS\system32\netware\NWWS2SAP.DLL (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [Novell SLP Provider] - C:\WINDOWS\system32\netware\NWWS2SLP.DLL (Novell, Inc.)
O15 - HKLM\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 55 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://www.bitdefender.co.uk/scan_uk/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{4AE66722-3678-49D2-B956-C59100B9D5E3}\\Domain = herts.ac.uk
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{4AE66722-3678-49D2-B956-C59100B9D5E3}\\NameServer = 147.197.200.2,147.197.200.44
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: System - (ziswin.exe) - C:\WINDOWS\system32\ziswin.exe (Novell)
O20 - HKLM Winlogon: GinaDLL - (NWGINA.DLL) - C:\WINDOWS\system32\NWGINA.DLL (Novell, Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\NetIdentity Notification: DllName - C:\WINDOWS\system32\Novell\XtNotify.dll - C:\WINDOWS\system32\Novell\XtNotify.dll (Novell, Inc.)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {763370C4-268E-4308-A60C-D8DA0342BE32} - C:\Program Files\Novell\ZENworks\NalShell.dll (Novell, Inc)
O30 - LSA: Authentication Packages - (nwv1_0) - C:\WINDOWS\System32\nwv1_0.dll (Novell, Inc.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{9e6745b3-0d82-11dc-ad17-001b7735fb1b}\Shell\AutoRun\command - "" = a.txt
O33 - MountPoints2\{9e6745b5-0d82-11dc-ad17-001b7735fb1b}\Shell\Auto\command - "" = tel.xls.exe
O33 - MountPoints2\{9e6745b5-0d82-11dc-ad17-001b7735fb1b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9e6745b7-0d82-11dc-ad17-001b7735fb1b}\Shell\AutoRun\command - "" = a.txt
O34 - HKLM BootExecute: (autocheck autochk *) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/03/29 16:20:23 | 00,000,000 | —D | C] – C:\32788R22FWJFW
[2009/03/29 16:19:07 | 00,000,284 | —- | C] () – C:\Documents and Settings\secqmr\Desktop\Shortcut to Combo - Fix.exe.lnk
[2009/03/28 10:30:45 | 00,000,060 | —- | C] () – C:\_.bat
[2009/03/28 08:40:04 | 00,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[2009/03/27 20:24:03 | 00,001,608 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/03/27 20:23:57 | 00,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2009/03/27 18:32:09 | 00,000,000 | —D | C] – C:\WINDOWS\BDOSCAN8
[2009/03/27 17:35:14 | 00,000,000 | —D | C] – C:\WINDOWS\CSC
[2009/03/26 21:40:25 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/09 20:24:42 | 04,568,726 | —- | C] () – C:\Documents and Settings\secqmr\Desktop\homeremedysecrets.pdf
[2009/03/08 17:08:37 | 00,000,886 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
[2009/03/08 16:33:14 | 00,003,658 | —- | C] () – C:\WINDOWS\System32\tmp.reg
[2009/03/08 16:32:30 | 00,082,944 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\IEDFix.C.exe
[2009/03/08 16:32:30 | 00,080,384 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\o4Patch.exe
[2009/03/08 16:32:30 | 00,078,336 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\Agent.OMZ.Fix.exe
[2009/03/08 16:32:29 | 00,087,552 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\VACFix.exe
[2009/03/08 16:32:29 | 00,082,944 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\IEDFix.exe
[2009/03/08 16:32:29 | 00,082,432 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\404Fix.exe
[2009/03/08 16:32:28 | 00,289,144 | —- | C] (S!Ri) – C:\WINDOWS\System32\VCCLSID.exe
[2009/03/08 16:32:28 | 00,025,600 | —- | C] () – C:\WINDOWS\System32\WS2Fix.exe
[2009/03/08 16:32:27 | 00,288,417 | —- | C] (S!Ri) – C:\WINDOWS\System32\SrchSTS.exe
[2009/03/08 16:32:27 | 00,079,360 | —- | C] (SteelWerX) – C:\WINDOWS\System32\swxcacls.exe
[2009/03/08 16:32:27 | 00,051,200 | —- | C] () – C:\WINDOWS\System32\dumphive.exe
[2009/03/08 16:32:26 | 00,135,168 | —- | C] (SteelWerX) – C:\WINDOWS\System32\swreg.exe
[2009/03/08 16:32:26 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\swsc.exe
[2009/03/08 16:32:25 | 00,053,248 | —- | C] (http://www.beyondlogic.org) – C:\WINDOWS\System32\Process.exe
[2009/03/08 13:31:44 | 00,001,152 | —- | C] () – C:\WINDOWS\System32\windrv.sys
[2009/03/08 13:30:31 | 00,000,000 | —D | C] – C:\Documents and Settings\secqmr\Application Data\GetRightToGo
[2009/03/08 13:13:00 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/03/05 19:59:11 | 00,059,392 | —- | C] () – C:\WINDOWS\System32\inform.dat
[2009/03/05 19:59:11 | 00,014,119 | —- | C] () – C:\WINDOWS\System32\wh
[2009/03/02 20:08:10 | 00,000,000 | —D | C] – C:\WINDOWS\Temporary Internet Files
[2009/03/02 20:08:10 | 00,000,000 | —D | C] – C:\WINDOWS\Recent
[2009/03/02 20:08:10 | 00,000,000 | —D | C] – C:\WINDOWS\History
[2009/03/02 20:08:10 | 00,000,000 | —D | C] – C:\WINDOWS\Cookies

========== Files - Modified Within 30 Days ==========

[2009/03/29 16:19:07 | 00,000,284 | —- | M] () – C:\Documents and Settings\secqmr\Desktop\Shortcut to Combo - Fix.exe.lnk
[2009/03/29 16:03:44 | 00,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
[2009/03/29 15:49:49 | 00,000,304 | —- | M] () – C:\WINDOWS\system.ini
[2009/03/29 08:21:04 | 00,000,000 | —- | M] () – C:\Documents and Settings\secqmr\Local Settings\Application Data\prvlcl.dat
[2009/03/29 08:00:09 | 00,555,756 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/29 08:00:09 | 00,466,140 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/29 08:00:09 | 00,079,608 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/29 07:58:40 | 00,043,616 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/03/29 07:58:27 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/29 07:33:53 | 00,350,193 | —- | M] () – C:\WINDOWS\System32\vsconfig.xml
[2009/03/29 07:32:53 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/29 07:32:46 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/03/28 23:27:00 | 09,259,034 | -H– | M] () – C:\Documents and Settings\secqmr\Local Settings\Application Data\IconCache.db
[2009/03/28 10:30:48 | 00,000,060 | —- | M] () – C:\_.bat
[2009/03/27 20:24:03 | 00,001,608 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/03/26 21:01:41 | 00,069,624 | —- | M] () – C:\Documents and Settings\secqmr\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/26 20:26:55 | 34,098,246 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/03/26 20:26:53 | 00,325,640 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/03/26 20:26:53 | 00,107,912 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/03/26 20:26:53 | 00,037,975 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/03/26 20:26:45 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/03/25 20:53:12 | 00,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2009/03/25 18:55:26 | 00,305,864 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/03/24 21:05:31 | 00,001,457 | —- | M] () – C:\Documents and Settings\secqmr\Application Data\mainhst.zgh
[2009/03/23 18:32:28 | 00,004,608 | —- | M] () – C:\Documents and Settings\secqmr\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/22 22:09:37 | 00,000,026 | —- | M] () – C:\WINDOWS\Zone.Identifier
[2009/03/18 20:44:08 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/03/18 18:55:11 | 00,305,062 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090325-175526.backup
[2009/03/18 18:50:18 | 00,270,192 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/13 20:12:31 | 00,304,810 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090318-175511.backup
[2009/03/09 20:25:45 | 04,568,726 | —- | M] () – C:\Documents and Settings\secqmr\Desktop\homeremedysecrets.pdf
[2009/03/08 17:08:37 | 00,000,886 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
[2009/03/08 16:44:50 | 00,003,658 | —- | M] () – C:\WINDOWS\System32\tmp.reg
[2009/03/08 16:44:45 | 00,304,456 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090313-191231.backup
[2009/03/08 13:31:44 | 00,001,152 | —- | M] () – C:\WINDOWS\System32\windrv.sys
[2009/03/08 12:46:43 | 00,000,694 | —- | M] () – C:\WINDOWS\win.ini
[2009/03/08 12:46:43 | 00,000,211 | RHS- | M] () – C:\boot.ini
[2009/03/05 19:59:11 | 00,059,392 | —- | M] () – C:\WINDOWS\System32\inform.dat
[2009/03/05 19:59:11 | 00,014,119 | —- | M] () – C:\WINDOWS\System32\wh
[2009/03/02 21:53:20 | 00,001,548 | —- | M] () – C:\Documents and Settings\secqmr\Desktop\CCleaner.lnk

========== LOP Check ==========

[2009/03/26 20:25:41 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/09/24 18:52:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/06/21 02:51:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ahead
[2009/03/26 20:26:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2007/06/21 03:00:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/04/24 21:29:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2009/03/28 08:39:55 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2009/03/17 22:09:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2008/09/25 18:41:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NOS
[2008/01/09 12:31:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\nView_Profiles
[2009/03/29 15:44:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/03/26 22:26:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/06/20 09:12:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/03/26 22:26:02 | 00,000,000 | RH-D | M] – C:\Documents and Settings\secqmr\Application Data
[2008/09/24 18:54:27 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Adobe
[2009/01/17 10:00:46 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\AdobeUM
[2008/02/17 13:13:22 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Ahead
[2009/01/15 19:58:16 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\CyberLink
[2007/06/21 04:28:03 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\F-Secure
[2009/03/08 13:31:30 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\GetRightToGo
[2007/12/09 17:05:59 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Google
[2009/01/22 18:31:25 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Help
[2005/09/10 21:10:36 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Identities
[2009/01/18 12:42:55 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\IObit
[2008/08/28 18:15:44 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Juniper Networks
[2007/11/10 08:46:45 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Macromedia
[2009/01/22 20:39:28 | 00,000,000 | –SD | M] – C:\Documents and Settings\secqmr\Application Data\Microsoft
[2008/08/26 18:24:33 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Mozilla
[2009/01/13 20:58:20 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Software Informer
[2007/06/21 02:38:14 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Sun
[2007/06/20 13:48:04 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\Windows Desktop Search
[2008/11/18 20:21:00 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\ZipGenius
[2004/08/04 13:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/03/29 16:03:44 | 00,000,882 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachine.job
[2009/03/29 07:32:53 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/02/25 21:23:35 | 00,000,386 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag.job

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >

Regards,

Mick
Hi,

please do the following:

Run OTList2.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTLI2 (do not copy the word "code" )

    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O2 - BHO: (Google plugin) - {684EE1DB-CD52-4ca9-9CCF-93D5F6B419BA} - File not found
    O2 - BHO: (Ask Toolbar BHO) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - Reg Error: Value error. File not found
    O3 - HKLM\..\Toolbar: (Ask Toolbar) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - Reg Error: Value error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {FE063DB9-4EC0-403E-8DD8-394C54984B2C} - Reg Error: Value error. File not found
    O33 - MountPoints2\{9e6745b3-0d82-11dc-ad17-001b7735fb1b}\Shell\AutoRun\command - "" = a.txt
    O33 - MountPoints2\{9e6745b5-0d82-11dc-ad17-001b7735fb1b}\Shell\Auto\command - "" = tel.xls.exe
    O33 - MountPoints2\{9e6745b5-0d82-11dc-ad17-001b7735fb1b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{9e6745b7-0d82-11dc-ad17-001b7735fb1b}\Shell\AutoRun\command - "" = a.txt
    [2009/03/28 10:30:45 | 00,000,060 | —- | C] () – C:\_.bat
    [2009/03/08 16:33:14 | 00,003,658 | —- | C] () – C:\WINDOWS\System32\tmp.reg
    [2009/03/05 19:59:11 | 00,014,119 | —- | C] () – C:\WINDOWS\System32\wh
    [2009/03/05 19:59:11 | 00,059,392 | —- | C] () – C:\WINDOWS\System32\inform.dat
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [resethosts]
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )

NEXT

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer. (version 6 update 13)


NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


NEXT


Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.


In your next reply please include:


  • OTListIt log
  • MBAM log
  • Kaspersky report
  • Fresh HJT log
HI…

This is the first log:

OTListIt logfile created on: 29/03/2009 17:50:22 - Run 2
OTListIt2 by OldTimer - Version 2.0.7.2 Folder = C:\Documents and Settings\secqmr\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.50 Gb Total Physical Memory | 0.93 Gb Available Physical Memory | 62.34% Memory free
2.85 Gb Paging File | 2.40 Gb Available in Paging File | 83.99% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 101.26 Gb Total Space | 79.51 Gb Free Space | 78.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 963.70 Mb Total Space | 957.39 Mb Free Space | 99.34% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SEC-SECQMR-LAP
Current User Name: secqmr
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\System32\Novell\XTAgent.exe (Novell, Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
PRC - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe (F-Secure Corp.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Novell\ZENworks\nalntsrv.exe (Novell, Inc.)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe (Novell, Inc.)
PRC - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe ()
PRC - C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe ()
PRC - C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe (SRS Labs, Inc.)
PRC - C:\Program Files\Novell\ZENworks\wm.exe (Novell, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Novell\ZENworks\WMRUNDLL.EXE (Novell, Inc.)
PRC - C:\Program Files\Novell\ZENworks\WMRUNDLL.EXE (Novell, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\WINDOWS\AGRSMMSG.exe (Agere Systems)
PRC - C:\Program Files\Samsung\DisplayManager\DisplayManager.exe (SAMSUNG)
PRC - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe ()
PRC - C:\WINDOWS\system32\iprntctl.exe (Novell, Inc.)
PRC - C:\WINDOWS\system32\iprntlgn.exe (Novell, Inc.)
PRC - C:\WINDOWS\system32\dpmw32.exe (Novell, Inc.)
PRC - C:\WINDOWS\system32\NWTRAY.EXE (Novell, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Office 2007\Office12\WINWORD.EXE (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Documents and Settings\secqmr\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (BackWeb Plug-in - 7681197 [Disabled | Stopped]) – C:\Program Files\F-Secure\BackWeb\7681197\program\ServiceWrapper-7681197.exe (F-Secure Automatic Update)
SRV - (btwdins [Auto | Running]) – C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (cusrvc [On_Demand | Stopped]) – C:\WINDOWS\system32\cusrvc.exe (Novell, Inc.)
SRV - (dsNcService [Auto | Running]) – C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
SRV - (F-Secure Network Request Broker [Disabled | Stopped]) – C:\Program Files\F-Secure\Common\FNRB32.EXE (F-Secure Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (fsbwsys [Auto | Running]) – C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe (F-Secure Corp.)
SRV - (FSMA [Disabled | Stopped]) – C:\Program Files\F-Secure\Common\FSMA32.EXE (F-Secure Corporation)
SRV - (gupdate1c99396c91d592 [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NALNTSERVICE [Auto | Running]) – C:\Program Files\Novell\ZENworks\nalntsrv.exe (Novell, Inc.)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Remote Management Agent [Auto | Running]) – C:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe (Novell, Inc.)
SRV - (Samsung Update Plus [Auto | Running]) – C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe ()
SRV - (SNM WLAN Service [Auto | Running]) – C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe ()
SRV - (SRS_PostInstaller [Auto | Running]) – C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe (SRS Labs, Inc.)
SRV - (vsmon [Auto | Running]) – C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (XTAgent [Auto | Running]) – C:\WINDOWS\System32\Novell\XTAgent.exe (Novell, Inc.)
SRV - (ZFDWM [Auto | Running]) – C:\Program Files\Novell\ZENworks\wm.exe (Novell, Inc.)

========== Driver Services (SafeList) ==========

DRV - (ADIHdAudAddService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (AEAudioService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\AEAudio.sys (Andrea Electronics Corporation)
DRV - (AgereSoftModem [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\AGRSM.sys (Agere Systems)
DRV - (amdagp [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (b57w2k [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (bcm4sbxp [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BlankScr [Auto | Running]) – C:\WINDOWS\System32\drivers\blankscr.sys (Novell Inc.)
DRV - (btaudio [On_Demand | Running]) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTKRNL [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\btkrnl.sys (Broadcom Corporation.)
DRV - (BTWUSB [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\btwusb.sys (Broadcom Corporation.)
DRV - (CmdIde [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DOSMEMIO [Auto | Running]) – C:\WINDOWS\system32\MEMIO.SYS ()
DRV - (dsNcAdpt [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys (Juniper Networks)
DRV - (FBAPI [Auto | Running]) – C:\WINDOWS\system32\drivers\FBAPI.sys ()
DRV - (HdAudAddService [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\HdAudio.sys (Windows ® Server 2003 DDK provider)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (ialm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (mraid35x [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (NETw3x32 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\NETw3x32.sys (Intel® Corporation)
DRV - (NetwareWorkstation [Auto | Running]) – C:\WINDOWS\system32\NetWare\nwfs.sys (Novell, Inc.)
DRV - (NICM [Boot | Running]) – C:\WINDOWS\system32\drivers\nicm.sys (Novell, Inc.)
DRV - (nipplpt2 [System | Running]) – C:\WINDOWS\system32\drivers\nipplpt.sys ()
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (NWDHCP [Auto | Running]) – C:\WINDOWS\system32\NetWare\nwdhcp.sys (Novell, Inc.)
DRV - (NWDNS [On_Demand | Running]) – C:\WINDOWS\system32\NetWare\nwdns.sys (Novell, Inc.)
DRV - (NWFILTER [Boot | Running]) – C:\WINDOWS\system32\NetWare\nwfilter.sys (Novell, Inc.)
DRV - (NWHOST [On_Demand | Running]) – C:\WINDOWS\system32\NetWare\NWHOST.sys (Novell, Inc.)
DRV - (NWSAP [On_Demand | Stopped]) – C:\WINDOWS\system32\NetWare\NWSAP.sys ()
DRV - (NWSIPX32 [Auto | Stopped]) – C:\WINDOWS\system32\NetWare\nwsipx32.sys (Novell, Inc.)
DRV - (NWSLP [On_Demand | Running]) – C:\WINDOWS\system32\NetWare\nwslp.sys (Novell, Inc.)
DRV - (NWSNS [On_Demand | Running]) – C:\WINDOWS\system32\NetWare\NWSNS.sys (Novell, Inc.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ql1080 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (RESMGR [Auto | Running]) – C:\WINDOWS\system32\NetWare\resmgr.sys (Novell, Inc.)
DRV - (rimmptsk [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\rimmptsk.sys (REDC)
DRV - (rimsptsk [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\rimsptsk.sys (REDC)
DRV - (RimVSerPort [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\RimSerial.sys (Research in Motion Ltd)
DRV - (rismxdp [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\rixdptsk.sys (REDC)
DRV - (RITCPT [Boot | Running]) – C:\WINDOWS\System32\drivers\RITCPT.SYS ()
DRV - (ROOTMODEM [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Sparrow [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (srescan [Boot | Running]) – C:\WINDOWS\system32\ZoneLabs\srescan.sys (Check Point Software Technologies LTD)
DRV - (SRVLOC [Auto | Running]) – C:\WINDOWS\system32\NetWare\srvloc.sys (Novell, Inc.)
DRV - (SSB2413 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\SSB2413.sys (Atheros Communications, Inc.)
DRV - (symc810 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (SynTP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (ultra [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (vsdatant [System | Running]) – C:\WINDOWS\System32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (wowfilter [On_Demand | Running]) – C:\WINDOWS\system32\drivers\wowfilter.sys ()

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.ntlworld.com"
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/27 20:23:58 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/27 20:23:58 | 00,000,000 | —D | M]

[2008/08/26 18:24:33 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\mozilla\Extensions
[2008/08/26 18:24:33 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/01/01 15:40:56 | 00,000,000 | —D | M] – C:\Documents and Settings\secqmr\Application Data\mozilla\Firefox\Profiles\kbs9bkyr.default\extensions
[2009/03/27 20:24:17 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/03/27 20:23:58 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/26 20:11:21 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/26 20:11:22 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/03/26 19:56:22 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/03/26 19:56:22 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/03/26 19:56:22 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/03/26 19:56:22 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/03/26 19:56:22 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/03/26 19:56:22 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/03/26 19:56:22 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (56 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AGRSMMSG] AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe ()
O4 - HKLM..\Run: [DisplayManager] C:\Program Files\Samsung\DisplayManager\DisplayManager.exe (SAMSUNG)
O4 - HKLM..\Run: [iPrint Event Monitor] C:\WINDOWS\system32\iprntlgn.exe (Novell, Inc.)
O4 - HKLM..\Run: [iPrint Tray] C:\WINDOWS\system32\iprntctl.exe TRAY_ICON (Novell, Inc.)
O4 - HKLM..\Run: [NDPS] C:\WINDOWS\system32\dpmw32.exe (Novell, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NWTRAY] NWTRAY.EXE (Novell, Inc.)
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [RestoreIT!] "C:\Program Files\Phoenix Technologies Ltd\RecoverPro_XP\VBPTASK.EXE" VBStart (FarStone Tech. Inc.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_1_0 -reboot 1 (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: CompatibleRUPSecurity = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI69DF~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Novell delivered applications - {C1994287-422F-47aa-8E5E-6323E210A125} - C:\Program Files\Novell\ZENworks\AxNalServer.dll (Novell, Inc)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [Novell Directory Services Name Provider] - C:\WINDOWS\system32\netware\NWWS2NDS.DLL (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [Novell IPX/SPX SAP Name Provider] - C:\WINDOWS\system32\netware\NWWS2SAP.DLL (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [Novell SLP Provider] - C:\WINDOWS\system32\netware\NWWS2SLP.DLL (Novell, Inc.)
O15 - HKLM\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 55 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://www.bitdefender.co.uk/scan_uk/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{4AE66722-3678-49D2-B956-C59100B9D5E3}\\Domain = herts.ac.uk
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{4AE66722-3678-49D2-B956-C59100B9D5E3}\\NameServer = 147.197.200.2,147.197.200.44
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: System - (ziswin.exe) - C:\WINDOWS\system32\ziswin.exe (Novell)
O20 - HKLM Winlogon: GinaDLL - (NWGINA.DLL) - C:\WINDOWS\system32\NWGINA.DLL (Novell, Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\NetIdentity Notification: DllName - C:\WINDOWS\system32\Novell\XtNotify.dll - C:\WINDOWS\system32\Novell\XtNotify.dll (Novell, Inc.)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {763370C4-268E-4308-A60C-D8DA0342BE32} - C:\Program Files\Novell\ZENworks\NalShell.dll (Novell, Inc)
O30 - LSA: Authentication Packages - (nwv1_0) - C:\WINDOWS\System32\nwv1_0.dll (Novell, Inc.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/03/29 17:46:20 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/03/29 17:43:08 | 00,498,688 | —- | C] (OldTimer Tools) – C:\Documents and Settings\secqmr\Desktop\OTListIt2.exe
[2009/03/29 16:20:23 | 00,000,000 | —D | C] – C:\32788R22FWJFW
[2009/03/28 08:40:04 | 00,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[2009/03/27 20:24:03 | 00,001,608 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/03/27 20:23:57 | 00,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2009/03/27 18:32:09 | 00,000,000 | —D | C] – C:\WINDOWS\BDOSCAN8
[2009/03/27 17:35:14 | 00,000,000 | —D | C] – C:\WINDOWS\CSC
[2009/03/26 21:40:25 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/09 20:24:42 | 04,568,726 | —- | C] () – C:\Documents and Settings\secqmr\Desktop\homeremedysecrets.pdf
[2009/03/08 17:08:37 | 00,000,886 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
[2009/03/08 16:32:30 | 00,082,944 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\IEDFix.C.exe
[2009/03/08 16:32:30 | 00,080,384 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\o4Patch.exe
[2009/03/08 16:32:30 | 00,078,336 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\Agent.OMZ.Fix.exe
[2009/03/08 16:32:29 | 00,087,552 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\VACFix.exe
[2009/03/08 16:32:29 | 00,082,944 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\IEDFix.exe
[2009/03/08 16:32:29 | 00,082,432 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\404Fix.exe
[2009/03/08 16:32:28 | 00,289,144 | —- | C] (S!Ri) – C:\WINDOWS\System32\VCCLSID.exe
[2009/03/08 16:32:28 | 00,025,600 | —- | C] () – C:\WINDOWS\System32\WS2Fix.exe
[2009/03/08 16:32:27 | 00,288,417 | —- | C] (S!Ri) – C:\WINDOWS\System32\SrchSTS.exe
[2009/03/08 16:32:27 | 00,079,360 | —- | C] (SteelWerX) – C:\WINDOWS\System32\swxcacls.exe
[2009/03/08 16:32:27 | 00,051,200 | —- | C] () – C:\WINDOWS\System32\dumphive.exe
[2009/03/08 16:32:26 | 00,135,168 | —- | C] (SteelWerX) – C:\WINDOWS\System32\swreg.exe
[2009/03/08 16:32:26 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\swsc.exe
[2009/03/08 16:32:25 | 00,053,248 | —- | C] (http://www.beyondlogic.org) – C:\WINDOWS\System32\Process.exe
[2009/03/08 13:31:44 | 00,001,152 | —- | C] () – C:\WINDOWS\System32\windrv.sys
[2009/03/08 13:30:31 | 00,000,000 | —D | C] – C:\Documents and Settings\secqmr\Application Data\GetRightToGo
[2009/03/08 13:13:00 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/03/02 20:08:10 | 00,000,000 | —D | C] – C:\WINDOWS\Temporary Internet Files
[2009/03/02 20:08:10 | 00,000,000 | —D | C] – C:\WINDOWS\Recent
[2009/03/02 20:08:10 | 00,000,000 | —D | C] – C:\WINDOWS\History
[2009/03/02 20:08:10 | 00,000,000 | —D | C] – C:\WINDOWS\Cookies

========== Files - Modified Within 30 Days ==========

[2009/03/29 17:49:05 | 00,043,616 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/03/29 17:48:50 | 00,350,193 | —- | M] () – C:\WINDOWS\System32\vsconfig.xml
[2009/03/29 17:48:44 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/29 17:48:29 | 00,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
[2009/03/29 17:47:54 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/29 17:47:47 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/03/29 17:46:37 | 16,831,808 | -H– | M] () – C:\Documents and Settings\secqmr\Local Settings\Application Data\IconCache.db
[2009/03/29 17:46:30 | 00,000,056 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2009/03/29 16:29:14 | 00,498,688 | —- | M] (OldTimer Tools) – C:\Documents and Settings\secqmr\Desktop\OTListIt2.exe
[2009/03/29 15:49:49 | 00,000,304 | —- | M] () – C:\WINDOWS\system.ini
[2009/03/29 08:21:04 | 00,000,000 | —- | M] () – C:\Documents and Settings\secqmr\Local Settings\Application Data\prvlcl.dat
[2009/03/29 08:00:09 | 00,555,756 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/29 08:00:09 | 00,466,140 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/29 08:00:09 | 00,079,608 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/27 20:24:03 | 00,001,608 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/03/26 21:01:41 | 00,069,624 | —- | M] () – C:\Documents and Settings\secqmr\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/26 20:26:55 | 34,098,246 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/03/26 20:26:53 | 00,325,640 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/03/26 20:26:53 | 00,107,912 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/03/26 20:26:53 | 00,037,975 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/03/26 20:26:45 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/03/25 20:53:12 | 00,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2009/03/24 21:05:31 | 00,001,457 | —- | M] () – C:\Documents and Settings\secqmr\Application Data\mainhst.zgh
[2009/03/23 18:32:28 | 00,004,608 | —- | M] () – C:\Documents and Settings\secqmr\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/22 22:09:37 | 00,000,026 | —- | M] () – C:\WINDOWS\Zone.Identifier
[2009/03/18 20:44:08 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/03/18 18:55:11 | 00,305,062 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090325-175526.backup
[2009/03/18 18:50:18 | 00,270,192 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/13 20:12:31 | 00,304,810 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090318-175511.backup
[2009/03/09 20:25:45 | 04,568,726 | —- | M] () – C:\Documents and Settings\secqmr\Desktop\homeremedysecrets.pdf
[2009/03/08 17:08:37 | 00,000,886 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
[2009/03/08 16:44:45 | 00,304,456 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090313-191231.backup
[2009/03/08 13:31:44 | 00,001,152 | —- | M] () – C:\WINDOWS\System32\windrv.sys
[2009/03/08 12:46:43 | 00,000,694 | —- | M] () – C:\WINDOWS\win.ini
[2009/03/08 12:46:43 | 00,000,211 | RHS- | M] () – C:\boot.ini
[2009/03/02 21:53:20 | 00,001,548 | —- | M] () – C:\Documents and Settings\secqmr\Desktop\CCleaner.lnk

========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >

The javaRa, says it has encountered a problem when removing older versions . I've downloaded the latest version (it gives the status as downloaded), but I can't seem to make it install!

I'll carry on with the anti-malware programme and post the log…

Regards,

Mick
Hi … This is the MBAM file… Malwarebytes' Anti-Malware 1.35 Database version: 1904 Windows 5.1.2600 Service Pack 3 29/03/2009 18:20:40 mbam-log-2009-03-29 (18-20-40).txt Scan type: Quick Scan Objects scanned: 73160 Time elapsed: 2 minute(s), 38 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{684ee1db-cd52-4ca9-9ccf-93d5f6b419ba} (Trojan.Banker) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{0ea88f0f-b698-4ab1-8dbc-ebe2cd00927f} (Backdoor.Bot) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\clup.cmd (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\secqmr\Start Menu\Programs\Startup\ChkDisk.lnk (Trojan.FakeAlert) -> Quarantined and deleted successfully. I'll do the on-line virus checker now…if the laptop will connect!! … Regards, Mick
Hi… Sorry for the delay the On-line scanner is doing its thing, buts its taken 51 mins and has only done 46% so far!! …and isn't showing its found anything at all so far :unsure: Regards, Mick

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI