This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Windows Installer - wherefore are't thou?

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
This question has been asked a 1000 times, because I have read all the answers. My windows installer does not install. I get the classic "Windows Installer Service etc…Get technical assistance".

I have tried all the obvious including Dial-a-Fix and support.microsoft. There also seems to be a COM+ event problem mixed in with it as I get a message also saying it is not properly installed in the Services Event log.

I know I am a bit scant on details but if someone can look at my log and just tell me if there is something there that shouldn't be that will be a big help.

Next stop is a windows repair.

The unit is a Toshiba Satellite 2450 laptop and I am hesitant to run the OEM OS discs as they are dated 2003.

Thanks in advance.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:27:28 PM, on 4/5/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\ScsiAccess.EXE
C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\imapi.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TP-LINK\TL-WN321G Wireless Utility\Installer\WINXP\TWCU.exe
C:\Program Files\TradeComm\TradeComm.exe
C:\Program Files\Optus Wireless Broadband\Optus Wireless Broadband.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\FxPro MetaTrader\terminal.exe
C:\Program Files\AmiBroker\Broker.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-3326087701-2093908761-825061208-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-21-3326087701-2093908761-825061208-1005 Startup: TradeComm.lnk = C:\Program Files\TradeComm\TradeComm.exe (User '?')
O4 - Startup: TradeComm.lnk = C:\Program Files\TradeComm\TradeComm.exe
O4 - Global Startup: TL-WN321G Wireless Utility.lnk = C:\Program Files\TP-LINK\TL-WN321G Wireless Utility\Installer\WINXP\TWCU.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://a248.e.akamai.net
O15 - Trusted Zone: http://*.bitdefender.com
O15 - Trusted Zone: http://ssl-hints.netflame.cc
O16 - DPF: {0BE35204-8F91-11CE-9DE3-00AA004BB851} (CLSID_StdPict) - http://wwwau.kodak.com/AU/en/consumer/prin…e/OPW_25900.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/betaactivesca…s/as2stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1191501172608
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1191500714049
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u1…=javadl.sun.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{F75D7FAB-B30C-49C3-9808-DA30AF1C3450}: NameServer = 61.88.88.88 61.88.88.88
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Tmesbs32 (Tmesbs) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe

–
End of file - 7331 bytes
Hi PeterPumpkinEater,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Thanks Tomk for your help.

Did both items as requested. Computer performs the same as previously. I still can not install windows update MS NET Framework 3.5 Services Pack and the NET Framework 3.5 Family Update. Also get "The Eindows Installer Service etc..Contaact your support personnel for asistance" message when trying to load any program that requires "Install"

Also, drop downs when navigating to a directory to save a document, or to access a document has a huge lag. Eddect also present in Windows Explorer. However can navigate around inside the window to open directories, or go up the tree using the directory ip button.

Hijack file===
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:42:08 PM, on 4/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\ScsiAccess.EXE
C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\System32\imapi.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TP-LINK\TL-WN321G Wireless Utility\Installer\WINXP\TWCU.exe
C:\Program Files\TradeComm\TradeComm.exe
C:\Program Files\Optus Wireless Broadband\Optus Wireless Broadband.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-3326087701-2093908761-825061208-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-21-3326087701-2093908761-825061208-1005 Startup: TradeComm.lnk = C:\Program Files\TradeComm\TradeComm.exe (User '?')
O4 - Startup: TradeComm.lnk = C:\Program Files\TradeComm\TradeComm.exe
O4 - Global Startup: TL-WN321G Wireless Utility.lnk = C:\Program Files\TP-LINK\TL-WN321G Wireless Utility\Installer\WINXP\TWCU.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.bitdefender.com
O16 - DPF: {0BE35204-8F91-11CE-9DE3-00AA004BB851} (CLSID_StdPict) - http://wwwau.kodak.com/AU/en/consumer/prin…e/OPW_25900.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/betaactivesca…s/as2stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1191501172608
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1191500714049
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u1…=javadl.sun.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{F75D7FAB-B30C-49C3-9808-DA30AF1C3450}: NameServer = 61.88.88.88 61.88.88.88
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Tmesbs32 (Tmesbs) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe

–
End of file - 6975 bytes


Malware Log=====
Malwarebytes' Anti-Malware 1.36
Database version: 1966
Windows 5.1.2600 Service Pack 3

4/11/2009 8:18:28 PM
mbam-log-2009-04-11 (20-18-28).txt

Scan type: Quick Scan
Objects scanned: 83150
Time elapsed: 12 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\reset.cmd (Trojan.Agent) -> Quarantined and deleted successfully.
====
This last file may have been me putting something here to fix, but I never ran it.
PeterPumpkinEater,

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
PeterPumpkinEater,

There are some things we will need to "fix" in your CF log. But first I'd like another scan.

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here
Tomk, As requested - one Rooter log. [Sidebar - I noticed refereces to ACDSee and Kodak in earlier logs. Neither programs show up as Program Files on "Add/Remove software". Kodak was advised ages ago to gotten rid of and I did, or thought I had, ACDSee started having problems a long time ago (long delays to load images) and I deinstalled with ADD/Remove but it failed. Something was broken a long time ago in that corner of the box but had little other impact anywhere else except install/uninstall.]

Attachments:

PeterPumpkinEater,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    REGLOCK:: 
    [HKEY_USERS\S-1-5-21-3326087701-2093908761-825061208-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\OpenWithProgids]
    [HKEY_USERS\S-1-5-21-3326087701-2093908761-825061208-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\OpenWithProgids]
    [HKEY_USERS\S-1-5-21-3326087701-2093908761-825061208-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ico\OpenWithProgids]
    [HKEY_USERS\S-1-5-21-3326087701-2093908761-825061208-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\OpenWithProgids]
    [HKEY_USERS\S-1-5-21-3326087701-2093908761-825061208-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\OpenWithProgids]
    [HKEY_USERS\S-1-5-21-3326087701-2093908761-825061208-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\OpenWithProgids]
    [HKEY_USERS\S-1-5-21-3326087701-2093908761-825061208-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\OpenWithProgids]
    [HKEY_USERS\S-1-5-21-3326087701-2093908761-825061208-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\OpenWithProgids]
    [HKEY_USERS\S-1-5-21-3326087701-2093908761-825061208-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\OpenWithProgids]
    [HKEY_USERS\S-1-5-21-3326087701-2093908761-825061208-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wri\OpenWithProgids]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{CA8A9781-280D-11CF-A24D-444553540000}\ProxyStubClsid]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{CA8A9781-280D-11CF-A24D-444553540000}\ProxyStubClsid32]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{CA8A9781-280D-11CF-A24D-444553540000}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{CA8A9782-280D-11CF-A24D-444553540000}\ProxyStubClsid]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{CA8A9782-280D-11CF-A24D-444553540000}\ProxyStubClsid32]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{CA8A9782-280D-11CF-A24D-444553540000}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\App Management\ARPCache]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\App Paths\DVDFORM.EXE]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\App Paths\NDSTray.exe]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\App Paths\TFncKy.exe]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\App Paths\TInTouch.exe]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\App Paths\TosHKCW.exe]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\App Paths\WinDVD.exe]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Control Panel\Settings]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Controls Folder\Mouse]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Controls Folder\Mouse\shellex\PropertySheetHandlers\TouchED]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\IviDVDEventHandler]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\IviVideoCDHandler]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Extensions]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\Secure]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\[u]0[/u]1BFF40EC9B6C834F80600354B0EACBA]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\1447934FAA440AB4CBFE80BB67E1FC0C]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\75FB05CE46035D115AA4000972A8B18B]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F841731866D117AB7000B0D410201]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\9BFA78E9338CDA04B83BCD497AF72EBD]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\9C0121F80A833D11581E000540386890]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\B0C43A05208F394489371868D4D946CE]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\B9551A0E68894D11D8600005AD82A493]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\[u]0[/u]FB8417F0885D3347914AB59BB450F0C]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\221F0CD0C1B14D11EA6D000CF420C235]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\35D1205B464EB704B9839D77C8B504E1]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\6B4EB6F053AF15F4492A506C16406DBA]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\6DB9693FD6475D547865C3E8B29F7676]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\7B73981E6A6E123438FB6987B71B60C7]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\8C7742A7731173F41A5EE101AAD5DE47]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\8D88AA868F834D845A1A1C5B421BDE44]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\F5BDCE32BCC8C874A998E6F61E9C9E76]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\[u]0[/u]B79C053C7D38EE4AB9A00CB3B5D2472\Features]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\79BB0A83D277E224CBACB42A5A8DF124\Features]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\79BB0A83D277E224CBACB42A5A8DF124\InstallProperties]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\8756E3AD9AC3968459B7C1B4C8BC3648\Features]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\8756E3AD9AC3968459B7C1B4C8BC3648\InstallProperties]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\8A0F841731866D117AB7000B0D410201\Features]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\8A0F841731866D117AB7000B0D410201\InstallProperties]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\BFB6BBEC807D99F46A33CB62000EE16F\Features]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\BFB6BBEC807D99F46A33CB62000EE16F\InstallProperties]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3326087701-2093908761-825061208-1005\Products\B9551A0E68894D11D8600005AD82A493\Features]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3326087701-2093908761-825061208-1005\Products\B9551A0E68894D11D8600005AD82A493\InstallProperties]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3326087701-2093908761-825061208-1005\Products\FDBA9EEADFFC2CC458918ECEBEA5A2FA\Features]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3326087701-2093908761-825061208-1005\Products\FDBA9EEADFFC2CC458918ECEBEA5A2FA\InstallProperties]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\OemStartMenuData]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\NVIDIA]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\SynTPDeinstKey]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\TDspBtn]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\TFNF5]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{3CF0858D-1AC5-4308-9DE7-AD15288A8BDC}]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{7862BAD8-A379-4128-8AA1-EFD5A9603C53}]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{98E8A2EF-4EAE-43B8-A172-74842B764777}]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{9D765FA6-F2BC-40AF-8145-50808F9BDF4E}]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{A6690C0E-B96E-4F0F-A8EB-D5B332454AC6}]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}]
    
    
    Registry::
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7bc49992-e409-11dc-a9bc-a0eac07de0cd}]
    
    Driver::
    Aplix2k
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Tomk,

This is a dawn buster here. 2:15 am. Thx for dedicating your Saturday.

CombiFix Log
==========
ComboFix 09-04-04.01 - Customer 2009-04-12 2:17:45.2 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Customer\Desktop\CFScript.txt
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_Aplix2k


((((((((((((((((((((((((( Files Created from 2009-03-11 to 2009-04-11 )))))))))))))))))))))))))))))))
.

2009-04-12 02:16 . 2006-03-02 23:42 73,728 –a—— C:\pv.exe
2009-04-12 02:15 . 2009-04-12 02:16 d——– C:\32788R22FWJFW
2009-04-12 01:17 . 2009-04-12 01:19 d——– C:\Rooter$
2009-04-12 00:08 . 2009-04-12 02:27 54,156 –ah—– c:\windows\QTFont.qfn
2009-04-12 00:08 . 2009-04-12 02:22 1,409 –a—— c:\windows\QTFont.for
2009-04-11 20:02 . 2009-04-11 20:02 d——– c:\documents and settings\Customer\Application Data\Malwarebytes
2009-04-11 20:01 . 2009-04-11 20:02 d——– c:\program files\Malwarebytes' Anti-Malware
2009-04-11 20:01 . 2009-04-11 20:01 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-11 20:01 . 2009-04-06 15:32 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-11 20:01 . 2009-04-06 15:32 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-04-06 17:54 . 2009-04-06 17:54 d–hs—- c:\documents and settings\NetworkService\IETldCache
2009-04-06 16:02 . 2009-04-06 16:02 d–hs—- c:\documents and settings\LocalService\IETldCache
2009-04-06 15:59 . 2009-04-06 15:59 d——– c:\windows\system32\GroupPolicy
2009-04-06 15:59 . 2009-04-06 16:00 d——– c:\program files\Windows Desktop Search
2009-04-05 17:26 . 2009-04-05 17:26 d——– c:\program files\Trend Micro
2009-04-04 07:13 . 2009-04-04 07:13 d–hs—- c:\documents and settings\Computer God Mk 2\PrivacIE
2009-04-04 07:09 . 2009-04-04 07:09 d–hs—- c:\documents and settings\Computer God Mk 2\IETldCache
2009-04-04 07:08 . 2003-01-07 09:31 d——– c:\documents and settings\Computer God Mk 2\Application Data\InterTrust
2009-04-04 07:08 . 2003-01-07 10:12 d——– c:\documents and settings\Computer God Mk 2\Application Data\Drag'n Drop CD
2009-04-04 07:07 . 2009-04-04 07:13 d——– c:\documents and settings\Computer God Mk 2
2009-04-03 10:41 . 2009-04-12 02:17 d——– c:\windows\system32\CatRoot2
2009-03-30 17:36 . 2009-03-30 17:36 d–hs—- c:\documents and settings\Customer\IECompatCache
2009-03-30 17:23 . 2009-03-30 17:23 d–hs—- c:\documents and settings\Administrator\IETldCache
2009-03-30 17:18 . 2009-03-30 17:18 d–hs—- c:\documents and settings\Customer\IETldCache
2009-03-30 17:11 . 2009-04-01 12:30 d–h-c— c:\windows\ie8
2009-03-30 16:33 . 2009-03-30 16:33 d–h—– c:\program files\Zero G Registry
2009-03-30 16:33 . 2009-03-30 16:33 d——– c:\program files\Marketmaker
2009-03-30 16:32 . 2009-03-30 16:32 d–h—– c:\documents and settings\Customer\InstallAnywhere
2009-03-30 15:59 . 2009-03-30 15:59 d——– C:\Qantas Frequent Flyer
2009-03-30 09:49 . 2009-03-30 09:49 d——– c:\program files\Belarc
2009-03-30 09:49 . 2008-02-27 13:49 3,840 –a—— c:\windows\system32\drivers\BANTExt.sys
2009-03-29 16:24 . 2009-04-04 13:36 d——– C:\Algae Patents
2009-03-29 11:45 . 2009-03-29 11:45 d——– c:\program files\Panda Security
2009-03-29 11:45 . 2008-06-19 16:24 28,544 –a—— c:\windows\system32\drivers\pavboot.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-11 16:15 ——— d—–w c:\documents and settings\Customer\Application Data\Skype
2009-04-11 15:31 ——— d—–w c:\documents and settings\Customer\Application Data\skypePM
2009-04-10 09:03 ——— d—–w c:\program files\AmiBroker
2009-04-03 06:55 ——— d—–w c:\program files\ICQ6
2009-04-02 00:15 ——— d—–w c:\program files\FxPro MetaTrader
2009-03-29 01:06 ——— d—–w c:\program files\a-squared Free
2009-03-16 03:41 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-02-28 00:17 ——— d-sh–w c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-02-23 05:17 ——— d—–w c:\program files\Dead Pixel Buddy
2009-02-16 18:03 ——— d—–w c:\documents and settings\All Users\Application Data\{66E2F539-12B6-4870-A500-7689CDE75C5E}
2009-02-14 10:04 ——— d—–w c:\program files\Universal Extractor
2009-02-13 18:48 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-29 07:20 60,744 —-a-w c:\documents and settings\Customer\g2mdlhlpx.exe
2003-09-06 06:36 234,680 —-a-w c:\program files\CDSTART.EXE
2003-09-06 06:36 1,733,816 —-a-w c:\program files\SymSetup.EXE
2003-07-21 08:04 26,934 —-a-w c:\program files\GNULicns.txt
.

((((((((((((((((((((((((((((( SnapShot@2009-04-12_ 0.13.09.38 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-04-11 10:36:49 72,498 —-a-w c:\windows\system32\perfc009.dat
+ 2009-04-11 14:10:15 72,498 —-a-w c:\windows\system32\perfc009.dat
- 2009-04-11 10:36:49 443,704 —-a-w c:\windows\system32\perfh009.dat
+ 2009-04-11 14:10:15 443,704 —-a-w c:\windows\system32\perfh009.dat
+ 2009-04-11 16:25:37 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_200.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-05 1601304]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2003-09-27 77824]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Customer\Start Menu\Programs\Startup\
TradeComm.lnk - c:\program files\TradeComm\TradeComm.exe [2008-11-30 404999]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
TL-WN321G Wireless Utility.lnk - c:\program files\TP-LINK\TL-WN321G Wireless Utility\Installer\WINXP\TWCU.exe [2009-01-16 622592]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-05 23:31 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.DVSD"= pdvcodec.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe"
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"TFncKy"=c:\program files\Toshiba\TOSHIBA Controls\TFncKy.exe /Type 28
"TFNF5"=TFNF5.exe
"00THotkey"=c:\windows\System32\00THotkey.exe
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"SSBkgdUpdate"=c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
"000StTHK"=000StTHK.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\ICQ6\\ICQ.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R3 wlags48b;Wireless LAN PCCard Driver;c:\windows\system32\DRIVERS\wlags48b.sys [2002-06-28 156672]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-06-19 28544]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-02-05 325128]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-02-05 107272]
S1 GhPciScan;GhostPciScanner;c:\program files\Symantec\Norton Ghost 2003\ghpciscan.sys [2002-08-14 5632]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-02-05 903960]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-05 298264]
S2 Tmesbs;Tmesbs32;c:\program files\TOSHIBA\TME3\Tmesbs32.exe [2002-09-06 77824]


— Other Services/Drivers In Memory —

*Deregistered* - AegisP
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - Arp1394
*Deregistered* - Aspi32
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - avg8emc
*Deregistered* - avg8wd
*Deregistered* - AvgLdx86
*Deregistered* - AvgMfx86
*Deregistered* - AvgTdiX
*Deregistered* - BANTExt
*Deregistered* - Beep
*Deregistered* - Browser
*Deregistered* - Compbatt
*Deregistered* - COMSysApp
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - Dnscache
*Deregistered* - DVD-RAM_Service
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - GhostStartService
*Deregistered* - GhPciScan
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HTTP
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - irda
*Deregistered* - Irmon
*Deregistered* - JavaQuickStarterService
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - LanmanWorkstation
*Deregistered* - LmHosts
*Deregistered* - MASPINT
*Deregistered* - MCSTRM
*Deregistered* - meiudf
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - NVSvc
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - pavboot
*Deregistered* - PCIIde
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasirda
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - RpcLocator
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - ScFBPNT3
*Deregistered* - Schedule
*Deregistered* - ScsiAccess
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - Tmesbs
*Deregistered* - TrkWks
*Deregistered* - Udfs
*Deregistered* - Update
*Deregistered* - upnphost
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-04-11 c:\windows\Tasks\User_Feed_Synchronization-{8243BA94-49C8-4971-B568-5F8117DCB72F}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 04:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
IE: &ICQ; Toolbar Search - c:\program files\ICQToolbar\toolbaru.dll/SEARCH.HTML
Trusted Zone: bitdefender.com
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\www.update
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-12 02:27:09
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV;_0175&SUBSYS;_00101179&REV;_A3]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Controls Folder\Mouse\shellex\PropertySheetHandlers]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\01BFF40EC9B6C834F80600354B0EACBA]
@DACL=(02 0000)
"79BB0A83D277E224CBACB42A5A8DF124"=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\0FB8417F0885D3347914AB59BB450F0C]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\fca0ba.msp"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\221F0CD0C1B14D11EA6D000CF420C235]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\b9c8d.msp"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\35D1205B464EB704B9839D77C8B504E1]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\275d5.msp"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\6B4EB6F053AF15F4492A506C16406DBA]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\fca084.msp"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\6DB9693FD6475D547865C3E8B29F7676]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\1beb3e2.msp"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\7B73981E6A6E123438FB6987B71B60C7]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\275e8.msp"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\8C7742A7731173F41A5EE101AAD5DE47]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\a7fe9.msp"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\8D88AA868F834D845A1A1C5B421BDE44]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\fca0aa.msp"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\F5BDCE32BCC8C874A998E6F61E9C9E76]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\a7fd6.msp"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\0B79C053C7D38EE4AB9A00CB3B5D2472\Features]
@DACL=(02 0000)
"WebPublFiles"="]aZF&kXsf;(lf*L[_GKba}gbvW,Qmf(G'*L[H+8]b_aZF&kXsf;(lf*L[_GKba_{@h=i,nf(R8(L[JO9}X_}M^V8Xqf(Rp)L[_GKbahlT]jI{jf(=1&L;[-81-]eoT]jI{jf(=1&L;[-81-]as@O+Khtf(=V*L[JO9}X"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\79BB0A83D277E224CBACB42A5A8DF124\Features]
@DACL=(02 0000)
"X"="9!CSbHOa`AH^LbXu6rdD5UP.+3Xx)=SXC.NJ0mG`\02ImageEncodingDecodingPlugIns"
"MIME"="URuxK_zbk8CPpt&6@=yqaowC@Kgmn?tPMoc57s$,\02ArchivePlugIns"
"Font"="kqBx`JW_e?I-^e?1w9ZAab_.d-~Jw8+KFZpSR+gC\02ImageEncodingDecodingPlugIns"
"Media"="Hv~SBRnct94mmS1_Zdq^`]~AOmAIR@+eeh4'?Mze-)%UDnvSn=_!6JzU60{9ugr1s8(AP9kc48!$smPT~0{TcaP10=CoX]%O9e3a\02ImageEncodingDecodingPlugIns"
"ACDSee"="d^i7HZo?`@O[qlZYpOP09ijjnf!}P?!UW?VD9?N2VqtTDP`?E=0(!KZ0p`eCLr}G%%8Q?AQDa7pcdR9.kj2Kt`oGA?r]ENl6nkK=6=UJnz3i=={3ZGb`F(N3Fhu^eOh$Y83chXarC!uIq+polyrLD@(U@Wddg+9sK2bg,'u+Y@7Fap3QknuPe[`8dx'eD=s`kw&LyhK;(dROGSr^Oq9U$Qehl3u_DMZvSxAsQT@hP^4+L}_mzDGSAsKsfd@gvqw^jY*]EdGT&b8;+6-=D1GoJ)1Q9q_l-qyO&q;)=mtpqBMA3Svue*oh=3s5@RF7G^JjAvac@VX%}!t2?U)RTl,m@}6N*KJtFUgw@-7h,?d[.M]'9bY+dG+C=Thg.C.x]2F07-v9=Top9[tUT*MwCLge7pFrcp0g=)e'[WRkl$J)aCjzT0d%A)(sOD$Vh&{$wikM@{)D@)XVp2yAY&gjYRyX;_34l8?3LT2?xQYtOT5Z9*ZO4=e,$&DuTtpDS;=?+]s6rS?b?9mpYq)t7u6yTR%3R[AaFWoN8ru&?YKUQm{3n?=y[X)m`ZXJVsQw0Q*~LO=$0O{&XLU-;+7d~l%QYf{8nBD?XkaPtdjtwfy~iG%@OtmSx^Isj$@3Bdyg23{9cGnC8]kA~v8vv[lLqi?=}QqJUhg`rwy8K&Yn;{E.?%xc^e{1SHiUD1MFhV%0?Bt,yCECF=thxHZut0K*9Idzt3J@+CPf14xbr!Ga=*sfAv9L_11[WU6j=I+y=X$t]sQ%VYD=5Vt*Umk`@9K,S&IGNGhB3;&5,B^pf(V%eqFgkW_B83&5,B^pf(V%eqFgkW_BBsu{dRF1g(Qpy?VXB]2dKsu{dRF1g(Qpy?VXB]2d?su{dRF1g(Qpy?VXB]2d8su{dRF1g(Qpy?VXB]2dNsu{dRF1g(Qpy?VXB]2d"
"Filters"="c@VX%}!t2?U)RTl,m@}6@oF'u@$HS@}V6NwGuf@ymN&%.00DG=$ok!FaK7.z\02FotoCanvas"
"ImageEncodingDecodingPlugIns"=""
"ArchivePlugIns"=""
"DevDetect"="Xr,7,7U].9A2Hm5GP^q2Z3C^kD~$%?=4Y5Jh5).*Eb{Ah'Aur@MHHFRv.9ys"
"FotoCanvas"="+OREZ&ecp;?CR&U;[eNr-q7d~l%QYf{8nBD?XkaPtdOg0)Z2PL.=bIdFkpt)k9@3P}o$gC??KA4]b{.dmQr}W6-YVd*9c'Pq@l3ZI4'}'cljHMI9k@,Biry31!wOteqf]U!?8AcXOK}erqr+vv,zj*B=@gAF${V{0ti(I.DdY1+AR'7y5SZqBQ}*LRV$U~*=*L^3gT$Hz7"
"FotoSlate"=".ORe&j;%}?=_7gF@Gm_GQrtVsY*LS8=$B9F^jo2?Tf'wSkjnJq=bRS%mh5P.$+ox(]qE7b=X8+ncCoczCD=7n_h=RSAxZa*'yo&_jao@=h~2(bAGK3gKv1c5QnOa$^~DOP@?k,EIE=Rp'D6d)2BhOc@.{tWf'=f@wW7^U$PulVA9v!_E+*JnrcxeW@R'V!@Ic}~&1pH(8=zV=V-9U19Zc+$ht}QVy8ejfWb%0$@KDWrUk8*lq%EXPO!1V6@7dK^,[r`tcmXh8TRKW.9~Vj%CBwlC'ZN[P]kWB[=T`$8(^-Z.EwAQPQzA@3?A'A_M5_PhKKQK4Fx1)k?snbjeR6r3&ELt;@P(53Q9diF,EJ@$Wm6J&'Tb)LA9Lp'N*73LgE6B7cFX$z2@LfO6B72]HO3XJMV6@J+AR]nnE!s+s)xSx4{.{,H@H+Fvj(BEZ=k2m'N^!bO?B}UUKlq!,xN6H8_*yKA=pnc^ba_YQpwRNKvV?LL9oz1Q2FgKFKnxs4rYG[[=)c@T0^BVrl7AE&6[j]g9NKv.WkV`7GTd6aZ*k+EAg6AHAMo=W(-^R4fVB2-A[F.RR0.{qC{}Q9R3chw9[+M'IW._W[FfFCovX,)?dHYyF(uAZ!K1!caQT=C9*g5=LE4L7B4[g1{qV,i=%JQ1=.%-+9tTRG=-OsS@kxn,ovz`Z+lmy!]s0}n@so@^P?]&^ks3B$aalC2@qhv%QY2=iTL^in?)oGY9$zkuCT_{Oh@37ATb@+%@VRjcG~wVTSG.)mJk-r%=Sb.WJ?[EnzK9-SWW{Ef8fhZ{+[0`@(X^`&4U-u0=5]*dH2L(=L@O1rzNQTR?kSq,.WomR0_fotd^N9IA]URsM$[rb!_fqW_eU`+9TVMoU~'@'C[Yn4Ltt^V?Z1]l6T&ep;]'Pci1R`0u=FDZX2i%OYvi.C0dm9Oz9[DM2V]c1k_pb$z=OD)b9zjtjFa[SHapXSO3gjBw8768KV)8ljfdK0N6BW~{99gg(^?E.WC}Ggu8[?}n9}MN.(k0$DEofWSYRS~r=d!JdN9DF{5oS)yd8SJi?bNXrTwmjDBulO)^}3nz=RWoY1$P^EIoM4JnLQ5t@_W7Tjld8=&^LId9qfx7@_BtAEogjjzi(51G'luK@[f^!Tk-Y&YeDb;]V$oFz9jFVLYGRm^Lj]=Mw*k~~@&$K[Ae}f?x45PVgm'OaA@X.'l2YUgO~i{b`SR8N==N]%W~H&%0sM~`U5Jpd8gJAFgt-^Z5hGg%(o[Uj9pXS&1KgBWM+txdbmD^UA0&i2ofoK00NFdjg5Y.LAm;?J7+laR_v53YD(VMm19YnVI2*l]zoZCim4+eqP90&n;^[_HCL266MUvkmpe=CVX.3L{3Mc2],CyVN}O9{$^])Gv!nQr`xa3E@+?AxQ`P_v)h&]},yT3j!~+9-{,7IJ`7mRehM1,is=~9*i5}qo8y4E1ZrDGE6qr=0GuyXBGcRWOJ.w7D^@BA(%}I-a.a&)ajsiV}Lm%@yM%u,[3fcX2}KE5QiCQ9lF?z,-M6W7xPX[7q=v1?}$cm73Jz(Xx@@VQFSdo8nq]ux2*(3b7Y's+?*E.@@R%saicMSMpAZoujiWC?(T9ob99I7*Fi&Sc0lL;[9Gr@kS,(~[hu]PBMjrDk@5e$55e.W~mW5fAgpPy_A%ih6SHRV`iaozWyhI7+AE(L,bLpA5j(.D?0uwL,?J%wtw*{dh+[4P~My?]~8$Nj^ohzP'p-W7peu2uy=~sl_aHHaHhD(CEuO3sa?2Q$kFnYS[N9HN&4j)g3A6o{^pH0Ag)+VyT[.9+?9M8)8c`^'pq0huD'mA..@DCe8kz{%qsk2yt4O(}NAgir?MCPL%nkj-B)(,,69=NS~9hSul$1GYuP'DMY@77~jer1bV-xd1-?`CX*A%57Bd9`$*D5-2&pVV;{v8=3KGRzHf@(`-MMi],Da=xf7EwiJ$WnVZRR3N+Y$9l_SIv$nCD4m5.iFsFqY@e^){P=O'NTG[T]9EtHf8S`8vZJE4z-w^s@8@=J.A],7wwTR0td{{Go-~0~A@Q6+09aKfVnu-F+10i{1AHl&j0SKh;'nM+IAW.uWr@TU@Dvb8bu=ivVi%.]sT@8gqgMmE3?thuttHuItz8-9}5Q4p,L_4}ZIW!`mR9yY^A=0M%B3pT(tdtm!!94kj_0]FpFkbgHtTdR_T@DOLq!3DR$0Q8x54tZ?t85&ty;*TML'R$wOK%F}6g9n0efG'QOe,^1z5d`oi{?JR8iqol=@)nR@cQNWDL?fP61m0afWE~gH3$@n4r8*apBmF?9djFv%9z?`PbACPqkfP0^Xot{}QtPz@s=^piwAPc~YNNnNd!_-Wc8PQ5CO~^p-FBUI)8sHu!@rs0afNq}jQTuXF=,(ll?}p0C]wP${[nQ_LX,LLZ9mVn}VTjYCY*LK{%+-f,=yxZn)-)ybH@ZOUK^f2%=rzxfWOjwDC9(yq_$eU&?j'p-R}=k*Iz=]6AOdp[=&zwrSkcU8SDp;!Mk7bgh9gE0qoiq2i]Dk5&]k(O,=1V5w,K(76mW1X-E_r@m@K_TS?VueEb"
"ACDSeePowerPackRetail"="{eckUP`Ji@8sZ~E}I_8dSqQQLMUQ'90PcL)3%AS0I[l%Qc^90Ao]4B_aEY6+m41E5TgZ@?e9g?oO6HR`\02ACDSee"
"ACE"="N7b[8Y'bF=n?^KhMgYr1wr~n7X9?=9aY1sPd%D_RmTm0oq@qi8h}Tk`M[A(n\02ArchivePlugIns"
"Adobe"="L-MP*7l=m@M=,8Ce^S@Uu?PiJVO,-?ojL+T0FL[A\02ImageEncodingDecodingPlugIns"
"CommandExtensionPlugIns"=""
"Archive"="F4%gcQ=ra8*'bNy0jU*^+`VY)TXgTApP%ef'kHo6\02CommandExtensionPlugIns"
"ARJ"="tBL`v?!DHA%$8]kZ73(nT@L?c(jiW=SD03.$DboB\02ArchivePlugIns"
"CAB"="Bzn}r329q=R$=A`$z(CE,3+Tr.47{?iw*2!T0_sL\02ArchivePlugIns"
"CameraPlugIns"=""
"CanonPS"="gn5X&KEB;%@k3q)IO&=3YHyDoNC)bg=-I~diWZOC@[C^^C4=h]9ugh@bfQ[Fdl`P8))0T!9cl-_1r4y~mrqO+a78fA=IM?LV'6[KsoDYB!FFd^=N{i-8Skt!Jy-TA2dFzs?Z'T_viwrMUCkqkJP'oNA3AV&v0t9;@w`Ai!R^rTg9(L}cTi'boO~Yug1R=a[8~0X9Hd,B%&qE.q;(AH'x@WZ[9E7I)m8bprwFGMQL?(i'f??!ye%uNW,B3*tG?dk6tc]S3v@hjh9!bCe09cat82Kie4$K8dkHTB%6AUS0pCq94q]7t0(WU7PG9jEU]eI!9gzEzV1g-n[`?,LvESQEgHj$?$z@~Iy]?76rb.J`q=(fbO)bGWf`?68lQHC8@Jp'P4+DUdGV@**1?X%M~`G_v2ThcBxR@a4MMuDSr)6L{^@5nO=m@?9}xmDW3K1zShP3VzVQAt{jlu}Rua[@@x_[@r}'=fYu![.k4ge8M,TWf-rV?I4tXED}Y-w)WYgnh2Ep8t,`*Pos@J%UZLUAFSsU=}DS8tLT$Yb\02CameraPlugIns"
"Canvas"="xK{cITqadAX){Rofa&?c\02ImageEncodingDecodingPlugIns"
"DFinder"="S!RyzgclX?1NzLZ_W=%@=4G6LVa9eAOEx3lON^h0\02CommandExtensionPlugIns"
"Digita"="J(uHT=1p$9Fav$VSJ!F[~oeIP_P`p=',`(C67-&x6s7SuplR9;=ypy$`(XP@xpoyL7TDKJ?$8h%p@MTt**4['+oVhM@HYQYV-J)y[Hz)E3&YXf;=,%xlDWcdh$,8c(TWF.HA}ORe_0Tnb@?V7BKrCz!?O0b&B;]'0ZW\02CameraPlugIns"
"DjVu"="Ku[gK-G5u=-2hsoNk(ZfMKkB4{HBY??iOSq0B!'%\02ImageEncodingDecodingPlugIns"
"Email"="=vcJcYlR[?Bvqfu'@[sse!neJmMV6@XdVs7{Mg64\02CommandExtensionPlugIns"
"Encryption"="ws=`aph,Q=6fCGW{'%StH9V+HMh44@]A},=,0],B\02ArchivePlugIns"
"FotoCanvasPowerPackRetail"="W9td=3,%MAY[5T`bRgP]5j4_0,F8?@TZlm]-~Ova4mu6]){+-=V*KFhKb,qd\02FotoCanvas"
"FotoSlatePowerPackRetail"="!NviH&Z;%t?gV=a_9P(VxKJhx?]VW-9WZ%8j*fLQ5if,[wF7@z=YSi]VIIrai\02FotoSlate"
"FPX"=",*IXg-='S?_'W'jvI`fhd@,RhAnz.9C7,MgH?d@mS]-l'.bNj8m}T1p&QUrl;\02ImageEncodingDecodingPlugIns"
"HPC20"="cSA_CKN!u8jx^Sr]fh9&\02CameraPlugIns"
"HTML"="5+Yg]+YDy@a$R{'kT3[@\02CommandExtensionPlugIns"
"ICN"="99}(ru=*Z9qA@FO}0fFsqk,o]Xf*69f4ev3,U$RX\02ImageEncodingDecodingPlugIns"
"ICO"="RYX+B$xBF?pt+&8^?Bx69-HbLCA$3=x!R1zM.m*q\02ImageEncodingDecodingPlugIns"
"IFF"="S~FM&qf0H;@}j8.7c*cUOu0s@E{?Kz?5AXVRDlK4-\02ImageEncodingDecodingPlugIns"
"KDC"="PXq4Z~j6$@yq3w8a=@cw!Kb[y929Y={t1(IBcyMXRgk6Q1]x)?T5x-E'^+ql\02ImageEncodingDecodingPlugIns"
"Kodak"="\02CameraPlugIns"
"KDC120"="PXq4Z~j6$@yq3w8a=@cwTVkxzW_?q?cc]A3pNs.(ZS!!eqg}a9QJNcmeva.YM=gv^xYS8@Be*Dp-dmcF5&0wST[Bl8UV$el6=8RfI1pRbQFo`9-+iwobN^YzK9Fg.Uo5N9V1sF1}+okg\02Kodak"
"KDC210"="ndw.5pbxQAxND-KnIxf3TElEO!}It@FKBA-k*NzVqi50QxEBo99OCc-vV.2R`DRA75&+`8Z[kjhp6znoR9SzjK6QL?,e*$0nyt7i\02Kodak"
"KDC265"="ZS!!eqg}a9QJNcmeva.YM=gv^xYS8@Be*Dp-dmcF5&0wST[Bl8UV$el6=8RfI1pRbQFo`9-+iwobN^YzK9Fg.Uo5N9V1sF1}+okg*zXIp!MN!=.2E0b!Z~_eG{_w[mhz8={K)yDO=hWH0(DX'dVWb9mz9Yoj@N1=V}1sumMgSAWV.~zzw(x[\02Kodak"
"LHA"="QC!U,9?gY=ZJyOUg!YMVIa1mPfSkD9^X~?GMl,pD\02ArchivePlugIns"
"MAG"="yLr4cB{9c?}`xa$+mfYrir`z'AY]cAiXT!2mzZL9\02ImageEncodingDecodingPlugIns"
"PaneExtension"=""
"PhotoCD"="p1Ao[sa]AAqJyZ&[d@hV0L[.M=YNKAcHPgo}G?&F;\02ImageEncodingDecodingPlugIns"
"PIC"="N2G*v@%bj80m@J,eIS`t2D&ymg27i9g;,9pw54a7f\02ImageEncodingDecodingPlugIns"
"PICT"="F4}_QE}7`8mWBdAeO2paGINQ65aMk=2(ni,`*E7@\02ImageEncodingDecodingPlugIns"
"PIX"="hVq.ZMza_9.Mv59U-m3iorqQ78yaj9]Q*VC=B[fP\02ImageEncodingDecodingPlugIns"
"PNM"="nM(2v.`e}8'gpE%=z8*oTO[Q3ucmr9bT)6YhPFl.\02ImageEncodingDecodingPlugIns"
"PrintsGifts"="Yv+Huydr^@&E;``'nK'{gJntb7~NbC9'I!Yv?smnS\02PaneExtension"
"PSD"="A16Z`Libo@miJm+z4_FLb*&A;`B3b(A{vPq&q;,({S\02ImageEncodingDecodingPlugIns"
"PSP"="JWZm6dwMX=@8MBW%P~LICMPHH.B$F=IKI4$WKf8V\02ImageEncodingDecodingPlugIns"
"RAR"="4eXBkrCH0@6aP*hixQp+RlL-8!Q-i=!3b.a4SP5K\02ArchivePlugIns"
"RAS"="y{ZxQvQxT?_O@7^348yhi(c~?uf_z8NX6XUtOb[X\02ImageEncodingDecodingPlugIns"
"RSB"="Wjot!T2r-9*FRV.gNc}^2b1_n&lov8;[]ja8=ws@)\02ImageEncodingDecodingPlugIns"
"SendPix"="jB3y@EXo(9hR(=m(rMIt$n{5._Pq[A(n_3Cxd8yRrjwg8.gFQ9%6Q84-Uh6=\02CommandExtensionPlugIns"
"SGI"="v~0rhJ)!]@4Lz2MNhL*(_^twL!rxv@T)6?&JxZGo;\02ImageEncodingDecodingPlugIns"
"SII"="]oN`b'7n6A5y0_3W%GL5\02CameraPlugIns"
"SusieArchive"="O&PCno;$pDAcPr15nnj8sp!yjFY@Vo?vBoK5'v!,E\02ArchivePlugIns"
"SusieImage"="^&nYuKuGn;@V!pm$uUdv'C^Iv6!l?ZAdAMsl?5z.B\02ImageEncodingDecodingPlugIns"
"TGZ"="C91zKY5.l=g@)^OJw=7nH12x%@TWX@I_xL^p5p+B\02ArchivePlugIns"
"UUE"="ctW}TJKVU9kY]'a6q.m99=7pXTGLr8WVI1I+(4M!\02ArchivePlugIns"
"ZIP"="!ZuWyJqoVA?6j73p}e}%3$dP.jfGl@[Uq8*dh.tK\02ArchivePlugIns"
"CrossSellHelp"="z}{GOg7UT9%gPXnP%qa)\02FotoCanvas"
"PhotoWorks"="XIQ*=UOL}?^FfJ_Z&=[J\02ACDSee"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\79BB0A83D277E224CBACB42A5A8DF124\InstallProperties]
@DACL=(02 0000)
"RegOwner"="Peter C. Winch"
"RegCompany"="none"
"ProductID"="61"
"LocalPackage"="c:\\WINDOWS\\Installer\\d734a.msi"
"AuthorizedCDFPrefix"=""
"Comments"="This database contains the necessary files and logic to install ACDSee and additional support programs and plug-ins where appropriate"
"Contact"="Technical Support"
"DisplayVersion"="6.0.2"
"HelpLink"=expand:"http://www.acdsystems.com/English/Support"
"HelpTelephone"="[removed]"
"InstallDate"="20031215"
"InstallLocation"="c:\\Program Files\\ACD Systems\\"
"InstallSource"="c:\\WINDOWS\\Downloaded Installations\\{B0CC1A89-E31E-455D-85F9-E168107BAC9F}\\"
"ModifyPath"=expand:"MsiExec.exe /I{38A0BB97-772D-422E-BCCA-4BA2A5D81F42}"
"NoRepair"=dword:00000001
"Publisher"="ACD Systems Ltd."
"Readme"=expand:"\"\""
"Size"=""
"EstimatedSize"=dword:0000e005
"UninstallString"=expand:"MsiExec.exe /I{38A0BB97-772D-422E-BCCA-4BA2A5D81F42}"
"URLInfoAbout"="http://www.acdsystems.com"
"URLUpdateInfo"="\"\""
"VersionMajor"=dword:00000006
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:06000002
"Language"=dword:00000409
"DisplayName"="ACDSee 6.0 PowerPack"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\8756E3AD9AC3968459B7C1B4C8BC3648\Features]
@DACL=(02 0000)
"Titler"="mn6(6GwQ$?cxVktbHkE9VEqqhyd9^?!bScoo)Lf8698X]YlG8?r)Pu&x;]tFu\02Sample_Files"
"Sample_Files"="mn6(6GwQ$?cxVktbHkE9VEqqhyd9^?!bScoo)Lf8698X]YlG8?r)Pu&x;]tFukN'L9Kl@W9_L,mJ%&!I@"
"Tutorial"="jP(T%hu92@$%paK8lhnmHgdQ5z~d^A7+{VR9%09,"
"DVD_VRWriter"=""
"CNC_3DArrange"="e%!@gE?u{9l86i+Hv6bO"
"pal"="9ua-{)=}c@3o@Wby=2Q$\02Program_Files"
"Program_Files"="bC,m8i'Ko9Pg{bdzQ4ff-JscgT!XWA}yjj1xvIKr-Rh9!lrcO=dhwSoRE5n%h8z[=@Oo}?35+5lMkI}02cH^=Hj-_@jkulxQ,+(^(%2ivb@([removed]]rFg]f2]bR2}4ks?mdvyh?x=^ljTLO'P.uZ==(7]6^{e?)K8SW=Zm%c9{)lZ!u*8}w%_tIW'iW+Abej4vym']$2PRiW6j,dA(-SrUT&Ica;[D-Iu!^pz?T4[kx]YuM8pUq@r}*~,@g[Dt$eXtr-dEieE'GcbAdtl.Tql33UvG{S[M0bK9wb^`a?DW)p&Z;{^K`Ckl@zR(]&sO7Ew8;`q)ADaww9~+FIlg0{6,Im2S^j%VRAuX'78eqg*+D?L_'9Lc'APo1B%='0!x*e&XrO1M;~=uMkzb,zae5tV3LUfPMj=&uh;__5&,FK.^f5oX!Pe?UD[8=^Xz.LfW~6{z[~~9YwOrl^6$&8FHr,WGAy{?-XmGqZ&@d['%1V7FA5R=5UQ@s9^fMuu53qJ=PD7?{8j}v+EfOH{G`DHhq.h9B$MZMNXMiP~^l9.c9cz8=[fj'DQi`m*GHBX{}j,9!fu]%?HOLjwHf*29bV(?YX3iI5n{Y%ja_)uW)mz?}26LK?a63eMos'mmf^^=Lx$v'ezrH5Fj_@Xcky]9R(G02mmg^ga?XG)b-mk@K+A$Dey0Q=eeaT5oSiz?(i-y]sdBZk5n}[Oo({_@T_2vm[[b(Q!$uWqX}`^8sEU}'iT)7t*P%X2aL%9=jZX-VN8]}[(6rOGx97f=4dX3D{nP-_=4WH!aUnd8XF,gmbBQdqu@_W=p~7p?exlfPUS8O.XBLLKz7Lc8fRMj?_^}YP"
"Movies"="kN'L9Kl@W9_L,mJ%&!I@\02Sample_Files"
"CNC_VideoGift"="XLx6k8~Dc?aEB=^9p_+*b66ekq_Gr@,VH79TD)4!.9hq0.^=o=^nr36pFur==yZi?jCWp9`Si+D=&otz;"
"mpeg2_Files"="6]3Y%=(4^@_90zF8h=2m3KJxH1T28@aN$TnL~]KIcGY6sJfl3@h+S`HS3YY%[l3Me1a){?oL0,330r+4GZjdYh,zL?t0t4F))-o+{kp}y^%K6?jKf={!4kK8"
"Help_Files"=""
"DVDR_Record_Module"="9T0x7~{Av9?_3Oc0CSYZ"
"CNC_DVDfunSTUDIO"="d^&GFgLgi;@-*86,VFa@'"
"Multi"="f+$j6fuA&@SCHDDK)6IV"
"English"="\02Multi"
"SwitchProducts"=""
"VED_PACKAGE_311E"="\02SwitchProducts"
"DVDRAM_311E"="\02SwitchProducts"
"DVHS_Driver"="RGH8utfEt=jP2-22s']0\02Driver_Files"
"Driver_Files"=""
"ntsc"="t3{tu1kpb=gb'6OFV+Pk\02Program_Files"
"DVHS_Record"="(O,Z!0ukF@$b3bP`8{)ZvH8f)K.$q81h$f]f'anYM=exZt&!h=m-T-!x6*74"
"Meiavc_Driver"="@L(68s*`_8bZZ-_i%b5.\02Driver_Files"
"QFE_Packege"="bC,m8i'Ko9Pg{bdzQ4ff\02Driver_Files"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\8756E3AD9AC3968459B7C1B4C8BC3648\InstallProperties]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\296bf8a.msi"
"AuthorizedCDFPrefix"=""
"Comments"=" "
"Contact"=" "
"DisplayVersion"="3.20.000"
"HelpLink"=expand:" "
"HelpTelephone"=" "
"InstallDate"="20030726"
"InstallLocation"=""
"NoModify"=dword:00000001
"NoRemove"=dword:00000001
"Publisher"="Panasonic"
"Readme"=expand:" "
"Size"=""
"EstimatedSize"=dword:00006212
"SystemComponent"=dword:00000001
"URLInfoAbout"=" "
"URLUpdateInfo"=" "
"VersionMajor"=dword:00000003
"VersionMinor"=dword:00000014
"WindowsInstaller"=dword:00000001
"Version"=dword:03140000
"Language"=dword:00000000
"DisplayName"="MotionDV STUDIO 3"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\8A0F841731866D117AB7000B0D410201\Features]
@DACL=(02 0000)
"other_US"="t)Sf^.oCg(^O3Xa,A]FH"
"extra"="xqyr1p^$G@n}-$+KWS4r"
"jrecore"="SDg%C'KCg([I3Xa,A]FHSDg%C'KCg([I3Xa-JxbHSDg%C'KCg([I3Xa.S9!ISDg%C'KCg([I3Xa9dT3(lp-To$qd*?do.B$rpHeT"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\8A0F841731866D117AB7000B0D410201\InstallProperties]
@DACL=(02 0000)
"RegOwner"="Customer"
"RegCompany"=""
"ProductID"="none"
"LocalPackage"="c:\\WINDOWS\\Installer\\16ff83b.msi"
"AuthorizedCDFPrefix"=""
"Comments"="http://www.java.com"
"Contact"="http://www.java.com"
"DisplayVersion"="1.4.2_01"
"HelpLink"=expand:"http://www.java.com"
"HelpTelephone"="http://www.java.com"
"InstallDate"="20031201"
"InstallLocation"=""
"InstallSource"="c:\\Documents and Settings\\Customer\\Local Settings\\Application Data\\{7148F0A6-6813-11D6-A77B-00B0D0142010}\\"
"ModifyPath"=expand:"MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142010}"
"NoRepair"=dword:00000001
"Publisher"="Sun Microsystems, Inc."
"Readme"=expand:"Readme.txt"
"Size"=""
"EstimatedSize"=dword:0001abe4
"UninstallString"=expand:"MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142010}"
"URLInfoAbout"="http://www.java.com"
"URLUpdateInfo"="http://java.sun.com"
"VersionMajor"=dword:00000001
"VersionMinor"=dword:00000004
"WindowsInstaller"=dword:00000001
"Version"=dword:81040000
"Language"=dword:00000000
"DisplayName"="Java 2 Runtime Environment, SE v1.4.2_01"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\BFB6BBEC807D99F46A33CB62000EE16F\Features]
@DACL=(02 0000)
"Help"="B)H`h(~iv=gv%eterg5w"
"Driver"="({1vvG&}m=&ojg;%~gO1zMPFGsq1sm9,oE`Rn=yDURKmXF7)]v8Mzj'ec&F;&5UK!ozvZ7a??!rRNK=qhg)SGhDuALv=F~jUJaJQhU@iggIe2k]AW*u+CWJidjX,-Q(N{v]8Iw!*E3%!YVf{o._1iFg(hh%!!SOt.,g{o._1iFg(hh%!!SOt.,"
"Utility"="X5HKV)hgq=LUMrk3]y2Cgy&^[8'jp?O~ubw^jFLIK$0pdmaR2@lSP&A;$e[5HHmI']!XhHAb3f^a7fm[=A%JMWfDWo9CbTROk~Ou0wq4p4+wkq?hV+j`Evuq(BJORzIFuB=Up*EWON^SpD-*tHtm`3=S&Z;[E'{VTWoJ?EkzeEg(hh%!!SOt.,]K?EkzeEg(hh%!!SOt.,V{o._1iFg(hh%!!SOt.,"
"DriverInstall"="=3trvGg}H9%N7.PdmwaH"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\BFB6BBEC807D99F46A33CB62000EE16F\InstallProperties]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\4748e.msi"
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="2.01.0000"
"HelpLink"=expand:" "
"HelpTelephone"=" "
"InstallDate"="20030106"
"InstallLocation"=""
"ModifyPath"=expand:"MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="Toshiba"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000528
"UninstallString"=expand:"MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}"
"URLInfoAbout"=" "
"URLUpdateInfo"=" "
"VersionMajor"=dword:00000002
"VersionMinor"=dword:00000001
"WindowsInstaller"=dword:00000001
"Version"=dword:02010000
"Language"=dword:00000409
"DisplayName"="Bluetooth Stack for Windows by Toshiba"
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\DVDRAMSV.exe
c:\program files\Symantec\Norton Ghost 2003\GhostStartService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\locator.exe
c:\windows\system32\ScsiAccess.EXE
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2009-04-12 2:34:28 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-11 16:34:15
ComboFix2.txt 2009-04-11 14:15:06

Pre-Run: 10,405,126,144 bytes free
Post-Run: 10,390,794,240 bytes free

542 — E O F — 2009-04-03 03:49:55
PeterPumpkinEater,

JavaRa …by: Paul McLain and Fred de Vries

Please download JavaRa (Copyright © 2008 RaProducts.org) and unzip it to your desktop.
***Please close any instances of Internet Explorer before continuing!***
Print these instructions…you won't have Internet access during this particular phase!
  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English or the appropriate language…and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location.
  • Copy and paste the contents of the JavaRa log, in your next reply.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    RegLockDel::
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0175&SUBSYS_00101179&REV_A3]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Controls Folder\Mouse\shellex\PropertySheetHandlers]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\01BFF40EC9B6C834F80600354B0EACBA]
    
    
    RegLock::
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\0FB8417F0885D3347914AB59BB450F0C]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\221F0CD0C1B14D11EA6D000CF420C235]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\35D1205B464EB704B9839D77C8B504E1]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\6B4EB6F053AF15F4492A506C16406DBA]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\6DB9693FD6475D547865C3E8B29F7676]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\7B73981E6A6E123438FB6987B71B60C7]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\8C7742A7731173F41A5EE101AAD5DE47]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\8D88AA868F834D845A1A1C5B421BDE44]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\F5BDCE32BCC8C874A998E6F61E9C9E76]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\0B79C053C7D38EE4AB9A00CB3B5D2472\Features]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\79BB0A83D277E224CBACB42A5A8DF124\Features]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\79BB0A83D277E224CBACB42A5A8DF124\InstallProperties]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\8756E3AD9AC3968459B7C1B4C8BC3648\Features]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\8756E3AD9AC3968459B7C1B4C8BC3648\InstallProperties]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\8A0F841731866D117AB7000B0D410201\Features]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\BFB6BBEC807D99F46A33CB62000EE16F\Features]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\BFB6BBEC807D99F46A33CB62000EE16F\InstallProperties]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
TomK,

JavaRa log followed by CombiFix log
==========
JavaRa 1.13 Removal Log.

Report follows after line.

————————————

The JavaRa removal process was started on Sun Apr 12 03:38:33 2009

Found and removed: C:\Program Files\Java\j2re1.4.2_01

Found and removed: C:\Program Files\Java\jre1.5.0_06

Found and removed: C:\Program Files\Java\jre1.6.0_03

Found and removed: C:\Windows\Installer\{7148F0A8-6813-11D6-A77B-00B0D0142010}

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4

Found and removed: Software\JavaSoft\Java2D\1.5.0_04

Found and removed: Software\JavaSoft\Java2D\1.5.0_06

Found and removed: Software\JavaSoft\Java2D\1.5.0_11

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510006

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510006

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510006

Found and removed: SOFTWARE\Classes\JavaPlugin.150_06

Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_06

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_06

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510006

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510006

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150060}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Classes\JavaPlugin.160_03

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_03

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_03

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160030}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7148F0A8-6813-11D6-A77B-00B0D0142010}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F841731866D117AB7000B0D410201

Found and removed: SOFTWARE\Classes\JavaPlugin.142_01

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_01

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4.2_01

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.4.2_01

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_06

Found and removed: Software\Classes\JavaPlugin.142_01

Found and removed: Software\Classes\JavaPlugin.160_03

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_03

Found and removed: Software\JavaSoft\Java2D\1.6.0_03

Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_03

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_06\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_03.b05\

————————————

Finished reporting.

===============CombiFix Log=========
ComboFix 09-04-04.01 - Customer 2009-04-12 3:48:19.3 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Customer\Desktop\CFScript.txt
.

((((((((((((((((((((((((( Files Created from 2009-03-11 to 2009-04-11 )))))))))))))))))))))))))))))))
.

2009-04-12 01:17 . 2009-04-12 01:19 d——– C:\Rooter$
2009-04-12 00:08 . 2009-04-12 02:27 54,156 –ah—– c:\windows\QTFont.qfn
2009-04-12 00:08 . 2009-04-12 02:22 1,409 –a—— c:\windows\QTFont.for
2009-04-11 20:02 . 2009-04-11 20:02 d——– c:\documents and settings\Customer\Application Data\Malwarebytes
2009-04-11 20:01 . 2009-04-11 20:02 d——– c:\program files\Malwarebytes' Anti-Malware
2009-04-11 20:01 . 2009-04-11 20:01 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-11 20:01 . 2009-04-06 15:32 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-11 20:01 . 2009-04-06 15:32 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-04-06 17:54 . 2009-04-06 17:54 d–hs—- c:\documents and settings\NetworkService\IETldCache
2009-04-06 16:02 . 2009-04-06 16:02 d–hs—- c:\documents and settings\LocalService\IETldCache
2009-04-06 15:59 . 2009-04-06 15:59 d——– c:\windows\system32\GroupPolicy
2009-04-06 15:59 . 2009-04-06 16:00 d——– c:\program files\Windows Desktop Search
2009-04-05 17:26 . 2009-04-05 17:26 d——– c:\program files\Trend Micro
2009-04-04 07:13 . 2009-04-04 07:13 d–hs—- c:\documents and settings\Computer God Mk 2\PrivacIE
2009-04-04 07:09 . 2009-04-04 07:09 d–hs—- c:\documents and settings\Computer God Mk 2\IETldCache
2009-04-04 07:08 . 2003-01-07 09:31 d——– c:\documents and settings\Computer God Mk 2\Application Data\InterTrust
2009-04-04 07:08 . 2003-01-07 10:12 d——– c:\documents and settings\Computer God Mk 2\Application Data\Drag'n Drop CD
2009-04-04 07:07 . 2009-04-04 07:13 d——– c:\documents and settings\Computer God Mk 2
2009-04-03 10:41 . 2009-04-12 03:48 d——– c:\windows\system32\CatRoot2
2009-03-30 17:36 . 2009-03-30 17:36 d–hs—- c:\documents and settings\Customer\IECompatCache
2009-03-30 17:23 . 2009-03-30 17:23 d–hs—- c:\documents and settings\Administrator\IETldCache
2009-03-30 17:18 . 2009-03-30 17:18 d–hs—- c:\documents and settings\Customer\IETldCache
2009-03-30 17:11 . 2009-04-01 12:30 d–h-c— c:\windows\ie8
2009-03-30 16:33 . 2009-03-30 16:33 d–h—– c:\program files\Zero G Registry
2009-03-30 16:33 . 2009-03-30 16:33 d——– c:\program files\Marketmaker
2009-03-30 16:32 . 2009-03-30 16:32 d–h—– c:\documents and settings\Customer\InstallAnywhere
2009-03-30 15:59 . 2009-03-30 15:59 d——– C:\Qantas Frequent Flyer
2009-03-30 09:49 . 2009-03-30 09:49 d——– c:\program files\Belarc
2009-03-30 09:49 . 2008-02-27 13:49 3,840 –a—— c:\windows\system32\drivers\BANTExt.sys
2009-03-29 16:24 . 2009-04-04 13:36 d——– C:\Algae Patents
2009-03-29 11:45 . 2009-03-29 11:45 d——– c:\program files\Panda Security
2009-03-29 11:45 . 2008-06-19 16:24 28,544 –a—— c:\windows\system32\drivers\pavboot.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-11 17:38 ——— d—–w c:\program files\Java
2009-04-11 17:34 ——— d—–w c:\documents and settings\Customer\Application Data\Skype
2009-04-11 15:31 ——— d—–w c:\documents and settings\Customer\Application Data\skypePM
2009-04-10 09:03 ——— d—–w c:\program files\AmiBroker
2009-04-03 06:55 ——— d—–w c:\program files\ICQ6
2009-04-02 00:15 ——— d—–w c:\program files\FxPro MetaTrader
2009-03-29 01:06 ——— d—–w c:\program files\a-squared Free
2009-03-16 03:41 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-03-07 18:34 914,944 —-a-w c:\windows\system32\wininet.dll
2009-03-07 18:34 43,008 —-a-w c:\windows\system32\licmgr10.dll
2009-03-07 18:33 420,352 —-a-w c:\windows\system32\vbscript.dll
2009-03-07 18:33 18,944 —-a-w c:\windows\system32\corpol.dll
2009-03-07 18:32 72,704 —-a-w c:\windows\system32\admparse.dll
2009-03-07 18:32 71,680 —-a-w c:\windows\system32\iesetup.dll
2009-03-07 18:31 48,128 —-a-w c:\windows\system32\mshtmler.dll
2009-03-07 18:31 45,568 —-a-w c:\windows\system32\mshta.exe
2009-03-07 18:31 34,816 —-a-w c:\windows\system32\imgutil.dll
2009-03-07 18:22 156,160 —-a-w c:\windows\system32\msls31.dll
2009-02-28 00:17 ——— d-sh–w c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-02-23 05:17 ——— d—–w c:\program files\Dead Pixel Buddy
2009-02-16 18:03 ——— d—–w c:\documents and settings\All Users\Application Data\{66E2F539-12B6-4870-A500-7689CDE75C5E}
2009-02-14 10:04 ——— d—–w c:\program files\Universal Extractor
2009-02-13 18:48 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2009-02-05 13:31 10,520 —-a-w c:\windows\system32\avgrsstx.dll
2008-10-29 07:20 60,744 —-a-w c:\documents and settings\Customer\g2mdlhlpx.exe
2003-09-06 06:36 234,680 —-a-w c:\program files\CDSTART.EXE
2003-09-06 06:36 1,733,816 —-a-w c:\program files\SymSetup.EXE
2003-07-21 08:04 26,934 —-a-w c:\program files\GNULicns.txt
.

((((((((((((((((((((((((((((( SnapShot@2009-04-12_ 0.13.09.38 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-04-11 10:36:49 72,498 —-a-w c:\windows\system32\perfc009.dat
+ 2009-04-11 16:30:32 72,498 —-a-w c:\windows\system32\perfc009.dat
- 2009-04-11 10:36:49 443,704 —-a-w c:\windows\system32\perfh009.dat
+ 2009-04-11 16:30:33 443,704 —-a-w c:\windows\system32\perfh009.dat
+ 2009-04-11 16:25:37 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_200.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-05 1601304]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2003-09-27 77824]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Customer\Start Menu\Programs\Startup\
TradeComm.lnk - c:\program files\TradeComm\TradeComm.exe [2008-11-30 404999]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
TL-WN321G Wireless Utility.lnk - c:\program files\TP-LINK\TL-WN321G Wireless Utility\Installer\WINXP\TWCU.exe [2009-01-16 622592]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-05 23:31 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.DVSD"= pdvcodec.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe"
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"TFncKy"=c:\program files\Toshiba\TOSHIBA Controls\TFncKy.exe /Type 28
"TFNF5"=TFNF5.exe
"00THotkey"=c:\windows\System32\00THotkey.exe
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"SSBkgdUpdate"=c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
"000StTHK"=000StTHK.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\ICQ6\\ICQ.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R3 wlags48b;Wireless LAN PCCard Driver;c:\windows\system32\DRIVERS\wlags48b.sys [2002-06-28 156672]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-06-19 28544]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-02-05 325128]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-02-05 107272]
S1 GhPciScan;GhostPciScanner;c:\program files\Symantec\Norton Ghost 2003\ghpciscan.sys [2002-08-14 5632]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-02-05 903960]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-05 298264]
S2 Tmesbs;Tmesbs32;c:\program files\TOSHIBA\TME3\Tmesbs32.exe [2002-09-06 77824]


— Other Services/Drivers In Memory —

*Deregistered* - AegisP
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - Arp1394
*Deregistered* - Aspi32
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - avg8emc
*Deregistered* - avg8wd
*Deregistered* - AvgLdx86
*Deregistered* - AvgMfx86
*Deregistered* - AvgTdiX
*Deregistered* - BANTExt
*Deregistered* - Beep
*Deregistered* - Browser
*Deregistered* - Compbatt
*Deregistered* - COMSysApp
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - Dnscache
*Deregistered* - DVD-RAM_Service
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - GhostStartService
*Deregistered* - GhPciScan
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HTTP
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - irda
*Deregistered* - Irmon
*Deregistered* - JavaQuickStarterService
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - LanmanWorkstation
*Deregistered* - LmHosts
*Deregistered* - MASPINT
*Deregistered* - MCSTRM
*Deregistered* - meiudf
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - NVSvc
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - pavboot
*Deregistered* - PCIIde
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasirda
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - RpcLocator
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - ScFBPNT3
*Deregistered* - Schedule
*Deregistered* - ScsiAccess
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - Tmesbs
*Deregistered* - TrkWks
*Deregistered* - Udfs
*Deregistered* - Update
*Deregistered* - upnphost
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-04-11 c:\windows\Tasks\User_Feed_Synchronization-{8243BA94-49C8-4971-B568-5F8117DCB72F}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 04:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
IE: &ICQ; Toolbar Search - c:\program files\ICQToolbar\toolbaru.dll/SEARCH.HTML
Trusted Zone: bitdefender.com
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\www.update
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-12 03:53:31
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV;_0175&SUBSYS;_00101179&REV;_A3\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0001,0\1024x768 x 60Hz]
@DACL=(02 0000)
@SACL=
"16 bpp"=dword:00000001
"32 bpp"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV;_0175&SUBSYS;_00101179&REV;_A3\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0001,0\1400x1050 x 60Hz]
@DACL=(02 0000)
@SACL=
"32 bpp"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV;_0175&SUBSYS;_00101179&REV;_A3\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0002,1\1024x768 x 60Hz]
@DACL=(02 0000)
@SACL=
"16 bpp"=dword:00000001
"32 bpp"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV;_0175&SUBSYS;_00101179&REV;_A3\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0002,1\1400x1050 x 60Hz]
@DACL=(02 0000)
@SACL=
"32 bpp"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV;_0175&SUBSYS;_00101179&REV;_A3\Monitor:TOS5086:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0003,2\1024x768 x 60Hz]
@DACL=(02 0000)
@SACL=
"16 bpp"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV;_0175&SUBSYS;_00101179&REV;_A3\Monitor:TOS5086:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0003,2\1400x1050 x 60Hz]
@DACL=(02 0000)
@SACL=
"32 bpp"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\0FB8417F0885D3347914AB59BB450F0C]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\fca0ba.msp"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\221F0CD0C1B14D11EA6D000CF420C235]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\b9c8d.msp"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\35D1205B464EB704B9839D77C8B504E1]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\275d5.msp"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\6B4EB6F053AF15F4492A506C16406DBA]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\fca084.msp"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\6DB9693FD6475D547865C3E8B29F7676]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\1beb3e2.msp"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\7B73981E6A6E123438FB6987B71B60C7]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\275e8.msp"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\8C7742A7731173F41A5EE101AAD5DE47]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\a7fe9.msp"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\8D88AA868F834D845A1A1C5B421BDE44]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\fca0aa.msp"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Patches\F5BDCE32BCC8C874A998E6F61E9C9E76]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\a7fd6.msp"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\0B79C053C7D38EE4AB9A00CB3B5D2472\Features]
@DACL=(02 0000)
"WebPublFiles"="]aZF&kXsf;(lf*L[_GKba}gbvW,Qmf(G'*L[H+8]b_aZF&kXsf;(lf*L[_GKba_{@h=i,nf(R8(L[JO9}X_}M^V8Xqf(Rp)L[_GKbahlT]jI{jf(=1&L;[-81-]eoT]jI{jf(=1&L;[-81-]as@O+Khtf(=V*L[JO9}X"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\79BB0A83D277E224CBACB42A5A8DF124\Features]
@DACL=(02 0000)
"X"="9!CSbHOa`AH^LbXu6rdD5UP.+3Xx)=SXC.NJ0mG`\02ImageEncodingDecodingPlugIns"
"MIME"="URuxK_zbk8CPpt&6@=yqaowC@Kgmn?tPMoc57s$,\02ArchivePlugIns"
"Font"="kqBx`JW_e?I-^e?1w9ZAab_.d-~Jw8+KFZpSR+gC\02ImageEncodingDecodingPlugIns"
"Media"="Hv~SBRnct94mmS1_Zdq^`]~AOmAIR@+eeh4'?Mze-)%UDnvSn=_!6JzU60{9ugr1s8(AP9kc48!$smPT~0{TcaP10=CoX]%O9e3a\02ImageEncodingDecodingPlugIns"
"ACDSee"="d^i7HZo?`@O[qlZYpOP09ijjnf!}P?!UW?VD9?N2VqtTDP`?E=0(!KZ0p`eCLr}G%%8Q?AQDa7pcdR9.kj2Kt`oGA?r]ENl6nkK=6=UJnz3i=={3ZGb`F(N3Fhu^eOh$Y83chXarC!uIq+polyrLD@(U@Wddg+9sK2bg,'u+Y@7Fap3QknuPe[`8dx'eD=s`kw&LyhK;(dROGSr^Oq9U$Qehl3u_DMZvSxAsQT@hP^4+L}_mzDGSAsKsfd@gvqw^jY*]EdGT&b8;+6-=D1GoJ)1Q9q_l-qyO&q;)=mtpqBMA3Svue*oh=3s5@RF7G^JjAvac@VX%}!t2?U)RTl,m@}6N*KJtFUgw@-7h,?d[.M]'9bY+dG+C=Thg.C.x]2F07-v9=Top9[tUT*MwCLge7pFrcp0g=)e'[WRkl$J)aCjzT0d%A)(sOD$Vh&{$wikM@{)D@)XVp2yAY&gjYRyX;_34l8?3LT2?xQYtOT5Z9*ZO4=e,$&DuTtpDS;=?+]s6rS?b?9mpYq)t7u6yTR%3R[AaFWoN8ru&?YKUQm{3n?=y[X)m`ZXJVsQw0Q*~LO=$0O{&XLU-;+7d~l%QYf{8nBD?XkaPtdjtwfy~iG%@OtmSx^Isj$@3Bdyg23{9cGnC8]kA~v8vv[lLqi?=}QqJUhg`rwy8K&Yn;{E.?%xc^e{1SHiUD1MFhV%0?Bt,yCECF=thxHZut0K*9Idzt3J@+CPf14xbr!Ga=*sfAv9L_11[WU6j=I+y=X$t]sQ%VYD=5Vt*Umk`@9K,S&IGNGhB3;&5,B^pf(V%eqFgkW_B83&5,B^pf(V%eqFgkW_BBsu{dRF1g(Qpy?VXB]2dKsu{dRF1g(Qpy?VXB]2d?su{dRF1g(Qpy?VXB]2d8su{dRF1g(Qpy?VXB]2dNsu{dRF1g(Qpy?VXB]2d"
"Filters"="c@VX%}!t2?U)RTl,m@}6@oF'u@$HS@}V6NwGuf@ymN&%.00DG=$ok!FaK7.z\02FotoCanvas"
"ImageEncodingDecodingPlugIns"=""
"ArchivePlugIns"=""
"DevDetect"="Xr,7,7U].9A2Hm5GP^q2Z3C^kD~$%?=4Y5Jh5).*Eb{Ah'Aur@MHHFRv.9ys"
"FotoCanvas"="+OREZ&ecp;?CR&U;[eNr-q7d~l%QYf{8nBD?XkaPtdOg0)Z2PL.=bIdFkpt)k9@3P}o$gC??KA4]b{.dmQr}W6-YVd*9c'Pq@l3ZI4'}'cljHMI9k@,Biry31!wOteqf]U!?8AcXOK}erqr+vv,zj*B=@gAF${V{0ti(I.DdY1+AR'7y5SZqBQ}*LRV$U~*=*L^3gT$Hz7"
"FotoSlate"=".ORe&j;%}?=_7gF@Gm_GQrtVsY*LS8=$B9F^jo2?Tf'wSkjnJq=bRS%mh5P.$+ox(]qE7b=X8+ncCoczCD=7n_h=RSAxZa*'yo&_jao@=h~2(bAGK3gKv1c5QnOa$^~DOP@?k,EIE=Rp'D6d)2BhOc@.{tWf'=f@wW7^U$PulVA9v!_E+*JnrcxeW@R'V!@Ic}~&1pH(8=zV=V-9U19Zc+$ht}QVy8ejfWb%0$@KDWrUk8*lq%EXPO!1V6@7dK^,[r`tcmXh8TRKW.9~Vj%CBwlC'ZN[P]kWB[=T`$8(^-Z.EwAQPQzA@3?A'A_M5_PhKKQK4Fx1)k?snbjeR6r3&ELt;@P(53Q9diF,EJ@$Wm6J&'Tb)LA9Lp'N*73LgE6B7cFX$z2@LfO6B72]HO3XJMV6@J+AR]nnE!s+s)xSx4{.{,H@H+Fvj(BEZ=k2m'N^!bO?B}UUKlq!,xN6H8_*yKA=pnc^ba_YQpwRNKvV?LL9oz1Q2FgKFKnxs4rYG[[=)c@T0^BVrl7AE&6[j]g9NKv.WkV`7GTd6aZ*k+EAg6AHAMo=W(-^R4fVB2-A[F.RR0.{qC{}Q9R3chw9[+M'IW._W[FfFCovX,)?dHYyF(uAZ!K1!caQT=C9*g5=LE4L7B4[g1{qV,i=%JQ1=.%-+9tTRG=-OsS@kxn,ovz`Z+lmy!]s0}n@so@^P?]&^ks3B$aalC2@qhv%QY2=iTL^in?)oGY9$zkuCT_{Oh@37ATb@+%@VRjcG~wVTSG.)mJk-r%=Sb.WJ?[EnzK9-SWW{Ef8fhZ{+[0`@(X^`&4U-u0=5]*dH2L(=L@O1rzNQTR?kSq,.WomR0_fotd^N9IA]URsM$[rb!_fqW_eU`+9TVMoU~'@'C[Yn4Ltt^V?Z1]l6T&ep;]'Pci1R`0u=FDZX2i%OYvi.C0dm9Oz9[DM2V]c1k_pb$z=OD)b9zjtjFa[SHapXSO3gjBw8768KV)8ljfdK0N6BW~{99gg(^?E.WC}Ggu8[?}n9}MN.(k0$DEofWSYRS~r=d!JdN9DF{5oS)yd8SJi?bNXrTwmjDBulO)^}3nz=RWoY1$P^EIoM4JnLQ5t@_W7Tjld8=&^LId9qfx7@_BtAEogjjzi(51G'luK@[f^!Tk-Y&YeDb;]V$oFz9jFVLYGRm^Lj]=Mw*k~~@&$K[Ae}f?x45PVgm'OaA@X.'l2YUgO~i{b`SR8N==N]%W~H&%0sM~`U5Jpd8gJAFgt-^Z5hGg%(o[Uj9pXS&1KgBWM+txdbmD^UA0&i2ofoK00NFdjg5Y.LAm;?J7+laR_v53YD(VMm19YnVI2*l]zoZCim4+eqP90&n;^[_HCL266MUvkmpe=CVX.3L{3Mc2],CyVN}O9{$^])Gv!nQr`xa3E@+?AxQ`P_v)h&]},yT3j!~+9-{,7IJ`7mRehM1,is=~9*i5}qo8y4E1ZrDGE6qr=0GuyXBGcRWOJ.w7D^@BA(%}I-a.a&)ajsiV}Lm%@yM%u,[3fcX2}KE5QiCQ9lF?z,-M6W7xPX[7q=v1?}$cm73Jz(Xx@@VQFSdo8nq]ux2*(3b7Y's+?*E.@@R%saicMSMpAZoujiWC?(T9ob99I7*Fi&Sc0lL;[9Gr@kS,(~[hu]PBMjrDk@5e$55e.W~mW5fAgpPy_A%ih6SHRV`iaozWyhI7+AE(L,bLpA5j(.D?0uwL,?J%wtw*{dh+[4P~My?]~8$Nj^ohzP'p-W7peu2uy=~sl_aHHaHhD(CEuO3sa?2Q$kFnYS[N9HN&4j)g3A6o{^pH0Ag)+VyT[.9+?9M8)8c`^'pq0huD'mA..@DCe8kz{%qsk2yt4O(}NAgir?MCPL%nkj-B)(,,69=NS~9hSul$1GYuP'DMY@77~jer1bV-xd1-?`CX*A%57Bd9`$*D5-2&pVV;{v8=3KGRzHf@(`-MMi],Da=xf7EwiJ$WnVZRR3N+Y$9l_SIv$nCD4m5.iFsFqY@e^){P=O'NTG[T]9EtHf8S`8vZJE4z-w^s@8@=J.A],7wwTR0td{{Go-~0~A@Q6+09aKfVnu-F+10i{1AHl&j0SKh;'nM+IAW.uWr@TU@Dvb8bu=ivVi%.]sT@8gqgMmE3?thuttHuItz8-9}5Q4p,L_4}ZIW!`mR9yY^A=0M%B3pT(tdtm!!94kj_0]FpFkbgHtTdR_T@DOLq!3DR$0Q8x54tZ?t85&ty;*TML'R$wOK%F}6g9n0efG'QOe,^1z5d`oi{?JR8iqol=@)nR@cQNWDL?fP61m0afWE~gH3$@n4r8*apBmF?9djFv%9z?`PbACPqkfP0^Xot{}QtPz@s=^piwAPc~YNNnNd!_-Wc8PQ5CO~^p-FBUI)8sHu!@rs0afNq}jQTuXF=,(ll?}p0C]wP${[nQ_LX,LLZ9mVn}VTjYCY*LK{%+-f,=yxZn)-)ybH@ZOUK^f2%=rzxfWOjwDC9(yq_$eU&?j'p-R}=k*Iz=]6AOdp[=&zwrSkcU8SDp;!Mk7bgh9gE0qoiq2i]Dk5&]k(O,=1V5w,K(76mW1X-E_r@m@K_TS?VueEb"
"ACDSeePowerPackRetail"="{eckUP`Ji@8sZ~E}I_8dSqQQLMUQ'90PcL)3%AS0I[l%Qc^90Ao]4B_aEY6+m41E5TgZ@?e9g?oO6HR`\02ACDSee"
"ACE"="N7b[8Y'bF=n?^KhMgYr1wr~n7X9?=9aY1sPd%D_RmTm0oq@qi8h}Tk`M[A(n\02ArchivePlugIns"
"Adobe"="L-MP*7l=m@M=,8Ce^S@Uu?PiJVO,-?ojL+T0FL[A\02ImageEncodingDecodingPlugIns"
"CommandExtensionPlugIns"=""
"Archive"="F4%gcQ=ra8*'bNy0jU*^+`VY)TXgTApP%ef'kHo6\02CommandExtensionPlugIns"
"ARJ"="tBL`v?!DHA%$8]kZ73(nT@L?c(jiW=SD03.$DboB\02ArchivePlugIns"
"CAB"="Bzn}r329q=R$=A`$z(CE,3+Tr.47{?iw*2!T0_sL\02ArchivePlugIns"
"CameraPlugIns"=""
"CanonPS"="gn5X&KEB;%@k3q)IO&=3YHyDoNC)bg=-I~diWZOC@[C^^C4=h]9ugh@bfQ[Fdl`P8))0T!9cl-_1r4y~mrqO+a78fA=IM?LV'6[KsoDYB!FFd^=N{i-8Skt!Jy-TA2dFzs?Z'T_viwrMUCkqkJP'oNA3AV&v0t9;@w`Ai!R^rTg9(L}cTi'boO~Yug1R=a[8~0X9Hd,B%&qE.q;(AH'x@WZ[9E7I)m8bprwFGMQL?(i'f??!ye%uNW,B3*tG?dk6tc]S3v@hjh9!bCe09cat82Kie4$K8dkHTB%6AUS0pCq94q]7t0(WU7PG9jEU]eI!9gzEzV1g-n[`?,LvESQEgHj$?$z@~Iy]?76rb.J`q=(fbO)bGWf`?68lQHC8@Jp'P4+DUdGV@**1?X%M~`G_v2ThcBxR@a4MMuDSr)6L{^@5nO=m@?9}xmDW3K1zShP3VzVQAt{jlu}Rua[@@x_[@r}'=fYu![.k4ge8M,TWf-rV?I4tXED}Y-w)WYgnh2Ep8t,`*Pos@J%UZLUAFSsU=}DS8tLT$Yb\02CameraPlugIns"
"Canvas"="xK{cITqadAX){Rofa&?c\02ImageEncodingDecodingPlugIns"
"DFinder"="S!RyzgclX?1NzLZ_W=%@=4G6LVa9eAOEx3lON^h0\02CommandExtensionPlugIns"
"Digita"="J(uHT=1p$9Fav$VSJ!F[~oeIP_P`p=',`(C67-&x6s7SuplR9;=ypy$`(XP@xpoyL7TDKJ?$8h%p@MTt**4['+oVhM@HYQYV-J)y[Hz)E3&YXf;=,%xlDWcdh$,8c(TWF.HA}ORe_0Tnb@?V7BKrCz!?O0b&B;]'0ZW\02CameraPlugIns"
"DjVu"="Ku[gK-G5u=-2hsoNk(ZfMKkB4{HBY??iOSq0B!'%\02ImageEncodingDecodingPlugIns"
"Email"="=vcJcYlR[?Bvqfu'@[sse!neJmMV6@XdVs7{Mg64\02CommandExtensionPlugIns"
"Encryption"="ws=`aph,Q=6fCGW{'%StH9V+HMh44@]A},=,0],B\02ArchivePlugIns"
"FotoCanvasPowerPackRetail"="W9td=3,%MAY[5T`bRgP]5j4_0,F8?@TZlm]-~Ova4mu6]){+-=V*KFhKb,qd\02FotoCanvas"
"FotoSlatePowerPackRetail"="!NviH&Z;%t?gV=a_9P(VxKJhx?]VW-9WZ%8j*fLQ5if,[wF7@z=YSi]VIIrai\02FotoSlate"
"FPX"=",*IXg-='S?_'W'jvI`fhd@,RhAnz.9C7,MgH?d@mS]-l'.bNj8m}T1p&QUrl;\02ImageEncodingDecodingPlugIns"
"HPC20"="cSA_CKN!u8jx^Sr]fh9&\02CameraPlugIns"
"HTML"="5+Yg]+YDy@a$R{'kT3[@\02CommandExtensionPlugIns"
"ICN"="99}(ru=*Z9qA@FO}0fFsqk,o]Xf*69f4ev3,U$RX\02ImageEncodingDecodingPlugIns"
"ICO"="RYX+B$xBF?pt+&8^?Bx69-HbLCA$3=x!R1zM.m*q\02ImageEncodingDecodingPlugIns"
"IFF"="S~FM&qf0H;@}j8.7c*cUOu0s@E{?Kz?5AXVRDlK4-\02ImageEncodingDecodingPlugIns"
"KDC"="PXq4Z~j6$@yq3w8a=@cw!Kb[y929Y={t1(IBcyMXRgk6Q1]x)?T5x-E'^+ql\02ImageEncodingDecodingPlugIns"
"Kodak"="\02CameraPlugIns"
"KDC120"="PXq4Z~j6$@yq3w8a=@cwTVkxzW_?q?cc]A3pNs.(ZS!!eqg}a9QJNcmeva.YM=gv^xYS8@Be*Dp-dmcF5&0wST[Bl8UV$el6=8RfI1pRbQFo`9-+iwobN^YzK9Fg.Uo5N9V1sF1}+okg\02Kodak"
"KDC210"="ndw.5pbxQAxND-KnIxf3TElEO!}It@FKBA-k*NzVqi50QxEBo99OCc-vV.2R`DRA75&+`8Z[kjhp6znoR9SzjK6QL?,e*$0nyt7i\02Kodak"
"KDC265"="ZS!!eqg}a9QJNcmeva.YM=gv^xYS8@Be*Dp-dmcF5&0wST[Bl8UV$el6=8RfI1pRbQFo`9-+iwobN^YzK9Fg.Uo5N9V1sF1}+okg*zXIp!MN!=.2E0b!Z~_eG{_w[mhz8={K)yDO=hWH0(DX'dVWb9mz9Yoj@N1=V}1sumMgSAWV.~zzw(x[\02Kodak"
"LHA"="QC!U,9?gY=ZJyOUg!YMVIa1mPfSkD9^X~?GMl,pD\02ArchivePlugIns"
"MAG"="yLr4cB{9c?}`xa$+mfYrir`z'AY]cAiXT!2mzZL9\02ImageEncodingDecodingPlugIns"
"PaneExtension"=""
"PhotoCD"="p1Ao[sa]AAqJyZ&[d@hV0L[.M=YNKAcHPgo}G?&F;\02ImageEncodingDecodingPlugIns"
"PIC"="N2G*v@%bj80m@J,eIS`t2D&ymg27i9g;,9pw54a7f\02ImageEncodingDecodingPlugIns"
"PICT"="F4}_QE}7`8mWBdAeO2paGINQ65aMk=2(ni,`*E7@\02ImageEncodingDecodingPlugIns"
"PIX"="hVq.ZMza_9.Mv59U-m3iorqQ78yaj9]Q*VC=B[fP\02ImageEncodingDecodingPlugIns"
"PNM"="nM(2v.`e}8'gpE%=z8*oTO[Q3ucmr9bT)6YhPFl.\02ImageEncodingDecodingPlugIns"
"PrintsGifts"="Yv+Huydr^@&E;``'nK'{gJntb7~NbC9'I!Yv?smnS\02PaneExtension"
"PSD"="A16Z`Libo@miJm+z4_FLb*&A;`B3b(A{vPq&q;,({S\02ImageEncodingDecodingPlugIns"
"PSP"="JWZm6dwMX=@8MBW%P~LICMPHH.B$F=IKI4$WKf8V\02ImageEncodingDecodingPlugIns"
"RAR"="4eXBkrCH0@6aP*hixQp+RlL-8!Q-i=!3b.a4SP5K\02ArchivePlugIns"
"RAS"="y{ZxQvQxT?_O@7^348yhi(c~?uf_z8NX6XUtOb[X\02ImageEncodingDecodingPlugIns"
"RSB"="Wjot!T2r-9*FRV.gNc}^2b1_n&lov8;[]ja8=ws@)\02ImageEncodingDecodingPlugIns"
"SendPix"="jB3y@EXo(9hR(=m(rMIt$n{5._Pq[A(n_3Cxd8yRrjwg8.gFQ9%6Q84-Uh6=\02CommandExtensionPlugIns"
"SGI"="v~0rhJ)!]@4Lz2MNhL*(_^twL!rxv@T)6?&JxZGo;\02ImageEncodingDecodingPlugIns"
"SII"="]oN`b'7n6A5y0_3W%GL5\02CameraPlugIns"
"SusieArchive"="O&PCno;$pDAcPr15nnj8sp!yjFY@Vo?vBoK5'v!,E\02ArchivePlugIns"
"SusieImage"="^&nYuKuGn;@V!pm$uUdv'C^Iv6!l?ZAdAMsl?5z.B\02ImageEncodingDecodingPlugIns"
"TGZ"="C91zKY5.l=g@)^OJw=7nH12x%@TWX@I_xL^p5p+B\02ArchivePlugIns"
"UUE"="ctW}TJKVU9kY]'a6q.m99=7pXTGLr8WVI1I+(4M!\02ArchivePlugIns"
"ZIP"="!ZuWyJqoVA?6j73p}e}%3$dP.jfGl@[Uq8*dh.tK\02ArchivePlugIns"
"CrossSellHelp"="z}{GOg7UT9%gPXnP%qa)\02FotoCanvas"
"PhotoWorks"="XIQ*=UOL}?^FfJ_Z&=[J\02ACDSee"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\79BB0A83D277E224CBACB42A5A8DF124\InstallProperties]
@DACL=(02 0000)
"RegOwner"="Peter C. Winch"
"RegCompany"="none"
"ProductID"="61"
"LocalPackage"="c:\\WINDOWS\\Installer\\d734a.msi"
"AuthorizedCDFPrefix"=""
"Comments"="This database contains the necessary files and logic to install ACDSee and additional support programs and plug-ins where appropriate"
"Contact"="Technical Support"
"DisplayVersion"="6.0.2"
"HelpLink"=expand:"http://www.acdsystems.com/English/Support"
"HelpTelephone"="[removed]"
"InstallDate"="20031215"
"InstallLocation"="c:\\Program Files\\ACD Systems\\"
"InstallSource"="c:\\WINDOWS\\Downloaded Installations\\{B0CC1A89-E31E-455D-85F9-E168107BAC9F}\\"
"ModifyPath"=expand:"MsiExec.exe /I{38A0BB97-772D-422E-BCCA-4BA2A5D81F42}"
"NoRepair"=dword:00000001
"Publisher"="ACD Systems Ltd."
"Readme"=expand:"\"\""
"Size"=""
"EstimatedSize"=dword:0000e005
"UninstallString"=expand:"MsiExec.exe /I{38A0BB97-772D-422E-BCCA-4BA2A5D81F42}"
"URLInfoAbout"="http://www.acdsystems.com"
"URLUpdateInfo"="\"\""
"VersionMajor"=dword:00000006
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:06000002
"Language"=dword:00000409
"DisplayName"="ACDSee 6.0 PowerPack"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\8756E3AD9AC3968459B7C1B4C8BC3648\Features]
@DACL=(02 0000)
"Titler"="mn6(6GwQ$?cxVktbHkE9VEqqhyd9^?!bScoo)Lf8698X]YlG8?r)Pu&x;]tFu\02Sample_Files"
"Sample_Files"="mn6(6GwQ$?cxVktbHkE9VEqqhyd9^?!bScoo)Lf8698X]YlG8?r)Pu&x;]tFukN'L9Kl@W9_L,mJ%&!I@"
"Tutorial"="jP(T%hu92@$%paK8lhnmHgdQ5z~d^A7+{VR9%09,"
"DVD_VRWriter"=""
"CNC_3DArrange"="e%!@gE?u{9l86i+Hv6bO"
"pal"="9ua-{)=}c@3o@Wby=2Q$\02Program_Files"
"Program_Files"="bC,m8i'Ko9Pg{bdzQ4ff-JscgT!XWA}yjj1xvIKr-Rh9!lrcO=dhwSoRE5n%h8z[=@Oo}?35+5lMkI}02cH^=Hj-_@jkulxQ,+(^(%2ivb@([removed]]rFg]f2]bR2}4ks?mdvyh?x=^ljTLO'P.uZ==(7]6^{e?)K8SW=Zm%c9{)lZ!u*8}w%_tIW'iW+Abej4vym']$2PRiW6j,dA(-SrUT&Ica;[D-Iu!^pz?T4[kx]YuM8pUq@r}*~,@g[Dt$eXtr-dEieE'GcbAdtl.Tql33UvG{S[M0bK9wb^`a?DW)p&Z;{^K`Ckl@zR(]&sO7Ew8;`q)ADaww9~+FIlg0{6,Im2S^j%VRAuX'78eqg*+D?L_'9Lc'APo1B%='0!x*e&XrO1M;~=uMkzb,zae5tV3LUfPMj=&uh;__5&,FK.^f5oX!Pe?UD[8=^Xz.LfW~6{z[~~9YwOrl^6$&8FHr,WGAy{?-XmGqZ&@d['%1V7FA5R=5UQ@s9^fMuu53qJ=PD7?{8j}v+EfOH{G`DHhq.h9B$MZMNXMiP~^l9.c9cz8=[fj'DQi`m*GHBX{}j,9!fu]%?HOLjwHf*29bV(?YX3iI5n{Y%ja_)uW)mz?}26LK?a63eMos'mmf^^=Lx$v'ezrH5Fj_@Xcky]9R(G02mmg^ga?XG)b-mk@K+A$Dey0Q=eeaT5oSiz?(i-y]sdBZk5n}[Oo({_@T_2vm[[b(Q!$uWqX}`^8sEU}'iT)7t*P%X2aL%9=jZX-VN8]}[(6rOGx97f=4dX3D{nP-_=4WH!aUnd8XF,gmbBQdqu@_W=p~7p?exlfPUS8O.XBLLKz7Lc8fRMj?_^}YP"
"Movies"="kN'L9Kl@W9_L,mJ%&!I@\02Sample_Files"
"CNC_VideoGift"="XLx6k8~Dc?aEB=^9p_+*b66ekq_Gr@,VH79TD)4!.9hq0.^=o=^nr36pFur==yZi?jCWp9`Si+D=&otz;"
"mpeg2_Files"="6]3Y%=(4^@_90zF8h=2m3KJxH1T28@aN$TnL~]KIcGY6sJfl3@h+S`HS3YY%[l3Me1a){?oL0,330r+4GZjdYh,zL?t0t4F))-o+{kp}y^%K6?jKf={!4kK8"
"Help_Files"=""
"DVDR_Record_Module"="9T0x7~{Av9?_3Oc0CSYZ"
"CNC_DVDfunSTUDIO"="d^&GFgLgi;@-*86,VFa@'"
"Multi"="f+$j6fuA&@SCHDDK)6IV"
"English"="\02Multi"
"SwitchProducts"=""
"VED_PACKAGE_311E"="\02SwitchProducts"
"DVDRAM_311E"="\02SwitchProducts"
"DVHS_Driver"="RGH8utfEt=jP2-22s']0\02Driver_Files"
"Driver_Files"=""
"ntsc"="t3{tu1kpb=gb'6OFV+Pk\02Program_Files"
"DVHS_Record"="(O,Z!0ukF@$b3bP`8{)ZvH8f)K.$q81h$f]f'anYM=exZt&!h=m-T-!x6*74"
"Meiavc_Driver"="@L(68s*`_8bZZ-_i%b5.\02Driver_Files"
"QFE_Packege"="bC,m8i'Ko9Pg{bdzQ4ff\02Driver_Files"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\8756E3AD9AC3968459B7C1B4C8BC3648\InstallProperties]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\296bf8a.msi"
"AuthorizedCDFPrefix"=""
"Comments"=" "
"Contact"=" "
"DisplayVersion"="3.20.000"
"HelpLink"=expand:" "
"HelpTelephone"=" "
"InstallDate"="20030726"
"InstallLocation"=""
"NoModify"=dword:00000001
"NoRemove"=dword:00000001
"Publisher"="Panasonic"
"Readme"=expand:" "
"Size"=""
"EstimatedSize"=dword:00006212
"SystemComponent"=dword:00000001
"URLInfoAbout"=" "
"URLUpdateInfo"=" "
"VersionMajor"=dword:00000003
"VersionMinor"=dword:00000014
"WindowsInstaller"=dword:00000001
"Version"=dword:03140000
"Language"=dword:00000000
"DisplayName"="MotionDV STUDIO 3"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\8A0F841731866D117AB7000B0D410201\Features]
@DACL=(02 0000)
"other_US"="t)Sf^.oCg(^O3Xa,A]FH"
"extra"="xqyr1p^$G@n}-$+KWS4r"
"jrecore"="SDg%C'KCg([I3Xa,A]FHSDg%C'KCg([I3Xa-JxbHSDg%C'KCg([I3Xa.S9!ISDg%C'KCg([I3Xa9dT3(lp-To$qd*?do.B$rpHeT"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\8A0F841731866D117AB7000B0D410201\InstallProperties]
@DACL=(02 0000)
"RegOwner"="Customer"
"RegCompany"=""
"ProductID"="none"
"LocalPackage"="c:\\WINDOWS\\Installer\\16ff83b.msi"
"AuthorizedCDFPrefix"=""
"Comments"="http://www.java.com"
"Contact"="http://www.java.com"
"DisplayVersion"="1.4.2_01"
"HelpLink"=expand:"http://www.java.com"
"HelpTelephone"="http://www.java.com"
"InstallDate"="20031201"
"InstallLocation"=""
"InstallSource"="c:\\Documents and Settings\\Customer\\Local Settings\\Application Data\\{7148F0A6-6813-11D6-A77B-00B0D0142010}\\"
"ModifyPath"=expand:"MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142010}"
"NoRepair"=dword:00000001
"Publisher"="Sun Microsystems, Inc."
"Readme"=expand:"Readme.txt"
"Size"=""
"EstimatedSize"=dword:0001abe4
"UninstallString"=expand:"MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142010}"
"URLInfoAbout"="http://www.java.com"
"URLUpdateInfo"="http://java.sun.com"
"VersionMajor"=dword:00000001
"VersionMinor"=dword:00000004
"WindowsInstaller"=dword:00000001
"Version"=dword:81040000
"Language"=dword:00000000
"DisplayName"="Java 2 Runtime Environment, SE v1.4.2_01"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\BFB6BBEC807D99F46A33CB62000EE16F\Features]
@DACL=(02 0000)
"Help"="B)H`h(~iv=gv%eterg5w"
"Driver"="({1vvG&}m=&ojg;%~gO1zMPFGsq1sm9,oE`Rn=yDURKmXF7)]v8Mzj'ec&F;&5UK!ozvZ7a??!rRNK=qhg)SGhDuALv=F~jUJaJQhU@iggIe2k]AW*u+CWJidjX,-Q(N{v]8Iw!*E3%!YVf{o._1iFg(hh%!!SOt.,g{o._1iFg(hh%!!SOt.,"
"Utility"="X5HKV)hgq=LUMrk3]y2Cgy&^[8'jp?O~ubw^jFLIK$0pdmaR2@lSP&A;$e[5HHmI']!XhHAb3f^a7fm[=A%JMWfDWo9CbTROk~Ou0wq4p4+wkq?hV+j`Evuq(BJORzIFuB=Up*EWON^SpD-*tHtm`3=S&Z;[E'{VTWoJ?EkzeEg(hh%!!SOt.,]K?EkzeEg(hh%!!SOt.,V{o._1iFg(hh%!!SOt.,"
"DriverInstall"="=3trvGg}H9%N7.PdmwaH"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Products\BFB6BBEC807D99F46A33CB62000EE16F\InstallProperties]
@DACL=(02 0000)
"LocalPackage"="c:\\WINDOWS\\Installer\\4748e.msi"
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="2.01.0000"
"HelpLink"=expand:" "
"HelpTelephone"=" "
"InstallDate"="20030106"
"InstallLocation"=""
"ModifyPath"=expand:"MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="Toshiba"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000528
"UninstallString"=expand:"MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}"
"URLInfoAbout"=" "
"URLUpdateInfo"=" "
"VersionMajor"=dword:00000002
"VersionMinor"=dword:00000001
"WindowsInstaller"=dword:00000001
"Version"=dword:02010000
"Language"=dword:00000409
"DisplayName"="Bluetooth Stack for Windows by Toshiba"
.
Completion time: 2009-04-12 3:57:40
ComboFix-quarantined-files.txt 2009-04-11 17:56:24
ComboFix2.txt 2009-04-11 16:34:30
ComboFix3.txt 2009-04-11 14:15:06

Pre-Run: 10,498,392,064 bytes free
Post-Run: 10,480,648,192 bytes free

551 — E O F — 2009-04-03 03:49:55
PeterPumpkinEater,


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
PeterPumpkinEater, Unfortunately I can't tell which email it is. Please you through all of the email in Outlook Express and delete all email that you don't want/need. The odds are that the contaminated email will contain an attachment or a live link. Don't open any attachments or click any links while doing this. :) Let me have another HijackThis log and tell me how things are running.
Tomk, Before running HijackThis I found obvious email with attachment in Inbox. Deleted it. Ran reduced Kapersky scan on OutLook Express and came back clear. Attached HiJackThis log. Ran Pandasoft AV to double check. Log attached. Something found and removed automatically. Currently running BitDefender but 6 hours from completion. Ran RegSeeker cleaner just to check how much debris. 250 somethings (obsolete entry etc) Usually run once a week and typially less than 10 innocuous things. Took no action i.e. did not clean. (Just curious).

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI