This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] redirecting and blocking

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi guys put this in wrong forum at first hope this right one, Problem is google search results are redirected to various sites and attempts to scan computer with spybot or malwarebytes fail to start, i tried to upload a hijackthis result but it is an old version i was using and this site will not let me put in the topic keeps telling me to download an up to date version, which i can do but it will not load or start, any malware program downloads but willnot run even in safe mode. advice please
Hi and welcome

Can you download and run this programme in safe mode please

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
Hi, done as asked, here are logs.
OTListIt logfile created on: 08/04/2009 22:45:54 - Run 1
OTListIt2 by OldTimer - Version 2.0.12.2 Folder = C:\Documents and Settings\peter\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.48 Mb Total Physical Memory | 814.75 Mb Available Physical Memory | 79.61% Memory free
2.40 Gb Paging File | 2.32 Gb Available in Paging File | 96.49% Paging File free
Paging file location(s): C:\pagefile.sys 0 0;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 52.66 Gb Free Space | 70.65% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PETERS
Current User Name: peter
Logged in as Administrator.

Current Boot Mode: SafeMode
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\Iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\peter\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Stopped]) – C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (BlueSoleil Hid Service [Disabled | Stopped]) – C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe ()
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (cmdAgent [Auto | Stopped]) – C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe ()
SRV - (ComodoBackupService [Auto | Stopped]) – C:\Program Files\Comodo\BackUp\CmdBkSvc.exe (COMODO)
SRV - (gupdate1c99152d3ef0640 [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [On_Demand | Stopped]) – File not found
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [Disabled | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (InCDsrv [Disabled | Stopped]) – C:\Program Files\Ahead\InCD\InCDsrv.exe (Ahead Software AG)
SRV - (JavaQuickStarterService [Auto | Stopped]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KService [Disabled | Stopped]) – C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (LexBceS [Auto | Stopped]) – C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (ServiceLayer [Disabled | Stopped]) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (STI Simulator [Disabled | Stopped]) – C:\WINDOWS\System32\PAStiSvc.exe ()
SRV - (UMWdf [Auto | Stopped]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (YPCService [On_Demand | Stopped]) – C:\WINDOWS\system32\YPcservice.exe (Yahoo! Inc.)

========== Driver Services (SafeList) ==========

DRV - (alcan5wn [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\alcan5wn.sys (THOMSON)
DRV - (alcaudsl [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\alcaudsl.sys (THOMSON)
DRV - (ati2mtag [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ATTSCAP [Auto | Stopped]) – C:\WINDOWS\system32\drivers\attscap.sys (AVerMedia Technologies, Inc.)
DRV - (ATVCAP [Auto | Stopped]) – C:\WINDOWS\system32\drivers\atvcap.sys (AVerMedia Technologies, Inc.)
DRV - (ATXBAR [Auto | Stopped]) – C:\WINDOWS\system32\drivers\ATXBAR.sys (AVerMedia Technologies, Inc.)
DRV - (BlueletAudio [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\blueletaudio.sys (IVT Corporation)
DRV - (BlueletSCOAudio [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys (IVT Corporation)
DRV - (BT [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\btnetdrv.sys (IVT Corporation)
DRV - (Btcsrusb [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\btcusb.sys (IVT Corporation)
DRV - (BTHidEnum [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\vbtenum.sys ()
DRV - (BTHidMgr [Boot | Running]) – C:\WINDOWS\System32\Drivers\BTHidMgr.sys (IVT Corporation)
DRV - (BTNetFilter [On_Demand | Stopped]) – C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys ()
DRV - (Cam5603C [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\VdCap03C.sys ()
DRV - (cmdGuard [System | Stopped]) – C:\WINDOWS\System32\DRIVERS\cmdguard.sys (COMODO)
DRV - (cmdHlp [System | Stopped]) – C:\WINDOWS\System32\DRIVERS\cmdhlp.sys (COMODO)
DRV - (cmuda [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\cmuda.sys (C-Media Inc)
DRV - (ENTECH [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ENTECH.SYS (EnTech Taiwan)
DRV - (gameenum [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (InCDfs [Disabled | Stopped]) – C:\WINDOWS\System32\drivers\incdfs.sys (Ahead Software AG)
DRV - (InCDPass [System | Running]) – C:\WINDOWS\System32\DRIVERS\InCDPass.sys (Ahead Software AG)
DRV - (Inspect [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (L8042Kbd [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys (Logitech, Inc.)
DRV - (L8042mou [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\L8042mou.Sys (Logitech, Inc.)
DRV - (LMouKE [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\LMouKE.Sys (Logitech, Inc.)
DRV - (MREMPR5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (ms_mpu401 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (nmwcd [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmwcd.sys (Nokia)
DRV - (nmwcdc [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmwcdc.sys (Nokia)
DRV - (nmwcdcj [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmwcdcj.sys (Nokia)
DRV - (nmwcdcm [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmwcdcm.sys (Nokia)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nv4 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4.sys (NVIDIA Corporation)
DRV - (PAC7311 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PA707UCM.SYS (PixArt Imaging Inc.)
DRV - (pcouffin [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (Ptilink [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ROOTMODEM [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Ser2pl [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ser2pl.sys (Prolific Technology Inc.)
DRV - (SiS7018 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ac97sis.sys (Silicon Integrated Systems Corp.)
DRV - (sisagp [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (TVICHW32 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS (EnTech Taiwan)
DRV - (USB_RNDIS [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\usb8023.sys (Microsoft Corporation)
DRV - (VComm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\VComm.sys (IVT Corporation)
DRV - (VcommMgr [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\VcommMgr.sys (IVT Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bt.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google.co.uk"
FF - prefs.js..extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/10 23:24:13 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/31 21:25:35 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/29 17:03:44 | 00,000,000 | —D | M]

[2008/07/05 17:27:47 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\mozilla\Extensions
[2008/07/05 17:27:47 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/07 17:58:20 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\mozilla\Firefox\Profiles\oo3sxysz.default\extensions
[2008/12/12 01:17:47 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\mozilla\Firefox\Profiles\oo3sxysz.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2009/04/07 17:58:20 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/03/29 17:03:44 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/05/17 16:54:13 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/11/17 00:43:36 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2009/03/10 23:24:34 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/04/02 21:43:44 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/03/29 17:03:35 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/29 17:03:35 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/11/15 22:49:30 | 00,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2008/11/15 22:49:30 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/11/15 22:49:30 | 00,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2008/11/15 22:49:30 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/15 22:49:30 | 00,000,759 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2008/11/15 22:49:30 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/11/15 22:49:30 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/11/15 22:49:30 | 00,000,831 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (no name) - {4F06B779-D0FD-4580-8C9B-6EAEB70F10AE} - Reg Error: Key error. File not found
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SidebarAutoLaunch Class) - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (no name) - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-84BA-B830E8D4E122} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay (ATI Technologies Inc.)
O4 - HKLM..\Run: [btbb_wcm_McciTrayApp] C:\Program Files\btbb_wcm\McciTrayApp.exe (Motive Communications, Inc.)
O4 - HKLM..\Run: [COMODO Internet Security] "C:\Program Files\Comodo\COMODO Internet Security\cfp.exe" -h ()
O4 - HKLM..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s (COMODO)
O4 - HKLM..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" (Lexmark International, Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide (Heidi Computers Ltd)
O4 - HKCU..\Run: [geaia] "c:\documents and settings\peter\local settings\application data\geaia.exe" geaia ()
O4 - HKCU..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~2\YAHOOM~1.EXE" -quiet (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\WINDOWS\system32\GPhotos.scr/200 (Google Inc.)
O9 - Extra Button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [Bluetooth Namespace] - C:\WINDOWS\system32\wshbth.dll (Microsoft Corporation)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (Intertrust Technologies, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} http://download.microsoft.com/download/7/0…tualEarth3D.cab (SentinelVE3D Class)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} C:\Program Files\Yahoo!\common\yucconfig.dll (yucsetreg Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll (Installation Support)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab (Reg Error: Key error.)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} http://secure2.comned.com/signuptemplates/…login-devel.cab (SecureLogin class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} http://download.yahoo.com/dl/installs/ymail/ymmapi.dll (Yahoo! MailTo)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://download.yahoo.com/dl/installs/yab_af.cab (YAddBook Class)
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} http://help.broadbandassist.com/bbdesktop/…tivePreQual.cab (PreQualifier Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} http://eu.download.games.yahoo.com/zylom/a…zylomloader.cab (Zylom Loader Object)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://3dlifeplayer.dl.3dvia.com/player/in…l/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} http://driveragent.com/files/driveragent.cab (Driver Agent ActiveX Control)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{EFBA1530-5D85-4113-95C6-41FD82DA661C}\\NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\cssdll32.dll) - C:\WINDOWS\system32\cssdll32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\geBrrRjK: DllName - geBrrRjK.dll - File not found
O20 - Winlogon\Notify\xxyawuu: DllName - xxyawuu.dll - File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {4F06B779-D0FD-4580-8C9B-6EAEB70F10AE} - Reg Error: Key error. File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[5 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\peter\Application Data\*.tmp files]
[2009/04/08 22:41:45 | 00,500,736 | —- | C] (OldTimer Tools) – C:\Documents and Settings\peter\Desktop\OTListIt2.exe
[2009/04/08 16:34:41 | 00,000,000 | —D | C] – C:\Avenger
[2009/04/08 00:34:45 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\peter\Desktop\HJTInstall.exe
[2009/04/08 00:22:17 | 02,967,800 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\peter\Desktop\mbam-setup.exe
[2009/04/07 18:20:47 | 03,067,803 | —- | C] () – C:\Documents and Settings\peter\Desktop\ComboFix.exe
[2009/04/07 17:46:12 | 00,000,933 | —- | C] () – C:\Documents and Settings\peter\Desktop\Spybot - Search & Destroy.lnk
[2009/04/05 23:05:12 | 00,000,064 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/04/04 16:00:32 | 00,027,136 | —- | C] () – C:\WINDOWS\ieocx.dll
[2009/04/03 23:00:49 | 00,325,613 | —- | C] () – C:\Documents and Settings\peter\Local Settings\Application Data\geaia_nav.dat
[2009/04/03 23:00:49 | 00,003,125 | —- | C] () – C:\Documents and Settings\peter\Local Settings\Application Data\geaia_navps.dat
[2009/04/03 23:00:49 | 00,003,040 | —- | C] () – C:\Documents and Settings\peter\Local Settings\Application Data\geaia.dat
[2009/04/03 23:00:48 | 00,257,536 | —- | C] () – C:\Documents and Settings\peter\Local Settings\Application Data\geaia.exe
[2009/04/03 21:46:43 | 01,022,464 | —- | C] () – C:\Documents and Settings\peter\Application Data\pcdefender.exe
[2009/04/02 17:48:10 | 00,591,588 | —- | C] () – C:\02174809.mpg
[2009/04/02 17:37:45 | 00,000,737 | —- | C] () – C:\Documents and Settings\peter\Desktop\AVerTV DVB-T (2).lnk
[2009/04/02 17:35:51 | 00,000,000 | —D | C] – C:\Documents and Settings\peter\Desktop\bristow and sutor
[2009/03/31 00:03:51 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/03/27 23:54:51 | 00,243,200 | —- | C] () – C:\Documents and Settings\peter\Local Settings\Application Data\umwoegi.exe
[2009/03/24 19:11:34 | 00,000,737 | —- | C] () – C:\Documents and Settings\peter\Desktop\AVerTV DVB-T.lnk
[2009/03/23 00:19:15 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/03/23 00:19:15 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/03/22 00:01:07 | 00,000,000 | —D | C] – C:\WINDOWS\.jagex_cache_32
[2009/03/20 19:12:02 | 00,000,000 | —D | C] – C:\Documents and Settings\peter\Application Data\Media Player Classic
[2009/03/16 21:09:59 | 00,022,016 | —- | C] () – C:\Documents and Settings\peter\My Documents\bristow march09.doc
[2009/03/15 11:11:37 | 00,000,000 | —D | C] – C:\finalburner
[2009/03/14 10:57:55 | 00,000,000 | —D | C] – C:\Program Files\FinalBurner
[2008/12/12 01:16:58 | 00,155,384 | —- | C] () – C:\WINDOWS\System32\guard32.dll
[2008/08/30 23:33:33 | 02,076,672 | —- | C] () – C:\WINDOWS\System32\dz3delight.dll
[2008/08/30 23:33:31 | 06,131,712 | —- | C] () – C:\WINDOWS\System32\daz-qt-mt.dll
[2008/08/30 23:33:31 | 01,785,856 | —- | C] () – C:\WINDOWS\System32\daz-qsa.dll
[2008/01/06 11:32:26 | 00,000,050 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/08/22 23:44:31 | 00,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/08/19 17:13:57 | 00,394,240 | —- | C] () – C:\WINDOWS\System32\Smab.dll
[2007/07/25 15:24:30 | 01,559,040 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2007/07/11 14:05:08 | 00,000,004 | —- | C] () – C:\WINDOWS\info147.sys
[2007/03/30 00:00:40 | 00,203,264 | R— | C] () – C:\WINDOWS\System32\CddbCdda.dll
[2007/01/03 00:19:02 | 00,001,275 | —- | C] () – C:\WINDOWS\AVerDVBT.ini
[2006/12/30 21:16:35 | 00,000,441 | —- | C] () – C:\WINDOWS\lexstat.ini
[2006/12/30 21:01:55 | 00,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2006/12/30 17:48:16 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2006/12/30 17:34:42 | 00,005,606 | —- | C] () – C:\WINDOWS\System32\stci.dll
[2006/12/29 19:25:09 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/04/14 10:14:12 | 00,014,312 | —- | C] () – C:\WINDOWS\System32\drivers\BTNetFilter.sys
[2006/03/31 21:57:42 | 00,000,966 | —- | C] () – C:\WINDOWS\videoimp.ini
[2006/03/31 21:57:12 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2006/03/31 21:56:51 | 00,000,021 | —- | C] () – C:\WINDOWS\VI_setup.ini
[2006/03/31 21:55:24 | 00,295,374 | —- | C] () – C:\WINDOWS\System32\drivers\VdCap03C.sys
[2006/03/31 21:55:19 | 00,081,920 | —- | C] () – C:\WINDOWS\System32\VfwExtC.dll
[2006/03/31 21:55:19 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\VfwECamC.dll
[2006/03/31 21:55:19 | 00,015,190 | —- | C] () – C:\WINDOWS\VdTwn03C.ini
[2006/02/26 16:08:28 | 00,585,728 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2006/01/13 23:33:03 | 00,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2005/07/30 08:21:32 | 00,011,988 | —- | C] () – C:\WINDOWS\System32\drivers\vbtenum.sys
[2003/08/18 15:46:38 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\LXBKLCNP.DLL
[2002/11/13 20:40:22 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\lxbkvs.dll
[2002/09/13 16:40:06 | 00,000,266 | —- | C] () – C:\WINDOWS\System32\lxbkcoin.ini
[2001/08/23 13:00:00 | 00,001,049 | —- | C] () – C:\WINDOWS\win.ini
[2001/08/23 13:00:00 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2001/07/25 13:00:10 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\HWINV.DLL
[2001/07/25 13:00:10 | 00,026,572 | —- | C] () – C:\WINDOWS\System32\INV16.DLL
[1999/01/22 19:46:58 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/01/12 09:00:00 | 00,040,448 | —- | C] () – C:\WINDOWS\System32\regobj.dll

========== Files - Modified Within 30 Days ==========

[3 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\peter\Application Data\*.tmp files]
[1 C:\Documents and Settings\peter\My Documents\*.tmp files]
[2009/04/08 22:44:22 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/08 22:43:06 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/08 22:42:46 | 00,003,125 | —- | M] () – C:\Documents and Settings\peter\Local Settings\Application Data\geaia_navps.dat
[2009/04/08 22:42:36 | 00,003,040 | —- | M] () – C:\Documents and Settings\peter\Local Settings\Application Data\geaia.dat
[2009/04/08 22:41:45 | 00,500,736 | —- | M] (OldTimer Tools) – C:\Documents and Settings\peter\Desktop\OTListIt2.exe
[2009/04/08 22:37:03 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\peter\Desktop\HJTInstall.exe
[2009/04/08 01:53:12 | 00,001,275 | —- | M] () – C:\WINDOWS\AVerDVBT.ini
[2009/04/08 01:23:06 | 00,000,000 | —- | M] () – C:\mediatype.dat
[2009/04/08 00:22:47 | 02,967,800 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\peter\Desktop\mbam-setup.exe
[2009/04/07 18:21:16 | 03,067,803 | —- | M] () – C:\Documents and Settings\peter\Desktop\ComboFix.exe
[2009/04/07 17:46:12 | 00,000,933 | —- | M] () – C:\Documents and Settings\peter\Desktop\Spybot - Search & Destroy.lnk
[2009/04/05 23:56:18 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/04/05 23:05:12 | 00,000,064 | —- | M] () – C:\WINDOWS\wininit.ini
[2009/04/04 16:00:32 | 00,027,136 | —- | M] () – C:\WINDOWS\ieocx.dll
[2009/04/04 15:57:54 | 00,245,760 | —- | M] () – C:\Documents and Settings\peter\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/03 23:00:48 | 00,257,536 | —- | M] () – C:\Documents and Settings\peter\Local Settings\Application Data\geaia.exe
[2009/04/03 21:46:43 | 01,022,464 | —- | M] () – C:\Documents and Settings\peter\Application Data\pcdefender.exe
[2009/04/02 17:48:14 | 00,591,588 | —- | M] () – C:\02174809.mpg
[2009/04/02 17:37:45 | 00,000,737 | —- | M] () – C:\Documents and Settings\peter\Desktop\AVerTV DVB-T (2).lnk
[2009/04/01 22:19:46 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/29 21:28:18 | 00,471,326 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/29 21:28:18 | 00,401,064 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/29 21:28:18 | 00,062,344 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/29 03:30:00 | 00,000,394 | —- | M] () – C:\WINDOWS\tasks\ErrorEasy Scheduled Scan.job
[2009/03/27 23:55:02 | 00,325,613 | —- | M] () – C:\Documents and Settings\peter\Local Settings\Application Data\geaia_nav.dat
[2009/03/27 23:54:51 | 00,243,200 | —- | M] () – C:\Documents and Settings\peter\Local Settings\Application Data\umwoegi.exe
[2009/03/27 00:08:25 | 00,002,473 | —- | M] () – C:\Documents and Settings\peter\Desktop\Microsoft Word.lnk
[2009/03/24 19:11:34 | 00,000,737 | —- | M] () – C:\Documents and Settings\peter\Desktop\AVerTV DVB-T.lnk
[2009/03/23 00:19:15 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/03/22 11:22:17 | 00,001,049 | —- | M] () – C:\WINDOWS\win.ini
[2009/03/22 11:20:59 | 00,002,335 | —- | M] () – C:\Documents and Settings\peter\Desktop\AmCap (2).lnk
[2009/03/20 19:15:14 | 00,023,392 | —- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2009/03/20 19:15:14 | 00,016,832 | —- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2009/03/20 19:14:07 | 00,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2009/03/16 21:16:09 | 00,022,016 | —- | M] () – C:\Documents and Settings\peter\My Documents\bristow march09.doc
[2009/03/16 21:15:19 | 00,000,441 | —- | M] () – C:\WINDOWS\lexstat.ini
[2009/03/14 09:42:28 | 00,253,688 | —- | M] (COMODO) – C:\WINDOWS\System32\cssdll32.dll
[2009/03/11 01:56:51 | 00,000,049 | —- | M] () – C:\WINDOWS\NeroDigital.ini

========== LOP Check ==========

[2009/02/09 21:20:31 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2006/12/29 19:36:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ahead
[2006/07/16 01:21:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/12/12 01:11:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg7
[2008/02/06 21:48:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Bluetooth
[2006/03/13 22:49:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2008/02/22 22:30:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Channel4
[2009/02/19 20:21:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Comodo
[2006/12/29 19:33:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/03/24 02:47:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\dslic
[2007/11/22 00:30:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2009/02/09 21:20:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2008/10/18 00:03:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\grypctkf
[2008/02/04 20:35:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2008/02/23 11:23:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2008/10/17 23:54:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2007/11/07 22:53:39 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/02/04 17:05:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2008/07/31 17:58:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Software
[2008/07/31 17:58:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2008/02/04 20:38:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2007/01/07 12:39:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QubeSoft
[2006/12/29 19:28:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBT
[2009/04/07 17:45:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/07/25 21:54:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/04/15 16:25:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2008/09/15 22:38:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2006/01/08 15:25:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/07/13 18:12:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2008/05/15 16:41:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\yahoo!
[2006/10/05 21:48:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2006/01/28 20:43:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Zylom
[1 C:\Documents and Settings\peter\Application Data\*.tmp files]
[2009/04/07 18:22:49 | 00,000,000 | RH-D | M] – C:\Documents and Settings\peter\Application Data
[2006/12/07 00:28:18 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Adobe
[2007/07/22 21:32:03 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Ahead
[2007/02/04 17:55:51 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Apple Computer
[2007/09/16 10:50:41 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\ATI
[2006/02/19 23:35:00 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\AverAlbum
[2008/12/12 01:11:41 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\AVG7
[2009/03/03 21:35:37 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Comodo
[2008/09/15 22:33:21 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\ErrorEasy
[2006/01/19 02:04:06 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Google
[2007/02/02 21:36:50 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Help
[2007/09/16 12:09:10 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\IGN_DLM
[2009/02/18 00:20:08 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Joost
[2006/01/13 23:11:12 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Lavasoft
[2006/12/25 11:42:27 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Logitech
[2006/04/16 10:21:43 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Macromedia
[2008/10/17 23:54:14 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Malwarebytes
[2009/03/20 19:12:02 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Media Player Classic
[2008/04/15 23:27:35 | 00,000,000 | –SD | M] – C:\Documents and Settings\peter\Application Data\Microsoft
[2008/07/26 08:43:36 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Motive
[2008/07/05 17:27:47 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Mozilla
[2008/10/05 01:57:24 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\NCH Swift Sound
[2008/03/27 23:48:24 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Nokia
[2009/03/22 13:35:10 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Nokia Multimedia Player
[2007/01/27 21:09:07 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\OTVREG
[2008/02/04 20:38:16 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\PC Suite
[2006/01/08 02:58:26 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Real
[2007/01/25 22:09:18 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\SlipStream
[2006/01/21 01:07:37 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Sun
[2008/08/12 21:47:10 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Ulead Systems
[2007/09/11 21:24:35 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Uniblue
[2009/03/22 23:54:18 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\uTorrent
[2008/05/28 23:53:30 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\vghd
[2007/03/09 00:14:06 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Vso
[2007/09/27 23:43:22 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\WinRAR
[2008/08/09 10:59:58 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Yahoo!
[2001/08/23 13:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/03/29 03:30:00 | 00,000,394 | —- | M] () – C:\WINDOWS\Tasks\ErrorEasy Scheduled Scan.job
[2009/04/08 22:43:06 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\eli car.mpg:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\peter\Desktop\HJTInstall.exe:SummaryInformation
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EB68C370
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
OTListIt Extras logfile created on: 08/04/2009 22:45:54 - Run 1
OTListIt2 by OldTimer - Version 2.0.12.2 Folder = C:\Documents and Settings\peter\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.48 Mb Total Physical Memory | 814.75 Mb Available Physical Memory | 79.61% Memory free
2.40 Gb Paging File | 2.32 Gb Available in Paging File | 96.49% Paging File free
Paging file location(s): C:\pagefile.sys 0 0;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 52.66 Gb Free Space | 70.65% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PETERS
Current User Name: peter
Logged in as Administrator.

Current Boot Mode: SafeMode
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = YBrowser.HTML] – C:\Program Files\Yahoo!\browser\ybrowser.exe (Yahoo!, Inc.)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Yahoo!\Messenger\ypager.exe:*:Enabled:Yahoo! Messenger File not found
C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server (Yahoo! Inc.)
C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe:*:Enabled:Yahoo! Messenger File not found
C:\PROGRA~1\Yahoo!\MESSEN~1\yserver.exe:*:Enabled:Yahoo! FT Server File not found
C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent (BitTorrent, Inc.)
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil (IVT Corporation)
C:\Program Files\Kontiki\KService.exe:*:Enabled:Delivery Manager Service (Kontiki Inc.)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Joost\xulrunner\tvprunner.exe:*:Enabled:tvprunner (Joost Technologies B.V.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00030409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Small Business
"{00040409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Disc 2
"{025C3792-E9C6-432A-92C1-661F99D021CA}" = Ulead Photo Explorer 8.5 Trial
"{0FF55FD0-BEE0-46FA-AA5B-1D16405562CE}" = DreamStripper
"{11964613-805F-432D-A12B-169554B793E7}" = Nokia Connectivity Cable Driver
"{1A3E23D7-7A1E-43EC-B35D-EB8A31BED943}" = FinalBurner Free v2.9.0.151
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 13
"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}" = Logitech SetPoint
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{39CE3C17-846D-4D9B-8B3E-C01A4B90FB73}" = Virtual Earth 3D (Beta)
"{548EAC70-EE00-11DD-908C-005056806466}" = Google Earth
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6A750221-B84D-419D-B11C-5F597FDBA826}" = Movavi Video Converter 6
"{6D8C8814-00DF-4F4B-BBC7-E817531416CC}" = Norton Spyware Scan
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{996D8BB8-9B47-46C7-92DC-DCCE64467AB8}" = BlueSoleil
"{99A40651-0BC2-4095-8F9A-A40FAB224FEF}" = PC Connectivity Solution
"{A15ED800-19FF-11D5-AF7F-0050BA1191E9}" = InterVideo FilterSDK
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}" = Nokia PC Suite
"{B13F0567-F96A-4BEA-8024-B185F16C9BEF}" =
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B80CC46C-5839-4A48-B051-3CACF23A2718}_is1" = Eraser 5.8
"{C21D5524-A970-42FA-AC8A-59B8C7CDCA31}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D1696920-9794-4BBC-8A30-7A88763DE5A2}" = ABBYY FineReader 5.0 Sprint
"{EA9FAF16-0E5C-42C4-9742-9AF8D5F6D69B}" = ATI Catalyst Control Center
"{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial
"{ED10343F-D30A-4200-9B00-665FC45F52B4}" = ArcSoft VideoImpression 1.6
"{F45298E5-0083-426F-A668-1A2C5F04B8A0}" = FaxTools
"{F6C4EE06-DA6D-45DC-A129-04166F5FF238}" = PC VGA Camera
"0C5EDC3653FED5B121F464339EAC12534D253B25" = Windows Driver Package - Nokia Modem (02/15/2007 3.1)
"4077F884D1BB007055BDB83B621D87220A73F30F" = Windows Driver Package - Nokia (WUDFRd) WPD (06/01/2007 6.84.33.0)
"7-Zip" = 7-Zip 4.57
"ABBYY FineReader 5.0 Sprint" =
"ABC Amber Nokia Converter" = ABC Amber Nokia Converter
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"AddressBook" =
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"All ATI Software" = ATI - Software Uninstall Utility
"Ask Toolbar_is1" = Ask Toolbar
"ATI Display Driver" = ATI Display Driver
"AVerTV DVB-T" = AVerTV DVB-T
"B726756F5B5A5AA9D798B399386FC6205A45F19E" = Windows Driver Package - Nokia Modem (02/15/2007 3.1)
"Branding" =
"BT Yahoo! Applications" = BT Yahoo! Applications
"BT Yahoo! Broadband" = BT Yahoo! Broadband Internet Connection Manager 4.2
"btbb.MCCInstall" = BT Broadband Desktop Help
"BTHomeHub" = BTHomeHub
"CCleaner" = CCleaner (remove only)
"CD8424B9400BFF7D34AA18F816C71322AC4BDAA7" = Windows Driver Package - Nokia Modem (05/24/2007 6.84.0.1)
"Comodo BackUp" = Comodo BackUp
"COMODO Internet Security" = COMODO Internet Security
"COMODO SafeSurf" = COMODO SafeSurf
"Connection Manager" =
"DAZ Studio 2.3" = DAZ Studio
"DirectAnimation" =
"DirectDrawEx" =
"DreamStripper Professional Demo" = DreamStripper Professional Demo
"DVD Shrink_is1" = DVD Shrink 3.2
"DXM_Runtime" =
"expinst" =
"ExpressRip" = Express Rip
"Fontcore" =
"geaia" = Favorit
"HijackThis" = HijackThis 1.99.1
"ICW" =
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"IE40" =
"IE4Data" =
"IE5BAKEX" =
"ie7" = Windows Internet Explorer 7
"IEData" =
"IEREADME" =
"InCD!UninstallKey" = InCD
"InstallShield Uninstall Information" =
"InstallShield_{C21D5524-A970-42FA-AC8A-59B8C7CDCA31}" = QuickTime
"InstallShield_{F6C4EE06-DA6D-45DC-A129-04166F5FF238}" = PC VGA Camera
"Joost" = Joost ™ Beta 1.0.8
"Lexmark X1100 Series" = Lexmark X1100 Series
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Magic Video Converter_is1" = Magic Video Converter Trial Version (English) 8.0.2.18
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft NetShow Player 2.0" =
"MobileOptionPack" =
"Mozilla Firefox (3.0.8)" = Mozilla Firefox (3.0.8)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSI30a-KB884016" =
"MSI30-Beta1" =
"MSI30-Beta2" =
"MSI30-KB884016" =
"MSI30-RC1" =
"MSI30-RC2" =
"MSI31-Beta" =
"MSI31-RC1" =
"MsJavaVM" =
"NetMeeting" =
"Network Play System (Patching)" = Network Play System (Patching)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Nokia PC Suite" = Nokia PC Suite
"OutlookExpress" =
"PCHealth" =
"Picasa 3" = Picasa 3
"Quest3DVirtual Hottie 2" = Virtual Hottie 2
"RealJukebox 1.0" =
"RealPlayer 6.0" = RealPlayer
"SchedulingAgent" =
"Shockwave" =
"Tomb Raider: Legend" = Tomb Raider: Legend 1.2
"Trust 360 USB 2.0 SpaceCam" = Trust 360 USB 2.0 SpaceCam
"Tweak UI 2.10" = Tweak UI
"Virtools3DLifePlayer" = Virtools 3D Life Player
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Toolbar" = Yahoo! Toolbar
"Zattoo" = Zattoo 3.3.1 Beta

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 07/04/2009 20:24:40 | Computer Name = PETERS | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3372, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 08/04/2009 11:35:22 | Computer Name = PETERS | Source = Application Error | ID = 1000
Description = Faulting application GoogleUpdate.exe, version 1.2.131.7, faulting
module GoogleUpdate.exe, version 1.2.131.7, fault address 0x00006eef.

Error - 08/04/2009 11:40:05 | Computer Name = PETERS | Source = Application Error | ID = 1000
Description = Faulting application GoogleUpdate.exe, version 1.2.131.7, faulting
module GoogleUpdate.exe, version 1.2.131.7, fault address 0x00006eef.

Error - 08/04/2009 11:40:12 | Computer Name = PETERS | Source = Application Error | ID = 1004
Description = Faulting application GoogleUpdate.exe, version 1.2.131.7, faulting
module GoogleUpdate.exe, version 1.2.131.7, fault address 0x00006eef.

Error - 08/04/2009 16:49:54 | Computer Name = PETERS | Source = Application Error | ID = 1000
Description = Faulting application GoogleUpdate.exe, version 1.2.131.7, faulting
module GoogleUpdate.exe, version 1.2.131.7, fault address 0x00006eef.

Error - 08/04/2009 16:50:32 | Computer Name = PETERS | Source = Application Error | ID = 1000
Description = Faulting application GoogleUpdate.exe, version 1.2.131.7, faulting
module GoogleUpdate.exe, version 1.2.131.7, fault address 0x00006eef.

Error - 08/04/2009 16:50:46 | Computer Name = PETERS | Source = Application Error | ID = 1004
Description = Faulting application GoogleUpdate.exe, version 1.2.131.7, faulting
module GoogleUpdate.exe, version 1.2.131.7, fault address 0x00006eef.

Error - 08/04/2009 17:21:52 | Computer Name = PETERS | Source = Application Error | ID = 1000
Description = Faulting application GoogleUpdate.exe, version 1.2.131.7, faulting
module GoogleUpdate.exe, version 1.2.131.7, fault address 0x00006eef.

Error - 08/04/2009 17:22:12 | Computer Name = PETERS | Source = Application Error | ID = 1000
Description = Faulting application GoogleUpdate.exe, version 1.2.131.7, faulting
module GoogleUpdate.exe, version 1.2.131.7, fault address 0x00006eef.

Error - 08/04/2009 17:22:18 | Computer Name = PETERS | Source = Application Error | ID = 1004
Description = Faulting application GoogleUpdate.exe, version 1.2.131.7, faulting
module GoogleUpdate.exe, version 1.2.131.7, fault address 0x00006eef.

[ System Events ]
Error - 08/04/2009 17:23:11 | Computer Name = PETERS | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Google Update Service
(gupdate1c99152d3ef0640) service to connect.

Error - 08/04/2009 17:23:11 | Computer Name = PETERS | Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate1c99152d3ef0640) service failed
to start due to the following error: %%1053

Error - 08/04/2009 17:25:38 | Computer Name = PETERS | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 08/04/2009 17:45:15 | Computer Name = PETERS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 08/04/2009 17:45:18 | Computer Name = PETERS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 08/04/2009 17:45:58 | Computer Name = PETERS | Source = Service Control Manager | ID = 7001
Description = The DHCP Client service depends on the NetBios over Tcpip service
which failed to start because of the following error: %%31

Error - 08/04/2009 17:45:58 | Computer Name = PETERS | Source = Service Control Manager | ID = 7001
Description = The DNS Client service depends on the TCP/IP Protocol Driver service
which failed to start because of the following error: %%31

Error - 08/04/2009 17:45:58 | Computer Name = PETERS | Source = Service Control Manager | ID = 7001
Description = The TCP/IP NetBIOS Helper service depends on the AFD Networking Support
Environment service which failed to start because of the following error: %%31

Error - 08/04/2009 17:45:58 | Computer Name = PETERS | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 08/04/2009 17:45:58 | Computer Name = PETERS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD AmdK7 cmdGuard cmdHlp Fips IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip WS2IFSL


< End of report >
Good luck
and thanks again
On completion of this I would like you to run MBAM

Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    O3 - HKLM\..\Toolbar: (no name) - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-84BA-B830E8D4E122} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - Reg Error: Key error. File not found
    O4 - HKCU..\Run: [geaia] "c:\documents and settings\peter\local settings\application data\geaia.exe" geaia ()
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O20 - Winlogon\Notify\geBrrRjK: DllName - geBrrRjK.dll - File not found
    O20 - Winlogon\Notify\xxyawuu: DllName - xxyawuu.dll - File not found
    O28 - HKLM ShellExecuteHooks: {4F06B779-D0FD-4580-8C9B-6EAEB70F10AE} - Reg Error: Key error. File not found
    O34 - HKLM BootExecute: (*) - File not found
    
    :Files
    C:\WINDOWS\ieocx.dll
    C:\Documents and Settings\peter\Local Settings\Application Data\geaia_nav.dat
    C:\Documents and Settings\peter\Local Settings\Application Data\geaia_navps.dat
    C:\Documents and Settings\peter\Local Settings\Application Data\geaia.dat
    C:\Documents and Settings\peter\Local Settings\Application Data\geaia.exe
    C:\Documents and Settings\peter\Application Data\pcdefender.exe
    C:\02174809.mpg
    C:\WINDOWS\info147.sys
    C:\Documents and Settings\All Users\Application Data\grypctkf
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )

THEN

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.
Hi did as asked, did you mean run in ordinary (which i did) or safe mode? got one error message flash up then it run, log below, tried to download MBAM but freezes during set up always on finishing page so will not complete and will not uninstall again just freezes halfway through ========== OTLISTIT ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{8B79EE88-E62D-4AA8-B530-CC357BA112B7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8B79EE88-E62D-4AA8-B530-CC357BA112B7}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4E7BD74F-2B8D-469E-84BA-B830E8D4E122} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-84BA-B830E8D4E122}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{8B79EE88-E62D-4AA8-B530-CC357BA112B7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8B79EE88-E62D-4AA8-B530-CC357BA112B7}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\geaia deleted successfully. c:\documents and settings\peter\local settings\application data\geaia.exe moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geBrrRjK\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xxyawuu\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{4F06B779-D0FD-4580-8C9B-6EAEB70F10AE} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F06B779-D0FD-4580-8C9B-6EAEB70F10AE}\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session manager\\BootExecute:* deleted successfully. ========== FILES ========== LoadLibrary failed for C:\WINDOWS\ieocx.dll C:\WINDOWS\ieocx.dll NOT unregistered. C:\WINDOWS\ieocx.dll moved successfully. C:\Documents and Settings\peter\Local Settings\Application Data\geaia_nav.dat moved successfully. C:\Documents and Settings\peter\Local Settings\Application Data\geaia_navps.dat moved successfully. C:\Documents and Settings\peter\Local Settings\Application Data\geaia.dat moved successfully. File/Folder C:\Documents and Settings\peter\Local Settings\Application Data\geaia.exe not found. C:\Documents and Settings\peter\Application Data\pcdefender.exe moved successfully. C:\02174809.mpg moved successfully. C:\WINDOWS\info147.sys moved successfully. C:\Documents and Settings\All Users\Application Data\grypctkf moved successfully. ========== COMMANDS ========== File delete failed. C:\Documents and Settings\peter\Local Settings\Temp\Perflib_Perfdata_67c.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\peter\Local Settings\Temp\Perflib_Perfdata_91c.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\peter\Local Settings\Temp\Perflib_Perfdata_97c.dat scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\peter\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\peter\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot. User's Temporary Internet Files folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Network Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_3e0.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.12.2 log created on 04092009_172103 Files moved on Reboot… File C:\Documents and Settings\peter\Local Settings\Temp\Perflib_Perfdata_67c.dat not found! File C:\Documents and Settings\peter\Local Settings\Temp\Perflib_Perfdata_91c.dat not found! File C:\Documents and Settings\peter\Local Settings\Temp\Perflib_Perfdata_97c.dat not found! File move failed. C:\Documents and Settings\peter\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\Perflib_Perfdata_3e0.dat not found! Registry entries deleted on Reboot…
OK then lets try the big boy

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a OTListit log so we can continue cleaning the system.
Hi guys
Thats one mean peice of software, make you nervous just running it.
logs for both combofix and OTlist below, and can load programmes again by the looks of it although not run any yet until you give all clear, hats off to you, thanks again for helping us not so cleverones.

OTListIt logfile created on: 09/04/2009 22:01:12 - Run 2
OTListIt2 by OldTimer - Version 2.0.12.2 Folder = C:\Documents and Settings\peter\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.48 Mb Total Physical Memory | 632.76 Mb Available Physical Memory | 61.82% Memory free
2.40 Gb Paging File | 2.06 Gb Available in Paging File | 85.65% Paging File free
Paging file location(s): C:\pagefile.sys 0 0;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 52.99 Gb Free Space | 71.10% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PETERS
Current User Name: peter
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe ()
PRC - C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\Program Files\Comodo\BackUp\CmdBkSvc.exe (COMODO)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
PRC - C:\Program Files\btbb_wcm\McciTrayApp.exe (Motive Communications, Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Yahoo!\browser\ycommon.exe (Yahoo!, Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
PRC - C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe (Lexmark International, Inc.)
PRC - C:\Program Files\COMODO\SafeSurf\cssurf.exe (COMODO)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Eraser\eraser.exe (Heidi Computers Ltd)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
PRC - C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe (Yahoo! Inc.)
PRC - C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE (Logitech Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Comodo\COMODO Internet Security\cfp.exe ()
PRC - C:\Documents and Settings\peter\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (BlueSoleil Hid Service [Disabled | Stopped]) – C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe ()
SRV - (clr_optimization_v2.0.50727_32 [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (cmdAgent [Auto | Running]) – C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe ()
SRV - (ComodoBackupService [Auto | Running]) – C:\Program Files\Comodo\BackUp\CmdBkSvc.exe (COMODO)
SRV - (gupdate1c99152d3ef0640 [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [On_Demand | Stopped]) – File not found
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [Disabled | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (InCDsrv [Disabled | Stopped]) – C:\Program Files\Ahead\InCD\InCDsrv.exe (Ahead Software AG)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KService [Disabled | Stopped]) – C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (LexBceS [Auto | Running]) – C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (ServiceLayer [Disabled | Stopped]) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (STI Simulator [Disabled | Stopped]) – C:\WINDOWS\System32\PAStiSvc.exe ()
SRV - (UMWdf [Auto | Running]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (YPCService [On_Demand | Stopped]) – C:\WINDOWS\system32\YPcservice.exe (Yahoo! Inc.)

========== Driver Services (SafeList) ==========

DRV - (alcan5wn [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\alcan5wn.sys (THOMSON)
DRV - (alcaudsl [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\alcaudsl.sys (THOMSON)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ATTSCAP [Auto | Running]) – C:\WINDOWS\system32\drivers\attscap.sys (AVerMedia Technologies, Inc.)
DRV - (ATVCAP [Auto | Running]) – C:\WINDOWS\system32\drivers\atvcap.sys (AVerMedia Technologies, Inc.)
DRV - (ATXBAR [Auto | Running]) – C:\WINDOWS\system32\drivers\ATXBAR.sys (AVerMedia Technologies, Inc.)
DRV - (BlueletAudio [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\blueletaudio.sys (IVT Corporation)
DRV - (BlueletSCOAudio [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys (IVT Corporation)
DRV - (BT [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\btnetdrv.sys (IVT Corporation)
DRV - (Btcsrusb [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\btcusb.sys (IVT Corporation)
DRV - (BTHidEnum [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\vbtenum.sys ()
DRV - (BTHidMgr [Boot | Running]) – C:\WINDOWS\System32\Drivers\BTHidMgr.sys (IVT Corporation)
DRV - (BTNetFilter [On_Demand | Stopped]) – C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys ()
DRV - (Cam5603C [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\VdCap03C.sys ()
DRV - (catchme [Disabled | Running]) – File not found
DRV - (cmdGuard [System | Running]) – C:\WINDOWS\System32\DRIVERS\cmdguard.sys (COMODO)
DRV - (cmdHlp [System | Running]) – C:\WINDOWS\System32\DRIVERS\cmdhlp.sys (COMODO)
DRV - (cmuda [On_Demand | Running]) – C:\WINDOWS\system32\drivers\cmuda.sys (C-Media Inc)
DRV - (ENTECH [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ENTECH.SYS (EnTech Taiwan)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (InCDfs [Disabled | Running]) – C:\WINDOWS\System32\drivers\incdfs.sys (Ahead Software AG)
DRV - (InCDPass [System | Running]) – C:\WINDOWS\System32\DRIVERS\InCDPass.sys (Ahead Software AG)
DRV - (Inspect [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (L8042Kbd [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys (Logitech, Inc.)
DRV - (L8042mou [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\L8042mou.Sys (Logitech, Inc.)
DRV - (LMouKE [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\LMouKE.Sys (Logitech, Inc.)
DRV - (MREMPR5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5 [On_Demand | Running]) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (ms_mpu401 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (nmwcd [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmwcd.sys (Nokia)
DRV - (nmwcdc [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmwcdc.sys (Nokia)
DRV - (nmwcdcj [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmwcdcj.sys (Nokia)
DRV - (nmwcdcm [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmwcdcm.sys (Nokia)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nv4 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4.sys (NVIDIA Corporation)
DRV - (PAC7311 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PA707UCM.SYS (PixArt Imaging Inc.)
DRV - (pcouffin [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ROOTMODEM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Ser2pl [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ser2pl.sys (Prolific Technology Inc.)
DRV - (SiS7018 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ac97sis.sys (Silicon Integrated Systems Corp.)
DRV - (sisagp [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (TVICHW32 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS (EnTech Taiwan)
DRV - (USB_RNDIS [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\usb8023.sys (Microsoft Corporation)
DRV - (VComm [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\VComm.sys (IVT Corporation)
DRV - (VcommMgr [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\VcommMgr.sys (IVT Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bt.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google.co.uk"
FF - prefs.js..extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/10 23:24:13 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/31 21:25:35 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/29 17:03:44 | 00,000,000 | —D | M]

[2008/07/05 17:27:47 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\mozilla\Extensions
[2008/07/05 17:27:47 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/08 23:06:16 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\mozilla\Firefox\Profiles\oo3sxysz.default\extensions
[2008/12/12 01:17:47 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\mozilla\Firefox\Profiles\oo3sxysz.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2009/04/08 23:06:16 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/03/29 17:03:44 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/05/17 16:54:13 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/11/17 00:43:36 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2009/03/10 23:24:34 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/04/02 21:43:44 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/03/29 17:03:35 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/29 17:03:35 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/11/15 22:49:30 | 00,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2008/11/15 22:49:30 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/11/15 22:49:30 | 00,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2008/11/15 22:49:30 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/15 22:49:30 | 00,000,759 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2008/11/15 22:49:30 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/11/15 22:49:30 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/11/15 22:49:30 | 00,000,831 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SidebarAutoLaunch Class) - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay (ATI Technologies Inc.)
O4 - HKLM..\Run: [btbb_wcm_McciTrayApp] C:\Program Files\btbb_wcm\McciTrayApp.exe (Motive Communications, Inc.)
O4 - HKLM..\Run: [COMODO Internet Security] "C:\Program Files\Comodo\COMODO Internet Security\cfp.exe" -h ()
O4 - HKLM..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s (COMODO)
O4 - HKLM..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" (Lexmark International, Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide (Heidi Computers Ltd)
O4 - HKCU..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~2\YAHOOM~1.EXE" -quiet (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\WINDOWS\system32\GPhotos.scr/200 (Google Inc.)
O9 - Extra Button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [Bluetooth Namespace] - C:\WINDOWS\system32\wshbth.dll (Microsoft Corporation)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (Intertrust Technologies, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} http://download.microsoft.com/download/7/0…tualEarth3D.cab (SentinelVE3D Class)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} C:\Program Files\Yahoo!\common\yucconfig.dll (yucsetreg Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll (Installation Support)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab (Reg Error: Key error.)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} http://download.yahoo.com/dl/installs/ymail/ymmapi.dll (Yahoo! MailTo)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://download.yahoo.com/dl/installs/yab_af.cab (YAddBook Class)
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} http://help.broadbandassist.com/bbdesktop/…tivePreQual.cab (PreQualifier Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} http://eu.download.games.yahoo.com/zylom/a…zylomloader.cab (Zylom Loader Object)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://3dlifeplayer.dl.3dvia.com/player/in…l/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} http://driveragent.com/files/driveragent.cab (Driver Agent ActiveX Control)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{EFBA1530-5D85-4113-95C6-41FD82DA661C}\\NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\cssdll32.dll) - C:\WINDOWS\system32\cssdll32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)

========== Files/Folders - Created Within 30 Days ==========

[5 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\peter\Application Data\*.tmp files]
[2009/04/09 21:51:32 | 00,000,000 | —D | C] – C:\WINDOWS\LastGood
[2009/04/09 21:24:31 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/04/09 21:24:31 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/04/09 21:24:31 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/04/09 21:24:31 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/04/09 21:24:31 | 00,089,504 | —- | C] (Smallfrogs Studio) – C:\WINDOWS\fdsv.exe
[2009/04/09 21:24:31 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/04/09 21:24:31 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/04/09 21:24:31 | 00,049,152 | —- | C] () – C:\WINDOWS\VFIND.exe
[2009/04/09 21:24:31 | 00,029,696 | —- | C] () – C:\WINDOWS\NIRCMD.exe
[2009/04/09 21:23:57 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/04/09 21:23:56 | 00,000,000 | —D | C] – C:\Combo-Fix
[2009/04/09 21:22:16 | 00,073,728 | —- | C] () – C:\pv.exe
[2009/04/09 21:21:37 | 03,067,803 | R— | C] () – C:\Documents and Settings\peter\Desktop\Combo-Fix.exe
[2009/04/09 17:47:11 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware2
[2009/04/09 17:30:02 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/09 17:30:00 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/09 17:21:03 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/04/09 15:38:50 | 00,019,456 | —- | C] () – C:\Documents and Settings\peter\My Documents\covering letter questionnaire.doc
[2009/04/08 22:41:45 | 00,500,736 | —- | C] (OldTimer Tools) – C:\Documents and Settings\peter\Desktop\OTListIt2.exe
[2009/04/07 18:20:47 | 03,067,803 | —- | C] () – C:\Documents and Settings\peter\Desktop\ComboFix.exe
[2009/04/07 17:46:12 | 00,000,933 | —- | C] () – C:\Documents and Settings\peter\Desktop\Spybot - Search & Destroy.lnk
[2009/04/05 23:05:12 | 00,000,064 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/04/02 17:37:45 | 00,000,737 | —- | C] () – C:\Documents and Settings\peter\Desktop\AVerTV DVB-T (2).lnk
[2009/04/02 17:35:51 | 00,000,000 | —D | C] – C:\Documents and Settings\peter\Desktop\bristow and sutor
[2009/03/31 00:03:51 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/03/27 23:54:51 | 00,243,200 | —- | C] () – C:\Documents and Settings\peter\Local Settings\Application Data\umwoegi.exe
[2009/03/24 19:11:34 | 00,000,737 | —- | C] () – C:\Documents and Settings\peter\Desktop\AVerTV DVB-T.lnk
[2009/03/23 00:19:15 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/03/23 00:19:15 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/03/22 00:01:07 | 00,000,000 | —D | C] – C:\WINDOWS\.jagex_cache_32
[2009/03/20 19:12:02 | 00,000,000 | —D | C] – C:\Documents and Settings\peter\Application Data\Media Player Classic
[2009/03/16 21:09:59 | 00,022,016 | —- | C] () – C:\Documents and Settings\peter\My Documents\bristow march09.doc
[2009/03/15 11:11:37 | 00,000,000 | —D | C] – C:\finalburner
[2009/03/14 10:57:55 | 00,000,000 | —D | C] – C:\Program Files\FinalBurner
[2008/12/12 01:16:58 | 00,155,384 | —- | C] () – C:\WINDOWS\System32\guard32.dll
[2008/08/30 23:33:33 | 02,076,672 | —- | C] () – C:\WINDOWS\System32\dz3delight.dll
[2008/08/30 23:33:31 | 06,131,712 | —- | C] () – C:\WINDOWS\System32\daz-qt-mt.dll
[2008/08/30 23:33:31 | 01,785,856 | —- | C] () – C:\WINDOWS\System32\daz-qsa.dll
[2008/01/06 11:32:26 | 00,000,050 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/08/22 23:44:31 | 00,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/08/19 17:13:57 | 00,394,240 | —- | C] () – C:\WINDOWS\System32\Smab.dll
[2007/07/25 15:24:30 | 01,559,040 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2007/03/30 00:00:40 | 00,203,264 | R— | C] () – C:\WINDOWS\System32\CddbCdda.dll
[2007/01/03 00:19:02 | 00,001,275 | —- | C] () – C:\WINDOWS\AVerDVBT.ini
[2006/12/30 21:16:35 | 00,000,441 | —- | C] () – C:\WINDOWS\lexstat.ini
[2006/12/30 21:01:55 | 00,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2006/12/30 17:48:16 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2006/12/30 17:34:42 | 00,005,606 | —- | C] () – C:\WINDOWS\System32\stci.dll
[2006/12/29 19:25:09 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/04/14 10:14:12 | 00,014,312 | —- | C] () – C:\WINDOWS\System32\drivers\BTNetFilter.sys
[2006/03/31 21:57:42 | 00,000,966 | —- | C] () – C:\WINDOWS\videoimp.ini
[2006/03/31 21:57:12 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2006/03/31 21:56:51 | 00,000,021 | —- | C] () – C:\WINDOWS\VI_setup.ini
[2006/03/31 21:55:24 | 00,295,374 | —- | C] () – C:\WINDOWS\System32\drivers\VdCap03C.sys
[2006/03/31 21:55:19 | 00,081,920 | —- | C] () – C:\WINDOWS\System32\VfwExtC.dll
[2006/03/31 21:55:19 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\VfwECamC.dll
[2006/03/31 21:55:19 | 00,015,190 | —- | C] () – C:\WINDOWS\VdTwn03C.ini
[2006/02/26 16:08:28 | 00,585,728 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2006/01/13 23:33:03 | 00,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2005/07/30 08:21:32 | 00,011,988 | —- | C] () – C:\WINDOWS\System32\drivers\vbtenum.sys
[2003/08/18 15:46:38 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\LXBKLCNP.DLL
[2002/11/13 20:40:22 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\lxbkvs.dll
[2002/09/13 16:40:06 | 00,000,266 | —- | C] () – C:\WINDOWS\System32\lxbkcoin.ini
[2001/08/23 13:00:00 | 00,001,049 | —- | C] () – C:\WINDOWS\win.ini
[2001/08/23 13:00:00 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2001/07/25 13:00:10 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\HWINV.DLL
[2001/07/25 13:00:10 | 00,026,572 | —- | C] () – C:\WINDOWS\System32\INV16.DLL
[1999/01/22 19:46:58 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/01/12 09:00:00 | 00,040,448 | —- | C] () – C:\WINDOWS\System32\regobj.dll

========== Files - Modified Within 30 Days ==========

[3 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\peter\Application Data\*.tmp files]
[1 C:\Documents and Settings\peter\My Documents\*.tmp files]
[2009/04/09 21:57:46 | 00,002,473 | —- | M] () – C:\Documents and Settings\peter\Desktop\Microsoft Word.lnk
[2009/04/09 21:42:46 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/04/09 21:41:27 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/04/09 21:40:37 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/09 21:40:32 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/09 21:21:44 | 03,067,803 | R— | M] () – C:\Documents and Settings\peter\Desktop\Combo-Fix.exe
[2009/04/09 15:50:33 | 00,000,441 | —- | M] () – C:\WINDOWS\lexstat.ini
[2009/04/09 15:38:50 | 00,019,456 | —- | M] () – C:\Documents and Settings\peter\My Documents\covering letter questionnaire.doc
[2009/04/08 22:41:45 | 00,500,736 | —- | M] (OldTimer Tools) – C:\Documents and Settings\peter\Desktop\OTListIt2.exe
[2009/04/08 01:53:12 | 00,001,275 | —- | M] () – C:\WINDOWS\AVerDVBT.ini
[2009/04/08 01:23:06 | 00,000,000 | —- | M] () – C:\mediatype.dat
[2009/04/07 18:21:16 | 03,067,803 | —- | M] () – C:\Documents and Settings\peter\Desktop\ComboFix.exe
[2009/04/07 17:46:12 | 00,000,933 | —- | M] () – C:\Documents and Settings\peter\Desktop\Spybot - Search & Destroy.lnk
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/05 23:56:18 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/04/05 23:05:12 | 00,000,064 | —- | M] () – C:\WINDOWS\wininit.ini
[2009/04/04 15:57:54 | 00,245,760 | —- | M] () – C:\Documents and Settings\peter\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/02 17:37:45 | 00,000,737 | —- | M] () – C:\Documents and Settings\peter\Desktop\AVerTV DVB-T (2).lnk
[2009/04/01 22:19:46 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/29 21:28:18 | 00,471,326 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/29 21:28:18 | 00,401,064 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/29 21:28:18 | 00,062,344 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/29 03:30:00 | 00,000,394 | —- | M] () – C:\WINDOWS\tasks\ErrorEasy Scheduled Scan.job
[2009/03/27 23:54:51 | 00,243,200 | —- | M] () – C:\Documents and Settings\peter\Local Settings\Application Data\umwoegi.exe
[2009/03/24 19:11:34 | 00,000,737 | —- | M] () – C:\Documents and Settings\peter\Desktop\AVerTV DVB-T.lnk
[2009/03/23 00:19:15 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/03/22 11:22:17 | 00,001,049 | —- | M] () – C:\WINDOWS\win.ini
[2009/03/22 11:20:59 | 00,002,335 | —- | M] () – C:\Documents and Settings\peter\Desktop\AmCap (2).lnk
[2009/03/20 19:15:14 | 00,023,392 | —- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2009/03/20 19:15:14 | 00,016,832 | —- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2009/03/20 19:14:07 | 00,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2009/03/16 21:16:09 | 00,022,016 | —- | M] () – C:\Documents and Settings\peter\My Documents\bristow march09.doc
[2009/03/14 09:42:28 | 00,253,688 | —- | M] (COMODO) – C:\WINDOWS\System32\cssdll32.dll
[2009/03/11 01:56:51 | 00,000,049 | —- | M] () – C:\WINDOWS\NeroDigital.ini

========== LOP Check ==========

[2009/04/09 17:21:10 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2006/12/29 19:36:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ahead
[2006/07/16 01:21:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/12/12 01:11:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg7
[2008/02/06 21:48:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Bluetooth
[2006/03/13 22:49:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2008/02/22 22:30:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Channel4
[2009/02/19 20:21:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Comodo
[2006/12/29 19:33:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/03/24 02:47:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\dslic
[2007/11/22 00:30:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2009/02/09 21:20:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2008/02/04 20:35:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2008/02/23 11:23:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2008/10/17 23:54:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2007/11/07 22:53:39 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/02/04 17:05:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2008/07/31 17:58:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Software
[2008/07/31 17:58:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2008/02/04 20:38:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2007/01/07 12:39:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QubeSoft
[2006/12/29 19:28:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBT
[2009/04/07 17:45:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/07/25 21:54:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/04/15 16:25:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2008/09/15 22:38:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2006/01/08 15:25:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/07/13 18:12:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2008/05/15 16:41:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\yahoo!
[2006/10/05 21:48:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2006/01/28 20:43:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Zylom
[1 C:\Documents and Settings\peter\Application Data\*.tmp files]
[2009/04/09 17:21:09 | 00,000,000 | RH-D | M] – C:\Documents and Settings\peter\Application Data
[2006/12/07 00:28:18 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Adobe
[2007/07/22 21:32:03 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Ahead
[2007/02/04 17:55:51 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Apple Computer
[2007/09/16 10:50:41 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\ATI
[2006/02/19 23:35:00 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\AverAlbum
[2008/12/12 01:11:41 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\AVG7
[2009/03/03 21:35:37 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Comodo
[2008/09/15 22:33:21 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\ErrorEasy
[2006/01/19 02:04:06 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Google
[2007/02/02 21:36:50 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Help
[2007/09/16 12:09:10 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\IGN_DLM
[2009/02/18 00:20:08 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Joost
[2006/01/13 23:11:12 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Lavasoft
[2006/12/25 11:42:27 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Logitech
[2006/04/16 10:21:43 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Macromedia
[2008/10/17 23:54:14 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Malwarebytes
[2009/03/20 19:12:02 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Media Player Classic
[2009/04/08 23:07:01 | 00,000,000 | –SD | M] – C:\Documents and Settings\peter\Application Data\Microsoft
[2008/07/26 08:43:36 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Motive
[2008/07/05 17:27:47 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Mozilla
[2008/10/05 01:57:24 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\NCH Swift Sound
[2008/03/27 23:48:24 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Nokia
[2009/03/22 13:35:10 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Nokia Multimedia Player
[2007/01/27 21:09:07 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\OTVREG
[2008/02/04 20:38:16 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\PC Suite
[2006/01/08 02:58:26 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Real
[2007/01/25 22:09:18 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\SlipStream
[2006/01/21 01:07:37 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Sun
[2008/08/12 21:47:10 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Ulead Systems
[2007/09/11 21:24:35 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Uniblue
[2009/03/22 23:54:18 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\uTorrent
[2008/05/28 23:53:30 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\vghd
[2007/03/09 00:14:06 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Vso
[2007/09/27 23:43:22 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\WinRAR
[2008/08/09 10:59:58 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Yahoo!
[2001/08/23 13:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/03/29 03:30:00 | 00,000,394 | —- | M] () – C:\WINDOWS\Tasks\ErrorEasy Scheduled Scan.job
[2009/04/09 21:40:37 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\eli car.mpg:SummaryInformation
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EB68C370
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
and Combofix
ComboFix 09-04-04.01 - peter 2009-04-09 21:34:15.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.724 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe
AV: COMODO Antivirus *On-access scanning enabled* (Updated)
FW: COMODO Firewall *enabled*

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\peter\Local Settings\Application Data\geaia_navps.dat
C:\Program Files\ADS Plugins
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\drivers\UACpxetjkvx.sys
C:\WINDOWS\system32\Show Pink Zone.ico
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\UACboylltiv.dll
C:\WINDOWS\system32\UACekcampui.log
C:\WINDOWS\system32\UACibakpgod.dll
C:\WINDOWS\system32\UACilbabrvj.dll
C:\WINDOWS\system32\uacinit.dll
C:\WINDOWS\system32\UACkkfvnsdr.dat
C:\WINDOWS\system32\UACrbitsmkn.log
C:\WINDOWS\system32\UACuipmyxym.log
C:\WINDOWS\system32\UACutewqxwp.dll
C:\WINDOWS\system32\UACwqptqscg.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat . . . . failed to delete
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat . . . . failed to delete

—– BITS: Possible infected sites —–

hxxp://tubeloyaln.com
hxxp://sunmicro.ht.rd.llnw.net
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-03-09 to 2009-04-09 )))))))))))))))))))))))))))))))
.

2009-04-09 21:22 . 2006-03-03 00:42 73,728 –a—— C:\pv.exe
2009-04-09 17:47 . 2009-04-09 18:09 d——– C:\Program Files\Malwarebytes' Anti-Malware2
2009-04-09 17:30 . 2009-04-06 15:32 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2009-04-09 17:30 . 2009-04-06 15:32 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2009-04-09 17:21 . 2009-04-09 17:21 d——– C:\_OTListIt
2009-04-05 23:05 . 2009-04-05 23:05 64 –a—— C:\WINDOWS\wininit.ini
2009-03-31 00:03 . 2009-03-31 00:03 d——– C:\Program Files\Microsoft Silverlight
2009-03-23 00:19 . 2009-04-05 23:56 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2009-03-23 00:19 . 2009-03-23 00:19 1,409 –a—— C:\WINDOWS\QTFont.for
2009-03-22 00:01 . 2009-03-22 00:01 d——– C:\WINDOWS\.jagex_cache_32
2009-03-22 00:01 . 2009-03-22 00:02 34 –a—— C:\Documents and Settings\peter\jagex_runescape_preferences.dat
2009-03-20 19:12 . 2009-03-20 19:12 d——– C:\Documents and Settings\peter\Application Data\Media Player Classic
2009-03-15 11:11 . 2009-03-15 11:11 d——– C:\finalburner
2009-03-14 10:57 . 2009-03-14 10:58 d——– C:\Program Files\FinalBurner

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-09 20:31 ——— d—–w C:\Program Files\Eraser
2009-04-09 16:44 ——— d—–w C:\Program Files\Malwarebytes' Anti-Malware
2009-04-09 14:50 ——— d—–w C:\Program Files\Lexmark X1100 Series
2009-04-08 22:07 ——— d—–w C:\Program Files\DreamStripper Professional Demo
2009-04-08 00:53 ——— d—–w C:\Program Files\AVerTV DVB-T
2009-04-08 00:23 0 —-a-w C:\mediatype.dat
2009-04-07 16:46 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2009-04-07 16:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-02 20:43 ——— d—–w C:\Program Files\Java
2009-03-22 22:54 ——— d—–w C:\Documents and Settings\peter\Application Data\uTorrent
2009-03-22 12:35 ——— d—–w C:\Documents and Settings\peter\Application Data\Nokia Multimedia Player
2009-03-14 08:42 253,688 —-a-w C:\WINDOWS\system32\cssdll32.dll
2009-03-13 17:32 ——— d—–w C:\Program Files\Common Files\Ahead
2009-03-13 17:32 ——— d—–w C:\Program Files\Ahead
2009-03-09 04:19 410,984 —-a-w C:\WINDOWS\system32\deploytk.dll
2009-03-03 20:35 ——— d—–w C:\Documents and Settings\peter\Application Data\Comodo
2009-03-03 20:30 ——— d—–w C:\Program Files\Comodo
2009-02-26 21:57 155,384 —-a-w C:\WINDOWS\system32\guard32.dll
2009-02-26 21:56 110,992 —-a-w C:\WINDOWS\system32\drivers\cmdguard.sys
2009-02-19 19:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Comodo
2009-02-19 19:17 24,336 —-a-w C:\WINDOWS\system32\drivers\cmdhlp.sys
2009-02-17 23:20 ——— d—–w C:\Documents and Settings\peter\Application Data\Joost
2009-02-17 22:55 ——— d—–w C:\Program Files\Google
2009-02-09 20:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2007-03-08 23:14 87,608 —-a-w C:\Documents and Settings\peter\Application Data\ezpinst.exe
2007-03-08 23:14 47,360 —-a-w C:\Documents and Settings\peter\Application Data\pcouffin.sys
2008-09-04 19:55 32,768 –sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090420080905\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-08-06 16:20 279944 –a—— C:\Program Files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "C:\Program Files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 16:20 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "C:\Program Files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 16:20 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~2\YAHOOM~1.EXE" [2007-08-30 17:43 4670704]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 01:12 15360]
"Eraser"="C:\Program Files\Eraser\eraser.exe" [2006-08-07 22:07 634880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 17:19 129536]
"btbb_wcm_McciTrayApp"="C:\Program Files\btbb_wcm\McciTrayApp.exe" [2005-12-29 11:22 543232]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 16:41 45056]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 15:43 57344]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-01-08 02:56 180269]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-07-16 01:18 282624]
"COMODO SafeSurf"="C:\Program Files\COMODO\SafeSurf\cssurf.exe" [2009-03-14 09:42 278264]
"COMODO Internet Security"="C:\Program Files\Comodo\COMODO Internet Security\cfp.exe" [2009-02-26 22:56 1851128]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2009-03-09 05:19 148888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 01:12 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 11:17 1241088]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2006-12-25 11:34:27 450560]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\WINDOWS\system32\cssdll32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.dvsd"= pdvcodec.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BT Broadband Desktop Help.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BT Broadband Desktop Help.lnk
backup=C:\WINDOWS\pss\BT Broadband Desktop Help.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^peter^Start Menu^Programs^Startup^VirtuaGirl HD.LNK]
path=C:\Documents and Settings\peter\Start Menu\Programs\Startup\VirtuaGirl HD.LNK
backup=C:\WINDOWS\pss\VirtuaGirl HD.LNKStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\btbb_McciTrayApp]
——— 2007-05-23 07:22 936960 C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
–a—— 2006-08-07 22:07 634880 C:\Program Files\Eraser\eraser.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
——— 2004-03-24 11:41 1294446 C:\Program Files\Ahead\InCD\InCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]
–a—— 2007-04-23 12:23 1032640 C:\Program Files\Kontiki\KHost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-14 01:12 1695232 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
–a—— 2007-06-18 16:10 271360 C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickDVBT]
–a—— 2004-03-17 14:28 196608 C:\Program Files\AVerTV DVB-T\QuickDVB-T.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-07-16 01:18 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-11-10 14:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SWHelper]
–a—— 2009-03-22 11:52 53248 C:\WINDOWS\system32\Macromed\Shockwave 10\PostUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2006-01-08 02:56 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
–a—— 2008-04-14 01:12 110592 C:\WINDOWS\system32\bthprops.cpl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"STI Simulator"=2 (0x2)
"ServiceLayer"=3 (0x3)
"KService"=2 (0x2)
"InCDsrv"=2 (0x2)
"IDriverT"=3 (0x3)
"BlueSoleil Hid Service"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Joost\\xulrunner\\tvprunner.exe"=

R2 gupdate1c99152d3ef0640;Google Update Service (gupdate1c99152d3ef0640);C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-17 23:55 133104]
R3 PAC7311;VGA SoC PC-Camera;C:\WINDOWS\system32\DRIVERS\PA707UCM.SYS [2005-10-18 12:48 154752]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2009-02-26 22:56 110992]
S1 cmdHlp;COMODO Internet Security Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2009-02-19 20:17 24336]
S2 ATTSCAP;AVerMedia, WDM MPEG-2 TS Capture (DVBT);C:\WINDOWS\system32\drivers\attscap.sys [2003-06-24 12:19 18048]
S2 ATVCAP;AVerMedia, DVB-T WDM Video Capture;C:\WINDOWS\system32\drivers\atvcap.sys [2003-06-24 12:22 56320]
S2 ATXBAR;AVerMedia, DVB-T WDM Crossbar;C:\WINDOWS\system32\drivers\ATXBAR.sys [2003-06-24 12:23 8576]
S2 ComodoBackupService;ComodoBackupService;C:\Program Files\Comodo\BackUp\CmdBkSvc.exe [2009-03-03 21:30 1023488]


— Other Services/Drivers In Memory —

*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - Ati HotKey Poller
*Deregistered* - ATI Smart
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - Beep
*Deregistered* - BITS
*Deregistered* - BlueletAudio
*Deregistered* - BlueletSCOAudio
*Deregistered* - Browser
*Deregistered* - BT
*Deregistered* - BTHidEnum
*Deregistered* - BTHidMgr
*Deregistered* - BthServ
*Deregistered* - Cdfs
*Deregistered* - cmdAgent
*Deregistered* - cmdGuard
*Deregistered* - cmdHlp
*Deregistered* - ComodoBackupService
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - gupdate1c99152d3ef0640
*Deregistered* - helpsvc
*Deregistered* - HTTP
*Deregistered* - HTTPFilter
*Deregistered* - ImapiService
*Deregistered* - InCDfs
*Deregistered* - Inspect
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - JavaQuickStarterService
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LexBceS
*Deregistered* - LmHosts
*Deregistered* - mnmdd
*Deregistered* - Modem
*Deregistered* - MountMgr
*Deregistered* - MRENDIS5
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - UMWdf
*Deregistered* - Update
*Deregistered* - VComm
*Deregistered* - VcommMgr
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - WmiApSrv
*Deregistered* - WS2IFSL
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
Contents of the 'Scheduled Tasks' folder

2009-03-29 C:\WINDOWS\Tasks\ErrorEasy Scheduled Scan.job
- C:\Program Files\ErrorEasy\ErrorEasy.exe []

2009-03-29 C:\WINDOWS\Tasks\ErrorEasy Scheduled Scan.job
- C:\Program Files\ErrorEasy []
.
- - - - ORPHANS REMOVED - - - -

BHO-{4F06B779-D0FD-4580-8C9B-6EAEB70F10AE} - (no file)
HKCU-Run-geaia - c:\documents and settings\peter\local settings\application data\geaia.exe
MSConfigStartUp-ISTray - C:\Program Files\Spyware Doctor\pctsTray.exe
MSConfigStartUp-Motive SmartBridge - C:\PROGRA~1\BTBROA~1\SMARTB~1\BTHelpNotifier.exe
MSConfigStartUp-NeroFilterCheck - C:\WINDOWS\system32\NeroCheck.exe
MSConfigStartUp-Uniblue RegistryBooster 2 - C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
MSConfigStartUp-Veoh - C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
MSConfigStartUp-Cmaudio - cmicnfg.cpl


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bt.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
IE: Add to Google Photos Screensa&ver; - C:\WINDOWS\system32\GPhotos.scr/200
TCP: {EFBA1530-5D85-4113-95C6-41FD82DA661C} = 208.67.220.220,208.67.222.222
DPF: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
FF - ProfilePath - C:\Documents and Settings\peter\Application Data\Mozilla\Firefox\Profiles\oo3sxysz.default\
FF - prefs.js: browser.search.selectedEngine - Google.co.uk
FF - plugin: C:\Program Files\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npJoostPlugin.dll
FF - plugin: C:\Program Files\Virtual Earth 3D\npVE3D.dll
.

**************************************************************************
scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-606747145-1708537768-854245398-1003\0*" ¨*!*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"WriteErrorLog"="No"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(904)
C:\WINDOWS\system32\guard32.dll
C:\WINDOWS\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(964)
C:\WINDOWS\system32\guard32.dll

- - - - - - - > 'explorer.exe'(1032)
C:\WINDOWS\system32\guard32.dll
C:\Program Files\Logitech\SetPoint\lgscroll.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\PROGRA~1\Yahoo!\MESSEN~2\Ymsgr_tray.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
.
**************************************************************************
.
Completion time: 2009-04-09 21:46:47 - machine was rebooted [peter]
ComboFix-quarantined-files.txt 2009-04-09 20:46:38

Pre-Run: 56,930,127,872 bytes free
Post-Run: 57,020,588,032 bytes free

390 — E O F — 2008-12-10 22:06:37
OK that looks pretty now ;)

You had the UAC rootkit so lets now run MBAM and see what orphans are left, also what problems are you experiencing on completion of this ?

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.
loaded and ran MBAM with no problem found six problems and got rid of them, log below. Just want to say a massive thanks to you guys the internet would be a hard place without you sorts. Many thanks again. Malwarebytes' Anti-Malware 1.36 Database version: 1945 Windows 5.1.2600 Service Pack 3 10/04/2009 15:43:46 mbam-log-2009-04-10 (15-43-46).txt Scan type: Quick Scan Objects scanned: 77424 Time elapsed: 4 minute(s), 51 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 5 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{72aec387-4e92-4db2-8c6b-4f4496887f35} (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Cheers again.
Even better a few orphan registry entries :thumbup: Now subject to no further problems

Now the best part of the day —– Your log now appears clean :thumbup:

A good workman always cleans up after himself so..Run OTListit and hit the cleanup button. It will remove all the programmes we have used plus itself. MBAM can be uninstalled via control panel add/remove along with ERUNT. But they may be useful tools to keep

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

Upgrading Java:
  • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 13.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u13-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u13-windows-i586-p.exe and select "Run as an Administrator.")

XP
Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE
You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SuperAntispyware Run weekly to keep your system clean
It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :wavey:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI