This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Browser Redirections to unknown search sites.

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi- I have had a problem since last week and I hope that someone may be willing to help-
Toshiba Laptop running XP. Firefox (and IE/Chrome when tried) has been redirecting to unknown search pages showing results related to the target page. PC has been ver slow- often 20 secs to even show signs of acknowledging a command.
Very frequent crashes of browser and any applications which are running.

Norton shows no problems, Spyware Doctor reveals adware continually - claims to have cleaned it but problems remain and the next scan reveals further problems.
Windows defender reveals nothing.

Any help much appreciated.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:16:44, on 10/04/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\USBStorage\USBDetector.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Lexmark 2400 Series\lxcrmon.exe
C:\Program Files\Lexmark 2400 Series\ezprint.exe
C:\Program Files\Atheros\ACU.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\Program Files\MouseDriver\OfficeMouse.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Documents and Settings\Lar and Svet\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\lxcrcoms.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Safari\Safari.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [USBDetector] C:\USBStorage\USBDetector.exe
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\PROGRA~1\Symantec\osCheck.exe"
O4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [iWareV3] C:\Program Files\MouseDriver\OfficeMouse.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Lar and Svet\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://flashcasino.ladbrokes.com/instant-p…-en/FlashAX.cab
O23 - Service: Atheros Configuration Service (ACS) - Atheros - C:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: Google Update Service (gupdate1c9b8beff34d2de) (gupdate1c9b8beff34d2de) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\PROGRA~1\Symantec\isPwdSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

–
End of file - 11290 bytes

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.


Unless informed of in advance, failure to post replies within 5 days will result in this thread being closed.


Hi Larka

I'm Gary R, I'll be glad to help you with your computer problems.

Before we start: Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Because of this, I advise you to backup any personal files and folders before you start.

Please observe these rules while we work:
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with it till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
If you can do these things, everything should go smoothly.
  • If you're using XP, you'll need Administrator privileges to perform the fixes. (XP accounts are Administrator by default)
  • If you're using Vista, it will be necessary to right click all tools we use and select —-> Run as Admistrator

It may be helpful to you to print out or take a copy of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.


Nothing showing on your HJT log, but there's a whole lot of areas that HJT doesn't look at, so I'd like to run some further scans that should hopefully show us what we need to know.

First I'd like to ask: Do you use a router to connect to the internet ?

Next

Download OTListIt2 by OldTimer to your Desktop.

  • Double click OTListIt2.exe to launch the programme.
  • Check the following.
    • Scan all users.
    • Lop check.
    • Purity check.
  • Under Extra Registry section, select Use SafeList
  • Click the Run Scan button and wait for the scan to finish (usually about 10-15 mins).
  • When finished it will produce two logs.
    • OTListIt.txt (open on your desktop).
    • Extras.txt (minimised in your taskbar)
  • Please post me both logs.

Next

Please do a scan with ESET Online Scanner
Note: The scan will only work with Internet Explorer
  • Check the box "Yes, I accept the Terms of Use" and click Start
  • Accept the ActiveX by clicking the yellow bar at the top.
  • Install the software when prompted.
  • Read the Welcome notice and then click Start to download the necessary components.
  • When download is complete, make sure Remove found threats stays Unchecked.
  • Click Start to begin the scan.
  • After the scan completes, the Details tab in the Results window will display what was found.
  • A file will also be saved at: C:/program files/esetonlinescanner/log.txt
  • Please post me the content of that file.

Summary of the logs I need from you in your next post:
  • OTListIt.txt
  • Extra.txt
  • E-Set log


Please post each log separately to prevent them being cut off by the forum post size limiter.
Gary,
Thanks for taking this on. My connection is via a cable modem (provider is a cable tv company).
I have the OTLISTIT files but cannot run the ESET- I agree with the terms of use- it then asks me to download an activex , which I do- I then start the 3 steps and immediately get a message update failed error 200.
I will post the two logs I have and continue to try with ESET.

regards,
Lar

OTListIt logfile created on: 11/04/2009 18:42:46 - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Lar and Svet\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

510.98 Mb Total Physical Memory | 239.79 Mb Available Physical Memory | 46.93% Memory free
1.22 Gb Paging File | 0.56 Gb Available in Paging File | 45.50% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 83.86 Gb Free Space | 75.02% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OUR
Current User Name: Lar and Svet
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2006/11/03 19:19:58 | 00,013,592 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MsMpEng.exe
PRC - [2007/01/10 00:59:32 | 00,108,648 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2007/01/05 03:19:28 | 00,047,712 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
PRC - [2005/09/05 09:40:42 | 00,376,917 | —- | M] (Atheros) – C:\WINDOWS\system32\acs.exe
PRC - [2007/09/12 13:27:24 | 00,554,352 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
PRC - [2007/01/10 00:59:32 | 00,108,648 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2009/01/16 16:31:58 | 00,161,064 | —- | M] (Seagate Technology LLC) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
PRC - [2009/03/09 05:19:15 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/04/08 21:56:27 | 00,133,104 | —- | M] (Google Inc.) – C:\Program Files\Google\Update\GoogleUpdate.exe
PRC - [2003/07/31 18:08:00 | 00,077,824 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvsvc32.exe
PRC - [2005/09/13 04:45:16 | 00,053,248 | R— | M] (Prolific Technology Inc.) – C:\WINDOWS\system32\IoctlSvc.exe
PRC - [2008/06/13 15:29:14 | 00,356,920 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsAuxs.exe
PRC - [2009/04/08 22:52:59 | 01,079,176 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsSvc.exe
PRC - [2007/06/13 05:23:07 | 01,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2009/04/08 22:53:16 | 01,168,264 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsTray.exe
PRC - [2004/01/07 04:55:02 | 00,053,248 | —- | M] (ali) – C:\USBStorage\USBDetector.exe
PRC - [2007/06/26 08:48:14 | 00,509,224 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\YOP\yop.exe
PRC - [2007/01/10 00:59:52 | 00,115,816 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2006/01/22 12:45:08 | 00,286,720 | —- | M] () – C:\Program Files\Lexmark 2400 Series\lxcrmon.exe
PRC - [2006/03/03 09:18:10 | 00,200,704 | —- | M] (Yahoo!, Inc.) – C:\Program Files\Yahoo!\browser\ycommon.exe
PRC - [2006/02/07 00:10:34 | 00,098,304 | —- | M] (Lexmark International Inc.) – C:\Program Files\Lexmark 2400 Series\ezprint.exe
PRC - [2005/09/05 09:40:58 | 00,331,776 | —- | M] (Atheros Communications, Inc.) – C:\Program Files\Atheros\ACU.exe
PRC - [2003/07/18 10:24:08 | 00,049,152 | —- | M] (COMPAL ELECTRONIC INC.) – C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
PRC - [2006/11/03 06:01:16 | 00,319,488 | —- | M] (PixArt Imaging Incorporation) – C:\WINDOWS\PixArt\PAC207\Monitor.exe
PRC - [2007/12/07 23:35:02 | 00,471,040 | —- | M] () – C:\Program Files\MouseDriver\OfficeMouse.exe
PRC - [2006/11/03 19:20:12 | 00,866,584 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2009/01/16 16:31:26 | 00,181,544 | —- | M] (Seagate LLC) – C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
PRC - [2006/06/01 08:32:12 | 00,094,208 | —- | M] (Nero AG) – C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2008/09/27 13:05:28 | 00,133,104 | —- | M] (Google Inc.) – C:\Documents and Settings\Lar and Svet\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
PRC - [2007/02/16 07:20:32 | 00,628,352 | —- | M] (Symantec Corporation) – C:\Program Files\Yahoo!\YOP\SSDK02.exe
PRC - [2006/02/02 22:11:22 | 00,495,616 | —- | M] ( ) – C:\WINDOWS\system32\lxcrcoms.exe
PRC - [2008/01/11 18:22:27 | 01,174,664 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PRC - [2009/04/11 18:41:08 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lar and Svet\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2005/09/05 09:40:42 | 00,376,917 | —- | M] (Atheros) – C:\WINDOWS\system32\acs.exe – (ACS [Auto | Running])
SRV - [2008/01/13 18:29:58 | 00,068,096 | —- | M] () – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe – (Adobe LM Service [On_Demand | Stopped])
SRV - [2003/10/13 11:24:14 | 00,061,440 | —- | M] (Adobe Sytems) – C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe – (AdobeVersionCue [On_Demand | Stopped])
SRV - [2005/09/23 07:28:32 | 00,029,896 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2007/09/12 13:27:24 | 00,554,352 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe – (Automatic LiveUpdate Scheduler [Auto | Running])
SRV - [2007/01/10 00:59:32 | 00,108,648 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (ccEvtMgr [Auto | Running])
SRV - [2007/01/10 00:59:32 | 00,108,648 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (ccSetMgr [Auto | Running])
SRV - [2005/09/23 07:28:56 | 00,066,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2007/01/10 00:59:32 | 00,108,648 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (CLTNetCnService [Auto | Running])
SRV - [2007/01/12 22:40:58 | 00,049,248 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe – (comHost [On_Demand | Stopped])
SRV - [2009/01/16 16:31:58 | 00,161,064 | —- | M] (Seagate Technology LLC) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe – (FreeAgentGoNext Service [Auto | Running])
SRV - [2009/04/08 21:56:27 | 00,133,104 | —- | M] (Google Inc.) – C:\Program Files\Google\Update\GoogleUpdate.exe – (gupdate1c9b8beff34d2de [Auto | Stopped])
SRV - [2009/04/08 21:41:49 | 00,183,280 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [Auto | Stopped])
SRV - [2004/08/03 15:56:46 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2005/11/13 20:06:04 | 00,069,632 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2007/01/14 02:11:06 | 00,080,504 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\isPwdSvc.exe – (ISPwdSvc [On_Demand | Stopped])
SRV - [2009/03/09 05:19:15 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2007/09/12 13:27:24 | 02,999,664 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE – (LiveUpdate [On_Demand | Stopped])
SRV - [2007/01/10 00:59:32 | 00,108,648 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (LiveUpdate Notice Ex [Auto | Running])
SRV - [2008/01/29 11:38:31 | 00,583,048 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe – (LiveUpdate Notice Service [Auto | Stopped])
SRV - [2006/02/02 22:11:22 | 00,495,616 | —- | M] ( ) – C:\WINDOWS\system32\lxcrcoms.exe – (lxcr_device [On_Demand | Running])
SRV - [2003/07/31 18:08:00 | 00,077,824 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvsvc32.exe – (NVSvc [Auto | Running])
SRV - [2003/07/28 07:28:22 | 00,089,136 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2005/09/13 04:45:16 | 00,053,248 | R— | M] (Prolific Technology Inc.) – C:\WINDOWS\system32\IoctlSvc.exe – (PLFlash DeviceIoControl Service [Auto | Running])
SRV - [2008/06/13 15:29:14 | 00,356,920 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsAuxs.exe – (sdAuxService [Auto | Running])
SRV - [2009/04/08 22:52:59 | 01,079,176 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsSvc.exe – (sdCoreService [Auto | Running])
SRV - [2008/01/11 18:22:27 | 01,174,664 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe – (Symantec Core LC [On_Demand | Running])
SRV - [2007/01/05 03:19:28 | 00,047,712 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe – (SymAppCore [Auto | Running])
SRV - [2007/10/18 06:31:54 | 00,098,328 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\Messenger\usnsvc.exe – (usnjsvc [On_Demand | Stopped])
SRV - [2006/11/03 19:19:58 | 00,013,592 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MsMpEng.exe – (WinDefend [Auto | Running])
SRV - [2007/10/25 10:27:54 | 00,266,240 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe – (WLSetupSvc [On_Demand | Stopped])
SRV - [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])
SRV - [2003/05/19 11:07:38 | 00,086,016 | —- | M] (Yahoo! Inc.) – C:\WINDOWS\system32\YPcservice.exe – (YPCService [On_Demand | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2008/01/23 20:03:47 | 00,019,915 | —- | M] (Meetinghouse Data Communications) – C:\WINDOWS\system32\DRIVERS\AegisP.sys – (AegisP [Auto | Running])
DRV - [2006/11/10 10:05:00 | 00,018,688 | —- | M] (Arcsoft, Inc.) – C:\WINDOWS\system32\drivers\Afc.sys – (Afc [On_Demand | Running])
DRV - [2008/09/24 10:40:22 | 04,122,368 | R— | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM [On_Demand | Running])
DRV - [2005/08/29 21:14:22 | 00,486,656 | —- | M] (Atheros Communications, Inc.) – C:\WINDOWS\system32\DRIVERS\ar5211.sys – (AR5211 [On_Demand | Stopped])
DRV - [2009/02/25 04:00:00 | 00,371,248 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl [System | Running])
DRV - [2009/02/25 04:00:00 | 00,101,936 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv [On_Demand | Running])
DRV - [2009/04/08 22:52:40 | 00,040,840 | —- | M] (PCTools Research Pty Ltd.) – C:\WINDOWS\system32\drivers\ikfilesec.sys – (IKFileSec [Boot | Running])
DRV - [2009/04/08 22:52:41 | 00,066,952 | —- | M] (PCTools Research Pty Ltd.) – C:\WINDOWS\system32\drivers\iksysflt.sys – (IKSysFlt [System | Running])
DRV - [2009/04/08 22:52:41 | 00,081,288 | —- | M] (PCTools Research Pty Ltd.) – C:\WINDOWS\system32\drivers\iksyssec.sys – (IKSysSec [System | Running])
DRV - [2009/02/20 04:00:00 | 00,089,104 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090411.003\NAVENG.SYS – (NAVENG [On_Demand | Running])
DRV - [2009/02/20 04:00:00 | 00,876,144 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090411.003\NAVEX15.SYS – (NAVEX15 [On_Demand | Running])
DRV - [2003/07/31 18:08:00 | 01,329,723 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys – (nv [On_Demand | Running])
DRV - [2007/06/12 06:39:38 | 00,508,416 | —- | M] (PixArt Imaging Inc.) – C:\WINDOWS\system32\DRIVERS\PFC027.SYS – (PAC207 [On_Demand | Stopped])
DRV - [2003/09/25 22:53:00 | 00,010,368 | —- | M] (Padus, Inc.) – C:\WINDOWS\system32\drivers\pfc.sys – (pfc [On_Demand | Running])
DRV - [2001/08/23 07:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\system32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2008/07/31 17:17:04 | 00,043,872 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2004/08/03 17:31:34 | 00,020,992 | —- | M] (Realtek Semiconductor Corporation) – C:\WINDOWS\system32\DRIVERS\RTL8139.SYS – (rtl8139 [On_Demand | Running])
DRV - [2007/11/13 05:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\system32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2001/08/17 08:56:16 | 00,007,552 | —- | M] (Sony Corporation) – C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS – (SONYPVU1 [On_Demand | Stopped])
DRV - [2007/04/13 21:49:32 | 00,418,104 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys – (SPBBCDrv [System | Running])
DRV - [2007/11/30 18:57:12 | 00,279,088 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\Drivers\SRTSP.SYS – (SRTSP [On_Demand | Running])
DRV - [2007/11/30 18:57:12 | 00,317,616 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\Drivers\SRTSPL.SYS – (SRTSPL [On_Demand | Stopped])
DRV - [2007/11/30 18:57:12 | 00,043,696 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\Drivers\SRTSPX.SYS – (SRTSPX [System | Running])
DRV - [2002/07/17 12:45:48 | 00,004,183 | —- | M] () – C:\WINDOWS\System32\Drivers\TPIoMngr.sys – (SrvcTPIOMngr [System | Running])
DRV - [2008/10/03 15:14:08 | 00,012,848 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\Drivers\SYMDNS.SYS – (SYMDNS [On_Demand | Running])
DRV - [2009/02/16 20:20:01 | 00,124,464 | —- | M] (Symantec Corporation) – C:\WINDOWS\system32\Drivers\SYMEVENT.SYS – (SymEvent [On_Demand | Running])
DRV - [2008/10/03 15:14:10 | 00,146,096 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\Drivers\SYMFW.SYS – (SYMFW [On_Demand | Running])
DRV - [2008/10/03 15:14:10 | 00,039,984 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\Drivers\SYMIDS.SYS – (SYMIDS [On_Demand | Running])
DRV - [2009/02/09 17:59:18 | 00,251,768 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20090404.001\SymIDSCo.sys – (SYMIDSCO [On_Demand | Running])
DRV - [2008/10/03 15:14:10 | 00,035,120 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS – (SYMNDIS [On_Demand | Running])
DRV - [2008/10/03 15:14:10 | 00,027,696 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS – (SYMREDRV [On_Demand | Running])
DRV - [2008/10/03 15:14:10 | 00,187,952 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS – (SYMTDI [System | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar;=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-789336058-1563985344-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar;=msnhome
IE - HKU\S-1-5-21-789336058-1563985344-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
IE - HKU\S-1-5-21-789336058-1563985344-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-789336058-1563985344-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-21-789336058-1563985344-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\S-1-5-21-789336058-1563985344-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-789336058-1563985344-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-789336058-1563985344-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-789336058-1563985344-839522115-1003\S-1-5-21-789336058-1563985344-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-789336058-1563985344-839522115-1003\S-1-5-21-789336058-1563985344-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "chrome://speeddial/content/speeddial.xul"
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090123.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.0.3
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008/12/19 16:42:48 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/11 17:49:29 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/09 19:11:25 | 00,000,000 | —D | M]

[2008/09/10 18:55:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\mozilla\Extensions
[2008/09/10 18:55:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/11 08:33:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\mozilla\Firefox\Profiles\f4e9w3pa.default\extensions
[2009/02/06 19:00:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\mozilla\Firefox\Profiles\f4e9w3pa.default\extensions\{07d43380-b306-4a08-a47a-140efd1b4700}
[2009/04/05 22:48:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\mozilla\Firefox\Profiles\f4e9w3pa.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2009/01/07 00:52:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\mozilla\Firefox\Profiles\f4e9w3pa.default\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
[2009/02/05 02:15:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\mozilla\Firefox\Profiles\f4e9w3pa.default\extensions\{8c483120-01da-11d9-9669-0800200c9a66}
[2009/02/05 01:56:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\mozilla\Firefox\Profiles\f4e9w3pa.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2008/07/23 17:30:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\mozilla\Firefox\Profiles\f4e9w3pa.default\extensions\{DAD0F81A-CF67-4eed-98D6-26F6E47274CA}
[2009/03/06 00:04:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\mozilla\Firefox\Profiles\f4e9w3pa.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2009/04/01 19:05:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\mozilla\Firefox\Profiles\f4e9w3pa.default\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
[2009/01/07 00:51:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\mozilla\Firefox\Profiles\f4e9w3pa.default\extensions\dropio@dropio
[2009/01/23 01:41:09 | 00,002,192 | —- | M] () – C:\Documents and Settings\Lar and Svet\Application Data\Mozilla\FireFox\Profiles\f4e9w3pa.default\searchplugins\qtl.xml
[2009/04/11 08:33:24 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/03/27 20:03:22 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/01/13 21:40:05 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008/03/17 15:37:51 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/08/14 08:57:20 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2008/12/19 16:43:12 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/04/05 22:36:25 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/03/27 20:03:14 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/27 20:03:15 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/02/05 01:34:58 | 00,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2009/02/05 01:34:58 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/02/05 01:34:58 | 00,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2009/02/05 01:34:58 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/02/05 01:34:58 | 00,000,759 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2009/02/05 01:34:58 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/02/05 01:34:58 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/02/05 01:34:58 | 00,000,831 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (UberButton Class) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo!)
O2 - BHO: (YahooTaggedBM Class) - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SidebarAutoLaunch Class) - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - SITEguard - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-789336058-1563985344-839522115-1003\..\Toolbar\WebBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKU\S-1-5-21-789336058-1563985344-839522115-1003\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKU\S-1-5-21-789336058-1563985344-839522115-1003\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKU\S-1-5-21-789336058-1563985344-839522115-1003\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui (Atheros Communications, Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
O4 - HKLM..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe" (Lexmark International Inc.)
O4 - HKLM..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s ()
O4 - HKLM..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe" (PC Tools)
O4 - HKLM..\Run: [iWareV3] C:\Program Files\MouseDriver\OfficeMouse.exe ()
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16 ()
O4 - HKLM..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe" ()
O4 - HKLM..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" (Seagate LLC)
O4 - HKLM..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [osCheck] "C:\PROGRA~1\Symantec\osCheck.exe" (Symantec Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" (Symantec Corporation)
O4 - HKLM..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [USBDetector] C:\USBStorage\USBDetector.exe (ali)
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
O4 - HKLM..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart (Yahoo! Inc.)
O4 - HKU\S-1-5-21-789336058-1563985344-839522115-1003..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (Nero AG)
O4 - HKU\S-1-5-21-789336058-1563985344-839522115-1003..\Run: [Google Update] "C:\Documents and Settings\Lar and Svet\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
O4 - HKU\S-1-5-21-789336058-1563985344-839522115-1003..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook (NVIDIA Corporation)
O4 - HKU\S-1-5-21-789336058-1563985344-839522115-1003..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-789336058-1563985344-839522115-1003\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-789336058-1563985344-839522115-1003\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-789336058-1563985344-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-789336058-1563985344-839522115-1003_Classes\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-789336058-1563985344-839522115-1003_Classes\Software\Policies\Microsoft\Internet Explorer\restrictions present
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\WINDOWS\system32\GPhotos.scr/200 (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo!)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll (Installation Support)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} https://flashcasino.ladbrokes.com/instant-p…-en/FlashAX.cab (FlashXControl Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (athgina.dll) - C:\WINDOWS\system32\athgina.dll (Atheros)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/01/11 12:28:51 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[6 C:\WINDOWS\*.tmp files]
[2009/04/11 18:40:55 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Lar and Svet\Desktop\OTListIt2.exe
[2009/04/10 23:14:30 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Lar and Svet\My Documents\HJTInstall.exe
[2009/04/10 22:51:54 | 00,001,734 | —- | C] () – C:\Documents and Settings\Lar and Svet\Desktop\HijackThis.lnk
[2009/04/10 22:51:51 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/10 22:43:10 | 00,001,510 | —- | C] () – C:\Documents and Settings\Lar and Svet\Desktop\Registrar Lite.lnk
[2009/04/10 22:43:08 | 00,000,000 | —D | C] – C:\Program Files\Registrar Lite
[2009/04/10 09:49:29 | 00,266,276 | —- | C] () – C:\Documents and Settings\Lar and Svet\Desktop\f3903.pdf
[2009/04/09 23:06:47 | 00,001,863 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Seagate Manager.lnk
[2009/04/09 23:06:24 | 00,000,000 | —D | C] – C:\Program Files\Seagate
[2009/04/09 23:06:24 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Seagate
[2009/04/09 23:04:05 | 00,000,000 | —D | C] – C:\Program Files\MSXML 6.0
[2009/04/09 23:03:45 | 00,000,000 | -HSD | C] – C:\WINDOWS\ftpcache
[2009/04/09 19:10:57 | 00,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/04/09 19:10:19 | 00,000,000 | —D | C] – C:\Program Files\QuickTime
[2009/04/09 08:59:32 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/04/09 08:59:32 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/04/08 22:10:20 | 00,029,576 | —- | C] (PCTools Research Pty Ltd.) – C:\WINDOWS\System32\drivers\kcom.sys
[2009/04/08 22:10:19 | 00,081,288 | —- | C] (PCTools Research Pty Ltd.) – C:\WINDOWS\System32\drivers\iksyssec.sys
[2009/04/08 22:10:19 | 00,066,952 | —- | C] (PCTools Research Pty Ltd.) – C:\WINDOWS\System32\drivers\iksysflt.sys
[2009/04/08 22:10:19 | 00,040,840 | —- | C] (PCTools Research Pty Ltd.) – C:\WINDOWS\System32\drivers\ikfilesec.sys
[2009/04/08 22:09:30 | 00,000,000 | —D | C] – C:\Program Files\Spyware Doctor
[2009/04/08 22:09:30 | 00,000,000 | —D | C] – C:\Documents and Settings\Lar and Svet\Application Data\PC Tools
[2009/04/08 22:06:58 | 00,001,836 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2009/04/08 21:58:04 | 00,000,894 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
[2009/04/08 21:54:46 | 00,000,422 | —- | C] () – C:\WINDOWS\tasks\Norton Security Scan for Lar and Svet.job
[2009/04/08 21:53:48 | 00,000,000 | —D | C] – C:\Program Files\Norton Security Scan
[2009/04/08 21:50:27 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google
[2009/04/08 21:48:04 | 00,000,000 | —D | C] – C:\Documents and Settings\Lar and Svet\My Documents\My Google Gadgets
[2009/04/08 21:42:06 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2009/04/08 21:42:01 | 00,000,868 | —- | C] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/04/08 21:39:31 | 01,075,800 | —- | C] () – C:\Documents and Settings\Lar and Svet\Desktop\Google Updater.exe
[2009/04/08 19:26:44 | 00,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/04/08 19:23:16 | 00,000,000 | —D | C] – C:\Program Files\Windows Defender
[2009/04/07 21:55:16 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/04/07 21:07:15 | 00,266,452 | —- | C] () – C:\Documents and Settings\Lar and Svet\Desktop\DSC04653.JPG
[2009/04/07 21:07:11 | 00,268,245 | —- | C] () – C:\Documents and Settings\Lar and Svet\Desktop\DSC04651.JPG
[2009/04/06 23:36:35 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2009/04/06 23:29:25 | 00,000,000 | —D | C] – C:\Program Files\Common Files\iS3
[2009/04/06 23:29:23 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2009/04/06 21:48:38 | 00,000,000 | —D | C] – C:\Documents and Settings\Lar and Svet\Desktop\tax
[2009/03/31 19:48:57 | 00,050,865 | —- | C] () – C:\Documents and Settings\Lar and Svet\Desktop\n743505021_6325904_6064214.jpg
[2009/03/29 03:13:41 | 01,673,728 | —- | C] () – C:\Documents and Settings\Lar and Svet\Desktop\citp-app-word.doc
[2009/03/27 23:09:21 | 00,000,000 | —D | C] – C:\Documents and Settings\Lar and Svet\Application Data\Facebook
[2009/03/25 19:04:31 | 00,000,000 | —D | C] – C:\Documents and Settings\Lar and Svet\Desktop\share
[2009/03/16 00:12:30 | 00,001,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2008/03/03 14:30:41 | 00,000,284 | —- | C] () – C:\WINDOWS\System32\Remover.ini
[2008/02/23 06:29:20 | 00,000,000 | —- | C] () – C:\WINDOWS\TPTray.INI
[2008/01/18 09:02:49 | 00,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2008/01/13 17:33:15 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\lxcrvs.dll
[2008/01/13 17:33:13 | 00,409,600 | —- | C] ( ) – C:\WINDOWS\System32\lxcrinpa.dll
[2008/01/13 17:33:13 | 00,393,216 | —- | C] ( ) – C:\WINDOWS\System32\lxcriesc.dll
[2008/01/13 17:33:12 | 00,303,104 | —- | C] () – C:\WINDOWS\System32\lxcrcoin.dll
[2008/01/13 17:32:15 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\LXPRMON.DLL
[2008/01/13 17:32:15 | 00,032,768 | —- | C] () – C:\WINDOWS\System32\LXPMONUI.DLL
[2008/01/13 17:30:33 | 01,183,744 | —- | C] ( ) – C:\WINDOWS\System32\lxcrserv.dll
[2008/01/13 17:30:33 | 00,995,328 | —- | C] ( ) – C:\WINDOWS\System32\lxcrusb1.dll
[2008/01/13 17:30:33 | 00,233,472 | —- | C] () – C:\WINDOWS\System32\LXCRinst.dll
[2008/01/13 17:30:32 | 00,536,576 | —- | C] ( ) – C:\WINDOWS\System32\lxcrlmpm.dll
[2008/01/13 17:30:32 | 00,163,840 | —- | C] ( ) – C:\WINDOWS\System32\lxcrprox.dll
[2008/01/13 17:30:32 | 00,114,688 | —- | C] ( ) – C:\WINDOWS\System32\lxcrpplc.dll
[2008/01/13 17:30:30 | 00,610,304 | —- | C] ( ) – C:\WINDOWS\System32\lxcrcomc.dll
[2008/01/13 17:30:30 | 00,421,888 | —- | C] ( ) – C:\WINDOWS\System32\lxcrcomm.dll
[2008/01/12 22:06:49 | 00,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/01/12 21:49:17 | 00,524,288 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/01/12 21:49:17 | 00,139,264 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/01/12 20:30:39 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/01/11 21:11:09 | 00,147,456 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2008/01/11 15:15:09 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2007/06/12 06:08:10 | 00,000,518 | —- | C] () – C:\WINDOWS\System32\SP207.INI
[2006/01/23 01:43:48 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\lxcrcaps.dll
[2006/01/22 12:47:36 | 00,684,032 | —- | C] () – C:\WINDOWS\System32\lxcrdrs.dll
[2005/12/20 11:54:04 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\lxcrcnv4.dll
[2004/08/03 15:56:44 | 00,081,920 | —- | C] () – C:\WINDOWS\System32\ieencode.dll
[2003/01/07 10:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/07/17 12:45:48 | 00,004,183 | —- | C] () – C:\WINDOWS\System32\drivers\TPIOMngr.sys
[2001/08/23 07:00:00 | 00,000,779 | —- | C] () – C:\WINDOWS\win.ini
[2001/08/23 07:00:00 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini

========== Files - Modified Within 30 Days ==========

[6 C:\WINDOWS\*.tmp files]
[2009/04/11 18:41:08 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lar and Svet\Desktop\OTListIt2.exe
[2009/04/11 18:14:55 | 00,000,894 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
[2009/04/11 18:14:53 | 00,000,954 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-789336058-1563985344-839522115-1003.job
[2009/04/11 17:29:21 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/04/11 17:27:48 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/11 17:26:15 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/04/11 17:26:09 | 00,000,326 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2009/04/11 17:25:53 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/11 17:25:49 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/11 00:09:29 | 00,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/04/10 23:15:20 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Lar and Svet\My Documents\HJTInstall.exe
[2009/04/10 22:51:54 | 00,001,734 | —- | M] () – C:\Documents and Settings\Lar and Svet\Desktop\HijackThis.lnk
[2009/04/10 22:43:10 | 00,001,510 | —- | M] () – C:\Documents and Settings\Lar and Svet\Desktop\Registrar Lite.lnk
[2009/04/10 16:40:32 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/04/10 15:00:00 | 00,000,422 | —- | M] () – C:\WINDOWS\tasks\Norton Security Scan for Lar and Svet.job
[2009/04/10 10:00:15 | 00,266,276 | —- | M] () – C:\Documents and Settings\Lar and Svet\Desktop\f3903.pdf
[2009/04/09 23:50:08 | 00,021,504 | —- | M] () – C:\Documents and Settings\Lar and Svet\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/09 23:06:47 | 00,001,863 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Seagate Manager.lnk
[2009/04/09 19:10:57 | 00,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/04/09 19:06:38 | 00,001,759 | —- | M] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2009/04/09 08:59:32 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/04/09 08:59:32 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/04/09 01:13:13 | 00,000,624 | —- | M] () – C:\Documents and Settings\All Users\Desktop\WebTV.exe.lnk
[2009/04/08 23:42:50 | 00,000,212 | RHS- | M] () – C:\boot.ini
[2009/04/08 23:09:16 | 00,395,944 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/08 23:09:15 | 00,059,952 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/08 23:09:14 | 00,462,344 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/08 22:52:41 | 00,081,288 | —- | M] (PCTools Research Pty Ltd.) – C:\WINDOWS\System32\drivers\iksyssec.sys
[2009/04/08 22:52:41 | 00,066,952 | —- | M] (PCTools Research Pty Ltd.) – C:\WINDOWS\System32\drivers\iksysflt.sys
[2009/04/08 22:52:40 | 00,040,840 | —- | M] (PCTools Research Pty Ltd.) – C:\WINDOWS\System32\drivers\ikfilesec.sys
[2009/04/08 22:06:58 | 00,001,836 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2009/04/08 21:40:14 | 01,075,800 | —- | M] () – C:\Documents and Settings\Lar and Svet\Desktop\Google Updater.exe
[2009/04/08 20:37:23 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/04/07 21:10:03 | 00,112,128 | -HS- | M] () – C:\Documents and Settings\Lar and Svet\Desktop\Thumbs.db
[2009/04/07 21:09:49 | 00,082,432 | -HS- | M] () – C:\Documents and Settings\Lar and Svet\My Documents\Thumbs.db
[2009/04/07 21:09:00 | 00,266,452 | —- | M] () – C:\Documents and Settings\Lar and Svet\Desktop\DSC04653.JPG
[2009/04/07 21:08:20 | 00,268,245 | —- | M] () – C:\Documents and Settings\Lar and Svet\Desktop\DSC04651.JPG
[2009/04/06 20:00:00 | 00,000,590 | —- | M] () – C:\WINDOWS\tasks\Norton Security Online - Run Full System Scan - Lar and Svet.job
[2009/03/31 19:49:01 | 00,050,865 | —- | M] () – C:\Documents and Settings\Lar and Svet\Desktop\n743505021_6325904_6064214.jpg
[2009/03/29 03:13:43 | 01,673,728 | —- | M] () – C:\Documents and Settings\Lar and Svet\Desktop\citp-app-word.doc
[2009/03/27 21:52:00 | 00,000,569 | —- | M] () – C:\Documents and Settings\Lar and Svet\My Documents\My Sharing Folders.lnk
[2009/03/23 20:00:06 | 00,002,297 | —- | M] () – C:\Documents and Settings\Lar and Svet\Desktop\Google Chrome.lnk
[2009/03/16 00:12:30 | 00,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk

========== LOP Check ==========

[2009/04/09 23:06:24 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/12/19 17:03:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ABBYY
[2009/03/10 06:03:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/12/09 19:04:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2009/04/09 19:10:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/01/13 17:31:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FaxCtr
[2009/04/08 21:50:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009/04/11 01:40:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2009/04/08 19:23:16 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/12/09 02:22:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Software
[2008/09/21 22:44:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2008/02/11 16:55:06 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Question Tools
[2009/04/09 23:06:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2009/04/08 19:03:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2009/04/09 01:01:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2008/12/01 14:27:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2009/04/11 17:51:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/01/23 20:10:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/02/10 07:32:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2008/01/11 18:34:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\yahoo!
[2008/12/19 17:07:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2008/01/11 12:05:59 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Default User\Application Data
[2008/01/11 12:28:42 | 00,000,000 | –SD | M] – C:\Documents and Settings\Default User\Application Data\Microsoft
[2009/04/08 22:09:30 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Lar and Svet\Application Data
[2009/03/10 06:03:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Adobe
[2008/03/08 05:44:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\AdobeAUM
[2008/11/18 06:13:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\AdobeUM
[2008/06/21 21:13:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Ahead
[2009/02/16 23:19:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Apple Computer
[2008/03/03 16:07:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\ArcSoft
[2008/01/12 21:52:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\AVS4YOU
[2009/03/10 06:03:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2008/12/19 11:54:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\EurekaLog
[2009/03/28 00:00:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Facebook
[2008/01/30 13:54:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\FaxCtr
[2008/05/13 12:54:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Flickr
[2008/11/27 02:21:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\GlarySoft
[2008/02/04 13:03:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Google
[2008/01/11 12:38:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Identities
[2008/09/20 13:09:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\InstallShield
[2008/03/21 22:56:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Leadertech
[2008/03/17 09:24:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\LimeWire
[2009/01/31 09:42:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Macromedia
[2009/03/10 22:40:48 | 00,000,000 | –SD | M] – C:\Documents and Settings\Lar and Svet\Application Data\Microsoft
[2008/01/11 16:42:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Motive
[2008/09/10 18:55:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Mozilla
[2008/09/18 18:45:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\NCH Software
[2008/01/13 11:24:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Nero
[2009/04/08 22:09:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\PC Tools
[2008/02/11 16:55:06 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Question Tools
[2008/10/14 20:20:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Real
[2008/01/12 21:28:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Simple Star
[2008/01/20 18:14:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Snapfish
[2008/12/19 11:28:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Softplicity
[2008/01/13 21:40:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Sun
[2008/09/21 22:16:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\SystemRequirementsLab
[2008/12/21 12:33:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\TrueCrypt
[2008/10/01 22:27:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Lar and Svet\Application Data\Yahoo!
[2008/01/11 12:34:45 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data
[2008/09/18 19:26:01 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2008/01/11 12:34:30 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data
[2009/04/08 19:44:20 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/04/10 16:40:32 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2001/08/23 07:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/04/11 17:26:09 | 00,000,326 | —- | M] () – C:\WINDOWS\Tasks\GlaryInitialize.job
[2009/04/11 17:26:15 | 00,000,868 | —- | M] () – C:\WINDOWS\Tasks\Google Software Updater.job
[2009/04/11 18:14:55 | 00,000,894 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachine.job
[2009/04/11 18:14:53 | 00,000,954 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-789336058-1563985344-839522115-1003.job
[2009/04/11 17:29:21 | 00,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009/04/06 20:00:00 | 00,000,590 | —- | M] () – C:\WINDOWS\Tasks\Norton Security Online - Run Full System Scan - Lar and Svet.job
[2009/04/10 15:00:00 | 00,000,422 | —- | M] () – C:\WINDOWS\Tasks\Norton Security Scan for Lar and Svet.job
[2009/04/11 17:25:53 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
Extras log

OTListIt Extras logfile created on: 11/04/2009 18:42:46 - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Lar and Svet\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

510.98 Mb Total Physical Memory | 239.79 Mb Available Physical Memory | 46.93% Memory free
1.22 Gb Paging File | 0.56 Gb Available in Paging File | 45.50% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 83.86 Gb Free Space | 75.02% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OUR
Current User Name: Lar and Svet
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2007/10/18 06:34:02 | 05,724,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
[2007/10/02 12:18:24 | 00,304,488 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2004/08/03 15:56:52 | 00,240,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard
File not found – C:\Program Files\Yahoo!\Messenger\ypager.exe:*:Enabled:Yahoo! Messenger
[2007/08/30 12:43:18 | 00,091,376 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server
File not found – C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
File not found – C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
[2007/10/18 06:34:02 | 05,724,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
[2007/10/02 12:18:24 | 00,304,488 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)
[2007/10/29 00:23:14 | 00,017,408 | —- | M] () – C:\Documents and Settings\Lar and Svet\Application Data\Facebook\facebook.exe:127.0.0.1/255.255.255.255:Enabled:Facebook

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{00C62B23-9336-4AF2-8DD4-BBDBE599DD76}" = Google Photos Screensaver
"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" = Lexmark Toolbar
"{172423F9-522A-483A-AD65-03600CE4CA4F}" = Microsoft Works 6-9 Converter
"{215C3C3E-D5D5-4B78-A5B5-5E42EDA59468}_is1" = 3GP Player 2008
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3CCAD2EF-CFF2-4637-82AA-AABF370282D3}" = ccCommon
"{48185814-A224-447A-81DA-71BD20580E1B}" = Norton Internet Security
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{4D6183C0-005C-4B1F-8261-4B0F71F1C4A5}" = Nokia Multimedia Player
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{51C8EC70-B8A3-4341-A3FB-0F70DBC6D422}" = WebTV
"{520CF7BB-4F9D-4C9F-8FC3-BEC36DA5B2CD}" = Symantec Real Time Storage Protection Component
"{548EAC70-EE00-11DD-908C-005056806466}" = Google Earth
"{59723760-CFF1-45D8-B739-1995F610864F}" = SymNet
"{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}" = Norton Internet Security
"{621C02EA-AAFF-4026-A903-165D59529A16}" = Driver Detective
"{643E1970-324F-474C-8610-55F3F053BC01}" = MouseDriver
"{6693E024-E2D3-477C-8EF9-4D484F3B3071}" = Seagate Manager Installer
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69640730-B830-4C24-BB5C-222DA1260548}" = Turbo Lister 2
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC 32bit
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{795AF20A-51C5-4BAF-9EF5-AA38105C6141}" = Norton Security Scan
"{830D8CBD-C668-49e2-A969-C2C2106332E0}" = Norton AntiVirus
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A367C28-423C-48E2-8C76-EBA1171F932A}" = Adobe Photoshop Album 2.0
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9A129ABC-A53A-4209-A21E-D5DEDFB7CCA8}" = Norton Protection Center
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{B7C61755-DB48-4003-948F-3D34DB8EAF69}" = MSRedist
"{B9135AC5-0FA4-4565-9768-61BF6C79CD29}" = WebTV
"{C679F9B9-C65D-4C65-BD6C-BF90B859E281}" = Microcular
"{C894366E-51C4-4162-BA82-ECBEFC1C2C61}" = PayPal Plug-In
"{D52ECEBC-9B20-41A5-81C4-A62DE2367419}" = Adobe Creative Suite
"{D88A7919-C81E-4F6A-8B77-D1B2E42EE0CD}" = One Button
"{D90AFDE3-3E67-407A-ACA8-F0BAAD012F08}" = Safari
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)
"{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}" = Norton Internet Security
"{E5EE9939-259F-4DE2-8023-5C49E16A4F43}" = Norton Internet Security
"{E629851A-1B1A-4671-961A-A9AF549E03A2}" = ArcSoft PhotoImpression 5
"{E9F6FE78-DD7B-461E-B037-352EA3FABB43}" = TouchPad On/Off Utility
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}" = AppCore
"{F17F7703-1E72-40C1-A0DD-E5B365661049}" = Nero 7 Essentials
"{F4DB525F-A986-4249-B98B-42A8066251CA}" = AV
"{FA200000-0001-0000-0000-074957833700}" = ABBYY PDF Transformer 2.0
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Ask Toolbar_is1" = Ask Toolbar
"BT Yahoo! Applications" = BT Yahoo! Applications
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Flickr Uploadr" = Flickr Uploadr 3.0.5
"Free PDF to Word Doc Converter_is1" = Free PDF to Word Doc Converter v1.1
"Glary Utilities_is1" = Glary Utilities 2.8.0.366
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"InstallShield_{4D6183C0-005C-4B1F-8261-4B0F71F1C4A5}" = Nokia Multimedia Player
"InstallShield_{621C02EA-AAFF-4026-A903-165D59529A16}" = Driver Detective
"InstallShield_{6693E024-E2D3-477C-8EF9-4D484F3B3071}" = Seagate Manager Installer
"InstallShield_{69640730-B830-4C24-BB5C-222DA1260548}" = Turbo Lister 2
"InstallShield_{C679F9B9-C65D-4C65-BD6C-BF90B859E281}" = Microcular
"InstallShield_{E9F6FE78-DD7B-461E-B037-352EA3FABB43}" = Утилита включения/отключения сенсорного планшета
"Lexmark 2400 Series" = Lexmark 2400 Series
"Lexmark Fax Solutions" = Lexmark Fax Solutions
"Live Picture Viewer Plugin" = Live Picture Viewer Plugin
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Mozilla Firefox (3.0.8)" = Mozilla Firefox (3.0.8)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"Nero PhotoShow Express 4" = Nero PhotoShow Express 4
"NSSSetup.{795AF20A-51C5-4BAF-9EF5-AA38105C6141}" = Norton Security Scan (Symantec Corporation)
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"NVIDIA Drivers" = NVIDIA Drivers
"Picasa 3" = Picasa 3
"Prism" = Prism Video Converter
"RealPlayer 6.0" = RealPlayer
"Registrar Lite 2.00" = Registrar Lite 2.00
"Spyware Doctor" = Spyware Doctor 6.0
"SystemRequirementsLab" = System Requirements Lab
"Total PDF Converter_is1" = TotalPDFConverter
"Uninstall_is1" = Uninstall 1.0.0.1
"ViewpointMediaPlayer" = Viewpoint Media Player
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-789336058-1563985344-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/04/2009 01:07:51 | Computer Name = OUR | Source = Application Error | ID = 1000
Description = Faulting application webtv.exe, version 3.3.0.2, faulting module unknown,
version 0.0.0.0, fault address 0x100e1e39.

Error - 11/04/2009 01:08:27 | Computer Name = OUR | Source = Application Error | ID = 1000
Description = Faulting application webtv.exe, version 3.3.0.2, faulting module unknown,
version 0.0.0.0, fault address 0x100e1e39.

Error - 11/04/2009 01:08:58 | Computer Name = OUR | Source = Application Error | ID = 1000
Description = Faulting application webtv.exe, version 3.3.0.2, faulting module unknown,
version 0.0.0.0, fault address 0x100e1e39.

Error - 11/04/2009 04:48:23 | Computer Name = OUR | Source = Application Error | ID = 1000
Description = Faulting application webtv.exe, version 3.3.0.2, faulting module unknown,
version 0.0.0.0, fault address 0x100e1e39.

Error - 11/04/2009 07:04:42 | Computer Name = OUR | Source = Microsoft Office 11 | ID = 1000
Description = Faulting application outlook.exe, version 11.0.8217.0, stamp 480f95d9,
faulting module unknown, version 0.0.0.0, stamp 00000000, debug? 0, fault address
0x100e1e39.

Error - 11/04/2009 09:00:34 | Computer Name = OUR | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3372, faulting module
unknown, version 0.0.0.0, fault address 0x10001e39.

Error - 11/04/2009 18:31:00 | Computer Name = OUR | Source = Application Hang | ID = 1002
Description = Hanging application OUTLOOK.EXE, version 11.0.8217.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/04/2009 18:31:58 | Computer Name = OUR | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error Initialization of the COM subsystem failed.
Error code: 0x8007041D

Error - 11/04/2009 18:48:47 | Computer Name = OUR | Source = Microsoft Office 11 | ID = 2001
Description = Rejected Safe Mode action : Microsoft Office Word.

Error - 11/04/2009 19:03:50 | Computer Name = OUR | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3372, faulting module
unknown, version 0.0.0.0, fault address 0x10001e39.

[ System Events ]
Error - 24/03/2009 02:16:38 | Computer Name = OUR | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 00023F943A85 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 24/03/2009 02:19:30 | Computer Name = OUR | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.100.11
on the Network Card with network address 00023F943A85.

Error - 24/03/2009 02:26:45 | Computer Name = OUR | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.100.11
on the Network Card with network address 00023F943A85.

Error - 25/03/2009 00:57:35 | Computer Name = OUR | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 00023F943A85 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 25/03/2009 00:57:58 | Computer Name = OUR | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.100.11
on the Network Card with network address 00023F943A85.

Error - 25/03/2009 12:59:03 | Computer Name = OUR | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 00023F943A85 has been denied by the DHCP server [removed] (The DHCP Server
sent a DHCPNACK message).

Error - 25/03/2009 22:35:06 | Computer Name = OUR | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service LiveUpdate
with arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435}

Error - 25/03/2009 22:35:10 | Computer Name = OUR | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the LiveUpdate service to
connect.

Error - 25/03/2009 22:35:11 | Computer Name = OUR | Source = Service Control Manager | ID = 7000
Description = The LiveUpdate service failed to start due to the following error:
%%1053

Error - 29/03/2009 21:42:22 | Computer Name = OUR | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.


< End of report >
Looking over your latest logs, will get back to you as soon as possible.

If you're having trouble with the E-Set scan, try the following instead …………

  • Please go to Kaspersky Online Scanner.
  • Read through the requirements and privacy statement and click on the Accept button.
  • It will start downloading and installing the scanner and virus definitions.
    • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they're not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers and other potentially dangerous programs.
    • Archives.
    • Mail databases.
  • Under Scan, click on My Computer.
  • Once the scan is complete, it will display the results.
    • Click on View Scan Report.
  • You will see a list of infected items.
    • Click the Save Report As… button (see red arrow below)

      [external image: Posted Image]
    • In the Save as… prompt, select Desktop
    • In the File name box, name the file KAVScan
    • In the Save as type prompt, select Text file (see below)

      [external image: Posted Image]
    • Copy and paste that information in your next post please.


Can you also do the following.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :reg
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32 /s
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found at on your Desktop entitled SystemLook.txt
Hi Gary, Kapinsky reports no malare detected. Sunday, April 12, 2009 Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Sunday, April 12, 2009 05:23:56 Records in database: 2036368 Scan settings Scan using the following database extended Scan archives yes Scan mail databases yes Scan area My Computer C:\ D:\ Scan statistics Files scanned 67129 Threat name 0 Infected objects 0 Suspicious objects 0 Duration of the scan 03:43:24 No malware has been detected. The scan area is clean. The selected area was scanned. SystemLook v1.0 by jpshortstuff (02.03.09) Log created at 05:10 on 12/04/2009 by Lar and Svet (Administrator - Elevation successful) ========== reg ========== [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"="C:\DOCUME~1\LARAND~1\LOCALS~1\Temp\..\coq.ycm" "midi"="wdmaud.drv" "midimapper"="midimap.dll" "mixer"="wdmaud.drv" "msacm.iac2"="C:\WINDOWS\system32\iac25_32.ax" "msacm.imaadpcm"="imaadp32.acm" "msacm.l3acm"="C:\WINDOWS\system32\l3codeca.acm" "msacm.msadpcm"="msadp32.acm" "msacm.msaudio1"="msaud32.acm" "msacm.msg711"="msg711.acm" "msacm.msg723"="msg723.acm" "msacm.msgsm610"="msgsm32.acm" "msacm.siren"="sirenacm.dll" "msacm.sl_anet"="sl_anet.acm" "msacm.trspch"="tssoft32.acm" "MSVideo8"="VfWWDM32.dll" "vidc.cvid"="iccvid.dll" "VIDC.I420"="msh263.drv" "vidc.iv31"="ir32_32.dll" "vidc.iv32"="ir32_32.dll" "vidc.iv41"="ir41_32.ax" "vidc.iv50"="ir50_32.dll" "VIDC.IYUV"="iyuv_32.dll" "vidc.LEAD"="LCODCCMP.DLL" "vidc.M261"="msh261.drv" "vidc.M263"="msh263.drv" "vidc.mrle"="msrle32.dll" "vidc.msvc"="msvidc32.dll" "VIDC.UYVY"="msyuv.dll" "VIDC.YUY2"="msyuv.dll" "VIDC.YVU9"="tsbyuv.dll" "VIDC.YVYU"="msyuv.dll" "wave"="wdmaud.drv" "wavemapper"="msacm32.drv" [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32\Terminal Server] (No values found) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32\Terminal Server\RDP] "EnableMP3Codec"= 0x00000001 (1) "MaxBandwidth"= 0x000056b9 (22201) "midimapper"="midimap.dll" "mixer"="rdpsnd.dll" "wave"="rdpsnd.dll" "wavemapper"="msacm32.drv" -=End Of File=- Maybe doesn't help much? Another thing - while scanning and doing nothing else the machine stayed stable for hours. As soon as I start moving around the Internet the browser crashes.
The last scan you ran turned up what I expected to see (or something very like it). I need to find out a little more information before we can try and resolve your problem.

Please do the following

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    coq.ycm
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found at on your Desktop entitled SystemLook.txt
Gary, I am glad to hear that its what you were expecting ! I have pasted the Look log below that you asked for. SystemLook v1.0 by jpshortstuff (02.03.09) Log created at 12:09 on 12/04/2009 by Lar and Svet (Administrator - Elevation successful) ========== filefind ========== Searching for "coq.ycm" C:\Documents and Settings\Lar and Svet\Local Settings\coq.ycm –a— 23040 bytes [20:56 03/08/2004] [15:52 16/04/2007] FB429345E2897FE556AAA808FEFF38A2 -=End Of File=- Regards, Lar
Sorry I'm a bit late getting back to you, I was called out last night and didn't get in till late.

OK, let's see if we can set about clearing you up.

First

We'll need to disable Windows Defender, as it will interfere with what we're trying to do.

To disable Windows Defender Real-time Protection
  • Open Windows Defender.
  • Click on Tools > General Settings.
  • Scroll down to Real-time Protection Options.
  • Uncheck Turn on Real Time Protection (recommended).
  • Close Windows Defender.
Once your log is clean you can re-enable Windows Defender Real Time Protection.

Next

  • Double click OTListIt2.exe to launch the programme.
  • Copy/Paste the contents of the code box below into the Custom Scans/Fixes box.
:OTLI
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-789336058-1563985344-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present

:Reg
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"="wdmaud.drv"

:Files
C:\Documents and Settings\Lar and Svet\Local Settings\coq.ycm

:Commands
[Purity]
[EmptyTemp]
[Reboot]
  • Click the Run Fix button.
  • OTListIt will now process the instructions.
  • When finished a box will open asking you to open the fix log, click OK.
  • The fix log will open.
  • Copy/Paste the log in your next reply please.

Note: If necessary, OTLI may re-boot your computer, or request that you do so, if it does, re-boot your computer. A log will be produced upon re-boot.

Do you know what these two files are?

C:\Documents and Settings\Lar and Svet\Desktop\f3903.pdf
C:\Documents and Settings\Lar and Svet\Desktop\n743505021_6325904_6064214.jpg
Gary, I think our clocks are ouit of synch anyway. You are 6 hours ahead of me. I have done what you told me to do and log is below… from a totally uninformed position it doesn't fill me with confidence that it has worked as planned–the word failed appears a lot! I hope that I am wrong. Thanks, Lar HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\CustomSearch| /E : value set successfully! HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully! Unable to set value : HKU\S-1-5-21-789336058-1563985344-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E! Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\control panel\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\restrictions\ deleted successfully. ========== REGISTRY ========== HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32\\"aux"|"wdmaud.drv" /E : value set successfully! ========== FILES ========== C:\Documents and Settings\Lar and Svet\Local Settings\coq.ycm moved successfully. ========== COMMANDS ========== User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\Lar and Svet\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. User's Temporary Internet Files folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. Network Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_508.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Lar and Svet\Local Settings\Application Data\Mozilla\Firefox\Profiles\f4e9w3pa.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Lar and Svet\Local Settings\Application Data\Mozilla\Firefox\Profiles\f4e9w3pa.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Lar and Svet\Local Settings\Application Data\Mozilla\Firefox\Profiles\f4e9w3pa.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Lar and Svet\Local Settings\Application Data\Mozilla\Firefox\Profiles\f4e9w3pa.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Lar and Svet\Local Settings\Application Data\Mozilla\Firefox\Profiles\f4e9w3pa.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Lar and Svet\Local Settings\Application Data\Mozilla\Firefox\Profiles\f4e9w3pa.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. OTListIt2 by OldTimer - Version 2.0.14.0 log created on 04132009_195022 Files moved on Reboot… File C:\WINDOWS\temp\Perflib_Perfdata_508.dat not found! C:\Documents and Settings\Lar and Svet\Local Settings\Application Data\Mozilla\Firefox\Profiles\f4e9w3pa.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\Lar and Svet\Local Settings\Application Data\Mozilla\Firefox\Profiles\f4e9w3pa.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\Lar and Svet\Local Settings\Application Data\Mozilla\Firefox\Profiles\f4e9w3pa.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\Lar and Svet\Local Settings\Application Data\Mozilla\Firefox\Profiles\f4e9w3pa.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\Lar and Svet\Local Settings\Application Data\Mozilla\Firefox\Profiles\f4e9w3pa.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\Lar and Svet\Local Settings\Application Data\Mozilla\Firefox\Profiles\f4e9w3pa.default\XUL.mfl moved successfully. Registry entries deleted on Reboot…
Actually things have gone pretty much as expected.

The failed removals were temp files locked by their parent processes, they were deleted when your computer re-booted and the parent processes weren't running. Anything that didn't go was of no real concern.

The file and reg keys/entries I wanted rid of seem to have gone peacefully.

However I'd like to check ………….

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :reg
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32 /s
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found at on your Desktop entitled SystemLook.txt

Are you still being re-directed, and is your browser still crashing ?
Hi Gary, Thanks for staying with it even though it is taking me a while to respond- as I said we are working at different times. The browser has stopped redirecting (touch wood) and things seem to be ok now- although the machine took 20 minutes to boot earlier. The time and effort that you put in is really admirable- thanks. log from look below- SystemLook v1.0 by jpshortstuff (02.03.09) Log created at 20:18 on 14/04/2009 by Lar and Svet (Administrator - Elevation successful) ========== reg ========== [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"="wdmaud.drv" "midi"="wdmaud.drv" "midimapper"="midimap.dll" "mixer"="wdmaud.drv" "msacm.iac2"="C:\WINDOWS\system32\iac25_32.ax" "msacm.imaadpcm"="imaadp32.acm" "msacm.l3acm"="C:\WINDOWS\system32\l3codeca.acm" "msacm.msadpcm"="msadp32.acm" "msacm.msaudio1"="msaud32.acm" "msacm.msg711"="msg711.acm" "msacm.msg723"="msg723.acm" "msacm.msgsm610"="msgsm32.acm" "msacm.siren"="sirenacm.dll" "msacm.sl_anet"="sl_anet.acm" "msacm.trspch"="tssoft32.acm" "MSVideo8"="VfWWDM32.dll" "vidc.cvid"="iccvid.dll" "VIDC.I420"="msh263.drv" "vidc.iv31"="ir32_32.dll" "vidc.iv32"="ir32_32.dll" "vidc.iv41"="ir41_32.ax" "vidc.iv50"="ir50_32.dll" "VIDC.IYUV"="iyuv_32.dll" "vidc.LEAD"="LCODCCMP.DLL" "vidc.M261"="msh261.drv" "vidc.M263"="msh263.drv" "vidc.mrle"="msrle32.dll" "vidc.msvc"="msvidc32.dll" "VIDC.UYVY"="msyuv.dll" "VIDC.YUY2"="msyuv.dll" "VIDC.YVU9"="tsbyuv.dll" "VIDC.YVYU"="msyuv.dll" "wave"="wdmaud.drv" "wavemapper"="msacm32.drv" [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32\Terminal Server] (No values found) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32\Terminal Server\RDP] "EnableMP3Codec"= 0x00000001 (1) "MaxBandwidth"= 0x000056b9 (22201) "midimapper"="midimap.dll" "mixer"="rdpsnd.dll" "wave"="rdpsnd.dll" "wavemapper"="msacm32.drv" -=End Of File=-
Can you also advise please- once you have cleared me what package or combination from Norton, windows defender and Doctor Spyware would be most effective to keep me clean?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI