This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Something is going wrong

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, how are you

I have some small problems so I need you experience to analyze my Pc
Please!!!


Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:08:21, on 5/7/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\ZSSnp211.exe
C:\WINDOWS\Domino.exe
C:\Program Files\Athan\Athan.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe
O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1FA058AC-28DB-4DB7-861C-6ECAB3EF71B4}: NameServer = 82.114.64.3,82.114.64.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{1FA058AC-28DB-4DB7-861C-6ECAB3EF71B4}: NameServer = 82.114.64.3,82.114.64.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{1FA058AC-28DB-4DB7-861C-6ECAB3EF71B4}: NameServer = 82.114.64.3,82.114.64.4
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

–
End of file - 5346 bytes





OTListIt logfile

CODE
OTListIt logfile created on: 5/7/2009 12:11:24 AM - Run 2
OTListIt2 by OldTimer - Version 2.0.10.0 Folder = D:\CybeRnotic\Tutorials\OTListIt2
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.73 Mb Total Physical Memory | 127.52 Mb Available Physical Memory | 24.97% Memory free
1.22 Gb Paging File | 0.83 Gb Available in Paging File | 68.27% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.54 Gb Total Space | 12.53 Gb Free Space | 67.56% Space Free | Partition Type: FAT32
Drive D: | 57.77 Gb Total Space | 52.85 Gb Free Space | 91.50% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: QENDRIM-A527419
Current User Name: Qendrim
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\ZSSnp211.exe (ZSMCSNAP)
PRC - C:\WINDOWS\Domino.exe ()
PRC - C:\Program Files\Athan\Athan.exe (www.IslamicFinder.org)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Ares\Ares.exe (Ares Development Group)
PRC - C:\Program Files\RALINK\Common\RaUI.exe (Ralink Technology, Corp.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe ()
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe ()
PRC - C:\Program Files\Winamp\winamp.exe (Nullsoft)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
PRC - D:\CybeRnotic\Tutorials\OTListIt2\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (helpsvc [Disabled | Stopped]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (ServiceLayer [On_Demand | Running]) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (UMWdf [Auto | Running]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (usnjsvc [Disabled | Stopped]) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (Aavmker4 [System | Running]) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (AegisP [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\AegisP.sys (Meetinghouse Data Communications)
DRV - (aswFsBlk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (BANTExt [System | Running]) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (cmuda [On_Demand | Running]) – C:\WINDOWS\system32\drivers\cmuda.sys (C-Media Inc)
DRV - (FETNDIS [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\fetnd5.sys (VIA Technologies, Inc. )
DRV - (FETNDISB [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\fetnd5b.sys (VIA Technologies, Inc. )
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (nmwcd [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ccdcmb.sys (Nokia)
DRV - (nmwcdc [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ccdcmbo.sys (Nokia)
DRV - (NTSIM [On_Demand | Stopped]) – C:\WINDOWS\system32\ntsim.sys (VIA Networking Technologies, Inc. )
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (pccsmcfd [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys (Nokia)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (RT61 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\RT61.sys (Ralink Technology Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys ()
DRV - (upperdev [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys (Windows ® Codename Longhorn DDK provider)
DRV - (usbser [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\usbser.sys (Microsoft Corporation)
DRV - (viaagp1 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (viamraid [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\viamraid.sys (VIA Technologies inc,.ltd)
DRV - (vulfnths [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\vulfnth.sys (VIA Technologies, Inc.)
DRV - (vulfntrs [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\vulfntr.sys (VIA Technologies, Inc.)
DRV - (ZSMC211 [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\ZS211.sys (ZSMC Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {ecdc465a-cf20-4b82-9a26-47c9dc52fa32}:1.5.48.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.685
FF - prefs.js..extensions.enabledItems: {CE128952-A9BB-47EF-80CD-EA63A731AA66}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - prefs.js..keyword.URL: "http://search.speedbit.com/searchresults.asp?src=default&q;="

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 7\BKMRKSYNC\ [2009/03/14 23:46:30 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/24 22:27:44 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/26 01:06:56 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/06 09:47:12 | 00,000,000 | —D | M]

[2009/03/26 01:07:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\mozilla\Extensions
[2009/03/26 01:07:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/03/26 01:07:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\mozilla\Firefox\Profiles\qze6xf13.default\extensions
[2009/05/01 18:01:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\mozilla\Firefox\Profiles\qze6xf13.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}
[2009/03/18 22:06:22 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/03/26 01:06:58 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/04/04 00:05:20 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/04/07 23:24:00 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CE128952-A9BB-47EF-80CD-EA63A731AA66}
[2009/04/25 08:38:18 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{ecdc465a-cf20-4b82-9a26-47c9dc52fa32}
[2009/04/28 11:30:56 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/28 11:30:56 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/02/19 20:33:08 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/02/19 20:33:08 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/02/19 20:33:08 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/02/19 20:33:08 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/02/19 20:33:08 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/02/19 20:33:08 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/02/19 20:33:08 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
[2009/05/01 18:01:48 | 00,002,194 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml

O1 HOSTS File: (698 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (FlashFXP Helper for Internet Explorer) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program Files\FlashFXP\IEFlash.dll (IniCom Networks, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Athan] C:\Program Files\Athan\Athan.exe (www.IslamicFinder.org)
O4 - HKLM..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe" (ALWIL Software)
O4 - HKLM..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd File not found
O4 - HKLM..\Run: [Domino] C:\WINDOWS\Domino.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe (ZSMCSNAP)
O4 - HKCU..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h (Ares Development Group)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray (Nokia)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe (Ralink Technology, Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSimpleStartMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{1FA058AC-28DB-4DB7-861C-6ECAB3EF71B4}\\NameServer = 82.114.64.3,82.114.64.4
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ FAT32 ]
O32 - Autorun File - C:\autorun.inf [2009/03/26 11:32:56 | 00,000,000 | RHSD | M] - [ FAT32 ]
O32 - Autorun File - D:\autorun.inf [2009/03/26 12:32:56 | 00,000,000 | RHSD | M] - [ NTFS ]
O33 - MountPoints2\{1173ecf8-0ff6-11de-9b68-0008a1a520f9}\Shell\AuTopLaY\comMAnd - "" = nbqvwk.exe
O33 - MountPoints2\{1173ecf8-0ff6-11de-9b68-0008a1a520f9}\Shell\AutoRun\command - "" = nbqvwk.exe
O33 - MountPoints2\{1173ecf8-0ff6-11de-9b68-0008a1a520f9}\Shell\ExPLOre\CommanD - "" = nbqvwk.exe
O33 - MountPoints2\{1173ecf8-0ff6-11de-9b68-0008a1a520f9}\Shell\open\COmmaNd - "" = nbqvwk.exe
O34 - HKLM BootExecute: (autocheck autochk /p \??\C:) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found

========== Files/Folders - Created Within 30 Days ==========

[3 C:\WINDOWS\*.tmp files]
[2009/05/05 09:57:41 | 00,000,000 | —D | C] – C:\SDFix
[2009/05/02 10:48:10 | 05,250,719 | —- | C] () – C:\Documents and Settings\Qendrim\My Documents\TiMoo fEAt zAiM SeJdIu- MaTuRaNt a jEnI GaTi.mp3
[2009/05/02 00:27:44 | 00,003,584 | —- | C] () – C:\Documents and Settings\Qendrim\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/01 18:01:38 | 00,000,000 | —D | C] – C:\Program Files\Babylon
[2009/04/30 11:07:55 | 00,000,000 | —D | C] – C:\4DiskcleanG
[2009/04/29 10:25:06 | 00,000,225 | —- | C] () – C:\WINDOWS\hpbafd.ini
[2009/04/29 10:14:35 | 00,000,000 | —D | C] – C:\1100
[2009/04/29 10:11:05 | 00,000,000 | —D | C] – C:\SureSupply
[2009/04/28 22:25:30 | 00,010,752 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2009/04/27 00:02:50 | 00,110,592 | —- | C] (TechSmith Corporation) – C:\WINDOWS\System32\tsccvid.dll
[2009/04/26 21:08:06 | 00,023,152 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/04/26 21:08:06 | 00,001,613 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/04/26 21:08:05 | 00,051,376 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/04/26 21:08:05 | 00,026,944 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/04/26 21:08:04 | 00,114,768 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/04/26 21:08:04 | 00,097,480 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\AvastSS.scr
[2009/04/26 21:08:04 | 00,020,560 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/04/26 21:08:03 | 00,094,032 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/04/26 21:08:03 | 00,093,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/04/26 21:07:38 | 01,256,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/04/26 21:07:38 | 00,380,928 | —- | C] () – C:\WINDOWS\System32\actskin4.ocx
[2009/04/26 18:41:44 | 00,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot2
[2009/04/26 18:07:27 | 00,000,388 | —- | C] () – C:\WINDOWS\tasks\SmartDefrag.job
[2009/04/26 18:07:04 | 00,000,000 | —D | C] – C:\Documents and Settings\Qendrim\Application Data\IObit
[2009/04/26 17:49:38 | 00,000,000 | —D | C] – C:\Documents and Settings\Qendrim\Application Data\Malwarebytes
[2009/04/26 17:49:29 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/26 00:41:41 | 00,000,000 | —D | C] – C:\LaserJet517
[2009/04/25 08:38:22 | 00,000,000 | —D | C] – C:\Documents and Settings\Qendrim\Application Data\PhotoFrameShow
[2009/04/25 08:38:17 | 00,000,000 | —D | C] – C:\Program Files\Conduit
[2009/04/25 08:38:17 | 00,000,000 | —D | C] – C:\Documents and Settings\Qendrim\Local Settings\Application Data\Conduit
[2009/04/25 08:38:04 | 00,000,598 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Photo Frame Show.lnk
[2009/04/25 08:38:00 | 00,000,000 | —D | C] – C:\Program Files\FrameShow
[2009/04/24 23:59:41 | 00,000,000 | —D | C] – C:\Program Files\Wipe
[2009/04/21 01:15:43 | 00,000,000 | —D | C] – C:\Program Files\MagicISO
[2009/04/21 00:14:00 | 00,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2009/04/17 01:07:53 | 00,000,000 | —D | C] – C:\WINDOWS\Logs
[2009/04/17 00:28:19 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/12 15:57:53 | 00,000,000 | —D | C] – C:\Documents and Settings\Qendrim\Local Settings\Application Data\Yahoo
[2009/04/12 15:57:46 | 00,000,000 | R–D | C] – C:\Documents and Settings\Qendrim\My Documents\My Widgets
[2009/04/11 22:12:27 | 00,000,000 | —D | C] – C:\Program Files\Alwil Software
[2009/04/11 21:47:49 | 00,000,000 | —D | C] – C:\WINDOWS\System32\URTTEMP
[2009/04/11 16:06:33 | 00,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2009/04/11 15:53:02 | 00,000,121 | —- | C] () – C:\WINDOWS\bdagent.INI
[2009/04/10 15:20:49 | 00,000,000 | —D | C] – C:\Documents and Settings\Qendrim\My Documents\3dsmax
[2009/04/10 15:17:31 | 00,000,000 | R–D | C] – C:\Documents and Settings\Qendrim\My Documents\Adlm
[2009/04/10 15:14:34 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2009/04/10 15:11:37 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Autodesk Shared
[2009/04/10 15:11:37 | 00,000,000 | —D | C] – C:\Program Files\Autodesk
[2009/04/10 15:11:37 | 00,000,000 | —D | C] – C:\Documents and Settings\Qendrim\Local Settings\Application Data\Autodesk
[2009/04/10 15:09:05 | 02,297,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_26.dll
[2009/04/07 22:20:56 | 00,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2009/04/05 19:45:42 | 00,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2009/03/26 12:49:48 | 00,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2009/03/25 23:30:18 | 00,081,920 | —- | C] () – C:\WINDOWS\System32\ieencode.dll
[2009/03/23 09:46:06 | 00,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/03/21 20:04:40 | 00,000,728 | —- | C] () – C:\WINDOWS\Mp3CutterJoiner.ini
[2009/03/19 11:42:56 | 00,219,136 | —- | C] () – C:\WINDOWS\sqlite3_engine.dll
[2009/03/06 11:16:55 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/03/06 08:56:20 | 00,081,920 | —- | C] () – C:\WINDOWS\System32\Install6x.dll
[2009/03/06 08:52:43 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\vusetup.dll
[2009/03/06 08:50:52 | 00,028,672 | R— | C] () – C:\WINDOWS\System32\cmirmdrv.dll
[2009/03/06 08:49:34 | 00,003,244 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009/03/06 08:49:33 | 00,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/03/06 08:37:57 | 00,000,000 | —- | C] () – C:\WINDOWS\control.ini
[2009/03/06 08:35:39 | 00,000,002 | —- | C] () – C:\WINDOWS\System32\desktop.ini
[2009/03/06 08:35:39 | 00,000,002 | —- | C] () – C:\WINDOWS\desktop.ini
[2009/03/06 08:34:07 | 00,000,037 | —- | C] () – C:\WINDOWS\vbaddin.ini
[2009/03/06 08:34:07 | 00,000,036 | —- | C] () – C:\WINDOWS\vb.ini
[2009/03/06 08:33:31 | 00,013,223 | —- | C] () – C:\WINDOWS\System32\tslabels.ini
[2009/03/06 08:33:30 | 00,001,931 | —- | C] () – C:\WINDOWS\System32\msdtcprf.ini
[2009/03/06 08:27:39 | 00,445,060 | —- | C] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/06 08:27:38 | 00,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2007/03/29 22:00:40 | 00,203,264 | —- | C] () – C:\WINDOWS\System32\CddbCdda.dll
[2005/12/27 16:17:32 | 00,122,939 | —- | C] () – C:\WINDOWS\System32\perf32.ini
[2004/08/03 22:56:46 | 01,287,680 | —- | C] () – C:\WINDOWS\System32\quartz.dll
[2004/08/03 22:56:46 | 00,562,176 | —- | C] () – C:\WINDOWS\System32\qedit.dll
[2004/08/03 22:56:46 | 00,385,024 | —- | C] () – C:\WINDOWS\System32\qdvd.dll
[2004/08/03 22:56:46 | 00,279,040 | —- | C] () – C:\WINDOWS\System32\qdv.dll
[2004/08/03 22:56:46 | 00,270,848 | —- | C] () – C:\WINDOWS\System32\sbe.dll
[2004/08/03 22:56:46 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\qcap.dll
[2004/08/03 22:56:44 | 00,498,205 | —- | C] () – C:\WINDOWS\System32\dxmasf.dll
[2004/08/03 22:56:44 | 00,186,368 | —- | C] () – C:\WINDOWS\System32\encdec.dll
[2004/08/03 22:56:44 | 00,059,904 | —- | C] () – C:\WINDOWS\System32\devenum.dll
[2004/08/03 22:56:44 | 00,035,328 | —- | C] () – C:\WINDOWS\System32\mciqtz32.dll
[2004/08/03 22:56:44 | 00,014,336 | —- | C] () – C:\WINDOWS\System32\msdmo.dll
[2004/08/03 22:56:42 | 00,252,928 | —- | C] () – C:\WINDOWS\System32\compatUI.dll
[2004/08/03 22:56:42 | 00,070,656 | —- | C] () – C:\WINDOWS\System32\amstream.dll
[2004/08/03 22:56:26 | 00,733,696 | —- | C] () – C:\WINDOWS\System32\qedwipes.dll
[2004/08/03 22:56:14 | 00,004,126 | —- | C] () – C:\WINDOWS\System32\msdxmlc.dll
[2004/08/03 20:46:56 | 00,042,537 | —- | C] () – C:\WINDOWS\System32\keyboard.sys
[2004/08/03 20:45:16 | 00,035,424 | —- | C] () – C:\WINDOWS\System32\ntio412.sys
[2004/08/03 20:45:16 | 00,034,560 | —- | C] () – C:\WINDOWS\System32\ntio404.sys
[2004/08/03 20:45:14 | 00,034,560 | —- | C] () – C:\WINDOWS\System32\ntio804.sys
[2004/08/03 20:45:12 | 00,035,648 | —- | C] () – C:\WINDOWS\System32\ntio411.sys
[2004/08/03 20:45:10 | 00,033,840 | —- | C] () – C:\WINDOWS\System32\ntio.sys
[2004/07/17 09:46:14 | 00,053,478 | —- | C] () – C:\WINDOWS\System32\tcpmon.ini
[2004/07/17 09:36:38 | 00,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2003/01/07 12:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/08/23 10:00:00 | 01,015,477 | —- | C] () – C:\WINDOWS\System32\esentprf.ini
[2001/08/23 10:00:00 | 00,199,168 | —- | C] () – C:\WINDOWS\System32\ir32_32.dll
[2001/08/23 10:00:00 | 00,094,282 | —- | C] () – C:\WINDOWS\System32\msencode.dll
[2001/08/23 10:00:00 | 00,042,809 | —- | C] () – C:\WINDOWS\System32\key01.sys
[2001/08/23 10:00:00 | 00,029,370 | —- | C] () – C:\WINDOWS\System32\ntdos411.sys
[2001/08/23 10:00:00 | 00,029,274 | —- | C] () – C:\WINDOWS\System32\ntdos412.sys
[2001/08/23 10:00:00 | 00,029,146 | —- | C] () – C:\WINDOWS\System32\ntdos804.sys
[2001/08/23 10:00:00 | 00,029,146 | —- | C] () – C:\WINDOWS\System32\ntdos404.sys
[2001/08/23 10:00:00 | 00,027,866 | —- | C] () – C:\WINDOWS\System32\ntdos.sys
[2001/08/23 10:00:00 | 00,027,097 | —- | C] () – C:\WINDOWS\System32\country.sys
[2001/08/23 10:00:00 | 00,015,360 | —- | C] () – C:\WINDOWS\System32\tsd32.dll
[2001/08/23 10:00:00 | 00,013,312 | —- | C] () – C:\WINDOWS\System32\win87em.dll
[2001/08/23 10:00:00 | 00,012,082 | —- | C] () – C:\WINDOWS\System32\rsvp.ini
[2001/08/23 10:00:00 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\scriptpw.dll
[2001/08/23 10:00:00 | 00,010,110 | —- | C] () – C:\WINDOWS\System32\mqperf.ini
[2001/08/23 10:00:00 | 00,009,029 | —- | C] () – C:\WINDOWS\System32\ansi.sys
[2001/08/23 10:00:00 | 00,006,877 | —- | C] () – C:\WINDOWS\System32\pschdprf.ini
[2001/08/23 10:00:00 | 00,004,768 | —- | C] () – C:\WINDOWS\System32\himem.sys
[2001/08/23 10:00:00 | 00,003,458 | —- | C] () – C:\WINDOWS\System32\rasctrs.ini
[2001/08/23 10:00:00 | 00,002,891 | —- | C] () – C:\WINDOWS\System32\perfci.ini
[2001/08/23 10:00:00 | 00,002,732 | —- | C] () – C:\WINDOWS\System32\perfwci.ini
[2001/08/23 10:00:00 | 00,002,656 | —- | C] () – C:\WINDOWS\System32\netware.drv
[2001/08/23 10:00:00 | 00,001,405 | —- | C] () – C:\WINDOWS\msdfmap.ini
[2001/08/23 10:00:00 | 00,001,152 | —- | C] () – C:\WINDOWS\System32\perffilt.ini
[2001/08/23 10:00:00 | 00,000,970 | —- | C] () – C:\WINDOWS\win.ini
[2001/08/23 10:00:00 | 00,000,343 | —- | C] () – C:\WINDOWS\System32\prodspec.ini
[2001/08/23 10:00:00 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2001/08/17 22:36:28 | 00,157,696 | —- | C] () – C:\WINDOWS\System32\paqsp.dll

========== Files - Modified Within 30 Days ==========

[3 C:\WINDOWS\*.tmp files]
[2009/05/07 00:11:02 | 00,000,225 | —- | M] () – C:\WINDOWS\hpbafd.ini
[2009/05/06 23:39:24 | 00,000,970 | —- | M] () – C:\WINDOWS\win.ini
[2009/05/06 21:18:58 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/06 18:22:06 | 01,576,998 | -H– | M] () – C:\Documents and Settings\Qendrim\Local Settings\Application Data\IconCache.db
[2009/05/06 16:06:02 | 00,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/05/04 11:13:28 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/05/04 11:13:28 | 00,000,211 | -HS- | M] () – C:\boot.ini
[2009/05/02 15:24:50 | 00,003,584 | —- | M] () – C:\Documents and Settings\Qendrim\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/02 10:47:04 | 05,250,719 | —- | M] () – C:\Documents and Settings\Qendrim\My Documents\TiMoo fEAt zAiM SeJdIu- MaTuRaNt a jEnI GaTi.mp3
[2009/04/28 22:28:42 | 00,010,752 | —- | M] () – C:\WINDOWS\System32\BASSMOD.dll
[2009/04/27 10:09:52 | 00,002,639 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/04/26 22:29:40 | 00,087,382 | —- | M] () – C:\Documents and Settings\Qendrim\Application Data\NMM-MetaData.db
[2009/04/26 21:08:08 | 00,001,613 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/04/26 18:24:10 | 00,024,064 | —- | M] (Gerhard Schlager) – C:\WINDOWS\System32\dllcache\ctfmon.exe
[2009/04/26 18:24:10 | 00,024,064 | —- | M] (Gerhard Schlager) – C:\WINDOWS\System32\ctfmon.exe
[2009/04/26 18:07:28 | 00,000,388 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag.job
[2009/04/25 08:38:06 | 00,000,598 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Photo Frame Show.lnk
[2009/04/25 00:02:38 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/17 22:59:20 | 00,395,530 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/17 22:59:20 | 00,059,644 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/17 22:59:18 | 00,445,060 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/11 16:05:00 | 00,000,121 | —- | M] () – C:\WINDOWS\bdagent.INI
[2009/04/07 22:20:58 | 00,004,096 | —- | M] () – C:\WINDOWS\d3dx.dat

========== LOP Check ==========

[2009/03/06 08:27:02 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/03/16 21:08:12 | 00,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2009/03/06 13:31:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2009/04/10 15:14:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2009/03/25 00:43:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FlashFXP
[2009/03/14 23:44:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2009/04/26 17:49:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/03/06 08:26:38 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2009/03/29 14:13:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2009/03/14 23:47:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2009/03/15 23:22:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/03/16 21:08:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2009/03/29 14:13:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/03/06 23:32:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2009/03/06 08:27:02 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Qendrim\Application Data
[2009/03/06 09:25:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\Adobe
[2009/03/22 23:12:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\Ahead
[2009/03/23 20:44:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\Any Video Converter Professional
[2009/03/08 11:08:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\DMCache
[2009/03/06 09:15:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\Google
[2009/03/15 10:02:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\GRETECH
[2009/03/06 08:47:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\Identities
[2009/04/26 18:07:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\IObit
[2009/03/06 09:25:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\Macromedia
[2009/04/26 17:49:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\Malwarebytes
[2009/03/06 08:26:38 | 00,000,000 | –SD | M] – C:\Documents and Settings\Qendrim\Application Data\Microsoft
[2009/03/26 01:07:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\Mozilla
[2009/03/14 23:47:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\Nokia
[2009/03/14 23:47:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\PC Suite
[2009/04/25 08:38:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\PhotoFrameShow
[2009/03/24 22:19:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\Sun
[2009/03/07 12:35:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\TeamViewer
[2009/03/16 21:09:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\TuneUp Software
[2009/03/06 09:06:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\Winamp
[2009/03/06 09:51:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\WinRAR
[2009/03/21 16:49:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Qendrim\Application Data\WIPE
[2001/08/23 11:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/04/25 00:02:38 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/04/26 18:07:28 | 00,000,388 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag.job

========== Purity Check ==========

< End of report >
Hi sysss,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI