This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Explorer.exe problem

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The problem starts at startup. Explorer.exe randomly closes then restarts. Please help, here's my HijackThis log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:46:21 AM, on 5/14/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\TEMP\UF58E5.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\mmc.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\TuneUp Utilities 2009\Integrator.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\willy\LOCALS~1\Temp\Rar$EX00.094\shexview.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\TuneUp Utilities 2009\ProcessManager.exe
C:\Program Files\WinRAR\WinRAR.exe
E:\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\explorer.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://aa.rd.yahoo.com/customize/ie/defaul…://ph.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ph.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ph.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://aa.rd.yahoo.com/customize/ie/defaul…://ph.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://aa.rd.yahoo.com/customize/ie/defaul…://ph.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ph.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://aa.rd.yahoo.com/customize/ie/defaul…://ph.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Cleanup] C:\Documents and Settings\willy\Contacts\svchost.exe
O4 - HKLM\..\Run: [TV Card Remote Control Device Monitor] C:\WINDOWS\713xRMTMon.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Java Load] C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\minisvr4.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Cleanup] C:\Documents and Settings\willy\Contacts\svchost.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PC Suite Tray] "E:\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-18\..\Run: [Windows Update Utility] \\?\globalroot\systemroot\system32\svchast.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Windows Update Utility] \\?\globalroot\systemroot\system32\svchast.exe (User 'Default user')
O4 - Startup: Multiply AutoUploader.lnk = E:\Multiply\AutoUploader\Multiply AutoUploader\Multiply AutoUploader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Post Image to Blog - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1240363149828
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\

–
End of file - 9045 bytes

Oh and, explorer.exe closes the same time a process called imapi.exe closes.

Thanks in advance :)
Hi sesema, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

You have several problems here, so we'll see if we can slow some of it down and find the rest this time.


Open hijackthis, do a system scan only and checkmark these lines, if present

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Cleanup] C:\Documents and Settings\willy\Contacts\svchost.exe
O4 - HKLM\..\Run: [Java Load] C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\minisvr4.exe
O4 - HKCU\..\Run: [Cleanup] C:\Documents and Settings\willy\Contacts\svchost.exe
O4 - HKUS\S-1-5-18\..\Run: [Windows Update Utility] \\?\globalroot\systemroot\system32\svchast.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Windows Update Utility] \\?\globalroot\systemroot\system32\svchast.exe (User 'Default user')


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.


Next
Download OTListIt2 to your desktop.
  • Next, Double click on OTList2.exe
    • Under the Custom Scans/Fixes box at the bottom, paste in the following
    • Do Not copy the word CODE
    • please note the fix starts with the :
    :OTLI
    PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
    
    :Processes
    UF58E5.EXE
    
    :Services
    
    :Reg
    
    :Files
    C:\Documents and Settings\willy\Contacts\svchost.exe
    C:\svchast.exe /s
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\minisvr4.exe
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]

    Then click the Run Fix button at the top
    • Let the program run unhindered
    • Please save the resulting log to be posted in your next reply.

    Next
    Please download RootRepeal to your desktop
    • Physically disconnect your machine from the internet as your system will be unprotected.
    • Unzip it to it's own folder, close all other programs especially your security programs (anti-spyware, anti-virus, and firewall) and run RootRepeal.exe
    • Click the Report tab at the bottom and then the Scan button.
    • A box will pop up, check the boxes beside Drivers, Files, Processes SSDT and click OK.
    • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
    • The scan will take a little while to run, so let it go unhindered.
    • Once it is done, click the Save Report button, call it RepealScan and save the log to your desktop.
    • Reconnect to the internet.
    • Post the log here in your reply.


    Next
    • Double click on OTList2.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • When the window appears, underneath Output at the top change it to Minimal Output
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.

    Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

    Please post backwith
    • all 3 OTLISTIT2 logs
    • RootRepeal log
    No need for a HJT log this time.

    Use additional replies if needed to fit it all in.

    Thanks
First of all, thank you oldman960 :D

Here's the first OTLISTIT2 Log:

========== OTLISTIT ==========
Process Explorer.EXE killed successfully!
========== PROCESSES ==========
No active process named UF58E5.EXE was found!
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\Documents and Settings\willy\Contacts\svchost.exe moved successfully.
C:\WINDOWS\system32\svchast.exe moved successfully.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\minisvr4.exe moved successfully.
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\willy\Local Settings\Temp\etilqs_U78i33d6XxMzskkcaSp4 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\willy\Local Settings\Temp\~DF5B4.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\EK1679.EXE scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_c8.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTListIt2 by OldTimer - Version 2.0.15.7 log created on 05142009_111657

Files moved on Reboot…
File C:\Documents and Settings\willy\Local Settings\Temp\etilqs_U78i33d6XxMzskkcaSp4 not found!
C:\Documents and Settings\willy\Local Settings\Temp\~DF5B4.tmp moved successfully.
C:\WINDOWS\temp\EK1679.EXE moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_c8.dat not found!

Registry entries deleted on Reboot…

Here's the other 2 logs:

OTListIt logfile created on: 5/14/2009 11:51:43 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.7 Folder = E:\dtA Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18241)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1023.17 Mb Total Physical Memory | 469.33 Mb Available Physical Memory | 45.87% Memory free
2.41 Gb Paging File | 2.04 Gb Available in Paging File | 84.74% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.06 Gb Total Space | 1.78 Gb Free Space | 4.57% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 109.99 Gb Total Space | 59.71 Gb Free Space | 54.28% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JOSE
Current User Name: willy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe (Trend Micro Inc.)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe (Trend Micro Inc.)
PRC - C:\WINDOWS\System32\TUProgSt.exe (TuneUp Software)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe (Trend Micro Inc.)
PRC - C:\WINDOWS\TEMP\OHABF9.EXE ()
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - E:\dtA Downloads\OTListIt2.exe (OldTimer Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (eapqolnz [Auto | Running]) – C:\WINDOWS\system32\bitiiuz.dll (Microsoft Corporation)
SRV - (EPSONStatusAgent2 [Auto | Running]) – C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe (SEIKO EPSON CORPORATION)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KodakCCS [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\KodakCCS.exe (Eastman Kodak Company)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (npggsvc [On_Demand | Stopped]) – C:\WINDOWS\system32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (ntrtscan [Auto | Running]) – C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe (Trend Micro Inc.)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (OfcPfwSvc [Auto | Running]) – C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe (Trend Micro Inc.)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (ServiceLayer [On_Demand | Stopped]) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (tmlisten [Auto | Running]) – C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe (Trend Micro Inc.)
SRV - (TuneUp.Defrag [On_Demand | Stopped]) – C:\WINDOWS\System32\TuneUpDefragService.exe (TuneUp Software)
SRV - (TuneUp.ProgramStatisticsSvc [Auto | Running]) – C:\WINDOWS\System32\TUProgSt.exe (TuneUp Software)
SRV - (UleadBurningHelper [Auto | Running]) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (UxTuneUp [Auto | Running]) – C:\WINDOWS\System32\uxtuneup.dll (TuneUp Software)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (2a0dcc1b [System | Stopped]) – C:\WINDOWS\System32\drivers\2a0dcc1b.sys ()
DRV - (2cb8e0ee [System | Stopped]) – C:\WINDOWS\System32\drivers\2cb8e0ee.sys ()
DRV - (713xTVCard [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\SAA713x.sys (Philips Semiconductors)
DRV - (AtcL002 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atl02_xp.sys (Attansic Technology corporation.)
DRV - (DcCam [System | Running]) – C:\WINDOWS\system32\DRIVERS\DcCam.sys (Eastman Kodak Company)
DRV - (DcFpoint [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\DcFpoint.sys (Eastman Kodak Company)
DRV - (DCFS2K [Auto | Running]) – C:\WINDOWS\system32\drivers\dcfs2k.sys (Eastman Kodak Company)
DRV - (DcLps [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\DcLps.sys (Eastman Kodak Company)
DRV - (DcPTP [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\DcPTP.sys (Eastman Kodak Company)
DRV - (Exportit [System | Stopped]) – C:\WINDOWS\system32\DRIVERS\exportit.sys (Eastman Kodak Company)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (IntcAzAudAddService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (MTsensor [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ASACPI.sys ()
DRV - (nmwcd [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ccdcmb.sys (Nokia)
DRV - (nmwcdc [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ccdcmbo.sys (Nokia)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (pccsmcfd [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys (Nokia)
DRV - (pcouffin [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys ()
DRV - (TmFilter [Auto | Running]) – C:\Program Files\Trend Micro\OfficeScan Client\TmXPFlt.sys (Trend Micro Inc.)
DRV - (TmPreFilter [Auto | Running]) – C:\Program Files\Trend Micro\OfficeScan Client\TmPreFlt.sys (Trend Micro Inc.)
DRV - (TM_CFW [Auto | Running]) – C:\Program Files\Trend Micro\OfficeScan Client\tm_cfw.sys (Trend Micro Inc.)
DRV - (upperdev [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys (Windows ® Codename Longhorn DDK provider)
DRV - (usbser [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbser.sys (Microsoft Corporation)
DRV - (UsbserFilt [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys (Windows ® Codename Longhorn DDK provider)
DRV - (vcdrom [System | Running]) – C:\WINDOWS\system32\drivers\VCdRom.sys (Microsoft Corporation)
DRV - (VSApiNt [Auto | Running]) – C:\Program Files\Trend Micro\OfficeScan Client\VSApiNt.sys (Trend Micro Inc.)
DRV - (w200bus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\w200bus.sys (MCCI)
DRV - (w200mdfl [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\w200mdfl.sys (MCCI)
DRV - (w200mdm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\w200mdm.sys (MCCI)
DRV - (w200mgmt [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\w200mgmt.sys (MCCI)
DRV - (w200obex [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\w200obex.sys (MCCI)
DRV - (W700bus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\W700bus.sys (MCCI)
DRV - (W700mdfl [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\W700mdfl.sys (MCCI)
DRV - (W700mdm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\W700mdm.sys (MCCI)
DRV - (W700mgmt [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\W700mgmt.sys (MCCI)
DRV - (W700obex [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\W700obex.sys (MCCI)
DRV - (WDMTVTuner [Auto | Running]) – C:\WINDOWS\system32\drivers\WDMTuner.sys (Philips Semiconductors)
DRV - (xeclrhpo [Boot | Running]) – C:\WINDOWS\system32\drivers\xeclrhpo.sys (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ph.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://aa.rd.yahoo.com/customize/ie/defaul…://ph.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://aa.rd.yahoo.com/customize/ie/defaul…://ph.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ph.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://aa.rd.yahoo.com/customize/ie/defaul…://ph.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ph.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.2
FF - prefs.js..extensions.enabledItems: [removed]:1.8
FF - prefs.js..extensions.enabledItems: {097d3191-e6fa-4728-9826-b533d755359d}:0.7.10
FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.84
FF - prefs.js..extensions.enabledItems: [removed]:2.7.2
FF - prefs.js..extensions.enabledItems: [removed]:1.1.3
FF - prefs.js..extensions.enabledItems: [removed]:4.1
FF - prefs.js..extensions.enabledItems: [removed]:1.1
FF - prefs.js..extensions.enabledItems: [removed]:0.8.1
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.3
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.3
FF - prefs.js..extensions.enabledItems: [removed]:0.6
FF - prefs.js..extensions.enabledItems: {2E18002D-DF43-4c65-9FDA-40D02F066D9E}:1.6
FF - prefs.js..extensions.enabledItems: {4BBDD651-70CF-4821-84F8-2B918CF89CA3}:6.1
FF - prefs.js..extensions.enabledItems: [removed]:3.1.6
FF - prefs.js..extensions.enabledItems: {89506680-e3f4-484c-a2c0-ed711d481eda}:0.9.5
FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.4
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:0.17
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:[removed]
FF - prefs.js..extensions.enabledItems: {cc85cd4e-5a5b-4eda-a25c-bdaffa93b406}:0.2.5
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090123.1
FF - prefs.js..extensions.enabledItems: {7102aba3-045c-4ec2-b921-46d87636d84b}:1.33
FF - prefs.js..extensions.enabledItems: {7378B8C2-FC38-41b8-A8C9-875D1F5B0A24}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {EDA7B1D7-F793-4e03-B074-E6F303317FB0}:1.2.6
FF - prefs.js..extensions.enabledItems: {b749fc7c-e949-447f-926c-3f4eed6accfe}:0.6.6
FF - prefs.js..extensions.enabledItems: [removed]:20090112.01
FF - prefs.js..extensions.enabledItems: [removed]:1.2.1
FF - prefs.js..extensions.enabledItems: {1ced4832-f06e-413f-aa14-9eb63ad40ace}:0.68.2
FF - prefs.js..extensions.enabledItems: [removed]:1.2.3
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2c}:0.6.3
FF - prefs.js..extensions.enabledItems: {B17C1C5A-04B1-11DB-9804-B622A1EF5492}:1.1
FF - prefs.js..extensions.enabledItems: pastetotab@loucypher:0.2.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.685
FF - prefs.js..extensions.enabledItems: [removed]:4.1.4
FF - prefs.js..extensions.enabledItems: {5b1fdac4-a239-4933-9c52-b65a2a720b75}:2.3
FF - prefs.js..extensions.enabledItems: {5e594888-3e8e-47da-b2c6-b0b545112f84}:1.2.6
FF - prefs.js..extensions.enabledItems: [removed]:0.9.3
FF - prefs.js..extensions.enabledItems: [removed]:1.5
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.0.3
FF - prefs.js..extensions.enabledItems: ststusscicalc@sunny:4.5
FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.0.1
FF - prefs.js..extensions.enabledItems: [removed]:2.2.1
FF - prefs.js..extensions.enabledItems: {43520B8F-4107-4351-AC64-9BCC5EEA24B9}:0.6.9
FF - prefs.js..extensions.enabledItems: [removed]:0.1.4.10
FF - prefs.js..extensions.enabledItems: {DAD0F81A-CF67-4eed-98D6-26F6E47274CA}:1.3
FF - prefs.js..extensions.enabledItems: {95f24680-9e31-11da-a746-0800200c9a66}:0.1.5.4
FF - prefs.js..extensions.enabledItems: {10c62ce3-3794-4c18-a881-481733c1a425}:1.5.9
FF - prefs.js..extensions.enabledItems: [removed]:3.1.0
FF - prefs.js..extensions.enabledItems: {77AA1884-7357-459B-9AA1-F4F821803754}:1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..extensions.enabledItems: yetanothersmoothscrolling@kataho:2.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.1b4
FF - prefs.js..extensions.enabledItems: {D46E8522-6E86-44b1-A622-58C0668AD78E}:3.0.9
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - prefs.js..extensions.enabledItems: [removed]:3.02
FF - prefs.js..extensions.enabledItems: [removed]:3.0.4
FF - prefs.js..extensions.enabledItems: {224d6e00-0336-11dd-95ff-0800200c9a66}:[removed]
FF - prefs.js..extensions.enabledItems: {29852C08-1E91-4889-A6BF-C77F91D6A8F3}:1.8.49
FF - prefs.js..extensions.enabledItems: {dc961bb0-dfb2-11dc-95ff-0800200c9a66}:2.081108
FF - prefs.js..extensions.enabledItems: [removed]:0.6.20090428
FF - prefs.js..extensions.enabledItems: {8a39fe10-f553-11dd-87af-0800200c9a66}:1.0
FF - prefs.js..extensions.enabledItems: {6ce6f000-9b3c-11dd-ad8b-0800200c9a66}:1.3.1
FF - prefs.js..extensions.enabledItems: {07b2a769-ed19-4483-87ce-c643914c81bb}:3.0.0.34


FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/18 08:59:56 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: E:\NOKIA\NOKIA PC SUITE 7\BKMRKSYNC\ [2009/03/30 10:53:58 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/11 19:04:49 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/05/03 02:15:29 | 00,000,000 | —D | M]

[2009/05/03 02:15:33 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Extensions
[2009/05/03 02:15:33 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/03/30 10:58:37 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Extensions\[removed]
[2009/05/14 11:30:58 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions
[2009/05/03 02:17:38 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}
[2009/05/03 02:18:21 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{097d3191-e6fa-4728-9826-b533d755359d}
[2009/05/03 02:18:09 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{10c62ce3-3794-4c18-a881-481733c1a425}
[2009/05/07 06:06:33 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2009/05/03 02:18:10 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{1ced4832-f06e-413f-aa14-9eb63ad40ace}
[2009/05/03 02:17:36 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{224d6e00-0336-11dd-95ff-0800200c9a66}
[2009/05/03 02:17:37 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{29852C08-1E91-4889-A6BF-C77F91D6A8F3}
[2009/05/03 02:18:16 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{2E18002D-DF43-4c65-9FDA-40D02F066D9E}
[2009/05/03 02:18:10 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2c}
[2009/05/03 02:18:08 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{43520B8F-4107-4351-AC64-9BCC5EEA24B9}
[2009/05/07 06:06:36 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2009/05/03 02:18:16 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
[2009/05/03 02:18:20 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2009/05/03 02:18:10 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{5b1fdac4-a239-4933-9c52-b65a2a720b75}
[2009/05/03 02:18:10 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{5e594888-3e8e-47da-b2c6-b0b545112f84}
[2009/05/03 02:18:08 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/05/03 02:18:10 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2009/05/03 02:19:17 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{65d266e0-85b7-11dd-ad8b-0800200c9a66}
[2009/05/03 02:17:38 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{6ce6f000-9b3c-11dd-ad8b-0800200c9a66}
[2009/05/12 09:28:21 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{7102aba3-045c-4ec2-b921-46d87636d84b}
[2009/05/07 06:06:34 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{7378B8C2-FC38-41b8-A8C9-875D1F5B0A24}
[2009/05/03 02:18:16 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
[2009/05/03 02:17:38 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{8a39fe10-f553-11dd-87af-0800200c9a66}
[2009/05/03 02:18:09 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{95f24680-9e31-11da-a746-0800200c9a66}
[2009/05/03 02:18:16 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2009/05/03 02:18:08 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}
[2009/05/03 02:18:11 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{b749fc7c-e949-447f-926c-3f4eed6accfe}
[2009/05/03 02:18:20 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/05/03 02:18:16 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{cc85cd4e-5a5b-4eda-a25c-bdaffa93b406}
[2009/05/03 02:18:21 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/05/03 02:17:36 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{D46E8522-6E86-44b1-A622-58C0668AD78E}
[2009/05/03 02:18:19 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2009/05/03 02:18:09 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{DAD0F81A-CF67-4eed-98D6-26F6E47274CA}
[2009/05/03 02:17:37 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{dc961bb0-dfb2-11dc-95ff-0800200c9a66}
[2009/05/11 02:06:24 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/05/03 02:18:16 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2009/05/03 02:18:08 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\{EDA7B1D7-F793-4e03-B074-E6F303317FB0}
[2009/05/03 02:18:21 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/03 02:18:17 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/03 02:18:20 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/04 08:42:58 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/03 02:18:20 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/03 02:18:10 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/03 02:18:20 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/03 02:18:16 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/03 02:18:16 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/03 02:18:16 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/07 20:34:10 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/11 02:06:14 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/04 08:43:00 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/03 02:18:10 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/13 10:39:18 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/03 02:18:11 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/03 02:17:37 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/03 02:18:20 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/03 02:18:10 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/03 02:18:10 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\pastetotab@loucypher
[2009/05/03 02:18:10 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/03 02:18:10 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\ststusscicalc@sunny
[2009/05/03 02:18:09 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/03 02:17:36 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/03 02:18:20 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\[removed]
[2009/05/03 02:18:08 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\mozilla\Firefox\Profiles\77jcme81.default\extensions\yetanothersmoothscrolling@kataho
[2009/05/14 10:13:25 | 00,001,299 | —- | M] () – C:\Documents and Settings\willy\Application Data\Mozilla\FireFox\Profiles\77jcme81.default\searchplugins\-what-the-tech.xml
[2009/05/04 18:26:03 | 00,001,767 | —- | M] () – C:\Documents and Settings\willy\Application Data\Mozilla\FireFox\Profiles\77jcme81.default\searchplugins\deviantart.xml
[2009/05/03 14:31:21 | 00,002,042 | —- | M] () – C:\Documents and Settings\willy\Application Data\Mozilla\FireFox\Profiles\77jcme81.default\searchplugins\facebook.xml
[2009/05/11 02:14:22 | 00,002,347 | —- | M] () – C:\Documents and Settings\willy\Application Data\Mozilla\FireFox\Profiles\77jcme81.default\searchplugins\howstuffworks.xml
[2009/05/04 07:34:21 | 00,000,561 | —- | M] () – C:\Documents and Settings\willy\Application Data\Mozilla\FireFox\Profiles\77jcme81.default\searchplugins\rapidshares.xml
[2009/05/03 02:47:41 | 00,001,997 | —- | M] () – C:\Documents and Settings\willy\Application Data\Mozilla\FireFox\Profiles\77jcme81.default\searchplugins\userstylesorg.xml
[2009/05/04 07:39:15 | 00,004,096 | —- | M] () – C:\Documents and Settings\willy\Application Data\Mozilla\FireFox\Profiles\77jcme81.default\searchplugins\warez-bborg–search.xml
[2009/05/03 02:20:28 | 00,000,872 | —- | M] () – C:\Documents and Settings\willy\Application Data\Mozilla\FireFox\Profiles\77jcme81.default\searchplugins\yahoo.gif
[2009/05/03 02:20:28 | 00,000,466 | —- | M] () – C:\Documents and Settings\willy\Application Data\Mozilla\FireFox\Profiles\77jcme81.default\searchplugins\yahoo.src
[2009/05/03 02:20:28 | 00,001,767 | —- | M] () – C:\Documents and Settings\willy\Application Data\Mozilla\FireFox\Profiles\77jcme81.default\searchplugins\yahoo.xml
[2009/05/07 06:04:32 | 00,000,945 | —- | M] () – C:\Documents and Settings\willy\Application Data\Mozilla\FireFox\Profiles\77jcme81.default\searchplugins\youtube-video-search.xml
[2009/05/14 11:30:58 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/03/14 18:18:53 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{77AA1884-7357-459B-9AA1-F4F821803754}
[2009/05/03 02:15:29 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/18 09:00:07 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/03/27 05:14:04 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/04/24 12:38:30 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/24 12:38:32 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/24 08:39:08 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/24 08:39:08 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/24 08:39:08 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/24 08:39:08 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/24 08:39:08 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/24 08:39:08 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/24 08:39:08 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IE7Pro BHO) - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll (IE7Pro.com)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {07DC0C7D-693D-4AB3-B736-266E62BE3EC4} - C:\WINDOWS\system32\byXQIXQJ.dll ()
O2 - BHO: (FGCatchUrl) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\ddcBRHXp.dll ()
O2 - BHO: (Windows Live Sign-in Helper) - {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: () - {993A2DC4-1E2F-43DC-9B01-9AA1C4358DC3} - c:\windows\system32\bitiiuz.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (ImageShack Toolbar) - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll (ImageShack Corp.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install ()
O4 - HKLM..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow (Trend Micro Inc.)
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SkyTel] SkyTel.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TV Card Remote Control Device Monitor] C:\WINDOWS\713xRMTMon.exe ()
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" (Nero AG)
O4 - HKCU..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [PC Suite Tray] "E:\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray (Nokia)
O4 - HKLM..\RunOnceEx: [] File not found
O4 - Startup: C:\Documents and Settings\willy\Start Menu\Programs\Startup\Multiply AutoUploader.lnk = E:\Multiply\AutoUploader\Multiply AutoUploader\Multiply AutoUploader.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O8 - Extra context menu item: Post Image to Blog - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5003 (ImageShack Corp.)
O8 - Extra context menu item: Tag This Image - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5002 (ImageShack Corp.)
O8 - Extra context menu item: Transload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5004 (ImageShack Corp.)
O8 - Extra context menu item: Upload All Images to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5000 (ImageShack Corp.)
O8 - Extra context menu item: Upload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5001 (ImageShack Corp.)
O9 - Extra Button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll (IE7Pro.com)
O9 - Extra 'Tools' menuitem : IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll (IE7Pro.com)
O9 - Extra Button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll (IE7Pro.com)
O9 - Extra 'Tools' menuitem : IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll (IE7Pro.com)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [Bluetooth Namespace] - C:\WINDOWS\system32\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1240363149828 (WUWebControl Class)
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab (ImageShack Toolbar)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ddcBRHXp: DllName - ddcBRHXp.dll - C:\WINDOWS\system32\ddcBRHXp.dll ()
O20 - Winlogon\Notify\fidyljyn: DllName - bitiiuz.dll - C:\WINDOWS\system32\bitiiuz.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\ddcBRHXp.dll ()
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\byXQIXQJ) - C:\WINDOWS\system32\byXQIXQJ.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2008/12/11 10:47:15 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{6656a2cc-c739-11dd-9f8c-001bfc727f38}\Shell - "" = AutoRun
O33 - MountPoints2\{6656a2cc-c739-11dd-9f8c-001bfc727f38}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{943a7e6e-f30d-11dd-a0c0-001bfc727f38}\Shell - "" = AutoRun
O33 - MountPoints2\{943a7e6e-f30d-11dd-a0c0-001bfc727f38}\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[2009/05/14 09:46:10 | 00,000,704 | —- | C] () – C:\Documents and Settings\willy\Desktop\HijackThis.lnk
[2009/05/14 09:18:45 | 00,537,376 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\All Users\Documents\Q815021_WXP_SP2_x86_ENU.exe
[2009/05/14 08:42:45 | 00,708,096 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\All Users\Documents\ntdll.dll
[2009/05/14 08:38:10 | 00,000,667 | —- | C] () – C:\Documents and Settings\All Users\Documents\shexview.cfg
[2009/05/14 08:33:04 | 00,107,888 | —- | C] (Sony DADC Austria AG.) – C:\WINDOWS\System32\CmdLineExt.dll
[2009/05/14 08:32:26 | 05,238,784 | —- | C] (Sony DADC Austria AG) – C:\Documents and Settings\All Users\Documents\Repair.exe
[2009/05/14 08:32:24 | 00,038,912 | —- | C] (NirSoft) – C:\Documents and Settings\All Users\Documents\shexview.exe
[2009/05/14 08:32:24 | 00,017,394 | —- | C] () – C:\Documents and Settings\All Users\Documents\shexview.chm
[2009/05/14 01:33:32 | 00,166,385 | -HS- | C] () – C:\WINDOWS\System32\JQXIQXyb.ini2
[2009/05/14 01:33:32 | 00,166,385 | -HS- | C] () – C:\WINDOWS\System32\JQXIQXyb.ini
[2009/05/14 01:33:28 | 00,236,544 | —- | C] () – C:\WINDOWS\System32\byXQIXQJ.dll
[2009/05/14 00:56:18 | 00,036,352 | —- | C] () – C:\WINDOWS\System32\ddcBRHXp.dll
[2009/05/14 00:56:05 | 00,413,267 | —- | C] () – C:\Documents and Settings\willy\My Documents\ec2a58fe3512453043f311f5efa4783c.jpg
[2009/05/12 10:42:02 | 00,630,784 | —- | C] () – C:\Documents and Settings\willy\My Documents\Doc2.doc
[2009/05/12 10:20:11 | 00,393,216 | —- | C] () – C:\Documents and Settings\willy\My Documents\hanz.ppt
[2009/05/12 10:18:16 | 00,265,216 | —- | C] () – C:\Documents and Settings\willy\My Documents\hanz.doc
[2009/05/12 08:48:01 | 81,425,951 | —- | C] () – C:\Documents and Settings\willy\My Documents\Watch_Katekyo_Hitman_Reborn__Episode_103_Online___English_Dubbed_Subbed_Epi
sodes_vid_7593562e0b2a430e9ea56e559a7b7850.flv
[2009/05/12 08:17:22 | 00,154,624 | —- | C] () – C:\Documents and Settings\willy\Desktop\Youth_Camp_Training_Manual.doc
[2009/05/12 08:17:09 | 00,205,824 | —- | C] () – C:\Documents and Settings\willy\Desktop\Youth Camp Manual.doc
[2009/05/12 07:41:50 | 89,387,554 | —- | C] () – C:\Documents and Settings\willy\My Documents\Watch_Katekyo_Hitman_Reborn__Episode_102_Online___English_Dubbed_Subbed_Epi
sodes_vid_92c9e02d293b4707becf2ed675cc6846.flv
[2009/05/12 07:34:45 | 71,216,884 | —- | C] () – C:\Documents and Settings\willy\My Documents\Watch_Katekyo_Hitman_Reborn__Episode_101_Online___English_Dubbed_Subbed_Epi
sodes_vid_1ce55dfc16de4249828b89d32387b7b0.flv
[2009/05/11 02:03:16 | 00,000,712 | —- | C] () – C:\Documents and Settings\willy\Start Menu\Programs\Startup\Multiply AutoUploader.lnk
[2009/05/11 02:03:15 | 00,000,000 | —D | C] – C:\Documents and Settings\willy\Application Data\com.Multiply.AutoUploader.C7DF09F73C2059D294831784007C5F0856677385.1
[2009/05/11 02:03:12 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adobe
[2009/05/11 02:03:11 | 00,000,712 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Multiply AutoUploader.lnk
[2009/05/11 02:03:07 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2009/05/10 08:17:28 | 42,855,474 | —- | C] () – C:\Documents and Settings\willy\My Documents\Blackout RO Installer [0204].exe
[2009/05/09 04:09:13 | 00,000,000 | —D | C] – C:\Program Files\Gravity
[2009/05/09 04:06:09 | 26,439,260 | —- | C] (Pantaray Research LTD.) – C:\Documents and Settings\willy\Desktop\DarkRO-Setup.exe
[2009/05/09 02:22:59 | 00,000,000 | —D | C] – C:\Documents and Settings\willy\Desktop\200MOVIE
[2009/05/08 07:26:44 | 01,228,107 | —- | C] () – C:\Documents and Settings\willy\My Documents\GrafArt_v1_0_by_trawnick.rar
[2009/05/07 20:36:59 | 15,731,9168 | —- | C] () – C:\Documents and Settings\willy\My Documents\[DB]_Bleach_218_[F3D45E74].avi
[2009/05/07 20:36:59 | 00,013,814 | —- | C] () – C:\Documents and Settings\willy\My Documents\[DB]_Bleach_218_[F3D45E74].avi.torrent
[2009/05/07 14:28:01 | 00,276,480 | —- | C] () – C:\Documents and Settings\willy\My Documents\YFCDOODLE2.thm
[2009/05/07 14:27:02 | 00,368,640 | —- | C] () – C:\Documents and Settings\willy\My Documents\YFCDOODLE1.thm
[2009/05/07 10:20:43 | 12,091,486 | —- | C] () – C:\Documents and Settings\willy\My Documents\GMA1-7.part1.rar
[2009/05/07 10:20:15 | 03,098,680 | —- | C] () – C:\Documents and Settings\willy\My Documents\3.rar
[2009/05/06 17:55:23 | 00,088,560 | R— | C] (MCCI) – C:\WINDOWS\System32\drivers\W700mgmt.sys
[2009/05/06 17:55:19 | 00,086,368 | R— | C] (MCCI) – C:\WINDOWS\System32\drivers\W700obex.sys
[2009/05/06 17:55:10 | 00,097,056 | R— | C] (MCCI) – C:\WINDOWS\System32\drivers\W700mdm.sys
[2009/05/06 17:55:10 | 00,009,264 | R— | C] (MCCI) – C:\WINDOWS\System32\drivers\W700mdfl.sys
[2009/05/06 17:55:10 | 00,006,208 | R— | C] (MCCI) – C:\WINDOWS\System32\drivers\W700cmnt.sys
[2009/05/06 17:55:10 | 00,006,208 | R— | C] (MCCI) – C:\WINDOWS\System32\drivers\W700cm.sys
[2009/05/06 17:55:07 | 00,061,536 | R— | C] (MCCI) – C:\WINDOWS\System32\drivers\W700bus.sys
[2009/05/06 17:55:07 | 00,005,840 | R— | C] (MCCI) – C:\WINDOWS\System32\drivers\W700whnt.sys
[2009/05/06 17:55:07 | 00,005,840 | R— | C] (MCCI) – C:\WINDOWS\System32\drivers\W700wh.sys
[2009/05/06 16:53:04 | 10,526,923 | —- | C] () – C:\Documents and Settings\willy\My Documents\Remix.wma
[2009/05/06 08:06:56 | 00,204,800 | —- | C] (dqrahrqttw Corporation) – C:\WINDOWS\System32\inst_e82.exe
[2009/05/06 00:00:52 | 00,047,668 | —- | C] () – C:\Documents and Settings\willy\My Documents\iwantobold_2.jpg
[2009/05/05 22:05:28 | 00,116,303 | —- | C] () – C:\Documents and Settings\willy\My Documents\Cheskascopy.jpg
[2009/05/05 21:45:38 | 00,026,112 | —- | C] () – C:\Documents and Settings\willy\My Documents\Apostles of Christ.doc
[2009/05/05 21:45:26 | 00,209,408 | —- | C] () – C:\Documents and Settings\willy\My Documents\movingletting.ppt
[2009/05/04 19:43:08 | 00,000,000 | —D | C] – C:\Documents and Settings\willy\Application Data\Adobe
[2009/05/04 19:10:25 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2009/05/03 02:15:29 | 00,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/04/29 20:52:21 | 03,631,020 | —- | C] () – C:\Documents and Settings\willy\Desktop\Paradiso Girls ft Eve - Patron Tequila.mp3
[2009/04/24 06:14:07 | 00,191,488 | —- | C] (fluigxxfuu Corporation) – C:\WINDOWS\System32\wingo.exe
[2009/04/23 21:15:19 | 00,002,319 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Nero StartSmart.lnk
[2009/04/23 21:15:19 | 00,002,227 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Nero Home.lnk
[2009/04/23 21:14:53 | 00,000,000 | —D | C] – C:\Documents and Settings\willy\Application Data\Ahead
[2009/04/23 21:12:12 | 00,000,000 | —D | C] – C:\Program Files\Nero
[2009/04/23 21:12:12 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Ahead
[2009/04/23 19:34:44 | 03,966,367 | —- | C] () – C:\Documents and Settings\willy\Desktop\Are You Going To Finish Strong.wmv
[2009/04/23 07:32:45 | 00,014,336 | —- | C] (Casimir666 Incorporated) – C:\WINDOWS\System32\drivers\PN31Snoop.sys
[2009/04/22 15:05:21 | 00,013,794 | —- | C] () – C:\Documents and Settings\willy\My Documents\b216.torrent
[2009/04/22 09:19:47 | 00,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2009/04/22 06:18:58 | 00,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/04/22 05:35:37 | 02,077,424 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\willy\My Documents\WindowsXP-KB894391-x86-ENU.exe
[2009/04/22 05:22:30 | 00,000,000 | —D | C] – C:\WINDOWS\System32\kktools
[2009/04/20 15:21:38 | 00,212,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\richtx32.ocx
[2009/04/20 15:21:38 | 00,209,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tabctl32.ocx
[2009/04/20 15:21:38 | 00,200,704 | —- | C] (Sheridan Software Systems, Inc.) – C:\WINDOWS\System32\THREED32.OCX
[2009/04/20 15:21:38 | 00,193,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mci32.ocx
[2009/04/20 15:21:38 | 00,000,000 | —D | C] – C:\Program Files\The Holy Bible
[2009/04/20 15:16:18 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\ST5UNST.EXE
[2009/04/20 15:16:18 | 00,029,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\VB5StKit.dll
[2009/04/18 08:48:15 | 00,000,000 | —D | C] – C:\Downloads
[2009/04/18 06:10:40 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\2cb8e0ee.sys
[2009/04/16 21:18:46 | 00,000,000 | —D | C] – C:\Documents and Settings\willy\Application Data\vlc
[2009/04/16 21:15:11 | 00,000,448 | —- | C] () – C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2009/04/15 23:01:09 | 00,435,107 | —- | C] () – C:\Documents and Settings\willy\My Documents\vlcsnap-115337.png
[2009/04/15 22:55:56 | 00,278,928 | —- | C] () – C:\Documents and Settings\willy\My Documents\vlcsnap-112213.png
[2009/04/15 22:44:08 | 00,454,055 | —- | C] () – C:\Documents and Settings\willy\My Documents\vlcsnap-105134.png
[2009/04/15 22:44:01 | 00,430,687 | —- | C] () – C:\Documents and Settings\willy\My Documents\vlcsnap-105067.png
[2009/04/15 22:43:36 | 00,412,703 | —- | C] () – C:\Documents and Settings\willy\My Documents\vlcsnap-104809.png
[2009/04/15 22:39:45 | 00,606,320 | —- | C] () – C:\Documents and Settings\willy\My Documents\vlcsnap-102506.png
[2009/04/15 22:39:36 | 00,433,414 | —- | C] () – C:\Documents and Settings\willy\My Documents\vlcsnap-102418.png
[2009/04/15 22:39:29 | 00,345,930 | —- | C] () – C:\Documents and Settings\willy\My Documents\vlcsnap-102341.png
[2009/04/15 22:39:22 | 00,476,453 | —- | C] () – C:\Documents and Settings\willy\My Documents\vlcsnap-102276.png
[2009/04/15 22:37:26 | 00,380,758 | —- | C] () – C:\Documents and Settings\willy\My Documents\vlcsnap-101085.png
[2009/04/15 22:35:30 | 00,302,793 | —- | C] () – C:\Documents and Settings\willy\My Documents\vlcsnap-99939.png
[2009/04/15 22:35:10 | 00,232,804 | —- | C] () – C:\Documents and Settings\willy\My Documents\vlcsnap-99749.png
[2009/04/15 22:35:02 | 00,384,335 | —- | C] () – C:\Documents and Settings\willy\My Documents\vlcsnap-98149.png
[2009/04/15 22:28:37 | 00,558,079 | —- | C] () – C:\Documents and Settings\willy\My Documents\vlcsnap-95784.png
[2009/04/15 17:09:12 | 00,000,000 | —D | C] – C:\Documents and Settings\willy\Application Data\esnbentp
[2009/04/15 14:15:39 | 00,000,434 | —- | C] () – C:\WINDOWS\tasks\At1.job
[2009/04/14 17:44:14 | 00,107,520 | —- | C] () – C:\Documents and Settings\willy\My Documents\Holy Family Files.xls
[2009/04/14 14:39:50 | 00,000,513 | —- | C] () – C:\Documents and Settings\willy\Desktop\Emsa DLL Register Tool.lnk
[2009/04/14 14:36:31 | 00,286,208 | —- | C] () – C:\Documents and Settings\willy\My Documents\binkw32.dll
[2009/04/14 14:25:47 | 00,000,651 | —- | C] () – C:\Documents and Settings\willy\Desktop\Blackout RO Patcher.lnk
[2009/04/14 14:25:47 | 00,000,593 | —- | C] () – C:\Documents and Settings\willy\Desktop\Blackout RO.lnk
[2009/04/14 14:16:03 | 00,000,540 | —- | C] () – C:\Documents and Settings\willy\Desktop\sakray.LNK
[2009/04/14 14:13:24 | 00,065,536 | —- | C] () – C:\WINDOWS\IFinst27.exe
[2009/04/09 15:22:39 | 00,000,096 | —- | C] () – C:\WINDOWS\Vstudio.INI
[2009/04/09 15:20:49 | 00,000,041 | —- | C] () – C:\WINDOWS\dswplug.ini
[2009/04/09 15:19:26 | 00,001,173 | —- | C] () – C:\WINDOWS\Ulead32.ini
[2009/04/09 15:19:26 | 00,000,061 | —- | C] () – C:\WINDOWS\Msdevctl.ini
[2009/04/04 00:11:08 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\2a0dcc1b.sys
[2009/03/27 09:17:31 | 00,000,000 | —- | C] () – C:\WINDOWS\WB.ini
[2009/03/26 06:38:26 | 00,000,031 | —- | C] () – C:\WINDOWS\GunzLauncher.INI
[2009/03/22 20:34:40 | 00,004,616 | —- | C] () – C:\WINDOWS\FORGE32.INI
[2009/03/22 20:34:20 | 00,061,952 | —- | C] () – C:\WINDOWS\System32\rmmerge2.dll
[2009/03/22 20:34:20 | 00,009,728 | —- | C] () – C:\WINDOWS\System32\rmevents.dll
[2009/03/22 20:22:41 | 00,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2009/03/06 23:48:44 | 00,000,022 | —- | C] () – C:\WINDOWS\kodakpcd.willy.ini
[2009/02/16 22:10:39 | 00,000,098 | —- | C] () – C:\WINDOWS\VPPLAYS.INI
[2009/01/28 23:18:35 | 00,000,202 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/12/26 01:22:44 | 00,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2008/12/21 13:39:01 | 00,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2008/12/15 17:29:08 | 01,724,416 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2008/12/15 17:29:08 | 01,101,824 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/12/15 17:29:04 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2008/12/15 17:29:03 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2008/12/15 17:29:01 | 01,507,328 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2008/12/11 12:16:49 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/12/11 11:55:28 | 00,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2008/12/11 11:55:27 | 00,013,265 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008/12/11 11:55:17 | 00,010,288 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007/12/15 14:55:30 | 05,423,104 | —- | C] () – C:\WINDOWS\System32\tlpsplib10.dll
[2007/03/29 22:00:40 | 00,203,264 | —- | C] () – C:\WINDOWS\System32\CddbCdda.dll
[2004/07/17 11:36:38 | 00,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2003/01/07 15:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/08/29 20:00:00 | 00,000,654 | —- | C] () – C:\WINDOWS\win.ini
[2002/08/29 20:00:00 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2000/09/08 17:53:50 | 00,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll
[1995/10/21 10:37:52 | 00,035,328 | —- | C] () – C:\WINDOWS\System32\INETWH32.DLL
[1995/10/21 10:37:52 | 00,035,328 | —- | C] () – C:\WINDOWS\INETWH32.DLL

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\willy\My Documents\*.tmp files]
[2009/05/14 11:53:01 | 00,166,861 | -HS- | M] () – C:\WINDOWS\System32\JQXIQXyb.ini2
[2009/05/14 11:53:01 | 00,166,861 | -HS- | M] () – C:\WINDOWS\System32\JQXIQXyb.ini
[2009/05/14 11:20:10 | 00,000,486 | —- | M] () – C:\WINDOWS\tasks\1-Click Maintenance.job
[2009/05/14 11:19:19 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/14 11:19:18 | 00,000,434 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2009/05/14 11:19:14 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\willy\Local Settings\desktop.ini
[2009/05/14 11:19:03 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/14 10:22:52 | 00,000,202 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/05/14 09:46:10 | 00,000,704 | —- | M] () – C:\Documents and Settings\willy\Desktop\HijackThis.lnk
[2009/05/14 09:14:38 | 00,537,376 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\All Users\Documents\Q815021_WXP_SP2_x86_ENU.exe
[2009/05/14 09:05:35 | 00,000,667 | —- | M] () – C:\Documents and Settings\All Users\Documents\shexview.cfg
[2009/05/14 09:01:07 | 00,107,888 | —- | M] (Sony DADC Austria AG.) – C:\WINDOWS\System32\CmdLineExt.dll
[2009/05/14 08:57:30 | 00,000,212 | RHS- | M] () – C:\boot.ini
[2009/05/14 01:33:31 | 00,236,544 | —- | M] () – C:\WINDOWS\System32\byXQIXQJ.dll
[2009/05/14 01:29:58 | 00,000,712 | —- | M] () – C:\Documents and Settings\willy\Start Menu\Programs\Startup\Multiply AutoUploader.lnk
[2009/05/14 01:28:31 | 00,203,853 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/05/14 00:56:18 | 00,036,352 | —- | M] () – C:\WINDOWS\System32\ddcBRHXp.dll
[2009/05/14 00:56:05 | 00,413,267 | —- | M] () – C:\Documents and Settings\willy\My Documents\ec2a58fe3512453043f311f5efa4783c.jpg
[2009/05/12 17:39:47 | 00,002,013 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Steam.lnk
[2009/05/12 10:42:02 | 00,630,784 | —- | M] () – C:\Documents and Settings\willy\My Documents\Doc2.doc
[2009/05/12 10:20:11 | 00,393,216 | —- | M] () – C:\Documents and Settings\willy\My Documents\hanz.ppt
[2009/05/12 10:18:16 | 00,265,216 | —- | M] () – C:\Documents and Settings\willy\My Documents\hanz.doc
[2009/05/12 08:55:36 | 81,425,951 | —- | M] () – C:\Documents and Settings\willy\My Documents\Watch_Katekyo_Hitman_Reborn__Episode_103_Online___English_Dubbed_Subbed_Epi
sodes_vid_7593562e0b2a430e9ea56e559a7b7850.flv
[2009/05/12 08:17:23 | 00,154,624 | —- | M] () – C:\Documents and Settings\willy\Desktop\Youth_Camp_Training_Manual.doc
[2009/05/12 08:17:10 | 00,205,824 | —- | M] () – C:\Documents and Settings\willy\Desktop\Youth Camp Manual.doc
[2009/05/12 07:50:01 | 89,387,554 | —- | M] () – C:\Documents and Settings\willy\My Documents\Watch_Katekyo_Hitman_Reborn__Episode_102_Online___English_Dubbed_Subbed_Epi
sodes_vid_92c9e02d293b4707becf2ed675cc6846.flv
[2009/05/12 07:41:17 | 71,216,884 | —- | M] () – C:\Documents and Settings\willy\My Documents\Watch_Katekyo_Hitman_Reborn__Episode_101_Online___English_Dubbed_Subbed_Epi
sodes_vid_1ce55dfc16de4249828b89d32387b7b0.flv
[2009/05/12 07:05:26 | 00,359,344 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/05/11 19:03:59 | 00,087,608 | —- | M] () – C:\Documents and Settings\willy\Application Data\inst.exe
[2009/05/11 19:03:59 | 00,047,360 | —- | M] (VSO Software) – C:\Documents and Settings\willy\Application Data\pcouffin.sys
[2009/05/11 19:03:59 | 00,007,887 | —- | M] () – C:\Documents and Settings\willy\Application Data\pcouffin.cat
[2009/05/11 19:03:59 | 00,001,144 | —- | M] () – C:\Documents and Settings\willy\Application Data\pcouffin.inf
[2009/05/11 02:03:11 | 00,000,712 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Multiply AutoUploader.lnk
[2009/05/10 13:42:16 | 10,700,800 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2009/05/10 13:42:16 | 07,571,456 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mb
[2009/05/10 13:28:00 | 00,000,000 | —- | M] () – C:\EasyShare.dmp
[2009/05/10 08:21:35 | 42,855,474 | —- | M] () – C:\Documents and Settings\willy\My Documents\Blackout RO Installer [0204].exe
[2009/05/09 04:08:41 | 26,439,260 | —- | M] (Pantaray Research LTD.) – C:\Documents and Settings\willy\Desktop\DarkRO-Setup.exe
[2009/05/08 07:27:20 | 01,228,107 | —- | M] () – C:\Documents and Settings\willy\My Documents\GrafArt_v1_0_by_trawnick.rar
[2009/05/07 20:46:53 | 15,731,9168 | —- | M] () – C:\Documents and Settings\willy\My Documents\[DB]_Bleach_218_[F3D45E74].avi
[2009/05/07 20:36:59 | 00,013,814 | —- | M] () – C:\Documents and Settings\willy\My Documents\[DB]_Bleach_218_[F3D45E74].avi.torrent
[2009/05/07 14:28:10 | 00,276,480 | —- | M] () – C:\Documents and Settings\willy\My Documents\YFCDOODLE2.thm
[2009/05/07 14:27:02 | 00,368,640 | —- | M] () – C:\Documents and Settings\willy\My Documents\YFCDOODLE1.thm
[2009/05/07 10:32:50 | 12,091,486 | —- | M] () – C:\Documents and Settings\willy\My Documents\GMA1-7.part1.rar
[2009/05/07 10:21:17 | 03,098,680 | —- | M] () – C:\Documents and Settings\willy\My Documents\3.rar
[2009/05/06 17:45:48 | 10,526,923 | —- | M] () – C:\Documents and Settings\willy\My Documents\Remix.wma
[2009/05/06 08:06:58 | 00,204,800 | —- | M] (dqrahrqttw Corporation) – C:\WINDOWS\System32\inst_e82.exe
[2009/05/06 00:00:55 | 00,047,668 | —- | M] () – C:\Documents and Settings\willy\My Documents\iwantobold_2.jpg
[2009/05/05 22:05:33 | 00,116,303 | —- | M] () – C:\Documents and Settings\willy\My Documents\Cheskascopy.jpg
[2009/05/05 21:45:40 | 00,026,112 | —- | M] () – C:\Documents and Settings\willy\My Documents\Apostles of Christ.doc
[2009/05/05 21:45:26 | 00,209,408 | —- | M] () – C:\Documents and Settings\willy\My Documents\movingletting.ppt
[2009/05/03 02:15:29 | 00,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/05/02 12:36:24 | 00,017,394 | —- | M] () – C:\Documents and Settings\All Users\Documents\shexview.chm
[2009/04/29 22:42:22 | 00,004,616 | —- | M] () – C:\WINDOWS\FORGE32.INI
[2009/04/29 21:12:15 | 03,631,020 | —- | M] () – C:\Documents and Settings\willy\Desktop\Paradiso Girls ft Eve - Patron Tequila.mp3
[2009/04/29 14:32:02 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/04/28 06:35:30 | 00,191,488 | —- | M] (fluigxxfuu Corporation) – C:\WINDOWS\System32\wingo.exe
[2009/04/24 05:59:07 | 00,000,155 | —- | M] () – C:\WINDOWS\System32\SelfDel.bat
[2009/04/23 21:15:19 | 00,002,319 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Nero StartSmart.lnk
[2009/04/23 21:15:19 | 00,002,227 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Nero Home.lnk
[2009/04/23 19:40:13 | 03,966,367 | —- | M] () – C:\Documents and Settings\willy\Desktop\Are You Going To Finish Strong.wmv
[2009/04/23 07:32:45 | 00,014,336 | —- | M] (Casimir666 Incorporated) – C:\WINDOWS\System32\drivers\PN31Snoop.sys
[2009/04/22 18:28:14 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/04/22 15:05:21 | 00,013,794 | —- | M] () – C:\Documents and Settings\willy\My Documents\b216.torrent
[2009/04/22 10:38:02 | 00,000,654 | —- | M] () – C:\WINDOWS\win.ini
[2009/04/22 10:38:02 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/04/22 08:06:23 | 00,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/04/22 05:35:43 | 02,077,424 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\willy\My Documents\WindowsXP-KB894391-x86-ENU.exe
[2009/04/18 21:35:58 | 00,075,776 | -HS- | M] () – C:\Documents and Settings\willy\My Documents\Thumbs.db
[2009/04/18 07:57:52 | 00,002,003 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2009/04/18 07:40:06 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\2cb8e0ee.sys
[2009/04/16 21:15:11 | 00,000,448 | —- | M] () – C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2009/04/15 23:01:09 | 00,435,107 | —- | M] () – C:\Documents and Settings\willy\My Documents\vlcsnap-115337.png
[2009/04/15 22:55:56 | 00,278,928 | —- | M] () – C:\Documents and Settings\willy\My Documents\vlcsnap-112213.png
[2009/04/15 22:44:08 | 00,454,055 | —- | M] () – C:\Documents and Settings\willy\My Documents\vlcsnap-105134.png
[2009/04/15 22:44:01 | 00,430,687 | —- | M] () – C:\Documents and Settings\willy\My Documents\vlcsnap-105067.png
[2009/04/15 22:43:36 | 00,412,703 | —- | M] () – C:\Documents and Settings\willy\My Documents\vlcsnap-104809.png
[2009/04/15 22:39:45 | 00,606,320 | —- | M] () – C:\Documents and Settings\willy\My Documents\vlcsnap-102506.png
[2009/04/15 22:39:36 | 00,433,414 | —- | M] () – C:\Documents and Settings\willy\My Documents\vlcsnap-102418.png
[2009/04/15 22:39:29 | 00,345,930 | —- | M] () – C:\Documents and Settings\willy\My Documents\vlcsnap-102341.png
[2009/04/15 22:39:23 | 00,476,453 | —- | M] () – C:\Documents and Settings\willy\My Documents\vlcsnap-102276.png
[2009/04/15 22:37:26 | 00,380,758 | —- | M] () – C:\Documents and Settings\willy\My Documents\vlcsnap-101085.png
[2009/04/15 22:35:30 | 00,302,793 | —- | M] () – C:\Documents and Settings\willy\My Documents\vlcsnap-99939.png
[2009/04/15 22:35:10 | 00,232,804 | —- | M] () – C:\Documents and Settings\willy\My Documents\vlcsnap-99749.png
[2009/04/15 22:35:02 | 00,384,335 | —- | M] () – C:\Documents and Settings\willy\My Documents\vlcsnap-98149.png
[2009/04/15 22:28:38 | 00,558,079 | —- | M] () – C:\Documents and Settings\willy\My Documents\vlcsnap-95784.png
[2009/04/15 21:05:02 | 00,065,536 | —- | M] () – C:\WINDOWS\IFinst27.exe
[2009/04/15 02:08:51 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\2a0dcc1b.sys
[2009/04/14 17:44:15 | 00,107,520 | —- | M] () – C:\Documents and Settings\willy\My Documents\Holy Family Files.xls
[2009/04/14 14:39:50 | 00,000,513 | —- | M] () – C:\Documents and Settings\willy\Desktop\Emsa DLL Register Tool.lnk
[2009/04/14 14:25:47 | 00,000,651 | —- | M] () – C:\Documents and Settings\willy\Desktop\Blackout RO Patcher.lnk
[2009/04/14 14:25:47 | 00,000,593 | —- | M] () – C:\Documents and Settings\willy\Desktop\Blackout RO.lnk
[2009/04/14 14:16:03 | 00,000,540 | —- | M] () – C:\Documents and Settings\willy\Desktop\sakray.LNK

========== LOP Check ==========

[2009/05/13 10:34:04 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/12/21 13:18:23 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{148D8B8A-8F96-4822-81EC-D510B626B7D5}
[2009/03/18 11:24:49 | 00,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2009/04/10 08:42:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\1Click DVD Copy
[2009/05/11 02:03:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2009/03/07 09:14:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2009/04/12 07:24:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/03/30 10:53:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2008/12/20 23:59:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kodak
[2009/01/24 13:08:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2009/01/24 11:30:09 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/12/19 20:20:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\nView_Profiles
[2009/03/30 10:55:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2009/01/08 21:13:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Real
[2009/01/16 21:20:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2009/04/17 07:29:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony Ericsson
[2008/12/26 01:14:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Teleca
[2009/03/18 11:25:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2009/01/16 21:24:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/12/11 12:22:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/12/19 19:25:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2008/12/21 13:07:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/05/13 10:34:04 | 00,000,000 | RH-D | M] – C:\Documents and Settings\willy\Application Data
[2009/01/01 17:50:01 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\2K Sports
[2009/05/12 19:12:00 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Adobe
[2009/01/11 19:04:21 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\AdobeUM
[2009/04/26 13:02:58 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Ahead
[2009/03/07 09:15:12 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Apple Computer
[2009/05/11 02:03:15 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\com.Multiply.AutoUploader.C7DF09F73C2059D294831784007C5F0856677385.1
[2009/03/07 17:54:42 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\dvdcss
[2009/04/15 17:09:12 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\esnbentp
[2009/03/22 23:24:56 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Foxit
[2009/01/03 22:02:41 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Help
[2008/12/11 10:51:36 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Identities
[2009/02/21 17:08:10 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\IEPro
[2009/03/27 05:19:42 | 00,000,000 | -H-D | M] – C:\Documents and Settings\willy\Application Data\ijjigame
[2009/04/09 21:12:21 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Kodak
[2009/04/28 11:35:14 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\LimeWire
[2008/12/19 19:00:27 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Macromedia
[2009/01/07 21:40:22 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Media Player Classic
[2009/05/01 22:33:01 | 00,000,000 | –SD | M] – C:\Documents and Settings\willy\Application Data\Microsoft
[2009/01/19 05:28:25 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\MiniDm
[2009/03/14 23:18:23 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Mozilla
[2009/03/11 10:29:38 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\MxBoost
[2009/01/19 06:27:42 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Nero
[2009/03/30 11:02:26 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Nokia
[2009/05/06 10:44:37 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Opera
[2009/03/30 10:55:41 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\PC Suite
[2009/03/24 18:29:16 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Real
[2008/12/31 10:39:43 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Red Alert 3
[2009/01/21 18:51:48 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Sony
[2008/12/26 01:16:40 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Sony Ericsson
[2008/12/19 23:12:17 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Sun
[2009/01/13 18:27:35 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\SystemRequirementsLab
[2008/12/26 01:17:09 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Teleca
[2009/04/28 12:23:25 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Thinstall
[2009/03/18 11:25:24 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\TuneUp Software
[2009/01/16 21:24:54 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Ulead Systems
[2009/05/08 07:24:35 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\uTorrent
[2009/04/16 21:18:50 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\vlc
[2009/05/11 19:04:00 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Vso
[2008/12/20 11:38:52 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\WinRAR
[2008/12/19 19:24:06 | 00,000,000 | —D | M] – C:\Documents and Settings\willy\Application Data\Yahoo!
[2009/05/14 11:20:10 | 00,000,486 | —- | M] () – C:\WINDOWS\Tasks\1-Click Maintenance.job
[2009/04/29 14:32:02 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2009/05/14 11:19:18 | 00,000,434 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2002/08/29 20:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/05/14 11:19:19 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >

And the last one:

OTListIt Extras logfile created on: 5/14/2009 11:51:43 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.7 Folder = E:\dtA Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18241)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1023.17 Mb Total Physical Memory | 469.33 Mb Available Physical Memory | 45.87% Memory free
2.41 Gb Paging File | 2.04 Gb Available in Paging File | 84.74% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.06 Gb Total Space | 1.78 Gb Free Space | 4.57% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 109.99 Gb Total Space | 59.71 Gb Free Space | 54.28% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JOSE
Current User Name: willy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = Opera.HTML] – Reg Error: Key error. File not found

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"24389:TCP" = 24389:TCP:*:Enabled:BitComet 24389 TCP
"24389:UDP" = 24389:UDP:*:Enabled:BitComet 24389 UDP

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.)
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare ()
C:\Program Files\IEPro\MiniDM.exe:*:Enabled:MiniDM (IE7Pro.com)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\WINDOWS\TEMP\zchMiB.exe:*:Enabled:Windows Time Synchronization File not found
E:\dtA Downloads\utorrent.exe:*:Enabled:µTorrent (BitTorrent, Inc.)
C:\Documents and Settings\willy\Desktop\Garena files\utorrent.exe:*:Enabled:µTorrent (BitTorrent, Inc.)
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\minisvr4.exe:*:Enabled:WinSvrHost32 File not found
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Documents and Settings\willy\Local Settings\Temp\7zS451.tmp\LW\LimeWire.exe:*:Enabled:LimeWire File not found
C:\Documents and Settings\willy\Local Settings\Temp\7zS45E.tmp\LW\LimeWire.exe:*:Enabled:LimeWire File not found

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{048298c9-a4d3-490b-9ff9-ab023a9238f3}" = Steam
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{15AC0C5D-A6FB-4CE2-8CD0-28179EEB5625}" = Nokia Connectivity Cable Driver
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1" = Media Player Classic - Home Cinema v1.2.1008.0
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 13
"{27113ca3-36b8-48ab-a419-79cf1fc0eced}" = Ulead VideoStudio 5.0 DV
"{27cc6ab1-e72b-4179-af1a-eae507ebaf51}_is1" = ConvertHelper 2.2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{356CD0B5-47CF-485A-8F6D-4D137F3D5600}_is1" = Firefox Optimizers
"{38441BE7-79B0-42B8-8297-833704F949FE}" = HLPIndex
"{3b4e636e-9d65-4d67-ba61-189800823f52}" = Windows Live Communications Platform
"{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}" = OTtBPSDK
"{432C3720-37BF-4BD7-8E49-F38E090246D0}" = CR2
"{4448ABF6-786D-4C3D-A49D-7BB237E6DD17}" = Foxit PDF IFilter
"{45338b07-a236-4270-9a77-ebb4115517b5}" = Windows Live Sign-in Assistant
"{4781569D-5404-1F26-4B2B-6DF444441031}" = Nero 7 Ultra Edition
"{48C82F7A-F100-4DAB-A310-8E18BF2159E1}" = ESSvpot
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{4F677FC7-7AA8-412B-A957-F13CBE1C7331}" = ESSSONIC
"{54C8FE84-89C4-40E8-976C-439EB0729BD6}" = CardRd81
"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009
"{58FB2F9A-5F2D-40E8-82DF-4987E60AD8BD}" = Nokia PC Suite
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{87843A41-7808-4F2E-B13F-25C1E67CF2FD}" = ESShelp
"{88F92798-59AB-474F-B40D-1EC5F782F7EE}" = Ulead VideoStudio 9.0
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8}" = ESSCT
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}" = ESScore
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A518D6D8-0A3F-4A91-B4B5-07AF2CDD6E57}" = ImageShack Toolbar for Internet Explorer
"{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}" = ESSvpaht
"{AADAC983-FDE9-42FA-8FD9-7BB324155593}" = HLPRFO
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{af10d7e4-d29a-45da-8050-b116097b69b5}" = Safari
"{AF52AC44-8AE8-44C4-83A4-F9921AB72B83}_is1" = Dirrect X11Beta
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B56B1487-9A26-4AFD-A1FD-949C40F5F2BC}" = Sony Ericsson PC Suite
"{b7f98125-4955-41e3-8a71-4ce11ce9c198}" = KODAK Gallery Upload Software
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
"{BE27845A-6438-4DCF-AE3D-44EC96CB31CA}" = honestech TVR
"{C13A8E73-7E98-4295-BA94-6931701CD1F9}" = Topaz Vivacity
"{c6ca8874-5f22-4af0-9be3-016bf299c536}" = Windows Live Essentials
"{C9E4932C-8417-4E4C-A0E3-EE534810AB4D}" = ClearType Tuning Control Panel Applet
"{CA60320D-6A16-49C8-A34F-84EEF4799567}" = ESSTUTOR
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{D848D140-41C3-4A53-86D8-E866A100B4CD}" = PC Connectivity Solution
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{f6bd194c-4190-4d73-b1b1-c48c99921bfe}" = Windows Live Call
"{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}" = OTtBP
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FB5C5641-EB28-1F59-8F73-14A7F2A3EF89}" = Multiply AutoUploader
"{FDF9943A-3D5C-46B3-9679-586BD237DDEE}" = SKIN0001
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"5986551A16FD8E9B1B4C89E7AAD17C1BB3196D28" = Windows Driver Package - Nokia Modem (10/27/2008 7.01.0.1)
"6D296974BAB6CA8429D5E687B292A6DA3E9FBD4A" = Windows Driver Package - Nokia Modem (10/27/2008 3.9)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AtcL2" = Attansic L2 Fast Ethernet Driver
"CCleaner" = CCleaner (remove only)
"CinePlayer Editor" = CinePlayer Editor 1.4.5
"DarkRO" = DarkRO
"emsa dll register tool_is1" = Emsa DLL Register Tool 1.0
"EPSON Printer and Utilities" = EPSON Printer Software
"Foxit Reader" = Foxit Reader
"garena" = Garena
"HijackThis" = HijackThis 2.0.2
"IE7Pro" = IE7Pro
"ie8" = Windows Internet Explorer 8 Beta 2
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"kristanix right click image converter" = Right Click Image Converter
"Left 4 Dead" = Left 4 Dead
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nokia PC Suite" = Nokia PC Suite
"NVIDIA Drivers" = NVIDIA Drivers
"OfficeScanNT" = Trend Micro OfficeScan Client
"QuickShot_is1" = QuickShot 1.52
"QuicktimeAlt_is1" = QuickTime Alternative 2.7.0
"Ragnarok Online" = Ragnarok Online
"ragnarok sakray" = Ragnarok Sakray
"RealAlt_is1" = Real Alternative 1.9.0
"Sound Forge" = Sound Forge 4.0 for Windows 95 and NT (x86)
"ST5UNST #1" = The Holy Bible KJV Ver.8
"steam app 100" = Condition Zero Deleted Scenes
"steam app 80" = Condition Zero
"SUPER ©" = SUPER © Version 2009.bld.35 (Jan 5, 2009)
"SystemRequirementsLab" = System Requirements Lab
"Update Service" = Update Service
"VLC media player" = VLC media player 0.9.9
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01005" = Microsoft User-Mode Driver Framework Feature Pack 1.5
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ijji.com" = ijji
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/12/2009 12:01:06 AM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18241, faulting
module urlmon.dll, version 8.0.6001.18241, fault address 0x000a85df.

Error - 5/12/2009 12:02:00 AM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18241, faulting
module urlmon.dll, version 8.0.6001.18241, fault address 0x000a85df.

Error - 5/12/2009 12:03:29 AM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18241, faulting
module urlmon.dll, version 8.0.6001.18241, fault address 0x000a85df.

Error - 5/12/2009 12:05:19 AM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18241, faulting
module urlmon.dll, version 8.0.6001.18241, fault address 0x000a85df.

Error - 5/12/2009 12:05:36 AM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18241, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x00018fea.

Error - 5/12/2009 2:31:40 AM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application multiply autouploader.exe, version 0.0.0.0, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x00018fea.

Error - 5/12/2009 3:39:39 AM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application nero.exe, version 7.0.0.0, faulting module bcgcbpro730.dll,
version 7.30.0.0, fault address 0x0011d51b.

Error - 5/12/2009 3:39:51 AM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application nero.exe, version 7.0.0.0, faulting module bcgcbpro730.dll,
version 7.30.0.0, fault address 0x0011d51b.

Error - 5/13/2009 9:46:33 PM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application hijackthis.exe, version 2.0.0.2, faulting module
byxqixqj.dll, version 0.0.0.0, fault address 0x00057e43.

Error - 5/13/2009 9:47:35 PM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application hijackthis.exe, version 2.0.0.2, faulting module
byxqixqj.dll, version 0.0.0.0, fault address 0x00057e43.

[ Application Events ]
Error - 5/12/2009 12:01:06 AM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18241, faulting
module urlmon.dll, version 8.0.6001.18241, fault address 0x000a85df.

Error - 5/12/2009 12:02:00 AM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18241, faulting
module urlmon.dll, version 8.0.6001.18241, fault address 0x000a85df.

Error - 5/12/2009 12:03:29 AM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18241, faulting
module urlmon.dll, version 8.0.6001.18241, fault address 0x000a85df.

Error - 5/12/2009 12:05:19 AM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18241, faulting
module urlmon.dll, version 8.0.6001.18241, fault address 0x000a85df.

Error - 5/12/2009 12:05:36 AM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18241, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x00018fea.

Error - 5/12/2009 2:31:40 AM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application multiply autouploader.exe, version 0.0.0.0, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x00018fea.

Error - 5/12/2009 3:39:39 AM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application nero.exe, version 7.0.0.0, faulting module bcgcbpro730.dll,
version 7.30.0.0, fault address 0x0011d51b.

Error - 5/12/2009 3:39:51 AM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application nero.exe, version 7.0.0.0, faulting module bcgcbpro730.dll,
version 7.30.0.0, fault address 0x0011d51b.

Error - 5/13/2009 9:46:33 PM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application hijackthis.exe, version 2.0.0.2, faulting module
byxqixqj.dll, version 0.0.0.0, fault address 0x00057e43.

Error - 5/13/2009 9:47:35 PM | Computer Name = JOSE | Source = Application Error | ID = 1000
Description = Faulting application hijackthis.exe, version 2.0.0.2, faulting module
byxqixqj.dll, version 0.0.0.0, fault address 0x00057e43.

[ System Events ]
Error - 5/13/2009 8:16:25 PM | Computer Name = JOSE | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip

Error - 5/13/2009 8:16:39 PM | Computer Name = JOSE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 5/13/2009 8:17:37 PM | Computer Name = JOSE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 5/13/2009 8:29:53 PM | Computer Name = JOSE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 5/13/2009 8:32:24 PM | Computer Name = JOSE | Source = Service Control Manager | ID = 7000
Description = The Background Intelligent Transfer Service service failed to start
due to the following error: %%2

Error - 5/13/2009 8:32:24 PM | Computer Name = JOSE | Source = Service Control Manager | ID = 7000
Description = The Automatic Updates service failed to start due to the following
error: %%2

Error - 5/13/2009 8:40:48 PM | Computer Name = JOSE | Source = Service Control Manager | ID = 7000
Description = The Background Intelligent Transfer Service service failed to start
due to the following error: %%2

Error - 5/13/2009 8:40:48 PM | Computer Name = JOSE | Source = Service Control Manager | ID = 7000
Description = The Automatic Updates service failed to start due to the following
error: %%2

Error - 5/13/2009 9:00:21 PM | Computer Name = JOSE | Source = Service Control Manager | ID = 7000
Description = The Background Intelligent Transfer Service service failed to start
due to the following error: %%2

Error - 5/13/2009 9:00:21 PM | Computer Name = JOSE | Source = Service Control Manager | ID = 7000
Description = The Automatic Updates service failed to start due to the following
error: %%2


< End of report >

Oh and here's the log for RootRepeal:

ROOTREPEAL © AD, 2007-2008
==================================================
Scan Time: 2009/05/14 11:29
Program Version: Version 1.2.3.0
Windows Version: Windows XP SP2
==================================================

Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF3E25000 Size: 98304 File Visible: No
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7B23000 Size: 8192 File Visible: No
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB9739000 Size: 45056 File Visible: No
Status: -

Name: senekascdpucbq.sys
Image Path: C:\WINDOWS\system32\drivers\senekascdpucbq.sys
Address: 0xF4076000 Size: 122880 File Visible: -
Status: Hidden from Windows API!

Hidden/Locked Files
——————-
Path: C:\Documents and Settings\willy\ntuser.dat.LOG
Status: Size mismatch (API: 32768, Raw: 16384)

Path: C:\WINDOWS\system32\senekalhyiginm.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\senekalog.dat
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\senekathopabwu.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\senekauhxrvite.dat
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\senekaxidqbpxn.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\senekaybhvvjhy.dat
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\senekaecylnosexf.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\drivers\seneka.sys
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\drivers\senekascdpucbq.sys
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\willy\Local Settings\Temp\etilqs_NeoAwqgZyD1C6RVcwGGK
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: C:\WINDOWS\system32\wbem\Logs\wbemess.log
Status: Size mismatch (API: 31120, Raw: 30392)

I guess that's all.
Hi sesema,

You are welcome, but we have a ways to go yet. :)

E:\dtA Downloads\OTListIt2.exe (OldTimer Tools)


Before we continue

The tools we use are meant to be downloaded and ran from the location specified in the instructions provided. This is for backup purposes. In the event we need to restore a file we may not be able to if they are in a different location or drive. Please move OTLISTIT.exe to your desktop

We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path, one at a time, into the "Suspicious files to scan" box on the top of the page:
  • Please ensure that the scan has completed and you have saved the results before submitting the next one.
  • Please make sure each is clearly identified
    C:\WINDOWS\system32\bitiiuz.dll
    C:\WINDOWS\system32\drivers\xeclrhpo.sys

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

There are several .png files in this folder C:\Documents and Settings\willy\My Documents vlcsnap-XXXX.png Are they yours?

Please post back with the VirScan results. One we have that information we can go forward.

Thanks
Hey there oldman960:

Thanks again by the way :D

Like you said, I scanned C:\WINDOWS\system32\bitiiuz.dll and C:\WINDOWS\system32\drivers\xeclrhpo.sys using VirSCAN.org FREE on-line scan service. Here's what I got:

bitiiuz.dll
VirSCAN.org Scanned Report :
Scanned time : 2009/05/14 21:06:17 (PHT)
Scanner results: 32% Scanner(12/38) found malware!
File Name : bitiiuz.dll
File Size : 102400 byte
File Type : PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bi
MD5 : 182e43b526adf16ebecd190d98ceabe2
SHA1 : b02da210e31c6625d2eca86b360245e4a51bab8f
Online report : http://virscan.org/report/0b9c3be16b0d3df9…09b534859d.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090514170141 2009-05-14 1.99 -
AhnLab V3 2009.05.14.02 2009.05.14 2009-05-14 0.69 -
AntiVir 8.2.0.166 7.1.3.202 2009-05-14 0.24 TR/Crypt.FKM.Gen
Antiy 2.0.18 20090514.2406876 2009-05-14 0.12 -
Arcavir 2009 200905141011 2009-05-14 0.07 -
Authentium 5.1.1 200905131722 2009-05-13 1.18 W32/Boaxxe.A.gen!Eldorado (Possible)
AVAST! 4.7.4 090513-0 2009-05-13 0.01 -
AVG 8.5.286 270.12.29/2114 2009-05-14 3.27 Win32/Cryptor
BitDefender 7.81008.2972063 7.25390 2009-05-14 2.79 Trojan.Boaxxe.P
CA (VET) 9.0.0.143 31.6.6504 2009-05-14 8.09 -
ClamAV 0.95 9356 2009-05-13 0.02 -
Comodo 3.8 1157 2009-05-08 0.73 -
CP Secure 1.1.0.715 2009.05.14 2009-05-14 9.01 -
Dr.Web 4.44.0.9170 2009.05.14 2009-05-14 4.61 -
F-Prot 4.4.4.56 20090513 2009-05-13 1.16 W32/Boaxxe.A.gen!Eldorado (generic, not disinfectable)
F-Secure 5.51.6100 2009.05.14.03 2009-05-14 8.69 -
Fortinet 2.81-3.117 10.388 2009-05-14 0.35 -
GData 19.5214/19.329 20090514 2009-05-14 4.08 -
ViRobot 20090513 2009.05.13 2009-05-13 0.41 -
Ikarus T3.1.01.49 2009.05.14.72717 2009-05-14 3.09 -
JiangMin 11.0.706 2009.05.13 2009-05-13 2.43 -
Kaspersky 5.5.10 2009.05.14 2009-05-14 0.06 -
KingSoft 2009.2.5.15 2009.5.14.18 2009-05-14 0.53 Win32.Troj.MorphineT.iv.102912
McAfee 5.3.00 5614 2009-05-13 2.89 Boaxxe
Microsoft 1.4602 2009.05.14 2009-05-14 4.62 Trojan:Win32/Boaxxe.F
mks_vir 2.01 2009.05.12 2009-05-12 3.34 -
Norman 6.01.05 6.01.00 2009-05-13 2.01 -
Panda 9.05.01 2009.05.13 2009-05-13 2.07 -
Trend Micro 8.700-1004 6.129.00 2009-05-14 0.04 -
Quick Heal 10.00 2009.05.14 2009-05-14 1.24 -
Rising 20.0 21.29.32.00 2009-05-14 0.88 Packer.Win32.Morphine.b
Sophos 2.86.0 4.41 2009-05-14 2.40 Mal/EncPk-CL
Sunbelt 5134 5134 2009-05-13 0.91 -
Symantec 1.3.0.24 20090513.003 2009-05-13 0.08 Suspicious.Vundo.2
nProtect 20090514.01 3674098 2009-05-14 5.55 Trojan.Boaxxe.P
The Hacker [removed] v00325 2009-05-13 0.64 -
VBA32 3.12.10.5 20090513.1549 2009-05-13 4.64 -
VirusBuster 4.5.11.10 10.105.25/1350489 2009-05-13 1.74 -


xeclrhpo.sys
VirSCAN.org Scanned Report :
Scanned time : 2009/05/14 21:14:48 (PHT)
Scanner results: 3% Scanner(1/38) found malware!
File Name : xeclrhpo.sys
File Size : 23424 byte
File Type : PE32 executable for MS Windows (native) Intel 80386 32-bit
MD5 : 9c59630075ec11a8085293988c604bf7
SHA1 : bf555f8cdd389c4b8a4464a51ae3585de3e168c4
Online report : http://virscan.org/report/4ea2f57cdeee8bfa…ea2fb56d61.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090514170141 2009-05-14 2.83 -
AhnLab V3 2009.05.14.02 2009.05.14 2009-05-14 0.69 -
AntiVir 8.2.0.166 7.1.3.204 2009-05-14 0.48 -
Antiy 2.0.18 20090514.2406876 2009-05-14 0.12 -
Arcavir 2009 200905141011 2009-05-14 0.03 -
Authentium 5.1.1 200905131722 2009-05-13 1.14 -
AVAST! 4.7.4 090513-0 2009-05-13 0.01 -
AVG 8.5.286 270.12.29/2114 2009-05-14 3.40 -
BitDefender 7.81008.2972662 7.25392 2009-05-14 2.79 -
CA (VET) 9.0.0.143 31.6.6504 2009-05-14 4.55 -
ClamAV 0.95 9356 2009-05-13 0.01 -
Comodo 3.8 1157 2009-05-08 1.65 -
CP Secure 1.1.0.715 2009.05.14 2009-05-14 9.04 -
Dr.Web 4.44.0.9170 2009.05.14 2009-05-14 4.56 -
F-Prot 4.4.4.56 20090513 2009-05-13 1.15 -
F-Secure 5.51.6100 2009.05.14.03 2009-05-14 5.48 -
Fortinet 2.81-3.117 10.388 2009-05-14 0.23 -
GData 19.5214/19.329 20090514 2009-05-14 4.22 -
ViRobot 20090513 2009.05.13 2009-05-13 0.45 -
Ikarus T3.1.01.49 2009.05.14.72718 2009-05-14 3.07 -
JiangMin 11.0.706 2009.05.13 2009-05-13 2.35 -
Kaspersky 5.5.10 2009.05.14 2009-05-14 0.08 -
KingSoft 2009.2.5.15 2009.5.14.18 2009-05-14 0.59 -
McAfee 5.3.00 5614 2009-05-13 2.91 -
Microsoft 1.4602 2009.05.14 2009-05-14 4.52 -
mks_vir 2.01 2009.05.12 2009-05-12 3.27 -
Norman 6.01.05 6.01.00 2009-05-13 4.01 -
Panda 9.05.01 2009.05.13 2009-05-13 1.71 -
Trend Micro 8.700-1004 6.129.00 2009-05-14 0.03 -
Quick Heal 10.00 2009.05.14 2009-05-14 1.86 Trojan.Agent.ATV
Rising 20.0 21.29.32.00 2009-05-14 1.06 -
Sophos 2.86.0 4.41 2009-05-14 2.33 -
Sunbelt 5134 5134 2009-05-13 1.06 -
Symantec 1.3.0.24 20090513.003 2009-05-13 0.24 -
nProtect 20090514.01 3674098 2009-05-14 5.65 -
The Hacker [removed] v00325 2009-05-13 0.70 -
VBA32 3.12.10.5 20090513.1549 2009-05-13 2.22 -
VirusBuster 4.5.11.10 10.105.25/1350489 2009-05-13 2.39 -

There are several .png files in this folder C:\Documents and Settings\willy\My Documents vlcsnap-XXXX.png Are they yours?


Yes. Those pictures are screenshots from Bleach episodes. It's okay if it needs to be deleted.

That's all.
Hi sesema,

The pictures are fine.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]

[external image: Posted Image]

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please post back with the combofix log and a new HJT log taken last.

Thanks
oldman960,

Explorer.exe doesn't restart recycle anymore! :D But it restarted while combofix is creating a log. Is that normal? o.o Well it only happened once anyway.

Here are the logs you requested:

ComboFix
ComboFix 09-05-14.03 - willy 05/15/2009 9:17.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.700 [GMT 8:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
FW: Trend Micro OfficeScan Enterprise Client Firewall *enabled* {65B74F4A-006B-4EF3-80F2-72F34F3B91AE}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\willy\Application Data\inst.exe
c:\documents and settings\willy\Local Settings\Temporary Internet Files\ijjistarter_verinfo.dat
c:\windows\IE4 Error Log.txt
c:\windows\system32\byXQIXQJ.dll
c:\windows\system32\ddcBRHXp.dll
c:\windows\system32\drivers\seneka.sys
c:\windows\system32\drivers\senekascdpucbq.sys
c:\windows\system32\JQXIQXyb.ini
c:\windows\system32\JQXIQXyb.ini2
c:\windows\system32\senekaigftymov.db
c:\windows\system32\senekalhyiginm.dll
c:\windows\system32\senekalog.dat
c:\windows\system32\senekathopabwu.dll
c:\windows\system32\senekauhxrvite.dat
c:\windows\system32\senekaxidqbpxn.dll
c:\windows\system32\senekaybhvvjhy.dat
c:\windows\Tasks\At1.job
c:\windows\TEMP\PUF539.EXE
c:\windows\system32\bitiiuz.dll . . . . failed to delete

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SENEKA
——-\Legacy_EAPQOLNZ
——-\Service_eapqolnz


((((((((((((((((((((((((( Files Created from 2009-04-15 to 2009-05-15 )))))))))))))))))))))))))))))))
.

2009-05-14 00:33 . 2009-05-14 01:01 107888 —-a-w c:\windows\system32\CmdLineExt.dll
2009-05-10 18:03 . 2009-05-10 18:03 ——– d—–w c:\documents and settings\willy\Application Data\com.Multiply.AutoUploader.C7DF09F73C2059D294831784007C5F0856677385.1
2009-05-10 18:03 . 2009-05-10 18:03 ——– d—–w c:\program files\Common Files\Adobe AIR
2009-05-08 20:09 . 2009-05-08 20:09 ——– d—–w c:\program files\Gravity
2009-05-06 09:55 . 2006-02-19 08:48 88560 —-a-r c:\windows\system32\drivers\W700mgmt.sys
2009-05-06 09:55 . 2006-02-19 08:48 86368 —-a-r c:\windows\system32\drivers\W700obex.sys
2009-05-06 09:55 . 2006-02-19 08:47 9264 —-a-r c:\windows\system32\drivers\W700mdfl.sys
2009-05-06 09:55 . 2006-02-19 08:47 6208 —-a-r c:\windows\system32\drivers\W700cm.sys
2009-05-06 09:55 . 2006-02-19 08:47 6208 —-a-r c:\windows\system32\drivers\W700cmnt.sys
2009-05-06 09:55 . 2006-02-19 08:47 97056 —-a-r c:\windows\system32\drivers\W700mdm.sys
2009-05-06 09:55 . 2006-02-19 08:48 5840 —-a-r c:\windows\system32\drivers\W700whnt.sys
2009-05-06 09:55 . 2006-02-19 08:48 5840 —-a-r c:\windows\system32\drivers\W700wh.sys
2009-05-06 09:55 . 2006-02-19 08:47 61536 —-a-r c:\windows\system32\drivers\W700bus.sys
2009-05-06 00:06 . 2009-05-06 00:06 204800 —-a-w c:\windows\system32\inst_e82.exe
2009-05-04 11:10 . 2009-05-04 11:10 ——– d—–w c:\program files\Common Files\Adobe
2009-04-23 22:14 . 2009-04-27 22:35 191488 —-a-w c:\windows\system32\wingo.exe
2009-04-23 13:21 . 2009-04-24 11:09 ——– d—–w c:\documents and settings\willy\Local Settings\Application Data\Ahead
2009-04-23 13:14 . 2009-04-26 05:02 ——– d—–w c:\documents and settings\willy\Application Data\Ahead
2009-04-23 13:12 . 2009-04-23 13:12 ——– d—–w c:\program files\Common Files\Ahead
2009-04-23 13:12 . 2009-04-23 13:12 ——– d—–w c:\program files\Nero
2009-04-22 23:32 . 2009-04-22 23:32 14336 —-a-w c:\windows\system32\drivers\PN31Snoop.sys
2009-04-21 22:18 . 2009-04-22 00:06 664 —-a-w c:\windows\system32\d3d9caps.dat
2009-04-21 22:17 . 2009-04-21 22:17 102224 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-21 22:16 . 2009-04-21 22:16 ——– d—–w c:\documents and settings\Administrator\Application Data\TuneUp Software
2009-04-21 21:22 . 2009-04-22 00:07 ——– d—–w c:\windows\system32\kktools
2009-04-20 07:21 . 2009-05-04 01:55 ——– d—–w c:\program files\The Holy Bible
2009-04-20 07:16 . 1997-01-15 17:00 29696 —-a-w c:\windows\system32\VB5StKit.dll
2009-04-20 07:16 . 1997-01-15 17:00 71680 —-a-w c:\windows\ST5UNST.EXE
2009-04-18 00:48 . 2009-04-20 00:52 ——– d—–w C:\Downloads
2009-04-17 22:10 . 2009-04-17 23:40 0 —-a-w c:\windows\system32\drivers\2cb8e0ee.sys
2009-04-16 13:18 . 2009-04-16 13:18 ——– d—–w c:\documents and settings\willy\Application Data\vlc
2009-04-15 09:09 . 2009-04-15 09:09 ——– d—–w c:\documents and settings\willy\Application Data\esnbentp
2009-04-15 09:09 . 2009-04-15 09:09 ——– d—–w c:\documents and settings\willy\Local Settings\Application Data\esnbentp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-15 01:19 . 2002-08-29 12:00 102400 —-a-w c:\windows\system32\dtsjjpb.dll
2009-05-14 06:12 . 2008-12-30 15:49 ——– d—–w c:\program files\Left 4 Dead
2009-05-12 13:24 . 2008-12-25 03:23 ——– d—–w c:\program files\Warcraft III
2009-05-11 14:12 . 2008-12-19 10:53 110056 —-a-w c:\documents and settings\willy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-11 11:04 . 2009-04-10 00:43 ——– d—–w c:\program files\Amazing CD & DVD Burner
2009-05-11 11:03 . 2009-04-10 00:38 47360 —-a-w c:\documents and settings\willy\Application Data\pcouffin.sys
2009-04-29 14:42 . 2009-03-22 12:34 ——– d—–w c:\program files\Sound Forge
2009-04-23 21:59 . 2009-04-09 04:20 155 —-a-w c:\windows\system32\SelfDel.bat
2009-04-18 00:51 . 2009-03-18 03:25 ——– d—–w c:\program files\TuneUp Utilities 2009
2009-04-16 23:29 . 2008-12-25 17:14 ——– d—–w c:\program files\Sony Ericsson
2009-04-16 23:29 . 2008-12-11 04:04 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-15 13:05 . 2009-04-14 06:13 65536 —-a-w c:\windows\IFinst27.exe
2009-04-14 18:08 . 2009-04-03 16:11 0 —-a-w c:\windows\system32\drivers\2a0dcc1b.sys
2009-04-11 23:25 . 2009-03-07 01:15 74776 —ha-w c:\windows\system32\mlfcache.dat
2009-04-10 00:38 . 2009-04-10 00:38 47360 —-a-w c:\windows\system32\drivers\pcouffin.sys
2009-04-09 13:11 . 2008-12-20 15:56 ——– d—–w c:\program files\Kodak
2009-04-09 07:19 . 2009-01-16 13:17 ——– d—–w c:\program files\Ulead Systems
2009-04-09 07:17 . 2008-12-11 04:04 ——– d—–w c:\program files\Common Files\InstallShield
2009-03-30 02:55 . 2009-03-30 02:55 0 —ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-03-30 02:55 . 2009-03-30 02:55 0 —ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-03-30 02:53 . 2009-03-30 02:53 ——– d—–w c:\program files\Common Files\PCSuite
2009-03-30 02:53 . 2009-03-30 02:53 ——– d—–w c:\program files\Common Files\Nokia
2009-03-30 02:53 . 2009-03-30 02:53 ——– d—–w c:\program files\DIFX
2009-03-30 02:53 . 2009-03-30 02:53 ——– d—–w c:\program files\PC Connectivity Solution
2009-03-26 21:13 . 2009-03-18 00:59 ——– d—–w c:\program files\Java
2009-03-25 06:48 . 2008-12-21 08:07 121015 —-a-w c:\windows\War3Unin.dat
2009-03-22 12:22 . 2009-03-22 12:22 ——– d—–w c:\program files\AviSynth 2.5
2009-03-18 03:25 . 2009-03-18 03:25 603904 —-a-w c:\windows\system32\TUProgSt.exe
2009-03-18 03:25 . 2009-03-18 03:25 360192 —-a-w c:\windows\system32\TuneUpDefragService.exe
2009-03-17 08:30 . 2009-03-06 15:57 ——– d—–w c:\program files\ViStart
2009-03-17 08:30 . 2009-03-06 16:02 ——– d—–w c:\program files\ViOrb
2009-03-17 08:30 . 2009-03-06 16:08 ——– d—–w c:\program files\ViSplore
2009-03-17 08:30 . 2009-01-21 10:51 ——– d—–w c:\program files\Sony
2009-03-11 02:13 . 2009-03-11 02:13 0 —-a-w c:\windows\system32\cid_store.dat
2009-03-08 21:19 . 2008-12-19 15:12 410984 -c–a-w c:\windows\system32\deploytk.dll
2009-02-22 23:24 . 2009-02-22 23:24 2131 —-a-w c:\windows\system32\unins000.dat
2009-02-22 23:23 . 2009-02-22 23:24 728858 —-a-w c:\windows\system32\unins000.exe
2006-05-03 10:06 . 2009-03-22 12:22 163328 –sha-r c:\windows\system32\flvDX.dll
2007-02-21 11:47 . 2009-03-22 12:22 31232 –sha-r c:\windows\system32\msfDX.dll
2008-03-16 13:30 . 2009-03-22 12:22 216064 –sha-r c:\windows\system32\nbDX.dll
.

——- Sigcheck ——-

[-] 2006-05-04 09:28 1580544 49E741CF0DE7C469155E6F2136813D46 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{993A2DC4-1E2F-43DC-9B01-9AA1C4358DC3}]
2002-08-29 12:00 102400 —-a-w c:\windows\system32\bitiiuz.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-03 1667584]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"PC Suite Tray"="e:\nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-08 94208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeScanNT Monitor"="c:\program files\Trend Micro\OfficeScan Client\pccntmon.exe" [2007-10-02 356429]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-09 13680640]
"TV Card Remote Control Device Monitor"="c:\windows\713xRMTMon.exe" [2005-07-20 352256]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-09 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-08 148888]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-12-17 16062464]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-15 2879488]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-02-09 1657376]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-03 110592]

c:\documents and settings\willy\Start Menu\Programs\Startup\
Multiply AutoUploader.lnk - e:\multiply\AutoUploader\Multiply AutoUploader\Multiply AutoUploader.exe [2009-5-11 95744]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 0 (0x0)
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
"AdVantage"=c:\documents and settings\willy\Application Data\advantage\AdVantage.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\IEPro\\MiniDM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\dtA Downloads\\utorrent.exe"=
"c:\\Documents and Settings\\willy\\Desktop\\Garena files\\utorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24389:TCP"= 24389:TCP:BitComet 24389 TCP
"24389:UDP"= 24389:UDP:BitComet 24389 UDP

R0 xeclrhpo;xeclrhpo;c:\windows\system32\drivers\xeclrhpo.sys [8/29/2002 8:00 PM 23424]
R1 vcdrom;Virtual CD-ROM Device Driver;c:\windows\system32\drivers\VCdRom.sys [12/19/2001 11:45 AM 8576]
R2 713xTVCard;SAA7130 TV Card;c:\windows\system32\drivers\SAA713x.sys [1/28/2009 9:46 PM 289280]
R2 TmFilter;Trend Micro Filter;c:\program files\Trend Micro\OfficeScan Client\tmxpflt.sys [8/16/2008 3:00 AM 225296]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\Trend Micro\OfficeScan Client\tmpreflt.sys [8/16/2008 3:00 AM 36368]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [3/18/2009 11:25 AM 603904]
R2 WDMTVTuner;Universal WDM TV Tuner;c:\windows\system32\drivers\WDMTuner.sys [1/28/2009 9:46 PM 26880]
R3 AtcL002;NDIS Miniport Driver for Attansic L2 Fast Ethernet Controller;c:\windows\system32\drivers\atl02_xp.sys [12/11/2008 12:00 PM 28416]
S1 2a0dcc1b;2a0dcc1b;c:\windows\system32\drivers\2a0dcc1b.sys [4/4/2009 12:11 AM 0]
S1 2cb8e0ee;2cb8e0ee;c:\windows\system32\drivers\2cb8e0ee.sys [4/18/2009 6:10 AM 0]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\willy\LOCALS~1\Temp\YJV593.tmp –> c:\docume~1\willy\LOCALS~1\Temp\YJV593.tmp [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 w200bus;Sony Ericsson W200 driver (WDM);c:\windows\system32\drivers\w200bus.sys [12/26/2008 1:23 AM 61504]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;c:\windows\system32\drivers\w200mdfl.sys [12/26/2008 1:23 AM 9328]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;c:\windows\system32\drivers\w200mdm.sys [12/26/2008 1:23 AM 97056]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w200mgmt.sys [12/26/2008 1:23 AM 88560]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;c:\windows\system32\drivers\w200obex.sys [12/26/2008 1:23 AM 86368]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6656a2cc-c739-11dd-9f8c-001bfc727f38}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe DEADLY-c.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{943a7e6e-f30d-11dd-a0c0-001bfc727f38}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL win32usbservice.exe
.
Contents of the 'Scheduled Tasks' folder

2009-05-15 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 13:36]

2009-04-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 04:34]
.
- - - - ORPHANS REMOVED - - - -

BHO-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - c:\windows\system32\ddcBRHXp.dll
BHO-{74EF7B82-FC1E-4D30-8403-08283C3C46AC} - c:\windows\system32\byXQIXQJ.dll
ShellExecuteHooks-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - c:\windows\system32\ddcBRHXp.dll


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ph.yahoo.com/
mStart Page = hxxp://ph.yahoo.com/
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://aa.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://ph.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Post Image to Blog - c:\program files\ImageShackToolbar\ImageShackToolbar.dll/5003
IE: Tag This Image - c:\program files\ImageShackToolbar\ImageShackToolbar.dll/5002
IE: Transload Image to ImageShack - c:\program files\ImageShackToolbar\ImageShackToolbar.dll/5004
IE: Upload All Images to ImageShack - c:\program files\ImageShackToolbar\ImageShackToolbar.dll/5000
IE: Upload Image to ImageShack - c:\program files\ImageShackToolbar\ImageShackToolbar.dll/5001
IE: {{000002a3-84fe-43f1-b958-f2c3ca804f1a} - {CD275D4E-791A-4993-9D4D-6A071EDD2709} - c:\program files\IEPro\iepro.dll
FF - ProfilePath - c:\documents and settings\willy\Application Data\Mozilla\Firefox\Profiles\77jcme81.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\documents and settings\willy\Application Data\Mozilla\Firefox\Profiles\77jcme81.default\extensions\{7378B8C2-FC38-41b8-A8C9-875D1F5B0A24}\components\NativeComponent.dll
FF - component: c:\documents and settings\willy\Application Data\Mozilla\Firefox\Profiles\77jcme81.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: e:\nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: e:\real alternative\browser\plugins\nppl3260.dll
FF - plugin: e:\real alternative\browser\plugins\nprpjplug.dll
FF - plugin: e:\vlc\npvlc.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-15 09:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
TV Card Remote Control Device Monitor = c:\windows\713xRMTMon.exe???????????????C?a??B??a?r?a???????????????????????????????x???????????????????????????????????x????????B??????????C?a?x???a?r?a??????????????|?B??????????????????????????????????????????????????????x???????C?a?n?d?a?r???????????A????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\willy\LOCALS~1\Temp\YJV593.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1844237615-1958367476-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(368)
c:\windows\system32\nview.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
e:\nokia\Nokia PC Suite 7\PhoneBrowser.dll
e:\nokia\Nokia PC Suite 7\NGSCM.DLL
e:\nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr
e:\nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\EPSON\EBAPI\SAgent2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Trend Micro\OfficeScan Client\NTRtScan.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Trend Micro\OfficeScan Client\TmListen.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
c:\windows\Temp\TFDAC1.EXE
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\windows\713xRMT.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
.
**************************************************************************
.
Completion time: 2009-05-15 9:27 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-15 01:27

Pre-Run: 2,052,243,456 bytes free
Post-Run: 2,060,972,032 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptOut

Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
299


HijackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:28:29 AM, on 5/15/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINDOWS\TEMP\TFDAC1.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\713xRMTMon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\713xRMT.exe
E:\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
E:\Multiply\AutoUploader\Multiply AutoUploader\Multiply AutoUploader.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
E:\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntupd.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ph.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ph.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://aa.rd.yahoo.com/customize/ie/defaul…://ph.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: IE7Pro BHO - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {993A2DC4-1E2F-43DC-9B01-9AA1C4358DC3} - c:\windows\system32\bitiiuz.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TV Card Remote Control Device Monitor] C:\WINDOWS\713xRMTMon.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PC Suite Tray] "E:\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Startup: Multiply AutoUploader.lnk = E:\Multiply\AutoUploader\Multiply AutoUploader\Multiply AutoUploader.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Post Image to Blog - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1240363149828
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

–
End of file - 9427 bytes

Thank you so much, oldman960 :)
Hi sesema,

There are signs of an autorun infection involving removable USB storage devices. Please do not connect any of these devices to your computer until we have cleaned them. What devices do you have?


One more file to check at VirScan Please have this file analysed like you did before.

c:\windows\system32\wingo.exe



Open hijackthis, do a system scan only and checkmark these lines, if present

O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
O2 - BHO: (no name) - {993A2DC4-1E2F-43DC-9B01-9AA1C4358DC3} - c:\windows\system32\bitiiuz.dll
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.



We will be using Combofix again but will run it differently.

Please follow all previous instructions regarding security programs.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the script we will use, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the all of the text in the code box below into the Notepad, (including the URL). Do Not copy the word CODE

http://forums.whatthetech.com/Explorer_exe_problem_t103043.html&pid=558743#entry558743

KillAll::

Collect::[4]
c:\windows\system32\drivers\2cb8e0ee.sys
c:\windows\system32\dtsjjpb.dll
c:\windows\system32\drivers\2a0dcc1b.sys
c:\windows\system32\mlfcache.dat
c:\windows\system32\bitiiuz.dll
c:\windows\system32\drivers\xeclrhpo.sys 

DirLook::
c:\documents and settings\willy\Application Data\esnbentp

RegLock::
[HKEY_USERS\S-1-5-21-1844237615-1958367476-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6656a2cc-c739-11dd-9f8c-001bfc727f38}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{943a7e6e-f30d-11dd-a0c0-001bfc727f38}]

Driver::
xeclrhpo
2a0dcc1b
2cb8e0ee
senekascdpucbq

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again. Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

Please post back with
  • VirScan results
  • combofix log
  • new HJT log
How's the computer now?

Thanks
Sorry for replying so late, I was out for 3 days.

Cellphones connected through USB, USB Flash Disks, Bluetooth USB, Card Reader, Printer.

VirScan results
VirSCAN.org Scanned Report :
Scanned time : 2009/05/17 14:32:13 (PHT)
Scanner results: 71% Scanner(27/38) found malware!
File Name : wingo.exe
File Size : 191488 byte
File Type : PE32 executable for MS Windows (console) Intel 80386 32-bit
MD5 : 0ef9d3c2689c01f2a7082224eda87d7a
SHA1 : 287971dfdbea1119c930aee12b8b558a7bd5d46e
Online report : http://virscan.org/report/c4381720e66819a2…e72e7e9d81.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090516190230 2009-05-16 2.06 Trojan-Dropper.Win32.BHO!IK
AhnLab V3 2009.05.17.00 2009.05.17 2009-05-17 0.70 -
AntiVir 8.2.0.168 7.1.3.215 2009-05-15 0.43 TR/Boaxxe.R
Antiy 2.0.18 20090516.2420010 2009-05-16 0.12 -
Arcavir 2009 200905160757 2009-05-16 0.20 Trojan.Dropper.Bho.Bj
Authentium 5.1.1 200905161041 2009-05-16 1.69 -
AVAST! 4.7.4 090516-0 2009-05-16 0.01 Win32:BHO-XF [Trj]
AVG 8.5.286 270.12.32/2118 2009-05-17 3.63 Dropper.Generic.ANKQ
BitDefender 7.81008.2986880 7.25453 2009-05-17 2.79 Gen:Trojan.Heur.B084E57474
CA (VET) 9.0.0.143 31.6.6507 2009-05-16 5.78 Win32/Vundo.CUE trojan.
ClamAV 0.95 9364 2009-05-16 0.09 -
Comodo 3.9 1167 2009-05-16 0.69 TrojWare.Win32.TrojanDropper.BHO.~GD
CP Secure 1.1.0.715 2009.05.17 2009-05-17 9.09 Troj.Dropper.W32.BHO.bj
Dr.Web 4.44.0.9170 2009.05.17 2009-05-17 4.55 Trojan.Click.25877
F-Prot 4.4.4.56 20090516 2009-05-16 1.61 -
F-Secure 5.51.6100 2009.05.16.01 2009-05-16 0.03 Trojan:W32/Boaxxe.F [Orion]
Fortinet 2.81-3.117 10.397 2009-05-16 0.19 W32/BHO.BJ!tr
GData 19.5261/19.333 20090517 2009-05-17 4.41 Trojan-Dropper.Win32.BHO.bj [Engine:A]
ViRobot 20090515 2009.05.15 2009-05-15 0.41 -
Ikarus T3.1.01.49 2009.05.16.72728 2009-05-16 3.10 Trojan-Dropper.Win32.BHO
JiangMin 11.0.706 2009.05.17 2009-05-17 2.16 Trojan/Ck88866.Gen
Kaspersky 5.5.10 2009.05.17 2009-05-17 0.06 Trojan-Dropper.Win32.BHO.bj
KingSoft 2009.2.5.15 2009.5.16.21 2009-05-16 0.53 Win32.VirInstaller.BHO.bj.270336
McAfee 5.3.00 5617 2009-05-16 2.88 Generic Dropper!n
Microsoft 1.4602 2009.05.16 2009-05-16 7.43 Trojan:Win32/Boaxxe.E
mks_vir 2.01 2009.05.16 2009-05-16 3.39 -
Norman 6.01.05 6.01.00 2009-05-15 4.01 -
Panda 9.05.01 2009.05.16 2009-05-16 1.92 Adware/WebSearch
Trend Micro 8.700-1004 6.134.13 2009-05-16 0.06 -
Quick Heal 10.00 2009.05.15 2009-05-15 1.20 TrojanDropper.BHO.bj
Rising 20.0 21.29.60.00 2009-05-17 1.05 -
Sophos 2.86.0 4.41 2009-05-17 2.37 -
Sunbelt 5139 5139 2009-05-16 0.81 Trojan-Win32/Boaxxe.E
Symantec 1.3.0.24 20090516.003 2009-05-16 0.07 Trojan.Vundo
nProtect 20090517.01 3708563 2009-05-17 5.65 Trojan-Dropper/W32.BHO.191488
The Hacker 6.3.4.1 v00326 2009-05-16 0.61 Trojan/Dropper.BHO.bj
VBA32 3.12.10.5 20090516.1854 2009-05-16 1.89 Trojan-Dropper.Win32.BHO.bj
VirusBuster 4.5.11.10 10.105.28/1378347 2009-05-16 1.68 Trojan.DR.BHO.TYN

combofix log
ComboFix 09-05-16.05 - willy 05/17/2009 14:30.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.562 [GMT 8:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\willy\Desktop\CFScript.txt
FW: Trend Micro OfficeScan Enterprise Client Firewall *enabled* {65B74F4A-006B-4EF3-80F2-72F34F3B91AE}

file zipped: c:\windows\system32\bitiiuz.dll
file zipped: c:\windows\system32\drivers\2a0dcc1b.sys
file zipped: c:\windows\system32\drivers\2cb8e0ee.sys
file zipped: c:\windows\system32\drivers\xeclrhpo.sys
file zipped: c:\windows\system32\dtsjjpb.dll
file zipped: c:\windows\system32\mlfcache.dat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\bitiiuz.dll
c:\windows\system32\drivers\2a0dcc1b.sys
c:\windows\system32\drivers\2cb8e0ee.sys
c:\windows\system32\drivers\xeclrhpo.sys
c:\windows\system32\dtsjjpb.dll
c:\windows\system32\mlfcache.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_XECLRHPO
——-\Service_2a0dcc1b
——-\Service_2cb8e0ee
——-\Service_xeclrhpo


((((((((((((((((((((((((( Files Created from 2009-04-17 to 2009-05-17 )))))))))))))))))))))))))))))))
.

2009-05-14 00:33 . 2009-05-14 01:01 107888 —-a-w c:\windows\system32\CmdLineExt.dll
2009-05-10 18:03 . 2009-05-10 18:03 ——– d—–w c:\documents and settings\willy\Application Data\com.Multiply.AutoUploader.C7DF09F73C2059D294831784007C5F0856677385.1
2009-05-10 18:03 . 2009-05-10 18:03 ——– d—–w c:\program files\Common Files\Adobe AIR
2009-05-06 09:55 . 2006-02-19 08:48 88560 —-a-r c:\windows\system32\drivers\W700mgmt.sys
2009-05-06 09:55 . 2006-02-19 08:48 86368 —-a-r c:\windows\system32\drivers\W700obex.sys
2009-05-06 09:55 . 2006-02-19 08:47 9264 —-a-r c:\windows\system32\drivers\W700mdfl.sys
2009-05-06 09:55 . 2006-02-19 08:47 6208 —-a-r c:\windows\system32\drivers\W700cm.sys
2009-05-06 09:55 . 2006-02-19 08:47 6208 —-a-r c:\windows\system32\drivers\W700cmnt.sys
2009-05-06 09:55 . 2006-02-19 08:47 97056 —-a-r c:\windows\system32\drivers\W700mdm.sys
2009-05-06 09:55 . 2006-02-19 08:48 5840 —-a-r c:\windows\system32\drivers\W700whnt.sys
2009-05-06 09:55 . 2006-02-19 08:48 5840 —-a-r c:\windows\system32\drivers\W700wh.sys
2009-05-06 09:55 . 2006-02-19 08:47 61536 —-a-r c:\windows\system32\drivers\W700bus.sys
2009-05-06 00:06 . 2009-05-06 00:06 204800 —-a-w c:\windows\system32\inst_e82.exe
2009-05-04 11:10 . 2009-05-04 11:10 ——– d—–w c:\program files\Common Files\Adobe
2009-04-23 22:14 . 2009-04-27 22:35 191488 —-a-w c:\windows\system32\wingo.exe
2009-04-23 13:21 . 2009-04-24 11:09 ——– d—–w c:\documents and settings\willy\Local Settings\Application Data\Ahead
2009-04-23 13:14 . 2009-04-26 05:02 ——– d—–w c:\documents and settings\willy\Application Data\Ahead
2009-04-23 13:12 . 2009-04-23 13:12 ——– d—–w c:\program files\Common Files\Ahead
2009-04-23 13:12 . 2009-04-23 13:12 ——– d—–w c:\program files\Nero
2009-04-22 23:32 . 2009-04-22 23:32 14336 —-a-w c:\windows\system32\drivers\PN31Snoop.sys
2009-04-21 22:18 . 2009-04-22 00:06 664 —-a-w c:\windows\system32\d3d9caps.dat
2009-04-21 22:17 . 2009-04-21 22:17 102224 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-21 22:16 . 2009-04-21 22:16 ——– d—–w c:\documents and settings\Administrator\Application Data\TuneUp Software
2009-04-21 21:22 . 2009-04-22 00:07 ——– d—–w c:\windows\system32\kktools
2009-04-20 07:21 . 2009-05-04 01:55 ——– d—–w c:\program files\The Holy Bible
2009-04-20 07:16 . 1997-01-15 17:00 29696 —-a-w c:\windows\system32\VB5StKit.dll
2009-04-20 07:16 . 1997-01-15 17:00 71680 —-a-w c:\windows\ST5UNST.EXE
2009-04-18 00:48 . 2009-04-20 00:52 ——– d—–w C:\Downloads

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-17 06:30 . 2002-08-29 12:00 23424 —-a-w c:\windows\system32\drivers\vppmnuhc.sys
2009-05-14 06:12 . 2008-12-30 15:49 ——– d—–w c:\program files\Left 4 Dead
2009-05-12 13:24 . 2008-12-25 03:23 ——– d—–w c:\program files\Warcraft III
2009-05-11 14:12 . 2008-12-19 10:53 110056 —-a-w c:\documents and settings\willy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-11 11:04 . 2009-04-10 00:43 ——– d—–w c:\program files\Amazing CD & DVD Burner
2009-05-11 11:03 . 2009-04-10 00:38 47360 —-a-w c:\documents and settings\willy\Application Data\pcouffin.sys
2009-04-29 14:42 . 2009-03-22 12:34 ——– d—–w c:\program files\Sound Forge
2009-04-23 21:59 . 2009-04-09 04:20 155 —-a-w c:\windows\system32\SelfDel.bat
2009-04-18 00:51 . 2009-03-18 03:25 ——– d—–w c:\program files\TuneUp Utilities 2009
2009-04-16 23:29 . 2008-12-25 17:14 ——– d—–w c:\program files\Sony Ericsson
2009-04-16 23:29 . 2008-12-11 04:04 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-15 13:05 . 2009-04-14 06:13 65536 —-a-w c:\windows\IFinst27.exe
2009-04-10 00:38 . 2009-04-10 00:38 47360 —-a-w c:\windows\system32\drivers\pcouffin.sys
2009-04-09 13:11 . 2008-12-20 15:56 ——– d—–w c:\program files\Kodak
2009-04-09 07:19 . 2009-01-16 13:17 ——– d—–w c:\program files\Ulead Systems
2009-04-09 07:17 . 2008-12-11 04:04 ——– d—–w c:\program files\Common Files\InstallShield
2009-03-30 02:55 . 2009-03-30 02:55 0 —ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-03-30 02:55 . 2009-03-30 02:55 0 —ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-03-30 02:53 . 2009-03-30 02:53 ——– d—–w c:\program files\Common Files\PCSuite
2009-03-30 02:53 . 2009-03-30 02:53 ——– d—–w c:\program files\Common Files\Nokia
2009-03-30 02:53 . 2009-03-30 02:53 ——– d—–w c:\program files\DIFX
2009-03-30 02:53 . 2009-03-30 02:53 ——– d—–w c:\program files\PC Connectivity Solution
2009-03-26 21:13 . 2009-03-18 00:59 ——– d—–w c:\program files\Java
2009-03-25 06:48 . 2008-12-21 08:07 121015 —-a-w c:\windows\War3Unin.dat
2009-03-22 12:22 . 2009-03-22 12:22 ——– d—–w c:\program files\AviSynth 2.5
2009-03-18 03:25 . 2009-03-18 03:25 603904 —-a-w c:\windows\system32\TUProgSt.exe
2009-03-18 03:25 . 2009-03-18 03:25 360192 —-a-w c:\windows\system32\TuneUpDefragService.exe
2009-03-11 02:13 . 2009-03-11 02:13 0 —-a-w c:\windows\system32\cid_store.dat
2009-03-08 21:19 . 2008-12-19 15:12 410984 -c–a-w c:\windows\system32\deploytk.dll
2009-02-22 23:24 . 2009-02-22 23:24 2131 —-a-w c:\windows\system32\unins000.dat
2009-02-22 23:23 . 2009-02-22 23:24 728858 —-a-w c:\windows\system32\unins000.exe
2006-05-03 10:06 . 2009-03-22 12:22 163328 –sha-r c:\windows\system32\flvDX.dll
2007-02-21 11:47 . 2009-03-22 12:22 31232 –sha-r c:\windows\system32\msfDX.dll
2008-03-16 13:30 . 2009-03-22 12:22 216064 –sha-r c:\windows\system32\nbDX.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\documents and settings\willy\Application Data\esnbentp —-

2009-04-15 10:39 . 2009-04-15 10:39 367 —-a-w c:\documents and settings\willy\Application Data\esnbentp\Profiles\3fd6uo51.default\prefs.js
2009-04-15 09:09 . 2009-04-15 09:09 569 —-a-w c:\documents and settings\willy\Application Data\esnbentp\Profiles\3fd6uo51.default\localstore.rdf
2009-04-15 09:09 . 2009-04-15 09:09 5518 —-a-w c:\documents and settings\willy\Application Data\esnbentp\Profiles\3fd6uo51.default\pluginreg.dat
2009-04-15 09:09 . 2009-04-15 10:39 2048 —-a-w c:\documents and settings\willy\Application Data\esnbentp\Profiles\3fd6uo51.default\webappsstore.sqlite
2009-04-15 09:09 . 2009-04-15 09:09 4096 —-a-w c:\documents and settings\willy\Application Data\esnbentp\Profiles\3fd6uo51.default\formhistory.sqlite
2009-04-15 09:09 . 2009-04-15 10:39 131072 —-a-w c:\documents and settings\willy\Application Data\esnbentp\Profiles\3fd6uo51.default\places.sqlite
2009-04-15 09:09 . 2009-04-15 10:39 0 —-a-w c:\documents and settings\willy\Application Data\esnbentp\Profiles\3fd6uo51.default\places.sqlite-journal
2009-04-15 09:09 . 2009-04-15 09:09 16384 —-a-w c:\documents and settings\willy\Application Data\esnbentp\Profiles\3fd6uo51.default\key3.db
2009-04-15 09:09 . 2009-04-15 09:10 65536 —-a-w c:\documents and settings\willy\Application Data\esnbentp\Profiles\3fd6uo51.default\cert8.db
2009-04-15 09:09 . 2009-04-15 09:09 16384 —-a-w c:\documents and settings\willy\Application Data\esnbentp\Profiles\3fd6uo51.default\secmod.db
2009-04-15 09:09 . 2009-04-15 10:59 2048 —-a-w c:\documents and settings\willy\Application Data\esnbentp\Profiles\3fd6uo51.default\cookies.sqlite
2009-04-15 09:09 . 2009-04-15 09:09 2048 —-a-w c:\documents and settings\willy\Application Data\esnbentp\Profiles\3fd6uo51.default\permissions.sqlite
2009-04-15 09:09 . 2009-04-15 10:39 127885 —-a-w c:\documents and settings\willy\Application Data\esnbentp\Profiles\3fd6uo51.default\compreg.dat
2009-04-15 09:09 . 2009-04-15 09:09 111 —-a-w c:\documents and settings\willy\Application Data\esnbentp\profiles.ini
2009-04-15 09:09 . 2009-04-15 10:39 207 —-a-w c:\documents and settings\willy\Application Data\esnbentp\Profiles\3fd6uo51.default\compatibility.ini
2009-04-15 09:09 . 2009-04-15 10:39 96173 —-a-w c:\documents and settings\willy\Application Data\esnbentp\Profiles\3fd6uo51.default\xpti.dat


——- Sigcheck ——-

[-] 2006-05-04 09:28 1580544 49E741CF0DE7C469155E6F2136813D46 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-05-15_01.25.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-17 06:34 . 2009-05-17 06:34 16384 c:\windows\temp\Perflib_Perfdata_c28.dat
+ 2009-05-17 06:32 . 2009-05-17 06:32 16384 c:\windows\temp\Perflib_Perfdata_714.dat
+ 2009-05-17 06:33 . 2007-10-02 03:29 176195 c:\windows\temp\ISBDAA.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-03 1667584]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"PC Suite Tray"="e:\nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-08 94208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeScanNT Monitor"="c:\program files\Trend Micro\OfficeScan Client\pccntmon.exe" [2007-10-02 356429]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-09 13680640]
"TV Card Remote Control Device Monitor"="c:\windows\713xRMTMon.exe" [2005-07-20 352256]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-09 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-08 148888]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-12-17 16062464]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-15 2879488]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-02-09 1657376]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-03 110592]

c:\documents and settings\willy\Start Menu\Programs\Startup\
Multiply AutoUploader.lnk - e:\multiply\AutoUploader\Multiply AutoUploader\Multiply AutoUploader.exe [2009-5-11 95744]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 0 (0x0)
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\IEPro\\MiniDM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\dtA Downloads\\utorrent.exe"=
"c:\\Documents and Settings\\willy\\Desktop\\Garena files\\utorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24389:TCP"= 24389:TCP:BitComet 24389 TCP
"24389:UDP"= 24389:UDP:BitComet 24389 UDP

R1 vcdrom;Virtual CD-ROM Device Driver;c:\windows\system32\drivers\VCdRom.sys [12/19/2001 11:45 AM 8576]
R2 713xTVCard;SAA7130 TV Card;c:\windows\system32\drivers\SAA713x.sys [1/28/2009 9:46 PM 289280]
R2 TmFilter;Trend Micro Filter;c:\program files\Trend Micro\OfficeScan Client\tmxpflt.sys [8/16/2008 3:00 AM 225296]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\Trend Micro\OfficeScan Client\tmpreflt.sys [8/16/2008 3:00 AM 36368]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [3/18/2009 11:25 AM 603904]
R2 WDMTVTuner;Universal WDM TV Tuner;c:\windows\system32\drivers\WDMTuner.sys [1/28/2009 9:46 PM 26880]
R3 AtcL002;NDIS Miniport Driver for Attansic L2 Fast Ethernet Controller;c:\windows\system32\drivers\atl02_xp.sys [12/11/2008 12:00 PM 28416]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\willy\LOCALS~1\Temp\YJV593.tmp –> c:\docume~1\willy\LOCALS~1\Temp\YJV593.tmp [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 w200bus;Sony Ericsson W200 driver (WDM);c:\windows\system32\drivers\w200bus.sys [12/26/2008 1:23 AM 61504]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;c:\windows\system32\drivers\w200mdfl.sys [12/26/2008 1:23 AM 9328]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;c:\windows\system32\drivers\w200mdm.sys [12/26/2008 1:23 AM 97056]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w200mgmt.sys [12/26/2008 1:23 AM 88560]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;c:\windows\system32\drivers\w200obex.sys [12/26/2008 1:23 AM 86368]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2009-05-17 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 13:36]

2009-04-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 04:34]
.
- - - - ORPHANS REMOVED - - - -

BHO-{993A2DC4-1E2F-43DC-9B01-9AA1C4358DC3} - c:\windows\system32\bitiiuz.dll


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ph.yahoo.com/
mStart Page = hxxp://ph.yahoo.com/
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://aa.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://ph.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Post Image to Blog - c:\program files\ImageShackToolbar\ImageShackToolbar.dll/5003
IE: Tag This Image - c:\program files\ImageShackToolbar\ImageShackToolbar.dll/5002
IE: Transload Image to ImageShack - c:\program files\ImageShackToolbar\ImageShackToolbar.dll/5004
IE: Upload All Images to ImageShack - c:\program files\ImageShackToolbar\ImageShackToolbar.dll/5000
IE: Upload Image to ImageShack - c:\program files\ImageShackToolbar\ImageShackToolbar.dll/5001
IE: {{000002a3-84fe-43f1-b958-f2c3ca804f1a} - {CD275D4E-791A-4993-9D4D-6A071EDD2709} - c:\program files\IEPro\iepro.dll
FF - ProfilePath - c:\documents and settings\willy\Application Data\Mozilla\Firefox\Profiles\77jcme81.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\documents and settings\willy\Application Data\Mozilla\Firefox\Profiles\77jcme81.default\extensions\{7378B8C2-FC38-41b8-A8C9-875D1F5B0A24}\components\NativeComponent.dll
FF - component: c:\documents and settings\willy\Application Data\Mozilla\Firefox\Profiles\77jcme81.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: e:\nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: e:\real alternative\browser\plugins\nppl3260.dll
FF - plugin: e:\real alternative\browser\plugins\nprpjplug.dll
FF - plugin: e:\vlc\npvlc.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-17 14:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
TV Card Remote Control Device Monitor = c:\windows\713xRMTMon.exe???????????????C?a??B??a?r?a???????????????????????????????x???????????????????????????????????x????????B??????????C?a?x???a?r?a??????????????|?B??????????????????????????????????????????????????????x???????C?a?n?d?a?r???????????A????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\willy\LOCALS~1\Temp\YJV593.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(1040)
c:\windows\system32\nview.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
e:\nokia\Nokia PC Suite 7\PhoneBrowser.dll
e:\nokia\Nokia PC Suite 7\NGSCM.DLL
e:\nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr
e:\nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\EPSON\EBAPI\SAgent2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Trend Micro\OfficeScan Client\NTRtScan.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Trend Micro\OfficeScan Client\TmListen.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\windows\713xRMT.exe
c:\windows\temp\ISBDAA.EXE
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
.
**************************************************************************
.
Completion time: 2009-05-17 14:36 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-17 06:36
ComboFix2.txt 2009-05-15 01:27

Pre-Run: 3,419,914,240 bytes free
Post-Run: 3,399,585,792 bytes free

Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
287

new HJT log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:45:15 PM, on 5/17/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\713xRMTMon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\713xRMT.exe
E:\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\WINDOWS\TEMP\ISBDAA.EXE
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
E:\Multiply\AutoUploader\Multiply AutoUploader\Multiply AutoUploader.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntupd.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ph.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ph.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://aa.rd.yahoo.com/customize/ie/defaul…://ph.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: IE7Pro BHO - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Windows Live Sign-in Helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TV Card Remote Control Device Monitor] C:\WINDOWS\713xRMTMon.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PC Suite Tray] "E:\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Startup: Multiply AutoUploader.lnk = E:\Multiply\AutoUploader\Multiply AutoUploader\Multiply AutoUploader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Post Image to Blog - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1240363149828
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

–
End of file - 9410 bytes

It's working fine now, but not when CF ran. Explorer.exe restarted a few times while CF is running. But it turned back to normal after running CF.
Hi sesema,

That may have been combofix stopping explorer as it was removing some services.

Let's get rid of that file then look at your USB devices.

Next, Double click on OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:OTLI
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)

:Services

:Reg

:Files
c:\windows\system32\wingo.exe

:Commands
[emptytemp]
[start explorer]
[reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.


Now for the USB

Extra note when using the utility: -Hold the shift key down while inserting the USB device. This will prevent it from autoruning.
-Repeat the procedure for each device you have that is capable of storing data. The printer is OK.
-Make sure that you run the utility with each device attached.
-You can, if possible, attach more than one device at a time.


Download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.



Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post bavk with
  • OTLISIT2 log
  • MBAM
  • new HJT log

Thanks
Hey there :D

Here are the logs you requested.

OTLISIT2 log
========== OTLISTIT ==========
Process Explorer.EXE killed successfully!
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
c:\windows\system32\wingo.exe moved successfully.
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\willy\Local Settings\temp\NGLATempNokia\Nokia Sans Wide Bold v3.1.ttf scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\willy\Local Settings\temp\etilqs_P2O2gXssxj45e0j6R8cQ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\willy\Local Settings\temp\NGLALog.txt scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_564.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_c1c.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\YSCFA0.EXE scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTListIt2 by OldTimer - Version 2.0.15.7 log created on 05172009_223416

Files moved on Reboot…
C:\Documents and Settings\willy\Local Settings\temp\NGLATempNokia\Nokia Sans Wide Bold v3.1.ttf moved successfully.
File C:\Documents and Settings\willy\Local Settings\temp\etilqs_P2O2gXssxj45e0j6R8cQ not found!
C:\Documents and Settings\willy\Local Settings\temp\NGLALog.txt moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_564.dat not found!
File C:\WINDOWS\temp\Perflib_Perfdata_c1c.dat not found!
C:\WINDOWS\temp\YSCFA0.EXE moved successfully.

Registry entries deleted on Reboot…

MBAM
Malwarebytes' Anti-Malware 1.36
Database version: 2145
Windows 5.1.2600 Service Pack 2

5/17/2009 10:54:51 PM
mbam-log-2009-05-17 (22-54-51).txt

Scan type: Quick Scan
Objects scanned: 85281
Time elapsed: 2 minute(s), 53 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

new HJT log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:00:39 PM, on 5/17/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\713xRMTMon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\rundll32.exe
E:\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
E:\Multiply\AutoUploader\Multiply AutoUploader\Multiply AutoUploader.exe
C:\WINDOWS\713xRMT.exe
C:\WINDOWS\TEMP\NXF5B5.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
E:\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ph.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ph.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://aa.rd.yahoo.com/customize/ie/defaul…://ph.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: IE7Pro BHO - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Windows Live Sign-in Helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TV Card Remote Control Device Monitor] C:\WINDOWS\713xRMTMon.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PC Suite Tray] "E:\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Startup: Multiply AutoUploader.lnk = E:\Multiply\AutoUploader\Multiply AutoUploader\Multiply AutoUploader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Post Image to Blog - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1240363149828
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

–
End of file - 9235 bytes


Thanks again :P
Hi sesema,

One more scan just to be certain everything is gone.

You will need to use Internet Explorer for this scan.
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.




Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply along with a new HijackThis log.

Thanks
Hello oldman960,

Again, here are the logs you requested.

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Monday, May 18, 2009
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Sunday, May 17, 2009 22:42:56
Records in database: 2189078
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\

Scan statistics:
Files scanned: 116189
Threat name: 16
Infected objects: 27
Suspicious objects: 0
Duration of the scan: 03:30:53


File name / Threat name / Threats count
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\A0020918.EXE Infected: Trojan-PSW.Win32.Agent.meo 1
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\dLer.EXE Infected: Trojan.Win32.VB.lku 1
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ftp_non_crp.EXE Infected: Packed.Win32.PolyCrypt.d 1
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ftp_non_crp_8c8.VIR Infected: Packed.Win32.PolyCrypt.d 1
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\jesus my number one hillsong.MP3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ldr[1].EXE Infected: Backdoor.Win32.AutoIt.o 1
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\minisvr4.EXE Infected: Trojan-Spy.Win32.AutoIt.c 1
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\minisvr4[1].EXE Infected: Trojan-Spy.Win32.AutoIt.c 1
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\nDler2.EXE Infected: Trojan.Win32.VB.mtm 1
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\part.EXE Infected: not-a-virus:Server-Proxy.Win32.3proxy.bo 1
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\part[2].EXE Infected: not-a-virus:Server-Proxy.Win32.3proxy.bo 1
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\psvrr.EXE Infected: not-a-virus:Server-Proxy.Win32.3proxy.bo 1
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\vfhr.EXE Infected: Backdoor.Win32.AutoIt.o 1
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\zchMiB.EXE Infected: Trojan-Downloader.Win32.AutoIt.ji 1
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\zchMiB[1].EXE Infected: Trojan-Downloader.Win32.AutoIt.ji 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\ddcBRHXp.dll.vir Infected: Trojan.Win32.Monderb.aqqu 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\senekalhyiginm.dll.vir Infected: Packed.Win32.Tdss.f 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\senekathopabwu.dll.vir Infected: Packed.Win32.Tdss.f 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\senekaxidqbpxn.dll.vir Infected: Packed.Win32.Tdss.f 1
C:\Qoobox\Quarantine\[4]-Submit_2009-05-17_14.30.01.zip Infected: Trojan.Win32.BHO.ext 1
C:\System Volume Information\_restore{C16B871B-91B7-431B-ABC1-021AFE774FD4}\RP1\A0000018.dll Infected: Trojan.Win32.Monderb.aqqu 1
C:\WINDOWS\Resources\Themes\Windows 7 Original Theme NEW_www.addaclub.com\UX Theme Patcher\Setup.exe Infected: not-a-virus:PSWTool.Win32.Agent.ab 1
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KD6ZKTMN\eula[1].exe Infected: Backdoor.Win32.AutoIt.o 1
C:\WINDOWS\system32\WgaLogon.exe Infected: Net-Worm.Win32.Kolab.bff 1
C:\_OTListIt\MovedFiles\05172009_223416\windows\system32\wingo.exe Infected: Trojan-Dropper.Win32.BHO.bj 1
E:\pc user\My Documents\PortableApps\FirefoxPortable\FireFoxOptimizer.exe Infected: Packed.Win32.Black.a 1
E:\_OTListIt\MovedFiles\05142009_111657\WINDOWS\system32\svchast.exe Infected: Backdoor.Win32.AutoIt.o 1

The selected area was scanned.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:30:49 AM, on 5/18/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\713xRMTMon.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\713xRMT.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
E:\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
E:\Multiply\AutoUploader\Multiply AutoUploader\Multiply AutoUploader.exe
C:\WINDOWS\TEMP\XC7A9C.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntupd.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\TUProgSt.exe
E:\pc user\My Documents\Opera USB\op.com
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
E:\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ph.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ph.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://aa.rd.yahoo.com/customize/ie/defaul…://ph.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: IE7Pro BHO - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Windows Live Sign-in Helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TV Card Remote Control Device Monitor] C:\WINDOWS\713xRMTMon.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PC Suite Tray] "E:\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Startup: Multiply AutoUploader.lnk = E:\Multiply\AutoUploader\Multiply AutoUploader\Multiply AutoUploader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Post Image to Blog - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1240363149828
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

–
End of file - 9476 bytes
Hi sesema,

Most of those detections are in quarantine all ready. We'll use a tool to empty OfficeScan's suspet folder.

Next, Double click on OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:OTLI
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)

:Services

:Reg

:Files
C:\WINDOWS\system32\WgaLogon.exe
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\A0020918.EXE 
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\dLer.EXE 
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ftp_non_crp.EXE 
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ftp_non_crp_8c8.VIR 
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\jesus my number one hillsong.MP3 
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ldr[1].EXE 
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\minisvr4.EXE 
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\minisvr4[1].EXE 
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\nDler2.EXE 
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\part.EXE 
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\part[2].EXE 
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\psvrr.EXE 
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\vfhr.EXE 
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\zchMiB.EXE 
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\zchMiB[1].EXE 

:Commands
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL2 log and if you have no problems, we'll clean up our tools and send you on your way.

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI