This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Ctfmon.exe and Recycler

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Dear All,

I hope someone can help me… :)
- I have been hit by a trojan, virus or whatever you want to call it…to make it short:
- A while ago I discovered the RECYCLER folder on my thumbdrive.
- Not knowing what it was about and not thinking of anything I formatted the thumbdrive.
- Yesterday I discovered the same file on my external harddrive AND thumbdrive again as I plugged it in at college using mac.
- Also some other autorun and dll files.
- I tried to delete it.
- At home I tried to search for the files on the drives again but my computer can't enable 'show hidden files and folders' anymore.
- Today my computer goes crazy!
- I do not dare plugging in my harddrive again as on it is ALL my data.
- Hence, I am not so sure which infections are still on it.
- I research and discovered it must be the ctfmon.exe. I also read that it is difficult to remove completely and I didn't dare using
flash disinfector and alike without supervision. Also I read that this software does not completely remove the infection.
- This would mean that the infection has been there since longer and spread from the thumbdrive to my external harddrive and computer.
- Here my cry for help :

I wouldn't even mind to reformat my computer if necessary but PLEASE help me to save my external harddrive and thumbdrive
if it's really affected by the Recycler!!!!! There must be a way to remove it completely (I hope :unsure: )

- Also my friends computer has been affected with the ctfmon.exe through the same external drives.

Here my HJT code…

Thanks a lot!
Regards,
Sandra





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:38:06 PM, on 5/16/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\lxdccoms.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Samsung\DisplayManager\DisplayManager.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\tsnpstd3.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\UnHackMe\hackmon.exe
C:\Program Files\DAP\DAP.EXE
C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.60.1.2:8080
O1 - Hosts: 69.57.152.127 auto.search.msn.com
O1 - Hosts: 69.57.152.127 auto.search.msn.es
O1 - Hosts: 69.57.152.127 pagead2.googlesyndication.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program

Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark

Toolbar\toolband.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [EDS] C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [MagicKeyboard] C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe
O4 - HKLM\..\Run: [DMHotKey] C:\Program Files\Samsung\DisplayManager\DMLoader.exe
O4 - HKLM\..\Run: [DisplayManager] C:\Program Files\Samsung\DisplayManager\DisplayManager.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [lxdcmon.exe] "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe"
O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot

1
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [UnHackMe Monitor] C:\Program Files\UnHackMe\hackmon.exe
O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - HKCU\..\Run: [SpeedBitVideoAccelerator] C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: DW_Start.lnk = C:\Documents and Settings\sandra\Local Settings\Temp\DealioKit97-stub-0.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DW_Start.lnk = C:\Documents and Settings\sandra\Local Settings\Temp\DealioKit97-stub-0.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://www.update.microsoft.com/windowsupd…b?1207410961515
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision

Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common

Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: lxdcCATSCustConnectService - Lexmark International, Inc. -

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdcserv.exe
O23 - Service: lxdc_device - - C:\WINDOWS\system32\lxdccoms.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda

Software\PavShld\pavprsrv.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared

files\RichVideo.exe
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe

–
End of file - 10007 bytes
Hello.

Please do the following.

Download and Run HostsXpert

Some infections will put malicious lines into your hosts files. We will reset your hosts file with HostsXpert.

  • Please down load HostsXpert.zip to your desktop.
  • unzip the file by right-clicking and select Extract All…
  • A folder named HostsXpert will be created. Open it and run HostsXpert.exe by double clicking it.
  • Click on the botton Make Writeable? .
  • Click Restore Microsoft's Hosts File.
  • Close out of the window.
Note: If your Hosts file no longer exists, you will get a warning similar to "HOSTS file does not exist, Press OK to create HOSTS file". Please select Ok if that is the case.
2Note:If you have added modifications to your hosts file, they will need to be re-added

Download and run OTListIT2

We need to create an OTListIt2 Report

  • Please download OTListIt2 from one of the following mirrors:
  • Save it to your desktop.
  • Double click on the [external image: Posted Image] icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Push the [external image: Posted Image] button.
  • Two reports will open, copy and paste them in a reply here:
    • OTListIt.txt <– Will be opened
    • Extra.txt <– Will be minimized
  • Post both logs in your next reply please.

With Regards,
Extremeboy
Hello.

Sorry for the late reply, I was outstation. I have done as you said and these are the two logs created.
Please advice me further. Thanks a lot!

Regards,
Sandra


OTListIt logfile created on: 6/22/2009 12:03:49 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\sandra\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.10 Mb Total Physical Memory | 384.84 Mb Available Physical Memory | 43.04% Memory free
2.12 Gb Paging File | 1.59 Gb Available in Paging File | 75.26% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 86.04 Gb Total Space | 60.55 Gb Free Space | 70.37% Space Free | Partition Type: NTFS
Drive D: | 4.50 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SURFERGIRL
Current User Name: sandra
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2006/03/28 22:42:44 | 00,405,504 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2006/03/28 22:42:44 | 00,405,504 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\SYSTEM32\Ati2evxx.exe
PRC - [2006/10/15 23:38:20 | 01,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2009/05/11 16:00:51 | 00,298,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2007/05/01 04:03:50 | 00,537,520 | —- | M] ( ) – C:\WINDOWS\system32\lxdccoms.exe
PRC - [2005/08/08 13:54:00 | 00,167,936 | —- | M] () – C:\Program Files\CyberLink\Shared files\RichVideo.exe
PRC - [2009/06/19 23:31:55 | 00,486,680 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2008/08/26 22:04:39 | 00,288,360 | —- | M] (Speedbit Ltd.) – C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe
PRC - [2009/05/11 16:00:56 | 00,594,712 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2009/05/11 16:00:55 | 00,908,568 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2008/08/26 22:04:39 | 00,124,528 | —- | M] (Speedbit Ltd.) – C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorEngine.exe
PRC - [2009/05/11 16:00:58 | 00,692,504 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2004/08/04 06:56:58 | 00,218,112 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\wbem\wmiprvse.exe
PRC - [2006/01/02 18:41:22 | 00,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2006/04/04 16:44:58 | 16,120,832 | R— | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\RTHDCPL.EXE
PRC - [2006/03/28 13:27:16 | 00,634,880 | —- | M] () – C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
PRC - [2006/06/29 12:32:14 | 00,089,541 | R— | M] (Agere Systems) – C:\WINDOWS\AGRSMMSG.exe
PRC - [2005/12/07 13:44:16 | 00,761,947 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2006/05/03 19:22:18 | 00,413,696 | —- | M] (SAMSUNG ELECTRONICS) – C:\Program Files\Samsung\DisplayManager\DisplayManager.exe
PRC - [2008/01/16 06:54:54 | 00,037,376 | —- | M] () – C:\Program Files\Winamp\winampa.exe
PRC - [2005/12/07 22:57:00 | 00,030,208 | —- | M] (Cyberlink Corp.) – C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
PRC - [2006/05/03 19:11:02 | 00,520,192 | —- | M] (SAMSUNG) – C:\Program Files\Samsung\DisplayManager\dmhkcore.exe
PRC - [2005/12/20 14:39:32 | 00,094,208 | —- | M] () – C:\WINDOWS\tsnpstd3.exe
PRC - [2008/02/22 04:25:21 | 00,144,784 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
PRC - [2007/03/06 04:40:25 | 00,020,480 | —- | M] (Lexmark) – C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
PRC - [2009/05/11 16:00:54 | 01,947,928 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2005/09/05 15:55:08 | 00,339,968 | —- | M] () – C:\WINDOWS\vsnpstd3.exe
PRC - [2008/06/12 02:25:18 | 00,037,232 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe
PRC - [2008/06/11 22:43:26 | 00,640,376 | —- | M] (Adobe Systems Inc.) – C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
PRC - [2007/09/17 15:37:22 | 00,228,352 | —- | M] (Greatis Software) – C:\Program Files\UnHackMe\hackmon.exe
PRC - [2008/08/26 20:34:28 | 03,057,152 | —- | M] (Speedbit Ltd.) – C:\Program Files\DAP\DAP.EXE
PRC - [2008/08/26 22:04:39 | 02,799,200 | —- | M] (Speedbit Ltd.) – C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe
PRC - [2008/11/05 21:59:00 | 04,347,120 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2009/04/24 12:38:11 | 00,307,704 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2006/01/02 18:41:22 | 00,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2006/01/02 18:41:22 | 00,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2009/06/21 23:43:34 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\sandra\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/07/25 11:16:40 | 00,034,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2006/03/28 22:42:44 | 00,405,504 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\Ati2evxx.exe – (Ati HotKey Poller [Auto | Running])
SRV - [2009/05/11 16:00:55 | 00,908,568 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe – (avg8emc [Auto | Running])
SRV - [2009/05/11 16:00:51 | 00,298,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe – (avg8wd [Auto | Running])
SRV - File not found – – (cfghgn [Auto | Stopped])
SRV - [2008/07/25 11:17:02 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - File not found – – (dxjnkns [Auto | Stopped])
SRV - File not found – – (flaye [Auto | Stopped])
SRV - [2009/01/12 20:49:43 | 00,651,720 | —- | M] (Macrovision Europe Ltd.) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service [On_Demand | Stopped])
SRV - [2008/07/29 21:10:04 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2004/08/04 06:56:46 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2004/10/22 03:24:18 | 00,073,728 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2008/07/29 19:24:50 | 00,881,664 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2007/05/01 04:04:10 | 00,099,248 | —- | M] () – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdcserv.exe – (lxdcCATSCustConnectService [Auto | Stopped])
SRV - [2007/05/01 04:03:50 | 00,537,520 | —- | M] ( ) – C:\WINDOWS\system32\lxdccoms.exe – (lxdc_device [Auto | Running])
SRV - [2008/07/29 19:16:38 | 00,132,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - File not found – – (NNServ [Auto | Stopped])
SRV - [2006/10/26 19:49:34 | 00,441,136 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
SRV - [2006/10/26 14:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - File not found – – (PavPrSrv [Auto | Stopped])
SRV - [2005/08/08 13:54:00 | 00,167,936 | —- | M] () – C:\Program Files\CyberLink\Shared files\RichVideo.exe – (RichVideo [Auto | Running])
SRV - [2008/08/26 22:04:39 | 00,288,360 | —- | M] (Speedbit Ltd.) – C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe – (VideoAcceleratorService [Auto | Running])
SRV - [2005/10/06 18:12:30 | 00,855,552 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Connect 2\wmccds.exe – (WMConnectCDS [On_Demand | Stopped])
SRV - [2006/05/09 21:03:00 | 00,823,808 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2009/03/13 13:29:13 | 00,016,855 | —- | M] (An Chen Computer Co., Ltd.) – C:\WINDOWS\system32\Drivers\Achernar.sys – (Achernar [Boot | Running])
DRV - [2006/06/29 12:13:08 | 01,160,320 | R— | M] (Agere Systems) – C:\WINDOWS\system32\DRIVERS\AGRSM.sys – (AgereSoftModem [On_Demand | Running])
DRV - [2009/03/13 13:29:13 | 00,021,808 | —- | M] (An Chen Computer Co., Ltd.) – C:\WINDOWS\system32\Drivers\Aldebaran.sys – (Aldebaran [On_Demand | Running])
DRV - [2006/03/28 22:50:14 | 01,522,688 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys – (ati2mtag [On_Demand | Running])
DRV - [2009/05/11 16:00:59 | 00,325,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86 [System | Running])
DRV - [2009/05/11 16:00:59 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86 [System | Running])
DRV - [2009/05/11 16:00:56 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX [System | Running])
DRV - [2006/03/29 12:59:12 | 00,027,648 | —- | M] (Samsung Electronics,.LTD) – C:\WINDOWS\system32\drivers\SamsungEDS.sys – (DNSeFilter [On_Demand | Running])
DRV - [2006/10/15 23:38:24 | 00,138,752 | —- | M] (Windows ® Server 2003 DDK provider) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys – (HDAudBus [On_Demand | Running])
DRV - [2006/04/06 13:20:44 | 04,258,816 | R— | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService [On_Demand | Running])
DRV - [2009/05/10 12:10:00 | 00,030,946 | —- | M] (Greatis Software) – C:\WINDOWS\system32\drivers\Partizan.sys – (Partizan [Boot | Stopped])
DRV - [2001/08/23 20:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\system32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2007/03/08 07:51:00 | 00,043,528 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2005/11/16 20:28:32 | 00,028,928 | —- | M] (REDC) – C:\WINDOWS\system32\DRIVERS\rimmptsk.sys – (rimmptsk [On_Demand | Running])
DRV - [2005/11/01 17:54:50 | 00,051,584 | —- | M] (REDC) – C:\WINDOWS\system32\DRIVERS\rimsptsk.sys – (rimsptsk [On_Demand | Running])
DRV - [2005/11/01 18:08:00 | 00,308,992 | —- | M] (REDC) – C:\WINDOWS\system32\DRIVERS\rixdptsk.sys – (rismxdp [On_Demand | Running])
DRV - [2006/01/18 17:41:58 | 00,080,512 | R— | M] (Realtek Semiconductor Corporation ) – C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys – (RTL8023xp [On_Demand | Running])
DRV - [2004/08/04 06:31:34 | 00,020,992 | —- | M] (Realtek Semiconductor Corporation) – C:\WINDOWS\system32\DRIVERS\RTL8139.SYS – (rtl8139 [On_Demand | Stopped])
DRV - [2008/08/26 22:04:40 | 00,035,968 | —- | M] (SpeedBit Ltd.) – C:\Program Files\SpeedBit Video Accelerator\sbbotdi.sys – (sbbotdi [Auto | Running])
DRV - [2006/10/15 23:39:23 | 00,163,644 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\system32\DRIVERS\secdrv.sys – (Secdrv [Auto | Running])
DRV - [2006/04/18 15:25:36 | 08,532,864 | —- | M] (Sonix Co. Ltd.) – C:\WINDOWS\system32\DRIVERS\snpstd3.sys – (SNPSTD3 [On_Demand | Stopped])
DRV - [2006/01/16 10:15:24 | 00,470,112 | —- | M] (Atheros Communications, Inc.) – C:\WINDOWS\system32\DRIVERS\SSB2413.sys – (SSB2413 [On_Demand | Running])
DRV - [2005/12/07 13:30:52 | 00,191,936 | —- | M] (Synaptics, Inc.) – C:\WINDOWS\system32\DRIVERS\SynTP.sys – (SynTP [On_Demand | Running])
DRV - [2004/08/03 23:07:56 | 00,059,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\usbaudio.sys – (usbaudio [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar;=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar;=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes

IE - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.microsoft.com/isapi/redir.dll?P…pdate&O1;=b1
IE - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…&ar;=msnhome
IE - HKU\S-1-5-21-839522115-1417001333-682003330-1003\S-1-5-21-839522115-1417001333-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1
FF - prefs.js..extensions.enabledItems: {F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}:[removed]
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090123.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX [2009/05/12 08:28:00 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/05/09 16:09:04 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/09 21:01:33 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/05/03 17:48:05 | 00,000,000 | —D | M]

[2008/09/15 18:15:32 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Extensions
[2008/09/15 18:15:32 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/06/21 23:22:49 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Firefox\Profiles\7vxwuliu.default\extensions
[2008/02/28 21:47:08 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Firefox\Profiles\7vxwuliu.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/05/09 17:16:24 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Firefox\Profiles\7vxwuliu.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2008/01/21 15:05:38 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Firefox\Profiles\7vxwuliu.default\extensions\[removed]
[2009/04/22 22:52:34 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Firefox\Profiles\7vxwuliu.default\extensions\[removed]
[2009/06/21 23:22:49 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/05/03 17:48:06 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/05/23 15:21:25 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{AF8637B0-18E3-44D3-86B7-55E09D9C4261}
[2008/03/30 23:12:37 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2009/04/24 12:38:30 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/24 12:38:32 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/24 08:39:08 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/24 08:39:08 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/24 08:39:08 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/24 08:39:08 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/24 08:39:08 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/24 08:39:08 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/24 08:39:08 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (698 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-839522115-1417001333-682003330-1003\..\Toolbar\WebBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKU\S-1-5-21-839522115-1417001333-682003330-1003\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AGRSMMSG] AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [Alcmtr] ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay (ATI Technologies Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DisplayManager] C:\Program Files\Samsung\DisplayManager\DisplayManager.exe (SAMSUNG ELECTRONICS)
O4 - HKLM..\Run: [DMHotKey] C:\Program Files\Samsung\DisplayManager\DMLoader.exe (SAMSUNG)
O4 - HKLM..\Run: [EDS] C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe ()
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" ()
O4 - HKLM..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe" (Lexmark)
O4 - HKLM..\Run: [lxdcmon.exe] "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe" File not found
O4 - HKLM..\Run: [MagicKeyboard] C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe ()
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" ()
O4 - HKU\S-1-5-21-839522115-1417001333-682003330-1003..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP (Speedbit Ltd.)
O4 - HKU\S-1-5-21-839522115-1417001333-682003330-1003..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.)
O4 - HKU\S-1-5-21-839522115-1417001333-682003330-1003..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background File not found
O4 - HKU\S-1-5-21-839522115-1417001333-682003330-1003..\Run: [SpeedBitVideoAccelerator] C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe (Speedbit Ltd.)
O4 - HKU\S-1-5-21-839522115-1417001333-682003330-1003..\Run: [UnHackMe Monitor] C:\Program Files\UnHackMe\hackmon.exe (Greatis Software)
O4 - HKU\S-1-5-21-839522115-1417001333-682003330-1003..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 (Adobe Systems Incorporated)
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - HKLM..\RunOnceEx: [Title] UnHackMe Rootkit Check File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRun = 0
O7 - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: &Clean; Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm ()
O8 - Extra context menu item: &Download; with &DAP; - C:\Program Files\DAP\dapextie.htm ()
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Download &all; with DAP - C:\Program Files\DAP\dapextie2.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1207410961515 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\SYSTEM32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\SYSTEM32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/01/17 14:12:28 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{0735350c-83a7-11dd-b712-001377316941}\Shell\AutoRun\command - "" = RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\win32.exe
O33 - MountPoints2\{0735350c-83a7-11dd-b712-001377316941}\Shell\open\command - "" = RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\win32.exe
O33 - MountPoints2\{0735350e-83a7-11dd-b712-001377316941}\Shell - "" = AutoRun
O33 - MountPoints2\{0735350e-83a7-11dd-b712-001377316941}\Shell\Auto\command - "" = E:\MicrosoftPowerPoint.exe – File not found
O33 - MountPoints2\{0735350e-83a7-11dd-b712-001377316941}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{0a1a0d86-078a-11dd-b617-001377316941}\Shell - "" = AutoRun
O33 - MountPoints2\{0a1a0d86-078a-11dd-b617-001377316941}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{0a1a0d86-078a-11dd-b617-001377316941}\Shell\explore\Command - "" = E:\data.exe – File not found
O33 - MountPoints2\{0a1a0d86-078a-11dd-b617-001377316941}\Shell\open\Command - "" = E:\data.exe – File not found
O33 - MountPoints2\{7b1c7458-0e30-11de-8804-001377316941}\Shell\Auto\command - "" = E:\RavMonE.exe – File not found
O33 - MountPoints2\{7b1c7458-0e30-11de-8804-001377316941}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{8b1f23f2-f568-11dc-b5d0-001377316941}\Shell - "" = AutoRun
O33 - MountPoints2\{8b1f23f2-f568-11dc-b5d0-001377316941}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{8b1f23f2-f568-11dc-b5d0-001377316941}\Shell\explore\Command - "" = data.exe -e
O33 - MountPoints2\{8b1f23f2-f568-11dc-b5d0-001377316941}\Shell\open\Command - "" = data.exe
O33 - MountPoints2\{97c03c2e-c58e-11dd-b772-001377316941}\Shell\AutoRun\command - "" = wscript.exe VirusRemoval.vbs
O33 - MountPoints2\{97c03c2e-c58e-11dd-b772-001377316941}\Shell\open\Command - "" = wscript.exe VirusRemoval.vbs
O33 - MountPoints2\{9cb55fcc-db9f-11dc-b591-001377316941}\Shell - "" = AutoRun
O33 - MountPoints2\{9cb55fcc-db9f-11dc-b591-001377316941}\Shell\Auto\command - "" = E:\MicrosoftPowerPoint.exe – File not found
O33 - MountPoints2\{9cb55fcc-db9f-11dc-b591-001377316941}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{a07ba4ce-1148-11de-880a-001377316941}\Shell\Auto\command - "" = E:\RavMonE.exe – File not found
O33 - MountPoints2\{a07ba4ce-1148-11de-880a-001377316941}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{a9b2108f-ab1b-11dd-b760-001377316941}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\win32.exe – File not found
O33 - MountPoints2\{a9b2108f-ab1b-11dd-b760-001377316941}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\win32.exe – File not found
O33 - MountPoints2\{adeceddf-c724-11dd-b777-001377316941}\Shell - "" = AutoRun
O33 - MountPoints2\{adeceddf-c724-11dd-b777-001377316941}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{adeceddf-c724-11dd-b777-001377316941}\Shell\AutoRun\command - "" = E:\AutoRun.exe – File not found
O33 - MountPoints2\{adecede1-c724-11dd-b777-001377316941}\Shell - "" = AutoRun
O33 - MountPoints2\{adecede1-c724-11dd-b777-001377316941}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{adecede1-c724-11dd-b777-001377316941}\Shell\AutoRun\command - "" = E:\AutoRun.exe – File not found
O33 - MountPoints2\{c15fd5f6-cfc5-11dc-b58c-001377316941}\Shell\AutoRun\command - "" = E:\SYSTEM\G-923-321232-3232-32211-23\driver.exe – File not found
O33 - MountPoints2\{c15fd5f6-cfc5-11dc-b58c-001377316941}\Shell\open\command - "" = E:\SYSTEM\G-923-321232-3232-32211-23\driver.exe – File not found
O33 - MountPoints2\{d82afc38-aafe-11dd-b75f-001377316941}\Shell\AutoRun\command - "" = E:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\win32.exe – File not found
O33 - MountPoints2\{d82afc38-aafe-11dd-b75f-001377316941}\Shell\open\command - "" = E:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\win32.exe – File not found
O33 - MountPoints2\{e2019ea6-c8e6-11dc-b586-001377316941}\Shell\AutoRun\command - "" = RECYCLER\k-1-3542-4232123213-7676767-8888886\root.exe
O33 - MountPoints2\{e2019ea6-c8e6-11dc-b586-001377316941}\Shell\open\command - "" = RECYCLER\k-1-3542-4232123213-7676767-8888886\root.exe
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/06/21 23:44:03 | 00,000,000 | —D | M]
O34 - HKLM BootExecute: (Partizan) - C:\WINDOWS\System32\Partizan.exe (Greatis Software)
O34 - HKLM BootExecute: (ootExecute) - File not found
O34 - HKLM BootExecute: (settings…) - File not found
O34 - HKLM BootExecute: (on\E) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/06/21 23:40:52 | 00,000,000 | —D | C] – C:\Documents and Settings\sandra\Desktop\HostsXpert
[2009/06/21 23:36:07 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\sandra\Desktop\OTListIt2.exe
[2009/06/21 23:35:28 | 00,353,485 | —- | C] () – C:\Documents and Settings\sandra\Desktop\HostsXpert.zip
[2009/06/18 23:49:45 | 00,060,416 | —- | C] () – C:\Documents and Settings\sandra\Desktop\Database new.xls
[2009/06/16 22:56:16 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2009/06/16 22:56:10 | 00,000,000 | —D | C] – C:\Program Files\Security Task Manager
[2009/04/30 21:12:15 | 00,001,024 | —- | C] () – C:\WINDOWS\System32\grcauth2.dll
[2009/04/30 21:12:15 | 00,001,024 | —- | C] () – C:\WINDOWS\System32\grcauth1.dll
[2009/04/30 21:12:15 | 00,000,100 | —- | C] () – C:\WINDOWS\System32\prsgrc.dll
[2009/04/30 21:07:50 | 00,001,025 | —- | C] () – C:\WINDOWS\System32\sysprs7.dll
[2009/04/30 21:07:50 | 00,000,205 | —- | C] () – C:\WINDOWS\System32\lsprst7.dll
[2009/02/18 22:04:07 | 00,000,109 | —- | C] () – C:\WINDOWS\RealFlight.INI
[2009/02/18 21:51:56 | 00,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2009/02/18 15:19:46 | 00,000,265 | —- | C] () – C:\WINDOWS\emug3.ini
[2008/06/04 08:57:38 | 00,290,816 | —- | C] () – C:\WINDOWS\System32\XDogcat.dll
[2008/05/23 16:12:53 | 00,000,713 | -HS- | C] () – C:\WINDOWS\System32\qrutv.ini2
[2008/05/23 16:03:34 | 00,077,312 | —- | C] () – C:\WINDOWS\System32\ztvunace26.dll
[2008/05/23 16:03:33 | 00,162,304 | —- | C] () – C:\WINDOWS\System32\ztvunrar36.dll
[2008/05/23 16:03:33 | 00,153,088 | —- | C] () – C:\WINDOWS\System32\unrar3.dll
[2008/05/23 16:03:33 | 00,075,264 | —- | C] () – C:\WINDOWS\System32\unacev2.dll
[2008/05/23 15:57:48 | 00,000,713 | -HS- | C] () – C:\WINDOWS\System32\qrutv.ini
[2008/05/23 15:17:14 | 00,039,424 | —- | C] () – C:\WINDOWS\System32\fccywxy.dll.vir
[2008/05/17 19:55:40 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\lxdcvs.dll
[2008/05/17 19:55:37 | 00,344,064 | —- | C] () – C:\WINDOWS\System32\lxdccoin.dll
[2008/05/17 19:50:15 | 00,000,044 | —- | C] () – C:\WINDOWS\System32\lxdcrwrd.ini
[2008/05/17 19:49:44 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\LXDCinst.dll
[2008/05/17 19:49:43 | 00,413,696 | —- | C] ( ) – C:\WINDOWS\System32\lxdcinpa.dll
[2008/05/17 19:49:43 | 00,323,584 | —- | C] ( ) – C:\WINDOWS\System32\LXDChcp.dll
[2008/05/17 19:49:42 | 01,232,896 | —- | C] ( ) – C:\WINDOWS\System32\lxdcserv.dll
[2008/05/17 19:49:42 | 00,999,424 | —- | C] ( ) – C:\WINDOWS\System32\lxdcusb1.dll
[2008/05/17 19:49:42 | 00,397,312 | —- | C] ( ) – C:\WINDOWS\System32\lxdciesc.dll
[2008/05/17 19:49:41 | 00,643,072 | —- | C] ( ) – C:\WINDOWS\System32\lxdcpmui.dll
[2008/05/17 19:49:41 | 00,585,728 | —- | C] ( ) – C:\WINDOWS\System32\lxdclmpm.dll
[2008/05/17 19:49:41 | 00,163,840 | —- | C] ( ) – C:\WINDOWS\System32\lxdcprox.dll
[2008/05/17 19:49:41 | 00,094,208 | —- | C] ( ) – C:\WINDOWS\System32\lxdcpplc.dll
[2008/05/17 19:49:40 | 00,700,416 | —- | C] ( ) – C:\WINDOWS\System32\lxdchbn3.dll
[2008/05/17 19:49:40 | 00,208,896 | —- | C] () – C:\WINDOWS\System32\lxdcgrd.dll
[2008/05/17 19:49:39 | 00,684,032 | —- | C] ( ) – C:\WINDOWS\System32\lxdccomc.dll
[2008/05/17 19:49:39 | 00,425,984 | —- | C] ( ) – C:\WINDOWS\System32\lxdccomm.dll
[2008/03/27 19:46:44 | 01,537,735 | -HS- | C] () – C:\WINDOWS\System32\awilncfr.ini
[2008/03/26 19:47:08 | 01,587,085 | -HS- | C] () – C:\WINDOWS\System32\knmdbwjh.ini
[2008/03/25 23:29:30 | 01,578,421 | -HS- | C] () – C:\WINDOWS\System32\paldhxfa.ini
[2008/03/24 23:28:09 | 01,578,121 | -HS- | C] () – C:\WINDOWS\System32\geodexbj.ini
[2008/03/23 23:27:03 | 01,217,859 | -HS- | C] () – C:\WINDOWS\System32\dbwxjjrh.ini
[2008/03/22 23:26:32 | 01,270,400 | -HS- | C] () – C:\WINDOWS\System32\slotpvjw.ini
[2008/03/21 19:27:59 | 01,382,987 | -HS- | C] () – C:\WINDOWS\System32\uqedluxv.ini
[2008/03/20 18:13:41 | 01,624,124 | -HS- | C] () – C:\WINDOWS\System32\vodpxbwd.ini
[2008/03/19 17:07:04 | 01,413,952 | -HS- | C] () – C:\WINDOWS\System32\udquiolm.ini
[2008/03/18 15:47:50 | 01,928,200 | -HS- | C] () – C:\WINDOWS\System32\wibdblai.ini
[2008/03/14 12:32:58 | 01,409,307 | -HS- | C] () – C:\WINDOWS\System32\ahwtqhvu.ini
[2008/03/13 19:50:41 | 01,235,367 | -HS- | C] () – C:\WINDOWS\System32\fafokiyg.ini
[2008/03/12 15:48:40 | 01,214,015 | -HS- | C] () – C:\WINDOWS\System32\jagygtnr.ini
[2008/03/10 19:42:29 | 01,201,641 | -HS- | C] () – C:\WINDOWS\System32\axdxnegv.ini
[2008/03/09 19:41:24 | 01,269,267 | -HS- | C] () – C:\WINDOWS\System32\grrvmptc.ini
[2008/03/08 19:41:46 | 01,237,113 | -HS- | C] () – C:\WINDOWS\System32\rkybghgo.ini
[2008/03/06 19:28:44 | 01,236,319 | -HS- | C] () – C:\WINDOWS\System32\kvrqfsvj.ini
[2008/03/06 19:19:35 | 00,000,396 | —- | C] () – C:\WINDOWS\System32\ibfauufn.dll
[2008/03/05 19:26:37 | 01,302,346 | -HS- | C] () – C:\WINDOWS\System32\txohdmpb.ini
[2008/03/05 19:20:34 | 00,000,396 | —- | C] () – C:\WINDOWS\System32\bdmljolu.dll
[2008/03/04 19:23:02 | 00,000,048 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/03/04 19:23:01 | 01,303,628 | -HS- | C] () – C:\WINDOWS\System32\okhscrlv.ini
[2008/03/04 19:22:50 | 00,000,396 | —- | C] () – C:\WINDOWS\System32\kqspqvdd.dll
[2008/03/04 19:16:51 | 00,000,396 | —- | C] () – C:\WINDOWS\System32\eeymnsxk.dll
[2008/02/29 17:34:26 | 00,000,396 | —- | C] () – C:\WINDOWS\System32\cdwnbqfa.dll
[2008/02/27 22:08:21 | 01,246,961 | -HS- | C] () – C:\WINDOWS\System32\jyqahwit.ini
[2008/02/27 22:02:11 | 00,000,396 | —- | C] () – C:\WINDOWS\System32\nqcmqkkn.dll
[2008/02/26 21:58:56 | 00,185,519 | -HS- | C] () – C:\WINDOWS\System32\prutv.ini2
[2008/02/26 21:58:54 | 00,185,519 | -HS- | C] () – C:\WINDOWS\System32\prutv.ini
[2008/02/20 20:09:42 | 00,168,220 | -HS- | C] () – C:\WINDOWS\System32\ehhkj.ini2
[2008/02/20 20:09:42 | 00,168,220 | -HS- | C] () – C:\WINDOWS\System32\ehhkj.ini
[2008/02/19 19:46:52 | 00,015,498 | —- | C] () – C:\WINDOWS\snpstd3.ini
[2008/02/19 19:46:47 | 00,053,248 | —- | C] ( ) – C:\WINDOWS\vsnpstd3.dll
[2008/02/19 19:46:46 | 00,147,456 | —- | C] ( ) – C:\WINDOWS\System32\rsnpstd3.dll
[2008/02/19 19:46:46 | 00,053,248 | —- | C] ( ) – C:\WINDOWS\System32\csnpstd3.dll
[2008/02/17 15:51:20 | 00,167,017 | -HS- | C] () – C:\WINDOWS\System32\qqstv.ini2
[2008/02/17 15:51:19 | 00,167,017 | -HS- | C] () – C:\WINDOWS\System32\qqstv.ini
[2008/01/29 21:43:08 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2008/01/17 14:45:34 | 00,000,135 | R— | C] () – C:\WINDOWS\System32\lngEng.ini
[2008/01/17 14:45:34 | 00,000,117 | —- | C] () – C:\WINDOWS\System32\lngKor.ini
[2008/01/17 14:39:12 | 00,001,697 | —- | C] () – C:\WINDOWS\System32\sandra_KBD.ini
[2008/01/17 14:39:12 | 00,001,697 | —- | C] () – C:\WINDOWS\System32\MagicKBD.INI
[2008/01/17 14:39:10 | 00,003,425 | —- | C] () – C:\WINDOWS\System32\KBDR.INI
[2008/01/17 14:39:10 | 00,002,741 | —- | C] () – C:\WINDOWS\System32\KBDD.INI
[2008/01/17 14:39:10 | 00,002,699 | —- | C] () – C:\WINDOWS\System32\KBDO.INI
[2008/01/17 14:39:10 | 00,002,699 | —- | C] () – C:\WINDOWS\System32\KBDC.INI
[2008/01/17 14:39:10 | 00,002,606 | —- | C] () – C:\WINDOWS\System32\KBDB.INI
[2008/01/17 14:39:10 | 00,002,236 | —- | C] () – C:\WINDOWS\System32\KBDQ.INI
[2008/01/17 14:39:10 | 00,001,956 | —- | C] () – C:\WINDOWS\System32\KBDE.INI
[2008/01/17 14:39:10 | 00,001,885 | —- | C] () – C:\WINDOWS\System32\KBDP.INI
[2008/01/17 14:39:10 | 00,001,857 | —- | C] () – C:\WINDOWS\System32\KBDUU.INI
[2008/01/17 14:39:10 | 00,001,835 | —- | C] () – C:\WINDOWS\System32\KBDG.INI
[2008/01/17 14:39:10 | 00,001,835 | —- | C] () – C:\WINDOWS\System32\KBDA.INI
[2008/01/17 14:39:10 | 00,001,834 | —- | C] () – C:\WINDOWS\System32\KBDU.INI
[2008/01/17 14:39:10 | 00,001,819 | —- | C] () – C:\WINDOWS\System32\KBDN.INI
[2008/01/17 14:39:10 | 00,001,699 | —- | C] () – C:\WINDOWS\System32\KBDT.INI
[2008/01/17 14:39:10 | 00,001,697 | —- | C] () – C:\WINDOWS\System32\KBDV.INI
[2008/01/17 14:39:10 | 00,001,522 | —- | C] () – C:\WINDOWS\System32\KBDS.INI
[2008/01/17 14:39:10 | 00,001,476 | —- | C] () – C:\WINDOWS\System32\KBDF.INI
[2008/01/17 14:38:54 | 00,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2008/01/17 14:36:42 | 00,135,168 | R— | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2007/03/12 11:41:52 | 00,061,440 | —- | C] ( ) – C:\WINDOWS\System32\vsnpstd3.dll
[2004/08/04 06:56:44 | 00,081,920 | —- | C] () – C:\WINDOWS\System32\ieencode.dll
[2001/08/23 20:00:00 | 00,000,817 | —- | C] () – C:\WINDOWS\win.ini
[2001/08/23 20:00:00 | 00,000,231 | —- | C] () – C:\WINDOWS\system.ini

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[5 C:\WINDOWS\System32\*.tmp files]
[6 C:\WINDOWS\*.tmp files]
[2009/06/22 12:00:13 | 36,325,133 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/06/22 11:57:42 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\sandra\Local Settings\desktop.ini
[2009/06/22 11:57:41 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/06/22 11:57:39 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/06/22 00:05:20 | 00,004,732 | —- | M] () – C:\WINDOWS\System32\ProxyServer.bak
[2009/06/22 00:05:03 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/06/22 00:05:03 | 00,000,499 | —- | M] () – C:\WINDOWS\System32\CommPipe.bak
[2009/06/22 00:05:03 | 00,000,390 | —- | M] () – C:\WINDOWS\System32\SbLsp.bak
[2009/06/21 23:43:34 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\sandra\Desktop\OTListIt2.exe
[2009/06/21 23:35:35 | 00,353,485 | —- | M] () – C:\Documents and Settings\sandra\Desktop\HostsXpert.zip
[2009/06/21 23:12:37 | 00,058,917 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/06/18 23:49:47 | 00,060,416 | —- | M] () – C:\Documents and Settings\sandra\Desktop\Database new.xls

========== Alternate Data Streams ==========

@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0F8F5844
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5BB923A2
< End of report >


OTListIt Extras logfile created on: 6/22/2009 12:03:49 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\sandra\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.10 Mb Total Physical Memory | 384.84 Mb Available Physical Memory | 43.04% Memory free
2.12 Gb Paging File | 1.59 Gb Available in Paging File | 75.26% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 86.04 Gb Total Space | 60.55 Gb Free Space | 70.37% Space Free | Partition Type: NTFS
Drive D: | 4.50 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SURFERGIRL
Current User Name: sandra
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
"DisableMonitoring" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
"DisableMonitoring" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Connect
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Connect
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Connect
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Connect
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Connect
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Connect

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Connect
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Connect
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Connect
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Connect
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Connect
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Connect
"9420:TCP" = 9420:TCP:*:Enabled:Akamai Network Manager
"5000:UDP" = 5000:UDP:*:Enabled:Akamai Network Manager
"14478:TCP" = 14478:TCP:*:Enabled:NortonAV
"12830:TCP" = 12830:TCP:*:Enabled:NortonAV
"18882:TCP" = 18882:TCP:*:Enabled:NortonAV
"15474:TCP" = 15474:TCP:*:Enabled:NortonAV
"16253:TCP" = 16253:TCP:*:Enabled:NortonAV
"17278:TCP" = 17278:TCP:*:Enabled:NortonAV
"12140:TCP" = 12140:TCP:*:Enabled:NortonAV
"14498:TCP" = 14498:TCP:*:Enabled:NortonAV
"13748:TCP" = 13748:TCP:*:Enabled:NortonAV

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2006/10/15 23:39:56 | 00,557,568 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2007/05/07 19:18:00 | 00,029,616 | —- | M] () – C:\Program Files\Lexmark 1300 Series\App4R.exe:*:Enabled:Lexmark Imaging Studio
File not found – C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
File not found – C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2006/10/15 23:39:56 | 00,557,568 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2007/11/13 03:02:18 | 00,551,508 | —- | M] ( ) – C:\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM
[2008/12/06 01:50:27 | 00,270,128 | —- | M] (BitTorrent, Inc.) – C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent
[2007/05/01 04:03:50 | 00,537,520 | —- | M] ( ) – C:\WINDOWS\system32\lxdccoms.exe:*:Enabled:Lexmark Communications System
[2007/03/06 04:40:25 | 00,020,480 | —- | M] (Lexmark) – C:\Program Files\Lexmark 1300 Series\lxdcamon.exe:*:Enabled:Lexmark Device Monitor
[2007/05/07 19:18:00 | 00,029,616 | —- | M] () – C:\Program Files\Lexmark 1300 Series\App4R.exe:*:Enabled:Lexmark Imaging Studio
[2009/05/11 15:56:29 | 01,085,208 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe
[2009/05/11 16:00:55 | 00,908,568 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe
[2007/05/01 04:04:02 | 00,291,760 | —- | M] () – C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdcpswx.exe:*:Enabled:
[2007/05/01 04:04:07 | 00,398,256 | —- | M] () – C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdcjswx.exe:*:Enabled:
[2007/05/01 04:04:21 | 00,082,864 | —- | M] (Lexmark International, Inc.) – C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdctime.exe:*:Enabled:
File not found – C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
File not found – C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)
[2008/02/01 17:22:12 | 21,898,024 | R— | M] (Skype Technologies S.A.) – C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype
[2008/08/25 18:39:38 | 00,075,048 | —- | M] (SPSS Inc) – C:\Program Files\SPSSInc\Statistics17\statistics.com:*:Disabled:Statistics17:com
[2008/08/25 18:09:06 | 00,087,328 | —- | M] (SPSS Inc) – C:\Program Files\SPSSInc\Statistics17\statistics.exe:*:Disabled:Statistics17:exe
[2008/08/25 18:39:24 | 00,058,664 | —- | M] (SPSS Inc.) – C:\Program Files\SPSSInc\Statistics17\SPSSWinWrapIDE.exe:*:Disabled:SPSS Basic Script Editor

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" = Lexmark Toolbar
"{17283B95-21A8-4996-97DA-547A48DB266F}" = DisplayManager
"{22B63674-C542-4CE0-8016-A1FE3C919B82}" = DVD Power Burner
"{2E6567D5-BCDA-4A7B-855F-687480D0835C}" = Gantt Designer
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{46B65150-F8AA-42F2-94FB-2729A8AE5F7E}" = SPSS Statistics 17.0
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.6
"{6009E11B-1E6D-4B6B-9B68-8D8851955652}" = RealFlightG3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7CCEBC24-62DB-4280-A8EC-BFA49F167920}" = Software Update for Web Folders
"{8D70145A-3BD3-4DBF-9CBF-223EF4A43257}" = ATI Parental Control & Encoder
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{ABB14904-A11B-4F42-996C-80FD608A0F17}" = Samsung EDS
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-1033-F400-7760-000000000004}{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-A70800000002}" = Adobe Reader 7.0.8
"{B18B7901-4025-4BFF-9DA2-BCC45F594DE2}" = Atheros WLAN Client
"{B69F28DF-CBB1-41B7-008A-210E4D0518FC}" = Harry Potter and the Order of the Phoenix™
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BD723E53-A42C-4702-AA04-1D74A0311590}" = Magic Keyboard
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E12DA139-1E5B-46DB-BAEA-683DC9F27CBC}" = ATI Catalyst Control Center
"{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = PC-1100S
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = SENS LT56ADW Modem
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"AVG8Uninstall" = AVG Free 8.5
"Cashflow Plan Free" = Cashflow Plan Free
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2007-02-22
"Download Accelerator Plus (DAP)" = Download Accelerator Plus (DAP)
"ENTERPRISE" = Microsoft Office Enterprise 2007
"HijackThis" = HijackThis 2.0.2
"InstallShield_{22B63674-C542-4CE0-8016-A1FE3C919B82}" = DVD Power Burner
"Lexmark 1300 Series" = Lexmark 1300 Series
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Miranda IM" = Miranda IM 0.7.3
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"RealFlightG3Pro" = RealFlight G3 R/C Simulator
"Reflexive Arcade Games - Card" = Reflexive Arcade Games - Card
"Reflexive Arcade Games - Strategy" = Reflexive Arcade Games - Strategy
"SpeedBit Video Accelerator" = SpeedBit Video Accelerator
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TOEFL Sample Questions" = TOEFL Sample Questions
"UnHackMe_is1" = UnHackMe 4.70 release
"VLC media player" = VideoLAN VLC media player 0.8.6i
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0.0 (Pre-Release 5348)
"xp-AntiSpy" = xp-AntiSpy 3.96-7
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger
"YouTube Downloader 3000_is1" = YouTube Downloader 3000 ver. 1.0.2.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"SpeedyiTunes" = SpeedyiTunes
"uTorrent" = µTorrent

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"SpeedyiTunes" = SpeedyiTunes
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/12/2009 8:19:01 AM | Computer Name = SURFERGIRL | Source = NOSSO® | ID = 0
Description =

Error - 1/12/2009 8:21:05 AM | Computer Name = SURFERGIRL | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 1/12/2009 10:11:20 AM | Computer Name = SURFERGIRL | Source = Application Error | ID = 1000
Description = Faulting application winamp.exe, version 5.5.2.1800, faulting module
ml_bookmarks.dll, version 0.0.0.0, fault address 0x0000125b.

Error - 1/12/2009 12:08:55 PM | Computer Name = SURFERGIRL | Source = Application Error | ID = 1000
Description = Faulting application adobe_updater.exe, version 6.0.2.1471, faulting
module adobe_updater.exe, version 6.0.2.1471, fault address 0x00004a75.

Error - 1/20/2009 12:17:45 AM | Computer Name = SURFERGIRL | Source = Application Error | ID = 1000
Description = Faulting application vlc.exe, version 0.8.6.0, faulting module libvlc.dll,
version 0.0.0.0, fault address 0x0007a615.

Error - 1/20/2009 12:23:51 AM | Computer Name = SURFERGIRL | Source = Application Error | ID = 1000
Description = Faulting application vlc.exe, version 0.8.6.0, faulting module libvlc.dll,
version 0.0.0.0, fault address 0x0007a615.

Error - 1/20/2009 7:23:07 AM | Computer Name = SURFERGIRL | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 1/21/2009 10:09:51 AM | Computer Name = SURFERGIRL | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 1/27/2009 1:48:00 AM | Computer Name = SURFERGIRL | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 1/28/2009 7:42:14 AM | Computer Name = SURFERGIRL | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

[ System Events ]
Error - 6/21/2009 12:06:35 PM | Computer Name = SURFERGIRL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
ShldDrv

Error - 6/21/2009 1:44:39 PM | Computer Name = SURFERGIRL | Source = Cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 6/21/2009 11:59:08 PM | Computer Name = SURFERGIRL | Source = Service Control Manager | ID = 7023
Description = The Config Support service terminated with the following error: %%126

Error - 6/21/2009 11:59:08 PM | Computer Name = SURFERGIRL | Source = Service Control Manager | ID = 7023
Description = The Universal Time service terminated with the following error: %%126

Error - 6/21/2009 11:59:08 PM | Computer Name = SURFERGIRL | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxdcCATSCustConnectService
service to connect.

Error - 6/21/2009 11:59:08 PM | Computer Name = SURFERGIRL | Source = Service Control Manager | ID = 7023
Description = The Microsoft Network service terminated with the following error:
%%126

Error - 6/21/2009 11:59:08 PM | Computer Name = SURFERGIRL | Source = Service Control Manager | ID = 7000
Description = The lxdcCATSCustConnectService service failed to start due to the
following error: %%1053

Error - 6/21/2009 11:59:08 PM | Computer Name = SURFERGIRL | Source = Service Control Manager | ID = 7000
Description = The Panda Process Protection Driver service failed to start due to
the following error: %%2

Error - 6/21/2009 11:59:08 PM | Computer Name = SURFERGIRL | Source = Service Control Manager | ID = 7000
Description = The Panda Process Protection Service service failed to start due to
the following error: %%3

Error - 6/21/2009 11:59:08 PM | Computer Name = SURFERGIRL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
ShldDrv


< End of report >
Hello.

Sorry for the late reply, I was outstation. I have done as you said and these are the two logs created.
Please advice me further. Thanks a lot!

Regards,
Sandra


OTListIt logfile created on: 6/22/2009 12:03:49 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\sandra\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.10 Mb Total Physical Memory | 384.84 Mb Available Physical Memory | 43.04% Memory free
2.12 Gb Paging File | 1.59 Gb Available in Paging File | 75.26% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 86.04 Gb Total Space | 60.55 Gb Free Space | 70.37% Space Free | Partition Type: NTFS
Drive D: | 4.50 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SURFERGIRL
Current User Name: sandra
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2006/03/28 22:42:44 | 00,405,504 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2006/03/28 22:42:44 | 00,405,504 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\SYSTEM32\Ati2evxx.exe
PRC - [2006/10/15 23:38:20 | 01,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2009/05/11 16:00:51 | 00,298,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2007/05/01 04:03:50 | 00,537,520 | —- | M] ( ) – C:\WINDOWS\system32\lxdccoms.exe
PRC - [2005/08/08 13:54:00 | 00,167,936 | —- | M] () – C:\Program Files\CyberLink\Shared files\RichVideo.exe
PRC - [2009/06/19 23:31:55 | 00,486,680 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2008/08/26 22:04:39 | 00,288,360 | —- | M] (Speedbit Ltd.) – C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe
PRC - [2009/05/11 16:00:56 | 00,594,712 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2009/05/11 16:00:55 | 00,908,568 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2008/08/26 22:04:39 | 00,124,528 | —- | M] (Speedbit Ltd.) – C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorEngine.exe
PRC - [2009/05/11 16:00:58 | 00,692,504 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2004/08/04 06:56:58 | 00,218,112 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\wbem\wmiprvse.exe
PRC - [2006/01/02 18:41:22 | 00,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2006/04/04 16:44:58 | 16,120,832 | R— | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\RTHDCPL.EXE
PRC - [2006/03/28 13:27:16 | 00,634,880 | —- | M] () – C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
PRC - [2006/06/29 12:32:14 | 00,089,541 | R— | M] (Agere Systems) – C:\WINDOWS\AGRSMMSG.exe
PRC - [2005/12/07 13:44:16 | 00,761,947 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2006/05/03 19:22:18 | 00,413,696 | —- | M] (SAMSUNG ELECTRONICS) – C:\Program Files\Samsung\DisplayManager\DisplayManager.exe
PRC - [2008/01/16 06:54:54 | 00,037,376 | —- | M] () – C:\Program Files\Winamp\winampa.exe
PRC - [2005/12/07 22:57:00 | 00,030,208 | —- | M] (Cyberlink Corp.) – C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
PRC - [2006/05/03 19:11:02 | 00,520,192 | —- | M] (SAMSUNG) – C:\Program Files\Samsung\DisplayManager\dmhkcore.exe
PRC - [2005/12/20 14:39:32 | 00,094,208 | —- | M] () – C:\WINDOWS\tsnpstd3.exe
PRC - [2008/02/22 04:25:21 | 00,144,784 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
PRC - [2007/03/06 04:40:25 | 00,020,480 | —- | M] (Lexmark) – C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
PRC - [2009/05/11 16:00:54 | 01,947,928 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2005/09/05 15:55:08 | 00,339,968 | —- | M] () – C:\WINDOWS\vsnpstd3.exe
PRC - [2008/06/12 02:25:18 | 00,037,232 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe
PRC - [2008/06/11 22:43:26 | 00,640,376 | —- | M] (Adobe Systems Inc.) – C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
PRC - [2007/09/17 15:37:22 | 00,228,352 | —- | M] (Greatis Software) – C:\Program Files\UnHackMe\hackmon.exe
PRC - [2008/08/26 20:34:28 | 03,057,152 | —- | M] (Speedbit Ltd.) – C:\Program Files\DAP\DAP.EXE
PRC - [2008/08/26 22:04:39 | 02,799,200 | —- | M] (Speedbit Ltd.) – C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe
PRC - [2008/11/05 21:59:00 | 04,347,120 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2009/04/24 12:38:11 | 00,307,704 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2006/01/02 18:41:22 | 00,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2006/01/02 18:41:22 | 00,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2009/06/21 23:43:34 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\sandra\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/07/25 11:16:40 | 00,034,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2006/03/28 22:42:44 | 00,405,504 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\Ati2evxx.exe – (Ati HotKey Poller [Auto | Running])
SRV - [2009/05/11 16:00:55 | 00,908,568 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe – (avg8emc [Auto | Running])
SRV - [2009/05/11 16:00:51 | 00,298,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe – (avg8wd [Auto | Running])
SRV - File not found – – (cfghgn [Auto | Stopped])
SRV - [2008/07/25 11:17:02 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - File not found – – (dxjnkns [Auto | Stopped])
SRV - File not found – – (flaye [Auto | Stopped])
SRV - [2009/01/12 20:49:43 | 00,651,720 | —- | M] (Macrovision Europe Ltd.) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service [On_Demand | Stopped])
SRV - [2008/07/29 21:10:04 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2004/08/04 06:56:46 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2004/10/22 03:24:18 | 00,073,728 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2008/07/29 19:24:50 | 00,881,664 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2007/05/01 04:04:10 | 00,099,248 | —- | M] () – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdcserv.exe – (lxdcCATSCustConnectService [Auto | Stopped])
SRV - [2007/05/01 04:03:50 | 00,537,520 | —- | M] ( ) – C:\WINDOWS\system32\lxdccoms.exe – (lxdc_device [Auto | Running])
SRV - [2008/07/29 19:16:38 | 00,132,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - File not found – – (NNServ [Auto | Stopped])
SRV - [2006/10/26 19:49:34 | 00,441,136 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
SRV - [2006/10/26 14:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - File not found – – (PavPrSrv [Auto | Stopped])
SRV - [2005/08/08 13:54:00 | 00,167,936 | —- | M] () – C:\Program Files\CyberLink\Shared files\RichVideo.exe – (RichVideo [Auto | Running])
SRV - [2008/08/26 22:04:39 | 00,288,360 | —- | M] (Speedbit Ltd.) – C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe – (VideoAcceleratorService [Auto | Running])
SRV - [2005/10/06 18:12:30 | 00,855,552 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Connect 2\wmccds.exe – (WMConnectCDS [On_Demand | Stopped])
SRV - [2006/05/09 21:03:00 | 00,823,808 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2009/03/13 13:29:13 | 00,016,855 | —- | M] (An Chen Computer Co., Ltd.) – C:\WINDOWS\system32\Drivers\Achernar.sys – (Achernar [Boot | Running])
DRV - [2006/06/29 12:13:08 | 01,160,320 | R— | M] (Agere Systems) – C:\WINDOWS\system32\DRIVERS\AGRSM.sys – (AgereSoftModem [On_Demand | Running])
DRV - [2009/03/13 13:29:13 | 00,021,808 | —- | M] (An Chen Computer Co., Ltd.) – C:\WINDOWS\system32\Drivers\Aldebaran.sys – (Aldebaran [On_Demand | Running])
DRV - [2006/03/28 22:50:14 | 01,522,688 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys – (ati2mtag [On_Demand | Running])
DRV - [2009/05/11 16:00:59 | 00,325,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86 [System | Running])
DRV - [2009/05/11 16:00:59 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86 [System | Running])
DRV - [2009/05/11 16:00:56 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX [System | Running])
DRV - [2006/03/29 12:59:12 | 00,027,648 | —- | M] (Samsung Electronics,.LTD) – C:\WINDOWS\system32\drivers\SamsungEDS.sys – (DNSeFilter [On_Demand | Running])
DRV - [2006/10/15 23:38:24 | 00,138,752 | —- | M] (Windows ® Server 2003 DDK provider) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys – (HDAudBus [On_Demand | Running])
DRV - [2006/04/06 13:20:44 | 04,258,816 | R— | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService [On_Demand | Running])
DRV - [2009/05/10 12:10:00 | 00,030,946 | —- | M] (Greatis Software) – C:\WINDOWS\system32\drivers\Partizan.sys – (Partizan [Boot | Stopped])
DRV - [2001/08/23 20:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\system32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2007/03/08 07:51:00 | 00,043,528 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2005/11/16 20:28:32 | 00,028,928 | —- | M] (REDC) – C:\WINDOWS\system32\DRIVERS\rimmptsk.sys – (rimmptsk [On_Demand | Running])
DRV - [2005/11/01 17:54:50 | 00,051,584 | —- | M] (REDC) – C:\WINDOWS\system32\DRIVERS\rimsptsk.sys – (rimsptsk [On_Demand | Running])
DRV - [2005/11/01 18:08:00 | 00,308,992 | —- | M] (REDC) – C:\WINDOWS\system32\DRIVERS\rixdptsk.sys – (rismxdp [On_Demand | Running])
DRV - [2006/01/18 17:41:58 | 00,080,512 | R— | M] (Realtek Semiconductor Corporation ) – C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys – (RTL8023xp [On_Demand | Running])
DRV - [2004/08/04 06:31:34 | 00,020,992 | —- | M] (Realtek Semiconductor Corporation) – C:\WINDOWS\system32\DRIVERS\RTL8139.SYS – (rtl8139 [On_Demand | Stopped])
DRV - [2008/08/26 22:04:40 | 00,035,968 | —- | M] (SpeedBit Ltd.) – C:\Program Files\SpeedBit Video Accelerator\sbbotdi.sys – (sbbotdi [Auto | Running])
DRV - [2006/10/15 23:39:23 | 00,163,644 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\system32\DRIVERS\secdrv.sys – (Secdrv [Auto | Running])
DRV - [2006/04/18 15:25:36 | 08,532,864 | —- | M] (Sonix Co. Ltd.) – C:\WINDOWS\system32\DRIVERS\snpstd3.sys – (SNPSTD3 [On_Demand | Stopped])
DRV - [2006/01/16 10:15:24 | 00,470,112 | —- | M] (Atheros Communications, Inc.) – C:\WINDOWS\system32\DRIVERS\SSB2413.sys – (SSB2413 [On_Demand | Running])
DRV - [2005/12/07 13:30:52 | 00,191,936 | —- | M] (Synaptics, Inc.) – C:\WINDOWS\system32\DRIVERS\SynTP.sys – (SynTP [On_Demand | Running])
DRV - [2004/08/03 23:07:56 | 00,059,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\usbaudio.sys – (usbaudio [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar;=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar;=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes

IE - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.microsoft.com/isapi/redir.dll?P…pdate&O1;=b1
IE - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…&ar;=msnhome
IE - HKU\S-1-5-21-839522115-1417001333-682003330-1003\S-1-5-21-839522115-1417001333-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1
FF - prefs.js..extensions.enabledItems: {F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}:[removed]
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090123.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX [2009/05/12 08:28:00 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/05/09 16:09:04 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/09 21:01:33 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/05/03 17:48:05 | 00,000,000 | —D | M]

[2008/09/15 18:15:32 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Extensions
[2008/09/15 18:15:32 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/06/21 23:22:49 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Firefox\Profiles\7vxwuliu.default\extensions
[2008/02/28 21:47:08 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Firefox\Profiles\7vxwuliu.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/05/09 17:16:24 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Firefox\Profiles\7vxwuliu.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2008/01/21 15:05:38 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Firefox\Profiles\7vxwuliu.default\extensions\[removed]
[2009/04/22 22:52:34 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Firefox\Profiles\7vxwuliu.default\extensions\[removed]
[2009/06/21 23:22:49 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/05/03 17:48:06 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/05/23 15:21:25 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{AF8637B0-18E3-44D3-86B7-55E09D9C4261}
[2008/03/30 23:12:37 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2009/04/24 12:38:30 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/24 12:38:32 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/24 08:39:08 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/24 08:39:08 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/24 08:39:08 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/24 08:39:08 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/24 08:39:08 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/24 08:39:08 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/24 08:39:08 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (698 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-839522115-1417001333-682003330-1003\..\Toolbar\WebBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKU\S-1-5-21-839522115-1417001333-682003330-1003\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AGRSMMSG] AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [Alcmtr] ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay (ATI Technologies Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DisplayManager] C:\Program Files\Samsung\DisplayManager\DisplayManager.exe (SAMSUNG ELECTRONICS)
O4 - HKLM..\Run: [DMHotKey] C:\Program Files\Samsung\DisplayManager\DMLoader.exe (SAMSUNG)
O4 - HKLM..\Run: [EDS] C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe ()
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" ()
O4 - HKLM..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe" (Lexmark)
O4 - HKLM..\Run: [lxdcmon.exe] "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe" File not found
O4 - HKLM..\Run: [MagicKeyboard] C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe ()
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" ()
O4 - HKU\S-1-5-21-839522115-1417001333-682003330-1003..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP (Speedbit Ltd.)
O4 - HKU\S-1-5-21-839522115-1417001333-682003330-1003..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.)
O4 - HKU\S-1-5-21-839522115-1417001333-682003330-1003..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background File not found
O4 - HKU\S-1-5-21-839522115-1417001333-682003330-1003..\Run: [SpeedBitVideoAccelerator] C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe (Speedbit Ltd.)
O4 - HKU\S-1-5-21-839522115-1417001333-682003330-1003..\Run: [UnHackMe Monitor] C:\Program Files\UnHackMe\hackmon.exe (Greatis Software)
O4 - HKU\S-1-5-21-839522115-1417001333-682003330-1003..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 (Adobe Systems Incorporated)
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - HKLM..\RunOnceEx: [Title] UnHackMe Rootkit Check File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRun = 0
O7 - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKU\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: &Clean; Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm ()
O8 - Extra context menu item: &Download; with &DAP; - C:\Program Files\DAP\dapextie.htm ()
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Download &all; with DAP - C:\Program Files\DAP\dapextie2.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1207410961515 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\SYSTEM32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\SYSTEM32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/01/17 14:12:28 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{0735350c-83a7-11dd-b712-001377316941}\Shell\AutoRun\command - "" = RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\win32.exe
O33 - MountPoints2\{0735350c-83a7-11dd-b712-001377316941}\Shell\open\command - "" = RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\win32.exe
O33 - MountPoints2\{0735350e-83a7-11dd-b712-001377316941}\Shell - "" = AutoRun
O33 - MountPoints2\{0735350e-83a7-11dd-b712-001377316941}\Shell\Auto\command - "" = E:\MicrosoftPowerPoint.exe – File not found
O33 - MountPoints2\{0735350e-83a7-11dd-b712-001377316941}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{0a1a0d86-078a-11dd-b617-001377316941}\Shell - "" = AutoRun
O33 - MountPoints2\{0a1a0d86-078a-11dd-b617-001377316941}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{0a1a0d86-078a-11dd-b617-001377316941}\Shell\explore\Command - "" = E:\data.exe – File not found
O33 - MountPoints2\{0a1a0d86-078a-11dd-b617-001377316941}\Shell\open\Command - "" = E:\data.exe – File not found
O33 - MountPoints2\{7b1c7458-0e30-11de-8804-001377316941}\Shell\Auto\command - "" = E:\RavMonE.exe – File not found
O33 - MountPoints2\{7b1c7458-0e30-11de-8804-001377316941}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{8b1f23f2-f568-11dc-b5d0-001377316941}\Shell - "" = AutoRun
O33 - MountPoints2\{8b1f23f2-f568-11dc-b5d0-001377316941}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{8b1f23f2-f568-11dc-b5d0-001377316941}\Shell\explore\Command - "" = data.exe -e
O33 - MountPoints2\{8b1f23f2-f568-11dc-b5d0-001377316941}\Shell\open\Command - "" = data.exe
O33 - MountPoints2\{97c03c2e-c58e-11dd-b772-001377316941}\Shell\AutoRun\command - "" = wscript.exe VirusRemoval.vbs
O33 - MountPoints2\{97c03c2e-c58e-11dd-b772-001377316941}\Shell\open\Command - "" = wscript.exe VirusRemoval.vbs
O33 - MountPoints2\{9cb55fcc-db9f-11dc-b591-001377316941}\Shell - "" = AutoRun
O33 - MountPoints2\{9cb55fcc-db9f-11dc-b591-001377316941}\Shell\Auto\command - "" = E:\MicrosoftPowerPoint.exe – File not found
O33 - MountPoints2\{9cb55fcc-db9f-11dc-b591-001377316941}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{a07ba4ce-1148-11de-880a-001377316941}\Shell\Auto\command - "" = E:\RavMonE.exe – File not found
O33 - MountPoints2\{a07ba4ce-1148-11de-880a-001377316941}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{a9b2108f-ab1b-11dd-b760-001377316941}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\win32.exe – File not found
O33 - MountPoints2\{a9b2108f-ab1b-11dd-b760-001377316941}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\win32.exe – File not found
O33 - MountPoints2\{adeceddf-c724-11dd-b777-001377316941}\Shell - "" = AutoRun
O33 - MountPoints2\{adeceddf-c724-11dd-b777-001377316941}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{adeceddf-c724-11dd-b777-001377316941}\Shell\AutoRun\command - "" = E:\AutoRun.exe – File not found
O33 - MountPoints2\{adecede1-c724-11dd-b777-001377316941}\Shell - "" = AutoRun
O33 - MountPoints2\{adecede1-c724-11dd-b777-001377316941}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{adecede1-c724-11dd-b777-001377316941}\Shell\AutoRun\command - "" = E:\AutoRun.exe – File not found
O33 - MountPoints2\{c15fd5f6-cfc5-11dc-b58c-001377316941}\Shell\AutoRun\command - "" = E:\SYSTEM\G-923-321232-3232-32211-23\driver.exe – File not found
O33 - MountPoints2\{c15fd5f6-cfc5-11dc-b58c-001377316941}\Shell\open\command - "" = E:\SYSTEM\G-923-321232-3232-32211-23\driver.exe – File not found
O33 - MountPoints2\{d82afc38-aafe-11dd-b75f-001377316941}\Shell\AutoRun\command - "" = E:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\win32.exe – File not found
O33 - MountPoints2\{d82afc38-aafe-11dd-b75f-001377316941}\Shell\open\command - "" = E:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\win32.exe – File not found
O33 - MountPoints2\{e2019ea6-c8e6-11dc-b586-001377316941}\Shell\AutoRun\command - "" = RECYCLER\k-1-3542-4232123213-7676767-8888886\root.exe
O33 - MountPoints2\{e2019ea6-c8e6-11dc-b586-001377316941}\Shell\open\command - "" = RECYCLER\k-1-3542-4232123213-7676767-8888886\root.exe
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/06/21 23:44:03 | 00,000,000 | —D | M]
O34 - HKLM BootExecute: (Partizan) - C:\WINDOWS\System32\Partizan.exe (Greatis Software)
O34 - HKLM BootExecute: (ootExecute) - File not found
O34 - HKLM BootExecute: (settings…) - File not found
O34 - HKLM BootExecute: (on\E) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/06/21 23:40:52 | 00,000,000 | —D | C] – C:\Documents and Settings\sandra\Desktop\HostsXpert
[2009/06/21 23:36:07 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\sandra\Desktop\OTListIt2.exe
[2009/06/21 23:35:28 | 00,353,485 | —- | C] () – C:\Documents and Settings\sandra\Desktop\HostsXpert.zip
[2009/06/18 23:49:45 | 00,060,416 | —- | C] () – C:\Documents and Settings\sandra\Desktop\Database new.xls
[2009/06/16 22:56:16 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2009/06/16 22:56:10 | 00,000,000 | —D | C] – C:\Program Files\Security Task Manager
[2009/04/30 21:12:15 | 00,001,024 | —- | C] () – C:\WINDOWS\System32\grcauth2.dll
[2009/04/30 21:12:15 | 00,001,024 | —- | C] () – C:\WINDOWS\System32\grcauth1.dll
[2009/04/30 21:12:15 | 00,000,100 | —- | C] () – C:\WINDOWS\System32\prsgrc.dll
[2009/04/30 21:07:50 | 00,001,025 | —- | C] () – C:\WINDOWS\System32\sysprs7.dll
[2009/04/30 21:07:50 | 00,000,205 | —- | C] () – C:\WINDOWS\System32\lsprst7.dll
[2009/02/18 22:04:07 | 00,000,109 | —- | C] () – C:\WINDOWS\RealFlight.INI
[2009/02/18 21:51:56 | 00,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2009/02/18 15:19:46 | 00,000,265 | —- | C] () – C:\WINDOWS\emug3.ini
[2008/06/04 08:57:38 | 00,290,816 | —- | C] () – C:\WINDOWS\System32\XDogcat.dll
[2008/05/23 16:12:53 | 00,000,713 | -HS- | C] () – C:\WINDOWS\System32\qrutv.ini2
[2008/05/23 16:03:34 | 00,077,312 | —- | C] () – C:\WINDOWS\System32\ztvunace26.dll
[2008/05/23 16:03:33 | 00,162,304 | —- | C] () – C:\WINDOWS\System32\ztvunrar36.dll
[2008/05/23 16:03:33 | 00,153,088 | —- | C] () – C:\WINDOWS\System32\unrar3.dll
[2008/05/23 16:03:33 | 00,075,264 | —- | C] () – C:\WINDOWS\System32\unacev2.dll
[2008/05/23 15:57:48 | 00,000,713 | -HS- | C] () – C:\WINDOWS\System32\qrutv.ini
[2008/05/23 15:17:14 | 00,039,424 | —- | C] () – C:\WINDOWS\System32\fccywxy.dll.vir
[2008/05/17 19:55:40 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\lxdcvs.dll
[2008/05/17 19:55:37 | 00,344,064 | —- | C] () – C:\WINDOWS\System32\lxdccoin.dll
[2008/05/17 19:50:15 | 00,000,044 | —- | C] () – C:\WINDOWS\System32\lxdcrwrd.ini
[2008/05/17 19:49:44 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\LXDCinst.dll
[2008/05/17 19:49:43 | 00,413,696 | —- | C] ( ) – C:\WINDOWS\System32\lxdcinpa.dll
[2008/05/17 19:49:43 | 00,323,584 | —- | C] ( ) – C:\WINDOWS\System32\LXDChcp.dll
[2008/05/17 19:49:42 | 01,232,896 | —- | C] ( ) – C:\WINDOWS\System32\lxdcserv.dll
[2008/05/17 19:49:42 | 00,999,424 | —- | C] ( ) – C:\WINDOWS\System32\lxdcusb1.dll
[2008/05/17 19:49:42 | 00,397,312 | —- | C] ( ) – C:\WINDOWS\System32\lxdciesc.dll
[2008/05/17 19:49:41 | 00,643,072 | —- | C] ( ) – C:\WINDOWS\System32\lxdcpmui.dll
[2008/05/17 19:49:41 | 00,585,728 | —- | C] ( ) – C:\WINDOWS\System32\lxdclmpm.dll
[2008/05/17 19:49:41 | 00,163,840 | —- | C] ( ) – C:\WINDOWS\System32\lxdcprox.dll
[2008/05/17 19:49:41 | 00,094,208 | —- | C] ( ) – C:\WINDOWS\System32\lxdcpplc.dll
[2008/05/17 19:49:40 | 00,700,416 | —- | C] ( ) – C:\WINDOWS\System32\lxdchbn3.dll
[2008/05/17 19:49:40 | 00,208,896 | —- | C] () – C:\WINDOWS\System32\lxdcgrd.dll
[2008/05/17 19:49:39 | 00,684,032 | —- | C] ( ) – C:\WINDOWS\System32\lxdccomc.dll
[2008/05/17 19:49:39 | 00,425,984 | —- | C] ( ) – C:\WINDOWS\System32\lxdccomm.dll
[2008/03/27 19:46:44 | 01,537,735 | -HS- | C] () – C:\WINDOWS\System32\awilncfr.ini
[2008/03/26 19:47:08 | 01,587,085 | -HS- | C] () – C:\WINDOWS\System32\knmdbwjh.ini
[2008/03/25 23:29:30 | 01,578,421 | -HS- | C] () – C:\WINDOWS\System32\paldhxfa.ini
[2008/03/24 23:28:09 | 01,578,121 | -HS- | C] () – C:\WINDOWS\System32\geodexbj.ini
[2008/03/23 23:27:03 | 01,217,859 | -HS- | C] () – C:\WINDOWS\System32\dbwxjjrh.ini
[2008/03/22 23:26:32 | 01,270,400 | -HS- | C] () – C:\WINDOWS\System32\slotpvjw.ini
[2008/03/21 19:27:59 | 01,382,987 | -HS- | C] () – C:\WINDOWS\System32\uqedluxv.ini
[2008/03/20 18:13:41 | 01,624,124 | -HS- | C] () – C:\WINDOWS\System32\vodpxbwd.ini
[2008/03/19 17:07:04 | 01,413,952 | -HS- | C] () – C:\WINDOWS\System32\udquiolm.ini
[2008/03/18 15:47:50 | 01,928,200 | -HS- | C] () – C:\WINDOWS\System32\wibdblai.ini
[2008/03/14 12:32:58 | 01,409,307 | -HS- | C] () – C:\WINDOWS\System32\ahwtqhvu.ini
[2008/03/13 19:50:41 | 01,235,367 | -HS- | C] () – C:\WINDOWS\System32\fafokiyg.ini
[2008/03/12 15:48:40 | 01,214,015 | -HS- | C] () – C:\WINDOWS\System32\jagygtnr.ini
[2008/03/10 19:42:29 | 01,201,641 | -HS- | C] () – C:\WINDOWS\System32\axdxnegv.ini
[2008/03/09 19:41:24 | 01,269,267 | -HS- | C] () – C:\WINDOWS\System32\grrvmptc.ini
[2008/03/08 19:41:46 | 01,237,113 | -HS- | C] () – C:\WINDOWS\System32\rkybghgo.ini
[2008/03/06 19:28:44 | 01,236,319 | -HS- | C] () – C:\WINDOWS\System32\kvrqfsvj.ini
[2008/03/06 19:19:35 | 00,000,396 | —- | C] () – C:\WINDOWS\System32\ibfauufn.dll
[2008/03/05 19:26:37 | 01,302,346 | -HS- | C] () – C:\WINDOWS\System32\txohdmpb.ini
[2008/03/05 19:20:34 | 00,000,396 | —- | C] () – C:\WINDOWS\System32\bdmljolu.dll
[2008/03/04 19:23:02 | 00,000,048 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/03/04 19:23:01 | 01,303,628 | -HS- | C] () – C:\WINDOWS\System32\okhscrlv.ini
[2008/03/04 19:22:50 | 00,000,396 | —- | C] () – C:\WINDOWS\System32\kqspqvdd.dll
[2008/03/04 19:16:51 | 00,000,396 | —- | C] () – C:\WINDOWS\System32\eeymnsxk.dll
[2008/02/29 17:34:26 | 00,000,396 | —- | C] () – C:\WINDOWS\System32\cdwnbqfa.dll
[2008/02/27 22:08:21 | 01,246,961 | -HS- | C] () – C:\WINDOWS\System32\jyqahwit.ini
[2008/02/27 22:02:11 | 00,000,396 | —- | C] () – C:\WINDOWS\System32\nqcmqkkn.dll
[2008/02/26 21:58:56 | 00,185,519 | -HS- | C] () – C:\WINDOWS\System32\prutv.ini2
[2008/02/26 21:58:54 | 00,185,519 | -HS- | C] () – C:\WINDOWS\System32\prutv.ini
[2008/02/20 20:09:42 | 00,168,220 | -HS- | C] () – C:\WINDOWS\System32\ehhkj.ini2
[2008/02/20 20:09:42 | 00,168,220 | -HS- | C] () – C:\WINDOWS\System32\ehhkj.ini
[2008/02/19 19:46:52 | 00,015,498 | —- | C] () – C:\WINDOWS\snpstd3.ini
[2008/02/19 19:46:47 | 00,053,248 | —- | C] ( ) – C:\WINDOWS\vsnpstd3.dll
[2008/02/19 19:46:46 | 00,147,456 | —- | C] ( ) – C:\WINDOWS\System32\rsnpstd3.dll
[2008/02/19 19:46:46 | 00,053,248 | —- | C] ( ) – C:\WINDOWS\System32\csnpstd3.dll
[2008/02/17 15:51:20 | 00,167,017 | -HS- | C] () – C:\WINDOWS\System32\qqstv.ini2
[2008/02/17 15:51:19 | 00,167,017 | -HS- | C] () – C:\WINDOWS\System32\qqstv.ini
[2008/01/29 21:43:08 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2008/01/17 14:45:34 | 00,000,135 | R— | C] () – C:\WINDOWS\System32\lngEng.ini
[2008/01/17 14:45:34 | 00,000,117 | —- | C] () – C:\WINDOWS\System32\lngKor.ini
[2008/01/17 14:39:12 | 00,001,697 | —- | C] () – C:\WINDOWS\System32\sandra_KBD.ini
[2008/01/17 14:39:12 | 00,001,697 | —- | C] () – C:\WINDOWS\System32\MagicKBD.INI
[2008/01/17 14:39:10 | 00,003,425 | —- | C] () – C:\WINDOWS\System32\KBDR.INI
[2008/01/17 14:39:10 | 00,002,741 | —- | C] () – C:\WINDOWS\System32\KBDD.INI
[2008/01/17 14:39:10 | 00,002,699 | —- | C] () – C:\WINDOWS\System32\KBDO.INI
[2008/01/17 14:39:10 | 00,002,699 | —- | C] () – C:\WINDOWS\System32\KBDC.INI
[2008/01/17 14:39:10 | 00,002,606 | —- | C] () – C:\WINDOWS\System32\KBDB.INI
[2008/01/17 14:39:10 | 00,002,236 | —- | C] () – C:\WINDOWS\System32\KBDQ.INI
[2008/01/17 14:39:10 | 00,001,956 | —- | C] () – C:\WINDOWS\System32\KBDE.INI
[2008/01/17 14:39:10 | 00,001,885 | —- | C] () – C:\WINDOWS\System32\KBDP.INI
[2008/01/17 14:39:10 | 00,001,857 | —- | C] () – C:\WINDOWS\System32\KBDUU.INI
[2008/01/17 14:39:10 | 00,001,835 | —- | C] () – C:\WINDOWS\System32\KBDG.INI
[2008/01/17 14:39:10 | 00,001,835 | —- | C] () – C:\WINDOWS\System32\KBDA.INI
[2008/01/17 14:39:10 | 00,001,834 | —- | C] () – C:\WINDOWS\System32\KBDU.INI
[2008/01/17 14:39:10 | 00,001,819 | —- | C] () – C:\WINDOWS\System32\KBDN.INI
[2008/01/17 14:39:10 | 00,001,699 | —- | C] () – C:\WINDOWS\System32\KBDT.INI
[2008/01/17 14:39:10 | 00,001,697 | —- | C] () – C:\WINDOWS\System32\KBDV.INI
[2008/01/17 14:39:10 | 00,001,522 | —- | C] () – C:\WINDOWS\System32\KBDS.INI
[2008/01/17 14:39:10 | 00,001,476 | —- | C] () – C:\WINDOWS\System32\KBDF.INI
[2008/01/17 14:38:54 | 00,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2008/01/17 14:36:42 | 00,135,168 | R— | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2007/03/12 11:41:52 | 00,061,440 | —- | C] ( ) – C:\WINDOWS\System32\vsnpstd3.dll
[2004/08/04 06:56:44 | 00,081,920 | —- | C] () – C:\WINDOWS\System32\ieencode.dll
[2001/08/23 20:00:00 | 00,000,817 | —- | C] () – C:\WINDOWS\win.ini
[2001/08/23 20:00:00 | 00,000,231 | —- | C] () – C:\WINDOWS\system.ini

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[5 C:\WINDOWS\System32\*.tmp files]
[6 C:\WINDOWS\*.tmp files]
[2009/06/22 12:00:13 | 36,325,133 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/06/22 11:57:42 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\sandra\Local Settings\desktop.ini
[2009/06/22 11:57:41 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/06/22 11:57:39 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/06/22 00:05:20 | 00,004,732 | —- | M] () – C:\WINDOWS\System32\ProxyServer.bak
[2009/06/22 00:05:03 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/06/22 00:05:03 | 00,000,499 | —- | M] () – C:\WINDOWS\System32\CommPipe.bak
[2009/06/22 00:05:03 | 00,000,390 | —- | M] () – C:\WINDOWS\System32\SbLsp.bak
[2009/06/21 23:43:34 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\sandra\Desktop\OTListIt2.exe
[2009/06/21 23:35:35 | 00,353,485 | —- | M] () – C:\Documents and Settings\sandra\Desktop\HostsXpert.zip
[2009/06/21 23:12:37 | 00,058,917 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/06/18 23:49:47 | 00,060,416 | —- | M] () – C:\Documents and Settings\sandra\Desktop\Database new.xls

========== Alternate Data Streams ==========

@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0F8F5844
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5BB923A2
< End of report >


OTListIt Extras logfile created on: 6/22/2009 12:03:49 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\sandra\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.10 Mb Total Physical Memory | 384.84 Mb Available Physical Memory | 43.04% Memory free
2.12 Gb Paging File | 1.59 Gb Available in Paging File | 75.26% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 86.04 Gb Total Space | 60.55 Gb Free Space | 70.37% Space Free | Partition Type: NTFS
Drive D: | 4.50 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SURFERGIRL
Current User Name: sandra
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
"DisableMonitoring" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
"DisableMonitoring" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Connect
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Connect
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Connect
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Connect
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Connect
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Connect

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Connect
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Connect
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Connect
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Connect
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Connect
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Connect
"9420:TCP" = 9420:TCP:*:Enabled:Akamai Network Manager
"5000:UDP" = 5000:UDP:*:Enabled:Akamai Network Manager
"14478:TCP" = 14478:TCP:*:Enabled:NortonAV
"12830:TCP" = 12830:TCP:*:Enabled:NortonAV
"18882:TCP" = 18882:TCP:*:Enabled:NortonAV
"15474:TCP" = 15474:TCP:*:Enabled:NortonAV
"16253:TCP" = 16253:TCP:*:Enabled:NortonAV
"17278:TCP" = 17278:TCP:*:Enabled:NortonAV
"12140:TCP" = 12140:TCP:*:Enabled:NortonAV
"14498:TCP" = 14498:TCP:*:Enabled:NortonAV
"13748:TCP" = 13748:TCP:*:Enabled:NortonAV

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2006/10/15 23:39:56 | 00,557,568 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2007/05/07 19:18:00 | 00,029,616 | —- | M] () – C:\Program Files\Lexmark 1300 Series\App4R.exe:*:Enabled:Lexmark Imaging Studio
File not found – C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
File not found – C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2006/10/15 23:39:56 | 00,557,568 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2007/11/13 03:02:18 | 00,551,508 | —- | M] ( ) – C:\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM
[2008/12/06 01:50:27 | 00,270,128 | —- | M] (BitTorrent, Inc.) – C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent
[2007/05/01 04:03:50 | 00,537,520 | —- | M] ( ) – C:\WINDOWS\system32\lxdccoms.exe:*:Enabled:Lexmark Communications System
[2007/03/06 04:40:25 | 00,020,480 | —- | M] (Lexmark) – C:\Program Files\Lexmark 1300 Series\lxdcamon.exe:*:Enabled:Lexmark Device Monitor
[2007/05/07 19:18:00 | 00,029,616 | —- | M] () – C:\Program Files\Lexmark 1300 Series\App4R.exe:*:Enabled:Lexmark Imaging Studio
[2009/05/11 15:56:29 | 01,085,208 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe
[2009/05/11 16:00:55 | 00,908,568 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe
[2007/05/01 04:04:02 | 00,291,760 | —- | M] () – C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdcpswx.exe:*:Enabled:
[2007/05/01 04:04:07 | 00,398,256 | —- | M] () – C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdcjswx.exe:*:Enabled:
[2007/05/01 04:04:21 | 00,082,864 | —- | M] (Lexmark International, Inc.) – C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdctime.exe:*:Enabled:
File not found – C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
File not found – C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)
[2008/02/01 17:22:12 | 21,898,024 | R— | M] (Skype Technologies S.A.) – C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype
[2008/08/25 18:39:38 | 00,075,048 | —- | M] (SPSS Inc) – C:\Program Files\SPSSInc\Statistics17\statistics.com:*:Disabled:Statistics17:com
[2008/08/25 18:09:06 | 00,087,328 | —- | M] (SPSS Inc) – C:\Program Files\SPSSInc\Statistics17\statistics.exe:*:Disabled:Statistics17:exe
[2008/08/25 18:39:24 | 00,058,664 | —- | M] (SPSS Inc.) – C:\Program Files\SPSSInc\Statistics17\SPSSWinWrapIDE.exe:*:Disabled:SPSS Basic Script Editor

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" = Lexmark Toolbar
"{17283B95-21A8-4996-97DA-547A48DB266F}" = DisplayManager
"{22B63674-C542-4CE0-8016-A1FE3C919B82}" = DVD Power Burner
"{2E6567D5-BCDA-4A7B-855F-687480D0835C}" = Gantt Designer
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{46B65150-F8AA-42F2-94FB-2729A8AE5F7E}" = SPSS Statistics 17.0
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.6
"{6009E11B-1E6D-4B6B-9B68-8D8851955652}" = RealFlightG3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7CCEBC24-62DB-4280-A8EC-BFA49F167920}" = Software Update for Web Folders
"{8D70145A-3BD3-4DBF-9CBF-223EF4A43257}" = ATI Parental Control & Encoder
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{ABB14904-A11B-4F42-996C-80FD608A0F17}" = Samsung EDS
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-1033-F400-7760-000000000004}{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-A70800000002}" = Adobe Reader 7.0.8
"{B18B7901-4025-4BFF-9DA2-BCC45F594DE2}" = Atheros WLAN Client
"{B69F28DF-CBB1-41B7-008A-210E4D0518FC}" = Harry Potter and the Order of the Phoenix™
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BD723E53-A42C-4702-AA04-1D74A0311590}" = Magic Keyboard
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E12DA139-1E5B-46DB-BAEA-683DC9F27CBC}" = ATI Catalyst Control Center
"{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = PC-1100S
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = SENS LT56ADW Modem
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"AVG8Uninstall" = AVG Free 8.5
"Cashflow Plan Free" = Cashflow Plan Free
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2007-02-22
"Download Accelerator Plus (DAP)" = Download Accelerator Plus (DAP)
"ENTERPRISE" = Microsoft Office Enterprise 2007
"HijackThis" = HijackThis 2.0.2
"InstallShield_{22B63674-C542-4CE0-8016-A1FE3C919B82}" = DVD Power Burner
"Lexmark 1300 Series" = Lexmark 1300 Series
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Miranda IM" = Miranda IM 0.7.3
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"RealFlightG3Pro" = RealFlight G3 R/C Simulator
"Reflexive Arcade Games - Card" = Reflexive Arcade Games - Card
"Reflexive Arcade Games - Strategy" = Reflexive Arcade Games - Strategy
"SpeedBit Video Accelerator" = SpeedBit Video Accelerator
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TOEFL Sample Questions" = TOEFL Sample Questions
"UnHackMe_is1" = UnHackMe 4.70 release
"VLC media player" = VideoLAN VLC media player 0.8.6i
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0.0 (Pre-Release 5348)
"xp-AntiSpy" = xp-AntiSpy 3.96-7
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger
"YouTube Downloader 3000_is1" = YouTube Downloader 3000 ver. 1.0.2.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"SpeedyiTunes" = SpeedyiTunes
"uTorrent" = µTorrent

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-839522115-1417001333-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"SpeedyiTunes" = SpeedyiTunes
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/12/2009 8:19:01 AM | Computer Name = SURFERGIRL | Source = NOSSO® | ID = 0
Description =

Error - 1/12/2009 8:21:05 AM | Computer Name = SURFERGIRL | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 1/12/2009 10:11:20 AM | Computer Name = SURFERGIRL | Source = Application Error | ID = 1000
Description = Faulting application winamp.exe, version 5.5.2.1800, faulting module
ml_bookmarks.dll, version 0.0.0.0, fault address 0x0000125b.

Error - 1/12/2009 12:08:55 PM | Computer Name = SURFERGIRL | Source = Application Error | ID = 1000
Description = Faulting application adobe_updater.exe, version 6.0.2.1471, faulting
module adobe_updater.exe, version 6.0.2.1471, fault address 0x00004a75.

Error - 1/20/2009 12:17:45 AM | Computer Name = SURFERGIRL | Source = Application Error | ID = 1000
Description = Faulting application vlc.exe, version 0.8.6.0, faulting module libvlc.dll,
version 0.0.0.0, fault address 0x0007a615.

Error - 1/20/2009 12:23:51 AM | Computer Name = SURFERGIRL | Source = Application Error | ID = 1000
Description = Faulting application vlc.exe, version 0.8.6.0, faulting module libvlc.dll,
version 0.0.0.0, fault address 0x0007a615.

Error - 1/20/2009 7:23:07 AM | Computer Name = SURFERGIRL | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 1/21/2009 10:09:51 AM | Computer Name = SURFERGIRL | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 1/27/2009 1:48:00 AM | Computer Name = SURFERGIRL | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 1/28/2009 7:42:14 AM | Computer Name = SURFERGIRL | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

[ System Events ]
Error - 6/21/2009 12:06:35 PM | Computer Name = SURFERGIRL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
ShldDrv

Error - 6/21/2009 1:44:39 PM | Computer Name = SURFERGIRL | Source = Cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 6/21/2009 11:59:08 PM | Computer Name = SURFERGIRL | Source = Service Control Manager | ID = 7023
Description = The Config Support service terminated with the following error: %%126

Error - 6/21/2009 11:59:08 PM | Computer Name = SURFERGIRL | Source = Service Control Manager | ID = 7023
Description = The Universal Time service terminated with the following error: %%126

Error - 6/21/2009 11:59:08 PM | Computer Name = SURFERGIRL | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxdcCATSCustConnectService
service to connect.

Error - 6/21/2009 11:59:08 PM | Computer Name = SURFERGIRL | Source = Service Control Manager | ID = 7023
Description = The Microsoft Network service terminated with the following error:
%%126

Error - 6/21/2009 11:59:08 PM | Computer Name = SURFERGIRL | Source = Service Control Manager | ID = 7000
Description = The lxdcCATSCustConnectService service failed to start due to the
following error: %%1053

Error - 6/21/2009 11:59:08 PM | Computer Name = SURFERGIRL | Source = Service Control Manager | ID = 7000
Description = The Panda Process Protection Driver service failed to start due to
the following error: %%2

Error - 6/21/2009 11:59:08 PM | Computer Name = SURFERGIRL | Source = Service Control Manager | ID = 7000
Description = The Panda Process Protection Service service failed to start due to
the following error: %%3

Error - 6/21/2009 11:59:08 PM | Computer Name = SURFERGIRL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
ShldDrv


< End of report >
Hello.

You have an awful a lot of stuff in your machine. I see several infections. One of them seems to be "partially" done.

Please do the following:

Install Recovery Console and Run ComboFix

Note to readers of this post other than the starter of this thread:
ComboFix is a VERY POWERFUL tool which should NOT BE USED without guidance of an expert.

Please download Combofix from any of the links below, and save it to your desktop.

Link 1
Link 2
Link 3

  • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
  • Close any open windows, including this one.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • If you did not have it installed, you will see the prompt below. Choose YES.
  • [external image: Posted Image]
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Note:The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you
should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.


  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
  • When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).
Leave your computer alone while ComboFix is running.
ComboFix will restart your computer if malware is found; allow it to do so.


Note: Please Do NOT mouseclick combofix's window while its running because it may call it to stall.

Download and Run FlashDisinfector

  • Please download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: Flash_Disinfector will create a hidden file named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.

Post back wtih the Combofix log.

~Extremeboy
Hello.

Here the ComboFix log. The flash disinfector was done with scanning very fast, it took maybe 5sec. Is that normal?

ComboFix 09-05-22.07 - sandra 05/23/2009 18:59.1 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\newdotnet
c:\program files\newdotnet\nncore.dll.vir
c:\program files\newdotnet\nnrun.exe.vir
c:\program files\newdotnet\readme.html
c:\program files\newdotnet\uninstall.exe
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
c:\system\G-923-321232-3232-32211-23
c:\system\G-923-321232-3232-32211-23\Desktop.ini
c:\temp\tn3
c:\windows\BM430fd4d8.txt
c:\windows\BM430fd4d8.xml
c:\windows\system32\ahwtqhvu.ini
c:\windows\system32\awilncfr.ini
c:\windows\system32\axdxnegv.ini
c:\windows\system32\bdmljolu.dll
c:\windows\system32\cdwnbqfa.dll
c:\windows\system32\dbwxjjrh.ini
c:\windows\system32\eeymnsxk.dll
c:\windows\system32\ehhkj.ini
c:\windows\system32\ehhkj.ini2
c:\windows\system32\fafokiyg.ini
c:\windows\system32\geodexbj.ini
c:\windows\system32\grrvmptc.ini
c:\windows\system32\ibfauufn.dll
c:\windows\system32\jagygtnr.ini
c:\windows\system32\jyqahwit.ini
c:\windows\system32\knmdbwjh.ini
c:\windows\system32\kqspqvdd.dll
c:\windows\system32\kvrqfsvj.ini
c:\windows\system32\lsprst7.dll
c:\windows\system32\nqcmqkkn.dll
c:\windows\system32\okhscrlv.ini
c:\windows\system32\paldhxfa.ini
c:\windows\system32\prsgrc.dll
c:\windows\system32\prutv.ini
c:\windows\system32\prutv.ini2
c:\windows\system32\qqstv.ini
c:\windows\system32\qqstv.ini2
c:\windows\system32\qrutv.ini
c:\windows\system32\qrutv.ini2
c:\windows\system32\rkybghgo.ini
c:\windows\system32\slotpvjw.ini
c:\windows\system32\txohdmpb.ini
c:\windows\system32\udquiolm.ini
c:\windows\system32\uqedluxv.ini
c:\windows\system32\vodpxbwd.ini
c:\windows\system32\wibdblai.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NNSERV
——-\Service_NNServ


((((((((((((((((((((((((( Files Created from 2009-04-23 to 2009-05-23 )))))))))))))))))))))))))))))))
.

2009-05-16 09:37 . 2009-05-16 09:37 ——– d—–w c:\program files\Trend Micro
2009-05-15 14:02 . 2009-05-23 11:00 ——– d-sh–r C:\SYSTEM
2009-05-12 12:35 . 2009-06-21 16:08 95744 —-a-w c:\documents and settings\All Users\Application Data\SpeedBit\DAP\Updates\Condition.dll
2009-05-09 08:05 . 2009-05-09 08:06 ——– d—–w C:\9170fca23a570560f4e0
2009-05-09 07:47 . 2009-05-09 08:16 ——– d—–w C:\b7ce5d7c133b4fb2911ac904a6c852f1
2009-04-30 13:14 . 2009-04-30 13:14 ——– d—–w c:\documents and settings\sandra\.spss
2009-04-30 13:12 . 2009-04-30 13:12 1024 —-a-w c:\windows\system32\grcauth2.dll
2009-04-30 13:12 . 2009-04-30 13:12 1024 —-a-w c:\windows\system32\grcauth1.dll
2009-04-30 13:08 . 2009-04-30 13:08 ——– d—–w c:\documents and settings\All Users\Application Data\SPSS
2009-04-30 13:08 . 2009-04-30 13:08 ——– d—–w c:\program files\Common Files\SPSS
2009-04-30 13:08 . 2009-04-30 13:08 ——– d—–w c:\program files\SPSSInc
2009-04-30 13:07 . 2009-04-30 13:07 1025 —-a-w c:\windows\system32\sysprs7.dll
2009-04-27 08:14 . 2009-04-27 08:14 ——– d–h–w c:\windows\PIF

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-21 16:13 . 2008-09-03 17:20 ——– d—–w c:\documents and settings\sandra\Application Data\dvdcss
2009-06-20 16:38 . 2008-10-25 10:48 ——– d—–w c:\program files\QuickTime
2009-06-17 03:21 . 2008-03-30 15:12 ——– d—–w c:\program files\Java
2009-06-16 15:06 . 2009-06-16 14:56 ——– d—–w c:\program files\Security Task Manager
2009-06-16 15:06 . 2009-06-16 14:56 ——– d—–w c:\documents and settings\All Users\Application Data\SecTaskMan
2009-05-23 11:03 . 2008-05-17 11:49 ——– d—–w c:\program files\Lexmark 1300 Series
2009-05-23 11:03 . 2008-01-17 06:30 ——– d—–w c:\program files\ATI Technologies
2009-05-23 11:03 . 2008-08-26 12:34 ——– d—–w c:\program files\DAP
2009-05-23 11:03 . 2008-08-26 14:04 ——– d—–w c:\program files\SpeedBit Video Accelerator
2009-05-23 11:03 . 2008-01-20 08:03 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-23 07:17 . 2009-03-09 04:18 ——– d—–w c:\program files\RealFlightG3
2009-05-11 08:00 . 2008-05-23 09:54 11952 —-a-w c:\windows\system32\avgrsstx.dll
2009-05-11 08:00 . 2008-05-23 09:54 325896 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-05-11 08:00 . 2008-05-23 09:54 27784 —-a-w c:\windows\system32\drivers\avgmfx86.sys
2009-05-11 08:00 . 2008-05-23 09:54 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-05-10 05:06 . 2009-04-30 13:11 186 —-a-w c:\documents and settings\All Users\Application Data\SafeNet Sentinel\Sentinel RMS Development Kit\System\prsgrc.dll
2009-05-09 15:44 . 2009-01-25 08:15 279728 —-a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-05-09 08:21 . 2008-01-17 06:26 71072 —-a-w c:\documents and settings\sandra\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-09 08:17 . 2008-01-20 08:35 ——– d—–w c:\documents and settings\sandra\Application Data\uTorrent
2009-05-09 07:02 . 2008-06-24 11:20 ——– d—–w c:\program files\uTorrent
2009-05-08 13:56 . 2008-01-20 08:15 ——– d—–w c:\program files\Winamp
2009-05-05 17:29 . 2008-01-17 14:30 ——– d—–w c:\program files\Miranda IM
2009-04-21 13:28 . 2008-05-23 09:54 ——– d—–w c:\documents and settings\All Users\Application Data\avg8
2009-04-08 14:00 . 2008-01-17 14:05 348160 —-a-w c:\windows\system32\msvcr71.dll
2009-04-05 04:41 . 2008-03-28 10:06 ——– d—–w c:\program files\UnHackMe
2009-03-13 05:29 . 2004-02-11 07:34 21808 —-a-w c:\windows\system32\drivers\Aldebaran.sys
2009-03-13 05:29 . 2004-02-11 07:34 16855 —-a-w c:\windows\system32\drivers\Achernar.sys
2009-03-09 04:30 . 2009-02-18 07:13 25 —-a-w C:\KEInstaller.tmp
2008-05-23 09:05 . 2008-03-28 10:07 2 –shatr c:\windows\winstart.bat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2008-08-26 3057152]
"SpeedBitVideoAccelerator"="c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe" [2008-08-26 2799200]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-11-05 4347120]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"EDS"="c:\program files\Samsung\Samsung EDS\EDSAgent.exe" [2006-03-28 634880]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-07 761947]
"MagicKeyboard"="c:\program files\SAMSUNG\MagicKBD\PreMKBD.exe" [2006-05-17 151552]
"DMHotKey"="c:\program files\Samsung\DisplayManager\DMLoader.exe" [2005-11-23 356352]
"DisplayManager"="c:\program files\Samsung\DisplayManager\DisplayManager.exe" [2006-05-03 413696]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2005-12-20 94208]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-21 144784]
"lxdcamon"="c:\program files\Lexmark 1300 Series\lxdcamon.exe" [2007-03-05 20480]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"snpstd3"="c:\windows\vsnpstd3.exe" [2005-09-05 339968]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-11 37232]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2006-10-15 169984]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-04-04 16120832]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2006-06-29 89541]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-1-21 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-11 08:00 11952 —-a-w c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Miranda IM\\miranda32.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\WINDOWS\\system32\\lxdccoms.exe"=
"c:\\Program Files\\Lexmark 1300 Series\\lxdcamon.exe"=
"c:\\Program Files\\Lexmark 1300 Series\\App4R.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdcpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdcjswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdctime.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\SPSSInc\\Statistics17\\statistics.com"=
"c:\\Program Files\\SPSSInc\\Statistics17\\statistics.exe"=
"c:\\Program Files\\SPSSInc\\Statistics17\\SPSSWinWrapIDE.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9420:TCP"= 9420:TCP:Akamai Network Manager
"5000:UDP"= 5000:UDP:Akamai Network Manager
"14478:TCP"= 14478:TCP:NortonAV
"12830:TCP"= 12830:TCP:NortonAV
"18882:TCP"= 18882:TCP:NortonAV
"15474:TCP"= 15474:TCP:NortonAV
"16253:TCP"= 16253:TCP:NortonAV
"17278:TCP"= 17278:TCP:NortonAV
"12140:TCP"= 12140:TCP:NortonAV
"14498:TCP"= 14498:TCP:NortonAV
"13748:TCP"= 13748:TCP:NortonAV

R0 Achernar;Achernar - Storage Filter Drivers;c:\windows\system32\drivers\Achernar.sys [2/11/2004 3:34 PM 16855]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/23/2008 5:54 PM 325896]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/23/2008 5:54 PM 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/4/2008 1:14 PM 908568]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/4/2008 1:14 PM 298776]
R2 lxdc_device;lxdc_device;c:\windows\system32\lxdccoms.exe -service –> c:\windows\system32\lxdccoms.exe -service [?]
R2 sbbotdi;sbbotdi;c:\progra~1\SPEEDB~1\sbbotdi.sys [8/26/2008 10:04 PM 35968]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm –> c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?]
R3 Aldebaran;Aldebaran - Storage Filter Drivers;c:\windows\system32\drivers\Aldebaran.sys [2/11/2004 3:34 PM 21808]
R3 DNSeFilter;DNSeFilter;c:\windows\system32\drivers\SamsungEDS.SYS [3/29/2006 12:59 PM 27648]
R3 SSB2413;SSB2413 Wireless Network Adapter Service;c:\windows\system32\drivers\SSB2413.sys [1/17/2008 2:37 PM 470112]
S1 ndproxyy;ndproxyy; [x]
S1 ShldDrv;Panda File Shield Driver;c:\windows\system32\DRIVERS\ShlDrv51.sys –> c:\windows\system32\DRIVERS\ShlDrv51.sys [?]
S2 cfghgn;Config Support;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 6:56 AM 14336]
S2 dxjnkns;Microsoft Network;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 6:56 AM 14336]
S2 flaye;Universal Time;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 6:56 AM 14336]
S2 lxdcCATSCustConnectService;lxdcCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdcserv.exe [5/17/2008 7:55 PM 99248]
S2 PavProc;Panda Process Protection Driver;\??\c:\windows\system32\DRIVERS\PavProc.sys –> c:\windows\system32\DRIVERS\PavProc.sys [?]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
flaye
cfghgn
dxjnkns
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-MsnMsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe
HKLM-Run-lxdcmon.exe - c:\program files\Lexmark 1300 Series\lxdcmon.exe
SafeBoot-procexp90.Sys


.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyServer = 172.60.1.2:8080
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\progra~1\SPEEDB~1\sblsp.dll
FF - ProfilePath - c:\documents and settings\sandra\Application Data\Mozilla\Firefox\Profiles\7vxwuliu.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-23 19:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\cfghgn]
"ServiceDll"="c:\windows\system32\yideq.dll"
–

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\dxjnkns]
"ServiceDll"="c:\windows\system32\yideq.dll"
–

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\flaye]
"ServiceDll"="c:\windows\system32\yideq.dll"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(628)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(684)
c:\progra~1\SPEEDB~1\sblsp.dll
c:\program files\SpeedBit Video Accelerator\ConfigDB.dll
c:\program files\SpeedBit Video Accelerator\Accelerator.dll
c:\program files\SpeedBit Video Accelerator\CommPipe.dll

- - - - - - - > 'explorer.exe'(200)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Samsung\DisplayManager\dmhkcore.exe
c:\windows\system32\lxdccoms.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorEngine.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-05-23 19:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-23 11:06

Pre-Run: 65,365,958,656 bytes free
Post-Run: 66,036,281,344 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

277
Hello.

Here the ComboFix log. The flash disinfector was done with scanning very fast, it took maybe 5sec. Is that normal?

Yeah, that's about it. Takes aboue 5-10 seconds on my other XP computer.

Run ComboFix with CFScript

We will run ComboFix again. This time it will be slightly different from the initial run.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are unsure how.
  • Open notepad (Start>Run>"notepad") and copy/paste ALL the text in the codebox below into it: (MAKE SURE YOU DON'T MISS ANYTHING OR CHANGE ANYTHING IN THE CODE BOX BELOW). Do not copy the word "code".
    http://forums.whatthetech.com/Ctfmon_exe_Recycler_t103117.html
    
    KillAll::
    
    Collect::[68]
    c:\windows\system32\yideq.dll
    File::
    c:\windows\system32\grcauth2.dll
    c:\windows\system32\grcauth1.dll
    c:\windows\system32\sysprs7.dll
    c:\windows\winstart.bat
    DirLook::
    C:\SYSTEM
    C:\b7ce5d7c133b4fb2911ac904a6c852f1
    C:\9170fca23a570560f4e0
    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "14478:TCP"=- 
    "12830:TCP"=- 
    "18882:TCP"=- 
    "15474:TCP"=- 
    "16253:TCP"=- 
    "17278:TCP"=-
    "12140:TCP"=- 
    "14498:TCP"=- 
    "13748:TCP"=- 
    [-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\cfghgn]
    [-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\dxjnkns]
    [-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\flaye]
    Driver::
    ndproxyy
    ShldDrv
    cfghgn
    dxjnkns
     flaye
    PavProc
    NetSvc::
    flaye
    cfghgn
    dxjnkns
    Save this as CFScript.txt, in the same location as ComboFix.exe. (This should be your desktop.)
    [external image: Posted Image]
  • Refering to the picture above, drag CFScript into ComboFix.exe.
  • When finished, it shall produce a log for you at "C:\ComboFix.txt"

Upload Samples by ComboFix

When Combofix finishes running, the ComboFix log will open along with a message box. With the above script, ComboFix captured some files to submit for analysis.
  • Important: Ensure you are connected to the internet before clicking OK on the message box.
  • A blue-screen would appear auto-uploading the zipped file I requested.
  • After the uploading is done you should see a message near the bottom saying "Upload was Succesfull".

**NOTE**
=================
  • IF for some reason Combofix fails to upload anything please do the following:
  • Go to Start >> My Computer > C:\
  • Then Navigate to the C:\Qoobox\Quarantine folder.
  • Find the archive zip file called "[68]-Submit_Date_Time.zip"
  • Simply go to This Channel and upload the submit.zip archive file to me.
  • Follow the instructions on that page to copy/paste/send the requested file.

Let me know how it goes and if the upload went successfully or not in your next reply.

Download and Run Scan with GMER

We will use GMER to scan for rootkits. This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop. Unzip/extract the file to its own folder. (Click here for information on how to do this if not sure. Win 2000 users click here.

  • Close any and all open programs, as this process may crash your computer.
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • When you have done this, close all running programs.
    There is a small chance this application may crash your computer so save any work you have open.
  • Double-click on Gmer.exe to start the program. Right-click and select Run As Administrator… if you are using Vista
  • Allow the gmer.sys driver to load if asked.
    If it detects rootkit activity, you will receive a prompt (refer below) to run a full scan. Click NO..
    [external image: Posted Image]

  • In the right panel, you will see several boxes that have been checked. Please UNCHECK the following:
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show all (Don't miss this one!)
  • Click on [external image: Posted Image] and wait for the scan to finish.
  • If you see a rootkit warning window, click OK.
  • Push [external image: Posted Image] and save the logfile to your desktop.
  • Copy and Paste the contents of that file in your next post.

If GMER doesn't work in Normal Mode try running it in Safe Mode

Note: Do Not run any program while GMER is running
*Note*: Rootkit scans often produce false positives. Do NOT take any actions on "<— ROOKIT" entries

Download and Run DDS

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results, click no to the Optional_Scan
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE

– Note: The screen instructions indicate the attach.txt must be zipped before attaching (not posted) to your forum post. Instead, we want you to include attach.txt as an attachment to upload using the "Browse" button in the text editor when making your reply.

For your next reply include:
-Combofix log
-Did the upload go successfully?
-GMER log
-DDS log
-Attach log

Thanks.

~Extremeboy
Hello.

I have done what you said and attached the following .txt: Combofix, DDS and Atttach.
I wasn't able to attach GMER so I'm posting it here.

I'm not too sure if the upload went successfully. I didn't notice any success message
but I also couldn't find the .zip in the quarantine folder. Maybe you could confirm if you
have received the file.
By the way, no rootkit warning appeared while GMER was running.

Another question: Are my USB drives save to use again after I used the FlashDisinfector?
And, is the ctfmon on other computers able to transfer the virus to my USB drives again or
are they protected by the autron.inf?

Thanks, Sandra

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-05-25 21:10:19
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.15 —-

Code \??\C:\DOCUME~1\sandra\LOCALS~1\Temp\catchme.sys pIofCallDriver

—- Devices - GMER 1.0.15 —-

Device \Driver\Tcpip \Device\Ip sbbotdi.sys (Speedbit Driver/SpeedBit Ltd.)

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

Device \Driver\Tcpip \Device\Tcp sbbotdi.sys (Speedbit Driver/SpeedBit Ltd.)

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Tcpip \Device\Udp sbbotdi.sys (Speedbit Driver/SpeedBit Ltd.)

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Tcpip \Device\RawIp sbbotdi.sys (Speedbit Driver/SpeedBit Ltd.)

AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Tcpip \Device\IPMULTICAST sbbotdi.sys (Speedbit Driver/SpeedBit Ltd.)

—- EOF - GMER 1.0.15 —-
Hello.

I'm not too sure if the upload went successfully. I didn't notice any success message
but I also couldn't find the .zip in the quarantine folder. Maybe you could confirm if you
have received the file.

I didn't recieve the file. Please check again.

Are my USB drives save to use again after I used the FlashDisinfector?
And, is the ctfmon on other computers able to transfer the virus to my USB drives again or
are they protected by the autron.inf?

They are protected from those autorun.inf worms but NOTHING ELSE.

There are still a few more things we can take care of. First, we'll update Java an run a MBAM scan.

Update Java to Version 6 Update 13

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Look for "Java Runtime Environment (JRE)" JRE 6 Update 13.
  • Click the Download button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
    Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u13-windows-i586-p.exe to install the newest version.
*If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
** If you choose to update via the Java applet in Control Panel, uncheck the option to install the Toolbar unless you want it.
*** The uninstaller incorporated in this release removes previous Updates 10 and above, but does not remove older versions, so they still need to be removed manually.


Download and Run ATFCleaner

Please download ATF Cleaner by Atribune. This program will clear out temporary files and settings. You will likely be logged out of the forum where you are recieving help.

This program is for XP and Windows 2000 only.

  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main Select Files to Delete choose: Select All.
  • Click the Empty Selected button.
If you use Firefox browser also…
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser also…
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Download and run MalwareBytes Anti-Malware

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

For complete or visual instructions on installing and running Malwarebytes Anti-Malware please read this link

With Regards,
Extremeboy
Hello. Are you still with me? If you resolved it I would like to know. Otherwise, if you do not reply within 5-7 days from my inital reply this topic will be close. ~Extremeboy
Hello. I'm still with you!! So sorry that I reply so late but I was so busy that I almost forgot. I checked again but I can't find the combofix exe in the folder. So what do you want me to do? Below the Malwarebytes log. Thanks! Malwarebytes' Anti-Malware 1.37 Database version: 2212 Windows 5.1.2600 Service Pack 2 6/2/2009 4:17:17 PM mbam-log-2009-06-02 (16-17-17).txt Scan type: Quick Scan Objects scanned: 78665 Time elapsed: 4 minute(s), 43 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
Hello.

I checked again but I can't find the combofix exe in the folder. So what do you
want me to do?

After looking at the Combofix log again it seems you didn't copy the whole CFScript or perhaps the file wasn't there anymore.

We need to update Java again and run an online scan.

Download and Install Latest Version of Java

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Look for "Java Runtime Environment (JRE)" JRE 6 Update 14.
  • Click the Download button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u14-windows-i586-p.exe to install the newest version.
– If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
– If you choose to update via the Java applet in Control Panel, uncheck the option to install the Toolbar unless you want it.
– The uninstaller incorporated in this release removes previous Updates 10 and above, but does not remove older versions, so they still need to be removed manually.


Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click Ok and reboot your computer.

Run Scan with Kaspersky

Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.)

If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.


  • Please disable your realtime protection software before proceeding. Refer to this page if you are unsure how.
  • Open the Kaspersky WebScanner
    page.
  • Click on the 🖼Click to load external image (Posted Image) button on the main page.
  • The program will launch and fill in the Information section on the left.
  • Read the "Requirements and Limitations" then press the 🖼Click to load external image (Posted Image) button.
  • The program will begin downloading the latest program and definition files. It may take a while so please be patient and let it finish.
  • Once the files have been downloaded, click on the 🖼Click to load external image (Posted Image) …button.
    In the scan settings make sure the following are selected:
    • Detect malicious programs of the following categories:
      Viruses, Worms, Trojan Horses, Rootkits
      Spyware, Adware, Dialers and other potentially dangerous programs
    • Scan compound files (doesn't apply to the File scan area):
      Archives
      Mail databases
      By default the above items should already be checked.
    • Click the 🖼Click to load external image (Posted Image) button, if you made any changes.
  • Now under the Scan section on the left:

    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis.

Then re-run OTListIT2 and post back with the logs.

With Regards
Extremeboy
Hello..
Here both logs. Let me know what to do next.

Thanks!



——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Wednesday, June 3, 2009
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Wednesday, June 03, 2009 09:18:31
Records in database: 2300997
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Files scanned: 64346
Threat name: 2
Infected objects: 2
Suspicious objects: 0
Duration of the scan: 01:28:00


File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\Program Files\NewDotNet\nncore.dll.vir.vir Infected: not-a-virus:AdWare.Win32.NewDotNet.m 1
C:\WINDOWS\system32\drivers\etc\hosts.msn Infected: Trojan.Win32.Qhost.hi 1

The selected area was scanned.

________________________________________________________________________________
_________________

OTListIt logfile created on: 6/4/2009 1:06:47 AM - Run 2
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\sandra\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.10 Mb Total Physical Memory | 527.19 Mb Available Physical Memory | 58.96% Memory free
2.12 Gb Paging File | 1.51 Gb Available in Paging File | 71.33% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 86.04 Gb Total Space | 62.90 Gb Free Space | 73.10% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SURFERGIRL
Current User Name: sandra
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2006/03/28 22:42:44 | 00,405,504 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2006/03/28 22:42:44 | 00,405,504 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2006/10/15 23:38:20 | 01,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2006/01/02 18:41:22 | 00,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2006/04/04 16:44:58 | 16,120,832 | R— | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\RTHDCPL.EXE
PRC - [2006/03/28 13:27:16 | 00,634,880 | —- | M] () – C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
PRC - [2006/06/29 12:32:14 | 00,089,541 | R— | M] (Agere Systems) – C:\WINDOWS\AGRSMMSG.exe
PRC - [2005/12/07 13:44:16 | 00,761,947 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2006/05/03 19:22:18 | 00,413,696 | —- | M] (SAMSUNG ELECTRONICS) – C:\Program Files\Samsung\DisplayManager\DisplayManager.exe
PRC - [2005/12/07 22:57:00 | 00,030,208 | —- | M] (Cyberlink Corp.) – C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
PRC - [2005/12/20 14:39:32 | 00,094,208 | —- | M] () – C:\WINDOWS\tsnpstd3.exe
PRC - [2007/03/06 04:40:25 | 00,020,480 | —- | M] (Lexmark) – C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
PRC - [2005/09/05 15:55:08 | 00,339,968 | —- | M] () – C:\WINDOWS\vsnpstd3.exe
PRC - [2008/06/11 22:43:26 | 00,640,376 | —- | M] (Adobe Systems Inc.) – C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
PRC - [2009/05/11 16:00:54 | 01,947,928 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2009/06/03 13:44:21 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008/08/26 20:34:28 | 03,057,152 | —- | M] (Speedbit Ltd.) – C:\Program Files\DAP\DAP.EXE
PRC - [2008/08/26 22:04:39 | 02,799,200 | —- | M] (Speedbit Ltd.) – C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe
PRC - [2008/11/05 21:59:00 | 04,347,120 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2009/05/11 16:00:51 | 00,298,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2009/06/03 13:44:21 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2007/05/01 04:03:50 | 00,537,520 | —- | M] ( ) – C:\WINDOWS\system32\lxdccoms.exe
PRC - [2005/08/08 13:54:00 | 00,167,936 | —- | M] () – C:\Program Files\CyberLink\Shared files\RichVideo.exe
PRC - [2009/06/19 23:31:55 | 00,486,680 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/05/11 16:00:56 | 00,594,712 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2008/08/26 22:04:39 | 00,288,360 | —- | M] (Speedbit Ltd.) – C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe
PRC - [2009/05/11 16:00:55 | 00,908,568 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2009/05/11 16:00:58 | 00,692,504 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2004/08/04 06:56:58 | 00,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\wscntfy.exe
PRC - [2006/01/02 18:41:22 | 00,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2006/01/02 18:41:22 | 00,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2009/04/24 12:38:11 | 00,307,704 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2008/08/26 22:04:39 | 00,124,528 | —- | M] (Speedbit Ltd.) – C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorEngine.exe
PRC - [2009/06/21 23:43:34 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\sandra\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/07/25 11:16:40 | 00,034,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2006/03/28 22:42:44 | 00,405,504 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\Ati2evxx.exe – (Ati HotKey Poller [Auto | Running])
SRV - [2009/05/11 16:00:55 | 00,908,568 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe – (avg8emc [Auto | Running])
SRV - [2009/05/11 16:00:51 | 00,298,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe – (avg8wd [Auto | Running])
SRV - [2008/07/25 11:17:02 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2009/01/12 20:49:43 | 00,651,720 | —- | M] (Macrovision Europe Ltd.) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service [On_Demand | Stopped])
SRV - [2008/07/29 21:10:04 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2004/08/04 06:56:46 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2004/10/22 03:24:18 | 00,073,728 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2008/07/29 19:24:50 | 00,881,664 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2009/06/03 13:44:21 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2007/05/01 04:04:10 | 00,099,248 | —- | M] () – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdcserv.exe – (lxdcCATSCustConnectService [Auto | Stopped])
SRV - [2007/05/01 04:03:50 | 00,537,520 | —- | M] ( ) – C:\WINDOWS\system32\lxdccoms.exe – (lxdc_device [Auto | Running])
SRV - [2008/07/29 19:16:38 | 00,132,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2006/10/26 19:49:34 | 00,441,136 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
SRV - [2006/10/26 14:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - File not found – – (PavPrSrv [Auto | Stopped])
SRV - [2005/08/08 13:54:00 | 00,167,936 | —- | M] () – C:\Program Files\CyberLink\Shared files\RichVideo.exe – (RichVideo [Auto | Running])
SRV - [2008/08/26 22:04:39 | 00,288,360 | —- | M] (Speedbit Ltd.) – C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe – (VideoAcceleratorService [Auto | Running])
SRV - [2005/10/06 18:12:30 | 00,855,552 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Connect 2\wmccds.exe – (WMConnectCDS [On_Demand | Stopped])
SRV - [2006/05/09 21:03:00 | 00,823,808 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2009/03/13 13:29:13 | 00,016,855 | —- | M] (An Chen Computer Co., Ltd.) – C:\WINDOWS\system32\Drivers\Achernar.sys – (Achernar [Boot | Running])
DRV - [2006/06/29 12:13:08 | 01,160,320 | R— | M] (Agere Systems) – C:\WINDOWS\system32\DRIVERS\AGRSM.sys – (AgereSoftModem [On_Demand | Running])
DRV - [2009/03/13 13:29:13 | 00,021,808 | —- | M] (An Chen Computer Co., Ltd.) – C:\WINDOWS\system32\Drivers\Aldebaran.sys – (Aldebaran [On_Demand | Running])
DRV - [2006/03/28 22:50:14 | 01,522,688 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys – (ati2mtag [On_Demand | Running])
DRV - [2009/05/11 16:00:59 | 00,325,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86 [System | Running])
DRV - [2009/05/11 16:00:59 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86 [System | Running])
DRV - [2009/05/11 16:00:56 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX [System | Running])
DRV - [2006/03/29 12:59:12 | 00,027,648 | —- | M] (Samsung Electronics,.LTD) – C:\WINDOWS\system32\drivers\SamsungEDS.sys – (DNSeFilter [On_Demand | Running])
DRV - [2006/10/15 23:38:24 | 00,138,752 | —- | M] (Windows ® Server 2003 DDK provider) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys – (HDAudBus [On_Demand | Running])
DRV - [2006/04/06 13:20:44 | 04,258,816 | R— | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService [On_Demand | Running])
DRV - [2001/08/23 20:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\system32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2007/03/08 07:51:00 | 00,043,528 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2005/11/16 20:28:32 | 00,028,928 | —- | M] (REDC) – C:\WINDOWS\system32\DRIVERS\rimmptsk.sys – (rimmptsk [On_Demand | Running])
DRV - [2005/11/01 17:54:50 | 00,051,584 | —- | M] (REDC) – C:\WINDOWS\system32\DRIVERS\rimsptsk.sys – (rimsptsk [On_Demand | Running])
DRV - [2005/11/01 18:08:00 | 00,308,992 | —- | M] (REDC) – C:\WINDOWS\system32\DRIVERS\rixdptsk.sys – (rismxdp [On_Demand | Running])
DRV - [2006/01/18 17:41:58 | 00,080,512 | R— | M] (Realtek Semiconductor Corporation ) – C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys – (RTL8023xp [On_Demand | Running])
DRV - [2004/08/04 06:31:34 | 00,020,992 | —- | M] (Realtek Semiconductor Corporation) – C:\WINDOWS\system32\DRIVERS\RTL8139.SYS – (rtl8139 [On_Demand | Stopped])
DRV - [2008/08/26 22:04:40 | 00,035,968 | —- | M] (SpeedBit Ltd.) – C:\Program Files\SpeedBit Video Accelerator\sbbotdi.sys – (sbbotdi [Auto | Running])
DRV - [2006/10/15 23:39:23 | 00,163,644 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\system32\DRIVERS\secdrv.sys – (Secdrv [Auto | Running])
DRV - [2006/04/18 15:25:36 | 08,532,864 | —- | M] (Sonix Co. Ltd.) – C:\WINDOWS\system32\DRIVERS\snpstd3.sys – (SNPSTD3 [On_Demand | Stopped])
DRV - [2006/01/16 10:15:24 | 00,470,112 | —- | M] (Atheros Communications, Inc.) – C:\WINDOWS\system32\DRIVERS\SSB2413.sys – (SSB2413 [On_Demand | Running])
DRV - [2005/12/07 13:30:52 | 00,191,936 | —- | M] (Synaptics, Inc.) – C:\WINDOWS\system32\DRIVERS\SynTP.sys – (SynTP [On_Demand | Running])
DRV - [2004/08/03 23:07:56 | 00,059,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\usbaudio.sys – (usbaudio [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.microsoft.com/isapi/redir.dll?P…pdate&O1=b1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1
FF - prefs.js..extensions.enabledItems: {F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}:[removed]
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090123.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX [2009/05/12 08:28:00 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/05/09 16:09:04 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/06/03 13:44:21 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/09 21:01:33 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/06/02 15:54:42 | 00,000,000 | —D | M]

[2008/09/15 18:15:32 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Extensions
[2008/09/15 18:15:32 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/06/03 13:45:20 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Firefox\Profiles\7vxwuliu.default\extensions
[2009/05/09 17:16:24 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Firefox\Profiles\7vxwuliu.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2008/01/21 15:05:38 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Firefox\Profiles\7vxwuliu.default\extensions\[removed]
[2009/04/22 22:52:34 | 00,000,000 | —D | M] – C:\Documents and Settings\sandra\Application Data\mozilla\Firefox\Profiles\7vxwuliu.default\extensions\[removed]
[2009/06/03 13:45:08 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/05/03 17:48:06 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/06/03 13:44:42 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2009/04/24 12:38:30 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/24 12:38:32 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/24 08:39:08 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/24 08:39:08 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/24 08:39:08 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/24 08:39:08 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/24 08:39:08 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/24 08:39:08 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/24 08:39:08 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AGRSMMSG] AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay (ATI Technologies Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DisplayManager] C:\Program Files\Samsung\DisplayManager\DisplayManager.exe (SAMSUNG ELECTRONICS)
O4 - HKLM..\Run: [DMHotKey] C:\Program Files\Samsung\DisplayManager\DMLoader.exe (SAMSUNG)
O4 - HKLM..\Run: [EDS] C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe ()
O4 - HKLM..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" ()
O4 - HKLM..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe" (Lexmark)
O4 - HKLM..\Run: [MagicKeyboard] C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe ()
O4 - HKCU..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP (Speedbit Ltd.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.)
O4 - HKCU..\Run: [SpeedBitVideoAccelerator] C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe (Speedbit Ltd.)
O4 - HKCU..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm ()
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm ()
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\SpeedBit Video Accelerator\sblsp.dll (Speedbit Ltd.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1207410961515 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/01/17 14:12:28 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/05/23 19:37:35 | 00,000,000 | RHSD | M] - C:\autorun.inf – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/06/03 22:08:53 | 00,000,000 | —D | M]

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[6 C:\WINDOWS\*.tmp files]
[2009/06/21 23:40:52 | 00,000,000 | —D | C] – C:\Documents and Settings\sandra\Desktop\HostsXpert
[2009/06/21 23:36:07 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\sandra\Desktop\OTListIt2.exe
[2009/06/21 23:35:28 | 00,353,485 | —- | C] () – C:\Documents and Settings\sandra\Desktop\HostsXpert.zip
[2009/06/16 22:56:16 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2009/06/16 22:56:10 | 00,000,000 | —D | C] – C:\Program Files\Security Task Manager
[2009/06/03 22:08:01 | 00,003,094 | —- | C] () – C:\Documents and Settings\sandra\Desktop\kaspersky log.html
[2009/06/02 22:32:17 | 00,000,000 | —D | C] – C:\Documents and Settings\sandra\Desktop\Resume
[2009/06/02 16:11:18 | 00,000,000 | —D | C] – C:\Documents and Settings\sandra\Application Data\Malwarebytes
[2009/06/02 16:11:14 | 00,040,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/02 16:11:12 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/02 16:11:12 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/06/02 16:11:12 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/06/02 16:08:28 | 03,371,384 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\sandra\Desktop\mbam-setup.exe
[2009/05/29 16:18:02 | 00,000,162 | -H– | C] () – C:\Documents and Settings\sandra\Desktop\~$mpetitors 2.doc
[2009/05/29 16:02:26 | 00,000,162 | -H– | C] () – C:\Documents and Settings\sandra\Desktop\~$me_Line 1X.dot
[2009/05/29 12:45:01 | 00,000,162 | -H– | C] () – C:\Documents and Settings\sandra\Desktop\~$sBeans PR Plan.doc
[2009/05/26 13:12:13 | 16,283,032 | —- | C] () – C:\Documents and Settings\sandra\Desktop\jre-6u13-windows-i586-p.exe
[2009/05/25 22:17:11 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2009/05/25 20:23:17 | 00,286,208 | —- | C] () – C:\Documents and Settings\sandra\Desktop\urmrtj8x.exe
[2009/05/25 20:17:52 | 00,000,000 | —D | C] – C:\WINDOWS\temp
[2009/05/25 20:11:57 | 00,000,000 | —D | C] – C:\Documents and Settings\sandra\Local Settings\temp
[2009/05/25 20:09:04 | 00,000,000 | –SD | C] – C:\ComboFix
[2009/05/23 19:37:35 | 00,000,000 | RHSD | C] – C:\autorun.inf
[2009/05/23 18:58:57 | 00,000,211 | —- | C] () – C:\Boot.bak
[2009/05/23 18:58:53 | 00,260,272 | —- | C] () – C:\cmldr
[2009/05/23 18:58:52 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/05/23 18:56:42 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/05/23 18:56:42 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/05/23 18:56:42 | 00,139,776 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/05/23 18:56:42 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/05/23 18:56:42 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/05/23 18:56:42 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/05/23 18:56:42 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/05/23 18:56:42 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/05/23 18:55:41 | 02,977,615 | R— | C] () – C:\Documents and Settings\sandra\Desktop\ComboFix.exe
[2009/05/23 18:44:19 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/05/23 18:44:15 | 00,000,000 | —D | C] – C:\Qoobox
[2009/05/23 18:37:00 | 00,000,000 | —D | C] – C:\WINDOWS\pss
[2009/05/23 18:16:55 | 00,132,597 | —- | C] () – C:\Documents and Settings\sandra\Desktop\Flash_Disinfector.exe
[2009/05/16 17:37:54 | 00,001,734 | —- | C] () – C:\Documents and Settings\sandra\Desktop\HijackThis.lnk
[2009/05/16 17:37:53 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/05/16 17:37:44 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\sandra\Desktop\HJTInstall.exe
[2009/05/15 22:02:40 | 00,000,000 | RHSD | C] – C:\SYSTEM
[2009/05/10 07:18:55 | 00,000,000 | —D | C] – C:\Documents and Settings\sandra\Desktop\CAM
[2009/05/09 16:05:40 | 00,000,000 | —D | C] – C:\9170fca23a570560f4e0
[2009/05/09 15:47:38 | 00,000,000 | —D | C] – C:\b7ce5d7c133b4fb2911ac904a6c852f1
[2009/02/18 22:04:07 | 00,000,140 | —- | C] () – C:\WINDOWS\RealFlight.INI
[2009/02/18 21:51:56 | 00,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2009/02/18 15:19:46 | 00,000,265 | —- | C] () – C:\WINDOWS\emug3.ini
[2008/06/04 08:57:38 | 00,290,816 | —- | C] () – C:\WINDOWS\System32\XDogcat.dll
[2008/05/23 16:03:34 | 00,077,312 | —- | C] () – C:\WINDOWS\System32\ztvunace26.dll
[2008/05/23 16:03:33 | 00,162,304 | —- | C] () – C:\WINDOWS\System32\ztvunrar36.dll
[2008/05/23 16:03:33 | 00,153,088 | —- | C] () – C:\WINDOWS\System32\unrar3.dll
[2008/05/23 16:03:33 | 00,075,264 | —- | C] () – C:\WINDOWS\System32\unacev2.dll
[2008/05/23 15:17:14 | 00,039,424 | —- | C] () – C:\WINDOWS\System32\fccywxy.dll.vir
[2008/05/17 19:55:40 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\lxdcvs.dll
[2008/05/17 19:55:37 | 00,344,064 | —- | C] () – C:\WINDOWS\System32\lxdccoin.dll
[2008/05/17 19:50:15 | 00,000,044 | —- | C] () – C:\WINDOWS\System32\lxdcrwrd.ini
[2008/05/17 19:49:44 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\LXDCinst.dll
[2008/05/17 19:49:43 | 00,413,696 | —- | C] ( ) – C:\WINDOWS\System32\lxdcinpa.dll
[2008/05/17 19:49:43 | 00,323,584 | —- | C] ( ) – C:\WINDOWS\System32\LXDChcp.dll
[2008/05/17 19:49:42 | 01,232,896 | —- | C] ( ) – C:\WINDOWS\System32\lxdcserv.dll
[2008/05/17 19:49:42 | 00,999,424 | —- | C] ( ) – C:\WINDOWS\System32\lxdcusb1.dll
[2008/05/17 19:49:42 | 00,397,312 | —- | C] ( ) – C:\WINDOWS\System32\lxdciesc.dll
[2008/05/17 19:49:41 | 00,643,072 | —- | C] ( ) – C:\WINDOWS\System32\lxdcpmui.dll
[2008/05/17 19:49:41 | 00,585,728 | —- | C] ( ) – C:\WINDOWS\System32\lxdclmpm.dll
[2008/05/17 19:49:41 | 00,163,840 | —- | C] ( ) – C:\WINDOWS\System32\lxdcprox.dll
[2008/05/17 19:49:41 | 00,094,208 | —- | C] ( ) – C:\WINDOWS\System32\lxdcpplc.dll
[2008/05/17 19:49:40 | 00,700,416 | —- | C] ( ) – C:\WINDOWS\System32\lxdchbn3.dll
[2008/05/17 19:49:40 | 00,208,896 | —- | C] () – C:\WINDOWS\System32\lxdcgrd.dll
[2008/05/17 19:49:39 | 00,684,032 | —- | C] ( ) – C:\WINDOWS\System32\lxdccomc.dll
[2008/05/17 19:49:39 | 00,425,984 | —- | C] ( ) – C:\WINDOWS\System32\lxdccomm.dll
[2008/03/04 19:23:02 | 00,000,048 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/02/19 19:46:52 | 00,015,498 | —- | C] () – C:\WINDOWS\snpstd3.ini
[2008/02/19 19:46:47 | 00,053,248 | —- | C] ( ) – C:\WINDOWS\vsnpstd3.dll
[2008/02/19 19:46:46 | 00,147,456 | —- | C] ( ) – C:\WINDOWS\System32\rsnpstd3.dll
[2008/02/19 19:46:46 | 00,053,248 | —- | C] ( ) – C:\WINDOWS\System32\csnpstd3.dll
[2008/01/29 21:43:08 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2008/01/17 14:45:34 | 00,000,135 | R— | C] () – C:\WINDOWS\System32\lngEng.ini
[2008/01/17 14:45:34 | 00,000,117 | —- | C] () – C:\WINDOWS\System32\lngKor.ini
[2008/01/17 14:39:12 | 00,001,697 | —- | C] () – C:\WINDOWS\System32\sandra_KBD.ini
[2008/01/17 14:39:12 | 00,001,697 | —- | C] () – C:\WINDOWS\System32\MagicKBD.INI
[2008/01/17 14:39:10 | 00,003,425 | —- | C] () – C:\WINDOWS\System32\KBDR.INI
[2008/01/17 14:39:10 | 00,002,741 | —- | C] () – C:\WINDOWS\System32\KBDD.INI
[2008/01/17 14:39:10 | 00,002,699 | —- | C] () – C:\WINDOWS\System32\KBDO.INI
[2008/01/17 14:39:10 | 00,002,699 | —- | C] () – C:\WINDOWS\System32\KBDC.INI
[2008/01/17 14:39:10 | 00,002,606 | —- | C] () – C:\WINDOWS\System32\KBDB.INI
[2008/01/17 14:39:10 | 00,002,236 | —- | C] () – C:\WINDOWS\System32\KBDQ.INI
[2008/01/17 14:39:10 | 00,001,956 | —- | C] () – C:\WINDOWS\System32\KBDE.INI
[2008/01/17 14:39:10 | 00,001,885 | —- | C] () – C:\WINDOWS\System32\KBDP.INI
[2008/01/17 14:39:10 | 00,001,857 | —- | C] () – C:\WINDOWS\System32\KBDUU.INI
[2008/01/17 14:39:10 | 00,001,835 | —- | C] () – C:\WINDOWS\System32\KBDG.INI
[2008/01/17 14:39:10 | 00,001,835 | —- | C] () – C:\WINDOWS\System32\KBDA.INI
[2008/01/17 14:39:10 | 00,001,834 | —- | C] () – C:\WINDOWS\System32\KBDU.INI
[2008/01/17 14:39:10 | 00,001,819 | —- | C] () – C:\WINDOWS\System32\KBDN.INI
[2008/01/17 14:39:10 | 00,001,699 | —- | C] () – C:\WINDOWS\System32\KBDT.INI
[2008/01/17 14:39:10 | 00,001,697 | —- | C] () – C:\WINDOWS\System32\KBDV.INI
[2008/01/17 14:39:10 | 00,001,522 | —- | C] () – C:\WINDOWS\System32\KBDS.INI
[2008/01/17 14:39:10 | 00,001,476 | —- | C] () – C:\WINDOWS\System32\KBDF.INI
[2008/01/17 14:38:54 | 00,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2008/01/17 14:36:42 | 00,135,168 | R— | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2007/03/12 11:41:52 | 00,061,440 | —- | C] ( ) – C:\WINDOWS\System32\vsnpstd3.dll
[2004/08/04 06:56:44 | 00,081,920 | —- | C] () – C:\WINDOWS\System32\ieencode.dll
[2001/08/23 20:00:00 | 00,000,817 | —- | C] () – C:\WINDOWS\win.ini
[2001/08/23 20:00:00 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[5 C:\WINDOWS\System32\*.tmp files]
[6 C:\WINDOWS\*.tmp files]
[2009/06/21 23:43:34 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\sandra\Desktop\OTListIt2.exe
[2009/06/21 23:35:35 | 00,353,485 | —- | M] () – C:\Documents and Settings\sandra\Desktop\HostsXpert.zip
[2009/06/03 22:08:01 | 00,003,094 | —- | M] () – C:\Documents and Settings\sandra\Desktop\kaspersky log.html
[2009/06/03 13:51:40 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\sandra\Local Settings\desktop.ini
[2009/06/03 13:51:39 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/06/03 13:51:37 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/06/03 13:50:32 | 00,006,511 | —- | M] () – C:\WINDOWS\System32\ProxyServer.bak
[2009/06/03 13:42:05 | 00,000,499 | —- | M] () – C:\WINDOWS\System32\CommPipe.bak
[2009/06/03 13:42:05 | 00,000,390 | —- | M] () – C:\WINDOWS\System32\SbLsp.bak
[2009/06/03 11:40:30 | 36,736,380 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/06/03 11:40:30 | 00,064,732 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/06/03 00:00:11 | 00,000,140 | —- | M] () – C:\WINDOWS\RealFlight.INI
[2009/06/02 16:09:36 | 03,371,384 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\sandra\Desktop\mbam-setup.exe
[2009/06/01 12:07:31 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/05/29 16:18:02 | 00,000,162 | -H– | M] () – C:\Documents and Settings\sandra\Desktop\~$mpetitors 2.doc
[2009/05/29 16:02:26 | 00,000,162 | -H– | M] () – C:\Documents and Settings\sandra\Desktop\~$me_Line 1X.dot
[2009/05/29 12:45:01 | 00,000,162 | -H– | M] () – C:\Documents and Settings\sandra\Desktop\~$sBeans PR Plan.doc
[2009/05/26 13:20:08 | 00,040,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/26 13:19:56 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/26 13:14:49 | 16,283,032 | —- | M] () – C:\Documents and Settings\sandra\Desktop\jre-6u13-windows-i586-p.exe
[2009/05/26 00:11:54 | 00,000,817 | —- | M] () – C:\WINDOWS\win.ini
[2009/05/26 00:11:54 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/05/26 00:11:54 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/05/25 20:23:29 | 00,286,208 | —- | M] () – C:\Documents and Settings\sandra\Desktop\urmrtj8x.exe
[2009/05/25 20:13:41 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/05/23 18:56:15 | 02,977,615 | R— | M] () – C:\Documents and Settings\sandra\Desktop\ComboFix.exe
[2009/05/23 18:37:55 | 00,000,211 | —- | M] () – C:\Boot.bak
[2009/05/23 18:16:58 | 00,132,597 | —- | M] () – C:\Documents and Settings\sandra\Desktop\Flash_Disinfector.exe
[2009/05/23 17:54:06 | 00,000,265 | —- | M] () – C:\WINDOWS\emug3.ini
[2009/05/23 17:25:44 | 00,139,776 | —- | M] () – C:\WINDOWS\PEV.exe
[2009/05/16 17:37:54 | 00,001,734 | —- | M] () – C:\Documents and Settings\sandra\Desktop\HijackThis.lnk
[2009/05/16 00:06:25 | 00,005,924 | —- | M] () – C:\WINDOWS\ProxyServer.bak
[2009/05/15 22:03:14 | 00,000,471 | —- | M] () – C:\WINDOWS\CommPipe.bak
[2009/05/15 22:03:14 | 00,000,390 | —- | M] () – C:\WINDOWS\SbLsp.bak
[2009/05/11 16:00:59 | 00,325,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/05/11 16:00:59 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/05/11 16:00:59 | 00,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/05/11 16:00:56 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/05/09 16:19:34 | 00,271,784 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/05/09 16:04:13 | 00,552,920 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/05/09 16:04:13 | 00,480,600 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/05/09 16:04:13 | 00,082,426 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/05/06 00:14:38 | 00,080,896 | -HS- | M] () – C:\Documents and Settings\sandra\Desktop\Thumbs.db

========== Alternate Data Streams ==========

@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0F8F5844
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5BB923A2
< End of report >
Hello.

We're almost done over here ;)

Please navigate to the following location and delete the following file.

C:\WINDOWS\system32\drivers\etc\hosts.msn <- Delete this file

Then could you post the Extras.txt log as well. Delete Extras.txt you currently have and re-run OTListIT2, post just the Extras.txt in your next reply.

With Regards,
Extremeboy

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI