This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Browser Redirect, AV killer, MS Update Killer,

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am at my wits end here, and if I could find my install CD's I'd simply wipe and start over. Here's my problem. I have
1. A browser redirect, in firefox, that sends me to toseeka.com, advancedfeed.com, and a few others, whenever I click on any link
2. Something keeps disabling Panda AVPro on my machine, by causing '… has encountered a problem and needs to close.' errors
3. Something keeps causing select programs to routinely crash. Steam (Sierra programs, HL etc.) Microsoft updaters, anything WotC, CIV4 games, DOS programs…
4. Something has corrupted my RTHDCPL.exe file, and it fails to initialize and crashes everytime my computer restarts
5. My computer keeps finding an SM Bus Controller upon start-up, even though I've added nothing to it since I built it.
6. My computer is incredibly sloooowwww, and seems to 'grind' for a long time after my AV is shut down.
7. I can't save any changes I make to IE, it keeps reporting an unknown error. (I very rarely use IE anyway)
8. My firefox browser will randomly load as if I'm on a mobile device. (http://m.www.yahoo.com instead of http://www.yahoo.com)

Panda AV, Trendmicro, Spybot, Malwarebytes AM, Ad-Aware…. nothing finds anything.

I have something listening on port 80 at 96.17.76.XXX and 96.17.77.XXX that seems active when I get problems, other times not.

I've deleted nearly anything I don't use or have reciprocally scanned, but considering my AV and AM tells me I'm 100% ok, I'm not sure I trust my attempts.

Any help, ideas, anything? Thanks in advance. HJ to follow.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:34:17 AM, on 8/5/2009
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files (x86)\Java\jre6\bin\jqs.exe
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PsCtrls.exe
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PavFnSvr.exe
C:\Program Files (x86)\Common Files\Panda Security\PavShld\pavprsrv.exe
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\pavsrvx86.exe
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\psimsvc.exe
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\AVENGINE.EXE
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PskSvc.exe
C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\Firewall\PSHOST.EXE
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\apvxdwin.exe
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\TPSrvWow.exe
C:\PROGRAM FILES (X86)\PANDA SECURITY\PANDA ANTIVIRUS PRO 2009\WebProxy.exe
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\IFACE.EXE
C:\PROGRA~2\MOZILL~1\FIREFOX.EXE
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\psimreal.exe
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\avciman.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
F2 - REG:system.ini: UserInit=c:\windows\syswow64\userinit.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files (x86)\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\Inicio.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Ad-Watch] "C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe"
O4 - HKCU\..\Run: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files (x86)\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O15 - ESC Trusted Zone: http://runonce.msn.com
O23 - Service: avast!Antivirus - Unknown owner - C:\WINDOWS\System32\avast!Antivirus.exe (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe (file missing)
O23 - Service: Event Log (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe (file missing)
O23 - Service: HTTP SSL (HTTPFilter) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files (x86)\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Distributed Transaction Coordinator (MSDTC) - Unknown owner - C:\WINDOWS\system32\msdtc.exe (file missing)
O23 - Service: Net Logon (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NT LM Security Support Provider (NtLmSsp) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\WINDOWS\system32\nvsvc64.exe (file missing)
O23 - Service: Panda Software Controller - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Security, S.L. - C:\Program Files (x86)\Common Files\Panda Security\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\pavsrvx86.exe
O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe (file missing)
O23 - Service: IPSEC Services (PolicyAgent) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Protected Storage (ProtectedStorage) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Panda Host Service (PSHost) - Panda Software International - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\Firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Security S.L. - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\psimsvc.exe
O23 - Service: Panda PSK service (PskSvcRetail) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PskSvc.exe
O23 - Service: Remote Desktop Help Session Manager (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe (file missing)
O23 - Service: Security Accounts Manager (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: Telnet (TlntSvr) - Unknown owner - C:\WINDOWS\system32\tlntsvr.exe (file missing)
O23 - Service: Panda TPSrv (TPSrv) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\TPSrvWow.exe
O23 - Service: Virtual Disk Service (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: Volume Shadow Copy (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe (file missing)
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe (file missing)

–
End of file - 8927 bytes
netstat -a results Active Connections Proto Local Address Foreign Address State TCP thunderdome:epmap thunderdome:0 LISTENING TCP thunderdome:microsoft-ds thunderdome:0 LISTENING TCP thunderdome:1026 thunderdome:0 LISTENING TCP thunderdome:netbios-ssn thunderdome:0 LISTENING TCP thunderdome:2065 a96-17-77-120.deploy.akamaitechnologies.com:http CLOSE_WAIT TCP thunderdome:3363 a96-17-77-97.deploy.akamiatechnologies.com:http ESTABLISHED TCP thunderdome:3369 vx-in-f102.google.com:http ESTABLISHED TCP thunderdome:3408 a96-17-150-32.deploy.akamaitechnologies.com:http TIME WAIT TCP thunderdome:1028 thunderdome:0 LISTENING TCP thunderdome:2438 thunderdome:2439 ESTABLISHED TCP thunderdome:2439 thunderdome:2438 ESTABLISHED **There's a few more like these, reciprocally listening UDP thunderdome:microsoft-ds *.* UDP thunderdome:iskamp *.* UDP thunderdome:1025 *.* UDP thunderdome:ipsec-msft *.* UDP thunderdome:ntp *.* UDP thunderdome:netbios-ns *.* UDP thunderdome:netbios-dgm *.* UDP thunderdome:ssdp *.* UDP thunderdome:ntp *.* UDP thunderdome:ssdp *.* UDP thunderdome:18001 *.* UDP thunderdome:18002 *.* Don't know if this will help, but the last time I had a problem the admin asked me to run, copy, paste
I followed advice on another topic and ATF'd and then MBAM'd my computer, and got this log. Interestingly enough, immediately after I deleted the KEY my Panda AV 'encountered a system error' and was closed. Malwarebytes' Anti-Malware 1.40 Database version: 2578 Windows 5.2.3790 Service Pack 2 8/8/2009 6:50:04 AM mbam-log-2009-08-08 (06-50-04).txt Scan type: Quick Scan Objects scanned: 79517 Time elapsed: 2 minute(s), 15 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\avast!AntiVirus (Trojan.Agent) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi Mattressgnome,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.


Do you have AVAST installed? If so, uninstall it. You only want one Anti-virus program.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Thanks for the help! I don't have Avast! installed that I know of. I'm running Windows XP 64 Pro and had to try several AV programs until one worked, and uninstalled the ones that did not. Whether they left registry entries or loose files I don't know. Currently I run/wish to run Panda AV (even though it sucks IMHO), Spybot, and Ad-Aware. If these are mutually exclusive, please let me know. As for Kaspersky. I ran it a few days ago with no results, and when I went to run it a few minutes ago I got this error message. "Update has failed. Program has failed to start. Close the Kaspersky Online Scanner 7.0 window and open it again to install the program. You must be online to update the Kaspersky Online Scanner 7.0 database. With the latest database updates, you can find new viruses and other threats. Please go online to use Kaspersky Online Scanner 7.0. [ERROR: Key is expired]" I am online, obviously, and no amount or closing of windows, refreshing, emptying cookies seems to get me past this. Thanks again!
Mattressgnome,

Let's get a deeper look.

Please download gmer.zip from Gmer and save it to your desktop.

  • Right click on gmer.zip and select Extract All….
  • Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
  • Click on the Browse button. Click on Desktop. Then click OK.
  • Click Next. It will start extracting.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Double click on gmer.exe to run it.
  • Select the Rootkit tab.
  • On the right hand side, check all the items to be scanned, but leave Show All box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click on the Scan button.
  • When the scan is finished, click Copy to save the scan log to the Windows clipboard.
  • Open Notepad or a similar text editor.
  • Paste the clipboard contents into the text editor.
  • Save the Gmer scan log and post it in your next reply.

Note: Do not run any programs while Gmer is running.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
GMER scan to follow

GMER 1.0.15.15020 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-08-10 16:17:31
Windows 5.2.3790 Service Pack 2


—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF4 0x9D 0xE2 0xF9 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF4 0x9D 0xE2 0xF9 …

—- EOF - GMER 1.0.15 —-


DDS gave me an error message, "This tool does not support your operating system. Press any key to continue…"
Maybe because I'm running XP 64bit?
Mattressgnome,

Yep. That would do it. :blush:

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
OTL Extras logfile created on: 8/10/2009 11:48:48 PM - Run 1
OTL by OldTimer - Version 3.0.10.5 Folder = C:\Documents and Settings\Administrator\Desktop
64bit-Windows Server 2003 Service Pack 2 (Version = 5.2.3790) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.01 Gb Available Physical Memory | 75.30% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149.00 Gb Total Space | 20.34 Gb Free Space | 13.65% Space Free | Partition Type: NTFS
Drive D: | 4.14 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: THUNDERDOME
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html[@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.inf[@ = inffile] – C:\WINDOWS\SysNative\NOTEPAD.EXE File not found
.ini[@ = inifile] – C:\WINDOWS\SysNative\NOTEPAD.EXE File not found
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
.js[@ = JSFile] – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PAVSCRIP.EXE (Panda Security, S.L.)
.jse[@ = JSEFile] – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PAVSCRIP.EXE (Panda Security, S.L.)
.txt[@ = txtfile] – C:\WINDOWS\SysNative\NOTEPAD.EXE File not found
.vbe[@ = VBEFile] – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PAVSCRIP.EXE (Panda Security, S.L.)
.vbs[@ = VBSFile] – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PAVSCRIP.EXE (Panda Security, S.L.)
.wsf[@ = WSFFile] – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PAVSCRIP.EXE (Panda Security, S.L.)
.wsh[@ = WSHFile] – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PAVSCRIP.EXE (Panda Security, S.L.)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.js [@ = JSFile] – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PAVSCRIP.EXE (Panda Security, S.L.)
.jse [@ = JSEFile] – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PAVSCRIP.EXE (Panda Security, S.L.)
.reg [@ = regfile] – C:\WINDOWS\SysWow64\regedit.exe (Microsoft Corporation)
.vbe [@ = VBEFile] – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PAVSCRIP.EXE (Panda Security, S.L.)
.vbs [@ = VBSFile] – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PAVSCRIP.EXE (Panda Security, S.L.)
.wsf [@ = WSFFile] – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PAVSCRIP.EXE (Panda Security, S.L.)
.wsh [@ = WSHFile] – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PAVSCRIP.EXE (Panda Security, S.L.)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – File not found
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – File not found
"C:\Program Files (x86)\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword.exe" = C:\Program Files (x86)\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword – (Firaxis Games)
"C:\Program Files (x86)\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword_Pitboss.exe" = C:\Program Files (x86)\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword_Pitboss.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword Pitboss – (Firaxis Games)
"C:\Program Files (x86)\Steam\steamapps\mattressgnome\team fortress 2\hl2.exe" = C:\Program Files (x86)\Steam\steamapps\mattressgnome\team fortress 2\hl2.exe:*:Enabled:hl2 – ()
"C:\Program Files (x86)\Azureus\Azureus.exe" = C:\Program Files (x86)\Azureus\Azureus.exe:*:Enabled:Azureus – (Azureus Inc)
"C:\Program Files (x86)\Sony\Station\LaunchPad\LaunchPad.exe" = C:\Program Files (x86)\Sony\Station\LaunchPad\LaunchPad.exe:*:Enabled:LaunchPad – File not found
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – File not found
"C:\WINDOWS\system32\rundll32.exe" = C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App – File not found
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" = C:\Program Files (x86)\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files (x86)\Common Files\AOL\Loader\aolload.exe" = C:\Program Files (x86)\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – File not found
"C:\Program Files (x86)\Real\RealPlayer\realplay.exe" = C:\Program Files (x86)\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files (x86)\Steam\steamapps\mattressgnome\source sdk base\hl2.exe" = C:\Program Files (x86)\Steam\steamapps\mattressgnome\source sdk base\hl2.exe:*:Enabled:hl2 – ()
"C:\Program Files (x86)\Steam\steamapps\mattressgnome\day of defeat source\hl2.exe" = C:\Program Files (x86)\Steam\steamapps\mattressgnome\day of defeat source\hl2.exe:*:Enabled:hl2 – ()
"C:\Program Files (x86)\SecondLife\SLVoice.exe" = C:\Program Files (x86)\SecondLife\SLVoice.exe:*:Enabled:SLVoice – File not found
"C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" = C:\Program Files (x86)\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager – File not found
"C:\Program Files (x86)\Curse\CurseClient.exe" = C:\Program Files (x86)\Curse\CurseClient.exe:*:Enabled:Curse Client – File not found
"C:\Program Files (x86)\NetstormLaunch\package\Netstorm.exe" = C:\Program Files (x86)\NetstormLaunch\package\Netstorm.exe:*:Enabled:Netstorm – ()
"C:\Program Files (x86)\Steam\steam.exe" = C:\Program Files (x86)\Steam\steam.exe:*:Enabled:Steam – (Valve Corporation)
"C:\Documents and Settings\Administrator\Desktop\SRO_Full-Client_Downloader.exe" = C:\Documents and Settings\Administrator\Desktop\SRO_Full-Client_Downloader.exe:*:Enabled:Full-Client Downloader – File not found
"C:\Program Files (x86)\Steam\steamapps\common\xcom ufo defense\dosbox.exe" = C:\Program Files (x86)\Steam\steamapps\common\xcom ufo defense\dosbox.exe:*:Enabled:X-COM: UFO Defense – (DOSBox Team)
"C:\Program Files (x86)\Steam\steamapps\common\x-com terror from the deep\runme.exe" = C:\Program Files (x86)\Steam\steamapps\common\x-com terror from the deep\runme.exe:*:Enabled:X-COM: Terror from the Deep – ()
"C:\Program Files (x86)\Steam\steamapps\common\xcom interceptor\Interceptor.exe" = C:\Program Files (x86)\Steam\steamapps\common\xcom interceptor\Interceptor.exe:*:Enabled:X-COM: Interceptor – ()
"C:\Program Files (x86)\Steam\steamapps\common\xcom enforcer\System\XCom.exe" = C:\Program Files (x86)\Steam\steamapps\common\xcom enforcer\System\XCom.exe:*:Enabled:X-COM: Enforcer – ()
"C:\Program Files (x86)\Steam\steamapps\common\ricochet lost worlds\Ricochet.exe" = C:\Program Files (x86)\Steam\steamapps\common\ricochet lost worlds\Ricochet.exe:*:Enabled:Ricochet: Lost Worlds – ()
"C:\Program Files (x86)\Steam\steamapps\common\xcom apocalypse\dosbox.exe" = C:\Program Files (x86)\Steam\steamapps\common\xcom apocalypse\dosbox.exe:*:Enabled:X-COM: Apocalypse – (DOSBox Team)
"C:\Documents and Settings\Administrator\Local Settings\Temp\7zS19.tmp\SymNRT.exe" = C:\Documents and Settings\Administrator\Local Settings\Temp\7zS19.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool – File not found
"C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" = C:\Program Files (x86)\VideoLAN\VLC\vlc.exe:*:Enabled:vlc – ()
"C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\ApVxdWin.exe" = C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\ApVxdWin.exe:*:Enabled:ApvxdWin – (Panda Security, S.L.)
"C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\TPSrvWow.exe" = C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\TPSrvWow.exe:*:Enabled:TPSrvWow – (Panda Security, S.L.)
"C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtcmd.exe" = C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtcmd.exe:*:Enabled:sprtcmd – (SupportSoft, Inc.)
"C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtsvc.exe" = C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtsvc.exe:*:Enabled:sprtsvc – (SupportSoft, Inc.)
"C:\Program Files (x86)\Steam\steamapps\common\empire total war\Empire.exe" = C:\Program Files (x86)\Steam\steamapps\common\empire total war\Empire.exe:*:Enabled:Empire: Total War – (The Creative Assembly Ltd)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – File not found
"C:\Program Files (x86)\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword.exe" = C:\Program Files (x86)\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword – (Firaxis Games)
"C:\Program Files (x86)\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword_Pitboss.exe" = C:\Program Files (x86)\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword_Pitboss.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword Pitboss – (Firaxis Games)
"C:\Program Files (x86)\Steam\steamapps\mattressgnome\team fortress 2\hl2.exe" = C:\Program Files (x86)\Steam\steamapps\mattressgnome\team fortress 2\hl2.exe:*:Enabled:hl2 – ()
"C:\Program Files (x86)\Azureus\Azureus.exe" = C:\Program Files (x86)\Azureus\Azureus.exe:*:Enabled:Azureus – (Azureus Inc)
"C:\Program Files (x86)\Sony\Station\LaunchPad\LaunchPad.exe" = C:\Program Files (x86)\Sony\Station\LaunchPad\LaunchPad.exe:*:Enabled:LaunchPad – File not found
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" = C:\Program Files (x86)\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files (x86)\Common Files\AOL\Loader\aolload.exe" = C:\Program Files (x86)\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – File not found
"C:\Program Files (x86)\Real\RealPlayer\realplay.exe" = C:\Program Files (x86)\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files (x86)\Steam\steamapps\mattressgnome\source sdk base\hl2.exe" = C:\Program Files (x86)\Steam\steamapps\mattressgnome\source sdk base\hl2.exe:*:Enabled:hl2 – ()
"C:\Program Files (x86)\Steam\steamapps\mattressgnome\day of defeat source\hl2.exe" = C:\Program Files (x86)\Steam\steamapps\mattressgnome\day of defeat source\hl2.exe:*:Enabled:hl2 – ()
"C:\Program Files (x86)\SecondLife\SLVoice.exe" = C:\Program Files (x86)\SecondLife\SLVoice.exe:*:Enabled:SLVoice – File not found
"C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" = C:\Program Files (x86)\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager – File not found
"C:\Program Files (x86)\Curse\CurseClient.exe" = C:\Program Files (x86)\Curse\CurseClient.exe:*:Enabled:Curse Client – File not found
"C:\Program Files (x86)\NetstormLaunch\package\Netstorm.exe" = C:\Program Files (x86)\NetstormLaunch\package\Netstorm.exe:*:Enabled:Netstorm – ()
"C:\Program Files (x86)\Steam\steam.exe" = C:\Program Files (x86)\Steam\steam.exe:*:Enabled:Steam – (Valve Corporation)
"C:\Documents and Settings\Administrator\Desktop\SRO_Full-Client_Downloader.exe" = C:\Documents and Settings\Administrator\Desktop\SRO_Full-Client_Downloader.exe:*:Enabled:Full-Client Downloader – File not found
"C:\Program Files (x86)\Steam\steamapps\common\xcom ufo defense\dosbox.exe" = C:\Program Files (x86)\Steam\steamapps\common\xcom ufo defense\dosbox.exe:*:Enabled:X-COM: UFO Defense – (DOSBox Team)
"C:\Program Files (x86)\Steam\steamapps\common\x-com terror from the deep\runme.exe" = C:\Program Files (x86)\Steam\steamapps\common\x-com terror from the deep\runme.exe:*:Enabled:X-COM: Terror from the Deep – ()
"C:\Program Files (x86)\Steam\steamapps\common\xcom interceptor\Interceptor.exe" = C:\Program Files (x86)\Steam\steamapps\common\xcom interceptor\Interceptor.exe:*:Enabled:X-COM: Interceptor – ()
"C:\Program Files (x86)\Steam\steamapps\common\xcom enforcer\System\XCom.exe" = C:\Program Files (x86)\Steam\steamapps\common\xcom enforcer\System\XCom.exe:*:Enabled:X-COM: Enforcer – ()
"C:\Program Files (x86)\Steam\steamapps\common\ricochet lost worlds\Ricochet.exe" = C:\Program Files (x86)\Steam\steamapps\common\ricochet lost worlds\Ricochet.exe:*:Enabled:Ricochet: Lost Worlds – ()
"C:\Program Files (x86)\Steam\steamapps\common\xcom apocalypse\dosbox.exe" = C:\Program Files (x86)\Steam\steamapps\common\xcom apocalypse\dosbox.exe:*:Enabled:X-COM: Apocalypse – (DOSBox Team)
"C:\Documents and Settings\Administrator\Local Settings\Temp\7zS19.tmp\SymNRT.exe" = C:\Documents and Settings\Administrator\Local Settings\Temp\7zS19.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool – File not found
"C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" = C:\Program Files (x86)\VideoLAN\VLC\vlc.exe:*:Enabled:vlc – ()
"C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\ApVxdWin.exe" = C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\ApVxdWin.exe:*:Enabled:ApvxdWin – (Panda Security, S.L.)
"C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\TPSrvWow.exe" = C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\TPSrvWow.exe:*:Enabled:TPSrvWow – (Panda Security, S.L.)
"C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtcmd.exe" = C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtcmd.exe:*:Enabled:sprtcmd – (SupportSoft, Inc.)
"C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtsvc.exe" = C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtsvc.exe:*:Enabled:sprtsvc – (SupportSoft, Inc.)
"C:\Program Files (x86)\Steam\steamapps\common\empire total war\Empire.exe" = C:\Program Files (x86)\Steam\steamapps\common\empire total war\Empire.exe:*:Enabled:Empire: Total War – (The Creative Assembly Ltd)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{2BA00471-0328-3743-93BD-FA813353A783}" = Microsoft .NET Framework 3.0 Service Pack 1
"{2FC099BD-AC9B-33EB-809C-D332E1B27C40}" = Microsoft .NET Framework 3.5
"{5254156F-AA77-499A-B7C1-D5581D44E788}" = Marvell Miniport Driver
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8A7CAA24-7B23-410B-A7C3-F994B0944160}" = Microsoft Virtual PC 2007
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Microsoft .NET Framework 3.5" = Microsoft .NET Framework 3.5
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows x64
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows x64 Service Pack" = Windows XP Service Pack 2
"WMFDist11-64" = Windows Media Format 11 runtime
"wmp11-64" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02DFF6B1-1654-411C-8D7B-FD6052EF016F}" = Apple Software Update
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{51834149-2F93-4EC7-AA13-46FC93CD028C}" = Panda Antivirus Pro 2009
"{54AE3C08-D7D8-45FF-9348-0B4BE0D5A6CB}" = Comcast Universal Installer v1.2
"{626C034B-50B8-47BD-AF93-EEFD0FA78FF4}" = Character Builder
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.0.0.1
"{81E2D8D7-F104-4EB9-97A7-98996A611FF6}" = Sid Meier's Civilization 4 - Beyond the Sword
"{90840409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Excel Viewer 2003
"{A8589680-35C1-4732-ACCA-09B78921ECE3}" = Sid Meier's Civilization 4
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BFD96B89-B769-4CD6-B11E-E79FFD46F067}" = QuickTime
"{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}" = Sid Meier's Civilization 4
"{D12B1C49-D62F-46B6-9C4A-9E40664F0D52}" = Panda Antivirus Pro 2009
"{D87149B3-7A1D-4548-9CBF-032B791E5908}" = Desktop Doctor
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E55FB276-73C9-4776-AB53-BC028C0509ED}" = Panda Antivirus Pro 2009
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Ad-Aware" = Ad-Aware
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Azureus Vuze" = Azureus Vuze
"DECCHECK" = Microsoft Windows XP Video Decoder Checkup Utility
"HijackThis" = HijackThis 2.0.2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.0.13)" = Mozilla Firefox (3.0.13)
"NetstormLaunch" = Netstorm Launcher (Console)
"PoxNora [removed]" = PoxNora [removed]
"RealPlayer 6.0" = RealPlayer
"Security Task Manager" = Security Task Manager 1.7h
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"Steam App 10500" = Empire: Total War
"Steam App 215" = Source SDK Base
"Steam App 240" = Counter-Strike: Source
"Steam App 300" = Day of Defeat: Source
"Steam App 440" = Team Fortress 2
"Steam App 7400" = Ricochet: Lost Worlds
"Steam App 7650" = X-COM: Terror from the Deep
"Steam App 7660" = X-Com: Apocalypse
"Steam App 7730" = X-Com: Interceptor
"Steam App 7760" = X-Com: UFO Defense
"Steam App 7770" = X-Com: Enforcer
"VLC media player" = VideoLAN VLC media player 0.8.6i
"Winamp" = Winamp
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Media Player" = Move Media Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/5/2009 8:48:07 AM | Computer Name = THUNDERDOME | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 temprealcharacterbuilderupdater, P2 1.0.0.0,
P3 49f18ebd, P4 presentationframework, P5 3.0.0.0, P6 470bf5f6, P7 b60, P8 f, P9
system.typeloadexception, P10 NIL.

Error - 8/5/2009 8:48:23 AM | Computer Name = THUNDERDOME | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 temprealcharacterbuilderupdater, P2 1.0.0.0,
P3 49f18ebd, P4 presentationframework, P5 3.0.0.0, P6 470bf5f6, P7 b60, P8 f, P9
system.typeloadexception, P10 NIL.

Error - 8/5/2009 8:49:20 AM | Computer Name = THUNDERDOME | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 temprealcharacterbuilderupdater, P2 1.0.0.0,
P3 49f18ebd, P4 presentationframework, P5 3.0.0.0, P6 470bf5f6, P7 b60, P8 f, P9
system.typeloadexception, P10 NIL.

Error - 8/5/2009 8:59:20 AM | Computer Name = THUNDERDOME | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 temprealcharacterbuilderupdater, P2 1.0.0.0,
P3 49f18ebd, P4 presentationframework, P5 3.0.0.0, P6 470bf5f6, P7 b60, P8 f, P9
system.typeloadexception, P10 NIL.

Error - 8/5/2009 8:59:34 AM | Computer Name = THUNDERDOME | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 charactersheetviewer.exe, P2 [removed], P3 49f18e99,
P4 charactersheetviewer, P5 1.0.60.0, P6 49f18e99, P7 34, P8 0, P9 system.typeloadexception,
P10 NIL.

Error - 8/5/2009 9:03:20 AM | Computer Name = THUNDERDOME | Source = Application Error | ID = 1000
Description = Faulting application TPSrvWow.exe, version 9.0.0.0, faulting module
msvcr80.dll, version 8.0.50727.3053, fault address 0x00008aa0.

Error - 8/5/2009 10:22:37 AM | Computer Name = THUNDERDOME | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Failed to compile: System.Speech, Version=3.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
. Error code = 0x80131018

Error - 8/6/2009 4:04:39 AM | Computer Name = THUNDERDOME | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 temprealcharacterbuilderupdater, P2 1.0.0.0,
P3 49f18ebd, P4 presentationframework, P5 3.0.0.0, P6 470bf5f6, P7 b60, P8 f, P9
system.typeloadexception, P10 NIL.

Error - 8/8/2009 6:50:26 AM | Computer Name = THUNDERDOME | Source = Application Error | ID = 1000
Description = Faulting application TPSrvWow.exe, version 9.0.0.0, faulting module
msvcr80.dll, version 8.0.50727.3053, fault address 0x00008aa0.

Error - 8/8/2009 7:55:59 AM | Computer Name = THUNDERDOME | Source = Application Error | ID = 1000
Description = Faulting application TPSrvWow.exe, version 9.0.0.0, faulting module
msvcr80.dll, version 8.0.50727.3053, fault address 0x00008aa0.

[ System Events ]
Error - 8/8/2009 6:56:19 AM | Computer Name = THUNDERDOME | Source = DCOM | ID = 10016
Description = The machine-default permission settings do not grant Local Activation
permission for the COM Server application with CLSID {555F3418-D99E-4E51-800A-6E89CFD8B1D7}

to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19). This security permission
can be modified using the Component Services administrative tool.

Error - 8/8/2009 6:56:19 AM | Computer Name = THUNDERDOME | Source = DCOM | ID = 10016
Description = The machine-default permission settings do not grant Local Activation
permission for the COM Server application with CLSID {555F3418-D99E-4E51-800A-6E89CFD8B1D7}

to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19). This security permission
can be modified using the Component Services administrative tool.

Error - 8/8/2009 6:59:12 AM | Computer Name = THUNDERDOME | Source = DCOM | ID = 10010
Description = The server {49BD2028-1523-11D1-AD79-00C04FD8FDFF} did not register
with DCOM within the required timeout.

Error - 8/8/2009 7:00:14 AM | Computer Name = THUNDERDOME | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Application Layer Gateway
Service service to connect.

Error - 8/8/2009 7:00:14 AM | Computer Name = THUNDERDOME | Source = Service Control Manager | ID = 7000
Description = The Application Layer Gateway Service service failed to start due
to the following error: %%1053

Error - 8/8/2009 7:00:14 AM | Computer Name = THUNDERDOME | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the NVSvc service.

Error - 8/8/2009 7:00:14 AM | Computer Name = THUNDERDOME | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Panda Software Controller service.

Error - 8/8/2009 7:56:37 AM | Computer Name = THUNDERDOME | Source = Service Control Manager | ID = 7034
Description = The Panda TPSrv service terminated unexpectedly. It has done this
1 time(s).

Error - 8/9/2009 3:00:19 AM | Computer Name = THUNDERDOME | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Flash Player (KB913433).

Error - 8/10/2009 3:00:15 AM | Computer Name = THUNDERDOME | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Flash Player (KB913433).


< End of report >
OTL logfile created on: 8/10/2009 11:48:48 PM - Run 1
OTL by OldTimer - Version 3.0.10.5 Folder = C:\Documents and Settings\Administrator\Desktop
64bit-Windows Server 2003 Service Pack 2 (Version = 5.2.3790) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.01 Gb Available Physical Memory | 75.30% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149.00 Gb Total Space | 20.34 Gb Free Space | 13.65% Space Free | Partition Type: NTFS
Drive D: | 4.14 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: THUNDERDOME
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2009/03/31 17:50:42 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Java\jre6\bin\jqs.exe
PRC - [2008/07/16 14:45:20 | 00,181,504 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PsCtrls.exe
PRC - [2008/07/10 12:02:00 | 00,169,216 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PavFnSvr.exe
PRC - [2008/02/04 17:26:48 | 00,062,768 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Common Files\Panda Security\PavShld\pavprsrv.exe
PRC - [2008/06/19 12:59:50 | 00,108,288 | —- | M] (Panda Security S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\psimsvc.exe
PRC - [2008/06/25 16:43:08 | 00,028,928 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PskSvc.exe
PRC - [2008/04/24 14:26:18 | 00,202,560 | —- | M] (SupportSoft, Inc.) – C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtsvc.exe
PRC - [2008/06/12 15:31:40 | 00,226,608 | —- | M] (Panda Software International) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\Firewall\PSHOST.EXE
PRC - [2009/07/15 07:20:02 | 00,881,920 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\ApvxdWin.exe
PRC - [2008/07/04 14:28:34 | 00,290,048 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\pavsrvx86.exe
PRC - [2008/07/02 13:26:56 | 00,193,792 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\AVENGINE.EXE
PRC - [2008/04/24 14:25:22 | 00,202,560 | —- | M] (SupportSoft, Inc.) – C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtcmd.exe
PRC - [2009/03/31 17:50:42 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Java\jre6\bin\jusched.exe
PRC - [2008/07/17 13:44:18 | 00,173,824 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\TPSrvWow.exe
PRC - [2008/05/14 18:21:02 | 00,107,824 | —- | M] (Panda Security, S.L.) – C:\PROGRAM FILES (X86)\PANDA SECURITY\PANDA ANTIVIRUS PRO 2009\WebProxy.exe
PRC - [2008/07/19 20:54:42 | 00,747,776 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\Upgrader.exe
PRC - [2008/04/12 21:17:41 | 00,185,632 | —- | M] (RealNetworks, Inc.) – C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
PRC - [2009/07/01 20:32:11 | 01,029,456 | —- | M] (Lavasoft) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2009/06/29 20:34:49 | 00,520,024 | —- | M] (Lavasoft) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2009/08/10 23:41:02 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe

========== Win32 Services (SafeList) ==========

SRV - [2007/10/23 22:33:00 | 00,045,576 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework64\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2007/10/24 01:47:40 | 00,070,144 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2007/10/23 22:33:04 | 00,093,696 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_64 [On_Demand | Stopped])
SRV - [2007/10/09 15:06:28 | 00,036,864 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/07/02 14:09:42 | 00,072,448 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\Gwmsrv64.dll – (Gwmsrv [Auto | Running])
SRV - [2007/02/17 01:44:20 | 00,077,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2005/03/25 08:00:00 | 00,162,816 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWOW64\iasrecst.dll – (IASJet [On_Demand | Stopped])
SRV - [2005/04/04 00:41:10 | 00,069,632 | —- | M] (Macrovision Corporation) – C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2007/10/10 22:08:40 | 00,921,600 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2009/03/31 17:50:42 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2009/07/01 20:32:11 | 01,029,456 | —- | M] (Lavasoft) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service [Auto | Running])
SRV - [2007/02/18 12:05:42 | 00,430,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\netlogon.dll – (Netlogon [On_Demand | Stopped])
SRV - [2003/07/28 12:28:22 | 00,089,136 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2008/07/16 14:45:20 | 00,181,504 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PsCtrls.exe – (Panda Software Controller [Auto | Running])
SRV - [2008/07/10 12:02:00 | 00,169,216 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PavFnSvr.exe – (PAVFNSVR [Auto | Running])
SRV - [2008/02/04 17:26:48 | 00,062,768 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Common Files\Panda Security\PavShld\pavprsrv.exe – (PavPrSrv [Auto | Running])
SRV - [2008/07/04 14:28:34 | 00,290,048 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\pavsrvx86.exe – (PAVSRV [Auto | Running])
SRV - [2008/06/12 15:31:40 | 00,226,608 | —- | M] (Panda Software International) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\Firewall\PSHOST.EXE – (PSHost [Auto | Running])
SRV - [2008/06/19 12:59:50 | 00,108,288 | —- | M] (Panda Security S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\psimsvc.exe – (PSIMSVC [Auto | Running])
SRV - [2008/06/25 16:43:08 | 00,028,928 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PskSvc.exe – (PskSvcRetail [Auto | Running])
SRV - [2008/04/24 14:26:18 | 00,202,560 | —- | M] (SupportSoft, Inc.) – C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtsvc.exe – (sprtsvc_ddoctorv2 [Auto | Running])
SRV - [2008/07/17 13:44:18 | 00,173,824 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\TPSrvWow.exe – (TPSrv [Auto | Running])
SRV - [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2009/02/23 19:05:39 | 00,000,000 | —D | M] – C:\WINDOWS\FltMgr – (FltMgr [Boot | Running])
DRV - [2005/03/25 08:00:00 | 00,033,792 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\mnmdd.dll – (mnmdd [System | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Yoog Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13
FF - prefs.js..keyword.URL: "http://www10.yoog.com/search.php?q="

FF - user.js..browser.search.selectedEngine: "Yoog Search"
FF - user.js..keyword.URL: "http://www10.yoog.com/search.php?q="
FF - user.js..keyword.enabled: true

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files (x86)\Java\jre6\lib\deploy\jqs\ff [2009/03/31 17:50:43 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2009/08/06 23:22:43 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2009/08/05 08:14:36 | 00,000,000 | —D | M]

[2008/08/29 01:54:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions
[2008/08/29 01:54:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/07/12 15:37:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Firefox\Profiles\08p9vs40.default\extensions
[2009/08/09 14:21:12 | 00,001,687 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Mozilla\FireFox\Profiles\08p9vs40.default\searchplugins\nutritiondata.xml
[2009/01/02 11:11:47 | 00,000,247 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Mozilla\FireFox\Profiles\08p9vs40.default\searchplugins\Yoog Search.xml
[2009/08/10 05:08:12 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions
[2009/08/05 08:14:36 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/31 17:50:54 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/08/05 08:14:31 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll
[2009/08/05 08:14:31 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll
[2007/11/29 18:31:02 | 00,479,232 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\msvcm80.dll
[2007/11/29 18:31:02 | 00,548,864 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\msvcp80.dll
[2007/11/29 18:31:04 | 00,626,688 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\msvcr80.dll
[2007/04/10 18:21:08 | 00,163,256 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll
[2009/01/16 20:17:04 | 00,114,688 | —- | M] (Adobe Systems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\np32dsw.dll
[2007/02/10 17:59:00 | 00,806,912 | —- | M] ( ) – C:\Program Files (x86)\mozilla firefox\plugins\npActiveGS.dll
[2009/03/31 17:50:43 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeploytk.dll
[2007/10/11 15:17:50 | 01,435,688 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2009/08/05 08:14:32 | 00,065,528 | —- | M] (mozilla.org) – C:\Program Files (x86)\mozilla firefox\plugins\npnul32.dll
[2006/12/18 05:18:30 | 00,077,824 | —- | M] (Adobe Systems Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll
[2008/04/12 21:17:47 | 00,144,720 | —- | M] (RealNetworks, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll
[2008/02/25 15:39:04 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll
[2008/02/25 15:39:04 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll
[2008/02/25 15:39:04 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll
[2008/02/25 15:39:04 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll
[2008/02/25 15:39:04 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll
[2008/02/25 15:39:04 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll
[2008/02/25 15:39:04 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll
[2008/04/12 21:17:53 | 00,024,576 | —- | M] (RealNetworks, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\nprjplug.dll
[2008/04/12 21:17:44 | 00,081,920 | —- | M] (RealNetworks, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\nprpjplug.dll
[2007/04/16 13:07:12 | 00,180,293 | —- | M] () – C:\Program Files (x86)\mozilla firefox\plugins\npViewpoint.dll
[2008/07/02 12:31:38 | 00,001,394 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom.xml
[2008/07/02 12:31:38 | 00,002,193 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\answers.xml
[2008/07/02 12:31:38 | 00,001,534 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/13 05:43:34 | 00,002,343 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay.xml
[2008/07/02 12:31:38 | 00,001,706 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2008/07/02 12:31:38 | 00,001,178 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia.xml
[2008/07/02 12:31:38 | 00,000,792 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml

Hosts file not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files (x86)\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4:64bit: - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4:64bit: - HKLM..\Run: [AlcWzrd] C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\SysNative\NvCpl.DLL File not found
O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\SysNative\NvMcTray.DLL File not found
O4:64bit: - HKLM..\Run: [nwiz] File not found
O4:64bit: - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4:64bit: - HKLM..\Run: [SkyTel] C:\WINDOWS\SkyTel.EXE (Realtek Semiconductor Corp.)
O4:64bit: - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [APVXDWIN] C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\APVXDWIN.EXE (Panda Security, S.L.)
O4 - HKLM..\Run: [ddoctorv2] C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files (x86)\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SCANINICIO] C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\Inicio.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Steam] c:\program files (x86)\steam\steam.exe (Valve Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files (x86)\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O9:64bit: - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9:64bit: - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre6\bin\npjpi160_13.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15:64bit: - ..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKLM\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SysNative\mshtml.dll File not found
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SysNative\mshtml.dll File not found
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SysNative\mshtml.dll File not found
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SysNative\mshtml.dll File not found
O18:64bit: - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\SysNative\mshtml.dll File not found
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SysNative\mshtml.dll File not found
O18:64bit: - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\SysNative\wiascr.dll File not found
O18:64bit: - Protocol\Filter: - application/octet-stream - File not found
O18:64bit: - Protocol\Filter: - application/x-complus - File not found
O18:64bit: - Protocol\Filter: - application/x-msdownload - File not found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UIHost - (%SystemRoot%\system32\logonui.exe) - C:\WINDOWS\SysNative\logonui.exe File not found
O20:64bit: - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\SysWow64\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: System - (lsass.exe) - File not found
O20:64bit: - Winlogon\Notify\avldr: DllName - Reg Error: Value error. - File not found
O20:64bit: - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - File not found
O20:64bit: - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - File not found
O20:64bit: - Winlogon\Notify\cscdll: DllName - cscdll.dll - File not found
O20:64bit: - Winlogon\Notify\dimsntfy: DllName - dimsntfy.dll - File not found
O20:64bit: - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - File not found
O20:64bit: - Winlogon\Notify\Schedule: DllName - wlnotify.dll - File not found
O20:64bit: - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - File not found
O20:64bit: - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - File not found
O20:64bit: - Winlogon\Notify\termsrv: DllName - Reg Error: Value error. - File not found
O20:64bit: - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - File not found
O20 - Winlogon\Notify\avldr: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - File not found
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - File not found
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - File not found
O20 - Winlogon\Notify\termsrv: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - File not found
O21:64bit: - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\SysNative\stobject.dll File not found
O21:64bit: - SSODL: UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\SysNative\upnpui.dll File not found
O21:64bit: - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\SysNative\WPDShServiceObj.dll File not found
O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/11/07 22:53:42 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\SysWow64\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2 C:\WINDOWS\SysWow64\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2099/01/01 12:00:00 | 00,000,000 | -HS- | C] () – C:\WINDOWS\SysWow64\zeraseba.dll
[2009/08/10 23:40:44 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2009/08/10 16:18:26 | 00,359,932 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\dds.scr
[2009/08/10 16:18:21 | 00,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2009/08/10 15:31:31 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\gmer(2)
[2009/08/10 15:31:05 | 00,279,461 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\gmer(2).zip
[2009/08/09 14:41:46 | 00,145,495 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\3795385154_c52a6e73ab.jpg
[2009/08/08 06:45:47 | 03,942,048 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\Desktop\mbam-setup.exe
[2009/08/07 06:39:04 | 69,548,6782 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\StudentFriends—Episode-16.avi
[2009/08/07 01:30:46 | 00,278,846 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\gmer.zip
[2009/08/06 22:19:18 | 00,024,788 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\bustedtees.9577de9ebb920d053ef4f51d44843978.gif
[2009/08/05 16:05:57 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\goddesses
[2009/08/05 08:58:52 | 00,002,153 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Character Builder.lnk
[2009/08/05 08:58:50 | 00,000,000 | —D | C] – C:\Program Files (x86)\Wizards of the Coast
[2009/08/05 08:55:03 | 00,608,578 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\700_DDI_CB(2).exe
[2009/08/05 08:06:48 | 00,000,000 | —D | C] – C:\Program Files (x86)\MSBuild
[2009/08/05 08:06:44 | 00,000,000 | —D | C] – C:\Program Files\MSBuild
[2009/08/05 08:06:37 | 00,000,000 | —D | C] – C:\WINDOWS\SysWow64\XPSViewer
[2009/08/05 08:06:29 | 00,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2009/08/05 08:06:29 | 00,000,000 | —D | C] – C:\Program Files (x86)\Reference Assemblies
[2009/08/05 08:04:44 | 00,391,730 | —- | C] () – C:\WINDOWS\SysWow64\PerfStringBackup.INI
[2009/08/05 07:05:07 | 20,669,2864 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Administrator\Desktop\dotnetfx35.exe
[2009/08/05 06:56:57 | 00,122,992 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Administrator\Desktop\clwireg-x64.exe
[2009/08/05 06:45:29 | 02,959,376 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Administrator\Desktop\dotnetfx35setup.exe
[2009/08/05 06:40:46 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\ddi
[2009/08/05 05:06:00 | 00,060,568 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\rs005.jpg
[2009/08/05 04:59:44 | 00,136,802 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\rs001.jpg
[2009/08/01 17:53:21 | 00,034,473 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\n1380782321_30191200_414.jpg
[2009/07/29 18:11:04 | 00,000,000 | R-SD | C] – C:\WINDOWS\assembly
[2009/07/29 18:10:23 | 00,000,000 | —D | C] – C:\WINDOWS\Microsoft.NET
[2009/07/29 17:58:34 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\WotC Games
[2009/07/29 17:58:14 | 00,608,578 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\700_DDI_CB.exe
[2009/07/28 12:43:03 | 25,368,146 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\c8932fa141d6.wmv
[2009/07/25 18:40:57 | 00,035,229 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\cooper1952.jpg
[2009/07/25 18:39:48 | 00,045,855 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\n1064207944_30131462_4640.jpg
[2009/07/25 18:01:28 | 00,064,417 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\6093_1184953216984_1022854898_30587081_5179701_n.jpg
[2009/07/25 06:30:49 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\ybookself
[2009/07/21 20:55:48 | 00,001,666 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PoxNora.lnk
[2009/07/21 20:55:38 | 00,000,000 | —D | C] – C:\Program Files (x86)\PoxNora
[2009/07/21 20:54:06 | 15,087,616 | —- | C] (Octopi, Inc) – C:\Documents and Settings\Administrator\Desktop\PoxNora.exe
[2009/07/21 06:17:24 | 00,047,443 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30146852_337.jpg
[2009/07/21 06:16:57 | 00,044,009 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30146846_8302.jpg
[2009/07/21 06:16:29 | 00,046,932 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30146813_7295.jpg
[2009/07/21 06:13:37 | 00,038,316 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30253702_5922.jpg
[2009/07/21 06:07:38 | 00,034,882 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30406666_8089571.jpg
[2009/07/20 00:11:48 | 03,597,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\SysWow64\mshtml.dll
[2009/07/20 00:11:48 | 01,159,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\SysWow64\urlmon.dll
[2009/07/20 00:11:48 | 00,827,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\SysWow64\wininet.dll
[2009/07/20 00:11:48 | 00,268,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\SysWow64\iertutil.dll
[2009/07/20 00:11:48 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\SysWow64\url.dll
[2009/07/20 00:11:48 | 00,027,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\SysWow64\jsproxy.dll
[2009/07/19 06:02:17 | 00,269,311 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\152p0l.png
[2009/07/19 05:44:20 | 00,046,825 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\ryanhead.jpg
[2009/07/19 05:41:51 | 00,050,368 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\kseniahead.jpg
[2009/07/17 03:01:23 | 00,020,516 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\null.pdf
[2009/07/12 16:26:12 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\rob wedding
[2009/03/30 15:43:02 | 00,000,425 | —- | C] () – C:\WINDOWS\AvDetected.ini
[2009/01/14 19:59:31 | 00,000,615 | —- | C] () – C:\WINDOWS\tlknw4.ini
[2009/01/05 23:09:54 | 00,000,002 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/11/29 18:20:56 | 00,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2008/10/07 14:33:00 | 01,486,848 | —- | C] () – C:\WINDOWS\SysWow64\nview.dll
[2008/10/07 14:33:00 | 01,019,904 | —- | C] () – C:\WINDOWS\SysWow64\nvwimg.dll
[2008/07/09 22:10:24 | 00,034,308 | —- | C] () – C:\WINDOWS\SysWow64\bassmod.dll
[2007/11/07 23:45:58 | 00,002,467 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2007/11/07 23:45:38 | 00,010,288 | —- | C] () – C:\WINDOWS\SysWow64\drivers\ASUSHWIO.SYS
[2007/11/07 22:52:15 | 00,000,570 | —- | C] () – C:\WINDOWS\win.ini
[2007/11/07 17:33:35 | 00,000,150 | —- | C] () – C:\WINDOWS\system.ini
[2006/01/12 17:09:14 | 00,090,112 | —- | C] () – C:\WINDOWS\SysWow64\DXFLib.dll
[2006/01/12 17:08:06 | 00,143,360 | —- | C] () – C:\WINDOWS\SysWow64\opcode.dll
[2005/03/25 08:00:00 | 01,277,952 | —- | C] () – C:\WINDOWS\SysWow64\quartz.dll
[2005/03/25 08:00:00 | 00,733,696 | —- | C] () – C:\WINDOWS\SysWow64\qedwipes.dll
[2005/03/25 08:00:00 | 00,512,512 | —- | C] () – C:\WINDOWS\SysWow64\qedit.dll
[2005/03/25 08:00:00 | 00,498,742 | —- | C] () – C:\WINDOWS\SysWow64\dxmasf.dll
[2005/03/25 08:00:00 | 00,396,288 | —- | C] () – C:\WINDOWS\SysWow64\encdec.dll
[2005/03/25 08:00:00 | 00,385,536 | —- | C] () – C:\WINDOWS\SysWow64\qdvd.dll
[2005/03/25 08:00:00 | 00,355,112 | —- | C] () – C:\WINDOWS\SysWow64\msjetoledb40.dll
[2005/03/25 08:00:00 | 00,279,040 | —- | C] () – C:\WINDOWS\SysWow64\qdv.dll
[2005/03/25 08:00:00 | 00,276,992 | —- | C] () – C:\WINDOWS\SysWow64\sbe.dll
[2005/03/25 08:00:00 | 00,199,168 | —- | C] () – C:\WINDOWS\SysWow64\ir32_32.dll
[2005/03/25 08:00:00 | 00,192,512 | —- | C] () – C:\WINDOWS\SysWow64\qcap.dll
[2005/03/25 08:00:00 | 00,114,688 | —- | C] () – C:\WINDOWS\SysWow64\msencode.dll
[2005/03/25 08:00:00 | 00,072,704 | —- | C] () – C:\WINDOWS\SysWow64\amstream.dll
[2005/03/25 08:00:00 | 00,062,464 | —- | C] () – C:\WINDOWS\SysWow64\mciqtz32.dll
[2005/03/25 08:00:00 | 00,061,440 | —- | C] () – C:\WINDOWS\SysWow64\devenum.dll
[2005/03/25 08:00:00 | 00,016,896 | —- | C] () – C:\WINDOWS\SysWow64\tsd32.dll
[2005/03/25 08:00:00 | 00,014,336 | —- | C] () – C:\WINDOWS\SysWow64\msdmo.dll
[2005/03/25 08:00:00 | 00,004,126 | —- | C] () – C:\WINDOWS\SysWow64\msdxmlc.dll

========== Files - Modified Within 30 Days ==========

[2 C:\WINDOWS\SysWow64\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2099/01/01 12:00:00 | 00,000,000 | -HS- | M] () – C:\WINDOWS\SysWow64\zeraseba.dll
[2009/08/10 23:41:02 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2009/08/10 20:32:14 | 00,000,496 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/08/10 16:18:27 | 00,359,932 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\dds.scr
[2009/08/10 15:31:06 | 00,279,461 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\gmer(2).zip
[2009/08/09 14:41:48 | 00,145,495 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\3795385154_c52a6e73ab.jpg
[2009/08/08 20:35:33 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/08/08 07:00:14 | 00,000,326 | —- | M] () – C:\WINDOWS\tasks\bmpnzxfh.job
[2009/08/08 06:55:56 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/08/08 06:55:42 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/08/08 06:46:22 | 00,000,726 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/08 06:45:48 | 03,942,048 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\Desktop\mbam-setup.exe
[2009/08/08 05:02:06 | 00,012,720 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/08/07 01:30:47 | 00,278,846 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\gmer.zip
[2009/08/06 22:19:20 | 00,024,788 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\bustedtees.9577de9ebb920d053ef4f51d44843978.gif
[2009/08/06 15:33:01 | 00,000,296 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/08/06 11:49:10 | 00,008,627 | —- | M] () – C:\WINDOWS\SysWow64\PAV_FOG.OPC
[2009/08/05 08:58:52 | 00,002,153 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Character Builder.lnk
[2009/08/05 08:55:06 | 00,608,578 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\700_DDI_CB(2).exe
[2009/08/05 08:04:51 | 00,391,730 | —- | M] () – C:\WINDOWS\SysWow64\PerfStringBackup.INI
[2009/08/05 07:39:21 | 20,669,2864 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Administrator\Desktop\dotnetfx35.exe
[2009/08/05 06:56:57 | 00,122,992 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Administrator\Desktop\clwireg-x64.exe
[2009/08/05 06:45:31 | 02,959,376 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Administrator\Desktop\dotnetfx35setup.exe
[2009/08/05 05:06:00 | 00,060,568 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\rs005.jpg
[2009/08/05 04:59:45 | 00,136,802 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\rs001.jpg
[2009/08/03 13:36:28 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\SysWow64\drivers\mbamswissarmy.sys
[2009/08/01 17:53:22 | 00,034,473 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\n1380782321_30191200_414.jpg
[2009/07/29 17:58:26 | 00,608,578 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\700_DDI_CB.exe
[2009/07/29 03:01:04 | 00,000,970 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/07/29 00:49:09 | 00,111,104 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/28 12:44:30 | 25,368,146 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\c8932fa141d6.wmv
[2009/07/25 18:40:57 | 00,035,229 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\cooper1952.jpg
[2009/07/25 18:39:50 | 00,045,855 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\n1064207944_30131462_4640.jpg
[2009/07/25 18:01:30 | 00,064,417 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\6093_1184953216984_1022854898_30587081_5179701_n.jpg
[2009/07/21 20:55:48 | 00,001,666 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PoxNora.lnk
[2009/07/21 20:54:40 | 15,087,616 | —- | M] (Octopi, Inc) – C:\Documents and Settings\Administrator\Desktop\PoxNora.exe
[2009/07/21 06:17:24 | 00,047,443 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30146852_337.jpg
[2009/07/21 06:16:58 | 00,044,009 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30146846_8302.jpg
[2009/07/21 06:16:29 | 00,046,932 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30146813_7295.jpg
[2009/07/21 06:13:37 | 00,038,316 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30253702_5922.jpg
[2009/07/21 06:07:39 | 00,034,882 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30406666_8089571.jpg
[2009/07/20 00:11:48 | 06,067,200 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ieframe.dll
[2009/07/20 00:11:48 | 03,597,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\mshtml.dll
[2009/07/20 00:11:48 | 02,452,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ieapfltr.dat
[2009/07/20 00:11:48 | 01,830,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\inetcpl.cpl
[2009/07/20 00:11:48 | 01,159,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\urlmon.dll
[2009/07/20 00:11:48 | 00,991,232 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ieframe.dll.mui
[2009/07/20 00:11:48 | 00,827,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\wininet.dll
[2009/07/20 00:11:48 | 00,671,232 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\mstime.dll
[2009/07/20 00:11:48 | 00,477,696 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\mshtmled.dll
[2009/07/20 00:11:48 | 00,459,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\msfeeds.dll
[2009/07/20 00:11:48 | 00,389,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\html.iec
[2009/07/20 00:11:48 | 00,385,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\iedkcs32.dll
[2009/07/20 00:11:48 | 00,380,928 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ieapfltr.dll
[2009/07/20 00:11:48 | 00,347,136 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\dxtmsft.dll
[2009/07/20 00:11:48 | 00,268,288 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\iertutil.dll
[2009/07/20 00:11:48 | 00,233,472 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\webcheck.dll
[2009/07/20 00:11:48 | 00,230,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ieaksie.dll
[2009/07/20 00:11:48 | 00,214,528 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\dxtrans.dll
[2009/07/20 00:11:48 | 00,193,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\msrating.dll
[2009/07/20 00:11:48 | 00,161,792 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ieakui.dll
[2009/07/20 00:11:48 | 00,153,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ieakeng.dll
[2009/07/20 00:11:48 | 00,133,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\extmgr.dll
[2009/07/20 00:11:48 | 00,124,928 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\advpack.dll
[2009/07/20 00:11:48 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\url.dll
[2009/07/20 00:11:48 | 00,102,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\occache.dll
[2009/07/20 00:11:48 | 00,078,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ieencode.dll
[2009/07/20 00:11:48 | 00,070,656 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ie4uinit.exe
[2009/07/20 00:11:48 | 00,063,488 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\icardie.dll
[2009/07/20 00:11:48 | 00,052,224 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\msfeedsbs.dll
[2009/07/20 00:11:48 | 00,044,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\pngfilt.dll
[2009/07/20 00:11:48 | 00,044,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\iernonce.dll
[2009/07/20 00:11:48 | 00,027,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\jsproxy.dll
[2009/07/20 00:11:48 | 00,017,408 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\corpol.dll
[2009/07/20 00:11:48 | 00,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ieudinit.exe
[2009/07/19 06:02:17 | 00,269,311 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\152p0l.png
[2009/07/19 05:44:21 | 00,046,825 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\ryanhead.jpg
[2009/07/19 05:41:52 | 00,050,368 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\kseniahead.jpg
[2009/07/17 03:01:24 | 00,020,516 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\null.pdf

========== LOP Check ==========

[2009/04/16 16:26:29 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Administrator\Application Data
[2008/03/04 23:31:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\acccore
[2009/08/08 05:02:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Azureus
[2008/11/10 20:29:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\DAEMON Tools
[2008/07/10 02:35:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\dvdcss
[2009/07/12 15:37:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Move Networks
[2007/11/12 01:34:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\My Games
[2009/03/30 15:48:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Panda Security
[2007/11/14 00:18:13 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Administrator\Application Data\SecuROM
[2008/02/12 22:51:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\teamspeak2
[2009/04/16 16:26:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\The Creative Assembly
[2008/10/24 21:36:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Ventrilo
[2009/03/29 22:57:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Vso
[2009/02/10 16:28:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Wal-Mart Digital Photo Viewer
[2009/06/10 20:29:38 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/06/10 20:29:39 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2007/12/02 20:51:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2009/02/11 07:11:42 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/01/07 18:53:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Comcast
[2008/05/13 10:19:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Funcom
[2009/02/23 17:41:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Norton
[2009/02/23 18:21:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009/03/30 15:48:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security
[2009/05/07 06:30:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2008/11/10 20:11:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Redirected
[2009/06/18 09:01:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2009/01/03 12:32:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2008/03/04 23:30:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/07/09 21:41:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2009/08/10 20:32:14 | 00,000,496 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/08/06 15:33:01 | 00,000,296 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2009/08/08 07:00:14 | 00,000,326 | —- | M] () – C:\WINDOWS\Tasks\bmpnzxfh.job
[2005/03/25 08:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/08/08 06:55:56 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/08/08 06:54:48 | 00,032,286 | —- | M] () – C:\WINDOWS\Tasks\SchedLgU.Txt

========== Purity Check ==========


< End of report >
Mattressgnome,

Azureus
You have Azureus, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm://http://www.techweb.com/wire/1605005…cles/art053.htm
See Clean/Infected P2P Programs here

I would recommend that you uninstall Azureus, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes
explorer.exe

:OTL
FF - prefs.js..browser.search.selectedEngine: "Yoog Search"
FF - prefs.js..keyword.URL: "http://www10.yoog.com/search.php?q="
FF - user.js..browser.search.selectedEngine: "Yoog Search"
FF - user.js..keyword.URL: "http://www10.yoog.com/search.php?q="
[2009/01/02 11:11:47 | 00,000,247 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Mozilla\FireFox\Profiles\08p9vs40.default\searchplugins\Yoog Search.xml
[2099/01/01 12:00:00 | 00,000,000 | -HS- | C] () – C:\WINDOWS\SysWow64\zeraseba.dll

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log and a new HJT log.

Then please try:
ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI