This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Your System is Infected wallpaper virus/malware

38 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I seem to have a malware with the above symptom. It looks like there are different solutions and so i would like some assistance to remove the virus. Thanks
My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems. I'd be grateful if you would note the following:
  • Logs from malware removal programs (DDS is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within five days
    . I will post a reminder should you seem to fail to do this, however, if you fail to reply within three days then,
    unless I have been notified of your absence in advance, the topic shall be closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic.
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your log, I will post back shortly with instructions.
Hi SweetTech. Thank you for helping me. I will follow your advise about not running any scans from now on but when i got this malware 2 days ago I assumed it could be removed using Avast! virus scan and Malwarebytes scan so I used them both already and deleted some files and keys. When I first did that I could change my wallpaper again but when I restarted the computer which was supposed to get rid of all the leftover viruses it changed my wallpaper back in a few moments after starting up again.Should I post all logs from those scans ?

Should I post all logs from those scans ?

Yes, please go ahead and include those logs in your next reply. Copy and Paste the logs. Do not attach them. If you need to post them in separate posts then that is fine.


Next:


OTL Custom Scan
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Next:


Please make sure you include the following items in your next post:

1. The logs that you have from the other scans that you have run.
2. The log that was produced after running OTL.
3. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Sorry about the late reply,I was going back to college. Here are my malwarebytes scan logs. The first was full scan and the next two are fast scans. Malwarebytes' Anti-Malware 1.40 Database version: 2644 Windows 5.1.2600 Service Pack 2 1/17/2010 1:29:39 AM mbam-log-2010-01-17 (01-29-39).txt Scan type: Full Scan (C:\|D:\|H:\|) Objects scanned: 501521 Time elapsed: 10 hour(s), 37 minute(s), 56 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 1 Registry Data Items Infected: 10 Folders Infected: 1 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\sdra64.exe -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: system32\sdra64.exe -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\winlogon32.exe,C:\WINDOWS\system32\sdra64.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully. Folders Infected: C:\WINDOWS\system32\lowsec (Stolen.data) -> Delete on reboot. Files Infected: C:\WINDOWS\system32\lowsec\local.ds (Stolen.data) -> Delete on reboot. C:\WINDOWS\system32\lowsec\user.ds (Stolen.data) -> Delete on reboot. C:\WINDOWS\system32\sdra64.exe (Trojan.FakeAlert) -> Delete on reboot. Malwarebytes' Anti-Malware 1.40 Database version: 2644 Windows 5.1.2600 Service Pack 2 1/17/2010 1:25:11 PM mbam-log-2010-01-17 (13-25-11).txt Scan type: Quick Scan Objects scanned: 112693 Time elapsed: 15 minute(s), 6 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 7 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Malwarebytes' Anti-Malware 1.40 Database version: 2644 Windows 5.1.2600 Service Pack 2 1/17/2010 1:55:26 PM mbam-log-2010-01-17 (13-55-25).txt Scan type: Quick Scan Objects scanned: 109925 Time elapsed: 11 minute(s), 11 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 7 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hello chaosknight, No worries on the delay. Did you have a chance to run the OTL Custom Scan yet? If so, please include the log in your next reply. Thanks, SweetTech.
Ill do the scan now.
Here is the avast………….. well …………….logs i guess.
Ill post them all but i got this virus only recently.

Warnings

1/19/2010 11:34:00 PM Administrator 3804 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "c:\windows\system32\winlogon32.exe" file.
1/19/2010 11:33:49 PM Administrator 3804 Sign of "Win32:Malware-gen" has been found in "c:\windows\system32\trz342.tmp" file.
1/19/2010 11:33:34 PM Administrator 3804 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "c:\windows\system32\smss32.exe" file.
1/19/2010 11:31:17 PM SYSTEM 2044 Sign of "Win32:Malware-gen" has been found in "C:\WINDOWS\system32\helper32.dll" file.
1/16/2010 2:30:59 PM SYSTEM 300 Sign of "Win32:Alureon-FB [Rtk]" has been found in "C:\WINDOWS\TEMP\3F26.tmp" file.
1/16/2010 2:11:35 PM SYSTEM 300 Sign of "Win32:Alureon-FB [Rtk]" has been found in "C:\WINDOWS\TEMP\3F18.tmp" file.
1/16/2010 1:24:06 PM SYSTEM 300 Sign of "JS:Pdfka-TW [Expl]" has been found in "http://google.com.analytics.ajbnmtoacun.com/nte/trest11.py/oH1f2928f2V03007f35002Ra0987a1f102T547b2cb7Q0000004c901801F0020000aJ0f000601l040
9K2612ede6317" file.
1/3/2010 5:16:40 AM SYSTEM 248 Sign of "JS:Redirector-AQ [Trj]" has been found in "http://yawibyve.info/cgi-bin/aer/jH8ce72347V03006f35002R79e066ce102Tc7a74dc2Q0000004c901801F0020000aJ0f000601L656
e2d55530000000000" file.
1/3/2010 12:45:48 AM SYSTEM 248 Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004.
12/29/2009 9:47:24 AM SYSTEM 292 An error has occured while attempting to update. Please check the logs.
12/29/2009 9:46:28 AM SYSTEM 292 Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004.
12/28/2009 1:38:26 AM SYSTEM 292 Sign of "HTML:Iframe-inf" has been found in "http://www.mangahut.com/\{gzip}" file.
12/28/2009 1:38:04 AM SYSTEM 292 Sign of "HTML:Iframe-inf" has been found in "http://www.mangahut.com/\{gzip}" file.
12/28/2009 1:37:35 AM SYSTEM 292 Sign of "HTML:Iframe-inf" has been found in "http://www.mangahut.com/\{gzip}" file.
12/24/2009 10:27:25 AM SYSTEM 292 Sign of "JS:Redirector-AP [Trj]" has been found in "http://cjbtiybcpnf.com/nte/TREST11%20.asp" file.
12/23/2009 7:19:23 PM SYSTEM 292 Sign of "HTML:Iframe-inf" has been found in "http://www.dogohonai.net/rqzwlnewoiwuaoqwlermtpp/" file.
12/19/2009 3:17:24 AM SYSTEM 288 Sign of "JS:Downloader-FT [Trj]" has been found in "http://statcstat.com/news/go.php?sign=ff56b6002a5bb2abf547760138d9c361&s=579" file.
12/11/2009 2:49:54 AM SYSTEM 288 Sign of "JS:Downloader-FT [Trj]" has been found in "http://statagreat.com/news/go.php?sign=e1b4cd0b43f8702afda889a228f53766&s=571" file.
12/9/2009 2:05:22 AM SYSTEM 288 Sign of "JS:FakeAV-CH [Trj]" has been found in "http://pc-scanner-2011.biz/?code=1124" file.
12/9/2009 2:05:06 AM SYSTEM 288 Sign of "JS:FakeAV-CH [Trj]" has been found in "http://pc-scanner-2011.biz/?code=1124" file.
12/6/2009 1:11:51 PM SYSTEM 288 Sign of "JS:Downloader-FT [Trj]" has been found in "http://stat-cntr.com/documents/?s=57" file.
12/5/2009 4:26:29 PM SYSTEM 288 Sign of "JS:Downloader-FT [Trj]" has been found in "http://statsadd.com/documents/?s=5711" file.
11/29/2009 10:01:11 PM SYSTEM 288 Sign of "JS:Downloader-FT [Trj]" has been found in "http://kuzibrak.com/documents/?s=573" file.
11/27/2009 10:18:24 AM SYSTEM 288 Sign of "JS:Downloader-FT [Trj]" has been found in "http://triplopak.com/documents/?s=577" file.
11/26/2009 5:32:23 PM SYSTEM 288 Sign of "JS:Downloader-FT [Trj]" has been found in "http://kariboka.com/documents/?s=578" file.
11/26/2009 4:24:33 PM SYSTEM 288 Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004.
11/25/2009 12:09:57 AM SYSTEM 288 An error has occured while attempting to update. Please check the logs.
11/25/2009 12:09:56 AM SYSTEM 288 Function setifaceUpdatePackages() has failed. Return code is 0x20000006, dwRes is 20000006.
11/20/2009 3:04:22 AM SYSTEM 976 Sign of "JS:Downloader-FT [Trj]" has been found in "http://trikifigi.com/documents/?s=572" file.
11/19/2009 4:02:00 AM SYSTEM 976 Sign of "JS:Downloader-GA [Trj]" has been found in "http://xrysha.com/news.php?s=5dfa006702\{gzip}" file.
11/17/2009 12:09:22 AM SYSTEM 976 Sign of "HTML:Iframe-inf" has been found in "http://nerpoitt.info/images/wait.html\{gzip}" file.
11/16/2009 3:03:58 AM SYSTEM 976 Sign of "JS:Downloader-FT [Trj]" has been found in "http://kulibaka.com/documents/?s=576" file.
11/15/2009 12:33:35 AM SYSTEM 976 Sign of "JS:Downloader-FT [Trj]" has been found in "http://kulibaka.com/documents/?s=576" file.
11/12/2009 5:27:19 AM SYSTEM 976 Sign of "JS:Downloader-FT [Trj]" has been found in "http://pakaraka.com/documents/?s=576" file.
11/10/2009 2:10:48 PM SYSTEM 976 Sign of "VBS:Obfuscated-gen [Trj]" has been found in "http://188.72.198.108/php5/p35.php" file.
11/10/2009 1:50:05 PM SYSTEM 976 Sign of "JS:FakeAV-AB [Trj]" has been found in "http://mediaresearch.ws/img/flist.js" file.
11/10/2009 1:49:47 PM SYSTEM 976 Sign of "JS:FakeAV-O [Trj]" has been found in "http://mediaresearch.ws/?tid=10&aid=10&engine=NWNiNDhhZTkzMzZiMmQwMDQ5MGY2OGVmYTAwMjQwN2U=" file.
11/9/2009 10:15:38 PM SYSTEM 976 AAVM - scanning warning: x_AavmCheckFileDirectEx: http://fim.adnxs.com/fpt?id=3593&size=…b=1257822936870 (C:\WINDOWS\TEMP\_avast4_\unp209899377.tmp) returning error, 0000A413.
11/8/2009 5:42:02 AM SYSTEM 976 Sign of "JS:Downloader-FT [Trj]" has been found in "http://piknikvik.com/documents/?s=57" file.
11/8/2009 1:42:45 AM SYSTEM 284 Sign of "JS:Downloader-FT [Trj]" has been found in "http://piknikvik.com/documents/?s=57" file.
11/6/2009 11:09:52 AM SYSTEM 1036 Sign of "JS:Downloader-FT [Trj]" has been found in "http://bigintcomp.com/docs/?s=573" file.
11/6/2009 11:08:39 AM SYSTEM 1036 AAVM - scanning warning: x_AavmCheckFileDirectEx: http://fim.adnxs.com/fpt?id=3593&size=…b=1257523719306 (C:\WINDOWS\TEMP\_avast4_\unp240198665.tmp) returning error, 0000A413.
11/6/2009 11:04:35 AM SYSTEM 1036 AAVM - scanning warning: x_AavmCheckFileDirectEx: http://www.searchingvalley.com/search.php?…rds=video+games (C:\WINDOWS\TEMP\_avast4_\unp56064328.tmp) returning error, 0000A413.
11/6/2009 12:22:10 AM SYSTEM 1036 AAVM - scanning warning: x_AavmCheckFileDirectEx: http://www.otakuzone.com/zone/ajax.php?type=getrecentfriend (C:\WINDOWS\TEMP\_avast4_\unp205931121.tmp) returning error, 0000A413.
11/6/2009 12:21:30 AM SYSTEM 1036 AAVM - scanning warning: x_AavmCheckFileDirectEx: http://www.otakuzone.com/zone/ajax.php?type=getrecentfriend (C:\WINDOWS\TEMP\_avast4_\unp246229829.tmp) returning error, 0000A413.
11/5/2009 2:42:30 AM SYSTEM 1036 AAVM - scanning warning: x_AavmCheckFileDirectEx: http://www.otakuzone.com/ajax.php?action=c…ter_ajax_search (C:\WINDOWS\TEMP\_avast4_\unp175878766.tmp) returning error, 0000A413.
11/2/2009 3:34:32 AM SYSTEM 1036 Sign of "HTML:Iframe-inf" has been found in "http://nancyypage.info/images/wait.html" file.
10/31/2009 5:32:46 AM SYSTEM 1036 Sign of "JS:Pdfka-SB [Expl]" has been found in "http://www1.esoriso.net/erwprquoz/xd/pdf.pdf" file.
10/25/2009 5:01:01 AM SYSTEM 1000 Sign of "HTML:RedirME-inf [Trj]" has been found in "http://adverbox.net/s/in.cgi?27&ab_iframe=1&ab_badtraffic=1&antibot_hash=1287437461&ur=1&HTTP_REFERER=http://ad.yieldmanager.com/iframe3?n3EnALDZBwB3vTMAAAAAAPQ8DgAAAAAAAgCMAAYAAAAAAP8AAAABBd4dDAAAAAAAOPwBAAAAAAD9GhQA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" file.
10/25/2009 2:57:57 AM SYSTEM 1000 Sign of "JS:Downloader-FE [Trj]" has been found in "http://www1.ecaytrader.net/wperwewa/in.php" file.
10/22/2009 3:44:21 AM SYSTEM 1000 Sign of "HTML:Iframe-inf" has been found in "http://sccgroupkzq.info/mtm6/\{gzip}" file.
10/19/2009 6:59:47 PM SYSTEM 1000 Sign of "HTML:Iframe-inf" has been found in "http://ad.yieldmanager.com/iframe3?n3EnALDZBwATZjIAAAAAADr8DQAAAAAAAgD4AQIAAAAAAP8AAAACE94dDAAAAAAAyzMQAAAAAAC9xxMA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADzEQQAAAAAAAIAAwAAAAAAm
pmZmZmZxT-amZmZmZnFP5qZmZmZmdU.mpmZmZmZ1T8AAAAAAADoPwAAAAAAA" file.
10/19/2009 6:58:56 PM SYSTEM 1000 Sign of "HTML:Iframe-inf" has been found in "http://ad.yieldmanager.com/iframe3?n3EnALDZBwATZjIAAAAAADr8DQAAAAAAAgD4AQIAAAAAAP8AAAACE94dDAAAAAAAyjMQAAAAAAC9xxMA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADzEQQAAAAAAAIAAwAAAAAAm
pmZmZmZxT-amZmZmZnFP5qZmZmZmdU.mpmZmZmZ1T8AAAAAAADoPwAAAAAAA" file.
10/19/2009 5:58:59 PM SYSTEM 1000 Sign of "HTML:Iframe-inf" has been found in "http://ad.yieldmanager.com/iframe3?n3EnALDZBwATZjIAAAAAADr8DQAAAAAAAgCcAQIAAAAAAP8AAAACEt4dDAAAAAAA1acQAAAAAAC9xxMA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADzEQQAAAAAAAIAAwAAAAAAm
pmZmZmZxT-amZmZmZnFP5qZmZmZmdU.mpmZmZmZ1T8AAAAAAADoPwAAAAAAA" file.
10/12/2009 1:37:38 AM SYSTEM 1220 Sign of "JS:Pdfka-RU [Trj]" has been found in "http://znt.dkoaeo.info/mkuazv/xd/pdf.pdf" file.
10/11/2009 4:37:27 AM SYSTEM 1220 Sign of "JS:Pdfka-RU [Trj]" has been found in "http://lnz.feiasroq.info/mkoaw/xd/pdf.pdf" file.
10/11/2009 4:36:48 AM SYSTEM 1220 Sign of "JS:Pdfka-RU [Trj]" has been found in "http://lnz.feiasroq.info/mkoaw/xd/pdf.pdf" file.
10/10/2009 7:11:56 PM SYSTEM 1220 Sign of "JS:Pdfka-RU [Trj]" has been found in "http://laz.dkasoewo.info/mkaw/xd/pdf.pdf" file.
10/4/2009 3:20:00 AM SYSTEM 1280 Sign of "HTML:Iframe-inf" has been found in "http://d3.zedo.com//ads2/k/628474/2333/172/0/790001754/790001754//0/790/1387//1000011/i.js\{gzip}" file.
10/4/2009 3:19:46 AM SYSTEM 1280 Sign of "HTML:Iframe-inf" has been found in "http://d3.zedo.com//ads2/k/628474/2333/172/0/790001754/790001754//0/790/1387//1000011/i.js\{gzip}" file.
9/29/2009 1:38:55 AM SYSTEM 1180 Sign of "JS:Downloader-EC [Trj]" has been found in "http://floweragents.com/documents/?tr=103-1-161553-658-411890-2241-12534750835692-1254202777-5018329151-576446\{gzip}" file.
9/27/2009 5:54:18 PM SYSTEM 1188 Sign of "JS:Downloader-EC [Trj]" has been found in "http://floweragents.com/documents/?tr=103-2-38335-658-411890-2241-12530830189011-1254088493-453229\{gzip}" file.
9/27/2009 3:15:30 PM SYSTEM 1188 Sign of "Nutcracker family" has been found in "http://network.realmedia.com/RealMedia/ads/adstream_sx.ads/TRACK_Mindsetmedia/Retarget_Secure/171178389@Bottom3?_RM_HTML_MM_=000000005000000000000" file.
9/25/2009 12:12:08 PM Administrator 3092 Sign of "Win32:Adan-156 [Adw]" has been found in "H:\Abhi\Abhi\Abhi\POKEMON !\ScreenSavers\pokemonv2.exe\%WIN%\iGator\Trickler3103_PIC_fs_DMPT.exe" file.
9/25/2009 12:12:07 PM Administrator 3092 Sign of "Win32:Ezula [Adw]" has been found in "H:\Abhi\Abhi\Abhi\POKEMON !\ScreenSavers\pokemonv2.exe\%WIN%\iLookup\TTIL.exe" file.
9/25/2009 12:12:06 PM Administrator 3092 Sign of "Win32:Newdotnet-B [Trj]" has been found in "H:\Abhi\Abhi\Abhi\POKEMON !\ScreenSavers\pokemonv2.exe\%MAINDIR%\nnez_388.exe" file.
9/25/2009 12:12:04 PM Administrator 3092 Sign of "Win32:Newdotnet-B [Trj]" has been found in "H:\Abhi\Abhi\Abhi\POKEMON !\ScreenSavers\pokemonv2.exe\%MAINDIR%\nnez_388.exe\[Embedded_I#06060]" file.
9/25/2009 12:11:59 PM Administrator 3092 Sign of "Win32:Adware-gen [Adw]" has been found in "H:\Abhi\Abhi\Abhi\POKEMON !\ScreenSavers\pokemonv2.exe\%MAINDIR%\nnez_388.exe\[Embedded_I#06060]\[Embedded_R#1baa8]" file.
9/25/2009 6:10:00 AM Administrator 3092 Sign of "Win32:Trojan-gen {Other}" has been found in "H:\Abhi\pokemon\Pokemon\pokesol.exe\%WinDir%\sbnet\ShowBehind.exe" file.
9/21/2009 12:12:10 AM SYSTEM 1160 Sign of "JS:Downloader-EC [Trj]" has been found in "http://floweragents.com/documents/?tr=103-1-161553-658-411890-2241-12534750835692-1253506359-5056068966-576446\{gzip}" file.
9/20/2009 3:19:32 AM SYSTEM 1160 Sign of "JS:Downloader-ED [Trj]" has been found in "http://wio.lkveoa.net/ewtr/in.php" file.
9/20/2009 3:18:23 AM SYSTEM 1160 Sign of "JS:Downloader-ED [Trj]" has been found in "http://wio.lkveoa.net/ewtr/in.php" file.
9/20/2009 12:42:39 AM SYSTEM 1160 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: H:\Wedding Card 1(telugu).jpg (H:\Wedding Card 1(telugu).jpg) returning error, 0000A420.
9/20/2009 12:42:39 AM SYSTEM 1160 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: H:\Wedding Card 2(English).jpg (H:\Wedding Card 2(English).jpg) returning error, 0000A420.
9/20/2009 12:42:39 AM SYSTEM 1160 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: H:\Wedding Card 2(telugu).jpg (H:\Wedding Card 2(telugu).jpg) returning error, 0000A420.
9/19/2009 9:59:51 PM SYSTEM 1160 Sign of "JS:Downloader-EC [Trj]" has been found in "http://floweragents.com/documents/?tr=103-2-38335-658-411890-2241-12530830189011-1253412006-453229\{gzip}" file.
9/13/2009 6:21:32 AM SYSTEM 1264 Sign of "HTML:Iframe-inf" has been found in "http://d3.zedo.com//ads2/k/628474/2325/172/0/790001754/790001754//0/790/1387//1000011/i.js\{gzip}" file.
9/11/2009 2:26:03 PM SYSTEM 1016 Sign of "HTML:Iframe-inf" has been found in "http://d3.zedo.com//ads2/k/628474/2325/172/0/790001754/790001754//0/790/1387//1000011/i.js\{gzip}" file.
9/11/2009 2:59:55 AM SYSTEM 1016 Sign of "JS:FakeAV-AZ [Trj]" has been found in "http://best-spyware-scan03.com/1/?sess=%3DmQz0jjxMi0yJmlwPTIxNi4xNzEuMjEuMjUyJnRpbWU9MTI1NTYwMU0MaQ%3DN" file.
9/11/2009 2:56:23 AM SYSTEM 1016 Sign of "HTML:Iframe-inf" has been found in "http://d3.zedo.com//ads2/k/628474/2325/172/0/790001754/790001754//0/790/1387//1000011/i.js\{gzip}" file.
9/11/2009 2:44:53 AM SYSTEM 1016 Sign of "HTML:Iframe-inf" has been found in "http://d3.zedo.com//ads2/k/628474/2325/172/0/790001754/790001754//0/790/1387//1000011/i.js\{gzip}" file.
9/11/2009 2:17:34 AM SYSTEM 1016 Sign of "JS:FakeAV-AZ [Trj]" has been found in "http://best-spyware-scan03.com/1/?sess=%3DWG49jDwMi0xMCZpcD0yMTYuMTcxLjIxLjI1MiZ0aW1lPTEyNTU2MQkMMQkN" file.
9/10/2009 2:02:56 AM SYSTEM 1016 Sign of "HTML:Iframe-inf" has been found in "http://d3.zedo.com//ads2/k/628474/2325/172/0/790001754/790001754//0/790/1387//1000009/i.js\{gzip}" file.
9/10/2009 12:28:20 AM SYSTEM 1016 Sign of "JS:Downloader-EC [Trj]" has been found in "http://flowersshoping.com/documents/\{gzip}" file.
9/10/2009 12:28:19 AM SYSTEM 1016 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://serving.adsrevenue.clicksor.net/serving/links_net.php?t=network&pnid=2&npid=umaianime&nsid=102476&sid=38335&pid=27103&ref=http%3A%2F%2Fwww.umaianime.com%2F&memkey=1ca487e5e28203ff768885c8bcb1d67b&qp=%60%5E%25%215%7B%21%28%25%F9%210%7D%21-%7D&sid=383\{gzip}" file.
8/31/2009 9:58:59 PM SYSTEM 1008 Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004.
8/18/2009 1:44:09 AM SYSTEM 1124 Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004.
5/9/2009 1:47:14 AM SYSTEM 1676 Sign of "HTML:IFrame-EE [Trj]" has been found in "http://everviza.com/" file.
5/8/2009 7:59:56 PM SYSTEM 1676 Sign of "HTML:IFrame-EE [Trj]" has been found in "http://everviza.com/" file.
5/7/2009 11:50:09 PM SYSTEM 1172 Sign of "HTML:IFrame-EE [Trj]" has been found in "http://pyrisiman.com/counter.php" file.
5/7/2009 4:00:40 PM SYSTEM 1172 Sign of "HTML:IFrame-EE [Trj]" has been found in "http://pyrisiman.com/counter.php" file.
5/6/2009 10:28:02 AM SYSTEM 1172 Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004.
5/5/2009 4:24:25 PM SYSTEM 1740 Sign of "HTML:Iframe-inf" has been found in "http://www.bizcash.info/go/to.php?id=005" file.
4/17/2009 3:06:05 PM SYSTEM 1256 An error has occured while attempting to update. Please check the logs.
4/17/2009 3:05:51 PM SYSTEM 1256 Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004.
3/30/2009 10:57:44 AM SYSTEM 196 Sign of "JS:Packed-AW [Trj]" has been found in "http://ashoping.com/?sid=aff0048\{gzip}" file.
3/29/2009 7:04:37 PM SYSTEM 196 Sign of "JS:Pdfka-AN [Expl]" has been found in "http://wambanet.com/qqp/pdf.php\{gzip}" file.
3/29/2009 1:58:02 PM SYSTEM 196 Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004.
3/27/2009 2:32:30 AM SYSTEM 1084 Sign of "JS:Packed-AW [Trj]" has been found in "http://ashoping.com/?sid=aff0048\{gzip}" file.
3/20/2009 1:10:40 PM SYSTEM 1628 Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004.
3/20/2009 12:36:20 PM SYSTEM 1628 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://zarudagcon.com/?id=60033034\{gzip}" file.
3/14/2009 11:47:19 AM SYSTEM 1020 Sign of "HTML:Iframe-inf" has been found in "http://www.fulldls.com/torrent-anime-1496095.html\{gzip}" file.
3/6/2009 11:32:45 PM SYSTEM 1720 Sign of "HTML:Iframe-inf" has been found in "http://feedsearchs.com/portal/a.php" file.
2/28/2009 11:29:28 PM SYSTEM 1272 Sign of "HTML:Iframe-inf" has been found in "http://ad.yieldmanager.com/iframe3?4Z1bAHXKCAB5aRwAyTsJAAIAAAAAAP8AAAAHFwIAAgJhHA0AezsNAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAB-F61G4Hs0.H4XrUbgezT9mZmZmZmbWP2ZmZmZmZtY.AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAVsun7vzz8gVMVsnzM5urfuZsWJA1i" file.
2/28/2009 11:04:00 PM SYSTEM 1272 Sign of "HTML:Iframe-inf" has been found in "http://ad.yieldmanager.com/iframe3?RwQAAGe.BgB5aRwAyTsJAAIAAAAAAP8AAAAHFwIAAgMN9QcAmL0GAHs7DQAAAAAAAAAAAAAAAAAAAAAA
AAAAABsv3SQGgcU.Gy.dJAaBxT.sUbgehevRP-xRuB6F69E.ZmZmZmZm1j9mZmZmZmbWPwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAATZWk2Q
Tu8gVkZDq2d8DPY7v8EHQKt" file.
2/27/2009 4:25:19 PM SYSTEM 1144 An error has occured while attempting to update. Please check the logs.
2/27/2009 4:25:18 PM SYSTEM 1144 Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004.
2/23/2009 2:15:40 AM SYSTEM 1144 Sign of "HTML:IFrame-CD [Trj]" has been found in "http://financestoc.com/?sid=aff0047\{gzip}" file.
2/23/2009 2:12:38 AM SYSTEM 1144 Sign of "HTML:IFrame-CD [Trj]" has been found in "http://automobilewdew.com/?a=rubriccarp\{gzip}" file.
2/22/2009 5:10:41 PM SYSTEM 1144 Sign of "HTML:IFrame-CD [Trj]" has been found in "http://financestoc.com/?sid=aff0047" file.
2/22/2009 4:25:23 PM SYSTEM 1144 Sign of "HTML:IFrame-CD [Trj]" has been found in "http://ashoping.com/?sid=aff0048" file.
2/20/2009 8:00:23 PM SYSTEM 1144 Sign of "HTML:Iframe-inf" has been found in "http://feedsearchs.com/portal/a.php" file.
2/19/2009 1:17:18 AM SYSTEM 1144 Sign of "HTML:IFrame-CD [Trj]" has been found in "http://financestoc.com/?sid=aff0047" file.


Errors

11/9/2009 10:15:38 PM SYSTEM 976 AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of http://fim.adnxs.com/fpt?id=3593&size=…b=1257822936870 failed, 0000A413.
11/6/2009 11:08:39 AM SYSTEM 1036 AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of http://fim.adnxs.com/fpt?id=3593&size=…b=1257523719306 failed, 0000A413.
11/6/2009 11:04:34 AM SYSTEM 1036 AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of http://www.searchingvalley.com/search.php?…rds=video+games failed, 0000A413.
11/6/2009 12:22:10 AM SYSTEM 1036 AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of http://www.otakuzone.com/zone/ajax.php?type=getrecentfriend failed, 0000A413.
11/6/2009 12:21:30 AM SYSTEM 1036 AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of http://www.otakuzone.com/zone/ajax.php?type=getrecentfriend failed, 0000A413.
11/5/2009 2:42:30 AM SYSTEM 1036 AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of http://www.otakuzone.com/ajax.php?action=c…ter_ajax_search failed, 0000A413.
9/20/2009 12:42:39 AM SYSTEM 1160 AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of H:\Wedding Card 2(telugu).jpg failed, 0000A420.
9/20/2009 12:42:39 AM SYSTEM 1160 AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of H:\Wedding Card 2(English).jpg failed, 0000A420.
9/20/2009 12:42:39 AM SYSTEM 1160 AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of H:\Wedding Card 1(telugu).jpg failed, 0000A420.
Is it not needed to scan all users?
Here is the OTL.Txt

OTL logfile created on: 1/19/2010 11:52:10 PM - Run 1
OTL by OldTimer - Version 3.1.25.2 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 63.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 43.95 Gb Total Space | 7.26 Gb Free Space | 16.52% Space Free | Partition Type: NTFS
Drive D: | 49.20 Gb Total Space | 22.80 Gb Free Space | 46.34% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 535.75 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 1.89 Gb Total Space | 1.28 Gb Free Space | 67.44% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MALIPEDDI
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\System32\smss32.exe File not found
PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - D:\TortoiseSVN\bin\TSVNCache.exe (http://tortoisesvn.net)
PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - D:\New Folder\ashDisp.exe (ALWIL Software)
PRC - D:\New Folder\ashServ.exe (ALWIL Software)
PRC - D:\New Folder\ashMaiSv.exe (ALWIL Software)
PRC - D:\New Folder\ashWebSv.exe (ALWIL Software)
PRC - D:\New Folder\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\CyberLink\Shared Files\brs.exe (cyberlink)
PRC - C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe (Cyberlink Corp.)
PRC - C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\Mctray.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\CCM\CcmExec.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\CCM\clicomp\RemCtrl\Wuser32.exe (Microsoft Corporation)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
PRC - C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxext.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
PRC - C:\Program Files\Protector Suite QL\menusw.exe (UPEK Inc.)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\system32\CNAC3RPK.exe (CANON INC.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Program Files\Funk Software\Odyssey Client\OdTray.exe (Funk Software, Inc.)
PRC - C:\Program Files\Funk Software\Odyssey Client\odClientService.exe (Funk Software, Inc.)
PRC - C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
PRC - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
PRC - C:\WINDOWS\system32\qosservm.exe (AVAYA Communication)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS) – C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (iPod Service) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (avast! Antivirus) – D:\New Folder\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – D:\New Folder\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner) – D:\New Folder\ashWebSv.exe (ALWIL Software)
SRV - (aswUpdSv) – D:\New Folder\aswUpdSv.exe (ALWIL Software)
SRV - (Bonjour Service) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (SQLWriter) – C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (SQLBrowser) – C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper) – C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
SRV - (odserv) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (McAfeeFramework) – C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
SRV - (McTaskManager) – C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
SRV - (msvsmon90) – d:\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)
SRV - (CcmExec) – C:\WINDOWS\system32\CCM\CcmExec.exe (Microsoft Corporation)
SRV - (Wuser32) – C:\WINDOWS\system32\CCM\clicomp\RemCtrl\Wuser32.exe (Microsoft Corporation)
SRV - (SSScsiSV) – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (SonicStage Back-End Service) – C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe ()
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (VAIO Event Service) – C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (odClientService) – C:\Program Files\Funk Software\Odyssey Client\odClientService.exe (Funk Software, Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (iClarityQoSService) – C:\WINDOWS\system32\qosservm.exe (AVAYA Communication)


========== Driver Services (SafeList) ==========

DRV - (NETw5x32) Intel® – C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (GEARAspiWDM) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (aswMon2) – C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswSP) – C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswTdi) – C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswRdr) – C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (TVICHW32) – C:\WINDOWS\system32\drivers\TVICHW32.SYS (EnTech Taiwan)
DRV - (PxHelp20) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (USBAAPL) – C:\WINDOWS\system32\drivers\usbaapl.sys (Apple, Inc.)
DRV - ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}) – C:\Program Files\CyberLink\PowerDVD8\000.fcl (Cyberlink Corp.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfetdik) – C:\WINDOWS\system32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys (McAfee, Inc.)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Eacfilt) – C:\WINDOWS\system32\drivers\eacfilt.sys (Nortel Networks)
DRV - (IPSECSHM) – C:\WINDOWS\system32\drivers\ipsecw2k.sys (Nortel Networks NA, Inc.)
DRV - (IPSECEXT) – C:\WINDOWS\system32\drivers\ipsecw2k.sys (Nortel Networks NA, Inc.)
DRV - (prepdrvr) – C:\WINDOWS\system32\CCM\PrepDrv.sys (Microsoft Corporation)
DRV - (tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (TosRfSnd) – C:\WINDOWS\system32\drivers\TosRfSnd.sys (TOSHIBA Corporation)
DRV - (E100B) Intel® – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (RimUsb) – C:\WINDOWS\system32\drivers\RimUsb.sys (Research In Motion Limited)
DRV - (NWADI) – C:\WINDOWS\system32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NWUSBPort2) – C:\WINDOWS\system32\drivers\nwusbser2.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort) – C:\WINDOWS\system32\drivers\nwusbser.sys (Novatel Wireless Inc.)
DRV - (NWUSBModem) – C:\WINDOWS\system32\drivers\nwusbmdm.sys (Novatel Wireless Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
DRV - (SonyImgF) – C:\WINDOWS\system32\drivers\SonyImgF.sys (Sony Corporation)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (FdRedir) – C:\Program Files\Common Files\Protector Suite QL\Drivers\FdRedir.sys (UPEK Inc.)
DRV - (FileDisk2) – C:\Program Files\Common Files\Protector Suite QL\Drivers\filedisk.sys (UPEK Inc.)
DRV - (TcUsb) – C:\WINDOWS\system32\drivers\tcusb.sys (UPEK Inc.)
DRV - (ti21sony) – C:\WINDOWS\system32\drivers\ti21sony.sys (Texas Instruments)
DRV - (kbstuff) – C:\WINDOWS\system32\drivers\kbstuff5.sys (Microsoft Corporation)
DRV - (idisw2km) – C:\WINDOWS\system32\drivers\idisw2km.sys (Microsoft Corporation)
DRV - (shpf) – C:\WINDOWS\system32\DRIVERS\shpf.sys (Sony Corporation)
DRV - (IFXTPM) – C:\WINDOWS\system32\drivers\ifxtpm.sys (Infineon Technologies AG)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (mdmxsdk) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (hwusbser) – C:\WINDOWS\system32\drivers\ewusbser.sys (QUALCOMM Incorporated)
DRV - (hwcdcmdm0) – C:\WINDOWS\system32\drivers\ewusbmdm.sys (QUALCOMM Incorporated)
DRV - (toshidpt) – C:\WINDOWS\system32\drivers\Toshidpt.sys (TOSHIBA Corporation.)
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (MemStPCI) Sony Memory Stick controller (PCI) – C:\WINDOWS\system32\drivers\MemStPCI.SYS (Sony Corporation)
DRV - (odysseyIM3) – C:\WINDOWS\system32\drivers\odysseyIM3.sys (Funk Software, Inc.)
DRV - (SPI) – C:\WINDOWS\system32\drivers\SonyPI.sys (Sony Corporation)
DRV - (HPZius12) – C:\WINDOWS\system32\drivers\HPZius12.sys (HP)
DRV - (HPZipr12) – C:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
DRV - (HPZid412) – C:\WINDOWS\system32\drivers\hpzid412.sys (HP)
DRV - (SNC) – C:\WINDOWS\system32\drivers\SonyNC.sys (Sony Corporation)
DRV - (DMICall) – C:\WINDOWS\system32\drivers\DMICall.sys (Sony Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2009/03/29 23:31:48 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/12 03:09:55 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/12 03:09:55 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2009/10/05 16:29:27 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2009/06/29 03:36:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2010/01/19 23:31:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xj005yl9.default\extensions
[2010/01/19 23:31:51 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2006/02/22 07:48:48 | 00,103,936 | —- | M] (UPEK Inc.) – C:\Program Files\Mozilla Firefox\components\pwd_fir.dll

O1 HOSTS File: ([2004/08/04 07:00:00 | 00,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (ViewerHelper Class) - {78104A01-8E71-4F30-9A36-3793799615B4} - C:\Program Files\Microsoft\Rights Management Add-on\RMAFilt.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AvayaIEHlprObj Class) - {E6DF0B46-7D6F-407A-A6A2-62D17A021A9A} - C:\Program Files\Avaya\Avaya IP Softphone\AvayaWebDial.dll ()
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avast!] D:\New Folder\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [BDRegion] C:\Program Files\CyberLink\Shared Files\brs.exe (cyberlink)
O4 - HKLM..\Run: [Biomenu] C:\Program Files\Protector Suite QL\menusw.exe (UPEK Inc.)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] File not found
O4 - HKLM..\Run: [OdTray.exe] C:\Program Files\Funk Software\Odyssey Client\OdTray.exe (Funk Software, Inc.)
O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe ()
O4 - HKLM..\Run: [PWRESET] C:\Program Files\Avaya\Avaya IP Softphone\IP Service Provider\pwreset.exe (Avaya Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RemoteControl8] C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [SkyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKCU..\Run: [Google Update] C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKCU..\Run: [Steam] c:\program files\steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [uTorrent] D:\uTorrent.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Microsoft\Rights Management Add-on\RMARes.dll,-40971 - {685ec120-f786-4498-a8f0-794d47916161} - C:\Program Files\Microsoft\Rights Management Add-on\RMAFilt.dll (Microsoft Corporation)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Microsoft\Rights Management Add-on\RMARes.dll,-205 - {aede78a6-42b6-4c3c-96eb-5ae6dbec4859} - C:\Program Files\Microsoft\Rights Management Add-on\RMAFilt.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Microsoft\Rights Management Add-on\RMARes.dll,-40970 - {aede78a6-42b6-4c3c-96eb-5ae6dbec4859} - C:\Program Files\Microsoft\Rights Management Add-on\RMAFilt.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} http://esupport.sony.com/VaioInfo.CAB (VaioInfo.CMClass)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu…b?1208346242046 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1208346223312 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} http://plugin.driveragent.com/files/driveragent.cab (Driver Agent ActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\rmh {23C585BB-48FF-4865-8934-185F0A7EB84C} - C:\Program Files\Microsoft\Rights Management Add-on\RMAFilt.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/msword {DFF82902-0B96-3B98-6F62-D655E146A23A} - C:\Program Files\Microsoft\Rights Management Add-on\RMAFilt.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/vnd.ms-excel {DFF82902-0B96-3B98-6F62-D655E146A23A} - C:\Program Files\Microsoft\Rights Management Add-on\RMAFilt.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/vnd.ms-powerpoint {DFF82902-0B96-3B98-6F62-D655E146A23A} - C:\Program Files\Microsoft\Rights Management Add-on\RMAFilt.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/vnd-viewer {CD4527E8-4FC7-48DB-9806-10537B501237} - C:\Program Files\Microsoft\Rights Management Add-on\rmadoc.exe (Microsoft Corporation)
O18 - Protocol\Filter\application/x-microsoft-rpmsg-message {DFF82902-0B96-3B98-6F62-D655E146A23A} - C:\Program Files\Microsoft\Rights Management Add-on\RMAFilt.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (PSLogon.dll) - C:\WINDOWS\System32\PSLogon.dll (UPEK Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\OdysseyClient: DllName - odyEvent.dll - C:\WINDOWS\System32\odyEvent.dll (Funk Software, Inc.)
O20 - Winlogon\Notify\psfus: DllName - fusstub.dll - C:\WINDOWS\System32\fusstub.dll (UPEK Inc.)
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\WINDOWS\System32\VESWinlogon.dll (Sony Corporation)
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/16 02:07:32 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{ae95b8ce-ac56-11de-a2c4-0013a9f85c69}\Shell\AutoRun\command - "" = E:\setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/12/30 21:02:07 | 00,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (53765113575899136)

========== Files/Folders - Created Within 30 Days ==========

[2010/01/17 20:01:57 | 00,547,328 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/01/17 13:37:00 | 00,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\Administrator\Desktop\ATF_Cleaner.exe
[2010/01/17 13:30:16 | 00,000,000 | R-SD | C] – C:\Documents and Settings\Administrator\My Documents\My Safe
[2010/01/17 13:19:23 | 16,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Administrator\Desktop\spybotsd162.exe
[2009/12/21 16:37:23 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\music from sahil 2
[2009/10/18 00:41:03 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/09/28 12:46:59 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Intel
[2009/09/28 12:46:55 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Intel
[2009/08/28 14:33:35 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/04/20 20:06:11 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2009/01/07 04:17:09 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2008/10/14 01:18:34 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Xfire
[2008/09/20 11:30:11 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Xfire
[2008/09/09 18:46:20 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2008/04/23 04:19:30 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008/04/16 02:11:56 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/01/19 23:41:04 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\5447.exe
[2010/01/19 23:21:08 | 00,000,938 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1711238048-381789669-486400350-2299.job
[2010/01/19 23:21:03 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\19895.exe
[2010/01/17 23:22:16 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\19718.exe
[2010/01/17 23:18:00 | 00,001,010 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-1035525444-725345543-500UA.job
[2010/01/17 23:02:15 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\18716.exe
[2010/01/17 22:42:15 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\17421.exe
[2010/01/17 22:22:14 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\12382.exe
[2010/01/17 22:02:14 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\292.exe
[2010/01/17 21:42:13 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\153.exe
[2010/01/17 21:22:13 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\3902.exe
[2010/01/17 21:02:12 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\14604.exe
[2010/01/17 20:42:12 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\32391.exe
[2010/01/17 20:40:00 | 00,000,470 | —- | M] () – C:\WINDOWS\tasks\WebReg 20090601204014.job
[2010/01/17 20:22:11 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\5436.exe
[2010/01/17 20:02:11 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\4827.exe
[2010/01/17 20:02:03 | 00,547,328 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/01/17 19:42:10 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\11942.exe
[2010/01/17 19:22:10 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\2995.exe
[2010/01/17 19:02:09 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\491.exe
[2010/01/17 18:42:08 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\9961.exe
[2010/01/17 18:22:08 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\16827.exe
[2010/01/17 18:02:07 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\23281.exe
[2010/01/17 17:42:07 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\28145.exe
[2010/01/17 17:22:06 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\5705.exe
[2010/01/17 17:02:05 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\24464.exe
[2010/01/17 16:42:05 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\26962.exe
[2010/01/17 16:22:04 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\29358.exe
[2010/01/17 16:02:03 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\11478.exe
[2010/01/17 15:42:03 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\15724.exe
[2010/01/17 15:22:02 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\19169.exe
[2010/01/17 15:02:02 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\26500.exe
[2010/01/17 14:42:01 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\6334.exe
[2010/01/17 14:22:01 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\18467.exe
[2010/01/17 14:02:16 | 00,000,491 | —- | M] () – C:\WINDOWS\SMSCFG.ini
[2010/01/17 14:02:00 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\41.exe
[2010/01/17 14:01:58 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\IS15.exe
[2010/01/17 14:01:44 | 00,002,931 | —- | M] () – C:\WINDOWS\System32\warning.html
[2010/01/17 14:00:04 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/01/17 13:58:15 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/17 13:57:45 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/17 13:56:20 | 04,718,592 | -H– | M] () – C:\Documents and Settings\Administrator\NTUSER.DAT
[2010/01/17 13:56:20 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\Administrator\ntuser.ini
[2010/01/17 13:54:39 | 03,827,754 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2010/01/17 13:37:01 | 00,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Administrator\Desktop\ATF_Cleaner.exe
[2010/01/17 13:20:52 | 16,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Administrator\Desktop\spybotsd162.exe
[2010/01/17 12:51:46 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\27446.exe
[2010/01/17 12:31:46 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\22648.exe
[2010/01/17 12:11:45 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\19264.exe
[2010/01/17 11:51:45 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\8942.exe
[2010/01/17 11:31:45 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\9040.exe
[2010/01/17 11:11:44 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\30106.exe
[2010/01/17 10:51:44 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\288.exe
[2010/01/17 10:31:44 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\1842.exe
[2010/01/17 10:11:44 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\22190.exe
[2010/01/17 09:51:44 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\3035.exe
[2010/01/17 09:31:44 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\12316.exe
[2010/01/17 09:11:43 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\778.exe
[2010/01/17 08:51:43 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\27529.exe
[2010/01/17 08:31:43 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\9741.exe
[2010/01/17 08:11:43 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\8723.exe
[2010/01/17 07:51:43 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\12859.exe
[2010/01/17 07:31:43 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\20037.exe
[2010/01/17 07:11:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\32757.exe
[2010/01/17 06:51:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\32662.exe
[2010/01/17 06:31:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\27644.exe
[2010/01/17 06:11:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\25547.exe
[2010/01/17 05:51:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\6868.exe
[2010/01/17 05:31:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\28253.exe
[2010/01/17 05:18:06 | 00,000,958 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-1035525444-725345543-500Core.job
[2010/01/17 05:11:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\7711.exe
[2010/01/17 04:51:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\15141.exe
[2010/01/17 04:31:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\4664.exe
[2010/01/17 04:11:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\17673.exe
[2010/01/17 03:51:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\30333.exe
[2010/01/17 03:31:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\31322.exe
[2010/01/17 03:11:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\23811.exe
[2010/01/17 02:51:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\28703.exe
[2010/01/17 02:31:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\9894.exe
[2010/01/17 02:11:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\17035.exe
[2010/01/17 01:51:40 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\26299.exe
[2010/01/17 01:31:38 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\25667.exe
[2010/01/17 01:11:37 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\19912.exe
[2010/01/17 00:51:37 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\1869.exe
[2010/01/17 00:31:37 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\11538.exe
[2010/01/17 00:11:36 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\14771.exe
[2010/01/16 23:51:36 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\21726.exe
[2010/01/16 13:24:50 | 00,000,001 | —- | M] () – C:\s
[2010/01/14 02:56:22 | 00,029,696 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/09 17:21:47 | 00,513,630 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/01/09 17:21:47 | 00,097,520 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/01/09 17:21:46 | 00,623,014 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/01/07 03:46:15 | 01,563,176 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/01/07 03:43:45 | 00,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/12/28 18:47:08 | 00,000,480 | —- | M] () – C:\WINDOWS\tasks\WebReg 20091228184706.job
[2009/12/22 17:49:04 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/12/21 23:51:32 | 00,157,986 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Chess.zip
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/01/17 15:02:02 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\26500.exe
[2010/01/17 14:42:01 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\6334.exe
[2010/01/17 13:54:27 | 03,827,754 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2010/01/17 12:51:46 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\27446.exe
[2010/01/17 12:31:46 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\22648.exe
[2010/01/17 12:11:45 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\19264.exe
[2010/01/17 11:51:45 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\8942.exe
[2010/01/17 11:31:45 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\9040.exe
[2010/01/17 11:11:44 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\30106.exe
[2010/01/17 10:51:44 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\288.exe
[2010/01/17 10:31:44 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\1842.exe
[2010/01/17 10:11:44 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\22190.exe
[2010/01/17 09:51:44 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\3035.exe
[2010/01/17 09:31:44 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\12316.exe
[2010/01/17 09:11:43 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\778.exe
[2010/01/17 08:51:43 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\27529.exe
[2010/01/17 08:31:43 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\9741.exe
[2010/01/17 08:11:43 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\8723.exe
[2010/01/17 07:51:43 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\12859.exe
[2010/01/17 07:31:43 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\20037.exe
[2010/01/17 07:11:42 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\32757.exe
[2010/01/17 06:51:42 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\32662.exe
[2010/01/17 06:31:42 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\27644.exe
[2010/01/17 06:11:42 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\25547.exe
[2010/01/17 05:51:42 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\6868.exe
[2010/01/17 05:31:42 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\28253.exe
[2010/01/17 05:11:42 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\7711.exe
[2010/01/17 04:51:41 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\15141.exe
[2010/01/17 04:31:41 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\4664.exe
[2010/01/17 04:11:41 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\17673.exe
[2010/01/17 03:51:41 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\30333.exe
[2010/01/17 03:31:41 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\31322.exe
[2010/01/17 03:11:41 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\23811.exe
[2010/01/17 02:51:41 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\28703.exe
[2010/01/17 02:31:41 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\9894.exe
[2010/01/17 02:11:41 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\17035.exe
[2010/01/17 01:51:40 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\26299.exe
[2010/01/17 01:31:38 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\25667.exe
[2010/01/17 01:11:37 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\19912.exe
[2010/01/17 00:51:37 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\1869.exe
[2010/01/17 00:31:37 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\11538.exe
[2010/01/17 00:11:36 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\14771.exe
[2010/01/16 23:51:36 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\21726.exe
[2010/01/16 23:31:36 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\5447.exe
[2010/01/16 23:11:35 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\19895.exe
[2010/01/16 22:51:35 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\19718.exe
[2010/01/16 22:31:35 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\18716.exe
[2010/01/16 22:11:35 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\17421.exe
[2010/01/16 21:51:35 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\12382.exe
[2010/01/16 21:31:35 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\292.exe
[2010/01/16 21:11:34 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\153.exe
[2010/01/16 20:51:34 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\3902.exe
[2010/01/16 20:31:34 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\14604.exe
[2010/01/16 20:11:34 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\32391.exe
[2010/01/16 19:51:34 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\5436.exe
[2010/01/16 19:31:33 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\4827.exe
[2010/01/16 19:11:33 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\11942.exe
[2010/01/16 18:51:33 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\2995.exe
[2010/01/16 18:31:33 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\491.exe
[2010/01/16 18:11:32 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\9961.exe
[2010/01/16 17:51:32 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\16827.exe
[2010/01/16 17:31:32 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\23281.exe
[2010/01/16 17:11:32 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\28145.exe
[2010/01/16 16:51:31 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\5705.exe
[2010/01/16 16:31:31 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\24464.exe
[2010/01/16 16:11:31 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\26962.exe
[2010/01/16 15:51:29 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\29358.exe
[2010/01/16 15:31:27 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\11478.exe
[2010/01/16 15:11:26 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\15724.exe
[2010/01/16 14:51:24 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\19169.exe
[2010/01/16 13:50:18 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\18467.exe
[2010/01/16 13:30:11 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\41.exe
[2010/01/16 13:29:46 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\IS15.exe
[2010/01/16 13:28:52 | 00,002,931 | —- | C] () – C:\WINDOWS\System32\warning.html
[2010/01/16 13:24:50 | 00,000,001 | —- | C] () – C:\s
[2009/12/28 18:47:06 | 00,000,480 | —- | C] () – C:\WINDOWS\tasks\WebReg 20091228184706.job
[2009/12/21 23:51:31 | 00,157,986 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Chess.zip
[2009/12/13 23:58:49 | 00,000,600 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\PUTTY.RND
[2009/10/18 00:47:52 | 00,000,172 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/09/09 00:20:47 | 00,000,600 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\winscp.rnd
[2009/08/17 05:33:30 | 00,029,696 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/12 06:54:49 | 00,000,097 | —- | C] () – C:\WINDOWS\WirelessFTP.INI
[2009/06/29 02:47:23 | 00,000,136 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2009/05/21 17:51:48 | 00,041,808 | —- | C] () – C:\WINDOWS\System32\xfcodec.dll
[2009/04/22 01:19:06 | 00,172,173 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2008/08/07 06:28:12 | 00,000,075 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2008/08/01 10:00:28 | 00,593,920 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/08/01 10:00:28 | 00,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/08/01 10:00:24 | 00,010,752 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/08/01 10:00:24 | 00,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2008/07/23 11:50:52 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/07/23 11:47:34 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/07/23 11:47:34 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2008/07/23 11:46:38 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/06/09 03:58:43 | 00,274,432 | —- | C] () – C:\WINDOWS\eSTsnmp.dll
[2008/06/09 03:58:41 | 00,274,432 | —- | C] () – C:\WINDOWS\System32\eSTsnmp.dll
[2008/06/09 03:58:29 | 00,014,920 | —- | C] () – C:\WINDOWS\R2_9.ini
[2008/06/01 16:27:27 | 00,532,480 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Sony.dll
[2008/05/11 01:10:38 | 00,000,131 | —- | C] () – C:\WINDOWS\iridium.ini
[2008/05/09 07:40:55 | 00,000,055 | —- | C] () – C:\WINDOWS\ATTWKTOP.INI
[2008/05/09 02:38:36 | 00,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2008/05/09 02:14:24 | 00,000,467 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/04/24 01:46:54 | 00,000,491 | —- | C] () – C:\WINDOWS\SMSCFG.ini
[2008/04/23 03:38:54 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\IPDll.dll
[2008/04/23 03:28:15 | 00,000,280 | —- | C] () – C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2008/04/16 06:17:17 | 00,000,000 | —- | C] () – C:\WINDOWS\tosOBEX.INI
[2007/01/03 00:54:36 | 00,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 00:52:46 | 00,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 00:52:14 | 00,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/10/31 07:07:00 | 00,114,688 | —- | C] () – C:\WINDOWS\System32\TosBtAcc.dll
[2006/08/10 04:30:52 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\TosBtHcrpAPI.dll
[2005/07/22 11:00:20 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\TosCommAPI.dll
[2003/03/09 11:01:04 | 00,561,152 | —- | C] () – C:\WINDOWS\System32\hpotscl.dll

========== LOP Check ==========

[2008/04/23 03:59:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Funk Software
[2008/04/23 03:57:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Infineon
[2008/05/02 08:17:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Protector Suite
[2009/10/18 18:42:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Subversion
[2009/09/28 12:24:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\SystemRequirementsLab
[2009/08/29 15:19:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Thunderbird
[2010/01/09 17:54:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\uTorrent
[2008/04/24 01:38:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
[2008/04/16 03:30:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Infineon
[2008/04/23 03:28:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Network Associates
[2008/04/16 04:45:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Novatel Wireless
[2008/04/23 00:17:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/10/17 23:49:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PreEmptive Solutions
[2009/05/12 22:34:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/07/10 20:08:02 | 00,000,348 | —- | M] () – C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1100 series#1210333227.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 07:00:00 | 18,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/13 13:36:38 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 07:00:00 | 18,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/13 13:40:30 | 00,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[2004/08/03 12:29:44 | 00,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\dllcache\atapi.sys
[2004/08/03 12:29:44 | 00,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 07:00:00 | 00,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 00,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll
[2004/08/04 07:00:00 | 00,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2004/08/04 07:00:00 | 00,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[2009/02/06 13:46:09 | 00,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 13:46:09 | 00,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/04 07:00:00 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\dllcache\netlogon.dll
[2004/08/04 07:00:00 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 07:00:00 | 00,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\dllcache\scecli.dll
[2004/08/04 07:00:00 | 00,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >
< End of report >
Here is Extras.txt

OTL Extras logfile created on: 1/19/2010 11:52:10 PM - Run 1
OTL by OldTimer - Version 3.1.25.2 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 63.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 43.95 Gb Total Space | 7.26 Gb Free Space | 16.52% Space Free | Partition Type: NTFS
Drive D: | 49.20 Gb Total Space | 22.80 Gb Free Space | 46.34% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 535.75 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 1.89 Gb Total Space | 1.28 Gb Free Space | 67.44% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MALIPEDDI
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe" = C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0 – (CyberLink Corp.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\McAfee\Common Framework\FrameworkService.exe" = C:\Program Files\McAfee\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service – (McAfee, Inc.)
"C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe" = C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0 – (CyberLink Corp.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – (Apple Inc.)
"C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\Launcher.exe" = C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher – (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"D:\CS225\bin\XWin.exe" = D:\CS225\bin\XWin.exe:*:Enabled:XWin – ()
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Disabled:Yahoo! Messenger – (Yahoo! Inc.)
"D:\uTorrent.exe" = D:\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"C:\Program Files\Common Files\Microsoft Shared\XNA\XnaTrans\v3.0\XnaTransX.exe" = C:\Program Files\Common Files\Microsoft Shared\XNA\XnaTrans\v3.0\XnaTransX.exe:LocalSubNet:Enabled:XNA Game Studio 3.1 Transport – (Microsoft Corporation)
"C:\Program Files\Microsoft XNA\XNA Game Studio\v3.1\Bin\XnaLiveProxy.exe" = C:\Program Files\Microsoft XNA\XNA Game Studio\v3.1\Bin\XnaLiveProxy.exe:LocalSubNet:Enabled:XNA Framework Games for Windows - LIVE – (Microsoft Corporation)
"D:1\Abhi\Counter-Strike 1.6\hl.exe" = D:1\Abhi\Counter-Strike 1.6\hl.exe:*:Disabled:hl.exe


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{007BECB0-17DD-4230-9D2F-185287262B14}" = Microsoft XNA Game Studio 3.1 (Platformer)
"{01161F64-6897-4885-93A0-A9F7BE9A4253}" = hp psc 1100 series
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{054970C5-50A6-44A4-BEAC-3C1B5EACB0EE}" = Windows Desktop Search: Add-in for Outlook saved mail (.msg file) indexing
"{05B49229-22A2-4F88-842A-BBC2EBE1CCF6}" = Microsoft Games for Windows - LIVE Redistributable
"{05EC21B8-4593-3037-A781-A6B5AFFCB19D}" = Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0916B063-CC06-4AED-92BD-87B48ECA9037}" = Odyssey Client
"{0DC16794-7E69-4534-82FA-9DD0500FF338}" = Microsoft XNA Game Studio 3.1 (Redists)
"{0E9404D1-EE63-46C7-8B99-2389614F081B}" = TOSHIBA e-STUDIO282 Series Client
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1C70BE80-35E0-46DA-B81D-5BF5652F8D80}" = AV Mode Button Utility
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{241F2BF7-69EB-42A4-9156-96B2426C7504}" = Microsoft SQL Server Compact 3.5 for Devices ENU
"{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 15
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{291B3A3B-F808-45B8-8113-DF232FCB6C82}" = Microsoft .NET Compact Framework 3.5
"{2A0F3EF9-68EE-49E9-A05B-ED5B82DF63E5}" = Wireless Switch Setting Utility
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
"{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"{2C27866B-00E1-4AFF-A199-C7E978A10FC6}" = HUAWEI Mobile Connect
"{2E402AA9-5C0E-45E7-8E70-C23FA0F265D5}" = Microsoft XNA Game Studio 3.1 (devenv)
"{2E5C075E-11AB-4BDD-918C-7B9A68953FF8}" = Microsoft SQL Server Compact 3.5 Design Tools ENU
"{2FE4F7D0-49ED-4A85-88C1-1EA443789C4F}" = Microsoft Office Communicator 2005 MUI Pack
"{32A3A4F4-B792-11D6-A78A-00B0D0160110}" = Java™ SE Development Kit 6 Update 11
"{33BBE45C-6296-488A-B7D5-37E692E71B3F}" = TortoiseSVN 1.6.5.16974 (32 bit)
"{3505E1E2-8127-4681-A3EC-F9B5CAAA07C9}" = Rights Management Add-on for Internet Explorer
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35C03C04-3F1F-42C2-A989-A757EE691F65}" = McAfee VirusScan Enterprise
"{37FD2F04-EC91-41AE-B5AB-AFF904BF20EE}" = Mobile Broadband Drivers
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}" = Microsoft XNA Framework Redistributable 3.0
"{4235A9E5-EEFF-42E7-BEC9-9D421DD10ECB}" = 12Sky
"{4A39A27F-005B-407E-8CF5-F4D8065658E4}" = SMS Advanced Client
"{4E993095-28F2-4060-9101-99C1FD1195C0}" = VAIO Central
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{575B2F67-48E4-42C8-B783-C426CD602F72}" = Avaya IP Softphone R5 Service Pack 1
"{59452470-A902-477F-9338-9B88101681BD}" = Setting Utility Series
"{596F2287-ACD9-4E5F-978C-43A00A7A98B8}" = BlackBerry v4.2.1 for the 8800 Series Wireless Handheld
"{5AE5DB70-5CE6-4876-A83E-8246CC36FC28}" = Microsoft Office PowerPoint 2007 Get Started Tab
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8
"{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}" = iTunes
"{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}" = Adobe Setup
"{64c5b887-b5ee-42b8-8596-78905a6b5f1f}" = Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense
"{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008
"{68B52EFD-86CC-486E-A8D0-A3A1554CB5BC}" = Microsoft Office Word 2007 Get Started Tab
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6C9F6D23-E9AD-43C9-B43A-011562AAF876}" = Windows Mobile 5.0 SDK R2 for Pocket PC
"{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}" = Adobe Color Common Settings
"{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}" = HP Photo and Imaging 2.0 - All-in-One Drivers
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72EEB695-388B-4835-8EA6-0C04545B06B9}" = Intel® PROSet/Wireless WiFi Software
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7FD30AE7-281D-455F-AF9F-0C6C5E334EAD}" = Microsoft XNA Game Studio 3.1 Documentation
"{842FAF7C-50EF-4463-9B8F-6222E1384D7D}" = Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
"{8696ED8F-F797-40F0-A52A-CF6552E338E1}" = Mobile Broadband Drivers
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8DF4C627-4AF3-4245-9F13-3518FC8584DC}" = Protector Suite QL 5.3
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{EC665AD1-E403-4501-8201-8C51A591A7D1}" =
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0021-0000-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer 2007
"{90120000-0021-0000-0000-0000000FF1CE}_VisualWebDeveloper_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0021-0409-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer MUI (English) 2007
"{90120000-0021-0409-0000-0000000FF1CE}_VisualWebDeveloper_{E1044ED2-E4AD-4B39-B500-31109750F6B4}" = Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_VisualWebDeveloper_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_VisualWebDeveloper_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{93870D50-E624-40B4-936B-544FCB39898C}" = CITES VPN Connection
"{9656F3AC-6BA9-43F0-ABED-F214B5DAB27B}" = Windows Mobile 5.0 SDK R2 for Smartphone
"{9867A917-5D17-40DE-83BA-BEA5293194B1}" = HP Photo and Imaging 2.0 - All-in-One
"{998D6972-F58E-479D-9248-8F179E55AE38}" = Java DB 10.4.1.3
"{9A33B83D-FFC4-44CF-BEEF-632DECEF2FCD}" = Microsoft SQL Server Database Publishing Wizard 1.2
"{9E319E96-ED8E-4B01-9775-C521A1869A25}" = VAIO Power Management
"{A0EB195B-5876-48E6-879D-33D4B2102610}" = SonicStage 4.3
"{A1288842-D600-453F-B61F-6C2AA3D6A528}" = Ragnarok Online
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AA467959-A1D6-4F45-90CD-11DC57733F32}" = Crystal Reports Basic for Visual Studio 2008
"{AB706D91-2242-4E1D-B4D0-1ED35387F5A7}" = Microsoft Office Excel 2007 Get Started Tab
"{AC76BA86-1033-0000-7760-000000000001}" = Adobe Acrobat 6.0 Professional
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.5
"{AC76BA86-7AD7-1033-7B44-A81300000003}_814" = KB408682
"{AF9BDE67-11A5-449A-B9F0-BE572A093DDB}" = Microsoft XNA Game Studio 3.1 (Shared Components)
"{AFA20D47-69C3-4030-8DF8-D37466E70F13}" = Apple Mobile Device Support
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B268E9A1-04A9-40D0-9866-846BE2B74BA7}" = Microsoft Windows SDK for Visual Studio 2008 Win32 Tools
"{B32E7732-B2FB-3FD0-81AC-6025B1104C66}" = Microsoft Device Emulator version 3.0 - ENU
"{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BCC899FE-2DAA-460C-A5FB-60291E73D9C3}" = Microsoft SQL Server Compact 3.5 ENU
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}" = Windows Rights Management Client with Service Pack 2
"{BE56FEF0-1A0F-4719-B3AD-34B5087AFA6D}" = Sony Video Shared Library
"{BE5AD430-9E0C-4243-AB3F-593835869855}" = Microsoft Office Communicator 2005
"{BED4CEEC-863F-4AB3-BA23-541764E2D2CE}" = Microsoft XNA Game Studio Platform Tools
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C518C7BF-A345-4019-815B-FFDF32EBCAD9}" = VAIO HDD Protection
"{CAA376AF-0DE8-4FCA-942E-C6AC579B94B3}" = Microsoft Windows SDK for Visual Studio 2008 Tools
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D7DAD1E4-45F4-3B2B-899A-EA728167EC4F}" = Microsoft Visual Studio 2008 Professional Edition - ENU
"{D9952D4E-766C-4CD3-BF2E-A2C3D8B15EF3}" = VAIO Backup Utility
"{DFB81F19-ED3A-4DA5-AFE4-1B999E2A8DC5}" = Microsoft XNA Game Studio 3.1 (XnaLiveProxy)
"{E1D78366-91DA-4AD0-B417-28155743CC22}" = Microsoft XNA Game Studio 3.1 (ARP entry)
"{E56D39F8-2A9F-44B4-B068-A72E45A073E6}" = Safari
"{E6707034-D7A4-49B1-94D0-F5AACE46F06C}" = Instant Mode
"{E72019B8-1287-4093-BE9B-1CFA7BA1A8D2}" = Windows Desktop Search 3.01
"{EDDF99D9-9FE3-4871-A7DB-D1522C51EE9A}" = Microsoft .NET Compact Framework 2.0 SP2
"{EEE90C2D-8ACE-4007-9CF6-B07D0516F6B9}" = Intel® PRO Network Connections [removed]
"{EF3D45BB-2260-4008-88EA-492E7744A9DF}" = Sony Utilities DLL
"{EF964A78-078C-11D1-B7A7-0000C0134CE6}" = Nortel Networks Contivity VPN Client
"{F0D85ADD-DD61-4B43-87A0-6DA52A211A8B}" = VAIO Event Service
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"0D55F1DBECC31298ABB5EE87277086671C6C92D9" = Windows Driver Package - Intel (E100B) Net (06/13/2005 8.0.21.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2
"Adobe_6c8e2cb4fd241c55406016127a6ab2e" = Adobe Color Common Settings
"avast!" = avast! Antivirus
"BITSAT-2008-PCM Sample_is1" = BITSAT-2008-PCM Sample
"Blender" = Blender (remove only)
"Canon LBP5200" = Canon LBP5200
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_20030003" = HDAUDIO SoftV92 Data Fax Modem with SmartCP
"DL" = Delta Flight Schedules
"EAX™ Unified (SHELL)" = EAX™ Unified (SHELL)
"FINAL FANTASY VIII" = FINAL FANTASY VIII
"HP PSC 1100 Series" = HP Photo and Imaging 2.0 - hp psc 1100 series
"hp psc 1100 series_Driver" = hp psc 1100 series
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"InstallShield_{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"IrfanView" = IrfanView (remove only)
"Karnaugh Map Minimizer" = Karnaugh Map Minimizer 0.4
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 2.1.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Anti-Spyware Enterprise Module" = McAfee AntiSpyware Enterprise Module
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Microsoft Visual Studio 2008 Professional Edition - ENU" = Microsoft Visual Studio 2008 Professional Edition - ENU
"MouseSuite98" = Sony USB Mouse
"Mozilla Firefox (3.5.7)" = Mozilla Firefox (3.5.7)
"Mozilla Thunderbird (2.0.0.23)" = Mozilla Thunderbird (2.0.0.23)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OpenMG HotFix4.7-07-13-22-01" = OpenMG Limited Patch 4.7-07-14-05-01
"Picasa 3" = Picasa 3
"ProInst" = Intel PROSet Wireless
"PROPLUS" = Microsoft Office Professional Plus 2007
"PuTTY_is1" = PuTTY development snapshot 2009-12-14:r8755
"RealPlayer 6.0" = RealPlayer
"Steam App 10" = Counter-Strike
"Steam App 80" = Condition Zero
"SystemRequirementsLab" = System Requirements Lab
"uTorrent" = µTorrent
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime
"VisualWebDeveloper" = Microsoft Visual Studio Web Authoring Component
"VLC media player" = VideoLAN VLC media player 0.8.6i
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinRAR archiver" = WinRAR archiver
"winscp3_is1" = WinSCP 4.2.3 beta
"WinVNC_is1" = VNC 3.3.4
"WinZip" = WinZip
"World of Warcraft" = World of Warcraft
"Xfire" = Xfire (remove only)
"XNA Game Studio 3.1" = Microsoft XNA Game Studio 3.1
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 9/20/2009 1:42:39 AM | Computer Name = MALIPEDDI | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
H:\Wedding Card 2(telugu).jpg failed, 0000A420.

Error - 9/20/2009 1:42:39 AM | Computer Name = MALIPEDDI | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
H:\Wedding Card 2(English).jpg failed, 0000A420.

Error - 9/20/2009 1:42:39 AM | Computer Name = MALIPEDDI | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
H:\Wedding Card 1(telugu).jpg failed, 0000A420.

Error - 11/5/2009 3:42:30 AM | Computer Name = MALIPEDDI | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://www.otakuzone.com/ajax.php?action=c…ter_ajax_search failed, 0000A413.


Error - 11/6/2009 1:21:30 AM | Computer Name = MALIPEDDI | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://www.otakuzone.com/zone/ajax.php?type=getrecentfriend failed, 0000A413.

Error - 11/6/2009 1:22:10 AM | Computer Name = MALIPEDDI | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://www.otakuzone.com/zone/ajax.php?type=getrecentfriend failed, 0000A413.

Error - 11/6/2009 12:04:35 PM | Computer Name = MALIPEDDI | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://www.searchingvalley.com/search.php?…rds=video+games
failed, 0000A413.

Error - 11/6/2009 12:08:39 PM | Computer Name = MALIPEDDI | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://fim.adnxs.com/fpt?id=3593&size=…b=1257523719306
failed, 0000A413.

Error - 11/9/2009 11:15:38 PM | Computer Name = MALIPEDDI | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://fim.adnxs.com/fpt?id=3593&size=…b=1257822936870
failed, 0000A413.

[ Application Events ]
Error - 1/17/2010 7:18:13 AM | Computer Name = MALIPEDDI | Source = Google Update | ID = 20
Description =

Error - 1/17/2010 8:18:10 AM | Computer Name = MALIPEDDI | Source = Google Update | ID = 20
Description =

Error - 1/17/2010 9:18:09 AM | Computer Name = MALIPEDDI | Source = Google Update | ID = 20
Description =

Error - 1/17/2010 10:18:10 AM | Computer Name = MALIPEDDI | Source = Google Update | ID = 20
Description =

Error - 1/17/2010 11:18:11 AM | Computer Name = MALIPEDDI | Source = Google Update | ID = 20
Description =

Error - 1/17/2010 12:18:09 PM | Computer Name = MALIPEDDI | Source = Google Update | ID = 20
Description =

Error - 1/17/2010 1:18:09 PM | Computer Name = MALIPEDDI | Source = Google Update | ID = 20
Description =

Error - 1/17/2010 1:55:47 PM | Computer Name = MALIPEDDI | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 1/17/2010 1:59:44 PM | Computer Name = MALIPEDDI | Source = Windows Search Service | ID = 3102
Description = The per-user filter pool for session 0 could not be added <1245,0>.

Details:
The
operation being requested was not performed because the user has not logged on
to the network. The specified service does not exist. (0x800704dd)

Error - 1/17/2010 2:56:12 PM | Computer Name = MALIPEDDI | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

[ Application Events ]
Error - 1/17/2010 7:18:13 AM | Computer Name = MALIPEDDI | Source = Google Update | ID = 20
Description =

Error - 1/17/2010 8:18:10 AM | Computer Name = MALIPEDDI | Source = Google Update | ID = 20
Description =

Error - 1/17/2010 9:18:09 AM | Computer Name = MALIPEDDI | Source = Google Update | ID = 20
Description =

Error - 1/17/2010 10:18:10 AM | Computer Name = MALIPEDDI | Source = Google Update | ID = 20
Description =

Error - 1/17/2010 11:18:11 AM | Computer Name = MALIPEDDI | Source = Google Update | ID = 20
Description =

Error - 1/17/2010 12:18:09 PM | Computer Name = MALIPEDDI | Source = Google Update | ID = 20
Description =

Error - 1/17/2010 1:18:09 PM | Computer Name = MALIPEDDI | Source = Google Update | ID = 20
Description =

Error - 1/17/2010 1:55:47 PM | Computer Name = MALIPEDDI | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 1/17/2010 1:59:44 PM | Computer Name = MALIPEDDI | Source = Windows Search Service | ID = 3102
Description = The per-user filter pool for session 0 could not be added <1245,0>.

Details:
The
operation being requested was not performed because the user has not logged on
to the network. The specified service does not exist. (0x800704dd)

Error - 1/17/2010 2:56:12 PM | Computer Name = MALIPEDDI | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

[ System Events ]
Error - 1/17/2010 2:27:57 PM | Computer Name = MALIPEDDI | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 1/17/2010 2:31:17 PM | Computer Name = MALIPEDDI | Source = DCOM | ID = 10016
Description = The machine-default permission settings do not grant Local Activation
permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission
can be modified using the Component Services administrative tool.

Error - 1/17/2010 2:31:19 PM | Computer Name = MALIPEDDI | Source = DCOM | ID = 10016
Description = The machine-default permission settings do not grant Local Activation
permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission
can be modified using the Component Services administrative tool.

Error - 1/17/2010 2:31:19 PM | Computer Name = MALIPEDDI | Source = DCOM | ID = 10016
Description = The machine-default permission settings do not grant Local Activation
permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission
can be modified using the Component Services administrative tool.

Error - 1/17/2010 2:59:56 PM | Computer Name = MALIPEDDI | Source = Service Control Manager | ID = 7000
Description = The Nortel Extranet Access Protocol service failed to start due to
the following error: %%2

Error - 1/17/2010 2:59:56 PM | Computer Name = MALIPEDDI | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 1/17/2010 3:02:15 PM | Computer Name = MALIPEDDI | Source = DCOM | ID = 10016
Description = The machine-default permission settings do not grant Local Activation
permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission
can be modified using the Component Services administrative tool.

Error - 1/17/2010 3:02:16 PM | Computer Name = MALIPEDDI | Source = DCOM | ID = 10016
Description = The machine-default permission settings do not grant Local Activation
permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission
can be modified using the Component Services administrative tool.

Error - 1/17/2010 3:02:16 PM | Computer Name = MALIPEDDI | Source = DCOM | ID = 10016
Description = The machine-default permission settings do not grant Local Activation
permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission
can be modified using the Component Services administrative tool.

Error - 1/20/2010 12:23:55 AM | Computer Name = MALIPEDDI | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.10.108 for the Network Card with network
address 0019D28C9F5C has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).


< End of report >
As for how my computer is running, the speed seems fine but I get a lot of messages trying to get me to download anti virus software which are obviously the malware messages,my wallpaper is fixed, I cant access some website like youtube and some apps like chrome cant be opened because is it says its infected. Also recently avast caught some more viruses i moved to chest.

EDIT

I forgot to connect my external hard drive while doing this scan,should i do it again with it?
[external image: Posted Image] One or more of the identified infections is a backdoor trojan and password stealer.

This type of infection allows hackers to access and remotely control your computer, log keystrokes, steal critical system information, and download and execute files without your knowledge.
If you do any banking or other financial transactions on the PC or if it contains any other sensitive information, then from a clean computer, change all passwords where applicable.
It would also be wise to contact those same financial institutions to appraise them of your situation.


I highly suggest you take a look at the two links provided below:
1. How Do I Handle Possible Identify Theft, Internet Fraud, and CC Fraud?
2. When should I re-format? How should I reinstall?


Next:


ComboFix Warning
From the looks of your logs, I see that you recently downloaded ComboFix to your computer. After looking at your logs, I do not believe you've run it on your computer. Please refrain from running any additional tools, unless advised to do so by myself. It's important to mention that ComboFix is a very powerful tool and if used improperly can turn your computer into a paper weight.


Next:


Peer to Peer Program
While reviewing your logs I noticed that you currently have Peer to Peer program(s) installed on your computer.

You currently have the following P2P programs installed:
  • uTorrent
Most of the infections that we see today are through P2P file sharing. By uninstalling the programs that I mentioned above you will be doing yourself a favor. It's impossible to trust the source of what is being downloaded from them and a file may or may not be what it appears to be.

Should you decide to keep these programs installed on your computer PLEASE do not use these programs while we are getting your P.C. cleaned up.

How to Uninstall the P2P Programs:

Remove Program
We need to remove a program. To do this please do the following:
  • Click Start
  • Go to Control Panel
  • Go to Add/Remove Programs
  • Find and click Remove for the following (if present):
  • uTorrent
PLEASE NOTE: When your uninstalling the P2P Program(s) some questions are worded in various ways to try and deceive you and keep you from uninstalling their Program.


Next:


Multiple Anti-Virus Programs
Your currently running multiple Anti-Virus programs. This will cause your Anti-Virus programs to conflict with each other and will cause more problems than it will prevent. Please choose which one you would like to keep and uninstall the others.

  • Click Start
  • Go to Control Panel
  • Go to Add/Remove Programs
  • Find and click Remove for either avast! or McAfee AntiSpyware Enterprise Module (only uninstall 1).

Next:


OTL Fix
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\WINDOWS\System32\smss32.exe File not found
    O4 - HKLM..\Run: [KernelFaultCheck] File not found
    O4 - HKLM..\Run: [Mouse Suite 98 Daemon] File not found
    O4 - HKLM..\Run: [UserFaultCheck] File not found
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
    [2010/01/19 23:41:04 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\5447.exe
    [2010/01/19 23:21:03 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\19895.exe
    [2010/01/17 23:22:16 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\19718.exe
    [2010/01/17 23:02:15 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\18716.exe
    [2010/01/17 22:42:15 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\17421.exe
    [2010/01/17 22:22:14 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\12382.exe
    [2010/01/17 22:02:14 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\292.exe
    [2010/01/17 21:42:13 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\153.exe
    [2010/01/17 21:22:13 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\3902.exe
    [2010/01/17 21:02:12 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\14604.exe
    [2010/01/17 20:42:12 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\32391.exe
    [2010/01/17 20:22:11 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\5436.exe
    [2010/01/17 20:02:11 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\4827.exe
    [2010/01/17 19:42:10 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\11942.exe
    [2010/01/17 19:22:10 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\2995.exe
    [2010/01/17 19:02:09 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\491.exe
    [2010/01/17 18:42:08 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\9961.exe
    [2010/01/17 18:22:08 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\16827.exe
    [2010/01/17 18:02:07 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\23281.exe
    [2010/01/17 17:42:07 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\28145.exe
    [2010/01/17 17:22:06 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\5705.exe
    [2010/01/17 17:02:05 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\24464.exe
    [2010/01/17 16:42:05 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\26962.exe
    [2010/01/17 16:22:04 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\29358.exe
    [2010/01/17 16:02:03 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\11478.exe
    [2010/01/17 15:42:03 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\15724.exe
    [2010/01/17 15:22:02 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\19169.exe
    [2010/01/17 15:02:02 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\26500.exe
    [2010/01/17 14:42:01 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\6334.exe
    [2010/01/17 14:22:01 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\18467.exe
    [2010/01/17 14:02:00 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\41.exe
    [2010/01/17 14:01:58 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\IS15.exe
    [2010/01/17 14:01:44 | 00,002,931 | —- | M] () – C:\WINDOWS\System32\warning.html
    [2010/01/17 12:51:46 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\27446.exe
    [2010/01/17 12:31:46 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\22648.exe
    [2010/01/17 12:11:45 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\19264.exe
    [2010/01/17 11:51:45 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\8942.exe
    [2010/01/17 11:31:45 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\9040.exe
    [2010/01/17 11:11:44 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\30106.exe
    [2010/01/17 10:51:44 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\288.exe
    [2010/01/17 10:31:44 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\1842.exe
    [2010/01/17 10:11:44 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\22190.exe
    [2010/01/17 09:51:44 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\3035.exe
    [2010/01/17 09:31:44 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\12316.exe
    [2010/01/17 09:11:43 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\778.exe
    [2010/01/17 08:51:43 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\27529.exe
    [2010/01/17 08:31:43 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\9741.exe
    [2010/01/17 08:11:43 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\8723.exe
    [2010/01/17 07:51:43 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\12859.exe
    [2010/01/17 07:31:43 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\20037.exe
    [2010/01/17 07:11:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\32757.exe
    [2010/01/17 06:51:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\32662.exe
    [2010/01/17 06:31:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\27644.exe
    [2010/01/17 06:11:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\25547.exe
    [2010/01/17 05:51:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\6868.exe
    [2010/01/17 05:31:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\28253.exe
    [2010/01/17 05:11:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\7711.exe
    [2010/01/17 04:51:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\15141.exe
    [2010/01/17 04:31:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\4664.exe
    [2010/01/17 04:11:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\17673.exe
    [2010/01/17 03:51:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\30333.exe
    [2010/01/17 03:31:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\31322.exe
    [2010/01/17 03:11:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\23811.exe
    [2010/01/17 02:51:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\28703.exe
    [2010/01/17 02:31:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\9894.exe
    [2010/01/17 02:11:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\17035.exe
    [2010/01/17 01:51:40 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\26299.exe
    [2010/01/17 01:31:38 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\25667.exe
    [2010/01/17 01:11:37 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\19912.exe
    [2010/01/17 00:51:37 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\1869.exe
    [2010/01/17 00:31:37 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\11538.exe
    [2010/01/17 00:11:36 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\14771.exe
    [2010/01/16 23:51:36 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\21726.exe
    [2010/01/16 13:24:50 | 00,000,001 | —- | M] () – C:\s
    
    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    ""=-
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
Next:


Scanning with GMER

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



Next:


Please make sure you include the following items in your next post:

1. The log that was produced after running the OTL Fix.
2. The log that was produced after running the GMER scan.
3. An update on how the computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.

Next:


Peer to Peer Program
While reviewing your logs I noticed that you currently have Peer to Peer program(s) installed on your computer.

You currently have the following P2P programs installed:

  • uTorrent
Most of the infections that we see today are through P2P file sharing. By uninstalling the programs that I mentioned above you will be doing yourself a favor. It's impossible to trust the source of what is being downloaded from them and a file may or may not be what it appears to be.

Should you decide to keep these programs installed on your computer PLEASE do not use these programs while we are getting your P.C. cleaned up.

How to Uninstall the P2P Programs:

Remove Program
We need to remove a program. To do this please do the following:
  • Click Start
  • Go to Control Panel
  • Go to Add/Remove Programs
  • Find and click Remove for the following (if present):
  • uTorrent
PLEASE NOTE: When your uninstalling the P2P Program(s) some questions are worded in various ways to try and deceive you and keep you from uninstalling their Program.


Next:


Multiple Anti-Virus Programs
Your currently running multiple Anti-Virus programs. This will cause your Anti-Virus programs to conflict with each other and will cause more problems than it will prevent. Please choose which one you would like to keep and uninstall the others.

  • Click Start
  • Go to Control Panel
  • Go to Add/Remove Programs
  • Find and click Remove for either avast! or McAfee AntiSpyware Enterprise Module (only uninstall 1).


I am unable to uninstall uTorrent because it says it cannot be run as app is infected and I have to turn on my virus scan.

Also about the virus scans which do you think I should keep?
McAfee has been on this computer for a while, and since this was my fathers office laptop till around 1 year ago, I assume McAfee is one of those paid and upgraded ones. However Avast is a free version.
Oh and there are 2 McAfee programs, if i remove mcAfee should i remove them both?( McAfee AntiSpyware Enterprise Module and McAfee AntiVirus Enterprise )

Also I ran the OTL scan without my external hard drive which was also connected when I got the virus.Should I run it again and post logs?
Your probably unable to uninstall uTorrent, because the infection is preventing you from uninstalling applications. We can try and uninstall it later on after we've gotten you cleaned up.

McAfee is a paid security program. It's possible that the subscription to McAfee is expired. McAfee tends to be a little heavy on the resources and can slow down your computer a great deal. If I were you I would uninstall both versions of McAfee (McAfee Anti-Spyware Enterprise Module and McAfee Anti-Virus Enterprise) and stick with avast!

Go ahead and plug your external hard drive into your computer. Run the OTL Fix that was provided in my last set of instructions to you. Run a new OTL Scan and then continue to follow the directions from there.

Post the logs that are produced after running the tools.
When I ran the fix it terminated some processes which took it to a state like when my computer is just booting and so my wallpaper is back to the proper one when the fix is running but the fix seems to have stopped at PRC - C:\WINDOWS\System32\smss32.exe File not found Its been like that for over 4 hours now. Should I restart?
Hello chaosknight,


Yes, please go ahead and reboot your computer.

Then run the script that I've included below:

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] File not found
O4 - HKLM..\Run: [UserFaultCheck] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
[2010/01/19 23:41:04 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\5447.exe
[2010/01/19 23:21:03 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\19895.exe
[2010/01/17 23:22:16 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\19718.exe
[2010/01/17 23:02:15 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\18716.exe
[2010/01/17 22:42:15 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\17421.exe
[2010/01/17 22:22:14 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\12382.exe
[2010/01/17 22:02:14 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\292.exe
[2010/01/17 21:42:13 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\153.exe
[2010/01/17 21:22:13 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\3902.exe
[2010/01/17 21:02:12 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\14604.exe
[2010/01/17 20:42:12 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\32391.exe
[2010/01/17 20:22:11 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\5436.exe
[2010/01/17 20:02:11 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\4827.exe
[2010/01/17 19:42:10 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\11942.exe
[2010/01/17 19:22:10 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\2995.exe
[2010/01/17 19:02:09 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\491.exe
[2010/01/17 18:42:08 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\9961.exe
[2010/01/17 18:22:08 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\16827.exe
[2010/01/17 18:02:07 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\23281.exe
[2010/01/17 17:42:07 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\28145.exe
[2010/01/17 17:22:06 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\5705.exe
[2010/01/17 17:02:05 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\24464.exe
[2010/01/17 16:42:05 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\26962.exe
[2010/01/17 16:22:04 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\29358.exe
[2010/01/17 16:02:03 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\11478.exe
[2010/01/17 15:42:03 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\15724.exe
[2010/01/17 15:22:02 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\19169.exe
[2010/01/17 15:02:02 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\26500.exe
[2010/01/17 14:42:01 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\6334.exe
[2010/01/17 14:22:01 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\18467.exe
[2010/01/17 14:02:00 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\41.exe
[2010/01/17 14:01:58 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\IS15.exe
[2010/01/17 14:01:44 | 00,002,931 | —- | M] () – C:\WINDOWS\System32\warning.html
[2010/01/17 12:51:46 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\27446.exe
[2010/01/17 12:31:46 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\22648.exe
[2010/01/17 12:11:45 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\19264.exe
[2010/01/17 11:51:45 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\8942.exe
[2010/01/17 11:31:45 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\9040.exe
[2010/01/17 11:11:44 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\30106.exe
[2010/01/17 10:51:44 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\288.exe
[2010/01/17 10:31:44 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\1842.exe
[2010/01/17 10:11:44 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\22190.exe
[2010/01/17 09:51:44 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\3035.exe
[2010/01/17 09:31:44 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\12316.exe
[2010/01/17 09:11:43 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\778.exe
[2010/01/17 08:51:43 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\27529.exe
[2010/01/17 08:31:43 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\9741.exe
[2010/01/17 08:11:43 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\8723.exe
[2010/01/17 07:51:43 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\12859.exe
[2010/01/17 07:31:43 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\20037.exe
[2010/01/17 07:11:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\32757.exe
[2010/01/17 06:51:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\32662.exe
[2010/01/17 06:31:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\27644.exe
[2010/01/17 06:11:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\25547.exe
[2010/01/17 05:51:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\6868.exe
[2010/01/17 05:31:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\28253.exe
[2010/01/17 05:11:42 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\7711.exe
[2010/01/17 04:51:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\15141.exe
[2010/01/17 04:31:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\4664.exe
[2010/01/17 04:11:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\17673.exe
[2010/01/17 03:51:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\30333.exe
[2010/01/17 03:31:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\31322.exe
[2010/01/17 03:11:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\23811.exe
[2010/01/17 02:51:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\28703.exe
[2010/01/17 02:31:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\9894.exe
[2010/01/17 02:11:41 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\17035.exe
[2010/01/17 01:51:40 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\26299.exe
[2010/01/17 01:31:38 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\25667.exe
[2010/01/17 01:11:37 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\19912.exe
[2010/01/17 00:51:37 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\1869.exe
[2010/01/17 00:31:37 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\11538.exe
[2010/01/17 00:11:36 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\14771.exe
[2010/01/16 23:51:36 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\21726.exe
[2010/01/16 13:24:50 | 00,000,001 | —- | M] () – C:\s

:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
""=-
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI