This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] [Re-opend] Virus Found on Dimension E521, Virus

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello

I have recently switched virus programs on my main computer, my Dell Dimension E521.

For some reason I ran in to this viruses, although I could have sworn my computer was clean.

When I scanned my computer with AVG I found this two viruses which I put in the virus vault for now.

C:\WINDOWS\system32\Process.exe

C:\System Volume Information\_restore{D7DA9377-6CD2-4D98-B4BA-013F20854ED5}\RP676A0098646.exe

For virus name both read: Virus found Corrupted and Severity read: Infection
Hello, Mordimier
Welcome to the WhatTheTech Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.



Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.





  • Please download OTL from one of the following mirrors:
    • This is THE Mirror
  • Save it to your desktop.
  • Double click on the [external image: Posted Image] icon on your desktop.
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
  • Push the Quick Scan button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <– Will be opened
    • Extra.txt <– Will be minimized
Hey Tom and thanks for aiding me in my learning journey with this :)

Here is the OTL log:



OTL logfile created on: 3/28/2010 9:45:58 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\GUgenH3iMer schmidt\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 76.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 4989 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.46 Gb Total Space | 1.40 Gb Free Space | 1.96% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: USERCHRIS
Current User Name: GUgenH3iMer schmidt
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/03/28 21:24:18 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\OTL.exe
PRC - [2010/03/26 13:52:46 | 000,136,176 | —- | M] (Google Inc.) – C:\Documents and Settings\GUgenH3iMer schmidt\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe
PRC - [2010/03/24 12:58:30 | 001,086,744 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/03/24 12:58:30 | 000,617,752 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/03/24 12:58:28 | 000,508,184 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/03/24 12:58:25 | 000,710,424 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/03/24 12:58:10 | 002,059,544 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/03/24 12:58:05 | 002,325,816 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgfws9.exe
PRC - [2010/03/24 12:57:42 | 000,836,888 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgam.exe
PRC - [2010/03/24 12:57:39 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/03/24 12:57:28 | 000,596,488 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2010/03/24 12:57:25 | 005,888,008 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2010/03/22 13:51:30 | 000,530,928 | —- | M] (Google Inc.) – C:\Documents and Settings\GUgenH3iMer schmidt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2009/12/21 19:10:03 | 000,198,160 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009/05/27 04:27:04 | 029,262,680 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
PRC - [2008/11/24 23:31:12 | 000,087,904 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
PRC - [2008/11/24 23:31:08 | 000,239,968 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/02/05 18:20:42 | 000,150,040 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2008/02/05 18:18:48 | 000,186,904 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2006/07/27 15:19:00 | 000,282,624 | —- | M] (SigmaTel, Inc.) – C:\WINDOWS\stsystra.exe


========== Modules (SafeList) ==========

MOD - [2010/03/28 21:24:18 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\OTL.exe
MOD - [2008/02/05 18:20:30 | 000,109,080 | —- | M] (Logitech Inc.) – C:\WINDOWS\Temp\logishrd\LVPrcInj01.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/03/24 12:58:05 | 002,325,816 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgfws9.exe – (avgfws9)
SRV - [2010/03/24 12:57:39 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/03/24 12:57:25 | 005,888,008 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe – (AVGIDSAgent)
SRV - [2009/09/09 12:37:11 | 000,655,624 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2009/05/27 04:27:04 | 029,262,680 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe – (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS)
SRV - [2008/11/24 23:31:12 | 000,087,904 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe – (SQLWriter)
SRV - [2008/11/24 23:31:08 | 000,239,968 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe – (SQLBrowser)
SRV - [2008/11/24 23:31:08 | 000,045,408 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe – (MSSQLServerADHelper)
SRV - [2008/02/05 18:22:36 | 000,141,848 | —- | M] (Logitech Inc.) [Auto | Stopped] – C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe – (LVSrvLauncher)
SRV - [2008/02/05 18:20:42 | 000,150,040 | —- | M] (Logitech Inc.) [Auto | Running] – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcSrv)
SRV - [2008/02/05 18:18:48 | 000,186,904 | —- | M] (Logitech Inc.) [Auto | Running] – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe – (LVCOMSer)
SRV - [2007/01/04 17:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [Disabled | Stopped] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2005/09/23 07:01:16 | 002,799,808 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – c:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe – (msvsmon80)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/03/24 12:56:51 | 000,000,000 | —D | M]

[2010/03/26 13:55:17 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/03/26 13:52:14 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2010/02/23 22:54:14 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2007/09/05 11:11:14 | 000,081,920 | —- | M] (MeadCo Corp.) – C:\Program Files\Mozilla Firefox\plugins\npmeadax.dll
[2007/04/16 13:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll

O1 HOSTS File: ([2010/01/27 17:42:17 | 000,378,506 | R— | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 13048 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Save YouTube Video as MP3 - C:\Program Files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll (DVSTeam)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed] [removed] [removed]
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\WinCtrl32: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\Mozilla\Firefox\Desktop Background.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\ssqpq) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{b8cec85b-d3c9-11dd-ae2c-001372325061}\Shell - "" = AutoRun
O33 - MountPoints2\{b8cec85b-d3c9-11dd-ae2c-001372325061}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{b8cec85b-d3c9-11dd-ae2c-001372325061}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\AutoRunMorrowind.exe – File not found
O33 - MountPoints2\D\Shell\install\command - "" = D:\Setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: Ias - C:\WINDOWS\system32\ias [2010/01/28 17:48:54 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: LanmanServer - File not found
NetSvcs: LanmanWorkstation - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (32935965299310592)

========== Files/Folders - Created Within 14 Days ==========

File not found – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\[Torrentsworld.net] - Iria Zeiram - The Animation (Complete+ENG).torrent
[2010/03/28 21:24:17 | 000,555,520 | —- | C] (OldTimer Tools) – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\OTL.exe
[2010/03/28 13:29:34 | 000,000,000 | —D | C] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\AVG9
[2010/03/26 13:52:53 | 000,000,000 | —D | C] – C:\Documents and Settings\GUgenH3iMer schmidt\Local Settings\Application Data\Temp
[2010/03/26 13:52:46 | 000,000,000 | —D | C] – C:\Documents and Settings\GUgenH3iMer schmidt\Local Settings\Application Data\Google
[2010/03/25 10:59:39 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/03/24 12:59:03 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/03/24 12:59:00 | 000,029,512 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/03/24 12:58:52 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2010/03/24 12:57:49 | 000,025,096 | —- | C] (AVG Technologies CZ, s.r.o. ) – C:\WINDOWS\System32\drivers\AVGIDSxx.sys
[2010/03/24 12:57:47 | 000,052,872 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgrkx86.sys
[2010/03/24 12:57:44 | 000,242,696 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/03/24 12:57:42 | 000,216,200 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/03/24 12:53:44 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2010/03/23 16:43:24 | 000,094,208 | —- | C] (Blizzard Entertainment) – C:\WINDOWS\DIIUnin.exe
[2010/03/23 16:36:41 | 000,000,000 | —D | C] – C:\Diablo II
[2010/03/21 23:48:06 | 000,000,000 | —D | C] – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\Storage
[2010/03/21 22:54:22 | 000,000,000 | —D | C] – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\Camera Logs
[2010/03/20 23:16:07 | 000,524,288 | —- | C] (SerComm Corporation) – C:\WINDOWS\System32\Mpeg4Receiver.ax
[2010/03/20 23:15:53 | 000,000,000 | —D | C] – C:\Program Files\Cisco
[2010/03/17 23:21:29 | 000,118,784 | —- | C] (Blizzard Entertainment) – C:\WINDOWS\DiabUnin.exe
[2010/03/17 23:21:26 | 000,000,000 | —D | C] – C:\Program Files\Diablo
[2010/03/17 23:16:01 | 000,000,000 | —D | C] – C:\Program Files\Sierra
[2010/03/15 20:18:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Linksys
[2010/03/15 16:38:33 | 000,709,248 | R— | C] (Ralink Technology, Corp.) – C:\WINDOWS\System32\drivers\rt2870.sys
[2010/03/15 16:38:33 | 000,221,184 | R— | C] (Ralink Technology, Inc.) – C:\WINDOWS\System32\RaCoInst.dll
[2010/03/15 16:31:15 | 000,000,000 | —D | C] – C:\Program Files\WebEx
[2010/03/15 16:26:55 | 000,939,368 | R— | C] (Macromedia, Inc.) – C:\WINDOWS\System32\myflash.ocx
[2010/03/15 16:18:31 | 000,000,000 | —D | C] – C:\Program Files\Linksys
[2007/10/28 11:10:36 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/09/21 19:12:36 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2007/09/21 19:12:36 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Google
[2007/09/21 19:12:30 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Viewpoint
[2007/08/21 20:32:21 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2007/07/10 19:02:57 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2004/08/10 14:08:14 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

File not found – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\[Torrentsworld.net] - Iria Zeiram - The Animation (Complete+ENG).torrent
[2010/03/28 21:24:18 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\OTL.exe
[2010/03/28 20:57:00 | 000,001,034 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-688789844-839522115-1003UA.job
[2010/03/28 17:33:08 | 058,189,431 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/28 13:57:00 | 000,000,982 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-688789844-839522115-1003Core.job
[2010/03/26 13:53:30 | 000,002,386 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\Google Chrome.lnk
[2010/03/26 01:52:39 | 000,031,232 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/26 01:25:52 | 002,287,616 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\Planescape- Torment - Ravel Theme (music).mp3
[2010/03/26 01:25:18 | 002,273,280 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\Planescape- Torment - Ignus Theme (music).mp3
[2010/03/26 01:24:47 | 004,247,552 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\Planescape- Torment - Smoldering Corpse Bar (music).mp3
[2010/03/26 00:45:11 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/03/26 00:44:08 | 000,000,104 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2010/03/26 00:43:44 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/26 00:43:42 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/03/26 00:42:07 | 018,350,080 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\ntuser.dat
[2010/03/26 00:42:07 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\ntuser.ini
[2010/03/26 00:41:56 | 000,549,496 | -H– | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\Local Settings\Application Data\IconCache.db
[2010/03/26 00:34:57 | 000,026,794 | —- | M] () – C:\WINDOWS\DIIUnin.dat
[2010/03/26 00:34:02 | 000,021,840 | —- | M] () – C:\WINDOWS\System32\SIntfNT.dll
[2010/03/26 00:34:02 | 000,017,212 | —- | M] () – C:\WINDOWS\System32\SIntf32.dll
[2010/03/26 00:34:02 | 000,012,067 | —- | M] () – C:\WINDOWS\System32\SIntf16.dll
[2010/03/25 22:58:15 | 000,011,093 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\SkinnerArticle.docx
[2010/03/24 23:47:29 | 000,055,960 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\SNC00147.jpg
[2010/03/24 12:59:04 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/03/24 12:59:01 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/03/24 12:59:00 | 000,572,937 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavifw.avm
[2010/03/24 12:59:00 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/03/24 12:57:49 | 000,025,096 | —- | M] (AVG Technologies CZ, s.r.o. ) – C:\WINDOWS\System32\drivers\AVGIDSxx.sys
[2010/03/24 12:57:47 | 000,052,872 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgrkx86.sys
[2010/03/24 12:57:46 | 000,242,696 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/03/24 12:57:42 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/03/24 12:56:52 | 000,030,104 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgfwdx.sys
[2010/03/23 16:43:24 | 000,094,208 | —- | M] (Blizzard Entertainment) – C:\WINDOWS\DIIUnin.exe
[2010/03/23 16:43:24 | 000,002,829 | —- | M] () – C:\WINDOWS\DIIUnin.pif
[2010/03/22 13:32:00 | 005,245,209 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\befvp41_v2-ug-Rev_NC.pdf
[2010/03/18 15:59:35 | 004,495,360 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\The Peanuts Theme.mp3
[2010/03/17 23:32:17 | 000,000,008 | —- | M] () – C:\WINDOWS\System32\nvModes.dat
[2010/03/17 23:27:31 | 000,006,135 | —- | M] () – C:\WINDOWS\DiabUnin.dat
[2010/03/17 23:21:29 | 000,118,784 | —- | M] (Blizzard Entertainment) – C:\WINDOWS\DiabUnin.exe
[2010/03/17 23:21:29 | 000,002,829 | —- | M] () – C:\WINDOWS\DiabUnin.pif
[2010/03/15 16:39:49 | 000,579,754 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/15 16:39:49 | 000,482,936 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/03/15 16:39:49 | 000,086,322 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/03/15 14:55:06 | 000,065,517 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\img031.jpg
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/03/28 15:34:12 | 667,541,504 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\The Wire - 212 - Port in a Storm [FuckGov].avi
[2010/03/26 13:53:30 | 000,002,386 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\Google Chrome.lnk
[2010/03/26 13:52:52 | 000,001,034 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-688789844-839522115-1003UA.job
[2010/03/26 13:52:51 | 000,000,982 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-688789844-839522115-1003Core.job
[2010/03/26 01:25:48 | 002,287,616 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\Planescape- Torment - Ravel Theme (music).mp3
[2010/03/26 01:25:14 | 002,273,280 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\Planescape- Torment - Ignus Theme (music).mp3
[2010/03/26 01:24:40 | 004,247,552 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\Planescape- Torment - Smoldering Corpse Bar (music).mp3
[2010/03/25 21:48:21 | 000,011,093 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\SkinnerArticle.docx
[2010/03/24 23:46:44 | 000,055,960 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\SNC00147.jpg
[2010/03/24 12:59:00 | 000,572,937 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavifw.avm
[2010/03/24 12:59:00 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/03/24 12:58:52 | 058,189,431 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/23 16:43:27 | 000,026,794 | —- | C] () – C:\WINDOWS\DIIUnin.dat
[2010/03/23 16:43:24 | 000,002,829 | —- | C] () – C:\WINDOWS\DIIUnin.pif
[2010/03/22 13:31:55 | 005,245,209 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\befvp41_v2-ug-Rev_NC.pdf
[2010/03/20 23:16:07 | 000,221,184 | —- | C] () – C:\WINDOWS\System32\CiscoPlayer.ocx
[2010/03/20 23:16:04 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\DSKernel.dll
[2010/03/20 23:15:53 | 000,794,624 | R— | C] () – C:\WINDOWS\System32\ffdshowX.ax
[2010/03/20 23:15:53 | 000,557,056 | R— | C] () – C:\WINDOWS\System32\libavcodecX.dll
[2010/03/20 23:15:53 | 000,099,328 | R— | C] () – C:\WINDOWS\System32\realaacX.dll
[2010/03/18 15:59:29 | 004,495,360 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\The Peanuts Theme.mp3
[2010/03/17 23:21:29 | 000,002,829 | —- | C] () – C:\WINDOWS\DiabUnin.pif
[2010/03/17 23:21:25 | 000,006,135 | —- | C] () – C:\WINDOWS\DiabUnin.dat
[2010/03/15 16:38:33 | 000,013,931 | R— | C] () – C:\WINDOWS\System32\RaCoInst.dat
[2010/03/15 16:26:52 | 000,000,005 | —- | C] () – C:\Program Files\eula.txt
[2010/03/15 16:26:25 | 000,000,014 | —- | C] () – C:\Program Files\version.txt
[2010/03/15 14:55:14 | 000,065,517 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\img031.jpg
[2010/03/11 13:45:49 | 000,000,632 | —- | C] () – C:\WINDOWS\CoD.INI
[2009/11/07 14:27:16 | 000,000,760 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\setup_ldm.iss
[2009/09/11 17:26:50 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/09/09 16:33:53 | 000,066,482 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2009/09/03 05:12:54 | 000,000,882 | —- | C] () – C:\WINDOWS\DC.ini
[2009/08/28 15:12:09 | 000,000,306 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/10 01:02:49 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2009/05/31 01:41:07 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2009/05/28 04:39:16 | 000,815,104 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/05/28 04:39:12 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/05/01 00:31:06 | 001,724,416 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2009/05/01 00:31:06 | 001,507,328 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2009/05/01 00:31:06 | 001,101,824 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2009/05/01 00:31:06 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2009/01/06 10:02:31 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\Hook.dll
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/09/28 14:22:39 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/07/28 10:56:35 | 000,000,206 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/07/28 09:51:34 | 000,028,307 | —- | C] () – C:\WINDOWS\System32\kcopt.dll
[2008/07/28 09:51:34 | 000,004,546 | —- | C] () – C:\WINDOWS\System32\ksvcl.dll
[2008/06/24 11:26:51 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/06/24 11:26:51 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/06/24 11:26:51 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/04/22 16:34:08 | 000,000,260 | —- | C] () – C:\WINDOWS\cookies.ini
[2008/04/16 10:13:49 | 000,768,035 | -HS- | C] () – C:\WINDOWS\System32\xgcgqubr.ini
[2008/04/14 18:16:03 | 000,000,147 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/04/14 10:13:02 | 000,709,083 | -HS- | C] () – C:\WINDOWS\System32\chfgcovb.ini
[2008/04/13 10:05:44 | 000,708,447 | -HS- | C] () – C:\WINDOWS\System32\xtxkrrlt.ini
[2008/04/12 10:11:35 | 001,072,575 | -HS- | C] () – C:\WINDOWS\System32\gvsxbpcj.ini
[2008/04/11 10:14:35 | 001,095,585 | -HS- | C] () – C:\WINDOWS\System32\cccmcjdk.ini
[2008/04/10 10:08:35 | 001,256,745 | -HS- | C] () – C:\WINDOWS\System32\nuaknhvh.ini
[2008/04/08 10:06:45 | 001,270,011 | -HS- | C] () – C:\WINDOWS\System32\bfeefvtb.ini
[2008/03/17 11:01:20 | 001,027,160 | -HS- | C] () – C:\WINDOWS\System32\ukmtunwb.ini
[2008/03/17 09:58:20 | 001,017,318 | -HS- | C] () – C:\WINDOWS\System32\qckdiema.ini
[2008/03/17 08:58:20 | 001,017,258 | -HS- | C] () – C:\WINDOWS\System32\pwjkbpns.ini
[2008/03/17 07:55:21 | 001,017,198 | -HS- | C] () – C:\WINDOWS\System32\eroydpse.ini
[2008/03/17 06:55:20 | 001,017,255 | -HS- | C] () – C:\WINDOWS\System32\dyyeawtb.ini
[2008/03/17 05:55:20 | 001,017,195 | -HS- | C] () – C:\WINDOWS\System32\pqbsstqa.ini
[2008/03/17 04:55:20 | 001,013,778 | -HS- | C] () – C:\WINDOWS\System32\kwaiheye.ini
[2008/03/17 03:58:20 | 001,013,718 | -HS- | C] () – C:\WINDOWS\System32\hiuvgska.ini
[2008/03/17 02:55:20 | 001,005,222 | -HS- | C] () – C:\WINDOWS\System32\wwtoxnsp.ini
[2008/03/17 01:55:20 | 001,005,159 | -HS- | C] () – C:\WINDOWS\System32\smuiiwvw.ini
[2008/03/17 00:55:20 | 001,040,873 | -HS- | C] () – C:\WINDOWS\System32\xksybfem.ini
[2008/03/16 23:55:20 | 001,038,380 | -HS- | C] () – C:\WINDOWS\System32\qawpinfl.ini
[2008/03/16 22:55:20 | 001,038,320 | -HS- | C] () – C:\WINDOWS\System32\eivstxip.ini
[2008/03/16 21:52:20 | 001,038,260 | -HS- | C] () – C:\WINDOWS\System32\pjkxhjag.ini
[2008/03/16 20:52:20 | 001,038,200 | -HS- | C] () – C:\WINDOWS\System32\cgfiawdk.ini
[2008/03/16 19:52:21 | 001,038,140 | -HS- | C] () – C:\WINDOWS\System32\letqglbt.ini
[2008/03/16 18:49:20 | 001,038,080 | -HS- | C] () – C:\WINDOWS\System32\snabrpwq.ini
[2008/03/16 17:49:20 | 001,038,020 | -HS- | C] () – C:\WINDOWS\System32\adxhuevj.ini
[2008/03/16 16:49:20 | 001,037,960 | -HS- | C] () – C:\WINDOWS\System32\pewvvmev.ini
[2008/03/16 15:49:20 | 001,037,900 | -HS- | C] () – C:\WINDOWS\System32\qqaaoeog.ini
[2008/03/16 14:49:20 | 001,037,840 | -HS- | C] () – C:\WINDOWS\System32\yxsnkney.ini
[2008/03/16 13:46:20 | 001,037,780 | -HS- | C] () – C:\WINDOWS\System32\qoemgsit.ini
[2008/03/16 12:49:20 | 001,037,720 | -HS- | C] () – C:\WINDOWS\System32\iudrmnmo.ini
[2008/03/16 11:49:20 | 001,037,660 | -HS- | C] () – C:\WINDOWS\System32\gtjdlxlj.ini
[2008/03/16 10:49:21 | 001,037,600 | -HS- | C] () – C:\WINDOWS\System32\rwdeddfb.ini
[2008/03/16 09:46:20 | 001,037,540 | -HS- | C] () – C:\WINDOWS\System32\hragwxgi.ini
[2008/03/16 08:46:20 | 001,037,480 | -HS- | C] () – C:\WINDOWS\System32\sovoboov.ini
[2008/03/16 07:43:20 | 001,037,420 | -HS- | C] () – C:\WINDOWS\System32\xutgmrct.ini
[2008/03/16 06:43:20 | 001,037,360 | -HS- | C] () – C:\WINDOWS\System32\urgqomgy.ini
[2008/03/16 05:43:19 | 001,037,300 | -HS- | C] () – C:\WINDOWS\System32\ddkabamu.ini
[2008/03/16 04:43:20 | 001,037,240 | -HS- | C] () – C:\WINDOWS\System32\lthiwovj.ini
[2008/03/16 03:40:20 | 001,037,180 | -HS- | C] () – C:\WINDOWS\System32\maaoimmn.ini
[2008/03/16 02:40:19 | 001,037,120 | -HS- | C] () – C:\WINDOWS\System32\belmigbk.ini
[2008/03/16 01:40:20 | 001,037,060 | -HS- | C] () – C:\WINDOWS\System32\pxvxolrp.ini
[2008/03/16 00:40:20 | 001,037,000 | -HS- | C] () – C:\WINDOWS\System32\ocydaenk.ini
[2008/03/15 23:43:20 | 001,036,940 | -HS- | C] () – C:\WINDOWS\System32\lwyaydtn.ini
[2008/03/15 22:40:20 | 001,036,880 | -HS- | C] () – C:\WINDOWS\System32\eotyxsts.ini
[2008/03/15 21:37:20 | 001,036,820 | -HS- | C] () – C:\WINDOWS\System32\xcllcrdd.ini
[2008/03/15 20:40:20 | 001,036,760 | -HS- | C] () – C:\WINDOWS\System32\xobyxvpe.ini
[2008/03/15 19:37:20 | 001,036,700 | -HS- | C] () – C:\WINDOWS\System32\qluiwtuo.ini
[2008/03/15 18:40:19 | 001,036,640 | -HS- | C] () – C:\WINDOWS\System32\lrvnanwe.ini
[2008/03/15 17:37:19 | 001,036,580 | -HS- | C] () – C:\WINDOWS\System32\sschmtgw.ini
[2008/03/15 16:37:37 | 001,036,520 | -HS- | C] () – C:\WINDOWS\System32\chmrpvrv.ini
[2008/03/15 15:34:38 | 001,036,460 | -HS- | C] () – C:\WINDOWS\System32\tljrpfyl.ini
[2008/03/15 14:34:38 | 001,036,400 | -HS- | C] () – C:\WINDOWS\System32\kemibabe.ini
[2008/03/15 13:34:38 | 001,036,340 | -HS- | C] () – C:\WINDOWS\System32\vxpslccr.ini
[2008/03/15 12:37:38 | 001,036,280 | -HS- | C] () – C:\WINDOWS\System32\chrwhnsx.ini
[2008/03/15 11:34:39 | 001,036,220 | -HS- | C] () – C:\WINDOWS\System32\edbnjlso.ini
[2008/03/15 10:34:38 | 001,036,160 | -HS- | C] () – C:\WINDOWS\System32\qalmtnie.ini
[2008/03/15 09:34:37 | 001,036,100 | -HS- | C] () – C:\WINDOWS\System32\avakbaoa.ini
[2008/03/15 08:31:37 | 001,036,040 | -HS- | C] () – C:\WINDOWS\System32\oushunec.ini
[2008/03/15 07:31:38 | 001,035,980 | -HS- | C] () – C:\WINDOWS\System32\fnfxkqgc.ini
[2008/03/15 06:31:37 | 001,035,920 | -HS- | C] () – C:\WINDOWS\System32\tnwdroco.ini
[2008/03/15 05:31:37 | 001,035,860 | -HS- | C] () – C:\WINDOWS\System32\elnnggxi.ini
[2008/03/15 04:28:37 | 001,035,800 | -HS- | C] () – C:\WINDOWS\System32\islpartr.ini
[2008/03/15 03:28:37 | 001,035,740 | -HS- | C] () – C:\WINDOWS\System32\oyiltrjk.ini
[2008/03/15 02:31:37 | 001,035,680 | -HS- | C] () – C:\WINDOWS\System32\ikoaclmg.ini
[2008/03/15 01:31:38 | 001,035,620 | -HS- | C] () – C:\WINDOWS\System32\jhosptag.ini
[2008/03/15 00:28:38 | 001,035,560 | -HS- | C] () – C:\WINDOWS\System32\dtkjpgpt.ini
[2008/03/14 23:25:37 | 001,035,500 | -HS- | C] () – C:\WINDOWS\System32\xixnshlc.ini
[2008/03/14 22:25:37 | 001,035,440 | -HS- | C] () – C:\WINDOWS\System32\mbbiilrs.ini
[2008/03/14 21:25:37 | 001,035,380 | -HS- | C] () – C:\WINDOWS\System32\nogagtgk.ini
[2008/03/14 20:28:37 | 001,089,944 | -HS- | C] () – C:\WINDOWS\System32\pgsvbqoi.ini
[2008/03/14 19:25:38 | 001,197,835 | -HS- | C] () – C:\WINDOWS\System32\wrmxucau.ini
[2008/03/14 14:54:01 | 000,001,639 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2008/03/13 20:41:32 | 001,119,020 | -HS- | C] () – C:\WINDOWS\System32\sqdofbwf.ini
[2008/03/12 20:46:45 | 001,082,155 | -HS- | C] () – C:\WINDOWS\System32\nysmfdqm.ini
[2008/03/11 20:43:45 | 001,084,170 | -HS- | C] () – C:\WINDOWS\System32\cjfoghkm.ini
[2008/03/10 20:46:52 | 001,129,962 | -HS- | C] () – C:\WINDOWS\System32\batyjgtl.ini
[2008/03/09 20:46:44 | 001,111,061 | -HS- | C] () – C:\WINDOWS\System32\nlfkpqvi.ini
[2008/03/08 20:43:44 | 001,111,001 | -HS- | C] () – C:\WINDOWS\System32\jpdhscpk.ini
[2008/02/13 18:33:58 | 001,239,857 | -HS- | C] () – C:\WINDOWS\System32\bghtmhsp.ini
[2008/02/12 18:39:56 | 001,235,101 | -HS- | C] () – C:\WINDOWS\System32\jejqmmxw.ini
[2008/02/12 18:36:38 | 001,203,415 | -HS- | C] () – C:\WINDOWS\System32\qcvmedvh.ini
[2008/02/11 18:39:27 | 001,214,606 | -HS- | C] () – C:\WINDOWS\System32\aueqhqde.ini
[2008/02/11 18:36:26 | 001,210,435 | -HS- | C] () – C:\WINDOWS\System32\hesebuij.ini
[2008/02/10 18:39:14 | 001,203,294 | -HS- | C] () – C:\WINDOWS\System32\oebljdft.ini
[2008/02/10 18:33:14 | 001,203,114 | -HS- | C] () – C:\WINDOWS\System32\ixeosydx.ini
[2008/02/10 16:35:15 | 001,203,054 | -HS- | C] () – C:\WINDOWS\System32\tnawmxao.ini
[2008/02/10 16:32:16 | 001,202,934 | -HS- | C] () – C:\WINDOWS\System32\hnfwllhh.ini
[2008/02/09 16:32:23 | 001,202,874 | -HS- | C] () – C:\WINDOWS\System32\ffbtxhfh.ini
[2008/02/09 16:29:23 | 001,202,814 | -HS- | C] () – C:\WINDOWS\System32\hmsrmdwk.ini
[2008/02/08 16:29:21 | 001,202,754 | -HS- | C] () – C:\WINDOWS\System32\acniniav.ini
[2008/02/08 16:26:20 | 001,202,574 | -HS- | C] () – C:\WINDOWS\System32\pasftbut.ini
[2008/02/07 16:30:46 | 001,204,645 | -HS- | C] () – C:\WINDOWS\System32\ixjvlgft.ini
[2008/02/07 16:27:46 | 001,204,058 | -HS- | C] () – C:\WINDOWS\System32\hrmhuojc.ini
[2008/02/06 16:24:47 | 001,207,461 | -HS- | C] () – C:\WINDOWS\System32\vcwvvfjp.ini
[2008/02/06 16:21:47 | 001,201,793 | -HS- | C] () – C:\WINDOWS\System32\uvipipfr.ini
[2008/02/05 18:20:08 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008/02/05 16:29:31 | 001,194,375 | -HS- | C] () – C:\WINDOWS\System32\likijins.ini
[2008/02/05 16:26:32 | 001,194,255 | -HS- | C] () – C:\WINDOWS\System32\fouhugyl.ini
[2008/02/04 12:17:51 | 001,194,315 | -HS- | C] () – C:\WINDOWS\System32\xlwsmqtw.ini
[2008/02/04 12:12:06 | 001,192,538 | -HS- | C] () – C:\WINDOWS\System32\iepndqnr.ini
[2008/02/03 10:54:46 | 000,031,232 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/03 04:14:01 | 000,532,796 | -HS- | C] () – C:\WINDOWS\System32\qpqss.ini
[2008/02/03 01:59:06 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2008/02/03 01:59:06 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2002/03/21 15:39:02 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\UNACEV2.DLL

========== LOP Check ==========

[2008/12/19 18:46:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\acccore
[2009/05/28 00:33:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\ACD Systems
[2009/12/01 18:35:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AIM
[2008/12/07 18:16:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AIM Toolbar
[2010/02/24 03:39:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Alwil Software
[2010/03/24 12:55:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\avg9
[2008/04/04 15:04:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Azureus
[2010/03/15 20:18:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Linksys
[2009/09/11 16:31:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\PreEmptive Solutions
[2009/12/21 19:06:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Screaming Bee
[2008/08/07 07:05:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2009/06/10 17:35:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint
[2008/02/03 10:48:52 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\acccore
[2009/05/28 00:39:06 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\ACD Systems
[2010/03/28 13:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\AVG9
[2009/12/21 19:02:08 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\Avnex
[2010/03/22 12:07:00 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\Azureus
[2009/09/03 11:51:32 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\Electronic Arts
[2009/08/28 15:11:24 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\GetRightToGo
[2009/09/09 16:33:35 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\Leadertech
[2009/12/21 19:06:19 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\Screaming Bee
[2008/07/28 09:50:23 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\TmpRecentIcons
[2008/02/20 21:53:34 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\Viewpoint
[2009/05/22 14:55:24 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\WinPatrol

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 06:00:00 | 018,738,937 | —- | M] () .cab file – C:\i386\sp2.cab:AGP440.sys
[2004/08/04 08:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/08/03 16:46:14 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/08/03 16:46:14 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 00:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\i386\AGP440.SYS

< MD5 for: ATAPI.SYS >
[2004/08/04 06:00:00 | 018,738,937 | —- | M] () .cab file – C:\i386\sp2.cab:atapi.sys
[2004/08/04 08:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/08/03 16:46:14 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/08/03 16:46:14 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\i386\atapi.sys
[2004/08/04 08:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 06:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\i386\eventlog.dll
[2004/08/04 08:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 06:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\i386\netlogon.dll
[2004/08/04 08:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: NVATABUS.SYS >
[2006/08/05 10:00:40 | 000,105,344 | —- | M] (NVIDIA Corporation) MD5=75562456AA672BB5FE56D3C64C6D1C7D – C:\dell\drivers\R133282\nvatabus.sys
[2006/08/05 08:00:40 | 000,105,344 | —- | M] (NVIDIA Corporation) MD5=75562456AA672BB5FE56D3C64C6D1C7D – C:\drivers\storage\r133282\nvatabus.sys
[2006/08/05 08:00:40 | 000,105,344 | —- | M] (NVIDIA Corporation) MD5=75562456AA672BB5FE56D3C64C6D1C7D – C:\i386\nvatabus.sys

< MD5 for: SCECLI.DLL >
[2004/08/04 06:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\i386\scecli.dll
[2004/08/04 08:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:DFC5A2B2
< End of report >














And here is the Extras log






OTL Extras logfile created on: 3/28/2010 9:45:58 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\GUgenH3iMer schmidt\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 76.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 4989 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.46 Gb Total Space | 1.40 Gb Free Space | 1.96% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: USERCHRIS
Current User Name: GUgenH3iMer schmidt
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = Reg Error: Value error.] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" File not found
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" File not found
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDSee 9.0.Browse] – "C:\Program Files\ACD Systems\ACDSee\9.0\ACDSeeQV.exe" "%1" (ACD Systems Ltd.)
Directory [AddToPlaylistVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MI1933~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4
"3389:TCP" = 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"6114:UDP" = 6114:UDP:*:Enabled:Chris' Laptop
"49901:TCP" = 49901:TCP:*:Enabled:Vuze
"49901:UDP" = 49901:UDP:*:Enabled:Vuze

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\Program Files\EA Games\Ultima Online Mondain's Legacy\client.exe" = C:\Program Files\EA Games\Ultima Online Mondain's Legacy\client.exe:*:Enabled:Ultima Online Client – (Electronic Arts)
"C:\Program Files\AIM6\aim6 .exe" = C:\Program Files\AIM6\aim6 .exe:*:Enabled:AIM – File not found
"C:\Program Files\LucasArts\Star Wars JK II Jedi Outcast\GameData\jk2mp.exe" = C:\Program Files\LucasArts\Star Wars JK II Jedi Outcast\GameData\jk2mp.exe:*:Enabled:jk2mp – File not found
"C:\Program Files\Steam\steamapps\zankuro\counter-strike\hl.exe" = C:\Program Files\Steam\steamapps\zankuro\counter-strike\hl.exe:*:Enabled:Half-Life Launcher – (Valve)
"C:\Program Files\Vuze\Azureus.exe" = C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus – (Vuze Inc.)
"C:\Program Files\Steam\steamapps\zankuro\half-life\hl.exe" = C:\Program Files\Steam\steamapps\zankuro\half-life\hl.exe:*:Enabled:Half-Life Launcher – (Valve)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – File not found
"C:\Program Files\Call of Duty\CoDMP.exe" = C:\Program Files\Call of Duty\CoDMP.exe:*:Enabled:CoDMP – File not found
"C:\Program Files\Warcraft III\Warcraft III.exe" = C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III – File not found
"C:\Warcraft III\Warcraft III.exe" = C:\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III – File not found
"C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\uo hacks\SphereAgent\SphereAgent.exe" = C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\uo hacks\SphereAgent\SphereAgent.exe:*:Enabled:SphereAgent – File not found
"C:\Program Files\Diablo\Diablo.exe" = C:\Program Files\Diablo\Diablo.exe:*:Enabled:Diablo – (Blizzard Entertainment)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\AlephOne-20081226\M1A1\AlephOne.exe" = C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\AlephOne-20081226\M1A1\AlephOne.exe:*:Enabled:Aleph One/SDL for Win32 – File not found
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\Steam\steamapps\zankuro\counter-strike source\hl2.exe" = C:\Program Files\Steam\steamapps\zankuro\counter-strike source\hl2.exe:*:Enabled:hl2 – ()
"C:\Program Files\Steam\steamapps\zankuro\half-life 2 deathmatch\hl2.exe" = C:\Program Files\Steam\steamapps\zankuro\half-life 2 deathmatch\hl2.exe:*:Enabled:hl2 – ()
"C:\Program Files\PFPortChecker\PFPortChecker.exe" = C:\Program Files\PFPortChecker\PFPortChecker.exe:*:Enabled:PFPortchecker by portforward.com helps check if your ports are properly forwarded. – (portforward.com)
"C:\Program Files\Steam\steamapps\zankuro\day of defeat\hl.exe" = C:\Program Files\Steam\steamapps\zankuro\day of defeat\hl.exe:*:Enabled:Half-Life Launcher – (Valve)
"C:\Program Files\Steam\steamapps\zankuro\opposing force\hl.exe" = C:\Program Files\Steam\steamapps\zankuro\opposing force\hl.exe:*:Enabled:Half-Life Launcher – (Valve)
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 – (Adobe Systems Incorporated)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – File not found
"C:\Program Files\AIM6\aim6 .exe" = C:\Program Files\AIM6\aim6 .exe:*:Enabled:AIM – File not found
"C:\Program Files\Ventrilo\Ventrilo.exe" = C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe – (Flagship Industries, Inc.)
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AIM – (AOL LLC)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\WINDOWS\system32\a.exe" = C:\WINDOWS\system32\a.exe:*:Disabled:a – File not found
"C:\Doom 3\DOOM3DED.exe" = C:\Doom 3\DOOM3DED.exe:*:Enabled:DOOM 3 – File not found
"C:\Program Files\AVG\AVG9\avgam.exe" = C:\Program Files\AVG\AVG9\avgam.exe:*:Enabled:avgam.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgdiagex.exe" = C:\Program Files\AVG\AVG9\avgdiagex.exe:*:Enabled:avgdiagex.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{1389C6A4-4965-4AEC-9175-08B54A10FA48}" = Microsoft SQL Server 2005 Mobile [ENU] Developer Tools
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{14AFE241-FC6E-4FDB-BCA0-7AD6F4974171}" = Adobe Setup
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}" = QuickTime
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1BE321C4-6E17-4ECD-A6CB-3EF73791BE87}" = Decoder
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23210453-8608-4FF2-B84B-B90453618781}" = Police Quest Collection™
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 17
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{296B2D8E-CE82-92AF-B2E8-A646E7CB78A2}_is1" = RegAlyzer
"{29D3773E-54F4-23C2-D523-236A4453B844}_is1" = FileAlyzer
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{346D717A-A506-47FC-8AB0-FBB470B42266}" = Wireless-N Home Surveillance Camera
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35CB6715-41F8-4F99-8881-6FC75BF054B0}" = Oblivion
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{437AB8E0-FB69-4222-B280-A64F3DE22591}" = Microsoft Visual Studio 2005 Professional Edition - ENU
"{44D4AF75-6870-41F5-9181-662EA05507E1}" = Microsoft Document Explorer 2005
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{49FC50FC-F965-40D9-89B4-CBFF80941033}" = Windows Movie Maker 2.0
"{53735ECE-E461-4FD0-B742-23A352436D3A}" = Logitech Updater
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{625386A4-B6B6-4911-A6E8-23189C3F2D15}" = Microsoft .NET Compact Framework 2.0
"{6444D9D9-CD6C-4464-B970-55C606C944DC}" = Logitech QuickCam
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{6C531060-84FB-4F96-8F33-29DF020632EB}" = Microsoft .NET Compact Framework 1.0 SP3 Developer
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{78B75C6D-E53C-424C-BF83-4B63BD4A6682}" = Microsoft Device Emulator version 1.0 - ENU
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ULTIMATER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_VISSTDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ULTIMATER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_VISSTDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ULTIMATER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_VISSTDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2007
"{90120000-0054-0409-0000-0000000FF1CE}_VISSTDR_{519D9F45-CBF4-4E57-B419-11F196CCA8AE}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_VISSTDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_VISSTDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002E-0000-0000-0000000FF1CE}" = Microsoft Office Ultimate 2007
"{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91120000-0053-0000-0000-0000000FF1CE}" = Microsoft Office Visio Standard 2007
"{91120000-0053-0000-0000-0000000FF1CE}_VISSTDR_{0FD405D3-CAF8-4CA6-8BFD-911D2F8A6585}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{91120000-0053-0000-0000-0000000FF1CE}_VISSTDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92022F8E-2E55-4A16-88EB-B4778B35E942}" = ACDSee for PENTAX 3.0
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9C9D0F85-5658-4A5E-95A9-65F7DB2916EE}" = Broadcom 440x 10/100 Integrated Controller
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A5181519-9F3D-4372-ABC6-C333C2F3A816}_is1" = RunAlyzer
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.1
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = Athlon 64 Processor Driver
"{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{DF7B213D-2065-41ED-BB51-7A3EED31EA7B}" = Ultima Online: Mondain's Legacy
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F49FEF83-45CA-4CE8-8304-A7372BA07AA9}" = Motorola Phone Tools
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FCD9CD52-7222-4672-94A0-A722BA702FD0}" = Dell Resource CD
"AC3Filter_is1" = AC3Filter 1.60b
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_acce07fd2c8fe7f9e3f26243e626578" = Adobe Dreamweaver CS4
"AIM_7" = AIM 7
"AnalogX HyperTrace" = AnalogX HyperTrace
"AVG9Uninstall" = AVG 9.0
"BootLog XP_is1" = BootLog XP
"CamStudio" = CamStudio
"CodeStuff Starter" = CodeStuff Starter
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Diablo" = Diablo
"Diablo II" = Diablo II
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DOOM Collector's Edition" = DOOM Collector's Edition
"Fallout" = Fallout
"Fallout2" = Fallout2
"Free YouTube to Mp3 Converter_is1" = Free YouTube to Mp3 Converter version 3.2
"hp deskjet 940c series" = hp deskjet 940c series (Remove only)
"ie8" = Windows Internet Explorer 8
"lvdrivers_11.70" = Logitech QuickCam Driver Package
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Document Explorer 2005" = Microsoft Document Explorer 2005
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Microsoft Visual Studio 2005 Professional Edition - ENU" = Microsoft Visual Studio 2005 Professional Edition - ENU
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Natural Selection_is1" = Natural Selection 3.2
"NVIDIA Drivers" = NVIDIA Drivers
"PFPortChecker" = PFPortChecker 1.0.28
"PowerStrip 3 (remove only)" = PowerStrip 3 (remove only)
"RealPlayer 12.0" = RealPlayer
"Rise of The Triad_is1" = Rise of The Triad
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Steam App 10" = Counter-Strike
"Steam App 220" = Half-Life 2
"Steam App 240" = Counter-Strike: Source
"Steam App 320" = Half-Life 2: Deathmatch
"Steam App 70" = Half-Life
"ULTIMATER" = Microsoft Office Ultimate 2007
"Uninstall_is1" = Uninstall 1.0.0.1
"ViewpointMediaPlayer" = Viewpoint Media Player
"VISSTDR" = Microsoft Office Visio Standard 2007 Trial
"VLC media player" = VLC media player 0.9.6
"Vuze" = Vuze
"WAV to MP3 Encoder" = WAV to MP3 Encoder
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPatrol" = WinPatrol 2009
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xvid_is1" = Xvid 1.2.1 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Diablo" = Diablo
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/11/2010 2:03:28 PM | Computer Name = USERCHRIS | Source = Application Hang | ID = 1002
Description = Hanging application Morrowind.exe, version 1.3.0.1029, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/14/2010 1:31:42 AM | Computer Name = USERCHRIS | Source = Ci | ID = 4124
Description = Content index on c:\system volume information\catalog.wci is corrupt.
Please shutdown and restart the Indexing Service (cisvc).

Error - 3/14/2010 1:31:42 AM | Computer Name = USERCHRIS | Source = Ci | ID = 4126
Description = Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci.
Index will be automatically restored by refiltering all documents.

Error - 3/14/2010 3:13:10 AM | Computer Name = USERCHRIS | Source = Ci | ID = 4126
Description = Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci.
Index will be automatically restored by refiltering all documents.

Error - 3/14/2010 3:13:11 AM | Computer Name = USERCHRIS | Source = Ci | ID = 4127
Description = Content index on c:\documents and settings\all users.windows\application
data\microsoft\visio\catalog.wci could not be initialized. Error 3221225529.

Error - 3/17/2010 11:23:56 PM | Computer Name = USERCHRIS | Source = Application Hang | ID = 1002
Description = Hanging application Diablo.exe, version 2000.2.2.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 3/17/2010 11:40:52 PM | Computer Name = USERCHRIS | Source = Application Hang | ID = 1002
Description = Hanging application autorun.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 3/17/2010 11:40:52 PM | Computer Name = USERCHRIS | Source = Application Hang | ID = 1002
Description = Hanging application autorun.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 3/24/2010 1:01:21 AM | Computer Name = USERCHRIS | Source = Application Hang | ID = 1002
Description = Hanging application msiexec.exe, version 4.5.6001.22159, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/28/2010 9:45:35 PM | Computer Name = USERCHRIS | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.1.37.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 3/27/2010 5:44:50 AM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.

Error - 3/27/2010 8:50:10 AM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.

Error - 3/27/2010 6:00:20 PM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.

Error - 3/28/2010 12:09:46 AM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.

Error - 3/28/2010 3:12:24 AM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.

Error - 3/28/2010 6:17:39 AM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.

Error - 3/28/2010 9:25:41 AM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.

Error - 3/28/2010 12:29:28 PM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.

Error - 3/28/2010 3:32:02 PM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.

Error - 3/28/2010 6:37:30 PM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.


< End of report >
Hi there :)

Download GMER from Here. Note the file's name and save it to your root folder, such as C:\.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security program drivers will not conflict with this file.
  • Click on this link to see a list of programs that should be disabled.
  • Double-click on the downloaded file to start the program. (If running Vista, right click on it and select "Run as an Administrator")
  • Allow the driver to load if asked.
  • You may be prompted to scan immediately if it detects rootkit activity.
  • If you are prompted to scan your system click "No", save the log and post back the results.
  • If not prompted, click the "Rootkit/Malware" tab.
  • On the right-side, all items to be scanned should be checked by default except for "Show All". Leave that box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click the Scan button to begin. (Please be patient as it can take some time to complete)
  • When the scan is finished, click Save to save the scan results to your Desktop.
  • Save the file as Results.log and copy/paste the contents in your next reply.
  • Exit the program and re-enable all active protection when done.
Hello again!


Here is the GMERlog:







GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-31 16:25:59
Windows 5.1.2600 Service Pack 3
Running: gvufond9.exe; Driver: C:\DOCUME~1\GUGENH~1\LOCALS~1\Temp\pwriypog.sys


—- Kernel code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB6FF3360, 0x3CEED5, 0xE8000020]

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\WINDOWS\system32\cidaemon.exe[540] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00982F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\cidaemon.exe[540] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00982CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\cidaemon.exe[540] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00982D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\cidaemon.exe[540] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00982CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe[984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00A82F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe[984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00A82CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe[984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00A82D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe[984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00A82CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\ctfmon.exe[1184] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00522F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\ctfmon.exe[1184] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00522CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\ctfmon.exe[1184] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00522D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\ctfmon.exe[1184] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00522CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\cidaemon.exe[1516] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00982F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\cidaemon.exe[1516] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00982CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\cidaemon.exe[1516] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00982D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\cidaemon.exe[1516] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00982CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\stsystra.exe[2304] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003D2F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\stsystra.exe[2304] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003D2CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\stsystra.exe[2304] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [003D2D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\stsystra.exe[2304] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003D2CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\gvufond9.exe[2448] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00802F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\gvufond9.exe[2448] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00802CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\gvufond9.exe[2448] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00802D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\gvufond9.exe[2448] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00802CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\RUNDLL32.EXE[2512] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00AC2F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\RUNDLL32.EXE[2512] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00AC2CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\RUNDLL32.EXE[2512] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00AC2D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\RUNDLL32.EXE[2512] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00AC2CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2860] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003B2F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2860] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003B2CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2860] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [003B2D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2860] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003B2CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Java\Java Update\jusched.exe[2884] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00C22F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Java\Java Update\jusched.exe[2884] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00C22CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Java\Java Update\jusched.exe[2884] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00C22D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Java\Java Update\jusched.exe[2884] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00C22CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[2904] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [009F2F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[2904] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [009F2CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[2904] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [009F2D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[2904] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [009F2CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[2912] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00C72F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[2912] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00C72CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[2912] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00C72D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[2912] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00C72CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3132] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00DD2F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3132] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00DD2CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3132] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00DD2D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3132] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00DD2CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[3644] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00C62F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[3644] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00C62CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[3644] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00C62D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[3644] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00C62CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\GUgenH3iMer schmidt\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe[3872] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003B2F30] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\GUgenH3iMer schmidt\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe[3872] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003B2CA0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\GUgenH3iMer schmidt\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe[3872] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [003B2D00] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\GUgenH3iMer schmidt\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe[3872] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003B2CD0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device B1493D20

AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-






I had difficulty disabling certain parts of AVG's settings. I was at least able to stop the online shield, firewall, anti-spam, e-mail scanner, resident shield, identity protection, link scanner and anti-spyware. I could not locate a main disable option for the whole program. To my knowledge, Anti virus and anti-rootkit were still enabled during this process.
Looks not so bad :)


Please go here and have a look how you can disable your security software.

Download Combofix from any of the links below but rename it to before saving it to your desktop.

Link 1
Link 2



——————————————————————–

Double click on the renamed Combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
To Schrauber

Here is the Combofix.exe log, sorry I took sometime getting back to you, been very busy.



ComboFix 10-04-21.01 - GUgenH3iMer schmidt 04/24/2010 15:42:13.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2646 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\schrauber.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\GUgenH3iMer schmidt\Application Data\Microsoft\Internet Explorer\Quick Launch\AntiSpywareMaster.lnk
c:\documents and settings\GUgenH3iMer schmidt\Desktop\[Torrentsworld.net] - Iria Zeiram - The Animation (Complete+ENG).torrent
c:\documents and settings\GUgenH3iMer schmidt\Desktop\[Torrentsworld.net] - Iria Zeiram - The Animation (Complete+ENG).torrent
c:\documents and settings\GUgenH3iMer schmidt\Recent\Thumbs.db
c:\program files\version.txt
c:\recycler\S-1-5-21-3207471940-1968957563-28871492-1007
c:\windows\BMe7ab1d42.txt
c:\windows\BMe7ab1d42.xml
c:\windows\cookies.ini
c:\windows\system32\404Fix.exe
c:\windows\system32\acniniav.ini
c:\windows\system32\adxhuevj.ini
c:\windows\system32\aueqhqde.ini
c:\windows\system32\avakbaoa.ini
c:\windows\system32\batyjgtl.ini
c:\windows\system32\belmigbk.ini
c:\windows\system32\bfeefvtb.ini
c:\windows\system32\bghtmhsp.ini
c:\windows\system32\cccmcjdk.ini
c:\windows\system32\cgfiawdk.ini
c:\windows\system32\chfgcovb.ini
c:\windows\system32\chmrpvrv.ini
c:\windows\system32\chrwhnsx.ini
c:\windows\system32\cjfoghkm.ini
c:\windows\system32\ddkabamu.ini
c:\windows\system32\dtkjpgpt.ini
c:\windows\system32\dumphive.exe
c:\windows\system32\dyyeawtb.ini
c:\windows\system32\edbnjlso.ini
c:\windows\system32\eivstxip.ini
c:\windows\system32\elnnggxi.ini
c:\windows\system32\eotyxsts.ini
c:\windows\system32\eroydpse.ini
c:\windows\system32\ffbtxhfh.ini
c:\windows\system32\fnfxkqgc.ini
c:\windows\system32\fouhugyl.ini
c:\windows\system32\gtjdlxlj.ini
c:\windows\system32\gvsxbpcj.ini
c:\windows\system32\hesebuij.ini
c:\windows\system32\hiuvgska.ini
c:\windows\system32\hmsrmdwk.ini
c:\windows\system32\hnfwllhh.ini
c:\windows\system32\Hook.dll
c:\windows\system32\hragwxgi.ini
c:\windows\system32\hrmhuojc.ini
c:\windows\system32\IEDFix.exe
c:\windows\system32\iepndqnr.ini
c:\windows\system32\ikoaclmg.ini
c:\windows\system32\islpartr.ini
c:\windows\system32\iudrmnmo.ini
c:\windows\system32\ixeosydx.ini
c:\windows\system32\ixjvlgft.ini
c:\windows\system32\jejqmmxw.ini
c:\windows\system32\jhosptag.ini
c:\windows\system32\jpdhscpk.ini
c:\windows\system32\kemibabe.ini
c:\windows\system32\ksvcl.dll
c:\windows\system32\kwaiheye.ini
c:\windows\system32\letqglbt.ini
c:\windows\system32\likijins.ini
c:\windows\system32\lrvnanwe.ini
c:\windows\system32\lthiwovj.ini
c:\windows\system32\lwyaydtn.ini
c:\windows\system32\maaoimmn.ini
c:\windows\system32\mbbiilrs.ini
c:\windows\system32\mcrh.tmp
c:\windows\system32\nlfkpqvi.ini
c:\windows\system32\nogagtgk.ini
c:\windows\system32\nuaknhvh.ini
c:\windows\system32\nysmfdqm.ini
c:\windows\system32\ocydaenk.ini
c:\windows\system32\oebljdft.ini
c:\windows\system32\oushunec.ini
c:\windows\system32\oyiltrjk.ini
c:\windows\system32\pasftbut.ini
c:\windows\system32\pewvvmev.ini
c:\windows\system32\pgsvbqoi.ini
c:\windows\system32\pjkxhjag.ini
c:\windows\system32\pqbsstqa.ini
c:\windows\system32\pwjkbpns.ini
c:\windows\system32\pxvxolrp.ini
c:\windows\system32\qalmtnie.ini
c:\windows\system32\qawpinfl.ini
c:\windows\system32\qckdiema.ini
c:\windows\system32\qcvmedvh.ini
c:\windows\system32\qluiwtuo.ini
c:\windows\system32\qoemgsit.ini
c:\windows\system32\qpqss.ini
c:\windows\system32\qqaaoeog.ini
c:\windows\system32\rwdeddfb.ini
c:\windows\system32\smuiiwvw.ini
c:\windows\system32\snabrpwq.ini
c:\windows\system32\sovoboov.ini
c:\windows\system32\sqdofbwf.ini
c:\windows\system32\SrchSTS.exe
c:\windows\system32\sschmtgw.ini
c:\windows\system32\tljrpfyl.ini
c:\windows\system32\tmp.reg
c:\windows\system32\tnawmxao.ini
c:\windows\system32\tnwdroco.ini
c:\windows\system32\ukmtunwb.ini
c:\windows\system32\urgqomgy.ini
c:\windows\system32\uvipipfr.ini
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\vcwvvfjp.ini
c:\windows\system32\vxpslccr.ini
c:\windows\system32\wrmxucau.ini
c:\windows\system32\WS2Fix.exe
c:\windows\system32\wwtoxnsp.ini
c:\windows\system32\xcllcrdd.ini
c:\windows\system32\xgcgqubr.ini
c:\windows\system32\xixnshlc.ini
c:\windows\system32\xksybfem.ini
c:\windows\system32\xlwsmqtw.ini
c:\windows\system32\xobyxvpe.ini
c:\windows\system32\xtxkrrlt.ini
c:\windows\system32\xutgmrct.ini
c:\windows\system32\yxsnkney.ini
c:\windows\TEMP\logishrd\LVPrcInj01.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_TNIDRIVER


((((((((((((((((((((((((( Files Created from 2010-03-24 to 2010-04-24 )))))))))))))))))))))))))))))))
.

2010-04-23 22:45 . 2010-04-23 22:45 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-04-23 22:45 . 2010-04-23 22:45 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-23 22:45 . 2010-04-23 22:45 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-04-23 22:45 . 2010-04-23 22:45 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-04-23 22:44 . 2010-04-24 13:44 ——– d—–w- c:\windows\system32\drivers\Avg
2010-04-17 05:01 . 2008-07-11 16:25 1700352 —-a-w- c:\windows\system32\GdiPlus.dll
2010-04-17 05:01 . 2010-04-17 05:01 ——– d—–w- c:\program files\AVS4YOU
2010-04-07 01:55 . 2010-04-07 01:55 ——– d—–w- c:\program files\Common Files\Software Update Utility
2010-04-06 03:53 . 2010-04-06 03:57 ——– d—–w- c:\documents and settings\GUgenH3iMer schmidt\Application Data\Apple Computer
2010-04-06 03:53 . 2009-05-18 17:17 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-04-06 03:53 . 2008-04-17 16:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2010-04-06 03:52 . 2010-04-06 03:52 ——– d—–w- c:\program files\iPod
2010-04-06 03:51 . 2010-04-06 03:53 ——– d—–w- c:\program files\iTunes
2010-04-06 03:51 . 2010-04-06 03:53 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-06 03:50 . 2010-04-06 03:51 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer
2010-04-06 03:49 . 2010-04-06 03:49 ——– d—–w- c:\program files\Apple Software Update
2010-04-06 03:48 . 2010-04-06 03:48 ——– d—–w- c:\program files\Bonjour
2010-04-06 03:48 . 2010-04-06 03:52 ——– d—–w- c:\program files\Common Files\Apple
2010-04-06 03:48 . 2010-04-06 03:48 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple
2010-03-28 17:29 . 2010-03-28 17:29 ——– d—–w- c:\documents and settings\GUgenH3iMer schmidt\Application Data\AVG9
2010-03-26 17:52 . 2010-04-21 06:57 ——– d—–w- c:\documents and settings\GUgenH3iMer schmidt\Local Settings\Application Data\Temp
2010-03-26 17:52 . 2010-03-26 17:53 ——– d—–w- c:\documents and settings\GUgenH3iMer schmidt\Local Settings\Application Data\Google

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-23 22:43 . 2010-02-24 09:27 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\avg9
2010-04-23 02:39 . 2010-02-03 04:53 8 —-a-w- c:\windows\system32\nvModes.dat
2010-04-22 01:33 . 2010-03-18 03:16 ——– d—–w- c:\program files\Sierra
2010-04-22 01:33 . 2006-11-30 11:13 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-04-18 21:34 . 2006-12-01 13:58 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment
2010-04-18 14:22 . 2008-04-04 19:04 ——– d—–w- c:\documents and settings\GUgenH3iMer schmidt\Application Data\Azureus
2010-04-17 05:01 . 2009-05-19 22:16 ——– d—–w- c:\documents and settings\GUgenH3iMer schmidt\Application Data\AVS4YOU
2010-04-17 05:01 . 2009-05-19 22:16 ——– d—–w- c:\program files\Common Files\AVSMedia
2010-04-15 11:23 . 2006-11-21 07:12 ——– d—–w- c:\program files\Real
2010-04-15 11:22 . 2008-04-15 10:52 499712 —-a-w- c:\windows\system32\msvcp71.dll
2010-04-15 11:22 . 2008-04-15 10:52 348160 —-a-w- c:\windows\system32\msvcr71.dll
2010-04-15 07:09 . 2009-05-20 02:05 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2010-04-09 12:28 . 2008-08-12 01:56 ——– d—–w- c:\program files\Steam
2010-04-07 01:55 . 2009-12-01 22:35 ——– d—–w- c:\program files\AIM
2010-04-06 03:51 . 2006-12-01 11:21 ——– d—–w- c:\program files\QuickTime
2010-03-30 22:35 . 2006-11-21 07:05 ——– d—–w- c:\program files\Common Files\Java
2010-03-30 22:34 . 2006-11-21 07:05 ——– d—–w- c:\program files\Java
2010-03-26 04:34 . 2008-06-24 15:26 21840 —-atw- c:\windows\system32\SIntfNT.dll
2010-03-26 04:34 . 2008-06-24 15:26 17212 —-atw- c:\windows\system32\SIntf32.dll
2010-03-26 04:34 . 2008-06-24 15:26 12067 —-atw- c:\windows\system32\SIntf16.dll
2010-03-24 16:53 . 2010-03-24 16:53 ——– d—–w- c:\program files\AVG
2010-03-21 03:16 . 2010-03-21 03:15 ——– d—–w- c:\program files\Cisco
2010-03-21 01:19 . 2010-03-15 20:18 ——– d—–w- c:\program files\Linksys
2010-03-21 01:13 . 2010-02-24 09:32 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2010-03-18 03:30 . 2010-03-18 03:21 ——– d—–w- c:\program files\Diablo
2010-03-18 03:27 . 2010-03-18 03:21 6135 —-a-w- c:\windows\DiabUnin.dat
2010-03-18 03:21 . 2010-03-18 03:21 2829 —-a-w- c:\windows\DiabUnin.pif
2010-03-18 03:21 . 2010-03-18 03:21 118784 —-a-w- c:\windows\DiabUnin.exe
2010-03-16 00:18 . 2010-03-16 00:18 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Linksys
2010-03-15 20:31 . 2010-03-15 20:31 ——– d—–w- c:\program files\WebEx
2010-03-15 20:26 . 2010-03-15 20:26 5 —-a-w- c:\program files\eula.txt
2010-03-11 03:35 . 2008-07-20 22:35 ——– d—–w- c:\program files\DOSBox-0.72
2010-03-10 06:15 . 2004-08-04 12:00 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-03-09 08:28 . 2009-01-09 01:37 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-03-04 06:12 . 2010-03-03 18:24 ——– d—–w- c:\program files\Final Fantasy VII
2010-03-03 21:53 . 2006-11-30 02:41 ——– d—–w- c:\program files\Razor
2010-02-26 21:55 . 2010-02-03 04:44 ——– d—–w- c:\documents and settings\GUgenH3iMer schmidt\Application Data\vlc
2010-02-25 06:24 . 2004-08-04 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2004-08-04 12:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-24 07:39 . 2010-01-27 20:30 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Alwil Software
2010-02-16 14:08 . 2004-08-04 12:00 2146304 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2004-08-03 22:59 2024448 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 15:46 . 2010-02-12 15:46 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-02-12 15:46 . 2010-02-12 15:46 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-02-12 04:33 . 2004-08-04 12:00 100864 —-a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-04 12:00 226880 —-a-w- c:\windows\system32\drivers\tcpip6.sys
2010-01-27 15:39 . 2008-06-24 13:20 52224 —-a-w- c:\windows\ipuninst.exe
2009-01-03 22:47 . 2008-08-10 10:35 2 –shatr- c:\windows\winstart.bat
.
c:\program files\Common Files\InstallShield\UpdateService\issch .exe
c:\program files\Common Files\InstallShield\UpdateService\isuspm		   .exe
c:\program files\Common Files\Real\Update_OB\realsched .exe
c:\program files\Common Files\Symantec Shared\ccApp .exe
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe
c:\program files\Dell\Media Experience\DMXLauncher .exe
c:\program files\Dell Support\DSAgnt .exe
c:\program files\Google\Google Talk\googletalk .exe
c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
c:\program files\Messenger\msmsgs .exe
c:\program files\QuickTime\qttask			.exe
c:\program files\Spybot - Search & Destroy\TeaTimer .exe
c:\windows\ime\imjp8_1\IMJPMIG .EXE
c:\windows\system32\IME\TINTLGNT\TINTSETP .EXE

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Google Update"="c:\documents and settings\GUgenH3iMer schmidt\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-03-26 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-27 282624]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"nwiz"="nwiz.exe" [2009-05-01 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-05-01 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-05-01 13750272]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-15 202256]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-04-23 22:45 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wincm07.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winjt07.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winmw18.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winnw75.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winow75.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winoy20.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winuc86.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winvd64.sys]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\EA Games\\Ultima Online Mondain's Legacy\\client.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Steam\\steamapps\\zankuro\\counter-strike\\hl.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Steam\\steamapps\\zankuro\\half-life\\hl.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Diablo\\Diablo.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Steam\\steamapps\\zankuro\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\zankuro\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\PFPortChecker\\PFPortChecker.exe"=
"c:\\Program Files\\Steam\\steamapps\\zankuro\\day of defeat\\hl.exe"=
"c:\\Program Files\\Steam\\steamapps\\zankuro\\opposing force\\hl.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\quake\\Winquake.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\quake\\qwcl.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\quake\\Glquake.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\quake\\glqwcl.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"6114:UDP"= 6114:UDP:Chris' Laptop
"49901:TCP"= 49901:TCP:Vuze
"49901:UDP"= 49901:UDP:Vuze

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [4/23/2010 6:45 PM 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/23/2010 6:45 PM 242896]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [4/23/2010 6:44 PM 308064]
R2 PStrip;PStrip;c:\windows\system32\drivers\pstrip.sys [7/14/2007 9:37 PM 27992]
R3 MN130;Microsoft® PCI Adapter MN-130;c:\windows\system32\drivers\MN130-51.sys [1/27/2010 1:43 AM 38400]
S3 aaudstum;aaudstum;\??\c:\docume~1\GUGENH~1\LOCALS~1\Temp\aaudstum.sys –> c:\docume~1\GUGENH~1\LOCALS~1\Temp\aaudstum.sys [?]
S3 PbsAuDrv;PolderbitS Audio Driver;c:\windows\system32\drivers\pbsaudrv.sys –> c:\windows\system32\drivers\pbsaudrv.sys [?]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [11/26/2009 1:06 AM 34384]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [9/23/2005 7:01 AM 2799808]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/10/2009 5:36 PM 24652]
.
Contents of the 'Scheduled Tasks' folder

2010-04-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]

2010-04-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-688789844-839522115-1003Core.job
- c:\documents and settings\GUgenH3iMer schmidt\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-26 17:52]

2010-04-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-688789844-839522115-1003UA.job
- c:\documents and settings\GUgenH3iMer schmidt\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-26 17:52]

2010-04-24 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1957994488-688789844-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]

2010-04-22 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1957994488-688789844-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Save YouTube Video as MP3 - c:\program files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
TCP: {F393972F-1D38-45AC-821F-5AA4C0F459D0} = 24.151.8.211,24.151.8.210
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
Notify-WinCtrl32 - (no file)
SafeBoot-Winbj07.sys
SafeBoot-Winbj20.sys
SafeBoot-Winck42.sys
SafeBoot-Winfm32.sys
SafeBoot-Wingn08.sys
SafeBoot-Winiq10.sys
SafeBoot-Winks07.sys
SafeBoot-Winls18.sys
SafeBoot-Winmu07.sys
SafeBoot-Winmv75.sys
SafeBoot-Winov08.sys
SafeBoot-Winow08.sys
SafeBoot-Winsb64.sys



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-24 15:58
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(8028)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvsvc32.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\stsystra.exe
c:\windows\system32\RUNDLL32.EXE
c:\documents and settings\GUgenH3iMer schmidt\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-04-24 16:11:43 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-24 20:11

Pre-Run: 1,420,607,488 bytes free
Post-Run: 4,581,990,400 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - D891555FA0122C9D27F9C7D59F46E469
Hi again :)


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

RenV::
c:\program files\Common Files\InstallShield\UpdateService\issch .exe
c:\program files\Common Files\InstallShield\UpdateService\isuspm		   .exe
c:\program files\Common Files\Real\Update_OB\realsched .exe
c:\program files\Common Files\Symantec Shared\ccApp .exe
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe
c:\program files\Dell\Media Experience\DMXLauncher .exe
c:\program files\Dell Support\DSAgnt .exe
c:\program files\Google\Google Talk\googletalk .exe
c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
c:\program files\Messenger\msmsgs .exe
c:\program files\QuickTime\qttask			.exe
c:\program files\Spybot - Search & Destroy\TeaTimer .exe
c:\windows\ime\imjp8_1\IMJPMIG .EXE
c:\windows\system32\IME\TINTLGNT\TINTSETP .EXE
Registry::
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wincm07.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winjt07.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winmw18.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winnw75.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winow75.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winoy20.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winuc86.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winvd64.sys]

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.






[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.




Please post back with a fresh OTL logfile and tell me how the system is running.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI