This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] WPP... I think

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I think it is Windows Police Pro. I have been hit by it before, about 6 months ago. Here is what I tried:

I used the system recovery console as advised here:
http://forums.whatthetech.com/How_do_syste…le_t105819.html

I ran Windows but the virus started up again after a few seconds, blocking .exe and .com applications

Then I ran an old version of exehelper by Raktor, hoping it would stop the malware processes. I know that I am not supposed to use whatthetech tools without being directed to but I was desperate. Here is the log:

exeHelper by Raktor - 09
Build 20090925
Run at 01:11:12 on 10/12/09
Now searching…
Checking for numerical processes…
Deleting file C:\Documents and Settings\All Users\Application Data\88742938\88742938.exe
Removing HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\88742938
Checking for bad processes…
Killed process svchast.exe
Killed process Windows Police Pro.exe
Killed process b.exe
Checking for bad files…
Deleting file C:\WINDOWS\svchast.exe
Deleting file C:\WINDOWS\system32\minix32.exe
Deleting file C:\Program Files\Windows Police Pro\Windows Police Pro.exe
Deleting file C:\Documents and Settings\John\Desktop\Windows Police Pro.lnk
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–

exeHelper by Raktor - 09
Build 20090925
Run at 02:18:19 on exeHelper by Raktor - 09
exeHelper by Raktor - 09
Build 20090925
exeHelper by Raktor - 09
Run at Build 20090925
02:57:49Run at on 02:57:5010/12/09 on
10/12/09Now searching…

Now searching…
Checking for numerical processes…
Killed numerical process 65104824
Deleting file C:\Documents and Settings\All Users\Application Data\65104824\65104824.exe
Removing HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\65104824
Checking for bad processes…
Killed process b.exe
Checking for bad files…
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–

exeHelper by Raktor - 09
exeHelper by Raktor - 09
Build 20090925
Build 20090925
Run at Run at 03:03:3403:03:34 on on 10/12/0910/12/09

Now searching…
Checking for numerical processes…
Checking for bad processes…
Killed process b.exe
Checking for bad files…
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–

exeHelper by Raktor - 09
Build 20090925
Run at 03:49:20 on 10/12/09
Now searching…
Checking for numerical processes…
Checking for bad processes…
Checking for bad files…
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–

exeHelper by Raktor - 09
Build 20090925
Run at 23:55:27 on 11/28/09
Now searching…
Checking for numerical processes…
exeHelper by Raktor - 09
Build 20090925
Run at 01:02:56 on 04/27/10
Now searching…
Checking for numerical processes…
Checking for bad processes…
Checking for bad files…
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–
Hello there, someguy

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

**In any case where you happen to be busy or unable to give us a reply, we would be more than grateful if you keep us informed in advance and we will be more than happy to wait. :)
Hi,

Delete the old copy of exeHelper and download the new one as below.

Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)

===================================================

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please try to re-run GMER in Safe Mode if it fails to execute in normal windows.

===================================================

On your next reply please post :
exeHelper log
OTL log
GMER log

Good Day!
here is the new exehelper log exeHelper by Raktor - 09 Build 20090925 Run at 01:11:12 on 10/12/09 Now searching… Checking for numerical processes… Deleting file C:\Documents and Settings\All Users\Application Data\88742938\88742938.exe Removing HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\88742938 Checking for bad processes… Killed process svchast.exe Killed process Windows Police Pro.exe Killed process b.exe Checking for bad files… Deleting file C:\WINDOWS\svchast.exe Deleting file C:\WINDOWS\system32\minix32.exe Deleting file C:\Program Files\Windows Police Pro\Windows Police Pro.exe Deleting file C:\Documents and Settings\John\Desktop\Windows Police Pro.lnk Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished– exeHelper by Raktor - 09 Build 20090925 Run at 02:18:19 on exeHelper by Raktor - 09 exeHelper by Raktor - 09 Build 20090925 exeHelper by Raktor - 09 Run at Build 20090925 02:57:49Run at on 02:57:5010/12/09 on 10/12/09Now searching… Now searching… Checking for numerical processes… Killed numerical process 65104824 Deleting file C:\Documents and Settings\All Users\Application Data\65104824\65104824.exe Removing HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\65104824 Checking for bad processes… Killed process b.exe Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished– exeHelper by Raktor - 09 exeHelper by Raktor - 09 Build 20090925 Build 20090925 Run at Run at 03:03:3403:03:34 on on 10/12/0910/12/09 Now searching… Checking for numerical processes… Checking for bad processes… Killed process b.exe Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished– exeHelper by Raktor - 09 Build 20090925 Run at 03:49:20 on 10/12/09 Now searching… Checking for numerical processes… Checking for bad processes… Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished– exeHelper by Raktor - 09 Build 20090925 Run at 23:55:27 on 11/28/09 Now searching… Checking for numerical processes… exeHelper by Raktor - 09 Build 20090925 Run at 01:02:56 on 04/27/10 Now searching… Checking for numerical processes… Checking for bad processes… Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished– exeHelper by Raktor - 09 Build 20090925 Run at 19:39:48 on 04/28/10 Now searching… Checking for numerical processes… Checking for bad processes… Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished–
sorry to spread out the updates. I can only run programs when my computer just starts up. after that they are quickly blocked. I got exehelper to work but OTL is taking a long time. All the while more and more malware stuff is popping up. I dont like the idea of letting the malware run for all this time.
OTL logfile created on: 4/28/2010 7:45:20 PM - Run 1
OTL by OldTimer - Version 3.2.3.0 Folder = C:\Documents and Settings\John\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 70.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 2.54 Gb Free Space | 0.85% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: J-7
Current User Name: John
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\John\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\John\Local Settings\Application Data\asam.exe ()
PRC - C:\Documents and Settings\John\Local Settings\Application Data\tiysatkin\mqhlgwvtssd.exe ()
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Essentials\MpCmdRun.exe (Microsoft Corporation)
PRC - C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
PRC - C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
PRC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
PRC - C:\Program Files\ICQ6Toolbar\ICQ Service.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
PRC - C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrobat_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe ()
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\system32\Crypserv.exe (Kenonic Controls Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\John\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (DAUpdaterSvc) – C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (ICQ Service) – C:\Program Files\ICQ6Toolbar\ICQ Service.exe ()
SRV - (NICCONFIGSVC) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
SRV - (mi-raysat_3dsmax9_32) mental ray 3.5 Satellite (32-bit) – C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe ()
SRV - (Autodesk Network Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe (Autodesk, Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (Crypkey License) – C:\WINDOWS\System32\Crypserv.exe (Kenonic Controls Ltd.)


========== Driver Services (SafeList) ==========

DRV - (MpFilter) – C:\WINDOWS\system32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (SCDEmu) – C:\WINDOWS\system32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (guardian2) – C:\WINDOWS\system32\drivers\oz776.sys (O2Micro)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (NETw3x32) Intel® – C:\WINDOWS\system32\drivers\NETw3x32.sys (Intel® Corporation)
DRV - (monfilt) – C:\WINDOWS\system32\drivers\monfilt.sys (Creative Technology Ltd.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (CTUSFSYN) – C:\WINDOWS\system32\drivers\ctusfsyn.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (NetworkX) – C:\WINDOWS\system32\ckldrv.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.gmail.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/03 10:24:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/03 10:24:32 | 000,000,000 | —D | M]

[2009/02/15 22:49:03 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\Mozilla\Extensions
[2010/04/26 23:54:28 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\j1cizrmh.default\extensions
[2009/09/22 20:20:35 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\j1cizrmh.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/20 23:48:36 | 000,000,944 | —- | M] () – C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\j1cizrmh.default\searchplugins\icqplugin.xml
[2010/04/21 18:20:20 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/07/17 10:17:02 | 000,000,000 | —D | M] (TextAloud Firefox Plugin) – C:\Program Files\Mozilla Firefox\extensions\{99a0337c-6303-4879-b72e-500fd9aaca8c}

O1 HOSTS File: ([2009/10/13 07:51:20 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.2.7.dll (BitComet)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (TextAloud) - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\Program Files\TextAloud\TAForIE.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [asam] C:\Documents and Settings\John\Local Settings\Application Data\asam.exe ()
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe (Google)
O4 - HKLM..\Run: [lfgwemtr] C:\Documents and Settings\John\Local Settings\Application Data\tiysatkin\mqhlgwvtssd.exe ()
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\WINDOWS\System32\nvhotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKCU..\Run: [asam] C:\Documents and Settings\John\Local Settings\Application Data\asam.exe ()
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [lfgwemtr] C:\Documents and Settings\John\Local Settings\Application Data\tiysatkin\mqhlgwvtssd.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk = C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe ()
O4 - Startup: C:\Documents and Settings\John\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &D;&ownload; &with; BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D;&ownload; all video with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D;&ownload; all with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/02/12 21:04:48 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/02/11 19:30:41 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

========== Files/Folders - Created Within 30 Days ==========

[2010/04/28 19:42:06 | 000,563,712 | —- | C] (OldTimer Tools) – C:\Documents and Settings\John\Desktop\OTL.exe
[2010/04/26 23:19:28 | 000,000,000 | —D | C] – C:\Documents and Settings\John\Local Settings\Application Data\tiysatkin
[2010/04/23 13:44:22 | 000,000,000 | —D | C] – C:\Program Files\Mass Effect
[2010/04/23 12:59:51 | 000,000,000 | —D | C] – C:\Documents and Settings\John\Local Settings\Application Data\STDUViewer
[2010/04/23 12:59:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\STDUtility
[2010/04/23 12:59:43 | 000,000,000 | —D | C] – C:\Program Files\STDU Viewer
[2010/04/23 12:56:18 | 002,025,633 | —- | C] (STDUtility ) – C:\Documents and Settings\John\My Documents\stduviewer.exe
[2010/04/22 22:35:19 | 000,000,000 | —D | C] – C:\Documents and Settings\John\Local Settings\Application Data\Ironclad Games
[2010/04/22 22:34:29 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{0E8E33D8-193A-414A-A909-0F101A142D26}
[2010/04/22 22:30:07 | 000,000,000 | —D | C] – C:\Program Files\Stardock Games
[2010/04/22 22:29:24 | 000,000,000 | —D | C] – C:\Documents and Settings\John\Local Settings\Application Data\Stardock
[2010/04/22 22:16:43 | 000,000,000 | —D | C] – C:\Documents and Settings\John\Desktop\New Folder
[2010/04/20 11:45:15 | 000,131,072 | R— | C] (Creative Technology Ltd) – C:\WINDOWS\System32\eax.dll
[2010/04/20 11:45:01 | 000,000,000 | —D | C] – C:\Program Files\Ubisoft
[2010/04/18 20:28:56 | 000,000,000 | —D | C] – C:\Documents and Settings\John\Local Settings\Application Data\Gas Powered Games
[2010/04/18 19:51:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Media Center Programs
[2010/04/18 19:48:26 | 000,000,000 | —D | C] – C:\Program Files\THQ
[2010/04/18 10:21:58 | 000,000,000 | —D | C] – C:\Documents and Settings\John\Application Data\SpaceMonger
[2010/04/18 10:21:57 | 000,000,000 | —D | C] – C:\Program Files\SpaceMonger
[2010/04/15 04:18:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Symantec
[2010/04/15 04:18:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Norton
[2010/04/15 04:18:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2010/04/15 00:55:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\DivX
[2010/04/14 20:52:43 | 000,000,000 | —D | C] – C:\Documents and Settings\John\My Documents\ad for new phone_files
[2010/03/30 20:58:24 | 000,353,592 | —- | C] (DivX, Inc.) – C:\WINDOWS\System32\DivXControlPanelApplet.cpl
[2010/03/30 16:00:47 | 003,558,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/04/28 19:48:02 | 000,512,960 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/04/28 19:48:02 | 000,435,828 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/04/28 19:48:02 | 000,068,558 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/04/28 19:44:08 | 000,002,337 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
[2010/04/28 19:44:03 | 000,031,776 | —- | M] () – C:\WINDOWS\System32\nvModes.001
[2010/04/28 19:43:57 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/04/28 19:43:50 | 000,191,197 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/04/28 19:43:46 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/28 19:43:44 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/04/28 19:43:42 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/04/28 19:43:38 | 2145,869,824 | -HS- | M] () – C:\hiberfil.sys
[2010/04/28 19:42:13 | 000,563,712 | —- | M] (OldTimer Tools) – C:\Documents and Settings\John\Desktop\OTL.exe
[2010/04/28 19:38:32 | 000,294,400 | —- | M] () – C:\Documents and Settings\John\Desktop\exeHelper.com
[2010/04/28 19:35:40 | 000,000,024 | —- | M] () – C:\WINDOWS\herjek.config
[2010/04/28 19:34:09 | 000,060,160 | —- | M] () – C:\Documents and Settings\John\Local Settings\Application Data\syssvc.exe
[2010/04/28 19:34:09 | 000,060,160 | —- | M] () – C:\Documents and Settings\John\Local Settings\Application Data\asam.exe
[2010/04/28 19:32:56 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/04/27 01:04:58 | 009,961,472 | —- | M] () – C:\Documents and Settings\John\NTUSER.DAT
[2010/04/27 01:01:43 | 005,277,314 | -H– | M] () – C:\Documents and Settings\John\Local Settings\Application Data\IconCache.db
[2010/04/26 23:57:56 | 000,284,160 | —- | M] () – C:\Documents and Settings\John\Desktop\exeHelper.exe
[2010/04/26 22:52:01 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1844823847-725345543-1004UA.job
[2010/04/26 22:50:06 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/04/26 22:45:46 | 000,031,776 | —- | M] () – C:\WINDOWS\System32\nvModes.dat
[2010/04/26 12:07:33 | 000,099,328 | —- | M] () – C:\Documents and Settings\John\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/26 10:36:26 | 206,847,140 | —- | M] () – C:\Documents and Settings\John\Desktop\Jonathan Miller - A Brief History of Disbelief - Noughts and Crosses.mp4
[2010/04/26 05:52:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1844823847-725345543-1004Core.job
[2010/04/26 02:03:12 | 000,000,408 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/04/24 19:09:53 | 000,019,968 | —- | M] () – C:\Documents and Settings\John\Desktop\cost of living.xls
[2010/04/24 18:45:16 | 000,010,353 | —- | M] () – C:\Documents and Settings\John\My Documents\cost of living.xlsx
[2010/04/23 14:02:47 | 000,000,753 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mass Effect.lnk
[2010/04/23 12:59:51 | 000,000,002 | —- | M] () – C:\WINDOWS\System32\C
[2010/04/23 12:56:53 | 002,025,633 | —- | M] (STDUtility ) – C:\Documents and Settings\John\My Documents\stduviewer.exe
[2010/04/20 22:57:17 | 000,235,686 | —- | M] () – C:\Documents and Settings\John\My Documents\GammaClassAssaultShuttleDiagram-ISB.jpg
[2010/04/18 19:54:27 | 000,002,132 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Supreme Commander Demo.lnk
[2010/04/18 18:21:46 | 225,763,824 | —- | M] () – C:\Documents and Settings\John\Desktop\supremecommanderdemo.zip
[2010/04/18 10:19:07 | 000,000,004 | —- | M] () – C:\WINDOWS\System32\wnsm2i.rdb
[2010/04/16 10:12:18 | 000,090,624 | —- | M] () – C:\Documents and Settings\John\My Documents\John_Sullivan_Archinect_Resume_April_16_2010.doc
[2010/04/15 01:20:29 | 000,001,466 | —- | M] () – C:\Documents and Settings\John\Desktop\DivX Movies.lnk
[2010/04/14 20:52:44 | 000,005,193 | —- | M] () – C:\Documents and Settings\John\My Documents\ad for new phone.html
[2010/04/14 10:54:13 | 000,001,915 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/04/14 03:59:35 | 000,735,354 | —- | M] () – C:\Documents and Settings\John\My Documents\img001.jpg
[2010/04/14 03:59:30 | 000,735,354 | —- | M] () – C:\Documents and Settings\John\Desktop\img001.jpg
[2010/04/11 17:16:58 | 000,138,644 | —- | M] () – C:\Documents and Settings\John\Desktop\SULLIVAN-FEDOCK Conditional MArch Offer Letter.jpg
[2010/04/07 05:26:27 | 018,271,921 | —- | M] () – C:\Documents and Settings\John\Desktop\audiosample-Science-of-Good-and-Evil.mp3
[2010/04/05 15:29:44 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/04/05 00:53:29 | 002,780,332 | —- | M] () – C:\Documents and Settings\John\Desktop\dsouza-hitchens-09-debate.mp3
[2010/03/31 19:16:45 | 000,260,230 | —- | M] () – C:\Documents and Settings\John\My Documents\BS09_1693_1698.pdf
[2010/03/31 12:00:27 | 000,077,811 | —- | M] () – C:\Documents and Settings\John\Desktop\UPenn_Decision.pdf
[2010/03/30 20:58:24 | 000,353,592 | —- | M] (DivX, Inc.) – C:\WINDOWS\System32\DivXControlPanelApplet.cpl
[2010/03/30 00:46:30 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/30 00:45:52 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/04/28 19:38:29 | 000,294,400 | —- | C] () – C:\Documents and Settings\John\Desktop\exeHelper.com
[2010/04/28 19:35:40 | 000,000,024 | —- | C] () – C:\WINDOWS\herjek.config
[2010/04/28 19:35:10 | 000,060,160 | —- | C] () – C:\Documents and Settings\John\Local Settings\Application Data\asam.exe
[2010/04/28 19:34:07 | 000,060,160 | —- | C] () – C:\Documents and Settings\John\Local Settings\Application Data\syssvc.exe
[2010/04/26 23:57:55 | 000,284,160 | —- | C] () – C:\Documents and Settings\John\Desktop\exeHelper.exe
[2010/04/26 10:13:02 | 206,847,140 | —- | C] () – C:\Documents and Settings\John\Desktop\Jonathan Miller - A Brief History of Disbelief - Noughts and Crosses.mp4
[2010/04/24 19:09:53 | 000,019,968 | —- | C] () – C:\Documents and Settings\John\Desktop\cost of living.xls
[2010/04/24 18:45:15 | 000,010,353 | —- | C] () – C:\Documents and Settings\John\My Documents\cost of living.xlsx
[2010/04/23 14:02:47 | 000,000,753 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mass Effect.lnk
[2010/04/23 12:59:51 | 000,000,002 | —- | C] () – C:\WINDOWS\System32\C
[2010/04/20 22:57:16 | 000,235,686 | —- | C] () – C:\Documents and Settings\John\My Documents\GammaClassAssaultShuttleDiagram-ISB.jpg
[2010/04/18 19:54:27 | 000,002,132 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Supreme Commander Demo.lnk
[2010/04/18 11:44:37 | 225,763,824 | —- | C] () – C:\Documents and Settings\John\Desktop\supremecommanderdemo.zip
[2010/04/18 10:19:07 | 000,000,004 | —- | C] () – C:\WINDOWS\System32\wnsm2i.rdb
[2010/04/16 10:09:57 | 000,090,624 | —- | C] () – C:\Documents and Settings\John\My Documents\John_Sullivan_Archinect_Resume_April_16_2010.doc
[2010/04/15 01:20:29 | 000,001,466 | —- | C] () – C:\Documents and Settings\John\Desktop\DivX Movies.lnk
[2010/04/14 20:52:43 | 000,005,193 | —- | C] () – C:\Documents and Settings\John\My Documents\ad for new phone.html
[2010/04/14 10:54:13 | 000,001,915 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/04/14 03:59:34 | 000,735,354 | —- | C] () – C:\Documents and Settings\John\My Documents\img001.jpg
[2010/04/14 03:59:26 | 000,735,354 | —- | C] () – C:\Documents and Settings\John\Desktop\img001.jpg
[2010/04/11 17:16:55 | 000,138,644 | —- | C] () – C:\Documents and Settings\John\Desktop\SULLIVAN-FEDOCK Conditional MArch Offer Letter.jpg
[2010/04/07 05:26:23 | 018,271,921 | —- | C] () – C:\Documents and Settings\John\Desktop\audiosample-Science-of-Good-and-Evil.mp3
[2010/04/05 00:53:29 | 002,780,332 | —- | C] () – C:\Documents and Settings\John\Desktop\dsouza-hitchens-09-debate.mp3
[2010/03/31 19:16:45 | 000,260,230 | —- | C] () – C:\Documents and Settings\John\My Documents\BS09_1693_1698.pdf
[2010/03/31 12:00:24 | 000,077,811 | —- | C] () – C:\Documents and Settings\John\Desktop\UPenn_Decision.pdf
[2010/01/17 06:07:50 | 000,000,000 | —- | C] () – C:\WINDOWS\EEventManager.INI
[2009/12/30 15:15:28 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2009/10/22 13:15:18 | 000,000,058 | —- | C] () – C:\WINDOWS\OSA.INI
[2009/10/15 05:36:12 | 000,000,248 | —- | C] () – C:\WINDOWS\RomeTW.ini
[2009/08/10 00:42:36 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2009/08/09 13:24:52 | 000,034,308 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2009/07/10 03:49:08 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2009/04/17 17:12:45 | 000,000,056 | —- | C] () – C:\WINDOWS\Crypkey.ini
[2009/04/17 17:12:42 | 000,024,608 | —- | C] () – C:\WINDOWS\System32\Ckldrv.sys
[2009/04/17 17:12:42 | 000,018,432 | —- | C] () – C:\WINDOWS\Setup_ck.dll
[2009/04/17 17:12:38 | 000,097,802 | —- | C] () – C:\WINDOWS\System32\Crp32dll.dll
[2009/02/21 16:20:26 | 000,168,448 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/02/21 16:20:21 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2009/02/21 16:20:21 | 000,795,648 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/02/21 16:20:21 | 000,130,048 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/02/21 16:20:19 | 000,067,584 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/02/21 16:20:19 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/02/16 00:18:42 | 000,721,904 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2009/02/15 23:06:27 | 000,022,629 | —- | C] () – C:\WINDOWS\System32\CiFilter.ini
[2009/02/15 21:48:06 | 001,724,416 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2009/02/15 21:48:06 | 001,507,328 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2009/02/15 21:48:06 | 001,101,824 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2009/02/15 21:48:06 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2008/10/07 10:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 10:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/04/30 17:16:30 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2004/11/18 11:16:42 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\nktwab.dll
[2001/10/28 17:42:30 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\pdfcmnnt.dll

========== LOP Check ==========

[2009/07/30 17:28:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2009/11/30 20:21:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BioWare
[2009/08/11 02:20:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2009/02/16 01:25:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/12/30 15:22:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2009/04/14 16:19:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ICQ
[2009/08/09 12:48:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\JollyBear
[2009/04/24 13:47:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McNeel
[2009/06/04 13:44:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2009/10/08 19:37:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PrettyMay
[2010/04/22 22:34:31 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{0E8E33D8-193A-414A-A909-0F101A142D26}
[2009/02/22 23:14:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/07/28 18:55:15 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\Arcen Games, LLC
[2009/07/30 17:28:10 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\Autodesk
[2009/02/16 01:26:08 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\DAEMON Tools
[2009/07/10 07:05:44 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\DAEMON Tools Lite
[2009/02/16 01:26:08 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\DAEMON Tools Pro
[2010/01/09 19:21:34 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\Epson
[2009/08/09 12:50:37 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\Gaijin Ent
[2009/04/14 16:19:33 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\ICQ
[2009/02/16 04:15:04 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\LucasArts
[2009/02/15 22:17:01 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\Opera
[2010/03/02 02:25:14 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\Petroglyph
[2009/10/08 19:36:46 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\PrettyMay
[2009/07/28 16:35:29 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\SaintXi
[2010/04/18 10:21:58 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\SpaceMonger
[2010/02/21 03:57:37 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\SPORE
[2010/04/26 02:03:12 | 000,000,408 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/12 09:06:15 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/02/15 21:59:57 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/02/15 21:59:57 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/12 09:06:15 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/02/15 21:59:57 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009/02/15 21:59:57 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\ReinstallBackups\0014\DriverFiles\i386\atapi.sys
[2004/08/12 08:55:51 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/12 08:57:17 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: IASTOR.SYS >
[2004/08/12 09:11:50 | 000,467,200 | —- | M] (Intel Corporation) MD5=F26BFD48B1C314E0F23BF77ACFA75940 – C:\WINDOWS\dell\iastor\iastor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/12 09:02:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/12 09:04:44 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2009/07/05 20:04:36 | 000,721,904 | —- | M] () Unable to obtain MD5 – C:\WINDOWS\system32\drivers\sptd.sys

< %systemroot%\System32\config\*.sav >
[2009/02/11 19:36:11 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/02/11 19:36:11 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/02/11 19:36:11 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\drivers\*.sys /90 >
[2010/03/30 00:45:52 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbam.sys
[2010/03/30 00:46:30 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys
< End of report >




OTL Extras logfile created on: 4/28/2010 7:45:20 PM - Run 1
OTL by OldTimer - Version 3.2.3.0 Folder = C:\Documents and Settings\John\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 70.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 2.54 Gb Free Space | 0.85% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: J-7
Current User Name: John
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = Opera.HTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Opera\opera.exe" (Opera Software)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [SpaceMonger] – "C:\Program Files\SpaceMonger\SpaceMonger.exe" ; show-free-space false ; show-system-space false ; set-root "%l" (Sixty-Five Software, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"15043:TCP" = 15043:TCP:*:Enabled:BitComet 15043 TCP
"15043:UDP" = 15043:UDP:*:Enabled:BitComet 15043 UDP
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Valve\Steam\SteamApps\sulljoh1\source sdk base 2007\hl2.exe" = C:\Program Files\Valve\Steam\SteamApps\sulljoh1\source sdk base 2007\hl2.exe:*:Enabled:hl2 – ()
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\Program Files\Valve\Steam\SteamApps\sulljoh1\source sdk base\hl2.exe" = C:\Program Files\Valve\Steam\SteamApps\sulljoh1\source sdk base\hl2.exe:*:Enabled:hl2 – ()
"C:\Program Files\BitComet\BitComet.exe" = C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client – (www.BitComet.com)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\LucasArts\Star Wars Empire at War\GameData\sweaw.exe" = C:\Program Files\LucasArts\Star Wars Empire at War\GameData\sweaw.exe:*:Enabled:Petroglyph – (Lucasfilm Entertainment Company, Ltd.)
"C:\Documents and Settings\John\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll" = C:\Documents and Settings\John\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin – (Google)
"C:\Documents and Settings\John\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\John\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\Google\Google Talk\googletalk.exe" = C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk – (Google)
"C:\Program Files\ICQ6.5\ICQ.exe" = C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6 – (ICQ, LLC.)
"C:\Program Files\Autodesk\3ds Max 9\3dsmax.exe" = C:\Program Files\Autodesk\3ds Max 9\3dsmax.exe:*:Enabled:Autodesk 3ds Max 9 32-bit – (Autodesk, Inc.)
"C:\Program Files\Autodesk\Backburner\monitor.exe" = C:\Program Files\Autodesk\Backburner\monitor.exe:*:Enabled:backburner 2.3 monitor – (Autodesk, Inc.)
"C:\Program Files\Autodesk\Backburner\manager.exe" = C:\Program Files\Autodesk\Backburner\manager.exe:*:Enabled:backburner 2.3 manager – (Autodesk, Inc.)
"C:\Program Files\Autodesk\Backburner\server.exe" = C:\Program Files\Autodesk\Backburner\server.exe:*:Enabled:backburner 2.3 server – (Autodesk, Inc.)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\Codemasters\Overlord\Overlord.exe" = C:\Program Files\Codemasters\Overlord\Overlord.exe:*:Enabled:Game Application – (Triumph Studios)
"C:\Program Files\Codemasters\Overlord II\Overlord2.exe" = C:\Program Files\Codemasters\Overlord II\Overlord2.exe:*:Enabled:Overlord II – ()
"C:\WINDOWS\system32\HPZipm12.exe" = C:\WINDOWS\system32\HPZipm12.exe:*:Enabled:HPZipm12 – (HP)
"C:\Program Files\Dragon Age\bin_ship\daorigins.exe" = C:\Program Files\Dragon Age\bin_ship\daorigins.exe:*:Enabled:Dragon Age Origins Game – (BioWare)
"C:\Program Files\Dragon Age\DAOriginsLauncher.exe" = C:\Program Files\Dragon Age\DAOriginsLauncher.exe:*:Enabled:Dragon Age Origins Launcher – (BioWare)
"C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe" = C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe:*:Enabled:Dragon Age Origins Updater – (BioWare)
"C:\Program Files\Epson Software\Event Manager\EEventManager.exe" = C:\Program Files\Epson Software\Event Manager\EEventManager.exe:*:Disabled:EEventManager Application – (SEIKO EPSON CORPORATION)
"C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" = C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Enabled:Veoh Web Player – (Veoh Networks)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\LucasArts\Star Wars Empire at War Forces of Corruption\swfoc.exe" = C:\Program Files\LucasArts\Star Wars Empire at War Forces of Corruption\swfoc.exe:*:Enabled:Star Wars™: Empire at War™: Forces of Corruption™ – (Lucasfilm Entertainment Company, Ltd.)
"C:\Program Files\Real Alternative\Media Player Classic\mplayerc.exe" = C:\Program Files\Real Alternative\Media Player Classic\mplayerc.exe:*:Enabled:Media Player Classic – (Gabest)
"c:\documents and settings\john\local settings\application data\asam.exe" = c:\documents and settings\john\local settings\application data\asam.exe:*:Enabled:enable – ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam™
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{06F80017-8F98-4C94-B868-52358569FC32}" = Command & Conquer Generals
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{08C0729E-3E50-11DF-9D81-005056806466}" = Google Earth
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1B0FBB9A-995D-47cd-87CD-13E68B676E4F}" = Mass Effect
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{259A8A5E-2886-4BED-9EF1-D5485282CCC3}" = Overlord - Raising Hell
"{25A1E6A4-2DBD-4AC0-8650-8EA9A45B1848}" = Supreme Commander Demo
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 17
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{325079BC-CA11-46CE-A457-C61CA126B367}" = AOTC - Revit Architecture 2008 Essentials
"{342F5437-C87D-4BB5-89B9-B23E16C6A395}" = Microsoft VC80 Support DLLs
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3D347E6D-5A03-4342-B5BA-6A771885F379}" = Backburner
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{450063AA-643B-417C-8CF5-405BA3F4EF40}" = Autodesk Design Review 2009
"{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = Epson Event Manager
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{5783F2D7-6001-0409-0002-0060B0CE6BBA}" = AutoCAD 2008 - English
"{5C2CBFFD-FC3B-4AA9-993B-CE2B8DA25B87}" = Rhinoceros 4.0
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{6592FDEC-2C1A-413A-9985-25FEC2F0848D}" = Star Wars Empire at War Forces of Corruption
"{6663554C-2FC7-4CDC-809D-1BCD59189853}_is1" = Trine
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6BB42024-D62A-33F5-B883-52069E2C9668}" = Google Talk Plugin
"{6BF81CE7-3D5A-497F-8912-2A65A0253E1B}" = Beyond Good & Evil
"{6C6E880E-FFD4-47C4-A5CE-DFE225662995}" = SendBlaster
"{6E348319-3301-4A32-ABDC-249F49DFF07E}" = TJ-Beam
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{783E0AD7-C128-4398-9F74-99D3EFF2875D}" = Deep Space Nine The Fallen
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7C3EC6B0-663E-4DF9-8231-EA486CD0A400}" = Maya Fluid Effects Screensaver
"{7C8B5E63-821A-4DFB-BDFA-19854D88EC5C}" = 3dsmax ancillary install
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8D49D55D-9837-4E0E-AE3B-05C7BEC5CD1F}" = Opera 10.51
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{8EDBA74D-0686-4C99-BFDD-F894678E5102}" = Adobe Common File Installer
"{8FFC924C-ED06-44CB-8867-3CA778ECE903}" = Adobe Help Center 2.0
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_PRJPRO_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_PRJPRO_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_PRJPRO_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-003B-0000-0000-0000000FF1CE}" = Microsoft Office Project Professional 2007
"{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{9E73617F-2F38-4864-BD61-BB2DDFE43323}" = Microsoft Office Project 2007 Service Pack 2 (SP2)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_PRJPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B4-0409-0000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2007
"{90120000-00B4-0409-0000-0000000FF1CE}_PRJPRO_{27A9D316-D332-433B-8EB1-1D93EE49F26D}" = Microsoft Office Project 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_PRJPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{99AE7207-8612-4DBA-A8F8-BAE5C633390D}" = Star Wars Empire at War
"{9A346205-EA92-4406-B1AB-50379DA3F057}" = Autodesk DWF Viewer 7
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9DF0196F-B6B8-4C3A-8790-DE42AA530101}" = SPORE™
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A350E867-DC1D-4CEC-9B05-6590420F3C36}" = TJ-Beam
"{A3A37DA6-70C0-497C-BCB1-148E9EC1D32E}" = Revit Architecture 2009
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A642BB6B-CA1D-4142-8DD4-318C3F3DC834}" = Rome - Total War™
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-1033-F400-7760-000000000003}" = Adobe Acrobat 8 Professional - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.1
"{AE3D38A6-13B1-40B3-9423-D1FA9982FB6A}" = Adobe Bridge 1.0
"{AEB9948B-4FF2-47C9-990E-47014492A0FE}" = MSXML 6.0 Parser
"{AEC81925-9C76-4707-84A9-40696C613ED3}" = Dragon Age: Origins
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D1BB4446-AE9C-4256-9A7F-4D46604D2462}" = Adobe Setup
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D45EC259-4A19-4656-B588-C2C360DD18EA}" = Half-Life® 2
"{D5395E5F-4D45-4665-8F00-234FA33678AF}" = SlimDX Redistributable (March 2009)
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DD1865F0-AD73-40FB-B23E-1822E02396FF}" = NVIDIA PhysX
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E426CEC1-35C5-42BF-913E-6EF8F1211D01}" = Overlord II
"{E590FD1C-E8C6-4D2E-8CA9-77B403F7EE01}" = Microsoft Antimalware
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E96D4088-AAC5-437F-9E39-EC0E387897B4}" = Autodesk 3ds Max 9 32-bit
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{ECCA8FE7-767A-4C8A-9DAA-BAB60F877C41}" = Sins of a Solar Empire
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}" = iTunes
"{FA17A726-B229-4116-B793-A2AB1A4EAE2E}" = Adobe Premiere Pro 2.0
"4569969E1360D2854474C661EF9B4D54F143EB16" = Windows Driver Package - Ricoh Company (rimsptsk) hdc (11/14/2006 6.00.01.04)
"Adobe Acrobat 8 Professional - English, Français, Deutsch" = Adobe Acrobat 8 Professional - English, Français, Deutsch
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Premiere Pro 2.0" = Adobe Premiere Pro 2.0
"Adobe_2ac78060bc5856b0c1cf873bb919b58" = Adobe Photoshop CS3
"Arvoch Conflict" = Arvoch Conflict
"AutoCAD 2008 - English" = AutoCAD 2008 - English
"Autodesk Design Review 2009" = Autodesk Design Review 2009
"BitComet" = BitComet 0.84
"C5650E7D-B940-4018-B746-DA4EE5A80791" = Stargate Empire at War
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2BFA&SUBSYS;_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"CTMBDemo_Audigy" = Sound Blaster Audigy ADVANCED MB Demo
"Darwinia" = Darwinia
"Darwinia Demo2_is1" = Darwinia Demo2
"Deutz Engine" = Deutz Engine
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPSON NX100 Series" = EPSON NX100 Series Printer Uninstall
"EPSON Scanner" = EPSON Scan
"ERUNT_is1" = ERUNT 1.1j
"FBX Plugin 2006.08 for Max 9.0" = FBX Plugin 2006.08 for Max 9.0
"Google Chrome" = Google Chrome
"Google Updater" = Google Updater
"GoToAssist" = GoToAssist 8.0.0.514
"GRE POWERPREP" = GRE POWERPREP
"HijackThis" = HijackThis 2.0.2
"Homeworld2" = Homeworld2
"ICQToolbar" = ICQ Toolbar
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{06F80017-8F98-4C94-B868-52358569FC32}" = Command & Conquer Generals
"InstallShield_{A642BB6B-CA1D-4142-8DD4-318C3F3DC834}" = Rome - Total War™
"IrfanView" = IrfanView (remove only)
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.6.2 (Full)
"LemmingballZ_0" = LemmingballZ 3D 8460
"Mahjong Escape Ancient Japan" = Mahjong Escape Ancient Japan (remove only)
"Mahjong Fortuna 2 Deluxe" = Mahjong Fortuna 2 Deluxe
"Mahjongg Artifacts" = Mahjongg Artifacts
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"MIXERLITE" = Mixer
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"Multiwinia_is1" = Multiwinia v1.3.0
"Mythic Mahjong1.0" = Mythic Mahjong
"Nice PDF Compressor_is1" = Nice PDF Compressor 2.0
"NingPo MahJong Deluxe 1.04" = NingPo MahJong Deluxe 1.04
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OpenAL" = OpenAL
"PowerISO" = PowerISO
"PRJPRO" = Microsoft Office Project Professional 2007
"RealAlt_is1" = Real Alternative 1.9.0
"SAMB_ADVMB_FILTER_DRV" = Sound Blaster ADVANCED MB Drivers
"Sins of a Solar Empire" = Sins of a Solar Empire
"SpaceMonger" = SpaceMonger 2.1.1
"STDU Viewer_is1" = STDU Viewer version 1.5.402.0
"Steam App 218" = Source SDK Base - Orange Box
"Steam App 220" = Half-Life 2
"StickMen War 2.5" = StickMen War 2.5
"TextAloud MP3_is1" = TextAloud
"Veoh Web Player Beta" = Veoh Web Player
"VLC media player" = VideoLAN VLC media player 0.8.6c
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/12/2010 6:28:32 PM | Computer Name = J-7 | Source = Application Error | ID = 1000
Description = Faulting application swfoc.exe, version 1.0.0.0, faulting module swfoc.exe,
version 1.0.0.0, fault address 0x00626faa.

Error - 4/20/2010 1:36:56 AM | Computer Name = J-7 | Source = Application Error | ID = 1000
Description = Faulting application swfoc.exe, version 1.0.0.0, faulting module swfoc.exe,
version 1.0.0.0, fault address 0x0053d566.

Error - 4/20/2010 10:18:12 PM | Computer Name = J-7 | Source = Application Error | ID = 1000
Description = Faulting application swfoc.exe, version 1.0.0.0, faulting module swfoc.exe,
version 1.0.0.0, fault address 0x00626faa.

Error - 4/20/2010 10:20:39 PM | Computer Name = J-7 | Source = Application Error | ID = 1000
Description = Faulting application swfoc.exe, version 1.0.0.0, faulting module swfoc.exe,
version 1.0.0.0, fault address 0x00626faa.

Error - 4/21/2010 3:32:23 PM | Computer Name = J-7 | Source = Application Error | ID = 1000
Description = Faulting application bge.exe, version 1.0.0.0, faulting module bge.exe,
version 1.0.0.0, fault address 0x0008c618.

Error - 4/22/2010 6:00:48 PM | Computer Name = J-7 | Source = Application Error | ID = 1000
Description = Faulting application swfoc.exe, version 1.0.0.0, faulting module swfoc.exe,
version 1.0.0.0, fault address 0x00626faa.

Error - 4/22/2010 6:38:32 PM | Computer Name = J-7 | Source = Application Error | ID = 1000
Description = Faulting application swfoc.exe, version 1.0.0.0, faulting module swfoc.exe,
version 1.0.0.0, fault address 0x00626faa.

Error - 4/23/2010 8:12:57 PM | Computer Name = J-7 | Source = Application Error | ID = 1000
Description = Faulting application masseffect.exe, version 1.0.14184.0, faulting
module unknown, version 0.0.0.0, fault address 0x03fcf9e0.

Error - 4/25/2010 5:35:18 AM | Computer Name = J-7 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x0000100b.

Error - 4/26/2010 1:16:07 PM | Computer Name = J-7 | Source = Application Error | ID = 1000
Description = Faulting application mplayerc.exe, version 6.4.9.1, faulting module
rv40.dll, version 10.0.1.331, fault address 0x00003ca2.

[ System Events ]
Error - 4/24/2010 7:15:06 AM | Computer Name = J-7 | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.1.100
with the system having network hardware address 00:11:D9:01:4A:60. Network operations
on this system may be disrupted as a result.

Error - 4/24/2010 7:15:18 AM | Computer Name = J-7 | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.1.100
with the system having network hardware address 00:11:D9:01:4A:60. Network operations
on this system may be disrupted as a result.

Error - 4/24/2010 7:15:19 AM | Computer Name = J-7 | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.1.100
with the system having network hardware address 00:11:D9:01:4A:60. Network operations
on this system may be disrupted as a result.

Error - 4/24/2010 7:15:20 AM | Computer Name = J-7 | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.1.100
with the system having network hardware address 00:11:D9:01:4A:60. Network operations
on this system may be disrupted as a result.

Error - 4/24/2010 7:15:21 AM | Computer Name = J-7 | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.1.100
with the system having network hardware address 00:11:D9:01:4A:60. Network operations
on this system may be disrupted as a result.

Error - 4/24/2010 7:27:17 AM | Computer Name = J-7 | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.1.100
with the system having network hardware address 00:11:D9:01:4A:60. Network operations
on this system may be disrupted as a result.

Error - 4/24/2010 7:27:18 AM | Computer Name = J-7 | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.1.100
with the system having network hardware address 00:11:D9:01:4A:60. Network operations
on this system may be disrupted as a result.

Error - 4/24/2010 7:27:19 AM | Computer Name = J-7 | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.1.100
with the system having network hardware address 00:11:D9:01:4A:60. Network operations
on this system may be disrupted as a result.

Error - 4/25/2010 10:03:26 PM | Computer Name = J-7 | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.1.100
with the system having network hardware address 00:11:D9:01:4A:60. Network operations
on this system may be disrupted as a result.

Error - 4/28/2010 8:38:09 PM | Computer Name = J-7 | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.1.100
with the system having network hardware address 00:11:D9:01:4A:60. Network operations
on this system may be disrupted as a result.


< End of report >
The GMER scan has been going for 3 or 4 hours now. I'll post it when it is done. EDIT: It is still in documents and settings, scanning every picture file. My 250 gig hard drive is nearly full. This scan could take a long time. Maybe more than 24 hours.
well I tried in safe mode and the file would not save. I tried to save on the desktop, in my documents, etc. 14 hours well spent.
Hello there,

***Read through this entire procedure and if you have any questions, please ask them before you begin. Then either print out, or copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.


Can you tell me about these two?

C:\Documents and Settings\John\My Documents\img001.jpg
C:\Documents and Settings\John\Desktop\img001.jpg

===================================================

You have ( BitComet ), a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.internetworldstats.com/articles…cles/art053.htm
See Clean/Infected P2P Programs here

I would recommend that you uninstall it, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


===================================================

Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • If it needs to, DeFogger may ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.

===================================================

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\Documents and Settings\John\Local Settings\Application Data\asam.exe ()
    PRC - C:\Documents and Settings\John\Local Settings\Application Data\tiysatkin\mqhlgwvtssd.exe ()
    O4 - HKLM..\Run: [asam] C:\Documents and Settings\John\Local Settings\Application Data\asam.exe ()
    O4 - HKLM..\Run: [lfgwemtr] C:\Documents and Settings\John\Local Settings\Application Data\tiysatkin\mqhlgwvtssd.exe ()
    O4 - HKCU..\Run: [asam] C:\Documents and Settings\John\Local Settings\Application Data\asam.exe ()
    O4 - HKCU..\Run: [lfgwemtr] C:\Documents and Settings\John\Local Settings\Application Data\tiysatkin\mqhlgwvtssd.exe ()
    [2010/04/26 23:19:28 | 000,000,000 | —D | C] – C:\Documents and Settings\John\Local Settings\Application Data\tiysatkin
    [2010/04/28 19:34:09 | 000,060,160 | —- | M] () – C:\Documents and Settings\John\Local Settings\Application Data\syssvc.exe
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
    [2010/04/28 19:35:40 | 000,000,024 | —- | C] () – C:\WINDOWS\herjek.config
    
    :Files
    C:\Documents and Settings\John\Local Settings\Application Data\asam.exe
    C:\Documents and Settings\John\Local Settings\Application Data\tiysatkin\mqhlgwvtssd.exe
    
    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "c:\documents and settings\john\local settings\application data\asam.exe" =-
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
===================================================

Malwarebytes' Anti-Malware
Download Malwarebytes' Anti-Malware here and save to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program. (Note to Vista users, please right-click and select Run as Administrator.)
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

On your next reply please post :
OTL log
MBAM log
How is the computer running?

Good Day!
All processes killed ========== OTL ========== No active process named asam.exe was found! No active process named mqhlgwvtssd.exe was found! Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\asam not found. File C:\Documents and Settings\John\Local Settings\Application Data\asam.exe not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\lfgwemtr not found. File C:\Documents and Settings\John\Local Settings\Application Data\tiysatkin\mqhlgwvtssd.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\asam not found. File C:\Documents and Settings\John\Local Settings\Application Data\asam.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\lfgwemtr not found. File C:\Documents and Settings\John\Local Settings\Application Data\tiysatkin\mqhlgwvtssd.exe not found. C:\Documents and Settings\John\Local Settings\Application Data\tiysatkin folder moved successfully. C:\Documents and Settings\John\Local Settings\Application Data\syssvc.exe moved successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully! C:\WINDOWS\herjek.config moved successfully. ========== FILES ========== File\Folder C:\Documents and Settings\John\Local Settings\Application Data\asam.exe not found. File\Folder C:\Documents and Settings\John\Local Settings\Application Data\tiysatkin\mqhlgwvtssd.exe not found. ========== REGISTRY ========== Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\c:\documents and settings\john\local settings\application data\asam.exe not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 41 bytes User: John ->Temp folder emptied: 383634363 bytes ->Temporary Internet Files folder emptied: 84775788 bytes ->Java cache emptied: 50075177 bytes ->FireFox cache emptied: 86526471 bytes ->Google Chrome cache emptied: 37721178 bytes ->Opera cache emptied: 1509557927 bytes ->Flash cache emptied: 77348 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 98520 bytes ->Flash cache emptied: 405 bytes User: NetworkService ->Temp folder emptied: 566146 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2362987 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 83499122 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 427158090 bytes Total Files Cleaned = 2,543.00 mb OTL by OldTimer - Version 3.2.3.0 log created on 05012010_005741 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
C:\Documents and Settings\John\My Documents\img001.jpg C:\Documents and Settings\John\Desktop\img001.jpg These are legit files I saved. They are my acceptance letters mailed to me from the University of Pennsylvania. I saved the file recently in 2 locations because it is an important document.
Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4052 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 5/1/2010 1:23:36 AM mbam-log-2010-05-01 (01-23-36).txt Scan type: Quick scan Objects scanned: 119772 Time elapsed: 6 minute(s), 17 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\avsuite (Rogue.AntivirusSuite) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
I am not sure how the computer is running. I am not doing anything (certainly not downloading torrents) while following your instructions. I leave the computer off until you reply to a post. Then I turn it on long enough to do exactly what you say and turn it off again.
Hi,

Please re-run OTL tools this time without copy pasting the custom scans command given in my earlier post.

===================================================

Eset online scannner

You can use either Internet Explorer or Mozilla FireFox for this scan.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish.
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.
===================================================

On your next reply please post :
OTL log
ESET log

Good Day!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI