This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

 Browser Freezes

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My Firefox has been freezing and I wait a few secs and it "lets Go". Then pulling the side bar or scrolling it freezes the lets go again. Typing this it freezes and then the words finish. I go on ebay and click the pictures to enlarge and it takes forever to get the window to come up. Any help deeply appreciated…Thank you…Lynne :) I'm trying to get a screen shot of what it does. I get the hour glass then it unfreezes and on Ebay not all the pictures will show. Screen shot uploaded.

Attachments:

Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post
•Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
•This may cause a delay in response time, but I will do my best to keep it as short as possible.
•I will reply back shortly with instructions.
Hi, Thank you. I did get the pop up thing fixed by turning off a couple of add-on's in Firefox. However I still have the problem of Ebay and some other sites doing what was posted in the attachment. The web page loads with the gallery pictures then the screen does a slight blip and they show like the attachment. Not all do this but most.
Hello Starwalker.Please do the following.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER won't run try with devices unchecked.If still no go try in safe mode.

In your next reply please post the following.
  • Both OTL logs
  • GMER log
OTL logfile created on: 5/29/2010 10:26:23 PM - Run 1
OTL by OldTimer - Version 3.2.5.1 Folder = C:\Documents and Settings\Starwalker\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 70.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 3072 4096 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 13.31 Gb Free Space | 35.72% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 931.51 Gb Total Space | 904.68 Gb Free Space | 97.12% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-2
Current User Name: Starwalker
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/05/29 22:25:07 | 000,571,392 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Starwalker\desktop\OTL.exe
PRC - [2010/05/06 15:59:42 | 002,815,192 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/05/06 15:59:38 | 000,040,384 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/04/30 06:06:31 | 000,353,736 | —- | M] (IncrediMail, Ltd.) – C:\Program Files\IncrediMail\bin\IncMail.exe
PRC - [2010/04/30 06:06:30 | 000,247,240 | —- | M] (IncrediMail, Ltd.) – C:\Program Files\IncrediMail\bin\ImApp.exe
PRC - [2010/04/15 08:25:20 | 001,872,320 | —- | M] (Emsi Software GmbH) – C:\Program Files\a-squared Free\a2service.exe
PRC - [2010/04/02 01:06:14 | 000,910,296 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/05/19 12:36:18 | 000,240,512 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2008/05/19 12:13:20 | 000,057,344 | —- | M] (Nalpeiron Ltd.) – C:\WINDOWS\system32\ASTSRV.EXE
PRC - [2008/05/09 20:42:21 | 000,068,856 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2001/08/17 17:36:42 | 000,024,064 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\system32\devldr32.exe


========== Modules (SafeList) ==========

MOD - [2010/05/29 22:25:07 | 000,571,392 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Starwalker\desktop\OTL.exe
MOD - [2008/04/13 19:10:20 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - [2010/05/06 15:59:38 | 000,040,384 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Web Scanner)
SRV - [2010/05/06 15:59:38 | 000,040,384 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Mail Scanner)
SRV - [2010/05/06 15:59:38 | 000,040,384 | —- | M] (ALWIL Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Antivirus)
SRV - [2010/04/15 08:25:20 | 001,872,320 | —- | M] (Emsi Software GmbH) [Auto | Running] – C:\Program Files\a-squared Free\a2service.exe – (a2free)
SRV - [2009/05/19 12:36:18 | 000,240,512 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort)
SRV - [2008/05/19 12:13:20 | 000,057,344 | —- | M] (Nalpeiron Ltd.) [Auto | Running] – C:\WINDOWS\system32\ASTSRV.EXE – (ASTSRV)
SRV - [2008/05/01 16:16:33 | 000,654,848 | —- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)


========== Driver Services (SafeList) ==========

DRV - [2010/05/28 06:04:52 | 000,014,896 | —- | M] (Secunia) [File_System | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\psi_mf.sys – (PSI)
DRV - [2010/05/15 03:17:25 | 000,068,168 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/05/06 15:39:23 | 000,046,672 | —- | M] (ALWIL Software) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\aswTdi.sys – (aswTdi)
DRV - [2010/05/06 15:39:00 | 000,164,048 | —- | M] (ALWIL Software) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\aswSP.sys – (aswSP)
DRV - [2010/05/06 15:34:27 | 000,023,376 | —- | M] (ALWIL Software) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\aswRdr.sys – (aswRdr)
DRV - [2010/05/06 15:33:59 | 000,100,432 | —- | M] (ALWIL Software) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\aswmon2.sys – (aswMon2)
DRV - [2010/05/06 15:33:47 | 000,019,024 | —- | M] (ALWIL Software) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\aswFsBlk.sys – (aswFsBlk)
DRV - [2010/05/06 15:33:29 | 000,028,880 | —- | M] (ALWIL Software) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\aavmker4.sys – (Aavmker4)
DRV - [2010/02/19 16:05:16 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS – (SASDIFSV)
DRV - [2010/02/19 16:05:16 | 000,012,872 | —- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS – (SASENUM)
DRV - [2008/04/13 13:45:30 | 000,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum)
DRV - [2008/02/27 13:49:00 | 000,003,840 | —- | M] () [Kernel | System | Running] – C:\windows\System32\Drivers\BANTExt.sys – (BANTExt)
DRV - [2008/01/05 16:14:47 | 000,102,664 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\tmcomm.sys – (tmcomm)
DRV - [2006/10/22 13:22:00 | 003,994,624 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2006/09/24 08:28:46 | 000,005,248 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Boot | Running] – C:\windows\system32\speedfan.sys – (speedfan)
DRV - [2004/08/03 22:31:34 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\rtl8139.sys – (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2003/03/05 13:19:28 | 000,015,840 | —- | M] (Creative Technology Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\PFMODNT.SYS – (PfModNT)
DRV - [2002/10/29 15:24:42 | 000,033,280 | —- | M] (DAVICOM Semiconductor, Inc. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\DM9PCI5.SYS – (DM9102)
DRV - [2002/06/23 16:31:20 | 000,045,568 | R— | M] (D-Link Corporation ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\DLKRTS.SYS – (DLKRTS)
DRV - [2001/08/17 07:50:26 | 000,731,648 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nv4.sys – (nv4)
DRV - [2001/08/17 07:19:34 | 000,036,480 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sfmanm.sys – (sfman) Creative SoundFont Manager Driver (WDM)
DRV - [2001/08/17 07:19:28 | 000,006,912 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctlfacem.sys – (emu10k1) Creative Interface Manager Driver (WDM)
DRV - [2001/08/17 07:19:26 | 000,283,904 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\emu10k1m.sys – (emu10k) Creative SB Live! (WDM)
DRV - [2001/08/17 07:19:20 | 000,003,712 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ctljystk.sys – (ctljystk)
DRV - [2001/05/14 18:15:40 | 000,010,368 | —- | M] (Dell Computer Corporation) [Kernel | System | Running] – C:\windows\SYSTEM32\DRIVERS\OMCI.SYS – (OMCI)
DRV - [1996/04/03 14:33:26 | 000,005,248 | —- | M] () [Kernel | Boot | Running] – C:\windows\system32\giveio.sys – (giveio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://news.yahoo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://eis.esnips.com/page/search/?client_…d2-41fde8d1391d

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = yahoo.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Reganam Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p="
FF - prefs.js..browser.search.order.1: "eSnips Search"
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.1.1
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 44
FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.6
FF - prefs.js..extensions.enabledItems: {249df6a2-e336-47d1-b6c3-ec711ad140ca}:0.5.0.00021
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {c50ca3c4-5656-43c2-a061-13e717f73fc8}:3.0.8
FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.0.5
FF - prefs.js..extensions.enabledItems: {1392b8d2-5c05-419f-a8f6-b9f15a596612}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:0.4.1.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.1.6
FF - prefs.js..extensions.enabledItems: {db9d7a78-a76c-4bf2-97c6-258925ee1542}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.6.7
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {c33c5b47-69c8-45a4-a5e0-af85bbe628dd}:[removed]
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}:1.0
FF - prefs.js..extensions.enabledItems: {95f24680-9e31-11da-a746-0800200c9a66}:0.1.5.5
FF - prefs.js..keyword.URL: "http://mystart.incredimail.com/?loc=ff_address_bar_im2_test_v2&search="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"


FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.17\extensions\\Components: F:\PORTAB~1\FIREFO~1\APP\firefox\components
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.17\extensions\\Plugins: F:\PORTAB~1\FIREFO~1\APP\firefox\plugins
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/16 01:41:44 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/25 23:50:30 | 000,000,000 | —D | M]

[2008/10/30 01:10:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Extensions
[2010/05/29 17:35:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions
[2010/05/08 22:13:02 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2010/05/08 22:13:01 | 000,000,000 | —D | M] (Flagfox) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2010/02/15 16:37:08 | 000,000,000 | —D | M] (Freecorder Toolbar) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2010/04/26 22:26:13 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/04 21:43:02 | 000,000,000 | —D | M] (eBay Toolbar) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{249df6a2-e336-47d1-b6c3-ec711ad140ca}
[2010/04/09 01:29:16 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/05/25 23:54:26 | 000,000,000 | —D | M] (Update Notifier) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{95f24680-9e31-11da-a746-0800200c9a66}
[2010/05/12 10:20:55 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/04/08 02:49:40 | 000,000,000 | —D | M] (Interclue) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{c33c5b47-69c8-45a4-a5e0-af85bbe628dd}
[2009/11/19 12:10:17 | 000,000,000 | —D | M] (Fast Video Download (with SearchMenu)) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
[2010/05/21 00:24:06 | 000,000,000 | —D | M] (flashget3 Extension) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}
[2010/02/11 00:38:31 | 000,000,000 | —D | M] (Reganam Toolbar) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{db9d7a78-a76c-4bf2-97c6-258925ee1542}
[2009/09/10 10:40:48 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/03/01 00:30:21 | 000,000,000 | —D | M] (SweetIM Toolbar for Firefox) – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2010/05/15 03:18:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]
[2010/03/16 19:00:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]
[2009/03/15 23:13:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]
[2010/03/25 18:03:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]
[2010/03/29 02:39:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]
[2010/04/01 02:17:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]
[2010/05/20 02:01:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]
[2010/05/10 23:57:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]
[2009/08/06 13:40:06 | 000,002,836 | —- | M] () – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\searchplugins\bing.xml
[2010/04/30 06:04:34 | 000,002,149 | —- | M] () – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\searchplugins\MyStart Search.xml
[2009/11/19 12:14:54 | 000,003,915 | —- | M] () – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\searchplugins\sweetim.xml
[2010/05/27 23:22:24 | 000,001,952 | —- | M] () – C:\Documents and Settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\searchplugins\thomasnet-industrial-search.xml
[2010/05/29 17:35:26 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/14 03:43:58 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/05/18 12:26:29 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2010/04/29 20:50:24 | 000,024,576 | —- | M] (My Web Search) – C:\Program Files\Mozilla Firefox\plugins\NPMySrWB.dll
[2010/03/19 18:59:38 | 000,238,776 | —- | M] (Pando Networks) – C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll

O1 HOSTS File: ([2010/02/09 01:40:50 | 000,612,589 | —- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 achmedia.com
O1 - Hosts: 127.0.0.1 aconti.net
O1 - Hosts: 127.0.0.1 secure.aconti.net
O1 - Hosts: 127.0.0.1 www.aconti.net #[Dialer.Aconti]
O1 - Hosts: 127.0.0.1 ads.active.com
O1 - Hosts: 127.0.0.1 am1.activemeter.com
O1 - Hosts: 127.0.0.1 www.activemeter.com #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ads.activepower.net
O1 - Hosts: 127.0.0.1 data2.activshopper.com #[Trackware.ActivShopper]
O1 - Hosts: 127.0.0.1 stat.active24stats.nl #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ad2games.com
O1 - Hosts: 127.0.0.1 cms.ad2click.nl
O1 - Hosts: 127.0.0.1 ads.ad2games.com
O1 - Hosts: 127.0.0.1 content.ad20.net
O1 - Hosts: 16208 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (no name) - {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - No CLSID value found.
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [NvCplDaemon] C:\windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103472 -Mozilla\5.0 ( File not found
O4 - Startup: C:\Documents and Settings\Starwalker\Start Menu\Programs\Startup\Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe (Secunia)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 67
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O15 - HKCU\..Trusted Domains: fnismls.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: getmedianow.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: kuaiche.com ([software] http in Trusted sites)
O15 - HKCU\..Trusted Domains: live.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: showingtime.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sitexdata.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: spellchecker.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: transactionpoint.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: trpoint.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: virtualearth.net ([]* in Trusted sites)
O16 - DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} http://static.ak.facebook.com/fbplugin/win…fbootloader.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Starwalker\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Starwalker\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/04/17 22:44:26 | 000,000,000 | —D | M] - F:\AutoFX.Mystical.Tint.Tone.and.Color.v2.0-FOSI – [ NTFS ]
O32 - AutoRun File - [2010/04/17 21:52:53 | 062,549,674 | —- | M] () - F:\AutoFX.Mystical.Tint.Tone.and.Color.v2.0-FOSI.rar – [ NTFS ]
O33 - MountPoints2\{70f5008a-175d-11df-bd31-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{70f5008a-175d-11df-bd31-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{70f5008a-175d-11df-bd31-806d6172696f}\Shell\AutoRun\command - "" = D:\AutoRun\AutoRun.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (autocheck lsdelete) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2007/07/05 23:27:12 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010/05/29 22:25:06 | 000,571,392 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Starwalker\Desktop\OTL.exe
[2010/05/29 22:24:48 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Starwalker\Recent
[2010/05/28 22:29:47 | 000,000,000 | —D | C] – C:\Program Files\Secunia
[2010/05/28 06:04:52 | 000,014,896 | —- | C] (Secunia) – C:\windows\System32\drivers\psi_mf.sys
[2010/05/19 01:13:45 | 000,000,000 | R–D | C] – C:\Documents and Settings\Starwalker\Desktop\Icons
[2010/05/18 23:37:33 | 000,057,344 | —- | C] (Nalpeiron Ltd.) – C:\windows\System32\ASTSRV.EXE
[2010/05/18 22:38:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Starwalker\Application Data\ThumbsPlus
[2010/05/18 22:35:40 | 000,000,000 | —D | C] – C:\Program Files\Thumbs7
[2010/05/18 22:29:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Starwalker\Application Data\Auto FX Software
[2010/05/18 22:27:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Starwalker\Application Data\ThePluginSite
[2010/05/18 22:27:22 | 000,000,000 | —D | C] – C:\Program Files\FocalBlade2
[2010/05/18 12:29:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Starwalker\Desktop\Readers
[2010/05/18 12:28:13 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Foxit Software
[2010/05/14 11:46:29 | 000,000,000 | R–D | C] – C:\Documents and Settings\Starwalker\Desktop\chickens
[2010/05/14 03:43:55 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\windows\System32\deployJava1.dll
[2010/05/14 03:43:55 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\windows\System32\javaws.exe
[2010/05/14 03:43:55 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\windows\System32\javaw.exe
[2010/05/14 03:43:55 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\windows\System32\java.exe
[2010/05/11 03:57:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Starwalker\Application Data\Facebook
[2010/05/04 14:38:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Starwalker\Desktop\Funeral
[29 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/05/29 22:30:04 | 000,284,915 | —- | M] () – C:\Documents and Settings\Starwalker\Desktop\gmer.zip
[2010/05/29 22:25:07 | 000,571,392 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Starwalker\Desktop\OTL.exe
[2010/05/29 22:23:08 | 000,000,894 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/29 22:01:07 | 000,000,244 | —- | M] () – C:\windows\tasks\Scheduled Update for Ask Toolbar.job
[2010/05/29 19:23:13 | 000,000,890 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/29 13:02:21 | 000,000,868 | —- | M] () – C:\windows\tasks\Google Software Updater.job
[2010/05/29 11:17:03 | 000,509,392 | —- | M] () – C:\windows\System32\PerfStringBackup.INI
[2010/05/29 11:17:03 | 000,432,664 | —- | M] () – C:\windows\System32\perfh009.dat
[2010/05/29 11:17:03 | 000,067,428 | —- | M] () – C:\windows\System32\perfc009.dat
[2010/05/29 11:12:43 | 000,000,322 | —- | M] () – C:\windows\tasks\GlaryInitialize.job
[2010/05/29 11:12:36 | 000,000,006 | -H– | M] () – C:\windows\tasks\SA.DAT
[2010/05/29 11:12:17 | 000,088,566 | —- | M] () – C:\windows\System32\nvapps.xml
[2010/05/29 11:11:34 | 000,002,048 | –S- | M] () – C:\windows\bootstat.dat
[2010/05/29 11:11:26 | 2146,516,992 | -HS- | M] () – C:\hiberfil.sys
[2010/05/29 03:41:09 | 014,680,064 | —- | M] () – C:\Documents and Settings\Starwalker\ntuser.dat
[2010/05/29 03:41:09 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Starwalker\ntuser.ini
[2010/05/28 22:30:00 | 000,000,727 | —- | M] () – C:\Documents and Settings\Starwalker\Start Menu\Programs\Startup\Secunia PSI.lnk
[2010/05/28 22:21:58 | 000,000,682 | —- | M] () – C:\Documents and Settings\Starwalker\Desktop\Glary Utilities.lnk
[2010/05/28 06:04:52 | 000,014,896 | —- | M] (Secunia) – C:\windows\System32\drivers\psi_mf.sys
[2010/05/24 02:21:23 | 000,077,389 | —- | M] () – C:\Documents and Settings\Starwalker\Desktop\vs17_129.pdf
[2010/05/24 00:26:57 | 000,000,245 | —- | M] () – C:\Documents and Settings\Starwalker\My Documents\Document-seeds.rtf
[2010/05/21 00:30:24 | 000,000,336 | —- | M] () – C:\windows\System32\secustat.dat
[2010/05/21 00:14:24 | 000,000,891 | —- | M] () – C:\windows\System32\secushr.dat
[2010/05/19 04:05:11 | 004,773,328 | -H– | M] () – C:\Documents and Settings\Starwalker\Local Settings\Application Data\IconCache.db
[2010/05/19 01:05:11 | 000,000,618 | —- | M] () – C:\Documents and Settings\All Users\Desktop\ThumbsPlus 7.lnk
[2010/05/16 13:46:13 | 000,000,811 | —- | M] () – C:\windows\lexstat.ini
[2010/05/11 13:43:57 | 000,014,848 | —- | M] () – C:\Documents and Settings\Starwalker\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/07 03:46:33 | 000,002,626 | —- | M] () – C:\windows\System32\CONFIG.NT
[2010/05/07 03:40:02 | 000,002,206 | —- | M] () – C:\windows\System32\wpa.dbl
[2010/05/06 15:59:36 | 000,165,032 | —- | M] (ALWIL Software) – C:\windows\System32\aswBoot.exe
[2010/05/06 15:39:23 | 000,046,672 | —- | M] (ALWIL Software) – C:\windows\System32\drivers\aswTdi.sys
[2010/05/06 15:39:00 | 000,164,048 | —- | M] (ALWIL Software) – C:\windows\System32\drivers\aswSP.sys
[2010/05/06 15:34:27 | 000,023,376 | —- | M] (ALWIL Software) – C:\windows\System32\drivers\aswRdr.sys
[2010/05/06 15:33:59 | 000,100,432 | —- | M] (ALWIL Software) – C:\windows\System32\drivers\aswmon2.sys
[2010/05/06 15:33:55 | 000,094,800 | —- | M] (ALWIL Software) – C:\windows\System32\drivers\aswmon.sys
[2010/05/06 15:33:47 | 000,019,024 | —- | M] (ALWIL Software) – C:\windows\System32\drivers\aswFsBlk.sys
[2010/05/06 15:33:29 | 000,028,880 | —- | M] (ALWIL Software) – C:\windows\System32\drivers\aavmker4.sys
[2010/05/05 03:41:31 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/04/30 06:07:11 | 000,001,750 | —- | M] () – C:\Documents and Settings\All Users\Desktop\IncrediMail.lnk
[29 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/28 22:30:00 | 000,000,727 | —- | C] () – C:\Documents and Settings\Starwalker\Start Menu\Programs\Startup\Secunia PSI.lnk
[2010/05/24 01:33:58 | 000,077,389 | —- | C] () – C:\Documents and Settings\Starwalker\Desktop\vs17_129.pdf
[2010/05/24 00:26:57 | 000,000,245 | —- | C] () – C:\Documents and Settings\Starwalker\My Documents\Document-seeds.rtf
[2010/05/18 22:35:54 | 000,000,618 | —- | C] () – C:\Documents and Settings\All Users\Desktop\ThumbsPlus 7.lnk
[2010/05/11 19:18:47 | 000,000,894 | —- | C] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/11 19:18:47 | 000,000,890 | —- | C] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/30 06:07:11 | 000,001,750 | —- | C] () – C:\Documents and Settings\All Users\Desktop\IncrediMail.lnk
[2010/03/25 22:08:36 | 000,000,025 | —- | C] () – C:\windows\libem.INI
[2010/02/13 01:00:58 | 000,000,116 | —- | C] () – C:\windows\NeroDigital.ini
[2009/10/13 17:49:20 | 000,230,752 | —- | C] () – C:\windows\patchw32.dll
[2009/01/31 12:39:09 | 000,003,840 | —- | C] () – C:\windows\System32\drivers\BANTExt.sys
[2008/10/29 13:25:37 | 000,000,049 | —- | C] () – C:\windows\System32\WRKVersion.ini
[2008/05/03 04:18:15 | 000,296,448 | —- | C] () – C:\windows\Xenofex.ini
[2008/01/24 21:59:23 | 000,000,670 | —- | C] () – C:\windows\nvrbm.ini
[2008/01/14 02:55:37 | 000,014,848 | —- | C] () – C:\windows\System32\BASSMOD.dll
[2008/01/06 00:34:46 | 000,005,515 | —- | C] () – C:\windows\fmachine.ini
[2007/11/05 12:16:51 | 000,000,061 | —- | C] () – C:\windows\PureEdgeAPI.ini
[2007/11/05 12:16:47 | 000,167,936 | —- | C] () – C:\windows\System32\MSQOLE.DLL
[2007/10/29 00:03:59 | 000,000,089 | —- | C] () – C:\windows\ULead32.ini
[2007/10/29 00:03:01 | 000,000,039 | —- | C] () – C:\windows\Wininit.ini
[2007/10/29 00:02:56 | 000,035,328 | —- | C] () – C:\windows\INETWH32.DLL
[2007/10/29 00:02:56 | 000,009,136 | —- | C] () – C:\windows\INETWH16.DLL
[2007/10/26 01:52:34 | 000,000,144 | —- | C] () – C:\windows\Eudcedit.ini
[2007/10/25 23:07:38 | 000,005,515 | —- | C] () – C:\windows\System32\fmachine.ini
[2007/10/15 04:38:46 | 000,373,248 | —- | C] () – C:\windows\EyeCand3.INI
[2007/10/02 17:59:26 | 000,210,944 | —- | C] () – C:\windows\System32\Msvcrt10.dll
[2007/10/02 17:59:25 | 000,057,344 | —- | C] () – C:\windows\System32\icmfilter.dll
[2007/07/18 12:11:22 | 000,004,096 | —- | C] () – C:\windows\System32\sysres.dll
[2007/07/07 23:10:53 | 000,000,811 | —- | C] () – C:\windows\lexstat.ini
[2006/10/22 13:22:00 | 001,662,976 | —- | C] () – C:\windows\System32\nvwdmcpl.dll
[2006/10/22 13:22:00 | 001,019,904 | —- | C] () – C:\windows\System32\nvwimg.dll
[2006/10/22 13:22:00 | 000,581,632 | —- | C] () – C:\windows\System32\nvhwvid.dll
[2006/10/22 13:22:00 | 000,286,720 | —- | C] () – C:\windows\System32\nvnt4cpl.dll
[2006/10/22 13:22:00 | 000,212,992 | —- | C] () – C:\windows\System32\nvapi.dll
[2003/08/18 05:46:38 | 000,077,824 | —- | C] () – C:\windows\System32\LXBKLCNP.DLL
[2003/07/28 16:19:00 | 001,470,464 | —- | C] () – C:\windows\System32\nview.dll
[2003/07/28 16:19:00 | 000,466,944 | —- | C] () – C:\windows\System32\nvshell.dll
[2002/11/13 10:40:22 | 000,040,960 | —- | C] () – C:\windows\System32\lxbkvs.dll
[2002/09/13 06:40:06 | 000,000,266 | —- | C] () – C:\windows\System32\lxbkcoin.ini
[1996/04/03 14:33:26 | 000,005,248 | —- | C] () – C:\windows\System32\giveio.sys

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[1996/10/24 17:45:24 | 000,059,952 | —- | M] () – C:\UNWISE.EXE


< MD5 for: AGP440.SYS >
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/01/03 14:06:23 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2009/01/03 14:06:23 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\AGP440.SYS

< MD5 for: ATAPI.SYS >
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/01/03 14:06:23 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2009/01/03 14:06:23 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 00:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 00:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 00:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 04:31:44 | 000,348,160 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtmsft.dll
[2009/03/08 04:31:38 | 000,216,064 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtrans.dll
[29 C:\windows\system32\*.tmp files -> C:\windows\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2007/07/05 18:13:17 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2007/07/05 18:13:17 | 000,606,208 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2007/07/05 18:13:17 | 000,393,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav

========== Alternate Data Streams ==========

@Alternate Data Stream - 187 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A31FAD21
@Alternate Data Stream - 168 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C5760A8B
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
OTL Extras logfile created on: 5/29/2010 10:26:23 PM - Run 1
OTL by OldTimer - Version 3.2.5.1 Folder = C:\Documents and Settings\Starwalker\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 70.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 3072 4096 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 13.31 Gb Free Space | 35.72% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 931.51 Gb Total Space | 904.68 Gb Free Space | 97.12% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-2
Current User Name: Starwalker
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
https [open] – F:\PORTAB~1\FIREFO~1\APP\FIREFOX\FIREFOX.EXE -requestPending -osint -url "%1" File not found
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Browse with XnView] – "C:\Program Files\XnView\xnview.exe" "%1" (XnView, http://www.xnview.com)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"59165:TCP" = 59165:TCP:*:Enabled:Pando
"59165:UDP" = 59165:UDP:*:Enabled:Pando

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\IncrediMail\bin\ImApp.exe" = C:\Program Files\IncrediMail\bin\ImApp.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\IncrediMail\bin\IncMail.exe" = C:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\IncrediMail\bin\ImpCnt.exe" = C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\IncrediMail\bin\ImLc.exe" = C:\Program Files\IncrediMail\bin\ImLc.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console – (Microsoft Corporation)
"C:\Program Files\IncrediMail\bin\ImPackr.exe" = C:\Program Files\IncrediMail\bin\ImPackr.exe:*:Enabled:IncrediMail – ()
"C:\Program Files\IncrediMail\bin\IncrediMail_Install.exe" = C:\Program Files\IncrediMail\bin\IncrediMail_Install.exe:*:Enabled:IncrediMail Installer – ()
"C:\Program Files\IncrediMail\bin\ImSc.exe" = C:\Program Files\IncrediMail\bin\ImSc.exe:*:Enabled:IncrediMail – (IncrediMail)
"C:\WINDOWS\system32\rtcshare.exe" = C:\WINDOWS\system32\rtcshare.exe:*:Enabled:RTC App Sharing – (Microsoft Corporation)
"C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\helpctr.exe" = C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\helpctr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice – (Microsoft Corporation)
"C:\Program Files\firefox.exe" = C:\Program Files\firefox.exe:*:Enabled:Firefox – File not found
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager – File not found
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\Program Files\TeamViewer\Version5\TeamViewer.exe" = C:\Program Files\TeamViewer\Version5\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application – (TeamViewer GmbH)
"C:\Program Files\Pando Networks\Pando\Pando.exe" = C:\Program Files\Pando Networks\Pando\Pando.exe:*:Enabled:Pando – (Pando Networks)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{15382D89-6EF6-4D21-9484-B500F2B10E46}" = PhotoMail Maker
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{18DB3375-0649-4EA3-959A-44F1ACD278BA}" = IncrediMail
"{1A15507A-8551-4626-915D-3D5FA095CC1B}" = Corel Paint Shop Pro X
"{1BCEA516-B4C5-4B2D-BFA0-AB7910BAD862}" = Adobe ExtendScript Toolkit 2
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F701DBD-1660-4108-B10A-FB435EA63BF0}" = PostgreSQL 8.2
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2086A549-ED96-4dc9-BBE3-0538AB29ABEC}" = PSP Thumbnail Handler
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java™ 6 Update 20
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{538D98C6-CFC9-4BD3-B373-653B7A382CE8}" = IE2K
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5C474A83-A45F-470C-9AC8-2BD1C251BF9A}" = Skype™ 4.2
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6ADD0603-16EF-400D-9F9E-486432835002}" = OpenOffice.org 3.2
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7C4196CA-CA41-4F34-9C08-7724E7705D52}" = Jasc Animation Shop 3
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{8F018A9E-56DE-4A79-A5EF-25F413F1D538}" = WeatherBug
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{961034C0-58DF-11DF-97FD-005056806466}" = Google Earth Plug-in
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB480DA0-7EE9-465D-9C12-4CDE65BF18FB}" = Pando
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B39DC03B-F2C0-4F7E-B1DD-328F73BD98FD}" = Font Thumbnail
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C6F34AE0-0576-11d4-82FE-4491FCC00000}" = IconViewer
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D1BB4446-AE9C-4256-9A7F-4D46604D2462}" = Adobe Setup
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7 ESD
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{DF6F459C-8B89-4F88-B63F-A2E136BB6B79}" = SweetIM for Messenger 2.8
"{E0000600-0600-0600-0600-000000000600}" = ICS Viewer 6.0
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F45298E5-0083-426F-A668-1A2C5F04B8A0}" = FaxTools
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F843C6A3-224D-4615-94F8-3C461BD9AEA0}" = Jasc Paint Shop Pro 9
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe® Flash® Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe® Flash® Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_2ac78060bc5856b0c1cf873bb919b58" = Adobe Photoshop CS3
"a-squared Free_is1" = a-squared Free 4.5
"avast5" = avast! Free Antivirus
"Belarc Advisor" = Belarc Advisor 8.1
"Belltech Label Maker With Data Merge 2.0_is1" = Belltech Label Maker With Data Merge 2.0
"Branding" =
"CCleaner" = CCleaner
"CleanUp!" = CleanUp!
"Connection Manager" =
"Direct MP3 Joiner_is1" = Direct MP3 Joiner version 3.0.1.5
"DiskCleaner" = Disk Cleaner (remove only)
"DreamLight Photo Editor_is1" = DreamLight Photo Editor 2.38
"DVD Photo Slideshow Professional" = DVD Photo Slideshow Pro 7.97
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"Eye Candy 3" = Eye Candy 3
"Eye Candy 6" = Alien Skin Eye Candy 6
"FocalBlade 2.0 Plugin_is1" = FocalBlade 2.0 Plugin
"Foxit Creator" = Foxit Creator
"Foxit PDF Editor" = Foxit PDF Editor
"Foxit Reader" = Foxit Reader
"Freecorder4.0" = Freecorder 4.0 Application
"Glary Utilities_is1" = Glary Utilities 2.23.0.923
"Google Updater" = Google Updater
"GTK 2.0" = GTK+ Runtime 2.12.12 rev a (remove only)
"Helicon Filter_is1" = Helicon Filter 4.86.1
"Home Cookin 5.9_is1" = Home Cookin 5.9
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"ImageSkillTranslucator" = ImageSkill Translucator (remove only)
"IncrediMail" = IncrediMail 2.0
"IncrediMail Collection Manager" = IncrediMail Collection Manager
"IncrediMail Data Manager" = IncrediMail Data Manager
"InstallShield Uninstall Information" =
"InstallShield_{538D98C6-CFC9-4BD3-B373-653B7A382CE8}" = Dell Picture Studio - Image Expert 2000
"Jasc Animation Shop 3 20041030_07 Help file Patch" = Jasc Animation Shop 3 20041030_07 Help file Patch
"Jasc Paint Shop Pro 9 GDI+ Patch" = Jasc Paint Shop Pro 9 GDI+ Patch
"Jasc Paint Shop Pro 9.01 - (9.0.1.1)" = Jasc Paint Shop Pro 9.01 - (9.0.1.1)
"Jasc Paint Shop Pro 9.01 Patch" = Jasc Paint Shop Pro 9.01 Patch
"Kaspersky Online Scanner" = Kaspersky Online Scanner
"Lexmark X1100 Series" = Lexmark X1100 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSI30a-KB884016" =
"MSI30-Beta1" =
"MSI30-Beta2" =
"MSI30-KB884016" =
"MSI30-RC1" =
"MSI30-RC2" =
"MSI31-Beta" =
"MSI31-RC1" =
"MVApplication1" = Memorex exPressit Label Design Studio
"MysticalTTC" = Uninstall MysticalTTC
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NSS" = Norton Security Scan
"NVIDIA Drivers" = NVIDIA Drivers
"PCHealth" =
"Pegtop XFader" = Pegtop XFader
"PhotoMail" = PhotoMail Maker
"Replay Converter 3" = Replay Converter 3
"Revo Uninstaller" = Revo Uninstaller 1.88
"Secunia PSI" = Secunia PSI
"Skin Creator" = Skin Creator
"SpeedFan" = SpeedFan (remove only)
"SpywareBlaster_is1" = SpywareBlaster 4.3
"SystemRequirementsLab" = System Requirements Lab
"TeamViewer 5" = TeamViewer 5
"The Font Thing" = The Font Thing
"ThumbsPlus" = ThumbsPlus 7.0 SP1 Build 2234
"ThumbsPlus7" = ThumbsPlus version 7.0
"Trend Micro HouseCall 6.6" = HouseCall 6.6
"Tweak UI 2.10" = Tweak UI
"Ulead ArtTexture.Plugin 1.0" = Ulead ArtTexture.Plugin 1.0
"VLC media player" = VLC media player 1.0.5
"WeatherBug" = WeatherBug
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPatrol" = WinPatrol 2009
"WinRAR archiver" = WinRAR archiver
"WMCSetup" =
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xenofex2" = Alien Skin Xenofex 2.0
"XnView_is1" = XnView 1.97.2

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"DAL Scanner" = DAL Scanner
"f031ef6ac137efc5" = Dell Driver Download Manager
"Facebook Plug-In" = Facebook Plug-In

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/25/2010 9:23:40 PM | Computer Name = OWNER-2 | Source = Application Error | ID = 1000
Description = Faulting application psp.exe, version 7.0.0.4, faulting module mfc42.dll,
version 6.2.4131.0, fault address 0x00098f5a.

Error - 3/27/2010 1:31:05 AM | Computer Name = OWNER-2 | Source = Application Error | ID = 1000
Description = Faulting application psp.exe, version 7.0.0.4, faulting module mfc42.dll,
version 6.2.4131.0, fault address 0x00098f5a.

Error - 3/28/2010 2:23:45 PM | Computer Name = OWNER-2 | Source = Application Error | ID = 1000
Description = Faulting application psp.exe, version 7.0.0.4, faulting module mfc42.dll,
version 6.2.4131.0, fault address 0x00098f5a.

Error - 3/30/2010 9:01:43 PM | Computer Name = OWNER-2 | Source = Application Error | ID = 1000
Description = Faulting application psp.exe, version 7.0.0.4, faulting module mfc42.dll,
version 6.2.4131.0, fault address 0x00098f5a.

Error - 4/3/2010 1:22:01 AM | Computer Name = OWNER-2 | Source = Application Error | ID = 1000
Description = Faulting application psp.exe, version 7.0.0.4, faulting module mfc42.dll,
version 6.2.4131.0, fault address 0x00098f5a.

Error - 4/12/2010 3:23:15 PM | Computer Name = OWNER-2 | Source = Application Error | ID = 1000
Description = Faulting application mysticalttc.exe, version 1.0.0.0, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x0000120e.

Error - 4/12/2010 3:45:06 PM | Computer Name = OWNER-2 | Source = Application Error | ID = 1000
Description = Faulting application mysticalttc.exe, version 1.0.0.0, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x0000120e.

Error - 4/12/2010 3:45:32 PM | Computer Name = OWNER-2 | Source = Application Error | ID = 1000
Description = Faulting application mysticalttc.exe, version 1.0.0.0, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x0000120e.

Error - 4/12/2010 10:24:46 PM | Computer Name = OWNER-2 | Source = Application Error | ID = 1000
Description = Faulting application mysticalttc.exe, version 1.0.0.0, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x0000120e.

Error - 5/20/2010 2:54:45 PM | Computer Name = OWNER-2 | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.2.3743, faulting module
npswf32.dll, version 10.1.51.66, fault address 0x002fe49d.

[ System Events ]
Error - 4/30/2010 3:25:35 AM | Computer Name = OWNER-2 | Source = DCOM | ID = 10010
Description = The server {D5E8041D-920F-45E9-B8FB-B1DEB82C6E5E} did not register
with DCOM within the required timeout.

Error - 4/30/2010 3:29:26 AM | Computer Name = OWNER-2 | Source = DCOM | ID = 10010
Description = The server {D5E8041D-920F-45E9-B8FB-B1DEB82C6E5E} did not register
with DCOM within the required timeout.

Error - 5/14/2010 4:08:30 PM | Computer Name = OWNER-2 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Dnscache service.

Error - 5/15/2010 2:38:31 AM | Computer Name = OWNER-2 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Dnscache service.

Error - 5/15/2010 4:17:29 AM | Computer Name = OWNER-2 | Source = Service Control Manager | ID = 7000
Description = The SASDIFSV service failed to start due to the following error: %%183

Error - 5/16/2010 2:38:24 PM | Computer Name = OWNER-2 | Source = Print | ID = 6161
Description = The document Copy from Lexmark X1100 Series All-In-One owned by Starwalker
failed to print on printer Lexmark X1100 Series (Copy 1). Data type: LEMF. Size
of the spool file in bytes: 1562546. Number of bytes printed: 1562546. Total number
of pages in the document: 1. Number of pages printed: 0. Client machine: \\OWNER-2.
Win32 error code returned by the print processor: 126 (0x7e).

Error - 5/16/2010 2:39:07 PM | Computer Name = OWNER-2 | Source = Print | ID = 6161
Description = The document Copy from Lexmark X1100 Series All-In-One owned by Starwalker
failed to print on printer Lexmark X1100 Series (Copy 1). Data type: LEMF. Size
of the spool file in bytes: 1562546. Number of bytes printed: 1562546. Total number
of pages in the document: 1. Number of pages printed: 0. Client machine: \\OWNER-2.
Win32 error code returned by the print processor: 126 (0x7e).

Error - 5/17/2010 6:50:29 PM | Computer Name = OWNER-2 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Dnscache service.

Error - 5/19/2010 2:13:43 AM | Computer Name = OWNER-2 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Dnscache service.

Error - 5/24/2010 5:02:57 PM | Computer Name = OWNER-2 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Dnscache service.


< End of report >
Hello Starwalker.Please do the following

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Hello starwalker,please do the following

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    DDS::
    Trusted Zone: fnismls.com
    Trusted Zone: getmedianow.com
    Trusted Zone: kuaiche.com\software
    Trusted Zone: live.com
    Trusted Zone: showingtime.com
    Trusted Zone: sitexdata.com
    Trusted Zone: spellchecker.net
    Trusted Zone: transactionpoint.com
    Trusted Zone: trpoint.com
    Trusted Zone: virtualearth.net
    
    RegNull::
    [HKEY_USERS\S-1-5-21-796845957-706699826-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6231081F-966B-C07D-59DB-9A3BE65E4114}*]
    [HKEY_USERS\S-1-5-21-796845957-706699826-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FC6F815C-487E-AA8F-848C-FB57828B94BA}*]
    
      
    RegLock::
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


Please do not attach the logs,use copy/paste
ComboFix 10-05-31.02 - Starwalker 05/31/2010 18:09:56.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1547 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Run These\Advanced\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2010-04-28 to 2010-05-31 )))))))))))))))))))))))))))))))
.

2010-05-29 03:29 . 2010-05-29 03:29 ——– d—–w- c:\program files\Secunia
2010-05-28 11:04 . 2010-05-28 11:04 14896 —-a-w- c:\windows\system32\drivers\psi_mf.sys
2010-05-25 19:25 . 2010-05-25 19:25 503808 —-a-w- c:\documents and settings\Starwalker\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4ae50dec-n\msvcp71.dll
2010-05-25 19:25 . 2010-05-25 19:25 499712 —-a-w- c:\documents and settings\Starwalker\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4ae50dec-n\jmc.dll
2010-05-25 19:25 . 2010-05-25 19:25 348160 —-a-w- c:\documents and settings\Starwalker\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4ae50dec-n\msvcr71.dll
2010-05-25 19:25 . 2010-05-25 19:25 61440 —-a-w- c:\documents and settings\Starwalker\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-494f992d-n\decora-sse.dll
2010-05-25 19:25 . 2010-05-25 19:25 12800 —-a-w- c:\documents and settings\Starwalker\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-494f992d-n\decora-d3d.dll
2010-05-21 05:24 . 2010-03-24 15:42 57418 —-a-w- c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}\components\FlashGetXPI.dll
2010-05-20 04:28 . 2010-05-20 04:28 2944904 —-a-w- c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]\chrome\temp\askToolbar.exe
2010-05-19 04:37 . 2008-05-19 17:13 57344 —-a-w- c:\windows\system32\ASTSRV.EXE
2010-05-19 04:21 . 2010-05-19 04:21 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\Foxit Software
2010-05-19 03:38 . 2010-05-19 03:38 ——– d—–w- c:\documents and settings\Starwalker\Application Data\ThumbsPlus
2010-05-19 03:35 . 2010-05-19 06:05 ——– d—–w- c:\program files\Thumbs7
2010-05-19 03:29 . 2010-05-19 03:29 ——– d—–w- c:\documents and settings\Starwalker\Application Data\Auto FX Software
2010-05-19 03:27 . 2010-05-19 03:27 ——– d—–w- c:\documents and settings\Starwalker\Application Data\ThePluginSite
2010-05-19 03:27 . 2010-05-19 03:27 ——– d—–w- c:\program files\FocalBlade2
2010-05-18 17:28 . 2010-05-18 17:28 ——– d—–w- c:\documents and settings\LocalService\Application Data\Foxit Software
2010-05-15 08:20 . 2010-05-15 08:20 63488 —-a-w- c:\documents and settings\Starwalker\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-05-14 08:43 . 2010-04-12 22:29 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-05-11 08:58 . 2010-05-11 08:58 50354 —-a-w- c:\documents and settings\Starwalker\Application Data\Facebook\uninstall.exe
2010-05-11 08:57 . 2010-05-11 08:58 ——– d—–w- c:\documents and settings\Starwalker\Application Data\Facebook
2010-05-11 04:57 . 2010-03-26 02:49 66048 —-a-w- c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]\platform\WINNT\components\nsTwitterFoxSign.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-31 17:03 . 2007-07-06 05:47 ——– d—–w- c:\program files\CCleaner
2010-05-31 17:00 . 2010-02-19 20:48 ——– d—–w- c:\documents and settings\Starwalker\Application Data\Disk Cleaner
2010-05-31 05:14 . 2008-05-10 01:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-05-29 03:24 . 2009-01-31 21:54 ——– d—–w- c:\program files\Glary Utilities
2010-05-21 05:14 . 2010-03-26 22:54 891 —-a-w- c:\windows\system32\secushr.dat
2010-05-20 09:13 . 2010-02-05 02:46 1 —-a-w- c:\documents and settings\Starwalker\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-05-20 07:01 . 2010-03-25 22:38 ——– d—–w- c:\program files\Ask.com
2010-05-20 03:00 . 2009-10-13 22:03 ——– d—–w- c:\program files\Outspark
2010-05-20 02:55 . 2007-07-06 04:34 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-05-19 04:41 . 2008-04-14 07:59 ——– d—–w- c:\documents and settings\Starwalker\Application Data\Alien Skin
2010-05-19 02:58 . 2008-03-04 17:22 ——– d—–w- c:\documents and settings\Starwalker\Application Data\XnView
2010-05-19 01:50 . 2010-02-11 17:49 ——– d—–w- c:\documents and settings\Starwalker\Application Data\Foxit Software
2010-05-18 17:28 . 2007-07-06 05:47 ——– d—–w- c:\program files\Foxit Software
2010-05-16 18:45 . 2007-07-08 04:09 ——– d—–w- c:\program files\Lexmark X1100 Series
2010-05-15 23:21 . 2007-07-23 02:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-05-15 16:35 . 2007-11-06 06:08 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-15 16:34 . 2007-07-06 05:48 ——– d—–w- c:\program files\SpywareBlaster
2010-05-15 08:59 . 2009-01-31 22:17 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-15 08:19 . 2010-02-03 17:38 117760 —-a-w- c:\documents and settings\Starwalker\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-05-15 08:17 . 2008-11-14 07:03 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-05-14 08:43 . 2007-07-08 01:48 ——– d—–w- c:\program files\Java
2010-05-14 03:58 . 2010-02-20 02:01 ——– d—–w- c:\documents and settings\Starwalker\Application Data\vlc
2010-05-12 00:20 . 2007-09-10 23:27 ——– d—–w- c:\program files\Google
2010-05-06 20:59 . 2010-02-19 22:58 165032 —-a-w- c:\windows\system32\aswBoot.exe
2010-05-06 20:39 . 2010-02-19 22:58 46672 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-06 20:39 . 2010-02-19 22:58 164048 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-06 20:34 . 2010-02-19 22:58 23376 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-06 20:33 . 2010-02-19 22:58 100432 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-06 20:33 . 2010-02-19 22:58 94800 —-a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-06 20:33 . 2010-02-19 22:58 19024 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-06 20:33 . 2010-02-19 22:58 28880 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-05 08:41 . 2010-02-10 08:39 ——– d—–w- c:\documents and settings\Starwalker\Application Data\Skype
2010-05-04 09:32 . 2010-02-19 20:43 ——– d—–w- c:\program files\CleanUp!
2010-04-30 11:08 . 2007-07-08 00:24 ——– d—–w- c:\program files\IncrediMail
2010-04-30 01:46 . 2010-04-30 01:46 ——– d—–w- c:\documents and settings\Starwalker\Application Data\WeatherBug
2010-04-30 01:46 . 2010-04-30 01:46 18944 —-a-r- c:\documents and settings\Starwalker\Application Data\Microsoft\Installer\{8F018A9E-56DE-4A79-A5EF-25F413F1D538}\IconBB6A16301.exe
2010-04-30 01:46 . 2010-04-30 01:46 11264 —-a-r- c:\documents and settings\Starwalker\Application Data\Microsoft\Installer\{8F018A9E-56DE-4A79-A5EF-25F413F1D538}\IconBB6A1630.exe
2010-04-30 01:46 . 2010-04-30 01:46 ——– d—–w- c:\program files\AWS
2010-04-29 22:31 . 2010-04-25 04:13 ——– d—–w- c:\program files\a-squared Free
2010-04-29 20:39 . 2009-01-31 22:17 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 20:39 . 2009-01-31 22:17 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-26 19:27 . 2007-08-04 09:50 83888 —-a-w- c:\documents and settings\Starwalker\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-26 18:41 . 2010-04-26 18:41 ——– d—–w- c:\documents and settings\Starwalker\Application Data\AMPSoft
2010-04-18 05:27 . 2010-04-18 05:27 ——– d—–w- c:\program files\dayam NFO Viewer
2010-04-14 16:47 . 2010-02-19 22:58 38848 —-a-w- c:\windows\system32\avastSS.scr
2010-04-14 15:16 . 2010-04-14 15:16 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-04-14 15:08 . 2010-04-14 15:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2010-04-14 15:08 . 2010-04-14 15:08 ——– d—–w- c:\program files\Norton Security Scan
2010-04-14 15:08 . 2010-04-14 15:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-04-14 15:07 . 2010-04-14 15:07 ——– d—–w- c:\program files\NortonInstaller
2010-04-14 15:07 . 2010-04-14 15:07 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-04-09 14:47 . 2010-04-09 14:46 ——– d—–w- c:\program files\QuickTime
2010-04-09 14:45 . 2010-02-20 02:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-04-09 09:06 . 2007-07-08 01:48 ——– d—–w- c:\program files\Common Files\Java
2010-04-09 09:03 . 2010-04-09 09:03 0 —-a-w- c:\windows\system32\REN23C.tmp
2010-04-09 09:03 . 2010-04-09 09:03 0 —-a-w- c:\windows\system32\REN23B.tmp
2010-04-09 09:03 . 2010-04-09 09:03 0 —-a-w- c:\windows\system32\REN23A.tmp
2010-04-09 09:00 . 2010-04-09 09:00 ——– d—–r- c:\program files\Skype
2010-04-09 09:00 . 2009-03-25 17:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2010-03-10 06:15 . 2001-08-18 12:00 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-03-10 05:24 . 2010-03-10 05:23 53319 —-a-w- c:\documents and settings\All Users\Application Data\TEMP\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\PostBuild.exe
2010-03-06 05:30 . 2010-03-06 05:30 847040 —-a-w- c:\documents and settings\Starwalker\Application Data\Facebook\axfbootloader.dll
2010-03-06 05:30 . 2010-03-06 05:30 5582848 —-a-w- c:\documents and settings\Starwalker\Application Data\Facebook\npfbplugin_1_0_3.dll
.

——- Sigcheck ——-

[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\ERDNT\cache\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . 4AFB3B0919649F95C1964AA1FAD27D73 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2007-10-30 . 64798ECFA43D78C7178375FCDD16D8C8 . 360832 . . [5.1.2600.3244] . . c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[-] 2006-04-20 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892] . . c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-17 23:43 1385864 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-17 1385864]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-17 1385864]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-10 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

c:\documents and settings\Starwalker\Start Menu\Programs\Startup\
Secunia PSI.lnk - c:\program files\Secunia\PSI\psi.exe [2010-5-28 911920]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0autocheck lsdelete

[HKLM\~\startupfolder\C:^Documents and Settings^Starwalker^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ——w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
2003-08-19 10:43 57344 —-a-w- c:\program files\Lexmark X1100 Series\lxbkbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-10-22 18:22 7700480 —-a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-10-22 18:22 86016 —-a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-10-22 18:22 1622016 —-a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-04-06 07:27 26105128 —-a-r- c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-05-15 08:17 2017280 —-a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
2009-10-20 19:59 111928 —-a-r- c:\program files\SweetIM\Messenger\SweetIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
2009-12-29 15:08 1653248 ——w- c:\program files\AWS\WeatherBug\Weather.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Lexmark X1100 Series"="c:\program files\Lexmark X1100 Series\lxbkbmgr.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImPackr.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncrediMail_Install.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImSc.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\helpctr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\Pando Networks\\Pando\\Pando.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"59165:TCP"= 59165:TCP:Pando
"59165:UDP"= 59165:UDP:Pando

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2/19/2010 5:58 PM 164048]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [1/5/2010 8:56 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 8:56 AM 68168]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [4/24/2010 11:13 PM 1872320]
R2 ASTSRV;Nalpeiron Licensing Service;c:\windows\system32\ASTSRV.EXE [5/18/2010 11:37 PM 57344]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2/19/2010 5:58 PM 19024]
R3 DLKRTS;D-Link DFE-530TX+ PCI Adapter;c:\windows\system32\drivers\DLKRTS.SYS [7/7/2007 3:28 PM 45568]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/11/2010 7:18 PM 136176]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [5/28/2010 6:04 AM 14896]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 8:56 AM 12872]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 09:32 128512 —-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2010-03-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]

2010-05-31 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-01-31 15:01]

2010-05-31 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-10 20:55]

2010-05-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-12 00:18]

2010-05-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-12 00:18]

2010-05-31 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-05-17 23:43]
.
.
——- Supplementary Scan ——-
.
uStart Page = yahoo.com
mStart Page = hxxp://eis.esnips.com/page/search/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d
uInternet Settings,ProxyOverride = *.local
Trusted Zone: fnismls.com
Trusted Zone: getmedianow.com
Trusted Zone: kuaiche.com\software
Trusted Zone: live.com
Trusted Zone: showingtime.com
Trusted Zone: sitexdata.com
Trusted Zone: spellchecker.net
Trusted Zone: transactionpoint.com
Trusted Zone: trpoint.com
Trusted Zone: virtualearth.net
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} - hxxp://static.ak.facebook.com/fbplugin/win32/axfbootloader.cab
FF - ProfilePath - c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr;=ytff-&p;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar_im2_test_v2&search;=
FF - component: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}\components\FlashGetXPI.dll
FF - component: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{db9d7a78-a76c-4bf2-97c6-258925ee1542}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{db9d7a78-a76c-4bf2-97c6-258925ee1542}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]\platform\WINNT\components\nsTwitterFoxSign.dll
FF - plugin: c:\documents and settings\Starwalker\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]\plugins\npiaplayer.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMySrWB.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-31 18:14
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-796845957-706699826-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6231081F-966B-C07D-59DB-9A3BE65E4114}*]
"oakmlpghgaeipbemeebnchjkilmlpd"=hex:64,61,6e,6b,69,6e,6a,6e,00,85
"oaondankojcjpeakdjmmaflmajkcne"=hex:6a,61,6e,6b,66,70,6b,70,68,6c,65,62,64,64,
64,6b,68,6b,61,6c,00,00
"nainfebememljhcgebjbdnniaded"=hex:6a,61,6e,6b,6c,6f,61,6f,66,6d,6e,6c,6c,61,
70,66,70,67,6e,66,00,00

[HKEY_USERS\S-1-5-21-796845957-706699826-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FC6F815C-487E-AA8F-848C-FB57828B94BA}*]
"bbcomeemeknodeoakeekimmnlfageghgkiik"=hex:61,62,68,70,64,67,61,63,6f,6f,6a,6e,
68,6c,70,69,6d,6e,63,6b,68,63,6e,6f,62,66,69,66,6d,6b,6a,6f,62,6e,00,77
"abcomeemeknodeoakenldbfcjckbnognoo"=hex:61,62,61,70,70,68,6e,64,6f,65,6f,6d,
6f,67,6b,63,65,67,68,70,70,6a,64,67,63,68,65,6c,61,70,69,6e,66,6b,00,77

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil10e_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil10e_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(564)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(3924)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-05-31 18:18:07
ComboFix-quarantined-files.txt 2010-05-31 23:17
ComboFix2.txt 2010-05-31 17:31
ComboFix3.txt 2010-02-18 23:52

Pre-Run: 14,004,019,200 bytes free
Post-Run: 13,994,684,416 bytes free

- - End Of File - - F3A7C620196FEF894A3C8599BFB21AAE

When I run combofix I get this for the recovery console download…

Attachments:

Hello Starwalker

The script did not work,we need to run it again.Did you have trouble dragging and dropping the file into ComboFix ?



Please follow the instructions exactly as written


COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    DDS::
    Trusted Zone: fnismls.com
    Trusted Zone: getmedianow.com
    Trusted Zone: kuaiche.com\software
    Trusted Zone: live.com
    Trusted Zone: showingtime.com
    Trusted Zone: sitexdata.com
    Trusted Zone: spellchecker.net
    Trusted Zone: transactionpoint.com
    Trusted Zone: trpoint.com
    Trusted Zone: virtualearth.net
    
    RegNull::
    [HKEY_USERS\S-1-5-21-796845957-706699826-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6231081F-966B-C07D-59DB-9A3BE65E4114}*]
    [HKEY_USERS\S-1-5-21-796845957-706699826-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FC6F815C-487E-AA8F-848C-FB57828B94BA}*]
    
    RegLock::
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


Next

Please download BootCheck.exe to your desktop.
  • Double click BootCheck.exe to run the check
  • When complete, a Notepad window will open with some text in it
  • Save the Notepad file to your desktop as BootCheck.txt
  • Copy the contents of BootCheck.txt and post it in your next reply
I redid the combofix. Exactly as posted. I get the same error I attached. Going to download the BootCheck. exe now.

Any ideas why it won't download the Recovery console?

I get this from BootCheck..
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !

Contents of boot.ini:
An internet search I found this…
http://tips.vlaurie.com/2006/05/recovery-c…out-an-xp-disk/

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI