This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can’t access site via “clkuk.tradedoubler.com” cashback tracking link.

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I’m trying to access www.theaa.com [U.K. car breakdown company], via www.topcashback.co.uk, a reputable U.K. cashback site, but theaa.com is continually blocked, no matter what I do. I can access it when going direct to the site.

I’ve done the following:

1. Run Microsoft FixIt 50267 to replace my MVPS Hosts file with IE7’s default, which I presume it did; rebooted; tried cashback site link again, but was still blocked.
“tradedoubler” isn’t listed as a “Restricted site” in IE7.

2. Spybot S&D 1.6.2 – couldn’t locate “tradedoubler” in the hosts list, so I disabled the list. I was still blocked, so I uninstalled Spybot, cleaned out junk files using CCleaner and Temp File Cleaner by Old Timer, rebooted and tried again – still blocked.

3. Removed the block on ad/tracking hosts, in A-squared Anti-malware 5.0.

Tracking cookies: block silently
Ad/tracking hosts: don’t block
Malware hosts: don’t block
Exploiting hosts: don’t block
Fraudulent hosts: block & notify
Hijacking hosts: block & notify
Phishing hosts: don’t block
Warez hosts: block & notify
Other malicious hosts: don’t block
[This is how it was set-up when I originally installed it and I haven’t changed it.]

Rebooted and tried to access; still blocked. Tried disabling all above “Surf protection”, but with same results.

4. Removed A-squared all together, but no change.

5. Re-installed MVPS Hosts, but nullified every instance of "tradedoubler". No change.

OTL logfile created on: 05/08/2010 16:27:41 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Arjun\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,023.00 Mb Total Physical Memory | 565.00 Mb Available Physical Memory | 55.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 3.96 Gb Free Space | 20.27% Space Free | Partition Type: NTFS
Drive D: | 278.55 Gb Total Space | 30.08 Gb Free Space | 10.80% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: POWERC250107
Current User Name: Arjun
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Arjun\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Chameleon Manager\monitor.exe (NeoSoft Tools)
PRC - C:\Program Files\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
PRC - C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe (DT Soft Ltd)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\WINDOWS\system32\TUProgSt.exe (TuneUp Software)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\AnVir Task Manager\AnVir.exe (AnVir Software)
PRC - C:\Program Files\Raxco\PerfectDisk10\PerfectDisk.exe (Raxco Software, Inc.)
PRC - C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe (Raxco Software, Inc.)
PRC - C:\Program Files\Raxco\PerfectDisk10\PDAgentS1.exe (Raxco Software, Inc.)
PRC - C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe (Raxco Software, Inc.)
PRC - C:\Program Files\SourceTec\Sothink Web Video Downloader Stand-alone\VideoDownloader.exe (SourceTec Software Co., LTD)
PRC - C:\Program Files\Zinio\ZinioReader.exe (Zinio, LLC)
PRC - C:\Program Files\WinSplit Revolution\WinSplit.exe ()
PRC - C:\Program Files\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe (ashampoo GmbH & Co. KG)
PRC - C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe ()
PRC - C:\Program Files\ShellLess\ShellLess.exe (ShellLessWorks Software)
PRC - C:\Program Files\Digiarty\WinX DVD Author 5.5\NMSAccessU.exe ()
PRC - C:\Program Files\Unlocker\UnlockerAssistant.exe ()
PRC - C:\Program Files\SSC Service Utility\ssc_serv.exe (SSC Localization Group)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\FastStone Capture\FSCapture.exe ()
PRC - C:\Program Files\OO Software\CleverCache\ooccctrl.exe (O&O Software GmbH)
PRC - C:\Program Files\OO Software\CleverCache\ooccag.exe (O&O Software GmbH)
PRC - C:\WINDOWS\system32\PSIService.exe ()
PRC - C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)
PRC - C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
PRC - C:\Program Files\TechSmith\SnagIt 7\SnagIt32.exe (TechSmith Corporation)
PRC - C:\Program Files\TechSmith\SnagIt 7\TscHelp.exe (TechSmith Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Arjun\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\AnVir Task Manager\AnvirHook62.dll (AnVir Software)
MOD - C:\Program Files\WinSplit Revolution\winsplithook.dll ()
MOD - C:\Program Files\SourceTec\Sothink Web Video Downloader Stand-alone\VideoDownloader.dll (SourceTec Software Co., LTD)
MOD - C:\Program Files\Unlocker\UnlockerHook.dll ()
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe -d -f %ProgramFiles%\WinPcap\rpcapd.ini File not found
SRV - (NMIndexingService) – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (TuneUp.ProgramStatisticsSvc) – C:\WINDOWS\system32\TUProgSt.exe (TuneUp Software)
SRV - (TuneUp.Defrag) – C:\WINDOWS\system32\TuneUpDefragService.exe (TuneUp Software)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (UxTuneUp) – C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
SRV - (PDEngine) – C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe (Raxco Software, Inc.)
SRV - (PDAgent) – C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe (Raxco Software, Inc.)
SRV - (DfSdkS) – C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe (mst software GmbH, Germany)
SRV - (NMSAccessU) – C:\Program Files\Digiarty\WinX DVD Author 5.5\NMSAccessU.exe ()
SRV - (OOCleverCacheAgent) – C:\Program Files\OO Software\CleverCache\ooccag.exe (O&O Software GmbH)
SRV - (ProtexisLicensing) – C:\WINDOWS\system32\PSIService.exe ()
SRV - (ATKKeyboardService) – C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)


========== Driver Services (SafeList) ==========

DRV - (Video3D) – C:\WINDOWS\System32\Drivers\Video3D32.sys File not found
DRV - (p17filt) – C:\WINDOWS\System32\drivers\p17filt.sys File not found
DRV - (MEMSWEEP2) – C:\WINDOWS\System32\5.tmp File not found
DRV - (EIO) – C:\WINDOWS\System32\drivers\EIO.sys File not found
DRV - (cpuz132) – C:\DOCUME~1\Arjun\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (BOCDRIVE) – C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys File not found
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (epmntdrv) – C:\WINDOWS\system32\epmntdrv.sys ()
DRV - (EuGdiDrv) – C:\WINDOWS\system32\EuGdiDrv.sys ()
DRV - (Uim_IM) – C:\WINDOWS\system32\drivers\Uim_IM.sys (Paragon)
DRV - (UimBus) – C:\WINDOWS\system32\drivers\UimBus.sys (Windows ® 2000 DDK provider)
DRV - (DefragFS) – C:\WINDOWS\System32\drivers\DefragFs.sys (Raxco Software, Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (WsAudio_DeviceS(1)) WsAudio_DeviceS(1) – C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys (Wondershare)
DRV - (StarPortLite) StarPort Storage Controller (Lite) – C:\WINDOWS\system32\drivers\StarPortLite.sys (Rocket Division Software)
DRV - (giveio) – C:\WINDOWS\system32\giveio.sys ()
DRV - (anf0100.sys) – C:\WINDOWS\system32\drivers\anf0100.sys (Netmarketing Pawel Wisniewski)
DRV - (P17) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (Ntfs) – C:\WINDOWS\System32\drivers\ntfs.old (Microsoft Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (AtcL001) – C:\WINDOWS\system32\drivers\atl01_xp.sys (Attansic Technology corporation.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (xfilt) – C:\WINDOWS\system32\DRIVERS\xfilt.sys (VIA Technologies,Inc)
DRV - (videX32) – C:\WINDOWS\system32\DRIVERS\videX32.sys (VIA Technologies, Inc.)
DRV - (asuskbnt) – C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (LHDriver) – C:\WINDOWS\system32\drivers\LHDriver.sys ()
DRV - (LADriver) – C:\WINDOWS\system32\drivers\LADriver.sys ()
DRV - (LDDriver) – C:\WINDOWS\system32\drivers\LDDriver.sys ()
DRV - (LMouKE) – C:\WINDOWS\system32\drivers\LMouKE.Sys (Logitech, Inc.)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (Changer) – C:\WINDOWS\System32\drivers\changer.sys (Microsoft Corporation)
DRV - (lbrtfdc) – C:\WINDOWS\System32\drivers\lbrtfdc.sys (Toshiba Corp.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (Aspi32) – C:\WINDOWS\System32\drivers\ASPI32.SYS (Adaptec)
DRV - (Sparrow) – C:\WINDOWS\System32\drivers\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\System32\drivers\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\System32\drivers\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\System32\drivers\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\System32\drivers\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\System32\drivers\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\System32\drivers\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\System32\drivers\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\System32\drivers\ql1280.sys (QLogic Corporation)
DRV - (mraid35x) – C:\WINDOWS\System32\drivers\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\System32\drivers\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\System32\drivers\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\System32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\System32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sky.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2010/08/04 20:55:42 | 000,610,637 | R— | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
O1 - Hosts: 127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
O1 - Hosts: 127.0.0.1 phpadsnew.abac.com
O1 - Hosts: 127.0.0.1 a.abnad.net
O1 - Hosts: 127.0.0.1 b.abnad.net
O1 - Hosts: 127.0.0.1 c.abnad.net #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 d.abnad.net
O1 - Hosts: 127.0.0.1 e.abnad.net
O1 - Hosts: 127.0.0.1 t.abnad.net
O1 - Hosts: 127.0.0.1 z.abnad.net
O1 - Hosts: 127.0.0.1 banners.absolpublisher.com
O1 - Hosts: 127.0.0.1 tracking.absolstats.com
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 gtb5.acecounter.com
O1 - Hosts: 127.0.0.1 gtb19.acecounter.com
O1 - Hosts: 16306 more lines…
O2 - BHO: (HelperObject Class) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll (TechSmith Corporation)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (SnagIt) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [ooccctrl.exe] C:\Program Files\OO Software\CleverCache\ooccctrl.exe (O&O Software GmbH)
O4 - HKLM..\Run: [P17Helper] C:\WINDOWS\System32\P17.DLL ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [ShellLess] C:\Program Files\ShellLess\ShellLess.exe (ShellLessWorks Software)
O4 - HKLM..\Run: [SkyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SSC Service Utility] C:\Program Files\SSC Service Utility\ssc_serv.exe (SSC Localization Group)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [ADSM] File not found
O4 - HKCU..\Run: [AnVir Task Manager] C:\Program Files\AnVir Task Manager\AnVir.exe (AnVir Software)
O4 - HKCU..\Run: [Chameleon System Monitor] C:\Program Files\Common Files\Chameleon Manager\monitor.exe (NeoSoft Tools)
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Invisible Security] File not found
O4 - HKCU..\Run: [SkinClock] C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe ()
O4 - HKCU..\Run: [UIWatcher] C:\Program Files\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe (ashampoo GmbH & Co. KG)
O4 - HKCU..\Run: [Web Video Downloader] C:\Program Files\SourceTec\Sothink Web Video Downloader Stand-alone\VideoDownloader.exe (SourceTec Software Co., LTD)
O4 - HKCU..\Run: [Winsplit] C:\Program Files\WinSplit Revolution\WinSplit.exe ()
O4 - HKCU..\Run: [Zinio DLM] C:\Program Files\Zinio\ZinioReader.exe (Zinio, LLC)
O4 - HKLM..\RunOnce: [MRUBlaster] C:\Program Files\MRU-Blaster\indexcleaner.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SnagIt 7.lnk = C:\Program Files\TechSmith\SnagIt 7\SnagIt32.exe (TechSmith Corporation)
O4 - Startup: C:\Documents and Settings\Arjun\Start Menu\Programs\Startup\FastStone Capture.lnk = C:\Program Files\FastStone Capture\FSCapture.exe ()
O4 - Startup: C:\Documents and Settings\Arjun\Start Menu\Programs\Startup\Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra Button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - File not found
O9 - Extra Button: Webpage Capture - {1F958B09-6612-7a0e-9223-4C7324C57B23} - Reg Error: Value error. File not found
O9 - Extra Button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE.dll (Nuclear Coffee Software)
O9 - Extra 'Tools' menuitem : Add to &VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE.dll (Nuclear Coffee Software)
O9 - Extra Button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O15 - HKCU\..Trusted Domains: cool.ne.jp ([]* in My Computer)
O15 - HKCU\..Trusted Domains: emjcd.com ([]* in My Computer)
O15 - HKCU\..Trusted Domains: gamehouse.com ([]* in My Computer)
O15 - HKCU\..Trusted Domains: kqzyfj.com ([]* in My Computer)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: pipni.cz ([]* in My Computer)
O15 - HKCU\..Trusted Domains: registerapi.com ([]* in My Computer)
O15 - HKCU\..Trusted Domains: spb.ru ([]* in My Computer)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([download] http in Trusted sites)
O15 - HKCU\..Trusted Domains: xat.com ([]* in My Computer)
O15 - HKCU\..Trusted Ranges: Range10 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range12 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range14 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range16 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range18 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range2 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range21 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range23 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range25 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range27 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range29 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range30 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range32 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range34 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range36 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range38 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range4 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range41 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range43 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range45 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range47 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range49 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range50 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range52 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range54 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range56 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range58 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range6 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range61 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range63 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range65 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range67 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range69 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range70 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range72 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range74 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range76 ([*]in My Computer)

O15 - HKCU\..Trusted Ranges: Range8 ([*]in My Computer)

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} http://download.sp.f-secure.com/ols/f-secu…/fslauncher.cab (F-Secure Online Scanner Launcher)
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} http://www.creative.com/su/ocx/15030/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} http://support.f-secure.com/ols/fscax.cab (F-Secure Online Scanner 3.1)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab (CKAVWebScan Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} http://downloads.ewido.net/ewidoOnlineScan.cab (ewidoOnlineScan Control)
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} http://www.trendsecure.com/framework/contr…vex/TmHcmsX.CAB (TmHcmsX Control)
O16 - DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} http://download.sp.f-secure.com/ols/f-secu…/fslauncher.cab (F-Secure Online Scanner Launcher)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2D9F7B63-EC7C-43FF-A41D-6E9EC984A5B9} https://myaccount.gateway.gov.uk/ClientObjects/GGSecSign.cab (GGSecSign Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} http://webeffective.keynote.com/applicatio…torLauncher.cab (Keynote Connector Launcher 2)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1197990575718 (MUWebControl Class)
O16 - DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC} http://esupport.epson-europe.com/selftest/…rg/ESTPTest.cab (EPSON Web Printer-SelfTest Control Class)
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab (WScanCtl Class)
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} http://www.nanoscan.com/cabs/nanoinst.cab (NanoInstaller Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} http://drm1.reelsurvey.com/ePlayer/V3_2_0_0/ACNePlayer.cab (ACNPlayer2 Class)
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} http://ax.emsisoft.com/asquared.cab (a-squared Scanner)
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} http://support.f-secure.com/ols/fscax.cab (F-Secure Online Scanner 3.3)
O16 - DPF: {C237A80A-4C55-4C68-BAA9-CBE4408D12B2} http://download.sp.f-secure.com/ols/f-secu…/fslauncher.cab (F-Secure Online Scanner 4.0 Launcher)
O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} http://www.freedom.net/viruscenter/onlinev…cabs/cssweb.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://vpn.pharmalink.co.uk/dana-cached/se…perSetupSP1.cab (JuniperSetupControlXP Class)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/su/ocx/15030/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O19 - User stylesheet: User Stylesheet - Reg Error: Value error.
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Arjun\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Arjun\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/02/02 17:33:45 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (PDBoot.exe) - C:\WINDOWS\System32\PDBoot.exe (Raxco Software, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619700398653440)

========== Files/Folders - Created Within 30 Days ==========

[2010/08/05 16:25:30 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Arjun\Recent
[2010/08/05 00:51:19 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Arjun\Desktop\OTL.exe
[2010/07/21 06:13:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Arjun\My Documents\Aneesoft Flash Gallery Classic GOTD Edition
[2010/07/21 06:12:23 | 000,000,000 | —D | C] – C:\Program Files\Aneesoft
[2002/04/11 09:41:06 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll
[56 C:\Documents and Settings\All Users\Documents\*.tmp files -> C:\Documents and Settings\All Users\Documents\*.tmp -> ]
[11 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/05 15:48:33 | 000,002,497 | —- | M] () – C:\Documents and Settings\Arjun\Desktop\Microsoft Office Word 2003.lnk
[2010/08/05 05:46:38 | 000,000,754 | —- | M] () – C:\Documents and Settings\Arjun\Application Data\AtomicAlarmClock.ini
[2010/08/05 05:46:29 | 000,063,804 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/08/05 05:46:27 | 000,000,312 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2010/08/05 05:46:25 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/05 05:46:23 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/05 05:45:27 | 030,932,992 | —- | M] () – C:\Documents and Settings\Arjun\NTUSER.DAT
[2010/08/05 05:45:27 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Arjun\ntuser.ini
[2010/08/05 00:51:20 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Arjun\Desktop\OTL.exe
[2010/08/04 20:55:42 | 000,610,637 | R— | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS
[2010/08/04 18:12:27 | 000,610,087 | —- | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS.MVP
[2010/08/04 15:45:31 | 001,014,645 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20100804-181227.backup
[2010/08/03 15:46:08 | 001,014,343 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20100804-154531.backup
[2010/08/03 02:54:09 | 000,128,000 | —- | M] () – C:\Documents and Settings\Arjun\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/30 18:05:54 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/07/21 06:12:52 | 000,000,865 | —- | M] () – C:\Documents and Settings\Arjun\Desktop\Aneesoft Flash Gallery Classic GOTD Edition.lnk
[2010/07/13 02:42:06 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[56 C:\Documents and Settings\All Users\Documents\*.tmp files -> C:\Documents and Settings\All Users\Documents\*.tmp -> ]
[11 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/21 06:12:52 | 000,000,865 | —- | C] () – C:\Documents and Settings\Arjun\Desktop\Aneesoft Flash Gallery Classic GOTD Edition.lnk
[2010/03/17 23:17:31 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2010/02/06 01:24:03 | 000,014,848 | —- | C] () – C:\WINDOWS\System32\EuEpmGdi.dll
[2010/02/06 01:24:03 | 000,013,192 | —- | C] () – C:\WINDOWS\System32\epmntdrv.sys
[2010/02/06 01:24:03 | 000,008,456 | —- | C] () – C:\WINDOWS\System32\EuGdiDrv.sys
[2009/07/18 00:53:57 | 000,000,848 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2009/06/23 03:47:55 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/06/23 03:47:54 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/05/29 21:02:56 | 000,697,328 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2009/05/19 21:31:54 | 000,000,037 | —- | C] () – C:\WINDOWS\SWFConverter.INI
[2009/03/24 05:42:57 | 000,000,023 | —- | C] () – C:\WINDOWS\SWFDecompiler.INI
[2009/02/28 18:14:57 | 000,000,064 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/12/29 05:10:48 | 000,000,140 | —- | C] () – C:\WINDOWS\System32\09wutili.sys
[2008/11/11 01:31:48 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys
[2008/10/28 00:46:42 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2008/10/28 00:45:39 | 000,000,025 | —- | C] () – C:\WINDOWS\CDE DX7000FEFDG.ini
[2008/09/19 22:57:34 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/09/19 22:55:10 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/09/19 22:55:10 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2008/09/19 22:54:18 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/06/28 20:10:46 | 000,143,360 | R— | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2008/06/05 01:22:02 | 000,000,080 | —- | C] () – C:\WINDOWS\DeliveryReader.INI
[2008/05/12 21:56:47 | 000,000,144 | —- | C] () – C:\WINDOWS\ScreenHunter.INI
[2008/01/02 00:44:23 | 000,000,250 | —- | C] () – C:\WINDOWS\gmer.ini
[2008/01/02 00:44:22 | 000,585,791 | —- | C] () – C:\WINDOWS\gmer.dll
[2007/10/25 11:26:48 | 000,000,453 | —- | C] () – C:\WINDOWS\bdoscandellang.ini
[2007/10/23 17:02:20 | 000,064,512 | —- | C] () – C:\WINDOWS\System32\P17.DLL
[2007/09/22 23:43:59 | 000,000,031 | -H– | C] () – C:\WINDOWS\UKCpInfo.sys
[2007/08/08 17:30:12 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\OnlineScannerLang.dll
[2007/08/02 19:11:28 | 000,253,952 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLA.dll
[2007/08/02 19:11:14 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLW.dll
[2007/07/31 16:39:13 | 000,014,336 | —- | C] () – C:\WINDOWS\System32\drivers\LHDriver.sys
[2007/07/31 16:39:12 | 000,027,136 | —- | C] () – C:\WINDOWS\System32\drivers\LADriver.sys
[2007/07/31 16:39:12 | 000,024,064 | —- | C] () – C:\WINDOWS\System32\drivers\LDDriver.sys
[2007/07/30 16:19:07 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\OctaneARM.dll
[2007/07/27 16:49:02 | 000,225,355 | —- | C] () – C:\WINDOWS\System32\lnod32apiW.dll
[2007/07/27 16:49:02 | 000,196,683 | —- | C] () – C:\WINDOWS\System32\lnod32apiA.dll
[2007/07/14 14:49:05 | 000,000,004 | —- | C] () – C:\WINDOWS\jknradee.sys
[2007/04/05 21:45:54 | 000,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2007/04/02 15:10:50 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/03/20 09:58:08 | 000,999,424 | —- | C] () – C:\WINDOWS\System32\FathMail.dll
[2007/02/15 18:08:04 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/02/15 17:57:01 | 000,000,029 | —- | C] () – C:\WINDOWS\sfbm.INI
[2007/02/15 17:37:08 | 000,010,496 | —- | C] () – C:\WINDOWS\System32\ATKOSDMini.DLL
[2007/02/15 17:37:08 | 000,000,018 | —- | C] () – C:\WINDOWS\System32\atkid.ini
[2007/02/15 17:37:05 | 000,046,592 | —- | C] () – C:\WINDOWS\System32\asfrench.dll
[2007/02/15 17:37:05 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\asrussian.dll
[2007/02/15 17:37:05 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\asgerman.dll
[2007/02/15 17:37:05 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\aseng.dll
[2007/02/15 17:37:05 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\askorean.dll
[2007/02/15 17:37:05 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\asjapan.dll
[2007/02/15 17:37:05 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\aschs.dll
[2007/02/15 17:37:04 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\ASCHT.dll
[2007/02/14 21:38:53 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2007/02/14 21:38:51 | 000,021,265 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2007/02/14 21:38:43 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007/02/06 18:29:04 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/06/01 10:22:00 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/06/01 10:22:00 | 001,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/06/01 10:22:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/06/01 10:22:00 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/06/01 10:22:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/06/01 10:22:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/06/01 10:22:00 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2005/12/30 21:18:26 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2005/12/05 21:25:22 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\lnod32umc.dll
[2005/12/05 14:37:10 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\lnod32upd.dll
[2005/07/07 10:26:56 | 000,005,663 | —- | C] () – C:\WINDOWS\System32\Ludap17.ini
[2005/03/08 07:17:08 | 000,000,075 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2004/10/11 12:19:00 | 000,092,672 | —- | C] () – C:\WINDOWS\System32\ASUSASV2.DLL
[2004/06/11 10:39:50 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\ACNePlayer.dll
[2003/10/02 18:48:18 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\P17CPI.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2009/11/09 03:55:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2007/10/27 21:13:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg7
[2008/09/03 22:44:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Channel4
[2010/06/17 23:47:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2010/05/17 21:27:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Eltima Software
[2008/11/02 19:02:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2009/08/13 05:32:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\explauncher
[2009/07/22 05:20:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2007/12/13 00:08:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2008/09/12 17:40:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2008/09/04 21:18:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2009/08/13 05:32:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\launcher
[2007/12/31 22:33:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/06/24 02:45:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NeoSoftTools
[2009/10/10 04:20:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Paragon
[2008/01/01 21:47:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Prevx
[2010/08/05 05:46:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/03/27 19:29:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2008/11/02 19:05:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UDL
[2008/10/28 04:20:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Watermark Factory
[2010/03/27 19:28:48 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2010/01/14 04:55:06 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{5DC53E13-E865-430F-97A7-98ACA32FC3D8}
[2009/05/24 21:57:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Amazon
[2009/10/16 21:22:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Apowersoft
[2009/09/25 01:14:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Ashampoo
[2009/06/22 03:40:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Audio Recorder Titanium
[2009/12/03 19:49:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Aunsoft
[2009/09/15 00:40:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Auslogics
[2009/10/05 01:49:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Autoplay Menu Designer
[2008/08/30 21:11:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\ComfortSoftware
[2008/11/08 02:47:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Conceptworld
[2010/01/02 18:51:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\ContentGuard
[2010/06/17 23:54:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\DAEMON Tools Pro
[2008/06/23 21:04:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Desktop Mechanic
[2009/12/19 19:10:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Desktopicon
[2010/06/21 04:15:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Digiarty
[2009/12/19 04:17:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\EAST Technologies
[2010/05/14 18:34:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Eltima Software
[2008/10/28 01:06:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\EPSON
[2009/05/23 19:20:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Gold Wave Editor Pro
[2009/08/10 01:56:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\ImgBurn
[2009/05/25 17:55:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\iRecordMax Sound Recorder
[2008/08/14 09:29:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Juniper Networks
[2008/08/25 02:01:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\mojosoft
[2009/08/09 22:44:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Moyea
[2010/06/24 02:45:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\NeoSoftTools
[2007/07/27 21:22:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\PandoraRecovery
[2008/03/22 00:28:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\PrevxCSI
[2009/06/18 01:49:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Smart Audio Editor
[2009/05/29 21:29:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\StarBurn
[2010/04/06 04:14:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Tidy Start Menu
[2010/03/27 19:29:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\TuneUp Software
[2008/06/19 20:24:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Uniblue
[2008/03/27 17:28:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\WebStripper
[2009/10/24 02:46:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Winsplit Revolution
[2010/02/10 04:19:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Zoner
[2010/08/05 05:46:27 | 000,000,312 | —- | M] () – C:\WINDOWS\Tasks\GlaryInitialize.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2006/02/28 13:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\system32\dllcache\agp440.sys

< MD5 for: ATAPI.SYS >
[2006/02/28 13:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2006/02/28 13:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\dllcache\atapi.sys
[2006/02/28 13:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\drivers\atapi.sys
[2006/02/28 13:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0015\DriverFiles\i386\atapi.sys
[2006/02/28 13:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0016\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2006/02/28 13:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\dllcache\cache\eventlog.dll
[2006/02/28 13:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2006/02/28 13:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2009/02/06 19:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 19:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2006/02/28 13:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\dllcache\cache\netlogon.dll
[2006/02/28 13:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\dllcache\netlogon.dll
[2006/02/28 13:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2006/02/28 13:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\dllcache\cache\scecli.dll
[2006/02/28 13:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\dllcache\scecli.dll
[2006/02/28 13:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010/06/17 23:48:38 | 000,697,328 | —- | M] () Unable to obtain MD5 – C:\WINDOWS\system32\drivers\sptd.sys

< %systemroot%\System32\config\*.sav >
[2007/02/02 17:10:28 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2007/02/02 17:10:28 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2007/02/02 17:10:28 | 000,917,504 | —- | M] () – C:\WINDOWS\system32\config\system.sav

========== Alternate Data Streams ==========

@Alternate Data Stream - 212 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:60466E88
@Alternate Data Stream - 203 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:44807EFA
@Alternate Data Stream - 203 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0C43407A
@Alternate Data Stream - 195 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C265C458
@Alternate Data Stream - 186 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:408F95E5
@Alternate Data Stream - 181 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:56AC8DD1
@Alternate Data Stream - 168 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EFC3A3C4
@Alternate Data Stream - 168 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C97C8631
@Alternate Data Stream - 165 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FB6AC38B
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9FB286BF
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
< End of report >


OTL Extras logfile created on: 05/08/2010 16:27:41 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Arjun\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,023.00 Mb Total Physical Memory | 565.00 Mb Available Physical Memory | 55.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 3.96 Gb Free Space | 20.27% Space Free | Partition Type: NTFS
Drive D: | 278.55 Gb Total Space | 30.08 Gb Free Space | 10.80% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: POWERC250107
Current User Name: Arjun
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"94:TCP" = 94:TCP:*:Enabled:VRS Recording System Web Control Panel

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\IpSharkk\IpSharkk.exe" = C:\Program Files\IpSharkk\IpSharkk.exe:*:Enabled:IpSharkk – (ipsharkk.com)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{027B7883-3778-4E8C-B3FA-0A28A3209D32}" = Pixo
"{07771631-6FE6-4D78-A705-D146C0D328A1}_is1" = Aunsoft SWF Converter version 2.0.2.35
"{0DD140D3-9563-481E-AA75-BA457CBDAEF2}" = PC Inspector File Recovery
"{0EDB29CF-5FFC-4824-9F13-3D1C4286CA98}_is1" = Audio Transcoder
"{10479E5C-2EC2-4A70-A816-4B0FF3D90FCD}_is1" = 3D Ebook Cover 1.0
"{12AEE067-4646-41E8-A6EA-FB2AD0E38D30}_is1" = Moyea PPT to DVD Burner Pro version 3.3.2.172
"{13CA4073-A66B-4F07-9491-B933018E63D2}_is1" = Moyea SWF to Video Converter Pro version 3.6.2.1
"{1719FAD6-2F6A-4F5E-BF2B-1F6F6F1E3806}_is1" = AnyBizSoft PDF Password Remover (Build 1.0.4)
"{1965C9BB-9114-4A50-AEC7-E62414BB117B}" = EASEUS Data Recovery Wizard Professional 4.3.6
"{1A15507A-8551-4626-915D-3D5FA095CC1B}" = Corel Paint Shop Pro X
"{1B1DDAD2-C704-49F8-8FC2-18DAAD9A87C5}" = Sound Blaster Audigy
"{1C63AA59-66B2-418C-BDF5-53A534DA5690}_is1" = Sothink SWF to Video Converter
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F698102-5739-441E-96F0-74F4EA540F06}" = Attansic Giga Ethernet Utility
"{208B53C3-FA83-40EF-BC07-ED61E78CC12A}}_is1" = Watermark Factory 2
"{20AC583C-A6FB-410A-807D-25308225C201}" = Paint.NET v3.35
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{21CA58E1-3C5F-4893-A753-EB296503073D}_is1" = Moyea PPT to Video Converter version 1.6.0.40
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 20
"{29C22873-B939-4EF9-B6E3-1EFE7FA391D1}" = ASUS nVidia Driver
"{2A6F734D-84CD-4472-877A-A070D76FAE74}_is1" = AnyBizSoft PDF to PowerPoint (Build [removed])
"{2CFE4799-CB85-456C-AABE-9BA2D02D81DB}" = Sky Broadband
"{30283233-3BE6-473D-A47C-ED964A2F78B4}_is1" = Inpaint 2.3
"{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}" = ASUS Enhanced Display Driver
"{3248F0A8-6813-11D6-A77B-00B0D0150210}" = J2SE Runtime Environment 5.0 Update 21
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{39352E3D-43FF-44E7-AC2F-0ADA04AF9BB2}_is1" = Sothink HD Movie Maker
"{4218F0E1-CBAF-4D68-B6FE-B3504770829F}" = AutoStreamer
"{4360BB46-507E-4361-8DCB-4FF9BDC9907B}" = SnagIt 7
"{43C67D92-F56E-4729-8673-9A2D5A6036F8}" = ASUS Utilities
"{44A69352-33DD-405E-ADB8-2D768643BBAE}_is1" = AnyBizSoft PDF to Word (Build 2.5.4)
"{485DF5E7-8379-4BFA-BAE1-9B8DBFE0D6B4}" = Paragon Drive Backup™ 9 Professional
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{53480390-0EC4-429E-BBEE-78E19EEB03BD}" = O&O CleverCache
"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B738CD9-D107-48C7-8E65-2E6639A39C8D}" = PerfectDisk 10 Professional
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8C52A46C-7961-4A81-AB4B-92CF65CB4772}_is1" = Sothink Web Video Downloader
"{8E3F691A-4972-47FF-9E09-1981B62A5D5A}_is1" = Moyea FLV Editor Ultimate version: 1.0.1.0
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A0AC043C-9834-4F9E-B33E-1683FFE67EA4}" = FW LiveUpdate
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A35001F0-F1E4-11DD-A38B-005056C00008}" = Paragon Partition Manager™ 9.5 Professional
"{A5FF2837-59C6-425B-8652-8CD385899F3F}" = uMark Professional 1.3
"{A855D6F0-DB2E-11DE-B032-005056C00008}" = Paragon Drive Backup™ 2010 Special Edition
"{AAF4238F-7C29-451D-9925-C753271A5728}" = Microsoft Visual C++ Run Time Lib Setup
"{AB67580-257C-45FF-B8F4-C8C30682091A}_is1" = SIW version 2010.03.11
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B80CC46C-5839-4A48-B051-3CACF23A2718}_is1" = Eraser 5.8.7
"{BCDB856C-D247-4DEE-9132-89C02F4D6B8C}_is1" = Sothink SWF Decompiler
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{BF50CF00-7CE6-11DE-A06C-005056C00008}" = Paragon Virtualization Manager™ 9.5
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3C23D52-4FE6-484D-9A8C-B0A6E2803655}}_is1" = Aneesoft Flash Gallery Classic GOTD Edition
"{CAAB0192-5704-469F-A0BE-2D842D70E93B}_is1" = Sothink FLV Player
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D3490D20-3AE0-459D-AAD6-59195140EAC2}_is1" = Sothink SWF Quicker
"{DB0BB9FA-1B60-4036-8E29-3D56D8085256}" = WOT for Internet Explorer
"{DBCF0030-9149-11DE-B8B6-005056C00008}" = Paragon Drive Copy™ 9.5 Personal
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E2CAFC9F-95A1-4F27-9C1D-34DC9426A81B}" = Invisible Security Full
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{EDF04509-B350-4EAB-BE77-5F2C87C33B35}_is1" = MPEG Video Wizard DVD 4.0.4.114 (06/2009)
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F20D1291-9FB8-46B1-BE46-6282F93C20E8}" = Registry Cleaner Pro
"{F7E1CA14-B39D-452A-960B-39423DDDD933}" = DriveImage XML (Private Edition)
"{FC274982-5AAD-4C20-848D-4424A5043009}_is1" = WinUtilities 9.7 Professional Edition
"44953928-E730-4e8c-A2B2-3A85BC96A3D0_is1" = FileSeek 1.7.1
"7-Zip" = 7-Zip 4.57
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe flex sdk redistributed by sothink_is1" = 3.4.0.9271.1
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adolix PDF to Image for Giveawayoftheday_is1" = Adolix PDF to Image v1.2
"Advanced Audio Titanium_is1" = Audio Recorder Titanium v6.0.2
"Aimersoft HD Video Converter GOTD Edition_is1" = Aimersoft HD Video Converter(Build [removed])
"AllMedia Grabber4.0" = AllMedia Grabber
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.4
"AnVir Task Manager" = AnVir Task Manager
"Ashampoo Burning Studio 2010_is1" = Ashampoo Burning Studio 2010
"Ashampoo Burning Studio 9_is1" = Ashampoo Burning Studio 9.12
"Ashampoo Music Studio 2009_is1" = Ashampoo Music Studio 2009
"Ashampoo Snap 3_is1" = Ashampoo Snap 3.40
"Ashampoo UnInstaller 3_is1" = Ashampoo UnInstaller 3.12
"Ashampoo WinOptimizer 6_is1" = Ashampoo WinOptimizer 6.60
"AtcL1" = Attansic L1 Gigabit Ethernet Driver
"Atomic Alarm Clock_is1" = Atomic Alarm Clock 5.81
"Autoplay Menu Designer_is1" = Autoplay Menu Designer 3.4
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Avira UnErase Personal" = Avira UnErase Personal
"AviSynth" = AviSynth 2.5
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.2
"AVS4YOU Video Editor 4_is1" = AVS Video Editor 4
"BusinessCardsMX3_is1" = BusinessCardsMX 3.92
"CCleaner" = CCleaner
"Chameleon Startup Manager 3" = Chameleon Startup Manager 3.2.0.723
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Corner-A ArtStudio" = Corner-A ArtStudio
"Cover Commander" = Cover Commander 3.0 by Insofta Development
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"CSSCOD" = Command On Demand for Command Software
"Dan Elwell's Broadband Speed Test_is1" = Dan Elwell's Broadband Speed Test
"Delivery" = Delivery
"Desktop Maestro_is1" = Desktop Maestro 2.0
"Device Control" = Device Control
"Disk Investigator_is1" = Disk Investigator v1.31
"Doc Scrubber_is1" = Doc Scrubber v1.1
"DriverGuide DriverScan" = DriverGuide DriverScan
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"EASEUS Partition Master Professional Edition_is1" = EASEUS Partition Master 5.0.1 Professional
"East-Tec Backup 2009_is1" = East-Tec Backup 2009 2.3
"East-Tec Eraser 2009_is1" = East-Tec Eraser 2009 Version 9.5
"EAX" = Creative EAX Console
"EAXSet" = Creative EAX Settings
"eCover Engineer Full Version_is1" = eCover Engineer 6.0 - Full Version
"eCover Engineer v3.02 FREE ecovers pack_is1" = eCover Engineer v3.02 ecovers pack
"eCover Engineer v4 FREE ecovers pack_is1" = eCover Engineer v4 ecovers pack
"eDATA Unerase" = eDATA Unerase
"Edraw Max_is1" = Edraw Max 4
"EPSON Printer and Utilities" = EPSON Printer Software
"ESCX6900F_DX7000F User's Guide" = ESCX6900F_DX7000F User's Guide
"EsetOnlineScanner" = ESET Online Scanner
"ExpressBurn" = Express Burn
"Extra DVD Ripper Professional_is1" = Extra DVD Ripper Professional 6.43
"Fast Video Converter_is1" = Fast Video Converter 1.0
"FastStone Capture" = FastStone Capture 5.3
"ffdshow_is1" = ffdshow [rev 2583] [2009-01-05]
"Flash Movie Player" = Flash Movie Player 1.5
"FLV Player" = FLV Player 2.0, build 24
"FREE eCovers for eCoverEngineer_is1" = FREE eCovers for eCoverEngineer from 5.0
"FREE Templates for eCoverEngineer_is1" = FREE Templates for eCoverEngineer
"FreeUndelete" = FreeUndelete
"Glary Utilities_is1" = Glary Utilities Pro 2.18.0.786
"Gold Wave Editor Pro_is1" = Gold Wave Editor Pro v10.2.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Image Mender" = Image Mender 1.1
"ImgBurn" = ImgBurn
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{43C67D92-F56E-4729-8673-9A2D5A6036F8}" = ASUS Utilities
"iRecordMax Sound Recorder_is1" = iRecordMax Sound Recorder v7.1.3
"IrfanView" = IrfanView (remove only)
"IsoBuster_is1" = IsoBuster 2.4
"Kaspersky Online Scanner" = Kaspersky Online Scanner
"KeynoteConnector" = Keynote Connector
"LockDisk_is1" = LockDisk 2.80
"MFZ0CODEC" = MFZ0 codec (Remove Only)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MRU-Blaster_is1" = MRU-Blaster v1.5 (Database 3/28/2004)
"MultiStage Recovery_is1" = MultiStage Recovery 3.6
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PandoraRecovery" = PandoraRecovery (Remove Only)
"PDFZilla_is1" = PDFZilla V1.2.9
"PhotoPerfect Express_is1" = PhotoPerfect Express 1.00
"PKR" = PKR
"RealPlayer 6.0" = RealPlayer
"Recover PDF Password_is1" = Recover PDF Password [removed]
"Recuva" = Recuva
"Registry Cleaner Pro" = Registry Cleaner Pro
"Revo Uninstaller" = Revo Uninstaller 1.85
"ShellLess_is1" = ShellLess Explorer 1.07
"Simpo PDF Merge & Split_is1" = Simpo PDF Merge & Split 2.0.0.5
"Smart Audio Editor_is1" = Smart Audio Editor v7.7.1 Build 78
"Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.0
"SPEAKER" = Creative Speaker Settings
"SSC Service Utility_is1" = SSC Service Utility v4.30
"StarBurn(GiveAwayOfTheDay)_is1" = StarBurn(GiveAwayOfTheDay) Version 12 (Build 0x20090527)
"SWF & FLV Toolbox 4_is1" = SWF & FLV Toolbox 4.0 (build 4.0.0.440)
"Tidy Start Menu" = Tidy Start Menu
"Turbo File Uneraser_is1" = Turbo File Uneraser 1.1
"UltimateDefrag V1 FREE Public Domain Version" = UltimateDefrag V1 FREE Public Domain Version
"Undelete Plus_is1" = Undelete Plus 2.9
"Unlocker" = Unlocker 1.8.7
"VideoGet_is1" = VideoGet
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"WinRAR archiver" = WinRAR archiver
"WinSplit Revolution" = WinSplit Revolution (v9.02)
"WinX Blu-ray Decrypter_is1" = WinX Blu-ray Decrypter 2.0
"WinX DVD Author_is1" = WinX DVD Author 5.5.8
"WinX DVD Ripper Platinum_is1" = WinX DVD Ripper Platinum 5.9.2
"WinX HD Video Converter Deluxe GOTD Edition_is1" = WinX HD Video Converter Deluxe 3.7
"Wondershare DVD Ripper Platinum_is1" = Wondershare DVD Ripper Platinum(Build [removed])
"Wondershare DVD to Flash Converter_is1" = Wondershare DVD to Flash Converter(Build [removed])
"Wondershare Flash Slideshow Builder GAOTD Edition_is1" = Wondershare Flash Slideshow Builder ([removed])
"Wondershare Music Converter_is1" = Wondershare Music Converter(Build 1.1.0.0)
"Wondershare Photo Collage Studio GAOTD Edition_is1" = Wondershare Photo Collage Studio [removed]
"Wondershare Photo Story Gold GAOTD Edition_is1" = Wondershare Photo Story Gold GAOTD Edition [removed]
"Wondershare QuizCreator 3.0 For GOTD_is1" = QuizCreator
"Wondershare Video Converter Platinum_is1" = Wondershare Video Converter Platinum(Build [removed])
"Wondershare Video to DVD Burner_is1" = Wondershare Video to DVD Burner(Build 2.0.17)
"Wondershare Video to DVD Converter_is1" = Wondershare Video to DVD Converter(Build [removed])
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Zilla Data Nuker_is1" = Zilla Data Nuker 2.0.0.0
"Zinio Reader" = Zinio Reader
"ZonerPhotoStudio12_EN_is1" = Zoner Photo Studio 12
"ZSoft Uninstaller" = ZSoft Uninstaller 2.4.1

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Juniper_Term_Services" = Juniper Terminal Services Client
"Neoteris_Host_Checker" = Juniper Networks Host Checker
"WinDirStat" = WinDirStat 1.1.2

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 19/07/2010 23:25:31 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x0666251c.

Error - 21/07/2010 01:09:02 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x0486251c.

Error - 24/07/2010 00:32:24 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x07c5251c.

Error - 24/07/2010 17:24:07 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application update.exe, version 10.0.0.29, faulting module
msvcr90.dll, version 9.0.30729.4148, fault address 0x000375b4.

Error - 24/07/2010 18:15:16 | Computer Name = POWERC250107 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17055, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 26/07/2010 00:28:01 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x04b7251c.

Error - 27/07/2010 00:51:09 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x0713251c.

Error - 28/07/2010 22:18:55 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x052e251c.

Error - 03/08/2010 00:37:54 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x077d251c.

Error - 03/08/2010 19:19:30 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application flvplayer.exe, version 0.0.0.0, faulting module
flashplayer.3.1.1e.ocx, version 9.0.115.0, fault address 0x000c1dc3.

[ System Events ]
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).

Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The Machine Debug Manager service terminated unexpectedly. It has
done this 1 time(s).

Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The O&O CleverCache Agent service terminated unexpectedly. It has
done this 1 time(s).

Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The NMSAccessU service terminated unexpectedly. It has done this
1 time(s).

Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The PDAgent service terminated unexpectedly. It has done this 1 time(s).

Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The ProtexisLicensing service terminated unexpectedly. It has done
this 1 time(s).

Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The TuneUp Program Statistics Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The Windows User Mode Driver Framework service terminated unexpectedly.
It has done this 1 time(s).

Error - 05/08/2010 00:46:50 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7000
Description = The EIO service failed to start due to the following error: %%2

[ TuneUp Events ]
Error - 08/05/2010 11:27:11 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-08 16:27:11', '\device\harddiskvolume1\documents
and settings\all users\application data\malwarebytes\malwarebytes' anti-malware\mbam-setup.exe','2952',0)

Error - 08/05/2010 11:27:41 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-08 16:27:41', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','2488',0)

Error - 09/05/2010 12:13:11 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-09 17:13:11', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','2400',0)

Error - 14/05/2010 20:48:05 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-15 01:48:05', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','504',0)

Error - 14/05/2010 21:09:15 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-15 02:09:15', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','1312',0)

Error - 29/05/2010 00:12:33 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-29 05:12:33', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','1428',0)

Error - 31/05/2010 14:42:03 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: database or disk is full; when executing SQL: UPDATE StartMenuEntries
SET Outdated='1'

Error - 31/05/2010 14:42:04 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: database or disk is full; when executing SQL: UPDATE SecurityProducts
SET Outdated='1'

Error - 03/07/2010 22:59:45 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-07-04 03:59:45', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\unins000.exe','2108',0)

Error - 03/07/2010 22:59:55 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-07-04 03:59:55', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbamgui.exe','3308',0)

< End of report >


Thanks for any help you can give.
Posted Image

DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")



The issues with your computer that you list, doesn't appear to be related to Malware/Spyware/Virus but we can have a look.


You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
[external image: Posted Image]
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .
I still can't access www.theaa.com, via the topcashback.co.uk tracking link. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4408 Windows 5.1.2600 Service Pack 2 Internet Explorer 7.0.5730.13 08/08/2010 23:31:55 mbam-log-2010-08-08 (23-31-55).txt Scan type: Quick scan Objects scanned: 140204 Time elapsed: 6 minute(s), 4 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\system32\Memman.vxd (Rogue.sysCleaner) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\Memman.vxd (Rogue.sysCleaner) -> Quarantined and deleted successfully. The Registry Value and infected file aren't infections; they were a part of the program "Invisible Security Full" [Macrosoft], also more widely known as "Folder Phantom", which I removed quite a while ago.
I don't think this is a Malware issue but we can try one more tool.

You also need to update to Windows Service Pack 3. Support for SP2 was ended.



Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
Thanks.
The link works now, but I'm baffled as to how.
………………………………………………….

ComboFix 10-08-08.01 - Arjun 09/08/2010 0:33.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.44.1033.18.1023.631 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Arjun\Application Data\Desktopicon
c:\documents and settings\Arjun\Application Data\Desktopicon\config.ini
c:\windows\settings.reg
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\SHELLLNK.TLB
c:\windows\system32\wpcap.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF
——-\Service_NPF


((((((((((((((((((((((((( Files Created from 2010-07-08 to 2010-08-08 )))))))))))))))))))))))))))))))
.

2010-08-08 22:22 . 2010-04-29 14:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-08 22:22 . 2010-08-08 22:22 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-08-08 22:22 . 2010-04-29 14:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-08-05 06:59 . 2010-08-05 06:59 503808 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-4ba56517-n\msvcp71.dll
2010-08-05 06:59 . 2010-08-05 06:59 499712 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-4ba56517-n\jmc.dll
2010-08-05 06:59 . 2010-08-05 06:59 348160 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-4ba56517-n\msvcr71.dll
2010-08-05 06:59 . 2010-08-05 06:59 61440 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-5df4cf9c-n\decora-sse.dll
2010-08-05 06:59 . 2010-08-05 06:59 12800 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-5df4cf9c-n\decora-d3d.dll
2010-07-21 05:12 . 2010-07-21 05:12 ——– d—–w- c:\program files\Aneesoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-08 23:39 . 2008-03-27 16:30 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-08-08 03:07 . 2009-10-21 01:52 ——– d—–w- c:\program files\AnyBizSoft
2010-08-04 22:37 . 2009-12-22 00:24 ——– d—–w- c:\program files\a-squared Anti-Malware
2010-08-04 17:30 . 2008-08-20 21:22 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-08-04 17:28 . 2007-02-21 20:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-29 17:02 . 2010-02-09 00:32 ——– d—–w- c:\program files\Simpo PDF Merge & Split
2010-07-20 03:45 . 2007-11-05 22:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Nero
2010-07-04 20:51 . 2010-07-04 20:51 ——– d—–w- c:\documents and settings\Arjun\Application Data\Avira
2010-07-04 20:41 . 2010-07-04 20:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
2010-07-04 20:41 . 2007-07-30 21:21 ——– d—–w- c:\program files\Avira
2010-07-04 03:36 . 2007-10-01 16:49 ——– d—–w- c:\program files\VideoLAN
2010-07-04 03:17 . 2007-02-15 03:01 ——– d—–w- c:\program files\ASUS
2010-07-04 03:10 . 2007-02-22 02:33 ——– d—–w- c:\program files\Common Files\Adobe
2010-07-04 03:03 . 2007-02-21 15:24 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-07-04 03:03 . 2009-12-20 22:13 ——– d—–w- c:\documents and settings\Arjun\Application Data\SUPERAntiSpyware.com
2010-06-26 23:59 . 2010-06-26 23:59 ——– d—–w- c:\program files\Windows Media Components
2010-06-26 23:59 . 2007-12-31 22:04 ——– d—–w- c:\program files\Ashampoo
2010-06-24 01:45 . 2010-06-24 01:45 ——– d—–w- c:\documents and settings\Arjun\Application Data\NeoSoftTools
2010-06-24 01:45 . 2010-06-24 01:45 ——– d—–w- c:\documents and settings\All Users\Application Data\NeoSoftTools
2010-06-24 01:44 . 2010-06-24 01:44 ——– d—–w- c:\program files\Common Files\Chameleon Manager
2010-06-24 01:44 . 2010-06-24 01:44 ——– d—–w- c:\program files\Chameleon Startup Manager 3
2010-06-21 03:15 . 2010-01-22 05:48 ——– d—–w- c:\documents and settings\Arjun\Application Data\Digiarty
2010-06-21 03:14 . 2009-09-16 21:03 ——– d—–w- c:\program files\Digiarty
2010-06-17 22:54 . 2010-06-17 22:47 ——– d—–w- c:\documents and settings\Arjun\Application Data\DAEMON Tools Pro
2010-06-17 22:48 . 2009-05-29 20:02 697328 —-a-w- c:\windows\system32\drivers\sptd.sys
2010-06-17 22:48 . 2010-06-17 22:48 ——– d—–w- c:\program files\DAEMON Tools Pro
2010-06-17 22:47 . 2010-06-17 22:47 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2010-06-10 17:49 . 2007-12-23 23:57 ——– d—–w- c:\program files\Microsoft Silverlight
2010-05-27 14:00 . 2010-05-27 14:00 503808 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-70a9f99a-n\msvcp71.dll
2010-05-27 14:00 . 2010-05-27 14:00 499712 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-70a9f99a-n\jmc.dll
2010-05-27 14:00 . 2010-05-27 14:00 348160 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-70a9f99a-n\msvcr71.dll
2010-05-27 14:00 . 2010-05-27 14:00 12800 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3f68b24b-n\decora-d3d.dll
2010-05-27 14:00 . 2010-05-27 14:00 61440 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3f68b24b-n\decora-sse.dll
2010-05-13 09:46 . 2010-05-26 04:42 40560 —-a-w- c:\windows\system32\drivers\hotcore3.sys
2008-11-07 01:09 . 2008-11-07 01:09 382 —-a-w- c:\program files\Shortcut to Program Files.lnk
2009-07-18 00:01 . 2009-07-17 23:53 848 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

——- Sigcheck ——-

[7] 2007-02-09 . 05AB81909514BFD69CBB1F2C147CF6B9 . 574976 . . [5.1.2600.3081] . . c:\windows\$hf_mig$\KB930916\SP2QFE\ntfs.sys
[7] 2007-02-09 . 19A811EF5F1ED5C926A028CE107FF1AF . 574464 . . [5.1.2600.3081] . . c:\windows\system32\dllcache\ntfs.sys
[-] 2003-03-31 . E3AE9C79498210A5F39FE5A9AD62BC55 . 561920 . . [5.1.2600.1106] . . c:\windows\system32\drivers\ntfs.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6F9DEF1A-C65A-F01A-B42D-9B6F763A94B3}"= "c:\windows\system32\appwiz.cpl" [2006-02-28 549888]

[HKEY_CLASSES_ROOT\clsid\{6f9def1a-c65a-f01a-b42d-9b6f763a94b3}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SkinClock"="c:\program files\Atomic Alarm Clock\AtomicAlarmClock.exe" [2008-09-11 1739264]
"Web Video Downloader"="c:\program files\SourceTec\Sothink Web Video Downloader Stand-alone\VideoDownloader.exe" [2009-08-07 3257616]
"Zinio DLM"="c:\program files\Zinio\ZinioReader.exe" [2009-07-21 2707526]
"Winsplit"="c:\program files\WinSplit Revolution\WinSplit.exe" [2009-02-27 3958784]
"UIWatcher"="c:\program files\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe" [2009-02-23 3508568]
"AnVir Task Manager"="c:\program files\AnVir Task Manager\AnVir.exe" [2009-12-28 3313888]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2010-06-11 427328]
"Chameleon System Monitor"="c:\program files\Common Files\Chameleon Manager\monitor.exe" [2010-06-18 1810432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-02-28 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-02-28 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-02-28 455168]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-01 7618560]
"nwiz"="nwiz.exe" [2006-06-01 1519616]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 86016]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"P17Helper"="P17.dll" [2005-05-03 64512]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-06 16262656]
"ShellLess"="c:\program files\ShellLess\ShellLess.exe" [2008-09-02 2198528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"ooccctrl.exe"="c:\program files\OO Software\CleverCache\ooccctrl.exe" [2007-01-28 1911568]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"SSC Service Utility"="c:\program files\SSC Service Utility\ssc_serv.exe" [2007-10-09 665600]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-02-28 15360]

c:\documents and settings\Arjun\Start Menu\Programs\Startup\
FastStone Capture.lnk - c:\program files\FastStone Capture\FSCapture.exe [2007-2-13 1111552]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
SnagIt 7.lnk - c:\program files\TechSmith\SnagIt 7\SnagIt32.exe [2005-10-14 3719168]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IpSharkk\\IpSharkk.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"94:TCP"= 94:TCP:VRS Recording System Web Control Panel

R1 anf0100.sys;anf0100.sys;c:\windows\system32\drivers\anf0100.sys [10/09/2008 21:33 9728]
R1 LADriver;LADriver;c:\windows\system32\drivers\LADriver.sys [31/07/2007 16:39 27136]
R1 LDDriver;LDDriver;c:\windows\system32\drivers\LDDriver.sys [31/07/2007 16:39 24064]
R1 LHDriver;LHDriver;c:\windows\system32\drivers\LHDriver.sys [31/07/2007 16:39 14336]
R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [29/05/2009 21:02 95592]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [04/07/2010 21:42 135336]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Adapter;c:\windows\system32\drivers\atl01_xp.sys [14/02/2007 21:55 35712]
R3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [15/05/2009 03:10 16640]
S3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 6\DfSdkS.exe [28/05/2010 05:16 406016]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [06/02/2010 01:24 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [06/02/2010 01:24 8456]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\5.tmp –> c:\windows\system32\5.tmp [?]
S3 p17filt;p17filt;c:\windows\system32\drivers\p17filt.sys –> c:\windows\system32\drivers\p17filt.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [29/05/2009 21:02 697328]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-08-08 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-01-15 12:09]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.sky.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
IE: {{08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com
Trusted Zone: microsoft.com\*.update
Trusted Zone: windowsupdate.com\download
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
DPF: {2D9F7B63-EC7C-43FF-A41D-6E9EC984A5B9} - hxxps://myaccount.gateway.gov.uk/ClientObjects/GGSecSign.cab
DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} - hxxp://drm1.reelsurvey.com/ePlayer/V3_2_0_0/ACNePlayer.cab
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKCU-Run-ADSM - (no file)
HKCU-Run-Invisible Security - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-09 00:40
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\5.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OOCC06.00.00.01WSSV"="857B7EBB918C69CDBE23E64DB8BEA656512C359BAD0D46908F07626C1D83FB78448C36DDAB9
3CDE24443834A71A4F258D6322D1FFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC
9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933C038D530D6EB3452A2D97
226D213B555BA7FD869164D679472BC2460482D2043FC6B7C6578A4CA103C8928950ECC19D82FA745
A727FBE28A1767CE8E3BDA16AE7007FBDCF539B6D33DF8ED30F271BC7EA8923531BCDAB935EB459B1
FA3CB54120FE74DF064A80E6DF613BF86188D5B923C08F95FFA7C1105DBAEA171829F95D9B3A1DA82
401BEF9B4E437B9795749BC27D6B08F5387D34B9C92288AB8BDD6BF52CE8A3B6BA21D39E1F9894AC3
95CF6C0F445687A80DCC195893E0E35A3EEB7DBBB18B877B72C003DB845924E06613BC39FC0353990
002C60E44983B9E89F338395ACC270CF929241DDA011C9AF0309076CAE21C0DC2F3B6899ABCD2AA92
3E96AE5C87914D00E7C7746A63EB2212557C94082EEE4099788F857F367B96A8D3B11C9322C16393E
01319AF3DDDFF50E6FCCF05477BC72C783E943505C616158D97BD3D23D71BE253B467CCD496981EAE
F584E5F27A2A6B66F9077184E5DFA614FB10AB923E1C8A8950D7E98E7AEC9C84AB59484FC35E6BA61
488042732DD5E976C166966769F593D2E626E1BB51851DC3B4F9C78FDAAB1046725E6D9214471800B
C57C0A9CB151486B1EF565838253E7528A5CF85369ED8DAF108588C9CD473EEB5BCB29A94AA3D1AD6
4B4A620D48E7CEE5B3E91BB69E18B3ADE4EACF913C6A9B466F08818FF085493D19B497BD46B990C83
5842188BD37B61252AB6203E94F308BB885384DD2C5A6D232AF467DA635D02F2D357C9F42819E8E22
485EC504552EA4D40FAC24F1BD158AE07A524128C4F87B13B1A3B32828FA179812EFF1E19868B6F7A
E622CA010CED96577B2C3BBB14896D45824401B3F2D236EFCD8618D14876B47936E43E9C2DE39F0AE
F18287AD4EE8CFA71F82813F6C2ED022ED38472B87EE5D8EFB0A093FA8A7ABC93041E44972E05B444
6FEEE844437E13F9A57042136714716C8666F555E26AF982004E1FCED72BCF4647D2F4F9343B53459
E868A1B82887C3278141378B398D8D0A16BEA4CE9431A6D487BFC48BD956863CD7D2B807CA9355FCC
756F90A6DC63FC8857100754068E887ED546D3585BEDF6955D0586D97D62D45EA3C990BCD536A4AA5
A3B099F4876F01C2D2B3E8D6618B195427558A4E2E500E5FB2F3166D1E6B948AB3BF4436A31259DC5
66A57E024FA998DCCE9D133EC6979DE2E4B806006463C0FB1985309CC4DBDD8AC44033CDDC34BFCEC
B20D0FD746BE6657467A415D23ED52E38A78F90041ED15D8DA42045D1FA4E36731D5AEA8D927370CE
F02AFEC4B67354447B81632B03D34"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(912)
c:\windows\system32\WININET.dll
c:\program files\SourceTec\Sothink Web Video Downloader Stand-alone\VideoDownloader.dll
c:\program files\AnVir Task Manager\AnvirHook62.dll
c:\windows\system32\ieframe.dll
c:\program files\Atomic Alarm Clock\Clock.dll
.
———————— Other Running Processes ————————
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\ATKKBService.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Digiarty\WinX DVD Author 5.5\NMSAccessU.exe
c:\windows\system32\RunDLL32.exe
c:\windows\system32\Rundll32.exe
c:\windows\system32\nvsvc32.exe
c:\program files\OO Software\CleverCache\ooccag.exe
c:\windows\RTHDCPL.EXE
c:\program files\Raxco\PerfectDisk10\PDAgent.exe
c:\windows\system32\PSIService.exe
c:\windows\System32\TUProgSt.exe
c:\windows\system32\wdfmgr.exe
c:\program files\TechSmith\SnagIt 7\TSCHelp.exe
.
**************************************************************************
.
Completion time: 2010-08-09 00:45:44 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-08 23:45

Pre-Run: 4,196,085,760 bytes free
Post-Run: 4,161,601,536 bytes free

- - End Of File - - 8310EFB94AD868AC017CBD9BD80E7B51
………………………………

Whatever ComboFix has changed or removed has resulted in all the ads returning to every site. I'm unsure what I should do now to protect myself from malicious ads, but still be able to use all the cashback site affiliate tracking links.

Also, visiting the "AA" page, on "topcashback.co.uk", to check if your help had worked, triggered Avira AntiVir with an "HTML/Infected.WebPage.Gen" detection. To be sure it wasn't a false positive, I closed the browser, ran CCleaner and visited the page again. The same detection was made.

Why didn't invalidating "tradedoubler", in the MVPS Hosts file, solve the problem?

I've just opened a new tab and suddenly this WhattheTech text box has become about 20 times wider; although the rest of the page is still the width of my screen.
Previewing this post results in the whole tab becoming about 20 times wider. Is the root of the problem linked with IE?
Thanks.
The link works now, but I'm baffled as to how.
………………………………………………….

ComboFix 10-08-08.01 - Arjun 09/08/2010 0:33.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.44.1033.18.1023.631 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Arjun\Application Data\Desktopicon
c:\documents and settings\Arjun\Application Data\Desktopicon\config.ini
c:\windows\settings.reg
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\SHELLLNK.TLB
c:\windows\system32\wpcap.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF
——-\Service_NPF


((((((((((((((((((((((((( Files Created from 2010-07-08 to 2010-08-08 )))))))))))))))))))))))))))))))
.

2010-08-08 22:22 . 2010-04-29 14:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-08 22:22 . 2010-08-08 22:22 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-08-08 22:22 . 2010-04-29 14:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-08-05 06:59 . 2010-08-05 06:59 503808 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-4ba56517-n\msvcp71.dll
2010-08-05 06:59 . 2010-08-05 06:59 499712 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-4ba56517-n\jmc.dll
2010-08-05 06:59 . 2010-08-05 06:59 348160 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-4ba56517-n\msvcr71.dll
2010-08-05 06:59 . 2010-08-05 06:59 61440 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-5df4cf9c-n\decora-sse.dll
2010-08-05 06:59 . 2010-08-05 06:59 12800 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-5df4cf9c-n\decora-d3d.dll
2010-07-21 05:12 . 2010-07-21 05:12 ——– d—–w- c:\program files\Aneesoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-08 23:39 . 2008-03-27 16:30 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-08-08 03:07 . 2009-10-21 01:52 ——– d—–w- c:\program files\AnyBizSoft
2010-08-04 22:37 . 2009-12-22 00:24 ——– d—–w- c:\program files\a-squared Anti-Malware
2010-08-04 17:30 . 2008-08-20 21:22 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-08-04 17:28 . 2007-02-21 20:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-29 17:02 . 2010-02-09 00:32 ——– d—–w- c:\program files\Simpo PDF Merge & Split
2010-07-20 03:45 . 2007-11-05 22:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Nero
2010-07-04 20:51 . 2010-07-04 20:51 ——– d—–w- c:\documents and settings\Arjun\Application Data\Avira
2010-07-04 20:41 . 2010-07-04 20:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
2010-07-04 20:41 . 2007-07-30 21:21 ——– d—–w- c:\program files\Avira
2010-07-04 03:36 . 2007-10-01 16:49 ——– d—–w- c:\program files\VideoLAN
2010-07-04 03:17 . 2007-02-15 03:01 ——– d—–w- c:\program files\ASUS
2010-07-04 03:10 . 2007-02-22 02:33 ——– d—–w- c:\program files\Common Files\Adobe
2010-07-04 03:03 . 2007-02-21 15:24 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-07-04 03:03 . 2009-12-20 22:13 ——– d—–w- c:\documents and settings\Arjun\Application Data\SUPERAntiSpyware.com
2010-06-26 23:59 . 2010-06-26 23:59 ——– d—–w- c:\program files\Windows Media Components
2010-06-26 23:59 . 2007-12-31 22:04 ——– d—–w- c:\program files\Ashampoo
2010-06-24 01:45 . 2010-06-24 01:45 ——– d—–w- c:\documents and settings\Arjun\Application Data\NeoSoftTools
2010-06-24 01:45 . 2010-06-24 01:45 ——– d—–w- c:\documents and settings\All Users\Application Data\NeoSoftTools
2010-06-24 01:44 . 2010-06-24 01:44 ——– d—–w- c:\program files\Common Files\Chameleon Manager
2010-06-24 01:44 . 2010-06-24 01:44 ——– d—–w- c:\program files\Chameleon Startup Manager 3
2010-06-21 03:15 . 2010-01-22 05:48 ——– d—–w- c:\documents and settings\Arjun\Application Data\Digiarty
2010-06-21 03:14 . 2009-09-16 21:03 ——– d—–w- c:\program files\Digiarty
2010-06-17 22:54 . 2010-06-17 22:47 ——– d—–w- c:\documents and settings\Arjun\Application Data\DAEMON Tools Pro
2010-06-17 22:48 . 2009-05-29 20:02 697328 —-a-w- c:\windows\system32\drivers\sptd.sys
2010-06-17 22:48 . 2010-06-17 22:48 ——– d—–w- c:\program files\DAEMON Tools Pro
2010-06-17 22:47 . 2010-06-17 22:47 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2010-06-10 17:49 . 2007-12-23 23:57 ——– d—–w- c:\program files\Microsoft Silverlight
2010-05-27 14:00 . 2010-05-27 14:00 503808 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-70a9f99a-n\msvcp71.dll
2010-05-27 14:00 . 2010-05-27 14:00 499712 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-70a9f99a-n\jmc.dll
2010-05-27 14:00 . 2010-05-27 14:00 348160 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-70a9f99a-n\msvcr71.dll
2010-05-27 14:00 . 2010-05-27 14:00 12800 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3f68b24b-n\decora-d3d.dll
2010-05-27 14:00 . 2010-05-27 14:00 61440 —-a-w- c:\documents and settings\Arjun\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3f68b24b-n\decora-sse.dll
2010-05-13 09:46 . 2010-05-26 04:42 40560 —-a-w- c:\windows\system32\drivers\hotcore3.sys
2008-11-07 01:09 . 2008-11-07 01:09 382 —-a-w- c:\program files\Shortcut to Program Files.lnk
2009-07-18 00:01 . 2009-07-17 23:53 848 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

——- Sigcheck ——-

[7] 2007-02-09 . 05AB81909514BFD69CBB1F2C147CF6B9 . 574976 . . [5.1.2600.3081] . . c:\windows\$hf_mig$\KB930916\SP2QFE\ntfs.sys
[7] 2007-02-09 . 19A811EF5F1ED5C926A028CE107FF1AF . 574464 . . [5.1.2600.3081] . . c:\windows\system32\dllcache\ntfs.sys
[-] 2003-03-31 . E3AE9C79498210A5F39FE5A9AD62BC55 . 561920 . . [5.1.2600.1106] . . c:\windows\system32\drivers\ntfs.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6F9DEF1A-C65A-F01A-B42D-9B6F763A94B3}"= "c:\windows\system32\appwiz.cpl" [2006-02-28 549888]

[HKEY_CLASSES_ROOT\clsid\{6f9def1a-c65a-f01a-b42d-9b6f763a94b3}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SkinClock"="c:\program files\Atomic Alarm Clock\AtomicAlarmClock.exe" [2008-09-11 1739264]
"Web Video Downloader"="c:\program files\SourceTec\Sothink Web Video Downloader Stand-alone\VideoDownloader.exe" [2009-08-07 3257616]
"Zinio DLM"="c:\program files\Zinio\ZinioReader.exe" [2009-07-21 2707526]
"Winsplit"="c:\program files\WinSplit Revolution\WinSplit.exe" [2009-02-27 3958784]
"UIWatcher"="c:\program files\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe" [2009-02-23 3508568]
"AnVir Task Manager"="c:\program files\AnVir Task Manager\AnVir.exe" [2009-12-28 3313888]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2010-06-11 427328]
"Chameleon System Monitor"="c:\program files\Common Files\Chameleon Manager\monitor.exe" [2010-06-18 1810432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-02-28 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-02-28 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-02-28 455168]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-01 7618560]
"nwiz"="nwiz.exe" [2006-06-01 1519616]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 86016]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"P17Helper"="P17.dll" [2005-05-03 64512]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-06 16262656]
"ShellLess"="c:\program files\ShellLess\ShellLess.exe" [2008-09-02 2198528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"ooccctrl.exe"="c:\program files\OO Software\CleverCache\ooccctrl.exe" [2007-01-28 1911568]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"SSC Service Utility"="c:\program files\SSC Service Utility\ssc_serv.exe" [2007-10-09 665600]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-02-28 15360]

c:\documents and settings\Arjun\Start Menu\Programs\Startup\
FastStone Capture.lnk - c:\program files\FastStone Capture\FSCapture.exe [2007-2-13 1111552]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
SnagIt 7.lnk - c:\program files\TechSmith\SnagIt 7\SnagIt32.exe [2005-10-14 3719168]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IpSharkk\\IpSharkk.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"94:TCP"= 94:TCP:VRS Recording System Web Control Panel

R1 anf0100.sys;anf0100.sys;c:\windows\system32\drivers\anf0100.sys [10/09/2008 21:33 9728]
R1 LADriver;LADriver;c:\windows\system32\drivers\LADriver.sys [31/07/2007 16:39 27136]
R1 LDDriver;LDDriver;c:\windows\system32\drivers\LDDriver.sys [31/07/2007 16:39 24064]
R1 LHDriver;LHDriver;c:\windows\system32\drivers\LHDriver.sys [31/07/2007 16:39 14336]
R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [29/05/2009 21:02 95592]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [04/07/2010 21:42 135336]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Adapter;c:\windows\system32\drivers\atl01_xp.sys [14/02/2007 21:55 35712]
R3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [15/05/2009 03:10 16640]
S3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 6\DfSdkS.exe [28/05/2010 05:16 406016]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [06/02/2010 01:24 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [06/02/2010 01:24 8456]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\5.tmp –> c:\windows\system32\5.tmp [?]
S3 p17filt;p17filt;c:\windows\system32\drivers\p17filt.sys –> c:\windows\system32\drivers\p17filt.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [29/05/2009 21:02 697328]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-08-08 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-01-15 12:09]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.sky.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
IE: {{08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com
Trusted Zone: microsoft.com\*.update
Trusted Zone: windowsupdate.com\download
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
DPF: {2D9F7B63-EC7C-43FF-A41D-6E9EC984A5B9} - hxxps://myaccount.gateway.gov.uk/ClientObjects/GGSecSign.cab
DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} - hxxp://drm1.reelsurvey.com/ePlayer/V3_2_0_0/ACNePlayer.cab
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKCU-Run-ADSM - (no file)
HKCU-Run-Invisible Security - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-09 00:40
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\5.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OOCC06.00.00.01WSSV"="857B7EBB918C69CDBE23E64DB8BEA656512C359BAD0D46908F07626C1D83FB78448C36DDAB9
3CDE24443834A71A4F258D6322D1FFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEB
C
9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933C038D530D6EB3452A2D9
7
226D213B555BA7FD869164D679472BC2460482D2043FC6B7C6578A4CA103C8928950ECC19D82FA74
5
A727FBE28A1767CE8E3BDA16AE7007FBDCF539B6D33DF8ED30F271BC7EA8923531BCDAB935EB459B
1
FA3CB54120FE74DF064A80E6DF613BF86188D5B923C08F95FFA7C1105DBAEA171829F95D9B3A1DA8
2
401BEF9B4E437B9795749BC27D6B08F5387D34B9C92288AB8BDD6BF52CE8A3B6BA21D39E1F9894AC
3
95CF6C0F445687A80DCC195893E0E35A3EEB7DBBB18B877B72C003DB845924E06613BC39FC035399
0
002C60E44983B9E89F338395ACC270CF929241DDA011C9AF0309076CAE21C0DC2F3B6899ABCD2AA9
2
3E96AE5C87914D00E7C7746A63EB2212557C94082EEE4099788F857F367B96A8D3B11C9322C16393
E
01319AF3DDDFF50E6FCCF05477BC72C783E943505C616158D97BD3D23D71BE253B467CCD496981EA
E
F584E5F27A2A6B66F9077184E5DFA614FB10AB923E1C8A8950D7E98E7AEC9C84AB59484FC35E6BA6
1
488042732DD5E976C166966769F593D2E626E1BB51851DC3B4F9C78FDAAB1046725E6D9214471800
B
C57C0A9CB151486B1EF565838253E7528A5CF85369ED8DAF108588C9CD473EEB5BCB29A94AA3D1AD
6
4B4A620D48E7CEE5B3E91BB69E18B3ADE4EACF913C6A9B466F08818FF085493D19B497BD46B990C8
3
5842188BD37B61252AB6203E94F308BB885384DD2C5A6D232AF467DA635D02F2D357C9F42819E8E2
2
485EC504552EA4D40FAC24F1BD158AE07A524128C4F87B13B1A3B32828FA179812EFF1E19868B6F7
A
E622CA010CED96577B2C3BBB14896D45824401B3F2D236EFCD8618D14876B47936E43E9C2DE39F0A
E
F18287AD4EE8CFA71F82813F6C2ED022ED38472B87EE5D8EFB0A093FA8A7ABC93041E44972E05B44
4
6FEEE844437E13F9A57042136714716C8666F555E26AF982004E1FCED72BCF4647D2F4F9343B5345
9
E868A1B82887C3278141378B398D8D0A16BEA4CE9431A6D487BFC48BD956863CD7D2B807CA9355FC
C
756F90A6DC63FC8857100754068E887ED546D3585BEDF6955D0586D97D62D45EA3C990BCD536A4AA
5
A3B099F4876F01C2D2B3E8D6618B195427558A4E2E500E5FB2F3166D1E6B948AB3BF4436A31259DC
5
66A57E024FA998DCCE9D133EC6979DE2E4B806006463C0FB1985309CC4DBDD8AC44033CDDC34BFCE
C
B20D0FD746BE6657467A415D23ED52E38A78F90041ED15D8DA42045D1FA4E36731D5AEA8D927370C
E
F02AFEC4B67354447B81632B03D34"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(912)
c:\windows\system32\WININET.dll
c:\program files\SourceTec\Sothink Web Video Downloader Stand-alone\VideoDownloader.dll
c:\program files\AnVir Task Manager\AnvirHook62.dll
c:\windows\system32\ieframe.dll
c:\program files\Atomic Alarm Clock\Clock.dll
.
———————— Other Running Processes ————————
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\ATKKBService.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Digiarty\WinX DVD Author 5.5\NMSAccessU.exe
c:\windows\system32\RunDLL32.exe
c:\windows\system32\Rundll32.exe
c:\windows\system32\nvsvc32.exe
c:\program files\OO Software\CleverCache\ooccag.exe
c:\windows\RTHDCPL.EXE
c:\program files\Raxco\PerfectDisk10\PDAgent.exe
c:\windows\system32\PSIService.exe
c:\windows\System32\TUProgSt.exe
c:\windows\system32\wdfmgr.exe
c:\program files\TechSmith\SnagIt 7\TSCHelp.exe
.
**************************************************************************
.
Completion time: 2010-08-09 00:45:44 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-08 23:45

Pre-Run: 4,196,085,760 bytes free
Post-Run: 4,161,601,536 bytes free

- - End Of File - - 8310EFB94AD868AC017CBD9BD80E7B51
………………………………

Whatever ComboFix has changed or removed has resulted in all the ads returning to every site. I'm unsure what I should do now to protect myself from malicious ads, but still be able to use all the cashback site affiliate tracking links.

Also, visiting the "AA" page, on "topcashback.co.uk", to check if your help had worked, triggered Avira AntiVir with an "HTML/Infected.WebPage.Gen" detection. To be sure it wasn't a false positive, I closed the browser, ran CCleaner and visited the page again. The same detection was made.

Why didn't invalidating "tradedoubler", in the MVPS Hosts file, solve the problem?

I've just opened a new tab and suddenly this WhattheTech text box has become about 20 times wider; although the rest of the page is still the width of my screen.
Previewing this post results in the whole tab becoming about 20 times wider. Is the root of the problem IE?

I plan to install SP3, but have put it off since learning of the problems associated with having an AMD chip.

Thanks for your help, so far.

The page has returned to its normal width, now that I've posted this reply.
Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4411 Windows 5.1.2600 Service Pack 2 Internet Explorer 7.0.5730.13 09/08/2010 19:02:54 mbam-log-2010-08-09 (19-02-54).txt Scan type: Quick scan Objects scanned: 138853 Time elapsed: 5 minute(s), 31 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
OTL Fix
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    
    O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    
    :Commands
    [EmptyFlash]
    [EmptyTemp]
    [RESETHOSTS] 
    [purity]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
Also please describe how your computer behaves at the moment.
Sorry, I thought I was being asked to download a new prog called "OTL Fix". My mistake. All processes killed ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\UpdReg deleted successfully. C:\WINDOWS\Updreg.EXE moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\HonorAutoRunSetting deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully. Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoLowDiskSpaceChecks deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully. ========== COMMANDS ========== [EMPTYFLASH] User: Administrator User: All Users User: Arjun ->Flash cache emptied: 45882 bytes User: Default User ->Flash cache emptied: 41620 bytes User: LocalService User: NetworkService Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Arjun ->Temp folder emptied: 604430 bytes ->Temporary Internet Files folder emptied: 2479899 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 598214 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 4.00 mb C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.9.1 log created on 08102010_013848 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\Arjun\Local Settings\Temp\~DFDEDA.tmp not found! File\Folder C:\Documents and Settings\Arjun\Local Settings\Temp\~DFDEF2.tmp not found! C:\Documents and Settings\Arjun\Local Settings\Temporary Internet Files\Content.IE5\RTH0ZOTR\iframe[1].htm moved successfully. C:\Documents and Settings\Arjun\Local Settings\Temporary Internet Files\Content.IE5\RTH0ZOTR\iframe[2].htm moved successfully. C:\Documents and Settings\Arjun\Local Settings\Temporary Internet Files\Content.IE5\NLIQON66\comment-iframe[1].htm moved successfully. C:\Documents and Settings\Arjun\Local Settings\Temporary Internet Files\Content.IE5\NLIQON66\iframe[1].htm moved successfully. C:\Documents and Settings\Arjun\Local Settings\Temporary Internet Files\Content.IE5\NLIQON66\iframe[2].htm moved successfully. C:\Documents and Settings\Arjun\Local Settings\Temporary Internet Files\Content.IE5\NLIQON66\navbar[1].htm moved successfully. C:\Documents and Settings\Arjun\Local Settings\Temporary Internet Files\Content.IE5\AK1GJAMO\blog-post-reactions[1].htm moved successfully. C:\Documents and Settings\Arjun\Local Settings\Temporary Internet Files\Content.IE5\AK1GJAMO\iframe[1].htm moved successfully. C:\Documents and Settings\Arjun\Local Settings\Temporary Internet Files\Content.IE5\AK1GJAMO\iframe[2].htm moved successfully. C:\Documents and Settings\Arjun\Local Settings\Temporary Internet Files\Content.IE5\AK1GJAMO\index[1].htm moved successfully. C:\Documents and Settings\Arjun\Local Settings\Temporary Internet Files\Content.IE5\AK1GJAMO\like[1].htm moved successfully. C:\Documents and Settings\Arjun\Local Settings\Temporary Internet Files\Content.IE5\84NDBQW8\analysis-politics-of-britain-are-still[1].htm moved successfully. C:\Documents and Settings\Arjun\Local Settings\Temporary Internet Files\Content.IE5\84NDBQW8\iframe[1].htm moved successfully. C:\Documents and Settings\Arjun\Local Settings\Temporary Internet Files\Content.IE5\84NDBQW8\ifr[1].htm moved successfully. C:\Documents and Settings\Arjun\Local Settings\Temporary Internet Files\Content.IE5\84NDBQW8\ifr[2].htm moved successfully. C:\Documents and Settings\Arjun\Local Settings\Temporary Internet Files\AntiPhishing\A0AB7674-8D67-4F4D-B5E1-96FAEADFB79D.dat moved successfully. Registry entries deleted on Reboot… ……………………. I still seem to be able to access the site via the cashback site, so everything appears to be O.K.
I've just logged-out and checked the home page and this post and all the ads are displayed as normal - nothing seems blocked. Similarly all the cashback tracking links appear to work and every advert is still visible on every other site I've checked.

When it says, "Hosts file reset successfully", what Hosts file is this? Similar to MVPS's or a basic Internet Explorer one?
My understanding is it takes the host back to basic.

We need to do this before I forget.

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI