This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ie redirecting me tp porno sites

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Guys
This is my first post so i hope i have done right
over the last week when either searching using google or fav bar i get directed to porno sites for some reason and also to other sites that sell anything from cars to to electricle goods.Can anyone help me to stop this.
Kind Regards John


Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 06:20:16, on 03/09/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\ehome\ehSched.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Toshiba Controls\CpRmtKey.EXE
C:\Program Files\EzButton\CplBTQ00.EXE
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Flying Club Alerts\flyingclubalerts.exe
C:\WINDOWS\system32\RAMASST.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Gibbo\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.toshiba.com/search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [TPNF] "C:\Program Files\TOSHIBA\TouchPad\TPTray.exe"
O4 - HKLM\..\Run: [ehTray] "C:\WINDOWS\ehome\ehtray.exe"
O4 - HKLM\..\Run: [CpRmtKey] "C:\Program Files\Toshiba Controls\CpRmtKey.EXE"
O4 - HKLM\..\Run: [CplBTQ00] "C:\Program Files\EzButton\CplBTQ00.EXE"
O4 - HKLM\..\Run: [CeEPOWER] "C:\Program Files\TOSHIBA\Power Management\CePMTray.exe"
O4 - HKLM\..\Run: [CeEKEY] "C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe"
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] "C:\PROGRA~1\AVG\AVG9\avgtray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Flying Club Alerts] "C:\Program Files\Flying Club Alerts\flyingclubalerts.exe"
O4 - HKCU\..\Run: [XBV6RD5SZF] C:\DOCUME~1\Gibbo\LOCALS~1\Temp\Rps.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {03B03C66-15CB-4F16-BA86-83A55A9B0EA4} (Intellinet_Viewer Control) - http://webcam.crowsnest-venice.com/Intellinet_Viewer.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6087.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1189168150828
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1189168106921
O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) - http://dl.uc.sina.com/cab/downloader.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://floridakeysmedia.tv/axiscam/Codebas…sCamControl.ocx
O16 - DPF: {96816368-C1E3-414D-A193-63C3CC921990} (MJPEGRender Control) - http://gretnaweddings-anvilhall.remotemana…MJPEGRender.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} (VodClient Control Class) - http://vexcast.com/download/vexcast.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://65.14.83.37/activex/AMC.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 10544 bytes
e
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post
•Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
•This may cause a delay in response time, but I will do my best to keep it as short as possible.
•I will reply back shortly with instructions.
Please do the following


Run hijackThis like this.Start HijackThis and select Do a system scan only Close all open windows leaving only HijackThis running. Place a check against each of the following if present.Then click fix checked

O4 - HKCU\..\Run: [XBV6RD5SZF] C:\DOCUME~1\Gibbo\LOCALS~1\Temp\Rps.exe








  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.




[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER won't run try with devices unchecked.If still no go try in safe mode.



In your next reply please post the following.
  • Both OTL logs
  • GMER log
OTL Extras logfile created on: 04/09/2010 06:58:43 - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Gibbo\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,023.00 Mb Total Physical Memory | 528.00 Mb Available Physical Memory | 52.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 13.74 Gb Free Space | 18.44% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: GIBBOMOBILE
Current User Name: Gibbo
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Connect
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Connect
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Connect
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Connect
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Connect
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Connect
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Connect
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Connect
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Connect
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Connect
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Connect
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Connect
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Flying Club Alerts\flyingclubalerts.exe" = C:\Program Files\Flying Club Alerts\flyingclubalerts.exe – (Skinkers Communications)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – (America Online, Inc.)
"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) – File not found
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – File not found
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe – File not found
"C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe – File not found
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Flying Club Alerts\flyingclubalerts.exe" = C:\Program Files\Flying Club Alerts\flyingclubalerts.exe – (Skinkers Communications)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – (America Online, Inc.)
"C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe" = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager – (Nexon)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\SopCast\adv\SopAdver.exe" = C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver – (www.sopcast.com)
"C:\Program Files\SopCast\SopCast.exe" = C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application – File not found
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Program Files\QuickTime\QuickTimePlayer.exe" = C:\Program Files\QuickTime\QuickTimePlayer.exe:*:Enabled:QuickTime Player – (Apple Inc.)
"C:\WINDOWS\system32\ppshell.exe" = C:\WINDOWS\system32\ppshell.exe:*:Enabled:ppshell – (ForceTech)
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\AVG\AVG9\avgam.exe" = C:\Program Files\AVG\AVG9\avgam.exe:*:Enabled:avgam.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgdiagex.exe" = C:\Program Files\AVG\AVG9\avgdiagex.exe:*:Enabled:avgdiagex.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgemc.exe" = C:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{01053FC0-0D8E-4452-BAC3-A41E364D22EF}" = SendPhotos
"{025C3792-E9C6-432A-92C1-661F99D021CA}" = Ulead Photo Explorer 8.5
"{0415F42D-B746-4166-99E4-1CA5FAEAC18F}" = TOSHIBA Hotkey Utility
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{079F3B36-05A1-4FA1-937C-E2EFF92A73E4}" = TouchPad On/Off Utility
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0DA9061C-A8C6-4B0E-BF2B-1E444D8642E3}" = Sonic PrimeTime
"{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{2CD2C0DB-81C3-416B-9FA6-589B9235359B}" = OpenOffice.org 2.4
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator 2
"{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3CF0858D-1AC5-4308-9DE7-AD15288A8BDC}" = TOSHIBA Console
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{48CF9A66-5F03-4025-ABD0-B3A3FA095A59}" = TOSHIBA SD Memory Card Format
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{6202755A-39B7-4465-BB0D-62D5D5991738}" = PC SpeedScan Pro
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{76E46F23-8DFB-4993-895E-80D95FEE6E86}" = Atheros Client Utility
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo
"{7F34A21F-2DEB-4598-BB19-611D6BD24271}" = Managed DirectX (0901)
"{80D95911-28E9-40AC-A6B5-1DA6D9F14B29}" = Software Suite
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83ED1E80-A1B7-4226-BCF1-AC4A88151A6B}" = Microsoft Streets & Trips 2006
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{876CD8AC-B62C-4F8A-9084-3201CC96A5D2}" = TOSHIBA Power Management Utility
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8D6AE289-7A5E-41B4-A7F0-687C2DAB1B87}" = Microsoft Location Finder
"{924EB80F-C2BB-4B9F-8412-88BBA937393F}" = MobileMe Control Panel
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97AA0C55-AFAD-4126-B21C-F1318FB6DADA}" = Realtek Fast Ethernet Adapter Driver
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD 4
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9D765FA6-F2BC-40AF-8145-50808F9BDF4E}" = DVD-RAM Driver
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A6C11493-C2E4-4240-A59F-5DC804071DA6}" = Hemera Photo-Objects 1000
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A962C8E1-4F0B-4BA9-806E-B8D9A3B31F82}" = SurfHere by Toshiba
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.4
"{AEC0CEBC-0FC7-4716-8222-1C4A742719B1}" = Samsung Master
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2D129C0-7508-11DF-9F1B-005056806466}" = Google Earth
"{C82E1703-ACBB-4015-856B-A8A0E5BAC661}" = Ulead CD & DVD PictureShow 3
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE325D55-FCAF-4273-BB79-069BB8747270}" = TomTom HOME
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{DDC146FA-73E0-4FA1-A353-841EA14BF600}" = Drag'n Drop CD+DVD
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{EC86822D-3A20-11D5-801B-00E029348F40}" = SMSC IrCC Driver V5.1.2462.0 (WinXP)
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F6C405D2-C50D-4D10-B89E-73A233A14D74}" = Toshiba Registration
"{F958CA02-BB40-4007-894B-258729456EE4}" = QuickTime
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"America Online us" = America Online (Choose which version to remove)
"AolCoach" = AOL Coach Version 1.0(Build:20030807.3)
"APU" = CANON iMAGE GATEWAY Album Plugin Utility
"AT&T Connection Services Software" = AT&T Connection Services Manager
"AVG9Uninstall" = AVG 9.0
"AXIS Media Control Embedded" = AXIS Media Control Embedded
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"Bicycle Board Games 1.0" = Bicycle Board Games
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"Canon Camera WIA Driver EOS D60" = Canon EOS D60 WIA Driver
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"Canon PhotoStitch 3.1" = Canon Utilities PhotoStitch 3.1
"Canon Utilities RAW Image Converter2" = Canon Utilities RAW Image Converter2
"CANONBJ_Deinstall_CNMCP3i.DLL" = Canon S9000
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CplBTQ00" = Easy Button
"CpRmtKey" = Toshiba Controls
"CSCLIB" = Canon Camera Support Core Library
"DPP" = Canon Utilities Digital Photo Professional 2.2
"DVDFab Passkey 7_is1" = DVDFab Passkey 7.0.3.6 BETA (04/08/2010)
"EOS Utility" = Canon Utilities EOS Utility
"Flying Club Alerts" = Flying Club Alerts (remove only)
"Game Booster_is1" = Game Booster
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"ImageRecall 3" = ImageRecall 3
"InstallShield_{0415F42D-B746-4166-99E4-1CA5FAEAC18F}" = TOSHIBA Hotkey Utility
"InstallShield_{079F3B36-05A1-4FA1-937C-E2EFF92A73E4}" = TouchPad On/Off Utility
"InstallShield_{876CD8AC-B62C-4F8A-9084-3201CC96A5D2}" = TOSHIBA Power Management Utility
"InstallShield_{A6C11493-C2E4-4240-A59F-5DC804071DA6}" = Hemera Photo-Objects 1000
"LMS" = C-Dilla Licence Management System
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Notebook_Maximizer" = Notebook Maximizer
"NSS" = Norton Security Scan
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"PhotoRecord" = Canon PhotoRecord
"PhotoStitch" = Canon Utilities PhotoStitch
"ProcessScanner_is1" = Uniblue ProcessScanner
"Q903235" = Internet Explorer Q903235
"Quicken 2002 Deluxe" = Quicken 2002 Deluxe
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 12.0" = RealPlayer
"RemoteCapture" = Canon Utilities RemoteCapture 2.3
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"RescuePRO-3.0" = RescuePRO 3.3
"Revo Uninstaller" = Revo Uninstaller 1.89
"Smart Defrag_is1" = Smart Defrag
"StreetPlugin" = Learn2 Player (Uninstall Only)
"SystemRequirementsLab" = System Requirements Lab
"TOSHIBA Access" = TOSHIBA Access
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"TOSHIBA Software Upgrades" = TOSHIBA Software Upgrades
"Toshiba Tbiosdrv Driver" = Toshiba Tbiosdrv Driver
"Veetle TV" = Veetle TV 0.9.16
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMCSetup" = Windows Media Connect
"Xvid_is1" = Xvid 1.1.2 final uninstall
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 06/08/2010 12:52:49 | Computer Name = GIBBOMOBILE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 06/08/2010 12:52:50 | Computer Name = GIBBOMOBILE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 07/08/2010 13:52:15 | Computer Name = GIBBOMOBILE | Source = Application Error | ID = 1000
Description = Faulting application googleearth.exe, version 5.2.1.1329, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

Error - 14/08/2010 13:19:53 | Computer Name = GIBBOMOBILE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module jvm.dll, version 16.3.0.1, fault address 0x000f9c30.

Error - 22/08/2010 05:20:12 | Computer Name = GIBBOMOBILE | Source = Application Error | ID = 1000
Description = Faulting application googleearth.exe, version 5.2.1.1329, faulting
module msvcr80.dll, version 8.0.50727.4053, fault address 0x00008aa0.

Error - 28/08/2010 12:22:48 | Computer Name = GIBBOMOBILE | Source = Application Error | ID = 1000
Description = Faulting application ccsvchst.exe, version 107.0.6.4, faulting module
netdog.dll, version 0.0.0.0, fault address 0x000067f9.

Error - 28/08/2010 15:59:24 | Computer Name = GIBBOMOBILE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established

Error - 28/08/2010 20:16:46 | Computer Name = GIBBOMOBILE | Source = MPSampleSubmission | ID = 5000
Description =

[ Media Center Events ]
Error - 24/08/2008 06:36:42 | Computer Name = GIBBOMOBILE | Source = Recording | ID = 19
Description = The recording schedule has been corrupted and was automatically deleted
on 8/24/2008 11:36:42 AM. You may need to reschedule your recordings.

[ System Events ]
Error - 02/09/2010 00:44:53 | Computer Name = GIBBOMOBILE | Source = Service Control Manager | ID = 7000
Description = The Application Layer Gateway Service service failed to start due
to the following error: %%1053

Error - 02/09/2010 03:20:31 | Computer Name = GIBBOMOBILE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Application Layer Gateway
Service service to connect.

Error - 02/09/2010 03:20:37 | Computer Name = GIBBOMOBILE | Source = Service Control Manager | ID = 7000
Description = The Application Layer Gateway Service service failed to start due
to the following error: %%1053

Error - 02/09/2010 10:07:44 | Computer Name = GIBBOMOBILE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Application Layer Gateway
Service service to connect.

Error - 02/09/2010 10:07:50 | Computer Name = GIBBOMOBILE | Source = Service Control Manager | ID = 7000
Description = The Application Layer Gateway Service service failed to start due
to the following error: %%1053

Error - 02/09/2010 18:03:48 | Computer Name = GIBBOMOBILE | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the WebrootSpySweeperService service.

Error - 02/09/2010 18:09:27 | Computer Name = GIBBOMOBILE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the HTTP SSL service to connect.

Error - 02/09/2010 18:09:27 | Computer Name = GIBBOMOBILE | Source = Service Control Manager | ID = 7000
Description = The HTTP SSL service failed to start due to the following error: %%1053

Error - 03/09/2010 14:19:33 | Computer Name = GIBBOMOBILE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Application Layer Gateway
Service service to connect.

Error - 03/09/2010 14:19:43 | Computer Name = GIBBOMOBILE | Source = Service Control Manager | ID = 7000
Description = The Application Layer Gateway Service service failed to start due
to the following error: %%1053


< End of report >
OTL logfile created on: 04/09/2010 06:58:43 - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Gibbo\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,023.00 Mb Total Physical Memory | 528.00 Mb Available Physical Memory | 52.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 13.74 Gb Free Space | 18.44% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: GIBBOMOBILE
Current User Name: Gibbo
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Gibbo\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgfws9.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgam.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Flying Club Alerts\flyingclubalerts.exe (Skinkers Communications)
PRC - C:\Program Files\EzButton\CplBTQ00.EXE (Dritek System Inc.)
PRC - C:\Program Files\Toshiba\E-KEY\CeEKey.exe (COMPAL ELECTRONIC INC.)
PRC - C:\Program Files\Toshiba Controls\CpRmtKey.EXE (Dritek System Inc.)
PRC - C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
PRC - C:\WINDOWS\system32\ezSP_Px.exe (Easy Systems Japan Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Gibbo\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\iphlpapi.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avgfws9) – C:\Program Files\AVG\AVG9\avgfws9.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (vvdsvc) – C:\WINDOWS\system32\nagasoft\vjocx.dll (NanJing Nagasoft Co, LTD.)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WMConnectCDS) – C:\Program Files\Windows Media Connect 2\wmccds.exe (Microsoft Corporation)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (DVD-RAM_Service) – C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
SRV - (WANMiniportService) WAN Miniport (ATW) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
SRV - (C-DillaSrv) – C:\WINDOWS\system32\drivers\CDANTSRV.EXE (C-Dilla Ltd)


========== Driver Services (SafeList) ==========

DRV - (SymIMMP) – C:\WINDOWS\System32\DRIVERS\SymIM.sys File not found
DRV - (SymIM) – C:\WINDOWS\System32\DRIVERS\SymIM.sys File not found
DRV - (npkcrypt) – C:\Program Files\Lineage II\system\npkcrypt.sys File not found
DRV - (EagleNT) – C:\WINDOWS\System32\drivers\EagleNT.sys File not found
DRV - (AvgMfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSErHrxpx) – C:\WINDOWS\System32\Drivers\AVGIDSxx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AvgRkx86) – C:\WINDOWS\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriverxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilterxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShimxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgfwfd) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgfwdx) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (dvdfab) – C:\WINDOWS\system32\drivers\dvdfab.sys (Fengtao Software Inc.)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (IrBus) – C:\WINDOWS\system32\drivers\irbus.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\SHP5211.sys (Atheros Communications, Inc.)
DRV - (genmcmnUSB) – C:\WINDOWS\system32\drivers\gflmouhid.sys ()
DRV - (BayTvKit) – C:\WINDOWS\system32\drivers\BayTvKit.sys (Emuzed, Inc.)
DRV - (MDC8021X) WPA Security Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (EPOWER) – C:\WINDOWS\system32\drivers\hkdrv.sys (Compal Electronic Inc.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (Pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (tsdhd) – C:\WINDOWS\system32\drivers\tsdhd.sys (TOSHIBA Corporation)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (DKbFltr) – C:\WINDOWS\system32\drivers\DKbFltr.SYS (Dritek System Inc.)
DRV - (pciSd) – C:\WINDOWS\system32\drivers\tossdpci.sys (TOSHIBA)
DRV - (meiudf) – C:\WINDOWS\system32\drivers\meiudf.sys (Matsushita Electric Industrial Co.,Ltd.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (SrvcSSIOMngr) – C:\WINDOWS\system32\drivers\SSIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (SrvcEPIOMngr) – C:\WINDOWS\system32\drivers\EPIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (SrvcEKIOMngr) – C:\WINDOWS\system32\drivers\EKIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\R8139n51.sys (Realtek Semiconductor Corporation )
DRV - (SrvcTPIOMngr) – C:\WINDOWS\system32\drivers\TPIOMngr.sys ()
DRV - (SMCIRDA) – C:\WINDOWS\system32\drivers\smcirda.sys (SMC)
DRV - (TBiosDrv) – C:\WINDOWS\system32\drivers\Tbiosdrv.sys ()
DRV - (C-Dilla) – C:\WINDOWS\system32\drivers\CDANT.SYS (Macrovision)
DRV - (mrtRate) – C:\WINDOWS\System32\drivers\MrtRate.sys (Marimba, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local

FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/07/16 17:33:34 | 000,000,000 | —D | M]

[2010/08/28 21:10:57 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/08/20 19:07:11 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/08/20 19:06:40 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2007/04/30 20:51:58 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {0A87E45F-537A-40B4-B812-E2544C21A09F} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [CplBTQ00] C:\Program Files\EzButton\CplBTQ00.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [CpRmtKey] C:\Program Files\Toshiba Controls\CpRmtKey.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe (Easy Systems Japan Ltd.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe (COMPAL ELECTRONIC INC.)
O4 - HKCU..\Run: [Flying Club Alerts] C:\Program Files\Flying Club Alerts\flyingclubalerts.exe (Skinkers Communications)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O16 - DPF: {03B03C66-15CB-4F16-BA86-83A55A9B0EA4} http://webcam.crowsnest-venice.com/Intellinet_Viewer.cab (Intellinet_Viewer Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/3/9…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6087.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu…b?1189168150828 (WUWebControl Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1189168106921 (MUWebControl Class)
O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} http://dl.uc.sina.com/cab/downloader.cab (DLoader Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://floridakeysmedia.tv/axiscam/Codebas…sCamControl.ocx (CamImage Class)
O16 - DPF: {96816368-C1E3-414D-A193-63C3CC921990} http://gretnaweddings-anvilhall.remotemana…MJPEGRender.ocx (MJPEGRender Control)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} http://vexcast.com/download/vexcast.cab (VodClient Control Class)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://65.14.83.37/activex/AMC.cab (AxisMediaControlEmb Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop BackupWallPaper: C:\WINDOWS\Toshiba.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: Ip6FwHlp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.siren - C:\WINDOWS\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (11272609819787264)

========== Files/Folders - Created Within 30 Days ==========

[2010/09/04 06:48:24 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Gibbo\Desktop\OTL.exe
[2010/09/04 06:44:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Gibbo\Desktop\backups
[2010/09/03 06:17:57 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Gibbo\Desktop\HiJackThis.exe
[2010/09/02 23:04:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Webroot
[2010/09/02 17:56:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Gibbo\Local Settings\Application Data\PackageAware
[2010/09/02 17:52:29 | 000,000,000 | —D | C] – C:\Program Files\Uniblue
[2010/08/31 22:26:28 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\NSS
[2010/08/31 22:26:28 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\NSS\0207030.022
[2010/08/31 22:26:27 | 000,000,000 | —D | C] – C:\Program Files\Norton Security Scan
[2010/08/31 22:26:23 | 000,000,000 | —D | C] – C:\Program Files\NortonInstaller
[2010/08/31 22:26:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2010/08/31 17:40:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Gibbo\Application Data\AVG9
[2010/08/30 15:33:14 | 007,484,936 | —- | C] (IObit ) – C:\Documents and Settings\Gibbo\Desktop\asc-setup-aff.exe
[2010/08/29 11:51:08 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/08/29 11:24:17 | 000,000,000 | —D | C] – C:\spoolerlogs
[2010/08/29 11:12:11 | 000,012,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/08/29 11:12:08 | 000,029,584 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/08/29 11:11:55 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2010/08/29 11:09:26 | 000,025,168 | —- | C] (AVG Technologies CZ, s.r.o. ) – C:\WINDOWS\System32\drivers\AVGIDSxx.sys
[2010/08/29 11:09:25 | 000,052,872 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgrkx86.sys
[2010/08/29 11:09:21 | 000,243,024 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/08/29 11:09:19 | 000,216,400 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/08/29 11:03:23 | 000,050,968 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgfwdx.dll
[2010/08/29 11:03:23 | 000,030,104 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgfwdx.sys
[2010/08/29 11:01:21 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2010/08/29 11:00:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/08/29 10:40:21 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2010/08/29 10:35:11 | 002,133,536 | —- | C] (AVG Technologies) – C:\Documents and Settings\Gibbo\Desktop\avg_free_stb_all_9_115_cnet.exe
[2010/08/29 02:13:13 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2010/08/29 01:18:29 | 000,221,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/08/28 21:04:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2010/08/28 21:01:59 | 000,000,000 | —D | C] – C:\Program Files\Common Files\iS3
[2010/08/28 21:01:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/08/28 20:43:48 | 000,532,480 | —- | C] (Trend Micro Incorporated) – C:\Documents and Settings\Gibbo\Desktop\cwshredder.exe
[2010/08/28 18:39:35 | 000,000,000 | —D | C] – C:\Program Files\Norton 360
[2010/08/20 21:01:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9 Installer
[2010/08/20 20:59:58 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/08/20 20:59:57 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/08/20 20:59:57 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/08/20 19:07:07 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/08/20 19:07:06 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/08/20 19:07:06 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/08/20 19:07:06 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/08/18 19:40:21 | 000,000,000 | —D | C] – C:\Program Files\IWONGEI
[2010/08/15 20:05:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Gibbo\Local Settings\Application Data\Mozilla
[2010/08/15 20:05:39 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/08/13 10:14:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Gibbo\My Documents\DVDFab Passkey
[2010/08/13 10:14:49 | 000,044,928 | —- | C] (Fengtao Software Inc.) – C:\WINDOWS\System32\drivers\dvdfab.sys
[2010/08/13 10:14:48 | 000,000,000 | —D | C] – C:\Program Files\DVDFab Passkey 7
[2010/08/07 16:05:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Gibbo\Desktop\100705_01_BDP1500_XAA
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/09/04 06:58:22 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-4022485809-4210471992-1704011695-1004.job
[2010/09/04 06:58:22 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-4022485809-4210471992-1704011695-1004.job
[2010/09/04 06:55:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/04 06:54:00 | 000,000,282 | -H– | M] () – C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/09/04 06:48:36 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Gibbo\Desktop\OTL.exe
[2010/09/04 05:50:30 | 064,275,422 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/09/04 05:47:38 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/09/04 05:45:36 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/04 05:45:35 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/04 05:45:24 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/04 05:45:19 | 1072,746,496 | -HS- | M] () – C:\hiberfil.sys
[2010/09/03 20:46:12 | 007,077,888 | —- | M] () – C:\Documents and Settings\Gibbo\ntuser.dat
[2010/09/03 20:46:12 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Gibbo\ntuser.ini
[2010/09/03 20:45:43 | 010,197,476 | -H– | M] () – C:\Documents and Settings\Gibbo\Local Settings\Application Data\IconCache.db
[2010/09/03 17:50:53 | 000,000,474 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for Gibbo.job
[2010/09/03 06:18:02 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Gibbo\Desktop\HiJackThis.exe
[2010/09/02 23:04:37 | 000,000,678 | —- | M] () – C:\WINDOWS\win.ini
[2010/09/02 17:52:30 | 000,000,792 | —- | M] () – C:\Documents and Settings\Gibbo\Application Data\Microsoft\Internet Explorer\Quick Launch\ProcessScanner.lnk
[2010/09/02 17:52:30 | 000,000,774 | —- | M] () – C:\Documents and Settings\Gibbo\Desktop\ProcessScanner.lnk
[2010/09/01 21:04:55 | 000,222,365 | —- | M] () – C:\Documents and Settings\Gibbo\Desktop\panasonic.pdf
[2010/08/31 22:26:32 | 000,000,979 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton Security Scan.lnk
[2010/08/31 22:26:28 | 000,000,172 | —- | M] () – C:\WINDOWS\System32\drivers\NSS\0207030.022\isolate.ini
[2010/08/30 17:12:05 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/08/30 15:33:34 | 007,484,936 | —- | M] (IObit ) – C:\Documents and Settings\Gibbo\Desktop\asc-setup-aff.exe
[2010/08/30 13:24:35 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/08/30 13:24:35 | 000,000,209 | RHS- | M] () – C:\boot.ini
[2010/08/29 11:12:14 | 000,012,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/08/29 11:12:14 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 9.0.lnk
[2010/08/29 11:12:11 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/08/29 11:12:08 | 000,616,965 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavifw.avm
[2010/08/29 11:12:07 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/08/29 11:09:26 | 000,025,168 | —- | M] (AVG Technologies CZ, s.r.o. ) – C:\WINDOWS\System32\drivers\AVGIDSxx.sys
[2010/08/29 11:09:25 | 000,052,872 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgrkx86.sys
[2010/08/29 11:09:24 | 000,243,024 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/08/29 11:09:19 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/08/29 11:03:23 | 000,050,968 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgfwdx.dll
[2010/08/29 11:03:23 | 000,030,104 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgfwdx.sys
[2010/08/29 10:40:21 | 000,000,917 | —- | M] () – C:\Documents and Settings\Gibbo\Desktop\Revo Uninstaller.lnk
[2010/08/29 10:40:10 | 002,406,288 | —- | M] () – C:\Documents and Settings\Gibbo\Desktop\revosetup.exe
[2010/08/29 10:35:17 | 002,133,536 | —- | M] (AVG Technologies) – C:\Documents and Settings\Gibbo\Desktop\avg_free_stb_all_9_115_cnet.exe
[2010/08/29 01:15:20 | 005,154,304 | —- | M] () – C:\Documents and Settings\Gibbo\Desktop\WindowsDefender.msi
[2010/08/28 21:41:13 | 001,757,184 | -H– | M] () – C:\SZKGFS.dat
[2010/08/28 21:35:56 | 000,000,240 | —- | M] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2010/08/28 20:43:55 | 000,532,480 | —- | M] (Trend Micro Incorporated) – C:\Documents and Settings\Gibbo\Desktop\cwshredder.exe
[2010/08/28 17:31:23 | 000,087,090 | —- | M] () – C:\Documents and Settings\Gibbo\My Documents\fairfield booking.eml
[2010/08/25 05:08:13 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/08/24 19:57:13 | 000,088,436 | —- | M] () – C:\Documents and Settings\Gibbo\Desktop\Confirmation(ST)_97997–815947937.pdf
[2010/08/22 09:12:18 | 000,034,569 | —- | M] () – C:\WINDOWS\System32\uninstall.exe
[2010/08/20 19:06:39 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/08/20 19:06:39 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/08/20 19:06:39 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/08/20 19:06:39 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/08/20 19:06:38 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/08/13 14:13:47 | 000,190,592 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/13 12:56:01 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/13 12:50:35 | 000,504,932 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/13 12:50:35 | 000,443,458 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/13 12:50:35 | 000,072,700 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/13 10:14:50 | 000,000,713 | —- | M] () – C:\Documents and Settings\Gibbo\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab Passkey 7.lnk
[2010/08/13 10:14:50 | 000,000,695 | —- | M] () – C:\Documents and Settings\Gibbo\Desktop\DVDFab Passkey 7.lnk
[2010/08/07 12:46:54 | 000,065,536 | —- | M] () – C:\Documents and Settings\Gibbo\Desktop\LLU_CPE_compatability_list.xls
[2010/08/07 12:43:12 | 000,003,735 | —- | M] () – C:\WINDOWS\machine.ver
[2010/08/07 12:43:06 | 000,000,067 | —- | M] () – C:\WINDOWS\swupdate.ini
[2010/08/07 09:55:31 | 000,001,915 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/08/06 16:44:43 | 000,084,069 | —- | M] () – C:\Documents and Settings\Gibbo\My Documents\anfield_seating_plan.pdf
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/02 17:52:30 | 000,000,792 | —- | C] () – C:\Documents and Settings\Gibbo\Application Data\Microsoft\Internet Explorer\Quick Launch\ProcessScanner.lnk
[2010/09/02 17:52:30 | 000,000,774 | —- | C] () – C:\Documents and Settings\Gibbo\Desktop\ProcessScanner.lnk
[2010/09/01 21:04:52 | 000,222,365 | —- | C] () – C:\Documents and Settings\Gibbo\Desktop\panasonic.pdf
[2010/08/31 22:26:34 | 000,000,474 | -H– | C] () – C:\WINDOWS\tasks\Norton Security Scan for Gibbo.job
[2010/08/31 22:26:32 | 000,000,979 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Norton Security Scan.lnk
[2010/08/31 22:26:28 | 000,000,172 | —- | C] () – C:\WINDOWS\System32\drivers\NSS\0207030.022\isolate.ini
[2010/08/29 11:12:14 | 000,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG 9.0.lnk
[2010/08/29 11:12:07 | 000,616,965 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavifw.avm
[2010/08/29 11:12:07 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/08/29 11:11:55 | 064,275,422 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/08/29 10:40:21 | 000,000,917 | —- | C] () – C:\Documents and Settings\Gibbo\Desktop\Revo Uninstaller.lnk
[2010/08/29 10:39:41 | 002,406,288 | —- | C] () – C:\Documents and Settings\Gibbo\Desktop\revosetup.exe
[2010/08/29 01:14:40 | 005,154,304 | —- | C] () – C:\Documents and Settings\Gibbo\Desktop\WindowsDefender.msi
[2010/08/28 21:41:13 | 001,757,184 | -H– | C] () – C:\SZKGFS.dat
[2010/08/28 21:35:56 | 000,000,240 | —- | C] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2010/08/28 17:31:23 | 000,087,090 | —- | C] () – C:\Documents and Settings\Gibbo\My Documents\fairfield booking.eml
[2010/08/27 17:11:22 | 000,000,282 | -H– | C] () – C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/08/24 19:57:13 | 000,088,436 | —- | C] () – C:\Documents and Settings\Gibbo\Desktop\Confirmation(ST)_97997–815947937.pdf
[2010/08/20 21:07:59 | 000,001,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/08/20 06:58:12 | 000,000,278 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-4022485809-4210471992-1704011695-1004.job
[2010/08/13 10:14:50 | 000,000,713 | —- | C] () – C:\Documents and Settings\Gibbo\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab Passkey 7.lnk
[2010/08/13 10:14:50 | 000,000,695 | —- | C] () – C:\Documents and Settings\Gibbo\Desktop\DVDFab Passkey 7.lnk
[2010/08/07 09:55:31 | 000,001,915 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/08/06 16:44:43 | 000,084,069 | —- | C] () – C:\Documents and Settings\Gibbo\My Documents\anfield_seating_plan.pdf
[2010/06/13 14:47:48 | 000,000,095 | —- | C] () – C:\WINDOWS\QHI.INI
[2009/11/17 18:58:51 | 000,307,200 | —- | C] () – C:\WINDOWS\System32\AscSQLite.dll
[2009/01/02 13:31:52 | 000,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/01/02 13:31:51 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/04/26 06:21:47 | 000,000,000 | —- | C] () – C:\WINDOWS\TPTray.INI
[2007/04/20 13:44:07 | 000,000,020 | —- | C] () – C:\WINDOWS\powerplayer.ini
[2007/04/20 13:44:02 | 000,000,270 | —- | C] () – C:\WINDOWS\psnetwork.ini
[2006/12/31 19:41:30 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\CNMVS3i.DLL
[2005/10/08 11:02:39 | 000,000,000 | —- | C] () – C:\WINDOWS\NDSBrow.INI
[2005/09/30 15:11:23 | 000,215,552 | —- | C] () – C:\WINDOWS\System32\Webupdate2.dll
[2005/09/30 15:11:22 | 000,002,309 | —- | C] () – C:\WINDOWS\System32\french.ini
[2005/09/30 15:11:22 | 000,002,194 | —- | C] () – C:\WINDOWS\System32\spanish.ini
[2005/09/30 15:11:22 | 000,001,673 | —- | C] () – C:\WINDOWS\System32\english.ini
[2005/09/30 13:47:21 | 000,000,071 | —- | C] () – C:\WINDOWS\Pex.INI
[2005/08/07 10:12:47 | 000,000,027 | —- | C] () – C:\WINDOWS\GraphicsDesk.INI
[2004/10/21 21:27:07 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2004/10/21 21:27:07 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2004/10/21 21:27:07 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2004/10/21 21:27:07 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2004/10/21 21:27:07 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2004/10/21 21:26:09 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/10/11 05:27:13 | 000,010,752 | —- | C] () – C:\Documents and Settings\Gibbo\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/10/09 17:59:56 | 000,000,196 | —- | C] () – C:\Documents and Settings\Gibbo\Application Data\G-Force Prefs (WindowsMediaPlayer).txt
[2004/10/02 14:48:34 | 000,000,000 | —- | C] () – C:\WINDOWS\OPPRIN~1.INI
[2004/10/02 13:26:39 | 000,000,000 | —- | C] () – C:\WINDOWS\QFN.ini
[2004/10/02 13:26:39 | 000,000,000 | —- | C] () – C:\WINDOWS\QDQICK.ini
[2004/10/02 11:07:51 | 000,000,128 | —- | C] () – C:\Documents and Settings\Gibbo\Local Settings\Application Data\fusioncache.dat
[2004/04/19 16:01:00 | 000,006,656 | —- | C] () – C:\WINDOWS\System32\drivers\gflmouhid.sys
[2003/08/28 00:57:32 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/08/28 00:17:10 | 000,000,000 | —- | C] () – C:\WINDOWS\CeEKey.INI
[2003/08/27 18:42:38 | 000,000,021 | —- | C] () – C:\WINDOWS\CS_setup.ini
[2003/08/27 18:37:31 | 000,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/08/27 18:37:03 | 000,001,271 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/08/27 18:29:57 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2003/08/27 18:29:57 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2003/08/27 18:29:57 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2003/08/27 18:29:57 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2003/08/27 18:29:57 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2003/08/27 18:29:57 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2003/08/27 18:29:13 | 000,000,426 | —- | C] () – C:\WINDOWS\System32\Px.ini
[2003/08/27 18:24:15 | 000,651,264 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2003/08/27 18:24:15 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2003/08/27 18:21:02 | 000,000,000 | —- | C] () – C:\WINDOWS\NDSTray.INI
[2003/08/27 18:14:42 | 000,000,000 | —- | C] () – C:\WINDOWS\CePMTray.INI
[2003/08/27 18:14:30 | 000,000,067 | —- | C] () – C:\WINDOWS\swupdate.ini
[2003/08/27 17:47:44 | 000,128,113 | —- | C] () – C:\WINDOWS\System32\csellang.ini
[2003/08/27 17:47:44 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\csellang.dll
[2003/08/27 17:47:44 | 000,009,538 | —- | C] () – C:\WINDOWS\System32\tosmreg.ini
[2003/08/27 17:47:44 | 000,007,671 | —- | C] () – C:\WINDOWS\System32\cseltbl.ini
[2003/08/27 17:05:51 | 000,006,528 | —- | C] () – C:\WINDOWS\System32\drivers\Tbiosdrv.sys
[2003/08/27 01:02:54 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/08/27 00:51:17 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/08/27 00:25:29 | 000,000,382 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/08/07 20:18:32 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\CeEPPolicy.dll
[2003/08/06 03:07:26 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\CeEPDefDat.dll
[2003/08/05 21:25:44 | 000,098,384 | —- | C] () – C:\WINDOWS\System32\EzRating.dll
[2003/06/10 01:48:16 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\CeEKPolicy.dll
[2002/07/18 01:45:48 | 000,004,183 | —- | C] () – C:\WINDOWS\System32\drivers\TPIOMngr.sys
[2001/09/06 23:35:00 | 000,000,036 | —- | C] () – C:\WINDOWS\A3W.ini
[2000/04/12 20:24:10 | 000,338,944 | —- | C] () – C:\WINDOWS\System32\LFFPX7.DLL
[1998/08/16 05:00:00 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll
[1997/09/30 19:30:02 | 000,122,880 | —- | C] () – C:\WINDOWS\System32\LFKODAK.DLL

========== LOP Check ==========

[2010/08/29 11:01:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2006/10/28 10:05:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cloudmark
[2010/04/09 13:24:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2008/12/01 19:24:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2010/08/28 21:04:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2010/08/29 01:10:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2007/10/13 20:40:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/04/19 12:40:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tenebril
[2007/02/09 21:43:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2009/12/18 18:53:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2005/08/07 09:58:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2004/10/25 12:17:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/10/19 18:28:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/03/25 19:48:46 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2009/12/18 18:52:33 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2010/08/31 17:40:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Gibbo\Application Data\AVG9
[2006/12/25 13:39:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Gibbo\Application Data\Canon
[2008/11/13 21:02:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Gibbo\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2005/08/07 10:11:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Gibbo\Application Data\Hemera
[2003/08/27 17:28:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Gibbo\Application Data\InterTrust
[2003/08/27 20:04:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Gibbo\Application Data\InterVideo
[2010/08/30 17:44:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Gibbo\Application Data\IObit
[2005/08/07 10:13:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Gibbo\Application Data\Novatix
[2007/04/19 21:31:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Gibbo\Application Data\PPMate
[2007/04/28 01:14:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Gibbo\Application Data\ppStream
[2004/10/11 13:41:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Gibbo\Application Data\Template
[2006/04/17 20:41:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Gibbo\Application Data\Tenebril
[2007/04/15 17:58:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Gibbo\Application Data\TuneUp Software
[2005/09/30 13:44:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Gibbo\Application Data\Ulead Systems
[2007/04/19 22:05:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Gibbo\Application Data\URSoft
[2010/01/26 20:07:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Gibbo\Application Data\Windows Live Writer
[2010/07/09 16:44:54 | 000,000,384 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag.job
[2010/09/04 06:54:00 | 000,000,282 | -H– | M] () – C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/02/07 10:58:59 | 001,423,737 | —- | M] () – C:\100SS-SDC10226_SDC10226.JPG
[2010/08/30 13:24:35 | 000,000,209 | RHS- | M] () – C:\boot.ini
[2006/05/21 22:08:49 | 000,000,008 | —- | M] () – C:\config.sys
[2008/10/24 14:20:19 | 000,000,182 | —- | M] () – C:\drwtsn32.log
[2010/09/04 05:45:19 | 1072,746,496 | -HS- | M] () – C:\hiberfil.sys
[2003/08/27 00:58:54 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2003/08/27 00:58:54 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/11/04 02:19:43 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/09 12:36:27 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/09/04 05:45:16 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2010/08/28 21:41:13 | 001,757,184 | -H– | M] () – C:\SZKGFS.dat
[2009/06/02 18:34:02 | 000,002,176 | -H– | M] () – C:\ZbThumbnail.info

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2003/08/27 00:58:13 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2002/02/12 06:00:00 | 000,013,824 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD3i.DLL
[2002/02/12 06:00:00 | 000,043,008 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP3i.DLL
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/07/10 13:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2003/08/26 17:45:00 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2003/08/26 17:45:00 | 000,626,688 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2003/08/26 17:44:59 | 000,421,888 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/08/09 12:45:08 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2004/10/21 21:53:15 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Gibbo\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/10/02 11:08:22 | 000,000,079 | —- | M] () – C:\Documents and Settings\Gibbo\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/08/30 15:33:34 | 007,484,936 | —- | M] (IObit ) – C:\Documents and Settings\Gibbo\Desktop\asc-setup-aff.exe
[2008/10/27 19:01:06 | 000,075,032 | —- | M] (Diskeeper Corporation) – C:\Documents and Settings\Gibbo\Desktop\Autorun.exe
[2010/08/29 10:35:17 | 002,133,536 | —- | M] (AVG Technologies) – C:\Documents and Settings\Gibbo\Desktop\avg_free_stb_all_9_115_cnet.exe
[2010/08/28 20:43:55 | 000,532,480 | —- | M] (Trend Micro Incorporated) – C:\Documents and Settings\Gibbo\Desktop\cwshredder.exe
[2010/07/09 16:44:33 | 001,830,784 | —- | M] (IObit ) – C:\Documents and Settings\Gibbo\Desktop\DefragSetup.exe
[2010/09/03 06:18:02 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Gibbo\Desktop\HiJackThis.exe
[2010/09/04 06:48:36 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Gibbo\Desktop\OTL.exe
[2010/08/29 10:40:10 | 002,406,288 | —- | M] () – C:\Documents and Settings\Gibbo\Desktop\revosetup.exe
[2006/10/30 15:19:47 | 010,065,232 | —- | M] (TomTom | Macrovision Corporation) – C:\Documents and Settings\Gibbo\Desktop\TomTomHOMEwinlatest.exe
[2009/12/18 18:52:32 | 021,197,128 | —- | M] (TuneUp Software) – C:\Documents and Settings\Gibbo\Desktop\TU2010TrialEN-GB.exe
[2003/07/11 03:15:38 | 000,106,496 | —- | M] (InterVideo Inc.) – C:\Documents and Settings\Gibbo\Desktop\WinDVD.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >
[2005/10/10 13:12:42 | 020,798,256 | —- | M] (Netopsystems AG ) – C:\Documents and Settings\Gibbo\My Documents\AdbeRdr70_enu_full.exe
[2008/12/06 11:30:57 | 028,455,240 | —- | M] (Diskeeper Corporation ) – C:\Documents and Settings\Gibbo\My Documents\Diskeeper2009-Professional.exe
[2005/05/06 08:58:41 | 000,173,704 | —- | M] () – C:\Documents and Settings\Gibbo\My Documents\FxVundoB.exe
[2008/10/25 08:24:34 | 133,227,519 | —- | M] () – C:\Documents and Settings\Gibbo\My Documents\OOo_2.4.1_Win32Intel_install_wJRE_en-US.exe
[2006/11/05 16:51:02 | 000,777,448 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Gibbo\My Documents\WindowsXP-KB885894-x86-enu.exe

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2003/07/30 13:00:00 | 000,000,791 | —- | M] () – C:\WINDOWS\addins\fxsext.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >
[2004/05/28 19:45:02 | 000,390,944 | —- | M] (Atheros Communications, Inc.) – C:\WINDOWS\Driver Cache\ar5211.sys
[2004/05/28 19:45:42 | 000,390,944 | —- | M] (Atheros Communications, Inc.) – C:\WINDOWS\Driver Cache\ar52119x.sys
[2001/03/21 21:49:00 | 000,031,232 | —- | M] () – C:\WINDOWS\Driver Cache\DrvUpdt.exe
[2004/10/02 11:31:35 | 000,005,432 | —- | M] () – C:\WINDOWS\Driver Cache\INFCACHE.1
[2004/06/02 00:33:08 | 000,008,326 | —- | M] () – C:\WINDOWS\Driver Cache\net5211.cat
[2004/05/31 19:43:44 | 000,013,198 | —- | M] () – C:\WINDOWS\Driver Cache\net5211.inf
[2004/10/02 11:31:35 | 000,017,928 | —- | M] () – C:\WINDOWS\Driver Cache\net5211.PNF
[2003/05/16 17:24:30 | 000,379,257 | —- | M] () – C:\WINDOWS\Driver Cache\SDCARD.exe
[2001/02/28 23:08:44 | 000,036,864 | —- | M] (TOSHIBA) – C:\WINDOWS\Driver Cache\SDDEVMGR.dll
[2002/07/30 02:22:24 | 000,036,864 | —- | M] (TOSHIBA) – C:\WINDOWS\Driver Cache\SDTOPCIA.dll
[2003/01/28 19:18:24 | 000,025,214 | —- | M] () – C:\WINDOWS\Driver Cache\sd_drive.ico
[2003/02/17 08:45:28 | 000,003,331 | —- | M] () – C:\WINDOWS\Driver Cache\SD_README_Eng.txt
[2003/02/17 08:45:42 | 000,002,844 | —- | M] () – C:\WINDOWS\Driver Cache\SD_README_Jp.txt
[2003/02/27 20:03:02 | 000,002,619 | —- | M] () – C:\WINDOWS\Driver Cache\TOSSDPCI.INF
[2003/08/27 17:58:40 | 000,007,416 | —- | M] () – C:\WINDOWS\Driver Cache\TOSSDPCI.PNF
[2003/02/12 17:03:54 | 000,015,143 | —- | M] (TOSHIBA) – C:\WINDOWS\Driver Cache\TosSdPCI.sys
[2003/05/15 19:36:18 | 000,003,035 | —- | M] () – C:\WINDOWS\Driver Cache\TSDHD.INF
[2003/08/27 17:58:40 | 000,007,200 | —- | M] () – C:\WINDOWS\Driver Cache\TSDHD.PNF
[2003/05/15 01:38:32 | 000,025,888 | —- | M] (TOSHIBA Corporation) – C:\WINDOWS\Driver Cache\TSDHD.sys
[2001/08/24 09:02:04 | 000,006,272 | —- | M] (TOSHIBA Corporation) – C:\WINDOWS\Driver Cache\TSDHDEXL.sys
[2003/03/04 00:50:34 | 000,008,424 | —- | M] () – C:\WINDOWS\Driver Cache\tsdpci2k.cat

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2004/10/21 21:53:15 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Gibbo\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2010/09/04 06:58:18 | 001,294,336 | —- | M] () – C:\Documents and Settings\Gibbo\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-02 06:27:02

< >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C4252FE0
< End of report >
Please do the following



Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (no name) - {0A87E45F-537A-40B4-B812-E2544C21A09F} - No CLSID value found
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
    O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
    [2010/09/04 06:54:00 | 000,000,282 | -H– | M] () – C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]





    Next

    Download ComboFix from one of these locations:

    Link 1
    Link 2


    * IMPORTANT !!! Save ComboFix.exe to your Desktop


    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
    • See this Link for programs that need to be disabled and instruction on how to disable them.
    • Remember to re-enable them when we're done.

    • Double click on ComboFix.exe & follow the prompts.

    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


    [external image: Posted Image]



    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.

    When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

    *If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Please do the following


Delete the copy of Combofix you have and download a fresh one from one of the links below,follow the instructions to rename it.Don't run it yet


Download Combofix from either of the links below. You must rename it to combo.com before saving it.
Save it to your desktop. Change the save as file type to "all files"

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

Link 1
Link 2


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

  • NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.




Next boot into safe mode

To get into the Windows 2000 / XP Safe mode, as the computer is booting press and hold your "F8 Key" which should bring up the "Windows Advanced Options Menu". Use your arrow keys to move to "Safe Mode" and press your Enter key.


Now run Combofix
Hi Results from combo fix
Regards John

ComboFix 10-09-06.01 - Gibbo 06/09/2010 20:09:18.1.2 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.807 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo.com
AV: AVG Internet Security *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\lldsmw.bak1
c:\windows\system32\uninstall.exe

.
((((((((((((((((((((((((( Files Created from 2010-08-06 to 2010-09-06 )))))))))))))))))))))))))))))))
.

2010-09-04 18:46 . 2010-09-04 18:46 ——– d—–w- C:\_OTL
2010-09-02 22:04 . 2010-09-02 22:04 ——– d—–w- c:\documents and settings\All Users\Application Data\Webroot
2010-09-02 17:07 . 2010-09-02 17:07 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2010-09-02 17:07 . 2010-09-02 17:07 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-09-02 16:56 . 2010-09-02 16:56 ——– d—–w- c:\documents and settings\Gibbo\Local Settings\Application Data\PackageAware
2010-09-02 16:52 . 2010-09-02 16:52 ——– d—–w- c:\program files\Uniblue
2010-08-31 21:26 . 2010-08-31 21:26 ——– d—–w- c:\windows\system32\drivers\NSS
2010-08-31 21:26 . 2010-08-31 21:26 ——– d—–w- c:\program files\Norton Security Scan
2010-08-31 21:26 . 2010-08-31 21:26 ——– d—–w- c:\program files\NortonInstaller
2010-08-31 21:26 . 2010-08-31 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-08-31 16:40 . 2010-08-31 16:40 ——– d—–w- c:\documents and settings\Gibbo\Application Data\AVG9
2010-08-29 10:51 . 2010-08-29 10:51 ——– d—–w- C:\$AVG
2010-08-29 10:24 . 2010-08-29 10:24 ——– d—–w- C:\spoolerlogs
2010-08-29 10:12 . 2010-08-29 10:12 12536 —-a-w- c:\windows\system32\avgrsstx.dll
2010-08-29 10:12 . 2010-08-29 10:12 29584 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-08-29 10:11 . 2010-09-06 18:39 ——– d—–w- c:\windows\system32\drivers\Avg
2010-08-29 10:09 . 2010-08-29 10:09 25168 —-a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-08-29 10:09 . 2010-08-29 10:09 52872 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-08-29 10:09 . 2010-08-29 10:09 243024 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-08-29 10:09 . 2010-08-29 10:09 216400 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-08-29 10:03 . 2010-08-29 10:03 50968 —-a-w- c:\windows\system32\avgfwdx.dll
2010-08-29 10:03 . 2010-08-29 10:03 30104 —-a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-08-29 10:01 . 2010-08-29 10:01 ——– d—–w- c:\program files\AVG
2010-08-29 10:00 . 2010-08-29 10:01 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-08-29 09:40 . 2010-08-29 09:40 ——– d—–w- c:\program files\VS Revo Group
2010-08-29 01:13 . 2010-08-29 01:13 ——– d—–w- c:\windows\system32\NtmsData
2010-08-29 00:18 . 2010-05-21 13:14 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-08-28 20:41 . 2010-08-28 20:41 1757184 —ha-w- C:\SZKGFS.dat
2010-08-28 20:04 . 2010-08-28 20:04 ——– d—–w- c:\documents and settings\All Users\Application Data\SITEguard
2010-08-28 20:01 . 2010-08-28 20:01 ——– d—–w- c:\program files\Common Files\iS3
2010-08-28 20:01 . 2010-08-29 00:10 ——– d—–w- c:\documents and settings\All Users\Application Data\STOPzilla!
2010-08-28 17:39 . 2010-08-28 20:32 ——– d—–w- c:\program files\Norton 360
2010-08-20 19:59 . 2010-08-20 19:59 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-08-20 19:57 . 2010-08-20 19:57 77184 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-08-18 18:40 . 2010-08-18 18:40 ——– d—–w- c:\program files\IWONGEI
2010-08-15 19:05 . 2010-08-15 19:05 ——– d—–w- c:\documents and settings\Gibbo\Local Settings\Application Data\Mozilla
2010-08-13 09:14 . 2010-07-20 17:59 44928 —-a-w- c:\windows\system32\drivers\dvdfab.sys
2010-08-13 09:14 . 2010-08-13 09:14 ——– d—–w- c:\program files\DVDFab Passkey 7
2010-08-09 05:18 . 2010-08-09 05:18 503808 —-a-w- c:\documents and settings\Gibbo\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-79ec60d5-n\msvcp71.dll
2010-08-09 05:18 . 2010-08-09 05:18 499712 —-a-w- c:\documents and settings\Gibbo\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-79ec60d5-n\jmc.dll
2010-08-09 05:18 . 2010-08-09 05:18 348160 —-a-w- c:\documents and settings\Gibbo\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-79ec60d5-n\msvcr71.dll
2010-08-09 05:18 . 2010-08-09 05:18 61440 —-a-w- c:\documents and settings\Gibbo\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-5248ec73-n\decora-sse.dll
2010-08-09 05:18 . 2010-08-09 05:18 12800 —-a-w- c:\documents and settings\Gibbo\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-5248ec73-n\decora-d3d.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-02 16:20 . 2003-08-27 17:38 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-09-02 07:18 . 2009-02-10 17:42 ——– d—–w- c:\program files\Microsoft Silverlight
2010-08-31 21:26 . 2010-04-29 03:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2010-08-31 21:26 . 2003-08-27 17:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-08-30 16:44 . 2009-12-26 20:56 ——– d—–w- c:\documents and settings\Gibbo\Application Data\IObit
2010-08-30 14:27 . 2010-03-13 12:28 ——– d—–w- c:\program files\Google
2010-08-30 08:35 . 2007-04-18 17:04 ——– d—–w- c:\program files\SopCast
2010-08-28 20:35 . 2010-08-28 20:35 240 —-a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-08-28 16:48 . 2003-08-27 16:07 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-08-21 04:44 . 2008-11-13 18:30 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-08-20 20:07 . 2003-08-27 16:28 ——– d—–w- c:\program files\Common Files\Adobe
2010-08-20 20:00 . 2008-11-13 18:33 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-08-20 18:06 . 2010-04-18 18:09 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-08-20 17:54 . 2003-08-27 00:48 ——– d—–w- c:\program files\Java
2010-08-20 17:17 . 2003-08-27 00:48 ——– d—–w- c:\program files\Common Files\Java
2010-08-13 07:29 . 2007-12-17 11:21 1 —-a-w- c:\documents and settings\Gibbo\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2010-08-13 07:29 . 2007-11-25 12:28 ——– d—–w- c:\documents and settings\Gibbo\Application Data\OpenOffice.org2
2010-07-18 18:34 . 2009-04-05 14:50 ——– d—–w- c:\documents and settings\Gibbo\Application Data\ZoomBrowser EX
2010-07-17 17:14 . 2009-04-05 14:42 ——– d—–w- c:\documents and settings\All Users\Application Data\ZoomBrowser
2010-07-16 16:33 . 2010-07-16 16:33 45056 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-07-16 16:33 . 2010-07-16 16:33 45056 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-07-16 16:33 . 2010-07-16 16:33 45056 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-07-16 16:33 . 2010-07-16 16:33 45056 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-07-16 16:33 . 2010-07-16 16:33 49152 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-07-16 16:33 . 2010-07-16 16:33 308808 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-07-16 16:33 . 2010-07-16 16:33 40960 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-07-16 16:33 . 2010-07-16 16:33 14848 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-07-16 16:33 . 2010-07-16 16:33 341600 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-07-16 16:33 . 2003-08-27 17:31 ——– d—–w- c:\program files\Common Files\Real
2010-07-16 16:32 . 2003-08-27 17:31 ——– d—–w- c:\program files\Real
2010-07-16 16:32 . 2010-07-16 16:32 ——– d—–w- c:\program files\Common Files\xing shared
2010-07-16 16:31 . 2003-03-18 21:14 499712 —-a-w- c:\windows\system32\msvcp71.dll
2010-07-16 16:31 . 2003-02-21 03:42 348160 —-a-w- c:\windows\system32\msvcr71.dll
2010-06-30 12:31 . 2004-10-21 20:25 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-27 06:01 . 2010-04-10 08:51 439816 —-a-w- c:\documents and settings\Gibbo\Application Data\Real\Update\setup3.10\setup.exe
2010-06-24 12:22 . 2006-06-23 10:33 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2004-10-21 20:25 1851904 —-a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2004-10-21 20:25 354304 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2004-10-21 20:26 80384 —-a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2004-10-21 20:26 744448 —-a-w- c:\windows\pchealth\helpctr\Binaries\helpsvc.exe
2010-06-14 07:41 . 2006-09-13 05:09 1172480 —-a-w- c:\windows\system32\msxml3.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Flying Club Alerts"="c:\program files\Flying Club Alerts\flyingclubalerts.exe" [2005-10-03 472064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ezShieldProtector for Px"="c:\windows\system32\ezSP_Px.exe" [2002-08-20 40960]
"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2003-06-12 49152]
"ehTray"="c:\windows\ehome\ehtray.exe" [2008-04-14 50176]
"CpRmtKey"="c:\program files\Toshiba Controls\CpRmtKey.EXE" [2003-05-29 94208]
"CplBTQ00"="c:\program files\EzButton\CplBTQ00.EXE" [2003-06-28 708608]
"CeEPOWER"="c:\program files\TOSHIBA\Power Management\CePMTray.exe" [2003-08-06 135168]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2003-06-10 638976]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2003-06-18 151552]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 75520]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2003-8-27 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-08-29 10:12 12536 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Billminder.lnk
backup=c:\windows\pss\Billminder.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk
backup=c:\windows\pss\Quicken Startup.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Gibbo^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
path=c:\documents and settings\Gibbo\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk
backup=c:\windows\pss\OpenOffice.org 2.4.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Gibbo^Start Menu^Programs^Startup^Scheduler.lnk]
path=c:\documents and settings\Gibbo\Start Menu\Programs\Startup\Scheduler.lnk
backup=c:\windows\pss\Scheduler.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Gibbo^Start Menu^Programs^Startup^SendPhotos For Outlook Express.lnk]
path=c:\documents and settings\Gibbo\Start Menu\Programs\Startup\SendPhotos For Outlook Express.lnk
backup=c:\windows\pss\SendPhotos For Outlook Express.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCPitStopEraser

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2008-11-07 14:16 111936 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Drag'n Drop CD+DVD]
2003-07-09 04:21 1171456 —-a-w- c:\program files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDFab Passkey]
2010-08-04 09:46 1472504 —-a-w- c:\program files\DVDFab Passkey 7\DVDFabPasskey.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2008-11-20 13:20 290088 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Location Finder]
2005-11-05 21:25 101064 —-a-w- c:\program files\Microsoft Location Finder\LocationFinder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pinger]
2002-10-17 20:21 159744 —-a-w- c:\toshiba\Ivp\ISM\pinger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2007-01-29 12:07 3718312 —-a-w- c:\program files\TomTom HOME\TomTomHOME.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SymWSC"=2 (0x2)
"SNDSrvc"=3 (0x3)
"SBService"=2 (0x2)
"SAVScan"=3 (0x3)
"C-DillaSrv"=2 (0x2)
"AOL ACS"=2 (0x2)
"wscsvc"=2 (0x2)
"Bonjour Service"=2 (0x2)
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"UleadBurningHelper"=2 (0x2)
"gupdate"=2 (0x2)
"CCALib8"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\program files\Flying Club Alerts\flyingclubalerts.exe"= c:\program files\Flying Club Alerts\flyingclubalerts.exe
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\WINDOWS\\system32\\ppshell.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=

R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [29/08/2010 11:09 25168]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [29/08/2010 11:09 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [29/08/2010 11:09 216400]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [29/08/2010 11:09 243024]
R2 mrtRate;mrtRate;c:\windows\system32\drivers\MrtRate.sys [02/10/2004 13:21 34712]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/01/2007 20:01 24652]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [29/08/2010 11:03 30104]
R3 dvdfab;dvdfab;c:\windows\system32\drivers\dvdfab.sys [13/08/2010 10:14 44928]
R3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\drivers\gflmouhid.sys [19/04/2004 16:01 6656]
S2 avg9emc;AVG E-mail Scanner;"c:\program files\AVG\AVG9\avgemc.exe" –> c:\program files\AVG\AVG9\avgemc.exe [?]
S2 avg9wd;AVG WatchDog;"c:\program files\AVG\AVG9\avgwdsvc.exe" –> c:\program files\AVG\AVG9\avgwdsvc.exe [?]
S2 avgfws9;AVG Firewall;"c:\program files\AVG\AVG9\avgfws9.exe" –> c:\program files\AVG\AVG9\avgfws9.exe [?]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [29/08/2010 11:03 30104]
S3 AVGIDSAgent;AVG9IDSAgent;"c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe" AVGIDSAgent –> c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [?]
S3 AVGIDSDriverxpx;AVG9IDSDriver;\??\c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys –> c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [?]
S3 AVGIDSFilterxpx;AVG9IDSFilter;\??\c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys –> c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [?]
S3 AVGIDSShimxpx;AVG9IDSShim;\??\c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys –> c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [?]
S3 BayTvKit;TOSHIBA Style Bay TV Tuner KiT Device;c:\windows\system32\drivers\BayTvKit.sys [28/08/2003 05:28 129536]
S4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [13/03/2010 13:29 135664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
vvdsvc REG_MULTI_SZ vvdsvc
.
Contents of the 'Scheduled Tasks' folder

2010-08-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 11:34]

2010-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-13 12:28]

2010-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-13 12:28]

2010-09-03 c:\windows\Tasks\Norton Security Scan for Gibbo.job
- c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-08-31 09:06]

2010-09-06 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-4022485809-4210471992-1704011695-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 02:02]

2010-09-06 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-4022485809-4210471992-1704011695-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 02:02]

2010-07-09 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-12-26 11:57]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.virginmedia.com/
uInternet Settings,ProxyOverride = local
DPF: {03B03C66-15CB-4F16-BA86-83A55A9B0EA4} - hxxp://webcam.crowsnest-venice.com/Intellinet_Viewer.cab
DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} - hxxp://dl.uc.sina.com/cab/downloader.cab
DPF: {96816368-C1E3-414D-A193-63C3CC921990} - hxxp://gretnaweddings-anvilhall.remotemanager.co.uk/common/activex/MJPEGRender.ocx
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://65.14.83.37/activex/AMC.cab
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-AVG9_TRAY - c:\progra~1\AVG\AVG9\avgtray.exe
AddRemove-AVG9Uninstall - c:\program files\AVG\AVG9\setup.exe
AddRemove-Canon Camera WIA Driver EOS D60 - e:\eos d60 wia\Uninst.isu
AddRemove-Canon PhotoStitch 3.1 - e:\photostitch\Uninst.isu
AddRemove-Canon Utilities RAW Image Converter2 - e:\raw image converter2\Uninst.isu



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-06 20:24
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x871D8ECC]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7505f28
\Driver\ACPI -> ACPI.sys @ 0xf7458cb8
\Driver\atapi -> atapi.sys @ 0xf73cc852
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805e710a
ParseProcedure -> ntoskrnl.exe @ 0x80578f7a
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805e710a
ParseProcedure -> ntoskrnl.exe @ 0x80578f7a
NDIS: Atheros AR5001X+ Wireless Network Adapter #2 -> SendCompleteHandler -> NDIS.sys @ 0xf72d9bd4
PacketIndicateHandler -> NDIS.sys @ 0xf72e5a21
SendHandler -> NDIS.sys @ 0xf72d9d44
user & kernel MBR OK

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1580)
c:\windows\system32\wininet.dll

- - - - - - - > 'lsass.exe'(1700)
c:\windows\system32\wininet.dll

- - - - - - - > 'explorer.exe'(2936)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\DVDRAMSV.exe
c:\windows\ehome\ehSched.exe
c:\windows\System32\nvsvc32.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\System32\wdfmgr.exe
c:\windows\wanmpsvc.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Apoint2K\Apntex.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2010-09-06 20:36:36 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-06 19:36

Pre-Run: 15,733,374,976 bytes free
Post-Run: 14,602,825,728 bytes free

- - End Of File - - D7FB1B290F9C2A488440D95E0B20735C
In normal mode please do the following

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.


Next please rerun Combofix,ensure that you install the recovery console when prompted.
MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Professional Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0000000c Kernel Drivers (total 147): 0x804D7000 \WINDOWS\system32\ntoskrnl.exe 0x806FF000 \WINDOWS\system32\hal.dll 0xF79A1000 \WINDOWS\system32\KDCOM.DLL 0xF78B1000 \WINDOWS\system32\BOOTVID.dll 0xF7452000 ACPI.sys 0xF79A3000 \WINDOWS\System32\DRIVERS\WMILIB.SYS 0xF7441000 pci.sys 0xF74A1000 isapnp.sys 0xF74B1000 ohci1394.sys 0xF74C1000 \WINDOWS\System32\DRIVERS\1394BUS.SYS 0xF78B5000 compbatt.sys 0xF78B9000 \WINDOWS\System32\DRIVERS\BATTC.SYS 0xF7A69000 pciide.sys 0xF7721000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS 0xF7423000 pcmcia.sys 0xF74D1000 MountMgr.sys 0xF7404000 ftdisk.sys 0xF79A5000 dmload.sys 0xF73DE000 dmio.sys 0xF78BD000 ACPIEC.sys 0xF7A6A000 \WINDOWS\System32\DRIVERS\OPRGHDLR.SYS 0xF7729000 PartMgr.sys 0xF74E1000 VolSnap.sys 0xF73C6000 atapi.sys 0xF74F1000 disk.sys 0xF7501000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS 0xF73A6000 fltmgr.sys 0xF7394000 sr.sys 0xF7731000 PxHelp20.sys 0xF737D000 KSecDD.sys 0xF72F0000 Ntfs.sys 0xF72C3000 NDIS.sys 0xF72A9000 Mup.sys 0xF7511000 avgrkx86.sys 0xF7521000 AVGIDSxx.sys 0xF7531000 agp440.sys 0xF7591000 \SystemRoot\System32\DRIVERS\intelppm.sys 0xF79EB000 \SystemRoot\System32\Drivers\hkdrv.sys 0xF6539000 \SystemRoot\System32\DRIVERS\nv4_mini.sys 0xF6525000 \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS 0xF7869000 \SystemRoot\System32\DRIVERS\usbuhci.sys 0xF6501000 \SystemRoot\System32\DRIVERS\USBPORT.SYS 0xF7871000 \SystemRoot\System32\DRIVERS\usbehci.sys 0xF75B1000 \SystemRoot\System32\DRIVERS\nic1394.sys 0xF64E4000 \SystemRoot\system32\DRIVERS\Rtnicxp.sys 0xF646C000 \SystemRoot\System32\DRIVERS\SHP5211.sys 0xF7879000 \SystemRoot\System32\DRIVERS\tsdhd.sys 0xF75C1000 \SystemRoot\System32\DRIVERS\i8042prt.sys 0xF6E7E000 \SystemRoot\System32\Drivers\DKbFltr.sys 0xF7881000 \SystemRoot\System32\DRIVERS\kbdclass.sys 0xF6455000 \SystemRoot\System32\DRIVERS\Apfiltr.sys 0xF7889000 \SystemRoot\System32\DRIVERS\mouclass.sys 0xF75D1000 \SystemRoot\System32\DRIVERS\smcirda.sys 0xF6E76000 \SystemRoot\System32\DRIVERS\irenum.sys 0xF7891000 \SystemRoot\System32\DRIVERS\fdc.sys 0xF6441000 \SystemRoot\System32\DRIVERS\parport.sys 0xF6E6E000 \SystemRoot\System32\DRIVERS\CmBatt.sys 0xF75E1000 \SystemRoot\System32\DRIVERS\imapi.sys 0xF7951000 \SystemRoot\system32\drivers\pfc.sys 0xF75F1000 \SystemRoot\system32\drivers\dvdfab.sys 0xF7601000 \SystemRoot\System32\DRIVERS\cdrom.sys 0xF7611000 \SystemRoot\System32\DRIVERS\redbook.sys 0xF641E000 \SystemRoot\System32\DRIVERS\ks.sys 0xF7955000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys 0xF636E000 \SystemRoot\system32\drivers\ALCXWDM.SYS 0xF634A000 \SystemRoot\system32\drivers\portcls.sys 0xF7621000 \SystemRoot\system32\drivers\drmk.sys 0xF622C000 \SystemRoot\System32\DRIVERS\AGRSM.sys 0xF7899000 \SystemRoot\System32\Drivers\Modem.SYS 0xF78A1000 \SystemRoot\system32\DRIVERS\avgfwdx.sys 0xF7B50000 \SystemRoot\System32\DRIVERS\audstub.sys 0xF78A9000 \SystemRoot\System32\DRIVERS\rasirda.sys 0xF7741000 \SystemRoot\System32\DRIVERS\TDI.SYS 0xF7631000 \SystemRoot\System32\DRIVERS\rasl2tp.sys 0xF796D000 \SystemRoot\System32\DRIVERS\ndistapi.sys 0xF61ED000 \SystemRoot\System32\DRIVERS\ndiswan.sys 0xF7641000 \SystemRoot\System32\DRIVERS\raspppoe.sys 0xF7651000 \SystemRoot\System32\DRIVERS\raspptp.sys 0xF61DC000 \SystemRoot\System32\DRIVERS\psched.sys 0xF7661000 \SystemRoot\System32\DRIVERS\msgpc.sys 0xF7761000 \SystemRoot\System32\DRIVERS\ptilink.sys 0xF7769000 \SystemRoot\System32\DRIVERS\raspti.sys 0xF7771000 \SystemRoot\System32\DRIVERS\wanatw4.sys 0xF61AC000 \SystemRoot\System32\DRIVERS\rdpdr.sys 0xF7671000 \SystemRoot\System32\DRIVERS\termdd.sys 0xF7A29000 \SystemRoot\System32\DRIVERS\swenum.sys 0xF614E000 \SystemRoot\System32\DRIVERS\update.sys 0xF7981000 \SystemRoot\System32\DRIVERS\mssmbios.sys 0xF7691000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xF76A1000 \SystemRoot\System32\DRIVERS\usbhub.sys 0xF7A31000 \SystemRoot\System32\DRIVERS\USBD.SYS 0xF7A33000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7AFE000 \SystemRoot\System32\Drivers\Null.SYS 0xF7A35000 \SystemRoot\System32\Drivers\Beep.SYS 0xF7789000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF7791000 \SystemRoot\System32\drivers\vga.sys 0xF7A37000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7A39000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF504F000 \SystemRoot\System32\Drivers\meiudf.sys 0xF503E000 \SystemRoot\System32\Drivers\Udfs.SYS 0xF7799000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF77A1000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF7271000 \SystemRoot\System32\DRIVERS\rasacd.sys 0xF5003000 \SystemRoot\System32\DRIVERS\ipsec.sys 0xF4FAA000 \SystemRoot\System32\DRIVERS\tcpip.sys 0xF4F70000 \SystemRoot\System32\Drivers\avgtdix.sys 0xF4F4A000 \SystemRoot\System32\DRIVERS\ipnat.sys 0xF76E1000 \SystemRoot\System32\DRIVERS\wanarp.sys 0xF76F1000 \SystemRoot\System32\DRIVERS\arp1394.sys 0xF6E86000 \SystemRoot\System32\DRIVERS\hidusb.sys 0xF66CD000 \SystemRoot\System32\DRIVERS\HIDCLASS.SYS 0xF7A3B000 \SystemRoot\system32\DRIVERS\gflmouhid.sys 0xF6E82000 \SystemRoot\System32\DRIVERS\mouhid.sys 0xF4F22000 \SystemRoot\System32\DRIVERS\netbt.sys 0xF4F00000 \SystemRoot\System32\drivers\afd.sys 0xF66DD000 \SystemRoot\System32\DRIVERS\netbios.sys 0xF7B63000 \SystemRoot\System32\Drivers\TPIoMngr.sys 0xF7A3F000 \SystemRoot\System32\Drivers\SSIoMngr.sys 0xF7A41000 \SystemRoot\System32\Drivers\EPIoMngr.sys 0xF7A43000 \SystemRoot\System32\Drivers\EKIoMngr.sys 0xF4ED5000 \SystemRoot\System32\DRIVERS\rdbss.sys 0xF4E65000 \SystemRoot\System32\DRIVERS\mrxsmb.sys 0xF66AD000 \SystemRoot\System32\Drivers\Fips.SYS 0xF77C1000 \SystemRoot\System32\Drivers\avgmfx86.sys 0xF4E09000 \SystemRoot\System32\Drivers\avgldx86.sys 0xBF800000 \SystemRoot\System32\win32k.sys 0xF4E5D000 \SystemRoot\System32\drivers\Dxapi.sys 0xF7829000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF7B6A000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\nv4_disp.dll 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xF75A1000 \SystemRoot\system32\DRIVERS\fssfltr_tdi.sys 0xEF296000 \SystemRoot\System32\DRIVERS\irda.sys 0xEF318000 \SystemRoot\System32\DRIVERS\mdc8021x.sys 0xEF314000 \SystemRoot\System32\DRIVERS\ndisuio.sys 0xF7561000 \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys 0xF0B68000 \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys 0xEEF4E000 \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys 0xEECB9000 \SystemRoot\system32\drivers\wdmaud.sys 0xEED9E000 \SystemRoot\system32\drivers\sysaudio.sys 0xF7A05000 \SystemRoot\System32\Drivers\ParVdm.SYS 0xEEA4B000 \SystemRoot\System32\Drivers\mrtRate.SYS 0xEE98C000 \SystemRoot\System32\DRIVERS\srv.sys 0xEE53B000 \SystemRoot\System32\Drivers\HTTP.sys 0xED576000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 55): 0 System Idle Process 4 System 1168 C:\WINDOWS\system32\smss.exe 1468 csrss.exe 1696 C:\WINDOWS\system32\winlogon.exe 1784 C:\WINDOWS\system32\services.exe 1796 C:\WINDOWS\system32\lsass.exe 256 C:\WINDOWS\system32\svchost.exe 444 svchost.exe 552 C:\WINDOWS\system32\svchost.exe 728 C:\Program Files\AVG\AVG9\avgchsvx.exe 736 C:\Program Files\AVG\AVG9\avgrsx.exe 772 svchost.exe 1096 C:\Program Files\AVG\AVG9\avgcsrvx.exe 1112 svchost.exe 1620 C:\WINDOWS\explorer.exe 624 C:\WINDOWS\system32\spoolsv.exe 1032 C:\Program Files\Google\Update\GoogleUpdate.exe 2940 C:\Program Files\AVG\AVG9\avgwdsvc.exe 2964 C:\Program Files\AVG\AVG9\avgfws9.exe 3392 C:\WINDOWS\system32\DVDRAMSV.exe 3592 C:\WINDOWS\eHome\ehsched.exe 3968 C:\Program Files\AVG\AVG9\avgam.exe 4000 C:\Program Files\AVG\AVG9\avgnsx.exe 208 C:\WINDOWS\system32\nvsvc32.exe 2496 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 2784 C:\WINDOWS\system32\svchost.exe 3028 wdfmgr.exe 3096 C:\Program Files\Viewpoint\Common\ViewpointService.exe 3436 C:\WINDOWS\wanmpsvc.exe 3844 C:\Program Files\AVG\AVG9\avgemc.exe 940 C:\Program Files\AVG\AVG9\avgcsrvx.exe 2584 C:\WINDOWS\system32\ezSP_Px.exe 2880 C:\Program Files\Toshiba\TouchPad\TPTray.exe 3124 C:\WINDOWS\eHome\ehtray.exe 3216 C:\Program Files\Toshiba Controls\CpRmtKey.EXE 2308 C:\Program Files\AVG\AVG9\avgcsrvx.exe 3320 C:\Program Files\EzButton\CplBTQ00.EXE 3336 C:\Program Files\Toshiba\Power Management\CePMTray.exe 3364 C:\Program Files\Toshiba\E-KEY\CeEKey.exe 3380 C:\Program Files\Apoint2K\Apoint.exe 3384 C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe 3408 C:\PROGRA~1\AVG\AVG9\avgtray.exe 3708 C:\Program Files\Flying Club Alerts\flyingclubalerts.exe 3184 C:\WINDOWS\system32\ctfmon.exe 3756 C:\WINDOWS\system32\RAMASST.exe 3260 C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe 268 C:\Program Files\Internet Explorer\iexplore.exe 2316 C:\WINDOWS\eHome\ehmsas.exe 3104 C:\Program Files\Internet Explorer\iexplore.exe 3908 C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSMonitor.exe 2908 C:\Program Files\Apoint2K\ApntEx.exe 4708 C:\WINDOWS\system32\wscntfy.exe 4900 C:\WINDOWS\system32\svchost.exe 4552 C:\Documents and Settings\Gibbo\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) PhysicalDrive0 Model Number: HTS548080M9AT00, Rev: MG4OA50A Size Device Name MBR Status ——————————————– 74 GB \\.\PhysicalDrive0 Windows 98 MBR code detected SHA1: 48F01D7E76A0F3C038D08611E3FDC0EE4EF9FD3E Done!

In normal mode please do the following

Next please rerun Combofix,ensure that you install the recovery console when prompted.


Did you run Combofix in normal mode ?
regards john


ComboFix 10-09-09.03 - Gibbo 10/09/2010 9:09.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.597 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo.com
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

Infected copy of c:\windows\system32\drivers\intelppm.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((( Files Created from 2010-08-10 to 2010-09-10 )))))))))))))))))))))))))))))))
.

2010-09-06 20:33 . 2010-06-30 13:23 2102600 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-09-06 20:05 . 2010-09-06 20:33 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-09-04 18:46 . 2010-09-04 18:46 ——– d—–w- C:\_OTL
2010-09-02 22:04 . 2010-09-02 22:04 ——– d—–w- c:\documents and settings\All Users\Application Data\Webroot
2010-09-02 17:07 . 2010-09-02 17:07 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2010-09-02 17:07 . 2010-09-02 17:07 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-09-02 16:56 . 2010-09-02 16:56 ——– d—–w- c:\documents and settings\Gibbo\Local Settings\Application Data\PackageAware
2010-09-02 16:52 . 2010-09-02 16:52 ——– d—–w- c:\program files\Uniblue
2010-08-31 21:26 . 2010-08-31 21:26 ——– d—–w- c:\windows\system32\drivers\NSS
2010-08-31 21:26 . 2010-08-31 21:26 ——– d—–w- c:\program files\Norton Security Scan
2010-08-31 21:26 . 2010-08-31 21:26 ——– d—–w- c:\program files\NortonInstaller
2010-08-31 21:26 . 2010-08-31 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-08-31 16:40 . 2010-08-31 16:40 ——– d—–w- c:\documents and settings\Gibbo\Application Data\AVG9
2010-08-29 10:51 . 2010-08-29 10:51 ——– d—–w- C:\$AVG
2010-08-29 10:24 . 2010-08-29 10:24 ——– d—–w- C:\spoolerlogs
2010-08-29 10:12 . 2010-08-29 10:12 12536 —-a-w- c:\windows\system32\avgrsstx.dll
2010-08-29 10:12 . 2010-08-29 10:12 29584 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-08-29 10:11 . 2010-09-10 06:07 ——– d—–w- c:\windows\system32\drivers\Avg
2010-08-29 10:09 . 2010-08-29 10:09 25168 —-a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-08-29 10:09 . 2010-08-29 10:09 52872 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-08-29 10:09 . 2010-08-29 10:09 243024 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-08-29 10:09 . 2010-08-29 10:09 216400 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-08-29 10:03 . 2010-08-29 10:03 50968 —-a-w- c:\windows\system32\avgfwdx.dll
2010-08-29 10:03 . 2010-08-29 10:03 30104 —-a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-08-29 10:01 . 2010-08-29 10:01 ——– d—–w- c:\program files\AVG
2010-08-29 10:00 . 2010-08-29 10:01 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-08-29 09:40 . 2010-08-29 09:40 ——– d—–w- c:\program files\VS Revo Group
2010-08-29 01:13 . 2010-08-29 01:13 ——– d—–w- c:\windows\system32\NtmsData
2010-08-29 00:18 . 2010-05-21 13:14 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-08-28 20:41 . 2010-08-28 20:41 1757184 —ha-w- C:\SZKGFS.dat
2010-08-28 20:04 . 2010-08-28 20:04 ——– d—–w- c:\documents and settings\All Users\Application Data\SITEguard
2010-08-28 20:01 . 2010-08-28 20:01 ——– d—–w- c:\program files\Common Files\iS3
2010-08-28 20:01 . 2010-08-29 00:10 ——– d—–w- c:\documents and settings\All Users\Application Data\STOPzilla!
2010-08-28 17:39 . 2010-08-28 20:32 ——– d—–w- c:\program files\Norton 360
2010-08-20 19:59 . 2010-08-20 19:59 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-08-20 19:57 . 2010-08-20 19:57 77184 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-08-18 18:40 . 2010-08-18 18:40 ——– d—–w- c:\program files\IWONGEI
2010-08-15 19:05 . 2010-08-15 19:05 ——– d—–w- c:\documents and settings\Gibbo\Local Settings\Application Data\Mozilla
2010-08-13 09:14 . 2010-07-20 17:59 44928 —-a-w- c:\windows\system32\drivers\dvdfab.sys
2010-08-13 09:14 . 2010-08-13 09:14 ——– d—–w- c:\program files\DVDFab Passkey 7

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-07 16:17 . 2003-08-27 17:38 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-09-02 07:18 . 2009-02-10 17:42 ——– d—–w- c:\program files\Microsoft Silverlight
2010-08-31 21:26 . 2010-04-29 03:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2010-08-31 21:26 . 2003-08-27 17:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-08-30 16:44 . 2009-12-26 20:56 ——– d—–w- c:\documents and settings\Gibbo\Application Data\IObit
2010-08-30 14:27 . 2010-03-13 12:28 ——– d—–w- c:\program files\Google
2010-08-30 08:35 . 2007-04-18 17:04 ——– d—–w- c:\program files\SopCast
2010-08-28 20:35 . 2010-08-28 20:35 240 —-a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-08-28 16:48 . 2003-08-27 16:07 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-08-21 04:44 . 2008-11-13 18:30 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-08-20 20:07 . 2003-08-27 16:28 ——– d—–w- c:\program files\Common Files\Adobe
2010-08-20 20:00 . 2008-11-13 18:33 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-08-20 18:06 . 2010-04-18 18:09 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-08-20 17:54 . 2003-08-27 00:48 ——– d—–w- c:\program files\Java
2010-08-20 17:17 . 2003-08-27 00:48 ——– d—–w- c:\program files\Common Files\Java
2010-08-13 07:29 . 2007-12-17 11:21 1 —-a-w- c:\documents and settings\Gibbo\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2010-08-13 07:29 . 2007-11-25 12:28 ——– d—–w- c:\documents and settings\Gibbo\Application Data\OpenOffice.org2
2010-08-09 05:18 . 2010-08-09 05:18 503808 —-a-w- c:\documents and settings\Gibbo\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-79ec60d5-n\msvcp71.dll
2010-08-09 05:18 . 2010-08-09 05:18 499712 —-a-w- c:\documents and settings\Gibbo\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-79ec60d5-n\jmc.dll
2010-08-09 05:18 . 2010-08-09 05:18 348160 —-a-w- c:\documents and settings\Gibbo\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-79ec60d5-n\msvcr71.dll
2010-08-09 05:18 . 2010-08-09 05:18 61440 —-a-w- c:\documents and settings\Gibbo\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-5248ec73-n\decora-sse.dll
2010-08-09 05:18 . 2010-08-09 05:18 12800 —-a-w- c:\documents and settings\Gibbo\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-5248ec73-n\decora-d3d.dll
2010-07-18 18:34 . 2009-04-05 14:50 ——– d—–w- c:\documents and settings\Gibbo\Application Data\ZoomBrowser EX
2010-07-17 17:14 . 2009-04-05 14:42 ——– d—–w- c:\documents and settings\All Users\Application Data\ZoomBrowser
2010-07-16 16:33 . 2010-07-16 16:33 45056 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-07-16 16:33 . 2010-07-16 16:33 45056 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-07-16 16:33 . 2010-07-16 16:33 45056 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-07-16 16:33 . 2010-07-16 16:33 45056 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-07-16 16:33 . 2010-07-16 16:33 49152 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-07-16 16:33 . 2010-07-16 16:33 308808 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-07-16 16:33 . 2010-07-16 16:33 40960 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-07-16 16:33 . 2010-07-16 16:33 14848 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-07-16 16:33 . 2010-07-16 16:33 341600 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-07-16 16:33 . 2003-08-27 17:31 ——– d—–w- c:\program files\Common Files\Real
2010-07-16 16:32 . 2003-08-27 17:31 ——– d—–w- c:\program files\Real
2010-07-16 16:32 . 2010-07-16 16:32 ——– d—–w- c:\program files\Common Files\xing shared
2010-07-16 16:31 . 2003-03-18 21:14 499712 —-a-w- c:\windows\system32\msvcp71.dll
2010-07-16 16:31 . 2003-02-21 03:42 348160 —-a-w- c:\windows\system32\msvcr71.dll
2010-06-30 12:31 . 2004-10-21 20:25 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-27 06:01 . 2010-04-10 08:51 439816 —-a-w- c:\documents and settings\Gibbo\Application Data\Real\Update\setup3.10\setup.exe
2010-06-24 12:22 . 2006-06-23 10:33 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2004-10-21 20:25 1851904 —-a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2004-10-21 20:25 354304 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2004-10-21 20:26 80384 —-a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2004-10-21 20:26 744448 —-a-w- c:\windows\pchealth\helpctr\Binaries\helpsvc.exe
2010-06-14 07:41 . 2006-09-13 05:09 1172480 —-a-w- c:\windows\system32\msxml3.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-06-30 2102600]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-06-30 13:23 2102600 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-06-30 2102600]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-06-30 2102600]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Flying Club Alerts"="c:\program files\Flying Club Alerts\flyingclubalerts.exe" [2005-10-03 472064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ezShieldProtector for Px"="c:\windows\system32\ezSP_Px.exe" [2002-08-20 40960]
"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2003-06-12 49152]
"ehTray"="c:\windows\ehome\ehtray.exe" [2008-04-14 50176]
"CpRmtKey"="c:\program files\Toshiba Controls\CpRmtKey.EXE" [2003-05-29 94208]
"CplBTQ00"="c:\program files\EzButton\CplBTQ00.EXE" [2003-06-28 708608]
"CeEPOWER"="c:\program files\TOSHIBA\Power Management\CePMTray.exe" [2003-08-06 135168]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2003-06-10 638976]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2003-06-18 151552]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 75520]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-09-06 2065760]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2003-8-27 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-08-29 10:12 12536 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Billminder.lnk
backup=c:\windows\pss\Billminder.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk
backup=c:\windows\pss\Quicken Startup.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Gibbo^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
path=c:\documents and settings\Gibbo\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk
backup=c:\windows\pss\OpenOffice.org 2.4.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Gibbo^Start Menu^Programs^Startup^Scheduler.lnk]
path=c:\documents and settings\Gibbo\Start Menu\Programs\Startup\Scheduler.lnk
backup=c:\windows\pss\Scheduler.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Gibbo^Start Menu^Programs^Startup^SendPhotos For Outlook Express.lnk]
path=c:\documents and settings\Gibbo\Start Menu\Programs\Startup\SendPhotos For Outlook Express.lnk
backup=c:\windows\pss\SendPhotos For Outlook Express.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2008-11-07 14:16 111936 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Drag'n Drop CD+DVD]
2003-07-09 04:21 1171456 —-a-w- c:\program files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDFab Passkey]
2010-08-04 09:46 1472504 —-a-w- c:\program files\DVDFab Passkey 7\DVDFabPasskey.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2008-11-20 13:20 290088 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Location Finder]
2005-11-05 21:25 101064 —-a-w- c:\program files\Microsoft Location Finder\LocationFinder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pinger]
2002-10-17 20:21 159744 —-a-w- c:\toshiba\Ivp\ISM\pinger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2007-01-29 12:07 3718312 —-a-w- c:\program files\TomTom HOME\TomTomHOME.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SymWSC"=2 (0x2)
"SNDSrvc"=3 (0x3)
"SBService"=2 (0x2)
"SAVScan"=3 (0x3)
"C-DillaSrv"=2 (0x2)
"AOL ACS"=2 (0x2)
"wscsvc"=2 (0x2)
"Bonjour Service"=2 (0x2)
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"UleadBurningHelper"=2 (0x2)
"gupdate"=2 (0x2)
"CCALib8"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\program files\Flying Club Alerts\flyingclubalerts.exe"= c:\program files\Flying Club Alerts\flyingclubalerts.exe
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\WINDOWS\\system32\\ppshell.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [29/08/2010 11:09 25168]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [29/08/2010 11:09 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [29/08/2010 11:09 216400]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [29/08/2010 11:09 243024]
R2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [06/09/2010 21:03 921952]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [06/09/2010 21:03 308136]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [06/09/2010 21:04 2331032]
R2 mrtRate;mrtRate;c:\windows\system32\drivers\MrtRate.sys [02/10/2004 13:21 34712]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/01/2007 20:01 24652]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [29/08/2010 11:03 30104]
R3 dvdfab;dvdfab;c:\windows\system32\drivers\dvdfab.sys [13/08/2010 10:14 44928]
R3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\drivers\gflmouhid.sys [19/04/2004 16:01 6656]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [06/09/2010 21:05 431432]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [29/08/2010 11:03 30104]
S3 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [06/09/2010 21:03 5897808]
S3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [06/09/2010 21:03 122448]
S3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [06/09/2010 21:03 30288]
S3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [06/09/2010 21:03 26192]
S3 BayTvKit;TOSHIBA Style Bay TV Tuner KiT Device;c:\windows\system32\drivers\BayTvKit.sys [28/08/2003 05:28 129536]
S4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [13/03/2010 13:29 135664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
vvdsvc REG_MULTI_SZ vvdsvc
.
Contents of the 'Scheduled Tasks' folder

2010-08-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 11:34]

2010-09-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-13 12:28]

2010-09-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-13 12:28]

2010-09-07 c:\windows\Tasks\Norton Security Scan for Gibbo.job
- c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-08-31 09:06]

2010-09-10 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-4022485809-4210471992-1704011695-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 02:02]

2010-09-10 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-4022485809-4210471992-1704011695-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 02:02]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.virginmedia.com/
uInternet Settings,ProxyOverride = local
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
DPF: {03B03C66-15CB-4F16-BA86-83A55A9B0EA4} - hxxp://webcam.crowsnest-venice.com/Intellinet_Viewer.cab
DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} - hxxp://dl.uc.sina.com/cab/downloader.cab
DPF: {96816368-C1E3-414D-A193-63C3CC921990} - hxxp://gretnaweddings-anvilhall.remotemanager.co.uk/common/activex/MJPEGRender.ocx
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://65.14.83.37/activex/AMC.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-10 09:20
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2010-09-10 09:23:54
ComboFix-quarantined-files.txt 2010-09-10 08:23
ComboFix2.txt 2010-09-06 19:36

Pre-Run: 14,314,467,328 bytes free
Post-Run: 14,346,129,408 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - B9357FF3D9463D17B771A245311F8170

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI