This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help with Backdoor.Tidserv!nf / Backdoor.Tidserv.I!nf

80 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL log without the custom scans/fix:

OTL logfile created on: 9/8/2010 3:51:45 AM - Run 2
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Darryle\Desktop
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 53.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 146.48 Gb Total Space | 14.16 Gb Free Space | 9.66% Space Free | Partition Type: NTFS
Drive D: | 195.31 Gb Total Space | 42.43 Gb Free Space | 21.72% Space Free | Partition Type: NTFS
Drive E: | 123.96 Gb Total Space | 55.64 Gb Free Space | 44.88% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DARRYL
Current User Name: Darryle
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Darryle\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\hale.exe ()
PRC - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Norton 360 Premier Edition\Engine\3.8.0.41\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe (Speedbit Ltd.)
PRC - C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorEngine.exe (Speedbit Ltd.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\timeout.exe (Microsoft Corporation)
PRC - C:\Windows\System32\cmd.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\audiodg.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Windows\System32\Crypserv.exe (CrypKey (Canada) Ltd.)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()


========== Modules (SafeList) ==========

MOD - C:\Users\Darryle\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe File not found
SRV - (TuneUp.Defrag) – C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe (TuneUp Software)
SRV - (TuneUp.UtilitiesSvc) – C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) – C:\Windows\System32\uxtuneup.dll (TuneUp Software)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (N360) – C:\Program Files\Norton 360 Premier Edition\Engine\3.8.0.41\ccSvcHst.exe (Symantec Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (VideoAcceleratorService) – C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe (Speedbit Ltd.)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Crypkey License) – C:\Windows\System32\Crypserv.exe (CrypKey (Canada) Ltd.)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies)


========== Driver Services (SafeList) ==========

DRV - (RimUsb) – C:\Windows\System32\Drivers\RimUsb.sys File not found
DRV - (npkycryp) – E:\RagnarokOnline\npkycryp.sys File not found
DRV - (npkcrypt) – E:\RagnarokOnline\npkcrypt.sys File not found
DRV - (hwusbfake) – C:\Windows\System32\DRIVERS\ewusbfake.sys File not found
DRV - (hwdatacard) – C:\Windows\System32\DRIVERS\ewusbmdm.sys File not found
DRV - (GarenaPEngine) – C:\Users\Darryle\AppData\Local\Temp\IOW6A48.tmp File not found
DRV - (cpuz132) – C:\Users\Darryle\AppData\Local\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (ccHP) – C:\Windows\System32\Drivers\N360\0308000.029\ccHPx86.sys (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\N360\0308000.029\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\N360\0308000.029\SRTSP.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\Windows\System32\Drivers\N360\0308000.029\BHDrvx86.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\Drivers\N360\0308000.029\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMFW) – C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS (Symantec Corporation)
DRV - (SYMNDISV) – C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\N360\0308000.029\SRTSPX.SYS (Symantec Corporation)
DRV - (SymIM) – C:\Windows\System32\drivers\SymIMV.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100906.024\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100906.024\NAVENG.SYS (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100906.001\IDSvix86.sys (Symantec Corporation)
DRV - (RTL8167) – C:\Windows\System32\drivers\Rt86win7.sys (Realtek )
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (DrvAgent32) – C:\Windows\System32\drivers\DrvAgent32.sys (Phoenix Technologies)
DRV - (UsbserFilt) – C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) – C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) – C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) – C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (nmwcdnsu) – C:\Windows\System32\drivers\nmwcdnsu.sys (Nokia)
DRV - (nmwcdnsuc) – C:\Windows\System32\drivers\nmwcdnsuc.sys (Nokia)
DRV - (TuneUpUtilitiesDrv) – C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (KSecPkg) – C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (SCDEmu) – C:\Windows\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (Mkd2kfNt) – C:\Windows\System32\drivers\Mkd2kfNT.sys (AhnLab, Inc.)
DRV - (kl1) – C:\Windows\System32\drivers\kl1.sys (Kaspersky Lab)
DRV - (fssfltr) – C:\Windows\System32\drivers\fssfltr.sys (Microsoft Corporation)
DRV - (cmdide) – C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vhdmp) – C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\Windows\system32\DRIVERS\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\Windows\system32\DRIVERS\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (HidBatt) – C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (Mkd2Nadr) – C:\Windows\System32\drivers\Mkd2Nadr.sys (AhnLab, Inc.)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek )
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (NetworkX) – C:\Windows\system32\ckldrv.sys ()
DRV - (NPF) – C:\Windows\System32\drivers\npf.sys (CACE Technologies)
DRV - (MTsensor) – C:\Windows\System32\drivers\ASACPI.sys ()
DRV - (ZSMC301b) – C:\Windows\System32\drivers\usbVM31b.sys (VM)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local;*.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:2
FF - prefs.js..extensions.enabledItems: 5
FF - prefs.js..extensions.enabledItems: 3
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: [removed]:1.3
FF - prefs.js..extensions.enabledItems: {5B52016C-D097-4aec-BE61-9F129D8FDDBA}:2.0
FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:3.3.4
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63
FF - prefs.js..extensions.enabledItems: {0329E7D6-6F54-462D-93F6-F5C3118BADF2}:2.1.5
FF - prefs.js..extensions.enabledItems: {F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..keyword.URL: "http://www.ask.com/web?o=13796&l=dis&q="
FF - prefs.js..network.proxy.http: "localhost"
FF - prefs.js..network.proxy.http_port: 9666
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.socks: "localhost"
FF - prefs.js..network.proxy.socks_port: 9050
FF - prefs.js..network.proxy.socks_remote_dns: true
FF - prefs.js..network.proxy.ssl: "localhost"
FF - prefs.js..network.proxy.ssl_port: 9666
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Firefox\Extensions\\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}: C:\Program Files\SpeedBit Video Downloader\SPFireFox [2010/02/13 14:01:23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\
FF - HKLM\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2010/07/17 21:50:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/22 21:36:34 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/06 03:51:24 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\

[2010/09/01 19:41:06 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\mozilla\Extensions
[2010/09/01 19:41:06 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\mozilla\Extensions\[removed]
[2010/09/07 22:33:56 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\mozilla\Firefox\Profiles\fu8b78q5.default\extensions
[2009/11/22 03:35:01 | 000,000,000 | —D | M] (No name found) – C:\Users\Darryle\AppData\Roaming\mozilla\Firefox\Profiles\fu8b78q5.default\extensions\{5B52016C-D097-4aec-BE61-9F129D8FDDBA}
[2010/08/29 02:54:01 | 000,000,000 | —D | M] (ImTranslator) – C:\Users\Darryle\AppData\Roaming\mozilla\Firefox\Profiles\fu8b78q5.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2010/08/22 11:23:51 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Darryle\AppData\Roaming\mozilla\Firefox\Profiles\fu8b78q5.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/07/02 16:09:40 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Users\Darryle\AppData\Roaming\mozilla\Firefox\Profiles\fu8b78q5.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/06/27 22:27:43 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\mozilla\Firefox\Profiles\fu8b78q5.default\extensions\[removed]
[2010/05/12 00:47:09 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\mozilla\Firefox\Profiles\fu8b78q5.default\extensions\[removed]
[2009/10/23 01:52:43 | 000,002,255 | —- | M] () – C:\Users\Darryle\AppData\Roaming\Mozilla\FireFox\Profiles\fu8b78q5.default\searchplugins\askcom.xml
[2009/12/19 11:47:29 | 000,009,941 | —- | M] () – C:\Users\Darryle\AppData\Roaming\Mozilla\FireFox\Profiles\fu8b78q5.default\searchplugins\mywebsearch.xml
[2009/10/22 19:08:05 | 000,001,250 | —- | M] () – C:\Users\Darryle\AppData\Roaming\Mozilla\FireFox\Profiles\fu8b78q5.default\searchplugins\winamp-search.xml
[2010/09/07 20:38:54 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/22 19:52:24 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/04/19 03:18:45 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/13 22:10:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/07/17 00:30:02 | 000,000,811 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SBCONVERT Class) - {3017FB3E-9A77-4396-88C5-0EC9548FB42F} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll ()
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360 Premier Edition\Engine\3.8.0.41\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360 Premier Edition\Engine\3.8.0.41\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (DAPIELoader Class) - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\DAP\dapieloader.dll (SpeedBit Ltd.)
O2 - BHO: (GrabberObj Class) - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\SpeedBit Video Downloader\Toolbar\Grabber.dll (Speedbit Ltd.)
O3 - HKLM\..\Toolbar: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360 Premier Edition\Engine\3.8.0.41\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360 Premier Edition\Engine\3.8.0.41\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Chew7Hale] C:\Windows\System32\hale.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKCU..\Run: [] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowRun = 0
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Plants%20vs.%20Zombies/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files\Norton 360 Premier Edition\Engine\3.8.0.41\CoIEPlg.dll (Symantec Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O24 - Desktop WallPaper: C:\Users\Darryle\Pictures\nvidia themes\Mega_Village_25x16.jpg
O24 - Desktop BackupWallPaper: C:\Users\Darryle\Pictures\nvidia themes\Mega_Village_25x16.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\System32\livessp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | —- | M] () - D:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{4c0e97d7-ef8f-11de-a610-002618f11bc6}\Shell - "" = AutoRun
O33 - MountPoints2\{4c0e97d7-ef8f-11de-a610-002618f11bc6}\Shell\AutoRun\command - "" = G:\AutoRun.exe – File not found
O33 - MountPoints2\{4c0e97e7-ef8f-11de-a610-002618f11bc6}\Shell - "" = AutoRun
O33 - MountPoints2\{4c0e97e7-ef8f-11de-a610-002618f11bc6}\Shell\AutoRun\command - "" = G:\AutoRun.exe – File not found
O33 - MountPoints2\{4c0e9833-ef8f-11de-a610-002618f11bc6}\Shell - "" = AutoRun
O33 - MountPoints2\{4c0e9833-ef8f-11de-a610-002618f11bc6}\Shell\AutoRun\command - "" = G:\AutoRun.exe – File not found
O33 - MountPoints2\{6fe74aea-bb88-11de-8e7c-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{6fe74aea-bb88-11de-8e7c-806e6f6e6963}\Shell\AutoRun\command - "" = F:\start.exe – File not found
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\Setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/09/08 00:04:52 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Darryle\Desktop\OTL.exe
[2010/09/07 23:42:55 | 000,000,000 | —D | C] – C:\Program Files\Recuva
[2010/09/07 02:46:17 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/09/06 04:15:38 | 000,000,000 | —D | C] – C:\Users\Darryle\Desktop\malware tools
[2010/09/06 02:21:50 | 000,000,000 | —D | C] – C:\ProgramData\RegCure
[2010/09/06 02:21:50 | 000,000,000 | —D | C] – C:\Program Files\RegCure
[2010/09/04 21:43:50 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/09/04 19:39:13 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/09/04 18:27:15 | 000,000,000 | —D | C] – C:\Users\Darryle\AppData\Local\temp
[2010/09/04 18:15:53 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/09/03 22:48:55 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/09/03 00:59:54 | 000,030,528 | —- | C] (TuneUp Software) – C:\Windows\System32\TURegOpt.exe
[2010/09/03 00:59:48 | 000,030,016 | —- | C] (TuneUp Software) – C:\Windows\System32\uxtuneup.dll
[2010/09/03 00:59:48 | 000,021,312 | —- | C] (TuneUp Software) – C:\Windows\System32\authuitu.dll
[2010/09/03 00:59:31 | 000,000,000 | —D | C] – C:\Program Files\TuneUp Utilities 2010
[2010/08/26 23:35:27 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/08/26 23:35:27 | 000,606,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/08/26 23:35:27 | 000,381,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/08/26 23:35:27 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/08/26 23:35:27 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/08/26 23:35:27 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/08/26 23:35:27 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/08/26 23:35:27 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/08/26 23:35:20 | 000,197,632 | —- | C] (Intel® Corporation) – C:\Windows\System32\ir32_32.dll
[2010/08/26 23:35:20 | 000,082,944 | —- | C] (Radius Inc.) – C:\Windows\System32\iccvid.dll
[2010/08/26 23:35:19 | 002,326,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/08/26 23:35:02 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rtutils.dll
[2010/08/26 23:34:57 | 003,955,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2010/08/26 23:34:57 | 003,899,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2010/08/26 23:27:04 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2010/08/26 22:43:25 | 000,000,000 | —D | C] – C:\Windows\System32\catroot2
[2010/08/17 05:58:25 | 011,008,072 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\drivers\nvlddmkm.sys
[2010/08/17 05:58:25 | 000,056,936 | —- | C] (Khronos Group) – C:\Windows\System32\OpenCL.dll
[2010/08/17 05:58:25 | 000,010,920 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\drivers\nvBridge.kmd
[2010/08/17 05:58:24 | 014,191,208 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvoglv32.dll
[2010/08/17 05:58:24 | 009,818,728 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvd3dum.dll
[2010/08/17 05:58:24 | 002,892,904 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcuvid.dll
[2010/08/17 05:58:24 | 002,506,344 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcuvenc.dll
[2010/08/17 05:58:24 | 000,314,472 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvdecodemft.dll
[2010/08/17 05:58:22 | 010,267,240 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcompiler.dll
[2010/08/17 05:58:22 | 004,553,832 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcuda.dll
[2010/08/17 05:58:22 | 000,240,232 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcod1924.dll
[2010/08/17 05:58:22 | 000,240,232 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcod.dll
[2010/08/13 22:18:06 | 000,000,000 | —D | C] – C:\Users\Darryle\AppData\Roaming\Research In Motion
[2010/08/13 22:10:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/08/13 22:10:25 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/08/13 22:10:25 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/08/13 22:10:24 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/08/10 19:28:05 | 000,000,000 | —D | C] – C:\Users\Darryle\AppData\Roaming\WinRAR
[2010/08/10 05:15:58 | 000,094,208 | —- | C] (Apple Inc.) – C:\Windows\System32\QuickTimeVR.qtx
[2010/08/10 05:15:58 | 000,069,632 | —- | C] (Apple Inc.) – C:\Windows\System32\QuickTime.qts
[5 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/09/08 03:51:39 | 012,320,768 | —- | M] () – C:\Users\Darryle\ntuser.dat
[2010/09/08 03:44:00 | 000,000,916 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4237152153-1231085273-1120153137-1000UA.job
[2010/09/08 03:44:00 | 000,000,864 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4237152153-1231085273-1120153137-1000Core.job
[2010/09/08 01:03:25 | 000,049,544 | —- | M] () – C:\Users\Darryle\Desktop\ScreenShot.jpg
[2010/09/08 00:05:25 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Darryle\Desktop\OTL.exe
[2010/09/08 00:04:03 | 000,133,632 | —- | M] () – C:\Users\Darryle\Desktop\RKUnhookerLE.EXE
[2010/09/07 20:41:38 | 000,000,868 | —- | M] () – C:\Windows\tasks\Google Software Updater.job
[2010/09/07 20:38:54 | 000,065,536 | —- | M] () – C:\Windows\System32\Ikeext.etl
[2010/09/07 20:38:51 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/07 20:38:42 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/07 04:34:00 | 001,347,191 | -H– | M] () – C:\Users\Darryle\AppData\Local\IconCache.db
[2010/09/07 03:47:05 | 000,001,371 | —- | M] () – C:\Users\Darryle\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/09/07 02:58:25 | 000,074,603 | —- | M] () – C:\Users\Darryle\Desktop\hosts file access denied.docx
[2010/09/07 02:12:14 | 000,011,645 | —- | M] () – C:\Users\Darryle\Desktop\message.docx
[2010/09/06 22:59:36 | 005,023,903 | —- | M] () – C:\Users\Darryle\Documents\n360.securityhistory
[2010/09/06 18:00:00 | 000,000,448 | —- | M] () – C:\Windows\tasks\ParetoLogic Registration3.job
[2010/09/06 18:00:00 | 000,000,446 | —- | M] () – C:\Windows\tasks\ParetoLogic Registration.job
[2010/09/06 17:34:00 | 000,000,478 | -H– | M] () – C:\Windows\tasks\Norton Security Scan for Darryle.job
[2010/09/06 17:00:03 | 000,000,394 | —- | M] () – C:\Windows\tasks\RegCure Program Check.job
[2010/09/06 03:55:31 | 000,000,023 | —- | M] () – C:\Windows\DownloadStudio.INI
[2010/09/06 03:07:40 | 000,000,384 | —- | M] () – C:\Windows\tasks\DriverCure.job
[2010/09/05 22:58:44 | 000,743,794 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/09/05 22:58:44 | 000,635,612 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/09/05 22:58:44 | 000,111,186 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/09/05 22:09:21 | 000,004,746 | —- | M] () – C:\Windows\System32\cwlog.dtl
[2010/09/05 22:09:12 | 002,169,856 | -HS- | M] () – C:\Windows\System32\hale.exe
[2010/09/04 22:01:41 | 000,015,584 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/04 22:01:41 | 000,015,584 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/04 22:01:39 | 000,524,288 | -HS- | M] () – C:\Users\Darryle\ntuser.dat{a21e2573-b816-11df-b60d-002618f11bc6}.TMContainer00000000000000000002.regtrans-ms
[2010/09/04 22:01:39 | 000,524,288 | -HS- | M] () – C:\Users\Darryle\ntuser.dat{a21e2573-b816-11df-b60d-002618f11bc6}.TMContainer00000000000000000001.regtrans-ms
[2010/09/04 22:01:39 | 000,065,536 | -HS- | M] () – C:\Users\Darryle\ntuser.dat{a21e2573-b816-11df-b60d-002618f11bc6}.TM.blf
[2010/09/03 13:14:51 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/03 13:14:51 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/27 21:02:10 | 000,030,528 | —- | M] (TuneUp Software) – C:\Windows\System32\TURegOpt.exe
[2010/08/27 20:56:42 | 000,021,312 | —- | M] (TuneUp Software) – C:\Windows\System32\authuitu.dll
[2010/08/27 20:56:30 | 000,030,016 | —- | M] (TuneUp Software) – C:\Windows\System32\uxtuneup.dll
[2010/08/27 02:24:06 | 000,062,837 | —- | M] () – C:\Users\Darryle\Desktop\passport app form.pdf
[2010/08/27 00:02:14 | 001,792,064 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/08/13 23:23:02 | 000,513,017 | —- | M] () – C:\Users\Darryle\Documents\LoaderBackup-(2010-08-13).ipd
[2010/08/10 23:13:01 | 000,002,503 | —- | M] () – C:\Users\Darryle\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2010/08/10 05:15:58 | 000,094,208 | —- | M] (Apple Inc.) – C:\Windows\System32\QuickTimeVR.qtx
[2010/08/10 05:15:58 | 000,069,632 | —- | M] (Apple Inc.) – C:\Windows\System32\QuickTime.qts
[2010/08/10 02:21:52 | 000,524,288 | -HS- | M] () – C:\Users\Darryle\ntuser.dat{b746f87b-a3c3-11df-96ff-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms
[2010/08/10 02:21:52 | 000,524,288 | -HS- | M] () – C:\Users\Darryle\ntuser.dat{b746f87b-a3c3-11df-96ff-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms
[2010/08/10 02:21:52 | 000,065,536 | -HS- | M] () – C:\Users\Darryle\ntuser.dat{b746f87b-a3c3-11df-96ff-806e6f6e6963}.TM.blf
[2010/08/09 22:41:04 | 012,058,624 | —- | M] () – C:\Users\Darryle\NTUSER.DAT_tureg_old
[2010/08/09 21:00:40 | 000,000,256 | —- | M] () – C:\Windows\System32\pool.bin
[2010/08/09 20:54:32 | 000,246,707 | —- | M] () – C:\Users\Darryle\Documents\LoaderBackup-(2010-08-09).ipd
[5 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/08 01:03:24 | 000,049,544 | —- | C] () – C:\Users\Darryle\Desktop\ScreenShot.jpg
[2010/09/08 00:03:50 | 000,133,632 | —- | C] () – C:\Users\Darryle\Desktop\RKUnhookerLE.EXE
[2010/09/07 03:47:05 | 000,001,371 | —- | C] () – C:\Users\Darryle\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/09/07 02:58:25 | 000,074,603 | —- | C] () – C:\Users\Darryle\Desktop\hosts file access denied.docx
[2010/09/07 02:12:14 | 000,011,645 | —- | C] () – C:\Users\Darryle\Desktop\message.docx
[2010/09/06 22:59:27 | 005,023,903 | —- | C] () – C:\Users\Darryle\Documents\n360.securityhistory
[2010/09/06 03:55:31 | 000,000,023 | —- | C] () – C:\Windows\DownloadStudio.INI
[2010/09/06 02:21:55 | 000,000,394 | —- | C] () – C:\Windows\tasks\RegCure Program Check.job
[2010/09/05 22:09:17 | 000,004,746 | —- | C] () – C:\Windows\System32\cwlog.dtl
[2010/09/05 22:09:12 | 002,169,856 | -HS- | C] () – C:\Windows\System32\hale.exe
[2010/09/04 21:42:58 | 000,524,288 | -HS- | C] () – C:\Users\Darryle\ntuser.dat{a21e2573-b816-11df-b60d-002618f11bc6}.TMContainer00000000000000000002.regtrans-ms
[2010/09/04 21:42:58 | 000,524,288 | -HS- | C] () – C:\Users\Darryle\ntuser.dat{a21e2573-b816-11df-b60d-002618f11bc6}.TMContainer00000000000000000001.regtrans-ms
[2010/09/04 21:42:58 | 000,065,536 | -HS- | C] () – C:\Users\Darryle\ntuser.dat{a21e2573-b816-11df-b60d-002618f11bc6}.TM.blf
[2010/08/27 02:24:01 | 000,062,837 | —- | C] () – C:\Users\Darryle\Desktop\passport app form.pdf
[2010/08/13 23:23:02 | 000,513,017 | —- | C] () – C:\Users\Darryle\Documents\LoaderBackup-(2010-08-13).ipd
[2010/08/09 22:42:12 | 000,524,288 | -HS- | C] () – C:\Users\Darryle\ntuser.dat{b746f87b-a3c3-11df-96ff-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms
[2010/08/09 22:42:12 | 000,524,288 | -HS- | C] () – C:\Users\Darryle\ntuser.dat{b746f87b-a3c3-11df-96ff-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms
[2010/08/09 22:42:12 | 000,065,536 | -HS- | C] () – C:\Users\Darryle\ntuser.dat{b746f87b-a3c3-11df-96ff-806e6f6e6963}.TM.blf
[2010/08/09 20:54:32 | 000,246,707 | —- | C] () – C:\Users\Darryle\Documents\LoaderBackup-(2010-08-09).ipd
[2010/08/09 20:51:47 | 000,000,256 | —- | C] () – C:\Windows\System32\pool.bin
[2010/08/09 13:05:45 | 000,000,886 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/09 13:05:44 | 000,000,882 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/09 02:21:55 | 000,005,564 | —- | C] () – C:\Users\Darryle\AppData\Roaming\BBMS_EXCEPTION.txt
[2010/08/07 02:07:36 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2010/07/31 21:11:19 | 000,000,068 | —- | C] () – C:\Windows\SPCDR.INI
[2010/07/31 21:11:11 | 000,000,070 | —- | C] () – C:\Windows\Crypkey.ini
[2010/07/31 21:11:07 | 000,019,584 | —- | C] () – C:\Windows\System32\Ckldrv.sys
[2010/07/31 21:11:07 | 000,018,432 | —- | C] () – C:\Windows\Setup_ck.dll
[2010/05/12 13:20:40 | 000,000,172 | —- | C] () – C:\Windows\System32\MRT.INI
[2010/04/19 14:18:17 | 000,000,014 | —- | C] () – C:\ProgramData\AdobeUpdater.rbt
[2009/12/29 17:21:45 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/12/20 13:24:28 | 000,107,008 | —- | C] () – C:\Users\Darryle\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/09 13:13:44 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2009/11/08 20:47:46 | 000,000,204 | —- | C] () – C:\Windows\struct~.ini
[2009/11/06 10:58:04 | 000,178,975 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2009/10/25 12:35:58 | 000,022,328 | —- | C] () – C:\Users\Darryle\AppData\Roaming\PnkBstrK.sys
[2009/10/20 05:16:36 | 000,000,033 | —- | C] () – C:\Windows\DownloadStudioScheduleMonitor.INI
[2009/10/18 14:09:49 | 001,058,871 | —- | C] () – C:\Users\Darryle\AppData\Roaming\UserTile.png
[2009/10/18 11:13:48 | 000,000,412 | —- | C] () – C:\Windows\MAXLINK.INI
[2009/10/18 10:40:00 | 002,463,976 | —- | C] () – C:\Windows\System32\NPSWF32.dll
[2009/10/18 10:23:05 | 000,164,352 | —- | C] () – C:\Windows\System32\unrar.dll
[2009/10/18 10:23:05 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2009/10/18 10:23:04 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2009/10/18 10:23:04 | 000,755,027 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2009/10/18 10:23:04 | 000,159,839 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2009/10/18 10:23:02 | 000,007,680 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2009/10/18 10:23:02 | 000,000,547 | —- | C] () – C:\Windows\System32\ff_vfw.dll.manifest
[2009/10/18 10:06:37 | 000,019,176 | —- | C] () – C:\Windows\Ascd_log.ini
[2009/10/18 10:06:28 | 000,007,680 | —- | C] () – C:\Windows\System32\drivers\ASACPI.sys
[2009/10/18 10:06:24 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2009/10/18 10:06:21 | 000,014,436 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2009/10/18 10:06:21 | 000,010,296 | —- | C] () – C:\Windows\System32\drivers\ASUSHWIO.SYS
[2009/10/18 10:04:36 | 000,000,107 | —- | C] () – C:\Windows\VSWizard.ini
[2009/07/14 07:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 07:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/07/14 07:11:15 | 000,021,584 | —- | C] () – C:\Windows\System32\drivers\atapi(56).sys
[2009/02/04 17:50:32 | 000,024,576 | —- | C] () – C:\Windows\System32\nsis_loader.dll
[2008/10/08 00:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/08 00:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/08 00:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/08 00:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/08 00:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/08 00:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/08 00:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/08 00:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/08 00:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
[2008/09/17 17:27:04 | 000,093,680 | —- | C] () – C:\Windows\System32\gtapi_pack.dll
[2007/11/07 04:19:28 | 000,053,299 | —- | C] () – C:\Windows\System32\pthreadVC.dll

========== LOP Check ==========

[2010/02/21 19:25:13 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\AnvSoft
[2010/08/06 21:27:09 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\Any Video Converter
[2009/12/20 13:47:59 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\Canon
[2010/08/01 01:39:23 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\CDRoller
[2010/05/16 08:51:30 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\DriverCure
[2010/05/02 01:54:55 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\Drivers
[2010/01/29 22:14:44 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\Friday's games
[2010/01/29 21:50:24 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\Fuzzy Games
[2009/12/07 20:38:58 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\Leadertech
[2010/09/01 23:30:16 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\LimeWire
[2009/11/19 14:10:40 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\Maxthon2
[2009/11/19 14:10:40 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\Meridian93
[2010/08/07 03:27:54 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\Nokia
[2010/04/23 20:22:08 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\Nokia Ovi Suite
[2010/04/23 20:20:41 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\PC Suite
[2009/11/19 14:10:50 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\PPMate
[2009/11/19 14:10:50 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\ppstream
[2010/08/13 22:18:06 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\Research In Motion
[2009/11/19 14:10:50 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\ScanSoft
[2010/01/14 20:10:32 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\SpinTop
[2009/11/19 14:10:51 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\StreamTorrent
[2010/03/25 18:14:53 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\SystemRequirementsLab
[2009/11/19 14:10:51 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\TuneUp Software
[2009/11/19 14:10:51 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\Ubisoft
[2010/09/06 20:08:51 | 000,000,000 | —D | M] – C:\Users\Darryle\AppData\Roaming\uTorrent
[2010/09/06 03:07:40 | 000,000,384 | —- | M] () – C:\Windows\Tasks\DriverCure.job
[2010/09/06 18:00:00 | 000,000,446 | —- | M] () – C:\Windows\Tasks\ParetoLogic Registration.job
[2010/09/06 18:00:00 | 000,000,448 | —- | M] () – C:\Windows\Tasks\ParetoLogic Registration3.job
[2010/06/14 16:19:40 | 000,000,420 | —- | M] () – C:\Windows\Tasks\ParetoLogic Update Version2.job
[2010/09/06 17:00:03 | 000,000,394 | —- | M] () – C:\Windows\Tasks\RegCure Program Check.job
[2010/04/23 07:32:23 | 000,032,622 | —- | M] () – C:\Windows\Tasks\SCHEDLGU(58).TXT
[2010/08/26 21:58:51 | 000,032,608 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========


< End of report >
Hello,

Yes, that's okay

Did you set these settings?

FF - prefs.js..network.proxy.http: "localhost"
FF - prefs.js..network.proxy.http_port: 9666
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.socks: "localhost"
FF - prefs.js..network.proxy.socks_port: 9050
FF - prefs.js..network.proxy.socks_remote_dns: true
FF - prefs.js..network.proxy.ssl: "localhost"
FF - prefs.js..network.proxy.ssl_port: 9666
FF - prefs.js..network.proxy.type: 0

———–

You have any idea what this file is?

[Chew7Hale] C:\Windows\System32\hale.exe ()



NEXT:



OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    DRV - (GarenaPEngine) – C:\Users\Darryle\AppData\Local\Temp\IOW6A48.tmp File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
    O4 - HKLM..\Run: [] File not found
    O4 - HKCU..\Run: [] File not found
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowRun = 0
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    O33 - MountPoints2\{4c0e97d7-ef8f-11de-a610-002618f11bc6}\Shell - "" = AutoRun
    O33 - MountPoints2\{4c0e97d7-ef8f-11de-a610-002618f11bc6}\Shell\AutoRun\command - "" = G:\AutoRun.exe – File not found
    O33 - MountPoints2\{4c0e97e7-ef8f-11de-a610-002618f11bc6}\Shell - "" = AutoRun
    O33 - MountPoints2\{4c0e97e7-ef8f-11de-a610-002618f11bc6}\Shell\AutoRun\command - "" = G:\AutoRun.exe – File not found
    O33 - MountPoints2\{4c0e9833-ef8f-11de-a610-002618f11bc6}\Shell - "" = AutoRun
    O33 - MountPoints2\{4c0e9833-ef8f-11de-a610-002618f11bc6}\Shell\AutoRun\command - "" = G:\AutoRun.exe – File not found
    O33 - MountPoints2\{6fe74aea-bb88-11de-8e7c-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{6fe74aea-bb88-11de-8e7c-806e6f6e6963}\Shell\AutoRun\command - "" = F:\start.exe – File not found
    O33 - MountPoints2\G\Shell - "" = AutoRun
    O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\Setup.exe – File not found
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    :Commands
    [purity]
    [resethosts]
    [CreateRestorePoint]
    [emptytemp]
    [EMPTYFLASH]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.


NEXT:



Running ComboFix
Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
I am not familiar with the settings you have listed, no. Chew7Hale on the other hand, is a tool I found out on a windows7 forums because my system is being incorrectly flagged by Microsoft as not genuine. I already did verify my key with them online and it came clean but there was still this annoying pop up saying "I may be a victim of software counterfeiting…blah…blah…" and a watermark in the lower right part of my screen saying my copy of windows is not genuine. It was said that the tool was safe so I used it. The annoying pop ups disappeared, so was the watermark. But then the option to activate my windows in the System page disappeared also, replaced by "Not Available". One thing I noticed about it is that it seems to have made itself an integral part of the PC's operation since it loads at startup I guess? Btw, I used the tool the same thing over the weekend when I was tinkering with a lot of stuff to figure out how to clean my PC. Did I mess up on this, did it make the situation worse? I'll post an update regarding your next instructions asap.

It was said that the tool was safe so I used it.

Where did you hear about this tool?


Did I mess up on this, did it make the situation worse?

I'm not really sure. I'll have a better idea once I see the logs.
Now that you've asked, I really can't remember what forums it was exactly, I was doing random searches then, I was really stressed over the weekend about this computer.

Here is the OTL Fix Log:

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Service GarenaPEngine stopped successfully!
Service GarenaPEngine deleted successfully!
File C:\Users\Darryle\AppData\Local\Temp\IOW6A48.tmp File not found not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoFind deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\DisallowRun deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4c0e97d7-ef8f-11de-a610-002618f11bc6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4c0e97d7-ef8f-11de-a610-002618f11bc6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4c0e97d7-ef8f-11de-a610-002618f11bc6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4c0e97d7-ef8f-11de-a610-002618f11bc6}\ not found.
File G:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4c0e97e7-ef8f-11de-a610-002618f11bc6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4c0e97e7-ef8f-11de-a610-002618f11bc6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4c0e97e7-ef8f-11de-a610-002618f11bc6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4c0e97e7-ef8f-11de-a610-002618f11bc6}\ not found.
File G:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4c0e9833-ef8f-11de-a610-002618f11bc6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4c0e9833-ef8f-11de-a610-002618f11bc6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4c0e9833-ef8f-11de-a610-002618f11bc6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4c0e9833-ef8f-11de-a610-002618f11bc6}\ not found.
File G:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6fe74aea-bb88-11de-8e7c-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6fe74aea-bb88-11de-8e7c-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6fe74aea-bb88-11de-8e7c-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6fe74aea-bb88-11de-8e7c-806e6f6e6963}\ not found.
File F:\start.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ not found.
File G:\Setup.exe not found.
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Darryle\Desktop\OTL\cmd.bat deleted successfully.
C:\Users\Darryle\Desktop\OTL\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully


[EMPTYTEMP]

User: All Users

User: Darryle
->Temp folder emptied: 35374676 bytes
->Temporary Internet Files folder emptied: 1581600 bytes
->Java cache emptied: 57618954 bytes
->FireFox cache emptied: 35354025 bytes
->Google Chrome cache emptied: 7099699 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 2141209 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes
->Flash cache emptied: 41620 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: test
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 2708101 bytes
->Flash cache emptied: 42076 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 602112 bytes
%systemroot%\System32 .tmp files removed: 8691672 bytes
%systemroot%\System32\drivers .tmp files removed: 43168 bytes
Windows Temp folder emptied: 1937206 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 517950 bytes

Total Files Cleaned = 147.00 mb


[EMPTYFLASH]

User: All Users

User: Darryle
->Flash cache emptied: 0 bytes

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

User: test
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.11.0 log created on 09082010_041954

Files\Folders moved on Reboot…
File\Folder C:\Windows\temp\JETD863.tmp not found!

Registry entries deleted on Reboot…

–
Will proceed now with ComboFix…
Here's the entire log from combofix: ComboFix 10-09-07.01 - Darryle 09/08/2010 4:35.1.2 - x86 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2047.1231 [GMT 8:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\struct~.ini Infected copy of c:\windows\system32\winlogon.exe was found and disinfected Restored copy from - c:\windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe Infected copy of c:\windows\System32\slui.exe was found and disinfected Restored copy from - c:\windows\winsxs\x86_microsoft-windows-security-spp-ux_31bf3856ad364e35_6.1.7600.16385_none_5b97f4df0025c6e9\slui.exe . ((((((((((((((((((((((((( Files Created from 2010-08-07 to 2010-09-07 ))))))))))))))))))))))))))))))) . 2010-09-07 20:42 . 2010-09-07 20:44 ——– d—–w- c:\users\Darryle\AppData\Local\temp 2010-09-07 20:42 . 2010-09-07 20:42 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp 2010-09-07 20:42 . 2010-09-07 20:42 ——– d—–w- c:\users\test\AppData\Local\temp 2010-09-07 20:42 . 2010-09-07 20:42 ——– d—–w- c:\users\Public\AppData\Local\temp 2010-09-07 20:42 . 2010-09-07 20:42 ——– d—–w- c:\users\Default\AppData\Local\temp 2010-09-07 20:33 . 2010-09-07 20:34 ——– d—–w- C:\32788R22FWJFW 2010-09-07 20:19 . 2010-09-07 20:19 ——– d—–w- C:\_OTL 2010-09-07 15:42 . 2010-09-07 15:43 ——– d—–w- c:\program files\Recuva 2010-09-06 18:46 . 2010-09-06 18:46 388096 —-a-r- c:\users\Darryle\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2010-09-06 18:46 . 2010-09-06 18:46 ——– d—–w- c:\program files\Trend Micro 2010-09-05 18:21 . 2010-09-05 18:47 ——– d—–w- c:\programdata\RegCure 2010-09-05 18:21 . 2010-09-05 18:24 ——– d—–w- c:\program files\RegCure 2010-09-05 14:09 . 2009-10-28 06:17 285696 —-a-w- c:\programdata\Microsoft\Windows\SXS\32\winlogon.exe 2010-09-05 14:09 . 2009-07-14 01:14 79872 —-a-w- c:\programdata\Microsoft\Windows\SXS\32\winver.exe 2010-09-05 14:09 . 2009-07-14 01:16 53760 —-a-w- c:\programdata\Microsoft\Windows\SXS\32\sppuinotify.dll 2010-09-05 14:09 . 2009-07-14 01:16 410624 —-a-w- c:\programdata\Microsoft\Windows\SXS\32\systemcpl.dll 2010-09-05 14:09 . 2009-07-14 01:16 345088 —-a-w- c:\programdata\Microsoft\Windows\SXS\32\sppcommdlg.dll 2010-09-05 14:09 . 2009-07-14 01:14 325632 —-a-w- c:\programdata\Microsoft\Windows\SXS\32\slui.exe 2010-09-05 14:09 . 2009-07-14 01:16 811520 —-a-w- c:\programdata\Microsoft\Windows\SXS\32\user32.dll 2010-09-05 14:09 . 2009-07-14 01:16 13824 —-a-w- c:\programdata\Microsoft\Windows\SXS\32\slwga.dll 2010-09-05 14:09 . 2009-07-14 01:16 118784 —-a-w- c:\programdata\Microsoft\Windows\SXS\32\sppwmi.dll 2010-09-05 14:09 . 2010-09-05 14:09 2169856 –sha-w- c:\windows\system32\hale.exe 2010-09-04 11:39 . 2010-09-04 11:39 ——– d—–w- c:\program files\ESET 2010-09-03 14:48 . 2010-09-03 14:48 ——– d—–w- c:\program files\iPod 2010-09-03 14:41 . 2010-09-03 14:41 73000 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 10.0.0.68\SetupAdmin.exe 2010-09-02 16:59 . 2010-08-27 13:02 30528 —-a-w- c:\windows\system32\TURegOpt.exe 2010-09-02 16:59 . 2010-08-27 12:56 21312 —-a-w- c:\windows\system32\authuitu.dll 2010-09-02 16:59 . 2010-08-27 12:56 30016 —-a-w- c:\windows\system32\uxtuneup.dll 2010-09-02 16:59 . 2010-09-03 17:02 ——– d—–w- c:\program files\TuneUp Utilities 2010 2010-08-30 18:36 . 2010-08-30 18:36 56765 —-a-w- c:\programdata\DivX\DivXPlusShortcuts\Uninstaller.exe 2010-08-30 18:36 . 2010-08-30 18:35 185640 —-a-w- c:\programdata\DivX\Setup\finishPlugin.dll 2010-08-30 18:36 . 2010-08-30 18:36 56997 —-a-w- c:\programdata\DivX\WebPlayer\Uninstaller.exe 2010-08-30 18:36 . 2010-08-30 18:36 53600 —-a-w- c:\programdata\DivX\Update\Uninstaller.exe 2010-08-30 18:36 . 2010-08-30 18:36 57691 —-a-w- c:\programdata\DivX\Player\Uninstaller.exe 2010-08-30 18:35 . 2010-08-30 18:35 54153 —-a-w- c:\programdata\DivX\DFXPlugin\Uninstaller.exe 2010-08-30 18:35 . 2010-08-30 18:35 144696 —-a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.exe 2010-08-26 15:34 . 2010-06-22 02:47 310784 —-a-w- c:\windows\system32\drivers\srv.sys 2010-08-26 15:34 . 2010-06-22 02:47 307200 —-a-w- c:\windows\system32\drivers\srv2.sys 2010-08-26 15:34 . 2010-06-22 02:47 113664 —-a-w- c:\windows\system32\drivers\srvnet.sys 2010-08-26 15:34 . 2010-06-08 06:02 1233920 —-a-w- c:\windows\system32\msxml3.dll 2010-08-26 15:34 . 2010-06-19 06:33 3955080 —-a-w- c:\windows\system32\ntkrnlpa.exe 2010-08-26 15:34 . 2010-06-19 06:33 3899784 —-a-w- c:\windows\system32\ntoskrnl.exe 2010-08-26 15:27 . 2010-09-05 19:44 ——– d—–w- C:\TDSSKiller_Quarantine 2010-08-26 14:43 . 2010-09-06 18:46 ——– d—–w- c:\windows\system32\catroot2 2010-08-16 21:58 . 2010-08-06 00:08 56936 —-a-w- c:\windows\system32\OpenCL.dll 2010-08-16 21:58 . 2010-08-06 00:08 11008072 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys 2010-08-16 21:58 . 2010-08-06 00:08 9818728 —-a-w- c:\windows\system32\nvd3dum.dll 2010-08-16 21:58 . 2010-08-06 00:08 314472 —-a-w- c:\windows\system32\nvdecodemft.dll 2010-08-16 21:58 . 2010-08-06 00:08 2892904 —-a-w- c:\windows\system32\nvcuvid.dll 2010-08-16 21:58 . 2010-08-06 00:08 2506344 —-a-w- c:\windows\system32\nvcuvenc.dll 2010-08-16 21:58 . 2010-08-06 00:08 14191208 —-a-w- c:\windows\system32\nvoglv32.dll 2010-08-16 21:58 . 2010-08-06 00:08 4553832 —-a-w- c:\windows\system32\nvcuda.dll 2010-08-16 21:58 . 2010-08-06 00:08 240232 —-a-w- c:\windows\system32\nvcod1924.dll 2010-08-16 21:58 . 2010-08-06 00:08 240232 —-a-w- c:\windows\system32\nvcod.dll 2010-08-16 21:58 . 2010-08-06 00:08 10267240 —-a-w- c:\windows\system32\nvcompiler.dll 2010-08-13 14:18 . 2010-08-13 14:18 ——– d—–w- c:\users\Darryle\AppData\Roaming\Research In Motion 2010-08-13 14:10 . 2010-08-13 14:10 ——– d—–w- c:\program files\Common Files\Java 2010-08-10 15:10 . 2010-08-10 15:10 72488 —-a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.33.17.8\SetupAdmin.exe 2010-08-09 12:51 . 2010-08-09 13:00 256 —-a-w- c:\windows\system32\pool.bin 2010-08-09 05:01 . 2010-08-09 05:00 509552 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtb7EC1.tmp.exe 2010-08-09 05:00 . 2010-08-09 05:00 ——– d—–w- c:\users\test\AppData\Roaming\TuneUp Software 2010-08-09 04:01 . 2007-01-18 02:24 26496 —-a-w- c:\windows\system32\drivers\RimSerial.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-09-07 20:43 . 2009-12-06 15:47 602 —-a-w- c:\programdata\ArcSoft\kodak-printcreations-22-080812-oem\acforall.dll 2010-09-06 16:26 . 2009-10-22 10:49 ——– d—–w- c:\users\Darryle\AppData\Roaming\Skype 2010-09-06 16:07 . 2009-10-22 10:49 ——– d—–w- c:\users\Darryle\AppData\Roaming\skypePM 2010-09-06 12:08 . 2009-10-19 16:37 ——– d—–w- c:\users\Darryle\AppData\Roaming\uTorrent 2010-09-05 19:58 . 2009-11-08 12:47 ——– d—–w- c:\program files\Google 2010-09-05 19:55 . 2010-08-08 13:39 ——– d—–w- c:\users\Darryle\AppData\Roaming\InstallShield 2010-09-05 19:55 . 2009-10-18 02:04 ——– d–h–w- c:\program files\InstallShield Installation Information 2010-09-05 19:04 . 2010-05-16 00:26 ——– d—–w- c:\programdata\DriverCure 2010-09-05 14:10 . 2009-11-09 09:42 ——– d—–w- c:\program files\Microsoft Silverlight 2010-09-04 13:41 . 2009-12-06 15:47 ——– d—–w- c:\programdata\ArcSoft 2010-09-04 13:41 . 2009-10-18 06:05 ——– d—–w- c:\programdata\FLEXnet 2010-09-04 09:27 . 2009-10-18 03:19 ——– d—–w- c:\programdata\CanonIJPLM 2010-09-03 21:55 . 2010-05-08 05:33 63488 —-a-w- c:\users\Darryle\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll 2010-09-03 21:55 . 2010-05-03 17:08 117760 —-a-w- c:\users\Darryle\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2010-09-03 14:49 . 2010-07-21 02:07 ——– d—–w- c:\program files\iTunes 2010-09-03 14:48 . 2009-10-18 05:42 ——– d—–w- c:\program files\Common Files\Apple 2010-09-02 04:19 . 2010-06-28 18:28 ——– d—–w- c:\program files\Hard Disk Sentinel 2010-09-01 15:30 . 2009-10-25 18:15 ——– d—–w- c:\users\Darryle\AppData\Roaming\LimeWire 2010-08-30 18:44 . 2010-04-18 11:53 57344 —-a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll 2010-08-30 18:36 . 2010-04-18 11:47 ——– d—–w- c:\program files\DivX 2010-08-30 18:36 . 2010-04-18 11:47 ——– d—–w- c:\programdata\DivX 2010-08-30 18:35 . 2010-04-18 11:53 1062184 —-a-w- c:\programdata\DivX\Setup\Resource.dll 2010-08-30 12:32 . 2009-12-06 15:47 ——– d—–w- c:\users\Darryle\AppData\Roaming\ArcSoft 2010-08-28 18:40 . 2010-05-03 17:07 ——– d—–w- c:\program files\SUPERAntiSpyware 2010-08-27 13:42 . 2009-10-19 16:37 ——– d—–w- c:\program files\uTorrent 2010-08-26 17:20 . 2009-10-18 02:18 ——– d—–w- c:\programdata\Microsoft Help 2010-08-26 15:29 . 2009-07-13 23:19 28240 —-a-w- c:\windows\system32\drivers\mssmbios.sys 2010-08-25 23:20 . 2010-04-18 11:53 850200 —-a-w- c:\programdata\DivX\Setup\DivXSetup.exe 2010-08-22 13:36 . 2009-10-18 02:40 ——– d—–w- c:\program files\QuickTime 2010-08-20 22:09 . 2009-10-22 09:55 ——– d—–w- c:\program files\Yahoo! 2010-08-20 19:17 . 2010-03-26 11:11 ——– d—–w- c:\users\Darryle\AppData\Roaming\Yahoo! 2010-08-17 05:38 . 2009-12-11 03:42 95744 —-a-w- c:\programdata\SpeedBit\DAP\SDCondition.dll 2010-08-16 22:01 . 2009-10-18 02:00 ——– d—–w- c:\programdata\NVIDIA 2010-08-16 22:00 . 2009-12-12 07:19 ——– d—–w- c:\program files\NVIDIA Corporation 2010-08-16 21:44 . 2010-05-03 17:07 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2010-08-13 14:10 . 2009-10-22 10:17 ——– d—–w- c:\program files\Java 2010-08-10 15:13 . 2009-12-14 12:07 ——– d—–w- c:\program files\Safari 2010-08-09 04:30 . 2010-08-08 13:38 ——– d—–w- c:\program files\Roxio 2010-08-09 04:04 . 2009-10-22 11:04 ——– d—–w- c:\program files\Common Files\PX Storage Engine 2010-08-08 17:55 . 2009-11-19 06:32 124768 —-a-w- c:\users\Darryle\AppData\Local\GDIPFONTCACHEV1.DAT 2010-08-08 13:39 . 2010-08-08 13:39 ——– d—–w- c:\programdata\Sonic 2010-08-08 13:39 . 2010-08-08 13:38 ——– d—–w- c:\programdata\Roxio 2010-08-08 13:38 . 2010-08-08 13:36 ——– d—–w- c:\program files\Common Files\Roxio Shared 2010-08-08 13:38 . 2010-08-08 13:38 ——– d—–w- c:\program files\Common Files\Sonic Shared 2010-08-08 11:03 . 2009-11-08 12:47 ——– d—–w- c:\programdata\Google Updater 2010-08-06 19:27 . 2010-04-23 12:15 ——– d—–w- c:\users\Darryle\AppData\Roaming\Nokia 2010-08-06 19:27 . 2010-01-15 14:31 ——– d—–w- c:\programdata\PopCap Games 2010-08-06 18:57 . 2010-06-28 16:51 ——– d—–w- c:\programdata\Innovative Solutions 2010-08-06 18:57 . 2010-08-06 18:57 ——– d—–w- c:\program files\Innovative Solutions 2010-08-06 18:52 . 2009-10-18 02:08 ——– d–h–w- c:\program files\Temp 2010-08-06 18:07 . 2009-11-19 05:46 ——– d—–w- c:\program files\Realtek 2010-08-06 18:03 . 2010-08-06 18:03 ——– d—–w- c:\program files\ParetoLogic 2010-08-06 17:41 . 2010-06-11 17:43 3248400 —-a-w- c:\programdata\ParetoLogic\UUS2\DriverCure\Temp\Update.exe 2010-08-06 13:27 . 2009-10-19 21:15 ——– d—–w- c:\users\Darryle\AppData\Roaming\Any Video Converter 2010-08-06 00:08 . 2010-08-16 21:58 10920 —-a-w- c:\windows\system32\drivers\nvBridge.kmd 2010-08-06 00:08 . 2009-09-27 15:12 5107816 —-a-w- c:\windows\system32\nvwgf2um.dll 2010-08-06 00:08 . 2009-09-27 15:12 1625192 —-a-w- c:\windows\system32\nvapi.dll 2010-08-05 10:40 . 2010-08-05 10:40 129640 —-a-w- c:\windows\system32\nvvsvc.exe 2010-08-05 10:40 . 2010-08-05 10:40 110696 —-a-w- c:\windows\system32\nvmctray.dll 2010-08-05 10:40 . 2010-08-05 10:40 1881704 —-a-w- c:\windows\system32\nvsvcr.dll 2010-08-05 10:40 . 2010-08-05 10:40 13939816 —-a-w- c:\windows\system32\nvcpl.dll 2010-08-05 10:40 . 2010-08-05 10:40 1469544 —-a-w- c:\windows\system32\nvsvc.dll 2010-08-04 06:56 . 2010-08-04 06:56 ——– d—–w- c:\program files\Core Services 2010-08-04 06:19 . 2010-08-04 06:19 1238 —-a-w- C:\reregister.bat 2010-08-01 17:46 . 2010-08-01 17:46 15341 —-a-w- c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat 2010-08-01 17:46 . 2010-08-01 17:46 ——– d—–w- c:\program files\Illustrate 2010-08-01 17:44 . 2010-08-01 17:46 5653224 —-a-w- c:\windows\system32\SpoonUninstall.exe 2010-08-01 11:05 . 2009-10-18 05:43 ——– d—–w- c:\users\Darryle\AppData\Roaming\Apple Computer 2010-07-31 17:39 . 2010-07-31 17:39 ——– d—–w- c:\users\Darryle\AppData\Roaming\CDRoller 2010-07-31 17:39 . 2010-07-31 17:39 ——– d—–w- c:\program files\CDRoller 2010-07-29 06:30 . 2010-08-26 15:35 197632 —-a-w- c:\windows\system32\ir32_32.dll 2010-07-29 06:30 . 2010-08-26 15:35 82944 —-a-w- c:\windows\system32\iccvid.dll 2010-07-28 12:42 . 2009-10-18 02:05 ——– d—–w- c:\program files\Common Files\Adobe 2010-07-28 10:23 . 2010-08-06 18:51 3154920 —-a-w- c:\windows\system32\drivers\RTKVHDA.sys 2010-07-28 10:23 . 2010-08-06 18:51 1829992 —-a-w- c:\windows\system32\RtkPgExt.dll 2010-07-28 10:23 . 2010-08-06 18:51 64616 —-a-w- c:\windows\system32\RtkCoInst.dll 2010-07-28 10:23 . 2010-08-06 18:51 367208 —-a-w- c:\windows\system32\RtkApoApi.dll 2010-07-28 10:23 . 2010-08-06 18:51 3604584 —-a-w- c:\windows\system32\RtkAPO.dll 2010-07-28 10:23 . 2010-08-06 18:51 371816 —-a-w- c:\windows\system32\RCoRes.dat 2010-07-27 05:54 . 2010-08-06 18:51 1251944 —-a-w- c:\windows\RtlExUpd.dll 2010-07-22 08:48 . 2010-08-06 18:51 214352 —-a-w- c:\windows\system32\SFNHK.dll 2010-07-22 08:48 . 2010-08-06 18:51 68944 —-a-w- c:\windows\system32\SFAPO.dll 2010-07-22 08:48 . 2010-08-06 18:51 74064 —-a-w- c:\windows\system32\SFCOM.dll 2010-07-22 08:37 . 2010-08-06 18:51 175200 —-a-w- c:\windows\system32\AERTACap.dll 2010-07-21 01:42 . 2010-07-21 01:42 71992 —-a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe 2010-07-17 07:31 . 2009-10-18 02:07 ——– d—–w- c:\programdata\Symantec 2010-07-16 21:00 . 2010-04-18 19:18 423656 —-a-w- c:\windows\system32\deployJava1.dll 2010-07-16 16:26 . 2010-07-16 15:13 ——– d—–w- c:\program files\Common Files\Symantec Shared 2010-07-16 16:26 . 2010-07-16 15:09 ——– d—–w- c:\programdata\NortonInstaller 2010-07-16 15:21 . 2009-10-18 02:07 ——– d—a-w- c:\programdata\Norton 2010-07-16 15:13 . 2010-07-16 15:13 ——– d—–w- c:\program files\Symantec 2010-07-16 15:13 . 2010-07-16 15:13 806 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF 2010-07-16 15:13 . 2010-07-16 15:13 7456 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT 2010-07-16 15:13 . 2010-07-16 15:13 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2010-07-16 15:13 . 2010-07-16 15:13 26600 —-a-r- c:\windows\system32\drivers\GEARAspiWDM.sys 2010-07-16 15:13 . 2010-07-16 15:13 25648 —-a-r- c:\windows\system32\drivers\SymIMV.sys 2010-07-16 15:13 . 2010-07-16 15:13 107368 —-a-r- c:\windows\system32\GEARAspi.dll 2010-07-16 15:13 . 2010-07-16 15:12 ——– d—–w- c:\program files\Norton 360 Premier Edition 2010-07-16 15:09 . 2010-05-01 22:05 ——– d—–w- c:\program files\NortonInstaller 2010-07-11 06:07 . 2010-04-18 11:53 ——– d—–w- c:\users\Darryle\AppData\Roaming\DivX 2009-06-10 21:26 . 2009-07-14 02:04 9633792 –sha-r- c:\windows\Fonts\StaticCache.dat 2009-07-14 01:14 . 2009-07-13 23:42 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe . ——- Sigcheck ——- [-] 2009-07-14 . 85AEB26057AAC125EEC1425305F86960 . 811520 . . [6.1.7600.16385] . . c:\windows\System32\user32.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3017FB3E-9A77-4396-88C5-0EC9548FB42F}] 2010-02-13 06:00 2447360 —-a-w- c:\program files\SpeedBit Video Downloader\Toolbar\tbcore3.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-07-28 9398888] "Chew7Hale"="c:\windows\System32\hale.exe" [2010-09-05 2169856] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 07:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys] @="FSFilter Activity Monitor" [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup backupExtension=Common Startup [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "Messenger (Yahoo!)"="c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet "Sidebar"=c:\program files\Windows Sidebar\sidebar.exe /autoRun "SpeedBitVideoAccelerator"=c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe "DownloadAccelerator"="c:\program files\DAP\DAP.EXE" /STARTUP "VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" "PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray "DriverCure"=c:\program files\ParetoLogic\DriverCure\DriverCure.exe -restart "AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" "Google Update"="c:\users\Darryle\AppData\Local\Google\Update\GoogleUpdate.exe" /c "Malwarebytes' Anti-Malware"=c:\program files\Malwarebytes' Anti-Malware\mbam.exe [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "ArcSoft Connection Service"=c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe "PWRISOVM.EXE"=d:\program files\PowerISO\PWRISOVM.EXE "BigDogPath"=c:\windows\VM_STI.EXE A4 Tech USB PC Camera "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW "NokiaMServer"=c:\program files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup "Google Updater"="c:\program files\Google\Google Updater\GoogleUpdater.exe" -check_deprecation "Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-08-09 135664] R3 DrvAgent32;DrvAgent32;c:\windows\system32\Drivers\DrvAgent32.sys [2010-05-10 23456] R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [x] R3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNt.sys [2009-10-13 133632] R3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2009-07-13 79360] R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2010-02-26 137344] R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320] R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2009-10-28 3407292] R3 npkycryp;npkycryp;e:\ragnarokonline\npkycryp.sys [x] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0308000.029\SYMEFA.SYS [2010-07-16 310320] S1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\Drivers\N360\0308000.029\BHDrvx86.sys [2010-07-16 259632] S1 ccHP;Symantec Hash Provider;c:\windows\System32\Drivers\N360\0308000.029\ccHPx86.sys [2010-07-16 482432] S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100906.001\IDSvix86.sys [2010-07-05 344112] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-28 67656] S2 N360;Norton 360;c:\program files\Norton 360 Premier Edition\Engine\3.8.0.41\ccSvcHst.exe [2010-07-16 117640] S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-08-27 1051968] S2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe [2010-02-13 300656] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-07-15 102448] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-06-23 275048] S3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS [2010-07-16 48688] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2010-02-24 10064] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] getPlusHelper REG_MULTI_SZ getPlusHelper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Contents of the 'Scheduled Tasks' folder 2010-09-05 c:\windows\Tasks\DriverCure.job - c:\program files\ParetoLogic\DriverCure\DriverCure.exe [2009-08-07 18:02] 2010-09-07 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-11-08 12:27] 2010-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-08-09 05:05] 2010-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-08-09 05:05] 2010-09-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4237152153-1231085273-1120153137-1000Core.job - c:\users\Darryle\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-29 09:33] 2010-09-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4237152153-1231085273-1120153137-1000UA.job - c:\users\Darryle\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-29 09:33] 2010-09-06 c:\windows\Tasks\Norton Security Scan for Darryle.job - c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-06-05 23:29] 2010-09-06 c:\windows\Tasks\ParetoLogic Registration.job - c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2009-01-13 14:59] 2010-09-06 c:\windows\Tasks\ParetoLogic Registration3.job - c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2010-04-06 21:30] 2010-06-14 c:\windows\Tasks\ParetoLogic Update Version2.job - c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2009-01-13 14:59] 2010-09-06 c:\windows\Tasks\RegCure Program Check.job - c:\program files\RegCure\RegCure.exe [2010-05-19 04:45] . . ——- Supplementary Scan ——- . mStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/ uInternet Settings,ProxyOverride = local;*.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html TCP: {29A2847F-9CE7-4448-AE56-D19EE5F6C256} = 192.168.1.1,212.159.11.150 Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll FF - ProfilePath - c:\users\Darryle\AppData\Roaming\Mozilla\Firefox\Profiles\fu8b78q5.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: keyword.URL - hxxp://www.ask.com/web?o=13796&l=dis&q= FF - prefs.js: network.proxy.http - localhost FF - prefs.js: network.proxy.http_port - 9666 FF - prefs.js: network.proxy.socks - localhost FF - prefs.js: network.proxy.socks_port - 9050 FF - prefs.js: network.proxy.ssl - localhost FF - prefs.js: network.proxy.ssl_port - 9666 FF - prefs.js: network.proxy.type - 0 FF - component: c:\program files\DAP\DAPFireFox\components\DAPFireFox.dll FF - component: c:\program files\SpeedBit Video Downloader\SPFireFox\components\Engine.dll FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll FF - plugin: c:\program files\Google\Google Updater\2.4.1908.5032\npCIDetect14.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll FF - plugin: c:\program files\TVUPlayer\npTVUAx.dll FF - plugin: c:\program files\Veetle\Player\npvlc.dll FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll FF - plugin: c:\program files\Veetle\VLCBroadcast\npvbp.dll FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: c:\users\Darryle\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\users\Darryle\AppData\Roaming\Mozilla\Firefox\Profiles\fu8b78q5.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll FF - plugin: c:\users\Darryle\AppData\Roaming\Mozilla\Firefox\Profiles\fu8b78q5.default\extensions\[removed]\plugins\npTVUAx.dll FF - plugin: c:\windows\system32\TVUAx\npTVUAx.dll —- FIREFOX POLICIES —- FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 FF - user.js: network.http.max-connections-per-server - 8 FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); . . ——- File Associations ——- . .txt= . - - - - ORPHANS REMOVED - - - - SafeBoot-klmdb.sys [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\N360] "ImagePath"="\"c:\program files\Norton 360 Premier Edition\Engine\3.8.0.41\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360 Premier Edition\Engine\3.8.0.41\diMaster.dll\" /prefetch:1" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'Explorer.exe'(1872) c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng-us.nlr c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr c:\windows\System32\netprofm.dll . ———————— Other Running Processes ———————— . c:\windows\system32\nvvsvc.exe c:\windows\system32\AUDIODG.EXE c:\windows\system32\nvvsvc.exe c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe c:\windows\system32\taskhost.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\windows\system32\crypserv.exe c:\program files\Canon\IJPLM\IJPLMSVC.EXE c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe c:\progra~1\SPEEDB~1\VideoAcceleratorEngine.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\windows\system32\conhost.exe c:\windows\system32\conhost.exe c:\windows\system32\DllHost.exe c:\windows\system32\timeout.exe c:\program files\NORTON 360 PREMIER EDITION\ENGINE\3.8.0.41\cltLMH.exe c:\windows\system32\conhost.exe . ************************************************************************** . Completion time: 2010-09-08 04:48:34 - machine was rebooted ComboFix-quarantined-files.txt 2010-09-07 20:48 Pre-Run: 15,084,896,256 bytes free Post-Run: 14,687,596,544 bytes free - - End Of File - - 2B0475578F6DACF7D6A29A8BB1A6D3D2
Running MGA Diagnostic
Please run the MGA Diagnostic Tool and post back the report it creates:
  • Download MGADiag to your desktop.
  • Double-click on MGADiag.exe to launch the program
  • Click "Continue"
  • Ensure that the "Windows" tab is selected (it should be by default).
  • Click the "Copy" button to copy the MGA Diagnostic Report to the Windows clipboard.
  • Paste the MGA Diagnostic Report back here in your next reply.


NEXT:


CKScanner
Download CKScanner.
Important - Save it to your desktop.
Doubleclick CKScanner.exe and click Search For Files.
After a very short time, when the cursor hourglass disappears, click Save List To File.
A message box will verify the file saved.
Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.



NEXT:



WVCheck
Please download WVCheck from Artellos.com.
  • Double click WVCheck.exe. (If you downloaded the zipped version you will need to extract it.)
  • As indicated by the prompt, This program can take a while depending on your hard drive space.
  • Once the program is done, copy the contents of the notepad file as a reply.
Here is the log: Diagnostic Report (1.9.0027.0): —————————————– Windows Validation Data–> Validation Code: 0 Cached Online Validation Code: N/A, hr = 0xc0000022 Windows Product Key: *****-*****-BJD6C-K3YVH-DVQJG Windows Product Key Hash: WFqPPaNJ0hrc3E/8MgITJa2Xf0M= Windows Product ID: 00359-OEM-8992687-00118 Windows Product ID Type: 2 Windows License Type: OEM SLP Windows OS version: 6.1.7600.2.00010300.0.0.003 ID: {86FEE77C-3826-41AB-B614-C0F5CB5526A9}(1) Is Admin: Yes TestCab: 0x0 LegitcheckControl ActiveX: N/A, hr = 0x80070002 Signed By: N/A, hr = 0x80070002 Product Name: Windows 7 Home Premium Architecture: 0x00000000 Build lab: 7600.win7_gdr.100618-1621 TTS Error: Validation Diagnostic: Resolution Status: N/A Vista WgaER Data–> ThreatID(s): N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 Windows XP Notifications Data–> Cached Result: N/A, hr = 0x80070002 File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 OGAExec.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data–> Office Status: 103 Blocked VLK Microsoft Office Enterprise 2007 - 103 Blocked VLK OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3 Browser Data–> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32) Default Browser: C:\Program Files\Internet Explorer\IEXPLORE.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data–> File Mismatch: C:\Windows\system32\wat\watadminsvc.exe
File Mismatch: C:\Windows\system32\wat\npwatweb.dll
File Mismatch: C:\Windows\system32\wat\watux.exe
File Mismatch: C:\Windows\system32\wat\watweb.dll
File Mismatch: C:\Windows\system32\sppuinotify.dll[6.1.7600.16385], Hr = 0x800b0100 File Mismatch: C:\Windows\system32\sppcommdlg.dll[6.1.7600.16385], Hr = 0x800b0100 File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7600.16385], Hr = 0x800b0100 File Mismatch: C:\Windows\system32\user32.dll[6.1.7600.16385], Hr = 0x800b0100 Other data–> Office Details: {86FEE77C-3826-41AB-B614-C0F5CB5526A9}1.9.0027.06.1.7600.2.00010300.0.0.003x32*****-*****-*****-*****-DVQJG00359-OEM-8992687-001182S-1-5-21-4237152153-1231085273-1120153137System manufacturerSystem Product NameAmerican Megatrends Inc.0506 20090527000000.000000+00089BA3607018400F804090409Taipei Standard Time(GMT+08:00)03ACRSYSACRPRDCT103 Spsys.log Content: 0x80070002 Licensing Data–> On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x80070426' to display the error text. Error: 0x80070426 Windows Activation Technologies–> HrOffline: 0x00000000 HrOnline: 0x80072EE2 HealthStatus: 0x0000000000000000 Event Time Stamp: 2:24:2010 17:50 ActiveX: Not Registered - 0x80040154 Admin Service: Not Registered - 0x80040154 HealthStatus Bitmask Output: HWID Data–> HWID Hash Current: MAAAAAEABAABAAEAAAABAAAAAQABAAEAJJSwUAhQqnZI5B4dWv8W3pZe4lwcJUbK OEM Activation 1.0 Data–> N/A OEM Activation 2.0 Data–> BIOS valid for OA 2.0: yes Windows marker version: 0x20001 OEMID and OEMTableID Consistent: yes BIOS Information: ACPI Table Name OEMID Value OEMTableID Value APIC A_M_I_ OEMAPIC FACP A_M_I_ OEMFACP HPET A_M_I_ OEMHPET MCFG A_M_I_ OEMMCFG OEMB A_M_I_ AMI_OEM GSCI A_M_I_ GMCHSCI SLIC ACRSYS ACRPRDCT
CKScanner - Additional Security Risks - These are not necessarily bad c:\$windows.~q\data\users\darryle\desktop\win7\microsoft windows 7 home premium x86 retail english dvd\windows 7 crack\keys.ini c:\users\darryle\desktop\desktop files\folders\win7\microsoft windows 7 home premium x86 retail english dvd\windows 7 crack\keys.ini c:\users\darryle\desktop\desktop files\folders\win7\microsoft windows 7 home premium x86 retail english dvd\windows 7 crack\windows 7 loader.exe c:\users\darryle\desktop\desktop files\folders\win7\microsoft windows 7 home premium x86 retail english dvd\windows 7 crack\certificates\note.txt c:\users\darryle\desktop\desktop files\folders\win7\microsoft windows 7 home premium x86 retail english dvd\windows 7 crack\notes\arguments.txt c:\users\darryle\desktop\desktop files\folders\win7\microsoft windows 7 home premium x86 retail english dvd\windows 7 crack\notes\beta loader changelog.txt c:\users\darryle\desktop\desktop files\folders\win7\microsoft windows 7 home premium x86 retail english dvd\windows 7 crack\notes\checksums.txt c:\users\darryle\desktop\desktop files\folders\win7\microsoft windows 7 home premium x86 retail english dvd\windows 7 crack\notes\how to recover windows.txt c:\users\darryle\desktop\desktop files\folders\win7\microsoft windows 7 home premium x86 retail english dvd\windows 7 crack\notes\how to restore tokens.txt c:\users\darryle\desktop\desktop files\folders\win7\microsoft windows 7 home premium x86 retail english dvd\windows 7 crack\notes\version history.txt c:\users\darryle\desktop\desktop files\tools\tuneup crack\tu2010trialen-us.exe c:\users\darryle\desktop\malware tools\chew7\reg\crack\regcure.exe c:\users\darryle\downloads\torrents\100 cookbooks\300 secret recipes - mcdonalds - starbucks etc\cracker jacks.txt c:\users\darryle\downloads\torrents\100 cookbooks\300 secret recipes - mcdonalds - starbucks etc\ranch flavored oyster crackers mix.txt c:\users\darryle\downloads\torrents\advanced uninstaller pro v10+crack [ kk ]\advanced uninstaller pro v10+crack [ kk ].7z c:\users\darryle\downloads\torrents\cd roller 7.70.91.0 + crack {dotcom1}\cdroller770_en.exe c:\users\darryle\downloads\torrents\cd roller 7.70.91.0 + crack {dotcom1}\dotcom1\dotcom1.nfo c:\users\darryle\downloads\torrents\cd roller 7.70.91.0 + crack {dotcom1}\dotcom1\dotcom1.txt c:\users\darryle\downloads\torrents\cd roller 7.70.91.0 + crack {dotcom1}\dotcom1\dotcom1 crack\cdroller.exe c:\users\darryle\downloads\torrents\cd roller 7.70.91.0 + crack {dotcom1}\dotcom1\dotcom1 crack\cracked by dotcom1.txt c:\users\darryle\downloads\torrents\download accelerator plus premium v9.21+crack [ kk ]\download accelerator plus premium v9.21+crack [ kk ].rar c:\users\darryle\downloads\torrents\download accelerator plus premium v9.21+crack [ kk ]\download accelerator premium v9.1 setup.exe c:\users\darryle\downloads\torrents\download accelerator plus premium v9.21+crack [ kk ]\instructions & crack.txt c:\users\darryle\downloads\torrents\download accelerator plus premium v9.21+crack [ kk ]\torrent downloaded from demonoid.com.txt c:\users\darryle\downloads\torrents\download accelerator plus premium v9.21+crack [ kk ]\tracked_by_h33t_com.txt c:\users\darryle\downloads\torrents\download accelerator plus premium v9.21+crack [ kk ]\crack\dap.exe c:\users\darryle\downloads\torrents\system tools & installers - do not delete\drivercure\2\paretologic.inc.drivercure.v1.5-lz0\crack\drivercure.exe c:\users\darryle\downloads\torrents\system tools & installers - do not delete\norton\nav.2010-v.17.0.0.136\crack.txt c:\users\darryle\downloads\torrents\system tools & installers - do not delete\norton trialreset 2010 v2.0 (cracked by box!) [rh]\ntr2010.v2.0_[rh].rar c:\users\darryle\downloads\torrents\system tools & installers - do not delete\tuneup\ttu9437a pb\crack\appinitialization.bpl c:\users\darryle\downloads\torrents\system tools & installers - do not delete\tuneup\ttu9437a pb\crack\commonforms.bpl c:\users\darryle\downloads\torrents\system tools & installers - do not delete\tuneup\ttu9437a pb\crack\registration.reg c:\users\darryle\downloads\torrents\system tools & installers - do not delete\tuneup\ttu9437a pb\crack\tulic.dll c:\users\darryle\favorites\keygens.nl - generates cracks serials keygens for the software to unlock it for free.url c:\users\darryle\favorites\microsoft windows 7 home premium x86 retail english dvd[cracked] torrent download - alivetorrents.url scanner sequence 3.ZZ.11 —– EOF —–
Hello,

The use of Keygens and Cracks inevitably leads to infection. Further, it is contrary to this sites Terms of Use. If you persist in their use you will no-longer receive help from this site in the future.

c:\windows\system32\hale.exe is not a legitimate system file. It's only purpose is to bypass Windows Validation, or allow a pirated version of Windows to appear legitimate. While this may have been installed without your knowledge, even by an unscrupulous dealer, it indicates an illegal version of Windows. Due to legal and ethical reasons we are unable to help people With pirated software.

Microsoft has a program for people who unknowingly receive counterfeit software:

Q:
What are the details of the genuine Windows offer?
A:

To help customers who unknowingly purchased a counterfeit version of Windows XP, Microsoft has created two genuine Windows offers for those who qualify:

* Complimentary offer: Microsoft will make a complimentary copy of Windows XP available to customers who have been sold counterfeit Windows. Customers will be required to submit a proof of purchase, the counterfeit CD, and a counterfeit report with details of their purchase. Only high-quality counterfeit Windows will qualify for the complimentary offer.
* Electronic License Key Offer: Microsoft will offer an alternative for customers who find out via the WGA validation process that they are not running genuine Windows, but do not qualify for, or choose not to take advantage of, the complimentary offer. These customers will be able to license a Windows Genuine Advantage Kit for Windows XP directly from Microsoft for a special on-line purchase price. The Windows Genuine Advantage Kit for Windows XP will include a new 25-character Product Key and a Windows Product Key Update tool that will allow customers to convert their counterfeit copy to genuine Windows XP electronically.


As per the sites Terms of Use this thread will now be closed.

If you feel this thread was closed in error please contact a member of the Administrator team.

Thread Closed.

Cheers,
SweetTech

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI