This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Internet issues

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I can open my browsers (Google Chrome usually, but have tried IE) and home page will load, which is Google. But after that, I can barely get anything to load. Sometimes I can get one page, (Comcast) but after trying to sign in, the page will not load. In Chrome or IE it will try for a few minutes, and then load the "can't display" page. If I shut the window and try again, same results. I recently updated AVG to 11, not sure if that was an issue or not, but uninstalled it to see if it would make a difference, (none that I could tell) I don't think it's my internet connection because I have 2 other computers in the house that will connect. This is my main computer and, of course, the one to go down. Any help appreciated and log is pasted below.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:12:55 PM, on 10/22/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17091)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Lexmark 8300 Series\lxcjmon.exe
C:\Program Files\Lexmark 8300 Series\ezprint.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\Documents and Settings\Christy Talley\Local Settings\Application Data\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\WINDOWS\system32\lxcjcoms.exe
C:\Documents and Settings\Christy Talley\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Christy Talley\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [zSPGuard] c:\program files\pjw\spguard\spguard.exe /s
O4 - HKLM\..\Run: [lxcjmon.exe] "C:\Program Files\Lexmark 8300 Series\lxcjmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 8300 Series\ezprint.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Christy Talley\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://zone.msn.com/bingame/dsh2/default/D…h2.1.0.0.68.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} (Lexmark eDiagnostics Class) - https://ediagnostics.lexmark.com/serval.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock…ash/swflash.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553635000} - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcj_device - - C:\WINDOWS\system32\lxcjcoms.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

–
End of file - 8773 bytes
Hi shelljj,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Let's get a deeper look at what's going on.

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
  • Click the Scan button and let the program do its work. GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.

In your next reply please provide:
  • Gmer log
  • DDS.txt
  • attach.txt
Thank you and I'm sorry it took so long. Hope I've got everything you asked for. :)

GMER 1.0.15.15477 - http://www.gmer.net
Rootkit scan 2010-10-28 04:35:30
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\fxtdqpow.sys


—- System - GMER 1.0.15 —-

SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xF74E787E]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xF74E7BFE]

—- Kernel code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF5BF8380, 0x566445, 0xE8000020]

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Classes\CLSID\{07340190-BCE0-11D1-BD7E-00207812DE95}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{07340190-BCE0-11D1-BD7E-00207812DE95}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{07340190-BCE0-11D1-BD7E-00207812DE95}\MiscStatus\1@ 132497
Reg HKLM\SOFTWARE\Classes\CLSID\{07340190-BCE0-11D1-BD7E-00207812DE95}\ProgID@ AppCtl.AppCtl.1
Reg HKLM\SOFTWARE\Classes\CLSID\{07340190-BCE0-11D1-BD7E-00207812DE95}\TypeLib@ {A92757C4-BE3F-11D1-BD7E-00207812DE95}
Reg HKLM\SOFTWARE\Classes\CLSID\{07340190-BCE0-11D1-BD7E-00207812DE95}\Version@ 1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{07340190-BCE0-11D1-BD7E-00207812DE95}\VersionIndependentProgID@ AppCtl.AppCtl
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3A0-18D6-101C-8158-221E4B551F8E}\Control@
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3A0-18D6-101C-8158-221E4B551F8E}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3A0-18D6-101C-8158-221E4B551F8E}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3A0-18D6-101C-8158-221E4B551F8E}\MiscStatus\1@ 197009
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3A0-18D6-101C-8158-221E4B551F8E}\ProgID@ VSOCX.VselasticCtrl.1
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3A0-18D6-101C-8158-221E4B551F8E}\TypeLib@ {2037E3AD-18D6-101C-8158-221E4B551F8E}
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3A0-18D6-101C-8158-221E4B551F8E}\Version@ 5.0
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3A5-18D6-101C-8158-221E4B551F8E}\Control@
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3A5-18D6-101C-8158-221E4B551F8E}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3A5-18D6-101C-8158-221E4B551F8E}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3A5-18D6-101C-8158-221E4B551F8E}\MiscStatus\1@ 229777
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3A5-18D6-101C-8158-221E4B551F8E}\ProgID@ VSOCX.VsindextabCtrl.1
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3A5-18D6-101C-8158-221E4B551F8E}\TypeLib@ {2037E3AD-18D6-101C-8158-221E4B551F8E}
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3A5-18D6-101C-8158-221E4B551F8E}\Version@ 5.0
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3AA-18D6-101C-8158-221E4B551F8E}\Control@
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3AA-18D6-101C-8158-221E4B551F8E}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3AA-18D6-101C-8158-221E4B551F8E}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3AA-18D6-101C-8158-221E4B551F8E}\MiscStatus\1@ 132497
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3AA-18D6-101C-8158-221E4B551F8E}\ProgID@ VSOCX.VsawkCtrl.1
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3AA-18D6-101C-8158-221E4B551F8E}\TypeLib@ {2037E3AD-18D6-101C-8158-221E4B551F8E}
Reg HKLM\SOFTWARE\Classes\CLSID\{2037E3AA-18D6-101C-8158-221E4B551F8E}\Version@ 5.0
Reg HKLM\SOFTWARE\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\Control@
Reg HKLM\SOFTWARE\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
Reg HKLM\SOFTWARE\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\MiscStatus\1@ 131473
Reg HKLM\SOFTWARE\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\ProgID@ AcerCtrls.APlunch
Reg HKLM\SOFTWARE\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\TypeLib@ {3895DD37-7573-11D2-8FED-00606730D3AA}
Reg HKLM\SOFTWARE\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\Version@ 1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\Control@
Reg HKLM\SOFTWARE\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
Reg HKLM\SOFTWARE\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\MiscStatus\1@ 131473
Reg HKLM\SOFTWARE\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\ProgID@ ctlDiags.Fs
Reg HKLM\SOFTWARE\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\TypeLib@ {1D676278-D6DF-11D1-90DC-0000C03DCA0D}
Reg HKLM\SOFTWARE\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\Version@ 33.0
Reg HKLM\SOFTWARE\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\Control@
Reg HKLM\SOFTWARE\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
Reg HKLM\SOFTWARE\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\MiscStatus\1@ 131473
Reg HKLM\SOFTWARE\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\ProgID@ ctlSCBtns.scAXbtns
Reg HKLM\SOFTWARE\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\TypeLib@ {932BF86E-2BAB-11D2-8EA2-0080C82D82A9}
Reg HKLM\SOFTWARE\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\Version@ 1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Control@
Reg HKLM\SOFTWARE\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
Reg HKLM\SOFTWARE\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
Reg HKLM\SOFTWARE\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}@
Reg HKLM\SOFTWARE\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
Reg HKLM\SOFTWARE\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}@
Reg HKLM\SOFTWARE\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\MiscStatus\1@ 131473
Reg HKLM\SOFTWARE\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\ProgID@ LunchApp.APlunch
Reg HKLM\SOFTWARE\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\TypeLib@ {D9998BD2-7957-11D2-8FED-00606730D3AA}
Reg HKLM\SOFTWARE\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Version@ 1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\Control@
Reg HKLM\SOFTWARE\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
Reg HKLM\SOFTWARE\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\MiscStatus\1@ 131473
Reg HKLM\SOFTWARE\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\ProgID@ ctlSupport.Fs
Reg HKLM\SOFTWARE\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\TypeLib@ {1D676278-D6DF-11D1-90DC-0000C03DCA0D}
Reg HKLM\SOFTWARE\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\Version@ 34.0
Reg HKLM\SOFTWARE\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\Control@
Reg HKLM\SOFTWARE\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
Reg HKLM\SOFTWARE\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\MiscStatus\1@ 131473
Reg HKLM\SOFTWARE\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\ProgID@ scIntro.UserControl1
Reg HKLM\SOFTWARE\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\TypeLib@ {F6940BE0-E4EB-11D1-8EA2-0080C82D82A9}
Reg HKLM\SOFTWARE\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\Version@ 1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\Control@
Reg HKLM\SOFTWARE\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}
Reg HKLM\SOFTWARE\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
Reg HKLM\SOFTWARE\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\MiscStatus\1@ 131473
Reg HKLM\SOFTWARE\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\ProgID@ Project1.Fs
Reg HKLM\SOFTWARE\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\TypeLib@ {1D676278-D6DF-11D1-90DC-0000C03DCA0D}
Reg HKLM\SOFTWARE\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\Version@ 33.0
Reg HKLM\SOFTWARE\Classes\GoogleGadget\DefaultIcon@ "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe",0
Reg HKLM\SOFTWARE\Classes\GoogleGadget\shell\open
Reg HKLM\SOFTWARE\Classes\GoogleGadget\shell\open@ &Open; with Google Desktop
Reg HKLM\SOFTWARE\Classes\GoogleGadget\shell\open\command
Reg HKLM\SOFTWARE\Classes\GoogleGadget\shell\open\command@ "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /display /load "%1"
Reg HKLM\SOFTWARE\Classes\GoogleGadgetContainer\DefaultIcon@ "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe",0
Reg HKLM\SOFTWARE\Classes\GoogleGadgetContainer\shell\open
Reg HKLM\SOFTWARE\Classes\GoogleGadgetContainer\shell\open@ &Open; with Google Desktop
Reg HKLM\SOFTWARE\Classes\GoogleGadgetContainer\shell\open\command
Reg HKLM\SOFTWARE\Classes\GoogleGadgetContainer\shell\open\command@ "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /display /load "%1"
Reg HKLM\SOFTWARE\Classes\GoogleGadgetManifest\DefaultIcon@ "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe",0
Reg HKLM\SOFTWARE\Classes\GoogleGadgetManifest\shell\open
Reg HKLM\SOFTWARE\Classes\GoogleGadgetManifest\shell\open\command
Reg HKLM\SOFTWARE\Classes\GoogleGadgetManifest\shell\open\command@ "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /display /load "%1"
Reg HKLM\SOFTWARE\Classes\Interface\{640f2578-c31b-4ff3-9891-042fa87bc781}\TypeLib@ {550DFE55-4B64-4039-95EF-2C1DB0B66D58}
Reg HKLM\SOFTWARE\Classes\Interface\{640f2578-c31b-4ff3-9891-042fa87bc781}\TypeLib@Version 5.0.0.0
Reg HKLM\SOFTWARE\Classes\Interface\{6EE4DCBB-CE99-4994-A12A-242CEBDD691C}\TypeLib@ {415FD1E7-5BC1-4BD4-B8F0-D6647D36EEC5}
Reg HKLM\SOFTWARE\Classes\Interface\{6EE4DCBB-CE99-4994-A12A-242CEBDD691C}\TypeLib@Version 8.0.12.6325
Reg HKLM\SOFTWARE\Classes\Interface\{8F5217C6-D374-4fd6-A973-1A8D9477A8FD}\TypeLib@ {75A4387C-BA5A-4C19-9709-707F11F8193D}
Reg HKLM\SOFTWARE\Classes\Interface\{8F5217C6-D374-4fd6-A973-1A8D9477A8FD}\TypeLib@Version 8.0.12.6325
Reg HKLM\SOFTWARE\Classes\TypeLib\{1D676278-D6DF-11D1-90DC-0000C03DCA0D}\21.0@ Project1
Reg HKLM\SOFTWARE\Classes\TypeLib\{1D676278-D6DF-11D1-90DC-0000C03DCA0D}\21.0\0
Reg HKLM\SOFTWARE\Classes\TypeLib\{1D676278-D6DF-11D1-90DC-0000C03DCA0D}\21.0\FLAGS
Reg HKLM\SOFTWARE\Classes\TypeLib\{1D676278-D6DF-11D1-90DC-0000C03DCA0D}\21.0\FLAGS@ 2
Reg HKLM\SOFTWARE\Classes\TypeLib\{1D676278-D6DF-11D1-90DC-0000C03DCA0D}\21.0\HELPDIR
Reg HKLM\SOFTWARE\Classes\TypeLib\{1D676278-D6DF-11D1-90DC-0000C03DCA0D}\21.0\HELPDIR@ C:\Windows\system
Reg HKLM\SOFTWARE\Classes\TypeLib\{1D676278-D6DF-11D1-90DC-0000C03DCA0D}\22.0@ ctlSupport
Reg HKLM\SOFTWARE\Classes\TypeLib\{1D676278-D6DF-11D1-90DC-0000C03DCA0D}\22.0\0
Reg HKLM\SOFTWARE\Classes\TypeLib\{1D676278-D6DF-11D1-90DC-0000C03DCA0D}\22.0\FLAGS
Reg HKLM\SOFTWARE\Classes\TypeLib\{1D676278-D6DF-11D1-90DC-0000C03DCA0D}\22.0\FLAGS@ 2
Reg HKLM\SOFTWARE\Classes\TypeLib\{1D676278-D6DF-11D1-90DC-0000C03DCA0D}\22.0\HELPDIR
Reg HKLM\SOFTWARE\Classes\TypeLib\{1D676278-D6DF-11D1-90DC-0000C03DCA0D}\22.0\HELPDIR@ C:\Windows\system
Reg HKLM\SOFTWARE\Classes\TypeLib\{2037E3AD-18D6-101C-8158-221E4B551F8E}\5.0@ :-) VideoSoft vsOcx Controls
Reg HKLM\SOFTWARE\Classes\TypeLib\{2037E3AD-18D6-101C-8158-221E4B551F8E}\5.0\0
Reg HKLM\SOFTWARE\Classes\TypeLib\{2037E3AD-18D6-101C-8158-221E4B551F8E}\5.0\FLAGS
Reg HKLM\SOFTWARE\Classes\TypeLib\{2037E3AD-18D6-101C-8158-221E4B551F8E}\5.0\FLAGS@ 2
Reg HKLM\SOFTWARE\Classes\TypeLib\{2037E3AD-18D6-101C-8158-221E4B551F8E}\5.0\HELPDIR
Reg HKLM\SOFTWARE\Classes\TypeLib\{2037E3AD-18D6-101C-8158-221E4B551F8E}\5.0\HELPDIR@ C:\Windows\system
Reg HKLM\SOFTWARE\Classes\TypeLib\{3895DD37-7573-11D2-8FED-00606730D3AA}\1.0@ AcerCtrls
Reg HKLM\SOFTWARE\Classes\TypeLib\{3895DD37-7573-11D2-8FED-00606730D3AA}\1.0\0
Reg HKLM\SOFTWARE\Classes\TypeLib\{3895DD37-7573-11D2-8FED-00606730D3AA}\1.0\FLAGS
Reg HKLM\SOFTWARE\Classes\TypeLib\{3895DD37-7573-11D2-8FED-00606730D3AA}\1.0\FLAGS@ 2
Reg HKLM\SOFTWARE\Classes\TypeLib\{3895DD37-7573-11D2-8FED-00606730D3AA}\1.0\HELPDIR
Reg HKLM\SOFTWARE\Classes\TypeLib\{3895DD37-7573-11D2-8FED-00606730D3AA}\1.0\HELPDIR@ C:\Windows\system
Reg HKLM\SOFTWARE\Classes\TypeLib\{932BF86E-2BAB-11D2-8EA2-0080C82D82A9}\1.0@ Service Center buttons for MAG
Reg HKLM\SOFTWARE\Classes\TypeLib\{932BF86E-2BAB-11D2-8EA2-0080C82D82A9}\1.0\0
Reg HKLM\SOFTWARE\Classes\TypeLib\{932BF86E-2BAB-11D2-8EA2-0080C82D82A9}\1.0\FLAGS
Reg HKLM\SOFTWARE\Classes\TypeLib\{932BF86E-2BAB-11D2-8EA2-0080C82D82A9}\1.0\FLAGS@ 2
Reg HKLM\SOFTWARE\Classes\TypeLib\{932BF86E-2BAB-11D2-8EA2-0080C82D82A9}\1.0\HELPDIR
Reg HKLM\SOFTWARE\Classes\TypeLib\{932BF86E-2BAB-11D2-8EA2-0080C82D82A9}\1.0\HELPDIR@ C:\Windows\system
Reg HKLM\SOFTWARE\Classes\TypeLib\{A269B061-7EBE-4630-8BF6-6C42D5BE41AE}\1.0@ GoogleDesktopDisplayInternalLib
Reg HKLM\SOFTWARE\Classes\TypeLib\{A269B061-7EBE-4630-8BF6-6C42D5BE41AE}\1.0\0
Reg HKLM\SOFTWARE\Classes\TypeLib\{A269B061-7EBE-4630-8BF6-6C42D5BE41AE}\1.0\FLAGS
Reg HKLM\SOFTWARE\Classes\TypeLib\{A269B061-7EBE-4630-8BF6-6C42D5BE41AE}\1.0\FLAGS@ 0
Reg HKLM\SOFTWARE\Classes\TypeLib\{A92757C4-BE3F-11D1-BD7E-00207812DE95}\1.0@ ACEAppCtl 1.0 Type Library
Reg HKLM\SOFTWARE\Classes\TypeLib\{A92757C4-BE3F-11D1-BD7E-00207812DE95}\1.0\0
Reg HKLM\SOFTWARE\Classes\TypeLib\{A92757C4-BE3F-11D1-BD7E-00207812DE95}\1.0\FLAGS
Reg HKLM\SOFTWARE\Classes\TypeLib\{A92757C4-BE3F-11D1-BD7E-00207812DE95}\1.0\FLAGS@ 0
Reg HKLM\SOFTWARE\Classes\TypeLib\{A92757C4-BE3F-11D1-BD7E-00207812DE95}\1.0\HELPDIR
Reg HKLM\SOFTWARE\Classes\TypeLib\{A92757C4-BE3F-11D1-BD7E-00207812DE95}\1.0\HELPDIR@ C:\Windows\system\
Reg HKLM\SOFTWARE\Classes\TypeLib\{ACD1A266-C77B-4691-B96A-AF712B83A364}\3.0@ GoogleDesktop.Panels 3.0 Type Library
Reg HKLM\SOFTWARE\Classes\TypeLib\{ACD1A266-C77B-4691-B96A-AF712B83A364}\3.0\0
Reg HKLM\SOFTWARE\Classes\TypeLib\{ACD1A266-C77B-4691-B96A-AF712B83A364}\3.0\FLAGS
Reg HKLM\SOFTWARE\Classes\TypeLib\{ACD1A266-C77B-4691-B96A-AF712B83A364}\3.0\FLAGS@ 0
Reg HKLM\SOFTWARE\Classes\TypeLib\{D9998BD2-7957-11D2-8FED-00606730D3AA}\1.0@ LunchApp
Reg HKLM\SOFTWARE\Classes\TypeLib\{D9998BD2-7957-11D2-8FED-00606730D3AA}\1.0\0
Reg HKLM\SOFTWARE\Classes\TypeLib\{D9998BD2-7957-11D2-8FED-00606730D3AA}\1.0\FLAGS
Reg HKLM\SOFTWARE\Classes\TypeLib\{D9998BD2-7957-11D2-8FED-00606730D3AA}\1.0\FLAGS@ 2
Reg HKLM\SOFTWARE\Classes\TypeLib\{D9998BD2-7957-11D2-8FED-00606730D3AA}\1.0\HELPDIR
Reg HKLM\SOFTWARE\Classes\TypeLib\{D9998BD2-7957-11D2-8FED-00606730D3AA}\1.0\HELPDIR@ C:\Windows\system
Reg HKLM\SOFTWARE\Classes\TypeLib\{F6940BE0-E4EB-11D1-8EA2-0080C82D82A9}\1.0@ scIntro
Reg HKLM\SOFTWARE\Classes\TypeLib\{F6940BE0-E4EB-11D1-8EA2-0080C82D82A9}\1.0\0
Reg HKLM\SOFTWARE\Classes\TypeLib\{F6940BE0-E4EB-11D1-8EA2-0080C82D82A9}\1.0\FLAGS
Reg HKLM\SOFTWARE\Classes\TypeLib\{F6940BE0-E4EB-11D1-8EA2-0080C82D82A9}\1.0\FLAGS@ 2
Reg HKLM\SOFTWARE\Classes\TypeLib\{F6940BE0-E4EB-11D1-8EA2-0080C82D82A9}\1.0\HELPDIR
Reg HKLM\SOFTWARE\Classes\TypeLib\{F6940BE0-E4EB-11D1-8EA2-0080C82D82A9}\1.0\HELPDIR@ C:\Windows\system
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotm\[removed].12
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotx\[removed].12
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potx\[removed].12
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potx\[removed].12
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppam\[removed].12
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsm\[removed].12
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsm\[removed].12
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsx\[removed].12
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsx\[removed].12
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlam\[removed]
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlam\[removed]

—- EOF - GMER 1.0.15 —-




DDS (Ver_10-10-21.02) - NTFSx86
Run by [removed] at 16:41:26.89 on Fri 10/29/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.894.177 [GMT -5:00]


============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Program Files\Lexmark 8300 Series\lxcjmon.exe
C:\Program Files\Lexmark 8300 Series\ezprint.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\Documents and Settings\Christy Talley\Local Settings\Application Data\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\WINDOWS\system32\lxcjcoms.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Christy Talley\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Christy Talley\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Christy Talley\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [Sonic RecordNow!]
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\christy talley\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [LaunchApp]
mRun: [BkupTray] "c:\program files\newtech infosystems\nti backup now 5\BkupTray.exe"
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [eRecoveryService] c:\acer\empowering technology\erecovery\eRAgent.exe
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [zSPGuard] c:\program files\pjw\spguard\spguard.exe /s
mRun: [lxcjmon.exe] "c:\program files\lexmark 8300 series\lxcjmon.exe"
mRun: [EzPrint] "c:\program files\lexmark 8300 series\ezprint.exe"
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111v2\WG111v2.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - i:\office11\REFIEBAR.DLL
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://pcpitstop.com/pcpitstop/PCPitStop.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} - hxxp://zone.msn.com/bingame/dsh2/default/DinerDash2.1.0.0.68.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} - hxxps://ediagnostics.lexmark.com/serval.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553635000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com

============= SERVICES / DRIVERS ===============

R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-2-14 64288]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-8-12 1357464]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-7 50424]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-4 131072]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2010-8-12 15008]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [2009-7-17 272128]
S0 nielprt;Nielsen Patch Service;c:\windows\system32\drivers\nielprt.sys –> c:\windows\system32\drivers\nielprt.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-10-3 136176]
S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys –> c:\windows\system32\drivers\nielgfx.sys [?]

=============== Created Last 30 ================

2010-10-24 14:09:50 ——– d—–w- c:\docume~1\christ~1\applic~1\Easy Image Modifier
2010-10-23 21:03:53 ——– d—–w- c:\program files\Defraggler
2010-10-23 01:11:47 388096 —-a-r- c:\docume~1\christ~1\applic~1\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2010-10-17 21:29:22 ——– d—–w- c:\docume~1\christ~1\applic~1\AVG10
2010-10-17 21:26:30 ——– d–h–w- c:\docume~1\alluse~1\applic~1\Common Files
2010-10-17 21:24:19 ——– d—–w- c:\docume~1\alluse~1\applic~1\AVG10
2010-10-16 14:12:59 ——– d—–w- c:\docume~1\alluse~1\applic~1\MFAData
2010-10-02 18:16:05 ——– d—–w- c:\windows\system32\wbem\repository\FS
2010-10-02 18:16:05 ——– d—–w- c:\windows\system32\wbem\Repository
2010-10-02 13:15:37 ——– d—–w- c:\program files\OE-Mail Recovery
2010-10-02 00:29:00 ——– d—–w- c:\documents and settings\christy talley\Collections

==================== Find3M ====================

2010-09-18 17:23:26 974848 —-a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53:25 974848 —-a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53:25 954368 —-a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53:25 953856 —-a-w- c:\windows\system32\mfc40u.dll
2010-09-09 13:38:01 832512 —-a-w- c:\windows\system32\wininet.dll
2010-09-09 13:38:01 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2010-09-09 13:38:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-09-09 13:38:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-09-08 16:17:46 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 16:17:46 69632 —-a-w- c:\windows\system32\QuickTime.qts
2010-09-08 15:57:57 389120 —-a-w- c:\windows\system32\html.iec
2010-09-01 11:51:14 285824 —-a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42:52 1852800 —-a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02:29 119808 —-a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57:43 99840 —-a-w- c:\windows\system32\srvsvc.dll
2010-08-26 12:52:45 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12:04 617472 —-a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17:06 58880 —-a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45:00 590848 —-a-w- c:\windows\system32\rpcrt4.dll

============= FINISH: 16:42:08.06 ===============
[attachment removed]

Attachments:

shelljj,

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Thanks for your help. Here is the log:


ComboFix 10-10-30.05 - Christy Talley 10/31/2010 9:54.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.894.449 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Christy Talley\Application Data\inst.exe
c:\windows\system32\start.exe
I:\Autorun.inf
I:\install.exe

.
((((((((((((((((((((((((( Files Created from 2010-09-28 to 2010-10-31 )))))))))))))))))))))))))))))))
.

2010-10-24 14:09 . 2010-10-24 14:10 ——– d—–w- c:\documents and settings\Christy Talley\Application Data\Easy Image Modifier
2010-10-23 21:03 . 2010-10-23 21:03 ——– d—–w- c:\program files\Defraggler
2010-10-23 01:11 . 2010-10-23 01:11 388096 —-a-r- c:\documents and settings\Christy Talley\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-10-17 21:29 . 2010-10-17 21:29 ——– d—–w- c:\documents and settings\Christy Talley\Application Data\AVG10
2010-10-17 21:26 . 2010-10-17 21:26 ——– d–h–w- c:\documents and settings\All Users\Application Data\Common Files
2010-10-17 21:24 . 2010-10-22 23:43 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG10
2010-10-16 14:12 . 2010-10-16 14:33 ——– d—–w- c:\documents and settings\All Users\Application Data\MFAData
2010-10-03 16:36 . 2010-10-03 16:36 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-10-02 18:16 . 2010-10-02 18:16 ——– d—–w- c:\windows\system32\wbem\Repository
2010-10-02 13:15 . 2010-10-02 13:15 ——– d—–w- c:\program files\OE-Mail Recovery
2010-10-02 00:29 . 2010-10-02 00:29 ——– d—–w- c:\documents and settings\Christy Talley\Collections

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-23 20:53 . 2009-03-01 15:09 392010 —-a-w- c:\windows\system32\drivers\etc\hosts.tmp
2010-10-01 21:49 . 2010-05-02 22:23 187 —-a-w- c:\windows\Fonts\READ ME .txt
2010-10-01 21:45 . 2001-06-18 01:44 1064 —-a-w- c:\windows\Fonts\KR ReadMe.txt
2010-10-01 20:30 . 2008-12-04 02:00 688 —-a-w- c:\windows\Fonts\neverletgo-TOU.txt
2010-10-01 20:29 . 2009-12-16 15:59 675 —-a-w- c:\windows\Fonts\writtenonhishands-TOU.txt
2010-09-18 17:23 . 2008-04-14 22:00 974848 —-a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-04-14 22:00 974848 —-a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-04-14 22:00 954368 —-a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2008-04-14 22:00 953856 —-a-w- c:\windows\system32\mfc40u.dll
2010-09-13 21:27 . 2010-09-13 21:27 25680 —-a-w- c:\windows\system32\drivers\AVGIDSEH.sys
2010-09-09 13:38 . 2007-08-14 02:54 832512 —-a-w- c:\windows\system32\wininet.dll
2010-09-09 13:38 . 2007-08-14 02:45 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2010-09-09 13:38 . 2009-06-04 10:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-09-09 13:38 . 2008-04-14 22:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-09-08 16:17 . 2010-09-08 16:17 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 16:17 . 2010-09-08 16:17 69632 —-a-w- c:\windows\system32\QuickTime.qts
2010-09-08 15:57 . 2008-04-14 22:00 389120 —-a-w- c:\windows\system32\html.iec
2010-09-01 11:51 . 2008-04-14 22:00 285824 —-a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42 . 2008-04-14 22:00 1852800 —-a-w- c:\windows\system32\win32k.sys
2010-08-31 10:11 . 2010-08-31 10:11 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-08-27 08:02 . 2008-04-14 22:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57 . 2008-04-14 22:00 99840 —-a-w- c:\windows\system32\srvsvc.dll
2010-08-26 13:39 . 2008-04-14 22:00 357248 —-a-w- c:\windows\system32\drivers\srv.sys
2010-08-26 12:52 . 2009-04-16 00:01 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12 . 2008-04-14 22:00 617472 —-a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2008-04-14 22:00 58880 —-a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45 . 2008-04-14 22:00 590848 —-a-w- c:\windows\system32\rpcrt4.dll
2010-08-12 12:15 . 2009-02-14 17:56 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Christy Talley\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-03-28 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-07 34040]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-15 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-09 52256]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-09-25 210216]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-16 16862720]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-07-10 421888]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-10-08 864624]
"zSPGuard"="c:\program files\pjw\spguard\spguard.exe" [2004-06-22 737280]
"lxcjmon.exe"="c:\program files\Lexmark 8300 Series\lxcjmon.exe" [2005-09-30 200704]
"EzPrint"="c:\program files\Lexmark 8300 Series\ezprint.exe" [2006-04-19 94208]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-09-24 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-04 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-04 13670504]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v2 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v2\WG111v2.exe [2009-7-17 1261568]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^mosascii m2 update check.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 13:42 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedBitVideoAccelerator]
2009-08-01 22:34 1443432 —-a-w- c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XboxStat]
2007-09-26 23:05 734264 —-a-w- c:\program files\Microsoft Xbox 360 Accessories\XBoxStat.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\Client\\Agentsvc.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\BackupSvc.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\SchedulerSvc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\lxcjcoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxcjpswx.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\NETGEAR\\WG111v2\\WG111v2.exe"=
"c:\\Program Files\\Outlook Express\\msimn.exe"=
"c:\\Program Files\\Digital Integration Ltd\\PS Media Tunnel\\PSMediaTunnel.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\VDOWNLOADER\\VDownloader.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020

R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 4:27 PM 25680]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/14/2009 12:56 PM 64288]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [3/3/2008 4:11 PM 16384]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [8/12/2010 7:15 AM 1357464]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [4/7/2008 1:42 AM 50424]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [8/12/2010 7:15 AM 15008]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [7/17/2009 8:15 PM 272128]
S0 nielprt;Nielsen Patch Service;c:\windows\system32\DRIVERS\nielprt.sys –> c:\windows\system32\DRIVERS\nielprt.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/3/2010 11:30 AM 136176]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [4/4/2008 6:03 AM 131072]
S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys –> c:\windows\system32\drivers\nielgfx.sys [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - FXTDQPOW
*Deregistered* - fxtdqpow
.
Contents of the 'Scheduled Tasks' folder

2010-10-29 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-08-12 10:27]

2010-10-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-10-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-03 16:30]

2010-10-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-03 16:30]

2010-10-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2368361500-1559728310-520348512-1006Core.job
- c:\documents and settings\Christy Talley\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-28 16:22]

2010-10-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2368361500-1559728310-520348512-1006UA.job
- c:\documents and settings\Christy Talley\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-28 16:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-Sonic RecordNow! - (no file)
HKLM-Run-LaunchApp - (no file)
HKLM-Run-nwiz - nwiz.exe
AddRemove-Agere Systems Soft Modem - c:\windows\agrsmdel
AddRemove-LSI Soft Modem - c:\windows\agrsmdel



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-31 09:59
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Local AppWizard-Generated Applications\Launch Tool\Settings]
@DACL=(02 0000)
@SACL=

[HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Microsoft\Internet Explorer\Main\Default Feeds\{13DB6A0C-A268-4AD1-9BA3-A9AEAA92594A}]
@DACL=(02 0000)
@SACL=
"Title"="Microsoft Feeds\\Microsoft at Home"
"Url"="http://go.microsoft.com/fwlink/?LinkId=68928"

[HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Microsoft\Internet Explorer\Main\Default Feeds\{A574C242-9F63-44E8-9466-5AF0999253DE}]
@DACL=(02 0000)
@SACL=
"Title"="Microsoft Feeds\\Microsoft at Work"
"Url"="http://go.microsoft.com/fwlink/?LinkId=68929"

[HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotm\OpenWithProgids]
@DACL=(02 0000)
@SACL=
"Word.TemplateMacroEnabled.12"=hex(0):

[HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotx\OpenWithProgids]
@DACL=(02 0000)
@SACL=
"Word.Template.12"=hex(0):

[HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potx\OpenWithProgids]
@DACL=(02 0000)
@SACL=
"PowerPoint.Template.12"=hex(0):
"PowerPointViewer.Template.12"=hex(0):

[HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppam\OpenWithProgids]
@DACL=(02 0000)
@SACL=
"PowerPoint.Addin.12"=hex(0):

[HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsm\OpenWithProgids]
@DACL=(02 0000)
@SACL=
"PowerPoint.SlideShowMacroEnabled.12"=hex(0):
"PowerPointViewer.SlideShowMacroEnabled.12"=hex(0):

[HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsx\OpenWithProgids]
@DACL=(02 0000)
@SACL=
"PowerPoint.SlideShow.12"=hex(0):
"PowerPointViewer.SlideShow.12"=hex(0):

[HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlam\OpenWithProgids]
@DACL=(02 0000)
@SACL=
"Excel.AddInMacroEnabled"=hex(0):
"Excel.Addin"=hex(0):

[HKEY_LOCAL_MACHINE\software\BigFix\BigFix]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07340190-BCE0-11D1-BD7E-00207812DE95}\Control]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07340190-BCE0-11D1-BD7E-00207812DE95}\Insertable]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07340190-BCE0-11D1-BD7E-00207812DE95}\MiscStatus]
@DACL=(02 0000)
@SACL=
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07340190-BCE0-11D1-BD7E-00207812DE95}\ProgID]
@DACL=(02 0000)
@SACL=
@="AppCtl.AppCtl.1"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07340190-BCE0-11D1-BD7E-00207812DE95}\Programmable]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07340190-BCE0-11D1-BD7E-00207812DE95}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{A92757C4-BE3F-11D1-BD7E-00207812DE95}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07340190-BCE0-11D1-BD7E-00207812DE95}\Version]
@DACL=(02 0000)
@SACL=
@="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07340190-BCE0-11D1-BD7E-00207812DE95}\VersionIndependentProgID]
@DACL=(02 0000)
@SACL=
@="AppCtl.AppCtl"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3A0-18D6-101C-8158-221E4B551F8E}\Control]
@DACL=(02 0000)
@SACL=
@=""

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3A0-18D6-101C-8158-221E4B551F8E}\MiscStatus]
@DACL=(02 0000)
@SACL=
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3A0-18D6-101C-8158-221E4B551F8E}\ProgID]
@DACL=(02 0000)
@SACL=
@="VSOCX.VselasticCtrl.1"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3A0-18D6-101C-8158-221E4B551F8E}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{2037E3AD-18D6-101C-8158-221E4B551F8E}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3A0-18D6-101C-8158-221E4B551F8E}\Version]
@DACL=(02 0000)
@SACL=
@="5.0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3A5-18D6-101C-8158-221E4B551F8E}\Control]
@DACL=(02 0000)
@SACL=
@=""

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3A5-18D6-101C-8158-221E4B551F8E}\MiscStatus]
@DACL=(02 0000)
@SACL=
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3A5-18D6-101C-8158-221E4B551F8E}\ProgID]
@DACL=(02 0000)
@SACL=
@="VSOCX.VsindextabCtrl.1"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3A5-18D6-101C-8158-221E4B551F8E}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{2037E3AD-18D6-101C-8158-221E4B551F8E}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3A5-18D6-101C-8158-221E4B551F8E}\Version]
@DACL=(02 0000)
@SACL=
@="5.0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3AA-18D6-101C-8158-221E4B551F8E}\Control]
@DACL=(02 0000)
@SACL=
@=""

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3AA-18D6-101C-8158-221E4B551F8E}\MiscStatus]
@DACL=(02 0000)
@SACL=
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3AA-18D6-101C-8158-221E4B551F8E}\ProgID]
@DACL=(02 0000)
@SACL=
@="VSOCX.VsawkCtrl.1"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3AA-18D6-101C-8158-221E4B551F8E}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{2037E3AD-18D6-101C-8158-221E4B551F8E}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3AA-18D6-101C-8158-221E4B551F8E}\Version]
@DACL=(02 0000)
@SACL=
@="5.0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\Control]
@DACL=(02 0000)
@SACL=
@=""

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\Implemented Categories]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\MiscStatus]
@DACL=(02 0000)
@SACL=
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\ProgID]
@DACL=(02 0000)
@SACL=
@="AcerCtrls.APlunch"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{3895DD37-7573-11D2-8FED-00606730D3AA}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\Version]
@DACL=(02 0000)
@SACL=
@="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\Control]
@DACL=(02 0000)
@SACL=
@=""

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\Implemented Categories]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\MiscStatus]
@DACL=(02 0000)
@SACL=
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\ProgID]
@DACL=(02 0000)
@SACL=
@="ctlDiags.Fs"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{1D676278-D6DF-11D1-90DC-0000C03DCA0D}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\Version]
@DACL=(02 0000)
@SACL=
@="33.0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\Control]
@DACL=(02 0000)
@SACL=
@=""

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\Implemented Categories]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\MiscStatus]
@DACL=(02 0000)
@SACL=
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\ProgID]
@DACL=(02 0000)
@SACL=
@="ctlSCBtns.scAXbtns"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{932BF86E-2BAB-11D2-8EA2-0080C82D82A9}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\Version]
@DACL=(02 0000)
@SACL=
@="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Control]
@DACL=(02 0000)
@SACL=
@=""

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Implemented Categories]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\MiscStatus]
@DACL=(02 0000)
@SACL=
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\ProgID]
@DACL=(02 0000)
@SACL=
@="LunchApp.APlunch"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{D9998BD2-7957-11D2-8FED-00606730D3AA}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Version]
@DACL=(02 0000)
@SACL=
@="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\Control]
@DACL=(02 0000)
@SACL=
@=""

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\Implemented Categories]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\MiscStatus]
@DACL=(02 0000)
@SACL=
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\ProgID]
@DACL=(02 0000)
@SACL=
@="ctlSupport.Fs"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{1D676278-D6DF-11D1-90DC-0000C03DCA0D}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\Version]
@DACL=(02 0000)
@SACL=
@="34.0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\Control]
@DACL=(02 0000)
@SACL=
@=""

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\Implemented Categories]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\MiscStatus]
@DACL=(02 0000)
@SACL=
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\ProgID]
@DACL=(02 0000)
@SACL=
@="scIntro.UserControl1"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{F6940BE0-E4EB-11D1-8EA2-0080C82D82A9}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\Version]
@DACL=(02 0000)
@SACL=
@="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\Control]
@DACL=(02 0000)
@SACL=
@=""

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\Implemented Categories]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\MiscStatus]
@DACL=(02 0000)
@SACL=
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\ProgID]
@DACL=(02 0000)
@SACL=
@="Project1.Fs"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{1D676278-D6DF-11D1-90DC-0000C03DCA0D}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\Version]
@DACL=(02 0000)
@SACL=
@="33.0"

[HKEY_LOCAL_MACHINE\software\Classes\GoogleGadget\DefaultIcon]
@DACL=(02 0000)
@SACL=
@="\"c:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\",0"

[HKEY_LOCAL_MACHINE\software\Classes\GoogleGadget\shell]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\GoogleGadgetContainer\DefaultIcon]
@DACL=(02 0000)
@SACL=
@="\"c:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\",0"

[HKEY_LOCAL_MACHINE\software\Classes\GoogleGadgetContainer\shell]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\GoogleGadgetManifest\DefaultIcon]
@DACL=(02 0000)
@SACL=
@="\"c:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\",0"

[HKEY_LOCAL_MACHINE\software\Classes\GoogleGadgetManifest\shell]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{640f2578-c31b-4ff3-9891-042fa87bc781}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{550DFE55-4B64-4039-95EF-2C1DB0B66D58}"
"Version"="5.0.0.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6EE4DCBB-CE99-4994-A12A-242CEBDD691C}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{415FD1E7-5BC1-4BD4-B8F0-D6647D36EEC5}"
"Version"="8.0.12.6325"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{8F5217C6-D374-4fd6-A973-1A8D9477A8FD}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{75A4387C-BA5A-4C19-9709-707F11F8193D}"
"Version"="8.0.12.6325"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{1D676278-D6DF-11D1-90DC-0000C03DCA0D}\21.0]
@DACL=(02 0000)
@SACL=
@="Project1"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{1D676278-D6DF-11D1-90DC-0000C03DCA0D}\22.0]
@DACL=(02 0000)
@SACL=
@="ctlSupport"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{2037E3AD-18D6-101C-8158-221E4B551F8E}\5.0]
@DACL=(02 0000)
@SACL=
@=":-) VideoSoft vsOcx Controls"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{3895DD37-7573-11D2-8FED-00606730D3AA}\1.0]
@DACL=(02 0000)
@SACL=
@="AcerCtrls"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{932BF86E-2BAB-11D2-8EA2-0080C82D82A9}\1.0]
@DACL=(02 0000)
@SACL=
@="Service Center buttons for MAG"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{A269B061-7EBE-4630-8BF6-6C42D5BE41AE}\1.0]
@DACL=(02 0000)
@SACL=
@="GoogleDesktopDisplayInternalLib"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{A92757C4-BE3F-11D1-BD7E-00207812DE95}\1.0]
@DACL=(02 0000)
@SACL=
@="ACEAppCtl 1.0 Type Library"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{ACD1A266-C77B-4691-B96A-AF712B83A364}\3.0]
@DACL=(02 0000)
@SACL=
@="GoogleDesktop.Panels 3.0 Type Library "

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{D9998BD2-7957-11D2-8FED-00606730D3AA}\1.0]
@DACL=(02 0000)
@SACL=
@="LunchApp"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{F6940BE0-E4EB-11D1-8EA2-0080C82D82A9}\1.0]
@DACL=(02 0000)
@SACL=
@="scIntro"

[HKEY_LOCAL_MACHINE\software\Cyberlink\PowerDVD\7.0]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Cyberlink\PowerDVD\BuildInfo]
@DACL=(02 0000)
@SACL=
"SR_No"="CDS080919-01"
"Setup"="7879"
"RC"="080902"
"Help"="080508"
"Readme"="080403"
"Skin"="080219"
"RegRC"="070620"
"TrialDialog RC"="080415"
"CLMUI"="080612"
"Ver"="7.0.3409.a"
"Utility"="2903"
"UI"="3320_Generic"
"Registry"="3116(EVR)"
"DShow"="3118(EVR)"
"AVSetting"="-"
"CPXM"="4721(Vista_Logo)"
"Other"="2729(Vista_Logo)"
"OlReg"="070531v4"
"CL264"="3104(Vista_Logo)"
"Pou"="2525_Gateway"
"TrialDialog"="061207_PowerDVD7(Vista_Logo)"
"Sim"="2322"
"UPnP"="3116(Vista_Logo)"
"RichVideo"="1711"
"SR_Ver"="7.00.452401"

[HKEY_LOCAL_MACHINE\software\Cyberlink\PowerDVD\UI_WndClassNameToHide]
@DACL=(02 0000)
@SACL=
"CSWatermark"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Cyberlink\PowerDVD\UserReg]
@DACL=(02 0000)
@SACL=
"SR_No"="CDS080919-01"
"Prod_Name"="PowerDVD"
"ProductName"="PowerDVD"
"Prod_Ver"="7.0"
"Prod_No"="DVD00011"
"CustomerNO"="1842"
"Hardware"="Desktop PC"
"Channel"="OEM"
"RegVType"="OEM 2CH"

[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IE UserData NT\RegBackup]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IE.HKCUZoneInfo\RegBackup]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IE40.UserAgent\RegBackup]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IEHomePageInfo\RegBackup]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP0\ie7\Filelist]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\NetZero, Inc.\NetZero]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Realtek Semiconductor Corp.\Realtek High Definition Audio Driver]
@DACL=(02 0000)
@SACL=
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(812)
c:\windows\system32\RtlGina2.dll
.
Completion time: 2010-10-31 10:02:05
ComboFix-quarantined-files.txt 2010-10-31 15:01

Pre-Run: 28,991,123,456 bytes free
Post-Run: 28,990,353,408 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - FD3210709BA45A01375D621AD49B3D1C
shelljj,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    RegLock::
    [HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Local AppWizard-Generated Applications\Launch Tool\Settings]
    [HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Microsoft\Internet Explorer\Main\Default Feeds\{13DB6A0C-A268-4AD1-9BA3-A9AEAA92594A}]
    [HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Microsoft\Internet Explorer\Main\Default Feeds\{A574C242-9F63-44E8-9466-5AF0999253DE}]
    [HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotm\OpenWithProgids]
    [HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotx\OpenWithProgids]
    [HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potx\OpenWithProgids]
    [HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppam\OpenWithProgids]
    [HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsm\OpenWithProgids]
    [HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsx\OpenWithProgids]
    [HKEY_USERS\S-1-5-21-2368361500-1559728310-520348512-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlam\OpenWithProgids]
    [HKEY_LOCAL_MACHINE\software\BigFix\BigFix]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07340190-BCE0-11D1-BD7E-00207812DE95}]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3A0-18D6-101C-8158-221E4B551F8E}]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}]
    [HKEY_LOCAL_MACHINE\software\Classes\GoogleGadget]
    [HKEY_LOCAL_MACHINE\software\Classes\GoogleGadgetManifest]
    
     Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "135:TCP"= -
    "5000:TCP"= -
    "5001:TCP"= -
    "5002:TCP"= -
    "5003:TCP"= -
    "5004:TCP"= -
    "5005:TCP"= -
    "5006:TCP"= -
    "5007:TCP"= -
    "5008:TCP"= -
    "5009:TCP"= -
    "5010:TCP"= -
    "5011:TCP"= -
    "5012:TCP"= -
    "5013:TCP"= -
    "5014:TCP"= -
    "5015:TCP"= -
    "5016:TCP"= -
    "5017:TCP"= -
    "5018:TCP"= -
    "5019:TCP"= -
    "5020:TCP"= -
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Here is the log: And once again, thanks for all your help and patience. :)


ComboFix 10-11-02.01 - Christy Talley 11/02/2010 17:48:00.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.894.330 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Christy Talley\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2010-10-02 to 2010-11-02 )))))))))))))))))))))))))))))))
.

2010-10-24 14:09 . 2010-10-24 14:10 ——– d—–w- c:\documents and settings\Christy Talley\Application Data\Easy Image Modifier
2010-10-23 21:03 . 2010-10-23 21:03 ——– d—–w- c:\program files\Defraggler
2010-10-23 01:11 . 2010-10-23 01:11 388096 —-a-r- c:\documents and settings\Christy Talley\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-10-17 21:29 . 2010-10-17 21:29 ——– d—–w- c:\documents and settings\Christy Talley\Application Data\AVG10
2010-10-17 21:26 . 2010-10-17 21:26 ——– d–h–w- c:\documents and settings\All Users\Application Data\Common Files
2010-10-17 21:24 . 2010-10-22 23:43 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG10
2010-10-16 14:12 . 2010-10-16 14:33 ——– d—–w- c:\documents and settings\All Users\Application Data\MFAData

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-23 20:53 . 2009-03-01 15:09 392010 —-a-w- c:\windows\system32\drivers\etc\hosts.tmp
2010-10-01 21:49 . 2010-05-02 22:23 187 —-a-w- c:\windows\Fonts\READ ME .txt
2010-10-01 21:45 . 2001-06-18 01:44 1064 —-a-w- c:\windows\Fonts\KR ReadMe.txt
2010-10-01 20:30 . 2008-12-04 02:00 688 —-a-w- c:\windows\Fonts\neverletgo-TOU.txt
2010-10-01 20:29 . 2009-12-16 15:59 675 —-a-w- c:\windows\Fonts\writtenonhishands-TOU.txt
2010-09-18 17:23 . 2008-04-14 22:00 974848 —-a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-04-14 22:00 974848 —-a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-04-14 22:00 954368 —-a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2008-04-14 22:00 953856 —-a-w- c:\windows\system32\mfc40u.dll
2010-09-13 21:27 . 2010-09-13 21:27 25680 —-a-w- c:\windows\system32\drivers\AVGIDSEH.sys
2010-09-09 13:38 . 2007-08-14 02:54 832512 —-a-w- c:\windows\system32\wininet.dll
2010-09-09 13:38 . 2007-08-14 02:45 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2010-09-09 13:38 . 2009-06-04 10:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-09-09 13:38 . 2008-04-14 22:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-09-08 16:17 . 2010-09-08 16:17 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 16:17 . 2010-09-08 16:17 69632 —-a-w- c:\windows\system32\QuickTime.qts
2010-09-08 15:57 . 2008-04-14 22:00 389120 —-a-w- c:\windows\system32\html.iec
2010-09-01 11:51 . 2008-04-14 22:00 285824 —-a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42 . 2008-04-14 22:00 1852800 —-a-w- c:\windows\system32\win32k.sys
2010-08-31 10:11 . 2010-08-31 10:11 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-08-27 08:02 . 2008-04-14 22:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57 . 2008-04-14 22:00 99840 —-a-w- c:\windows\system32\srvsvc.dll
2010-08-26 13:39 . 2008-04-14 22:00 357248 —-a-w- c:\windows\system32\drivers\srv.sys
2010-08-26 12:52 . 2009-04-16 00:01 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12 . 2008-04-14 22:00 617472 —-a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2008-04-14 22:00 58880 —-a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45 . 2008-04-14 22:00 590848 —-a-w- c:\windows\system32\rpcrt4.dll
2010-08-12 12:15 . 2009-02-14 17:56 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Christy Talley\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-03-28 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-07 34040]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-15 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-09 52256]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-09-25 210216]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-16 16862720]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-07-10 421888]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-10-08 864624]
"zSPGuard"="c:\program files\pjw\spguard\spguard.exe" [2004-06-22 737280]
"lxcjmon.exe"="c:\program files\Lexmark 8300 Series\lxcjmon.exe" [2005-09-30 200704]
"EzPrint"="c:\program files\Lexmark 8300 Series\ezprint.exe" [2006-04-19 94208]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-09-24 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-04 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-04 13670504]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v2 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v2\WG111v2.exe [2009-7-17 1261568]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^mosascii m2 update check.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 13:42 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedBitVideoAccelerator]
2009-08-01 22:34 1443432 —-a-w- c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XboxStat]
2007-09-26 23:05 734264 —-a-w- c:\program files\Microsoft Xbox 360 Accessories\XBoxStat.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\Client\\Agentsvc.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\BackupSvc.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\SchedulerSvc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\lxcjcoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxcjpswx.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\NETGEAR\\WG111v2\\WG111v2.exe"=
"c:\\Program Files\\Outlook Express\\msimn.exe"=
"c:\\Program Files\\Digital Integration Ltd\\PS Media Tunnel\\PSMediaTunnel.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\VDOWNLOADER\\VDownloader.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 4:27 PM 25680]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/14/2009 12:56 PM 64288]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [3/3/2008 4:11 PM 16384]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [8/12/2010 7:15 AM 1357464]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [4/7/2008 1:42 AM 50424]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [8/12/2010 7:15 AM 15008]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [7/17/2009 8:15 PM 272128]
S0 nielprt;Nielsen Patch Service;c:\windows\system32\DRIVERS\nielprt.sys –> c:\windows\system32\DRIVERS\nielprt.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/3/2010 11:30 AM 136176]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [4/4/2008 6:03 AM 131072]
S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys –> c:\windows\system32\drivers\nielgfx.sys [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - FXTDQPOW
*Deregistered* - fxtdqpow
.
Contents of the 'Scheduled Tasks' folder

2010-11-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-08-12 10:27]

2010-10-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-11-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-03 16:30]

2010-11-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-03 16:30]

2010-11-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2368361500-1559728310-520348512-1006Core.job
- c:\documents and settings\Christy Talley\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-28 16:22]

2010-11-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2368361500-1559728310-520348512-1006UA.job
- c:\documents and settings\Christy Talley\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-28 16:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-02 17:53
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07340190-BCE0-11D1-BD7E-00207812DE95}\MiscStatus\1]
@DACL=(02 0000)
@SACL=
@="132497"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3A0-18D6-101C-8158-221E4B551F8E}\MiscStatus\1]
@DACL=(02 0000)
@SACL=
@="197009"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3A5-18D6-101C-8158-221E4B551F8E}\Control]
@DACL=(02 0000)
@SACL=
@=""

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3A5-18D6-101C-8158-221E4B551F8E}\MiscStatus]
@DACL=(02 0000)
@SACL=
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3A5-18D6-101C-8158-221E4B551F8E}\ProgID]
@DACL=(02 0000)
@SACL=
@="VSOCX.VsindextabCtrl.1"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3A5-18D6-101C-8158-221E4B551F8E}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{2037E3AD-18D6-101C-8158-221E4B551F8E}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3A5-18D6-101C-8158-221E4B551F8E}\Version]
@DACL=(02 0000)
@SACL=
@="5.0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3AA-18D6-101C-8158-221E4B551F8E}\Control]
@DACL=(02 0000)
@SACL=
@=""

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3AA-18D6-101C-8158-221E4B551F8E}\MiscStatus]
@DACL=(02 0000)
@SACL=
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3AA-18D6-101C-8158-221E4B551F8E}\ProgID]
@DACL=(02 0000)
@SACL=
@="VSOCX.VsawkCtrl.1"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3AA-18D6-101C-8158-221E4B551F8E}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{2037E3AD-18D6-101C-8158-221E4B551F8E}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2037E3AA-18D6-101C-8158-221E4B551F8E}\Version]
@DACL=(02 0000)
@SACL=
@="5.0"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3895DD35-7573-11D2-8FED-00606730D3AA}\MiscStatus\1]
@DACL=(02 0000)
@SACL=
@="131473"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5A9D8748-FB00-11D1-8EA2-0080C82D82A9}\MiscStatus\1]
@DACL=(02 0000)
@SACL=
@="131473"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{932BF86C-2BAB-11D2-8EA2-0080C82D82A9}\MiscStatus\1]
@DACL=(02 0000)
@SACL=
@="131473"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}]
@DACL=(02 0000)
@SACL=
@=""

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}]
@DACL=(02 0000)
@SACL=
@=""

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D9998BD0-7957-11D2-8FED-00606730D3AA}\MiscStatus\1]
@DACL=(02 0000)
@SACL=
@="131473"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EC3A38E8-FB02-11D1-8EA2-0080C82D82A9}\MiscStatus\1]
@DACL=(02 0000)
@SACL=
@="131473"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F6940BDC-E4EB-11D1-8EA2-0080C82D82A9}\MiscStatus\1]
@DACL=(02 0000)
@SACL=
@="131473"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FD748A48-FB00-11D1-8EA2-0080C82D82A9}\MiscStatus\1]
@DACL=(02 0000)
@SACL=
@="131473"

[HKEY_LOCAL_MACHINE\software\Classes\GoogleGadget\shell\open]
@DACL=(02 0000)
@SACL=
@="&Open; with Google Desktop"

[HKEY_LOCAL_MACHINE\software\Classes\GoogleGadgetContainer\DefaultIcon]
@DACL=(02 0000)
@SACL=
@="\"c:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\",0"

[HKEY_LOCAL_MACHINE\software\Classes\GoogleGadgetContainer\shell]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\GoogleGadgetManifest\shell\open]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{640f2578-c31b-4ff3-9891-042fa87bc781}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{550DFE55-4B64-4039-95EF-2C1DB0B66D58}"
"Version"="5.0.0.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6EE4DCBB-CE99-4994-A12A-242CEBDD691C}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{415FD1E7-5BC1-4BD4-B8F0-D6647D36EEC5}"
"Version"="8.0.12.6325"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{8F5217C6-D374-4fd6-A973-1A8D9477A8FD}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{75A4387C-BA5A-4C19-9709-707F11F8193D}"
"Version"="8.0.12.6325"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{1D676278-D6DF-11D1-90DC-0000C03DCA0D}\21.0]
@DACL=(02 0000)
@SACL=
@="Project1"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{1D676278-D6DF-11D1-90DC-0000C03DCA0D}\22.0]
@DACL=(02 0000)
@SACL=
@="ctlSupport"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{2037E3AD-18D6-101C-8158-221E4B551F8E}\5.0]
@DACL=(02 0000)
@SACL=
@=":-) VideoSoft vsOcx Controls"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{3895DD37-7573-11D2-8FED-00606730D3AA}\1.0]
@DACL=(02 0000)
@SACL=
@="AcerCtrls"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{932BF86E-2BAB-11D2-8EA2-0080C82D82A9}\1.0]
@DACL=(02 0000)
@SACL=
@="Service Center buttons for MAG"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{A269B061-7EBE-4630-8BF6-6C42D5BE41AE}\1.0]
@DACL=(02 0000)
@SACL=
@="GoogleDesktopDisplayInternalLib"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{A92757C4-BE3F-11D1-BD7E-00207812DE95}\1.0]
@DACL=(02 0000)
@SACL=
@="ACEAppCtl 1.0 Type Library"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{ACD1A266-C77B-4691-B96A-AF712B83A364}\3.0]
@DACL=(02 0000)
@SACL=
@="GoogleDesktop.Panels 3.0 Type Library "

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{D9998BD2-7957-11D2-8FED-00606730D3AA}\1.0]
@DACL=(02 0000)
@SACL=
@="LunchApp"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{F6940BE0-E4EB-11D1-8EA2-0080C82D82A9}\1.0]
@DACL=(02 0000)
@SACL=
@="scIntro"

[HKEY_LOCAL_MACHINE\software\Cyberlink\PowerDVD\7.0]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Cyberlink\PowerDVD\BuildInfo]
@DACL=(02 0000)
@SACL=
"SR_No"="CDS080919-01"
"Setup"="7879"
"RC"="080902"
"Help"="080508"
"Readme"="080403"
"Skin"="080219"
"RegRC"="070620"
"TrialDialog RC"="080415"
"CLMUI"="080612"
"Ver"="7.0.3409.a"
"Utility"="2903"
"UI"="3320_Generic"
"Registry"="3116(EVR)"
"DShow"="3118(EVR)"
"AVSetting"="-"
"CPXM"="4721(Vista_Logo)"
"Other"="2729(Vista_Logo)"
"OlReg"="070531v4"
"CL264"="3104(Vista_Logo)"
"Pou"="2525_Gateway"
"TrialDialog"="061207_PowerDVD7(Vista_Logo)"
"Sim"="2322"
"UPnP"="3116(Vista_Logo)"
"RichVideo"="1711"
"SR_Ver"="7.00.452401"

[HKEY_LOCAL_MACHINE\software\Cyberlink\PowerDVD\UI_WndClassNameToHide]
@DACL=(02 0000)
@SACL=
"CSWatermark"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Cyberlink\PowerDVD\UserReg]
@DACL=(02 0000)
@SACL=
"SR_No"="CDS080919-01"
"Prod_Name"="PowerDVD"
"ProductName"="PowerDVD"
"Prod_Ver"="7.0"
"Prod_No"="DVD00011"
"CustomerNO"="1842"
"Hardware"="Desktop PC"
"Channel"="OEM"
"RegVType"="OEM 2CH"

[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IE UserData NT\RegBackup]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IE.HKCUZoneInfo\RegBackup]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IE40.UserAgent\RegBackup]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IEHomePageInfo\RegBackup]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP0\ie7\Filelist]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\NetZero, Inc.\NetZero]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\Realtek Semiconductor Corp.\Realtek High Definition Audio Driver]
@DACL=(02 0000)
@SACL=
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(812)
c:\windows\system32\RtlGina2.dll

- - - - - - - > 'explorer.exe'(860)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-11-02 17:56:07
ComboFix-quarantined-files.txt 2010-11-02 22:55
ComboFix2.txt 2010-10-31 15:02

Pre-Run: 28,854,603,776 bytes free
Post-Run: 28,843,261,952 bytes free

- - End Of File - - C4C6F4BB42A880A713709D0D5AA7219E
Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

Also, please let me know how things are running now?
I started the download at 9:00 am this morning. It finally finished after what was literally hours. I started the scan and it is now 1:20 pm, the scan froze at 620 objects and at 9.08 minutes. I've tried everything to make it re-start. I clicked on stop scanning so that (hopefully) I could re-start the scan. No such luck. Do I need to re-start the entire download process to get it to restart the scan? I don't mind, I'm just wondering if that is what I need to do.
shelljj,

Let's try a different one. Sometimes it will go faster.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
Thanks for the alternative program. Here is the log. ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=7.00.6000.17091 (vista_gdr.100824-1500) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=6fc80c5fc2e4314db15380cb91d8ad49 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-11-10 11:51:57 # local_time=2010-11-10 05:51:57 (-0600, Central Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 52593945 52593945 0 0 # compatibility_mode=1024 16777215 100 0 1266824 1266824 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=84366 # found=7 # cleaned=0 # scan_time=5121 C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GameVance11.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GameVance12.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I C:\Documents and Settings\Christy Talley\Application Data\Sun\Java\Deployment\cache\6.0\62\5fb5f17e-77cb79b3 Java/Boonana.A trojan 00000000000000000000000000000000 I C:\Documents and Settings\Christy Talley\Desktop\Unused Desktop\vdownloader1.12_setup.exe Win32/Adware.ADON application 00000000000000000000000000000000 I C:\Documents and Settings\Christy Talley\My Documents\Downloads\wirelesskeyview.zip a variant of Win32/WirelessKeyView.A application 00000000000000000000000000000000 I C:\Documents and Settings\Christy Talley\My Documents\Downloads\wirelesskeyview\WirelessKeyView.exe a variant of Win32/WirelessKeyView.A application 00000000000000000000000000000000 I C:\Program Files\Trend Micro\HijackThis\backups\backup-20090712-183633-928.dll a variant of Win32/Adware.Gamevance.AA application 00000000000000000000000000000000 I
shelljj,


The good news is that it looks like your spybot caught and stopped the bagle worm. It's a real nasty. It typically comes from downloading torrents or other P2p files.

A couple of questions on what else was found…

vdownloader1.12_setup.exe Is this something you purposefully installed? This sometimes is installed as part of a Trojan infection… however, I don't think it usually installs it to the desktop. Typically it relates to Ebay. It will track your ebay usage and will notify it's "host" when you log in to ebay. Sometimes it will manifest itself by redirecting you to a bogus ebay site.

How about this one - WirelessKeyView.exe? The program can be legitemately used to recover a forgotton key… but it is often used to steal the key off of your computer. Did you install it? If not… you need to immediately change your passwords.

The Java exploit needs to go for sure.

Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are two options in the window to clear the cache - Leave both Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.
The vdownloader1.12_setup.exe, I think I installed it as a youtube converter. It didn't work as I wanted, and just never uninstalled it. The WirelessKeyView.exe, I got that one from Kim Komando as a way to recover the key to my network, trying to tie my Vista laptop in with my two XP's. Haha, the laugh was on me on that one also. I still couldn't figure out how to tie the Vista in with the XP, and never got that done, yet again, did not uninstall. I cleared the Java cache. I'm not sure what torrent or P2p are, so not sure if I downloaded that or not. But I'm glad Spybot caught it, whatever is was. I do thank you for all your help. Do I need to check anything else or any other areas?
shelljj,

WirelessKeyView.exe is not "bad" in and of itself. If you put it on there… then it really isn't something to worry about. If it is on your computer and you didn't put it on there… then that means someone else did and there would be no reason to do that unless they were trying to get your information.

If you want help networking your computers together, I suggest you post in the Network forum and I'm sure someone will be able to help you.

P2p programs and torrents are file sharing. Music, videos, and even some programs that are almost always pirated and often full of infections. Here is my speech I would have given you if I had found "Limewire" (which is a P2p program) on your system.

Limewire
You have Limewire, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm://http://www.techweb.com/wire/1605005...cles/art053.htm


I would recommend that you uninstall Limewire, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.



How are things running now? If they are good, we just have a little housekeeping to do and you can be on your way.
Lol, After that "speech", I'm glad you did not find that Lime Wire on my computer. I don't do the file sharing thing. If I want to watch a movie, I usually go to Walmart (of all places) and buy it. Music…I do hit up Youtube quite a bit. I'm pretty sure that was what the vdownloader thing proposed to be. A converter for youtube videos. I seem to running pretty good right now, no connection issues that I can notice. I really do appreciate all of your help with this thing. I should pop into here with our work computers, now there is a mess. I may sign in from work and see if there is anyway to fix a couple of them. OK, I'm ready to do housecleaning. Whatever you say is dirty, I will clean… :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI