This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

my comp is turning off

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, the other night something happened with my pc. My mouse get crazy, arrow all over the place, my cd-rom also suddenly geting in and out. Now my progrmas seems not to work properly, or very slow. Computer is turning off after some time, or get restarted. I tried to use my nod32, or some other protection i have, but in the middle of process, the comp just went off, so I m not sure what happened, and if anything was found, quarantined and so on. Can someone help me pls, and tell me what to do? Thanks in advance.

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, johnnykg

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
Hello there,

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel"
  • Click the OK button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
===================================================

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===================================================

On your next reply please post :
OTL log
GMER log
Checkup log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hello Conspire,

thanks for ur help. Here are logs that u asked for:


OTL logfile created on: 7.3.2011 15:10:37 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Ziksi\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 0000081A | Country: Serbia and Montenegro | Language: SRL | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 73,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 91,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 68,36 Gb Total Space | 12,77 Gb Free Space | 18,68% Space Free | Partition Type: NTFS
Drive D: | 74,84 Gb Total Space | 39,05 Gb Free Space | 52,18% Space Free | Partition Type: NTFS
Drive E: | 154,89 Gb Total Space | 32,88 Gb Free Space | 21,23% Space Free | Partition Type: NTFS

Computer Name: CASA01 | User Name: Ziksi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Ziksi\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE (Software 2000 Limited)
PRC - C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Ziksi\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcInj.dll (Logitech Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (TuneUp.Defrag) – C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe (TuneUp Software)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (TuneUp.UtilitiesSvc) – C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) – C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
SRV - (EhttpSrv) – C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (ESET)
SRV - (ekrn) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
SRV - (LVSrvLauncher) – C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVCOMSer) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (nSvcIp) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA Corporation)
SRV - (nSvcLog) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA Corporation)
SRV - (ForcewareWebInterface) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe (Apache Software Foundation)


========== Driver Services (SafeList) ==========

DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (atksgt) – C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) – C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (TuneUpUtilitiesDrv) – C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (epfwtdir) – C:\WINDOWS\system32\drivers\epfwtdir.sys ()
DRV - (easdrv) – C:\WINDOWS\system32\drivers\easdrv.sys (ESET)
DRV - (eamon) – C:\WINDOWS\system32\drivers\eamon.sys (ESET)
DRV - ({B154377D-700F-42cc-9474-23858FBDF4BD}) – C:\Program Files\CyberLink\PowerDVD9\000.fcl (CyberLink Corp.)
DRV - (VCSVADHWSer) Avnex Virtual Audio Device (WDM) – C:\WINDOWS\system32\drivers\vcsvad.sys (Avnex)
DRV - (acedrv11) – C:\WINDOWS\system32\drivers\acedrv11.sys (Protect Software GmbH)
DRV - (LVMVDrv) – C:\WINDOWS\system32\drivers\LVMVdrv.sys (Logitech Inc.)
DRV - (LVcKap) – C:\WINDOWS\system32\drivers\Lvckap.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (PID_0928) Logitech QuickCam Express(PID_0928) – C:\WINDOWS\system32\drivers\LV561AV.SYS (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (tenCapture) – C:\WINDOWS\system32\drivers\tenCapture.sys (Hajo Krabbenhöft)
DRV - (nvata) – C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (CamthWDM) – C:\WINDOWS\system32\drivers\CamthWDM.sys (YewSoft)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (SenFiltService) – C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "SweetIM Search"
FF - prefs.js..browser.search.defaulturl: "http://search.sweetim.com/search.asp?src=2&q;="
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "SweetIM Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..extensions.enabledItems: [removed]:2
FF - prefs.js..extensions.enabledItems: 4
FF - prefs.js..extensions.enabledItems: 9
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220
FF - prefs.js..keyword.URL: "http://search.sweetim.com/search.asp?src=2&q;="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/webhp?client=firefox-a&rls;=org.mozilla:en-GB:official&channel;=s&hl;=en&source;=hp&btnG;=Google+Search"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "chrome://browser-region/locale/region.properties"


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.03.05 11:22:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.03.05 11:22:19 | 000,000,000 | —D | M]

[2009.07.04 16:34:50 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Ziksi\Application Data\Mozilla\Extensions
[2011.03.06 15:53:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Ziksi\Application Data\Mozilla\Firefox\Profiles\lf2dwene.default\extensions
[2009.07.29 19:53:45 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Ziksi\Application Data\Mozilla\Firefox\Profiles\lf2dwene.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009.12.11 20:41:50 | 000,000,000 | —D | M] (TVU Web Player) – C:\Documents and Settings\Ziksi\Application Data\Mozilla\Firefox\Profiles\lf2dwene.default\extensions\[removed]
[2010.12.15 21:42:46 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\Ziksi\Application Data\Mozilla\Firefox\Profiles\lf2dwene.default\extensions\[removed]
[2010.10.15 20:26:36 | 000,003,915 | —- | M] () – C:\Documents and Settings\Ziksi\Application Data\Mozilla\Firefox\Profiles\lf2dwene.default\searchplugins\sweetim.xml
[2011.03.06 15:53:31 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010.05.13 19:39:27 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.08.24 14:25:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.12.19 11:17:25 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2009.07.05 19:33:08 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010.11.12 18:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009.07.17 23:22:02 | 000,072,960 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2011.02.19 03:22:36 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2011.02.19 03:22:36 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2011.02.19 03:22:36 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2009.12.09 10:46:54 | 000,000,832 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\WebSearch.xml
[2011.02.19 03:22:36 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2004.08.04 02:07:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - No CLSID value found.
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [WebcamMaxMoniter] File not found
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: TaskMan - (I:\PRZHI\hladi.exe) - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Ziksi\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Ziksi\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.07.04 15:35:53 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010.02.23 20:49:19 | 000,000,000 | —D | M] - E:\AutoPatcher XP – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.avis - C:\WINDOWS\System32\ff_acm.acm ()
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.ffds - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.fvfw - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (38857157537431552)

========== Files/Folders - Created Within 30 Days ==========

[2011.03.06 14:48:38 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Ziksi\Recent
[2011.03.06 14:34:50 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2011.03.05 11:54:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Ziksi\Application Data\Google
[2011.03.05 11:53:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google
[2011.03.05 11:52:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Google SketchUp 8
[2011.03.05 11:52:38 | 000,000,000 | —D | C] – C:\Program Files\Google
[2011.03.03 18:02:23 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2011.02.21 16:02:32 | 000,000,000 | —D | C] – C:\Program Files\AV Vcs 7.0
[2004.08.04 02:07:00 | 000,502,272 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Ziksi\Application Data\Winlo.exe
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011.03.07 14:53:40 | 000,000,486 | —- | M] () – C:\WINDOWS\tasks\Automatic troubleshooting.job
[2011.03.07 14:40:38 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011.03.06 16:15:32 | 000,001,592 | —- | M] () – C:\Documents and Settings\Ziksi\Desktop\AviSub_Settings.ini
[2011.03.06 16:14:08 | 000,195,072 | —- | M] () – C:\Documents and Settings\Ziksi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.03.06 15:48:19 | 003,225,779 | —- | M] () – C:\Documents and Settings\Ziksi\My Documents\stampaci.PDF
[2011.03.06 14:34:51 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011.03.06 01:14:33 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011.03.05 22:20:48 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2011.03.05 11:52:49 | 000,001,762 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google SketchUp 8.lnk
[2011.03.03 18:00:25 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011.03.02 22:08:40 | 000,000,155 | —- | M] () – C:\WINDOWS\winamp.ini
[2011.03.02 20:28:50 | 000,001,620 | —- | M] () – C:\Documents and Settings\Ziksi\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011.03.02 20:28:50 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011.03.02 19:23:05 | 001,828,259 | —- | M] () – C:\Documents and Settings\Ziksi\My Documents\file.pdf
[2011.02.24 17:52:57 | 003,034,018 | —- | M] () – C:\Documents and Settings\Ziksi\My Documents\Lizenzen2010-01.pdf
[2011.02.20 23:07:42 | 000,001,831 | —- | M] () – C:\Documents and Settings\Ziksi\Application Data\Microsoft\Internet Explorer\Quick Launch\Subtitle Workshop.lnk
[2011.02.20 23:07:42 | 000,001,813 | —- | M] () – C:\Documents and Settings\Ziksi\Desktop\Subtitle Workshop.lnk
[2011.02.16 07:54:29 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011.02.12 23:04:54 | 000,076,748 | —- | M] () – C:\Documents and Settings\Ziksi\My Documents\FEST-oglas.jpg
[2011.02.11 17:23:09 | 000,202,511 | —- | M] () – C:\Documents and Settings\Ziksi\My Documents\view_file.pdf
[2011.02.09 12:43:33 | 000,007,555 | —- | M] () – C:\Documents and Settings\Ziksi\My Documents\Pepe.gif
[2011.02.08 21:21:29 | 000,164,972 | —- | M] () – C:\Documents and Settings\Ziksi\My Documents\Press Release EU bestselling authors 2009.pdf
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.03.06 16:31:41 | 003,225,779 | —- | C] () – C:\Documents and Settings\Ziksi\My Documents\stampaci.PDF
[2011.03.06 14:34:51 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011.03.06 14:14:09 | 000,001,592 | —- | C] () – C:\Documents and Settings\Ziksi\Desktop\AviSub_Settings.ini
[2011.03.05 11:52:49 | 000,001,762 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google SketchUp 8.lnk
[2011.03.02 19:23:05 | 001,828,259 | —- | C] () – C:\Documents and Settings\Ziksi\My Documents\file.pdf
[2011.02.24 17:52:57 | 003,034,018 | —- | C] () – C:\Documents and Settings\Ziksi\My Documents\Lizenzen2010-01.pdf
[2011.02.12 23:04:54 | 000,076,748 | —- | C] () – C:\Documents and Settings\Ziksi\My Documents\FEST-oglas.jpg
[2011.02.11 17:23:09 | 000,202,511 | —- | C] () – C:\Documents and Settings\Ziksi\My Documents\view_file.pdf
[2011.02.09 12:43:33 | 000,007,555 | —- | C] () – C:\Documents and Settings\Ziksi\My Documents\Pepe.gif
[2011.02.08 21:21:29 | 000,164,972 | —- | C] () – C:\Documents and Settings\Ziksi\My Documents\Press Release EU bestselling authors 2009.pdf
[2010.11.30 14:32:14 | 000,058,163 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2010.11.01 09:20:27 | 000,006,144 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010.08.29 13:56:19 | 000,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2010.02.20 17:33:07 | 000,278,728 | —- | C] () – C:\WINDOWS\System32\drivers\atksgt.sys
[2010.02.20 17:33:06 | 000,025,416 | —- | C] () – C:\WINDOWS\System32\drivers\lirsgt.sys
[2009.08.24 22:02:33 | 000,204,848 | —- | C] () – C:\WINDOWS\System32\gswin32c.exe
[2009.08.18 22:18:33 | 000,001,024 | —- | C] () – C:\WINDOWS\System32\grcauth2.dll
[2009.08.18 22:18:33 | 000,001,024 | —- | C] () – C:\WINDOWS\System32\grcauth1.dll
[2009.08.18 22:18:33 | 000,000,100 | —- | C] () – C:\WINDOWS\System32\prsgrc.dll
[2009.08.18 22:14:53 | 000,001,025 | —- | C] () – C:\WINDOWS\System32\sysprs7.dll
[2009.08.18 22:14:53 | 000,000,205 | —- | C] () – C:\WINDOWS\System32\lsprst7.dll
[2009.07.25 13:47:26 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\HPPLVS.dll
[2009.07.24 20:03:07 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009.07.14 22:11:06 | 000,000,000 | —- | C] () – C:\WINDOWS\Irremote.ini
[2009.07.14 22:07:54 | 000,000,108 | —- | C] () – C:\Documents and Settings\Ziksi\Application Data\default.pls
[2009.07.14 22:04:58 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009.07.07 16:05:24 | 000,195,072 | —- | C] () – C:\Documents and Settings\Ziksi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.07.04 18:00:36 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009.07.04 17:26:10 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009.07.04 17:25:06 | 001,471,112 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009.07.04 16:55:12 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\pxhpinst.exe
[2009.07.04 16:54:53 | 000,000,155 | —- | C] () – C:\WINDOWS\winamp.ini
[2009.07.04 16:34:51 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009.07.04 16:28:24 | 000,013,881 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009.07.04 16:15:06 | 000,000,804 | R— | C] () – C:\WINDOWS\System32\AsusSetup.ini
[2009.07.04 16:15:06 | 000,000,276 | R— | C] () – C:\WINDOWS\System32\raidmgmt.ini
[2009.07.04 16:14:33 | 000,014,129 | —- | C] () – C:\WINDOWS\Ascd_log.ini
[2009.07.04 16:13:34 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2009.07.04 16:13:19 | 000,010,288 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009.07.04 15:42:23 | 000,761,344 | —- | C] () – C:\WINDOWS\System32\autorun.exe
[2009.07.04 15:37:35 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009.07.04 15:33:17 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008.02.20 10:11:16 | 000,035,168 | —- | C] () – C:\WINDOWS\System32\drivers\epfwtdir.sys
[2007.07.18 17:42:42 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007.06.28 17:43:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007.06.28 17:43:00 | 001,626,112 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2007.06.28 17:43:00 | 001,474,560 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007.06.28 17:43:00 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2007.06.28 17:43:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007.06.28 17:43:00 | 001,018,772 | —- | C] () – C:\WINDOWS\System32\nvucode.bin
[2007.06.28 17:43:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007.06.28 17:43:00 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2007.06.28 17:43:00 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2007.06.28 17:43:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2004.08.04 02:07:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004.08.04 02:07:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004.08.04 02:07:00 | 000,403,664 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004.08.04 02:07:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004.08.04 02:07:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004.08.04 02:07:00 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\ieencode.dll
[2004.08.04 02:07:00 | 000,063,266 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004.08.04 02:07:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004.08.04 02:07:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004.08.04 02:07:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004.08.04 02:07:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004.08.04 02:07:00 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004.08.04 02:07:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2003.01.07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== Custom Scans ==========


< >

< %SYSTEMDRIVE%\*.* >
[2009.07.04 16:16:23 | 000,001,024 | —- | M] () – C:\.rnd
[2009.07.04 15:35:53 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009.11.06 23:33:54 | 000,000,223 | —- | M] () – C:\Boot.bak
[2010.05.16 23:12:52 | 000,000,293 | RHS- | M] () – C:\boot.ini
[2004.08.03 22:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010.05.15 23:16:53 | 000,012,693 | —- | M] () – C:\ComboFix.txt
[2009.07.04 15:35:53 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010.02.19 17:51:14 | 000,000,443 | —- | M] () – C:\INSTALL.LOG
[2009.07.04 15:35:53 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009.07.04 15:35:53 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004.08.04 02:07:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004.08.04 02:07:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2011.03.07 14:40:35 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009.07.04 15:35:34 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008.04.28 05:14:02 | 000,293,888 | —- | M] (Hewlett-Packard ) – C:\WINDOWS\system32\spool\prtprocs\w32x86\HP1006S.DLL
[2003.06.18 16:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010.04.17 00:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009.07.04 17:24:25 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009.07.04 17:24:25 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009.07.04 17:24:25 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009.07.04 15:35:58 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009.07.04 15:39:34 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Ziksi\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009.07.04 15:39:33 | 000,000,079 | —- | M] () – C:\Documents and Settings\Ziksi\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2009.07.11 20:19:48 | 001,831,936 | —- | M] () – C:\Documents and Settings\Ziksi\Desktop\AviSub.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-05-16 14:29:06

< End of report >

——————————————————————————————

OTL Extras logfile created on: 7.3.2011 15:10:37 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Ziksi\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 0000081A | Country: Serbia and Montenegro | Language: SRL | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 73,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 91,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 68,36 Gb Total Space | 12,77 Gb Free Space | 18,68% Space Free | Partition Type: NTFS
Drive D: | 74,84 Gb Total Space | 39,05 Gb Free Space | 52,18% Space Free | Partition Type: NTFS
Drive E: | 154,89 Gb Total Space | 32,88 Gb Free Space | 21,23% Space Free | Partition Type: NTFS

Computer Name: CASA01 | User Name: Ziksi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\CyberLink\PowerDVD9\PowerDVD9.exe" = C:\Program Files\CyberLink\PowerDVD9\PowerDVD9.exe:*:Enabled:CyberLink PowerDVD 9.0 – (CyberLink Corp.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe" = C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server – (Apache Software Foundation)
"C:\Program Files\CyberLink\PowerDVD9\PowerDVD Cinema\PowerDVDCinema.exe" = C:\Program Files\CyberLink\PowerDVD9\PowerDVD Cinema\PowerDVDCinema.exe:*:Enabled:CyberLink PowerDVD 9.0 – (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerDVD9\PowerDVD9.exe" = C:\Program Files\CyberLink\PowerDVD9\PowerDVD9.exe:*:Enabled:CyberLink PowerDVD 9.0 – (CyberLink Corp.)
"C:\Program Files\ApexDC++\ApexDC.exe" = C:\Program Files\ApexDC++\ApexDC.exe:*:Enabled:ApexDC++ - Pinnacle of File Sharing – (ApexDC++ Development Team)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE" = C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE:*:Enabled:SMLMProxy Module - HP1006MC.EXE – (Software 2000 Limited)
"C:\Program Files\SPSSInc\Statistics17\statistics.com" = C:\Program Files\SPSSInc\Statistics17\statistics.com:*:Disabled:Statistics17:com – (SPSS Inc)
"C:\Program Files\SPSSInc\Statistics17\SPSSWinWrapIDE.exe" = C:\Program Files\SPSSInc\Statistics17\SPSSWinWrapIDE.exe:*:Disabled:SPSS Basic Script Editor – (SPSS Inc.)
"C:\Program Files\SPSSInc\Statistics17\statistics.exe" = C:\Program Files\SPSSInc\Statistics17\statistics.exe:*:Disabled:Statistics17:exe – (SPSS Inc)
"C:\Documents and Settings\Ziksi\Application Data\Winlo.exe" = C:\Documents and Settings\Ziksi\Application Data\Winlo.exe:*:Enabled:Windows Messanger – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0FD95BFA-44E8-4AD5-954E-3407ADD55B06}" = Readon TV Movie Radio Player [removed]
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1F6423DE-7959-4178-80E0-023C7EAA5347}" = NVIDIA ForceWare Network Access Manager
"{20585CDC-114E-4372-986A-0686B1A37A30}" = Business Plan Pro 2007
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 23
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision
"{364EC092-93CF-4DDC-9D7A-7278452028E0}" = Logitech QuickCam
"{43602F34-1AA3-44FB-AEB2-D08C2C73743F}" = Paint.NET v3.36
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{46B65150-F8AA-42F2-94FB-2729A8AE5F7E}" = SPSS Statistics 17.0
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{7902E313-FF0F-4493-ACB1-A8147B78DCD0}" = HPSSupply
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA System Utility
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84B2CF01-194D-2284-B313-F2E0D78D1033}" = Nero 7 Demo
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.2
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{C10D6AB8-05BB-422D-AAE3-36D6E0381487}" = ESET NOD32 Antivirus
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D1BB4446-AE9C-4256-9A7F-4D46604D2462}" = Adobe Setup
"{D22002ED-EE2A-4CB1-A63D-430E62A2E8D8}" = Google SketchUp 8
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}" = TuneUp Utilities
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{FE3997D3-6B56-4AC4-A99C-9DDFC45359BF}" = TuneUp Utilities Language Pack (en-US)
"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_2ac78060bc5856b0c1cf873bb919b58" = Adobe Photoshop CS3
"ApexDC++" = ApexDC++ 1.3.5 (32-bit)
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"EMDB_is1" = EMDB 1.23
"FileRestorePlus™_is1" = FileRestorePlus™ 3.0.1.811
"Foxit Reader" = Foxit Reader
"GOM Player" = GOM Player
"HijackThis" = HijackThis 2.0.2
"HP LaserJet P1000 series" = HP LaserJet P1000 series
"InstallShield_{1F6423DE-7959-4178-80E0-023C7EAA5347}" = NVIDIA ForceWare Network Access Manager
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA System Utility
"InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Mozilla Firefox (3.6.15)" = Mozilla Firefox (3.6.15)
"NVIDIA Drivers" = NVIDIA Drivers
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"Ski Alpin 2005_0001" = Ski Alpin 2005
"Ski Jump International" = Ski Jump International 3.11 Shareware
"SubtitleWorkshop" = Subtitle Workshop 2.51
"Summer Athletics_is1" = Summer Athletics
"Total Commander XP_is1" = Total Commander 6.03a XP
"TuneUp Utilities" = TuneUp Utilities
"uTorrent" = µTorrent
"WIC" = Windows Imaging Component
"Winamp" = Winamp (remove only)
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"XnView_is1" = XnView 1.94.2

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4.3.2011 10:41:39 | Computer Name = CASA01 | Source = Application Hang | ID = 1002
Description = Hanging application rundll32.exe, version 5.1.2600.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4.3.2011 10:42:14 | Computer Name = CASA01 | Source = MsiInstaller | ID = 11921
Description = Product: Logitech QuickCam – Error 1921.Service LVCOMSer (LVCOMSer)
could not be stopped. Verify that you have sufficient privileges to stop system
services.

Error - 4.3.2011 11:09:56 | Computer Name = CASA01 | Source = Application Hang | ID = 1002
Description = Hanging application AviSub.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 5.3.2011 7:23:58 | Computer Name = CASA01 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module user32.dll, version 5.1.2600.2180, fault address 0x00027f4f.

Error - 5.3.2011 17:12:10 | Computer Name = CASA01 | Source = Application Error | ID = 1000
Description = Faulting application gom.exe, version 2.1.18.4762, faulting module
ntdll.dll, version 5.1.2600.2180, fault address 0x0002ae22.

Error - 5.3.2011 17:12:37 | Computer Name = CASA01 | Source = Application Error | ID = 1000
Description = Faulting application gom.exe, version 2.1.18.4762, faulting module
ntdll.dll, version 5.1.2600.2180, fault address 0x0002ae22.

Error - 5.3.2011 17:35:06 | Computer Name = CASA01 | Source = Application Error | ID = 1000
Description = Faulting application gom.exe, version 2.1.18.4762, faulting module
ntdll.dll, version 5.1.2600.2180, fault address 0x0002ae22.

Error - 5.3.2011 20:13:14 | Computer Name = CASA01 | Source = Application Hang | ID = 1002
Description = Hanging application AviSub.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 6.3.2011 9:21:59 | Computer Name = CASA01 | Source = Application Error | ID = 1000
Description = Faulting application divxmux.exe, version 0.0.0.0, faulting module
divxmux.exe, version 0.0.0.0, fault address 0x0001e636.

Error - 6.3.2011 9:22:32 | Computer Name = CASA01 | Source = Application Error | ID = 1000
Description = Faulting application divxmux.exe, version 0.0.0.0, faulting module
divxmux.exe, version 0.0.0.0, fault address 0x0001e636.

[ System Events ]
Error - 4.3.2011 10:36:05 | Computer Name = CASA01 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 4.3.2011 10:42:21 | Computer Name = CASA01 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 4.3.2011 10:51:55 | Computer Name = CASA01 | Source = Service Control Manager | ID = 7000
Description = The WebcamMax, WDM Video Capture service failed to start due to the
following error: %%1058

Error - 5.3.2011 6:23:16 | Computer Name = CASA01 | Source = Service Control Manager | ID = 7000
Description = The WebcamMax, WDM Video Capture service failed to start due to the
following error: %%1058

Error - 5.3.2011 7:29:07 | Computer Name = CASA01 | Source = Service Control Manager | ID = 7000
Description = The WebcamMax, WDM Video Capture service failed to start due to the
following error: %%1058

Error - 5.3.2011 9:10:37 | Computer Name = CASA01 | Source = Service Control Manager | ID = 7000
Description = The WebcamMax, WDM Video Capture service failed to start due to the
following error: %%1058

Error - 5.3.2011 16:42:51 | Computer Name = CASA01 | Source = Service Control Manager | ID = 7000
Description = The WebcamMax, WDM Video Capture service failed to start due to the
following error: %%1058

Error - 6.3.2011 16:11:19 | Computer Name = CASA01 | Source = Service Control Manager | ID = 7000
Description = The WebcamMax, WDM Video Capture service failed to start due to the
following error: %%1058

Error - 7.3.2011 9:42:17 | Computer Name = CASA01 | Source = Service Control Manager | ID = 7000
Description = The WebcamMax, WDM Video Capture service failed to start due to the
following error: %%1058

Error - 7.3.2011 10:01:40 | Computer Name = CASA01 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}


< End of report >
———————————————————————————————–


etsvcs
drivers32
%SYSTEMDRIVE%\*.*
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\Fonts\*.exe
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lnk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%PROGRAMFILES%\Internet Explorer\*.dat
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Desktop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
%systemroot%\AppPatch\Custom\*.*
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

————————————————————————————————-

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-03-07 16:12:00
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\0000006a WDC_WD3200AAJS-98B4A0 rev.01.03A01
Running: kg2pj5up.exe; Driver: C:\DOCUME~1\Ziksi\LOCALS~1\Temp\fwtdqpow.sys


—- System - GMER 1.0.15 —-

SSDT spav.sys ZwCreateKey [0xBA6AF0E0]
SSDT spav.sys ZwEnumerateKey [0xBA6C9E4C]
SSDT spav.sys ZwEnumerateValueKey [0xBA6CA1DA]
SSDT spav.sys ZwOpenKey [0xBA6AF0C0]
SSDT spav.sys ZwQueryKey [0xBA6CA2B2]
SSDT spav.sys ZwQueryValueKey [0xBA6CA132]
SSDT spav.sys ZwSetValueKey [0xBA6CA344]

INT 0x63 ? 89AE7C88
INT 0x73 ? 89D5BC88
INT 0x83 ? 89D5BC88
INT 0xB1 ? 89DCDC88
INT 0xB1 ? 89DCDC88
INT 0xB1 ? 89DD0C88

—- Kernel code sections - GMER 1.0.15 —-

? spav.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload BA14462C 5 Bytes JMP 89AE71D8
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB994A380, 0x2FF527, 0xE8000020]
init C:\WINDOWS\system32\drivers\Senfilt.sys entry point in "init" section [0xB64BDA00]
.reloc C:\WINDOWS\system32\drivers\acedrv11.sys section is executable [0xB5B72600, 0x25B0C, 0xE0000060]
.text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0xB5B13300, 0x3ACC8, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xBABA8300, 0x1B7E, 0xE8000020]
.text C:\Program Files\CyberLink\PowerDVD9\000.fcl section is writeable [0xB5790000, 0x2892, 0xE8000020]
.vmp2 C:\Program Files\CyberLink\PowerDVD9\000.fcl entry point in ".vmp2" section [0xB57B3050]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\firefox.exe[1372] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1928] kernel32.dll!SetUnhandledExceptionFilter 7C810386 4 Bytes [C2, 04, 00, 00]

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 89D5A1F8

AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)

Device \Driver\sptd \Device\856058746 spav.sys
Device \Driver\usbohci \Device\USBPDO-0 89AE51F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 89D5C1F8
Device \Driver\dmio \Device\DmControl\DmConfig 89D5C1F8
Device \Driver\dmio \Device\DmControl\DmPnP 89D5C1F8
Device \Driver\dmio \Device\DmControl\DmInfo 89D5C1F8
Device \Driver\usbehci \Device\USBPDO-1 89AD81F8
Device \Driver\PCI_PNP9996 \Device\00000047 spav.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{DF376222-CC01-4BD3-A499-031027A0043E} 898DB470

AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys

Device \Driver\Ftdisk \Device\HarddiskVolume1 89DCE1F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 89DCE1F8
Device \Driver\Cdrom \Device\CdRom0 89A9D1F8
Device \Driver\Ftdisk \Device\HarddiskVolume3 89DCE1F8
Device \Driver\atapi \Device\Ide\IdePort0 89DCD1F8
Device \Driver\atapi \Device\Ide\IdePort1 89DCD1F8
Device \Driver\atapi \Device\Ide\IdePort2 89DCD1F8
Device \Driver\atapi \Device\Ide\IdePort3 89DCD1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T1L0-14 89DCD1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-c 89DCD1F8
Device \Driver\Cdrom \Device\CdRom1 89A9D1F8
Device \Driver\Cdrom \Device\CdRom2 89A9D1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 898DB470
Device \Driver\NetBT \Device\NetbiosSmb 898DB470
Device \Driver\nvata \Device\0000006a 89D5B1F8
Device \Driver\nvata \Device\0000006b 89D5B1F8
Device \Driver\usbohci \Device\USBFDO-0 89AE51F8
Device \Driver\usbehci \Device\USBFDO-1 89AD81F8
Device \Driver\nvata \Device\NvAta0 89D5B1F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8921C1F8
Device \Driver\nvata \Device\NvAta1 89D5B1F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8921C1F8
Device \Driver\Ftdisk \Device\FtControl 89DCE1F8
Device \Driver\alzpk66n \Device\Scsi\alzpk66n1 89B531F8
Device \FileSystem\Cdfs \Cdfs 898E2470

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x82 0x74 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x2D 0x3B 0x0E 0xFE …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xF6 0x2E 0x21 0x0F …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0xA0 0x02 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0xD4 0x2F 0x54 0xAA …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0x63 0xF7 0x96 0x9C …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq1@hdf12 0x4D 0x16 0x1A 0x24 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x82 0x74 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x2D 0x3B 0x0E 0xFE …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xF6 0x2E 0x21 0x0F …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0xA0 0x02 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0xD4 0x2F 0x54 0xAA …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0x63 0xF7 0x96 0x9C …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq1@hdf12 0x4D 0x16 0x1A 0x24 …

—- EOF - GMER 1.0.15 —-
———————————————————————-

Results of screen317's Security Check version 0.99.9
Windows XP Service Pack 2
Out of date service pack!!
Internet Explorer 6 Out of date!
``````````````````````````````
Antivirus/Firewall Check:

Windows Security Center service is not running! This report may not be accurate!
Windows Firewall Enabled!
ESET NOD32 Antivirus
Antivirus up to date!
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
HijackThis 2.0.2
TuneUp Utilities
TuneUp Utilities Language Pack (en-US)
CCleaner
Java™ 6 Update 23
Out of date Java installed!
Adobe Flash Player 10.2.152.32
Adobe Reader 9.4.2
Out of date Adobe Reader installed!
Mozilla Firefox (3.6.15)
````````````````````````````````
Process Check:
objlist.exe by Laurent

``````````End of Log````````````
—————————————————————————————–


Waiting for ur instructions.

Thanks in advance.
Hi,

Your copy of XP appears to be severely outdated. Is there any reason that you avoid updating it?

You have ( µTorrent ), a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.internetworldstats.com/articles…cles/art053.htm
See Clean/Infected P2P Programs here

I would recommend that you uninstall it, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


===================================================

We Need to Diagnose a Possible Problem with WGA
This may be preventing you from installing that service pack.
  • Please download MGADiag and save it to your desktop.
  • Double click the [external image: Posted Image] icon on your desktop.
  • Push [external image: Posted Image]
  • Push [external image: Posted Image]
  • Go to Start -> Run and type in "Notepad"
  • Go to Edit -> Paste in notepad.
  • x out all of the numbers and letters in the line beginning with "Windows Product Key:"
  • Copy and paste that log here.
===================================================

On your next reply please post :
MGADiag log


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
I m sorry, I dont understand what x out means. English is not my language, so i dont get it. If you can write in different words,pls. And is there some other program for removing programs, I sometimes can not delete it or remove anything with add/remove. Have a nice day.
You can skip the number 7 instructions. Please continue with the rest of the instructions. Thank you.
I appreciate ur help so far, but I had a friend that came to my house, and he helped me and fixed all problems. Sorry for bothering you, thank you for you time and help.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI