This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe problem (Suspected of virus / malware)

31 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi everyone . Need help here .

Basically internet connection was running fine all the while until yesterday . When i type urls into the browser , normally it comes out quite quickly . However , i realised that the browser keeps getting timed out since yesterday .

Also noticed that ping.exe is running in my task manager and taking up loads of CPU usage .


Here is my hijackthis log file for a start . Any help is appreciated .


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at PM 8:34:26, on 24/10/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\EAVService\EavService.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\RTHDCPL.EXE
D:\downloads\FLVSrvc.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\FlashGet Network\FlashGet 3\flashget3.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Update\1.3.21.79\GoogleCrashHandler.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\System32\ping.exe
C:\WINDOWS\system32\conime.exe
C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\TANST\My Documents\Downloads\HiJackThis.exe

O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: FlashGetBHO - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Documents and Settings\DAISYTAY\Application Data\FlashGetBHO\FlashGetBHO3.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe
O4 - HKLM\..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
O4 - HKLM\..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [EAVSET] C:\Program Files\ESET\EAVSET\EAVSET.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BabylonToolbar] "C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.15.13\BabylonToolbarsrv.exe" /md I
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Freecorder FLV Service] "D:\downloads\FLVSrvc.exe" /run
O4 - HKLM\..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…uot;ver=9.0.872
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [FlashGet 3] "C:\Program Files\FlashGet Network\FlashGet 3\flashget3.exe" -minimize
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-21-2228970593-2351082760-789675871-1006\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'DAISYTAY')
O4 - HKUS\S-1-5-21-2228970593-2351082760-789675871-1006\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'DAISYTAY')
O4 - HKUS\S-1-5-21-2228970593-2351082760-789675871-1006\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'DAISYTAY')
O4 - HKUS\S-1-5-21-2228970593-2351082760-789675871-1006\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" (User 'DAISYTAY')
O4 - HKUS\S-1-5-21-2228970593-2351082760-789675871-1006\..\Run: [FlashGet 3] "C:\Program Files\FlashGet Network\FlashGet 3\Flashget3.exe" -minimize (User 'DAISYTAY')
O4 - HKUS\S-1-5-21-2228970593-2351082760-789675871-1006\..\Run: [Google Update] "C:\Documents and Settings\DAISYTAY\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (User 'DAISYTAY')
O4 - HKUS\S-1-5-21-2228970593-2351082760-789675871-1006\..\Run: [JP595IR86O] C:\DOCUME~1\DAISYTAY\LOCALS~1\Temp\Fd1.exe (User 'DAISYTAY')
O4 - HKUS\S-1-5-21-2228970593-2351082760-789675871-1006\..\Run: [NtWqIVLZEWZU] C:\DOCUME~1\DAISYTAY\LOCALS~1\Temp\Fd2.exe (User 'DAISYTAY')
O4 - HKUS\S-1-5-21-2228970593-2351082760-789675871-1006\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent (User 'DAISYTAY')
O4 - HKUS\S-1-5-21-2228970593-2351082760-789675871-1006\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe (User 'DAISYTAY')
O4 - HKUS\S-1-5-21-2228970593-2351082760-789675871-1006\..\Run: [KuGou] "C:\Program Files\KuGou\KuGou2011\KuGoo.exe" min (User 'DAISYTAY')
O4 - HKUS\S-1-5-21-2228970593-2351082760-789675871-1006\..\Run: [AdobeBridge] (User 'DAISYTAY')
O4 - HKUS\S-1-5-21-2228970593-2351082760-789675871-1006\..\Run: [Ngbabn] C:\Documents and Settings\DAISYTAY\Application Data\Ngbabn.exe (User 'DAISYTAY')
O4 - HKUS\S-1-5-21-2228970593-2351082760-789675871-1006\..\Run: [Windows Login access] C:\Documents and Settings\DAISYTAY\Application Data\windows.exe (User 'DAISYTAY')
O4 - S-1-5-21-2228970593-2351082760-789675871-1006 Startup: IMVU.lnk = C:\Documents and Settings\DAISYTAY\Application Data\IMVUClient\IMVUQualityAgent.exe (User 'DAISYTAY')
O4 - S-1-5-21-2228970593-2351082760-789675871-1006 Startup: 启动飞速土豆.lnk = ? (User 'DAISYTAY')
O4 - S-1-5-21-2228970593-2351082760-789675871-1006 Startup: 风行.lnk = D:\Downloads\Funshion.exe (User 'DAISYTAY')
O4 - S-1-5-21-2228970593-2351082760-789675871-1006 User Startup: IMVU.lnk = C:\Documents and Settings\DAISYTAY\Application Data\IMVUClient\IMVUQualityAgent.exe (User 'DAISYTAY')
O4 - S-1-5-21-2228970593-2351082760-789675871-1006 User Startup: 启动飞速土豆.lnk = ? (User 'DAISYTAY')
O4 - S-1-5-21-2228970593-2351082760-789675871-1006 User Startup: 风行.lnk = D:\Downloads\Funshion.exe (User 'DAISYTAY')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: SuperHybridEngine.lnk = ?
O8 - Extra context menu item: &使用快车(FlashGet)下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &使用快车(FlashGet)下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://software.kuaiche.com
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-SG/a-UNO1/GAME_UNO1.cab
O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://dist.globalgamecdn.com/dist/neffy/NeffyLauncher.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: KuGoo - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\WINDOWS\system32\KuGoo3DownXControl.ocx
O18 - Protocol: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\WINDOWS\system32\KuGoo3DownXControl.ocx
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: EavService - Unknown owner - C:\Program Files\ESET\EAVService\EavService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe

–
End of file - 15755 bytes
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)












  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hi . Many thanks for the response . While waiting for a response , I got impatient for a while and did further scans in safe mode and normal mode and removing threats as and when they come . I hope its still curable though and i promise not to do any more things on my own from now onwards without your instruction . Anyway , logs from TDSSkiller 06:10:48.0484 3656 TDSS rootkit removing tool [removed] Oct 21 2011 11:23:48 06:10:49.0421 3656 ============================================================ 06:10:49.0421 3656 Current date / time: 2011/10/25 06:10:49.0421 06:10:49.0421 3656 SystemInfo: 06:10:49.0421 3656 06:10:49.0421 3656 OS Version: 5.1.2600 ServicePack: 3.0 06:10:49.0421 3656 Product type: Workstation 06:10:49.0421 3656 ComputerName: TSTIOH5353 06:10:49.0421 3656 UserName: TANST 06:10:49.0421 3656 Windows directory: C:\WINDOWS 06:10:49.0421 3656 System windows directory: C:\WINDOWS 06:10:49.0421 3656 Processor architecture: Intel x86 06:10:49.0421 3656 Number of processors: 2 06:10:49.0421 3656 Page size: 0x1000 06:10:49.0421 3656 Boot type: Normal boot 06:10:49.0421 3656 ============================================================ 06:10:50.0609 3656 Initialize success 06:11:19.0375 3548 ============================================================ 06:11:19.0375 3548 Scan started 06:11:19.0375 3548 Mode: Manual; 06:11:19.0375 3548 ============================================================ 06:11:19.0671 3548 Abiosdsk - ok 06:11:19.0703 3548 abp480n5 - ok 06:11:19.0765 3548 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 06:11:19.0765 3548 ACPI - ok 06:11:19.0796 3548 adpu160m - ok 06:11:19.0843 3548 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 06:11:19.0859 3548 aec - ok 06:11:19.0921 3548 AFD (7618d5218f2a614672ec61a80d854a37) C:\WINDOWS\System32\drivers\afd.sys 06:11:19.0921 3548 AFD - ok 06:11:19.0937 3548 Aha154x - ok 06:11:19.0953 3548 aic78u2 - ok 06:11:19.0968 3548 aic78xx - ok 06:11:20.0015 3548 AliIde - ok 06:11:20.0031 3548 amsint - ok 06:11:20.0046 3548 asc - ok 06:11:20.0078 3548 asc3350p - ok 06:11:20.0093 3548 asc3550 - ok 06:11:20.0156 3548 AsusACPI (784fcb197f9a50a419d8ce4980655ae4) C:\WINDOWS\system32\DRIVERS\ASUSACPI.sys 06:11:20.0171 3548 AsusACPI - ok 06:11:20.0218 3548 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 06:11:20.0218 3548 AsyncMac - ok 06:11:20.0281 3548 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 06:11:20.0281 3548 atapi - ok 06:11:20.0296 3548 Atdisk - ok 06:11:20.0343 3548 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 06:11:20.0359 3548 Atmarpc - ok 06:11:20.0421 3548 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 06:11:20.0421 3548 audstub - ok 06:11:20.0453 3548 BCM42RLY - ok 06:11:20.0515 3548 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 06:11:20.0515 3548 Beep - ok 06:11:20.0546 3548 br3gmdm - ok 06:11:20.0687 3548 btaudio (faba1418646a2b433c0bded6ff92d2fa) C:\WINDOWS\system32\drivers\btaudio.sys 06:11:20.0703 3548 btaudio - ok 06:11:20.0781 3548 BTDriver (2f9f111d31aa3fbbe5781d829a4524e6) C:\WINDOWS\system32\DRIVERS\btport.sys 06:11:20.0781 3548 BTDriver - ok 06:11:20.0875 3548 BTKRNL (aef038061bc1cafb4865d43a85beb1a1) C:\WINDOWS\system32\DRIVERS\btkrnl.sys 06:11:20.0875 3548 BTKRNL - ok 06:11:20.0937 3548 BTWDNDIS (80f61de965c116051614ac2f04222ff7) C:\WINDOWS\system32\DRIVERS\btwdndis.sys 06:11:20.0953 3548 BTWDNDIS - ok 06:11:20.0984 3548 btwhid (949eca9c56f657c06d3166d51f3226c7) C:\WINDOWS\system32\DRIVERS\btwhid.sys 06:11:20.0984 3548 btwhid - ok 06:11:21.0015 3548 BTWUSB (179a37c86fd2b9cc28eb93d093d394c7) C:\WINDOWS\system32\Drivers\btwusb.sys 06:11:21.0015 3548 BTWUSB - ok 06:11:21.0078 3548 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 06:11:21.0078 3548 cbidf2k - ok 06:11:21.0125 3548 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 06:11:21.0125 3548 CCDECODE - ok 06:11:21.0156 3548 cd20xrnt - ok 06:11:21.0218 3548 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 06:11:21.0218 3548 Cdaudio - ok 06:11:21.0328 3548 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 06:11:21.0328 3548 Cdfs - ok 06:11:21.0375 3548 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 06:11:21.0390 3548 Cdrom - ok 06:11:21.0406 3548 Changer - ok 06:11:21.0500 3548 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 06:11:21.0500 3548 CmBatt - ok 06:11:21.0515 3548 CmdIde - ok 06:11:21.0546 3548 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 06:11:21.0546 3548 Compbatt - ok 06:11:21.0593 3548 Cpqarray - ok 06:11:21.0640 3548 dac2w2k - ok 06:11:21.0656 3548 dac960nt - ok 06:11:21.0718 3548 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 06:11:21.0718 3548 Disk - ok 06:11:21.0812 3548 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 06:11:21.0859 3548 dmboot - ok 06:11:21.0968 3548 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 06:11:21.0968 3548 dmio - ok 06:11:22.0046 3548 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 06:11:22.0046 3548 dmload - ok 06:11:22.0140 3548 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 06:11:22.0156 3548 DMusic - ok 06:11:22.0187 3548 dpti2o - ok 06:11:22.0218 3548 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 06:11:22.0234 3548 drmkaud - ok 06:11:22.0250 3548 EagleNT - ok 06:11:22.0359 3548 ewusbnet (9032405f762f1afa92dfef99cb078306) C:\WINDOWS\system32\DRIVERS\ewusbnet.sys 06:11:22.0359 3548 ewusbnet - ok 06:11:22.0437 3548 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 06:11:22.0437 3548 Fastfat - ok 06:11:22.0515 3548 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 06:11:22.0515 3548 Fdc - ok 06:11:22.0562 3548 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 06:11:22.0578 3548 Fips - ok 06:11:22.0609 3548 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 06:11:22.0609 3548 Flpydisk - ok 06:11:22.0687 3548 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 06:11:22.0687 3548 FltMgr - ok 06:11:22.0765 3548 fssfltr (c6ee3a87fe609d3e1db9dbd072a248de) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys 06:11:22.0765 3548 fssfltr - ok 06:11:22.0828 3548 FsVga (455f778ee14368468560bd7cb8c854d0) C:\WINDOWS\system32\DRIVERS\fsvga.sys 06:11:22.0828 3548 FsVga - ok 06:11:22.0859 3548 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 06:11:22.0859 3548 Fs_Rec - ok 06:11:22.0937 3548 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 06:11:22.0937 3548 Ftdisk - ok 06:11:23.0000 3548 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 06:11:23.0000 3548 Gpc - ok 06:11:23.0140 3548 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 06:11:23.0140 3548 HDAudBus - ok 06:11:23.0218 3548 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 06:11:23.0218 3548 HidUsb - ok 06:11:23.0234 3548 hpn - ok 06:11:23.0312 3548 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 06:11:23.0328 3548 HTTP - ok 06:11:23.0421 3548 hwdatacard (60aec3f4ec355d9f46d545a0fa08ce87) C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys 06:11:23.0437 3548 hwdatacard - ok 06:11:23.0500 3548 hwusbfake (b93d3c81ef1d372dc5bd5e6275362e1a) C:\WINDOWS\system32\DRIVERS\ewusbfake.sys 06:11:23.0500 3548 hwusbfake - ok 06:11:23.0531 3548 i2omgmt - ok 06:11:23.0546 3548 i2omp - ok 06:11:23.0609 3548 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 06:11:23.0609 3548 i8042prt - ok 06:11:23.0906 3548 ialm (0f68e2ec713f132ffb19e45415b09679) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 06:11:24.0156 3548 ialm - ok 06:11:24.0312 3548 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 06:11:24.0312 3548 Imapi - ok 06:11:24.0359 3548 ini910u - ok 06:11:24.0609 3548 IntcAzAudAddService (47c79f7e330cbb829934d00f64d55fc9) C:\WINDOWS\system32\drivers\RtkHDAud.sys 06:11:24.0671 3548 IntcAzAudAddService - ok 06:11:24.0765 3548 IntelIde - ok 06:11:24.0812 3548 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 06:11:24.0812 3548 intelppm - ok 06:11:24.0859 3548 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 06:11:24.0875 3548 Ip6Fw - ok 06:11:24.0937 3548 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 06:11:24.0937 3548 IpFilterDriver - ok 06:11:24.0968 3548 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 06:11:24.0968 3548 IpInIp - ok 06:11:25.0031 3548 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 06:11:25.0031 3548 IpNat - ok 06:11:25.0093 3548 IPSec (ec19e8b726b105b41915ed3061ccc3e0) C:\WINDOWS\system32\DRIVERS\ipsec.sys 06:11:25.0093 3548 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\ipsec.sys. Real md5: ec19e8b726b105b41915ed3061ccc3e0, Fake md5: 23c74d75e36e7158768dd63d92789a91 06:11:25.0093 3548 IPSec ( Rootkit.Win32.ZAccess.h ) - infected 06:11:25.0093 3548 IPSec - detected Rootkit.Win32.ZAccess.h (0) 06:11:25.0156 3548 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 06:11:25.0156 3548 IRENUM - ok 06:11:25.0234 3548 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 06:11:25.0234 3548 isapnp - ok 06:11:25.0312 3548 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 06:11:25.0312 3548 Kbdclass - ok 06:11:25.0390 3548 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 06:11:25.0390 3548 kbdhid - ok 06:11:25.0468 3548 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 06:11:25.0484 3548 kmixer - ok 06:11:25.0562 3548 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 06:11:25.0562 3548 KSecDD - ok 06:11:25.0625 3548 Ktp (8cba0d1da71efba17d15dde1a5ffbb43) C:\WINDOWS\system32\DRIVERS\ETD.sys 06:11:25.0640 3548 Ktp - ok 06:11:25.0687 3548 L1e (303627228dd739d98289679901a38c8f) C:\WINDOWS\system32\DRIVERS\l1e51x86.sys 06:11:25.0687 3548 L1e - ok 06:11:25.0718 3548 lbrtfdc - ok 06:11:25.0828 3548 massfilter (f0435fe3c1ec2659d2bbf073ca0752ee) C:\WINDOWS\system32\DRIVERS\massfilter.sys 06:11:25.0828 3548 massfilter - ok 06:11:25.0875 3548 MBAMProtector (69a6268d7f81e53d568ab4e7e991caf3) C:\WINDOWS\system32\drivers\mbam.sys 06:11:25.0875 3548 MBAMProtector - ok 06:11:25.0968 3548 Mkd2kfNt (6f4d79ea861137ef2f9078e265c2aa83) C:\WINDOWS\system32\drivers\Mkd2kfNt.sys 06:11:25.0984 3548 Mkd2kfNt - ok 06:11:26.0015 3548 Mkd2Nadr (fe7925784f6801e983b41ec118ef62ac) C:\WINDOWS\system32\drivers\Mkd2Nadr.sys 06:11:26.0015 3548 Mkd2Nadr - ok 06:11:26.0078 3548 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 06:11:26.0078 3548 mnmdd - ok 06:11:26.0171 3548 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 06:11:26.0171 3548 Modem - ok 06:11:26.0218 3548 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 06:11:26.0234 3548 Mouclass - ok 06:11:26.0265 3548 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 06:11:26.0281 3548 mouhid - ok 06:11:26.0328 3548 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 06:11:26.0328 3548 MountMgr - ok 06:11:26.0375 3548 mraid35x - ok 06:11:26.0421 3548 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 06:11:26.0421 3548 MRxDAV - ok 06:11:26.0500 3548 MRxSmb (0ea4d8ed179b75f8afa7998ba22285ca) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 06:11:26.0515 3548 MRxSmb - ok 06:11:26.0562 3548 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 06:11:26.0562 3548 Msfs - ok 06:11:26.0671 3548 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 06:11:26.0671 3548 MSKSSRV - ok 06:11:26.0718 3548 msloop (64e8b7c65eb4796939c0f64f8170821b) C:\WINDOWS\system32\DRIVERS\loop.sys 06:11:26.0718 3548 msloop - ok 06:11:26.0765 3548 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 06:11:26.0765 3548 MSPCLOCK - ok 06:11:26.0796 3548 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 06:11:26.0796 3548 MSPQM - ok 06:11:26.0875 3548 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 06:11:26.0875 3548 mssmbios - ok 06:11:26.0953 3548 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 06:11:26.0953 3548 MSTEE - ok 06:11:27.0000 3548 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 06:11:27.0015 3548 Mup - ok 06:11:27.0062 3548 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 06:11:27.0062 3548 NABTSFEC - ok 06:11:27.0140 3548 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 06:11:27.0140 3548 NDIS - ok 06:11:27.0187 3548 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 06:11:27.0187 3548 NdisIP - ok 06:11:27.0265 3548 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 06:11:27.0265 3548 NdisTapi - ok 06:11:27.0312 3548 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 06:11:27.0328 3548 Ndisuio - ok 06:11:27.0359 3548 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 06:11:27.0375 3548 NdisWan - ok 06:11:27.0406 3548 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 06:11:27.0421 3548 NDProxy - ok 06:11:27.0453 3548 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 06:11:27.0453 3548 NetBIOS - ok 06:11:27.0515 3548 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 06:11:27.0515 3548 NetBT - ok 06:11:27.0656 3548 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 06:11:27.0656 3548 Npfs - ok 06:11:27.0734 3548 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 06:11:27.0750 3548 Ntfs - ok 06:11:27.0828 3548 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 06:11:27.0828 3548 Null - ok 06:11:27.0906 3548 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 06:11:27.0921 3548 NwlnkFlt - ok 06:11:27.0953 3548 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 06:11:27.0953 3548 NwlnkFwd - ok 06:11:28.0031 3548 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys 06:11:28.0046 3548 Parport - ok 06:11:28.0078 3548 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 06:11:28.0078 3548 PartMgr - ok 06:11:28.0125 3548 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 06:11:28.0125 3548 ParVdm - ok 06:11:28.0187 3548 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 06:11:28.0187 3548 PCI - ok 06:11:28.0218 3548 pcidump - ok 06:11:28.0281 3548 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 06:11:28.0281 3548 PCIIde - ok 06:11:28.0343 3548 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 06:11:28.0343 3548 Pcmcia - ok 06:11:28.0390 3548 PDCOMP - ok 06:11:28.0437 3548 PDFRAME - ok 06:11:28.0437 3548 PDRELI - ok 06:11:28.0468 3548 PDRFRAME - ok 06:11:28.0500 3548 perc2 - ok 06:11:28.0546 3548 perc2hib - ok 06:11:28.0671 3548 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 06:11:28.0671 3548 PptpMiniport - ok 06:11:28.0718 3548 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 06:11:28.0718 3548 PSched - ok 06:11:28.0750 3548 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 06:11:28.0750 3548 Ptilink - ok 06:11:28.0781 3548 ql1080 - ok 06:11:28.0812 3548 Ql10wnt - ok 06:11:28.0828 3548 ql12160 - ok 06:11:28.0859 3548 ql1240 - ok 06:11:28.0890 3548 ql1280 - ok 06:11:28.0968 3548 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 06:11:28.0968 3548 RasAcd - ok 06:11:29.0031 3548 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 06:11:29.0031 3548 Rasl2tp - ok 06:11:29.0125 3548 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 06:11:29.0125 3548 RasPppoe - ok 06:11:29.0171 3548 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 06:11:29.0171 3548 Raspti - ok 06:11:29.0281 3548 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 06:11:29.0281 3548 Rdbss - ok 06:11:29.0375 3548 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 06:11:29.0375 3548 RDPCDD - ok 06:11:29.0453 3548 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 06:11:29.0468 3548 RDPWD - ok 06:11:29.0546 3548 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 06:11:29.0546 3548 redbook - ok 06:11:29.0671 3548 RT80x86 (162d6aee49372b9ce17c418cc5cde7b5) C:\WINDOWS\system32\DRIVERS\RT2860.sys 06:11:29.0718 3548 RT80x86 - ok 06:11:29.0828 3548 SASDIFSV (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 06:11:29.0828 3548 SASDIFSV - ok 06:11:29.0859 3548 SASKUTIL (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 06:11:29.0859 3548 SASKUTIL - ok 06:11:30.0015 3548 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 06:11:30.0031 3548 Secdrv - ok 06:11:30.0078 3548 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys 06:11:30.0078 3548 Serial - ok 06:11:30.0140 3548 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 06:11:30.0140 3548 Sfloppy - ok 06:11:30.0203 3548 Simbad - ok 06:11:30.0250 3548 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 06:11:30.0250 3548 SLIP - ok 06:11:30.0281 3548 Sparrow - ok 06:11:30.0328 3548 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 06:11:30.0328 3548 splitter - ok 06:11:30.0421 3548 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 06:11:30.0421 3548 sr - ok 06:11:30.0515 3548 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 06:11:30.0531 3548 Srv - ok 06:11:30.0593 3548 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 06:11:30.0593 3548 streamip - ok 06:11:30.0640 3548 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 06:11:30.0640 3548 swenum - ok 06:11:30.0687 3548 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 06:11:30.0703 3548 swmidi - ok 06:11:30.0734 3548 symc810 - ok 06:11:30.0765 3548 symc8xx - ok 06:11:30.0765 3548 sym_hi - ok 06:11:30.0843 3548 sym_u3 - ok 06:11:30.0906 3548 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 06:11:30.0906 3548 sysaudio - ok 06:11:30.0984 3548 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 06:11:31.0000 3548 Tcpip - ok 06:11:31.0046 3548 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 06:11:31.0046 3548 TDPIPE - ok 06:11:31.0093 3548 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 06:11:31.0093 3548 TDTCP - ok 06:11:31.0125 3548 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 06:11:31.0125 3548 TermDD - ok 06:11:31.0171 3548 TosIde - ok 06:11:31.0312 3548 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 06:11:31.0328 3548 Udfs - ok 06:11:31.0343 3548 ultra - ok 06:11:31.0390 3548 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 06:11:31.0406 3548 Update - ok 06:11:31.0484 3548 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 06:11:31.0484 3548 usbaudio - ok 06:11:31.0531 3548 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 06:11:31.0546 3548 usbccgp - ok 06:11:31.0656 3548 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 06:11:31.0671 3548 usbehci - ok 06:11:31.0687 3548 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 06:11:31.0687 3548 usbhub - ok 06:11:31.0718 3548 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 06:11:31.0734 3548 usbprint - ok 06:11:31.0781 3548 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 06:11:31.0781 3548 usbscan - ok 06:11:31.0828 3548 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 06:11:31.0828 3548 usbstor - ok 06:11:31.0875 3548 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 06:11:31.0875 3548 usbuhci - ok 06:11:31.0937 3548 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 06:11:31.0937 3548 usbvideo - ok 06:11:32.0000 3548 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 06:11:32.0000 3548 VgaSave - ok 06:11:32.0015 3548 ViaIde - ok 06:11:32.0078 3548 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 06:11:32.0078 3548 VolSnap - ok 06:11:32.0140 3548 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 06:11:32.0140 3548 Wanarp - ok 06:11:32.0156 3548 WDICA - ok 06:11:32.0203 3548 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 06:11:32.0203 3548 wdmaud - ok 06:11:32.0359 3548 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 06:11:32.0359 3548 WSTCODEC - ok 06:11:32.0421 3548 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 06:11:32.0421 3548 WudfPf - ok 06:11:32.0453 3548 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 06:11:32.0453 3548 WudfRd - ok 06:11:32.0515 3548 WUSB54GPV4SRV (70aeec67e87a2002e6b2cc353d56e222) C:\WINDOWS\system32\DRIVERS\rt2500usb.sys 06:11:32.0531 3548 WUSB54GPV4SRV - ok 06:11:32.0593 3548 ZTEusbmdm6k (b8b466103280e45e391e876f05122607) C:\WINDOWS\system32\DRIVERS\ZTEusbmdm6k.sys 06:11:32.0609 3548 ZTEusbmdm6k - ok 06:11:32.0640 3548 ZTEusbnet (911ba85906bc7602c73441502abfb565) C:\WINDOWS\system32\DRIVERS\ZTEusbnet.sys 06:11:32.0640 3548 ZTEusbnet - ok 06:11:32.0671 3548 ZTEusbnmea (69774b89725ddc4781e0eeb9809f3b20) C:\WINDOWS\system32\DRIVERS\ZTEusbnmea.sys 06:11:32.0671 3548 ZTEusbnmea - ok 06:11:32.0750 3548 ZTEusbser6k (b8b466103280e45e391e876f05122607) C:\WINDOWS\system32\DRIVERS\ZTEusbser6k.sys 06:11:32.0750 3548 ZTEusbser6k - ok 06:11:32.0765 3548 ZTEusbvoice (b8b466103280e45e391e876f05122607) C:\WINDOWS\system32\DRIVERS\ZTEusbvoice.sys 06:11:32.0765 3548 ZTEusbvoice - ok 06:11:32.0953 3548 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 06:11:33.0078 3548 \Device\Harddisk0\DR0 - ok 06:11:33.0078 3548 Boot (0x1200) (f3e45709e7adaf19e366907ca3f54bb6) \Device\Harddisk0\DR0\Partition0 06:11:33.0078 3548 \Device\Harddisk0\DR0\Partition0 - ok 06:11:33.0109 3548 Boot (0x1200) (5f74054fa3c14c74fb1df4bc63dd4e38) \Device\Harddisk0\DR0\Partition1 06:11:33.0109 3548 \Device\Harddisk0\DR0\Partition1 - ok 06:11:33.0125 3548 ============================================================ 06:11:33.0125 3548 Scan finished 06:11:33.0125 3548 ============================================================ 06:11:33.0156 3528 Detected object count: 1 06:11:33.0156 3528 Actual detected object count: 1 06:11:58.0046 3528 Backup copy found, using it.. 06:11:58.0109 3528 C:\WINDOWS\system32\DRIVERS\ipsec.sys - will be cured on reboot 06:11:58.0109 3528 IPSec ( Rootkit.Win32.ZAccess.h ) - User select action: Cure 06:12:02.0671 3920 Deinitialize success
Logs from extra.txt


OTL Extras logfile created on: 25/10/2011 AM 6:24:13 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\TANST\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001004 | Country: Singapore | Language: ZHI | Date Format: d/M/yyyy

1015.17 Mb Total Physical Memory | 492.05 Mb Available Physical Memory | 48.47% Memory free
2.38 Gb Paging File | 1.92 Gb Available in Paging File | 80.76% Paging File free
Paging file location(s): C:\pagefile.sys 1522 1522 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.99 Gb Total Space | 3.57 Gb Free Space | 8.92% Space Free | Partition Type: NTFS
Drive D: | 34.50 Gb Total Space | 26.27 Gb Free Space | 76.15% Space Free | Partition Type: NTFS

Computer Name: TSTIOH5353 | User Name: TANST | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"56074:TCP" = 56074:TCP:*:Enabled:Pando Media Booster
"56074:UDP" = 56074:UDP:*:Enabled:Pando Media Booster

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"56074:TCP" = 56074:TCP:*:Enabled:Pando Media Booster
"56074:UDP" = 56074:UDP:*:Enabled:Pando Media Booster
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"1039:TCP" = 1039:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Program Files\Veetle\Player\VeetleNet.exe" = C:\Program Files\Veetle\Player\VeetleNet.exe:*:Enabled:VeetleNet – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\FlashGet Network\FlashGet 3\Flashget3.exe" = C:\Program Files\FlashGet Network\FlashGet 3\Flashget3.exe:*:Enabled:FlashGet3 – (Trend Media Corporation Limited)
"C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" = C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Enabled:Veoh Web Player Beta
"C:\Documents and Settings\DAISYTAY\Desktop\my immortal\飞速Tudou\TudouVa.exe" = C:\Documents and Settings\DAISYTAY\Desktop\my immortal\飞速Tudou\TudouVa.exe:*:Enabled:飞速土豆1.20
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Program Files\Electronic Arts\EADM\Core.exe" = C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager
"C:\Nexon\MapleStory\AxedMS v88.exe" = C:\Nexon\MapleStory\AxedMS v88.exe:*:Enabled:AxedMS
"D:\opera.exe" = D:\opera.exe:*:Enabled:Opera Internet Browser
"D:\Downloads\FunshionUpgrade.exe" = D:\Downloads\FunshionUpgrade.exe:*:Enabled:FunshionUpgrade
"C:\Program Files\KuGou\KuGou2011\KuGoo.exe" = C:\Program Files\KuGou\KuGou2011\KuGoo.exe:*:Disabled:酷狗音乐2011 – (酷狗音乐)
"D:\World of Warcraft\Launcher.exe" = D:\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher
"D:\World of Warcraft\Launcher.patch.exe" = D:\World of Warcraft\Launcher.patch.exe:*:Enabled:Blizzard Launcher
"C:\Documents and Settings\DAISYTAY\My Documents\Downloads\BlackshotInstaller.exe" = C:\Documents and Settings\DAISYTAY\My Documents\Downloads\BlackshotInstaller.exe:*:Enabled:Garena Installer – ()
"D:\Games\BlackShot\BlackShot\system\BlackShot.exe" = D:\Games\BlackShot\BlackShot\system\BlackShot.exe:*:Enabled:BlackShot – (Vertigo Games)
"D:\Downloads\FunshionService.exe" = D:\Downloads\FunshionService.exe:*:Enabled:Funshion Network Transport Service
"C:\Program Files\Veetle\Player\VeetleNet.exe" = C:\Program Files\Veetle\Player\VeetleNet.exe:*:Enabled:VeetleNet – ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0990B5DF-92C3-4AD6-A18D-BF3ADF311240}" = Super Hybrid Engine
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{17424F35-8B77-4ADF-BC63-BF9B81418539}" = Apple Application Support
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{184E7118-0295-43C4-B72C-1D54AA75AAF7}" = Windows Live Mail
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{19F5658D-92E8-4A08-8657-D38ABB1574B2}" = Asus ACPI Driver
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 26
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{3560CE5A-C4EF-4DB0-9ECC-BA035FE309C5}" = MSN Toolbar
"{3B5C97AB-F523-4C8E-8A0D-A73A57C76F1C}" = AxedMS
"{3CA2B4FD-AEF2-ED4F-F5E5-0095DDA47AC7}" = Adobe Download Assistant
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate for Eee PC
"{5C52CED3-D45C-4DA9-932F-B91BD44BB461}" = Adabas D 13.01.00
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari
"{6E4DAE31-7CF3-441A-B6E5-B014D63C80CD}" = Eee Instant Key
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{80EAC1F5-3067-4E57-A09F-3AF728C59FE5}" = MapleStory
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = WIDCOMM Bluetooth Software
"{85E3CFBC-9B1B-470C-AF72-54EACA0F1322}" = ECAP
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8B7917E0-AF55-4E8A-9473-017F0AA03AC8}" = QuickTime
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Azurewave Wireless LAN
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9158FF30-78D7-40EF-B83E-451AC5334640}" = Adobe Photoshop CS5.1
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{9510AB97-A36C-4352-8725-E72E5528FA1B}" = StarOffice 8 ASUS Edition
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{96B51C0B-D3BE-4DF3-959C-28B22C10CFBB}" = Vodafone Mobile Connect Lite
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BBCFFFC-621F-47CB-8F81-E0E04A023A7F}}_is1" = 酷狗音乐2011(正式版)
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims 3
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D92FF8EB-BD77-40AE-B68B-A6BFC6F8661D}" = Windows Live Family Safety
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{DEB6ACEB-C418-4880-9133-1C5EB9AFBC79}" = Eee Storage
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EC48376E-5D6C-40AE-A226-1D3AC8BDA60F}" = AuditionSEA
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager
"{F270470B-D4A7-4EE2-B010-390E104443A7}" = croNous
"{FB8148DD-C575-4B0A-9F6C-0CFC46937930}" = Opera 10.10
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AhnLab Online Security" = AhnLab Online Security
"Akamai" = Akamai NetSession Interface
"BabylonToolbar" = Babylon toolbar
"BlackShot" = BlackShot 力芭
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"conduitEngine" = Conduit Engine
"Cucusoft YouTube Mate (Downloader+Player+Converter)_is1" = Cucusoft YouTube Mate 8.15
"EADM" = EA Download Manager
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FlashGet" = FlashGet 1.9.6.1073
"FlashGet 3.3" = FlashGet 3.3
"Freecorder4.1" = Freecorder
"GoldWave v5.58" = GoldWave v5.58
"HDMI" = Intel® Graphics Media Accelerator Driver
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Messenger Plus! Live" = Messenger Plus! Live
"Messenger_Plus_Live Toolbar" = Messenger_Plus_Live Toolbar
"MessengerPlusLive_TB Toolbar" = MessengerPlusLive TB Toolbar
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.7)" = Mozilla Firefox (3.0.7)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PhotoScape" = PhotoScape
"RegCure" = RegCure 2.0.0.0
"Synthesia" = Synthesia (remove only)
"uneavset" = ESET NOD32 register program
"Veetle TV" = Veetle TV
"vShare" = vShare Plugin
"vShare.tv plugin" = vShare.tv plugin 1.3
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"YTdetect" = Yahoo! Detect
"飞速土豆" = 飞速土豆 1.40.19.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome 浏览器

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 24/10/2011 AM 8:26:57 | Computer Name = TSTIOH5353 | Source = Application Hang | ID = 1001
Description = Fault bucket -1631001076.

Error - 24/10/2011 AM 8:32:39 | Computer Name = TSTIOH5353 | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.31.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 24/10/2011 AM 9:54:26 | Computer Name = TSTIOH5353 | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

Error - 24/10/2011 AM 10:17:18 | Computer Name = TSTIOH5353 | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

Error - 24/10/2011 AM 10:17:18 | Computer Name = TSTIOH5353 | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 24/10/2011 AM 10:43:11 | Computer Name = TSTIOH5353 | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007043C from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 24/10/2011 PM 12:27:28 | Computer Name = TSTIOH5353 | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

Error - 24/10/2011 PM 6:01:43 | Computer Name = TSTIOH5353 | Source = VMCService | ID = 0
Description = GetProcessOwner

Error - 24/10/2011 PM 6:03:05 | Computer Name = TSTIOH5353 | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

Error - 24/10/2011 PM 6:13:37 | Computer Name = TSTIOH5353 | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

[ OSession Events ]
Error - 11/10/2011 AM 1:45:10 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 13
seconds with 0 seconds of active time. This session ended with a crash.

Error - 11/10/2011 AM 2:52:12 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 4014
seconds with 120 seconds of active time. This session ended with a crash.

Error - 11/10/2011 AM 5:30:09 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 9472
seconds with 2040 seconds of active time. This session ended with a crash.

Error - 11/10/2011 AM 6:05:37 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 2025
seconds with 60 seconds of active time. This session ended with a crash.

Error - 12/10/2011 AM 8:26:14 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 4499
seconds with 60 seconds of active time. This session ended with a crash.

Error - 12/10/2011 AM 10:24:48 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 1364
seconds with 1080 seconds of active time. This session ended with a crash.

Error - 12/10/2011 PM 1:50:53 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 12352
seconds with 120 seconds of active time. This session ended with a crash.

Error - 29/10/2011 PM 12:47:06 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 1850
seconds with 120 seconds of active time. This session ended with a crash.

Error - 21/10/2011 AM 11:19:15 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 2073
seconds with 720 seconds of active time. This session ended with a crash.

Error - 22/10/2011 AM 6:47:31 | Computer Name = TSTIOH5353 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 767
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 24/10/2011 PM 6:04:25 | Computer Name = TSTIOH5353 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 24/10/2011 PM 6:04:30 | Computer Name = TSTIOH5353 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 24/10/2011 PM 6:05:03 | Computer Name = TSTIOH5353 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 24/10/2011 PM 6:05:08 | Computer Name = TSTIOH5353 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 24/10/2011 PM 6:05:18 | Computer Name = TSTIOH5353 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 24/10/2011 PM 6:05:35 | Computer Name = TSTIOH5353 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 24/10/2011 PM 6:05:58 | Computer Name = TSTIOH5353 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 24/10/2011 PM 6:06:02 | Computer Name = TSTIOH5353 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 24/10/2011 PM 6:07:52 | Computer Name = TSTIOH5353 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 24/10/2011 PM 6:13:50 | Computer Name = TSTIOH5353 | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring
the volume.


< End of report >
Log file from OTL.txt . Looking forward to your response sir . I shall leave the machine alone for now .


OTL logfile created on: 25/10/2011 AM 6:24:13 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\TANST\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001004 | Country: Singapore | Language: ZHI | Date Format: d/M/yyyy

1015.17 Mb Total Physical Memory | 492.05 Mb Available Physical Memory | 48.47% Memory free
2.38 Gb Paging File | 1.92 Gb Available in Paging File | 80.76% Paging File free
Paging file location(s): C:\pagefile.sys 1522 1522 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.99 Gb Total Space | 3.57 Gb Free Space | 8.92% Space Free | Partition Type: NTFS
Drive D: | 34.50 Gb Total Space | 26.27 Gb Free Space | 76.15% Space Free | Partition Type: NTFS

Computer Name: TSTIOH5353 | User Name: TANST | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\TANST\My Documents\Downloads\OTL (3).exe (OldTimer Tools)
PRC - C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Update\1.3.21.79\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - D:\Downloads\FLVSrvc.exe (Applian Technologies, Inc.)
PRC - C:\Program Files\FlashGet Network\FlashGet 3\Flashget3.exe (Trend Media Corporation Limited)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
PRC - C:\Program Files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\EeePC\ACPI\AsTray.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\EeePC\ACPI\AsEPCMon.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ESET\EAVService\EAVService.exe ()
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Modules (No Company Name) ==========

MOD - c:\Program Files\Common Files\Akamai\netsession_win_807ba95.dll ()
MOD - C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\ppgooglenaclpluginchrome.dll ()
MOD - C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\pdf.dll ()
MOD - C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\Locales\en-US.dll ()
MOD - C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\avutil-51.dll ()
MOD - C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\avformat-53.dll ()
MOD - C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\avcodec-53.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\042658de519bb1e22ec5925092061892\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e0d56c0582316e9ecb4c18186e37217c\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\1d03df7f7548613e8beab2cc21e57910\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\990d96810a21e0fa95f916ffc66f3a94\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\9e91cca51a5ed6fb13b67558109d2726\System.Security.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d6b4509225efde2a4e3db77205f8a51\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\b06e49ed8cbe07dbb90e313fa634b27b\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ed2bf0d86229128c194a872f70fe15ee\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d912066086a59f09424c7c69f95e2c55\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\1337829e3df6888464a17aab78bb9b8f\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\f02cf6430a9fc77908a74ab6925cb73c\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\62d5f089dd51f18472a7caf1593d9f6b\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_f2070df7\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_74f750fe\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_6445d94a\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_9330be91\system.windows.forms.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_70f045e8\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\FlashGet Network\FlashGet 3\VodCore.dll ()
MOD - C:\Program Files\FlashGet Network\FlashGet 3\ckcore.dll ()
MOD - C:\Program Files\FlashGet Network\FlashGet 3\zlib.dll ()
MOD - C:\Program Files\FlashGet Network\FlashGet 3\BugReport.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - c:\windows\assembly\gac\microsoft.visualbasic\7.0.5000.0__b03f5f7f11d50a3a\microsoft.visualbasic.dll ()
MOD - C:\WINDOWS\system32\btwicons.dll ()
MOD - C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll ()
MOD - C:\WINDOWS\system32\msjetoledb40.dll ()
MOD - C:\Program Files\ESET\EAVService\EAVService.exe ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_807ba95.dll ()
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (npggsvc) – C:\WINDOWS\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (VMCService) – C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (EavService) – C:\Program Files\ESET\EAVService\EavService.exe ()
SRV - (IviRegMgr) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Driver Services (SafeList) ==========

DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Mkd2kfNt) – C:\WINDOWS\system32\drivers\Mkd2kfNT.sys (AhnLab, Inc.)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (ewusbnet) – C:\WINDOWS\system32\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\WINDOWS\system32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (hwusbfake) – C:\WINDOWS\system32\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV - (Mkd2Nadr) – C:\WINDOWS\system32\drivers\Mkd2Nadr.sys (AhnLab, Inc.)
DRV - (ZTEusbnet) – C:\WINDOWS\system32\drivers\ZTEusbnet.sys (ZTE Corporation)
DRV - (ZTEusbnmea) – C:\WINDOWS\system32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbvoice) – C:\WINDOWS\system32\drivers\zteusbvoice.sys (ZTE Incorporated)
DRV - (ZTEusbser6k) – C:\WINDOWS\system32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\WINDOWS\system32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (FsVga) – C:\WINDOWS\system32\drivers\fsvga.sys (Microsoft Corporation)
DRV - (RT80x86) – C:\WINDOWS\system32\drivers\rt2860.sys (Ralink Technology, Corp.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (L1e) – C:\WINDOWS\system32\drivers\l1e51x86.sys (Atheros Communications, Inc.)
DRV - (btwhid) – C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (AsusACPI) – C:\WINDOWS\system32\drivers\ASUSACPI.SYS (ASUSTeK Computer Inc.)
DRV - (WUSB54GPV4SRV) – C:\WINDOWS\system32\drivers\rt2500usb.sys (Ralink Technology Inc.)
DRV - (msloop) – C:\WINDOWS\system32\drivers\loop.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.bing.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "data:text/plain,browser.startup.homepage=http://sg.downloads.yahoo.com/firefox/search"
FF - prefs.js..CommunityToolbar.SearchFromAddressBarSavedUrl: "data:text/plain,keyword.URL=http://sg.search.yahoo.com/search?fr=yff3u&p;="
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaultthis.engineName: "MessengerPlusLive TB Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2722653&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://startsear.ch/?aff=1"
FF - prefs.js..extensions.enabledItems: [removed]:3.2.3.3
FF - prefs.js..extensions.enabledItems: {DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {d8fb4583-db9d-4c7b-85be-294c13a3e5c4}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.3.20081117
FF - prefs.js..browser.startup.homepage: "http://redirecturls.info/"
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..keyword.URL: "http://startsear.ch/?aff=1&src;=sp&cf;=5a376474-f7c5-11e0-9759-001217887652&q;="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@ahnlab.com/asp/npaosmgr.1: C:\Program Files\AhnLab\ASP\Components\aosmgr\conflict_221\npaosmgr.dll (AhnLab, Inc.)
FF - HKLM\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\2.bin\NPMyWebS.dll File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MyWebSearch\bar\2.bin
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/01 11:02:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/16 15:06:45 | 000,000,000 | —D | M]

[2009/03/15 18:59:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\TANST\Application Data\Mozilla\Extensions
[2011/10/15 21:09:02 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions
[2009/11/18 10:13:58 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/13 16:25:37 | 000,000,000 | —D | M] (MessengerPlusLive TB Community Toolbar) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\{d8fb4583-db9d-4c7b-85be-294c13a3e5c4}
[2011/01/13 16:25:35 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\[removed]
[2011/10/15 21:09:02 | 000,000,000 | —D | M] (My Web Search) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\[removed]
[2011/01/15 04:57:06 | 000,000,000 | —D | M] (vShare) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\vshare@toolbar
[2010/11/07 19:06:10 | 000,000,943 | —- | M] () – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\searchplugins\conduit.xml
[2011/07/12 02:04:02 | 000,000,633 | —- | M] () – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\searchplugins\startsear.xml
[2011/01/15 04:58:18 | 000,001,583 | —- | M] () – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\searchplugins\web-search.xml
[2011/10/19 22:29:19 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2009/03/15 19:00:13 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/09/06 03:26:26 | 000,000,000 | —D | M] (Click to call with Skype) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2010/06/09 08:09:08 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/01/20 09:02:58 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/19 17:52:07 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/08/15 02:15:31 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2010/01/19 17:12:12 | 000,000,000 | —D | M] (flashget3 Extension) – C:\Program Files\Mozilla Firefox\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}
[2010/06/09 08:08:47 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
File not found (No name found) – C:\PROGRAM FILES\MYWEBSEARCH\BAR\2.BIN
[2010/06/12 02:05:14 | 000,253,952 | —- | M] () – C:\Program Files\mozilla firefox\components\CheckTudouVa.dll
[2011/05/04 04:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/10/03 17:14:54 | 000,083,456 | —- | M] (vShare.tv ) – C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
[2010/11/01 21:18:54 | 000,002,226 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml

========== Chrome ==========

CHR - default_search_provider: Web Search (Enabled)
CHR - default_search_provider: search_url = http://startsear.ch/?aff=1&src;=sp&…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: AhnLab Online Security (Enabled) = C:\Program Files\AhnLab\ASP\Components\aosmgr\conflict_221\npaosmgr.dll
CHR - plugin: AhnLab MyKeyDefense 2.5 (Enabled) = C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll
CHR - plugin: My Web Search Plugin Stub (Enabled) = C:\Program Files\MyWebSearch\bar\2.bin\NPMyWebS.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Adblock Plus for Google Chrome\u2122 (Beta) = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.1.4_1\
CHR - Extension: vshare plugin = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\

Hosts file not found
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (FlashGetBHO) - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Documents and Settings\DAISYTAY\Application Data\FlashGetBHO\FlashGetBHO3.dll (FlashGet)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {9B339F6E-DDCD-401B-8764-230ADBD01761} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D8FB4583-DB9D-4C7B-85BE-294C13A3E5C4} - No CLSID value found.
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [BabylonToolbar] "C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.15.13\BabylonToolbarsrv.exe" /md I File not found
O4 - HKLM..\Run: [EAVSET] C:\Program Files\ESET\eavset\EAVSET.exe ()
O4 - HKLM..\Run: [Freecorder FLV Service] D:\downloads\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [FlashGet 3] C:\Program Files\FlashGet Network\FlashGet 3\flashget3.exe (Trend Media Corporation Limited)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SuperHybridEngine.lnk = C:\Program Files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (ASUSTeK Computer Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95 00 00 00 [binary data]
O8 - Extra context menu item: &使用快车(FlashGet)下载 - C:\Program Files\FlashGet\jc_link.htm File not found
O8 - Extra context menu item: &使用快车(FlashGet)下载全部链接 - C:\Program Files\FlashGet\jc_all.htm File not found
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000036 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000038 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000039 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000040 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000041 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000042 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000043 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000044 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000045 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000046 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000047 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O15 - HKCU\..Trusted Domains: kuaiche.com ([software] http in Trusted sites)
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-SG/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} http://dist.globalgamecdn.com/dist/neffy/NeffyLauncher.cab (NeffyLauncherCtl Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{282EEB5D-959D-429E-B2C2-8C988CE08D4C}: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5E9E0E7F-8273-4BC1-BB14-7AE6A6A06CAE}: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EFEF631C-C01C-405D-9CF6-A643B57B9B0B}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\KuGoo {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\WINDOWS\system32\KuGoo3DownXControl.ocx ()
O18 - Protocol\Handler\KuGoo3 {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\WINDOWS\system32\KuGoo3DownXControl.ocx ()
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/27 13:28:13 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/06/14 12:37:49 | 000,000,021 | -H– | M] () - C:\autorun.inf – [ NTFS ]
O32 - AutoRun File - [2009/06/14 12:37:54 | 000,000,021 | -H– | M] () - D:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{216efcca-ebad-11e0-9732-002243a9b7b6}\Shell - "" = AutoRun
O33 - MountPoints2\{216efcca-ebad-11e0-9732-002243a9b7b6}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{216efcca-ebad-11e0-9732-002243a9b7b6}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{329815ae-b332-11df-94b5-002243a9b7b6}\Shell - "" = AutoRun
O33 - MountPoints2\{329815ae-b332-11df-94b5-002243a9b7b6}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{329815ae-b332-11df-94b5-002243a9b7b6}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{df227bf4-06c7-11de-90bc-002243a9b7b6}\Shell\AutoRun\command - "" = E:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isi32.exe
O33 - MountPoints2\{df227bf4-06c7-11de-90bc-002243a9b7b6}\Shell\open\command - "" = E:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isi32.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: SSHNAS - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/10/25 06:10:14 | 001,561,392 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\TANST\Desktop\TDSSKiller.exe
[2011/10/24 20:10:31 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/10/24 19:54:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2011/10/24 19:16:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2011/10/24 19:04:48 | 000,000,000 | —D | C] – C:\Documents and Settings\TANST\Application Data\Uniblue
[2011/10/24 19:04:44 | 000,000,000 | —D | C] – C:\Program Files\Uniblue
[2011/10/24 19:04:21 | 000,000,000 | —D | C] – C:\Documents and Settings\TANST\Local Settings\Application Data\PackageAware
[2011/10/24 19:03:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2011/10/24 14:18:11 | 000,000,000 | —D | C] – C:\Documents and Settings\TANST\Application Data\SUPERAntiSpyware.com
[2011/10/24 14:17:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2011/10/24 14:16:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/10/24 14:16:53 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/10/24 13:20:25 | 000,000,000 | —D | C] – C:\Documents and Settings\TANST\Application Data\Malwarebytes
[2011/10/24 13:20:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/10/24 13:20:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/10/24 13:20:10 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/10/24 13:20:10 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/10/24 09:33:21 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/10/24 09:33:21 | 000,000,000 | —D | C] – C:\Documents and Settings\TANST\Start Menu\Programs\HiJackThis
[2011/10/23 22:12:36 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/10/23 21:49:45 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/10/23 21:49:42 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/10/16 15:06:40 | 000,000,000 | —D | C] – C:\Program Files\vShare.tv plugin
[2011/10/01 18:27:49 | 000,000,000 | —D | C] – C:\Documents and Settings\TANST\Application Data\FLEXnet
[2011/10/01 05:43:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Vodafone
[2011/10/01 05:43:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Vodafone
[2011/10/01 05:43:23 | 000,000,000 | —D | C] – C:\Program Files\Vodafone
[2011/10/01 05:42:58 | 000,000,000 | —D | C] – C:\Documents and Settings\TANST\Local Settings\Application Data\{D632CC62-317B-4E7E-A5BC-BB40CE8A0B0C}
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/30 14:25:00 | 000,000,990 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2228970593-2351082760-789675871-1006UA.job
[2011/10/29 22:25:04 | 000,000,938 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2228970593-2351082760-789675871-1006Core.job
[2011/10/25 06:27:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/25 06:18:10 | 000,444,776 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/10/25 06:18:10 | 000,072,688 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/10/25 06:13:29 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/25 06:13:28 | 000,000,444 | —- | M] () – C:\WINDOWS\tasks\RegCure Program Check.job
[2011/10/25 06:13:28 | 000,000,384 | —- | M] () – C:\WINDOWS\tasks\RegCure Startup.job
[2011/10/25 06:13:21 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/10/25 06:12:16 | 000,000,468 | —- | M] () – C:\WINDOWS\System32\secustat.dat
[2011/10/25 06:05:01 | 000,000,632 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2228970593-2351082760-789675871-1007UA.job
[2011/10/25 06:03:16 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2011/10/25 02:00:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-TSTIOH5353-DAISYTAY.job
[2011/10/24 20:10:51 | 000,002,447 | —- | M] () – C:\Documents and Settings\TANST\Desktop\HiJackThis.lnk
[2011/10/24 19:53:37 | 000,000,272 | —- | M] () – C:\WINDOWS\reimage.ini
[2011/10/24 19:42:05 | 000,000,500 | —- | M] () – C:\WINDOWS\tasks\One-Click Tweak.job
[2011/10/24 18:54:45 | 000,000,366 | —- | M] () – C:\Documents and Settings\TANST\BITS.ini
[2011/10/24 14:50:24 | 000,002,063 | —- | M] () – C:\WINDOWS\System32\secushr.dat
[2011/10/24 14:17:34 | 000,001,678 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/10/24 13:20:16 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/24 13:05:02 | 000,000,580 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2228970593-2351082760-789675871-1007Core.job
[2011/10/24 10:54:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/10/24 02:41:50 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/10/24 01:07:51 | 000,202,994 | —- | M] () – C:\Documents and Settings\TANST\Local Settings\Application Data\census.cache
[2011/10/24 01:07:30 | 000,200,468 | —- | M] () – C:\Documents and Settings\TANST\Local Settings\Application Data\ars.cache
[2011/10/23 21:49:59 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/10/23 04:49:00 | 000,000,378 | —- | M] () – C:\WINDOWS\tasks\RegCure.job
[2011/10/21 11:24:50 | 001,561,392 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\TANST\Desktop\TDSSKiller.exe
[2011/10/21 10:06:49 | 000,002,557 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Vodafone Mobile Connect.lnk
[2011/10/18 16:27:28 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/10/15 19:15:11 | 000,000,716 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Cucusoft YouTube Mate.lnk
[2011/10/12 21:59:43 | 000,000,306 | —- | M] () – C:\Documents and Settings\TANST\Application DataBITS.ini
[2011/10/05 20:07:20 | 000,002,262 | —- | M] () – C:\Documents and Settings\TANST\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome 浏览器.lnk
[2011/10/05 20:07:19 | 000,002,284 | —- | M] () – C:\Documents and Settings\TANST\Desktop\Google Chrome 浏览器.lnk
[2011/10/01 05:43:33 | 000,001,986 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Vodafone SMS.lnk
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/24 19:53:19 | 000,000,272 | —- | C] () – C:\WINDOWS\reimage.ini
[2011/10/24 19:42:04 | 000,000,500 | —- | C] () – C:\WINDOWS\tasks\One-Click Tweak.job
[2011/10/24 14:17:34 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/10/24 13:20:16 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/24 09:33:22 | 000,002,447 | —- | C] () – C:\Documents and Settings\TANST\Desktop\HiJackThis.lnk
[2011/10/24 01:07:51 | 000,202,994 | —- | C] () – C:\Documents and Settings\TANST\Local Settings\Application Data\census.cache
[2011/10/24 01:07:30 | 000,200,468 | —- | C] () – C:\Documents and Settings\TANST\Local Settings\Application Data\ars.cache
[2011/10/23 21:49:59 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/10/01 05:43:33 | 000,002,557 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Vodafone Mobile Connect.lnk
[2011/10/01 05:43:33 | 000,001,986 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Vodafone SMS.lnk
[2011/09/02 03:56:57 | 000,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2011/07/17 16:49:26 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2011/05/28 22:18:53 | 000,000,036 | —- | C] () – C:\Documents and Settings\TANST\Local Settings\Application Data\housecall.guid.cache
[2011/04/29 21:47:42 | 000,011,304 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\615xt1y66r2c8inn7n8d851
[2011/03/14 00:33:56 | 000,000,200 | —- | C] () – C:\WINDOWS\System32\msexcr.ini
[2011/02/04 19:32:40 | 000,034,308 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2010/11/06 18:56:55 | 000,064,676 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/08/24 00:03:45 | 000,154,160 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/08/21 19:00:48 | 000,000,050 | —- | C] () – C:\WINDOWS\MegaManager.INI
[2009/11/24 15:53:35 | 000,002,063 | —- | C] () – C:\WINDOWS\System32\secushr.dat
[2009/11/23 15:28:09 | 000,000,468 | —- | C] () – C:\WINDOWS\System32\secustat.dat
[2009/11/23 15:27:31 | 000,000,025 | —- | C] () – C:\WINDOWS\libem.INI
[2009/08/28 15:16:16 | 000,130,238 | R— | C] () – C:\Documents and Settings\All Users\Application Data\DeviceManager.xml.rc4
[2009/03/15 18:59:45 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/03/07 23:14:00 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\GTW32N50.dll
[2008/09/03 10:46:52 | 000,000,128 | —- | C] () – C:\Documents and Settings\TANST\Local Settings\Application Data\fusioncache.dat
[2008/09/01 20:23:08 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008/07/23 06:28:41 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2008/07/23 06:28:06 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\drivers\SamSfPa.dat
[2008/06/27 20:04:38 | 000,005,312 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2008/06/27 15:53:45 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/06/27 14:17:15 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2008/06/27 14:17:15 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2008/06/27 14:17:15 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2008/06/27 14:17:15 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2008/06/27 14:17:15 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2008/06/27 14:17:15 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2008/06/27 13:40:13 | 000,049,152 | —- | C] () – C:\WINDOWS\INSTALLEEE.EXE
[2008/06/27 13:35:32 | 000,147,456 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4906.dll
[2008/06/27 13:30:40 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/06/27 13:26:00 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/06/27 13:13:14 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/06/27 13:13:13 | 000,444,776 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/06/27 13:13:13 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/06/27 13:13:13 | 000,072,688 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/06/27 13:13:13 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/06/27 13:13:13 | 000,004,562 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/06/27 13:13:12 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/06/27 13:13:12 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2008/06/27 13:13:10 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/06/27 13:13:10 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/06/27 13:13:08 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/06/27 13:13:06 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/06/27 06:20:40 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/06/27 06:19:44 | 003,608,760 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/04/15 04:58:40 | 002,854,912 | —- | C] () – C:\WINDOWS\System32\btwicons.dll
[2008/03/20 21:58:30 | 000,000,173 | —- | C] () – C:\WINDOWS\explorer.exe.config
[2008/03/18 06:54:36 | 000,012,208 | —- | C] () – C:\WINDOWS\AsTrayLang.ini
[2001/11/15 04:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll

========== LOP Check ==========

[2008/11/29 21:35:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ECAP
[2010/12/06 14:17:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2008/07/23 06:13:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ESET
[2010/10/14 19:51:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GoldWave
[2010/01/16 18:54:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2011/10/24 19:54:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/11/18 22:03:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2009/11/25 21:31:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RegCure
[2010/11/06 18:29:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2011/10/24 19:04:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2010/08/14 20:30:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/10/01 05:43:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Vodafone
[2011/10/24 19:16:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2011/10/25 06:13:34 | 000,000,000 | —D | M] – C:\Documents and Settings\TANST\Application Data\BITS
[2011/09/02 03:49:25 | 000,000,000 | —D | M] – C:\Documents and Settings\TANST\Application Data\GetRightToGo
[2011/02/17 18:52:23 | 000,000,000 | —D | M] – C:\Documents and Settings\TANST\Application Data\PriceGong
[2011/10/24 19:04:48 | 000,000,000 | —D | M] – C:\Documents and Settings\TANST\Application Data\Uniblue
[2009/08/12 16:03:15 | 000,000,000 | —D | M] – C:\Documents and Settings\TANST\Application Data\Vodafone
[2011/01/15 04:57:02 | 000,000,000 | —D | M] – C:\Documents and Settings\TANST\Application Data\vShare
[2011/10/24 19:42:05 | 000,000,500 | —- | M] () – C:\WINDOWS\Tasks\One-Click Tweak.job
[2011/10/25 06:13:28 | 000,000,444 | —- | M] () – C:\WINDOWS\Tasks\RegCure Program Check.job
[2011/10/25 06:13:28 | 000,000,384 | —- | M] () – C:\WINDOWS\Tasks\RegCure Startup.job
[2011/10/23 04:49:00 | 000,000,378 | —- | M] () – C:\WINDOWS\Tasks\RegCure.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/06/27 13:28:13 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/06/14 12:37:49 | 000,000,021 | -H– | M] () – C:\autorun.inf
[2011/10/25 06:03:16 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2008/06/27 13:28:13 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/06/27 13:28:13 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/10/15 19:56:19 | 000,002,685 | —- | M] () – C:\iPod2PC_log.txt
[2008/06/27 13:28:13 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 20:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 20:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/10/25 06:13:14 | 1595,932,672 | -HS- | M] () – C:\pagefile.sys
[2009/03/17 00:34:53 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2009/03/17 00:56:19 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2009/01/01 00:32:14 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2009/01/01 15:48:34 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2009/01/02 18:06:35 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2009/01/02 18:21:03 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2009/01/03 15:08:26 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2009/01/03 17:00:51 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2009/01/06 00:46:08 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2009/01/06 16:05:06 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2009/01/06 18:55:17 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2009/01/07 15:32:58 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2009/01/07 19:24:46 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2009/01/08 00:01:51 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2009/01/08 18:50:33 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2009/01/10 18:27:13 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2009/01/26 18:55:43 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2009/03/02 10:11:12 | 000,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/03/02 10:12:09 | 000,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2009/03/02 12:33:21 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2009/03/17 00:34:53 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/03/17 00:56:19 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/01/01 00:32:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/01/01 15:48:34 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/01/02 18:06:35 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/01/02 18:21:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/01/03 15:08:26 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/01/03 17:00:51 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/01/06 00:46:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/01/06 16:05:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/01/06 18:55:17 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/01/07 15:32:57 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/01/07 19:24:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/01/08 00:01:51 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/01/08 18:50:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/01/10 18:27:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/01/26 18:55:43 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/03/02 10:11:12 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/03/02 10:12:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/03/02 12:33:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2011/10/25 06:12:02 | 000,052,154 | —- | M] () – C:\TDSSKiller.2.6.12.0_25.10.2011_06.10.48_log.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/06/27 13:27:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 20:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 18:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/04/17 00:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/06/27 06:19:16 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/06/27 06:19:16 | 001,064,960 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/06/27 06:19:15 | 000,905,216 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/06/27 13:28:18 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >
[2008/03/20 21:58:30 | 000,000,173 | —- | M] () – C:\WINDOWS\explorer.exe.config
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/09/03 10:47:09 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\TANST\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/06/27 13:32:08 | 000,000,079 | —- | M] () – C:\Documents and Settings\TANST\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/05/28 22:18:29 | 001,914,496 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\TANST\Desktop\HousecallLauncher.exe
[2011/10/21 11:24:50 | 001,561,392 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\TANST\Desktop\TDSSKiller.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2008/09/03 10:47:07 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\TANST\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2009/11/18 10:24:06 | 000,000,067 | -HS- | M] () – C:\Documents and Settings\TANST\Cookies\desktop.ini
[2011/10/25 06:14:16 | 000,098,304 | —- | M] () – C:\Documents and Settings\TANST\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-28 13:22:22

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB29959$] -> Error: Cannot create file handle -> Unknown point type

========== Alternate Data Streams ==========

@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5E1404CE
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3E009DD5
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:282C9F32

< End of report >
Just to update the current status of the problem . I dun see ping.exe running in my task manager now . My internet connection has been responding to my commands for some time now which is great news . Hope the rescue package can help this machine get back to its usual ways .
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Appreciate your fast response sir . Done with combofix .


ComboFix 11-10-24.04 - TANST 0/2011 星期二 8:00.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.936.86.1033.18.1015.708 [GMT 8:00]
执行位置: c:\documents and settings\TANST\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( 被删除的档案 )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\autorun.inf
c:\documents and settings\All Users\Application Data\ECAP
c:\documents and settings\All Users\Application Data\ECAP\ECap.ini
c:\documents and settings\All Users\Application Data\ECAP\GenePccMon.ini
c:\documents and settings\DAISYTAY\WINDOWS
c:\documents and settings\TANST\Application Data\PriceGong
c:\documents and settings\TANST\Application Data\PriceGong\Data\1.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\a.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\b.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\c.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\d.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\e.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\f.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\g.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\h.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\i.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\J.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\k.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\l.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\m.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\n.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\o.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\p.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\q.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\r.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\s.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\t.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\u.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\v.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\w.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\x.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\y.xml
c:\documents and settings\TANST\Application Data\PriceGong\Data\z.xml
c:\documents and settings\TANST\WINDOWS
c:\windows\$NtUninstallKB29959$
c:\windows\$NtUninstallKB29959$\282093015\@
c:\windows\$NtUninstallKB29959$\282093015\bckfg.tmp
c:\windows\$NtUninstallKB29959$\282093015\cfg.ini
c:\windows\$NtUninstallKB29959$\282093015\Desktop.ini
c:\windows\$NtUninstallKB29959$\282093015\keywords
c:\windows\$NtUninstallKB29959$\282093015\kwrd.dll
c:\windows\$NtUninstallKB29959$\282093015\L\ixnfowmi
c:\windows\$NtUninstallKB29959$\282093015\U\00000001.@
c:\windows\$NtUninstallKB29959$\282093015\U\00000002.@
c:\windows\$NtUninstallKB29959$\282093015\U\80000000.@
c:\windows\$NtUninstallKB29959$\282093015\U\80000032.@
c:\windows\$NtUninstallKB29959$\3416925463
c:\windows\system32\135713d8.dll
c:\windows\system32\135beb18.dll
c:\windows\system32\1a25e76.dll
c:\windows\system32\7f9dccc.dll
c:\windows\system32\drivers\1.txt
c:\windows\system32\drivers\aa35.txt
D:\autorun.inf
.
.
((((((((((((((((((((((((((((((((((((((( 驱动/服务 )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_UPDATEDATA
.
.
((((((((((((((((((((((((( 2011-09-25 至 2011-10-25 的新的档案 )))))))))))))))))))))))))))))))
.
.
2011-10-24 11:54 . 2011-10-24 11:54 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2011-10-24 11:16 . 2011-10-24 11:16 ——– d—–w- c:\documents and settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-10-24 11:04 . 2011-10-24 11:04 ——– d—–w- c:\documents and settings\TANST\Application Data\Uniblue
2011-10-24 11:04 . 2011-10-24 11:04 ——– d—–w- c:\program files\Uniblue
2011-10-24 11:04 . 2011-10-24 11:04 ——– d—–w- c:\documents and settings\TANST\Local Settings\Application Data\PackageAware
2011-10-24 11:03 . 2011-10-24 11:04 ——– d—–w- c:\documents and settings\All Users\Application Data\SecTaskMan
2011-10-24 08:33 . 2011-10-24 14:39 ——– d—–w- c:\documents and settings\Administrator
2011-10-24 06:18 . 2011-10-24 06:18 ——– d—–w- c:\documents and settings\TANST\Application Data\SUPERAntiSpyware.com
2011-10-24 06:16 . 2011-10-24 06:18 ——– d—–w- c:\program files\SUPERAntiSpyware
2011-10-24 06:16 . 2011-10-24 06:16 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-10-24 05:20 . 2011-10-24 05:20 ——– d—–w- c:\documents and settings\TANST\Application Data\Malwarebytes
2011-10-24 05:20 . 2011-10-24 05:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-10-24 05:20 . 2011-10-24 05:20 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-10-24 05:20 . 2011-08-31 09:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-10-24 01:33 . 2011-10-24 01:33 388096 —-a-r- c:\documents and settings\TANST\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-10-24 01:33 . 2011-10-24 01:33 ——– d—–w- c:\program files\Trend Micro
2011-10-23 14:12 . 2011-10-23 14:13 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-10-16 07:06 . 2011-10-24 06:47 ——– d—–w- c:\program files\vShare.tv plugin
2011-10-03 09:14 . 2011-10-03 09:14 83456 —-a-w- c:\program files\Mozilla Firefox\plugins\npvsharetvplg.dll
2011-10-01 10:27 . 2011-10-01 10:27 ——– d—–w- c:\documents and settings\TANST\Application Data\FLEXnet
2011-09-30 21:43 . 2011-09-30 21:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Vodafone
2011-09-30 21:43 . 2011-09-30 21:43 ——– d—–w- c:\program files\Vodafone
2011-09-30 21:42 . 2011-09-30 21:42 ——– d—–w- c:\documents and settings\TANST\Local Settings\Application Data\{D632CC62-317B-4E7E-A5BC-BB40CE8A0B0C}
.
.
.
(((((((((((((((((((((((((((((((((((((((( 在三个月内被修改的档案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-24 22:12 . 2008-06-27 05:13 75264 —-a-w- c:\windows\system32\drivers\ipsec.sys
2011-10-23 18:41 . 2011-09-14 03:43 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2010-06-11 18:05 . 2009-06-22 05:48 253952 —-a-w- c:\program files\mozilla firefox\components\CheckTudouVa.dll
.
.
((((((((((((((((((((((((((((((((((((( 重要登入点 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白与合法缺省登录将不会被显示
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-13 39408]
"FlashGet 3"="c:\program files\FlashGet Network\FlashGet 3\flashget3.exe" [2009-12-22 2127408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2008-06-03 98304]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2008-06-03 479232]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2008-05-21 94208]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-10 86960]
"EAVSET"="c:\program files\ESET\EAVSET\EAVSET.exe" [2008-05-06 255488]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-02-15 417792]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-21 406992]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-16 16806400]
"Freecorder FLV Service"="d:\downloads\FLVSrvc.exe" [2010-06-26 167936]
"AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-11 1523360]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"MobileConnect"="c:\program files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe" [2009-09-18 2412032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...r=9.0.872" [?]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-4-15 596584]
SuperHybridEngine.lnk - c:\program files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2008-7-23 303104]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2011-08-31 09:00 449608 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2010-04-16 14:12 3872080 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2011-10-17 17:18 4615552 —-a-w- c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-05-13 09:59 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\FlashGet Network\\FlashGet 3\\Flashget3.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\KuGou\\KuGou2011\\KuGoo.exe"=
"c:\\Documents and Settings\\DAISYTAY\\My Documents\\Downloads\\BlackshotInstaller.exe"=
"d:\\Games\\BlackShot\\BlackShot\\system\\BlackShot.exe"=
"c:\\Program Files\\Veetle\\Player\\VeetleNet.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56074:TCP"= 56074:TCP:Pando Media Booster
"56074:UDP"= 56074:UDP:Pando Media Booster
"1035:TCP"= 1035:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [23/7/2011 AM 12:27 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [13/7/2011 AM 5:55 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [12/8/2011 AM 7:38 116608]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [27/6/2008 PM 1:13 14336]
R2 EavService;EavService;c:\program files\ESET\EAVService\EAVService.exe [23/7/2008 AM 6:14 111104]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [24/10/2011 PM 1:20 366152]
R2 VMCService;Vodafone Mobile Connect Service;c:\program files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [18/9/2009 PM 6:48 9216]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [24/10/2011 PM 1:20 22216]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [29/1/2010 PM 7:34 135664]
S3 br3gmdm;BandLuxe 3.5G USB Adapter - MODEM;c:\windows\system32\DRIVERS\br3gmdm.sys –> c:\windows\system32\DRIVERS\br3gmdm.sys [?]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [10/8/2011 PM 7:24 112640]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [29/1/2010 PM 7:34 135664]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [10/8/2011 PM 7:29 100480]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2/8/2009 PM 9:40 7680]
S3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNT.sys [30/9/2009 PM 9:40 133632]
S3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [30/9/2009 PM 9:40 79360]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [27/6/2008 PM 1:36 625024]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19/2/2010 PM 1:37 517096]
S3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\drivers\ZTEusbnet.sys [2/8/2009 PM 9:41 110080]
S3 ZTEusbvoice;ZTE VoUSB Port;c:\windows\system32\drivers\zteusbvoice.sys [2/8/2009 PM 9:40 104960]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
‘计划任务’ 文件夹 里的内容
.
2011-10-24 c:\windows\Tasks\AdobeAAMUpdater-1.0-TSTIOH5353-DAISYTAY.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-06-08 09:42]
.
2011-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 11:34]
.
2011-10-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 11:34]
.
2011-10-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2228970593-2351082760-789675871-1006Core.job
- c:\documents and settings\DAISYTAY\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-11-19 14:00]
.
2011-10-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2228970593-2351082760-789675871-1006UA.job
- c:\documents and settings\DAISYTAY\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-11-19 14:00]
.
2011-10-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2228970593-2351082760-789675871-1007Core.job
- c:\documents and settings\TANST\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-14 13:05]
.
2011-10-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2228970593-2351082760-789675871-1007UA.job
- c:\documents and settings\TANST\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-14 13:05]
.
.
——- 而外的扫描 ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
IE: &使用快车(FlashGet)下载 - c:\program files\FlashGet\jc_link.htm
IE: &使用快车(FlashGet)下载全部链接 - c:\program files\FlashGet\jc_all.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: Send to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: kuaiche.com\software
TCP: DhcpNameServer = [removed] [removed] [removed]
Handler: KuGoo - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - c:\windows\system32\KuGoo3DownXControl.ocx
Handler: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - c:\windows\system32\KuGoo3DownXControl.ocx
DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} - hxxp://dist.globalgamecdn.com/dist/neffy/NeffyLauncher.cab
FF - ProfilePath - c:\documents and settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2722653&SearchSource;=3&q;={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://startsear.ch/?aff=1
FF - prefs.js: browser.startup.homepage - hxxp://redirecturls.info/
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: keyword.URL - hxxp://startsear.ch/?aff=1&src;=sp&cf;=5a376474-f7c5-11e0-9759-001217887652&q;=
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - c:\program files\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: flashget3 Extension: {DB9127A2-3381-41ec-82B3-1B6ED4C6F29A} - c:\program files\Mozilla Firefox\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}
FF - Ext: Conduit Engine : [removed] - %profile%\extensions\[removed]
FF - Ext: vShare: vshare@toolbar - %profile%\extensions\vshare@toolbar
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: MessengerPlusLive TB Community Toolbar: {d8fb4583-db9d-4c7b-85be-294c13a3e5c4} - %profile%\extensions\{d8fb4583-db9d-4c7b-85be-294c13a3e5c4}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{9B339F6E-DDCD-401B-8764-230ADBD01761} - (no file)
WebBrowser-{D8FB4583-DB9D-4C7B-85BE-294C13A3E5C4} - (no file)
HKLM-Run-BabylonToolbar - c:\program files\BabylonToolbar\BabylonToolbar\1.4.15.13\BabylonToolbarsrv.exe
SafeBoot-68419048.sys
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
AddRemove-BabylonToolbar - c:\program files\BabylonToolbar\BabylonToolbar\1.4.15.13\uninstall.exe
AddRemove-conduitEngine - c:\progra~1\CONDUI~1\ConduitEngineUninstall.exe
AddRemove-EADM - c:\program files\Electronic Arts\EADM\Uninstall.exe
AddRemove-FlashGet - c:\program files\FlashGet\uninst.exe
AddRemove-Messenger Plus! Live - c:\program files\Messenger Plus! Live\Uninstall.exe
AddRemove-MessengerPlusLive_TB Toolbar - c:\progra~1\MESSEN~4\UNWISE.EXE
AddRemove-Messenger_Plus_Live Toolbar - c:\progra~1\MESSEN~3\UNWISE.EXE
AddRemove-RegCure - c:\program files\RegCure\uninst.exe
AddRemove-Synthesia - c:\documents and settings\DAISYTAY\Desktop\Synthesia\uninstall.exe
AddRemove-vShare - c:\program files\vShare\UNINSTALL.exe
AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\documents and settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}\bm_installer.exe
AddRemove-飞速土豆 - c:\documents and settings\DAISYTAY\Desktop\my immortal\飞速Tudou\uninst.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-25 08:15
Windows 5.1.2600 Service Pack 3 NTFS
.
扫描被隐藏的进程 。。。
.
扫描被隐藏的启动组 。。。
.
扫描被隐藏的文件 。。。
.
扫描完成
被隐藏的档案: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\G*o*o*g*l*e* *C*h*r*o*m*e* *Om葔hV\Capabilities]
"ApplicationName"="Google Chrome 浏览器"
"ApplicationIcon"="c:\\Documents and Settings\\TANST\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe,0"
"ApplicationDescription"="Google Chrome 浏览器是一款可高速运行网页和应用程序的网络浏览器。它快捷、稳定且易于使用。Google Chrome 浏览器内置的恶意软件和网上诱骗防护功能可让您更加安全地浏览网页。"
.
[HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\G*o*o*g*l*e* *C*h*r*o*m*e* *Om葔hV\Capabilities\FileAssociations]
".xhtml"="ChromeHTML"
".xht"="ChromeHTML"
".shtml"="ChromeHTML"
".html"="ChromeHTML"
".htm"="ChromeHTML"
.
[HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\G*o*o*g*l*e* *C*h*r*o*m*e* *Om葔hV\Capabilities\StartMenu]
"StartMenuInternet"="Google Chrome 浏览器"
.
[HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\G*o*o*g*l*e* *C*h*r*o*m*e* *Om葔hV\Capabilities\URLAssociations]
"webcal"="ChromeHTML"
"mailto"="ChromeHTML"
"https"="ChromeHTML"
"http"="ChromeHTML"
"ftp"="ChromeHTML"
.
[HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\G*o*o*g*l*e* *C*h*r*o*m*e* *Om葔hV\DefaultIcon]
@="c:\\Documents and Settings\\TANST\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe,0"
.
[HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\G*o*o*g*l*e* *C*h*r*o*m*e* *Om葔hV\InstallInfo]
"IconsVisible"=dword:00000001
"ShowIconsCommand"="\"c:\\Documents and Settings\\TANST\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe\" –show-icons"
"HideIconsCommand"="\"c:\\Documents and Settings\\TANST\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe\" –hide-icons"
"ReinstallCommand"="\"c:\\Documents and Settings\\TANST\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe\" –make-default-browser"
.
[HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\G*o*o*g*l*e* *C*h*r*o*m*e* *Om葔hV\shell\open\command]
@="\"c:\\Documents and Settings\\TANST\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe\""
.
——————— 运行进程下的动态链接库 ———————
.
- - - - - - - > 'winlogon.exe'(876)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(3004)
c:\windows\system32\WININET.dll
c:\documents and settings\TANST\Local Settings\Application Data\FLVService\lib\FLVSrvLib.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— 其他运行进程 ————————
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\conime.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\igfxext.exe
c:\windows\RTHDCPL.EXE
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
完成时间: 2011-10-25 08:21:24 - 电脑已重新启动
ComboFix-quarantined-files.txt 2011-10-25 00:21
.
Pre-Run: 3,684,716,544 bytes free
Post-Run: 4,520,251,392 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-CHS.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - D7BE7AFF875484B7D488EC8D65DD067F
Do you have an antivirus installed on this computer?



  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.









Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.


Also tell me how the computer is running now.
Antivirus ? I don't think so . I got malware bytes and superanti spyware only to cover it . Perhaps you can reco a freeware for me . Machine is running smoothly now internet wise , the clean up seems to make the machine run faster than before as well . Looking good for now . Would appreciate if i could know what was going on this while as i don't understand at all what those programmes do . I only know they are looking for something ! Log files coming up in the next 2 replies as i'm scanning them now .
Malwarebytes log file Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8009 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 25/10/2011 AM 9:40:45 mbam-log-2011-10-25 (09-40-45).txt Scan type: Quick scan Objects scanned: 201973 Time elapsed: 9 minute(s), 31 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Cant find the details tab . But here is what i got from the scan . Eset log details C:\Documents and Settings\DAISYTAY\Application Data\12.tmp a variant of Win32/Kryptik.REL trojan cleaned by deleting - quarantined C:\Documents and Settings\DAISYTAY\Application Data\80.tmp a variant of Win32/Kryptik.REL trojan cleaned by deleting - quarantined C:\Documents and Settings\DAISYTAY\Application Data\84.tmp a variant of Win32/Kryptik.REL trojan cleaned by deleting - quarantined C:\Documents and Settings\DAISYTAY\Application Data\85.tmp a variant of Win32/Kryptik.REL trojan cleaned by deleting - quarantined C:\Documents and Settings\DAISYTAY\Application Data\87.tmp a variant of Win32/Kryptik.REL trojan cleaned by deleting - quarantined C:\Documents and Settings\DAISYTAY\Application Data\89.tmp a variant of Win32/Kryptik.REL trojan cleaned by deleting - quarantined C:\Documents and Settings\DAISYTAY\Application Data\8A.tmp a variant of Win32/Kryptik.REL trojan cleaned by deleting - quarantined C:\Documents and Settings\DAISYTAY\Application Data\8E.tmp a variant of Win32/Kryptik.REL trojan cleaned by deleting - quarantined C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\prefs.js Win32/StartPage.OEV trojan cleaned by deleting - quarantined C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\prefs.js.BAK Win32/StartPage.OEV trojan cleaned by deleting - quarantined C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_00045b Win32/RegistryBooster application deleted - quarantined C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_0004c4 a variant of Win32/Adware.AdvPCTweak application deleted - quarantined C:\Documents and Settings\TANST\My Documents\Downloads\AdvancedPCTweaker.exe a variant of Win32/Adware.AdvPCTweak application deleted - quarantined C:\Documents and Settings\TANST\My Documents\Downloads\registrybooster.exe Win32/RegistryBooster application deleted - quarantined C:\Qoobox\Quarantine\C\autorun.inf.vir Win32/AutoRun.Agent.PG worm cleaned by deleting - quarantined C:\Qoobox\Quarantine\D\autorun.inf.vir Win32/AutoRun.Agent.PG worm cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP512\A0141773.sys Win32/Sirefef.DG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP512\A0141802.sys Win32/Sirefef.DG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP512\A0141819.sys Win32/Sirefef.DG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP512\A0141834.sys Win32/Sirefef.DG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP512\A0141858.sys Win32/Sirefef.DG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP512\A0141879.sys Win32/Sirefef.DG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP513\A0141905.sys Win32/Sirefef.DG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP513\A0142905.sys Win32/Sirefef.DG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP513\A0143905.sys Win32/Sirefef.DG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP513\A0143986.sys Win32/Sirefef.DG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP513\A0144010.sys Win32/Sirefef.DG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP513\A0144047.sys Win32/Sirefef.DG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP513\A0144069.sys Win32/Sirefef.DG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP514\A0144110.exe a variant of Win32/Adware.AdvPCTweak application cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP515\A0144253.sys Win32/Sirefef.DG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP515\A0144282.sys Win32/Sirefef.DG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP515\A0144302.sys Win32/Sirefef.DG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP515\A0144314.sys Win32/Sirefef.DG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP515\A0144334.sys Win32/Sirefef.DG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{47CE108E-5D7D-4625-9D5A-698840496DF7}\RP516\A0144429.inf Win32/AutoRun.Agent.PG worm cleaned by deleting - quarantined C:\WINDOWS\system32\drivers\etc\hosts.msn Win32/Qhost trojan cleaned by deleting - quarantined
I use Avira free antivirus,install it and run a full scan. http://www.avira.com/en/avira-free-antivirus

Also can you run OTL,click run scan and post the new log.
Avira log file Avira Free Antivirus Report file date: 星期二, 25 十月, 2011 18:41 Scanning for 3432844 virus strains and unwanted programs. The program is running as an unrestricted full version. Online services are available: Licensee : Avira AntiVir Personal - Free Antivirus Serial number : 0000149996-ADJIE-0000001 Platform : Windows XP Windows version : (Service Pack 3) [5.1.2600] Boot mode : Normally booted Username : TANST Computer name : TSTIOH5353 Version information: BUILD.DAT : 12.0.0.849 41825 Bytes 2011-9-23 20:19:00 AVSCAN.EXE : [removed] 490448 Bytes 2011-9-23 10:04:46 AVSCAN.DLL : [removed] 54224 Bytes 2011-9-23 05:34:56 LUKE.DLL : [removed] 68304 Bytes 2011-9-23 04:55:16 AVSCPLR.DLL : [removed] 99536 Bytes 2011-9-23 04:02:36 AVREG.DLL : [removed] 226512 Bytes 2011-10-25 10:40:13 VBASE000.VDF : 7.10.0.0 19875328 Bytes 2009-11-6 12:18:34 VBASE001.VDF : 7.11.0.0 13342208 Bytes 2010-12-14 03:07:39 VBASE002.VDF : 7.11.3.0 1950720 Bytes 2011-2-9 09:08:51 VBASE003.VDF : 7.11.5.225 1980416 Bytes 2011-4-7 04:00:55 VBASE004.VDF : 7.11.8.178 2354176 Bytes 2011-5-31 04:18:22 VBASE005.VDF : 7.11.10.251 1788416 Bytes 2011-7-7 06:12:53 VBASE006.VDF : 7.11.13.60 6411776 Bytes 2011-8-16 01:26:09 VBASE007.VDF : 7.11.15.106 2389504 Bytes 2011-10-5 10:39:47 VBASE008.VDF : 7.11.15.107 2048 Bytes 2011-10-5 10:39:48 VBASE009.VDF : 7.11.15.108 2048 Bytes 2011-10-5 10:39:49 VBASE010.VDF : 7.11.15.109 2048 Bytes 2011-10-5 10:39:50 VBASE011.VDF : 7.11.15.110 2048 Bytes 2011-10-5 10:39:51 VBASE012.VDF : 7.11.15.111 2048 Bytes 2011-10-5 10:39:51 VBASE013.VDF : 7.11.15.144 161792 Bytes 2011-10-7 10:39:52 VBASE014.VDF : 7.11.15.177 130048 Bytes 2011-10-10 10:39:53 VBASE015.VDF : 7.11.15.213 113664 Bytes 2011-10-11 10:39:55 VBASE016.VDF : 7.11.16.1 163328 Bytes 2011-10-14 10:39:56 VBASE017.VDF : 7.11.16.34 187904 Bytes 2011-10-18 10:39:57 VBASE018.VDF : 7.11.16.77 139264 Bytes 2011-10-20 10:39:58 VBASE019.VDF : 7.11.16.112 162816 Bytes 2011-10-24 10:39:59 VBASE020.VDF : 7.11.16.113 2048 Bytes 2011-10-24 10:40:00 VBASE021.VDF : 7.11.16.114 2048 Bytes 2011-10-24 10:40:00 VBASE022.VDF : 7.11.16.115 2048 Bytes 2011-10-24 10:40:00 VBASE023.VDF : 7.11.16.116 2048 Bytes 2011-10-24 10:40:00 VBASE024.VDF : 7.11.16.117 2048 Bytes 2011-10-24 10:40:01 VBASE025.VDF : 7.11.16.118 2048 Bytes 2011-10-24 10:40:01 VBASE026.VDF : 7.11.16.119 2048 Bytes 2011-10-24 10:40:01 VBASE027.VDF : 7.11.16.120 2048 Bytes 2011-10-24 10:40:01 VBASE028.VDF : 7.11.16.121 2048 Bytes 2011-10-24 10:40:02 VBASE029.VDF : 7.11.16.122 2048 Bytes 2011-10-24 10:40:02 VBASE030.VDF : 7.11.16.123 2048 Bytes 2011-10-24 10:40:02 VBASE031.VDF : 7.11.16.136 84992 Bytes 2011-10-25 10:40:03 Engineversion : 8.2.6.84 AEVDF.DLL : 8.1.2.1 106868 Bytes 2011-9-1 15:46:02 AESCRIPT.DLL : [removed] 467322 Bytes 2011-10-25 10:40:12 AESCN.DLL : [removed] 127349 Bytes 2011-9-1 15:46:02 AESBX.DLL : [removed] 323957 Bytes 2011-9-1 15:46:02 AERDL.DLL : [removed] 639348 Bytes 2011-9-8 15:16:06 AEPACK.DLL : [removed] 684408 Bytes 2011-9-22 08:18:45 AEOFFICE.DLL : [removed] 201083 Bytes 2011-9-15 17:17:25 AEHEUR.DLL : [removed] 3748217 Bytes 2011-10-25 10:40:10 AEHELP.DLL : [removed] 254327 Bytes 2011-9-1 15:46:01 AEGEN.DLL : [removed] 401780 Bytes 2011-9-1 15:46:01 AEEMU.DLL : [removed] 393589 Bytes 2011-9-1 15:46:01 AECORE.DLL : [removed] 196983 Bytes 2011-9-1 15:46:01 AEBB.DLL : 8.1.1.0 53618 Bytes 2011-9-1 15:46:01 AVWINLL.DLL : [removed] 27344 Bytes 2011-9-23 04:13:18 AVPREF.DLL : [removed] 51920 Bytes 2011-9-23 03:53:57 AVREP.DLL : [removed] 179408 Bytes 2011-9-23 03:55:01 AVARKT.DLL : [removed] 223184 Bytes 2011-9-23 03:25:26 AVEVTLOG.DLL : [removed] 169168 Bytes 2011-9-23 03:34:37 SQLITE3.DLL : [removed] 398288 Bytes 2011-9-15 18:05:58 AVSMTP.DLL : [removed] 62928 Bytes 2011-9-23 04:03:47 NETNT.DLL : [removed] 17104 Bytes 2011-9-23 04:58:06 RCIMAGE.DLL : [removed] 4450000 Bytes 2011-9-23 05:37:25 RCTEXT.DLL : [removed] 96208 Bytes 2011-9-23 05:37:24 Configuration settings for the scan: Jobname………………………..: Short system scan after installation Configuration file………………: c:\program files\avira\antivir desktop\setupprf.dat Logging………………………..: default Primary action………………….: interactive Secondary action………………..: ignore Scan master boot sector………….: on Scan boot sector………………..: on Process scan……………………: on Scan registry…………………..: on Search for rootkits……………..: off Integrity checking of system files..: off Scan all files………………….: Intelligent file selection Scan archives…………………..: on Recursion depth…………………: 20 Smart extensions………………..: on Macro heuristic…………………: on File heuristic………………….: extended Start of the scan: 星期二, 25 十月, 2011 18:41 Starting master boot sector scan: Master boot sector HD0 [INFO] No virus was found! Start scanning boot sectors: The scan of running processes will be started Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'avshadow.exe' - '1' Module(s) have been scanned Scan process 'avguard.exe' - '1' Module(s) have been scanned Scan process 'wuauclt.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'avconfig.exe' - '1' Module(s) have been scanned Scan process 'avgnt.exe' - '1' Module(s) have been scanned Scan process 'sched.exe' - '1' Module(s) have been scanned Scan process 'setup.exe' - '1' Module(s) have been scanned Scan process 'presetup.exe' - '1' Module(s) have been scanned Scan process 'avira_free_antivirus_en.exe' - '1' Module(s) have been scanned Scan process 'GoogleCrashHandler.exe' - '1' Module(s) have been scanned Scan process 'conime.exe' - '1' Module(s) have been scanned Scan process 'BTSTAC~1.EXE' - '1' Module(s) have been scanned Scan process 'SuperHybridEngine.exe' - '1' Module(s) have been scanned Scan process 'BTTray.exe' - '1' Module(s) have been scanned Scan process 'flashget3.exe' - '1' Module(s) have been scanned Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned Scan process 'MobileConnect.exe' - '1' Module(s) have been scanned Scan process 'jusched.exe' - '1' Module(s) have been scanned Scan process 'FLVSrvc.exe' - '1' Module(s) have been scanned Scan process 'igfxext.exe' - '1' Module(s) have been scanned Scan process 'RTHDCPL.EXE' - '1' Module(s) have been scanned Scan process 'igfxsrvc.exe' - '1' Module(s) have been scanned Scan process 'alg.exe' - '1' Module(s) have been scanned Scan process 'issch.exe' - '1' Module(s) have been scanned Scan process 'AsEPCMon.exe' - '1' Module(s) have been scanned Scan process 'AsAcpiSvr.exe' - '1' Module(s) have been scanned Scan process 'AsTray.exe' - '1' Module(s) have been scanned Scan process 'hkcmd.exe' - '1' Module(s) have been scanned Scan process 'igfxtray.exe' - '1' Module(s) have been scanned Scan process 'Explorer.EXE' - '1' Module(s) have been scanned Scan process 'VMCService.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'SeaPort.exe' - '1' Module(s) have been scanned Scan process 'mbamservice.exe' - '1' Module(s) have been scanned Scan process 'jqs.exe' - '1' Module(s) have been scanned Scan process 'iviRegMgr.exe' - '1' Module(s) have been scanned Scan process 'EavService.exe' - '1' Module(s) have been scanned Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'SASCORE.EXE' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'spoolsv.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'btwdins.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned Starting to scan executable files (registry). The registry was scanned ( '2048' files ). End of the scan: 星期二, 25 十月, 2011 18:43 Used time: 01:44 Minute(s) The scan has been done completely. 0 Scanned directories 2756 Files were scanned 0 Viruses and/or unwanted programs were found 0 Files were classified as suspicious 0 Files were deleted 0 Viruses and unwanted programs were repaired 0 Files were moved to quarantine 0 Files were renamed 0 Files cannot be scanned 2756 Files not concerned 23 Archives were scanned 0 Warnings 0 Notes
I don't have to check or uncheck anything right ? I went to run scan straight away though .

New OTL log file


OTL logfile created on: 25/10/2011 PM 6:46:10 - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\TANST\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001004 | Country: Singapore | Language: ZHI | Date Format: d/M/yyyy

1015.17 Mb Total Physical Memory | 588.38 Mb Available Physical Memory | 57.96% Memory free
2.38 Gb Paging File | 1.87 Gb Available in Paging File | 78.35% Paging File free
Paging file location(s): C:\pagefile.sys 1522 1522 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.99 Gb Total Space | 3.65 Gb Free Space | 9.12% Space Free | Partition Type: NTFS
Drive D: | 34.50 Gb Total Space | 26.27 Gb Free Space | 76.15% Space Free | Partition Type: NTFS

Computer Name: TSTIOH5353 | User Name: TANST | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\TANST\My Documents\Downloads\OTL (3).exe (OldTimer Tools)
PRC - C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Update\1.3.21.79\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - D:\Downloads\FLVSrvc.exe (Applian Technologies, Inc.)
PRC - C:\Program Files\FlashGet Network\FlashGet 3\Flashget3.exe (Trend Media Corporation Limited)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
PRC - C:\Program Files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\EeePC\ACPI\AsTray.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\EeePC\ACPI\AsEPCMon.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\ESET\EAVService\EAVService.exe ()
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Modules (No Company Name) ==========

MOD - c:\Program Files\Common Files\Akamai\netsession_win_807ba95.dll ()
MOD - C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\042658de519bb1e22ec5925092061892\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e0d56c0582316e9ecb4c18186e37217c\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\1d03df7f7548613e8beab2cc21e57910\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\990d96810a21e0fa95f916ffc66f3a94\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\9e91cca51a5ed6fb13b67558109d2726\System.Security.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d6b4509225efde2a4e3db77205f8a51\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\b06e49ed8cbe07dbb90e313fa634b27b\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ed2bf0d86229128c194a872f70fe15ee\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d912066086a59f09424c7c69f95e2c55\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\1337829e3df6888464a17aab78bb9b8f\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\f02cf6430a9fc77908a74ab6925cb73c\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\62d5f089dd51f18472a7caf1593d9f6b\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\Program Files\FlashGet Network\FlashGet 3\VodCore.dll ()
MOD - C:\Program Files\FlashGet Network\FlashGet 3\ckcore.dll ()
MOD - C:\Program Files\FlashGet Network\FlashGet 3\zlib.dll ()
MOD - C:\Program Files\FlashGet Network\FlashGet 3\BugReport.dll ()
MOD - C:\WINDOWS\system32\btwicons.dll ()
MOD - C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll ()
MOD - C:\WINDOWS\system32\msjetoledb40.dll ()
MOD - C:\Program Files\ESET\EAVService\EAVService.exe ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_807ba95.dll ()
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (npggsvc) – C:\WINDOWS\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (VMCService) – C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (EavService) – C:\Program Files\ESET\EAVService\EavService.exe ()
SRV - (IviRegMgr) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Driver Services (SafeList) ==========

DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avkmgr) – C:\WINDOWS\system32\drivers\avkmgr.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (Mkd2kfNt) – C:\WINDOWS\system32\drivers\Mkd2kfNT.sys (AhnLab, Inc.)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (ewusbnet) – C:\WINDOWS\system32\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\WINDOWS\system32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (hwusbfake) – C:\WINDOWS\system32\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV - (Mkd2Nadr) – C:\WINDOWS\system32\drivers\Mkd2Nadr.sys (AhnLab, Inc.)
DRV - (ZTEusbnet) – C:\WINDOWS\system32\drivers\ZTEusbnet.sys (ZTE Corporation)
DRV - (ZTEusbnmea) – C:\WINDOWS\system32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbvoice) – C:\WINDOWS\system32\drivers\zteusbvoice.sys (ZTE Incorporated)
DRV - (ZTEusbser6k) – C:\WINDOWS\system32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\WINDOWS\system32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (FsVga) – C:\WINDOWS\system32\drivers\fsvga.sys (Microsoft Corporation)
DRV - (RT80x86) – C:\WINDOWS\system32\drivers\rt2860.sys (Ralink Technology, Corp.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (L1e) – C:\WINDOWS\system32\drivers\l1e51x86.sys (Atheros Communications, Inc.)
DRV - (btwhid) – C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (AsusACPI) – C:\WINDOWS\system32\drivers\ASUSACPI.SYS (ASUSTeK Computer Inc.)
DRV - (WUSB54GPV4SRV) – C:\WINDOWS\system32\drivers\rt2500usb.sys (Ralink Technology Inc.)
DRV - (msloop) – C:\WINDOWS\system32\drivers\loop.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@ahnlab.com/asp/npaosmgr.1: C:\Program Files\AhnLab\ASP\Components\aosmgr\conflict_221\npaosmgr.dll (AhnLab, Inc.)
FF - HKLM\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MyWebSearch\bar\2.bin
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/01 11:02:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/16 15:06:45 | 000,000,000 | —D | M]

[2009/03/15 18:59:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\TANST\Application Data\Mozilla\Extensions
[2011/10/15 21:09:02 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions
[2009/11/18 10:13:58 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/13 16:25:37 | 000,000,000 | —D | M] (MessengerPlusLive TB Community Toolbar) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\{d8fb4583-db9d-4c7b-85be-294c13a3e5c4}
[2011/01/13 16:25:35 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\[removed]
[2011/10/15 21:09:02 | 000,000,000 | —D | M] (My Web Search) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\[removed]
[2011/01/15 04:57:06 | 000,000,000 | —D | M] (vShare) – C:\Documents and Settings\TANST\Application Data\Mozilla\Firefox\Profiles\wucnpvqz.default\extensions\vshare@toolbar
[2011/10/19 22:29:19 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2009/03/15 19:00:13 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/09/06 03:26:26 | 000,000,000 | —D | M] (Click to call with Skype) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2010/06/09 08:09:08 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/01/20 09:02:58 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/19 17:52:07 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/08/15 02:15:31 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2010/01/19 17:12:12 | 000,000,000 | —D | M] (flashget3 Extension) – C:\Program Files\Mozilla Firefox\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}
[2010/06/12 02:05:14 | 000,253,952 | —- | M] () – C:\Program Files\mozilla firefox\components\CheckTudouVa.dll
[2011/05/04 04:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/10/03 17:14:54 | 000,083,456 | —- | M] (vShare.tv ) – C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
[2010/11/01 21:18:54 | 000,002,226 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml

========== Chrome ==========

CHR - default_search_provider: Web Search (Enabled)
CHR - default_search_provider: search_url = http://startsear.ch/?aff=1&src;=sp&…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: AhnLab Online Security (Enabled) = C:\Program Files\AhnLab\ASP\Components\aosmgr\conflict_221\npaosmgr.dll
CHR - plugin: AhnLab MyKeyDefense 2.5 (Enabled) = C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll
CHR - plugin: My Web Search Plugin Stub (Enabled) = C:\Program Files\MyWebSearch\bar\2.bin\NPMyWebS.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Adblock Plus for Google Chrome\u2122 (Beta) = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.1.4_1\
CHR - Extension: vshare plugin = C:\Documents and Settings\TANST\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\

O1 HOSTS File: ([2011/10/25 08:15:38 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (FlashGetBHO) - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Documents and Settings\DAISYTAY\Application Data\FlashGetBHO\FlashGetBHO3.dll (FlashGet)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [EAVSET] C:\Program Files\ESET\eavset\EAVSET.exe ()
O4 - HKLM..\Run: [Freecorder FLV Service] D:\downloads\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [FlashGet 3] C:\Program Files\FlashGet Network\FlashGet 3\flashget3.exe (Trend Media Corporation Limited)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SuperHybridEngine.lnk = C:\Program Files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (ASUSTeK Computer Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &使用快车(FlashGet)下载 - C:\Program Files\FlashGet\jc_link.htm File not found
O8 - Extra context menu item: &使用快车(FlashGet)下载全部链接 - C:\Program Files\FlashGet\jc_all.htm File not found
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: kuaiche.com ([software] http in Trusted sites)
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-SG/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} http://dist.globalgamecdn.com/dist/neffy/NeffyLauncher.cab (NeffyLauncherCtl Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{282EEB5D-959D-429E-B2C2-8C988CE08D4C}: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5E9E0E7F-8273-4BC1-BB14-7AE6A6A06CAE}: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EFEF631C-C01C-405D-9CF6-A643B57B9B0B}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\KuGoo {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\WINDOWS\system32\KuGoo3DownXControl.ocx ()
O18 - Protocol\Handler\KuGoo3 {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\WINDOWS\system32\KuGoo3DownXControl.ocx ()
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/27 13:28:13 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/10/25 18:38:38 | 000,000,000 | —D | C] – C:\Documents and Settings\TANST\Application Data\Avira
[2011/10/25 18:38:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Avira
[2011/10/25 18:37:46 | 000,028,520 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/10/25 18:37:42 | 000,134,344 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2011/10/25 18:37:42 | 000,074,640 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/10/25 18:37:42 | 000,036,000 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avkmgr.sys
[2011/10/25 18:37:40 | 000,000,000 | —D | C] – C:\Program Files\Avira
[2011/10/25 18:37:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Avira
[2011/10/25 13:06:11 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/10/25 07:52:38 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/10/25 07:49:42 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/10/25 07:49:42 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/10/25 07:49:42 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/10/25 07:49:42 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/10/25 07:49:18 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/10/25 07:49:07 | 000,000,000 | —D | C] – C:\Qoobox
[2011/10/25 07:49:00 | 000,000,000 | R–D | C] – C:\Documents and Settings\TANST\My Documents\My Videos
[2011/10/25 07:49:00 | 000,000,000 | R–D | C] – C:\Documents and Settings\TANST\Start Menu\Programs\Administrative Tools
[2011/10/25 07:43:53 | 004,272,570 | R— | C] (Swearware) – C:\Documents and Settings\TANST\Desktop\ComboFix.exe
[2011/10/25 06:10:14 | 001,561,392 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\TANST\Desktop\TDSSKiller.exe
[2011/10/24 19:54:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2011/10/24 19:16:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2011/10/24 19:04:48 | 000,000,000 | —D | C] – C:\Documents and Settings\TANST\Application Data\Uniblue
[2011/10/24 19:04:44 | 000,000,000 | —D | C] – C:\Program Files\Uniblue
[2011/10/24 19:04:21 | 000,000,000 | —D | C] – C:\Documents and Settings\TANST\Local Settings\Application Data\PackageAware
[2011/10/24 19:03:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2011/10/24 14:18:11 | 000,000,000 | —D | C] – C:\Documents and Settings\TANST\Application Data\SUPERAntiSpyware.com
[2011/10/24 14:17:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2011/10/24 14:16:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/10/24 14:16:53 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/10/24 13:20:25 | 000,000,000 | —D | C] – C:\Documents and Settings\TANST\Application Data\Malwarebytes
[2011/10/24 13:20:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/10/24 13:20:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/10/24 13:20:10 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/10/24 13:20:10 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/10/24 09:33:21 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/10/24 09:33:21 | 000,000,000 | —D | C] – C:\Documents and Settings\TANST\Start Menu\Programs\HiJackThis
[2011/10/23 22:12:36 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/10/23 21:49:45 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/10/23 21:49:42 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/10/16 15:06:40 | 000,000,000 | —D | C] – C:\Program Files\vShare.tv plugin
[2011/10/01 18:27:49 | 000,000,000 | —D | C] – C:\Documents and Settings\TANST\Application Data\FLEXnet
[2011/10/01 05:43:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Vodafone
[2011/10/01 05:43:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Vodafone
[2011/10/01 05:43:23 | 000,000,000 | —D | C] – C:\Program Files\Vodafone
[2011/10/01 05:42:58 | 000,000,000 | —D | C] – C:\Documents and Settings\TANST\Local Settings\Application Data\{D632CC62-317B-4E7E-A5BC-BB40CE8A0B0C}
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/30 14:25:00 | 000,000,990 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2228970593-2351082760-789675871-1006UA.job
[2011/10/29 22:25:04 | 000,000,938 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2228970593-2351082760-789675871-1006Core.job
[2011/10/25 18:38:07 | 000,001,707 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Avira Control Center.lnk
[2011/10/25 18:27:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/25 18:05:00 | 000,000,632 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2228970593-2351082760-789675871-1007UA.job
[2011/10/25 13:05:05 | 000,000,580 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2228970593-2351082760-789675871-1007Core.job
[2011/10/25 11:40:44 | 000,444,776 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/10/25 11:40:44 | 000,072,688 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/10/25 11:36:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/25 11:35:44 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/10/25 08:15:38 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/10/25 07:52:48 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2011/10/25 07:44:14 | 004,272,570 | R— | M] (Swearware) – C:\Documents and Settings\TANST\Desktop\ComboFix.exe
[2011/10/25 06:12:16 | 000,000,468 | —- | M] () – C:\WINDOWS\System32\secustat.dat
[2011/10/25 06:03:16 | 000,000,211 | —- | M] () – C:\Boot.bak
[2011/10/25 02:00:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-TSTIOH5353-DAISYTAY.job
[2011/10/24 20:10:51 | 000,002,447 | —- | M] () – C:\Documents and Settings\TANST\Desktop\HiJackThis.lnk
[2011/10/24 19:53:37 | 000,000,272 | —- | M] () – C:\WINDOWS\reimage.ini
[2011/10/24 18:54:45 | 000,000,366 | —- | M] () – C:\Documents and Settings\TANST\BITS.ini
[2011/10/24 14:50:24 | 000,002,063 | —- | M] () – C:\WINDOWS\System32\secushr.dat
[2011/10/24 14:17:34 | 000,001,678 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/10/24 13:20:16 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/24 02:41:50 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/10/24 01:07:51 | 000,202,994 | —- | M] () – C:\Documents and Settings\TANST\Local Settings\Application Data\census.cache
[2011/10/24 01:07:30 | 000,200,468 | —- | M] () – C:\Documents and Settings\TANST\Local Settings\Application Data\ars.cache
[2011/10/23 21:49:59 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/10/21 11:24:50 | 001,561,392 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\TANST\Desktop\TDSSKiller.exe
[2011/10/21 10:06:49 | 000,002,557 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Vodafone Mobile Connect.lnk
[2011/10/18 16:27:28 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/10/15 19:15:11 | 000,000,716 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Cucusoft YouTube Mate.lnk
[2011/10/12 21:59:43 | 000,000,306 | —- | M] () – C:\Documents and Settings\TANST\Application DataBITS.ini
[2011/10/05 20:07:20 | 000,002,262 | —- | M] () – C:\Documents and Settings\TANST\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome 浏览器.lnk
[2011/10/05 20:07:19 | 000,002,284 | —- | M] () – C:\Documents and Settings\TANST\Desktop\Google Chrome 浏览器.lnk
[2011/10/01 05:43:33 | 000,001,986 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Vodafone SMS.lnk
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/25 18:38:07 | 000,001,707 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Avira Control Center.lnk
[2011/10/25 07:52:48 | 000,000,211 | —- | C] () – C:\Boot.bak
[2011/10/25 07:52:43 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/10/25 07:49:42 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/10/25 07:49:42 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/10/25 07:49:42 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/10/25 07:49:42 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/10/25 07:49:42 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/10/24 19:53:19 | 000,000,272 | —- | C] () – C:\WINDOWS\reimage.ini
[2011/10/24 14:17:34 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/10/24 13:20:16 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/24 09:33:22 | 000,002,447 | —- | C] () – C:\Documents and Settings\TANST\Desktop\HiJackThis.lnk
[2011/10/24 01:07:51 | 000,202,994 | —- | C] () – C:\Documents and Settings\TANST\Local Settings\Application Data\census.cache
[2011/10/24 01:07:30 | 000,200,468 | —- | C] () – C:\Documents and Settings\TANST\Local Settings\Application Data\ars.cache
[2011/10/23 21:49:59 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/10/01 05:43:33 | 000,002,557 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Vodafone Mobile Connect.lnk
[2011/10/01 05:43:33 | 000,001,986 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Vodafone SMS.lnk
[2011/09/02 03:56:57 | 000,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2011/07/17 16:49:26 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2011/05/28 22:18:53 | 000,000,036 | —- | C] () – C:\Documents and Settings\TANST\Local Settings\Application Data\housecall.guid.cache
[2011/04/29 21:47:42 | 000,011,304 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\615xt1y66r2c8inn7n8d851
[2011/03/14 00:33:56 | 000,000,200 | —- | C] () – C:\WINDOWS\System32\msexcr.ini
[2011/02/04 19:32:40 | 000,034,308 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2010/11/06 18:56:55 | 000,064,676 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/08/24 00:03:45 | 000,154,160 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/08/21 19:00:48 | 000,000,050 | —- | C] () – C:\WINDOWS\MegaManager.INI
[2009/11/24 15:53:35 | 000,002,063 | —- | C] () – C:\WINDOWS\System32\secushr.dat
[2009/11/23 15:28:09 | 000,000,468 | —- | C] () – C:\WINDOWS\System32\secustat.dat
[2009/11/23 15:27:31 | 000,000,025 | —- | C] () – C:\WINDOWS\libem.INI
[2009/08/28 15:16:16 | 000,130,238 | R— | C] () – C:\Documents and Settings\All Users\Application Data\DeviceManager.xml.rc4
[2009/03/15 18:59:45 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/03/07 23:14:00 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\GTW32N50.dll
[2008/09/03 10:46:52 | 000,000,128 | —- | C] () – C:\Documents and Settings\TANST\Local Settings\Application Data\fusioncache.dat
[2008/09/01 20:23:08 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008/07/23 06:28:41 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2008/07/23 06:28:06 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\drivers\SamSfPa.dat
[2008/06/27 20:04:38 | 000,005,312 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2008/06/27 15:53:45 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/06/27 14:17:15 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2008/06/27 14:17:15 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2008/06/27 14:17:15 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2008/06/27 14:17:15 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2008/06/27 14:17:15 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2008/06/27 14:17:15 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2008/06/27 13:40:13 | 000,049,152 | —- | C] () – C:\WINDOWS\INSTALLEEE.EXE
[2008/06/27 13:35:32 | 000,147,456 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4906.dll
[2008/06/27 13:30:40 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/06/27 13:26:00 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/06/27 13:13:14 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/06/27 13:13:13 | 000,444,776 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/06/27 13:13:13 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/06/27 13:13:13 | 000,072,688 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/06/27 13:13:13 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/06/27 13:13:13 | 000,004,562 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/06/27 13:13:12 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/06/27 13:13:12 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2008/06/27 13:13:10 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/06/27 13:13:10 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/06/27 13:13:08 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/06/27 13:13:06 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/06/27 06:20:40 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/06/27 06:19:44 | 003,608,760 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/04/15 04:58:40 | 002,854,912 | —- | C] () – C:\WINDOWS\System32\btwicons.dll
[2008/03/20 21:58:30 | 000,000,173 | —- | C] () – C:\WINDOWS\explorer.exe.config
[2008/03/18 06:54:36 | 000,012,208 | —- | C] () – C:\WINDOWS\AsTrayLang.ini
[2001/11/15 04:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5E1404CE
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3E009DD5
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:282C9F32

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI