This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Changed nothing but PC suddenly very slow [Closed]

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Not sure what has happened.

Everything is suddenly starting to be very slow. Outlook, skype, browser.

Here is my HJT log

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 05:18:06, on 13/01/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Belkin\F5D7050v3\Belkinwcui.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\LiveChat\LIVECHAT.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBitT.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: BitTorrentBar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBitT.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBitT.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [F5D7050v3] C:\Program Files\Belkin\F5D7050v3\Belkinwcui.exe
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Spotify] "C:\Documents and Settings\Administrator\Application Data\Spotify\Spotify.exe" /uri spotify:autostart
O4 - HKCU\..\Run: [Jing] C:\Program Files\TechSmith\Jing\Jing.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: LIVECHAT Operator.lnk = C:\Program Files\LiveChat\LIVECHAT.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: Socialbox.lnk = C:\Program Files\Socialbox\Socialbox.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: ZooskMessenger.lnk = C:\Program Files\ZooskMessenger\ZooskMessenger.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: LIVECHAT Operator.lnk = C:\Program Files\LiveChat\LIVECHAT.exe (User 'Default user')
O4 - .DEFAULT Startup: Socialbox.lnk = C:\Program Files\Socialbox\Socialbox.exe (User 'Default user')
O4 - .DEFAULT Startup: ZooskMessenger.lnk = C:\Program Files\ZooskMessenger\ZooskMessenger.exe (User 'Default user')
O4 - Startup: LIVECHAT Operator.lnk = C:\Program Files\LiveChat\LIVECHAT.exe
O4 - Startup: Socialbox.lnk = C:\Program Files\Socialbox\Socialbox.exe
O4 - Startup: ZooskMessenger.lnk = C:\Program Files\ZooskMessenger\ZooskMessenger.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1271357432776
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: BarDiscover Service - Unknown owner - C:\Documents and Settings\All Users\Application Data\BarDiscover\bardiscover141.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 10345 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

First we need to make all files and folders VISIBLE:

  • Go to Start >> Control Panel >> Folder Options >> View
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with ok
———-

Please download DDS from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post both of the logs created by DDS and the log created by aswMBR.exe. :)
I hope this is what you are looking for: . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_30 Run by [removed] at 16:24:46 on 2012-01-15 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.673 [GMT 1:00] . AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ============== Running Processes =============== . C:\PROGRA~1\AVG\AVG10\avgchsvx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe svchost.exe C:\Program Files\AVG\AVG10\avgwdsvc.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe C:\Program Files\AVG\AVG10\avgnsx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\hkcmd.exe C:\WINDOWS\System32\igfxpers.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\Belkin\F5D7050v3\Belkinwcui.exe C:\Program Files\AVG\AVG10\avgtray.exe C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\LiveChat\LIVECHAT.exe C:\Program Files\ZooskMessenger\ZooskMessenger.exe C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\PROGRA~1\AVG\AVG10\avgrsx.exe C:\Program Files\AVG\AVG10\avgcsrvx.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\Mozilla Firefox\plugin-container.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE C:\Program Files\AVG\AVG10\avgcsrvx.exe C:\Program Files\AVG\AVG10\avgui.exe C:\WINDOWS\system32\wscntfy.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\prxtbBitT.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\prxtbBitT.dll BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\prxtbBitT.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [Spotify] "c:\documents and settings\administrator\application data\spotify\Spotify.exe" /uri spotify:autostart uRun: [Jing] c:\program files\techsmith\jing\Jing.exe uRun: [Google Update] "c:\documents and settings\administrator\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [F5D7050v3] c:\program files\belkin\f5d7050v3\Belkinwcui.exe mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe" mRun: [] dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\livech~1.lnk - c:\program files\livechat\LIVECHAT.exe StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\social~1.lnk - c:\program files\socialbox\Socialbox.exe StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\zooskm~1.lnk - c:\program files\zooskmessenger\ZooskMessenger.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-ba7e-000000000002}\SC_Acrobat.exe IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert Link Target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1271357432776 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{1E19200E-8BE9-4FFF-AC48-2B047D3B07BD} : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{FC6541BB-2839-442A-8663-549BA349DEC1} : DhcpNameServer = [removed] [removed] Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll Hosts: 192.168.2.102 HP000D9D064481 . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\administrator\application data\mozilla\firefox\profiles\x85wc26u.default\ FF - prefs.js: browser.startup.homepage - www.google.com FF - prefs.js: keyword.URL - hxxp://blekko.com/?source=c3348dd4&tbp=main&q= FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll FF - component: c:\program files\avg\avg10\firefox4\components\avgssff5.dll FF - component: c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll FF - plugin: c:\documents and settings\administrator\application data\mozilla\plugins\npgoogletalk.dll FF - plugin: c:\documents and settings\administrator\application data\mozilla\plugins\npgtpo3dautoplugin.dll FF - plugin: c:\documents and settings\administrator\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\adobe\acrobat 10.0\acrobat\air\nppdf32.dll FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll . ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-3-16 32592] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-4-4 297168] R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-8-18 7390560] R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520] R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [2011-8-12 12184] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-4-14 134480] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 27216] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-12-3 136176] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-12-3 136176] . =============== Created Last 30 ================ . 2012-01-15 15:02:37 ——– d—–w- c:\program files\common files\Adobe Systems Shared 2012-01-13 13:37:43 ——– d—–w- c:\documents and settings\administrator\WINDOWS 2012-01-13 04:17:20 388096 —-a-r- c:\documents and settings\administrator\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2012-01-13 04:17:17 ——– d—–w- c:\program files\Trend Micro 2012-01-13 04:06:22 ——– d—–w- c:\documents and settings\administrator\application data\Malwarebytes 2012-01-13 04:06:14 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes 2012-01-12 06:53:06 ——– d—–w- c:\program files\ZooskMessenger 2012-01-11 19:01:31 ——– d—–w- c:\program files\NT Registry Optimizer 2012-01-11 01:49:47 ——– d—–w- c:\program files\LiveChat 2012-01-11 01:49:47 ——– d—–w- c:\documents and settings\all users\application data\LIVECHAT 2012-01-11 01:49:47 ——– d—–w- c:\documents and settings\administrator\application data\LIVECHAT 2012-01-07 00:32:41 ——– d—–w- c:\documents and settings\administrator\local settings\application data\TechSmith 2012-01-04 19:12:01 ——– d—–w- c:\documents and settings\administrator\application data\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1 2012-01-02 23:55:36 ——– d—–w- c:\documents and settings\administrator\local settings\application data\Spotify 2012-01-02 23:54:48 ——– d—–w- c:\documents and settings\administrator\application data\Spotify 2011-12-31 20:46:38 73728 —-a-w- c:\windows\system32\javacpl.cpl 2011-12-30 23:05:45 ——– d—–w- c:\documents and settings\administrator\local settings\application data\blekkotb 2011-12-29 23:50:59 21976 —-a-w- c:\program files\mozilla firefox\plc4.dll 2011-12-29 23:50:59 20440 —-a-w- c:\program files\mozilla firefox\plds4.dll 2011-12-29 23:50:59 170968 —-a-w- c:\program files\mozilla firefox\softokn3.dll 2011-12-29 23:50:59 16856 —-a-w- c:\program files\mozilla firefox\plugin-container.exe 2011-12-29 23:50:59 154584 —-a-w- c:\program files\mozilla firefox\ssl3.dll 2011-12-29 23:50:59 105432 —-a-w- c:\program files\mozilla firefox\smime3.dll 2011-12-29 23:50:58 715216 —-a-w- c:\program files\mozilla firefox\uninstall\helper.exe 2011-12-29 23:50:58 269272 —-a-w- c:\program files\mozilla firefox\updater.exe 2011-12-29 23:50:58 19928 —-a-w- c:\program files\mozilla firefox\xpcom.dll 2011-12-29 23:50:52 16096216 —-a-w- c:\program files\mozilla firefox\xul.dll 2011-12-24 07:43:36 ——– d—–w- c:\documents and settings\administrator\local settings\application data\FastStone 2011-12-24 07:43:36 ——– d—–w- c:\documents and settings\administrator\application data\FastStone 2011-12-24 07:31:08 ——– d—–w- c:\program files\Wisdom-soft AutoScreenRecorder 3 Pro 2011-12-24 06:56:06 ——– d—–w- c:\documents and settings\all users\application data\Deskshare 2011-12-24 06:55:55 ——– d—–w- c:\documents and settings\administrator\local settings\application data\DeskShare Data 2011-12-24 06:55:38 ——– d—–w- c:\documents and settings\administrator\local settings\application data\Spoon 2011-12-23 13:16:10 ——– d—–w- C:\Virtual Spaces 2011-12-23 13:15:38 ——– d—–w- C:\Virginie's house 2011-12-23 13:15:30 ——– d—–w- C:\Valbonne House 2011-12-23 13:15:28 ——– d—–w- C:\Social Media 2011-12-23 13:08:13 ——– d—–w- C:\Photos 2011-12-23 13:08:02 ——– d—–w- C:\Phone 2011-12-23 13:07:26 ——– d—–w- C:\Panomatics 2011-12-23 13:04:32 ——– d—–w- C:\Outlook backup 2011-12-23 13:02:00 ——– d—–w- C:\Music 2011-12-23 13:01:53 ——– d—–w- C:\Jorgen 2011-12-23 13:01:51 ——– d—–w- C:\Jobs 2011-12-23 13:01:50 ——– d—–w- C:\Fun 2011-12-23 13:01:05 ——– d—–w- C:\Divorce 2011-12-23 13:00:51 ——– d—–w- C:\Desktop 2011-12-23 13:00:45 ——– d—–w- C:\Dell drivers 2011-12-23 13:00:45 ——– d—–w- C:\David Kavanagh 2011-12-23 13:00:41 ——– d—–w- C:\Catalyst SEO 2011-12-23 12:43:40 ——– d—–w- C:\Catalyst Partnership 2011-12-23 12:43:36 ——– d—–w- C:\Catalyst Adwords 2011-12-22 11:40:28 ——– d—–w- c:\documents and settings\administrator\local settings\application data\BitTorrentBar 2011-12-22 11:40:25 ——– d—–w- c:\program files\BitTorrentBar 2011-12-22 11:40:11 ——– d—–w- c:\program files\BitTorrent 2011-12-22 11:39:26 ——– d—–w- c:\documents and settings\administrator\application data\BitTorrent 2011-12-20 16:24:33 ——– d—–w- c:\program files\MozBackup 2011-12-20 15:45:26 ——– d—–w- c:\documents and settings\administrator\local settings\application data\Batchwork 2011-12-20 02:14:47 ——– d-sh–w- c:\documents and settings\administrator\IECompatCache 2011-12-20 02:13:29 ——– d-sh–w- c:\documents and settings\administrator\PrivacIE 2011-12-20 02:12:16 ——– d-sh–w- c:\documents and settings\administrator\IETldCache 2011-12-20 02:08:30 ——– d—–w- c:\windows\ie8updates 2011-12-20 02:03:26 ——– dc-h–w- c:\windows\ie8 2011-12-20 02:00:14 6144 -c—-w- c:\windows\system32\dllcache\iecompat.dll 2011-12-20 02:00:07 602112 -c—-w- c:\windows\system32\dllcache\msfeeds.dll 2011-12-20 02:00:07 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll 2011-12-20 02:00:07 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll 2011-12-20 02:00:05 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll 2011-12-20 02:00:05 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll 2011-12-20 02:00:04 2000384 -c—-w- c:\windows\system32\dllcache\iertutil.dll 2011-12-20 02:00:02 11081728 -c—-w- c:\windows\system32\dllcache\ieframe.dll 2011-12-17 21:42:13 ——– d—–w- c:\documents and settings\administrator\application data\Affilorama 2011-12-17 15:06:15 ——– d—–w- c:\windows\system32\Adobe 2011-12-16 22:55:36 ——– d—–w- c:\documents and settings\administrator\application data\DDMSettings . ==================== Find3M ==================== . 2011-12-31 20:46:19 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-12-20 18:44:05 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-11-25 21:57:19 293376 —-a-w- c:\windows\system32\winsrv.dll 2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys 2011-11-18 12:35:08 60416 —-a-w- c:\windows\system32\packager.exe 2011-11-04 19:20:51 916992 —-a-w- c:\windows\system32\wininet.dll 2011-11-04 19:20:51 43520 ——w- c:\windows\system32\licmgr10.dll 2011-11-04 19:20:51 1469440 ——w- c:\windows\system32\inetcpl.cpl 2011-11-04 11:23:59 385024 ——w- c:\windows\system32\html.iec 2011-11-03 15:28:36 386048 —-a-w- c:\windows\system32\qdvd.dll 2011-11-03 15:28:36 1292288 —-a-w- c:\windows\system32\quartz.dll 2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll 2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll 2011-10-25 13:33:08 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 12:52:03 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-10-20 23:26:22 94208 —-a-w- c:\windows\system32\dpl100.dll 2011-10-18 11:13:22 186880 —-a-w- c:\windows\system32\encdec.dll . aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software Run date: 2012-01-15 16:28:15 —————————– 16:28:15.562 OS Version: Windows 5.1.2600 Service Pack 3 16:28:15.562 Number of processors: 1 586 0x401 16:28:15.562 ComputerName: ROLIGAN UserName: 16:28:16.453 Initialize success 16:28:47.140 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 16:28:47.140 Disk 0 Vendor: Maxtor_6L160P0 BAJ41G10 Size: 152587MB BusType: 3 16:28:47.171 Disk 0 MBR read successfully 16:28:47.171 Disk 0 MBR scan 16:28:47.171 Disk 0 Windows XP default MBR code 16:28:47.171 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 152578 MB offset 63 16:28:47.171 Disk 0 scanning sectors +312480315 16:28:47.265 Disk 0 scanning C:\WINDOWS\system32\drivers 16:28:55.609 Service scanning 16:28:56.750 Modules scanning 16:29:04.468 Disk 0 trace - called modules: 16:29:04.484 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS 16:29:04.484 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89bccab8] 16:29:04.484 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x89bbdd98] 16:29:04.843 Scan finished successfully 16:29:21.484 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Administrator\Desktop\MBR.dat" 16:29:21.484 The log file has been saved successfully to "C:\Documents and Settings\Administrator\Desktop\aswMBR - 15-01.txt"
Hi Roligan,

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
———-
I have AVG version 10.0.1416 and you can't disable anti-virus and anti-spyware. I have read through the instructions you have pointed to. Roligan
Hi Roligan,

Let's uninstall AVG (we can reinstall it later). Download and run the AVG uninstall tool found here.

Rerun ComboFix and post the log that is created into your next reply. :)
ComboFix 12-01-15.01 - Administrator 15/01/2012 18:48:16.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1023 [GMT 1:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\WINDOWS
C:\Thumbs.db
.
.
((((((((((((((((((((((((( Files Created from 2011-12-15 to 2012-01-15 )))))))))))))))))))))))))))))))
.
.
2012-01-15 15:02 . 2012-01-15 15:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Adobe Systems
2012-01-15 15:02 . 2012-01-15 15:02 ——– d—–w- c:\program files\Common Files\Adobe Systems Shared
2012-01-13 04:17 . 2012-01-13 04:17 388096 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-01-13 04:17 . 2012-01-13 04:17 ——– d—–w- c:\program files\Trend Micro
2012-01-13 04:06 . 2012-01-13 04:06 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2012-01-13 04:06 . 2012-01-13 08:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-01-12 06:53 . 2012-01-12 06:53 ——– d—–w- c:\program files\ZooskMessenger
2012-01-11 19:01 . 2012-01-11 19:01 ——– d—–w- c:\program files\NT Registry Optimizer
2012-01-11 01:49 . 2012-01-11 01:50 ——– d—–w- c:\documents and settings\Administrator\Application Data\LIVECHAT
2012-01-11 01:49 . 2012-01-11 01:49 ——– d—–w- c:\program files\LiveChat
2012-01-11 01:49 . 2012-01-11 01:49 ——– d—–w- c:\documents and settings\All Users\Application Data\LIVECHAT
2012-01-07 00:32 . 2012-01-07 00:32 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\TechSmith
2012-01-07 00:32 . 2012-01-07 00:32 ——– d—–w- c:\program files\TechSmith
2012-01-04 19:12 . 2012-01-04 19:12 ——– d—–w- c:\documents and settings\Administrator\Application Data\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1
2012-01-02 23:55 . 2012-01-05 02:49 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Spotify
2012-01-02 23:54 . 2012-01-15 17:34 ——– d—–w- c:\documents and settings\Administrator\Application Data\Spotify
2011-12-31 20:47 . 2011-12-31 20:47 ——– d—–w- c:\program files\Common Files\Java
2011-12-31 20:46 . 2011-12-31 20:46 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-12-31 20:46 . 2011-12-31 20:46 ——– d—–w- c:\program files\Java
2011-12-30 23:05 . 2011-12-30 23:05 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\blekkotb
2011-12-29 23:50 . 2011-12-29 23:50 21976 —-a-w- c:\program files\Mozilla Firefox\plc4.dll
2011-12-29 23:50 . 2011-12-29 23:50 20440 —-a-w- c:\program files\Mozilla Firefox\plds4.dll
2011-12-29 23:50 . 2011-12-29 23:50 170968 —-a-w- c:\program files\Mozilla Firefox\softokn3.dll
2011-12-29 23:50 . 2011-12-29 23:50 16856 —-a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2011-12-29 23:50 . 2011-12-29 23:50 154584 —-a-w- c:\program files\Mozilla Firefox\ssl3.dll
2011-12-29 23:50 . 2011-12-29 23:50 105432 —-a-w- c:\program files\Mozilla Firefox\smime3.dll
2011-12-29 23:50 . 2011-12-29 23:50 715216 —-a-w- c:\program files\Mozilla Firefox\uninstall\helper.exe
2011-12-29 23:50 . 2011-12-29 23:50 269272 —-a-w- c:\program files\Mozilla Firefox\updater.exe
2011-12-29 23:50 . 2011-12-29 23:50 19928 —-a-w- c:\program files\Mozilla Firefox\xpcom.dll
2011-12-29 23:50 . 2011-12-29 23:50 16096216 —-a-w- c:\program files\Mozilla Firefox\xul.dll
2011-12-24 07:43 . 2011-12-24 07:43 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\FastStone
2011-12-24 07:43 . 2011-12-24 07:43 ——– d—–w- c:\documents and settings\Administrator\Application Data\FastStone
2011-12-24 07:31 . 2011-12-24 07:31 ——– d—–w- c:\program files\Wisdom-soft AutoScreenRecorder 3 Pro
2011-12-24 06:56 . 2011-12-24 06:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Deskshare
2011-12-24 06:55 . 2011-12-24 06:55 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\DeskShare Data
2011-12-24 06:55 . 2011-12-24 06:55 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Spoon
2011-12-23 13:16 . 2011-12-23 14:13 ——– d—–w- C:\Virtual Spaces
2011-12-23 13:15 . 2011-12-23 13:16 ——– d—–w- C:\Virginie's house
2011-12-23 13:15 . 2011-12-23 13:15 ——– d—–w- C:\Valbonne House
2011-12-23 13:15 . 2012-01-03 09:51 ——– d—–w- C:\Social Media
2011-12-23 13:08 . 2011-12-23 13:12 ——– d—–w- C:\Photos
2011-12-23 13:08 . 2011-12-23 13:08 ——– d—–w- C:\Phone
2011-12-23 13:07 . 2011-12-23 13:07 ——– d—–w- C:\Panomatics
2011-12-23 13:04 . 2011-12-23 13:04 ——– d—–w- C:\Outlook backup
2011-12-23 13:02 . 2011-12-23 13:04 ——– d—–w- C:\Music
2011-12-23 13:01 . 2011-12-23 13:01 ——– d—–w- C:\Jorgen
2011-12-23 13:01 . 2012-01-13 12:58 ——– d—–w- C:\Jobs
2011-12-23 13:01 . 2011-12-23 13:01 ——– d—–w- C:\Fun
2011-12-23 13:01 . 2011-12-23 13:01 ——– d—–w- C:\Divorce
2011-12-23 13:00 . 2011-12-23 13:01 ——– d—–w- C:\Desktop
2011-12-23 13:00 . 2011-12-23 13:00 ——– d—–w- C:\Dell drivers
2011-12-23 13:00 . 2011-12-23 13:00 ——– d—–w- C:\David Kavanagh
2011-12-23 13:00 . 2011-12-23 13:00 ——– d—–w- C:\Catalyst SEO
2011-12-23 12:43 . 2012-01-10 17:10 ——– d—–w- C:\Catalyst Partnership
2011-12-23 12:43 . 2011-12-23 12:43 ——– d—–w- C:\Catalyst Adwords
2011-12-22 11:40 . 2012-01-13 23:39 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\BitTorrentBar
2011-12-22 11:40 . 2011-12-22 11:40 ——– d—–w- c:\program files\BitTorrent
2011-12-22 11:39 . 2012-01-11 19:17 ——– d—–w- c:\documents and settings\Administrator\Application Data\BitTorrent
2011-12-20 16:24 . 2011-12-20 16:24 ——– d—–w- c:\program files\MozBackup
2011-12-20 15:45 . 2011-12-20 15:45 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Batchwork
2011-12-20 02:14 . 2011-12-20 02:14 ——– d-sh–w- c:\documents and settings\Administrator\IECompatCache
2011-12-20 02:13 . 2011-12-20 02:13 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2011-12-20 02:12 . 2011-12-20 02:12 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2011-12-20 02:11 . 2011-12-20 02:11 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2011-12-20 02:03 . 2011-12-20 02:06 ——– dc-h–w- c:\windows\ie8
2011-12-20 02:00 . 2011-08-16 10:45 6144 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2011-12-20 02:00 . 2011-11-04 19:20 602112 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2011-12-20 02:00 . 2011-11-04 19:20 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-12-20 02:00 . 2011-11-04 19:20 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2011-12-20 02:00 . 2011-11-04 19:20 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2011-12-20 02:00 . 2011-11-04 19:20 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2011-12-20 02:00 . 2011-11-04 19:20 2000384 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2011-12-20 02:00 . 2011-11-04 19:20 11081728 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2011-12-17 21:42 . 2011-12-17 21:42 ——– d—–w- c:\documents and settings\Administrator\Application Data\Affilorama
2011-12-17 15:06 . 2011-12-17 15:06 ——– d—–w- c:\windows\system32\Adobe
2011-12-16 22:55 . 2011-12-16 22:55 ——– d—–w- c:\documents and settings\Administrator\Application Data\DDMSettings
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-31 20:46 . 2010-05-17 06:11 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-12-20 18:44 . 2011-06-05 12:11 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-25 21:57 . 2003-03-31 12:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-11-23 13:25 . 2003-03-31 12:00 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-18 12:35 . 2003-03-31 12:00 60416 —-a-w- c:\windows\system32\packager.exe
2011-11-04 19:20 . 2003-03-31 12:00 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2003-03-31 12:00 43520 ——w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2003-03-31 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2004-08-04 05:59 385024 ——w- c:\windows\system32\html.iec
2011-11-03 15:28 . 2003-03-31 12:00 386048 —-a-w- c:\windows\system32\qdvd.dll
2011-11-03 15:28 . 2003-03-31 12:00 1292288 —-a-w- c:\windows\system32\quartz.dll
2011-11-01 16:07 . 2003-03-31 12:00 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2003-03-31 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33 . 2003-03-31 12:00 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2002-08-29 01:04 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-20 23:26 . 2011-10-20 23:26 94208 —-a-w- c:\windows\system32\dpl100.dll
2011-10-18 11:13 . 2003-03-31 12:00 186880 —-a-w- c:\windows\system32\encdec.dll
2011-12-29 23:51 . 2011-12-29 23:51 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\prxtbBitT.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
2011-05-09 08:49 176936 —-a-w- c:\program files\BitTorrentBar\prxtbBitT.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\prxtbBitT.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{88C7F2AA-F93F-432C-8F0E-B7D85967A527}"= "c:\program files\BitTorrentBar\prxtbBitT.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 19550344]
"Spotify"="c:\documents and settings\Administrator\Application Data\Spotify\Spotify.exe" [2012-01-02 4016816]
"Jing"="c:\program files\TechSmith\Jing\Jing.exe" [2010-08-19 3069192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2005-04-05 94208]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2005-04-05 77824]
"Persistence"="c:\windows\System32\igfxpers.exe" [2005-04-05 114688]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"F5D7050v3"="c:\program files\Belkin\F5D7050v3\Belkinwcui.exe" [2007-10-30 1654784]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
LIVECHAT Operator.lnk - c:\program files\LiveChat\LIVECHAT.exe [2011-12-7 13829976]
Socialbox.lnk - c:\program files\Socialbox\Socialbox.exe [N/A]
ZooskMessenger.lnk - c:\program files\ZooskMessenger\ZooskMessenger.exe [2012-1-12 142336]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-BA7E-000000000002}\SC_Acrobat.exe [2012-1-15 25214]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\BitTorrent\\BitTorrent.exe"=
"c:\\Documents and Settings\\Administrator\\Application Data\\Spotify\\spotify.exe"=
"c:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
.
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [12/08/2011 21:30 12184]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [03/12/2010 11:05 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [03/12/2010 11:05 136176]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-03 10:05]
.
2012-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-03 10:05]
.
2012-01-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1214440339-839522115-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-01-12 09:40]
.
2012-01-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1214440339-839522115-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-01-12 09:40]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\x85wc26u.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://blekko.com/?source=c3348dd4&tbp=main&q=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-15 18:55
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1390067357-1214440339-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4e,51,79,84,27,37,2a,45,8e,7e,18,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4e,51,79,84,27,37,2a,45,8e,7e,18,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4e,51,79,84,27,37,2a,45,8e,7e,18,\
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="REMOVED"
.
Completion time: 2012-01-15 18:58:07
ComboFix-quarantined-files.txt 2012-01-15 17:57
.
Pre-Run: 79,764,570,112 bytes free
Post-Run: 79,936,827,392 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 373D03E9C5921C3791BEE681F1864CBC

Attachments:

Hi,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    DDS::  
    uURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\prxtbBitT.dll
    BHO: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\prxtbBitT.dll
    TB: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\prxtbBitT.dll
    TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
    
    Folder::
    c:\documents and settings\administrator\local settings\application data\BitTorrentBar
    c:\program files\BitTorrentBar
    c:\program files\BitTorrent
    c:\documents and settings\administrator\application data\BitTorrent
    
    RegLock::
    [HKEY_USERS\S-1-5-21-1390067357-1214440339-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
    
    RegNull::
    [HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{88C7F2AA-F93F-432C-8F0E-B7D85967A527}"=-
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\BitTorrent\\BitTorrent.exe"=-
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Hi Roligan,

c:\documents and settings\Administrator\My Documents\Downloads\ComboFix.exe >> actually you will need to move the ComboFix.exe to your Desktop and then run the fix that I posted. :)
It deleted loads of bittorrent stuff. I also had lots of 'insufficient resources' messages when I started using it. Might have been a clue - duhhhhhhhhhhhh

Here's the log

ComboFix 12-01-16.05 - Administrator 17/01/2012 3:52.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1362 [GMT 1:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\administrator\application data\BitTorrent
c:\documents and settings\administrator\application data\BitTorrent\100 Best Nature Full HD Wallpapers [1920x1080p] (www.freewallpapers2.blogspot.com).torrent
c:\documents and settings\administrator\application data\BitTorrent\1000+ Wallpaper Collection.torrent
c:\documents and settings\administrator\application data\BitTorrent\1369 HD wallpaper (By) sajiD.rar.torrent
c:\documents and settings\administrator\application data\BitTorrent\550 Windows Wallpaper Collection.torrent
c:\documents and settings\administrator\application data\BitTorrent\apps\3609FC884502A1DF0AA5D9D160C827BB1BD51FC9.btapp
c:\documents and settings\administrator\application data\BitTorrent\apps\player.btapp
c:\documents and settings\administrator\application data\BitTorrent\apps\plus.btapp
c:\documents and settings\administrator\application data\BitTorrent\apps\welcome.btapp
c:\documents and settings\administrator\application data\BitTorrent\dht.dat
c:\documents and settings\administrator\application data\BitTorrent\dht_feed.dat
c:\documents and settings\administrator\application data\BitTorrent\dlimagecache\10E6FBE4D921B475FA5FEC6E9A535A540D6FEED1
c:\documents and settings\administrator\application data\BitTorrent\houghi's_wallpapers.torrent
c:\documents and settings\administrator\application data\BitTorrent\resume.dat
c:\documents and settings\administrator\application data\BitTorrent\rss.dat
c:\documents and settings\administrator\application data\BitTorrent\settings.dat
c:\documents and settings\administrator\application data\BitTorrent\Widescreen HD Nature And Other [2560x1600] Wallpapers Collection 2.torrent
c:\documents and settings\administrator\local settings\application data\BitTorrentBar
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_92_279_CT2790392_Images_634220815653506250_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_92_279_CT2790392_Images_634220879921318750_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_92_279_CT2790392_Images_634220880607100000_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_92_279_CT2790392_Images_634225278165850000_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_92_279_CT2790392_Images_634225279692725000_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_92_279_CT2790392_Images_634225279948156250_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_92_279_CT2790392_Images_634225280304131250_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_92_279_CT2790392_Images_634225280526593750_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_92_279_CT2790392_Images_634225280643975000_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_92_279_CT2790392_Images_634225281436162500_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_92_279_CT2790392_Images_634225281783662500_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_92_279_CT2790392_Images_634225284383662500_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_92_279_CT2790392_Images_634225284881631250_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_92_279_CT2790392_Images_634225287181631250_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_92_279_CT2790392_Images_634225287547412500_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_92_279_CT2790392_Images_634226702545975000_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_92_279_CT2790392_Images_634226713903631250_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_92_279_CT2790392_Images_634244833256762500_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_About_png.p
ng
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Browse_png.
png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Contact_png
.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Hide_png.pn
g
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_LikeIcon_pn
g.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_More_png.pn
g
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_MoreFromPub
lisher_png.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Options_png
.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Privacy_png
.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Refresh_png
.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Upgrade_png
.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_bankImages_FaceBook_Events_png.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_bankImages_FaceBook_Friends_png.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_bankImages_FaceBook_Groups_png.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_bankImages_FaceBook_Home_png.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_bankImages_FaceBook_Inbox_png.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_bankImages_FaceBook_Logout_png.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_bankImages_FaceBook_Photos_png.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_bankImages_FaceBook_Profile_png.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_bankImages_FaceBook_Settings_png.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_bankImages_FaceBook_Share_png.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_bankImages_FaceBook_Status_png.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_images_main_menu_about_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_images_main_menu_clear_history_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_images_main_menu_contact_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_images_main_menu_help_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_images_main_menu_home_page_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_images_main_menu_options_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_images_main_menu_privacy_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_images_main_menu_refresh_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_images_main_menu_shrink_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_images_main_menu_upgrade_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_images_searchengines_go_btn_new_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_images_SearchEngines_images_search_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_images_SearchEngines_news_icon_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_images_searchengines_search_icon_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_images_searchengines_softonic_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_images_SearchEngines_tfd_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_images_SearchEngines_video_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___storage_conduit_com_MarketPlace_cc_704_cc8aceb9-fb96-4894-b4b6-78b5fb004704_Thumbnail_634503449712298469_png.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___weather_conduit_com_images_weather_Default_hazy_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___weather_conduit_com_images_weather_Default_smoke_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\CacheIcons\http___weather_conduit_com_images_weather_Default_smoke_night_gif.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\AddedAppDialog\app-added.js
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\AddedAppDialog\main.html
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\DefualtImages\icon.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\DetectedAppDialog\app-2go.js
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\DetectedAppDialog\main.html
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\DialogsAPI.js
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\EngineFirstTimeDialog\EngineFirstTimeDialog.js
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\EngineFirstTimeDialog\main.html
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\EngineFirstTimeDialog\right-click.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\excanvas.js
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\generalDialogStyle.css
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\NewSearchProtectorDialog\images\ok-button.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\NewSearchProtectorDialog\images\separation-line.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\NewSearchProtectorDialog\images\warning.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\NewSearchProtectorDialog\main.html
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\NewSearchProtectorDialog\SearchProtector.css
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\NewSearchProtectorDialog\SearchProtector.js
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\PIE.htc
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\RoundedCorners.css
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\RoundedCornersIE9.css
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\SearchProtectorBubbleDialog\bubble.css
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\SearchProtectorBubbleDialog\bubble.js
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\SearchProtectorBubbleDialog\images\information.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\SearchProtectorBubbleDialog\images\x-default-LTR.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\SearchProtectorBubbleDialog\images\x-default-RTL.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\SearchProtectorBubbleDialog\images\x-mouseover-LTR.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\SearchProtectorBubbleDialog\images\x-mouseover-RTL.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\SearchProtectorBubbleDialog\main.html
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\SearchProtectorDialog\Images\info.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\SearchProtectorDialog\Images\ok-on.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\SearchProtectorDialog\Images\ok.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\SearchProtectorDialog\main.html
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\SearchProtectorDialog\SearchProtector.css
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\SearchProtectorDialog\SearchProtector.js
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\settings.js
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\ToolbarFirstTimeDialog\images\app-store-icon.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\ToolbarFirstTimeDialog\images\arrow.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\ToolbarFirstTimeDialog\images\divider.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\ToolbarFirstTimeDialog\images\emailNotifier.gif
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\ToolbarFirstTimeDialog\images\facebook.png
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\ToolbarFirstTimeDialog\images\radio.GIF
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\ToolbarFirstTimeDialog\images\Thumbs.db
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\ToolbarFirstTimeDialog\images\truste_welcome.GIF
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\ToolbarFirstTimeDialog\images\weather.GIF
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\ToolbarFirstTimeDialog\main.html
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\ToolbarFirstTimeDialog\ToolbarFirstTimeDialog.css
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\ToolbarFirstTimeDialog\ToolbarFirstTimeDialog.js
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\ToolbarUntrustedAppsApprovalDialog\main.html
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\ToolbarUntrustedAppsApprovalDialog\ToolbarUntrustedAppsApprovalDialog.js
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\UntrustedAddedAppDialog\main.html
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\UntrustedAddedAppDialog\UT-app-dialog-added.js
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\UntrustedAppApprovalDialog\main.html
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\UntrustedAppApprovalDialog\UT-app-dialog-needs-your-approval.js
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\UntrustedAppPendingDialog\main.html
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\UntrustedAppPendingDialog\UT-app-dialog-is-waiting.js
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Dialogs\version.txt
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\EmailNotifier\AccountTypes.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\EmailNotifier\aol.com.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\EmailNotifier\comcast.net.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\EmailNotifier\google.com.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\EmailNotifier\hotmail.com.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\EmailNotifier\yahoo.com.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=GottenApps&locale=en.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=OtherApps&locale=en.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=SharedApps&locale=en.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=Toolbar&locale=en.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\ldrtbBitT.dll
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Repository\conduit_CT2790392_CT2790392\AppsMetaData\data.bck.txt
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Repository\conduit_CT2790392_CT2790392\AppsMetaData\data.txt
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Repository\conduit_CT2790392_CT2790392\DynamicDialogs\data.bck.txt
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Repository\conduit_CT2790392_CT2790392\DynamicDialogs\data.txt
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Repository\conduit_CT2790392_CT2790392\ToolbarLogin\data.bck.txt
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Repository\conduit_CT2790392_CT2790392\ToolbarLogin\data.txt
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Repository\conduit_CT2790392_CT2790392\ToolbarSettings\data.bck.txt
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Repository\conduit_CT2790392_CT2790392\ToolbarSettings\data.txt
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Repository\conduit_CT2790392_en\ToolbarTranslation\data.bck.txt
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Repository\conduit_CT2790392_en\ToolbarTranslation\data.txt
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Rss\http___feeds_news_com_au_public_rss_2_0_news_breaking_news_32_xml.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Rss\http___feeds_news_com_au_public_rss_2_0_news_breaking_news_32_xml_structure
d.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Rss\http___feeds_reuters_com_reuters_topNews.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Rss\http___feeds_reuters_com_reuters_topNews_structured.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Rss\http___newsrss_bbc_co_uk_rss_newsonline_world_edition_front_page_rss_xml.xm
l
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Rss\http___newsrss_bbc_co_uk_rss_newsonline_world_edition_front_page_rss_xml_hi
story.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Rss\http___newsrss_bbc_co_uk_rss_newsonline_world_edition_front_page_rss_xml_st
ructured.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Rss\http___rss_cbc_ca_lineup_latest_xml.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Rss\http___rss_cbc_ca_lineup_latest_xml_structured.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Rss\http___rss_cnn_com_rss_cnn_latest_rss.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Rss\http___rss_cnn_com_rss_cnn_latest_rss_structured.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Rss\http___rss_news_yahoo_com_rss_world.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Rss\http___rss_news_yahoo_com_rss_world_structured.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Rss\http___worldpress_org_feeds_topstories_xml.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Rss\http___worldpress_org_feeds_topstories_xml_structured.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Rss\http___www_thesun_co_uk_sol_homepage_feeds_rss_article312900_ece.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\Rss\http___www_thesun_co_uk_sol_homepage_feeds_rss_article312900_ece_structured
.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\SearchInNewTab\SearchInNewTabContent.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\tbBitT.dll
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\ThirdPartyComponents.xml
c:\documents and settings\administrator\local settings\application data\BitTorrentBar\toolbar.cfg
c:\program files\BitTorrent
c:\program files\BitTorrent\BitTorrent.exe
c:\program files\BitTorrentBar
c:\program files\BitTorrentBar\BitTorrentBarToolbarHelper.exe
c:\program files\BitTorrentBar\GottenAppsContextMenu.xml
c:\program files\BitTorrentBar\ldrtbBitT.dll
c:\program files\BitTorrentBar\OtherAppsContextMenu.xml
c:\program files\bittorrentbar\prxtbBitT.dll
c:\program files\BitTorrentBar\SharedAppsContextMenu.xml
c:\program files\BitTorrentBar\tbBitT.dll
c:\program files\BitTorrentBar\toolbar.cfg
c:\program files\BitTorrentBar\ToolbarContextMenu.xml
c:\program files\BitTorrentBar\uninstall.exe
C:\Thumbs.db
.
.
((((((((((((((((((((((((( Files Created from 2011-12-17 to 2012-01-17 )))))))))))))))))))))))))))))))
.
.
2012-01-17 02:16 . 2012-01-17 02:17 ——– d—–w- C:\## aswSnx private storage
2012-01-15 20:28 . 2012-01-15 20:28 ——– d—–w- c:\program files\TechSmith
2012-01-15 20:08 . 2012-01-17 02:41 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
2012-01-15 20:08 . 2012-01-15 20:08 ——– d—–w- c:\program files\AVAST Software
2012-01-15 15:02 . 2012-01-15 15:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Adobe Systems
2012-01-15 15:02 . 2012-01-15 15:02 ——– d—–w- c:\program files\Common Files\Adobe Systems Shared
2012-01-13 04:17 . 2012-01-13 04:17 388096 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-01-13 04:17 . 2012-01-13 04:17 ——– d—–w- c:\program files\Trend Micro
2012-01-13 04:06 . 2012-01-13 04:06 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2012-01-13 04:06 . 2012-01-13 08:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-01-12 06:53 . 2012-01-12 06:53 ——– d—–w- c:\program files\ZooskMessenger
2012-01-11 19:01 . 2012-01-11 19:01 ——– d—–w- c:\program files\NT Registry Optimizer
2012-01-11 01:49 . 2012-01-11 01:50 ——– d—–w- c:\documents and settings\Administrator\Application Data\LIVECHAT
2012-01-11 01:49 . 2012-01-11 01:49 ——– d—–w- c:\program files\LiveChat
2012-01-11 01:49 . 2012-01-11 01:49 ——– d—–w- c:\documents and settings\All Users\Application Data\LIVECHAT
2012-01-07 00:32 . 2012-01-07 00:32 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\TechSmith
2012-01-04 19:12 . 2012-01-04 19:12 ——– d—–w- c:\documents and settings\Administrator\Application Data\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1
2011-12-31 20:47 . 2011-12-31 20:47 ——– d—–w- c:\program files\Common Files\Java
2011-12-31 20:46 . 2011-12-31 20:46 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-12-31 20:46 . 2011-12-31 20:46 ——– d—–w- c:\program files\Java
2011-12-30 23:05 . 2011-12-30 23:05 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\blekkotb
2011-12-29 23:50 . 2011-12-29 23:50 21976 —-a-w- c:\program files\Mozilla Firefox\plc4.dll
2011-12-29 23:50 . 2011-12-29 23:50 20440 —-a-w- c:\program files\Mozilla Firefox\plds4.dll
2011-12-29 23:50 . 2011-12-29 23:50 170968 —-a-w- c:\program files\Mozilla Firefox\softokn3.dll
2011-12-29 23:50 . 2011-12-29 23:50 16856 —-a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2011-12-29 23:50 . 2011-12-29 23:50 154584 —-a-w- c:\program files\Mozilla Firefox\ssl3.dll
2011-12-29 23:50 . 2011-12-29 23:50 105432 —-a-w- c:\program files\Mozilla Firefox\smime3.dll
2011-12-29 23:50 . 2011-12-29 23:50 715216 —-a-w- c:\program files\Mozilla Firefox\uninstall\helper.exe
2011-12-29 23:50 . 2011-12-29 23:50 269272 —-a-w- c:\program files\Mozilla Firefox\updater.exe
2011-12-29 23:50 . 2011-12-29 23:50 19928 —-a-w- c:\program files\Mozilla Firefox\xpcom.dll
2011-12-29 23:50 . 2011-12-29 23:50 16096216 —-a-w- c:\program files\Mozilla Firefox\xul.dll
2011-12-24 07:43 . 2011-12-24 07:43 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\FastStone
2011-12-24 07:43 . 2011-12-24 07:43 ——– d—–w- c:\documents and settings\Administrator\Application Data\FastStone
2011-12-24 07:31 . 2011-12-24 07:31 ——– d—–w- c:\program files\Wisdom-soft AutoScreenRecorder 3 Pro
2011-12-24 06:56 . 2011-12-24 06:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Deskshare
2011-12-24 06:55 . 2011-12-24 06:55 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\DeskShare Data
2011-12-24 06:55 . 2011-12-24 06:55 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Spoon
2011-12-23 13:16 . 2011-12-23 14:13 ——– d—–w- C:\Virtual Spaces
2011-12-23 13:15 . 2011-12-23 13:16 ——– d—–w- C:\Virginie's house
2011-12-23 13:15 . 2011-12-23 13:15 ——– d—–w- C:\Valbonne House
2011-12-23 13:15 . 2012-01-15 20:13 ——– d—–w- C:\Social Media
2011-12-23 13:08 . 2011-12-23 13:12 ——– d—–w- C:\Photos
2011-12-23 13:08 . 2011-12-23 13:08 ——– d—–w- C:\Phone
2011-12-23 13:07 . 2011-12-23 13:07 ——– d—–w- C:\Panomatics
2011-12-23 13:04 . 2011-12-23 13:04 ——– d—–w- C:\Outlook backup
2011-12-23 13:02 . 2011-12-23 13:04 ——– d—–w- C:\Music
2011-12-23 13:01 . 2011-12-23 13:01 ——– d—–w- C:\Jorgen
2011-12-23 13:01 . 2012-01-13 12:58 ——– d—–w- C:\Jobs
2011-12-23 13:01 . 2011-12-23 13:01 ——– d—–w- C:\Fun
2011-12-23 13:01 . 2011-12-23 13:01 ——– d—–w- C:\Divorce
2011-12-23 13:00 . 2011-12-23 13:01 ——– d—–w- C:\Desktop
2011-12-23 13:00 . 2011-12-23 13:00 ——– d—–w- C:\Dell drivers
2011-12-23 13:00 . 2011-12-23 13:00 ——– d—–w- C:\David Kavanagh
2011-12-23 13:00 . 2011-12-23 13:00 ——– d—–w- C:\Catalyst SEO
2011-12-23 12:43 . 2012-01-10 17:10 ——– d—–w- C:\Catalyst Partnership
2011-12-23 12:43 . 2011-12-23 12:43 ——– d—–w- C:\Catalyst Adwords
2011-12-20 16:24 . 2011-12-20 16:24 ——– d—–w- c:\program files\MozBackup
2011-12-20 15:45 . 2011-12-20 15:45 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Batchwork
2011-12-20 02:14 . 2011-12-20 02:14 ——– d-sh–w- c:\documents and settings\Administrator\IECompatCache
2011-12-20 02:13 . 2011-12-20 02:13 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2011-12-20 02:12 . 2011-12-20 02:12 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2011-12-20 02:11 . 2011-12-20 02:11 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2011-12-20 02:03 . 2011-12-20 02:06 ——– dc-h–w- c:\windows\ie8
2011-12-20 02:00 . 2011-08-16 10:45 6144 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2011-12-20 02:00 . 2011-11-04 19:20 602112 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2011-12-20 02:00 . 2011-11-04 19:20 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-12-20 02:00 . 2011-11-04 19:20 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2011-12-20 02:00 . 2011-11-04 19:20 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2011-12-20 02:00 . 2011-11-04 19:20 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2011-12-20 02:00 . 2011-11-04 19:20 2000384 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2011-12-20 02:00 . 2011-11-04 19:20 11081728 -c—-w- c:\windows\system32\dllcache\ieframe.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-31 20:46 . 2010-05-17 06:11 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-12-20 18:44 . 2011-06-05 12:11 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-25 21:57 . 2003-03-31 12:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-11-23 13:25 . 2003-03-31 12:00 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-18 12:35 . 2003-03-31 12:00 60416 —-a-w- c:\windows\system32\packager.exe
2011-11-04 19:20 . 2003-03-31 12:00 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2003-03-31 12:00 43520 ——w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2003-03-31 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2004-08-04 05:59 385024 ——w- c:\windows\system32\html.iec
2011-11-03 15:28 . 2003-03-31 12:00 386048 —-a-w- c:\windows\system32\qdvd.dll
2011-11-03 15:28 . 2003-03-31 12:00 1292288 —-a-w- c:\windows\system32\quartz.dll
2011-11-01 16:07 . 2003-03-31 12:00 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2003-03-31 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33 . 2003-03-31 12:00 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2002-08-29 01:04 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-20 23:26 . 2011-10-20 23:26 94208 —-a-w- c:\windows\system32\dpl100.dll
2011-12-29 23:51 . 2011-12-29 23:51 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-15_17.55.24 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-11 23:02 . 2009-07-11 23:02 51008 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll
- 2009-07-11 22:02 . 2009-07-11 22:02 51008 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll
+ 2009-07-11 23:02 . 2009-07-11 23:02 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll
- 2009-07-11 22:02 . 2009-07-11 22:02 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll
- 2009-07-11 22:02 . 2009-07-11 22:02 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll
+ 2009-07-11 23:02 . 2009-07-11 23:02 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll
- 2009-07-11 22:02 . 2009-07-11 22:02 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll
+ 2009-07-11 23:02 . 2009-07-11 23:02 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll
- 2009-07-11 22:02 . 2009-07-11 22:02 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll
+ 2009-07-11 23:02 . 2009-07-11 23:02 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll
- 2009-07-11 22:02 . 2009-07-11 22:02 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll
+ 2009-07-11 23:02 . 2009-07-11 23:02 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll
- 2009-07-11 22:02 . 2009-07-11 22:02 61760 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll
+ 2009-07-11 23:02 . 2009-07-11 23:02 61760 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll
- 2009-07-11 22:02 . 2009-07-11 22:02 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll
+ 2009-07-11 23:02 . 2009-07-11 23:02 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll
- 2009-07-11 22:02 . 2009-07-11 22:02 53568 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll
+ 2009-07-11 23:02 . 2009-07-11 23:02 53568 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll
+ 2009-07-11 23:02 . 2009-07-11 23:02 63296 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll
- 2009-07-11 22:02 . 2009-07-11 22:02 63296 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll
+ 2009-07-11 23:02 . 2009-07-11 23:02 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll
- 2009-07-11 22:02 . 2009-07-11 22:02 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll
+ 2009-07-11 23:02 . 2009-07-11 23:02 35648 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll
- 2009-07-11 22:02 . 2009-07-11 22:02 35648 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll
+ 2009-07-11 23:05 . 2009-07-11 23:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll
- 2009-07-11 22:05 . 2009-07-11 22:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll
- 2009-07-11 22:05 . 2009-07-11 22:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll
+ 2009-07-11 23:05 . 2009-07-11 23:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll
+ 2012-01-16 22:02 . 2012-01-16 22:02 16384 c:\windows\Temp\Perflib_Perfdata_48c.dat
+ 2012-01-16 12:22 . 2005-09-23 20:28 14848 c:\windows\system32\spool\drivers\w32x86\ad2kregp.dll
- 2012-01-15 15:48 . 2005-09-23 20:28 14848 c:\windows\system32\spool\drivers\w32x86\ad2kregp.dll
- 2012-01-15 15:02 . 2012-01-15 15:52 25214 c:\windows\Installer\{AC76BA86-1033-0000-BA7E-000000000002}\SC_Distiller.exe
+ 2012-01-15 15:02 . 2012-01-16 12:24 25214 c:\windows\Installer\{AC76BA86-1033-0000-BA7E-000000000002}\SC_Distiller.exe
- 2012-01-15 15:02 . 2012-01-15 15:52 25214 c:\windows\Installer\{AC76BA86-1033-0000-BA7E-000000000002}\SC_Acrobat_Standard.exe
+ 2012-01-15 15:02 . 2012-01-16 12:24 25214 c:\windows\Installer\{AC76BA86-1033-0000-BA7E-000000000002}\SC_Acrobat_Standard.exe
+ 2012-01-15 15:02 . 2012-01-16 12:24 25214 c:\windows\Installer\{AC76BA86-1033-0000-BA7E-000000000002}\SC_Acrobat.exe
- 2012-01-15 15:02 . 2012-01-15 15:52 25214 c:\windows\Installer\{AC76BA86-1033-0000-BA7E-000000000002}\SC_Acrobat.exe
- 2012-01-15 15:02 . 2012-01-15 15:52 7278 c:\windows\Installer\{AC76BA86-1033-0000-BA7E-000000000002}\SC_ELEMENTS_DT.exe
+ 2012-01-15 15:02 . 2012-01-16 12:24 7278 c:\windows\Installer\{AC76BA86-1033-0000-BA7E-000000000002}\SC_ELEMENTS_DT.exe
- 2011-04-05 17:34 . 2011-04-05 17:34 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
+ 2009-07-11 23:02 . 2009-07-11 23:02 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
- 2011-04-05 17:34 . 2011-04-05 17:34 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
+ 2009-07-11 23:02 . 2009-07-11 23:02 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
- 2011-04-05 17:34 . 2011-04-05 17:34 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
+ 2009-07-11 23:05 . 2009-07-11 23:05 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
- 2009-07-11 22:02 . 2009-07-11 22:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
+ 2009-07-11 23:02 . 2009-07-11 23:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
+ 2012-01-16 12:22 . 2005-09-23 20:27 143360 c:\windows\system32\spool\drivers\w32x86\ad2kuigp.dll
- 2012-01-15 15:48 . 2005-09-23 20:27 143360 c:\windows\system32\spool\drivers\w32x86\ad2kuigp.dll
- 2012-01-07 00:32 . 2012-01-07 00:32 316416 c:\windows\Installer\{2AD738DC-FC24-4342-A2DA-BB6DCCF6B048}\IconA17C9A58.exe
+ 2012-01-15 20:28 . 2012-01-15 20:28 316416 c:\windows\Installer\{2AD738DC-FC24-4342-A2DA-BB6DCCF6B048}\IconA17C9A58.exe
+ 2009-07-11 23:02 . 2009-07-11 23:02 3780424 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll
- 2009-07-11 22:02 . 2009-07-11 22:02 3780424 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll
- 2009-07-11 22:02 . 2009-07-11 22:02 3765048 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll
+ 2009-07-11 23:02 . 2009-07-11 23:02 3765048 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll
+ 2012-01-15 20:28 . 2012-01-15 20:28 2449408 c:\windows\Installer\9dabd3.msi
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 19550344]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" [2006-03-30 313472]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2005-04-05 94208]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2005-04-05 77824]
"Persistence"="c:\windows\System32\igfxpers.exe" [2005-04-05 114688]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"F5D7050v3"="c:\program files\Belkin\F5D7050v3\Belkinwcui.exe" [2007-10-30 1654784]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
LIVECHAT Operator.lnk - c:\program files\LiveChat\LIVECHAT.exe [2011-12-7 13829976]
Socialbox.lnk - c:\program files\Socialbox\Socialbox.exe [N/A]
ZooskMessenger.lnk - c:\program files\ZooskMessenger\ZooskMessenger.exe [2012-1-12 142336]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-BA7E-000000000002}\SC_Acrobat.exe [2012-1-15 25214]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
.
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [12/08/2011 21:30 12184]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [03/12/2010 11:05 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [03/12/2010 11:05 136176]
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-03 10:05]
.
2012-01-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-03 10:05]
.
2012-01-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1214440339-839522115-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-01-12 09:40]
.
2012-01-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1214440339-839522115-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-01-12 09:40]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\x85wc26u.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://blekko.com/?source=c3348dd4&tbp=main&q=
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Spotify - c:\documents and settings\Administrator\Application Data\Spotify\Spotify.exe
AddRemove-BitTorrent - c:\program files\BitTorrent\BitTorrent.exe
AddRemove-BitTorrentBar Toolbar - c:\program files\BitTorrentBar\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-17 04:07
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-01-17 04:12:13
ComboFix-quarantined-files.txt 2012-01-17 03:12
ComboFix2.txt 2012-01-15 17:58
.
Pre-Run: 79,774,519,296 bytes free
Post-Run: 79,824,998,400 bytes free
.
- - End Of File - - AB89D12B0A872464A7108196E91B147B

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI