This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan + Registry Entries

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Tom,

Go ahead an empty out all you junk/spam mail. Do you know what theses are, and do you have a reason to use them?

F:\Program Files\CyberKit\CyberKit.exe
E:\Documents and Settings\John.MPARAM-2006\Local Settings\Temp\RarSFX1\RockXP4_.exe
F:\Documents and Settings\John.MPARAM-2006\Local Settings\Temp\RarSFX1\RockXP4_.exe

All the others in restore points etc… will be cleared out when we arer ready to rap thigs up :)


After chatting with ShadowPuterDude the creator of FixIEDef (the tool we tried to run in post # 7 that failed) we think that your systems WMI engine is damaged, and could be the reason for the "Expected Object not found" error message.

You can use either Dial-a-Fix or the WMI Diagnosis Utility to repair the WMI.

*Note* If you use Dial-a-Fix to repair the WMI; click-on the hammer button to access the Tools section and then select Reinstall WMI/WBEM and click the "GO" button.

After the repair, please try to re-run FixIEDef using the directions in post # 7, and post the log (if successful) in your next reply :thumbup:
Thanks for that, very interesting programs! And thanks also to ShadowPuterDude for his input. Cleaned up files as noted above. I tested to see if I can now launch IE Explorer, and it appears that I can. Then ran Dial a Fix with success, as FixIEDef worked, and returned the following log: ******************************************************************************** * * * FixIEDef Log * * Version 1.6.10.6263 * * * ******************************************************************************** Created at 14:20:22 on Sunday, October 19, 2008 Time Zone : (GMT-07:00) Mountain Time (US & Canada) Logged On User : JK Operating System : Microsoft Windows XP Professional Service Pack 2 OS Version : 5.1.2600 System Langauge : English (United States) Keyboard Layout : English (United States) Processor : X86 Intel® Pentium® 4 CPU 2.40GHz System Drive : C:\ Windows Directory : C:\WINDOWS System Directory : C:\WINDOWS\system32 System Drive Type : Fixed System Drive Status : READY System Drive Label : NS2_C System Drive Size : 110.23 GB System Drive Free : 7.51 GB Total Physical Memory: 1023 MB Free Physical Memory : 485 MB Total Page File : 1023 MB Free Page File : 1977 MB Total Virtual Memory : 2048 MB Free Virtual Memory : 1976 MB Boot State : Normal boot ——————————————————————————– !!! Files that have been deleted !!! C:\WINDOWS\system32\tmp.txt ——————————————————————————– !!! Directories that have been removed !!! No malicious directories to be removed ——————————————————————————– !!! Registry entries that have been removed !!! No malicious Registry entries found ================================================================================ All Done :) ShadowPuterDude Safe Surfing!!!
Hello Tom,

Just for fun (if you don’t mind helping me out) lets see if repairing you WMI engine will allow RSIT to run now.

RSIT
  • Download random's system information tool (RSIT) by random/random from here.
  • It is important that is saved to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<

Also let me know if you are having any other problems before we start the clean up process :thumbup:
No problem, I was also curious:

Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-19 16:02:24
Microsoft Windows XP Professional Service Pack 2
System drive C: has 8 GB (7%) free of 110 GB
Total RAM: 1023 MB (48% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:02:41, on 2008-10-19
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
f:\Program Files\FaxTalk Messenger Pro 7.0\FTMSGSVC.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
f:\Program Files\FaxTalk Messenger Pro 7.0\FAPIEXE.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
F:\Program Files\FaxTalk Messenger Pro 7.0\FTClCtrl.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\JK.NS2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
f:\PROGRA~1\POPFile\popfileib.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\PROGRA~1\MICROS~1\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Thumbs5\Thumbs.exe
C:\PROGRA~1\AVG\AVG8\avgscanx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Maxthon\Maxthon.exe
C:\Documents and Settings\JK.NS2\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\JK.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [FaxTalk Messenger Pro 7.0] "F:\Program Files\FaxTalk Messenger Pro 7.0\FTClCtrl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [FaxTalk CallControl 7.0] "f:\Program Files\FaxTalk Messenger Pro 7.0\FTClCtrl.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\JK.NS2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-18\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'Default user')
O4 - .DEFAULT User Startup: Run POPFile.lnk = D:\Program Files\POPFile\runpopfile.exe (User 'Default user')
O4 - Startup: Run POPFile.lnk = F:\Program Files\POPFile\runpopfile.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {66D393D5-4D80-497C-9F4F-F3839E090202} (PlayerOCX Control) - http://www.pysoft.com/Downloads/WebCamPlayerOCX.cab
O16 - DPF: {8FEED82A-42A6-4117-A803-7EC3EB9339E0} (ClientControl Class) - http://192.168.0.187:8080/plugin/client.cab
O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://142.179.144.33:8080/plugin/h263ctrl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D15F4A69-7188-4C20-A150-F80E084BBFFE}: NameServer = 75.154.132.68,75.154.132.100
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll ohnova.dll qivqgb.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FaxTalk Messenger Pro 7.0 - Thought Communications, Inc. - f:\Program Files\FaxTalk Messenger Pro 7.0\FTMSGSVC.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

–
End of file - 10818 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUser.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-07-07 1562448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-10-12 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar3.dll [2007-01-19 2403392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll [2008-10-15 652784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-10-12 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-10-12 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14 225280]
{724d43a0-0d85-11d4-9908-00400523e39a} - &RoboForm - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2008-07-20 5751624]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar3.dll [2007-01-19 2403392]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray"=C:\WINDOWS\ehome\ehtray.exe [2004-08-10 59392]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-10-12 144792]
"FaxTalk Messenger Pro 7.0"=F:\Program Files\FaxTalk Messenger Pro 7.0\FTClCtrl.exe [2004-12-22 122880]
"Acrobat Assistant 7.0"=C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2004-12-14 483328]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-09-29 1234712]
"FaxTalk CallControl 7.0"=f:\Program Files\FaxTalk Messenger Pro 7.0\FTClCtrl.exe [2004-12-22 122880]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-08-04 1667584]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-07-14 68856]
"Google Update"=C:\Documents and Settings\JK.NS2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-08 133104]
"RoboForm"=C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2008-07-20 160592]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe

C:\Documents and Settings\JK.NS2\Start Menu\Programs\Startup
Run POPFile.lnk - F:\Program Files\POPFile\runpopfile.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="avgrsstx.dll ohnova.dll qivqgb.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"NoDrives"=
"NoDriveAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e38c648a-51a7-11dd-a30d-806d6172696f}]
shell\AutoRun\command - L:\WD_Windows_Tools\Setup.exe


======File associations======

.js - open - "C:\Downloads 2008\Complete Torrents\Adobe CS3 Crack Collection - GeckoGold\Dreamweaver.exe","%1"
.reg - open - regedit.exe "%1" %*

======List of files/folders created in the last 1 months======

2008-10-19 14:18:04 —-D—- C:\WINDOWS\LastGood
2008-10-15 23:56:44 —-HD—- C:\WINDOWS\PIF
2008-10-15 21:14:22 —-D—- C:\_OTMoveIt
2008-10-13 11:07:26 —-D—- C:\Documents and Settings\JK.NS2\Application Data\Download Manager
2008-10-12 16:40:47 —-D—- C:\Program Files\Sun
2008-10-12 16:40:13 —-A—- C:\WINDOWS\system32\deploytk.dll
2008-10-12 16:40:12 —-A—- C:\WINDOWS\system32\javaws.exe
2008-10-12 16:40:12 —-A—- C:\WINDOWS\system32\javaw.exe
2008-10-12 16:40:12 —-A—- C:\WINDOWS\system32\java.exe
2008-10-12 16:33:55 —-A—- C:\WINDOWS\system32\PY_Uninstal.exe
2008-10-12 16:20:35 —-A—- C:\WINDOWS\system32\PsisDecd.dll
2008-10-12 15:35:17 —-A—- C:\hcwclear.txt
2008-10-12 15:32:22 —-A—- C:\WINDOWS\system32\xaudioD2_2.dll
2008-10-12 15:32:21 —-A—- C:\WINDOWS\system32\XAPOFXD1_1.dll
2008-10-12 15:32:21 —-A—- C:\WINDOWS\system32\XactEngineD3_2.dll
2008-10-12 15:32:21 —-A—- C:\WINDOWS\system32\XactEngineA3_2.dll
2008-10-12 15:32:21 —-A—- C:\WINDOWS\system32\X3DAudioD1_4.dll
2008-10-12 15:32:20 —-A—- C:\WINDOWS\system32\dinput8d.dll
2008-10-12 15:32:20 —-A—- C:\WINDOWS\system32\D3dx9d_39.dll
2008-10-12 15:32:19 —-A—- C:\WINDOWS\system32\d3dx9d_33.dll
2008-10-12 15:32:19 —-A—- C:\WINDOWS\system32\D3DX10d_39.dll
2008-10-12 15:32:18 —-A—- C:\WINDOWS\system32\d3dref9.dll
2008-10-12 15:32:18 —-A—- C:\WINDOWS\system32\d3d9d.dll
2008-10-12 15:30:08 —-A—- C:\WINDOWS\system32\XAudio2_2.dll
2008-10-12 15:30:08 —-A—- C:\WINDOWS\system32\XAPOFX1_1.dll
2008-10-12 15:30:08 —-A—- C:\WINDOWS\system32\xactengine3_2.dll
2008-10-12 15:30:07 —-A—- C:\WINDOWS\system32\d3dx10_39.dll
2008-10-12 15:30:07 —-A—- C:\WINDOWS\system32\D3DCompiler_39.dll
2008-10-12 15:30:06 —-A—- C:\WINDOWS\system32\D3DX9_39.dll
2008-10-12 15:30:05 —-A—- C:\WINDOWS\system32\XAudio2_1.dll
2008-10-12 15:30:05 —-A—- C:\WINDOWS\system32\XAPOFX1_0.dll
2008-10-12 15:30:04 —-A—- C:\WINDOWS\system32\xactengine3_1.dll
2008-10-12 15:30:04 —-A—- C:\WINDOWS\system32\X3DAudio1_4.dll
2008-10-12 15:30:03 —-A—- C:\WINDOWS\system32\d3dx10_38.dll
2008-10-12 15:30:03 —-A—- C:\WINDOWS\system32\D3DCompiler_38.dll
2008-10-12 15:30:02 —-A—- C:\WINDOWS\system32\D3DX9_38.dll
2008-10-12 15:30:01 —-A—- C:\WINDOWS\system32\XAudio2_0.dll
2008-10-12 15:30:01 —-A—- C:\WINDOWS\system32\xactengine3_0.dll
2008-10-12 15:30:00 —-A—- C:\WINDOWS\system32\X3DAudio1_3.dll
2008-10-12 15:29:59 —-A—- C:\WINDOWS\system32\D3DX9_37.dll
2008-10-12 15:29:59 —-A—- C:\WINDOWS\system32\d3dx10_37.dll
2008-10-12 15:29:59 —-A—- C:\WINDOWS\system32\D3DCompiler_37.dll
2008-10-12 15:29:58 —-A—- C:\WINDOWS\system32\xactengine2_10.dll
2008-10-12 15:29:56 —-A—- C:\WINDOWS\system32\d3dx9_36.dll
2008-10-12 15:29:56 —-A—- C:\WINDOWS\system32\d3dx10_36.dll
2008-10-12 15:29:56 —-A—- C:\WINDOWS\system32\D3DCompiler_36.dll
2008-10-12 15:29:55 —-A—- C:\WINDOWS\system32\xactengine2_9.dll
2008-10-12 15:29:54 —-A—- C:\WINDOWS\system32\d3dx10_35.dll
2008-10-12 15:29:54 —-A—- C:\WINDOWS\system32\D3DCompiler_35.dll
2008-10-12 15:29:53 —-A—- C:\WINDOWS\system32\d3dx9_35.dll
2008-10-12 15:29:52 —-A—- C:\WINDOWS\system32\xactengine2_8.dll
2008-10-12 15:29:52 —-A—- C:\WINDOWS\system32\X3DAudio1_2.dll
2008-10-12 15:29:51 —-A—- C:\WINDOWS\system32\d3dx10_34.dll
2008-10-12 15:29:51 —-A—- C:\WINDOWS\system32\D3DCompiler_34.dll
2008-10-12 15:29:50 —-A—- C:\WINDOWS\system32\xinput1_3.dll
2008-10-12 15:29:50 —-A—- C:\WINDOWS\system32\d3dx9_34.dll
2008-10-12 15:29:48 —-A—- C:\WINDOWS\system32\xactengine2_7.dll
2008-10-12 15:29:47 —-A—- C:\WINDOWS\system32\d3dx10_33.dll
2008-10-12 15:29:47 —-A—- C:\WINDOWS\system32\D3DCompiler_33.dll
2008-10-12 15:29:45 —-A—- C:\WINDOWS\system32\d3dx9_33.dll
2008-10-12 15:29:44 —-A—- C:\WINDOWS\system32\xactengine2_6.dll
2008-10-12 15:29:43 —-A—- C:\WINDOWS\system32\xactengine2_5.dll
2008-10-12 15:29:43 —-A—- C:\WINDOWS\system32\d3dx9_32.dll
2008-10-12 15:29:42 —-A—- C:\WINDOWS\system32\xactengine2_4.dll
2008-10-12 15:29:42 —-A—- C:\WINDOWS\system32\x3daudio1_1.dll
2008-10-12 15:29:41 —-A—- C:\WINDOWS\system32\xactengine2_3.dll
2008-10-12 15:29:41 —-A—- C:\WINDOWS\system32\d3dx9_31.dll
2008-10-12 15:29:40 —-A—- C:\WINDOWS\system32\xinput1_2.dll
2008-10-12 15:29:40 —-A—- C:\WINDOWS\system32\xactengine2_2.dll
2008-10-12 15:29:39 —-A—- C:\WINDOWS\system32\xinput1_1.dll
2008-10-12 15:29:39 —-A—- C:\WINDOWS\system32\xactengine2_1.dll
2008-10-12 15:29:22 —-A—- C:\WINDOWS\system32\d3dx9_30.dll
2008-10-12 15:29:20 —-A—- C:\WINDOWS\system32\xactengine2_0.dll
2008-10-12 15:29:20 —-A—- C:\WINDOWS\system32\x3daudio1_0.dll
2008-10-12 15:29:19 —-A—- C:\WINDOWS\system32\d3dx9_29.dll
2008-10-12 15:29:19 —-A—- C:\WINDOWS\system32\d3dx9_28.dll
2008-10-12 15:29:18 —-A—- C:\WINDOWS\system32\xinput9_1_0.dll
2008-10-12 15:29:17 —-A—- C:\WINDOWS\system32\d3dx9_27.dll
2008-10-12 15:29:16 —-A—- C:\WINDOWS\system32\d3dx9_26.dll
2008-10-12 15:29:15 —-A—- C:\WINDOWS\system32\d3dx9_25.dll
2008-10-12 15:29:11 —-A—- C:\WINDOWS\system32\d3dx9_24.dll
2008-10-12 15:24:26 —-D—- C:\Program Files\Microsoft DirectX SDK (August 2008)
2008-10-12 15:24:20 —-D—- C:\WINDOWS\Logs
2008-10-12 15:24:09 —-A—- C:\WINDOWS\dxsdkuninst.exe
2008-10-12 13:46:34 —-A—- C:\WINDOWS\system32\wmvdmoe.dll
2008-10-12 13:46:24 —-D—- C:\Documents and Settings\All Users.WINDOWS\Application Data\PY_Software
2008-10-12 13:46:12 —-D—- C:\Program Files\Active WebCam
2008-10-12 13:32:42 —-A—- C:\WINDOWS\system32\IVacDlg.dll
2008-10-12 13:32:42 —-A—- C:\WINDOWS\system32\IVacCtrl.dll
2008-10-12 12:22:08 —-D—- C:\!FixIEDef
2008-10-12 01:35:31 —-SHD—- C:\RECYCLER
2008-10-12 01:00:49 —-D—- C:\fae69869fb36c79c714704
2008-10-11 22:41:45 —-D—- C:\WINDOWS\temp
2008-10-11 22:41:37 —-A—- C:\ComboFix.txt
2008-10-11 18:07:47 —-D—- C:\rsit
2008-10-11 14:34:08 —-D—- C:\WINDOWS\Prefetch
2008-10-11 13:48:10 —-RAH—- C:\WINDOWS\system32\logonui.exe.manifest
2008-10-11 13:28:59 —-A—- C:\WINDOWS\system32\irclass.dll
2008-10-11 13:28:58 —-A—- C:\WINDOWS\system32\spxcoins.dll
2008-10-11 13:28:36 —-RA—- C:\WINDOWS\SET5C.tmp
2008-10-11 13:28:32 —-RA—- C:\WINDOWS\SET50.tmp
2008-10-11 13:28:29 —-RA—- C:\WINDOWS\SET4D.tmp
2008-10-07 21:16:05 —-D—- C:\Program Files\CommTest
2008-10-07 21:06:43 —-AD—- C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-10-07 18:49:37 —-D—- C:\Program Files\FTB2070
2008-09-28 22:40:15 —-D—- C:\Torrents

======List of files/folders modified in the last 1 months======

2008-10-19 14:19:56 —-D—- C:\WINDOWS\system32
2008-10-19 14:18:58 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-19 14:18:47 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-10-19 14:18:40 —-D—- C:\WINDOWS\system32\wbem
2008-10-19 14:18:08 —-D—- C:\WINDOWS\security
2008-10-19 14:18:04 —-D—- C:\WINDOWS
2008-10-19 14:16:27 —-D—- C:\WINDOWS\system32\CatRoot2
2008-10-18 23:03:13 —-D—- C:\Program Files\Thumbs5
2008-10-18 22:57:26 —-D—- C:\Documents and Settings\All Users.WINDOWS\Application Data\Google Updater
2008-10-17 20:14:41 —-A—- C:\WINDOWS\ModemLog_U.S. Robotics V.92 Voice Host Int.txt
2008-10-17 00:00:11 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-10-15 08:41:46 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-10-15 00:04:21 —-SD—- C:\WINDOWS\Tasks
2008-10-13 16:36:36 —-HD—- C:\$AVG8.VAULT$
2008-10-13 11:10:40 —-D—- C:\Documents and Settings\JK.NS2\Application Data\Adobe
2008-10-13 11:03:03 —-SHD—- C:\WINDOWS\Installer
2008-10-13 11:01:49 —-D—- C:\Program Files\Adobe
2008-10-13 10:10:11 —-D—- C:\Downloads 2008
2008-10-12 16:40:47 —-RAD—- C:\Program Files
2008-10-12 16:39:45 —-D—- C:\Program Files\Java
2008-10-12 16:34:57 —-D—- C:\Program Files\Maxthon
2008-10-12 16:20:56 —-D—- C:\WINDOWS\system32\drivers
2008-10-12 16:20:54 —-HD—- C:\WINDOWS\inf
2008-10-12 16:20:32 —-D—- C:\WINDOWS\system32\CatRoot
2008-10-12 15:54:14 —-RSD—- C:\WINDOWS\assembly
2008-10-12 15:54:14 —-D—- C:\WINDOWS\Microsoft.NET
2008-10-12 15:44:07 —-D—- C:\WINDOWS\Minidump
2008-10-12 15:35:19 —-D—- C:\Program Files\WinTV
2008-10-12 15:29:07 —-D—- C:\WINDOWS\system32\directx
2008-10-12 15:25:47 —-D—- C:\WINDOWS\WinSxS
2008-10-12 13:40:35 —-D—- C:\Documents and Settings\JK.NS2\Application Data\uTorrent
2008-10-12 13:32:43 —-D—- C:\WINDOWS\system
2008-10-12 13:30:44 —-D—- C:\Drivers
2008-10-12 01:03:28 —-D—- C:\Program Files\Common Files\Adobe
2008-10-12 01:01:42 —-HDC—- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2008-10-11 22:41:37 —-AD—- C:\QooBox
2008-10-11 22:37:54 —-A—- C:\WINDOWS\system.ini
2008-10-11 22:35:20 —-D—- C:\Program Files\Common Files
2008-10-11 22:35:19 —-D—- C:\WINDOWS\AppPatch
2008-10-11 13:57:04 —-D—- C:\WINDOWS\system32\config
2008-10-11 13:57:04 —-A—- C:\WINDOWS\setuplog.txt
2008-10-11 13:57:04 —-A—- C:\WINDOWS\imsins.BAK
2008-10-11 13:55:26 —-D—- C:\WINDOWS\ehome
2008-10-11 13:48:53 —-D—- C:\WINDOWS\system32\ias
2008-10-11 13:48:16 —-A—- C:\WINDOWS\ODBCINST.INI
2008-10-11 13:48:14 —-RD—- C:\WINDOWS\Web
2008-10-11 13:48:02 —-RAH—- C:\WINDOWS\system32\cdplayer.exe.manifest
2008-10-11 13:44:29 —-D—- C:\Program Files\Messenger
2008-10-11 13:42:29 —-SH—- C:\boot.ini
2008-10-11 13:28:48 —-ASH—- C:\Documents and Settings\All Users.WINDOWS\Application Data\desktop.ini
2008-10-11 09:09:30 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-11 07:24:50 —-D—- C:\WINDOWS\system32\Setup
2008-10-11 07:24:49 —-D—- C:\WINDOWS\Help
2008-10-11 07:24:42 —-D—- C:\WINDOWS\system32\usmt
2008-10-11 07:24:25 —-D—- C:\WINDOWS\mui
2008-10-11 07:24:24 —-D—- C:\WINDOWS\ime
2008-10-11 07:24:23 —-RSD—- C:\WINDOWS\Fonts
2008-10-11 07:24:22 —-D—- C:\WINDOWS\Media
2008-10-11 07:24:11 —-D—- C:\WINDOWS\PeerNet
2008-10-11 07:23:57 —-D—- C:\WINDOWS\system32\npp
2008-10-11 07:23:49 —-D—- C:\WINDOWS\msagent
2008-10-11 07:20:26 —-D—- C:\WINDOWS\twain_32
2008-10-11 07:19:27 —-D—- C:\WINDOWS\system32\icsxml
2008-10-11 07:18:47 —-D—- C:\WINDOWS\system32\1033
2008-10-11 07:17:43 —-D—- C:\WINDOWS\Driver Cache
2008-10-11 07:17:41 —-D—- C:\WINDOWS\system32\oobe
2008-10-10 22:18:59 —-A—- C:\WINDOWS\system32\13f49b3c-.txt
2008-10-07 18:44:26 —-HD—- C:\Program Files\InstallShield Installation Information
2008-09-21 16:35:00 —-D—- C:\chris folder

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-08-29 97928]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2008-07-29 26824]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 36096]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-04 14848]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2008-07-17 13059]
R2 MtxVideo;Matrox WDM capture/crossbar driver; C:\WINDOWS\system32\DRIVERS\MtxVideo.sys [2001-08-17 103296]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2004-08-04 88448]
R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2004-08-04 63232]
R2 NwlnkSpx;NWLink SPX/SPXII Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2004-08-04 55936]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-08-22 98752]
R3 atirage3;atirage3; C:\WINDOWS\system32\DRIVERS\atimpae.sys [2001-08-17 75136]
R3 Dot4;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2004-08-03 207360]
R3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
R3 dot4ufd;HP Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\hppaufd0.sys [2007-07-02 16800]
R3 E100B;Intel® PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2002-09-25 140800]
R3 G400;G400; C:\WINDOWS\system32\DRIVERS\G400m.sys [2001-08-17 322432]
R3 HidBatt;HID UPS Battery Driver; C:\WINDOWS\system32\DRIVERS\HidBatt.sys [2001-08-17 19200]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-04 9600]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\USR_MDMV.sys [2008-07-17 1035008]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\USR_BSC2.sys [2008-07-17 231168]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 Ser2pl;Prolific Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys [2004-06-28 42752]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2002-08-23 549672]
R3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-04 20480]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_USR.sys [2008-07-17 729728]
S1 P3;Intel PentiumIII Processor Driver; C:\WINDOWS\system32\DRIVERS\p3.sys [2004-08-04 42496]
S3 AIRPLUS;D-Link AirPlus Wireless Adapter; C:\WINDOWS\system32\DRIVERS\airplus.sys []
S3 ati2mtaa;ati2mtaa; C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys [2004-08-03 327040]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINDOWS\system32\drivers\es1371mp.sys [2001-08-17 40704]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys []
S3 hcwAVD2;Hauppauge PVR USB2 AVS Video Capture; C:\WINDOWS\system32\drivers\HCWUSB2AV.sys [2007-02-27 150784]
S3 HPFXBULK;HPFXBULK; C:\WINDOWS\system32\drivers\hpfxbulk.sys [2006-04-04 9344]
S3 mgau;mgau; C:\WINDOWS\system32\DRIVERS\mgaum.sys [2001-08-17 320384]
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 MPE;BDA MPE Filter; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-03 15360]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2004-08-10 194560]
R2 ehSched;Media Center Scheduler Service; C:\WINDOWS\eHome\ehSched.exe [2004-08-10 102912]
R2 FaxTalk Messenger Pro 7.0;FaxTalk Messenger Pro 7.0; f:\Program Files\FaxTalk Messenger Pro 7.0\FTMSGSVC.EXE [2004-12-22 147456]
R2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-15 168432]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-12 147456]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2004-03-13 49152]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2008-07-17 69632]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-07-23 654848]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2005-08-06 82160]
S3 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-09 38912]
S4 Macromedia Licensing Service;Macromedia Licensing Service; C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe [2008-09-13 68096]

—————–EOF—————–

info.txt logfile of random's system information tool 1.04 2008-10-19 16:02:44

======Uninstall list======

–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acrobat.com–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com–>MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Active WebCam Viewer–>"C:\WINDOWS\system32\PY_UNINSTAL.EXE" SOFTWARE\PySoft\Act_WebCam\Viewer
Active WebCam–>"C:\Program Files\Active WebCam\PY_UNINSTAL.EXE" SOFTWARE\PySoft\Act_WebCam
Adobe Acrobat 7.0 Professional–>msiexec /I {AC76BA86-1033-0000-7760-000000000002}
Adobe AIR–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR–>MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Anchor Service CS3–>MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3–>MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3–>MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting–>MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe Camera Raw 4.0–>MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps–>MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color Common Settings–>MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
Adobe Color EU Extra Settings–>MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
Adobe Color JA Extra Settings–>MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Recommended Settings–>MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
Adobe Default Language CS3–>MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3–>MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe Dreamweaver CS3–>C:\Program Files\Common Files\Adobe\Installers\7328fdfcb73660ec8b11d5a3d5c6232\Setup.exe
Adobe Dreamweaver CS3–>MsiExec.exe /I{7C10F5C7-F00F-4BD3-A110-C7D240D2DD25}
Adobe ExtendScript Toolkit 2–>MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
Adobe Extension Manager CS3–>MsiExec.exe /I{BE5F3842-8309-4754-92D5-83E02E6077A3}
Adobe Fireworks CS3–>C:\Program Files\Common Files\Adobe\Installers\bbef028176efa5abf0233d3e1747be8\Setup.exe
Adobe Fireworks CS3–>MsiExec.exe /I{7DFC1012-D346-46CE-B03E-FF79125AE029}
Adobe Flash Player 10 ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin–>C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Fonts All–>MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3–>MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Illustrator CS3–>C:\Program Files\Common Files\Adobe\Installers\a04a925a57548091300ada368235fc6\Setup.exe
Adobe Illustrator CS3–>MsiExec.exe /I{F08E8D2E-F132-4742-9C87-D5FF223A016A}
Adobe Linguistics CS3–>MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe PageMaker 7.0–>C:\WINDOWS\ISUNINST.EXE -f"m:\Program Files\Adobe\PageMaker 7.0\Uninst.isu" -c"m:\Program Files\Adobe\PageMaker 7.0\Uninst.dll"
Adobe PDF Library Files–>MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Reader 9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
Adobe Setup–>MsiExec.exe /I{0650BB10-BCF4-400A-85EE-04097E3046C6}
Adobe Setup–>MsiExec.exe /I{4F3E17F8-F1C8-4A4B-9EB8-1EE2D190CDA9}
Adobe Setup–>MsiExec.exe /I{C92A5A89-B218-46F7-8898-77C52113FFE0}
Adobe Stock Photos CS3–>MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support–>MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3–>MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client–>MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe WinSoft Linguistics Plugin–>MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3–>MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
AI RoboForm (All Users)–>"C:\Program Files\Siber Systems\AI RoboForm\rfwipeout.exe"
AVG Free 8.0–>C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
CommTest–>"C:\Program Files\CommTest\unins000.exe"
DeepBurner v1.9.0.228–>"C:\Program Files\Astonsoft\DeepBurner\Uninstall.exe" "C:\Program Files\Astonsoft\DeepBurner\install.log" -u
Electronic Shipping Tools–>"e:\Program Files\VCD\UninstallerData\Uninstall VCD.exe"
FaxTalk Messenger Pro 7.0–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{55387D04-929A-4C55-9543-BA5DA320E166}\setup.exe"
FTB2070–>"C:\Program Files\FTB2070\unins000.exe"
Google Gears–>MsiExec.exe /I{552171BC-30F8-3B29-9C4F-E3FE590B7CAC}
Google Toolbar for Internet Explorer–>MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer–>regsvr32 /u /s "c:\program files\google\googletoolbar3.dll"
Google Updater–>"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Hauppauge WinTV-PVR USB Drivers–>C:\PROGRA~1\WinTV\UNpvr43.EXE C:\PROGRA~1\WinTV\pvr43xxx.LOG
HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Intel® PRO Network Adapters and Drivers–>Prounstl.exe
InterVideo FilterSDK for Hauppauge–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2227E1FA-01F5-483C-AB0E-2A308E900B3D}\setup.exe" REMOVEALL
IsoBuster 1.6–>"C:\Program Files\Smart Projects\IsoBuster\Uninst\unins000.exe"
Java 2 Runtime Environment, SE v1.4.2_06–>MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142060}
Java™ 6 Update 10–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
Java™ 6 Update 7–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 2.0–>C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft DirectX SDK (August 2008)–>C:\WINDOWS\dxsdkuninst.exe "C:\Program Files\Microsoft DirectX SDK (August 2008)" "Microsoft DirectX SDK (August 2008)"
Microsoft Office Professional Edition 2003–>MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Windows XP Video Decoder Checkup Utility–>RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\DECCHECK.inf,Uninstall
OpenOffice.org Installer 1.0–>MsiExec.exe /X{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}
PDF Settings–>MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
PL-2303 USB-to-Serial–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\Setup.exe" -l0x9 Installed
POPFile 1.0.1–>"f:\Program Files\POPFile\uninstall.exe" /UNINSTALL
QuickBooks Pro Edition 2003–>C:\Program Files\Installshield Installation Information\{237a4b22-78c2-11d6-a394-00104bd190b1}\QBReplace.exe {237a4b22-78c2-11d6-a394-00104bd190b1}#{AD46C591-FB19-11D5-A316-00104BD190B1}
Spybot - Search & Destroy–>"C:\Program Files\Spybot - Search & Destroy\unins001.exe"
ThumbsPlus version 5.01-R–>C:\PROGRA~1\Thumbs5\UNWISE.EXE C:\PROGRA~1\Thumbs5\INSTALL.LOG
U.S. Robotics V.92 Voice Host Int–>C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F30&SUBSYS_200414F1\HXFSETUP.EXE -U -IVEN_14F1&DEV_2F30&SUBSYS_200414F1&REV_01
Ulead DVD MovieFactory 4.0 SE–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{448AB2CB-C94A-47DE-80B8-9D7824DEFA57}\setup.exe" -l0x9
Windows Installer 3.1 (KB893803)–>"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Media Encoder 9 Series–>msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Windows Media Encoder 9 Series–>MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
WinZip–>"C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
Yahoo! Install Manager–>C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
Yahoo! Messenger–>C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG

=====HijackThis Backups=====

O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O2 - BHO: (no name) - {2e0f1d95-7bc8-4bea-8da5-8cc28c8b15b9} - (no file)
O2 - BHO: (no name) - {9449BBA0-5EA5-4B6B-BA8D-48EB1F98A408} - (no file)
O2 - BHO: (no name) - {39D81A93-F4B0-4D39-89CE-519854C24F05} - (no file)

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Common Files\Ulead Systems\MPEG
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 7, GenuineIntel
"PROCESSOR_REVISION"=0207
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"DXSDK_DIR"=C:\Program Files\Microsoft DirectX SDK (August 2008)\

—————–EOF—————–
Hi Tom,

Thanks for checking to see if RSIT would run, that may prove useful with the creator’s diagnosis.

However I do see that you use peer to peer networking, please note that as long as you are using any form of Peer-to-Peer networking and downloading files from non-documented sources, you can expect infestations of malware to occur. Once upon a time, P2P file sharing was fairly safe. That is no longer true. You may continue to use P2P sharing at your own risk; however, please keep in mind that this practice may be the source of your current problem/infection. I would strongly suggest you remove uTorrent . Removing can be done through Add/Remove Programs.

===============================================

Also read this topic – We do not support

Even if you are unaware of it, you are using cracked/illegal software as it evident in your log here C:\Downloads 2008\Complete Torrents\Adobe CS3 Crack Collection - GeckoGold\Dreamweaver.exe 99.9% of the time cracked software includes malware, I have yet to see one that clean. As we do not support the use of illegal Pirated/Warez/Cracked software I must ask you to remove it. Failure to do so will result in you no longer being able to receive help here at WTT. Most other respectable help sites follow this guide as well.

Sorry to give you that bad news but we stand pretty firm on that.

===============================================

ComboFix Removal
Follow these steps to uninstall Combofix and tools used in the removal of malware
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    [external image: Posted Image]
===============================================

OTCleanIt

Download OTCleanit
Save it to your Desktop.

  • Double-click on OTCleanIt.exe to run
  • Click on the CleanUp! button
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You may be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

===============================================

Please let me know how everything is running, and also what you intend to do about the cracked software :thumbup:
Thanks. Probably more software from peer to peer on the external drive, as my son works on websites. I'll look into it and see what I can find, however not sure if I can recognize one from the other. Is it advisable to remove those tools, or can they be left installed?

Is it advisable to remove those tools, or can they be left installed?


Hi Tom,

Yes I would advise you to remove them as they contain the infected files we got rid of, and you don’t those to get back on your system :)

Is everything running ok ?
Hi

Just so you are aware, I will be going out of town this weekend. We are heading to Philadelphia to catch the Eagles game, so my access to a computer will be limited if at all, I will be returning on Monday evening. However I will be online tonight and most of the day tomorrow, so if you stay consistent we should be able to get you sorted before I leave.

Anyway I just wanted to let you know incase you don’t hear from me this weekend :)

Thanks
Thanks for the update, I've applied the cleanup and removed the questionable software that I could find, and now assessing the results. I notice Maxthon browser hangs rather than exiting properly, and sometimes IE Explorer does not launch, but if you open task manager you can find it running there, so I'm not sure what to think as it doesn't necessarily mean it's malware. We can let it slide for the weekend, sounds like it will be an interesting weekend for you, enjoy!
Hi Tom,

there is one more thing i would like to take a look at.

Please download RegQuery by Noviciate to your desktop
  • Copy the following registry keypath by highlighting the text and pressing CTRL and C at the same time
    • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows
  • Double click RegQuery.exe to run the program
  • Paste the text you have copied using CRTL and V, into the textbox
  • Click the Query button
  • A Notepad file will open. Please paste the contents in your next reply
  • You may now close the RegQuery program

thanks,
Thanks, Here's the results: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="avgrsstx.dll ohnova.dll qivqgb.dll" "DeviceNotSelectedTimeout"="15" "GDIProcessHandleQuota"=dword:00002710 "Spooler"="yes" "swapdisk"="" "TransmissionRetryTimeout"="90" "USERProcessHandleQuota"=dword:00002710
avgrsstx.dll is legit its part of your AVG antivirus

ohnova.dll & qivqgb.dll are both bad, so please re-open HiJackThis and scan. Check the box next to the entry listed below.

O20 - AppInit_DLLs: avgrsstx.dll ohnova.dll qivqgb.dll


Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.

After that, Reboot, and post a new HijackThis log here in your reply,

===============================================

If AVG for some reason doesn’t want to act right you may have to uninstall and then reinstall, although I don’t think that will happen it should just replace the AppInit_DLL on the reboot.

Let me know how everything is running after that, if all goes well we should be done :thumbup:
Thanks, did that:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:41:04, on 2008-10-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
F:\Program Files\FaxTalk Messenger Pro 7.0\FTClCtrl.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\JK.NS2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
f:\PROGRA~1\POPFile\popfileib.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\vmnetdhcp.exe
f:\Program Files\FaxTalk Messenger Pro 7.0\FTMSGSVC.EXE
f:\Program Files\FaxTalk Messenger Pro 7.0\FAPIEXE.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [FaxTalk Messenger Pro 7.0] "F:\Program Files\FaxTalk Messenger Pro 7.0\FTClCtrl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [FaxTalk CallControl 7.0] "f:\Program Files\FaxTalk Messenger Pro 7.0\FTClCtrl.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\JK.NS2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-18\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'Default user')
O4 - .DEFAULT User Startup: Run POPFile.lnk = D:\Program Files\POPFile\runpopfile.exe (User 'Default user')
O4 - Startup: Run POPFile.lnk = F:\Program Files\POPFile\runpopfile.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {66D393D5-4D80-497C-9F4F-F3839E090202} (PlayerOCX Control) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{D15F4A69-7188-4C20-A150-F80E084BBFFE}: NameServer = 75.154.132.68,75.154.132.100
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FaxTalk Messenger Pro 7.0 - Thought Communications, Inc. - f:\Program Files\FaxTalk Messenger Pro 7.0\FTMSGSVC.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

–
End of file - 11236 bytes
Hello again,

Looking good :) This is my standard post for when you are clear - which you now are - or seem to be. Please advise me of any problems you still have. . I know you already have some of these items like antivirus or firewall, but I like to include them anyway incase you ever need them or want to change them.

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

[external image: Posted Image] 1.) Watch what you download!
Many freeware programs, and P2P programs like Grokster, Imesh, Kazaa and others are amongst the most notorious, come with an enormous amount of bundled spyware that will eat system resources, slow down your system, clash with other installed software, or just plain crash your browser or even Windows itself. If you insist on using a P2P program, please read This Article written by Mike Healan of Spywareinfo.com fame. It is an updated and comprehensive article that gives in-depth detail about which P2P programs are "safe" to use.

[external image: Posted Image] 2.) Go to Intenet Explorer > Tools > Windows Update > Product Updates, and install ALL High-Priority Security Updates listed. If you're running Windows XP, that of course includes the Service Pack 2! If you suspect your computer is infected with Malware of any type, we advise you to not install SP2 if you don't already have it. You can post a HijackThis log on our Forums to get free Expert help cleaning your machine. Once you are sure you have a clean system, it is highly recommended to install SP2 to help prevent against future infections.

It's important to always keep current with the latest security fixes from Microsoft.
Install those patches for Internet Explorer, and make sure your installation of Java VM is up-to-date. There are some well known security bugs with Microsoft Java VM which are exploited regularly by browser hijackers.

[external image: Posted Image] 3.) Open Intenet Explorer and go to Internet Options > Security > Internet, then press "Default Level", then OK. Now press "Custom Level." In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".

Now you will be asked whether you want ActiveX objects to be executed and whether you want software to be installed.
Sites that you know for sure are above suspicion can be moved to the Trusted Zone in Internet Option > Security.

So why is ActiveX so dangerous that you have to increase the security for it?
When your browser runs an activex control, it is running an executable program. It's no different from doubleclicking an exe file on your hard drive.
Would you run just any random file downloaded off a web site without knowing what it is and what it does?

[external image: Posted Image] 4.) Install Javacool's SpywareBlaster

It will protect you from most spy/foistware in it's database by blocking installation of their ActiveX objects.

Download and install, download the latest updates, and you'll see a list of all spyware programs covered by the program (NOTE: this is NOT spyware found on your computer) Press "Enable All Protection", and you're done.
The spyware that you told Spywareblaster to set the "kill bit" for won't be a hazard to you any longer. Although it won't protect you from every form of spyware known to man, it is a very potent extra layer of protection.
Don't forget to check for updates every week or so.

[external image: Posted Image] 5.) Let's also not forget that Spybot Search & Destroy has the Immunize feature which works roughly the same way. Another feature within Spybot is the TeaTimer option. This option immediately detects known malicious processes wanting to start and terminates them. TeaTimer also detects when something wants to change some critical registry keys and gives you an option to allow them or not.

[external image: Posted Image] 6.) Microsoft now offers their own free malicious software blocking tool. Windows Defender improves Internet browsing safety by guarding over fifty (50) ways spyware can enter your PC.

[external image: Posted Image] 7.) Another excellent program by Javacool we recommend is SpywareGuard.
It provides a degree of real-time protection solution against spyware that is a great addition to SpywareBlaster's protection method.

[external image: Posted Image] 8.) IE-SPYAD puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all. Another good hosts program is mvpshosts. This little program packs a powerful punch as it block ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial.

*It is important to note that all of the above programs/files can be run simultaneously on your system. They will work together in layers, so to speak, to help protect your computer. However, the following suggestions are designed to only run one of each. It is not a good idea to run more than one firewall, and one anti-virus program. Running more than one of these at a time can cause system crashes, high system usage and/or conflicts with each other.*

[external image: Posted Image] 9.) It is critical that you use a firewall to protect your computer from hackers. We don't recommend the firewall that comes built in to Windows. It doesn't block everything that may try to get in, and the entire firewall is written to the registry. As various kinds of malware hack the Registry in order to disable the Windows firewall, it's far preferable to install one of the excellent third party solutions. Three good ones that are freeware to boot are ZoneAlarm, Kerio and Sygate

[external image: Posted Image] 10.) An Anti-Virus product is a necessity. There are many excellent programs that you can purchase. However, we choose to advocate the use of free programs whenever possible. Some very good and easy-to-use free A/V programs are AVG, Avast, and AntiVir. It's a good idea to set these to receive automatic updates so you are always as fully protected as possible from the newest virus threats.

NOTE: DO NOT install more than one anti-virus program. They will conflict, and provide less protection, not more.


Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Thanks for letting us help you!
THanks for all the help. THe suggestions in this last post should prove to be invaluable and I will follow them. Enjoy the game this weekend.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI