This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] (Solved) HJT Log

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:23:16 AM, on 10/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\VM_STI.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\runservice.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashQuick.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcydsl/defa…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/customize/sbcydsl/defa…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ActiveGS.cab - http://www.virtualapple.org/activegs.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1194487237125
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194838212828
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E32DD3E-43F6-43D0-8945-EDD532DF918F}: NameServer = 192.168.1.254
O20 - AppInit_DLLs:
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

–
End of file - 9527 bytes
Hi Spaceytjk,

Please tell me why you think you have a trojan on your machine and how your machine is behaving at present.

Download RSIT by random/random to your Desktop (right-click the link, select Save Target As…, select your Desktop and press Save)

  • Double click RSIT.exe to start the program, and click Continue at the disclaimer screen.
  • When the scan is complete, two text files will open - log.txt <- this one will be maximized and info.txt <-this one will be minimized
  • Make sure Format->Word Wrap is unchecked
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of log.txt and info.txt in your reply

Once complete, please post both RSIT logs, you won't need to produce a new HijackThis log as RSIT produces one for you.
I have Maplestory installed on my computer. When I clicked on the icon, an Avast window pops up, saying that Maplestory is a Gen-32 Trojan/worm or something similar to that. Avast had three options: to delete, to fix, or to quarantine. I first tried repairing it, but that didn't work. Then I quarantined the application in the Avast Virus Chest. I then posted the HJT log onto here, and restarted my computer to safe-mode. I used Spy-bot, Windows Defender, and Avast during safe-mode to scan if there were any viruses. All found nothing or nothing that was a virus.
Currently my computer is slow when it starts-up and loading applications takes longer than usual. It might be Windows XP SP3 that I had installed earlier last month. But SP3 made my computer super slow, so I uninstalled it and have SP2 now.

Thanks
-Jason

Here are both RSIT logs:

Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-21 17:15:28
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 33 GB (43%) free of 76 GB
Total RAM: 766 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:16:03 PM, on 10/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\VM_STI.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\runservice.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Owner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcydsl/defa…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/customize/sbcydsl/defa…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: AT&T; Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ActiveGS.cab - http://www.virtualapple.org/activegs.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1194487237125
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194838212828
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E32DD3E-43F6-43D0-8945-EDD532DF918F}: NameServer = 192.168.1.254
O20 - AppInit_DLLs:
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

–
End of file - 9529 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\MP Scheduled Scan.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2006-10-26 440384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D; IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
Yahoo! IE Services Button - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll [2006-10-31 198136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [2007-09-25 501136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D}]
SidebarAutoLaunch Class - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll [2005-02-03 124032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2006-10-26 440384]
{D0943516-5076-4020-A3B5-AEFAF26AB263} - Veoh Browser Plug-in - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll [2007-11-01 352256]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2007-12-18 185896]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2004-10-14 1404928]
"BigDogPath"=C:\WINDOWS\VM_STI.EXE [2004-06-09 40960]
"BCMSMMSG"=C:\WINDOWS\BCMSMMSG.exe [2003-08-29 122880]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2008-07-19 78008]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2006-11-03 866584]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2005-06-21 126976]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-09-08 289576]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"PeerGuardian"=C:\Program Files\PeerGuardian2\pg2.exe [2005-11-18 1457152]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2
"Apple Mobile Device"=2

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2005-06-21 348160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\PROGRA~1\WIFD1F~1\MpShHook.dll [2006-11-03 83224]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"AllowLegacyWebView"=
"AllowUnhashedWebView"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Veoh Networks\Veoh\VeohClient.exe"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Enabled:Veoh Client"
"c:\Program Files\Yahoo!\Messenger\YPager.exe"="c:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger"
"c:\Program Files\Yahoo!\Messenger\yserver.exe"="c:\Program Files\Yahoo!\Messenger\yserver.exe:*:Enabled:Yahoo! FT Server"
"C:\Program Files\Azureus\Azureus.exe"="C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\Program Files\AIM6\aim6.exe"="C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\Program Files\PdaNet for Windows Mobile\PdaNetPC.exe"="C:\Program Files\PdaNet for Windows Mobile\PdaNetPC.exe:*:Enabled:PdaNetPC"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe"="C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager"
"C:\Nexon\Combat Arms\CombatArms.exe"="C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe"
"C:\Nexon\Combat Arms\Engine.exe"="C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\Nexon\Combat Arms\CombatArms.exe"="C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe"
"C:\Nexon\Combat Arms\Engine.exe"="C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe"

======List of files/folders created in the last 1 months======

2008-10-21 17:15:28 —-D—- C:\rsit
2008-10-20 06:48:16 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-10-18 11:21:17 —-D—- C:\Program Files\Trend Micro
2008-10-16 18:55:58 —-D—- C:\Documents and Settings\All Users\Application Data\Trymedia
2008-10-16 18:53:42 —-D—- C:\Program Files\Delta Force 2
2008-10-16 07:01:47 —-HDC—- C:\WINDOWS\$NtUninstallKB956803$
2008-10-16 07:01:40 —-HDC—- C:\WINDOWS\$NtUninstallKB956391$
2008-10-16 07:01:30 —-HDC—- C:\WINDOWS\$NtUninstallKB957095$
2008-10-16 07:00:08 —-HDC—- C:\WINDOWS\$NtUninstallKB954211$
2008-10-16 07:00:01 —-A—- C:\WINDOWS\imsins.BAK
2008-10-16 06:59:43 —-HDC—- C:\WINDOWS\$NtUninstallKB956841$
2008-10-04 12:05:24 —-D—- C:\WINDOWS\system32\CatRoot_bak
2008-09-24 17:47:33 —-DC—- C:\WINDOWS\$NtUninstallKB951978$

======List of files/folders modified in the last 1 months======

2008-10-21 17:15:41 —-D—- C:\WINDOWS\Prefetch
2008-10-21 17:15:32 —-D—- C:\WINDOWS\Temp
2008-10-21 17:15:03 —-D—- C:\Documents and Settings\Owner\Application Data\LimeWire
2008-10-21 17:06:45 —-D—- C:\Program Files\Mozilla Firefox
2008-10-21 16:59:19 —-D—- C:\Program Files\PeerGuardian2
2008-10-21 16:58:29 —-SD—- C:\WINDOWS\Tasks
2008-10-21 16:55:43 —-D—- C:\WINDOWS\system32\CatRoot2
2008-10-21 07:04:48 —-D—- C:\Program Files\Microsoft Silverlight
2008-10-20 21:55:45 —-SHD—- C:\WINDOWS\Installer
2008-10-20 06:52:08 —-D—- C:\WINDOWS\system32\drivers
2008-10-20 06:48:16 —-D—- C:\WINDOWS
2008-10-19 12:36:40 —-AD—- C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-19 12:36:34 —-D—- C:\Program Files\SpywareBlaster
2008-10-19 12:33:23 —-D—- C:\Program Files\Spybot - Search & Destroy
2008-10-19 12:22:55 —-D—- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-18 11:21:17 —-RD—- C:\Program Files
2008-10-16 18:01:05 —-D—- C:\Program Files\LimeWire
2008-10-16 16:17:14 —-D—- C:\WINDOWS\system32
2008-10-16 16:06:44 —-HD—- C:\WINDOWS\inf
2008-10-16 16:06:30 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-10-16 16:06:26 —-D—- C:\Program Files\Internet Explorer
2008-10-16 16:06:13 —-D—- C:\WINDOWS\ie7updates
2008-10-16 07:01:46 —-HD—- C:\WINDOWS\$hf_mig$
2008-10-16 07:01:12 —-A—- C:\WINDOWS\win.ini
2008-10-16 06:56:39 —-D—- C:\WINDOWS\Debug
2008-10-11 13:34:57 —-D—- C:\Program Files\DivX
2008-10-07 15:28:38 —-A—- C:\WINDOWS\webica.ini
2008-10-07 15:19:40 —-A—- C:\WINDOWS\system32\MRT.exe
2008-10-05 16:14:50 —-D—- C:\Documents and Settings\Owner\Application Data\uTorrent
2008-10-04 15:38:01 —-D—- C:\WINDOWS\system32\CatRoot
2008-10-04 15:12:42 —-D—- C:\Program Files\Resco
2008-10-04 15:12:00 —-D—- C:\Nexon
2008-10-04 12:36:24 —-D—- C:\WINDOWS\security
2008-10-04 12:13:34 —-D—- C:\WINDOWS\WinSxS
2008-10-04 12:13:34 —-D—- C:\WINDOWS\system32\wbem
2008-10-04 12:13:31 —-RSD—- C:\WINDOWS\Fonts
2008-10-04 12:13:31 —-D—- C:\WINDOWS\AppPatch
2008-10-04 12:12:57 —-D—- C:\WINDOWS\system32\config
2008-10-04 12:12:38 —-D—- C:\WINDOWS\Registration
2008-10-04 12:10:52 —-D—- C:\WINDOWS\EHome
2008-10-04 12:09:02 —-D—- C:\WINDOWS\system32\usmt
2008-10-04 12:09:02 —-D—- C:\WINDOWS\system
2008-10-04 12:09:01 —-D—- C:\WINDOWS\system32\oobe
2008-10-04 12:08:59 —-D—- C:\WINDOWS\system32\Setup
2008-10-04 12:08:50 —-D—- C:\Program Files\Common Files\System
2008-10-04 12:08:49 —-D—- C:\WINDOWS\Help
2008-10-04 12:08:49 —-D—- C:\Program Files\Outlook Express
2008-10-04 12:08:48 —-D—- C:\Program Files\Windows NT
2008-10-04 12:08:47 —-D—- C:\Program Files\Windows Media Player
2008-10-04 12:08:46 —-D—- C:\WINDOWS\system32\Com
2008-10-04 12:08:46 —-D—- C:\Program Files\NetMeeting
2008-10-04 12:08:40 —-D—- C:\WINDOWS\ime
2008-10-04 12:08:39 —-D—- C:\WINDOWS\srchasst
2008-10-04 12:08:37 —-D—- C:\WINDOWS\msagent
2008-10-04 12:08:34 —-D—- C:\WINDOWS\system32\npp
2008-10-04 12:08:33 —-D—- C:\WINDOWS\system32\Restore
2008-10-04 12:08:32 —-D—- C:\Program Files\Movie Maker
2008-10-04 12:05:53 —-D—- C:\WINDOWS\peernet
2008-10-04 12:05:52 —-D—- C:\WINDOWS\system32\bits
2008-10-04 12:05:39 —-D—- C:\WINDOWS\network diagnostic
2008-10-04 12:05:35 —-D—- C:\Program Files\Messenger
2008-10-04 12:05:23 —-DC—- C:\WINDOWS\$NtUninstallKB938464$(2)
2008-10-04 12:05:22 —-DC—- C:\WINDOWS\$NtUninstallKB950762$(2)
2008-10-04 12:05:22 —-DC—- C:\WINDOWS\$NtUninstallKB946648$(2)
2008-10-04 12:05:21 —-DC—- C:\WINDOWS\$NtUninstallKB950974$(2)
2008-10-04 12:05:20 —-DC—- C:\WINDOWS\$NtUninstallKB951376$(2)
2008-10-04 12:05:20 —-DC—- C:\WINDOWS\$NtUninstallKB951066$(2)
2008-10-04 12:05:19 —-DC—- C:\WINDOWS\$NtUninstallKB951376-v2$(2)
2008-10-04 12:05:18 —-DC—- C:\WINDOWS\$NtUninstallKB951698$(2)
2008-10-04 12:05:17 —-DC—- C:\WINDOWS\$NtUninstallKB951748$(2)
2008-10-04 12:05:16 —-DC—- C:\WINDOWS\$NtUninstallKB952287$(2)
2008-10-04 12:05:15 —-DC—- C:\WINDOWS\$NtUninstallKB952954$(2)
2008-10-03 13:41:15 —-A—- C:\WINDOWS\system32\ieframe.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2008-07-19 26944]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2008-07-19 42912]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2004-08-04 36096]
R1 OMCI;OMCI; C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS [2001-08-22 13632]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2008-07-19 94416]
R2 npkcrypt;npkcrypt; \??\C:\Nexon\MapleStory\npkcrypt.sys []
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2008-07-19 23152]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys [2006-11-21 45568]
R3 BCMModem;BCM V.92 56K Modem; C:\WINDOWS\System32\DRIVERS\BCMSM.sys [2003-08-29 1101696]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
R3 ialm;ialm; C:\WINDOWS\System32\DRIVERS\ialmnt5.sys [2005-06-21 807998]
R3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\WINDOWS\system32\DRIVERS\mcdbus.sys [2008-07-28 116736]
R3 senfilt;senfilt; C:\WINDOWS\system32\drivers\senfilt.sys [2004-09-17 732928]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2005-01-27 260352]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-04 20480]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 dot4;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2004-08-04 207360]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 Dot4Scan;Scan Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Scan.sys [2001-08-17 8704]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-08-17 23808]
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-04 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 NETMDUSB;Net MD; C:\WINDOWS\System32\Drivers\NETMDUSB.sys [2001-12-11 37087]
S3 pnetmdm;PdaNet Modem; C:\WINDOWS\system32\DRIVERS\pnetmdm.sys [2006-09-28 9472]
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2003-07-16 5888]
S3 se45bus;Sony Ericsson Device 069 driver (WDM); C:\WINDOWS\system32\DRIVERS\se45bus.sys [2006-11-30 61536]
S3 se45mdfl;Sony Ericsson Device 069 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\se45mdfl.sys [2006-11-30 9360]
S3 se45mdm;Sony Ericsson Device 069 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\se45mdm.sys [2006-11-30 97088]
S3 se45mgmt;Sony Ericsson Device 069 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\se45mgmt.sys [2006-11-30 88624]
S3 se45nd5;Sony Ericsson Device 069 USB Ethernet Emulation SEMC45 (NDIS); C:\WINDOWS\system32\DRIVERS\se45nd5.sys [2006-11-30 18704]
S3 se45obex;Sony Ericsson Device 069 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\se45obex.sys [2006-11-30 86432]
S3 se45unic;Sony Ericsson Device 069 USB Ethernet Emulation SEMC45 (WDM); C:\WINDOWS\system32\DRIVERS\se45unic.sys [2006-11-30 90800]
S3 SilverLink;Texas Instruments SilverLink (USB GraphLink) Cable; C:\WINDOWS\System32\Drivers\SilvrLnk.sys [2004-01-28 21456]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 TIEHDUSB;TIEHDUSB; C:\WINDOWS\system32\drivers\tiehdusb.sys [2004-02-04 49536]
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2005-10-20 12800]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2004-08-04 31616]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 ZSMC302;VIMICRO USB PC Camera; C:\WINDOWS\System32\Drivers\usbVM31b.sys [2004-08-16 91263]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-07-07 611664]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-09-05 116040]
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2008-07-19 16056]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2008-07-19 147640]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 LicCtrlService;LicCtrl Service; C:\WINDOWS\runservice.exe [2007-12-28 2560]
R2 WinDefend;Windows Defender; C:\Program Files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2008-07-19 250040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2008-07-23 348344]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-09-08 536872]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 YPCService;YPCService; C:\WINDOWS\system32\YPCSER~1.EXE [2003-05-19 86016]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

—————–EOF—————–



info.txt logfile of random's system information tool 1.04 2008-10-21 17:16:06

======Uninstall list======

–>C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
–>C:\Program Files\SBC LightSpeed Self Support Tool\CustomUninstall.exe SBC
–>MsiExec.exe /X{48FCCE4F-9D37-41BA-92C1-17BF5CFAA347}
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Ad-Aware–>MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)–>MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
Adobe Reader 8.1.2–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Shockwave Player–>C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
AIM 6–>C:\Program Files\AIM6\uninst.exe
Apple Mobile Device Support–>MsiExec.exe /I{C7C895CA-331B-4D7D-A0FB-D3BC637949F9}
Apple Software Update–>MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
AT&T; Yahoo! Applications–>C:\PROGRA~1\Yahoo!\Common\uninstall.exe
Audacity 1.2.4–>"C:\Program Files\Audacity\unins000.exe"
AusLogics Disk Defrag–>"C:\Program Files\Auslogics\AusLogics Disk Defrag\unins000.exe"
avast! Antivirus–>C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
AviSynth 2.5–>"C:\Program Files\AviSynth 2.5\Uninstall.exe"
BCM V.92 56K Modem–>C:\WINDOWS\BCMSMU.exe quiet
Bonjour–>MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
Broadcom 440x 10/100 Integrated Controller–>MsiExec.exe /X{612B9183-67A9-4B44-9877-2F059E35B86A}
Broadcom Management Programs–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{89EE857B-8970-4F9F-AB58-A1C873AC72B3} /l1033
BroadJump Client Foundation–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\BroadJump\Client Foundation\Uninst.isu" -c"C:\Program Files\BroadJump\Client Foundation\RmvBJCFD.dll" -b"CFD" -h"CFD" -a
CCleaner (remove only)–>"C:\Program Files\CCleaner\uninst.exe"
ClearType Tuning Control Panel Applet–>MsiExec.exe /I{C9E4932C-8417-4E4C-A0E3-EE534810AB4D}
CNetX Face Contact–>"C:\Program Files\Microsoft ActiveSync\CNetX\Face Contact\uInstall.exe" C:\Program Files\Microsoft ActiveSync\CNetX\Face Contact\FACECNTX.uil
Compatibility Pack for the 2007 Office system–>MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Dell ResourceCD–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D78653C3-A8FF-415F-92E6-D774E634FF2D}\setup.exe"
Delta Force 2 (remove only)–>"C:\Program Files\Delta Force 2\Uninstall.exe"
DivX Codec–>C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Player–>C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player–>C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)–>"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399)–>"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)–>"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB896344)–>"C:\WINDOWS\$NtUninstallKB896344$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB909394)–>"C:\WINDOWS\$NtUninstallKB909394$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB914440)–>"C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB915865)–>"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB926239)–>"C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
hp officejet v series–>C:\WINDOWS\system32\hpocon09.exe /u 1195861215 /d "hp officejet v series"
Intel® Extreme Graphics Driver–>RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV;_2562
iTunes–>MsiExec.exe /I{EA418519-2160-43A0-AABD-6608DDD8D87F}
Java™ 6 Update 3–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
LimeWire 4.18.8–>"C:\Program Files\LimeWire\uninstall.exe"
MagicDisc 2.7.105–>C:\PROGRA~1\MAGICD~1\UNWISE.EXE C:\PROGRA~1\MAGICD~1\INSTALL.LOG
MapleStory–>MsiExec.exe /I{B68AD370-00ED-43F1-813C-F903F761D06B}
MetaFrame Presentation Server Web Client for Win32–>C:\WINDOWS\system32\ctxsetup.exe /uninst C:\PROGRA~1\Citrix\icaweb32\uninst.inf
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1–>MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft .NET Framework 3.0–>c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
Microsoft .NET Framework 3.0–>MsiExec.exe /X{15095BF3-A3D7-4DDF-B193-3A496881E003}
Microsoft ActiveSync–>MsiExec.exe /I{99052DB7-9592-4522-A558-5417BBAD48EE}
Microsoft Base Smart Card Cryptographic Service Provider Package–>"C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
Microsoft Compression Client Pack 1.0 for Windows XP–>"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Small Business Edition 2003–>MsiExec.exe /I{91CA0409-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight–>MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft User-Mode Driver Framework Feature Pack 1.0–>"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Mozilla Firefox (2.0.0.17)–>C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 6.0 Parser (KB933579)–>MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
Net MD Simple Burner–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{47E09785-B2FB-11D5-B8EE-00B0D0D26B88}\setup.exe" UNINSTALL
New York Real Estate Brokers Exam Drill and Practice–>MsiExec.exe /I{4F75367B-F73D-4293-BF73-70485251EE86}
New York Real Estate Salespersons Exam Drill and Practice–>MsiExec.exe /I{3A1A5B17-F07F-4500-94D6-235D6A9C31C5}
PC Inspector smart recovery–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C9A87D86-FDFD-418B-BF96-EF09320973B3}\Setup.exe" -l0x9
PeerGuardian 2.0–>"C:\Program Files\PeerGuardian2\unins000.exe"
Pocket Tunes for Windows Mobile–>MsiExec.exe /I{AC92AAC2-321A-4C29-BA7C-5EAD6D876699}
QuickTime–>MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
RealPlayer–>C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Security Update for Windows Internet Explorer 7 (KB938127)–>"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)–>"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)–>"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)–>"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)–>"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)–>"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB911564)–>"C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)–>"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 6.4 (KB925398)–>"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
Security Update for Windows Media Player 9 (KB911565)–>"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
Security Update for Windows Media Player 9 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.exe"
Security Update for Windows XP (KB890046)–>"C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
Security Update for Windows XP (KB893756)–>"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896358)–>"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896423)–>"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896424)–>"C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896428)–>"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899587)–>"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899591)–>"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
Security Update for Windows XP (KB900725)–>"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901017)–>"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901190)–>"C:\WINDOWS\$NtUninstallKB901190$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901214)–>"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
Security Update for Windows XP (KB902400)–>"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
Security Update for Windows XP (KB904706)–>"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905414)–>"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905749)–>"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB908519)–>"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911562)–>"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911927)–>"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
Security Update for Windows XP (KB912919)–>"C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe"
Security Update for Windows XP (KB913433)–>C:\WINDOWS\System32\MacroMed\Flash\genuinst.exe C:\WINDOWS\System32\MacroMed\Flash\KB913433.inf
Security Update for Windows XP (KB913580)–>"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
Security Update for Windows XP (KB914388)–>"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
Security Update for Windows XP (KB914389)–>"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917344)–>"C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917422)–>"C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917953)–>"C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918118)–>"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918439)–>"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
Security Update for Windows XP (KB919007)–>"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920213)–>"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920670)–>"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920683)–>"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920685)–>"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
Security Update for Windows XP (KB921398)–>"C:\WINDOWS\$NtUninstallKB921398$\spuninst\spuninst.exe"
Security Update for Windows XP (KB921503)–>"C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.exe"
Security Update for Windows XP (KB921883)–>"C:\WINDOWS\$NtUninstallKB921883$\spuninst\spuninst.exe"
Security Update for Windows XP (KB922616)–>"C:\WINDOWS\$NtUninstallKB922616$\spuninst\spuninst.exe"
Security Update for Windows XP (KB922819)–>"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923191)–>"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923414)–>"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923689)–>"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923980)–>"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924191)–>"C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924270)–>"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924496)–>"C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924667)–>"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
Security Update for Windows XP (KB925902)–>"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
Security Update for Windows XP (KB926255)–>"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
Security Update for Windows XP (KB926436)–>"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
Security Update for Windows XP (KB927779)–>"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
Security Update for Windows XP (KB927802)–>"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928255)–>"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928843)–>"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
Security Update for Windows XP (KB929123)–>"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
Security Update for Windows XP (KB930178)–>"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931261)–>"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931784)–>"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
Security Update for Windows XP (KB932168)–>"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
Security Update for Windows XP (KB933729)–>"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
Security Update for Windows XP (KB935839)–>"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB935840)–>"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
Security Update for Windows XP (KB936021)–>"C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938127)–>"C:\WINDOWS\$NtUninstallKB938127$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938829)–>"C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe"
Security Update for Windows XP (KB939653)–>"C:\WINDOWS\$NtUninstallKB939653$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941202)–>"C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941568)–>"C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941644)–>"C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941693)–>"C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943055)–>"C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943460)–>"C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943485)–>"C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944653)–>"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
Security Update for Windows XP (KB945553)–>"C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946026)–>"C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB948590)–>"C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe"
Security Update for Windows XP (KB948881)–>"C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950749)–>"C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)–>"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)–>"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
SlingPlayer–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1150\INTEL3~1\IDriver.exe /M{004B0DCB-4C60-465B-8F01-44B0A4111187} /l1033
Sony Ericsson PC Suite–>MsiExec.exe /I{FC906D5C-91F9-4DA4-A765-6DCBB669F317}
Sony Net MD Help–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F6BECFE0-74CE-11D5-B8A3-00B0D0D26B88}\setup.exe" UNINSTALL
SoundMAX–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\SETUP.exe" -l0x9 -removeonly
Spybot - Search & Destroy 1.5.2.20–>"C:\WINDOWS\unins000.exe"
Spybot - Search & Destroy–>"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SpywareBlaster 4.1–>"C:\Program Files\SpywareBlaster\unins000.exe"
TI Connect 1.6–>MsiExec.exe /I{A8B94669-8654-4126-BD28-D0D2412CDED6}
Uninstall Startup Inspector–>"C:\Program Files\Startup Inspector for Windows\unins000.exe"
Update for Windows XP (KB898461)–>"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Update for Windows XP (KB900485)–>"C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
Update for Windows XP (KB904942)–>"C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
Update for Windows XP (KB908531)–>"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
Update for Windows XP (KB910437)–>"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
Update for Windows XP (KB911280)–>"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
Update for Windows XP (KB916595)–>"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
Update for Windows XP (KB920342)–>"C:\WINDOWS\$NtUninstallKB920342$\spuninst\spuninst.exe"
Update for Windows XP (KB920872)–>"C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
Update for Windows XP (KB922582)–>"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
Update for Windows XP (KB925720)–>"C:\WINDOWS\$NtUninstallKB925720$\spuninst\spuninst.exe"
Update for Windows XP (KB927891)–>"C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
Update for Windows XP (KB930916)–>"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
Update for Windows XP (KB932823-v3)–>"C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe"
Update for Windows XP (KB933360)–>"C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.exe"
Update for Windows XP (KB936357)–>"C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.exe"
Update for Windows XP (KB938828)–>"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
Update for Windows XP (KB942763)–>"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
VeohTV BETA–>C:\Program Files\InstallShield Installation Information\{97A96172-A963-4A37-9FFB-DA6805BB915A}\setup.exe -runfromtemp -l0x0409
VideoLAN VLC media player 0.8.5–>C:\Program Files\VideoLAN\VLC\uninstall.exe
Videora iPod Converter 0.91–>C:\Program Files\VideoraiPodConverter\uninst.exe
WD Diagnostics–>MsiExec.exe /X{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}
Windows Communication Foundation–>MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
Windows Defender–>MsiExec.exe /I{A06275F4-324B-4E85-95E6-87B2CD729401}
Windows Imaging Component–>"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Installer 3.1 (KB893803)–>"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Internet Explorer 7–>"C:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows Live installer–>MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Messenger–>MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant–>MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Media Format 11 runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime–>"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Format SDK Hotfix - KB891122–>"C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe"
Windows Media Player 11–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11–>"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Presentation Foundation–>MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows Workflow Foundation–>MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
Windows XP Hotfix - KB873339–>C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
Windows XP Hotfix - KB885835–>C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
Windows XP Hotfix - KB885836–>C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
Windows XP Hotfix - KB886185–>C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
Windows XP Hotfix - KB887472–>C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
Windows XP Hotfix - KB888302–>C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
Windows XP Hotfix - KB890859–>"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
Windows XP Hotfix - KB891781–>C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
Windows XP Service Pack 2–>C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe
WinRAR archiver–>C:\Program Files\WinRAR\uninstall.exe

======Hosts File======

127.0.0.1 007guard.com
127.0.0.1 www.007guard.com
127.0.0.1 010402.com
127.0.0.1 032439.com
127.0.0.1 www.032439.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 10sek.com

======Security center information======

AV: avast! antivirus 4.8.1229 [VPS 081021-0]

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Teleca Shared;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 9, GenuineIntel
"PROCESSOR_REVISION"=0209
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip

—————–EOF—————–
Hi Jason,

Please try this:

1. Right click on the avast icon on your desktop (bottom right)
2. Click on On access protection control
3. Click on Standard Shield
4. Click on Customise
5. Then go to Advanced
6. On the bottom box, click on Add and paste this into it

C:\Nexon\MapleStory\GameGuard\dump_wmimmc.sys

and then click enter

Now try installing/running Maple Story again and tell me if there has been any change.
Hi Spaceytjk,

I'm glad to hear it's working now, I recommend you do the following:

Please open Start->Control Panel->Add/Remove Programs, and remove JavaT 6 Update 3. This is out of date and now a security risk, you can get the latest update (version 6 update 10) from here

You have LimeWire, a P2P file sharing program installed on your computer. This program does not come bundled with malware as some similar programs do, but peer-to-peer file sharing networks are one of the biggest sources of malware we see. Anything downloaded from them cannot be trusted to be clean, because even if the file appears to be what it claims to be, it can have malware embedded in it.
I strongly recommend you remove Limewire via Add/Remove Programs.

————————————————————————

Then, open HijackThis, choose Do a system scan only and place a checkmark next to the following lines:

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O20 - AppInit_DLLs:

Then close all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.

————————————————————————

Please do a scan to check for malware:

Download Malwarebytes' Anti-Malware to your Desktop (right-click the link, select Save Target As…, select your Desktop and press Save)
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to both of these options:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Quick Scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure everything is checked, and click Remove Selected.
  • When finished, a log will open in Notepad. Please save it to your Desktop, and post the contents in your reply.
  • The log can also be found here if you need it:
    • Start->All Programs->Malwarebytes' Anti-Malware->Logs

————————————————————————

Once complete, please post the Malwarebytes Antimalware report and a new HijackThis log.
Hi Silver, extremely sorry for the late post. I was busying with exams this past week.

I uninstalled Limewire, removed JavaT 6 Update 3. But when I installed Verison 6 update 10 and restarted my computer, a strange thing happened. The desktop continued running and the montior, keyboard, and mouse didn't respond. I pushed the power button and turned it back on. It worked, but hopefully nothing bad happened.

My Malwarebytes' Anti-Malware log -

Malwarebytes' Anti-Malware 1.30
Database version: 1333
Windows 5.1.2600 Service Pack 2

10/28/2008 8:05:24 PM
mbam-log-2008-10-28 (20-05-24).txt

Scan type: Quick Scan
Objects scanned: 54674
Time elapsed: 13 minute(s), 18 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




My HJT Log -

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:16:48 PM, on 10/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\VM_STI.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\runservice.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcydsl/defa…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/customize/sbcydsl/defa…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ActiveGS.cab - http://www.virtualapple.org/activegs.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1194487237125
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194838212828
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E32DD3E-43F6-43D0-8945-EDD532DF918F}: NameServer = 192.168.1.254
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

–
End of file - 9181 bytes

I have a quick question to ask, but not related to this. I have a file on my desktop and I want to delete it but a window pops up each time saying it is being used by another program when I haven't used the program at all. How do I delete it?

Thank you for your time and patience,
Jason
Hi Spaceytjk,

But when I installed Verison 6 update 10 and restarted my computer, a strange thing happened. The desktop continued running and the montior, keyboard, and mouse didn't respond. I pushed the power button and turned it back on. It worked, but hopefully nothing bad happened.

It's hard to say what could have caused that, we can't even be certain it was the Java upgrade but it sure sounds likely. If you don't use Java you can uninstall it completely if you wish.

I have a quick question to ask, but not related to this. I have a file on my desktop and I want to delete it but a window pops up each time saying it is being used by another program when I haven't used the program at all. How do I delete it?

Please tell me what the filename is and also do this:

Press Start->Run, copy/paste the following command (it's one long command) into the box and press OK:

cmd /c attrib "%userprofile%\desktop\*.*" >> "%userprofile%\desktop\results.txt"

A new file called results.txt should appear on your Desktop, please post the contents with your next response.

Once complete, please post the results.txt output and a new HijackThis log.
Also, let me know how your machine is running now (apart from the issue you raised above).
Hi SIlver,

The filename is CD1_ALLIED_DISC.ISO.

Here are the logs

results.txt -

A C:\Documents and Settings\Owner\desktop\Audacity.lnk
A C:\Documents and Settings\Owner\desktop\BYKIDownloaderPC.exe
A C:\Documents and Settings\Owner\desktop\CCleaner.lnk
A C:\Documents and Settings\Owner\desktop\CD1_ALLIED_DISC.ISO
A C:\Documents and Settings\Owner\desktop\Df2Setup.exe
A C:\Documents and Settings\Owner\desktop\HijackThis.lnk
A C:\Documents and Settings\Owner\desktop\IE 7.lnk
A C:\Documents and Settings\Owner\desktop\iTunes.lnk
A C:\Documents and Settings\Owner\desktop\JkDefrag.exe
A C:\Documents and Settings\Owner\desktop\MagicDisc.lnk
A C:\Documents and Settings\Owner\desktop\MapleStory.lnk
A C:\Documents and Settings\Owner\desktop\PeerGuardian.lnk
A C:\Documents and Settings\Owner\desktop\procexp.exe
A C:\Documents and Settings\Owner\desktop\results.txt
A C:\Documents and Settings\Owner\desktop\RSIT.exe
A C:\Documents and Settings\Owner\desktop\Spybot - Search & Destroy.lnk
A C:\Documents and Settings\Owner\desktop\Startup Inspector for Windows.lnk
A C:\Documents and Settings\Owner\desktop\Word 2003.lnk
A C:\Documents and Settings\Owner\desktop\YamiPod.lnk
A C:\Documents and Settings\Owner\desktop\æTorrent.lnk


HJT Log -

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:06:02 PM, on 10/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\VM_STI.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\runservice.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcydsl/defa…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/customize/sbcydsl/defa…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ActiveGS.cab - http://www.virtualapple.org/activegs.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1194487237125
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194838212828
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E32DD3E-43F6-43D0-8945-EDD532DF918F}: NameServer = 192.168.1.254
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

–
End of file - 9094 bytes

Thank you once again!
-Jason
Hi Spaceytjk,

Please try this:
Download Handle to your Desktop.

Open Notepad: press Start->Run, type notepad into the box and press OK
Select Format from the top menu and make sure Word Wrap is NOT checked.
Then, copy/paste the contents of the following code box into Notepad:
@echo off
del /f "C:\Documents and Settings\Owner\desktop\CD1_ALLIED_DISC.ISO" >> results.txt 2>>&1
if exist "C:\Documents and Settings\Owner\desktop\CD1_ALLIED_DISC.ISO" (
cacls "C:\Documents and Settings\Owner\desktop\CD1_ALLIED_DISC.ISO" >> results.txt 2>>&1
handle >> results.txt 2>>&1
)
del %0
Select File and Save as
Save it to your Desktop as "runme.bat" (you MUST type the quotes)
Locate runme.bat on your Desktop and double-click it.
A black box should open and close after a short time, this is normal.
A new file should appear on your Desktop called results.txt, post the contents of this file in your next response.
Hi, Silver, Here are the results: C:\Documents and Settings\Owner\desktop\CD1_ALLIED_DISC.ISO The process cannot access the file because it is being used by another process. C:\Documents and Settings\Owner\desktop\CD1_ALLIED_DISC.ISO JASON\Owner:F NT AUTHORITY\SYSTEM:F BUILTIN\Administrators:F Handle v3.41 Copyright © 1997-2008 Mark Russinovich Sysinternals - www.sysinternals.com —————————————————————————— System pid: 4 NT AUTHORITY\SYSTEM D10: File (-W-) C:\pagefile.sys D14: File (—) C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat D18: File (—) C:\WINDOWS\system32\config\SECURITY D20: File (—) C:\WINDOWS\system32\config\SECURITY.LOG D24: File (R–) C:\System Volume Information\_restore{AB8A671F-ECB8-4F78-A4EA-B8AD89ED652D}\RP106\change.log D28: File (—) C:\WINDOWS\system32\config\software D2C: File (—) C:\WINDOWS\system32\config\software.LOG D30: File (—) C:\Documents and Settings\NetworkService\NTUSER.DAT D34: File (—) C:\WINDOWS\system32\config\system D38: File (—) C:\WINDOWS\system32\config\system.LOG D40: File (—) C:\WINDOWS\system32\config\default D44: File (—) C:\WINDOWS\system32\config\default.LOG D4C: File (—) C:\WINDOWS\system32\config\SAM D50: File (—) C:\WINDOWS\system32\config\SAM.LOG D5C: File (—) C:\Documents and Settings\NetworkService\ntuser.dat.LOG D60: File (—) C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat D64: File (—) C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG E38: File (R–) C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl E40: File (—) C:\Documents and Settings\LocalService\ntuser.dat.LOG E44: File (—) C:\Documents and Settings\LocalService\NTUSER.DAT E48: File (—) C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat E4C: File (—) C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG E50: File (—) C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG E54: File (—) C:\Documents and Settings\Owner\ntuser.dat.LOG E58: File (—) C:\Documents and Settings\Owner\ntuser.dat 1390: File (R–) C:\Documents and Settings\Owner\Desktop\CD1_ALLIED_DISC.ISO —————————————————————————— smss.exe pid: 576 NT AUTHORITY\SYSTEM 8: File (RW-) C:\WINDOWS 1C: File (RW-) C:\WINDOWS\system32 —————————————————————————— csrss.exe pid: 648 NT AUTHORITY\SYSTEM C: File (RW-) C:\WINDOWS\system32 38: Section \NLS\NlsSectionUnicode 40: Section \NLS\NlsSectionLocale 44: Section \NLS\NlsSectionCType 48: Section \NLS\NlsSectionSortkey 4C: Section \NLS\NlsSectionSortTbls 12C: File (R–) C:\WINDOWS\system32\ega.cpi —————————————————————————— winlogon.exe pid: 672 NT AUTHORITY\SYSTEM DC: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 15C: Section \BaseNamedObjects\ShimSharedMemory 16C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 1E4: File (RW-) C:\WINDOWS\AppPatch 1E8: File (RW-) C:\WINDOWS\system32\dllcache 20C: File (RW-) C:\Program Files\Common Files\Microsoft Shared\web server extensions\40\isapi\_vti_adm 210: File (RW-) C:\Program Files\Common Files\Microsoft Shared\web server extensions\40\_vti_bin\_vti_adm 214: File (RW-) C:\WINDOWS\system32 218: File (RW-) C:\WINDOWS\Help 21C: File (RW-) C:\Program Files\Common Files\Microsoft Shared\web server extensions\40\isapi\_vti_aut 220: File (RW-) C:\Program Files\Common Files\Microsoft Shared\web server extensions\40\_vti_bin\_vti_aut 224: File (RW-) C:\Program Files\Common Files\Microsoft Shared\web server extensions\40\bin 228: File (RW-) C:\WINDOWS\Fonts 22C: File (RW-) C:\WINDOWS\system32\drivers 230: File (RW-) C:\Program Files\Common Files\Microsoft Shared\web server extensions\40\servsupp 234: File (RW-) C:\Program Files\Common Files\Microsoft Shared\web server extensions\40\bots\vinavbar 238: File (RW-) C:\Program Files\microsoft frontpage\version3.0\bin 23C: File (RW-) C:\Program Files\Common Files\Microsoft Shared\web server extensions\40\_vti_bin 240: File (RW-) C:\Program Files\Common Files\Microsoft Shared\web server extensions\40\bin\1033 244: File (RW-) C:\Program Files\Common Files\Microsoft Shared\web server extensions\40\isapi 248: File (RW-) C:\WINDOWS 24C: File (RW-) C:\Program Files\Common Files\Microsoft Shared\DAO 250: File (RW-) C:\Program Files\Windows Media Player 254: File (RW-) C:\Program Files\Common Files\System\msadc 258: File (RW-) C:\Program Files\Common Files\System\ado 25C: File (RW-) C:\Program Files\Common Files\System\Ole DB 260: File (RW-) C:\WINDOWS\inf 264: File (RW-) C:\WINDOWS\system 268: File (RW-) C:\WINDOWS\msagent 26C: File (RW-) C:\WINDOWS\msagent\intl 270: File (RW-) C:\WINDOWS\system32\inetsrv 274: File (RW-) C:\Program Files\MSN Gaming Zone\Windows 278: File (RW-) C:\WINDOWS\PCHealth\HelpCtr\Binaries 27C: File (RW-) C:\Program Files\NetMeeting 280: File (RW-) C:\WINDOWS\system32\drivers\disdn 284: File (RW-) C:\WINDOWS\ime\CHTIME\Applets 288: File (RW-) C:\WINDOWS\system32\wbem 28C: File (RW-) C:\WINDOWS\system32\IME\CINTLGNT 290: File (RW-) C:\WINDOWS\system32\Com 294: File (RW-) C:\WINDOWS\system32\Setup 298: File (RW-) C:\WINDOWS\ime\imjp8_1 29C: File (RW-) C:\Program Files\Common Files\Microsoft Shared\Triedit 2A0: File (RW-) C:\Program Files\Windows NT 2A4: File (RW-) C:\Program Files\Common Files\System 2A8: File (RW-) C:\WINDOWS\system32\1033 2AC: File (RW-) C:\Program Files\Common Files\Microsoft Shared\web server extensions\40\admcgi\scripts 2B0: File (RW-) C:\Program Files\Common Files\Microsoft Shared\web server extensions\40\admisapi\scripts 2B4: File (RW-) C:\WINDOWS\system32\usmt 2B8: File (RW-) C:\WINDOWS\ime\imkr6_1\dicts 2BC: File (RW-) C:\WINDOWS\system32\mui\0009 2C0: File (RW-) C:\Program Files\Internet Explorer 2C4: File (RW-) C:\WINDOWS\ime\imjp8_1\applets 2C8: File (RW-) C:\WINDOWS\ime\imkr6_1\applets 2CC: File (RW-) C:\WINDOWS\system32\xircom 2D0: File (RW-) C:\Program Files\Internet Explorer\Connection Wizard 2D4: File (RW-) C:\Program Files\Common Files\Microsoft Shared\MSInfo 2D8: File (RW-) C:\WINDOWS\ime\imkr6_1 2DC: File (RW-) C:\WINDOWS\ime\shared 2E0: File (RW-) C:\WINDOWS\system32\IME\PINTLGNT 2E4: File (RW-) C:\Program Files\Common Files\SpeechEngines\Microsoft\Lexicon\1033 2E8: File (RW-) C:\WINDOWS\Resources\Themes\Luna 2EC: File (RW-) C:\Program Files\Movie Maker 2F0: File (RW-) C:\WINDOWS\ime 2F4: File (RW-) C:\WINDOWS\srchasst 2F8: File (RW-) C:\Program Files\Outlook Express 2FC: File (RW-) C:\WINDOWS\system32\oobe 300: File (RW-) C:\Program Files\Common Files\MSSoap\Binaries 304: File (RW-) C:\Program Files\Common Files\MSSoap\Binaries\Resources\1033 308: File (RW-) C:\WINDOWS\system32\npp 30C: File (RW-) C:\WINDOWS\ime\shared\res 310: File (RW-) C:\Program Files\Windows NT\Pinball 314: File (RW-) C:\WINDOWS\ime\chsime\applets 318: File (RW-) C:\WINDOWS\system32\Restore 31C: File (RW-) C:\Program Files\Common Files\SpeechEngines\Microsoft\TTS\1033 320: File (RW-) C:\Program Files\Common Files\Microsoft Shared\Speech 324: File (RW-) C:\WINDOWS\Resources\Themes\Luna\Shell\NormalColor 328: File (RW-) C:\WINDOWS\Resources\Themes\Luna\Shell\Homestead 32C: File (RW-) C:\WINDOWS\Resources\Themes\Luna\Shell\Metallic 330: File (RW-) C:\WINDOWS\system32\wbem\snmp 334: File (RW-) C:\Program Files\Common Files\SpeechEngines\Microsoft 338: File (RW-) C:\Program Files\Common Files\Microsoft Shared\Speech\1033 33C: File (RW-) C:\WINDOWS\peernet 340: File (RW-) C:\WINDOWS\system32\spool\drivers\color 344: File (RW-) C:\WINDOWS\system32\IME\TINTLGNT 348: File (RW-) C:\WINDOWS\Help\Tours\mmTour 34C: File (RW-) C:\WINDOWS\PCHealth\UploadLB\Binaries 350: File (RW-) C:\Program Files\Common Files\Microsoft Shared\VGX 354: File (RW-) C:\WINDOWS\system32\wbem\xml 358: File (RW-) C:\Program Files\Windows NT\Accessories 35C: File (RW-) C:\WINDOWS\system32\mui\041b 360: File (RW-) C:\WINDOWS\system32\mui\0424 364: File (RW-) C:\Program Files\xerox\nwwia 374: File (RW-) C:\WINDOWS\WinSxS 538: Section \BaseNamedObjects\mmGlobalPnpInfo 5F8: Section \BaseNamedObjects\WDMAUD_Callbacks 64C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 6D8: File (RW-) C:\WINDOWS\system32 —————————————————————————— services.exe pid: 716 NT AUTHORITY\SYSTEM C: File (RW-) C:\WINDOWS\system32 26C: Section \BaseNamedObjects\ShimSharedMemory 2A8: File (R–) C:\WINDOWS\system32\config\Antivirus.Evt 2B8: File (R–) C:\WINDOWS\system32\config\AppEvent.Evt 2C8: File (R–) C:\WINDOWS\system32\config\Internet.evt 2D8: File (R–) C:\WINDOWS\system32\config\SecEvent.Evt 2E8: File (R–) C:\WINDOWS\system32\config\SysEvent.Evt —————————————————————————— lsass.exe pid: 728 NT AUTHORITY\SYSTEM C: File (RW-) C:\WINDOWS\system32 80: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 158: Section \BaseNamedObjects\Debug.Memory.2d8 244: File (RW-) C:\WINDOWS\Debug\PASSWD.LOG —————————————————————————— svchost.exe pid: 876 NT AUTHORITY\SYSTEM C: File (RW-) C:\WINDOWS\system32 60: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 100: File (—) \Dfs 14C: Section \BaseNamedObjects\RotHintTable 160: Section \BaseNamedObjects\{A64C7F33-DA35-459b-96CA-63B51FB0CDB9} 224: Section \BaseNamedObjects\ShimSharedMemory —————————————————————————— svchost.exe pid: 956 NT AUTHORITY\NETWORK SERVICE C: File (RW-) C:\WINDOWS\system32 58: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 BC: File (—) \Dfs —————————————————————————— MsMpEng.exe pid: 1044 NT AUTHORITY\SYSTEM C: File (RW-) C:\WINDOWS\system32 10: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 1C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 20: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 5C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 250: File (RWD) C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My 28C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 2D8: File (RWD) C: 3B4: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 404: File (R–) C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-05162008-233043.log 408: File (RWD) C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Updates 438: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 468: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 470: File (RW-) C:\Documents and Settings\NetworkService\Cookies\index.dat 494: Section \BaseNamedObjects\C:_Documents and Settings_NetworkService_Local Settings_Temporary Internet Files_Content.IE5_index.dat_49152 4D0: Section \BaseNamedObjects\C:_Documents and Settings_NetworkService_Local Settings_History_History.IE5_index.dat_16384 4DC: File (RW-) C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat 4E4: File (RW-) C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat 4E8: Section \BaseNamedObjects\C:_Documents and Settings_NetworkService_Cookies_index.dat_16384 538: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 —————————————————————————— svchost.exe pid: 1088 NT AUTHORITY\SYSTEM C: File (RW-) C:\WINDOWS\system32 60: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 2C0: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 2C8: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 2E8: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 47C: File (R–) C:\WINDOWS\SchedLgU.Txt 510: File (RWD) C:\WINDOWS\Tasks 5C8: Section \BaseNamedObjects\mmGlobalPnpInfo 6D4: File (RWD) C:\WINDOWS\PCHealth\HelpCtr\BATCH 728: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 730: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 7C4: Section \BaseNamedObjects\SENS Information Cache 7F8: File (—) \FileSystem\Filters\SystemRestore 8A8: File (RWD) C:\WINDOWS\system32\wbem\mof 928: File (RW-) C:\WINDOWS\WindowsUpdate.log 95C: Section \BaseNamedObjects\RotHintTable 9C0: File (RW-) C:\WINDOWS\WindowsUpdate.log A08: File (RW-) C:\WINDOWS\WindowsUpdate.log A1C: File (RW-) C:\WINDOWS\WindowsUpdate.log A24: File (RW-) C:\WINDOWS\WindowsUpdate.log A2C: File (RW-) C:\WINDOWS\WindowsUpdate.log A48: File (RW-) C:\WINDOWS\WindowsUpdate.log A4C: File (RW-) C:\WINDOWS\WindowsUpdate.log A54: File (RW-) C:\WINDOWS\WindowsUpdate.log A58: File (RW-) C:\WINDOWS\WindowsUpdate.log A9C: File (RW-) C:\WINDOWS\WindowsUpdate.log AC8: File (RW-) C:\WINDOWS\WindowsUpdate.log AD4: File (RW-) C:\WINDOWS\WindowsUpdate.log AD8: File (RW-) C:\WINDOWS\WindowsUpdate.log ADC: File (RW-) C:\WINDOWS\WindowsUpdate.log AE0: File (RW-) C:\WINDOWS\WindowsUpdate.log AE4: File (RW-) C:\WINDOWS\WindowsUpdate.log AE8: File (RW-) C:\WINDOWS\WindowsUpdate.log AEC: File (RW-) C:\WINDOWS\WindowsUpdate.log AF8: File (RW-) C:\WINDOWS\WindowsUpdate.log AFC: File (RW-) C:\WINDOWS\WindowsUpdate.log B00: File (RW-) C:\WINDOWS\WindowsUpdate.log B04: File (RW-) C:\WINDOWS\WindowsUpdate.log B08: File (RW-) C:\WINDOWS\WindowsUpdate.log B0C: File (RW-) C:\WINDOWS\WindowsUpdate.log B10: File (RW-) C:\WINDOWS\WindowsUpdate.log B14: File (RW-) C:\WINDOWS\WindowsUpdate.log B18: File (RW-) C:\WINDOWS\WindowsUpdate.log B1C: File (RW-) C:\WINDOWS\WindowsUpdate.log B20: File (RW-) C:\WINDOWS\WindowsUpdate.log B2C: Section \BaseNamedObjects\ShimSharedMemory B40: File (R–) C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP B44: File (R–) C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP B48: File (R–) C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER B4C: File (R–) C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP B50: File (R–) C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP B54: File (R–) C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA B58: File (R–) C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR B78: Section \BaseNamedObjects\Wmi Provider Sub System Counters C54: File (R–) C:\System Volume Information\tracking.log CA4: Section \BaseNamedObjects\IDA0: ESENT Performance Data Schema Version 40 CE4: Section \BaseNamedObjects\GDA: ESENT Performance Data Schema Version 40 1034: File (RWD) C:\$Extend\$ObjId 105C: File (R–) C:\WINDOWS\SoftwareDistribution\ReportingEvents.log 1168: File (—) C: 1378: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 14D4: File (R–) C:\WINDOWS\system32\h323log.txt 1534: Section \BaseNamedObjects\Debug.Memory.440 1668: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 1794: File (—) C:\WINDOWS\system32\CatRoot2\edb.log 179C: File (—) C:\WINDOWS\system32\CatRoot2\tmp.edb 1930: File (RWD) C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My —————————————————————————— svchost.exe pid: 1120 NT AUTHORITY\SYSTEM C: File (RW-) C:\WINDOWS\system32 60: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 —————————————————————————— svchost.exe pid: 1292 NT AUTHORITY\LOCAL SERVICE C: File (RW-) C:\WINDOWS\system32 58: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 158: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 198: File (RW-) C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\index.dat 19C: Section \BaseNamedObjects\C:_DOCUME~1_LOCALS~1_LOCALS~1_Temp_Temporary Internet Files_Content.IE5_index.dat_32768 1A0: File (RW-) C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Cookies\index.dat 1A8: Section \BaseNamedObjects\C:_DOCUME~1_LOCALS~1_LOCALS~1_Temp_Cookies_index.dat_16384 1AC: File (RW-) C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\History\History.IE5\index.dat 1B4: Section \BaseNamedObjects\C:_DOCUME~1_LOCALS~1_LOCALS~1_Temp_History_History.IE5_index.dat_16384 —————————————————————————— aawservice.exe pid: 1456 NT AUTHORITY\SYSTEM C: File (RW-) C:\WINDOWS\system32 60: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 6C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 C4: Section \BaseNamedObjects\8A9C54DB3AE7436f9F48B466F8F4DBB1 D8: Section \BaseNamedObjects\8A9C54DB3AE7436f9F48B466F8F4DBB1 E8: Section \BaseNamedObjects\8A9C54DB3AE7436f9F48B466F8F4DBB1 114: Section \BaseNamedObjects\8A9C54DB3AE7436f9F48B466F8F4DBB1 —————————————————————————— explorer.exe pid: 1512 JASON\Owner C: File (RW-) C:\Documents and Settings\Owner 3C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 80: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 8C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 90: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 9C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 C0: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 D4: Section \BaseNamedObjects\ShimSharedMemory 164: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 17C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 214: File (RWD) C:\Documents and Settings\All Users\Desktop 228: File (RWD) C:\Documents and Settings\Owner\Desktop 22C: Section \BaseNamedObjects\MSCTF.Shared.SFM.EPH 230: File (RWD) C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\CD Burning 258: Section \BaseNamedObjects\MSCTF.Shared.SFM.EPH 25C: File (RWD) C:\Documents and Settings\Owner\Start Menu 2B8: Section \BaseNamedObjects\MSCTF.Shared.SFM.MOF 30C: File (RWD) C:\Documents and Settings\All Users\Start Menu 318: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 330: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 348: Section \BaseNamedObjects\windows_shell_global_counters 34C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 368: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 374: File (RW-) C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat 378: Section \BaseNamedObjects\C:_Documents and Settings_Owner_Local Settings_Temporary Internet Files_Content.IE5_index.dat_491520 380: File (RW-) C:\Documents and Settings\Owner\Cookies\index.dat 384: Section \BaseNamedObjects\C:_Documents and Settings_Owner_Cookies_index.dat_49152 38C: File (RW-) C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat 390: Section \BaseNamedObjects\C:_Documents and Settings_Owner_Local Settings_History_History.IE5_index.dat_65536 3C8: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 3F8: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 430: Section \BaseNamedObjects\UrlZonesSM_Owner 460: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 49C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 4A0: File (RWD) C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Portable Devices 4AC: File (RWD) C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch 4B8: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 4BC: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 4C4: Section \BaseNamedObjects\MSCTF.Shared.SFM.EPH 518: Section \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-839522115-1123561945-2146948035-1003 520: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 534: Section \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-839522115-1123561945-2146948035-1003SFM.DefaultS-1-5-21-839522115-1123561945-2146948035-1003 560: Section \BaseNamedObjects\mmGlobalPnpInfo 588: Section \BaseNamedObjects\WDMAUD_Callbacks 5B0: File (RWD) C:\Documents and Settings\Owner\PrintHood 5E0: File (—) \Dfs 638: Section \BaseNamedObjects\MSCTF.Shared.SFM.MAG 664: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 68C: Section \BaseNamedObjects\DfSharedHeapBAF8C —————————————————————————— aswUpdSv.exe pid: 1572 NT AUTHORITY\SYSTEM C: File (RW-) C:\WINDOWS\system32 —————————————————————————— ashServ.exe pid: 1624 NT AUTHORITY\SYSTEM AC: File (RWD) C:\Program Files\Alwil Software\Avast4\DATA BC: Section \BaseNamedObjects\virDescs.mem C4: Section \BaseNamedObjects\fileID.mem C8: Section \BaseNamedObjects\defMacro.mem CC: Section \BaseNamedObjects\defPoly.mem D0: Section \BaseNamedObjects\defStd1.mem D4: Section \BaseNamedObjects\defStd.mem E0: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 134: Section \BaseNamedObjects\aavmGlob.cnt 144: File (RW-) C:\Program Files\Alwil Software\Avast4 150: File (R–) C:\Program Files\Alwil Software\Avast4\DATA\log\selfdef.log 168: Section \BaseNamedObjects\asw.mesxp2p.conf_data 180: File (RW-) C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log 19C: Section \BaseNamedObjects\asw.mesxp2p.conf_data 1DC: File (R–) C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat 1F4: Section \BaseNamedObjects\aswSqlt658.tls 1F8: File (RW-) C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db 1FC: File (R–) C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt 200: Section \BaseNamedObjects\virFlags.mem 208: Section \BaseNamedObjects\extDlls.mem 214: Section \BaseNamedObjects\packType.mem 234: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 2A0: Section \BaseNamedObjects\vpsLoad.mem 2B8: Section \BaseNamedObjects\aswSched.gui 2D0: File (RW-) C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db 328: Section \BaseNamedObjects\iniRecs.mem 330: Section \BaseNamedObjects\virNames.mem 388: Section \BaseNamedObjects\ShimSharedMemory 3AC: Section \BaseNamedObjects\virURLs.mem 3BC: Section \BaseNamedObjects\aswIntg.mem 3C4: File (RW-) C:\WINDOWS\Temp\Perflib_Perfdata_658.dat 3C8: Section \BaseNamedObjects\Perflib_Perfdata_658 510: Section \BaseNamedObjects\fileType.mem —————————————————————————— smax4pnp.exe pid: 1928 JASON\Owner C: File (RW-) C:\Documents and Settings\Owner 1C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 48: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 68: File (RW-) C:\Program Files\Analog Devices\SoundMAX 6C: File (RW-) C:\Program Files\Analog Devices\SoundMAX 78: Section \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-839522115-1123561945-2146948035-1003 94: Section \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-839522115-1123561945-2146948035-1003SFM.DefaultS-1-5-21-839522115-1123561945-2146948035-1003 A0: Section \BaseNamedObjects\DirectSound Administrator shared thread array BC: Section \BaseNamedObjects\mmGlobalPnpInfo 110: Section \BaseNamedObjects\WDMAUD_Callbacks 23C: Section \BaseNamedObjects\DirectSound Administrator capture focus array 24C: Section \BaseNamedObjects\ShimSharedMemory —————————————————————————— VM_STI.EXE pid: 1940 JASON\Owner C: File (RW-) C:\Documents and Settings\Owner 7C: Section \BaseNamedObjects\MyFileMappingObject E8: Section \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-839522115-1123561945-2146948035-1003SFM.DefaultS-1-5-21-839522115-1123561945-2146948035-1003 108: Section \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-839522115-1123561945-2146948035-1003 144: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 —————————————————————————— BCMSMMSG.exe pid: 1948 JASON\Owner C: File (RW-) C:\Documents and Settings\Owner 4C: Section \BaseNamedObjects\ShimSharedMemory 6C: Section \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-839522115-1123561945-2146948035-1003 —————————————————————————— ashDisp.exe pid: 1956 JASON\Owner C: File (RW-) C:\Documents and Settings\Owner 38: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 3C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 104: Section \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-839522115-1123561945-2146948035-1003 120: Section \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-839522115-1123561945-2146948035-1003SFM.DefaultS-1-5-21-839522115-1123561945-2146948035-1003 134: Section \BaseNamedObjects\ShimSharedMemory 148: Section \BaseNamedObjects\aswIntg.mem 174: Section \BaseNamedObjects\mmGlobalPnpInfo 1C8: Section \BaseNamedObjects\WDMAUD_Callbacks —————————————————————————— MSASCui.exe pid: 1972 JASON\Owner C: File (RW-) C:\Documents and Settings\Owner 10: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 1C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88 20: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 24: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 28: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 30: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 50: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 84: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 A0: Section \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-839522115-1123561945-2146948035-1003 BC: Section \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-839522115-1123561945-2146948035-1003SFM.DefaultS-1-5-21-839522115-1123561945-2146948035-1003 E8: Section \BaseNamedObjects\ShimSharedMemory 358: File (RWD) C:\WINDOWS\Tasks 35C: File (RWD) C:\Documents and Settings\All Users\Start Menu\Programs\Startup 3F4: File (RWD) C:\Documents and Settings\Owner\Start Menu\Programs\Startup 3F8: File (—) C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{A202909D-9151-4904-A94F-17759784D349} 4A4: File (RWD) C:\WINDOWS\system32\drivers\etc —————————————————————————— hkcmd.exe pid: 1984 JASON\Owner C: File (RW-) C:\Documents and Settings\Owner D4: Section \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-839522115-1123561945-2146948035-1003 134: Section \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-839522115-1123561945-2146948035-1003SFM.DefaultS-1-5-21-839522115-1123561945-2146948035-1003 13C: Section \BaseNamedObjects\ShimSharedMemory 14C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 —————————————————————————— jusched.exe pid: 2012 JASON\Owner C: File (RW-) C:\Documents and Settings\Owner 60: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 70: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 A0: File (RW-) C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat AC: Section \BaseNamedObjects\ShimSharedMemory BC: Section \BaseNamedObjects\C:_Documents and Settings_Owner_Local Settings_Temporary Internet Files_Content.IE5_index.dat_475136 C4: File (RW-) C:\Documents and Settings\Owner\Cookies\index.dat C8: Section \BaseNamedObjects\C:_Documents and Settings_Owner_Cookies_index.dat_49152 D0: File (RW-) C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat D4: Section \BaseNamedObjects\C:_Documents and Settings_Owner_Local Settings_History_History.IE5_index.dat_65536 150: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 19C: Section \BaseNamedObjects\SENS Information Cache 204: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 224: Section \BaseNamedObjects\UrlZonesSM_Owner —————————————————————————— ctfmon.exe pid: 2028 JASON\Owner C: File (RW-) C:\Documents and Settings\Owner 30: Section \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-839522115-1123561945-2146948035-1003 74: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 78: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 8C: Section \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-839522115-1123561945-2146948035-1003SFM.DefaultS-1-5-21-839522115-1123561945-2146948035-1003 94: Section \BaseNamedObjects\MSCTF.GCompartListSFM.DefaultS-1-5-21-839522115-1123561945-2146948035-1003 A0: Section \BaseNamedObjects\CTF.AsmListCache.FMPDefaultS-1-5-21-839522115-1123561945-2146948035-1003 110: Section \BaseNamedObjects\ShimSharedMemory 118: Section \BaseNamedObjects\MSCTF.Shared.SFM.EPH 130: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EPH.H.HNPK 134: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EPH.L.OGLM 138: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EPH.J.OGLM 13C: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EPH.K.OGLM 140: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EPH.IB.BPIFJ 144: Section \BaseNamedObjects\MSCTF.Shared.SFM.MOF 14C: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EPH.KB.BPIFJ 150: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EPH.AB.BNDIB 154: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EPH.JB.BPIFJ 15C: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EPH.GB.EDMDC 160: Section \BaseNamedObjects\MSCTF.Shared.SFM.MAG 164: Section \BaseNamedObjects\MSCTF.Shared.SFM.MNK 16C: Section \BaseNamedObjects\MSCTF.Shared.SFM.AHB 180: Section \BaseNamedObjects\MSCTF.Shared.SFM.MGF —————————————————————————— pg2.exe pid: 140 JASON\Owner C: File (RW-) C:\Documents and Settings\Owner 10: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 68: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 88: Section \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-839522115-1123561945-2146948035-1003 A8: Section \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-839522115-1123561945-2146948035-1003SFM.DefaultS-1-5-21-839522115-1123561945-2146948035-1003 AC: File (RW-) C:\Program Files\PeerGuardian2\history.db C8: Section \BaseNamedObjects\ShimSharedMemory 118: Section \BaseNamedObjects\MSCTF.Shared.SFM.EPH —————————————————————————— wcescomm.exe pid: 156 JASON\Owner C: File (RW-) C:\Documents and Settings\Owner 10: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 1C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 20: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 24: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 48: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 7C: File (RW-) C:\Documents and Settings\Owner\Application Data\$_hpcst$.hpc 80: Section \BaseNamedObjects\hpcsharedobjOwner DC: File (RW-) C:\Documents and Settings\Owner\Application Data\$_hpcst$.hpc E0: Section \BaseNamedObjects\hpcsharedobjOwner 194: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 19C: Section \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-839522115-1123561945-2146948035-1003 1BC: Section \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-839522115-1123561945-2146948035-1003SFM.DefaultS-1-5-21-839522115-1123561945-2146948035-1003 1C4: Section \BaseNamedObjects\ShimSharedMemory 218: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 —————————————————————————— spoolsv.exe pid: 220 NT AUTHORITY\SYSTEM C: File (RW-) C:\WINDOWS\system32 60: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 —————————————————————————— rapimgr.exe pid: 320 JASON\Owner C: File (RW-) C:\WINDOWS\system32 10: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 1C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 40: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 84: File (RW-) C:\Documents and Settings\Owner\Application Data\$_hpcst$.hpc 88: Section \BaseNamedObjects\hpcsharedobjOwner BC: File (RW-) C:\DOCUME~1\Owner\LOCALS~1\Temp\WCESLog.log F8: Section \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-839522115-1123561945-2146948035-1003 114: Section \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-839522115-1123561945-2146948035-1003SFM.DefaultS-1-5-21-839522115-1123561945-2146948035-1003 11C: Section \BaseNamedObjects\ShimSharedMemory 124: File (RW-) C:\Documents and Settings\Owner\Application Data\$_hpcst$.hpc 128: Section \BaseNamedObjects\hpcsharedobjOwner 1E8: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 —————————————————————————— DkService.exe pid: 908 NT AUTHORITY\SYSTEM C: File (RW-) C:\WINDOWS\system32 10: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 1C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 20: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 24: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 44: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 AC: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 B8: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 144: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 168: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 18C: File (—) C: 250: File (RW-) C:\WINDOWS\Temp\Perflib_Perfdata_38c.dat 254: Section \BaseNamedObjects\Perflib_Perfdata_38c 3DC: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 414: File (RW-) C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat 418: Section \BaseNamedObjects\C:_Documents and Settings_Owner_Local Settings_Temporary Internet Files_Content.IE5_index.dat_491520 420: File (RW-) C:\Documents and Settings\Owner\Cookies\index.dat 42C: Section \BaseNamedObjects\C:_Documents and Settings_Owner_Cookies_index.dat_49152 430: File (RW-) C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat 434: Section \BaseNamedObjects\C:_Documents and Settings_Owner_Local Settings_History_History.IE5_index.dat_65536 49C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 50C: Section \BaseNamedObjects\SENS Information Cache 538: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 554: Section \BaseNamedObjects\UrlZonesSM_Owner 5EC: File (RWD) C:\Documents and Settings\Owner\Application Data\Microsoft\SystemCertificates\My 708: File (RWD) C:\Documents and Settings\Owner\Application Data\Microsoft\SystemCertificates\My 724: Section \BaseNamedObjects\ShimSharedMemory —————————————————————————— jqs.exe pid: 1012 NT AUTHORITY\SYSTEM C: File (RW-) C:\WINDOWS\system32 44: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 F8: File (RW-) C:\WINDOWS\Temp\Perflib_Perfdata_3f4.dat 100: Section \BaseNamedObjects\Perflib_Perfdata_3f4 26C: Section \BaseNamedObjects\ShimSharedMemory —————————————————————————— Runservice.exe pid: 1060 NT AUTHORITY\SYSTEM C: File (RW-) C:\WINDOWS\system32 60: File (—) C:\WINDOWS\system32\mmf.sys 7C: Section \BaseNamedObjects\MMFsmCom —————————————————————————— svchost.exe pid: 1432 NT AUTHORITY\SYSTEM C: File (RW-) C:\WINDOWS\system32 60: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 B4: File (RW-) C:\WINDOWS\Sti_Trace.log 15C: File (RW-) C:\WINDOWS\wiaservc.log 1AC: File (RW-) C:\WINDOWS\Sti_Trace.log 1D0: File (RW-) C:\WINDOWS\wiadebug.log —————————————————————————— ashMaiSv.exe pid: 2424 NT AUTHORITY\SYSTEM C: File (RW-) C:\WINDOWS\system32 B4: Section \BaseNamedObjects\avast.remote.iframe.permitted.urls C4: File (RW-) C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log 11C: Section \BaseNamedObjects\ShimSharedMemory 174: File (RWD) C:\Program Files\Alwil Software\Avast4\DATA —————————————————————————— ashWebSv.exe pid: 2512 NT AUTHORITY\SYSTEM 30: File (RW-) C:\Program Files\Alwil Software\Avast4 A4: File (RW-) C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws EC: Section \BaseNamedObjects\virDescs.mem 128: File (RW-) C:\WINDOWS\Temp\_avast4_\Webshlock.txt 12C: Section \BaseNamedObjects\virURLs.mem 134: Section \BaseNamedObjects\fileID.mem 138: Section \BaseNamedObjects\defMacro.mem 140: Section \BaseNamedObjects\defPoly.mem 144: Section \BaseNamedObjects\defStd.mem 148: Section \BaseNamedObjects\defStd1.mem 298: Section \BaseNamedObjects\virFlags.mem 2A4: Section \BaseNamedObjects\fileType.mem 2A8: Section \BaseNamedObjects\packType.mem 2AC: Section \BaseNamedObjects\virNames.mem 2B0: Section \BaseNamedObjects\iniRecs.mem 2B4: Section \BaseNamedObjects\extDlls.mem 2B8: Section \BaseNamedObjects\vpsLoad.mem —————————————————————————— alg.exe pid: 2944 NT AUTHORITY\LOCAL SERVICE C: File (RW-) C:\WINDOWS\system32 58: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 —————————————————————————— wuauclt.exe pid: 1428 JASON\Owner C: File (RW-) C:\WINDOWS\system32 58: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 5C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 60: File (RW-) C:\WINDOWS\WindowsUpdate.log 64: File (RW-) C:\WINDOWS\WindowsUpdate.log 68: File (RW-) C:\WINDOWS\WindowsUpdate.log 6C: File (RW-) C:\WINDOWS\WindowsUpdate.log 70: File (RW-) C:\WINDOWS\WindowsUpdate.log 74: File (RW-) C:\WINDOWS\WindowsUpdate.log 78: File (RW-) C:\WINDOWS\WindowsUpdate.log 7C: File (RW-) C:\WINDOWS\WindowsUpdate.log 80: File (RW-) C:\WINDOWS\WindowsUpdate.log 84: File (RW-) C:\WINDOWS\WindowsUpdate.log 88: File (RW-) C:\WINDOWS\WindowsUpdate.log 8C: File (RW-) C:\WINDOWS\WindowsUpdate.log 90: File (RW-) C:\WINDOWS\WindowsUpdate.log 94: File (RW-) C:\WINDOWS\WindowsUpdate.log 98: File (RW-) C:\WINDOWS\WindowsUpdate.log 9C: File (RW-) C:\WINDOWS\WindowsUpdate.log A0: File (RW-) C:\WINDOWS\WindowsUpdate.log A4: File (RW-) C:\WINDOWS\WindowsUpdate.log A8: File (RW-) C:\WINDOWS\WindowsUpdate.log AC: File (RW-) C:\WINDOWS\WindowsUpdate.log B0: File (RW-) C:\WINDOWS\WindowsUpdate.log B4: File (RW-) C:\WINDOWS\WindowsUpdate.log B8: File (RW-) C:\WINDOWS\WindowsUpdate.log BC: File (RW-) C:\WINDOWS\WindowsUpdate.log C0: File (RW-) C:\WINDOWS\WindowsUpdate.log C4: File (RW-) C:\WINDOWS\WindowsUpdate.log C8: File (RW-) C:\WINDOWS\WindowsUpdate.log CC: File (RW-) C:\WINDOWS\WindowsUpdate.log D0: File (RW-) C:\WINDOWS\WindowsUpdate.log D4: File (RW-) C:\WINDOWS\WindowsUpdate.log DC: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 100: Section \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-839522115-1123561945-2146948035-1003 120: Section \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-839522115-1123561945-2146948035-1003SFM.DefaultS-1-5-21-839522115-1123561945-2146948035-1003 220: File (RW-) C:\WINDOWS\WindowsUpdate.log 224: File (RW-) C:\WINDOWS\WindowsUpdate.log 228: File (RW-) C:\WINDOWS\WindowsUpdate.log 22C: File (RW-) C:\WINDOWS\WindowsUpdate.log 230: File (RW-) C:\WINDOWS\WindowsUpdate.log 234: File (RW-) C:\WINDOWS\WindowsUpdate.log 238: File (RW-) C:\WINDOWS\WindowsUpdate.log 23C: File (RW-) C:\WINDOWS\WindowsUpdate.log 240: File (RW-) C:\WINDOWS\WindowsUpdate.log 244: File (RW-) C:\WINDOWS\WindowsUpdate.log 248: File (RW-) C:\WINDOWS\WindowsUpdate.log 24C: File (RW-) C:\WINDOWS\WindowsUpdate.log 250: File (RW-) C:\WINDOWS\WindowsUpdate.log 254: File (RW-) C:\WINDOWS\WindowsUpdate.log 258: File (RW-) C:\WINDOWS\WindowsUpdate.log 25C: File (RW-) C:\WINDOWS\WindowsUpdate.log 260: File (RW-) C:\WINDOWS\WindowsUpdate.log 264: File (RW-) C:\WINDOWS\WindowsUpdate.log 268: File (RW-) C:\WINDOWS\WindowsUpdate.log 26C: File (RW-) C:\WINDOWS\WindowsUpdate.log 270: File (RW-) C:\WINDOWS\WindowsUpdate.log 274: File (RW-) C:\WINDOWS\WindowsUpdate.log 278: File (RW-) C:\WINDOWS\WindowsUpdate.log 27C: File (RW-) C:\WINDOWS\WindowsUpdate.log 280: File (RW-) C:\WINDOWS\WindowsUpdate.log 284: File (RW-) C:\WINDOWS\WindowsUpdate.log 288: File (RW-) C:\WINDOWS\WindowsUpdate.log 28C: File (RW-) C:\WINDOWS\WindowsUpdate.log 290: File (RW-) C:\WINDOWS\WindowsUpdate.log 294: File (RW-) C:\WINDOWS\WindowsUpdate.log 2A0: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 2A4: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 2AC: File (RW-) C:\WINDOWS\WindowsUpdate.log 2B0: File (RW-) C:\WINDOWS\WindowsUpdate.log 2B4: File (RW-) C:\WINDOWS\WindowsUpdate.log 2B8: File (RW-) C:\WINDOWS\WindowsUpdate.log 2BC: File (RW-) C:\WINDOWS\WindowsUpdate.log 2C0: File (RW-) C:\WINDOWS\WindowsUpdate.log 2C4: File (RW-) C:\WINDOWS\WindowsUpdate.log 2C8: File (RW-) C:\WINDOWS\WindowsUpdate.log 2CC: File (RW-) C:\WINDOWS\WindowsUpdate.log 2D0: File (RW-) C:\WINDOWS\WindowsUpdate.log 2D4: File (RW-) C:\WINDOWS\WindowsUpdate.log 2D8: File (RW-) C:\WINDOWS\WindowsUpdate.log 2DC: File (RW-) C:\WINDOWS\WindowsUpdate.log 2E0: File (RW-) C:\WINDOWS\WindowsUpdate.log 2E4: File (RW-) C:\WINDOWS\WindowsUpdate.log 2E8: File (RW-) C:\WINDOWS\WindowsUpdate.log 2EC: File (RW-) C:\WINDOWS\WindowsUpdate.log 2F0: File (RW-) C:\WINDOWS\WindowsUpdate.log 2F4: File (RW-) C:\WINDOWS\WindowsUpdate.log 2F8: File (RW-) C:\WINDOWS\WindowsUpdate.log 2FC: File (RW-) C:\WINDOWS\WindowsUpdate.log 300: File (RW-) C:\WINDOWS\WindowsUpdate.log 304: File (RW-) C:\WINDOWS\WindowsUpdate.log 308: File (RW-) C:\WINDOWS\WindowsUpdate.log 30C: File (RW-) C:\WINDOWS\WindowsUpdate.log 310: File (RW-) C:\WINDOWS\WindowsUpdate.log 314: File (RW-) C:\WINDOWS\WindowsUpdate.log 318: File (RW-) C:\WINDOWS\WindowsUpdate.log 31C: File (RW-) C:\WINDOWS\WindowsUpdate.log 320: File (RW-) C:\WINDOWS\WindowsUpdate.log —————————————————————————— firefox.exe pid: 560 JASON\Owner C: File (RW-) C:\Program Files\Mozilla Firefox 10: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 4C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 74: Section \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-839522115-1123561945-2146948035-1003 94: Section \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-839522115-1123561945-2146948035-1003SFM.DefaultS-1-5-21-839522115-1123561945-2146948035-1003 A0: Section \BaseNamedObjects\ShimSharedMemory F8: File (—) C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5wxa5vgz.default\parent.lock 21C: File (RW-) C:\Program Files\Mozilla Firefox\chrome\en-US.jar 220: File (RW-) C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5wxa5vgz.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}\chrome\adblockplus.jar 22C: File (RW-) C:\Program Files\Mozilla Firefox\chrome\browser.jar 238: File (RW-) C:\Program Files\Mozilla Firefox\chrome\toolkit.jar 250: File (RW-) C:\Program Files\Mozilla Firefox\chrome\classic.jar 268: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 278: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2 2E4: Section \BaseNamedObjects\UrlZonesSM_Owner 30C: File (RW-) C:\Program Files\Mozilla Firefox\chrome\reporter.jar 310: File (RW-) C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5wxa5vgz.default\extensions\filtersetg@updater\chrome\fgupdater.jar 330: File (RW-) C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5wxa5vgz.default\cert8.db 334: File (RW-) C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5wxa5vgz.default\key3.db 33C: Section \BaseNamedObjects\MSCTF.Shared.SFM.AHB 354: File (RW-) C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wxa5vgz.default\Cache\_CACHE_001_ 358: File (RW-) C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wxa5vgz.default\Cache\_CACHE_003_ 35C: File (RW-) C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wxa5vgz.default\Cache\_CACHE_MAP_ 360: File (RW-) C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\5wxa5vgz.default\Cache\_CACHE_002_ 39C: File (RW-) C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5wxa5vgz.default\history.dat 3AC: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 3B8: File (RW-) C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5wxa5vgz.default\search.sqlite 3BC: File (RW-) C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5wxa5vgz.default\search.sqlite 3C8: File (RW-) C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5wxa5vgz.default\urlclassifier2.sqlite 3CC: File (RW-) C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5wxa5vgz.default\urlclassifier2.sqlite 410: Section \BaseNamedObjects\MSCTF.Shared.SFM.EPH 4BC: File (RW-) C:\Program Files\Mozilla Firefox\chrome\pippki.jar —————————————————————————— cmd.exe pid: 1520 JASON\Owner C: File (RW-) C:\Documents and Settings\Owner\Desktop 44: File (R–) C:\Documents and Settings\Owner\Desktop\results.txt 48: File (R–) C:\Documents and Settings\Owner\Desktop\results.txt 58: Section \BaseNamedObjects\ShimSharedMemory —————————————————————————— handle.exe pid: 3788 JASON\Owner C: File (RW-) C:\Documents and Settings\Owner\Desktop 44: File (R–) C:\Documents and Settings\Owner\Desktop\results.txt 48: File (R–) C:\Documents and Settings\Owner\Desktop\results.txt 7CC: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03
Hi,

You're most welcome. Here are some important final steps:

Please now delete rsit.exe, SDFix.exe and any remaining logs from your Desktop, also delete this folder:

C:\rsit


Create a new, clean System Restore point which you can use in case of future system problems:
Press Start->All Programs->Accessories->System Tools->System Restore
Select Create a restore point, then Next, type a name like All Clean then press the Create button and once it's done press Close

Now remove old, infected System Restore points:
Next click Start->Run and type cleanmgr in the box and press OK
Ensure the boxes for Recycle Bin, Temporary Files and Temporary Internet Files are checked, you can choose to check other boxes if you wish but they are not required.
Select the More Options tab, under System Restore press Clean up… and say Yes to the prompt
Press OK and Yes to confirm

————————————————————————

Here are some recommendations to help you keep your machine clean:

Windows XP SP3 has important updates and eventually it will be necessary in order to keep your machine safe.
I recommend you follow these instructions, then repeat them after SP3 has been installed.

Press Start->Run, copy/paste the following command (it's one long command) into the box and press OK:

cmd /c sc config dnscache start= disabled

Then reboot your computer


If you need further help with getting your machine working correctly with SP3 then I recommend you post in the Microsoft Windows forum here at WhatTheTech - the experts there specialise in this type of issue and you are very likely to get a speedy resolution.

I recommend you install a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.
Also: subscribe to the mailing list to get update notifications.

Please take care when downloading programs. One of the easiest ways to be infected is to download freeware/shareware programs which come laden with malware - this includes allowing websites to install browser plug-ins or ActiveX controls. Before downloading, it is crucial to check whether the source is reputable.
One way to check is to use McAfee SiteAdvisor. Copy the domain name into the space provided and SiteAdvisor will give you a report on the website which can help you decide if it is safe. They also have a toolbar for IE and Firefox which adds this functionality to your browser.

Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

Find out more about how to prevent infection in the future
http://forum.malwareremoval.com/viewtopic.php?p=33687

Please post back to let me know that you have read this, and if there are any further issues.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI