This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] PC operating very slowly

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
First what i want to say my english writing skills are bad sorry.
Ok when i rebooting my pc its takes ages to start it and windows freezing sometimes…



Logfile of HijackThis v1.99.1
Scan saved at 12:05:06 PM, on 26/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Windows Live\Family Safety\fssui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.winfuture.de/
O1 - Hosts: 78.61.97.143 l2testauthd.lineage2.com
O1 - Hosts: 78.61.97.143 l2authd.lineage2.com
O1 - Hosts: 216.107.250.194 nprotect.lineage2.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fssui.exe" -autorun
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&ksportuoti į Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Tyrimai - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Hi nasdad,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

bittorrent
You have bittorrent, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm://http://www.techweb.com/wire/1605005…cles/art053.htm
See Clean/Infected P2P Programs here

I would recommend that you uninstall bittorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Hey tomk,
I deleted bittorrent,downloaded Download - ATF Cleaner and cleaned with it my pc…I tried to install Malwarebytes' Anti-Malware its saying error "Unable to register the dll/ocx but i was scanned with it before…
HijackTHis log :
Logfile of HijackThis v1.99.1
Scan saved at 12:00:14 AM, on 29/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Windows Live\Family Safety\fssui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Registry Clean Expert\RCHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\mbam-setup.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\is-J9GGC.tmp\mbam-setup.tmp
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O1 - Hosts: 78.61.97.143 l2testauthd.lineage2.com
O1 - Hosts: 78.61.97.143 l2authd.lineage2.com
O1 - Hosts: 216.107.250.194 nprotect.lineage2.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fssui.exe" -autorun
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [RegClean Expert Scheduler] "C:\Program Files\Registry Clean Expert\RCHelper.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [eMuleAutoStart] C:\zMule\zmule.exe -AutoStart
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&ksportuoti į Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Tyrimai - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

Computer now working little better but still freezing and …..

NasDad
nasdad,

Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
tomk,
I scanned
——————-\\ Lop S&D 4.2.4-8 XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon™ 64 Processor 2800+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Owner ( Administrator )
BOOT : Normal boot
Antivirus : AVG 0.0 (Not Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:29 Go (Free:22 Go)
D:\ (Local Disk) - NTFS - Total:45 Go (Free:27 Go)
E:\ (CD or DVD)
F:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)

"C:\Lop SD" ( MAJ : 27-10-2008|09:15 )
Option : [1] ( Wed 29/10/2008|11:39 )

——————–\\ Listing folders in APPLIC~1

[03/10/2008|09:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[26/10/2008|09:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ avg8
[12/10/2008|05:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Avira
[12/10/2008|08:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ bivqvedw
[03/10/2008|09:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ CyberLink
[03/10/2008|09:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ GRETECH
[05/10/2008|05:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ IJJIGame
[26/10/2008|09:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[09/10/2008|12:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Mathematica
[12/10/2008|04:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[03/10/2008|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ nView_Profiles
[04/10/2008|05:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Skype
[04/10/2008|05:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SwiftKit
[03/10/2008|09:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[26/10/2008|09:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ WLInstaller

[03/10/2008|08:52] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft

[27/10/2008|12:12] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft

[26/10/2008|09:47] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft

[04/10/2008|05:27] C:\DOCUME~1\Owner\APPLIC~1\ Adobe
[26/10/2008|12:19] C:\DOCUME~1\Owner\APPLIC~1\ AVGTOOLBAR
[29/10/2008|11:35] C:\DOCUME~1\Owner\APPLIC~1\ DNA
[03/10/2008|09:45] C:\DOCUME~1\Owner\APPLIC~1\ GRETECH
[03/10/2008|08:57] C:\DOCUME~1\Owner\APPLIC~1\ Identities
[04/10/2008|05:27] C:\DOCUME~1\Owner\APPLIC~1\ Macromedia
[26/10/2008|09:55] C:\DOCUME~1\Owner\APPLIC~1\ Malwarebytes
[09/10/2008|12:02] C:\DOCUME~1\Owner\APPLIC~1\ Mathematica
[27/10/2008|12:10] C:\DOCUME~1\Owner\APPLIC~1\ Microsoft
[03/10/2008|09:19] C:\DOCUME~1\Owner\APPLIC~1\ Mozilla
[18/10/2008|04:06] C:\DOCUME~1\Owner\APPLIC~1\ SystemRequirementsLab
[29/10/2008|11:27] C:\DOCUME~1\Owner\APPLIC~1\ Skype
[29/10/2008|11:26] C:\DOCUME~1\Owner\APPLIC~1\ skypePM
[03/10/2008|09:13] C:\DOCUME~1\Owner\APPLIC~1\ Sun
[18/10/2008|04:43] C:\DOCUME~1\Owner\APPLIC~1\ teamspeak2
[12/10/2008|01:30] C:\DOCUME~1\Owner\APPLIC~1\ TeamViewer
[25/10/2008|12:09] C:\DOCUME~1\Owner\APPLIC~1\ Ventrilo
[05/10/2008|03:09] C:\DOCUME~1\Owner\APPLIC~1\ WinRAR
[18/10/2008|12:30] C:\DOCUME~1\Owner\APPLIC~1\ WNR

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[29/10/2008 11:24 AM][–a——] C:\WINDOWS\tasks\RegCure Program Check.job
[12/10/2008 04:48 PM][–a——] C:\WINDOWS\tasks\RegCure.job
[29/10/2008 12:20 AM][–a——] C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[29/10/2008 11:24 AM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[28/02/2006 02:00 PM][-r-h—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[03/10/2008|09:08] C:\Program Files\ Adobe
[03/10/2008|09:20] C:\Program Files\ Ahead
[12/10/2008|08:10] C:\Program Files\ Alwil Software
[26/10/2008|12:19] C:\Program Files\ AVG
[03/10/2008|09:28] C:\Program Files\ AvRack
[03/10/2008|09:44] C:\Program Files\ CyberLink
[26/10/2008|03:26] C:\Program Files\ Common Files
[03/10/2008|08:49] C:\Program Files\ ComPlus Applications
[26/10/2008|12:31] C:\Program Files\ DAEMON Tools
[03/10/2008|09:10] C:\Program Files\ DivX Total Pack
[04/10/2008|06:49] C:\Program Files\ DNA
[12/10/2008|08:52] C:\Program Files\ Enigma Software Group
[26/10/2008|10:40] C:\Program Files\ ERUNT
[03/10/2008|09:09] C:\Program Files\ Fotonija
[03/10/2008|09:45] C:\Program Files\ GRETECH
[29/10/2008|12:00] C:\Program Files\ Hijackthis
[25/10/2008|11:01] C:\Program Files\ InstallShield Installation Information
[03/10/2008|09:12] C:\Program Files\ Internet Explorer
[03/10/2008|09:18] C:\Program Files\ Java
[03/10/2008|09:50] C:\Program Files\ Messenger
[03/10/2008|08:52] C:\Program Files\ microsoft frontpage
[03/10/2008|09:40] C:\Program Files\ Microsoft Office
[11/10/2008|04:59] C:\Program Files\ Microsoft SQL Server Compact Edition
[03/10/2008|09:40] C:\Program Files\ Microsoft Visual Studio
[12/10/2008|10:40] C:\Program Files\ Microsoft Works
[03/10/2008|09:40] C:\Program Files\ Microsoft.NET
[05/10/2008|03:03] C:\Program Files\ MySQL
[03/10/2008|08:50] C:\Program Files\ Movie Maker
[29/10/2008|11:27] C:\Program Files\ Mozilla Firefox
[03/10/2008|08:48] C:\Program Files\ MSN
[03/10/2008|08:48] C:\Program Files\ MSN Gaming Zone
[28/10/2008|05:21] C:\Program Files\ NetMeeting
[03/10/2008|08:50] C:\Program Files\ Online Services
[03/10/2008|08:50] C:\Program Files\ Outlook Express
[05/10/2008|02:51] C:\Program Files\ PremiumSoft
[03/10/2008|09:28] C:\Program Files\ Realtek Sound Manager
[12/10/2008|04:48] C:\Program Files\ RegCure
[27/10/2008|04:32] C:\Program Files\ Registry Clean Expert
[03/10/2008|09:10] C:\Program Files\ SereneScreen
[18/10/2008|04:06] C:\Program Files\ SystemRequirementsLab
[04/10/2008|05:29] C:\Program Files\ Skype
[26/10/2008|10:30] C:\Program Files\ SwiftKit
[28/10/2008|10:16] C:\Program Files\ sXe Injected
[18/10/2008|04:43] C:\Program Files\ Teamspeak2_RC2
[05/10/2008|02:02] C:\Program Files\ TeamViewer3
[03/10/2008|08:57] C:\Program Files\ Uninstall Information
[22/10/2008|08:40] C:\Program Files\ Ventrilo
[03/10/2008|09:45] C:\Program Files\ Winamp
[12/10/2008|10:44] C:\Program Files\ Windows Live
[11/10/2008|04:58] C:\Program Files\ Windows Live Favorites
[11/10/2008|04:59] C:\Program Files\ Windows Live Toolbar
[03/10/2008|09:44] C:\Program Files\ Windows Media Player
[03/10/2008|08:48] C:\Program Files\ Windows NT
[03/10/2008|08:50] C:\Program Files\ WindowsUpdate
[03/10/2008|09:11] C:\Program Files\ WinRAR
[27/10/2008|04:24] C:\Program Files\ Wise Registry Cleaner 3
[03/10/2008|08:52] C:\Program Files\ xerox

——————–\\ Listing Folders in C:\Program Files\Common Files

[03/10/2008|09:09] C:\Program Files\Common Files\ Adobe
[03/10/2008|09:20] C:\Program Files\Common Files\ Ahead
[26/10/2008|03:26] C:\Program Files\Common Files\ Blizzard Entertainment
[03/10/2008|09:40] C:\Program Files\Common Files\ DESIGNER
[12/10/2008|04:45] C:\Program Files\Common Files\ Download Manager
[07/10/2008|02:45] C:\Program Files\Common Files\ INCA Shared
[09/10/2008|11:43] C:\Program Files\Common Files\ InstallShield
[03/10/2008|09:18] C:\Program Files\Common Files\ Java
[26/10/2008|12:18] C:\Program Files\Common Files\ Microsoft Shared
[03/10/2008|08:50] C:\Program Files\Common Files\ MSSoap
[03/10/2008|11:42] C:\Program Files\Common Files\ ODBC
[03/10/2008|08:50] C:\Program Files\Common Files\ Services
[03/10/2008|09:46] C:\Program Files\Common Files\ System
[04/10/2008|05:29] C:\Program Files\Common Files\ Skype
[03/10/2008|11:42] C:\Program Files\Common Files\ SpeechEngines
[11/10/2008|04:45] C:\Program Files\Common Files\ WindowsLiveInstaller
[22/10/2008|08:40] C:\Program Files\Common Files\ Wise Installation Wizard

——————–\\ Process

( 34 Processes )

… OK !

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

No Lop folder found !

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-29 11:40:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

——————–\\ Cracks & Keygens ..

C:\DOCUME~1\Owner\Recent\Mathematica 6.0 + Keygen.lnk


[F:30][D:2]-> C:\DOCUME~1\Owner\LOCALS~1\Temp
[F:9][D:0]-> C:\DOCUME~1\Owner\Cookies
[F:136][D:13]-> C:\DOCUME~1\Owner\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Wed 29/10/2008|11:42 - Option : [1]

——————–\\ Scan completed at 11:42:10
nasdad,

You were likely infected from downloading cracks.

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
      O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
      O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

Using Windows Explorer (Windows Key + E), locate the following file and DELETE it (if still present):
C:\Documents and Settings\Owner\Recent\Mathematica 6.0 + Keygen.lnk<–This file

Then

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Hey tom again, i scanned heres report ——————————————————————————- KASPERSKY ONLINE SCANNER 7 REPORT Wednesday, October 29, 2008 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Wednesday, October 29, 2008 04:28:52 Records in database: 1355156 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ Scan statistics: Files scanned: 33932 Threat name: 1 Infected objects: 2 Suspicious objects: 0 Duration of the scan: 01:05:20 File name / Threat name / Threats count C:\Documents and Settings\Owner\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1 C:\Documents and Settings\Owner\Local Settings\Temp\SmitfraudFix.zip Infected: not-a-virus:RiskTool.Win32.Reboot.f 1 The selected area was scanned.
Logfile of HijackThis v1.99.1
Scan saved at 9:44:44 PM, on 29/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Windows Live\Family Safety\fssui.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Registry Clean Expert\RCHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SwiftKit\SwiftKit.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: 78.61.97.143 l2testauthd.lineage2.com
O1 - Hosts: 78.61.97.143 l2authd.lineage2.com
O1 - Hosts: 216.107.250.194 nprotect.lineage2.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fssui.exe" -autorun
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [RegClean Expert Scheduler] "C:\Program Files\Registry Clean Expert\RCHelper.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [eMuleAutoStart] C:\zMule\zmule.exe -AutoStart
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&ksportuoti į Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Tyrimai - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Computer working better but still need wait ages to boot it…
nasdad,

OK, lets get another look.

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
Info

info.txt logfile of random's system information tool 1.04 2008-10-29 22:06:13

======Uninstall list======

–>C:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_DivX 132 C:\WINDOWS\INF\Tpack.inf
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin–>C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A80000000002}
Anglonas–>MsiExec.exe /I{A89D4ADB-754D-4A93-B612-F596D02EBA93}
AVG 8.0–>C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Counter-Strike 1.6–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{13B792AA-C078-43A4-8A3A-8B12D629940D}\Setup.exe" -l0x19
DivX Total Pack–>C:\Program Files\DivX Total Pack\uninstall.exe
ERUNT 1.1j–>"C:\Program Files\ERUNT\unins000.exe"
GOM Player–>"C:\Program Files\GRETECH\GomPlayer\Uninstall.exe"
Highlight Viewer (Windows Live Toolbar)–>MsiExec.exe /X{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}
Hijackthis 1.99.1–>"C:\Program Files\Hijackthis\unins000.exe"
HijackThis 2.0.2–>"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Java™ SE Runtime Environment 6–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
Map Button (Windows Live Toolbar)–>MsiExec.exe /X{7745B7A9-F323-4BB9-9811-01BF57A028DA}
Microsoft .NET Framework 2.0–>C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Office Professional leidimas 2003–>MsiExec.exe /I{90110427-6000-11D3-8CFE-0150048383C9}
Microsoft SQL Server 2005 Compact Edition [ENU]–>MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (3.0.3)–>C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MySQL Server 5.0–>MsiExec.exe /I{46F441C8-4193-4D54-9F93-751D27EFB8F4}
Nero 6 Ultra Edition–>C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
NVIDIA Drivers–>C:\WINDOWS\system32\NVUNINST.EXE UninstallGUI
PowerDVD–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
PremiumSoft Navicat 8.0 for MySQL–>"C:\Program Files\PremiumSoft\Navicat 8.0 MySQL\unins000.exe"
Realtek AC'97 Audio–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
RegCure 1.5.0.1–>C:\Program Files\RegCure\uninst.exe
Registry Clean Expert–>"C:\Program Files\Registry Clean Expert\unins000.exe"
RON Tool Offersfortoday–>C:\WINDOWS\system32\fkdfwyvhvywdcp.exe
Security Update for Windows Media Player 10 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923689)–>"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)–>C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953838)–>"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956390)–>"C:\WINDOWS\$NtUninstallKB956390$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
SereneScreen Marine Aquarium 2.6–>"C:\Program Files\SereneScreen\Marine Aquarium 2.6\unins000.exe"
Skype™ 3.8–>MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Smart Menus (Windows Live Toolbar)–>MsiExec.exe /X{F084395C-40FB-4DB3-981C-B51E74E1E83D}
SwiftKit–>C:\Program Files\SwiftKit\Uninstall.exe
sXe Injected–>"C:\Program Files\sXe Injected\uninstall.exe"
System Requirements Lab–>C:\Program Files\SystemRequirementsLab\Uninstall.exe
TeamSpeak 2 RC2–>"C:\Program Files\Teamspeak2_RC2\unins000.exe"
TeamViewer 3–>C:\Program Files\TeamViewer3\uninstall.exe
Update for Windows XP (KB898461)–>"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)–>"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Ventrilo Client–>MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
Winamp (remove only)–>"C:\Program Files\Winamp\UninstWA.exe"
Windows atskiros kalbos sąsajos paketas–>MsiExec.exe /X{0711E6D6-96D7-4F13-99F6-DF16D5EC22D3}
Windows Live Favorites for Windows Live Toolbar–>MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
Windows Live installer–>MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Mail–>MsiExec.exe /I{184E7118-0295-43C4-B72C-1D54AA75AAF7}
Windows Live Messenger–>MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live OneCare Family Safety–>MsiExec.exe /X{3403CB31-D7C1-43F4-9D2F-579758C0CF09}
Windows Live Photo Gallery–>MsiExec.exe /X{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}
Windows Live Sign-in Assistant–>MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Live Toolbar Extension (Windows Live Toolbar)–>MsiExec.exe /X{341201D4-4F61-4ADB-987E-9CCE4D83A58D}
Windows Live Toolbar–>"C:\Program Files\Windows Live Toolbar\UnInstall.exe" {D5A145FC-D00C-4F1A-9119-EB4D9D659750}
Windows Live Toolbar–>MsiExec.exe /X{D5A145FC-D00C-4F1A-9119-EB4D9D659750}
Windows Live Writer–>MsiExec.exe /X{9176251A-4CC1-4DDB-B343-B487195EB397}
Windows Media Format Runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Player 10–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
WinRAR archiver–>C:\Program Files\WinRAR\uninstall.exe
Wolfram Mathematica 6–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{38D69F3E-823F-4203-989D-4D47227AF920}
Wolfram Notebook Indexer 2.0–>MsiExec.exe /I{F9B2E82F-B10A-454E-B19B-735CFF6A5DD2}
World of Warcraft–>C:\Program Files\Common Files\Blizzard Entertainment\World of Warcraft\Uninstall.exe
zMule–>MsiExec.exe /I{9A6FFEF6-8E4E-4CD5-8C71-C121969D6924}

======Hosts File======

127.0.0.1 localhost
78.61.97.143 l2testauthd.lineage2.com
[removed] l2authd.lineage2.com
216.107.250.194 nprotect.lineage2.com

======Security center information======

AV: AVG (disabled) (outdated)

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 12 Stepping 0, AuthenticAMD
"PROCESSOR_REVISION"=0c00
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

—————–EOF—————–


Log

Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-29 22:05:49
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 23 GB (77%) free of 30 GB
Total RAM: 511 MB (17% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:06:07 PM, on 29/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Windows Live\Family Safety\fssui.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Registry Clean Expert\RCHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\zMule\zmule.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SwiftKit\SwiftKit.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\RSIT.exe
C:\Program Files\trend micro\Owner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: 78.61.97.143 l2testauthd.lineage2.com
O1 - Hosts: 78.61.97.143 l2authd.lineage2.com
O1 - Hosts: 216.107.250.194 nprotect.lineage2.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fssui.exe" -autorun
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [RegClean Expert Scheduler] "C:\Program Files\Registry Clean Expert\RCHelper.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [eMuleAutoStart] C:\zMule\zmule.exe -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: &Windows; Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&ksportuoti; į Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Tyrimai - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 6493 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
C:\WINDOWS\tasks\RegCure Program Check.job
C:\WINDOWS\tasks\RegCure.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
Windows Live OneCare Family Safety Browser Helper Class - C:\Program Files\Windows Live\Family Safety\fssbho.dll [2007-12-17 56360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0\bin\ssv.dll [2008-10-03 501384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0\bin\jusched.exe [2008-10-03 77824]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2006-01-12 155648]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-10-22 7700480]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMCTray.dll [2006-10-22 86016]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2004-07-01 67584]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2003-10-31 32768]
"DAEMON Tools"=C:\Program Files\DAEMON Tools\daemon.exe [2006-11-12 157592]
"fssui"=C:\Program Files\Windows Live\Family Safety\fssui.exe [2007-12-17 243240]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2008-09-23 21755688]
"BitTorrent DNA"=C:\Program Files\DNA\btdna.exe [2008-10-04 289088]
"MsnMsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
"RegClean Expert Scheduler"=C:\Program Files\Registry Clean Expert\RCHelper.exe [2008-04-02 605944]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"eMuleAutoStart"=C:\zMule\zmule.exe [2008-06-10 5279744]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup
ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"ForceClassicControlPanel"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
shell\AutoRun\command - F:\AutoRun.exe


======List of files/folders created in the last 1 months======

2008-10-29 22:05:56 —-D—- C:\Program Files\trend micro
2008-10-29 22:05:49 —-D—- C:\rsit
2008-10-29 11:39:43 —-A—- C:\lopR.txt
2008-10-29 11:37:44 —-D—- C:\Lop SD
2008-10-28 20:52:35 —-D—- C:\WINDOWS\Minidump
2008-10-28 10:44:53 —-D—- C:\csdos
2008-10-28 10:41:44 —-A—- C:\msvcr71.dll
2008-10-28 10:41:44 —-A—- C:\how to.txt
2008-10-28 10:41:44 —-A—- C:\csdos.exe
2008-10-27 20:34:36 —-D—- C:\Logs
2008-10-27 16:21:39 —-D—- C:\Program Files\Wise Registry Cleaner 3
2008-10-27 15:57:55 —-D—- C:\Program Files\Registry Clean Expert
2008-10-27 14:56:50 —-A—- C:\boot.txt
2008-10-27 12:09:46 —-D—- C:\zMule
2008-10-26 15:26:43 —-D—- C:\Program Files\Common Files\Blizzard Entertainment
2008-10-26 10:41:00 —-D—- C:\WINDOWS\ERDNT
2008-10-26 10:40:15 —-D—- C:\Program Files\ERUNT
2008-10-26 10:28:01 —-D—- C:\Program Files\Hijackthis
2008-10-26 09:55:33 —-D—- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-10-26 09:55:21 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-26 00:31:17 —-HD—- C:\$AVG8.VAULT$
2008-10-26 00:20:08 —-A—- C:\WINDOWS\system32\avgrsstx.dll
2008-10-26 00:19:43 —-D—- C:\Documents and Settings\Owner\Application Data\AVGTOOLBAR
2008-10-26 00:19:16 —-D—- C:\Program Files\AVG
2008-10-26 00:19:15 —-D—- C:\Documents and Settings\All Users\Application Data\avg8
2008-10-24 21:36:56 —-HDC—- C:\WINDOWS\$NtUninstallKB958644$
2008-10-24 13:09:52 —-D—- C:\Program Files\sXe Injected
2008-10-22 20:40:33 —-D—- C:\Documents and Settings\Owner\Application Data\Ventrilo
2008-10-22 20:40:16 —-D—- C:\Program Files\Ventrilo
2008-10-22 20:40:07 —-D—- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-18 16:43:07 —-D—- C:\Documents and Settings\Owner\Application Data\teamspeak2
2008-10-18 16:42:51 —-D—- C:\Program Files\Teamspeak2_RC2
2008-10-18 16:06:13 —-D—- C:\Program Files\SystemRequirementsLab
2008-10-18 16:06:09 —-D—- C:\Documents and Settings\Owner\Application Data\SystemRequirementsLab
2008-10-18 12:30:01 —-D—- C:\Documents and Settings\Owner\Application Data\WNR
2008-10-16 07:09:58 —-HDC—- C:\WINDOWS\$NtUninstallKB956803$
2008-10-16 07:09:50 —-HDC—- C:\WINDOWS\$NtUninstallKB956391$
2008-10-16 07:09:40 —-HDC—- C:\WINDOWS\$NtUninstallKB957095$
2008-10-16 07:05:26 —-HDC—- C:\WINDOWS\$NtUninstallKB954211$
2008-10-16 07:04:56 —-HDC—- C:\WINDOWS\$NtUninstallKB956841$
2008-10-15 17:48:42 —-HDC—- C:\WINDOWS\$NtUninstallKB956390$
2008-10-13 16:11:38 —-D—- C:\$WIN_NT$.~BT
2008-10-13 15:52:48 —-ASH—- C:\BOOT.BAK
2008-10-13 15:24:43 —-A—- C:\WINDOWS\UPGRADE.TXT
2008-10-13 13:18:31 —-A—- C:\WINDOWS\~DFF8A9.tmp
2008-10-12 21:26:14 —-A—- C:\WINDOWS\ntbtlog.txt
2008-10-12 20:52:18 —-D—- C:\Program Files\Enigma Software Group
2008-10-12 20:28:31 —-A—- C:\WINDOWS\IE4 Error Log.txt
2008-10-12 20:10:49 —-A—- C:\WINDOWS\system32\MSVCP71.dll
2008-10-12 20:10:49 —-A—- C:\WINDOWS\system32\MFC71.dll
2008-10-12 20:10:34 —-D—- C:\Program Files\Alwil Software
2008-10-12 17:56:27 —-D—- C:\kav
2008-10-12 16:48:40 —-D—- C:\Program Files\RegCure
2008-10-12 16:45:45 —-D—- C:\Program Files\Common Files\Download Manager
2008-10-12 14:22:51 —-D—- C:\Documents and Settings\All Users\Application Data\bivqvedw
2008-10-12 14:22:35 —-A—- C:\WINDOWS\system32\fkdfwyvhvywdcp.exe
2008-10-12 09:34:52 —-A—- C:\WINDOWS\system32\muweb.dll
2008-10-12 09:34:52 —-A—- C:\WINDOWS\system32\mucltui.dll.mui
2008-10-12 09:34:52 —-A—- C:\WINDOWS\system32\mucltui.dll
2008-10-11 16:59:40 —-D—- C:\Program Files\Microsoft SQL Server Compact Edition
2008-10-11 16:58:46 —-D—- C:\Program Files\Windows Live Toolbar
2008-10-11 16:58:42 —-D—- C:\Program Files\Windows Live Favorites
2008-10-11 16:56:27 —-DC—- C:\WINDOWS\system32\DRVSTORE
2008-10-11 16:45:22 —-SHDC—- C:\Program Files\Common Files\WindowsLiveInstaller
2008-10-11 16:44:37 —-D—- C:\Program Files\Windows Live
2008-10-11 16:44:27 —-D—- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-10-11 10:08:41 —-D—- C:\BattleScape
2008-10-11 10:04:19 —-D—- C:\WINDOWS\.silabclient_store_32
2008-10-10 16:54:03 —-A—- C:\WINDOWS\uninst.exe
2008-10-09 12:02:13 —-D—- C:\Documents and Settings\Owner\Application Data\Mathematica
2008-10-09 12:02:13 —-D—- C:\Documents and Settings\All Users\Application Data\Mathematica
2008-10-09 11:49:13 —-D—- C:\WINDOWS\Downloaded Installations
2008-10-08 16:23:02 —-D—- C:\WINDOWS\system32\LogFiles
2008-10-07 17:42:46 —-D—- C:\Program Files\DAEMON Tools
2008-10-07 14:45:18 —-D—- C:\Program Files\Common Files\INCA Shared
2008-10-07 14:25:08 —-A—- C:\WINDOWS\NeroDigital.ini
2008-10-05 17:16:06 —-D—- C:\Documents and Settings\All Users\Application Data\IJJIGame
2008-10-05 15:09:40 —-D—- C:\Documents and Settings\Owner\Application Data\WinRAR
2008-10-05 15:03:33 —-D—- C:\Program Files\MySQL
2008-10-05 14:51:04 —-A—- C:\WINDOWS\system32\libmysql_c.dll
2008-10-05 14:51:01 —-D—- C:\Program Files\PremiumSoft
2008-10-05 14:02:30 —-D—- C:\Documents and Settings\Owner\Application Data\TeamViewer
2008-10-05 14:02:25 —-D—- C:\Program Files\TeamViewer3
2008-10-05 08:36:42 —-HDC—- C:\WINDOWS\$NtUninstallKB941569$
2008-10-05 08:36:34 —-HDC—- C:\WINDOWS\$NtUninstallKB923689$
2008-10-05 08:36:20 —-HDC—- C:\WINDOWS\$NtUninstallKB936782_WMP10$
2008-10-04 18:49:13 —-D—- C:\Program Files\DNA
2008-10-04 18:49:13 —-D—- C:\Documents and Settings\Owner\Application Data\DNA
2008-10-04 17:41:07 —-D—- C:\WINDOWS\.jagex_cache_32
2008-10-04 17:40:52 —-D—- C:\WINDOWS\Sun
2008-10-04 17:36:53 —-D—- C:\Documents and Settings\All Users\Application Data\SwiftKit
2008-10-04 17:36:52 —-D—- C:\Program Files\SwiftKit
2008-10-04 17:33:11 —-D—- C:\Documents and Settings\Owner\Application Data\skypePM
2008-10-04 17:30:09 —-D—- C:\Documents and Settings\Owner\Application Data\Skype
2008-10-04 17:29:53 —-D—- C:\Program Files\Skype
2008-10-04 17:29:53 —-D—- C:\Program Files\Common Files\Skype
2008-10-04 17:29:45 —-D—- C:\Documents and Settings\All Users\Application Data\Skype
2008-10-04 17:27:17 —-D—- C:\Documents and Settings\Owner\Application Data\Macromedia
2008-10-03 23:46:58 —-A—- C:\WINDOWS\system32\h323log.txt
2008-10-03 23:45:11 —-A—- C:\WINDOWS\system32\nv4_disp.dll
2008-10-03 23:44:42 —-A—- C:\WINDOWS\system32\ksuser.dll
2008-10-03 23:44:13 —-A—- C:\WINDOWS\system32\usbui.dll
2008-10-03 23:42:59 —-A—- C:\WINDOWS\imsins.BAK
2008-10-03 23:42:57 —-SHD—- C:\WINDOWS\Installer
2008-10-03 23:42:57 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-03 23:42:56 —-D—- C:\Program Files\Common Files\ODBC
2008-10-03 23:42:56 —-A—- C:\WINDOWS\ODBCINST.INI
2008-10-03 23:42:53 —-D—- C:\Program Files\Common Files\SpeechEngines
2008-10-03 23:42:52 —-RD—- C:\Program Files
2008-10-03 23:42:52 —-D—- C:\Program Files\Common Files\Microsoft Shared
2008-10-03 23:42:52 —-D—- C:\Program Files\Common Files
2008-10-03 23:42:50 —-RA—- C:\WINDOWS\system32\kbdazel.dll
2008-10-03 23:42:49 —-RA—- C:\WINDOWS\system32\kbdtuq.dll
2008-10-03 23:42:49 —-RA—- C:\WINDOWS\system32\kbdtuf.dll
2008-10-03 23:42:48 —-RA—- C:\WINDOWS\system32\kbdycc.dll
2008-10-03 23:42:48 —-RA—- C:\WINDOWS\system32\kbduzb.dll
2008-10-03 23:42:48 —-RA—- C:\WINDOWS\system32\kbdur.dll
2008-10-03 23:42:48 —-RA—- C:\WINDOWS\system32\kbdtat.dll
2008-10-03 23:42:48 —-RA—- C:\WINDOWS\system32\kbdru1.dll
2008-10-03 23:42:48 —-RA—- C:\WINDOWS\system32\kbdru.dll
2008-10-03 23:42:48 —-RA—- C:\WINDOWS\system32\kbdmon.dll
2008-10-03 23:42:48 —-RA—- C:\WINDOWS\system32\kbdkyr.dll
2008-10-03 23:42:48 —-RA—- C:\WINDOWS\system32\kbdkaz.dll
2008-10-03 23:42:48 —-RA—- C:\WINDOWS\system32\kbdbu.dll
2008-10-03 23:42:48 —-RA—- C:\WINDOWS\system32\kbdblr.dll
2008-10-03 23:42:48 —-RA—- C:\WINDOWS\system32\kbdaze.dll
2008-10-03 23:42:47 —-RA—- C:\WINDOWS\system32\kbdhept.dll
2008-10-03 23:42:47 —-RA—- C:\WINDOWS\system32\kbdhela3.dll
2008-10-03 23:42:47 —-RA—- C:\WINDOWS\system32\kbdhela2.dll
2008-10-03 23:42:47 —-RA—- C:\WINDOWS\system32\kbdhe319.dll
2008-10-03 23:42:47 —-RA—- C:\WINDOWS\system32\kbdhe220.dll
2008-10-03 23:42:47 —-RA—- C:\WINDOWS\system32\kbdhe.dll
2008-10-03 23:42:47 —-RA—- C:\WINDOWS\system32\kbdgkl.dll
2008-10-03 23:42:46 —-RA—- C:\WINDOWS\system32\kbdlv1.dll
2008-10-03 23:42:46 —-RA—- C:\WINDOWS\system32\kbdlv.dll
2008-10-03 23:42:46 —-RA—- C:\WINDOWS\system32\kbdlt1.dll
2008-10-03 23:42:46 —-RA—- C:\WINDOWS\system32\kbdlt.dll
2008-10-03 23:42:46 —-RA—- C:\WINDOWS\system32\kbdest.dll
2008-10-03 23:42:45 —-RA—- C:\WINDOWS\system32\kbdsl1.dll
2008-10-03 23:42:45 —-RA—- C:\WINDOWS\system32\kbdsl.dll
2008-10-03 23:42:45 —-RA—- C:\WINDOWS\system32\kbdro.dll
2008-10-03 23:42:45 —-RA—- C:\WINDOWS\system32\kbdpl1.dll
2008-10-03 23:42:45 —-RA—- C:\WINDOWS\system32\kbdpl.dll
2008-10-03 23:42:45 —-RA—- C:\WINDOWS\system32\kbdhu1.dll
2008-10-03 23:42:45 —-RA—- C:\WINDOWS\system32\kbdhu.dll
2008-10-03 23:42:45 —-RA—- C:\WINDOWS\system32\kbdcz2.dll
2008-10-03 23:42:45 —-RA—- C:\WINDOWS\system32\kbdcz1.dll
2008-10-03 23:42:45 —-RA—- C:\WINDOWS\system32\kbdcz.dll
2008-10-03 23:42:45 —-RA—- C:\WINDOWS\system32\kbdcr.dll
2008-10-03 23:42:45 —-RA—- C:\WINDOWS\system32\KBDAL.DLL
2008-10-03 23:42:44 —-RA—- C:\WINDOWS\system32\kbdycl.dll
2008-10-03 23:42:43 —-A—- C:\WINDOWS\system32\irclass.dll
2008-10-03 23:42:42 —-A—- C:\WINDOWS\system32\spxcoins.dll
2008-10-03 23:42:42 —-A—- C:\WINDOWS\system32\EqnClass.Dll
2008-10-03 23:42:42 —-A—- C:\WINDOWS\system32\dgsetup.dll
2008-10-03 23:42:42 —-A—- C:\WINDOWS\system32\dgrpsetu.dll
2008-10-03 23:42:40 —-A—- C:\WINDOWS\TASKMAN.EXE
2008-10-03 23:42:39 —-N—- C:\WINDOWS\system32\CONFIG.TMP
2008-10-03 23:42:38 —-A—- C:\WINDOWS\system32\batt.dll
2008-10-03 23:42:36 —-A—- C:\WINDOWS\NOTEPAD.EXE
2008-10-03 23:42:35 —-A—- C:\WINDOWS\system32\storprop.dll
2008-10-03 23:42:28 —-RA—- C:\WINDOWS\SET25.tmp
2008-10-03 23:42:28 —-ASH—- C:\Documents and Settings\All Users\Application Data\desktop.ini
2008-10-03 23:42:24 —-RA—- C:\WINDOWS\SET8.tmp
2008-10-03 23:42:21 —-RA—- C:\WINDOWS\SET4.tmp
2008-10-03 23:42:20 —-RA—- C:\WINDOWS\SET3.tmp
2008-10-03 23:42:14 —-D—- C:\WINDOWS\system32\CatRoot2
2008-10-03 23:42:14 —-D—- C:\WINDOWS\system32\CatRoot
2008-10-03 23:42:08 —-SD—- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-10-03 23:41:43 —-A—- C:\WINDOWS\setuplog.txt
2008-10-03 23:41:39 —-D—- C:\Documents and Settings
2008-10-03 23:41:38 —-SHD—- C:\System Volume Information
2008-10-03 23:39:07 —-ASH—- C:\boot.ini
2008-10-03 23:39:00 —-D—- C:\drivers
2008-10-03 23:38:53 —-D—- C:\WINDOWS\OEMDIR
2008-10-03 23:38:53 —-D—- C:\apps
2008-10-03 23:34:09 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-10-03 23:34:09 —-RD—- C:\WINDOWS\Web
2008-10-03 23:34:09 —-D—- C:\WINDOWS\WinSxS
2008-10-03 23:34:09 —-D—- C:\WINDOWS\twain_32
2008-10-03 23:34:09 —-D—- C:\WINDOWS\Temp
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\wbem
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\usmt
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\ShellExt
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\Setup
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\oobe
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\npp
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\mui
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\inetsrv
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\IME
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\icsxml
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\ias
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\export
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\en
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\3com_dmi
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\3076
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\2052
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\1054
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\1042
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\1041
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\1037
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\1033
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\1031
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\1028
2008-10-03 23:34:09 —-D—- C:\WINDOWS\system32\1025
2008-10-03 23:34:09 —-D—- C:\WINDOWS\security
2008-10-03 23:34:09 —-D—- C:\WINDOWS\Resources
2008-10-03 23:34:09 —-D—- C:\WINDOWS\Provisioning
2008-10-03 23:34:09 —-D—- C:\WINDOWS\PeerNet
2008-10-03 23:34:09 —-D—- C:\WINDOWS\pchealth
2008-10-03 23:34:09 —-D—- C:\WINDOWS\Network Diagnostic
2008-10-03 23:34:09 —-D—- C:\WINDOWS\mui
2008-10-03 23:34:09 —-D—- C:\WINDOWS\msapps
2008-10-03 23:34:09 —-D—- C:\WINDOWS\Media
2008-10-03 23:34:09 —-D—- C:\WINDOWS\L2Schemas
2008-10-03 23:34:09 —-D—- C:\WINDOWS\java
2008-10-03 23:34:09 —-D—- C:\WINDOWS\ime
2008-10-03 23:34:09 —-D—- C:\WINDOWS\Driver Cache
2008-10-03 23:34:09 —-D—- C:\WINDOWS\Debug
2008-10-03 23:34:09 —-D—- C:\WINDOWS\Cursors
2008-10-03 23:34:09 —-D—- C:\WINDOWS\Connection Wizard
2008-10-03 23:34:09 —-D—- C:\WINDOWS\AppPatch
2008-10-03 23:34:09 —-D—- C:\WINDOWS\addins
2008-10-03 23:34:08 —-RSD—- C:\WINDOWS\Fonts
2008-10-03 23:34:08 —-HD—- C:\WINDOWS\inf
2008-10-03 23:34:08 —-D—- C:\WINDOWS\system32\wins
2008-10-03 23:34:08 —-D—- C:\WINDOWS\system32\spool
2008-10-03 23:34:08 —-D—- C:\WINDOWS\system32\ras
2008-10-03 23:34:08 —-D—- C:\WINDOWS\system32\drivers
2008-10-03 23:34:08 —-D—- C:\WINDOWS\system32\dhcp
2008-10-03 23:34:08 —-D—- C:\WINDOWS\system32\config
2008-10-03 23:34:08 —-D—- C:\WINDOWS\system32
2008-10-03 23:34:08 —-D—- C:\WINDOWS\system
2008-10-03 23:34:08 —-D—- C:\WINDOWS\repair
2008-10-03 23:34:08 —-D—- C:\WINDOWS\msagent
2008-10-03 23:34:08 —-D—- C:\WINDOWS\Help
2008-10-03 23:34:08 —-D—- C:\WINDOWS\Config
2008-10-03 23:34:08 —-D—- C:\WINDOWS
2008-10-03 22:21:51 —-D—- C:\Documents and Settings\All Users\Application Data\Avira
2008-10-03 21:50:47 —-HDC—- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-10-03 21:50:43 —-HDC—- C:\WINDOWS\$NtUninstallKB952954$
2008-10-03 21:50:40 —-HDC—- C:\WINDOWS\$NtUninstallKB946648$
2008-10-03 21:50:36 —-HDC—- C:\WINDOWS\$NtUninstallKB953839$
2008-10-03 21:50:31 —-HDC—- C:\WINDOWS\$NtUninstallKB951978$
2008-10-03 21:50:27 —-HDC—- C:\WINDOWS\$NtUninstallKB950974$
2008-10-03 21:50:23 —-HDC—- C:\WINDOWS\$NtUninstallKB951698$
2008-10-03 21:50:20 —-HDC—- C:\WINDOWS\$NtUninstallKB950762$
2008-10-03 21:50:16 —-HDC—- C:\WINDOWS\$NtUninstallKB951072-v2$
2008-10-03 21:50:13 —-HDC—- C:\WINDOWS\$NtUninstallKB952287$
2008-10-03 21:50:09 —-HDC—- C:\WINDOWS\$NtUninstallKB951066$
2008-10-03 21:50:01 —-HDC—- C:\WINDOWS\$NtUninstallKB953838$
2008-10-03 21:49:54 —-HDC—- C:\WINDOWS\$NtUninstallKB951748$
2008-10-03 21:49:50 —-HDC—- C:\WINDOWS\$NtUninstallKB938464$
2008-10-03 21:45:56 —-D—- C:\Documents and Settings\All Users\Application Data\GRETECH
2008-10-03 21:45:49 —-D—- C:\Documents and Settings\Owner\Application Data\GRETECH
2008-10-03 21:45:41 —-D—- C:\Program Files\GRETECH
2008-10-03 21:45:10 —-A—- C:\WINDOWS\winamp.ini
2008-10-03 21:45:06 —-D—- C:\Program Files\Winamp
2008-10-03 21:44:46 —-D—- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-10-03 21:44:43 —-D—- C:\Program Files\CyberLink
2008-10-03 21:41:51 —-D—- C:\WINDOWS\system32\PreInstall
2008-10-03 21:41:51 —-A—- C:\WINDOWS\ODBC.INI
2008-10-03 21:41:50 —-N—- C:\WINDOWS\system32\spmsg.dll
2008-10-03 21:41:50 —-A—- C:\WINDOWS\system32\spupdsvc.exe
2008-10-03 21:41:48 —-HDC—- C:\WINDOWS\$NtUninstallKB898461$
2008-10-03 21:41:47 —-HD—- C:\WINDOWS\$hf_mig$
2008-10-03 21:41:46 —-A—- C:\WINDOWS\system32\mdimon.dll
2008-10-03 21:40:47 —-D—- C:\Program Files\Common Files\DESIGNER
2008-10-03 21:40:43 —-D—- C:\Program Files\Microsoft Works
2008-10-03 21:40:35 —-D—- C:\Program Files\Microsoft Visual Studio
2008-10-03 21:40:30 —-D—- C:\WINDOWS\SHELLNEW
2008-10-03 21:40:28 —-D—- C:\Program Files\Microsoft.NET
2008-10-03 21:40:27 —-D—- C:\Program Files\Microsoft Office
2008-10-03 21:32:06 —-D—- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-10-03 21:28:58 —-D—- C:\Program Files\Realtek Sound Manager
2008-10-03 21:28:57 —-N—- C:\WINDOWS\avrack.ini
2008-10-03 21:28:57 —-D—- C:\Program Files\AvRack
2008-10-03 21:28:51 —-A—- C:\WINDOWS\system32\Audio3D.dll
2008-10-03 21:28:51 —-A—- C:\WINDOWS\system32\a3d.dll
2008-10-03 21:28:49 —-N—- C:\WINDOWS\system32\ChCfg.exe
2008-10-03 21:28:49 —-A—- C:\WINDOWS\system32\RTLCPAPI.dll
2008-10-03 21:28:49 —-A—- C:\WINDOWS\SOUNDMAN.EXE
2008-10-03 21:28:48 —-A—- C:\WINDOWS\system32\RTLCPL.EXE
2008-10-03 21:28:47 —-N—- C:\WINDOWS\alcupd.exe
2008-10-03 21:28:47 —-N—- C:\WINDOWS\alcrmv.exe
2008-10-03 21:28:47 —-HD—- C:\Program Files\InstallShield Installation Information
2008-10-03 21:26:14 —-A—- C:\WINDOWS\system32\wmpns.dll
2008-10-03 21:26:11 —-D—- C:\WINDOWS\system32\SoftwareDistribution
2008-10-03 21:26:01 —-A—- C:\WINDOWS\system32\nvunrm.exe
2008-10-03 21:26:00 —-A—- C:\WINDOWS\system32\nvusmb.exe
2008-10-03 21:25:58 —-A—- C:\WINDOWS\system32\nvugart.exe
2008-10-03 21:23:41 —-D—- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-10-03 21:21:30 —-D—- C:\WINDOWS\RegisteredPackages
2008-10-03 21:21:27 —-D—- C:\WINDOWS\nview
2008-10-03 21:21:27 —-A—- C:\WINDOWS\system32\nvudisp.exe
2008-10-03 21:21:07 —-D—- C:\WINDOWS\system32\ReinstallBackups
2008-10-03 21:20:46 —-N—- C:\WINDOWS\system32\TwnLib4.dll
2008-10-03 21:20:46 —-A—- C:\WINDOWS\system32\TwnLib20.dll
2008-10-03 21:20:45 —-N—- C:\WINDOWS\system32\ImagXRA7.dll
2008-10-03 21:20:45 —-N—- C:\WINDOWS\system32\ImagXR7.dll
2008-10-03 21:20:45 —-N—- C:\WINDOWS\system32\ImagXpr7.dll
2008-10-03 21:20:45 —-N—- C:\WINDOWS\system32\ImagX7.dll
2008-10-03 21:20:45 —-D—- C:\Program Files\Common Files\Ahead
2008-10-03 21:20:45 —-D—- C:\Program Files\Ahead
2008-10-03 21:20:45 —-A—- C:\WINDOWS\system32\NeroCheck.exe
2008-10-03 21:19:39 —-D—- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-10-03 21:19:35 —-D—- C:\Program Files\Mozilla Firefox
2008-10-03 21:19:28 —-A—- C:\WINDOWS\system32\NVUNINST.EXE
2008-10-03 21:19:19 —-D—- C:\Program Files\Common Files\InstallShield
2008-10-03 21:19:00 —-A—- C:\WINDOWS\system32\javaws.exe
2008-10-03 21:19:00 —-A—- C:\WINDOWS\system32\javaw.exe
2008-10-03 21:19:00 —-A—- C:\WINDOWS\system32\java.exe
2008-10-03 21:18:51 —-D—- C:\NVIDIA
2008-10-03 21:18:45 —-D—- C:\Program Files\Java
2008-10-03 21:18:45 —-D—- C:\Program Files\Common Files\Java
2008-10-03 21:13:22 —-D—- C:\Documents and Settings\Owner\Application Data\Sun
2008-10-03 21:13:09 —-RSD—- C:\WINDOWS\assembly
2008-10-03 21:12:57 —-A—- C:\WINDOWS\system32\xactengine2_8.dll
2008-10-03 21:12:57 —-A—- C:\WINDOWS\system32\x3daudio1_2.dll
2008-10-03 21:12:56 —-A—- C:\WINDOWS\system32\d3dx10_34.dll
2008-10-03 21:12:56 —-A—- C:\WINDOWS\system32\D3DCompiler_34.dll
2008-10-03 21:12:55 —-A—- C:\WINDOWS\system32\d3dx9_34.dll
2008-10-03 21:12:54 —-A—- C:\WINDOWS\system32\xinput1_3.dll
2008-10-03 21:12:53 —-A—- C:\WINDOWS\system32\xactengine2_7.dll
2008-10-03 21:12:46 —-A—- C:\WINDOWS\system32\d3dx10_33.dll
2008-10-03 21:12:46 —-A—- C:\WINDOWS\system32\D3DCompiler_33.dll
2008-10-03 21:12:40 —-A—- C:\WINDOWS\system32\d3dx9_33.dll
2008-10-03 21:12:39 —-A—- C:\WINDOWS\system32\xactengine2_6.dll
2008-10-03 21:12:39 —-A—- C:\WINDOWS\system32\xactengine2_5.dll
2008-10-03 21:12:38 —-D—- C:\WINDOWS\Microsoft.NET
2008-10-03 21:12:38 —-A—- C:\WINDOWS\system32\d3dx9_32.dll
2008-10-03 21:12:37 —-A—- C:\WINDOWS\system32\xactengine2_4.dll
2008-10-03 21:12:37 —-A—- C:\WINDOWS\system32\x3daudio1_1.dll
2008-10-03 21:12:37 —-A—- C:\WINDOWS\system32\d3dx9_31.dll
2008-10-03 21:12:36 —-A—- C:\WINDOWS\system32\xinput1_2.dll
2008-10-03 21:12:36 —-A—- C:\WINDOWS\system32\xactengine2_3.dll
2008-10-03 21:12:35 —-A—- C:\WINDOWS\system32\xinput1_1.dll
2008-10-03 21:12:35 —-A—- C:\WINDOWS\system32\xactengine2_2.dll
2008-10-03 21:12:34 —-A—- C:\WINDOWS\system32\xactengine2_1.dll
2008-10-03 21:12:33 —-A—- C:\WINDOWS\system32\d3dx9_30.dll
2008-10-03 21:12:32 —-A—- C:\WINDOWS\system32\xactengine2_0.dll
2008-10-03 21:12:32 —-A—- C:\WINDOWS\system32\x3daudio1_0.dll
2008-10-03 21:12:31 —-A—- C:\WINDOWS\system32\d3dx9_29.dll
2008-10-03 21:12:30 —-A—- C:\WINDOWS\system32\xinput9_1_0.dll
2008-10-03 21:12:30 —-A—- C:\WINDOWS\system32\d3dx9_28.dll
2008-10-03 21:12:29 —-A—- C:\WINDOWS\system32\d3dx9_27.dll
2008-10-03 21:12:29 —-A—- C:\WINDOWS\system32\d3dx9_26.dll
2008-10-03 21:12:29 —-A—- C:\WINDOWS\system32\d3dx9_25.dll
2008-10-03 21:12:28 —-A—- C:\WINDOWS\system32\d3dx9_24.dll
2008-10-03 21:11:35 —-D—- C:\Program Files\WinRAR
2008-10-03 21:10:49 —-D—- C:\Program Files\SereneScreen
2008-10-03 21:10:09 —-D—- C:\Documents and Settings\Owner\Application Data\Adobe
2008-10-03 21:10:06 —-D—- C:\Program Files\DivX Total Pack
2008-10-03 21:09:34 —-D—- C:\Program Files\Fotonija
2008-10-03 21:08:58 —-D—- C:\Documents and Settings\All Users\Application Data\Adobe
2008-10-03 21:08:54 —-D—- C:\Program Files\Common Files\Adobe
2008-10-03 21:08:54 —-D—- C:\Program Files\Adobe
2008-10-03 21:08:00 —-A—- C:\WINDOWS\system32\nvconrm.dll
2008-10-03 21:08:00 —-A—- C:\WINDOWS\system32\NVCOG.DLL
2008-10-03 21:07:57 —-A—- C:\WINDOWS\system32\fdco1.dll
2008-10-03 21:07:57 —-A—- C:\WINDOWS\system32\bdco1.dll
2008-10-03 20:58:10 —-SHD—- C:\RECYCLER
2008-10-03 20:57:03 —-D—- C:\Documents and Settings\Owner\Application Data\Identities
2008-10-03 20:57:02 —-HD—- C:\Program Files\Uninstall Information
2008-10-03 20:56:57 —-ASH—- C:\Documents and Settings\Owner\Application Data\desktop.ini
2008-10-03 20:56:56 —-SD—- C:\Documents and Settings\Owner\Application Data\Microsoft
2008-10-03 20:56:31 —-D—- C:\WINDOWS\SoftwareDistribution
2008-10-03 20:56:29 —-SD—- C:\WINDOWS\system32\Microsoft
2008-10-03 20:56:29 —-D—- C:\WINDOWS\Prefetch
2008-10-03 20:56:29 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-10-03 20:52:39 —-D—- C:\WINDOWS\system32\xircom
2008-10-03 20:52:39 —-D—- C:\Program Files\xerox
2008-10-03 20:52:39 —-D—- C:\Program Files\microsoft frontpage
2008-10-03 20:52:16 —-A—- C:\WINDOWS\control.ini
2008-10-03 20:52:16 —-A—- C:\AUTOEXEC.BAT
2008-10-03 20:51:59 —-A—- C:\WINDOWS\OEWABLog.txt
2008-10-03 20:51:55 —-A—- C:\WINDOWS\system32\mapi32.dll
2008-10-03 20:51:01 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-10-03 20:51:01 —-RD—- C:\WINDOWS\Offline Web Pages
2008-10-03 20:51:01 —-RAH—- C:\WINDOWS\system32\logonui.exe.manifest
2008-10-03 20:50:54 —-RAH—- C:\WINDOWS\system32\cdplayer.exe.manifest
2008-10-03 20:50:49 —-HD—- C:\Program Files\WindowsUpdate
2008-10-03 20:50:31 —-D—- C:\WINDOWS\system32\DirectX
2008-10-03 20:50:27 —-A—- C:\WINDOWS\system32\atrace.dll
2008-10-03 20:50:25 —-A—- C:\WINDOWS\system32\desktop.ini
2008-10-03 20:50:25 —-A—- C:\WINDOWS\desktop.ini
2008-10-03 20:50:20 —-A—- C:\WINDOWS\system32\nmevtmsg.dll
2008-10-03 20:50:19 —-D—- C:\Program Files\Common Files\Services
2008-10-03 20:50:19 —-A—- C:\WINDOWS\system32\acctres.dll
2008-10-03 20:50:17 —-SD—- C:\WINDOWS\Tasks
2008-10-03 20:50:17 —-A—- C:\WINDOWS\system32\icfgnt5.dll
2008-10-03 20:50:16 —-D—- C:\Program Files\Common Files\MSSoap
2008-10-03 20:50:14 —-D—- C:\WINDOWS\srchasst
2008-10-03 20:50:13 —-D—- C:\WINDOWS\system32\Macromed
2008-10-03 20:50:11 —-A—- C:\WINDOWS\system32\wuweb.dll
2008-10-03 20:50:11 —-A—- C:\WINDOWS\system32\wups.dll
2008-10-03 20:50:11 —-A—- C:\WINDOWS\system32\wucltui.dll
2008-10-03 20:50:11 —-A—- C:\WINDOWS\system32\wuauserv.dll
2008-10-03 20:50:11 —-A—- C:\WINDOWS\system32\wuaueng1.dll
2008-10-03 20:50:11 —-A—- C:\WINDOWS\system32\wuaueng.dll
2008-10-03 20:50:11 —-A—- C:\WINDOWS\system32\wuauclt1.exe
2008-10-03 20:50:11 —-A—- C:\WINDOWS\system32\wuauclt.exe
2008-10-03 20:50:11 —-A—- C:\WINDOWS\system32\wuapi.dll
2008-10-03 20:50:10 —-A—- C:\WINDOWS\system32\qmgrprxy.dll
2008-10-03 20:50:10 —-A—- C:\WINDOWS\system32\qmgr.dll
2008-10-03 20:50:10 —-A—- C:\WINDOWS\system32\bitsprx4.dll
2008-10-03 20:50:10 —-A—- C:\WINDOWS\system32\bitsprx3.dll
2008-10-03 20:50:10 —-A—- C:\WINDOWS\system32\bitsprx2.dll
2008-10-03 20:50:07 —-D—- C:\Program Files\Movie Maker
2008-10-03 20:49:55 —-A—- C:\WINDOWS\system32\safrslv.dll
2008-10-03 20:49:55 —-A—- C:\WINDOWS\system32\safrdm.dll
2008-10-03 20:49:55 —-A—- C:\WINDOWS\system32\safrcdlg.dll
2008-10-03 20:49:55 —-A—- C:\WINDOWS\system32\racpldlg.dll
2008-10-03 20:49:53 —-A—- C:\WINDOWS\system32\fltMc.exe
2008-10-03 20:49:53 —-A—- C:\WINDOWS\system32\fltlib.dll
2008-10-03 20:49:52 —-D—- C:\WINDOWS\system32\Restore
2008-10-03 20:49:52 —-A—- C:\WINDOWS\system32\srsvc.dll
2008-10-03 20:49:52 —-A—- C:\WINDOWS\system32\srrstr.dll
2008-10-03 20:49:52 —-A—- C:\WINDOWS\system32\srclient.dll
2008-10-03 20:49:52 —-A—- C:\WINDOWS\system32\mnmdd.dll
2008-10-03 20:49:52 —-A—- C:\WINDOWS\system32\isrdbg32.dll
2008-10-03 20:49:52 —-A—- C:\WINDOWS\system32\ils.dll
2008-10-03 20:49:51 —-A—- C:\WINDOWS\system32\nmmkcert.dll
2008-10-03 20:49:51 —-A—- C:\WINDOWS\system32\msconf.dll
2008-10-03 20:49:51 —-A—- C:\WINDOWS\system32\mnmsrvc.exe
2008-10-03 20:49:49 —-D—- C:\Program Files\NetMeeting
2008-10-03 20:49:49 —-A—- C:\WINDOWS\system32\msoert2.dll
2008-10-03 20:49:49 —-A—- C:\WINDOWS\system32\msoeacct.dll
2008-10-03 20:49:49 —-A—- C:\WINDOWS\system32\inetres.dll
2008-10-03 20:49:49 —-A—- C:\WINDOWS\system32\inetcomm.dll
2008-10-03 20:49:47 —-D—- C:\Program Files\Outlook Express
2008-10-03 20:49:47 —-A—- C:\WINDOWS\system32\schedsvc.dll
2008-10-03 20:49:47 —-A—- C:\WINDOWS\system32\mstinit.exe
2008-10-03 20:49:47 —-A—- C:\WINDOWS\system32\mstask.dll
2008-10-03 20:49:47 —-A—- C:\WINDOWS\system32\isign32.dll
2008-10-03 20:49:47 —-A—- C:\WINDOWS\system32\inetcfg.dll
2008-10-03 20:49:47 —-A—- C:\WINDOWS\system32\icwphbk.dll
2008-10-03 20:49:47 —-A—- C:\WINDOWS\system32\icwdial.dll
2008-10-03 20:49:42 —-D—- C:\Program Files\Common Files\System
2008-10-03 20:49:40 —-D—- C:\Program Files\Internet Explorer
2008-10-03 20:49:24 —-D—- C:\Program Files\ComPlus Applications
2008-10-03 20:49:22 —-A—- C:\WINDOWS\vbaddin.ini
2008-10-03 20:49:22 —-A—- C:\WINDOWS\vb.ini
2008-10-03 20:49:17 —-D—- C:\WINDOWS\Registration
2008-10-03 20:48:47 —-D—- C:\Program Files\Windows Media Player
2008-10-03 20:48:47 —-D—- C:\Program Files\Online Services
2008-10-03 20:48:41 —-D—- C:\Program Files\Messenger
2008-10-03 20:48:38 —-D—- C:\Program Files\MSN Gaming Zone
2008-10-03 20:48:38 —-A—- C:\WINDOWS\system32\write.exe
2008-10-03 20:48:32 —-A—- C:\WINDOWS\system32\sndvol32.exe
2008-10-03 20:48:32 —-A—- C:\WINDOWS\system32\hticons.dll
2008-10-03 20:48:31 —-A—- C:\WINDOWS\system32\winchat.exe
2008-10-03 20:48:31 —-A—- C:\WINDOWS\system32\avwav.dll
2008-10-03 20:48:31 —-A—- C:\WINDOWS\system32\avtapi.dll
2008-10-03 20:48:31 —-A—- C:\WINDOWS\system32\avmeter.dll
2008-10-03 20:48:27 —-A—- C:\WINDOWS\system32\getuname.dll
2008-10-03 20:48:26 —-A—- C:\WINDOWS\system32\winmine.exe
2008-10-03 20:48:26 —-A—- C:\WINDOWS\system32\sol.exe
2008-10-03 20:48:26 —-A—- C:\WINDOWS\system32\mshearts.exe
2008-10-03 20:48:26 —-A—- C:\WINDOWS\system32\charmap.exe
2008-10-03 20:48:26 —-A—- C:\WINDOWS\system32\calc.exe
2008-10-03 20:48:25 —-A—- C:\WINDOWS\system32\usrlogon.cmd
2008-10-03 20:48:25 —-A—- C:\WINDOWS\system32\tsshutdn.exe
2008-10-03 20:48:25 —-A—- C:\WINDOWS\system32\tslabels.ini
2008-10-03 20:48:25 —-A—- C:\WINDOWS\system32\tskill.exe
2008-10-03 20:48:25 —-A—- C:\WINDOWS\system32\tsdiscon.exe
2008-10-03 20:48:25 —-A—- C:\WINDOWS\system32\tscon.exe
2008-10-03 20:48:25 —-A—- C:\WINDOWS\system32\shadow.exe
2008-10-03 20:48:25 —-A—- C:\WINDOWS\system32\rwinsta.exe
2008-10-03 20:48:25 —-A—- C:\WINDOWS\system32\reset.exe
2008-10-03 20:48:25 —-A—- C:\WINDOWS\system32\regini.exe
2008-10-03 20:48:25 —-A—- C:\WINDOWS\system32\rdpcfgex.dll
2008-10-03 20:48:25 —-A—- C:\WINDOWS\system32\qwinsta.exe
2008-10-03 20:48:25 —-A—- C:\WINDOWS\system32\qappsrv.exe
2008-10-03 20:48:25 —-A—- C:\WINDOWS\system32\msg.exe
2008-10-03 20:48:25 —-A—- C:\WINDOWS\system32\logoff.exe
2008-10-03 20:48:25 —-A—- C:\WINDOWS\system32\freecell.exe
2008-10-03 20:48:25 —-A—- C:\WINDOWS\system32\cdmodem.dll
2008-10-03 20:48:24 —-A—- C:\WINDOWS\system32\msdtcprf.ini
2008-10-03 20:48:21 —-A—- C:\WINDOWS\system32\wmimgmt.msc
2008-10-03 20:48:14 —-D—- C:\Program Files\MSN
2008-10-03 20:48:13 —-D—- C:\Program Files\Windows NT
2008-10-03 20:48:13 —-A—- C:\WINDOWS\system32\sndrec32.exe
2008-10-03 20:48:13 —-A—- C:\WINDOWS\system32\mplay32.exe
2008-10-03 20:48:13 —-A—- C:\WINDOWS\system32\hypertrm.dll
2008-10-03 20:48:13 —-A—- C:\WINDOWS\system32\accwiz.exe
2008-10-03 20:48:12 —-D—- C:\WINDOWS\system32\en-US
2008-10-03 20:48:12 —-A—- C:\WINDOWS\system32\spider.exe
2008-10-03 20:48:12 —-A—- C:\WINDOWS\system32\mspaint.exe
2008-10-03 20:48:12 —-A—- C:\WINDOWS\system32\clipbrd.exe
2008-10-03 20:48:11 —-A—- C:\WINDOWS\system32\tsgqec.dll
2008-10-03 20:48:11 —-A—- C:\WINDOWS\system32\tscfgwmi.dll
2008-10-03 20:48:11 —-A—- C:\WINDOWS\system32\rhttpaa.dll
2008-10-03 20:48:11 —-A—- C:\WINDOWS\system32\mstscax.dll
2008-10-03 20:48:11 —-A—- C:\WINDOWS\system32\aaclient.dll
2008-10-03 20:48:10 —-A—- C:\WINDOWS\system32\termsrv.dll
2008-10-03 20:48:10 —-A—- C:\WINDOWS\system32\sessmgr.exe
2008-10-03 20:48:10 —-A—- C:\WINDOWS\system32\remotepg.dll
2008-10-03 20:48:10 —-A—- C:\WINDOWS\system32\rdshost.exe
2008-10-03 20:48:10 —-A—- C:\WINDOWS\system32\rdsaddin.exe
2008-10-03 20:48:10 —-A—- C:\WINDOWS\system32\rdpwsx.dll
2008-10-03 20:48:10 —-A—- C:\WINDOWS\system32\rdpsnd.dll
2008-10-03 20:48:10 —-A—- C:\WINDOWS\system32\rdpclip.exe
2008-10-03 20:48:10 —-A—- C:\WINDOWS\system32\rdchost.dll
2008-10-03 20:48:10 —-A—- C:\WINDOWS\system32\qprocess.exe
2008-10-03 20:48:10 —-A—- C:\WINDOWS\system32\mstsc.exe
2008-10-03 20:48:10 —-A—- C:\WINDOWS\system32\icaapi.dll
2008-10-03 20:48:10 —-A—- C:\WINDOWS\system32\cfgbkend.dll
2008-10-03 20:48:09 —-D—- C:\WINDOWS\system32\MsDtc
2008-10-03 20:48:09 —-A—- C:\WINDOWS\system32\xolehlp.dll
2008-10-03 20:48:09 —-A—- C:\WINDOWS\system32\mtxoci.dll
2008-10-03 20:48:09 —-A—- C:\WINDOWS\system32\msdtcuiu.dll
2008-10-03 20:48:09 —-A—- C:\WINDOWS\system32\msdtctm.dll
2008-10-03 20:48:09 —-A—- C:\WINDOWS\system32\msdtcprx.dll
2008-10-03 20:48:09 —-A—- C:\WINDOWS\system32\msdtclog.dll
2008-10-03 20:48:09 —-A—- C:\WINDOWS\system32\msdtc.exe
2008-10-03 20:48:08 —-D—- C:\WINDOWS\system32\Com
2008-10-03 20:48:08 —-A—- C:\WINDOWS\system32\mtxlegih.dll
2008-10-03 20:48:08 —-A—- C:\WINDOWS\system32\mtxex.dll
2008-10-03 20:48:08 —-A—- C:\WINDOWS\system32\mtxdm.dll
2008-10-03 20:48:08 —-A—- C:\WINDOWS\system32\dcomcnfg.exe
2008-10-03 20:48:08 —-A—- C:\WINDOWS\system32\comrepl.dll
2008-10-03 20:48:08 —-A—- C:\WINDOWS\system32\comaddin.dll
2008-10-03 20:48:08 —-A—- C:\WINDOWS\system32\colbact.dll
2008-10-03 20:48:07 —-A—- C:\WINDOWS\system32\stclient.dll
2008-10-03 20:48:07 —-A—- C:\WINDOWS\system32\comsvcs.dll
2008-10-03 20:48:07 —-A—- C:\WINDOWS\system32\clbcatex.dll
2008-10-03 20:48:07 —-A—- C:\WINDOWS\system32\catsrvut.dll
2008-10-03 20:48:07 —-A—- C:\WINDOWS\system32\catsrvps.dll
2008-10-03 20:48:07 —-A—- C:\WINDOWS\system32\catsrv.dll
2008-10-03 20:48:06 —-A—- C:\WINDOWS\system32\comuid.dll
2008-10-03 20:48:06 —-A—- C:\WINDOWS\system32\comsnap.dll
2008-10-03 20:48:06 —-A—- C:\WINDOWS\system32\clbcatq.dll
2008-10-03 20:47:59 —-A—- C:\WINDOWS\system32\servdeps.dll
2008-10-03 20:47:59 —-A—- C:\WINDOWS\system32\mmfutil.dll
2008-10-03 20:47:59 —-A—- C:\WINDOWS\system32\licwmi.dll
2008-10-03 20:47:59 —-A—- C:\WINDOWS\system32\cmprops.dll

======List of files/folders modified in the last 1 months======

2008-10-15 18:34:24 —-A—- C:\WINDOWS\system32\netapi32.dll
2008-10-03 21:46:27 —-A—- C:\WINDOWS\system.ini
2008-10-03 20:52:15 —-A—- C:\WINDOWS\win.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-10-26 97928]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2008-10-26 26824]
R1 AvgTdiX;AVG8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-10-26 90632]
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr.sys [2007-10-17 43816]
R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2004-02-24 400384]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-07-01 626977]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-10-22 3994624]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2004-05-17 33280]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2004-05-17 12928]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-14 17152]
S3 api8chay;api8chay; C:\WINDOWS\system32\drivers\api8chay.sys []
S3 ddsxeiservice;ddsxeiservice2; \??\C:\Program Files\sXe Injected\ddsxei.sys []
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 npkcrypt;npkcrypt; \??\D:\Interlude\system\npkcrypt.sys []
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avg8wd;AVG8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-10-26 231704]
R2 fsssvc;Windows Live OneCare Family Safety; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2007-12-17 523816]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-10-22 159810]
R3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S2 avg8emc;AVG8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-10-26 874776]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-09-22 38912]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S4 MySQL;MySQL; C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt –defaults-file=C:\Program Files\MySQL\MySQL Server 5.0\my.ini MySQL []

—————–EOF—————–
nasdad,

You have more P2P programs installed. I reccomend you get rid of them. Bittorrent, zmule.

You have several registry cleaner programs:
RegCure 1.5.0.1
Registry Clean Expert
Wise Registry Cleaner 3
I don't recommend that you use these types of programs. I believe that they will eventually cause you problems. It is your computer and your choice.

  • Click Start, then Settings, then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, Remove Hijackthis 1.99.1
  • Do the same for RON Tool Offersfortoday.

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\csdos.exe
    C:\WINDOWS\system32\fkdfwyvhvywdcp.exe
    
    :Folders
    C:\csdos
    C:\Documents and Settings\All Users\Application Data\bivqvedw
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Okay removed bittorrent,zmule and cleaner programs.. OTMoveIt3 by OldTimer. log ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\csdos.exe moved successfully. C:\WINDOWS\system32\fkdfwyvhvywdcp.exe moved successfully. Error: Unable to interpret <:Folders> in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_IoyE1Elwo0d3IjXSwrHM scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\Perflib_Perfdata_ad0.dat scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DF5C66.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFEEC3.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFEEE1.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFFE71.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFFECA.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.5.0 log created on 10302008_011001 Files moved on Reboot… File C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_IoyE1Elwo0d3IjXSwrHM not found! File C:\DOCUME~1\Owner\LOCALS~1\Temp\Perflib_Perfdata_ad0.dat not found! C:\DOCUME~1\Owner\LOCALS~1\Temp\~DF5C66.tmp moved successfully. File C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFEEC3.tmp not found! File C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFEEE1.tmp not found! File C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFFE71.tmp not found! File C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFFECA.tmp not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\XUL.mfl moved successfully.
nasdad,

Oops, I messed up the script a little. We have to try again.

  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\csdos
    C:\Documents and Settings\All Users\Application Data\bivqvedw
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Then

I need you to run the following scan: Eset Online Scanner

  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.

Please also give me a new HijackThis log and let me know how it is running?
========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\csdos\csdos moved successfully. C:\csdos moved successfully. C:\Documents and Settings\All Users\Application Data\bivqvedw moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_x90rRt193JGJctVxyD3U scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DF220D.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DF22D8.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DF7D16.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFB0E.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFB28.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\urlclassifier3.sqlite scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.5.0 log created on 10302008_170658 Files moved on Reboot… File C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_x90rRt193JGJctVxyD3U not found! File C:\DOCUME~1\Owner\LOCALS~1\Temp\~DF220D.tmp not found! File C:\DOCUME~1\Owner\LOCALS~1\Temp\~DF22D8.tmp not found! C:\DOCUME~1\Owner\LOCALS~1\Temp\~DF7D16.tmp moved successfully. File C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFB0E.tmp not found! File C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFB28.tmp not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\gynnvez1.default\urlclassifier3.sqlite moved successfully. Cant scan with free eset Your browser is not supported. ESET Online Scanner is based on ActiveX technology and requires Microsoft Internet Explorer with enabled ActiveX controls. User has to agree to install ActiveX package signed by ESET. For more details check System Requirements. I tried with inter exploer its say need to activate actived i activated and my inter exploer closing…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI