This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Help :-(

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A pop up in the bottom right corner sayin your compuer is infected
download this antispyware
havent clicked it tho
its very anoying..

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:19:16 PM, on 11/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\D-Tools\daemon.exe
S:\VMware\hqtray.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\brastk.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\Msmsgs.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\samuel\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Program Files\Analog Devices\Core\smax4pnp.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [VMware hqtray] "S:\VMware\hqtray.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [brastk] C:\WINDOWS\system32\brastk.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [brastk] C:\WINDOWS\system32\brastk.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: wbsys.dll,avgrsstx.dll
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 5578 bytes
Hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.



Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
Thank you very much for the help

SDFix: Version 1.240
Run by [removed] on Fri 11/07/2008 at 10:10 AM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\Documents and Settings\samuel\Local Settings\Temp\utt74.tmp.exe - Deleted
C:\Documents and Settings\samuel\Local Settings\Temp\utt8A.tmp.exe - Deleted
C:\Documents and Settings\samuel\My Documents\My Documents.url - Deleted
C:\Documents and Settings\samuel\My Documents\My Music\My Music.url - Deleted
C:\Documents and Settings\samuel\My Documents\My Videos\My Video.url - Deleted
C:\DOCUME~1\samuel\LOCALS~1\Temp\dssc32.exe.bat - Deleted
C:\DOCUME~1\samuel\LOCALS~1\Temp\wrdwn3 - Deleted
C:\WINDOWS\system32\wini10881.exe - Deleted
C:\DOCUME~1\samuel\LOCALS~1\Temp\s1265.php.bat - Deleted
C:\WINDOWS\system32\bb1.dat - Deleted
C:\WINDOWS\system32\brastk.exe - Deleted
C:\WINDOWS\system32\cookie1.dat - Deleted
C:\WINDOWS\system32\dpl.txt - Deleted
C:\WINDOWS\system32\rtc.dat - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-07 10:15:40
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\\New Game Files\\Counter-Strike 1.6\\hl.exe"="D:\\New Game Files\\Counter-Strike 1.6\\hl.exe:*:Enabled:Half-Life Launcher"
"S:\\Game Files\\Dawn of\\DarkCrusade.exe"="S:\\Game Files\\Dawn of\\DarkCrusade.exe:*:Enabled:DarkCrusade"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"S:\\Game Files\\Counter-Strike 1.6\\hl.exe"="S:\\Game Files\\Counter-Strike 1.6\\hl.exe:*:Enabled:Half-Life Launcher"
"S:\\Game Files\\Counter-Strike Source\\hl2.exe"="S:\\Game Files\\Counter-Strike Source\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"S:\\Game Files\\Dawn of War\\DarkCrusade.exe"="S:\\Game Files\\Dawn of War\\DarkCrusade.exe:*:Enabled:DarkCrusade"
"D:\\New Game Files\\WoW server\\DB\\bin\\mysqld-nt.exe"="D:\\New Game Files\\WoW server\\DB\\bin\\mysqld-nt.exe:*:Enabled:mysqld-nt"
"D:\\New Game Files\\WoW server\\realmd.exe"="D:\\New Game Files\\WoW server\\realmd.exe:*:Enabled:realmd"
"C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:DNA"
"S:\\Game Files\\BitTorrent\\bittorrent.exe"="S:\\Game Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"S:\\Game Files\\World of Warcraft\\WoW-2.3.3.7799-to-2.4.0.8089-enUS-downloader.exe"="S:\\Game Files\\World of Warcraft\\WoW-2.3.3.7799-to-2.4.0.8089-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"S:\\Game Files\\iTunes\\iTunes.exe"="S:\\Game Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"S:\\LineWire\\LimeWire\\LimeWire.exe"="S:\\LineWire\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"D:\\New Game Files\\AO2\\age2_x1.exe"="D:\\New Game Files\\AO2\\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"S:\\Game Files\\AO2\\age2_x1.exe"="S:\\Game Files\\AO2\\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"S:\\Game Files\\COD4\\iw3mp.exe"="S:\\Game Files\\COD4\\iw3mp.exe:*:Enabled:iw3mp"
"S:\\Game Files\\Warcraft III\\Warcraft III.exe"="S:\\Game Files\\Warcraft III\\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"="C:\\Program Files\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Documents and Settings\\samuel\\Local Settings\\Temp\\Rar$EX00.704\\WLM Lite 8.5.exe"="C:\\Documents and Settings\\samuel\\Local Settings\\Temp\\Rar$EX00.704\\WLM Lite 8.5.exe:*:Enabled:Windows Live Messenger Lite"
"D:\\Installers&abit; more\\Computer\\WLM Lite 8.5.exe"="D:\\Installers&abit; more\\Computer\\WLM Lite 8.5.exe:*:Enabled:Windows Live Messenger Lite"
"C:\\Documents and Settings\\samuel\\Desktop\\20080826EudemonsV1130_BC.exe"="C:\\Documents and Settings\\samuel\\Desktop\\20080826EudemonsV1130_BC.exe:*:Enabled:BitCometLite"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Wed 4 Jun 2008 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 22 Feb 2008 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Thu 8 May 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\fd0264849c01086f3c6b505dc02dbd44\BIT6.tmp"
Thu 25 Sep 2008 1,301 …HR — "C:\Documents and Settings\samuel\Application Data\SecuROM\UserData\securom_v7_01.bak"

Finished!





——————–\\ Lop S&D; 4.2.4-9c XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : AMD Athlon™ 64 X2 Dual Core Processor 4200+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : samuel ( Administrator )
BOOT : Normal boot
Antivirus : AVG Anti-Virus Free 8.0 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:48 Go (Free:18 Go)
D:\ (Local Disk) - NTFS - Total:186 Go (Free:72 Go)
E:\ (CD or DVD)
F:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
G:\ (CD or DVD) - UDF - Total:4 Go (Free:0 Go)
H:\ (CD or DVD)
J:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
S:\ (Local Disk) - NTFS - Total:416 Go (Free:47 Go)

"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [1] ( Fri 11/07/2008|10:24 )

——————–\\ Listing folders in APPLIC~1

[06/16/2008|03:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[02/05/2008|09:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe Systems
[05/02/2008|08:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Ahead
[05/15/2008|03:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[10/18/2008|05:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ avg8
[06/05/2008|08:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ DVD Shrink
[08/31/2008|10:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ LogiShrd
[08/31/2008|10:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Logitech
[03/31/2008|06:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ MailFrontier
[05/09/2008|03:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[08/11/2008|04:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[09/23/2008|11:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ NexonUS
[07/26/2008|03:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ nView_Profiles
[07/30/2008|09:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SUPERAntiSpyware.com
[10/18/2008|05:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[11/06/2008|08:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ VMware
[09/24/2008|11:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Webroot
[02/07/2008|07:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[03/01/2008|11:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ WLInstaller
[05/30/2008|07:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo!
[10/18/2008|05:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo! Companion

[03/26/2008|11:17] C:\DOCUME~1\Dad\APPLIC~1\ Identities
[03/26/2008|11:18] C:\DOCUME~1\Dad\APPLIC~1\ MEGAUPLOADTOOLBAR
[10/18/2008|05:35] C:\DOCUME~1\Dad\APPLIC~1\ Microsoft

[03/26/2008|11:24] C:\DOCUME~1\Dad.SAM\APPLIC~1\ Identities
[03/26/2008|11:27] C:\DOCUME~1\Dad.SAM\APPLIC~1\ MEGAUPLOADTOOLBAR
[10/18/2008|05:35] C:\DOCUME~1\Dad.SAM\APPLIC~1\ Microsoft
[03/26/2008|11:28] C:\DOCUME~1\Dad.SAM\APPLIC~1\ Mozilla
[03/26/2008|11:29] C:\DOCUME~1\Dad.SAM\APPLIC~1\ Yahoo!

[02/04/2008|09:03] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft

[10/18/2008|05:35] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft
[11/06/2008|08:20] C:\DOCUME~1\LOCALS~1\APPLIC~1\ VMware
[09/24/2008|11:13] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Webroot

[10/18/2008|05:35] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft

[06/16/2008|03:58] C:\DOCUME~1\samuel\APPLIC~1\ Adobe
[08/16/2008|03:19] C:\DOCUME~1\samuel\APPLIC~1\ AdobeUM
[10/22/2008|09:49] C:\DOCUME~1\samuel\APPLIC~1\ Ahead
[06/04/2008|01:53] C:\DOCUME~1\samuel\APPLIC~1\ Apple Computer
[06/17/2008|11:38] C:\DOCUME~1\samuel\APPLIC~1\ Armagetron
[11/06/2008|05:20] C:\DOCUME~1\samuel\APPLIC~1\ BitTorrent
[02/16/2008|09:46] C:\DOCUME~1\samuel\APPLIC~1\ Command & Conquer 3 Tiberium Wars
[11/07/2008|10:05] C:\DOCUME~1\samuel\APPLIC~1\ DNA
[08/02/2008|06:58] C:\DOCUME~1\samuel\APPLIC~1\ Help
[02/04/2008|09:09] C:\DOCUME~1\samuel\APPLIC~1\ Identities
[08/31/2008|10:33] C:\DOCUME~1\samuel\APPLIC~1\ InstallShield
[06/05/2008|09:43] C:\DOCUME~1\samuel\APPLIC~1\ LimeWire
[08/31/2008|10:36] C:\DOCUME~1\samuel\APPLIC~1\ Logitech
[02/05/2008|04:29] C:\DOCUME~1\samuel\APPLIC~1\ Macromedia
[02/04/2008|12:40] C:\DOCUME~1\samuel\APPLIC~1\ Media Player Classic
[03/10/2008|12:40] C:\DOCUME~1\samuel\APPLIC~1\ MegauploadToolbar
[10/18/2008|05:35] C:\DOCUME~1\samuel\APPLIC~1\ Microsoft
[07/09/2008|02:58] C:\DOCUME~1\samuel\APPLIC~1\ Mozilla
[08/29/2008|09:17] C:\DOCUME~1\samuel\APPLIC~1\ Real
[02/16/2008|09:42] C:\DOCUME~1\samuel\APPLIC~1\ SecuROM
[10/18/2008|05:15] C:\DOCUME~1\samuel\APPLIC~1\ SPORE
[02/12/2008|05:56] C:\DOCUME~1\samuel\APPLIC~1\ Sun
[10/22/2008|10:51] C:\DOCUME~1\samuel\APPLIC~1\ SUPERAntiSpyware.com
[11/04/2008|11:05] C:\DOCUME~1\samuel\APPLIC~1\ TeamViewer
[02/20/2008|06:55] C:\DOCUME~1\samuel\APPLIC~1\ Ventrilo
[02/04/2008|02:27] C:\DOCUME~1\samuel\APPLIC~1\ vlc
[11/02/2008|04:16] C:\DOCUME~1\samuel\APPLIC~1\ VMware
[10/22/2008|09:49] C:\DOCUME~1\samuel\APPLIC~1\ Vso
[09/24/2008|11:13] C:\DOCUME~1\samuel\APPLIC~1\ Webroot
[05/30/2008|07:29] C:\DOCUME~1\samuel\APPLIC~1\ Yahoo!

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[11/07/2008 10:20 AM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[08/24/2001 01:00 AM][-r-h—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[06/16/2008|03:56] C:\Program Files\ Adobe
[06/05/2008|08:35] C:\Program Files\ Ahead
[10/31/2008|09:05] C:\Program Files\ AMT
[02/04/2008|11:52] C:\Program Files\ Analog Devices
[10/18/2008|05:36] C:\Program Files\ AVG
[08/31/2008|10:35] C:\Program Files\ Common Files
[02/04/2008|09:00] C:\Program Files\ ComPlus Applications
[10/18/2008|05:37] C:\Program Files\ DNA
[02/06/2008|11:28] C:\Program Files\ D-Tools
[05/02/2008|07:53] C:\Program Files\ dvd43
[07/11/2008|03:44] C:\Program Files\ Eidos Interactive
[10/13/2008|01:49] C:\Program Files\ Electronic Arts
[10/18/2008|05:15] C:\Program Files\ Grisoft(2)
[07/26/2008|03:22] C:\Program Files\ Hero Editor
[10/18/2008|05:15] C:\Program Files\ InstallShield Installation Information
[08/16/2008|04:37] C:\Program Files\ Internet Explorer
[05/15/2008|03:06] C:\Program Files\ iPod
[07/28/2008|03:05] C:\Program Files\ Java
[08/31/2008|10:35] C:\Program Files\ Logitech
[05/09/2008|03:54] C:\Program Files\ Malwarebytes' Anti-Malware
[03/10/2008|12:38] C:\Program Files\ MegauploadToolbar
[10/31/2008|09:05] C:\Program Files\ Messenger
[02/04/2008|09:04] C:\Program Files\ microsoft frontpage
[02/04/2008|09:01] C:\Program Files\ Movie Maker
[11/07/2008|09:56] C:\Program Files\ Mozilla Firefox
[02/04/2008|08:59] C:\Program Files\ MSN
[02/04/2008|09:00] C:\Program Files\ MSN Gaming Zone
[10/17/2008|06:36] C:\Program Files\ MSN Messenger
[02/07/2008|07:40] C:\Program Files\ MSXML 4.0
[02/07/2008|07:46] C:\Program Files\ MSXML 6.0
[02/04/2008|09:01] C:\Program Files\ NetMeeting
[05/09/2008|03:43] C:\Program Files\ Online Services
[02/07/2008|07:46] C:\Program Files\ Outlook Express
[08/30/2008|03:43] C:\Program Files\ Oxin's Style!
[08/21/2008|04:46] C:\Program Files\ Return Fire
[02/04/2008|12:39] C:\Program Files\ Ringz Studio
[10/31/2008|09:05] C:\Program Files\ StuffPlug3
[05/22/2008|06:52] C:\Program Files\ Sun
[02/04/2008|12:39] C:\Program Files\ Super DVD Ripper
[10/22/2008|10:51] C:\Program Files\ SUPERAntiSpyware
[05/18/2008|03:57] C:\Program Files\ TeamViewer3
[05/14/2008|09:07] C:\Program Files\ thriXXX
[02/04/2008|09:09] C:\Program Files\ Uninstall Information
[02/05/2008|08:37] C:\Program Files\ Ventrilo
[02/04/2008|12:39] C:\Program Files\ VideoLAN
[08/19/2008|11:47] C:\Program Files\ VMware
[05/02/2008|07:54] C:\Program Files\ vso
[09/24/2008|11:13] C:\Program Files\ Webroot
[03/01/2008|11:35] C:\Program Files\ Windows Live
[11/06/2008|05:47] C:\Program Files\ Windows Live Safety Center
[10/31/2008|09:05] C:\Program Files\ Windows Media Connect 2
[02/22/2008|03:34] C:\Program Files\ Windows Media Player
[02/04/2008|09:00] C:\Program Files\ Windows NT
[02/04/2008|09:02] C:\Program Files\ WindowsUpdate
[02/04/2008|12:49] C:\Program Files\ WinRAR
[02/04/2008|09:04] C:\Program Files\ xerox
[10/18/2008|05:16] C:\Program Files\ Yahoo!
[10/15/2008|12:51] C:\Program Files\ Zone Labs

——————–\\ Listing Folders in C:\Program Files\Common Files

[03/03/2008|10:58] C:\Program Files\Common Files\ Adobe
[02/05/2008|09:42] C:\Program Files\Common Files\ Adobe Systems Shared
[06/05/2008|08:35] C:\Program Files\Common Files\ Ahead
[03/13/2008|01:27] C:\Program Files\Common Files\ Blizzard Entertainment
[05/15/2008|03:05] C:\Program Files\Common Files\ InstallShield
[02/05/2008|07:21] C:\Program Files\Common Files\ Java
[08/31/2008|10:35] C:\Program Files\Common Files\ LogiShared
[08/31/2008|10:33] C:\Program Files\Common Files\ Logitech
[10/18/2008|05:36] C:\Program Files\Common Files\ Microsoft Shared
[02/04/2008|09:01] C:\Program Files\Common Files\ MSSoap
[01/01/2007|09:52] C:\Program Files\Common Files\ ODBC
[02/04/2008|12:39] C:\Program Files\Common Files\ Real
[02/04/2008|09:01] C:\Program Files\Common Files\ Services
[01/01/2007|09:52] C:\Program Files\Common Files\ SpeechEngines
[02/07/2008|07:46] C:\Program Files\Common Files\ System
[08/19/2008|11:47] C:\Program Files\Common Files\ VMware
[03/01/2008|11:35] C:\Program Files\Common Files\ WindowsLiveInstaller
[10/22/2008|10:51] C:\Program Files\Common Files\ Wise Installation Wizard

——————–\\ Process

( 38 Processes )

… OK !

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

C:\DOCUME~1\samuel\Cookies\[removed][1].txt
C:\DOCUME~1\samuel\Cookies\samuel@advertising[2].txt
C:\DOCUME~1\samuel\Cookies\samuel@pacificpoker[1].txt
C:\DOCUME~1\samuel\Cookies\samuel@partypoker[1].txt

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-07 10:24:59
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 35

——————–\\ Searching for other infections

——————–\\ Cracks & Keygens ..

C:\DOCUME~1\samuel\Application Data\BitTorrent\3D SexVilla v2.7 + Crack.torrent


[F:22][D:88]-> C:\DOCUME~1\samuel\LOCALS~1\Temp
[F:202][D:0]-> C:\DOCUME~1\samuel\Cookies
[F:1328][D:6]-> C:\DOCUME~1\samuel\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Fri 11/07/2008|10:25 - Option : [1]

——————–\\ Scan completed at 10:25:36
Hello

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-11-07 20:11:10
Microsoft Windows XP Professional Service Pack 2
System drive C: has 19 GB (37%) free of 50 GB
Total RAM: 2046 MB (75% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:11:23 PM, on 11/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\D-Tools\daemon.exe
S:\VMware\hqtray.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\Msmsgs.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
D:\Installers&abit; more\Computer\WLM Lite 8.5.exe
D:\Installers&abit; more\Computer\WLM Lite\4000001900003i\usnsvc.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\samuel\Desktop\RSIT.exe
C:\Program Files\trend micro\samuel.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Program Files\Analog Devices\Core\smax4pnp.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [VMware hqtray] "S:\VMware\hqtray.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: wbsys.dll,avgrsstx.dll
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 5528 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo;! Toolbar Helper - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2007-12-19 817936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! ¤u¨ã¦C - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2007-12-19 817936]
{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - Megaupload Toolbar - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL [2007-08-01 1933256]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-12-05 8523776]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-12-05 81920]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2006-05-01 843776]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2006-04-10 729088]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"DAEMON Tools-1033"=C:\Program Files\D-Tools\daemon.exe [2002-09-13 73728]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"VMware hqtray"=S:\VMware\hqtray.exe [2007-10-08 55856]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-10-19 1234712]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"MSMSGS"=C:\Program Files\Messenger\Msmsgs.exe [2004-10-13 1694208]
"BitTorrent DNA"=C:\Program Files\DNA\btdna.exe [2008-10-18 289088]
"NBJ"=C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2005-02-10 1937408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dvd43]
C:\Program Files\dvd43\dvd43_tray.exe [2005-04-27 788992]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
S:\Game Files\iTunes\iTunesHelper.exe [2006-02-23 278528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\Ringz Studio\Storm Codec\qttask.exe [2008-05-15 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
S:\Game Files\Steam\Steam.exe [2008-06-07 1271032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StormCodec_Helper]
C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe [2005-07-19 96159]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [2006-03-30 313472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vmware-tray]
S:\VMware\vmware-tray.exe [2007-10-08 72240]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE [2007-08-30 4670704]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [2005-09-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3
"WLSetupSvc"=3
"VMware NAT Service"=2
"vmount2"=2
"VMnetDHCP"=2
"VMAuthdService"=2
"usnjsvc"=3
"ufad-ws60"=3
"iPodService"=3
"IDriverT"=3
"Eventlog"=2
"ERSvc"=2
"Browser"=2
"BITS"=2
"avg8wd"=2
"avg8emc"=2
"Adobe LM Service"=3

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Documents and Settings\samuel\Start Menu\Programs\Startup
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="wbsys.dll,avgrsstx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WBSrv]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-04-10 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WRNotifier]
WRLogonNTF.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=149

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\New Game Files\Counter-Strike 1.6\hl.exe"="D:\New Game Files\Counter-Strike 1.6\hl.exe:*:Enabled:Half-Life Launcher"
"S:\Game Files\Dawn of\DarkCrusade.exe"="S:\Game Files\Dawn of\DarkCrusade.exe:*:Enabled:DarkCrusade"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"S:\Game Files\Counter-Strike 1.6\hl.exe"="S:\Game Files\Counter-Strike 1.6\hl.exe:*:Enabled:Half-Life Launcher"
"S:\Game Files\Counter-Strike Source\hl2.exe"="S:\Game Files\Counter-Strike Source\hl2.exe:*:Enabled:hl2"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"S:\Game Files\Dawn of War\DarkCrusade.exe"="S:\Game Files\Dawn of War\DarkCrusade.exe:*:Enabled:DarkCrusade"
"D:\New Game Files\WoW server\DB\bin\mysqld-nt.exe"="D:\New Game Files\WoW server\DB\bin\mysqld-nt.exe:*:Enabled:mysqld-nt"
"D:\New Game Files\WoW server\realmd.exe"="D:\New Game Files\WoW server\realmd.exe:*:Enabled:realmd"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA"
"S:\Game Files\BitTorrent\bittorrent.exe"="S:\Game Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"S:\Game Files\World of Warcraft\WoW-2.3.3.7799-to-2.4.0.8089-enUS-downloader.exe"="S:\Game Files\World of Warcraft\WoW-2.3.3.7799-to-2.4.0.8089-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"S:\Game Files\iTunes\iTunes.exe"="S:\Game Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"S:\LineWire\LimeWire\LimeWire.exe"="S:\LineWire\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"D:\New Game Files\AO2\age2_x1.exe"="D:\New Game Files\AO2\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"S:\Game Files\AO2\age2_x1.exe"="S:\Game Files\AO2\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"S:\Game Files\COD4\iw3mp.exe"="S:\Game Files\COD4\iw3mp.exe:*:Enabled:iw3mp"
"S:\Game Files\Warcraft III\Warcraft III.exe"="S:\Game Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Documents and Settings\samuel\Local Settings\Temp\Rar$EX00.704\WLM Lite 8.5.exe"="C:\Documents and Settings\samuel\Local Settings\Temp\Rar$EX00.704\WLM Lite 8.5.exe:*:Enabled:Windows Live Messenger Lite"
"D:\Installers&abit; more\Computer\WLM Lite 8.5.exe"="D:\Installers&abit; more\Computer\WLM Lite 8.5.exe:*:Enabled:Windows Live Messenger Lite"
"C:\Documents and Settings\samuel\Desktop\20080826EudemonsV1130_BC.exe"="C:\Documents and Settings\samuel\Desktop\20080826EudemonsV1130_BC.exe:*:Enabled:BitCometLite"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"

======List of files/folders created in the last 1 months======

2008-11-07 20:11:11 —-D—- C:\Program Files\trend micro
2008-11-07 20:11:10 —-D—- C:\rsit
2008-11-07 10:23:55 —-A—- C:\lopR.txt
2008-11-07 10:21:43 —-D—- C:\Lop SD
2008-11-07 10:08:49 —-D—- C:\WINDOWS\ERUNT
2008-11-07 10:01:18 —-D—- C:\SDFix
2008-10-29 16:35:14 —-D—- C:\Downloads
2008-10-18 23:09:44 —-A—- C:\WINDOWS\system32\unicows.dll
2008-10-18 17:46:50 —-HD—- C:\$AVG8.VAULT$
2008-10-18 17:36:29 —-A—- C:\WINDOWS\system32\avgrsstx.dll
2008-10-18 17:36:15 —-D—- C:\Program Files\AVG
2008-10-18 17:36:15 —-D—- C:\Documents and Settings\All Users\Application Data\avg8
2008-10-18 17:28:51 —-A—- C:\WINDOWS\system32\PerfStringBackup.TMP
2008-10-18 17:17:00 —-D—- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-10-17 17:51:33 —-A—- C:\WINDOWS\system32\WRLogonNtf(2)(2).dll
2008-10-15 12:51:51 —-D—- C:\Program Files\Zone Labs
2008-10-15 12:51:04 —-D—- C:\Program Files\Grisoft(2)
2008-10-13 13:56:41 —-D—- C:\Documents and Settings\samuel\Application Data\SPORE

======List of files/folders modified in the last 1 months======

2008-11-07 20:11:23 —-D—- C:\WINDOWS\Temp
2008-11-07 20:11:11 —-RD—- C:\Program Files
2008-11-07 20:08:26 —-D—- C:\Program Files\Mozilla Firefox
2008-11-07 20:02:02 —-D—- C:\Documents and Settings\samuel\Application Data\DNA
2008-11-07 19:01:03 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-11-07 10:18:57 —-SH—- C:\boot.ini
2008-11-07 10:18:57 —-A—- C:\WINDOWS\win.ini
2008-11-07 10:18:57 —-A—- C:\WINDOWS\system.ini
2008-11-07 10:11:14 —-D—- C:\WINDOWS\system32
2008-11-07 10:08:49 —-D—- C:\WINDOWS
2008-11-06 23:08:08 —-D—- C:\WINDOWS\system32\CatRoot2
2008-11-06 20:21:59 —-D—- C:\WINDOWS\Prefetch
2008-11-06 20:20:42 —-D—- C:\Documents and Settings\All Users\Application Data\VMware
2008-11-06 17:47:17 —-HD—- C:\WINDOWS\inf
2008-11-06 17:47:17 —-D—- C:\Program Files\Windows Live Safety Center
2008-11-06 17:45:38 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-11-06 17:28:04 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-11-06 17:20:09 —-D—- C:\Documents and Settings\samuel\Application Data\BitTorrent
2008-11-04 23:05:20 —-D—- C:\Documents and Settings\samuel\Application Data\TeamViewer
2008-11-02 16:16:06 —-D—- C:\Documents and Settings\samuel\Application Data\VMware
2008-11-02 14:13:38 —-A—- C:\WINDOWS\NeroDigital.ini
2008-10-31 21:16:58 —-SHD—- C:\WINDOWS\CSC
2008-10-31 21:05:23 —-D—- C:\Program Files\Windows Media Connect 2
2008-10-31 21:05:23 —-D—- C:\Program Files\Messenger
2008-10-31 21:05:22 —-D—- C:\Program Files\StuffPlug3
2008-10-31 21:05:22 —-D—- C:\Program Files\AMT
2008-10-22 21:49:50 —-D—- C:\Documents and Settings\samuel\Application Data\Ahead
2008-10-22 21:49:38 —-D—- C:\Documents and Settings\samuel\Application Data\Vso
2008-10-22 20:41:39 —-HD—- C:\Config.Msi
2008-10-22 10:51:31 —-SHD—- C:\WINDOWS\Installer
2008-10-22 10:51:31 —-D—- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-22 10:51:28 —-D—- C:\Documents and Settings\samuel\Application Data\SUPERAntiSpyware.com
2008-10-22 10:51:26 —-D—- C:\Program Files\SUPERAntiSpyware
2008-10-20 12:09:04 —-D—- C:\WINDOWS\system32\ReinstallBackups
2008-10-19 09:47:17 —-D—- C:\WINDOWS\system32\drivers
2008-10-18 17:37:21 —-D—- C:\Program Files\DNA
2008-10-18 17:36:11 —-D—- C:\WINDOWS\WinSxS
2008-10-18 17:36:11 —-D—- C:\Program Files\Common Files\Microsoft Shared
2008-10-18 17:35:10 —-SD—- C:\Documents and Settings\samuel\Application Data\Microsoft
2008-10-18 17:27:56 —-AD—- C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-18 17:22:50 —-D—- C:\WINDOWS\system32\CatRoot
2008-10-18 17:21:34 —-D—- C:\WINDOWS\system32\twain_32
2008-10-18 17:20:30 —-D—- C:\WINDOWS\system32\config
2008-10-18 17:20:20 —-D—- C:\WINDOWS\system32\wbem
2008-10-18 17:20:19 —-D—- C:\WINDOWS\Registration
2008-10-18 17:16:33 —-D—- C:\Program Files\Yahoo!
2008-10-18 17:16:20 —-D—- C:\WINDOWS\system32\DirectX
2008-10-18 17:15:47 —-HD—- C:\Program Files\InstallShield Installation Information
2008-10-17 18:36:56 —-D—- C:\Program Files\MSN Messenger
2008-10-15 12:51:49 —-D—- C:\WINDOWS\Internet Logs
2008-10-15 12:42:30 —-D—- C:\WINDOWS\pss
2008-10-13 13:49:52 —-D—- C:\Program Files\Electronic Arts

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-10-19 97928]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2008-10-18 26824]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
R2 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-10-18 76040]
R2 hcmon;VMware hcmon; \??\C:\WINDOWS\system32\Drivers\hcmon.sys []
R2 VMnetBridge;VMware Bridge Protocol; C:\WINDOWS\system32\DRIVERS\vmnetbridge.sys [2007-10-08 28592]
R2 VMnetuserif;VMware Network Application Interface; \??\C:\WINDOWS\system32\drivers\vmnetuserif.sys []
R2 VMparport;VMware VMparport; \??\C:\WINDOWS\system32\Drivers\VMparport.sys []
R2 vmx86;VMware vmx86; \??\C:\WINDOWS\system32\Drivers\vmx86.sys []
R2 vstor2;Vstor2 Virtual Storage Driver; \??\C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys []
R2 vstor2-ws60;Vstor2 WS60 Virtual Storage Driver; \??\S:\VMware\vstor2-ws60.sys []
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2006-05-02 229376]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2006-04-27 93824]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2006-04-17 60800]
R3 dvd43llh;dvd43llh; C:\WINDOWS\System32\DRIVERS\dvd43llh.sys [2008-05-02 18816]
R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2005-02-02 14408]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-10-14 138752]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 ICAM3NT5;Intel USB Video Camera III; C:\WINDOWS\System32\Drivers\Icam3.sys [2001-08-17 141056]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2007-04-11 34832]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2006-04-17 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-12-05 7435392]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-03-22 52736]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-03-22 18944]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2008-05-02 47360]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2006-03-17 392960]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2005-06-16 31744]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2006-01-17 27264]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2006-02-13 57984]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]
R3 vmkbd;VMware kbd; \??\C:\WINDOWS\system32\drivers\VMkbd.sys []
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S3 catchme;catchme; \??\C:\DOCUME~1\samuel\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys [2007-04-11 20496]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NPF;Netgroup Packet Filter; C:\WINDOWS\system32\drivers\npf.sys [2008-08-30 42512]
S3 s116bus;Sony Ericsson Device 116 driver (WDM); C:\WINDOWS\system32\DRIVERS\s116bus.sys [2007-04-03 83336]
S3 s116mdfl;Sony Ericsson Device 116 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s116mdfl.sys [2007-04-03 15112]
S3 s116mdm;Sony Ericsson Device 116 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s116mdm.sys [2007-04-03 108680]
S3 s116obex;Sony Ericsson Device 116 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s116obex.sys [2007-04-03 98696]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 SSKBFD;Webroot Spy Sweeper Keylogger Shield Keyboard Filter; C:\WINDOWS\System32\Drivers\sskbfd.sys [2006-11-01 21056]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-04 59264]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-12-28 26368]
S3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\vmnetadapter.sys [2007-10-08 16816]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-12-05 155716]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S4 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2008-02-05 72704]
S4 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-10-19 875288]
S4 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-10-19 231704]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S4 iPodService;iPodService; C:\Program Files\iPod\bin\iPodService.exe [2006-02-23 323584]
S4 ufad-ws60;VMware Agent Service; S:\VMware\vmware-ufad.exe [2007-08-07 186928]
S4 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S4 VMAuthdService;VMware Authorization Service; S:\VMware\vmware-authd.exe [2007-10-08 109104]
S4 VMnetDHCP;VMware DHCP Service; C:\WINDOWS\system32\vmnetdhcp.exe [2007-10-08 121392]
S4 vmount2;VMware Virtual Mount Manager Extended; C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe [2007-03-23 269104]
S4 VMware NAT Service;VMware NAT Service; C:\WINDOWS\system32\vmnat.exe [2007-10-08 150064]
S4 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S4 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]

—————–EOF—————–
Hello

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.



Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI