This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Annoying pop ups

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OK so for about a hour now Ive been getting this annoying pop up on Internet Explorer hxxp://profesionalka.blogdns.com/g.php it keeps on coming even when I click X at first i thought my Explorer was acting up, so I restarted my computer and for a while it seemed fine after 30 mins it came back. I believe its a virus but I have no idea how it could of gotten in my computer :/

I'm hoping someone could help me with this…


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:10:46 AM, on 12/27/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16764)
Boot mode: Normal

Running processes:
D:\Windows\system32\Dwm.exe
D:\Windows\Explorer.EXE
D:\Windows\services.exe
D:\Program Files\Windows Defender\MSASCui.exe
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
D:\Program Files\HP\HP Software Update\hpwuSchd2.exe
D:\Windows\system32\taskeng.exe
D:\Program Files\Windows Sidebar\sidebar.exe
D:\Windows\ehome\ehtray.exe
D:\Program Files\Windows Live\Messenger\msnmsgr.exe
D:\Windows\ehome\ehmsas.exe
D:\Windows\system32\wbem\unsecapp.exe
D:\Program Files\MessengerDiscovery\MessengerDiscovery Live.exe
D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
D:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
D:\Windows\system32\wuauclt.exe
D:\Program Files\Internet Explorer\IEUser.exe
D:\Windows\system32\conime.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
D:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
D:\Windows\system32\SearchFilterHost.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
F3 - REG:win.ini: run=D:\Windows\services.exe
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - D:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [GSISETUP] D:\Users\hadi\AppData\Local\Temp\XS1634.tmp\setup.exe
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [MSConfig] "D:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [supertintin_skype] D:\Program Files\Supertintin for Skype\supertintin_skype.exe /start_context sys_auto
O4 - HKLM\..\RunOnce: [InstallShieldSetup] D:\PROGRA~1\COMMON~1\INSTAL~1\Driver\8\INTEL3~1\IDriver.exe /reboot{D4936AAF-FFD0-44A1-A7EA-A2DB41CEB5BC} /z
O4 - HKCU\..\Run: [Sidebar] D:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] D:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - D:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - D:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - file:///D:/Users/hadi/AppData/Local/Oberon%20Media/Oberon%20Games%20Host/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe

–
End of file - 9477 bytes
:welcome:

My name is BHowett and I will be helping you to get sorted. If for any reason you do not understand any of the instructions, or are just unsure then please do not guess , simply post back with your question, and we will go through it again.

Please do the following…


Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

===============================================

And lets take a deeper look at some things…

RSIT
  • Download random's system information tool (RSIT) by random/random from here.
  • It is important that is saved to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<

===============================================

Needed in the next reply:

Malwarebytes log
RSIT logs

Also let me know how things are running :thumbup:
Thanks a lot :)

here is the Malwarebytes log:



Malwarebytes' Anti-Malware 1.31
Database version: 1550
Windows 6.0.6000

12/27/2008 10:38:57 AM
mbam-log-2008-12-27 (10-38-57).txt

Scan type: Quick Scan
Objects scanned: 50877
Time elapsed: 5 minute(s), 30 second(s)


Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
D:\Windows\services.exe (Heuristics.Reserved.Word.Exploit) -> Failed to unload process.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Run (Backdoor.ProRat) -> Data: d:\windows\services.exe -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
D:\Windows\services.exe (Backdoor.ProRat) -> Delete on reboot.



And here is the RSIT LOGS:

log.txt

Logfile of random's system information tool 1.05 (written by random/random)
Run by [removed] at 2008-12-27 10:47:18
Microsoft® Windows Vista™ Ultimate
System drive D: has 5 GB (10%) free of 49 GB
Total RAM: 1022 MB (39% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:47:33 AM, on 12/27/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16764)
Boot mode: Normal

Running processes:
D:\Windows\system32\Dwm.exe
D:\Windows\system32\taskeng.exe
D:\Windows\Explorer.EXE
D:\Program Files\Windows Defender\MSASCui.exe
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
D:\Program Files\HP\HP Software Update\hpwuSchd2.exe
D:\Program Files\Windows Sidebar\sidebar.exe
D:\Windows\ehome\ehtray.exe
D:\Program Files\Windows Live\Messenger\msnmsgr.exe
D:\Windows\ehome\ehmsas.exe
D:\Windows\system32\wbem\unsecapp.exe
D:\Program Files\MessengerDiscovery\MessengerDiscovery Live.exe
D:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
D:\Windows\system32\wuauclt.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Windows\system32\SearchFilterHost.exe
D:\Users\hadi\Desktop\RSIT.exe
D:\Program Files\Trend Micro\HijackThis\hadi.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - D:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [GSISETUP] D:\Users\hadi\AppData\Local\Temp\XS1634.tmp\setup.exe
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [MSConfig] "D:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [supertintin_skype] D:\Program Files\Supertintin for Skype\supertintin_skype.exe /start_context sys_auto
O4 - HKCU\..\Run: [Sidebar] D:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] D:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - D:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - D:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - file:///D:/Users/hadi/AppData/Local/Oberon%20Media/Oberon%20Games%20Host/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe

–
End of file - 8927 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo;! Toolbar Helper - D:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2008-05-15 817936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
HP Print Clips - D:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-11-18 1082880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - D:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2008-05-15 817936]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=D:\Program Files\Windows Defender\MSASCui.exe [2008-08-20 1006264]
"GrooveMonitor"=D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2007-08-24 33648]
"GSISETUP"=D:\Users\hadi\AppData\Local\Temp\XS1634.tmp\setup.exe [2005-08-25 36864]
"avgnt"=D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]
"Adobe Reader Speed Launcher"=D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"MSConfig"=D:\Windows\system32\msconfig.exe [2006-11-02 222208]
"HP Software Update"=D:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
"supertintin_skype"=D:\Program Files\Supertintin for Skype\supertintin_skype.exe [2008-08-04 757760]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=D:\Program Files\Windows Sidebar\sidebar.exe [2008-08-23 1232896]
"ehTray.exe"=D:\Windows\ehome\ehTray.exe [2006-11-02 125440]
"MsnMsgr"=D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
"Messenger (Yahoo!)"=D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2008-11-05 4347120]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
D:\Program Files\QuickTime\QTTask.exe -atboottime []

D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======List of files/folders created in the last 1 months======

2008-12-27 10:47:18 —-D—- D:\rsit
2008-12-27 03:57:28 —-D—- D:\Users\hadi\AppData\Roaming\Malwarebytes
2008-12-27 03:57:19 —-D—- D:\ProgramData\Malwarebytes
2008-12-27 03:57:19 —-D—- D:\Program Files\Malwarebytes' Anti-Malware
2008-12-27 00:10:38 —-D—- D:\Program Files\Trend Micro
2008-12-26 23:59:08 —-D—- D:\Program Files\Hijackthis
2008-12-26 23:12:35 —-D—- D:\VundoFix Backups
2008-12-19 11:47:17 —-A—- D:\Windows\system32\mshtml.dll
2008-12-16 15:47:14 —-A—- D:\Windows\system32\yv12vfw.dll
2008-12-16 15:47:14 —-A—- D:\Windows\system32\MPG4c32.dll
2008-12-16 15:47:14 —-A—- D:\Windows\system32\mfc71.dll
2008-12-16 15:47:13 —-D—- D:\Program Files\Supertintin for Skype
2008-12-16 14:36:39 —-D—- D:\Users\hadi\AppData\Roaming\skypePM
2008-12-16 14:30:31 —-D—- D:\Users\hadi\AppData\Roaming\Skype
2008-12-16 14:30:06 —-D—- D:\Program Files\Skype
2008-12-16 14:30:06 —-D—- D:\Program Files\Common Files\Skype
2008-12-16 14:29:56 —-D—- D:\ProgramData\Skype
2008-12-13 15:28:06 —-A—- D:\Windows\oodcnt3.ini
2008-12-13 15:28:04 —-D—- D:\Program Files\Application name
2008-12-12 19:12:20 —-D—- D:\Users\hadi\AppData\Roaming\MySpace
2008-12-12 19:12:18 —-D—- D:\Program Files\MySpace
2008-12-12 14:31:53 —-A—- D:\Windows\system32\gdi32.dll
2008-12-12 14:31:37 —-A—- D:\Windows\system32\gameux.dll
2008-12-12 14:31:35 —-A—- D:\Windows\system32\Apphlpdm.dll
2008-12-12 14:31:34 —-A—- D:\Windows\system32\GameUXLegacyGDFs.dll
2008-12-12 14:29:19 —-A—- D:\Windows\system32\shell32.dll
2008-12-12 14:29:00 —-A—- D:\Windows\explorer.exe
2008-12-12 14:28:50 —-A—- D:\Windows\system32\urlmon.dll
2008-12-12 14:28:49 —-A—- D:\Windows\system32\ieframe.dll
2008-12-12 14:28:46 —-A—- D:\Windows\system32\wininet.dll
2008-12-12 14:28:46 —-A—- D:\Windows\system32\mshtmled.dll
2008-12-12 14:28:45 —-A—- D:\Windows\system32\mstime.dll
2008-12-12 14:28:45 —-A—- D:\Windows\system32\ieapfltr.dll
2008-12-12 14:28:45 —-A—- D:\Windows\system32\advpack.dll
2008-12-12 14:28:44 —-A—- D:\Windows\system32\ieui.dll
2008-12-12 14:28:44 —-A—- D:\Windows\system32\ie4uinit.exe
2008-12-12 14:28:43 —-A—- D:\Windows\system32\iesetup.dll
2008-12-12 14:28:43 —-A—- D:\Windows\system32\iertutil.dll
2008-12-12 14:28:43 —-A—- D:\Windows\system32\iernonce.dll
2008-12-12 14:28:43 —-A—- D:\Windows\system32\icardie.dll
2008-12-12 14:28:43 —-A—- D:\Windows\system32\dxtrans.dll
2008-12-12 14:28:43 —-A—- D:\Windows\system32\dxtmsft.dll
2008-12-12 14:28:42 —-A—- D:\Windows\system32\pngfilt.dll
2008-12-12 14:28:42 —-A—- D:\Windows\system32\jsproxy.dll
2008-12-12 14:28:42 —-A—- D:\Windows\system32\ieUnatt.exe
2008-12-12 14:28:04 —-A—- D:\Windows\system32\WMVCORE.DLL
2008-12-12 14:28:04 —-A—- D:\Windows\system32\mf.dll
2008-12-12 14:28:03 —-A—- D:\Windows\system32\WMNetMgr.dll
2008-12-12 14:28:03 —-A—- D:\Windows\system32\rrinstaller.exe
2008-12-12 14:28:03 —-A—- D:\Windows\system32\logagent.exe
2008-12-12 14:28:02 —-A—- D:\Windows\system32\mfps.dll
2008-12-12 14:28:02 —-A—- D:\Windows\system32\mfpmp.exe
2008-12-12 14:28:02 —-A—- D:\Windows\system32\mferror.dll
2008-12-12 12:24:02 —-A—- D:\Windows\system32\tzres.dll

======List of files/folders modified in the last 1 months======

2008-12-27 10:47:25 —-D—- D:\Windows\Temp
2008-12-27 10:45:57 —-D—- D:\Windows\System32
2008-12-27 10:45:56 —-D—- D:\Windows\inf
2008-12-27 10:45:56 —-A—- D:\Windows\system32\PerfStringBackup.INI
2008-12-27 10:41:07 —-HD—- D:\Config.Msi
2008-12-27 10:41:02 —-D—- D:\Windows
2008-12-27 10:41:01 —-D—- D:\Windows\system32\drivers
2008-12-27 03:57:19 —-RD—- D:\Program Files
2008-12-27 03:57:19 —-HD—- D:\ProgramData
2008-12-27 00:42:13 —-SHD—- D:\System Volume Information
2008-12-27 00:35:16 —-SHD—- D:\Windows\Installer
2008-12-26 23:56:19 —-D—- D:\Program Files\InstallShield Installation Information
2008-12-26 23:55:04 —-D—- D:\Program Files\iPod
2008-12-26 23:47:18 —-D—- D:\Windows\Prefetch
2008-12-26 23:46:29 —-D—- D:\ProgramData\Apple Computer
2008-12-26 23:46:29 —-D—- D:\Program Files\Common Files\Apple
2008-12-26 21:41:17 —-D—- D:\Windows\rescache
2008-12-26 21:24:19 —-D—- D:\Windows\winsxs
2008-12-26 21:24:12 —-D—- D:\Windows\system32\catroot
2008-12-26 21:24:02 —-ASH—- D:\Program Files\desktop.ini
2008-12-26 21:20:57 —-D—- D:\Program Files\Windows Mail
2008-12-26 21:20:55 —-D—- D:\Windows\AppPatch
2008-12-26 21:20:50 —-D—- D:\Windows\system32\migration
2008-12-26 21:20:50 —-D—- D:\Program Files\Internet Explorer
2008-12-26 18:02:39 —-D—- D:\Users\hadi\AppData\Roaming\LimeWire
2008-12-19 22:50:07 —-D—- D:\Program Files\Mozilla Firefox
2008-12-18 18:49:17 —-SD—- D:\Windows\Downloaded Program Files
2008-12-16 14:30:06 —-D—- D:\Program Files\Common Files
2008-12-16 14:16:22 —-D—- D:\ProgramData\Microsoft Help
2008-12-12 14:25:49 —-D—- D:\Windows\system32\en-US
2008-12-12 14:25:14 —-D—- D:\Windows\system32\catroot2
2008-12-07 01:13:39 —-SD—- D:\Users\hadi\AppData\Roaming\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys [2007-02-27 11840]
R1 avipbb;avipbb; D:\Windows\system32\DRIVERS\avipbb.sys [2008-11-26 75072]
R1 CSC;Offline Files Driver; D:\Windows\system32\drivers\csc.sys [2008-08-23 320000]
R1 ssmdrv;ssmdrv; D:\Windows\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
R3 avgntflt;avgntflt; \??\D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys [2008-05-20 52032]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; D:\Windows\system32\DRIVERS\CmBatt.sys [2008-08-20 14208]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; D:\Windows\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; D:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
R3 HSF_DPV;HSF_DPV; D:\Windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 987648]
R3 HSFHWAZL;HSFHWAZL; D:\Windows\system32\DRIVERS\VSTAZL3.SYS [2006-11-02 200704]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\D:\Windows\system32\drivers\mbamswissarmy.sys [2008-12-03 38496]
R3 NETw3v32;Intel® PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; D:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-02 1781760]
R3 SNC;Sony Notebook Control Device; D:\Windows\System32\Drivers\SonyNC.sys [2000-11-10 48896]
R3 winachsf;winachsf; D:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2006-11-02 654336]
R3 WUDFRd;WUDFRd; D:\Windows\system32\DRIVERS\WUDFRd.sys [2006-11-02 82560]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; D:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]
S3 BthEnum;Bluetooth Enumerator Service; D:\Windows\system32\DRIVERS\BthEnum.sys [2008-08-23 19456]
S3 BthPan;Bluetooth Device (Personal Area Network); D:\Windows\system32\DRIVERS\bthpan.sys [2006-11-02 92160]
S3 BTHPORT;Bluetooth Port Driver; D:\Windows\System32\Drivers\BTHport.sys [2008-08-23 220160]
S3 BTHUSB;Bluetooth Radio USB Driver; D:\Windows\System32\Drivers\BTHUSB.sys [2008-08-23 29184]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; D:\Windows\system32\drivers\drmkaud.sys [2006-11-02 5632]
S3 MSKSSRV;Microsoft Streaming Service Proxy; D:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; D:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; D:\Windows\system32\drivers\MSPQM.sys [2006-11-02 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; D:\Windows\system32\drivers\MSTEE.sys [2006-11-02 6016]
S3 ovt530;Dual Mode USB Camera OV530; D:\Windows\System32\Drivers\ov530vid.sys [2006-02-08 173939]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); D:\Windows\system32\DRIVERS\rfcomm.sys [2006-11-02 49664]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; D:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler; D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-25 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-25 151297]
R2 Apple Mobile Device;Apple Mobile Device; D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07 132424]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; D:\Windows\system32\svchost.exe [2006-11-02 22016]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; D:\Windows\System32\svchost.exe [2006-11-02 22016]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; D:\Windows\system32\svchost.exe [2006-11-02 22016]
R3 hpqcxs08;hpqcxs08; D:\Windows\system32\svchost.exe [2006-11-02 22016]
R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; D:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 AppMgmt;@appmgmts.dll,-3250; D:\Windows\system32\svchost.exe [2006-11-02 22016]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; D:\Windows\system32\fxssvc.exe [2006-11-02 521216]
S3 IDriverT;InstallDriver Table Manager; D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 iPodService;iPodService; D:\Program Files\iPod\bin\iPodService.exe [2005-09-21 323584]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; D:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2007-08-24 68464]
S3 odserv;Microsoft Office Diagnostics Service; D:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; D:\Windows\System32\svchost.exe [2006-11-02 22016]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; D:\Windows\system32\wbengine.exe [2006-11-02 562176]
S3 WLSetupSvc;Windows Live Setup Service; D:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]

—————–EOF—————–


info.txt

info.txt logfile of random's system information tool 1.05 2008-12-27 10:47:39

======Uninstall list======

–>D:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-0044-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-00BA-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-0114-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-0117-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
Acrobat.com–>D:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com–>MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Adobe AIR–>D:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR–>MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Flash Player 10 ActiveX–>D:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin–>D:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
Apple Mobile Device Support–>MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
Apple Software Update–>MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Assistant de connexion Windows Live–>MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Avira AntiVir Personal - Free Antivirus–>D:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
DivX Web Player–>D:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Dual Mode USB Camera OV530–>MsiExec.exe /X{6BDAD7BD-5FC5-42F4-8F2E-6A24610EF332}
Hijackthis 1.99.1–>"D:\Program Files\Hijackthis\unins000.exe"
HijackThis 2.0.2–>"D:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
HP Customer Participation Program 9.0–>D:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Deskjet Printer Driver Software 9.0–>D:\Program Files\HP\Digital Imaging\{03E66394-42F0-4745-85F7-0A2F8F35C09F}\setup\hpzscr01.exe -datfile hphscr15.dat -showdisconnect -forcereboot
HP Imaging Device Functions 9.0–>D:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart Essential 2.01–>D:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
HP Smart Web Printing–>MsiExec.exe /X{415CDA53-9100-476F-A7B2-476691E117C7}
HP Solution Center 9.0–>D:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Update–>MsiExec.exe /X{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}
HPSSupply–>MsiExec.exe /X{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}
iPod for Windows 2005-09-23–>D:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{D4936AAF-FFD0-44A1-A7EA-A2DB41CEB5BC} /l1033
Java™ 6 Update 7–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
LimeWire 4.18.6–>"D:\Program Files\LimeWire\uninstall.exe"
Malwarebytes' Anti-Malware–>"D:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
MessengerDiscovery 1.5.0800–>"D:\Program Files\MessengerDiscovery\unins000.exe"
Microsoft Office Access MUI (English) 2007–>MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007–>MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Enterprise 2007–>"D:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007–>MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007–>MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007–>MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007–>MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007–>MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007–>MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007–>MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007–>MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007–>MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007–>MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007–>MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007–>MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007–>MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007–>MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007–>MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007–>MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (2.0.0.20)–>D:\Program Files\Mozilla Firefox\uninstall\helper.exe
MySpace Toolbar–>D:\Program Files\MySpace\Toolbar\1.0.14.0\Uninstall.exe
OpenOffice.org Installer 1.0–>MsiExec.exe /X{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}
Security Update for 2007 Microsoft Office System (KB951550)–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
Security Update for 2007 Microsoft Office System (KB951944)–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
Security Update for 2007 Microsoft Office System (KB958439)–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {6491B8AA-D11C-4648-A461-6234B31EB7E2}
Security Update for Microsoft Office Excel 2007 (KB958437)–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {648FC016-2D6B-4A16-8D87-404533642F4B}
Security Update for Microsoft Office OneNote 2007 (KB950130)–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
Security Update for Microsoft Office PowerPoint 2007 (KB951338)–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
Security Update for Microsoft Office Publisher 2007 (KB950114)–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
Security Update for Microsoft Office system 2007 (KB954326)–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
Security Update for Microsoft Office system 2007 (KB956828)–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
Security Update for Microsoft Office Word 2007 (KB956358)–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
Skype™ 3.8–>MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Supertintin 1.1.0.0804–>"D:\Program Files\Supertintin for Skype\unins000.exe"
Update for Microsoft Office 2007 Help for Common Features (KB957244)–>msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {C8C72583-C907-4D20-8973-C3858D96BD9E}
Update for Microsoft Office Access 2007 Help (KB957241)–>msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {D670F9B9-3E84-47B5-8A4A-618B65DB1593}
Update for Microsoft Office Excel 2007 Help (KB957242)–>msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {51864046-74C8-487B-97CD-6167A4B1DB56}
Update for Microsoft Office InfoPath 2007 Help (KB957243)–>msiexec /package {90120000-0044-0409-0000-0000000FF1CE} /uninstall {766DF26B-5F03-48ED-9307-5326F2790ED0}
Update for Microsoft Office OneNote 2007 Help (KB957245)–>msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {7332DE60-DC79-4578-A60A-A5EA0D6E032B}
Update for Microsoft Office Outlook 2007 (KB952142)–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
Update for Microsoft Office Outlook 2007 Help (KB957246)–>msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {6F0E4983-E419-4591-B7DD-EFB0073D3E47}
Update for Microsoft Office PowerPoint 2007 Help (KB957247)–>msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {B20E2C59-EEC5-4102-9E50-5DBB2093C37D}
Update for Microsoft Office Publisher 2007 Help (KB957249)–>msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {4E140A5A-4A90-404A-B955-10C2D98CD3EE}
Update for Microsoft Office Word 2007 Help (KB957252)–>msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {54DF3345-0720-4224-9740-C7E00303F565}
Update for Microsoft Script Editor Help (KB957253)–>msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {F21BF703-548C-47B2-B92A-6876E9566C42}
Update for Office 2007 (KB946691)–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
Update for Outlook 2007 Junk Email Filter (kb958619)–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {79B301C1-DBC0-467C-AFDA-2A6CDAFA4302}
Windows Live installer–>MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
Windows Live Messenger–>MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
Windows Media Player Firefox Plugin–>MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
Yahoo! Messenger–>D:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U D:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Toolbar–>D:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE

======Security center information======

AV: Avira AntiVir PersonalEdition
AS: Windows Defender

System event log

Computer Name: hadi-PC
Event Code: 7036
Message: The Security Center service entered the running state.
Record Number: 45506
Source Name: Service Control Manager
Time Written: 20081227084340.000000-000
Event Type: Information
User:

Computer Name: hadi-PC
Event Code: 7036
Message: The Windows Media Center Service Launcher service entered the stopped state.
Record Number: 45507
Source Name: Service Control Manager
Time Written: 20081227084342.000000-000
Event Type: Information
User:

Computer Name: hadi-PC
Event Code: 7036
Message: The Windows Update service entered the running state.
Record Number: 45508
Source Name: Service Control Manager
Time Written: 20081227084344.000000-000
Event Type: Information
User:

Computer Name: hadi-PC
Event Code: 10029
Message: DCOM started the service TrustedInstaller with arguments "" in order to run the server:
{752073A1-23F2-4396-85F0-8FDB879ED0ED}
Record Number: 45509
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20081227084447.000000-000
Event Type: Information
User:

Computer Name: hadi-PC
Event Code: 7036
Message: The Windows Modules Installer service entered the running state.
Record Number: 45510
Source Name: Service Control Manager
Time Written: 20081227084448.000000-000
Event Type: Information
User:

Application event log

Computer Name: hadi-PC
Event Code: 12001
Message: The Messenger Sharing USN Journal Reader service started successfully.
Record Number: 6408
Source Name: usnjsvc
Time Written: 20081227084323.000000-000
Event Type: Information
User:

Computer Name: hadi-PC
Event Code: 102
Message: msnmsgr (3284) \\.\D:\Users\hadi\AppData\Local\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_9874_76A8_7476_8930\dfsr.db: The database engine (6.00.6000.0000) started a new instance (0).
Record Number: 6409
Source Name: ESENT
Time Written: 20081227084323.000000-000
Event Type: Information
User:

Computer Name: hadi-PC
Event Code: 1
Message: The Windows Security Center Service has started.
Record Number: 6410
Source Name: SecurityCenter
Time Written: 20081227084340.000000-000
Event Type: Information
User:

Computer Name: hadi-PC
Event Code: 1001
Message: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Record Number: 6411
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20081227084556.000000-000
Event Type: Information
User:

Computer Name: hadi-PC
Event Code: 1000
Message: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Record Number: 6412
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20081227084557.000000-000
Event Type: Information
User:

Security event log

Computer Name: hadi-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: \Device\HarddiskVolume3\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys
Record Number: 19974
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20081227084133.813130-000
Event Type: Audit Failure
User:

Computer Name: hadi-PC
Event Code: 4648
Message: A logon was attempted using explicit credentials.

Subject:
Security ID: S-1-5-18
Account Name: HADI-PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}

Account Whose Credentials Were Used:
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon GUID: {00000000-0000-0000-0000-000000000000}

Target Server:
Target Server Name: localhost
Additional Information: localhost

Process Information:
Process ID: 0x250
Process Name: D:\Windows\System32\services.exe

Network Information:
Network Address: -
Port: -

This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
Record Number: 19975
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20081227084446.961116-000
Event Type: Audit Success
User:

Computer Name: hadi-PC
Event Code: 4624
Message: An account was successfully logged on.

Subject:
Security ID: S-1-5-18
Account Name: HADI-PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7

Logon Type: 5

New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}

Process Information:
Process ID: 0x250
Process Name: D:\Windows\System32\services.exe

Network Information:
Workstation Name:
Source Network Address: -
Source Port: -

Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 19976
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20081227084446.961116-000
Event Type: Audit Success
User:

Computer Name: hadi-PC
Event Code: 4672
Message: Special privileges assigned to new logon.

Subject:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7

Privileges: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 19977
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20081227084446.961116-000
Event Type: Audit Success
User:

Computer Name: hadi-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: \Device\HarddiskVolume3\Windows\System32\drivers\mbamswissarmy.sys
Record Number: 19978
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20081227084633.296994-000
Event Type: Audit Failure
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 6, GenuineIntel
"PROCESSOR_REVISION"=0f06
"NUMBER_OF_PROCESSORS"=2

—————–EOF—————–


Everything is running smoothly now, hopefully it will stay that way :)
Thanks a lot again I really appreciate it :D
Hi hadi12,

Please do the following….

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.

===========================================================


Please do an online scan with Kaspersky WebScanner

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure the following is checked.
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
sorry for the late reply :) here is the report. ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Tuesday, December 30, 2008 Operating System: Microsoft Windows Vista Ultimate Edition, 32-bit (build 6000) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Monday, December 29, 2008 13:15:14 Records in database: 1528263 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Files scanned: 357818 Threat name: 13 Infected objects: 32 Suspicious objects: 0 Duration of the scan: 06:32:15 File name / Threat name / Threats count C:\fff\Programme\Zylom Games\Tiki Boom Boom Deluxe\tikiboomboom.dll Infected: Backdoor.Win32.IRCBot.nw 1 C:\Programme\Zylom Games\Tiki Boom Boom Deluxe\tikiboomboom.dll Infected: Backdoor.Win32.IRCBot.nw 1 C:\Windows\amFmYXI\asappsrv.dll Infected: not-a-virus:AdWare.Win32.CommAd.a 1 C:\Windows.old.000\Program Files\Save\ACM.dll Infected: not-a-virus:AdTool.Win32.WhenU.i 1 C:\Windows.old.000\Program Files\Save\ffext.mod Infected: not-a-virus:WebToolbar.Win32.WhenU.z 1 C:\Windows.old.000\Program Files\WhenUSearch\search.dll Infected: not-a-virus:AdWare.Win32.SaveNow.az 1 C:\Windows.old.000\Users\poorfarhadi\AppData\Local\Temp\pkg_d38101ef0\resource.0000.pkg Infected: Trojan-Downloader.Win32.Agent.hym 3 C:\Windows.old.000\Users\poorfarhadi\AppData\Local\Temp\pkg_d38101ef0\resource.0000.pkg Infected: not-a-virus:AdWare.Win32.Shopper.q 1 C:\Windows.old.000\Users\poorfarhadi\AppData\Local\Temp\pkg_d38101ef0\resource.0000.pkg Infected: not-a-virus:AdWare.Win32.Shopper.aq 1 C:\Windows.old.000\Users\poorfarhadi\AppData\Local\Temp\pkg_d38101ef0\resource.0000.pkg Infected: Trojan-Downloader.Win32.Agent.akyx 1 C:\Windows.old.000\Users\poorfarhadi\Documents\LimeWire\Incomplete\Preview-T-3545425-50cent stunt 101.mpg Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Windows.old.000\Users\poorfarhadi\Documents\LimeWire\Incomplete\Preview-T-3545425-50cent.mpg Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Windows.old.000\Users\poorfarhadi\Documents\LimeWire\Incomplete\T-3545425-50cent stunt 101.mpg Infected: Trojan-Downloader.WMA.GetCodec.c 1 D:\Users\hadi\Music\Limewire music\Day 26- co star.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1 D:\Users\hadi\Music\Limewire music\juels santana.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1 D:\Users\hadi\Music\Limewire music\Kurupt - It's over.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1 D:\Users\hadi\Music\Limewire music\Kurupt-Natina Reed - It's over.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1 D:\Users\hadi\Music\Limewire music\kurupt.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1 D:\Windows.old.000\Users\HADI\Documents\LimeWire\Incomplete\T-3545425-Day 26.mpg Infected: Trojan-Downloader.WMA.GetCodec.c 1 D:\Windows.old.000\Users\HADI\Documents\LimeWire\Incomplete\T-3545425-Tyrese.mpg Infected: Trojan-Downloader.WMA.GetCodec.c 1 D:\Windows.old.000\Users\HADI\Documents\LimeWire\Incomplete\T-460090-Secondhand Serenade.mp3 Infected: Trojan-Downloader.WMA.GetCodec.g 1 D:\Windows.old.000\Users\HADI\Documents\LimeWire\Incomplete\T-460090-Snoop Dogg.mp3 Infected: Trojan-Downloader.WMA.Wimad.o 1 D:\Windows.old.000\Users\HADI\Documents\LimeWire\Saved\friday night nsync.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1 D:\Windows.old.000\Users\HADI\Documents\LimeWire\Saved\R&B Greatest - Tyrese ft. Snoop Dogg - Just a baby boy.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1 D:\Users\HADI\Music\Limewire music\Day 26- co star.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1 D:\Users\HADI\Music\Limewire music\juels santana.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1 D:\Users\HADI\Music\Limewire music\Kurupt - It's over.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1 D:\Users\HADI\Music\Limewire music\Kurupt-Natina Reed - It's over.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1 D:\Users\HADI\Music\Limewire music\kurupt.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1 D:\Windows.old.000\Users\HADI\Downloads\installer-72114-19en-LimeWire-English.exe Infected: not-a-virus:AdWare.Win32.FakeInstaller.a 1 The selected area was scanned.
Hi hadi12,

Well it looks like you were using P2P with limewire and got a few infected files…. So now you get my P2P warning, and we will nuke the files.

P2P Warning!

Please note that as long as you are using any form of Peer-to-Peer networking and downloading files from non-documented sources, you can expect infestations of malware to occur. Once upon a time, P2P file sharing was fairly safe. That is no longer true. You may continue to use P2P sharing at your own risk; however, please keep in mind that this practice may be the source of your current problem/infection. I would strongly suggest you remove Limewire . Removing can be done through Add/Remove Programs.

===============================================

OTMoveIt3 by OldTimer

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy everything inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Files
    C:\fff\Programme\Zylom Games\Tiki Boom Boom Deluxe\tikiboomboom.dll C:\Programme\Zylom Games\Tiki Boom Boom Deluxe\tikiboomboom.dll C:\Windows\amFmYXI\asappsrv.dll 
    C:\Windows.old.000\Program Files\Save\ACM.dll 
    C:\Windows.old.000\Program Files\Save\ffext.mod 
    C:\Windows.old.000\Program Files\WhenUSearch\search.dll C:\Windows.old.000\Users\poorfarhadi\AppData\Local\Temp\pkg_d38101ef0\resource.0000.pkg C:\Windows.old.000\Users\poorfarhadi\AppData\Local\Temp\pkg_d38101ef0\resource.0000.pkg 
    C:\Windows.old.000\Users\poorfarhadi\AppData\Local\Temp\pkg_d38101ef0\resource.0000.pkg C:\Windows.old.000\Users\poorfarhadi\AppData\Local\Temp\pkg_d38101ef0\resource.0000.pkg C:\Windows.old.000\Users\poorfarhadi\Documents\LimeWire\Incomplete\Preview-T-3545425-50cent stunt 101.mpg C:\Windows.old.000\Users\poorfarhadi\Documents\LimeWire\Incomplete\Preview-T-3545425-50cent.mpg 
    C:\Windows.old.000\Users\poorfarhadi\Documents\LimeWire\Incomplete\T-3545425-50cent stunt 101.mpg 
    D:\Users\hadi\Music\Limewire music\Day 26- co star.mp3 D:\Users\hadi\Music\Limewire music\juels santana.mp3 
    D:\Users\hadi\Music\Limewire music\Kurupt - It's over.mp3 D:\Users\hadi\Music\Limewire music\Kurupt-Natina Reed - It's over.mp3 D:\Users\hadi\Music\Limewire music\kurupt.mp3 D:\Windows.old.000\Users\HADI\Documents\LimeWire\Incomplete\T-3545425-Day 26.mpg 
    D:\Windows.old.000\Users\HADI\Documents\LimeWire\Incomplete\T-3545425-Tyrese.mpg 
    D:\Windows.old.000\Users\HADI\Documents\LimeWire\Incomplete\T-460090-Secondhand Serenade.mp3 D:\Windows.old.000\Users\HADI\Documents\LimeWire\Incomplete\T-460090-Snoop Dogg.mp3 
    D:\Windows.old.000\Users\HADI\Documents\LimeWire\Saved\friday night nsync.mp3 D:\Windows.old.000\Users\HADI\Documents\LimeWire\Saved\R&B Greatest - Tyrese ft. Snoop Dogg - Just a baby boy.mp3 
    D:\Users\HADI\Music\Limewire music\Day 26- co star.mp3 D:\Users\HADI\Music\Limewire music\juels santana.mp3 D:\Users\HADI\Music\Limewire music\Kurupt - It's over.mp3 D:\Users\HADI\Music\Limewire music\Kurupt-Natina Reed - It's over.mp3 D:\Users\HADI\Music\Limewire music\kurupt.mp3 D:\Windows.old.000\Users\HADI\Downloads\installer-72114-19en-LimeWire-English.exe
    :Reg
    :Commands
    [purity]
    [emptytemp]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

===============================================

Needed in your next reply:

OTMoveIt3 log
Fresh HijackThis log

And let me know how things are running now :thumbup:
I have actually deleted Limewire about a week ago because I had a feeling it was the one who was getting me the viruses so that has been removed from my computer :)

Here is the OTMoveIt3 log

========== FILES ==========
File/Folder C:\fff\Programme\Zylom Games\Tiki Boom Boom Deluxe\tikiboomboom.dll C:\Programme\Zylom Games\Tiki Boom Boom Deluxe\tikiboomboom.dll C:\Windows\amFmYXI\asappsrv.dll not found.
File/Folder C:\Windows.old.000\Program Files\Save\ACM.dll not found.
File/Folder C:\Windows.old.000\Program Files\Save\ffext.mod not found.
File/Folder C:\Windows.old.000\Program Files\WhenUSearch\search.dll C:\Windows.old.000\Users\poorfarhadi\AppData\Local\Temp\pkg_d38101ef0\resource.0000.pkg C:\Windows.old.000\Users\poorfarhadi\AppData\Local\Temp\pkg_d38101ef0\resource.0000.pkg not found.
File/Folder C:\Windows.old.000\Users\poorfarhadi\AppData\Local\Temp\pkg_d38101ef0\resource.0000.pkg C:\Windows.old.000\Users\poorfarhadi\AppData\Local\Temp\pkg_d38101ef0\resource.0000.pkg C:\Windows.old.000\Users\poorfarhadi\Documents\LimeWire\Incomplete\Preview-T-3545425-50cent stunt 101.mpg C:\Windows.old.000\Users\poorfarhadi\Documents\LimeWire\Incomplete\Preview-T-3545425-50cent.mpg not found.
File/Folder C:\Windows.old.000\Users\poorfarhadi\Documents\LimeWire\Incomplete\T-3545425-50cent stunt 101.mpg not found.
File/Folder D:\Users\hadi\Music\Limewire music\Day 26- co star.mp3 D:\Users\hadi\Music\Limewire music\juels santana.mp3 not found.
File/Folder D:\Users\hadi\Music\Limewire music\Kurupt - It's over.mp3 D:\Users\hadi\Music\Limewire music\Kurupt-Natina Reed - It's over.mp3 D:\Users\hadi\Music\Limewire music\kurupt.mp3 D:\Windows.old.000\Users\HADI\Documents\LimeWire\Incomplete\T-3545425-Day 26.mpg not found.
File/Folder D:\Windows.old.000\Users\HADI\Documents\LimeWire\Incomplete\T-3545425-Tyrese.mpg not found.
File/Folder D:\Windows.old.000\Users\HADI\Documents\LimeWire\Incomplete\T-460090-Secondhand Serenade.mp3 D:\Windows.old.000\Users\HADI\Documents\LimeWire\Incomplete\T-460090-Snoop Dogg.mp3 not found.
File/Folder D:\Windows.old.000\Users\HADI\Documents\LimeWire\Saved\friday night nsync.mp3 D:\Windows.old.000\Users\HADI\Documents\LimeWire\Saved\R&B Greatest - Tyrese ft. Snoop Dogg - Just a baby boy.mp3 not found.
File/Folder D:\Users\HADI\Music\Limewire music\Day 26- co star.mp3 D:\Users\HADI\Music\Limewire music\juels santana.mp3 D:\Users\HADI\Music\Limewire music\Kurupt - It's over.mp3 D:\Users\HADI\Music\Limewire music\Kurupt-Natina Reed - It's over.mp3 D:\Users\HADI\Music\Limewire music\kurupt.mp3 D:\Windows.old.000\Users\HADI\Downloads\installer-72114-19en-LimeWire-English.exe not found.
========== REGISTRY ==========
========== COMMANDS ==========
File delete failed. D:\Users\hadi\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be deleted on reboot.
File delete failed. D:\Users\hadi\AppData\Local\Temp\~DF8575.tmp scheduled to be deleted on reboot.
File delete failed. D:\Users\hadi\AppData\Local\Temp\~DFB20D.tmp scheduled to be deleted on reboot.
File delete failed. D:\Users\hadi\AppData\Local\Temp\~DFCD24.tmp scheduled to be deleted on reboot.
File delete failed. D:\Users\hadi\AppData\Local\Temp\~DFCD48.tmp scheduled to be deleted on reboot.
File delete failed. D:\Users\hadi\AppData\Local\Temp\~DFD9E6.tmp scheduled to be deleted on reboot.
File delete failed. D:\Users\hadi\AppData\Local\Temp\~DFDBA2.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
File delete failed. D:\Users\hadi\AppData\Local\Mozilla\Firefox\Profiles\tmwyfqow.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. D:\Users\hadi\AppData\Local\Mozilla\Firefox\Profiles\tmwyfqow.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. D:\Users\hadi\AppData\Local\Mozilla\Firefox\Profiles\tmwyfqow.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. D:\Users\hadi\AppData\Local\Mozilla\Firefox\Profiles\tmwyfqow.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. D:\Users\hadi\AppData\Local\Mozilla\Firefox\Profiles\tmwyfqow.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.

OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12312008_130954

Files moved on Reboot…
D:\Users\hadi\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File D:\Users\hadi\AppData\Local\Temp\~DF8575.tmp not found!
D:\Users\hadi\AppData\Local\Temp\~DFB20D.tmp moved successfully.
File D:\Users\hadi\AppData\Local\Temp\~DFCD24.tmp not found!
File D:\Users\hadi\AppData\Local\Temp\~DFCD48.tmp not found!
File D:\Users\hadi\AppData\Local\Temp\~DFD9E6.tmp not found!
File D:\Users\hadi\AppData\Local\Temp\~DFDBA2.tmp not found!
D:\Users\hadi\AppData\Local\Mozilla\Firefox\Profiles\tmwyfqow.default\Cache\_CACHE_001_ moved successfully.
D:\Users\hadi\AppData\Local\Mozilla\Firefox\Profiles\tmwyfqow.default\Cache\_CACHE_002_ moved successfully.
D:\Users\hadi\AppData\Local\Mozilla\Firefox\Profiles\tmwyfqow.default\Cache\_CACHE_003_ moved successfully.
D:\Users\hadi\AppData\Local\Mozilla\Firefox\Profiles\tmwyfqow.default\Cache\_CACHE_MAP_ moved successfully.
D:\Users\hadi\AppData\Local\Mozilla\Firefox\Profiles\tmwyfqow.default\XUL.mfl moved successfully.



I just realized that it says that it couldnt find my files that have been infected. Last night I did a whole scanning with my antivirus AntiVir and I believe I'm not quite sure it could of removed the files.


And here is my new Hijack Log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:20:19 PM, on 12/31/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16764)
Boot mode: Normal

Running processes:
D:\Windows\system32\taskeng.exe
D:\Windows\system32\Dwm.exe
D:\Windows\Explorer.EXE
D:\Program Files\Windows Defender\MSASCui.exe
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
D:\Program Files\HP\HP Software Update\hpwuSchd2.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\Windows Sidebar\sidebar.exe
D:\Windows\ehome\ehtray.exe
D:\Program Files\Windows Live\Messenger\msnmsgr.exe
D:\Windows\ehome\ehmsas.exe
D:\Windows\system32\wbem\unsecapp.exe
D:\Program Files\MessengerDiscovery\MessengerDiscovery Live.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
D:\Windows\system32\wuauclt.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [GSISETUP] D:\Users\hadi\AppData\Local\Temp\XS1634.tmp\setup.exe
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [MSConfig] "D:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [supertintin_skype] D:\Program Files\Supertintin for Skype\supertintin_skype.exe /start_context sys_auto
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] D:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] D:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - file:///D:/Users/hadi/AppData/Local/Oberon%20Media/Oberon%20Games%20Host/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Bonjour Service - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe

–
End of file - 8168 bytes
Hi hadi12,

your all set now, just some clean up, tips to stay safe :thumbup:

OTCleanIt

Download OTCleanit
Save it to your Desktop.

  • Double-click on OTCleanIt.exe to run
  • Click on the CleanUp! button
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You may be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

===============================================

This is my standard post for when you are clear - which you now are - or seem to be. Please advise me of any problems you still have. . I know you already have some of these items like antivirus or firewall, but I like to include them anyway incase you ever need them or want to change them.

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

[external image: Posted Image] 1.) Watch what you download!
Many freeware programs, and P2P programs like Grokster, Imesh, Kazaa and others are amongst the most notorious, come with an enormous amount of bundled spyware that will eat system resources, slow down your system, clash with other installed software, or just plain crash your browser or even Windows itself. If you insist on using a P2P program, please read This Article written by Mike Healan of Spywareinfo.com fame. It is an updated and comprehensive article that gives in-depth detail about which P2P programs are "safe" to use.

[external image: Posted Image] 2.) Go to Intenet Explorer > Tools > Windows Update > Product Updates, and install ALL High-Priority Security Updates listed. If you're running Windows XP, that of course includes the Service Pack 2! If you suspect your computer is infected with Malware of any type, we advise you to not install SP2 if you don't already have it. You can post a HijackThis log on our Forums to get free Expert help cleaning your machine. Once you are sure you have a clean system, it is highly recommended to install SP2 to help prevent against future infections.

It's important to always keep current with the latest security fixes from Microsoft.
Install those patches for Internet Explorer, and make sure your installation of Java VM is up-to-date. There are some well known security bugs with Microsoft Java VM which are exploited regularly by browser hijackers.

[external image: Posted Image] 3.) Open Intenet Explorer and go to Internet Options > Security > Internet, then press "Default Level", then OK. Now press "Custom Level." In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".

Now you will be asked whether you want ActiveX objects to be executed and whether you want software to be installed.
Sites that you know for sure are above suspicion can be moved to the Trusted Zone in Internet Option > Security.

So why is ActiveX so dangerous that you have to increase the security for it?
When your browser runs an activex control, it is running an executable program. It's no different from doubleclicking an exe file on your hard drive.
Would you run just any random file downloaded off a web site without knowing what it is and what it does?

[external image: Posted Image] 4.) Install Javacool's SpywareBlaster

It will protect you from most spy/foistware in it's database by blocking installation of their ActiveX objects.

Download and install, download the latest updates, and you'll see a list of all spyware programs covered by the program (NOTE: this is NOT spyware found on your computer) Press "Enable All Protection", and you're done.
The spyware that you told Spywareblaster to set the "kill bit" for won't be a hazard to you any longer. Although it won't protect you from every form of spyware known to man, it is a very potent extra layer of protection.
Don't forget to check for updates every week or so.

[external image: Posted Image] 5.) Let's also not forget that Spybot Search & Destroy has the Immunize feature which works roughly the same way. Another feature within Spybot is the TeaTimer option. This option immediately detects known malicious processes wanting to start and terminates them. TeaTimer also detects when something wants to change some critical registry keys and gives you an option to allow them or not.

[external image: Posted Image] 6.) Microsoft now offers their own free malicious software blocking tool. Windows Defender improves Internet browsing safety by guarding over fifty (50) ways spyware can enter your PC.

[external image: Posted Image] 7.) Another excellent program by Javacool we recommend is SpywareGuard.
It provides a degree of real-time protection solution against spyware that is a great addition to SpywareBlaster's protection method.

[external image: Posted Image] 8.) IE-SPYAD puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all. Another good hosts program is mvpshosts. This little program packs a powerful punch as it block ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial.

*It is important to note that all of the above programs/files can be run simultaneously on your system. They will work together in layers, so to speak, to help protect your computer. However, the following suggestions are designed to only run one of each. It is not a good idea to run more than one firewall, and one anti-virus program. Running more than one of these at a time can cause system crashes, high system usage and/or conflicts with each other.*

[external image: Posted Image] 9.) It is critical that you use a firewall to protect your computer from hackers. We don't recommend the firewall that comes built in to Windows. It doesn't block everything that may try to get in, and the entire firewall is written to the registry. As various kinds of malware hack the Registry in order to disable the Windows firewall, it's far preferable to install one of the excellent third party solutions. Three good ones that are freeware to boot are ZoneAlarm, Kerio and Sygate

[external image: Posted Image] 10.) An Anti-Virus product is a necessity. There are many excellent programs that you can purchase. However, we choose to advocate the use of free programs whenever possible. Some very good and easy-to-use free A/V programs are AVG, Avast, and AntiVir. It's a good idea to set these to receive automatic updates so you are always as fully protected as possible from the newest virus threats.

NOTE: DO NOT install more than one anti-virus program. They will conflict, and provide less protection, not more.


Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Thanks for letting us help you!
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI