This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] IE popups, removal advice required please

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello to all the members out there, I've just been hit with some spyware/malware which is causing popups to appear when browsing with IE. Running Spybot detects some problems and tries to correct them, but the things that Spybot remove are recreated all the time. Can anyone please have a look at my Hijackthis log files below to resolve this issue, and let me know of any other advice that I might be able to use to speed up my machine.

Thanks in advance for any help as it will be really appreciated.

hijackthis.log:
===========
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:28:29 AM, on 30/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\system32\taskswitch.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\CodeGear\RAD Studio\5.0\bin\BSQLServer.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\PROGRA~1\InFocus\PROJEC~1\pmprjdet.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Program Files\Microsoft SQL Server\MSSQL.3\OLAP\bin\msmdsrv.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=1061006
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=1061006
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {b8b41c50-5722-43c1-8b70-5b81fc830f72} - C:\WINDOWS\system32\zizesabo.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [InFocusProjectorDetector] C:\PROGRA~1\InFocus\PROJEC~1\pmprjdet.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [lafirozeko] Rundll32.exe "C:\WINDOWS\system32\soyozisu.dll",s
O4 - HKLM\..\Run: [CPM1b075170] Rundll32.exe "c:\windows\system32\fevihife.dll",a
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [lafirozeko] Rundll32.exe "C:\WINDOWS\system32\soyozisu.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [lafirozeko] Rundll32.exe "C:\WINDOWS\system32\soyozisu.dll",s (User 'NETWORK SERVICE')
O4 - Startup: Extended Monitor & Laptop.lnk = ?
O4 - Global Startup: UltraMon.lnk = C:\Program Files\UltraMon\UltraMon.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} (ObjWinNTCheck Class) - http://192.168.10.31:2500/officescan/conso…ll/WinNTChk.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupINICtrl Class) - http://192.168.10.31:2500/officescan/conso…ll/setupini.cab
O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) - http://192.168.10.31:2500/officescan/conso…stall/setup.cab
O16 - DPF: {11818680-FCF6-11D0-9808-0800092A4865} (Adobe Form Control) - http://www.ato.gov.au/formflow/codebase/FormCtl.cab
O16 - DPF: {224F7DEA-B7C1-11D3-AB40-00902712A5C9} (PLSAddin Class) - http://www.ato.gov.au/formflow/codebase/plsspeller.cab
O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} (Encrypt Class) - http://192.168.10.31:2500/officescan/conso…root/AtxEnc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {4F3DCE50-E8E7-40AC-AB8D-99F87F1F89BD} (Trend Micro OfficeScan Management Console) - http://192.168.10.31:2500/officescan/conso…/AtxConsole.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1177289747921
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/Tran…ransferCtrl.cab
O16 - DPF: {8990AFAD-D352-42AC-A72F-A660BBF6E209} (OfficeScan Management Console) - http://192.168.10.31:2500/officescan/conso…/AtxConsole.cab
O16 - DPF: {A050E865-64E3-431B-8079-F0DFCEA90A2D} (PieChart Class) - http://192.168.10.31:2500/officescan/conso…root/AtxPie.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CDDCFBB3-4D93-11D2-B1A9-00A0C9B742BE} (Adobe Script Object) - http://www.ato.gov.au/formflow/codebase/scriptobject.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://freetrial.webex.com/client/T26L/webex/ieatgpc.cab
O16 - DPF: {EF2FB80F-0975-408E-A871-B00CC863478A} (Adobe Soft Font Installer) - http://www.ato.gov.au/formflow/codebase/fontinstaller.cab
O18 - Protocol: linkscanner - (no CLSID) - (no file)
O20 - AppInit_DLLs: C:\WINDOWS\system32\lawireyo.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - (no file)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: BlackfishSQL - CodeGear - C:\Program Files\CodeGear\RAD Studio\5.0\bin\BSQLServer.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Unknown owner - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe (file missing)
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 12411 bytes


startuplist.txt:
===========
StartupList report, 30/12/2008, 2:28:51 AM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows XP SP3 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16762)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\system32\taskswitch.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\CodeGear\RAD Studio\5.0\bin\BSQLServer.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\PROGRA~1\InFocus\PROJEC~1\pmprjdet.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Program Files\Microsoft SQL Server\MSSQL.3\OLAP\bin\msmdsrv.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

————————————————–

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Paul Senior\Start Menu\Programs\Startup]
Extended Monitor & Laptop.lnk = ?

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
UltraMon.lnk = C:\Program Files\UltraMon\UltraMon.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\SYSTEM32\Userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

MSKDetectorExe = C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
SynTPEnh = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
zBrowser Launcher = C:\Program Files\Logitech\iTouch\iTouch.exe
CoolSwitch = C:\WINDOWS\system32\taskswitch.exe
mcagent_exe = C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
DAEMON Tools-1033 = "C:\Program Files\D-Tools\daemon.exe" -lang 1033
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
InFocusProjectorDetector = C:\PROGRA~1\InFocus\PROJEC~1\pmprjdet.exe
AVG8_TRAY = C:\PROGRA~1\AVG\AVG8\avgtray.exe
lafirozeko = Rundll32.exe "C:\WINDOWS\system32\soyozisu.dll",s
CPM1b075170 = Rundll32.exe "c:\windows\system32\fevihife.dll",a

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

MsnMsgr = "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
SpybotSD TeaTimer = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

————————————————–

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=C:\WINDOWS\system32\lawireyo.dll

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\MATRIX~1.SCR
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
WormRadar.com IESiteBlocker.NavFilter - C:\Program Files\AVG\AVG8\avgssie.dll - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
(no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - C:\WINDOWS\system32\dla\tfswshx.dll - {5CA3D70E-1895-11CF-8E15-001234567890}
(no name) - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
scriptproxy - C:\Program Files\McAfee\VirusScan\scriptsn.dll - {7DB2D5A0-7241-4E79-B68D-6309F01C5231}
(no name) - (no file) - {7E853D72-626A-48EC-A868-BA8D5E23E045}
(no name) - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6}
(no name) - C:\WINDOWS\system32\zizesabo.dll - {b8b41c50-5722-43c1-8b70-5b81fc830f72}
Browser Address Error Redirector - C:\Program Files\BAE\BAE.dll - {CA6319C0-31B7-401E-A518-A07C3DB8F777}

————————————————–

Enumerating Task Scheduler jobs:

AppleSoftwareUpdate.job
CopyFilesIfNotExisting.job
McDefragTask.job
McQcTask.job
shutdown.job

————————————————–

Enumerating Download Program Files:

[ObjWinNTCheck Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\WinNTChk.dll
CODEBASE = http://192.168.10.31:2500/officescan/conso…ll/WinNTChk.cab

[QuickTime Object]
InProcServer32 = C:\Program Files\QuickTime\QTPlugin.ocx
CODEBASE = http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab

[OfficeScan Corp Edition Web-Deployment SetupINICtrl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\OfficeScanSetupINI.dll
CODEBASE = http://192.168.10.31:2500/officescan/conso…ll/setupini.cab

[OfficeScan Corp Edition Web-Deployment SetupCtrl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\OfficeScanSetup.dll
CODEBASE = http://192.168.10.31:2500/officescan/conso…stall/setup.cab

[Adobe Form Control]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\FormCtl.dll
CODEBASE = http://www.ato.gov.au/formflow/codebase/FormCtl.cab

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\legitcheckcontrol.dll
CODEBASE = http://download.microsoft.com/download/3/9…heckControl.cab

[PLSAddin Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\PLSSpeller.dll
CODEBASE = http://www.ato.gov.au/formflow/codebase/plsspeller.cab

[Encrypt Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\AtxEnc.dll
CODEBASE = http://192.168.10.31:2500/officescan/conso…root/AtxEnc.cab

[McAfee.com Operating System Class]
InProcServer32 = C:\WINDOWS\system32\mcinsctl.dll
CODEBASE = http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab

[Trend Micro OfficeScan Management Console]
InProcServer32 = C:\WINDOWS\DOWNLO~1\CONFLICT.1\ATXCON~1.OCX
CODEBASE = http://192.168.10.31:2500/officescan/conso…/AtxConsole.cab

[MUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\muweb.dll
CODEBASE = http://update.microsoft.com/microsoftupdat…b?1177289747921

[DLC Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\grTransferCtrl.dll
CODEBASE = https://transfers.ds.microsoft.com/FTM/Tran…ransferCtrl.cab

[OfficeScan Management Console]
InProcServer32 = C:\WINDOWS\DOWNLO~1\ATXCON~1.OCX
CODEBASE = http://192.168.10.31:2500/officescan/conso…/AtxConsole.cab

[PieChart Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\AtxPie.dll
CODEBASE = http://192.168.10.31:2500/officescan/conso…root/AtxPie.cab

[MessengerStatsClient Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll
CODEBASE = http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab

[Adobe Script Object]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\ScriptObject.dll
CODEBASE = http://www.ato.gov.au/formflow/codebase/scriptobject.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash10a.ocx
CODEBASE = http://fpdownload.macromedia.com/get/shock…ash/swflash.cab

[GpcContainer Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\ieatgpc.dll
CODEBASE = https://freetrial.webex.com/client/T26L/webex/ieatgpc.cab

[Adobe Soft Font Installer]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\FontInstaller.dll
CODEBASE = http://www.ato.gov.au/formflow/codebase/fontinstaller.cab

————————————————–

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\DOCUME~1\PAULSE~1\LOCALS~1\Temp\_iu14D2N.tmp|||C

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll

————————————————–
End of report, 12,016 bytes
Report generated in 0.110 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
hello

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
Hello Rorschach112, Thanks for your help so far. I run the "ATF-Cleaner" as instructed and that worked fine. Here is a copy of the Malwarebytes' Anti-Malware log (it did ask me to restart, so I did that): Malwarebytes' Anti-Malware 1.31 Database version: 1571 Windows 5.1.2600 Service Pack 3 30/12/2008 10:43:48 AM mbam-log-2008-12-30 (10-43-48).txt Scan type: Quick Scan Objects scanned: 69466 Time elapsed: 9 minute(s), 19 second(s) Memory Processes Infected: 0 Memory Modules Infected: 2 Registry Keys Infected: 5 Registry Values Infected: 3 Registry Data Items Infected: 3 Folders Infected: 0 Files Infected: 18 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\lawireyo.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\zizesabo.dll (Trojan.Vundo.H) -> Delete on reboot. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b8b41c50-5722-43c1-8b70-5b81fc830f72} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{b8b41c50-5722-43c1-8b70-5b81fc830f72} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b8b41c50-5722-43c1-8b70-5b81fc830f72} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lafirozeko (Trojan.Vundo.H) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm1b075170 (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\lawireyo.dll -> Delete on reboot. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\lawireyo.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\lawireyo.dll -> Delete on reboot. Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\kutirata.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\atarituk.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ledalesa.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\aseladel.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\wizuyebi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ibeyuziw.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\zizesabo.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\lawireyo.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\pefedamu.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\rijedatu.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ruvoyenu.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\wivawira.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\lulapifi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tehayela.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\Downloaded Program Files\atmccli.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\Downloaded Program Files\atmgr.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\inf\UltraMonMirror.inf (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\inf\UltraMonMirror.PNF (Malware.Trace) -> Quarantined and deleted successfully. After the restart, I tried to then run the Kasperkey antivirus, but it wouldn't load up in my internet browser… my download allowance has been reached, so my speed has been throttled back, so I'm not sure if it has anything to do with that. Since the antivirus page wouldn't load, I then ran the steps again, and here is the results of the second run of the Malwarebytes' Anti-Malware log: Malwarebytes' Anti-Malware 1.31 Database version: 1571 Windows 5.1.2600 Service Pack 3 30/12/2008 11:02:46 AM mbam-log-2008-12-30 (11-02-46).txt Scan type: Quick Scan Objects scanned: 68685 Time elapsed: 8 minute(s), 26 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 2 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lafirozeko (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm1b075170 (Trojan.Vundo.H) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Please let me know what I need to do next, as the 2 items listed in the second log are still appearing in the "Run" section of the registry.
Do this

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder.Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left unneutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.

Hello again Rorschach112, I ran the AVP Tool by Kaspersky in Windows "Safe" mode, but it didn't find any infections. The scan took about 22 hours to complete. I have just rebooted again, and run Malwarebytes, and this is the report: Malwarebytes' Anti-Malware 1.31 Database version: 1571 Windows 5.1.2600 Service Pack 3 31/12/2008 4:57:49 PM mbam-log-2008-12-31 (16-57-49).txt Scan type: Quick Scan Objects scanned: 69476 Time elapsed: 9 minute(s), 20 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 2 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lafirozeko (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm1b075170 (Trojan.Vundo.H) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) It detects the 2 items in the regisrty and removes them, but then they appear back in the regisrty straight away… so something else must be running that is always butting them back after they get removed… When I restart, I get 2 error messages on screen, saying that the files can't be found: C:\WINDOWS\system32\soyozisu.dll & C:\windows\system32\fevihife.dll, which these are the files referenced in the registry entries mentioned above. The popups look like they have stopped now since these files have been removed, so I just need to make it that the 2 registry entries are permanently deleted so I don't get the error messages every time the computer starts. Any more help will be greatly appreciated. Thanks again…
hello

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
Hello again Rorschach112,

Here is the output from the OTListIt.txt file:
===================================


OTListIt logfile created on: 1/01/2009 11:49:43 AM - Run
OTListIt2 by OldTimer - Version 1.0.1.1 Folder = C:\Documents and Settings\Paul Senior\My Documents\Robbie\Programs\Spyware & Malware Removal
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

2.00 Gb Total Physical Memory | 1.22 Gb Available Physical Memory | 61.28% Memory free
3.85 Gb Paging File | 3.03 Gb Available in Paging File | 78.91% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 53.71 Gb Total Space | 9.50 Gb Free Space | 17.69% Space Free | Partition Type: NTFS
Drive D: | 53.37 Gb Total Space | 36.96 Gb Free Space | 69.25% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ROBBIE
Current User Name: Paul Senior
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
C:\WINDOWS\system32\TaskSwitch.exe ()
C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
C:\Program Files\D-Tools\daemon.exe (DAEMON'S HOME)
C:\Program Files\InFocus\ProjectorManager III\pmprjdet.exe (InFocus AS)
C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
C:\Program Files\UltraMon\UltraMon.exe (Realtime Soft)
C:\Program Files\UltraMon\UltraMonTaskbar.exe (Realtime Soft)
C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\CodeGear\RAD Studio\5.0\bin\BSQLServer.exe (CodeGear)
C:\Program Files\FolderSize\FolderSizeSvc.exe (Brio)
C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe (Microsoft Corporation)
C:\Program Files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe (Microsoft Corporation)
C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe (Microsoft Corporation)
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
C:\Program Files\Microsoft SQL Server\MSSQL.3\OLAP\bin\msmdsrv.exe (Microsoft Corporation)
C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
C:\Documents and Settings\Paul Senior\My Documents\Robbie\Programs\Spyware & Malware Removal\OTListIt2.exe (OldTimer Tools)

========== (O23) Win32 Services (SafeList) ==========

(aawservice [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
(Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe ()
(aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
(Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
(avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
(BlackfishSQL [Auto | Running]) – C:\Program Files\CodeGear\RAD Studio\5.0\bin\BSQLServer.exe (CodeGear)
(clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
(EvtEng [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
(FolderSize [Auto | Running]) – C:\Program Files\FolderSize\FolderSizeSvc.exe (Brio)
(FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
(gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
(IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
(idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
(Imapi Helper [On_Demand | Stopped]) – C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe (Alex Feinman)
(LVPrcSrv [Auto | Stopped]) – File not found
(mcmscsvc [Auto | Running]) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
(McNASvc [Auto | Running]) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
(McODS [On_Demand | Stopped]) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
(McProxy [Auto | Running]) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
(McShield [Unknown | Running]) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
(McSysmon [On_Demand | Running]) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
(MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe (Microsoft Corporation)
(MsDtsServer [Auto | Running]) – C:\Program Files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe (Microsoft Corporation)
(MSSQL$MICROSOFTSMLBIZ [Auto | Running]) – C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe (Microsoft Corporation)
(MSSQL$SQLEXPRESS [Auto | Running]) – C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
(MSSQLSERVER [On_Demand | Stopped]) – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
(MSSQLServerADHelper [On_Demand | Stopped]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
(MSSQLServerOLAPService [Auto | Running]) – C:\Program Files\Microsoft SQL Server\MSSQL.3\OLAP\bin\msmdsrv.exe (Microsoft Corporation)
(msvsmon80 [Disabled | Stopped]) – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)
(NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
(NICCONFIGSVC [Auto | Running]) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
(ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
(Pml Driver HPZ12 [On_Demand | Stopped]) – C:\WINDOWS\system32\hpzipm12.exe (HP)
(QBCFMonitorService [Disabled | Stopped]) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
(QBFCService [Disabled | Stopped]) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
(RegSrvc [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
(S24EventMonitor [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
(SQLAgent$MICROSOFTSMLBIZ [On_Demand | Stopped]) – C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE (Microsoft Corporation)
(SQLBrowser [Auto | Running]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
(SQLWriter [Auto | Running]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
(usnjsvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
(WLANKEEPER [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
(WLSetupSvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
(WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

(AegisP [Auto | Running]) – C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
(AliIde [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\aliide.sys (Acer Laboratories Inc.)
(amdagp [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\amdagp.sys (Advanced Micro Devices, Inc.)
(APPDRV [System | Running]) – C:\WINDOWS\system32\drivers\APPDRV.SYS (Dell Inc)
(asc [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\asc.sys (Advanced System Products, Inc.)
(asc3550 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\asc3550.sys (Advanced System Products, Inc.)
(ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
(AvgLdx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
(AvgMfx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
(bcm4sbxp [On_Demand | Running]) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
(CmdIde [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\cmdide.sys (CMD Technology, Inc.)
(CVirtA [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\CVirtA.sys (Cisco Systems, Inc.)
(d347bus [Boot | Running]) – C:\WINDOWS\system32\drivers\d347bus.sys ( )
(d347prt [Boot | Running]) – C:\WINDOWS\system32\drivers\d347prt.sys ( )
(dac2w2k [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\dac2w2k.sys (Mylex Corporation)
(drvmcdb [Boot | Running]) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
(drvnddm [Auto | Running]) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
(DSproct [On_Demand | Stopped]) – C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys (GTek Technologies Ltd.)
(E100B [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
(ENTECH [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\Entech.sys (EnTech Taiwan)
(HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
(hnmwrlspkt [Auto | Running]) – C:\WINDOWS\system32\drivers\hnm_wrls_pkt.sys (SingleClick Systems)
(HSFHWAZL [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
(HSF_DPV [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
(itchfltr [On_Demand | Running]) – C:\WINDOWS\system32\drivers\itchfltr.sys (Logitech, Inc.)
(kbdhid [System | Stopped]) – C:\WINDOWS\system32\drivers\kbdhid.sys (Microsoft Corporation)
(LCcfltr [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\LCcfltr.sys (Logitech, Inc.)
(LHidUsb [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\LHidUsb.sys (Logitech, Inc.)
(mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
(mfeavfk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
(mfebopk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
(mfehidk [System | Running]) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
(mferkdk [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
(mfesmfk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
(MPFP [System | Running]) – C:\WINDOWS\system32\drivers\Mpfp.sys (McAfee, Inc.)
(mraid35x [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\mraid35x.sys (American Megatrends Inc.)
(nv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
(omci [System | Running]) – C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)
(Packet [Auto | Running]) – C:\WINDOWS\system32\drivers\packet.sys (SingleClick Systems)
(Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
(PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\drivers\pxhelp20.sys (Sonic Solutions)
(ql1080 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql1080.sys (QLogic Corporation)
(ql12160 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql12160.sys (QLogic Corporation)
(ql1280 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql1280.sys (QLogic Corporation)
(rimmptsk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
(rimsptsk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
(rismxdp [On_Demand | Running]) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
(s24trans [Auto | Running]) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
(SASDIFSV [System | Running]) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
(SASENUM [On_Demand | Running]) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
(SASKUTIL [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
(sdbus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sdbus.sys (Microsoft Corporation)
(Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(sffdisk [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\sffdisk.sys (Microsoft Corporation)
(sffp_sd [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\sffp_sd.sys (Microsoft Corporation)
(sisagp [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sisagp.sys (Silicon Integrated Systems Corporation)
(Sparrow [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sparrow.sys (Adaptec, Inc.)
(sptd [Boot | Running]) – C:\WINDOWS\system32\drivers\sptd.sys ()
(sscdbhk5 [System | Running]) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
(ssrtln [System | Running]) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
(STHDA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
(symc810 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\symc810.sys (Symbios Logic Inc.)
(symc8xx [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\symc8xx.sys (LSI Logic)
(sym_hi [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sym_hi.sys (LSI Logic)
(sym_u3 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sym_u3.sys (LSI Logic)
(SynTP [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
(tfsnboio [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
(tfsncofs [Auto | Running]) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
(tfsndrct [Auto | Running]) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
(tfsndres [Auto | Running]) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
(tfsnifs [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
(tfsnopio [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
(tfsnpool [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
(tfsnudf [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
(tfsnudfa [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
(ultra [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ultra.sys (Promise Technology, Inc.)
(UltraMonMirror [On_Demand | Running]) – C:\WINDOWS\system32\drivers\UltraMonMirror.sys (Realtime Soft)
(UltraMonUtility [Auto | Running]) – C:\WINDOWS\system32\UltraMonUtility.sys (Realtime Soft)
(usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
(vmm [System | Running]) – C:\WINDOWS\system32\drivers\VMM.sys (Microsoft Corporation)
(VPCNetS2 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\VMNetSrv.sys (Microsoft Corporation)
(w39n51 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
(winachsf [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
(WS2IFSL [System | Running]) – C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)
(wsppkt [Auto | Running]) – C:\WINDOWS\system32\drivers\wsp_pkt.sys (SingleClick Systems)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=1061006
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com.au/hws/sb/dell-row/e…html?channel=au
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=1061006

HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=1061006
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

O1 HOSTS File: (292262 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 10047 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (no name) - {b8b41c50-5722-43c1-8b70-5b81fc830f72} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O3 - HKCU\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key does not exist or could not be opened. File not found
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe ()
O4 - HKLM..\Run: [CPM1b075170] Rundll32.exe "c:\windows\system32\fevihife.dll",a File not found
O4 - HKLM..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 (DAEMON'S HOME)
O4 - HKLM..\Run: [InFocusProjectorDetector] C:\PROGRA~1\InFocus\PROJEC~1\pmprjdet.exe (InFocus AS)
O4 - HKLM..\Run: [lafirozeko] Rundll32.exe "C:\WINDOWS\system32\soyozisu.dll",s File not found
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey (McAfee, Inc.)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\UltraMon.lnk = C:\Program Files\UltraMon\UltraMon.exe (Realtime Soft)
O4 - Startup: C:\Documents and Settings\Paul Senior\Start Menu\Programs\Startup\Extended Monitor & Laptop.lnk = C:\Documents and Settings\Paul Senior\Application Data\Realtime Soft\UltraMon\Profiles\Extended Monitor & Laptop.ump File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Sites: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: 48 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} http://192.168.10.31:2500/officescan/conso…ll/WinNTChk.cab (ObjWinNTCheck Class)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B} http://192.168.10.31:2500/officescan/conso…ll/setupini.cab (OfficeScan Corp Edition Web-Deployment SetupINICtrl Class)
O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} http://192.168.10.31:2500/officescan/conso…stall/setup.cab (OfficeScan Corp Edition Web-Deployment SetupCtrl Class)
O16 - DPF: {11818680-FCF6-11D0-9808-0800092A4865} http://www.ato.gov.au/formflow/codebase/FormCtl.cab (Adobe Form Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/3/9…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {224F7DEA-B7C1-11D3-AB40-00902712A5C9} http://www.ato.gov.au/formflow/codebase/plsspeller.cab (PLSAddin Class)
O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} http://192.168.10.31:2500/officescan/conso…root/AtxEnc.cab (Encrypt Class)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab (McAfee.com Operating System Class)
O16 - DPF: {4F3DCE50-E8E7-40AC-AB8D-99F87F1F89BD} http://192.168.10.31:2500/officescan/conso…/AtxConsole.cab (Trend Micro OfficeScan Management Console)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1177289747921 (MUWebControl Class)
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} https://transfers.ds.microsoft.com/FTM/Tran…ransferCtrl.cab (DLC Class)
O16 - DPF: {8990AFAD-D352-42AC-A72F-A660BBF6E209} http://192.168.10.31:2500/officescan/conso…/AtxConsole.cab (OfficeScan Management Console)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {A050E865-64E3-431B-8079-F0DFCEA90A2D} http://192.168.10.31:2500/officescan/conso…root/AtxPie.cab (PieChart Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CDDCFBB3-4D93-11D2-B1A9-00A0C9B742BE} http://www.ato.gov.au/formflow/codebase/scriptobject.cab (Adobe Script Object)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://freetrial.webex.com/client/T26L/webex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {EF2FB80F-0975-408E-A871-B00CC863478A} http://www.ato.gov.au/formflow/codebase/fontinstaller.cab (Adobe Soft Font Installer)
O18 - Protocol\Handler: - about - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - cdl - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - dvd - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - file - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ftp - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - gopher - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - http\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - https\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ipp - No CLSID value found
O18 - Protocol\Handler: - ipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - its - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - javascript - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - linkscanner - No CLSID value found
O18 - Protocol\Handler: - livecall - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler: - local - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mailto - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mhtml - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mk - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp - No CLSID value found
O18 - Protocol\Handler: - msdaipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ms-help - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ms-its - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ms-itss - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msnim - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mso-offdap - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - mso-offdap11 - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - res - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - sysimage - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - tv - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - vbscript - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - wia - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - See sections below for AppInitDlls and Winlogon settings
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9}C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9}C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153}C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5}C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Browseui preloader) - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Component Categories cache daemon) - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

========== HKLM Winlogon Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell" = Explorer.exe
>C:\WINDOWS\explorer.exe (Microsoft Corporation)

"UserInit" = C:\WINDOWS\SYSTEM32\Userinit.exe,
>C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

"UIHost" = logonui.exe
>C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)

"VMApplet" = rundll32 shell32,Control_RunDLL "sysdm.cpl"
>C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
>C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)


========== Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
!SASWinLogon: "DllName" = C:\Program Files\SUPERAntiSpyware\SASWINLO.dll – C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
AtiExtEvent: "DllName" = Ati2evxx.dll – C:\WINDOWS\system32\ati2evxx.dll (ATI Technologies Inc.)
crypt32chain: "DllName" = crypt32.dll – C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
cryptnet: "DllName" = cryptnet.dll – C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
cscdll: "DllName" = cscdll.dll – C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
dimsntfy: "DllName" = %SystemRoot%\System32\dimsntfy.dll – C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
ScCertProp: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Schedule: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
sclgntfy: "DllName" = sclgntfy.dll – C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
SensLogn: "DllName" = WlNotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
termsrv: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
WgaLogon: "DllName" = WgaLogon.dll – C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
wlballoon: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)

========== IFEO "Debugger" Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\]
Your Image File Name Here without a path:"Debugger" = C:\WINDOWS\system32\ntsd.exe (Microsoft Corporation)

========== Shell Execute Hooks ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}" (HKLM) – C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}" (HKLM) – C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

========== HKLM *SecurityProviders* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders" = msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
>C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
>C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
>C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)

========== LSA *Authentication Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages" = msv1_0,
>C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)

========== LSA *Security Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Security Packages" = kerberos,msv1_0,schannel,wdigest,
>C:\WINDOWS\system32\kerberos.dll (Microsoft Corporation)
>C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
>C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\system32\wdigest.dll (Microsoft Corporation)

========== Safeboot Options ==========

"AlternateShell" = cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
C:\AUTOEXEC.BAT () – [ NTFS ]

autoexec.bat [REM Dummy file for NTVDM | ]
D:\autoexec.bat () – [ NTFS ]

========== MountPoints2 ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ff4b099-5908-11dd-b941-0015c5b39fa0}\Shell]
"" = AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ff4b099-5908-11dd-b941-0015c5b39fa0}\Shell\AutoRun]
"" = Auto&Play


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ff4b099-5908-11dd-b941-0015c5b39fa0}\Shell\AutoRun\command]
"" = F:\LaunchU3.exe – File not found

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{65e88db7-f874-11dc-8837-0015c5b39fa0}\Shell]
"" = AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{65e88db7-f874-11dc-8837-0015c5b39fa0}\Shell\AutoRun]
"" = Auto&Play


========== Files/Folders - Created Within 30 Days ==========

[13 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/01/01 01:34:04 | 21,458,45248 | -HS- | C] () – C:\hiberfil.sys
[2008/12/31 20:15:00 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2008/12/31 20:14:16 | 00,000,780 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2008/12/31 20:14:12 | 00,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2008/12/31 20:14:12 | 00,000,000 | —D | C] – C:\Documents and Settings\Paul Senior\Application Data\SUPERAntiSpyware.com
[2008/12/30 10:28:37 | 00,000,000 | —D | C] – C:\Documents and Settings\Paul Senior\Application Data\Malwarebytes
[2008/12/30 10:28:34 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2008/12/30 10:28:32 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2008/12/30 10:28:31 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/12/30 10:28:30 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2008/12/30 10:17:55 | 00,165,206 | —- | C] () – C:\Documents and Settings\Paul Senior\My Documents\spyware advice.pdf
[2008/12/30 02:28:03 | 00,001,734 | —- | C] () – C:\Documents and Settings\Paul Senior\Desktop\HijackThis.lnk
[2008/12/30 02:28:01 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2008/12/29 23:43:50 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2008/12/27 19:56:56 | 00,010,520 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2008/12/27 19:56:52 | 00,097,928 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2008/12/27 19:56:45 | 00,026,824 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2008/12/27 19:56:36 | 31,322,344 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2008/12/27 19:56:36 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2008/12/27 19:56:36 | 00,368,010 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2008/12/27 19:56:36 | 00,008,170 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2008/12/27 19:56:36 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2008/12/27 19:56:18 | 00,000,000 | —D | C] – C:\Program Files\AVG
[2008/12/27 19:56:17 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg8
[2008/12/24 22:31:55 | 00,040,960 | —- | C] () – C:\Documents and Settings\Paul Senior\My Documents\Andrew & Ret.pub
[2008/12/24 22:31:38 | 00,038,400 | —- | C] () – C:\Documents and Settings\Paul Senior\My Documents\Kids.pub
[2008/12/24 21:11:42 | 00,000,000 | —D | C] – C:\Program Files\Lavasoft
[2008/12/24 21:11:42 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2008/12/24 21:08:54 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2008/12/24 17:31:37 | 00,000,000 | -HSD | C] – C:\WINDOWS\System32\twain32
[2008/12/24 01:07:55 | 00,081,196 | —- | C] () – C:\Documents and Settings\Paul Senior\Desktop\Optus contact numbers.pdf
[2008/12/24 00:40:22 | 00,000,000 | —D | C] – C:\Program Files\Vuze
[2008/12/23 01:02:57 | 00,000,000 | —D | C] – C:\Documents and Settings\Paul Senior\Desktop\Kate Miller-Heidke - Curiouser
[2008/12/22 00:03:02 | 00,000,000 | —D | C] – C:\Documents and Settings\Paul Senior\Desktop\Netgear Wireless Router (WGT634U)
[2008/12/21 23:59:24 | 00,017,761 | —- | C] () – C:\Documents and Settings\Paul Senior\My Documents\IMG_0120.JPG
[2008/12/21 23:59:17 | 00,016,270 | —- | C] () – C:\Documents and Settings\Paul Senior\My Documents\IMG_0121.JPG
[2008/12/20 20:10:23 | 00,024,576 | —- | C] () – C:\Documents and Settings\Paul Senior\Desktop\Network Details.doc
[2008/12/18 11:11:13 | 00,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2008/12/18 09:36:20 | 00,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6r.dll
[2008/12/18 09:36:19 | 01,306,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6.dll
[2008/12/18 09:36:19 | 00,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msxml6r.dll
[2008/12/18 09:36:08 | 00,046,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\irbus.sys
[2008/12/18 09:36:08 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comsdupd.exe
[2008/12/18 09:36:07 | 00,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\smtpapi.dll
[2008/12/18 09:36:07 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rwnh.dll
[2008/12/18 09:36:04 | 00,233,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\azroles.dll
[2008/12/18 09:36:04 | 00,136,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\aaclient.dll
[2008/12/18 09:36:04 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2008/12/18 09:36:03 | 00,650,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3ui.dll
[2008/12/18 09:36:03 | 00,184,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapp3hst.dll
[2008/12/18 09:36:03 | 00,180,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapphost.dll
[2008/12/18 09:36:03 | 00,132,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3svc.dll
[2008/12/18 09:36:03 | 00,126,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappcfg.dll
[2008/12/18 09:36:03 | 00,094,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappgnui.dll
[2008/12/18 09:36:03 | 00,059,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapqec.dll
[2008/12/18 09:36:03 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3cfg.dll
[2008/12/18 09:36:03 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3msm.dll
[2008/12/18 09:36:03 | 00,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dhcpqec.dll
[2008/12/18 09:36:03 | 00,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappprxy.dll
[2008/12/18 09:36:03 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3gpclnt.dll
[2008/12/18 09:36:03 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dimsroam.dll
[2008/12/18 09:36:03 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapsvc.dll
[2008/12/18 09:36:03 | 00,030,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapolqec.dll
[2008/12/18 09:36:03 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3api.dll
[2008/12/18 09:36:03 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dimsntfy.dll
[2008/12/18 09:36:03 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\credssp.dll
[2008/12/18 09:36:03 | 00,009,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3dlg.dll
[2008/12/18 09:36:01 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdbhc.dll
[2008/12/18 09:36:00 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdiultn.dll
[2008/12/18 09:35:59 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdpash.dll
[2008/12/18 09:35:59 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdnepr.dll
[2008/12/18 09:35:58 | 00,061,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kmsvc.dll
[2008/12/18 09:35:58 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\l2gpstore.dll
[2008/12/18 09:35:56 | 00,397,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcex.dll
[2008/12/18 09:35:56 | 00,184,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\microsoft.managementconsole.dll
[2008/12/18 09:35:56 | 00,106,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcfxcommon.dll
[2008/12/18 09:35:56 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcperf.exe
[2008/12/18 09:35:54 | 00,155,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mssha.dll
[2008/12/18 09:35:54 | 00,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msshavmsg.dll
[2008/12/18 09:35:53 | 00,193,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napmontr.dll
[2008/12/18 09:35:53 | 00,176,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napstat.exe
[2008/12/18 09:35:53 | 00,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napipsec.dll
[2008/12/18 09:35:51 | 00,144,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\onex.dll
[2008/12/18 09:35:48 | 00,291,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qagentrt.dll
[2008/12/18 09:35:48 | 00,150,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qagent.dll
[2008/12/18 09:35:48 | 00,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qutil.dll
[2008/12/18 09:35:48 | 00,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qcliprov.dll
[2008/12/18 09:35:48 | 00,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rasqec.dll
[2008/12/18 09:35:47 | 00,290,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rhttpaa.dll
[2008/12/18 09:35:46 | 00,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\setupn.exe
[2008/12/18 09:35:45 | 00,053,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tsgqec.dll
[2008/12/18 09:35:45 | 00,050,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tspkg.dll
[2008/12/18 09:35:40 | 00,069,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wlanapi.dll
[2008/12/18 09:35:33 | 00,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2008/12/18 09:35:32 | 00,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2008/12/18 09:35:30 | 00,000,000 | —D | C] – C:\WINDOWS\System32\en
[2008/12/18 09:35:29 | 00,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2008/12/18 09:30:37 | 00,000,000 | —D | C] – C:\WINDOWS\ServicePackFiles
[2008/12/18 09:26:32 | 00,000,000 | —D | C] – C:\WINDOWS\network diagnostic
[2008/12/18 09:26:29 | 00,064,352 | —- | C] () – C:\WINDOWS\System32\drivers\ativmc20.cod
[2008/12/18 09:26:28 | 00,101,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthpan.sys
[2008/12/18 09:26:28 | 00,037,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthmodem.sys
[2008/12/18 09:26:28 | 00,036,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthprint.sys
[2008/12/18 09:26:28 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthusb.sys
[2008/12/18 09:26:28 | 00,017,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthenum.sys
[2008/12/18 09:26:27 | 00,129,045 | —- | C] () – C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2008/12/18 09:26:27 | 00,046,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\gagp30kx.sys
[2008/12/18 09:26:27 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\hidbth.sys
[2008/12/18 09:26:27 | 00,019,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\hidir.sys
[2008/12/18 09:26:24 | 00,067,866 | —- | C] () – C:\WINDOWS\System32\drivers\netwlan5.img
[2008/12/18 09:26:24 | 00,012,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mutohpen.sys
[2008/12/18 09:26:23 | 00,059,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\rfcomm.sys
[2008/12/18 09:26:23 | 00,030,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\rndismpx.sys
[2008/12/18 09:26:22 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\sffp_mmc.sys
[2008/12/18 09:26:21 | 00,121,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\usbvideo.sys
[2008/12/18 09:26:21 | 00,044,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\uagp35.sys
[2008/12/18 09:26:21 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\usb8023x.sys
[2008/12/18 09:26:21 | 00,005,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\smbali.sys
[2008/12/18 09:26:20 | 00,014,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\wacompen.sys
[2008/12/18 09:20:00 | 00,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstall$
[2008/12/11 16:25:51 | 01,706,496 | —- | C] (Elevate Software) – C:\WINDOWS\System32\edb202d7run.bpl
[2008/12/10 14:42:53 | 00,020,964 | —- | C] () – C:\Documents and Settings\Paul Senior\My Documents\Storm2.jpg
[2008/12/09 17:07:19 | 00,014,819 | —- | C] () – C:\Documents and Settings\Paul Senior\My Documents\Preview1.pdf
[2008/12/09 16:53:21 | 00,000,048 | —- | C] () – C:\Documents and Settings\Paul Senior\My Documents\vssver.scc
[2008/12/09 15:18:05 | 00,052,736 | R— | C] () – C:\Documents and Settings\Paul Senior\My Documents\MasterSystem.xls
[2008/12/09 11:29:25 | 00,010,240 | -HS- | C] () – C:\Documents and Settings\All Users\Documents\Thumbs.db

========== Files - Modified Within 30 Days ==========

[13 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/01/01 11:42:24 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/01/01 11:40:43 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/01/01 11:40:34 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/01/01 11:40:31 | 21,458,45248 | -HS- | M] () – C:\hiberfil.sys
[2008/12/31 20:14:16 | 00,000,780 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2008/12/31 18:19:39 | 00,000,130 | —- | M] () – C:\WINDOWS\wininit.ini
[2008/12/31 16:46:52 | 31,322,344 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2008/12/30 10:44:03 | 00,006,456 | -H– | M] () – C:\WINDOWS\System32\lijiduse
[2008/12/30 10:18:00 | 00,165,206 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\spyware advice.pdf
[2008/12/30 02:28:03 | 00,001,734 | —- | M] () – C:\Documents and Settings\Paul Senior\Desktop\HijackThis.lnk
[2008/12/30 01:14:57 | 00,000,896 | —- | M] () – C:\WINDOWS\win.ini
[2008/12/30 01:14:57 | 00,000,355 | -HS- | M] () – C:\boot.ini
[2008/12/30 01:14:57 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2008/12/30 00:22:30 | 00,000,595 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\My Sharing Folders.lnk
[2008/12/29 23:32:37 | 00,292,262 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2008/12/29 23:19:59 | 00,008,170 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2008/12/29 21:48:13 | 00,118,784 | —- | M] () – C:\Documents and Settings\Paul Senior\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/27 21:11:16 | 00,368,010 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2008/12/27 19:56:56 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2008/12/27 19:56:52 | 00,097,928 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2008/12/27 19:56:45 | 00,026,824 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2008/12/27 19:56:36 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2008/12/27 18:20:31 | 00,060,212 | -HS- | M] () – C:\WINDOWS\System32\bekehutu.dll
[2008/12/24 23:34:33 | 00,038,400 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\Kids.pub
[2008/12/24 23:34:24 | 00,040,960 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\Andrew & Ret.pub
[2008/12/24 21:52:55 | 00,292,262 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20081229-233237.backup
[2008/12/24 21:46:56 | 00,292,262 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20081224-215255.backup
[2008/12/24 01:07:58 | 00,081,196 | —- | M] () – C:\Documents and Settings\Paul Senior\Desktop\Optus contact numbers.pdf
[2008/12/22 23:07:26 | 00,024,576 | —- | M] () – C:\Documents and Settings\Paul Senior\Desktop\Network Details.doc
[2008/12/22 22:09:03 | 00,000,433 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2008/12/22 00:00:00 | 00,017,761 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\IMG_0120.JPG
[2008/12/21 23:59:40 | 00,016,270 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\IMG_0121.JPG
[2008/12/19 14:13:49 | 00,000,185 | —- | M] () – C:\WINDOWS\hpbafd.ini
[2008/12/19 10:38:55 | 00,000,065 | —- | M] () – C:\WINDOWS\iTouch.ini
[2008/12/18 17:06:30 | 00,090,616 | —- | M] () – C:\Documents and Settings\Paul Senior\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008/12/18 11:14:54 | 00,755,646 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2008/12/18 11:14:54 | 00,608,336 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2008/12/18 11:14:54 | 00,137,432 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2008/12/18 11:09:51 | 00,317,952 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/12/18 11:06:53 | 00,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2008/12/18 09:25:41 | 00,250,048 | RHS- | M] () – C:\ntldr
[2008/12/17 16:13:38 | 00,002,095 | —- | M] () – C:\WINDOWS\EliteCentral.ini
[2008/12/17 15:24:18 | 00,227,324 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20081224-214656.backup
[2008/12/17 14:01:09 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2008/12/16 08:05:00 | 00,000,486 | —- | M] () – C:\WINDOWS\tasks\CopyFilesIfNotExisting.job
[2008/12/13 17:40:02 | 03,593,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2008/12/13 17:40:02 | 03,593,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2008/12/11 14:18:49 | 00,015,792 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\Preview.pdf
[2008/12/10 14:43:09 | 00,020,964 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\Storm2.jpg
[2008/12/09 17:07:19 | 00,014,819 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\Preview1.pdf
[2008/12/09 16:53:21 | 00,000,048 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\vssver.scc
[2008/12/09 16:50:46 | 00,052,736 | R— | M] () – C:\Documents and Settings\Paul Senior\My Documents\MasterSystem.xls
[2008/12/09 11:27:07 | 00,010,240 | -HS- | M] () – C:\Documents and Settings\All Users\Documents\Thumbs.db
[2008/12/08 09:22:28 | 00,001,718 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Elite Central SQL (Beta).lnk
[2008/12/05 09:20:17 | 11,268,716 | —- | M] () – C:\Documents and Settings\Paul Senior\Desktop\Walking_On_A_Dream_Sam_La_More_Remix.mp3
[2008/12/04 14:47:17 | 00,027,136 | —- | M] () – C:\Documents and Settings\Paul Senior\Desktop\Secured areas of the website.doc
[2008/12/03 19:59:06 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2008/12/03 19:59:02 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2008/12/02 16:16:16 | 00,001,278 | —- | M] () – C:\WINDOWS\TaxUnderIDE.INI

========== LOP Check ==========

[2008/12/30 10:28:31 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/01/08 17:17:21 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{15EDF4CD-698A-4E52-8278-2E25143AD95B}
[2008/02/11 10:20:33 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{6AF0EFC6-B937-4704-A430-319EB93F4C12}
[2007/05/17 12:48:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{AB3EC276-D261-4943-A921-1CC1C6799AED}
[2008/12/01 16:58:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/06/11 11:01:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2008/06/11 11:02:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/12/27 19:56:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2008/03/11 10:55:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2006/10/13 11:14:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Borland
[2008/01/11 11:56:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CodeGear
[2007/09/13 12:48:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2008/10/24 13:17:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2008/03/11 11:36:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2006/10/06 19:04:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2006/10/06 18:59:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2006/10/06 18:48:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intel
[2007/09/24 15:59:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2008/12/24 21:11:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2004/01/07 13:13:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Macrovision
[2007/09/21 09:03:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2008/12/30 10:28:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2007/02/26 08:35:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2007/02/26 08:35:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2006/12/07 12:02:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
[2008/07/04 19:02:26 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2006/11/20 12:44:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Corporation
[2008/09/12 10:11:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2007/04/23 10:49:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PreEmptive Solutions
[2008/12/11 12:44:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Quicken Elite
[2006/10/12 12:08:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Realtime Soft
[2004/08/11 20:25:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2008/12/27 18:20:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/12/31 20:15:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2008/07/20 20:57:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/10/12 10:25:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/03/13 11:15:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2008/12/30 10:28:37 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Paul Senior\Application Data
[2008/12/01 16:58:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Adobe
[2006/10/16 15:07:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\AdobeUM
[2008/04/18 15:55:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Apple Computer
[2006/10/06 18:55:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\ATI
[2008/12/27 23:10:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Azureus
[2008/01/08 12:36:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Borland
[2006/10/12 13:07:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\CyberLink
[2008/03/14 14:35:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\DivX
[2008/10/22 15:14:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Elite Practice Solutions
[2008/03/11 11:36:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Grisoft
[2006/10/06 19:04:49 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Paul Senior\Application Data\Gtek
[2007/02/26 13:04:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Help
[2004/08/11 20:20:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Identities
[2006/10/06 18:48:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Intel
[2007/09/13 13:00:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Intuit
[2008/03/09 03:04:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\KeySafe
[2008/07/04 19:02:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Lavasoft
[2006/11/22 15:18:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Leadertech
[2008/03/12 10:13:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Macromedia
[2008/12/30 10:28:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Malwarebytes
[2006/12/07 12:07:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\McAfee.com Personal Firewall
[2008/04/12 12:39:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Media Player Classic
[2008/12/24 17:41:29 | 00,000,000 | –SD | M] – C:\Documents and Settings\Paul Senior\Application Data\Microsoft
[2006/11/20 13:51:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Microsoft Corporation
[2008/03/19 09:17:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Mozilla
[2008/08/25 10:14:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Quicken Elite
[2006/10/12 12:08:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Realtime Soft
[2006/11/22 15:18:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Sonic
[2008/07/04 19:18:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\SoundSpectrum
[2006/10/17 18:51:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\Sun
[2008/12/31 20:14:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\SUPERAntiSpyware.com
[2008/01/10 17:15:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\tmssoftware
[2008/08/28 12:57:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\U3
[2008/07/16 14:15:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\VideoReDo-TVSuite
[2008/03/13 15:48:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Paul Senior\Application Data\webex
[2008/06/21 17:11:02 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2008/12/16 08:05:00 | 00,000,486 | —- | M] () – C:\WINDOWS\Tasks\CopyFilesIfNotExisting.job
[2004/08/04 08:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2007/02/26 08:29:31 | 00,000,362 | —- | M] () – C:\WINDOWS\Tasks\McDefragTask.job
[2008/07/01 02:00:00 | 00,000,364 | —- | M] () – C:\WINDOWS\Tasks\McQcTask.job
[2009/01/01 11:40:43 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2007/03/09 11:22:03 | 00,000,278 | —- | M] () – C:\WINDOWS\Tasks\shutdown.job

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 211 bytes -> %AllUsersProfile%\Application Data\TEMP:66633281
@Alternate Data Stream - 116 bytes -> %AllUsersProfile%\Application Data\TEMP:0888F409
@Alternate Data Stream - 101 bytes -> %AllUsersProfile%\Application Data\TEMP:81530E8D
@Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %UserProfile%\Desktop\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %SystemRoot%\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %AllUsersProfile%\Documents\Thumbs.db:encryptable
< End of report >


Here is the output from the Extras.txt file:
==================================


OTListIt Extras logfile created on: 1/01/2009 11:49:43 AM - Run
OTListIt2 by OldTimer - Version 1.0.1.1 Folder = C:\Documents and Settings\Paul Senior\My Documents\Robbie\Programs\Spyware & Malware Removal
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

2.00 Gb Total Physical Memory | 1.22 Gb Available Physical Memory | 61.28% Memory free
3.85 Gb Paging File | 3.03 Gb Available in Paging File | 78.91% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 53.71 Gb Total Space | 9.50 Gb Free Space | 17.69% Space Free | Partition Type: NTFS
Drive D: | 53.37 Gb Total Space | 36.96 Gb Free Space | 69.25% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ROBBIE
Current User Name: Paul Senior
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe:*:Enabled:Dell Network Assistant (SingleClick Systems)
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe:*:Enabled:javaw File not found
C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:TrueVector Service File not found
C:\Program Files\Intuit\QuickBooks 2008\QBDBMgrN.exe:*:Enabled:QuickBooks 2007 Data Manager File not found
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent (McAfee, Inc.)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) (Microsoft Corporation)
C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus File not found
C:\Program Files\InFocus\ProjectorManager III\pmprjdet.exe:*:Enabled:Projector Detector (InFocus AS)
C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus (Vuze Inc.)
C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:IEXPLORE (Microsoft Corporation)
C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe (AVG Technologies CZ, s.r.o.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01E970F7-212F-4C07-87E9-5B48C52E247D}" = Wise Owl Demeanor for .NET, Personal Edition
"{0240BDFB-2995-4A3F-8C96-18D41282B716}" = Dell Network Assistant
"{02C0BC1F-E273-4FA7-BF75-46ACF9650765}" = HP LaserJet 2410/2420/2430
"{02DFF6B1-1654-411C-8D7B-FD6052EF016F}" = Apple Software Update
"{036AA4D4-6D32-11D4-9875-00105ACE7734}" = Logitech iTouch Software
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{082BDF7B-4810-4599-BF0D-E3AC44EC8524}" = Microsoft ASP.NET 2.0 AJAX Extensions 1.0
"{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{1389C6A4-4965-4AEC-9175-08B54A10FA48}" = Microsoft SQL Server 2005 Mobile [ENU] Developer Tools
"{16F0EE77-B2B1-4417-A8CC-07E06C78CCC4}" = Matrix-ks
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1
"{1AA69CCD-1078-473A-BD6E-11CE30A81C57}" = NUnit 2.2
"{20608BFA-6068-48FE-A410-400F2A124C27}" = Microsoft SQL Server Management Studio Express
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD LE
"{23959E96-A80F-4172-A655-210E9BB7BFBE}" = MSDN Library for Visual Studio 2005
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26E1BFB0-E87E-4696-9F89-B467F01F81E5}" = Broadcom Management Programs
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3846E811-639D-4DE1-844B-30491C0A6C0C}" = Dell Support 3.2
"{3DED3A72-61A8-4B87-98A5-EF0BC8038AA0}" = DAEMON Tools
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{437AB8E0-FB69-4222-B280-A64F3DE22591}" = Microsoft Visual Studio 2005 Professional Edition - ENU
"{44D4AF75-6870-41F5-9181-662EA05507E1}" = Microsoft Document Explorer 2005
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{58D379F7-62BC-4748-8237-FE071ECE797C}" = Microsoft SQL Server 2005 Tools
"{5C741A01-05D6-4306-BA6A-DC8401285AE8}" = Debugging Tools for Windows
"{625386A4-B6B6-4911-A6E8-23189C3F2D15}" = Microsoft .NET Compact Framework 2.0
"{63A5DC0D-1EDD-4D69-8F31-87FAEB1F7084}" = Microsoft SQL Server 2005 Notification Services
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.7
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{6C531060-84FB-4F96-8F33-29DF020632EB}" = Microsoft .NET Compact Framework 1.0 SP3 Developer
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{72263053-50D1-4598-9502-51ED64E54C51}" = Borland Delphi 7
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{78B75C6D-E53C-424C-BF83-4B63BD4A6682}" = Microsoft Device Emulator version 1.0 - ENU
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A7CAA24-7B23-410B-A7C3-F994B0944160}" = Microsoft Virtual PC 2007
"{8B4AB829-DFD3-436D-B808-D9733D76C590}" = Macromedia Dreamweaver MX
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8B9F6E7C-1EEA-46C5-8BB3-DC976AED2016}" = UltraMon
"{8C62A94B-4AB6-485F-A111-93056684D340}" = SQLXML4
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{96327C3C-96BE-4C7A-A6F7-A71635E5949A}" = Microsoft SQL Server 2005 Backward compatibility
"{982DB00A-9C4E-436B-8707-18E113BAA44C}" = Microsoft SQL Server 2005 Analysis Services
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9DE9E293-5D7B-4312-88C2-BDFAEC5310AE}" = Microsoft .NET Framework 3.0
"{A02ED372-22FA-448B-AB6A-1B0FC23B7D08}" = ATI Catalyst Control Center
"{A5BA14E0-7384-11D4-BAE7-00409631A2C8}" = Macromedia Extension Manager
"{A645BC30-D32A-408B-B964-C190C9056D7A}" = Application Verifier 3.3
"{A7050037-F0EA-4BAB-BCD5-FC05507D6147}" = Alt-Tab Task Switcher Powertoy for Windows XP
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A70800000002}" = Adobe Reader 7.0.8
"{AD6CA7BC-8989-4FBC-B569-9C37B7B301D5}" = Microsoft SQL Server 2005 Books Online (English) (April 2006)
"{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}" = Windows Live Sign-in Assistant
"{B0F9497C-52B4-4686-8E73-74D866BBDF59}" = Microsoft SQL Server 2005
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B7031148-C6E7-40F6-A978-EED2E77E7D1B}" = RAD Studio
"{BA68600E-96D9-4E92-80F2-26B9681B5A63}" = Microsoft Office Outlook 2003 with Business Contact Manager Update
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{CAFE2005-7F33-477F-8257-C49D3F7C91F4}" = CaliberRM SDK
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D8DBCF67-C44C-4768-8112-9CADBAC390E6}" = HP Printer Access Tool
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{DFC6573E-124D-4026-BFA4-B433C9D3FF21}" = ISO Recorder
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ)
"{E0A41F96-7231-4AE8-A654-EEB34F935462}" = Microsoft SQL Server 2005 Integration Services
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{E9B5AFCA-3956-462F-BD05-13BC8BDF10D1}" = Rad Studio Help System
"{E9F44C98-B8B6-480F-AF7B-E42A0A46F4E3}" = Microsoft SQL Server VSS Writer
"{EB9BD1D5-8DFB-48C4-927B-10BB47CA59B3}" = Microsoft .NET Framework SDK (English) 1.1
"{EEC0D74E-1E17-443E-ACA6-2559E46F8674}" = Wise Owl Demeanor for .NET, Personal Edition 4.0
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{F9B3DD02-B0B3-42E9-8650-030DFF0D133D}" = Microsoft SQL Server Native Client
"{FC8D21C8-7B29-4104-ADB0-FEE9CA1C7922}" = Folder Size for Windows
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"1stClass 4000 for Delphi 7" = 1stClass 4000 for Delphi 7
"ActiveTouchMeetingClient" = WebEx
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AdobeESD" = Adobe Download Manager 2.0 (Remove Only)
"Anywhere PE Viewer_is1" = Anywhere PE Viewer 0.1.7
"ATI Display Driver" = ATI Display Driver
"AVG8Uninstall" = AVG Free 8.0
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"CPD 2008 XYZ Model Financial Accounts" = 2008 XYZ Model Financial Accounts
"CutePDF Writer Installation" = CutePDF Writer 2.6
"DHTML_Menu_Builder" = DHTML Menu Builder 4.10
"DVD Shrink_is1" = DVD Shrink 3.2
"ElevateDB Additional Software_is1" = ElevateDB Additional Software 2.02 Build 1
"ElevateDB VCL Standard with Source for Delphi 7_is1" = ElevateDB VCL Standard with Source 2.02 Build 1 for Delphi 7
"Elite Central" = Elite Central
"ffdshow_is1" = ffdshow [rev 1926] [2008-04-07]
"FileZilla" = FileZilla (remove only)
"GExpertsDelphi7_is1" = GExperts for Delphi 7
"GIF Movie Gear_is1" = GIF Movie Gear 4.1.2
"Go your own way" = Go your own way Screen Saver
"Heavy Weapon Deluxe 1.0" = Heavy Weapon Deluxe 1.0
"HijackThis" = HijackThis 2.0.2
"hp LaserJet 2410 2420 2430" = HP LaserJet 2410/2420/2430
"HP LaserJet 3300 Uninstaller" = hp LaserJet 3300 Uninstaller
"HTML Help Workshop" = HTML Help Workshop
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InFocusProjectorManagerIII" = InFocus AS ProjectorManager III
"InfoPower 4000 Professional for Delphi 7/Builder 7" = InfoPower 4000 Professional for Delphi 7/Builder 7
"Intrepid BankData" = Intrepid BankData
"iriver plus 3" = iriver plus 3 (remove only)
"Java Runtime 1.5.0_03" = Java Runtime 1.5.0_03 for Borland COM APIs
"LMD-Tools (Delphi 7)" = LMD-Tools (Delphi 7)
"LMD-Tools (Source)" = LMD-Tools (Source)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Uninstall Utility" = McAfee Uninstaller
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"Microsoft Document Explorer 2005" = Microsoft Document Explorer 2005
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Microsoft Visual Studio 2005 Professional Edition - ENU" = Microsoft Visual Studio 2005 Professional Edition - ENU
"Mozilla Firefox (2.0.0.12)" = Mozilla Firefox (2.0.0.12)
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSDN Library for Visual Studio 2005" = MSDN Library for Visual Studio 2005
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OJOsoft Total Video Converter2.0.0.0430" = OJOsoft Total Video Converter
"Picasa 3" = Picasa 3
"Platypus_is1" = Platypus
"Pragnaan ReportBuilder Export Devices PRO_is1" = Pragnaan ReportBuilder Export Devices PRO 2.04
"ProInst" = Intel® PROSet/Wireless Software
"Quick Report 3.6.2 Professional for Delphi 7" = Quick Report 3.6.2 Professional for Delphi 7
"RAD Studio" = RAD Studio
"Rad Studio Help System" = Rad Studio Help System
"Rave Reports_is1" = Rave Reports 6.5 BE
"Reckon Elite Central" = Reckon Elite Central
"Reckon Elite Central SQL (Beta)" = Reckon Elite Central SQL (Beta)
"ReportBuilder Professional 10.07 for Delphi 7" = ReportBuilder Professional 10.07 for Delphi 7
"ReportBuilder Professional 7.04 for Delphi 7" = ReportBuilder Professional 7.04 for Delphi 7
"SearchAssist" = SearchAssist
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Task Manager" = Task Manager
"TestTrack Pro" = TestTrack Pro
"TMS ASP.NET Component Pack for Visual Studio .NE~4049046C_is1" = TMS ASP.NET Component Pack v2.5.3.0
"TMS Component Pack for Delphi / C++ Builder for ~8FF3CABA_is1" = TMS Component Pack for Delphi / C++ Builder for VCL/ VCL.NET v4
"TMS Component Pack Help Files for C++Builder 2007 for VCL_is1" = TMS Component Pack Help Files for C++Builder 2007 for VCL v4.5
"TMS Component Pack Help Files for Delphi 2007 fo~47A9AC81_is1" = TMS Component Pack Help Files for Delphi 2007 for VCL /VCL.NET
"TMS Component Pack Help Files for Delphi 7 for VCL_is1" = TMS Component Pack Help Files for Delphi 7 for VCL v4.5
"TMS Component Pack Samples_is1" = TMS Component Pack Samples v4.5
"TurboPower Sleuth QA Suite (3.06 patch)" = TurboPower Sleuth QA Suite (3.06 patch)
"VCXD7_is1" = VssConneXion 2.0 for Delphi 7
"VideoReDoTVSuite_is1" = VideoReDo TVSuite Version 3.1.4.549
"ViewpointMediaPlayer" = Viewpoint Media Player (Remove Only)
"VistaDB 2.1 Suite_is1" = VistaDB 2.1
"Visual SourceSafe 6.0" = Microsoft Visual SourceSafe 6.0
"Vuze" = Vuze
"WIC" = Windows Imaging Component
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"Wise Installation System 9.0" = Wise Installation System 9.0
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"wPDF V2.51" = wPDF V2.51
"wPDF V2.51 SourceCode - License" = wPDF V2.51 SourceCode - License
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"ZoneAlarmSB Uninstall" = ZoneAlarm Spy Blocker

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Anywhere PE Viewer" = Anywhere PE Viewer
"GoToMeeting" = GoToMeeting 4.0.0.320

========== Last 10 Event Log Errors ==========

[ System Events ]
Error - 31/12/2008 5:51:14 AM | Computer Name = ROBBIE | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD APPDRV AvgLdx86 AvgMfx86 Fips intelppm IPSec mfehidk MPFP MRxSmb NetBIOS NetBT RasAcd Rdbss
SASDIFSV
SASKUTIL
Tcpip
vmm
WS2IFSL

Error - 31/12/2008 5:51:29 AM | Computer Name = ROBBIE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 31/12/2008 5:53:02 AM | Computer Name = ROBBIE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}

Error - 31/12/2008 5:53:03 AM | Computer Name = ROBBIE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}

Error - 31/12/2008 5:57:55 AM | Computer Name = ROBBIE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service MDM with arguments
"" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064}

Error - 31/12/2008 10:33:03 AM | Computer Name = ROBBIE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 31/12/2008 10:35:17 AM | Computer Name = ROBBIE | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 31/12/2008 10:35:49 AM | Computer Name = ROBBIE | Source = Service Control Manager | ID = 7000
Description = The Logitech Process Monitor service failed to start due to the following
error: %%2

Error - 31/12/2008 8:41:47 PM | Computer Name = ROBBIE | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 31/12/2008 8:42:20 PM | Computer Name = ROBBIE | Source = Service Control Manager | ID = 7000
Description = The Logitech Process Monitor service failed to start due to the following
error: %%2


< End of report >
hello


1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {b8b41c50-5722-43c1-8b70-5b81fc830f72} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar: (no name) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - Reg Error: Key does not exist or could not be opened. File not found
O4 - HKLM..\Run: [CPM1b075170] Rundll32.exe "c:\windows\system32\fevihife.dll",a File not found
O4 - HKLM..\Run: [lafirozeko] Rundll32.exe "C:\WINDOWS\system32\soyozisu.dll",s File not found


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.



Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    aawservice.exe
    
    :Services
    
    :Reg
    [-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ff4b099-5908-11dd-b941-0015c5b39fa0}\Shell\AutoRun\command]
    
    :files
    C:\WINDOWS\System32\twain32
    C:\WINDOWS\System32\lijiduse
    C:\WINDOWS\System32\bekehutu.dll
    
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Open OTListIt2.exe
  • Click the None button at the top
  • Under the Custom Scan box at the bottom left paste the following in

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg
    %systemroot%\Prefetch\*.* /s
    %systemroot%\system32\drivers\*.dat
    %systemroot%\Temp\bca4e2da.$$$
    %systemroot%\Temp\ed47fa.$
    %systemroot%\Temp\fa56d7ec.$$$
    %systemroot%\Temp\*.$$$
    %systemroot%\System32\antiwpa.dll
    %SYSTEMDRIVE%\*.epk
    %systemroot%\*.epk
    %systemroot%\system32\*.epk
    %systemroot%\system32\bb*.dat
    %systemroot%\system32\cookie*.dat
    %systemroot%\system32\kaxs.dat
    %systemroot%\system32\ps*.dat
    %systemroot%\system32\*32.sys
    %systemroot%\*.dr
    %SYSTEMDRIVE%\*.dr
    %systemroot%\system32\*.dr
    %systemroot%\system32\nods32.dll
    %systemroot%\*.res
    %SYSTEMDRIVE%\*.res
    %systemroot%\system32\*.res
    %systemroot%\system32\sockins32.dll
    %systemroot%\system32\Spool\*.*
    %systemroot%\system32\Spool\*.exe
    %systemroot%\system32\Spool\*.rar /s
    %systemroot%\system32\Spool\*.zip /s
    %systemroot%\system32\Spool\*.dat /s
    %ProgramFiles%\MSN Messenger\*.zip
    %ProgramFiles%\MSN Messenger\*.exe
    %ProgramFiles%\MSN Messenger\*.rar
    %PROGRAMFILES%\*crack*.
    %PROGRAMFILES%\*keygen*.
    %SYSTEMDRIVE%\*crack*.
    %SYSTEMDRIVE%\*keygen*.
    %SYSTEMDRIVE%\*.zip
    %SYSTEMDRIVE%\*.rar
    %SYSTEMDRIVE%\*.exe
    %SYSTEMDRIVE%\*.dll
    %systemroot%\*.zip
    %systemroot%\*.rar
    %systemroot%\system32\*.zip
    %systemroot%\system32\*.rar
    %PROGRAMFILES%\*.zip
    %PROGRAMFILES%\*.rar
    %PROGRAMFILES%\*.exe
    %PROGRAMFILES%\*.dll
    %DESKTOP%\*.zip
    %DESKTOP%\*.rar
    %DESKTOP%\*.exe
    %DESKTOP%\*crack*.
    %DESKTOP%\*keygen*.
    %PROGRAMFILES%\Common Files\*.*
    %PROGRAMFILES%\Common Files\*bak*.
    %systemroot%\SYSTEM32\*bak*.
    %PROGRAMFILES%\*bak*.
    %systemroot%\ime\imjp8_1\*bak*.
    %PROGRAMFILES%\QuickTime\*bak*.
    %PROGRAMFILES%\Viewpoint\Viewpoint Manager\*bak*.
    %PROGRAMFILES%\Analog Devices\Core\*bak*.
    %SYSTEMDRIVE%\hp\KBD\*bak*.
    %PROGRAMFILES%\Adobe\Photoshop Album Starter Edition\3.2\Apps\*bak*.
    %PROGRAMFILES%\BillP Studios\WinPatrol\*bak*.
    %PROGRAMFILES%\BroadJump\Client Foundation\*bak*.
    %PROGRAMFILES%\Common Files\Real\Update_OB\*bak*.
    %PROGRAMFILES%\Common Files\Sonic\Update Manager\*bak*.
    %PROGRAMFILES%\\Google\GoogleToolbarNotifier\*bak*.
    %PROGRAMFILES%\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\*bak*.
    %PROGRAMFILES%\Yahoo!\Messenger\*bak*.
    %USERNAME%\*.zip
    %USERNAME%\*.rar
    %USERNAME%\*.exe
    %USERPROFILE%\*.zip
    %USERPROFILE%\*.rar
    %USERPROFILE%\*.exe
    %ALLUSERSPROFILE%\*.zip
    %ALLUSERSPROFILE%\*.rar
    %ALLUSERSPROFILE%\*.exe
    %APPDATA%\*.zip
    %APPDATA%\*.rar
    %APPDATA%\*.exe
    %ALLUSERSSTARTMENU%\*.zip
    %ALLUSERSSTARTMENU%\*.rar
    %ALLUSERSSTARTMENU%\*.exe
    %ALLUSERSSTARTUP%\*.zip
    %ALLUSERSSTARTUP%\*.rar
    %ALLUSERSSTARTUP%\*.exe
    %ALLUSERSPROGRAMS%\*.zip
    %ALLUSERSPROGRAMS%\*.rar
    %ALLUSERSPROGRAMS%\*.exe
    %ALLUSERSAPPDATA%\*.zip
    %ALLUSERSAPPDATA%\*.rar
    %ALLUSERSAPPDATA%\*.exe
    %APPDATA%\*.zip
    %APPDATA%\*.rar
    %APPDATA%\*.exe
    %APPDATA%\*.dat
    %APPDATA%\*.dll
    %QUICKLAUNCH%\*.zip
    %QUICKLAUNCH%\*.rar
    %QUICKLAUNCH%\*.exe
    %STARTUP%\*.zip
    %STARTUP%\*.rar
    %STARTUP%\*.exe
    %STARTMENU%\*.zip
    %STARTMENU%\*.rar
    %STARTMENU%\*.exe
    %MYDOCUMENTS%\*.zip
    %MYDOCUMENTS%\*.rar
    %MYDOCUMENTS%\*.exe
    %MYDOCUMENTS%\*crack*.
    %MYDOCUMENTS%\*keygen*.
    %PROGRAMFILES%\Mozilla Firefox\plugins\*.*
    %PROGRAMFILES%\Internet Explorer\*.*
    %PROGRAMFILES%\Internet Explorer\PLUGINS\*.*
    %PROGRAMFILES%\Mozilla Firefox\*.zip /s
    %PROGRAMFILES%\Mozilla Firefox\*.rar /s
    %PROGRAMFILES%\Mozilla Firefox\*.exe /s
    %PROGRAMFILES%\Internet Explorer\*.zip /s
    %PROGRAMFILES%\Internet Explorer\*.rar /s
    %PROGRAMFILES%\Internet Explorer\*.exe /s
    %SYSTEMDRIVE%\*.dat
    %SYSTEMDRIVE%\*.sys
    %SYSTEMROOT%\*.dat
    %SYSTEMROOT%\*.sys
    %systemroot%\system32\drivers\*.exe /s
    %systemroot%\system32\drivers\*.zip /s
    %systemroot%\system32\drivers\*.rar /s
    %systemroot%\system\*.exe /s
    %systemroot%\system\*.zip /s
    %systemroot%\system\*.rar /s
    %systemroot%\AppPatch\*.exe /s
    %systemroot%\AppPatch\*.zip /s
    %systemroot%\AppPatch\*.rar /s
    %systemroot%\Cache\*.*
    %systemroot%\Downloaded Program Files\*.*
    %systemroot%\Fonts\*.exe /s
    %systemroot%\Fonts\*.zip /s
    %systemroot%\Fonts\*.rar /s
    %systemroot%\Fonts\*.dll /s
    %systemroot%\Help\*.exe /s
    %systemroot%\Help\*.zip /s
    %systemroot%\Help\*.rar /s
    %systemroot%\Tasks\*.*
    %APPDATA%\*.sys
    %APPDATA%\Google\*.*
    %systemroot%\system32\serauth1.dll
    %systemroot%\system32\serauth2.dll
    %systemroot%\system32\sysaudio.sys
    %PROGRAMFILES%\*TinyProxy*.
    HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla|extensions /rs
    %systemroot%\system32\inf\*.exe /s
    %systemroot%\system32\inf\*.zip /s
    %systemroot%\system32\inf\*.rar /s
    %systemroot%\system32\inf\*.dll /s
    %PROGRAMFILES%\Bitlord\Downloads\*.zip /s
    %PROGRAMFILES%\Bitlord\Downloads\*.rar /s
    %PROGRAMFILES%\Bitlord\Downloads\*.exe /s
    %PROGRAMFILES%\Bitlord\Downloads\*crack*.
    %PROGRAMFILES%\Bitlord\Downloads\*keygen*.
    %PROGRAMFILES%\eMule\Incoming\*.zip /s
    %PROGRAMFILES%\eMule\Incoming\*.rar /s
    %PROGRAMFILES%\eMule\Incoming\*.exe /s
    %PROGRAMFILES%\eMule\Incoming\*crack*.
    %PROGRAMFILES%\eMule\Incoming\*keygen*.
    %ProgramFiles%\Bittorent\downloads\*.zip /s
    %ProgramFiles%\Bittorent\downloads\*.exe /s
    %ProgramFiles%\Bittorent\downloads\*.rar /s
    %PROGRAMFILES%\Bittorent\Downloads\*crack*.
    %PROGRAMFILES%\Bittorent\Downloads\*keygen*.
    %ProgramFiles%\Bearshare\Shared\*.zip /s
    %ProgramFiles%\Bearshare\Shared\*.exe /s
    %ProgramFiles%\Bearshare\Shared\*.rar /s
    %ProgramFiles%\Bearshare\Shared\*crack*.
    %ProgramFiles%\Bearshare\Shared\*keygen*.
    %ProgramFiles%\Morpheus\My Shared Folder\*.zip /s
    %ProgramFiles%\Morpheus\My Shared Folder\*.exe /s
    %ProgramFiles%\Morpheus\My Shared Folder\*.rar /s
    %ProgramFiles%\Morpheus\My Shared Folder\*crack*.
    %ProgramFiles%\Morpheus\My Shared Folder\*keygen*.
    %ProgramFiles%\uTorrent\Downloads\*.zip /s
    %ProgramFiles%\uTorrent\Downloads\*.exe /s
    %ProgramFiles%\uTorrent\Downloads\*.rar /s
    %ProgramFiles%\uTorrent\Downloads\*crack*.
    %ProgramFiles%\uTorrent\Downloads\*keygen*.
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*.zip /s
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*.exe /s
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*.rar /s
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*crack*.
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*keygen*.
    %ProgramFiles%\Kazaa\My Shared Folder\*.zip /s
    %ProgramFiles%\Kazaa\My Shared Folder\*.exe /s
    %ProgramFiles%\Kazaa\My Shared Folder\*.rar /s
    %ProgramFiles%\Kazaa\My Shared Folder\*crack*.
    %ProgramFiles%\Kazaa\My Shared Folder\*keygen*.
    %ProgramFiles%\Icq\Shared Files\*.zip /s
    %ProgramFiles%\Icq\Shared Files\*.exe /s
    %ProgramFiles%\Icq\Shared Files\*.rar /s
    %ProgramFiles%\Icq\Shared Files\*crack*.
    %ProgramFiles%\Icq\Shared Files\*keygen*.
    %ProgramFiles%\Direct Connect\Received Files\*.zip /s
    %ProgramFiles%\Direct Connect\Received Files\*.exe /s
    %ProgramFiles%\Direct Connect\Received Files\*.rar /s
    %ProgramFiles%\Direct Connect\Received Files\*crack*.
    %ProgramFiles%\Direct Connect\Received Files\*keygen*.
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.zip
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.rar
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.exe
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*crack*.
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*keygen*.
    %APPDATA%\Opera\Opera\profile\widgets\*.*
    %PROGRAMFILES%\Opera\program\plugins\*.* /s
    %APPDATA%\Opera\Opera\profile\toolbar\*.* /s


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open a notepad window called OTListIt.Txt. This saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the content of this file, and post it with your next reply.
Hello again Rorschach112,

I have AVG Antivirus currently installed and running, but when I try to download OTMoveIt3, it prompts me saying that the file contains a back door trojan horse… is this correct?

I have since turned off AVG and downloaded the file, but it doesn't appear to do anything, so I'm not sure if something else is blocking it from running silently?

Although I haven't been able to run the OTMoveIt3.exe, I went onto the next step you listed, and here is the next log from OTListIt.exe:

OTListIt logfile created on: 2/01/2009 2:25:40 AM - Run 3
OTListIt2 by OldTimer - Version 1.0.1.1 Folder = C:\Documents and Settings\Paul Senior\My Documents\Robbie\Programs\Spyware & Malware Removal
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

2.00 Gb Total Physical Memory | 1.31 Gb Available Physical Memory | 65.54% Memory free
3.85 Gb Paging File | 3.13 Gb Available in Paging File | 81.34% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 53.71 Gb Total Space | 9.42 Gb Free Space | 17.53% Space Free | Partition Type: NTFS
Drive D: | 53.37 Gb Total Space | 30.27 Gb Free Space | 56.72% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ROBBIE
Current User Name: Paul Senior
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\CodeGear\RAD Studio\5.0\bin\BSQLServer.exe (CodeGear)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
C:\WINDOWS\system32\TaskSwitch.exe ()
C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
C:\Program Files\D-Tools\daemon.exe (DAEMON'S HOME)
C:\Program Files\InFocus\ProjectorManager III\pmprjdet.exe (InFocus AS)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
C:\Program Files\UltraMon\UltraMon.exe (Realtime Soft)
C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\UltraMon\UltraMonTaskbar.exe (Realtime Soft)
C:\Program Files\FolderSize\FolderSizeSvc.exe (Brio)
C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe (Microsoft Corporation)
C:\Program Files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe (Microsoft Corporation)
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe (Microsoft Corporation)
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
C:\Program Files\Microsoft SQL Server\MSSQL.3\OLAP\bin\msmdsrv.exe (Microsoft Corporation)
C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe (Microsoft Corporation)
C:\Documents and Settings\Paul Senior\My Documents\Robbie\Programs\Spyware & Malware Removal\OTListIt2.exe (OldTimer Tools)

========== (O23) Win32 Services (SafeList) ==========

(aawservice [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
(Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe ()
(aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
(Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
(avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
(BlackfishSQL [Auto | Running]) – C:\Program Files\CodeGear\RAD Studio\5.0\bin\BSQLServer.exe (CodeGear)
(clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
(EvtEng [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
(FolderSize [Auto | Running]) – C:\Program Files\FolderSize\FolderSizeSvc.exe (Brio)
(FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
(gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
(IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
(idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
(Imapi Helper [On_Demand | Stopped]) – C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe (Alex Feinman)
(LVPrcSrv [Auto | Stopped]) – File not found
(mcmscsvc [Auto | Running]) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
(McNASvc [Auto | Running]) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
(McODS [On_Demand | Stopped]) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
(McProxy [Auto | Running]) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
(McShield [Unknown | Running]) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
(McSysmon [On_Demand | Running]) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
(MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe (Microsoft Corporation)
(MsDtsServer [Auto | Running]) – C:\Program Files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe (Microsoft Corporation)
(MSSQL$MICROSOFTSMLBIZ [Auto | Running]) – C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe (Microsoft Corporation)
(MSSQL$SQLEXPRESS [Auto | Running]) – C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
(MSSQLSERVER [On_Demand | Stopped]) – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
(MSSQLServerADHelper [On_Demand | Stopped]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
(MSSQLServerOLAPService [Auto | Running]) – C:\Program Files\Microsoft SQL Server\MSSQL.3\OLAP\bin\msmdsrv.exe (Microsoft Corporation)
(msvsmon80 [Disabled | Stopped]) – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)
(NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
(NICCONFIGSVC [Auto | Running]) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
(ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
(Pml Driver HPZ12 [On_Demand | Stopped]) – C:\WINDOWS\system32\hpzipm12.exe (HP)
(QBCFMonitorService [Disabled | Stopped]) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
(QBFCService [Disabled | Stopped]) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
(RegSrvc [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
(S24EventMonitor [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
(SQLAgent$MICROSOFTSMLBIZ [On_Demand | Stopped]) – C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE (Microsoft Corporation)
(SQLBrowser [Auto | Running]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
(SQLWriter [Auto | Running]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
(usnjsvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
(WLANKEEPER [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
(WLSetupSvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
(WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

(AegisP [Auto | Running]) – C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
(AliIde [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\aliide.sys (Acer Laboratories Inc.)
(amdagp [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\amdagp.sys (Advanced Micro Devices, Inc.)
(APPDRV [System | Running]) – C:\WINDOWS\system32\drivers\APPDRV.SYS (Dell Inc)
(asc [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\asc.sys (Advanced System Products, Inc.)
(asc3550 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\asc3550.sys (Advanced System Products, Inc.)
(ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
(AvgLdx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
(AvgMfx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
(bcm4sbxp [On_Demand | Running]) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
(CmdIde [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\cmdide.sys (CMD Technology, Inc.)
(CVirtA [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\CVirtA.sys (Cisco Systems, Inc.)
(d347bus [Boot | Running]) – C:\WINDOWS\system32\drivers\d347bus.sys ( )
(d347prt [Boot | Running]) – C:\WINDOWS\system32\drivers\d347prt.sys ( )
(dac2w2k [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\dac2w2k.sys (Mylex Corporation)
(drvmcdb [Boot | Running]) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
(drvnddm [Auto | Running]) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
(DSproct [On_Demand | Stopped]) – C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys (GTek Technologies Ltd.)
(E100B [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
(ENTECH [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\Entech.sys (EnTech Taiwan)
(HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
(hnmwrlspkt [Auto | Running]) – C:\WINDOWS\system32\drivers\hnm_wrls_pkt.sys (SingleClick Systems)
(HSFHWAZL [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
(HSF_DPV [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
(itchfltr [On_Demand | Running]) – C:\WINDOWS\system32\drivers\itchfltr.sys (Logitech, Inc.)
(kbdhid [System | Stopped]) – C:\WINDOWS\system32\drivers\kbdhid.sys (Microsoft Corporation)
(LCcfltr [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\LCcfltr.sys (Logitech, Inc.)
(LHidUsb [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\LHidUsb.sys (Logitech, Inc.)
(mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
(mfeavfk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
(mfebopk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
(mfehidk [System | Running]) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
(mferkdk [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
(mfesmfk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
(MPFP [System | Running]) – C:\WINDOWS\system32\drivers\Mpfp.sys (McAfee, Inc.)
(mraid35x [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\mraid35x.sys (American Megatrends Inc.)
(nv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
(omci [System | Running]) – C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)
(Packet [Auto | Running]) – C:\WINDOWS\system32\drivers\packet.sys (SingleClick Systems)
(Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
(PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\drivers\pxhelp20.sys (Sonic Solutions)
(ql1080 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql1080.sys (QLogic Corporation)
(ql12160 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql12160.sys (QLogic Corporation)
(ql1280 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql1280.sys (QLogic Corporation)
(rimmptsk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
(rimsptsk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
(rismxdp [On_Demand | Running]) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
(s24trans [Auto | Running]) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
(sdbus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sdbus.sys (Microsoft Corporation)
(Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(sffdisk [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\sffdisk.sys (Microsoft Corporation)
(sffp_sd [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\sffp_sd.sys (Microsoft Corporation)
(sisagp [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sisagp.sys (Silicon Integrated Systems Corporation)
(Sparrow [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sparrow.sys (Adaptec, Inc.)
(sptd [Boot | Running]) – C:\WINDOWS\system32\drivers\sptd.sys ()
(sscdbhk5 [System | Running]) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
(ssrtln [System | Running]) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
(STHDA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
(symc810 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\symc810.sys (Symbios Logic Inc.)
(symc8xx [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\symc8xx.sys (LSI Logic)
(sym_hi [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sym_hi.sys (LSI Logic)
(sym_u3 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sym_u3.sys (LSI Logic)
(SynTP [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
(tfsnboio [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
(tfsncofs [Auto | Running]) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
(tfsndrct [Auto | Running]) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
(tfsndres [Auto | Running]) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
(tfsnifs [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
(tfsnopio [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
(tfsnpool [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
(tfsnudf [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
(tfsnudfa [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
(ultra [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ultra.sys (Promise Technology, Inc.)
(UltraMonMirror [On_Demand | Running]) – C:\WINDOWS\system32\drivers\UltraMonMirror.sys (Realtime Soft)
(UltraMonUtility [Auto | Running]) – C:\WINDOWS\system32\UltraMonUtility.sys (Realtime Soft)
(usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
(vmm [System | Running]) – C:\WINDOWS\system32\drivers\VMM.sys (Microsoft Corporation)
(VPCNetS2 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\VMNetSrv.sys (Microsoft Corporation)
(w39n51 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
(winachsf [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
(WS2IFSL [System | Running]) – C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)
(wsppkt [Auto | Running]) – C:\WINDOWS\system32\drivers\wsp_pkt.sys (SingleClick Systems)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=1061006
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com.au/hws/sb/dell-row/e…html?channel=au
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=1061006

HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=1061006
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

O1 HOSTS File: (292314 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 10049 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O3 - HKCU\..\Toolbar: (no name) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key does not exist or could not be opened. File not found
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe ()
O4 - HKLM..\Run: [CPM1b075170] Rundll32.exe "c:\windows\system32\fevihife.dll",a File not found
O4 - HKLM..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 (DAEMON'S HOME)
O4 - HKLM..\Run: [InFocusProjectorDetector] C:\PROGRA~1\InFocus\PROJEC~1\pmprjdet.exe (InFocus AS)
O4 - HKLM..\Run: [lafirozeko] Rundll32.exe "C:\WINDOWS\system32\soyozisu.dll",s File not found
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey (McAfee, Inc.)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\UltraMon.lnk = C:\Program Files\UltraMon\UltraMon.exe (Realtime Soft)
O4 - Startup: C:\Documents and Settings\Paul Senior\Start Menu\Programs\Startup\Extended Monitor & Laptop.lnk = C:\Documents and Settings\Paul Senior\Application Data\Realtime Soft\UltraMon\Profiles\Extended Monitor & Laptop.ump File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Sites: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: 48 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} http://192.168.10.31:2500/officescan/conso…ll/WinNTChk.cab (ObjWinNTCheck Class)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B} http://192.168.10.31:2500/officescan/conso…ll/setupini.cab (OfficeScan Corp Edition Web-Deployment SetupINICtrl Class)
O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} http://192.168.10.31:2500/officescan/conso…stall/setup.cab (OfficeScan Corp Edition Web-Deployment SetupCtrl Class)
O16 - DPF: {11818680-FCF6-11D0-9808-0800092A4865} http://www.ato.gov.au/formflow/codebase/FormCtl.cab (Adobe Form Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/3/9…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {224F7DEA-B7C1-11D3-AB40-00902712A5C9} http://www.ato.gov.au/formflow/codebase/plsspeller.cab (PLSAddin Class)
O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} http://192.168.10.31:2500/officescan/conso…root/AtxEnc.cab (Encrypt Class)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab (McAfee.com Operating System Class)
O16 - DPF: {4F3DCE50-E8E7-40AC-AB8D-99F87F1F89BD} http://192.168.10.31:2500/officescan/conso…/AtxConsole.cab (Trend Micro OfficeScan Management Console)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1177289747921 (MUWebControl Class)
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} https://transfers.ds.microsoft.com/FTM/Tran…ransferCtrl.cab (DLC Class)
O16 - DPF: {8990AFAD-D352-42AC-A72F-A660BBF6E209} http://192.168.10.31:2500/officescan/conso…/AtxConsole.cab (OfficeScan Management Console)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {A050E865-64E3-431B-8079-F0DFCEA90A2D} http://192.168.10.31:2500/officescan/conso…root/AtxPie.cab (PieChart Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CDDCFBB3-4D93-11D2-B1A9-00A0C9B742BE} http://www.ato.gov.au/formflow/codebase/scriptobject.cab (Adobe Script Object)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://freetrial.webex.com/client/T26L/webex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {EF2FB80F-0975-408E-A871-B00CC863478A} http://www.ato.gov.au/formflow/codebase/fontinstaller.cab (Adobe Soft Font Installer)
O18 - Protocol\Handler: - ipp - No CLSID value found
O18 - Protocol\Handler: - ipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - linkscanner - No CLSID value found
O18 - Protocol\Handler: - livecall - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp - No CLSID value found
O18 - Protocol\Handler: - msdaipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ms-help - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ms-itss - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msnim - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mso-offdap - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - mso-offdap11 - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - See sections below for AppInitDlls and Winlogon settings

========== Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
AtiExtEvent: "DllName" = Ati2evxx.dll – C:\WINDOWS\system32\ati2evxx.dll (ATI Technologies Inc.)

========== Safeboot Options ==========

"AlternateShell" = cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
C:\AUTOEXEC.BAT () – [ NTFS ]

autoexec.bat [REM Dummy file for NTVDM | ]
D:\autoexec.bat () – [ NTFS ]

========== MountPoints2 ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ff4b099-5908-11dd-b941-0015c5b39fa0}\Shell]
"" = AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ff4b099-5908-11dd-b941-0015c5b39fa0}\Shell\AutoRun]
"" = Auto&Play


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ff4b099-5908-11dd-b941-0015c5b39fa0}\Shell\AutoRun\command]
"" = F:\LaunchU3.exe – File not found

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{65e88db7-f874-11dc-8837-0015c5b39fa0}\Shell]
"" = AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{65e88db7-f874-11dc-8837-0015c5b39fa0}\Shell\AutoRun]
"" = Auto&Play


========== Files/Folders - Created Within 30 Days ==========

[13 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/01/02 02:15:22 | 00,001,055 | —- | C] () – C:\Documents and Settings\Paul Senior\Desktop\Shortcut to OTMoveIt3.lnk
[2009/01/02 02:09:28 | 00,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2009/01/01 18:37:56 | 00,000,000 | -HSD | C] – C:\Config.Msi
[2009/01/01 01:34:04 | 21,458,45248 | -HS- | C] () – C:\hiberfil.sys
[2008/12/31 20:15:00 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2008/12/31 20:14:12 | 00,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2008/12/31 20:14:12 | 00,000,000 | —D | C] – C:\Documents and Settings\Paul Senior\Application Data\SUPERAntiSpyware.com
[2008/12/30 10:28:37 | 00,000,000 | —D | C] – C:\Documents and Settings\Paul Senior\Application Data\Malwarebytes
[2008/12/30 10:28:34 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2008/12/30 10:28:32 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2008/12/30 10:28:31 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/12/30 10:28:30 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2008/12/30 10:17:55 | 00,165,206 | —- | C] () – C:\Documents and Settings\Paul Senior\My Documents\spyware advice.pdf
[2008/12/30 02:28:03 | 00,001,734 | —- | C] () – C:\Documents and Settings\Paul Senior\Desktop\HijackThis.lnk
[2008/12/30 02:28:01 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2008/12/29 23:43:50 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2008/12/27 19:56:56 | 00,010,520 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2008/12/27 19:56:52 | 00,097,928 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2008/12/27 19:56:45 | 00,026,824 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2008/12/27 19:56:36 | 31,322,344 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2008/12/27 19:56:36 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2008/12/27 19:56:36 | 00,368,010 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2008/12/27 19:56:36 | 00,008,170 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2008/12/27 19:56:36 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2008/12/27 19:56:18 | 00,000,000 | —D | C] – C:\Program Files\AVG
[2008/12/27 19:56:17 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg8
[2008/12/24 22:31:55 | 00,040,960 | —- | C] () – C:\Documents and Settings\Paul Senior\My Documents\Andrew & Ret.pub
[2008/12/24 22:31:38 | 00,038,400 | —- | C] () – C:\Documents and Settings\Paul Senior\My Documents\Kids.pub
[2008/12/24 21:11:42 | 00,000,000 | —D | C] – C:\Program Files\Lavasoft
[2008/12/24 21:11:42 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2008/12/24 21:08:54 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2008/12/24 17:31:37 | 00,000,000 | -HSD | C] – C:\WINDOWS\System32\twain32
[2008/12/24 01:07:55 | 00,081,196 | —- | C] () – C:\Documents and Settings\Paul Senior\Desktop\Optus contact numbers.pdf
[2008/12/24 00:40:22 | 00,000,000 | —D | C] – C:\Program Files\Vuze
[2008/12/22 00:03:02 | 00,000,000 | —D | C] – C:\Documents and Settings\Paul Senior\Desktop\Netgear Wireless Router (WGT634U)
[2008/12/21 23:59:24 | 00,017,761 | —- | C] () – C:\Documents and Settings\Paul Senior\My Documents\IMG_0120.JPG
[2008/12/21 23:59:17 | 00,016,270 | —- | C] () – C:\Documents and Settings\Paul Senior\My Documents\IMG_0121.JPG
[2008/12/20 20:10:23 | 00,024,576 | —- | C] () – C:\Documents and Settings\Paul Senior\Desktop\Network Details.doc
[2008/12/18 11:11:13 | 00,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2008/12/18 09:36:20 | 00,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6r.dll
[2008/12/18 09:36:19 | 01,306,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6.dll
[2008/12/18 09:36:19 | 00,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msxml6r.dll
[2008/12/18 09:36:08 | 00,046,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\irbus.sys
[2008/12/18 09:36:08 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comsdupd.exe
[2008/12/18 09:36:07 | 00,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\smtpapi.dll
[2008/12/18 09:36:07 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rwnh.dll
[2008/12/18 09:36:04 | 00,233,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\azroles.dll
[2008/12/18 09:36:04 | 00,136,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\aaclient.dll
[2008/12/18 09:36:04 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2008/12/18 09:36:03 | 00,650,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3ui.dll
[2008/12/18 09:36:03 | 00,184,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapp3hst.dll
[2008/12/18 09:36:03 | 00,180,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapphost.dll
[2008/12/18 09:36:03 | 00,132,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3svc.dll
[2008/12/18 09:36:03 | 00,126,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappcfg.dll
[2008/12/18 09:36:03 | 00,094,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappgnui.dll
[2008/12/18 09:36:03 | 00,059,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapqec.dll
[2008/12/18 09:36:03 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3cfg.dll
[2008/12/18 09:36:03 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3msm.dll
[2008/12/18 09:36:03 | 00,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dhcpqec.dll
[2008/12/18 09:36:03 | 00,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappprxy.dll
[2008/12/18 09:36:03 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3gpclnt.dll
[2008/12/18 09:36:03 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dimsroam.dll
[2008/12/18 09:36:03 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapsvc.dll
[2008/12/18 09:36:03 | 00,030,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapolqec.dll
[2008/12/18 09:36:03 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3api.dll
[2008/12/18 09:36:03 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dimsntfy.dll
[2008/12/18 09:36:03 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\credssp.dll
[2008/12/18 09:36:03 | 00,009,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3dlg.dll
[2008/12/18 09:36:01 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdbhc.dll
[2008/12/18 09:36:00 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdiultn.dll
[2008/12/18 09:35:59 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdpash.dll
[2008/12/18 09:35:59 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdnepr.dll
[2008/12/18 09:35:58 | 00,061,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kmsvc.dll
[2008/12/18 09:35:58 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\l2gpstore.dll
[2008/12/18 09:35:56 | 00,397,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcex.dll
[2008/12/18 09:35:56 | 00,184,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\microsoft.managementconsole.dll
[2008/12/18 09:35:56 | 00,106,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcfxcommon.dll
[2008/12/18 09:35:56 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcperf.exe
[2008/12/18 09:35:54 | 00,155,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mssha.dll
[2008/12/18 09:35:54 | 00,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msshavmsg.dll
[2008/12/18 09:35:53 | 00,193,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napmontr.dll
[2008/12/18 09:35:53 | 00,176,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napstat.exe
[2008/12/18 09:35:53 | 00,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napipsec.dll
[2008/12/18 09:35:51 | 00,144,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\onex.dll
[2008/12/18 09:35:48 | 00,291,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qagentrt.dll
[2008/12/18 09:35:48 | 00,150,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qagent.dll
[2008/12/18 09:35:48 | 00,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qutil.dll
[2008/12/18 09:35:48 | 00,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qcliprov.dll
[2008/12/18 09:35:48 | 00,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rasqec.dll
[2008/12/18 09:35:47 | 00,290,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rhttpaa.dll
[2008/12/18 09:35:46 | 00,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\setupn.exe
[2008/12/18 09:35:45 | 00,053,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tsgqec.dll
[2008/12/18 09:35:45 | 00,050,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tspkg.dll
[2008/12/18 09:35:40 | 00,069,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wlanapi.dll
[2008/12/18 09:35:33 | 00,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2008/12/18 09:35:32 | 00,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2008/12/18 09:35:30 | 00,000,000 | —D | C] – C:\WINDOWS\System32\en
[2008/12/18 09:35:29 | 00,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2008/12/18 09:30:37 | 00,000,000 | —D | C] – C:\WINDOWS\ServicePackFiles
[2008/12/18 09:26:32 | 00,000,000 | —D | C] – C:\WINDOWS\network diagnostic
[2008/12/18 09:26:29 | 00,064,352 | —- | C] () – C:\WINDOWS\System32\drivers\ativmc20.cod
[2008/12/18 09:26:28 | 00,101,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthpan.sys
[2008/12/18 09:26:28 | 00,037,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthmodem.sys
[2008/12/18 09:26:28 | 00,036,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthprint.sys
[2008/12/18 09:26:28 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthusb.sys
[2008/12/18 09:26:28 | 00,017,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthenum.sys
[2008/12/18 09:26:27 | 00,129,045 | —- | C] () – C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2008/12/18 09:26:27 | 00,046,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\gagp30kx.sys
[2008/12/18 09:26:27 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\hidbth.sys
[2008/12/18 09:26:27 | 00,019,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\hidir.sys
[2008/12/18 09:26:24 | 00,067,866 | —- | C] () – C:\WINDOWS\System32\drivers\netwlan5.img
[2008/12/18 09:26:24 | 00,012,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mutohpen.sys
[2008/12/18 09:26:23 | 00,059,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\rfcomm.sys
[2008/12/18 09:26:23 | 00,030,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\rndismpx.sys
[2008/12/18 09:26:22 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\sffp_mmc.sys
[2008/12/18 09:26:21 | 00,121,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\usbvideo.sys
[2008/12/18 09:26:21 | 00,044,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\uagp35.sys
[2008/12/18 09:26:21 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\usb8023x.sys
[2008/12/18 09:26:21 | 00,005,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\smbali.sys
[2008/12/18 09:26:20 | 00,014,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\wacompen.sys
[2008/12/18 09:20:00 | 00,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstall$
[2008/12/11 16:25:51 | 01,706,496 | —- | C] (Elevate Software) – C:\WINDOWS\System32\edb202d7run.bpl
[2008/12/10 14:42:53 | 00,020,964 | —- | C] () – C:\Documents and Settings\Paul Senior\My Documents\Storm2.jpg
[2008/12/09 17:07:19 | 00,014,819 | —- | C] () – C:\Documents and Settings\Paul Senior\My Documents\Preview1.pdf
[2008/12/09 16:53:21 | 00,000,048 | —- | C] () – C:\Documents and Settings\Paul Senior\My Documents\vssver.scc
[2008/12/09 15:18:05 | 00,052,736 | R— | C] () – C:\Documents and Settings\Paul Senior\My Documents\MasterSystem.xls
[2008/12/09 11:29:25 | 00,010,240 | -HS- | C] () – C:\Documents and Settings\All Users\Documents\Thumbs.db

========== Files - Modified Within 30 Days ==========

[13 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/01/02 02:19:39 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/01/02 02:17:35 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/01/02 02:17:12 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/01/02 02:17:04 | 21,458,45248 | -HS- | M] () – C:\hiberfil.sys
[2009/01/02 02:15:22 | 00,001,055 | —- | M] () – C:\Documents and Settings\Paul Senior\Desktop\Shortcut to OTMoveIt3.lnk
[2009/01/01 23:36:50 | 00,119,296 | —- | M] () – C:\Documents and Settings\Paul Senior\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/01 20:16:30 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/01/01 17:58:42 | 00,292,314 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2008/12/31 18:19:39 | 00,000,130 | —- | M] () – C:\WINDOWS\wininit.ini
[2008/12/31 16:46:52 | 31,322,344 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2008/12/30 10:18:00 | 00,165,206 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\spyware advice.pdf
[2008/12/30 02:28:03 | 00,001,734 | —- | M] () – C:\Documents and Settings\Paul Senior\Desktop\HijackThis.lnk
[2008/12/30 01:14:57 | 00,000,896 | —- | M] () – C:\WINDOWS\win.ini
[2008/12/30 01:14:57 | 00,000,355 | -HS- | M] () – C:\boot.ini
[2008/12/30 01:14:57 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2008/12/30 00:22:30 | 00,000,595 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\My Sharing Folders.lnk
[2008/12/29 23:32:37 | 00,292,262 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090101-175842.backup
[2008/12/29 23:19:59 | 00,008,170 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2008/12/27 21:11:16 | 00,368,010 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2008/12/27 19:56:56 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2008/12/27 19:56:52 | 00,097,928 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2008/12/27 19:56:45 | 00,026,824 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2008/12/27 19:56:36 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2008/12/27 18:20:31 | 00,060,212 | -HS- | M] () – C:\WINDOWS\System32\bekehutu.dll
[2008/12/24 23:34:33 | 00,038,400 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\Kids.pub
[2008/12/24 23:34:24 | 00,040,960 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\Andrew & Ret.pub
[2008/12/24 21:52:55 | 00,292,262 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20081229-233237.backup
[2008/12/24 21:46:56 | 00,292,262 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20081224-215255.backup
[2008/12/24 01:07:58 | 00,081,196 | —- | M] () – C:\Documents and Settings\Paul Senior\Desktop\Optus contact numbers.pdf
[2008/12/22 23:07:26 | 00,024,576 | —- | M] () – C:\Documents and Settings\Paul Senior\Desktop\Network Details.doc
[2008/12/22 22:09:03 | 00,000,433 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2008/12/22 00:00:00 | 00,017,761 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\IMG_0120.JPG
[2008/12/21 23:59:40 | 00,016,270 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\IMG_0121.JPG
[2008/12/19 14:13:49 | 00,000,185 | —- | M] () – C:\WINDOWS\hpbafd.ini
[2008/12/19 10:38:55 | 00,000,065 | —- | M] () – C:\WINDOWS\iTouch.ini
[2008/12/18 17:06:30 | 00,090,616 | —- | M] () – C:\Documents and Settings\Paul Senior\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008/12/18 11:14:54 | 00,755,646 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2008/12/18 11:14:54 | 00,608,336 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2008/12/18 11:14:54 | 00,137,432 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2008/12/18 11:09:51 | 00,317,952 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/12/18 11:06:53 | 00,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2008/12/18 09:25:41 | 00,250,048 | RHS- | M] () – C:\ntldr
[2008/12/17 16:13:38 | 00,002,095 | —- | M] () – C:\WINDOWS\EliteCentral.ini
[2008/12/17 15:24:18 | 00,227,324 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20081224-214656.backup
[2008/12/16 08:05:00 | 00,000,486 | —- | M] () – C:\WINDOWS\tasks\CopyFilesIfNotExisting.job
[2008/12/13 17:40:02 | 03,593,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2008/12/13 17:40:02 | 03,593,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2008/12/11 14:18:49 | 00,015,792 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\Preview.pdf
[2008/12/10 14:43:09 | 00,020,964 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\Storm2.jpg
[2008/12/09 17:07:19 | 00,014,819 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\Preview1.pdf
[2008/12/09 16:53:21 | 00,000,048 | —- | M] () – C:\Documents and Settings\Paul Senior\My Documents\vssver.scc
[2008/12/09 16:50:46 | 00,052,736 | R— | M] () – C:\Documents and Settings\Paul Senior\My Documents\MasterSystem.xls
[2008/12/09 11:27:07 | 00,010,240 | -HS- | M] () – C:\Documents and Settings\All Users\Documents\Thumbs.db
[2008/12/08 09:22:28 | 00,001,718 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Elite Central SQL (Beta).lnk
[2008/12/05 09:20:17 | 11,268,716 | —- | M] () – C:\Documents and Settings\Paul Senior\Desktop\Walking_On_A_Dream_Sam_La_More_Remix.mp3
[2008/12/04 14:47:17 | 00,027,136 | —- | M] () – C:\Documents and Settings\Paul Senior\Desktop\Secured areas of the website.doc
[2008/12/03 19:59:06 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2008/12/03 19:59:02 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys

========== Custom Scans ==========


< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services >

< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg >

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BuildBU]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPM1b075170]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP AutoIndexer]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP SchedIndexer]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPLJ Config]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lafirozeko]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ModemOnHold]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StatusClient]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomcatStartup]

< %systemroot%\Prefetch\*.* /s >
[2009/01/02 02:19:49 | 00,016,082 | —- | M] () – C:\WINDOWS\Prefetch\ALG.EXE-275708CF.pf
[2009/01/02 02:12:47 | 00,026,418 | —- | M] () – C:\WINDOWS\Prefetch\ATF-CLEANER.EXE-108C9540.pf
[2009/01/02 02:24:00 | 00,009,714 | —- | M] () – C:\WINDOWS\Prefetch\AVGCMGR.EXE-017B654E.pf
[2009/01/02 02:18:46 | 00,014,104 | —- | M] () – C:\WINDOWS\Prefetch\FOLDERSIZESVC.EXE-36317F2B.pf
[2009/01/02 02:19:31 | 00,017,140 | —- | M] () – C:\WINDOWS\Prefetch\FXSSVC.EXE-140862E7.pf
[2009/01/02 02:19:02 | 00,026,634 | —- | M] () – C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-241EE54E.pf
[2009/01/02 02:20:28 | 00,062,874 | —- | M] () – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf
[2009/01/02 02:19:44 | 00,017,960 | —- | M] () – C:\WINDOWS\Prefetch\IMAPI.EXE-201490BB.pf
[2008/12/31 19:54:14 | 00,266,948 | —- | M] () – C:\WINDOWS\Prefetch\layout.ini
[2009/01/02 02:16:01 | 00,018,148 | —- | M] () – C:\WINDOWS\Prefetch\LOGONUI.EXE-312BE1BF.pf
[2009/01/02 02:19:10 | 00,015,736 | —- | M] () – C:\WINDOWS\Prefetch\MCAGENT.EXE-0AA61076.pf
[2009/01/02 02:23:12 | 00,011,976 | —- | M] () – C:\WINDOWS\Prefetch\MCINFO.EXE-39905246.pf
[2009/01/02 02:18:46 | 00,020,776 | —- | M] () – C:\WINDOWS\Prefetch\MCMSCSVC.EXE-3265B629.pf
[2009/01/02 02:18:47 | 00,027,838 | —- | M] () – C:\WINDOWS\Prefetch\MCNASVC.EXE-293157C7.pf
[2009/01/02 02:18:47 | 00,032,350 | —- | M] () – C:\WINDOWS\Prefetch\MCPROXY.EXE-1643A2F9.pf
[2009/01/02 02:18:47 | 00,012,784 | —- | M] () – C:\WINDOWS\Prefetch\MCSHIELD.EXE-2222BBC3.pf
[2009/01/02 02:20:28 | 00,037,226 | —- | M] () – C:\WINDOWS\Prefetch\MCSYSMON.EXE-045A2ADD.pf
[2009/01/02 02:21:49 | 00,018,656 | —- | M] () – C:\WINDOWS\Prefetch\MCUIMGR.EXE-05B9316A.pf
[2009/01/02 02:18:47 | 00,012,678 | —- | M] () – C:\WINDOWS\Prefetch\MDM.EXE-13735E69.pf
[2009/01/02 02:18:47 | 00,046,948 | —- | M] () – C:\WINDOWS\Prefetch\MSDTSSRVR.EXE-0B2B6680.pf
[2009/01/02 02:19:18 | 00,052,522 | —- | M] () – C:\WINDOWS\Prefetch\MSMDSRV.EXE-2BF753A7.pf
[2009/01/02 02:19:21 | 00,012,800 | —- | M] () – C:\WINDOWS\Prefetch\NICCONFIGSVC.EXE-00A30C75.pf
[2009/01/02 02:18:46 | 00,774,390 | —- | M] () – C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf
[2009/01/02 02:25:26 | 00,056,034 | —- | M] () – C:\WINDOWS\Prefetch\OTLISTIT2.EXE-3AF4348D.pf
[2009/01/02 02:19:22 | 00,013,762 | —- | M] () – C:\WINDOWS\Prefetch\REGSRVC.EXE-1A4FEDDE.pf
[2009/01/02 02:19:23 | 00,011,578 | —- | M] () – C:\WINDOWS\Prefetch\SQLBROWSER.EXE-008F6C94.pf
[2009/01/02 02:19:05 | 00,037,540 | —- | M] () – C:\WINDOWS\Prefetch\SQLSERVR.EXE-1222AF1D.pf
[2009/01/02 02:18:47 | 00,025,270 | —- | M] () – C:\WINDOWS\Prefetch\SQLSERVR.EXE-2B1A681C.pf
[2009/01/02 02:19:24 | 00,008,208 | —- | M] () – C:\WINDOWS\Prefetch\SQLWRITER.EXE-066D90AE.pf
[2009/01/02 02:19:58 | 00,015,116 | —- | M] () – C:\WINDOWS\Prefetch\SVCHOST.EXE-2D5FBD18.pf
[2009/01/02 02:15:38 | 00,021,484 | —- | M] () – C:\WINDOWS\Prefetch\TASKMGR.EXE-06144C13.pf
[2009/01/02 02:20:41 | 00,037,944 | —- | M] () – C:\WINDOWS\Prefetch\WLLOGINPROXY.EXE-1423C8C5.pf
[2009/01/02 02:19:47 | 00,030,390 | —- | M] () – C:\WINDOWS\Prefetch\WMIPRVSE.EXE-0D449B4F.pf

< %systemroot%\system32\drivers\*.dat >

< %systemroot%\Temp\bca4e2da.$$$ >

< %systemroot%\Temp\ed47fa.$ >

< %systemroot%\Temp\fa56d7ec.$$$ >

< %systemroot%\Temp\*.$$$ >

< %systemroot%\System32\antiwpa.dll >

< %SYSTEMDRIVE%\*.epk >

< %systemroot%\*.epk >

< %systemroot%\system32\*.epk >

< %systemroot%\system32\bb*.dat >

< %systemroot%\system32\cookie*.dat >

< %systemroot%\system32\kaxs.dat >

< %systemroot%\system32\ps*.dat >

< %systemroot%\system32\*32.sys >

< %systemroot%\*.dr >

< %SYSTEMDRIVE%\*.dr >

< %systemroot%\system32\*.dr >

< %systemroot%\system32\nods32.dll >

< %systemroot%\*.res >

< %SYSTEMDRIVE%\*.res >

< %systemroot%\system32\*.res >

< %systemroot%\system32\sockins32.dll >

< %systemroot%\system32\Spool\*.* >

< %systemroot%\system32\Spool\*.exe >

< %systemroot%\system32\Spool\*.rar /s >

< %systemroot%\system32\Spool\*.zip /s >

< %systemroot%\system32\Spool\*.dat /s >

< %ProgramFiles%\MSN Messenger\*.zip >

< %ProgramFiles%\MSN Messenger\*.exe >

< %ProgramFiles%\MSN Messenger\*.rar >

< %PROGRAMFILES%\*crack*. >
[2008/12/31 20:14:12 | 00,000,000 | R–D | M] – C:\Program Files

< %PROGRAMFILES%\*keygen*. >
[2008/12/31 20:14:12 | 00,000,000 | R–D | M] – C:\Program Files

< %SYSTEMDRIVE%\*crack*. >
[2009/01/02 02:08:58 | 00,000,000 | —D | M] – C:

< %SYSTEMDRIVE%\*keygen*. >
[2009/01/02 02:08:58 | 00,000,000 | —D | M] – C:

< %SYSTEMDRIVE%\*.zip >
[2008/08/11 09:53:36 | 03,788,905 | —- | M] () – C:\ELITE BACKUP 11_08_2008.ZIP

< %SYSTEMDRIVE%\*.rar >

< %SYSTEMDRIVE%\*.exe >

< %SYSTEMDRIVE%\*.dll >

< %systemroot%\*.zip >

< %systemroot%\*.rar >

< %systemroot%\system32\*.zip >

< %systemroot%\system32\*.rar >

< %PROGRAMFILES%\*.zip >

< %PROGRAMFILES%\*.rar >

< %PROGRAMFILES%\*.exe >
[2006/09/15 15:56:03 | 00,705,536 | —- | M] () – C:\Program Files\CopyFilesIfNotExisting.exe

< %PROGRAMFILES%\*.dll >

Invalid Environment Variable: DESKTOP

Invalid Environment Variable: DESKTOP

Invalid Environment Variable: DESKTOP

Invalid Environment Variable: DESKTOP

Invalid Environment Variable: DESKTOP

< %PROGRAMFILES%\Common Files\*.* >

< %PROGRAMFILES%\Common Files\*bak*. >
[2008/12/24 21:08:54 | 00,000,000 | —D | M] – C:\Program Files\Common Files

< %systemroot%\SYSTEM32\*bak*. >
[13 C:\WINDOWS\SYSTEM32\*.tmp files]
[2009/01/02 02:05:27 | 00,000,000 | —D | M] – C:\WINDOWS\SYSTEM32

< %PROGRAMFILES%\*bak*. >
[2008/12/31 20:14:12 | 00,000,000 | R–D | M] – C:\Program Files

< %systemroot%\ime\imjp8_1\*bak*. >
[2008/12/18 09:30:06 | 00,000,000 | —D | M] – C:\WINDOWS\ime\imjp8_1

< %PROGRAMFILES%\QuickTime\*bak*. >
[2008/06/11 11:02:55 | 00,000,000 | —D | M] – C:\Program Files\QuickTime

< %PROGRAMFILES%\Viewpoint\Viewpoint Manager\*bak*. >

< %PROGRAMFILES%\Analog Devices\Core\*bak*. >

< %SYSTEMDRIVE%\hp\KBD\*bak*. >

< %PROGRAMFILES%\Adobe\Photoshop Album Starter Edition\3.2\Apps\*bak*. >

< %PROGRAMFILES%\BillP Studios\WinPatrol\*bak*. >

< %PROGRAMFILES%\BroadJump\Client Foundation\*bak*. >

< %PROGRAMFILES%\Common Files\Real\Update_OB\*bak*. >

< %PROGRAMFILES%\Common Files\Sonic\Update Manager\*bak*. >

< %PROGRAMFILES%\\Google\GoogleToolbarNotifier\*bak*. >

< %PROGRAMFILES%\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\*bak*. >

< %PROGRAMFILES%\Yahoo!\Messenger\*bak*. >

< %USERNAME%\*.zip >

< %USERNAME%\*.rar >

< %USERNAME%\*.exe >

< %USERPROFILE%\*.zip >

< %USERPROFILE%\*.rar >

< %USERPROFILE%\*.exe >
[2008/10/29 10:17:26 | 00,060,744 | —- | M] () – C:\Documents and Settings\Paul Senior\g2mdlhlpx.exe

< %ALLUSERSPROFILE%\*.zip >

< %ALLUSERSPROFILE%\*.rar >

< %ALLUSERSPROFILE%\*.exe >

< %APPDATA%\*.zip >

< %APPDATA%\*.rar >

< %APPDATA%\*.exe >

Invalid Environment Variable: ALLUSERSSTARTMENU

Invalid Environment Variable: ALLUSERSSTARTMENU

Invalid Environment Variable: ALLUSERSSTARTMENU

Invalid Environment Variable: ALLUSERSSTARTUP

Invalid Environment Variable: ALLUSERSSTARTUP

Invalid Environment Variable: ALLUSERSSTARTUP

Invalid Environment Variable: ALLUSERSPROGRAMS

Invalid Environment Variable: ALLUSERSPROGRAMS

Invalid Environment Variable: ALLUSERSPROGRAMS

Invalid Environment Variable: ALLUSERSAPPDATA

Invalid Environment Variable: ALLUSERSAPPDATA

Invalid Environment Variable: ALLUSERSAPPDATA

< %APPDATA%\*.zip >

< %APPDATA%\*.rar >

< %APPDATA%\*.exe >

< %APPDATA%\*.dat >

< %APPDATA%\*.dll >

Invalid Environment Variable: QUICKLAUNCH

Invalid Environment Variable: QUICKLAUNCH

Invalid Environment Variable: QUICKLAUNCH

Invalid Environment Variable: STARTUP

Invalid Environment Variable: STARTUP

Invalid Environment Variable: STARTUP

Invalid Environment Variable: STARTMENU

Invalid Environment Variable: STARTMENU

Invalid Environment Variable: STARTMENU

Invalid Environment Variable: MYDOCUMENTS

Invalid Environment Variable: MYDOCUMENTS

Invalid Environment Variable: MYDOCUMENTS

Invalid Environment Variable: MYDOCUMENTS

Invalid Environment Variable: MYDOCUMENTS

< %PROGRAMFILES%\Mozilla Firefox\plugins\*.* >
[2008/02/02 21:07:55 | 00,022,664 | —- | M] (mozilla.org) – C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2007/03/22 20:23:30 | 00,017,248 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
[2008/06/11 11:03:12 | 00,004,208 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\QuickTimePlugin.class

< %PROGRAMFILES%\Internet Explorer\*.* >
[2006/10/27 15:09:58 | 00,033,792 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\custsat.dll
[2006/10/17 12:44:36 | 00,060,416 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\hmmapi.dll
[2006/10/17 13:04:50 | 00,069,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iedw.exe
[2006/10/27 15:09:58 | 00,287,744 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\ieproxy.dll
[2008/10/15 18:06:26 | 00,633,632 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe

< %PROGRAMFILES%\Internet Explorer\PLUGINS\*.* >
[2008/06/11 11:03:12 | 00,004,208 | —- | M] () – C:\Program Files\Internet Explorer\PLUGINS\QuickTimePlugin.class

< %PROGRAMFILES%\Mozilla Firefox\*.zip /s >

< %PROGRAMFILES%\Mozilla Firefox\*.rar /s >

< %PROGRAMFILES%\Mozilla Firefox\*.exe /s >
[2008/02/02 21:07:41 | 07,655,024 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
[2008/02/02 21:07:47 | 00,132,232 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\updater.exe
[2008/02/02 21:07:50 | 00,073,336 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\xpicleanup.exe
[2008/02/02 21:07:39 | 00,450,936 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\uninstall\helper.exe

< %PROGRAMFILES%\Internet Explorer\*.zip /s >

< %PROGRAMFILES%\Internet Explorer\*.rar /s >

< %PROGRAMFILES%\Internet Explorer\*.exe /s >
[2006/10/17 13:04:50 | 00,069,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iedw.exe
[2008/10/15 18:06:26 | 00,633,632 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe
[2008/04/14 05:42:24 | 00,214,528 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe
[2008/04/14 05:42:24 | 00,086,016 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\Connection Wizard\icwconn2.exe
[2008/04/14 05:42:24 | 00,024,576 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\Connection Wizard\icwrmind.exe
[2004/08/04 08:00:00 | 00,073,728 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\Connection Wizard\icwtutor.exe
[2008/04/14 05:42:24 | 00,020,480 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\Connection Wizard\inetwiz.exe
[2004/08/04 08:00:00 | 00,016,384 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\Connection Wizard\isignup.exe

< %SYSTEMDRIVE%\*.dat >

< %SYSTEMDRIVE%\*.sys >
[2004/08/11 20:15:00 | 00,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/01/02 02:17:04 | 21,458,45248 | -HS- | M] () – C:\hiberfil.sys
[2004/08/11 20:15:00 | 00,000,000 | -H– | M] () – C:\IO.SYS
[2004/08/11 20:15:00 | 00,000,000 | -H– | M] () – C:\MSDOS.SYS
[2009/01/02 02:17:00 | 21,453,86496 | -HS- | M] () – C:\pagefile.sys

< %SYSTEMROOT%\*.dat >
[2009/01/02 02:17:12 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2008/03/19 09:18:07 | 00,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2008/04/11 19:47:17 | 00,000,017 | —- | M] () – C:\WINDOWS\popcinfo.dat
[3 C:\WINDOWS\*.tmp files]

< %SYSTEMROOT%\*.sys >

< %systemroot%\system32\drivers\*.exe /s >

< %systemroot%\system32\drivers\*.zip /s >

< %systemroot%\system32\drivers\*.rar /s >

< %systemroot%\system\*.exe /s >

< %systemroot%\system\*.zip /s >

< %systemroot%\system\*.rar /s >

< %systemroot%\AppPatch\*.exe /s >

< %systemroot%\AppPatch\*.zip /s >

< %systemroot%\AppPatch\*.rar /s >

< %systemroot%\Cache\*.* >

< %systemroot%\Downloaded Program Files\*.* >
[2008/03/13 15:47:22 | 00,214,344 | —- | M] () – C:\WINDOWS\Downloaded Program Files\atcliun.exe
[2008/03/13 15:46:35 | 00,027,976 | —- | M] () – C:\WINDOWS\Downloaded Program Files\atgpcdec.dll
[2008/03/13 15:46:37 | 00,125,848 | —- | M] () – C:\WINDOWS\Downloaded Program Files\atgpcext.dll
[2006/02/07 15:37:16 | 00,573,440 | —- | M] () – C:\WINDOWS\Downloaded Program Files\AtxConsole.ocx
[2008/05/09 20:37:34 | 00,161,056 | —- | M] () – C:\WINDOWS\Downloaded Program Files\AtxEnc.dll
[2008/05/09 20:37:36 | 00,177,440 | —- | M] () – C:\WINDOWS\Downloaded Program Files\AtxPie.dll
[2002/11/29 16:15:52 | 00,163,840 | —- | M] () – C:\WINDOWS\Downloaded Program Files\axscrcalc.dll
[2002/11/29 01:24:26 | 00,024,064 | —- | M] () – C:\WINDOWS\Downloaded Program Files\bmpflt32.dll
[2007/04/12 09:01:44 | 00,001,024 | —- | M] () – C:\WINDOWS\Downloaded Program Files\custom.eng
[2004/08/11 20:13:34 | 00,000,065 | -H– | M] () – C:\WINDOWS\Downloaded Program Files\desktop.ini
[2006/02/22 15:26:38 | 00,001,505 | —- | M] () – C:\WINDOWS\Downloaded Program Files\dlc.inf
[2002/07/25 21:13:18 | 00,024,576 | —- | M] () – C:\WINDOWS\Downloaded Program Files\dwusplay.dll
[2002/07/25 21:13:12 | 00,196,608 | —- | M] () – C:\WINDOWS\Downloaded Program Files\dwusplay.exe
[2002/11/29 01:21:16 | 00,016,369 | —- | M] () – C:\WINDOWS\Downloaded Program Files\eng.clx
[2002/11/29 01:21:16 | 00,297,984 | —- | M] () – C:\WINDOWS\Downloaded Program Files\eng.lex
[2002/11/29 01:21:16 | 00,002,467 | —- | M] () – C:\WINDOWS\Downloaded Program Files\eng.phn
[2002/11/29 16:02:06 | 00,077,824 | —- | M] () – C:\WINDOWS\Downloaded Program Files\EUCresen.dll
[2002/11/29 17:08:16 | 00,208,896 | —- | M] () – C:\WINDOWS\Downloaded Program Files\FileDlg.dll
[2002/11/29 17:40:10 | 00,450,560 | —- | M] () – C:\WINDOWS\Downloaded Program Files\FontInstaller.dll
[2002/11/29 16:01:26 | 00,000,924 | —- | M] () – C:\WINDOWS\Downloaded Program Files\FontInstaller.inf
[2002/11/29 16:57:20 | 01,515,520 | —- | M] () – C:\WINDOWS\Downloaded Program Files\FormCtl.dll
[2002/11/29 16:01:26 | 00,007,647 | —- | M] () – C:\WINDOWS\Downloaded Program Files\FormCtl.inf
[2006/02/15 10:33:50 | 00,144,716 | —- | M] () – C:\WINDOWS\Downloaded Program Files\ftm_en-us.xml
[2006/02/15 10:34:30 | 00,005,524 | —- | M] () – C:\WINDOWS\Downloaded Program Files\ftm_LanguageList.xml
[2002/11/29 01:24:26 | 00,033,792 | —- | M] () – C:\WINDOWS\Downloaded Program Files\gifflt32.dll
[2008/03/13 15:47:53 | 00,013,471 | —- | M] () – C:\WINDOWS\Downloaded Program Files\gpc.php
[2006/02/22 14:57:26 | 00,092,960 | —- | M] () – C:\WINDOWS\Downloaded Program Files\grTransferCtrl.dll
[2006/02/22 20:00:00 | 00,539,424 | —- | M] () – C:\WINDOWS\Downloaded Program Files\grTransferMgr.dll
[2008/02/28 10:32:22 | 00,098,712 | —- | M] () – C:\WINDOWS\Downloaded Program Files\ieatgpc.dll
[2007/02/14 13:54:48 | 00,000,267 | —- | M] () – C:\WINDOWS\Downloaded Program Files\ieatgpc.inf
[2002/11/29 16:04:26 | 00,122,880 | —- | M] () – C:\WINDOWS\Downloaded Program Files\IEncryption.dll
[2002/11/29 16:05:02 | 00,180,224 | —- | M] () – C:\WINDOWS\Downloaded Program Files\iocom.dll
[2004/07/27 19:48:52 | 00,323,584 | —- | M] () – C:\WINDOWS\Downloaded Program Files\isusweb.dll
[2002/11/29 16:10:44 | 00,299,008 | —- | M] () – C:\WINDOWS\Downloaded Program Files\jf4calc.dll
[2002/11/29 16:03:52 | 00,126,976 | —- | M] () – C:\WINDOWS\Downloaded Program Files\jfAddin.dll
[2002/11/29 16:21:34 | 00,241,664 | —- | M] () – C:\WINDOWS\Downloaded Program Files\jfBoiler.dll
[2002/12/17 17:50:10 | 00,815,104 | —- | M] () – C:\WINDOWS\Downloaded Program Files\jfControls.dll
[2002/11/29 16:22:58 | 00,667,648 | —- | M] () – C:\WINDOWS\Downloaded Program Files\jfDataSource.dll
[2002/12/12 17:17:28 | 00,405,504 | —- | M] () – C:\WINDOWS\Downloaded Program Files\jfDateTime.dll
[2002/11/29 17:14:26 | 00,143,360 | —- | M] () – C:\WINDOWS\Downloaded Program Files\jfForceUpdate.dll
[2002/12/12 17:19:12 | 00,299,008 | —- | M] () – C:\WINDOWS\Downloaded Program Files\jfMaskedEdit.dll
[2002/11/29 01:24:26 | 00,044,544 | —- | M] () – C:\WINDOWS\Downloaded Program Files\jpgflt32.dll
[2006/12/11 16:44:00 | 00,000,367 | —- | M] () – C:\WINDOWS\Downloaded Program Files\LegitCheckControl.inf
[2005/04/13 14:46:10 | 00,000,678 | —- | M] () – C:\WINDOWS\Downloaded Program Files\mcinsctl.inf
[2007/02/23 00:41:12 | 00,304,544 | —- | M] () – C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll
[2005/05/26 05:19:32 | 00,000,293 | —- | M] () – C:\WINDOWS\Downloaded Program Files\muweb.inf
[2006/02/07 16:26:54 | 00,106,599 | —- | M] () – C:\WINDOWS\Downloaded Program Files\OfficeScanSetup.dll
[2004/03/05 15:19:50 | 00,000,482 | —- | M] () – C:\WINDOWS\Downloaded Program Files\OfficeScanSetup.inf
[2006/02/07 16:27:06 | 00,147,565 | —- | M] () – C:\WINDOWS\Downloaded Program Files\OfficeScanSetupINI.dll
[2003/05/02 12:07:44 | 00,000,254 | —- | M] () – C:\WINDOWS\Downloaded Program Files\OfficeScanSetupINI.inf
[2002/11/29 17:45:04 | 00,364,544 | —- | M] () – C:\WINDOWS\Downloaded Program Files\PLSSpeller.dll
[2002/11/29 02:12:14 | 00,008,777 | —- | M] () – C:\WINDOWS\Downloaded Program Files\PLSSpeller.hlp
[2002/11/29 16:01:30 | 00,001,738 | —- | M] () – C:\WINDOWS\Downloaded Program Files\PLSSpeller.inf
[2008/03/28 22:33:56 | 00,000,144 | —- | M] () – C:\WINDOWS\Downloaded Program Files\QTPlugin.inf
[2002/11/29 01:03:28 | 00,079,415 | —- | M] () – C:\WINDOWS\Downloaded Program Files\resourcesen.dll
[2002/11/29 16:37:22 | 01,224,704 | —- | M] () – C:\WINDOWS\Downloaded Program Files\RichEdit.dll
[2002/11/29 17:11:24 | 00,163,840 | —- | M] () – C:\WINDOWS\Downloaded Program Files\ScriptObject.dll
[2002/11/29 16:01:30 | 00,000,947 | —- | M] () – C:\WINDOWS\Downloaded Program Files\ScriptObject.inf
[2002/11/29 17:10:36 | 00,200,704 | —- | M] () – C:\WINDOWS\Downloaded Program Files\SvrCopy.dll
[2006/11/09 14:36:12 | 00,005,019 | —- | M] () – C:\WINDOWS\Downloaded Program Files\swflash.inf
[2002/11/29 01:24:28 | 00,050,176 | —- | M] () – C:\WINDOWS\Downloaded Program Files\tifflt32.dll
[2006/02/22 14:57:28 | 00,428,904 | —- | M] () – C:\WINDOWS\Downloaded Program Files\TransferMgr.exe
[2006/02/07 16:27:18 | 00,053,347 | —- | M] () – C:\WINDOWS\Downloaded Program Files\WinNTChk.dll
[2002/11/29 16:14:18 | 00,684,032 | —- | M] () – C:\WINDOWS\Downloaded Program Files\xftcom.dll
[2002/12/11 14:45:04 | 00,245,760 | —- | M] () – C:\WINDOWS\Downloaded Program Files\XMLSubmit.dll
[2002/11/29 16:11:32 | 00,434,176 | —- | M] () – C:\WINDOWS\Downloaded Program Files\xocom.dll

< %systemroot%\Fonts\*.exe /s >

< %systemroot%\Fonts\*.zip /s >

< %systemroot%\Fonts\*.rar /s >

< %systemroot%\Fonts\*.dll /s >

< %systemroot%\Help\*.exe /s >
[2006/08/21 15:57:14 | 01,077,321 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Help\SBSI\Training\orun32.exe
[2001/06/11 20:19:04 | 00,233,472 | —- | M] (Microsoft and LearnIT Corporation) – C:\WINDOWS\Help\SBSI\Training\ounins32_s.exe
[2001/11/07 15:28:32 | 00,049,152 | —- | M] () – C:\WINDOWS\Help\SBSI\Training\usersid.exe
[2004/08/04 08:00:00 | 03,374,640 | —- | M] (Macromedia, Inc.) – C:\WINDOWS\Help\Tours\mmTour\tour.exe

< %systemroot%\Help\*.zip /s >

< %systemroot%\Help\*.rar /s >

< %systemroot%\Tasks\*.* >
[2008/06/21 17:11:02 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2008/12/16 08:05:00 | 00,000,486 | —- | M] () – C:\WINDOWS\Tasks\CopyFilesIfNotExisting.job
[2004/08/04 08:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2007/02/26 08:29:31 | 00,000,362 | —- | M] () – C:\WINDOWS\Tasks\McDefragTask.job
[2008/07/01 02:00:00 | 00,000,364 | —- | M] () – C:\WINDOWS\Tasks\McQcTask.job
[2009/01/02 02:17:35 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2007/03/09 11:22:03 | 00,000,278 | —- | M] () – C:\WINDOWS\Tasks\shutdown.job

< %APPDATA%\*.sys >

< %APPDATA%\Google\*.* >

< %systemroot%\system32\serauth1.dll >

< %systemroot%\system32\serauth2.dll >

< %systemroot%\system32\sysaudio.sys >

< %PROGRAMFILES%\*TinyProxy*. >
[2008/12/31 20:14:12 | 00,000,000 | R–D | M] – C:\Program Files

< HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla|extensions /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71} -> %ProgramFiles%\AVG\AVG8\Firefox [C:\PROGRAM FILES\AVG\AVG8\FIREFOX] -> [2008/12/27 19:56:18 00,000,000 | —D | M]
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 2.0.0.12\extensions\\Components -> %ProgramFiles%\Mozilla Firefox\components [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2008/06/11 11:03:13 00,000,000 | —D | M]
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 2.0.0.12\extensions\\Plugins -> %ProgramFiles%\Mozilla Firefox\plugins [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2008/08/05 11:14:27 00,000,000 | —D | M]

< %systemroot%\system32\inf\*.exe /s >

< %systemroot%\system32\inf\*.zip /s >

< %systemroot%\system32\inf\*.rar /s >

< %systemroot%\system32\inf\*.dll /s >

< %PROGRAMFILES%\Bitlord\Downloads\*.zip /s >

< %PROGRAMFILES%\Bitlord\Downloads\*.rar /s >

< %PROGRAMFILES%\Bitlord\Downloads\*.exe /s >

< %PROGRAMFILES%\Bitlord\Downloads\*crack*. >

< %PROGRAMFILES%\Bitlord\Downloads\*keygen*. >

< %PROGRAMFILES%\eMule\Incoming\*.zip /s >

< %PROGRAMFILES%\eMule\Incoming\*.rar /s >

< %PROGRAMFILES%\eMule\Incoming\*.exe /s >

< %PROGRAMFILES%\eMule\Incoming\*crack*. >

< %PROGRAMFILES%\eMule\Incoming\*keygen*. >

< %ProgramFiles%\Bittorent\downloads\*.zip /s >

< %ProgramFiles%\Bittorent\downloads\*.exe /s >

< %ProgramFiles%\Bittorent\downloads\*.rar /s >

< %PROGRAMFILES%\Bittorent\Downloads\*crack*. >

< %PROGRAMFILES%\Bittorent\Downloads\*keygen*. >

< %ProgramFiles%\Bearshare\Shared\*.zip /s >

< %ProgramFiles%\Bearshare\Shared\*.exe /s >

< %ProgramFiles%\Bearshare\Shared\*.rar /s >

< %ProgramFiles%\Bearshare\Shared\*crack*. >

< %ProgramFiles%\Bearshare\Shared\*keygen*. >

< %ProgramFiles%\Morpheus\My Shared Folder\*.zip /s >

< %ProgramFiles%\Morpheus\My Shared Folder\*.exe /s >

< %ProgramFiles%\Morpheus\My Shared Folder\*.rar /s >

< %ProgramFiles%\Morpheus\My Shared Folder\*crack*. >

< %ProgramFiles%\Morpheus\My Shared Folder\*keygen*. >

< %ProgramFiles%\uTorrent\Downloads\*.zip /s >

< %ProgramFiles%\uTorrent\Downloads\*.exe /s >

< %ProgramFiles%\uTorrent\Downloads\*.rar /s >

< %ProgramFiles%\uTorrent\Downloads\*crack*. >

< %ProgramFiles%\uTorrent\Downloads\*keygen*. >

< %ProgramFiles%\Kazaa Lite\My Shared Folder\*.zip /s >

< %ProgramFiles%\Kazaa Lite\My Shared Folder\*.exe /s >

< %ProgramFiles%\Kazaa Lite\My Shared Folder\*.rar /s >

< %ProgramFiles%\Kazaa Lite\My Shared Folder\*crack*. >

< %ProgramFiles%\Kazaa Lite\My Shared Folder\*keygen*. >

< %ProgramFiles%\Kazaa\My Shared Folder\*.zip /s >

< %ProgramFiles%\Kazaa\My Shared Folder\*.exe /s >

< %ProgramFiles%\Kazaa\My Shared Folder\*.rar /s >

< %ProgramFiles%\Kazaa\My Shared Folder\*crack*. >

< %ProgramFiles%\Kazaa\My Shared Folder\*keygen*. >

< %ProgramFiles%\Icq\Shared Files\*.zip /s >

< %ProgramFiles%\Icq\Shared Files\*.exe /s >

< %ProgramFiles%\Icq\Shared Files\*.rar /s >

< %ProgramFiles%\Icq\Shared Files\*crack*. >

< %ProgramFiles%\Icq\Shared Files\*keygen*. >

< %ProgramFiles%\Direct Connect\Received Files\*.zip /s >

< %ProgramFiles%\Direct Connect\Received Files\*.exe /s >

< %ProgramFiles%\Direct Connect\Received Files\*.rar /s >

< %ProgramFiles%\Direct Connect\Received Files\*crack*. >

< %ProgramFiles%\Direct Connect\Received Files\*keygen*. >

< %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.zip >

< %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.rar >

< %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.exe >

< %ALLUSERSPROFILE%\Application Data\AOL Downloads\*crack*. >

< %ALLUSERSPROFILE%\Application Data\AOL Downloads\*keygen*. >

< %APPDATA%\Opera\Opera\profile\widgets\*.* >

< %PROGRAMFILES%\Opera\program\plugins\*.* /s >

< %APPDATA%\Opera\Opera\profile\toolbar\*.* /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %UserProfile%\Desktop\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %SystemRoot%\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %AllUsersProfile%\Documents\Thumbs.db:encryptable
< End of report >
Hello Rorschach112,

I think I may have fix my problem of the 2 registry items that were automatically getting put back in there once they were deleted… I had the TeaTimer functionality of SpyBot running, and had noticed that when things in the registry were getting changed, that it would prompt for confirmation, and I thought that I must have allowed the change for those two items at some point (without really knowing what they were) and set the option to "Always Allow". To try and catch the changes to registry, I uninstalled SpyBot and then re-started (and the two missing file prompts continued to appear), then re-installed SpyBot with TeaTimer, then ran HijackThis and checked those 2 RunDLL items from the registry and clicked [Fix]. TeaTimer prompted me with a confirmation that a change was getting made to those registry items, with the old data, and the new data of "". I allowed this change to remove those items, and was expecting another prompt from TeaTimer to appear with the items getting added again (in which I was going to select "Block", but nothing appeared. I restarted the computer, and the missing file "RunDLL" prompts no longer appeared, and then running HijackThis again showed those items no longer in the registry…. PHEW!!!!

Now that it looks like we've corrected my problems, what do you recommend of running as permanent spyware/malware applications (Spybot/AVG antivirus/MalwareByte/Adaware etc…), as I have quite a few things installed now in attempt to correct the original problem? Should I just have one or two of these installed or are the fine to all be running?

Thanks HEAPS for all your help so far… It's great to see people like yourself helping others overcome all these spyware problems!

Also, here is a copy of my latest HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:19:35 AM, on 2/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\D-Tools\daemon.exe
C:\PROGRA~1\InFocus\PROJEC~1\pmprjdet.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\CodeGear\RAD Studio\5.0\bin\BSQLServer.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.3\OLAP\bin\msmdsrv.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=1061006
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=1061006
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [InFocusProjectorDetector] C:\PROGRA~1\InFocus\PROJEC~1\pmprjdet.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - S-1-5-18 Startup: Extended Monitor & Laptop.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: Extended Monitor & Laptop.lnk = ? (User 'Default user')
O4 - Startup: Extended Monitor & Laptop.lnk = ?
O4 - Global Startup: UltraMon.lnk = C:\Program Files\UltraMon\UltraMon.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} (ObjWinNTCheck Class) - http://192.168.10.31:2500/officescan/conso…ll/WinNTChk.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupINICtrl Class) - http://192.168.10.31:2500/officescan/conso…ll/setupini.cab
O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) - http://192.168.10.31:2500/officescan/conso…stall/setup.cab
O16 - DPF: {11818680-FCF6-11D0-9808-0800092A4865} (Adobe Form Control) - http://www.ato.gov.au/formflow/codebase/FormCtl.cab
O16 - DPF: {224F7DEA-B7C1-11D3-AB40-00902712A5C9} (PLSAddin Class) - http://www.ato.gov.au/formflow/codebase/plsspeller.cab
O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} (Encrypt Class) - http://192.168.10.31:2500/officescan/conso…root/AtxEnc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {4F3DCE50-E8E7-40AC-AB8D-99F87F1F89BD} (Trend Micro OfficeScan Management Console) - http://192.168.10.31:2500/officescan/conso…/AtxConsole.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1177289747921
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/Tran…ransferCtrl.cab
O16 - DPF: {8990AFAD-D352-42AC-A72F-A660BBF6E209} (OfficeScan Management Console) - http://192.168.10.31:2500/officescan/conso…/AtxConsole.cab
O16 - DPF: {A050E865-64E3-431B-8079-F0DFCEA90A2D} (PieChart Class) - http://192.168.10.31:2500/officescan/conso…root/AtxPie.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CDDCFBB3-4D93-11D2-B1A9-00A0C9B742BE} (Adobe Script Object) - http://www.ato.gov.au/formflow/codebase/scriptobject.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://freetrial.webex.com/client/T26L/webex/ieatgpc.cab
O16 - DPF: {EF2FB80F-0975-408E-A871-B00CC863478A} (Adobe Soft Font Installer) - http://www.ato.gov.au/formflow/codebase/fontinstaller.cab
O18 - Protocol: linkscanner - (no CLSID) - (no file)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: BlackfishSQL - CodeGear - C:\Program Files\CodeGear\RAD Studio\5.0\bin\BSQLServer.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Unknown owner - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe (file missing)
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 11752 bytes
Boot into safe mode and delete these files/folders

C:\WINDOWS\System32\twain32
C:\WINDOWS\System32\lijiduse
C:\WINDOWS\System32\bekehutu.dll



Now we need to fix your problems by making a .reg file. Copy the code below into a Notepad file. Name the file as fix.reg, change the "Save as Type" to "All files" and save it on the desktop.

Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPM1b075170]


Then double click on the fix.reg file, when it prompts to merge click "Yes".



Tell me how that goes
Hello Rorschach112 Those 3 files you mentioned are no longer on my computer, and the fix.reg file has been run successfully. I just ran a spybot scan and it didn't find any infections, and I'm just running a full AVG scan now, and hopefully that won't find anything else either.
Hello Rorschach112 Those 3 files you mentioned are no longer on my computer, and the fix.reg file has been run successfully. I just ran a spybot scan and it didn't find any infections, and I'm just running a full AVG scan now, and hopefully that won't find anything else either.
your logs are clean

  • Make sure you have an Internet Connection.
  • Download OTCleanIt to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTCleanUp to reach the Internet, please allow the application to do so.
  • Click Yes to beging the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.



Your using an old version of Adobe Acrobat Reader, this can leave your pc open to vulnerabilities, you can update it here :
http://www.adobe.com/products/acrobat/readstep2.html



Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.



Now we need to create a new System Restore point.

Click Start Menu > Run > type (or copy and paste)

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it and click Create, when the confirmation screen shows the restore point has been created click Close.

Next goto Start Menu > Run > type

cleanmgr

Click OK, Disk Cleanup will open and start calculating the amount of space that can be freed, Once thats finished it will open the Disk Cleanup options screen, click the More Options tab then click Clean up on the system restore area and choose Yes at the confirmation window which will remove all the restore points except the one we just created.

To close Disk Cleanup and remove the Temporary Internet Files detected in the initial scan click OK then choose Yes on the confirmation window.




Below I have included a number of recommendations for how to protect your computer against malware infections.

* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.

* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:

SpywareBlaster protects against bad ActiveX

* SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender) or there will be a conflict.

Make Internet Explorer more secure
  • Click Start > Run
  • Type Inetcpl.cpl & click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected & Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.


*ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

*NoScript - Addon for Firefox that stops all scripts from running on websites. Stops malicious software from invading via flash, java, javascript, and many other entry points.

*Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

* MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here

* Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
Here

*ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

* Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

Thank you for your patience, and performing all of the procedures requested.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI