This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan Horse Downloader.Agent

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Help me please. I've downloaded something.

Here is my log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:30:36 PM, on 1/29/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\dnetc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Winsim\ConnectionManager\SimplyConnectionManager.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Winsim\ConnectionManager\Simply.SystemTrayIcon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\user\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {C5BF49A2-94F3-42BD-F434-3604812C8955} - (no file)
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE"
O4 - HKLM\..\Run: [SBDrvDet] "C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [WorksFUD] "C:\Program Files\Microsoft Works\wkfud.exe"
O4 - HKLM\..\Run: [Microsoft Works Portfolio] "C:\Program Files\Microsoft Works\WksSb.exe" /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ConnectionManager] C:\Program Files\Winsim\ConnectionManager\Simply.SystemTrayIcon.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKCU\..\Run: [RemoteCenter] "C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [WeatherWatcher] C:\Program Files\Weather Watcher\ww.exe
O4 - HKCU\..\Run: [WeatherEye] C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [tezrtsjhfr84iusjfo84f] C:\DOCUME~1\user\LOCALS~1\Temp\csrssc.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/2…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120829558027
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1136849927000
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O22 - SharedTaskScheduler: {03413bf7-e34c-445b-bfc0-a2b127255871} - incestuously - (no file)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: distributed.net client (dnetc) - Distributed Computing Technologies, Inc. - C:\WINDOWS\dnetc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Simply Accounting Database Connection Manager - Sage Software - C:\Program Files\Winsim\ConnectionManager\SimplyConnectionManager.exe

–
End of file - 14713 bytes
Hello and welcome to Posted Image

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your HJT log now, I will post back shortly with instructions.
Hello FreyjaGoddess

FIRST

Please download SDFix and save it to your Desktop.
  • You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.
Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\).
Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key repeatedly;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual user account.
  • Open the SDFix folder and double click on RunThis.bat to start the script.
  • Type Y and press Enter to begin the script.
  • It will start cleaning your PC and then prompt you to press any key to Reboot.
  • Press any key to restart the PC.
  • Your system will take longer than normal to restart as the fixtool will be removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished.
  • Press any key to end the script and to load your desktop icons.
  • A text file should automatically open, so please copy the contents and post them here.

NEXT

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, (AVG, Windows Defender) usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now


In your next reply I will need:

  • SDFIX log
  • ComboFix
  • fresh HJT log
SDFix: Version 1.240
Run by [removed] on Thu 01/29/2009 at 11:23 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\DOCUME~1\user\LOCALS~1\Temp\TMP3E.tmp - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\tmpBD.tmp - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\tmpC1.tmp - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\tmpC3.tmp - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\tmpC5.tmp - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\tmpC6.tmp - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\tmpC7.tmp - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\tmpF4.tmp - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-30 00:25:18
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:a1,98,79,0c,bf,8f,ee,44,a6,41,f4,dc,28,b2,73,d8,4b,19,31,0f,2c,..
"p0"="C:\Program Files\DAEMON Tools Lite\"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:80,6c,ad,83,bc,ae,36,67,a1,6b,44,a4,f5,be,7c,99,05,da,2b,99,8e,..
"a0"=hex:20,01,00,00,e8,54,a0,c7,c8,54,cb,a9,28,54,f7,1d,8c,37,65,40,ee,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:46,81,4c,70,95,30,30,c3,58,0e,54,0d,e0,58,bd,c7,67,82,61,03,1a,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:a1,98,79,0c,bf,8f,ee,44,a6,41,f4,dc,28,b2,73,d8,4b,19,31,0f,2c,..
"p0"="C:\Program Files\DAEMON Tools Lite\"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:80,6c,ad,83,bc,ae,36,67,a1,6b,44,a4,f5,be,7c,99,05,da,2b,99,8e,..
"a0"=hex:20,01,00,00,e8,54,a0,c7,c8,54,cb,a9,28,54,f7,1d,8c,37,65,40,ee,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:46,81,4c,70,95,30,30,c3,58,0e,54,0d,e0,58,bd,c7,67,82,61,03,1a,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:a1,98,79,0c,bf,8f,ee,44,a6,41,f4,dc,28,b2,73,d8,4b,19,31,0f,2c,..
"p0"="C:\Program Files\DAEMON Tools Lite\"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:80,6c,ad,83,bc,ae,36,67,a1,6b,44,a4,f5,be,7c,99,05,da,2b,99,8e,..
"a0"=hex:20,01,00,00,e8,54,a0,c7,c8,54,cb,a9,28,54,f7,1d,8c,37,65,40,ee,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:46,81,4c,70,95,30,30,c3,58,0e,54,0d,e0,58,bd,c7,67,82,61,03,1a,..

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1134336249\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1134336249\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
"C:\\Program Files\\Common Files\\AOL\\1134336249\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1134336249\\ee\\aim6.exe:*:Enabled:AIM"
"C:\\WINDOWS\\system32\\mshta.exe"="C:\\WINDOWS\\system32\\mshta.exe:*:Enabled:Microsoft ® HTML Application host"
"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWUCli.exe"="C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWUCli.exe:*:Enabled:HP Software Update Client"
"C:\\Program Files\\Java\\jre1.5.0_07\\bin\\javaw.exe"="C:\\Program Files\\Java\\jre1.5.0_07\\bin\\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\mIRC\\mirc.exe"="C:\\Program Files\\mIRC\\mirc.exe:*:Enabled:mIRC"
"C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\javaw.exe"="C:\\Program Files\\Java\\jre1.5.0_09\\bin\\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary"
"C:\\Program Files\\FrostWire\\FrostWire.exe"="C:\\Program Files\\FrostWire\\FrostWire.exe:*:Enabled:FrostWire 4.10.9 Beta"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"="C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Jukebox"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\Winsim\\ConnectionManager\\MySqlBinary\\5.0.38\\mysql\\mysqld-nt.exe"="C:\\Program Files\\Winsim\\ConnectionManager\\MySqlBinary\\5.0.38\\mysql\\mysqld-nt.exe:*:Enabled:mysqld-nt.exe 5.0.38"
"C:\\Program Files\\Winsim\\ConnectionManager\\SimplyConnectionManager.exe"="C:\\Program Files\\Winsim\\ConnectionManager\\SimplyConnectionManager.exe:*:Enabled:SimplyConnectionManager.exe"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqcopy.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqcopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Tue 23 Oct 2007 5,903,928 A..H. — "C:\Program Files\Picasa2\setup.exe"
Fri 12 Dec 2008 900 A.SH. — "C:\WINDOWS\system32\KGyGaAvL.sys"
Sun 6 Aug 2006 274,029 ..SH. — "C:\WINDOWS\system32\ppqss.tmp"
Thu 10 Aug 2006 279,300 ..SH. — "C:\WINDOWS\system32\ppqss.bak1"
Thu 10 Aug 2006 279,352 ..SH. — "C:\WINDOWS\system32\ppqss.bak2"
Sun 26 Feb 2006 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 5 Jun 2008 51 A..H. — "C:\Documents and Settings\user\My Documents\ZDS05556.TMP"
Tue 12 Dec 2006 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Wed 10 Sep 2008 444 …HR — "C:\Documents and Settings\user\Application Data\SecuROM\UserData\securom_v7_01.bak"

Finished!

___________________________________________

ComboFix 09-01-21.04 - user 2009-01-30 0:42:03.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1233 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\components
c:\windows\system32\mcrh.tmp
c:\windows\system32\ppqss.bak1
c:\windows\system32\ppqss.bak2
c:\windows\system32\ppqss.ini
c:\windows\system32\ppqss.ini2
c:\windows\system32\ppqss.tmp

.
((((((((((((((((((((((((( Files Created from 2008-12-28 to 2009-01-30 )))))))))))))))))))))))))))))))
.

2009-01-30 00:02 . 2009-01-30 00:02 10,520 –a—— c:\windows\system32\avgrsstx.dll.prepare
2009-01-29 23:22 . 2009-01-29 23:22 578,560 –a–c— c:\windows\system32\dllcache\user32.dll
2009-01-29 23:15 . 2009-01-29 23:16 d——– c:\windows\ERUNT
2009-01-29 23:02 . 2009-01-30 00:33 d——– C:\SDFix
2009-01-28 12:44 . 2009-01-28 12:44 d——– c:\documents and settings\All Users\Application Data\EA
2009-01-24 17:20 . 2008-12-17 00:53 2,686,104 –a—— c:\windows\system32\drivers\LV302V32.SYS
2009-01-24 17:20 . 2008-12-17 00:55 195,096 –a—— c:\windows\system32\lvci11901262.dll
2009-01-23 09:00 . 2009-01-23 09:00 d——– c:\program files\Games
2009-01-22 22:45 . 2009-01-22 22:45 d——– c:\windows\Parking Dash
2009-01-22 22:45 . 2009-01-22 22:45 d——– c:\program files\Parking Dash
2009-01-22 11:01 . 2009-01-22 11:01 d——– c:\documents and settings\user\Application Data\blg
2009-01-22 11:01 . 2009-01-22 11:01 d——– c:\documents and settings\All Users\Application Data\blg
2009-01-22 11:00 . 2009-01-22 11:00 d——– c:\program files\Spa Mania
2009-01-22 10:33 . 2009-01-22 10:33 d——– c:\program files\LeeGTs Games
2009-01-21 20:04 . 2009-01-21 20:04 d——– c:\windows\Operation Mania
2009-01-21 20:04 . 2009-01-21 20:05 d——– c:\program files\Operation Mania
2009-01-15 13:01 . 2009-01-15 13:01 d——– c:\documents and settings\user\Application Data\Home Sweet Home 2
2009-01-15 10:07 . 2009-01-15 10:07 d——– c:\windows\Restaurant Rush
2009-01-15 10:07 . 2009-01-15 10:07 d——– c:\windows\Home Sweet Home 2 Kitchens and Baths
2009-01-15 10:07 . 2009-01-26 23:06 d——– c:\program files\Restaurant Rush
2009-01-15 10:07 . 2009-01-15 10:07 d——– c:\program files\Home Sweet Home 2 Kitchens and Baths
2009-01-15 10:07 . 2009-01-15 10:08 d——– c:\documents and settings\user\Application Data\PetShowCraze
2009-01-15 10:05 . 2009-01-15 10:05 d——– c:\windows\Pet Show Craze
2009-01-14 23:33 . 2009-01-14 23:34 d——– c:\documents and settings\user\Application Data\BeachPartyCraze
2009-01-14 23:20 . 2009-01-14 23:20 d——– c:\windows\Beach Party Craze
2009-01-14 23:20 . 2009-01-14 23:20 d——– c:\program files\Beach Party Craze
2009-01-14 17:18 . 2009-01-14 17:18 d——– c:\documents and settings\All Users\Application Data\FreshGames
2009-01-14 17:17 . 2009-01-14 17:17 d——– c:\windows\Ranch Rush
2009-01-14 17:17 . 2009-01-14 17:18 d——– c:\program files\Ranch Rush
2009-01-14 15:42 . 2009-01-14 15:42 d——– c:\program files\Mystic Inn
2009-01-14 13:02 . 2009-01-14 19:44 d——– c:\documents and settings\All Users\Application Data\FarmFrenzy2
2009-01-14 13:01 . 2009-01-14 13:01 d——– c:\windows\Farm Frenzy 2
2009-01-14 13:01 . 2009-01-14 13:01 d——– c:\program files\Farm Frenzy 2
2009-01-11 10:14 . 2009-01-11 10:14 d——– c:\windows\Wedding Dash 2 - Rings Around the World
2009-01-11 10:14 . 2009-01-11 10:14 d——– c:\program files\Wedding Dash 2 - Rings Around the World
2009-01-09 23:44 . 2009-01-09 23:44 d——– c:\program files\Wedding Dash
2008-12-16 21:58 . 2008-12-16 21:58 25,624 –a—— c:\windows\system32\drivers\LVPr2Mon.sys
2008-12-16 21:50 . 2008-12-16 21:50 13,584 –a—— c:\windows\system32\drivers\iKeyLgFT.dll
2008-12-11 14:05 . 2008-12-11 14:05 d——– c:\program files\iTunes
2008-12-11 14:05 . 2008-12-11 14:05 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-11 14:03 . 2008-12-11 14:03 d——– c:\program files\QuickTime
2008-12-10 12:15 . 2008-10-24 06:21 455,296 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2008-12-10 12:14 . 2008-09-04 12:15 1,106,944 —–c— c:\windows\system32\dllcache\msxml3.dll
2008-12-10 12:12 . 2008-12-10 12:12 410,984 –a—— c:\windows\system32\deploytk.dll
2008-12-10 12:10 . 2008-12-17 01:00 494,104 –a—— c:\windows\system32\LVUI2.dll
2008-12-10 12:10 . 2008-12-17 00:55 416,280 –a—— c:\windows\system32\lvcodec2.dll
2008-12-10 12:09 . 2008-12-17 01:00 768,024 –a—— c:\windows\system32\drivers\lvrs.sys
2008-12-10 12:09 . 2008-07-26 10:23 195,096 –a—— c:\windows\system32\lvci11801048.dll
2008-12-10 12:04 . 2008-12-10 12:04 d——– c:\documents and settings\All Users\Application Data\HP Product Assistant

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-30 05:02 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-30 04:58 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-01-30 04:57 10,520 —-a-w c:\windows\system32\avgrsstx.dll
2009-01-29 22:07 ——— d—–w c:\program files\Paradise Pet Salon
2009-01-29 17:29 ——— d—–w c:\documents and settings\user\Application Data\Apple Computer
2009-01-29 17:27 ——— d—–w c:\program files\Simpaplex-Eng
2009-01-29 17:22 ——— d—–w c:\program files\Meteor
2009-01-29 17:21 ——— d—–w c:\program files\Super Blocks
2009-01-29 17:21 ——— d—–w c:\program files\Intricate Words
2009-01-29 17:21 ——— d—–w c:\program files\Dragon
2009-01-29 17:21 ——— d—–w c:\program files\Castle of Cards
2009-01-29 17:21 ——— d—–w c:\program files\Balloon Park
2009-01-29 17:20 ——— d—–w c:\program files\Pirate Stories Kit And Ellis
2009-01-29 17:20 ——— d—–w c:\program files\Butterfly Hunter
2009-01-29 17:19 ——— d—–w c:\program files\Babysitting Mania
2009-01-29 15:47 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-29 14:29 ——— d—–w c:\program files\Tower Constructor
2009-01-29 04:29 ——— d—–w c:\program files\Sallys Salon
2009-01-28 19:26 ——— d—–w c:\program files\PopCap Games
2009-01-28 19:24 ——— d—–w c:\program files\GameHouse Games Collection
2009-01-28 17:39 ——— d—–w c:\program files\Alice Greenfingers
2009-01-28 17:28 ——— d—–w c:\program files\Happy Hour
2009-01-28 17:27 ——— d—–w c:\program files\Turbo Gems
2009-01-28 17:27 ——— d—–w c:\program files\Private Eye - Greatest Unsolved Mysteries
2009-01-28 17:27 ——— d—–w c:\program files\Fab Fashion
2009-01-28 17:27 ——— d—–w c:\program files\Dr Daisy Pet Vet
2009-01-28 17:26 ——— d—–w c:\program files\Lottso Deluxe
2009-01-28 17:25 ——— d—–w c:\program files\Plant Tycoon
2009-01-28 17:25 ——— d—–w c:\program files\Kudos 2-in-1
2009-01-28 17:23 ——— d—–w c:\program files\The Scruffs
2009-01-28 17:22 ——— d—–w c:\program files\Triptych
2009-01-28 17:22 ——— d—–w c:\program files\Realore
2009-01-28 17:10 ——— d—–w c:\program files\EleFun Games
2009-01-28 17:08 ——— d—–w c:\program files\Yumsters
2009-01-28 17:07 ——— d—–w c:\program files\Zam BeeZee
2009-01-28 17:04 ——— d—–w c:\program files\Fireworks Extravaganza
2009-01-28 17:04 ——— d—–w c:\program files\Alawar
2009-01-28 17:03 ——— d—–w c:\program files\Cosmic Bugs
2009-01-28 17:03 ——— d—–w c:\program files\Button Up
2009-01-28 17:02 ——— d—–w c:\program files\Believe In Santa
2009-01-28 17:02 ——— d—–w c:\program files\Bejeweled 2 Deluxe
2009-01-28 17:01 ——— d—–w c:\program files\Beetle Bomp
2009-01-28 17:01 ——— d—–w c:\program files\Astrobatics
2009-01-28 16:14 ——— d—–w c:\program files\Around The World In 80 Days
2009-01-28 04:03 ——— d—–w c:\documents and settings\user\Application Data\Skype
2009-01-28 03:56 ——— d—–w c:\documents and settings\user\Application Data\skypePM
2009-01-24 22:22 ——— d—–w c:\program files\Common Files\LogiShrd
2009-01-24 22:17 ——— d—–w c:\program files\Logitech
2009-01-24 22:16 ——— d—–w c:\documents and settings\All Users\Application Data\LogiShrd
2009-01-24 22:01 ——— d—–w c:\documents and settings\user\Application Data\uTorrent
2009-01-23 03:46 ——— d—–w c:\documents and settings\user\Application Data\PlayFirst
2009-01-23 03:46 ——— d—–w c:\documents and settings\All Users\Application Data\PlayFirst
2009-01-22 01:05 ——— d—–w c:\documents and settings\user\Application Data\Pogo Games
2009-01-15 08:01 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-17 06:01 432,664 —-a-w c:\windows\system32\LVUI2RC.dll
2008-12-17 06:01 41,752 —-a-w c:\windows\system32\drivers\LVUSBSta.sys
2008-12-17 05:53 13,848 —-a-w c:\windows\system32\drivers\lv302af.sys
2008-12-17 05:37 29,562 —-a-w c:\windows\system32\Repository.reg
2008-12-11 20:21 ——— d—–w c:\documents and settings\user\Application Data\Hoyle Card Games
2008-12-11 19:05 ——— d—–w c:\program files\iPod
2008-12-11 19:05 ——— d—–w c:\program files\Common Files\Apple
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-10 18:04 ——— d—–w c:\program files\Common Files\Adobe
2008-12-10 17:12 ——— d—–w c:\program files\Java
2008-11-01 17:15 127,034 ——r c:\windows\bwUnin-8.1.1.50-8876480SL.exe
2008-10-23 12:36 286,720 —-a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 —-a-w c:\windows\system32\wininet.dll
2008-10-16 20:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 20:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 20:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 20:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 20:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 20:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 20:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 20:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 20:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 20:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-10-03 10:02 247,326 —-a-w c:\windows\system32\strmdll.dll
2007-12-21 19:12 1,719,336 —-a-w c:\documents and settings\All Users\Application Data\YugmaSE-Uninstaller.exe
2006-08-15 01:47 4,092 —-a-w c:\program files\hijackthis.log
2006-01-12 00:43 1,663 —-a-w c:\windows\inf\COMFF.tmp
2006-01-09 22:33 1,663 —-a-w c:\windows\inf\COM33.tmp
2008-06-24 03:47 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008062320080624\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WeatherEye"="c:\program files\TheWeatherNetwork\WeatherEye\WeatherEye" [X]
"RemoteCenter"="c:\program files\Creative\MediaSource\RemoteControl\RCMan.EXE" [2003-10-08 139264]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"CTDVDDET"="c:\program files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE" [2003-06-18 45056]
"SBDrvDet"="c:\program files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 45056]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-10 136600]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-05-07 188416]
"HPHUPD05"="c:\program files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-05-22 49152]
"HPHmon05"="c:\windows\system32\hphmon05.exe" [2003-05-22 483328]
"WorksFUD"="c:\program files\Microsoft Works\wkfud.exe" [2001-10-05 24576]
"Microsoft Works Portfolio"="c:\program files\Microsoft Works\WksSb.exe" [2001-08-23 331830]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-16 28738]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]
"RoxioEngineUtility"="c:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-01-13 69632]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-05 81920]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-29 1601304]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-05-22 185896]
"ConnectionManager"="c:\program files\Winsim\ConnectionManager\Simply.SystemTrayIcon.exe" [2008-06-06 87336]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-12-20 2656528]
"CTHelper"="CTHELPER.EXE" [2003-10-06 c:\windows\system32\CTHELPER.EXE]
"nwiz"="nwiz.exe" [2007-12-05 c:\windows\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]

c:\documents and settings\user\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
APC UPS Status.lnk - c:\program files\APC\APC PowerChute Personal Edition\Display.exe [2006-01-11 221247]
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
HP Image Zone Fast Start.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe [2004-05-29 53248]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-11-01 67128]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\KEM.exe [2006-03-26 581632]
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2001-08-07 24633]
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2006-06-01 118784]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 118784]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-02-05 54512]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-29 23:57 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=c:\windows\pss\ymetray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
–a—— 2006-05-09 19:24 50760 c:\program files\Common Files\AOL\1134336249\ee\aolsoftware.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1134336249\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1134336249\\ee\\aim6.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\Java\\jre1.5.0_07\\bin\\javaw.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Java\\jre1.5.0_09\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Winsim\\ConnectionManager\\MySqlBinary\\5.0.38\\mysql\\mysqld-nt.exe"=
"c:\\Program Files\\Winsim\\ConnectionManager\\SimplyConnectionManager.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqcopy.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-05-05 325128]
R3 dfmirage;dfmirage;c:\windows\system32\drivers\dfmirage.sys [2005-11-25 31896]
R4 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-05-05 298264]
R4 PfDetNT;PfDetNT;c:\windows\system32\drivers\PfModNT.sys [2003-03-05 15840]
R4 Simply Accounting Database Connection Manager;Simply Accounting Database Connection Manager;c:\program files\Winsim\ConnectionManager\SimplyConnectionManager.exe [2008-06-17 18216]
R4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S0 iteraid;ITERAID_Service_Install;c:\windows\system32\drivers\iteraid.sys [2005-07-08 24971]
S0 m5287;m5287;c:\windows\system32\drivers\m5287.sys [2005-07-08 85888]
S0 Si3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\drivers\Si3112r.sys [2005-07-08 89610]
S0 SiSRaid1;SiSRaid1;c:\windows\system32\drivers\sisraid1.sys [2005-07-08 45568]
S0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2005-07-08 77056]
S3 s3m;s3m;c:\windows\system32\drivers\s3m.sys [2005-11-29 166720]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-01-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-01-30 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-WeatherWatcher - c:\program files\Weather Watcher\ww.exe
HKU-Default-Run-jsf8uiw3jnjgffght - c:\windows\TEMP\winlognn.exe
Notify-AtiExtEvent - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.daemon-search.com/startpage
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
Trusted Zone: aol.com\free
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - c:\program files\QuickTax 2007\ic2007pp.dll
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\e99esdn6.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - hxxp://www.theweathernetwork.com/weather/caon0532
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\e99esdn6.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppopcaploader.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-30 00:43:31
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@SACL=

[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:67,9d,2d,cb,b3,11,e3,0c,e3,d9,ab,81,91,7c,f7,66,f4,25,e5,0b,c0,ba,5d,
a4,c1,20,87,5b,3b,70,6a,5c,28,1e,a0,73,d6,b9,ce,b5,f1,71,3d,ab,0c,a1,53,9b,\
"??"=hex:a1,8b,6a,e7,59,b6,32,f2,48,f4,97,aa,af,54,f9,39
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(696)
c:\windows\system32\avgrsstx.dll
.
Completion time: 2009-01-30 0:46:33
ComboFix-quarantined-files.txt 2009-01-30 05:45:28

Pre-Run: 82,498,187,264 bytes free
Post-Run: 82,577,715,200 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /noexecute=optin

348 — E O F — 2009-01-29 19:13:46

____________________________________

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:48:59 AM, on 1/30/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\dnetc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Winsim\ConnectionManager\SimplyConnectionManager.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winsim\ConnectionManager\Simply.SystemTrayIcon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Documents and Settings\user\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE"
O4 - HKLM\..\Run: [SBDrvDet] "C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [WorksFUD] "C:\Program Files\Microsoft Works\wkfud.exe"
O4 - HKLM\..\Run: [Microsoft Works Portfolio] "C:\Program Files\Microsoft Works\WksSb.exe" /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ConnectionManager] C:\Program Files\Winsim\ConnectionManager\Simply.SystemTrayIcon.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKCU\..\Run: [RemoteCenter] "C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [WeatherEye] C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/2…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120829558027
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1136849927000
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: distributed.net client (dnetc) - Distributed Computing Technologies, Inc. - C:\WINDOWS\dnetc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Simply Accounting Database Connection Manager - Sage Software - C:\Program Files\Winsim\ConnectionManager\SimplyConnectionManager.exe

–
End of file - 13768 bytes
Hi FrejaGoddess


I see you have peer to peer programs installed.

I my opinion, "peer to peer" file sharing is just another way to expose your system to virii, trojans, and worms…
You would be doing yourself a big favour by removing them.

You also have outdated versions of Java on your machine which are now a security vulnerability and can be uninstalled.
You already have the latest version of Java (v6.11) so any earlier versions can be removed.

Please go to Start>ControlPanel>Add/Remove Programs

A list of installed programs will populate

Look for the following programs and select REMOVE


* Limewire
* utorrent
* Java 5 update7
* Java 5 update 9



NEXT

Download Rooter.exe to your desktop

  • Doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have installed Windows).
  • Post that in your next reply.

Next

I would like you to run an online virus scan to make sure there is nothing remaining:


To do this, go to Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.

  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.


For your next reply I need:
  • Rooter Log
  • Eset Log

Please advise how your computer is running now.
Everything up to update 11 - that's the newest one so you want to keep that :thumbup:

(I don't think those other one's are there - so Windows will just ask you if you want them removed from the uninstall list -choose Yes :) )
Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3 X86-based PC ( Uniprocessor Free : AMD Athlon™ 64 Processor 3500+ ) BIOS : Phoenix - AwardBIOS v6.00PG USER : user ( Administrator ) BOOT : Normal boot Antivirus : AVG Anti-Virus Free 8.0 (Activated) A:\ (USB) C:\ (Local Disk) - NTFS - Total:186 Go (Free:81 Go) D:\ (CD or DVD) E:\ (CD or DVD) F:\ (CD or DVD) G:\ (USB) Fri 01/30/2009|20:29 ———————-\\ Search.. ———————-\\ Cracks & Keygens.. C:\DOCUME~1\user\Recent\How To Use The Crack.lnk 1 - "C:\Rooter$\Rooter_1.txt" - Fri 01/30/2009|20:05 2 - "C:\Rooter$\Rooter_2.txt" - Fri 01/30/2009|20:15 3 - "C:\Rooter$\Rooter_3.txt" - Fri 01/30/2009|20:28 4 - "C:\Rooter$\Rooter_4.txt" - Fri 01/30/2009|20:30 ———————-\\ Scan completed at 20:30 _________________________________ I don't know where to find an ESET log but the scan said that there were "No Threat Founds." _________________________________ Also, I have two other computers on this network, should I be concerned about their safety?
Lastly, my computer is still having some issues. The major one is that my gmail won't load properly, whereas before the infection it *always* loaded properly. It says I have a slow connection, yet if I load gmail on one of the other two computers on the *same* network there is no difficulty loading.
Hi drixisnoobs,

I see you ran rooter four times - did you experience problems with it? Please post the very first log you ran as it may give me some more insight into your issues.

The risk to your other computers on the network right now is fairly low I would say.

So lets see if there is any malware left on your computer:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


NEXT

Download OTViewIt to your desktop.
  • Close all windows and double click OTViewIt
  • Place a tick in the Scan all Users box
  • Click Run Scan and let the program run uninterrupted
  • On completion it will produce two logs on the Desktop, atttach the OTViewIt.txtand Extras.txt logs in your next post.


In your next response I need
  • MBAM log
  • OTViewIt.txt
  • Extra.txt
  • original rooter log

(eset should be located at C:\ProgramFiles\EsetOnlineScanner\log.txt - if you can find it )
ESET Log: # version=4 # OnlineScanner.ocx=1.0.0.635 # OnlineScannerDLLA.dll=1, 0, 0, 79 # OnlineScannerDLLW.dll=1, 0, 0, 78 # OnlineScannerUninstaller.exe=1, 0, 0, 49 # vers_standard_module=3813 (20090130) # vers_arch_module=1.064 (20080214) # vers_adv_heur_module=1.066 (20070917) # EOSSerial=51cdaa723f3b3548a727aa498e8ae0cf # end=finished # remove_checked=false # unwanted_checked=false # utc_time=2009-01-31 03:55:55 # local_time=2009-01-30 10:55:55 (-0500, Eastern Standard Time) # country="United States" # osver=5.1.2600 NT Service Pack 3 # scanned=1171007 # found=0 # scan_time=8467 _______________________________ Doing malware bytes scan at the mo.
Malwarebytes' Anti-Malware 1.33
Database version: 1712
Windows 5.1.2600 Service Pack 3

1/31/2009 12:43:07 PM
mbam-log-2009-01-31 (12-43-07).txt

Scan type: Full Scan (C:\|)
Objects scanned: 270352
Time elapsed: 2 hour(s), 8 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\Ranch Rush\ijl15.dll (Trojan.Agent) -> Quarantined and deleted successfully.

_________________________________________________

OTViewIt logfile created on: 1/31/2009 12:44:32 PM - Run
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\user\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.24 Gb Available Physical Memory | 62.17% Memory free
3.35 Gb Paging File | 2.65 Gb Available in Paging File | 79.15% Paging File free
Paging file location(s): c:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.31 Gb Total Space | 82.02 Gb Free Space | 44.03% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TOUGAS3
Current User Name: user
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== Processes ==========

[2006/11/03 19:19:58 | 00,013,592 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MsMpEng.exe
[2008/10/05 13:54:08 | 00,611,664 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
[2005/12/12 15:02:24 | 00,176,193 | —- | M] (American Power Conversion Corporation) – C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
[2008/11/07 15:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
[2004/07/20 15:15:20 | 00,090,112 | —- | M] (ASUSTeK COMPUTER INC.) – C:\WINDOWS\ATKKBService.exe
[2009/01/30 00:01:58 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe
[1999/12/13 01:01:00 | 00,044,032 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\CTSVCCDA.EXE
[2006/09/10 04:25:38 | 00,539,136 | —- | M] (Distributed Computing Technologies, Inc.) – C:\WINDOWS\dnetc.exe
[2008/12/10 12:12:50 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
[2008/12/16 21:59:50 | 00,150,040 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
[2006/10/26 13:40:34 | 00,335,872 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
[2007/12/05 02:41:00 | 00,155,716 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvsvc32.exe
[2005/08/08 14:54:00 | 00,167,936 | —- | M] () – C:\Program Files\CyberLink\Shared files\RichVideo.exe
[2008/06/06 00:00:00 | 00,018,216 | —- | M] (Sage Software) – C:\Program Files\Winsim\ConnectionManager\SimplyConnectionManager.exe
[2009/01/30 00:02:02 | 00,484,120 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgrsx.exe
[2003/10/06 01:57:32 | 00,024,576 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\CTHELPER.EXE
[2003/09/17 10:43:36 | 00,057,344 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
[2003/06/18 01:00:00 | 00,045,056 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.exe
[2003/05/07 00:56:22 | 00,188,416 | —- | M] (HP) – C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
[2003/05/22 07:55:38 | 00,483,328 | R— | M] (Hewlett-Packard) – C:\WINDOWS\system32\hphmon05.exe
[2001/08/16 23:41:58 | 00,028,738 | —- | M] (Microsoft® Corporation) – C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
[2005/06/07 00:46:24 | 00,057,344 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[2005/12/07 23:57:00 | 00,030,208 | —- | M] (Cyberlink Corp.) – C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[2006/12/10 21:52:38 | 00,049,152 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
[2007/08/24 07:00:48 | 00,033,648 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[2006/10/18 21:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe
[2008/04/13 19:12:33 | 00,033,280 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\rundll32.exe
[2009/01/30 00:01:55 | 01,601,304 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgtray.exe
[2008/05/22 21:14:39 | 00,185,896 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[2008/06/06 00:00:00 | 00,087,336 | —- | M] (Sage Software) – C:\Program Files\Winsim\ConnectionManager\Simply.SystemTrayIcon.exe
[2007/02/05 15:34:38 | 00,300,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\searchindexer.exe
[2008/11/20 14:20:54 | 00,290,088 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunesHelper.exe
[2008/12/20 07:50:34 | 02,656,528 | —- | M] () – C:\Program Files\Logitech\QuickCam\Quickcam.exe
[2008/12/10 12:12:50 | 00,136,600 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
[2003/10/08 16:35:42 | 00,139,264 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
[2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation) – C:\Program Files\Messenger\msmsgs.exe
[2009/01/16 11:30:40 | 04,519,832 | —- | M] (MétéoMédia/The Weather Network) – C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
[2008/12/20 07:46:58 | 00,558,864 | —- | M] () – C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
[2006/10/18 21:05:26 | 00,204,288 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnscfg.exe
[2008/04/01 04:39:48 | 00,486,856 | —- | M] (DT Soft Ltd) – C:\Program Files\DAEMON Tools Lite\daemon.exe
[2007/01/02 21:40:10 | 00,210,520 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
[2008/11/01 12:15:46 | 00,067,128 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
[2008/11/20 14:20:44 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe
[2004/07/15 12:56:56 | 00,581,632 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\SetPoint\KEM.exe
[2001/08/07 18:06:54 | 00,024,633 | —- | M] (Microsoft® Corporation) – C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
[2004/02/05 14:28:16 | 00,118,784 | —- | M] (Nikon Corporation) – C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
[2007/02/05 15:40:46 | 00,118,784 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Desktop Search\WindowsSearch.exe
[2008/02/05 15:29:20 | 00,054,512 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
[2007/12/07 20:44:36 | 00,101,440 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[2009/01/16 11:30:40 | 04,519,832 | —- | M] (MétéoMédia/The Weather Network) – C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
[2009/01/16 11:30:40 | 04,519,832 | —- | M] (MétéoMédia/The Weather Network) – C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
[2005/12/12 15:03:54 | 00,417,855 | —- | M] (American Power Conversion Corporation) – C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
[2004/06/08 13:31:38 | 00,029,696 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\SetPoint\KHALMNPR.exe
[2006/12/10 21:51:08 | 00,271,960 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe
[2004/05/29 00:08:52 | 00,520,192 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
[2007/02/05 15:32:28 | 00,182,784 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\searchprotocolhost.exe
[2007/02/05 15:31:10 | 00,076,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\searchfilterhost.exe
[2009/01/31 10:24:20 | 00,422,912 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTViewIt.exe

========== (O23) Win32 Services ==========

[2008/10/05 13:54:08 | 00,611,664 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe – (aawservice [Auto | Running])
[2005/12/12 15:02:24 | 00,176,193 | —- | M] (American Power Conversion Corporation) – C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe – (APC UPS Service [Auto | Running])
[2008/11/07 15:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device [Auto | Running])
[2007/10/24 01:47:22 | 00,033,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
[2004/07/20 15:15:20 | 00,090,112 | —- | M] (ASUSTeK COMPUTER INC.) – C:\WINDOWS\ATKKBService.exe – (ATKKeyboardService [Auto | Running])
File not found – – (Automatic LiveUpdate Scheduler [Auto | Stopped])
[2009/01/30 00:01:58 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe – (avg8wd [Auto | Running])
[2007/10/24 01:47:40 | 00,070,144 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[1999/12/13 01:01:00 | 00,044,032 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\CTSVCCDA.EXE – (Creative Service for CDROM Access [Auto | Running])
[2006/09/10 04:25:38 | 00,539,136 | —- | M] (Distributed Computing Technologies, Inc.) – C:\WINDOWS\dnetc.exe – (dnetc [Auto | Running])
[2007/01/03 20:40:21 | 00,136,120 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [On_Demand | Stopped])
[2005/04/04 01:41:10 | 00,069,632 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
[2008/11/20 14:20:44 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Running])
[2008/12/10 12:12:50 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
[2008/12/16 21:59:50 | 00,150,040 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcSrv [Auto | Running])
[2006/10/26 13:40:34 | 00,335,872 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe – (MDM [Auto | Running])
[2007/08/24 06:59:20 | 00,068,464 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe – (Microsoft Office Groove Audit Service [On_Demand | Stopped])
[2007/12/05 02:41:00 | 00,155,716 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvsvc32.exe – (NVSvc [Auto | Running])
[2007/08/24 03:19:12 | 00,443,776 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
[2006/10/26 14:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
[2005/08/08 14:54:00 | 00,167,936 | —- | M] () – C:\Program Files\CyberLink\Shared files\RichVideo.exe – (RichVideo [Auto | Running])
[2008/06/06 00:00:00 | 00,018,216 | —- | M] (Sage Software) – C:\Program Files\Winsim\ConnectionManager\SimplyConnectionManager.exe – (Simply Accounting Database Connection Manager [Auto | Running])
[2007/01/19 13:54:14 | 00,097,136 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\usnsvc.exe – (usnjsvc [On_Demand | Stopped])
[2006/11/03 19:19:58 | 00,013,592 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MsMpEng.exe – (WinDefend [Auto | Running])
[2006/10/18 21:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [Auto | Running])
[2007/02/05 15:34:38 | 00,300,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\searchindexer.exe – (WSearch [Auto | Running])

========== Driver Services ==========

[2004/10/07 20:16:04 | 00,035,840 | —- | M] (Oak Technology Inc.) – C:\WINDOWS\System32\drivers\AFS2K.SYS – (AFS2K [System | Running])
[2008/04/13 13:31:33 | 00,037,760 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\amdk7.sys – (AmdK7 [System | Stopped])
[2004/07/20 15:19:16 | 00,020,096 | —- | M] (ASUSTeK COMPUTER INC.) – C:\WINDOWS\system32\drivers\atkkbnt.sys – (asuskbnt [System | Running])
[2004/08/03 17:29:28 | 00,327,040 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\drivers\ati2mtaa.sys – (ati2mtaa [On_Demand | Stopped])
[2009/01/30 00:02:02 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgldx86.sys – (AvgLdx86 [System | Running])
[2009/01/30 00:02:02 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgmfx86.sys – (AvgMfx86 [System | Running])
[2006/10/18 04:00:00 | 00,002,432 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdr4_xp.sys – (Cdr4_xp [System | Running])
[2006/10/18 04:00:00 | 00,002,560 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdralw2k.sys – (Cdralw2k [System | Running])
[2003/11/05 01:26:02 | 00,645,392 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctac32k.sys – (ctac32k [On_Demand | Running])
[2003/11/18 21:13:54 | 00,366,160 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctaud2k.sys – (ctaud2k [On_Demand | Running])
[2003/10/13 22:17:56 | 00,332,800 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctdvda2k.sys – (ctdvda2k [On_Demand | Stopped])
[2003/10/07 21:08:12 | 00,006,096 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctprxy2k.sys – (ctprxy2k [On_Demand | Running])
[2003/10/07 21:09:10 | 00,130,288 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctsfm2k.sys – (ctsfm2k [On_Demand | Running])
[2005/11/25 17:43:48 | 00,031,896 | —- | M] (DemoForge, LLC) – C:\WINDOWS\system32\drivers\dfmirage.sys – (dfmirage [On_Demand | Running])
[2006/10/26 03:00:00 | 00,387,432 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl [System | Running])
[2004/10/11 00:51:00 | 00,008,037 | R— | M] (ASUSTeK Computer Inc.) – C:\WINDOWS\system32\drivers\EIO.sys – (EIO [Auto | Running])
[2003/10/13 04:42:12 | 00,145,488 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\emupia2k.sys – (emupia [On_Demand | Running])
[2008/04/13 13:36:40 | 00,046,464 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\gagp30kx.sys – (gagp30kx [Boot | Running])
[2008/04/13 13:45:29 | 00,010,624 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum [On_Demand | Running])
[2008/04/17 13:12:54 | 00,015,464 | —- | M] (GEAR Software Inc.) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
[2003/10/21 04:26:08 | 00,904,496 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ha10kx2k.sys – (ha10kx2k [On_Demand | Running])
[2003/10/21 04:23:44 | 00,148,432 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\haP16v2k.sys – (hap16v2k [On_Demand | Running])
[2008/04/13 13:36:38 | 00,020,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\hidbatt.sys – (HidBatt [On_Demand | Stopped])
[2006/03/19 19:48:36 | 00,049,920 | R— | M] (HP) – C:\WINDOWS\system32\drivers\HPZid412.sys – (HPZid412 [On_Demand | Running])
[2006/03/19 19:48:36 | 00,016,496 | R— | M] (HP) – C:\WINDOWS\system32\drivers\HPZipr12.sys – (HPZipr12 [On_Demand | Running])
[2006/03/19 19:48:37 | 00,021,568 | R— | M] (HP) – C:\WINDOWS\system32\drivers\HPZius12.sys – (HPZius12 [On_Demand | Running])
[2004/06/17 06:41:44 | 00,024,971 | —- | M] (Integrated Technology Express, Inc.) – C:\WINDOWS\system32\drivers\iteraid.sys – (iteraid [Boot | Stopped])
[2004/06/08 13:36:28 | 00,013,105 | —- | M] (Logitech, Inc.) – C:\WINDOWS\system32\drivers\L8042Kbd.sys – (L8042Kbd [On_Demand | Running])
[2004/06/08 13:35:18 | 00,054,817 | —- | M] (Logitech, Inc.) – C:\WINDOWS\system32\drivers\L8042mou.Sys – (L8042mou [On_Demand | Stopped])
[2004/06/08 13:35:08 | 00,071,533 | —- | M] (Logitech, Inc.) – C:\WINDOWS\system32\drivers\LMouKE.Sys – (LMouKE [On_Demand | Stopped])
[2008/12/16 21:58:54 | 00,025,624 | —- | M] () – C:\WINDOWS\system32\drivers\LVPr2Mon.sys – (LVPr2Mon [On_Demand | Running])
[2008/12/17 01:00:12 | 00,768,024 | —- | M] (Logitech Inc.) – C:\WINDOWS\system32\drivers\lvrs.sys – (LVRS [On_Demand | Running])
[2008/12/17 01:01:20 | 00,041,752 | —- | M] (Logitech Inc.) – C:\WINDOWS\system32\drivers\LVUSBSta.sys – (LVUSBSta [On_Demand | Running])
[2005/02/04 18:00:12 | 00,085,888 | —- | M] (ULi Electronics Inc.) – C:\WINDOWS\system32\drivers\m5287.sys – (m5287 [Boot | Stopped])
[2001/08/17 16:00:04 | 00,002,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\msmpu401.sys – (ms_mpu401 [On_Demand | Stopped])
[2004/08/12 21:56:20 | 00,005,810 | —- | M] () – C:\WINDOWS\system32\drivers\ASACPI.sys – (MTsensor [On_Demand | Running])
[2007/12/05 02:41:00 | 07,435,392 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv [On_Demand | Running])
[2003/10/07 21:06:50 | 00,178,672 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\system32\drivers\ctoss2k.sys – (ossrv [On_Demand | Running])
[2008/12/17 00:53:22 | 00,013,848 | —- | M] (Logitech Inc.) – C:\WINDOWS\system32\drivers\lv302af.sys – (pepifilter [On_Demand | Running])
[2003/09/19 15:47:24 | 00,010,368 | —- | M] (Padus, Inc.) – C:\WINDOWS\system32\drivers\pfc.sys – (pfc [On_Demand | Running])
[2003/03/05 12:19:28 | 00,015,840 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\system32\drivers\PfModNT.sys – (PfDetNT [Auto | Running])
[2003/03/05 12:19:28 | 00,015,840 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\system32\drivers\PfModNT.sys – (PfModNT [Auto | Stopped])
[2008/12/17 00:53:44 | 02,686,104 | —- | M] (Logitech Inc.) – C:\WINDOWS\system32\drivers\LV302V32.SYS – (PID_PEPI [On_Demand | Running])
[2004/08/04 07:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\system32\drivers\ptilink.sys – (Ptilink [On_Demand | Running])
[2006/10/18 04:00:00 | 00,036,624 | —- | M] (Sonic Solutions) – C:\WINDOWS\system32\drivers\pxhelp20.sys – (PxHelp20 [Boot | Running])
[2005/05/27 10:32:52 | 01,317,152 | —- | M] () – C:\WINDOWS\system32\drivers\lvcm.sys – (QCMerced [On_Demand | Stopped])
[2005/03/04 10:10:26 | 00,074,496 | —- | M] (Realtek Semiconductor Corporation ) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys – (RTL8023xp [On_Demand | Stopped])
[2001/08/17 13:50:34 | 00,166,720 | —- | M] (S3 Incorporated) – C:\WINDOWS\system32\drivers\s3m.sys – (s3m [On_Demand | Stopped])
[2007/11/13 05:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\system32\drivers\secdrv.sys – (Secdrv [On_Demand | Stopped])
[2003/05/30 03:05:30 | 00,089,610 | R— | M] (Silicon Image, Inc) – C:\WINDOWS\system32\drivers\Si3112r.sys – (Si3112r [Boot | Stopped])
[2005/01/19 01:30:52 | 00,067,200 | —- | M] (Silicon Image, Inc.) – C:\WINDOWS\system32\drivers\Si3132.sys – (SI3132 [Boot | Stopped])
[2003/12/09 01:43:36 | 00,045,568 | —- | M] (Silicon Integrated Systems) – C:\WINDOWS\system32\drivers\sisraid.sys – (SiSRaid [Boot | Stopped])
[2003/12/09 01:50:18 | 00,045,568 | —- | M] (Silicon Integrated Systems) – C:\WINDOWS\system32\drivers\sisraid1.sys – (SiSRaid1 [Boot | Stopped])
[2004/05/24 19:36:12 | 00,028,544 | —- | M] (Silicon Integrated Systems) – C:\WINDOWS\system32\drivers\sisraid2.sys – (SiSRaid2 [Boot | Stopped])
[2008/04/13 22:45:32 | 00,717,296 | —- | M] () – C:\WINDOWS\system32\drivers\sptd.sys – (sptd [Boot | Running])
[2008/04/13 13:45:12 | 00,060,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\USBAUDIO.sys – (usbaudio [On_Demand | Running])
[2004/07/06 09:45:42 | 00,060,672 | R— | M] (VIA Technologies inc,.ltd) – C:\WINDOWS\system32\drivers\viamraid.sys – (viamraid [Boot | Running])
[2003/10/01 02:59:14 | 00,077,056 | —- | M] (VIA Technologies inc,.ltd) – C:\WINDOWS\system32\drivers\viasraid.sys – (viasraid [Boot | Stopped])
[2004/08/04 07:00:00 | 00,012,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\ws2ifsl.sys – (WS2IFSL [System | Running])
[2005/05/06 07:27:00 | 00,232,064 | —- | M] (Marvell) – C:\WINDOWS\system32\drivers\yk51x86.sys – (yukonwxp [On_Demand | Running])

========== (R ) Internet Explorer ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.daemon-search.com/startpage

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) – C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
"ProxyOverride" = localhost

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://securityresponse.symantec.com/avcenter/fix_homepage/

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://securityresponse.symantec.com/avcenter/fix_homepage/

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.daemon-search.com/startpage


[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) – C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
"ProxyOverride" = localhost

========== (O1) Hosts File ==========

HOSTS File = (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries…
127.0.0.1 localhost

========== (O2) BHO's ==========

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) – C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)

========== (O3) Toolbars ==========

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{C4069E3A-68F1-403E-B40E-20066696354B}" (HKLM) – Reg Error: Key does not exist or could not be opened. File not found

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{C4069E3A-68F1-403E-B40E-20066696354B}" (HKLM) – Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{C4069E3A-68F1-403E-B40E-20066696354B}" (HKLM) – Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{C4069E3A-68F1-403E-B40E-20066696354B}" (HKLM) – Reg Error: Key does not exist or could not be opened. File not found

========== (O4) Run Keys ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
"ConnectionManager"=C:\Program Files\Winsim\ConnectionManager\Simply.SystemTrayIcon.exe (Sage Software)
"CTDVDDET"="C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE" (Creative Technology Ltd)
"CTHelper"=CTHELPER.EXE (Creative Technology Ltd)
"CTSysVol"="C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r (Creative Technology Ltd)
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" (Microsoft Corporation)
"HP Software Update"=C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
"HPDJ Taskbar Utility"=C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe (HP)
"HPHmon05"=C:\WINDOWS\system32\hphmon05.exe (Hewlett-Packard)
"HPHUPD05"="C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" (Hewlett-Packard)
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide ()
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" /AllUsers (Microsoft® Corporation)
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" (Microsoft® Corporation)
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
"nwiz"=nwiz.exe /install ()
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
"RoxioEngineUtility"="C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe" (Roxio)
"SBDrvDet"="C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" /r (Creative Technology Ltd)
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
"UpdReg"=C:\WINDOWS\UpdReg.EXE (Creative Technology Ltd.)
"WorksFUD"="C:\Program Files\Microsoft Works\wkfud.exe" (Microsoft® Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun (DT Soft Ltd)
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
"RemoteCenter"="C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE" (Creative Technology Ltd)
"WeatherEye"=C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye (MétéoMédia/The Weather Network)
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (Microsoft Corporation)

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun (DT Soft Ltd)
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
"RemoteCenter"="C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE" (Creative Technology Ltd)
"WeatherEye"=C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye (MétéoMédia/The Weather Network)
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)

========== (O4) Startup Folders ==========

[2005/12/12 15:05:30 | 00,221,247 | —- | M] (American Power Conversion Corporation) – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
[2007/01/02 21:40:10 | 00,210,520 | —- | M] (Hewlett-Packard Co.) – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
[2004/05/29 00:06:36 | 00,053,248 | —- | M] (Hewlett-Packard Co.) – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
[2008/11/01 12:15:46 | 00,067,128 | —- | M] (Logitech Inc.) – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
[2004/07/15 12:56:56 | 00,581,632 | —- | M] (Logitech Inc.) – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
[2001/08/07 18:06:54 | 00,024,633 | —- | M] (Microsoft® Corporation) – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
[2004/02/05 14:28:16 | 00,118,784 | —- | M] (Nikon Corporation) – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
[2007/02/05 15:40:46 | 00,118,784 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
[2008/02/05 15:29:20 | 00,054,512 | —- | M] (Yahoo! Inc.) – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
[2007/12/07 20:44:36 | 00,101,440 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\user\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

========== (O6 & O7) Current Version Policies ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableRegistryTools"=0

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"CDRAutoRun"=0
"NoDriveAutoRun"=67108863

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"CDRAutoRun"=0
"NoDriveAutoRun"=67108863

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

========== (O8) IE Context Menu Extensions ==========

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\Office12\EXCEL.EXE [2008/10/18 19:30:22 | 17,931,616 | —- | M] (Microsoft Corporation)

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE File not found

[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE File not found

[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\Office12\EXCEL.EXE [2008/10/18 19:30:22 | 17,931,616 | —- | M] (Microsoft Corporation)

========== (O9) IE Extensions ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console – %ProgramFiles%\Java\jre6\bin\npjpi160_11.dll [2008/12/10 12:12:50 | 00,132,504 | —- | M] (Sun Microsystems, Inc.)
{2670000A-7350-4f3c-8081-5663EE0C6C49}: Button: Send to OneNote – %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [2007/12/13 02:20:58 | 00,606,288 | —- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}: Menu: S&end to OneNote – %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [2007/12/13 02:20:58 | 00,606,288 | —- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research – %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [2006/10/26 20:12:22 | 00,040,424 | —- | M] (Microsoft Corporation)
{e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 – %SystemRoot%\network diagnostic\xpnetdiag.exe [2008/04/13 13:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger – %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger – %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre6\bin\npjpi160_11.dll [Sun Java Console] -> [2008/12/10 12:12:50 | 00,132,504 | —- | M] (Sun Microsystems, Inc.)
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [Research] -> [2006/10/26 20:12:22 | 00,040,424 | —- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre6\bin\npjpi160_11.dll [Sun Java Console] -> [2008/12/10 12:12:50 | 00,132,504 | —- | M] (Sun Microsystems, Inc.)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre6\bin\npjpi160_11.dll [Sun Java Console] -> [2008/12/10 12:12:50 | 00,132,504 | —- | M] (Sun Microsystems, Inc.)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre6\bin\npjpi160_11.dll [Sun Java Console] -> [2008/12/10 12:12:50 | 00,132,504 | —- | M] (Sun Microsystems, Inc.)
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [Research] -> [2006/10/26 20:12:22 | 00,040,424 | —- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)

========== (O12) Internet Explorer Plugins ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = http://activex.microsoft.com/controls/find…=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery

========== (O13) Default Prefixes ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://

========== (O15) Trusted Sites ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
1 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
aol.com\free: http in Local intranet
35 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
33 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
33 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
33 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
33 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
aol.com\free: http in Local intranet
35 domain(s) and sub-domain(s) not assigned to a zone.

========== (O16) DPF ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{0B79F48A-E8D6-11DB-9283-E25056D89593}: http://support.f-secure.com/ols/fscax.cab – F-Secure Online Scanner 3.1
{0E5F0222-96B9-11D3-8997-00104BD12D94}: http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB – PCPitstop Utility
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}: http://www.kaspersky.com/kos/eng/partner/2…can_unicode.cab – CKAVWebScan Object
{17492023-C23A-453E-A040-C7C580BBF700}: http://go.microsoft.com/fwlink/?linkid=39204 – Windows Genuine Advantage Validation Tool
{33564D57-0000-0010-8000-00AA00389B71}: http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB – Reg Error: Key does not exist or could not be opened.
{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}: http://office.microsoft.com/officeupdate/content/opuc3.cab – Office Update Installation Engine
{56762DEC-6B0D-4AB4-A8AD-989993B5D08B}: http://www.eset.eu/buxus/docs/OnlineScanner.cab – OnlineScanner Control
{6414512B-B978-451D-A0D8-FCFDF33E833C}: http://update.microsoft.com/windowsupdate/…b?1120829558027 – WUWebControl Class
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}: http://update.microsoft.com/microsoftupdat…b?1136849927000 – MUWebControl Class
{7B297BFD-85E4-4092-B2AF-16A91B2EA103}: http://www3.ca.com/securityadvisor/virusinfo/webscan.cab – WScanCtl Class
{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_11
{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}: http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab – Java Plug-in 1.5.0_11
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_01
{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_02
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_03
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_05
{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_06
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_07
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_11
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_11
{D27CDB6E-AE6D-11CF-96B8-444553540000}: http://download.macromedia.com/pub/shockwa…ash/swflash.cab – Shockwave Flash Object

========== (O17) DNS Name Servers ==========

{B66F470E-2EE2-499F-8CA2-0CEE25E0EB09} (Servers: | Description: )
{C4158F05-7D38-4C3C-9688-880B6D336870} (Servers: | Description: Marvell Yukon 88E8053 PCI-E Gigabit Ethernet Controller)
{CAD443DA-676E-4FAE-B114-A63FCB8974BF} (Servers: | Description: 1394 Net Adapter)
{ED77007E-0B02-466E-8D67-EBF7110D07E4} (Servers: | Description: )
{F03B4758-FF56-4F74-B713-CD05D160D368} (Servers: | Description: )

========== (O19) User Style Sheets ==========

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles]

========== (O20) Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
avgrsstarter: "DllName" = avgrsstx.dll – C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
WRNotifier: "DllName" = WRLogonNTF.dll – File not found

========== (O21) SSODL Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"CDBurn"={fbeb8a05-beee-4442-804e-409d6c4515e9} (HKLM) – CLSID or file not found.

========== Shell Execute Hooks ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}" (HKLM) – C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}" (HKLM) – C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" (HKLM) – C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

========== Safeboot Options ==========

"AlternateShell"=cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

autoAlbum.log [-i="C:\Documents and Settings\user\Local Settings\Application Data\HP\Digital Imaging\tmpAlb_20\tmpAlb_20_0.txt" -o="C:\Documents and Settings\user\Local Settings\Application Data\HP\Digital Imaging\tmpAlb_20\tmpAlb_20_0_out.txt" -g -b -s=4 -f="text"input text file: C:\Documents and Settings\user\Local Settings\Application Data\HP\Digital Imaging\tmpAlb_20\tmpAlb_20_0.txt | output file: C:\Documents and Settings\user\Local Settings\Application Data\HP\Digital Imaging\tmpAlb_20\tmpAlb_20_0_out.txt | | Value of width is 1165 and ht is 1701creating book layout … | layout is complete, writing output file of type 1… | ]
[2008/01/16 21:23:35 | 00,000,623 | —- | M] () – C:\autoAlbum.log – [ NTFS ]

AUTOEXEC.BAT []
[2005/07/08 08:20:19 | 00,000,000 | —- | M] () – C:\AUTOEXEC.BAT – [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[11 C:\WINDOWS\*.tmp files]
[2009/01/31 10:23:59 | 00,422,912 | —- | C] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTViewIt.exe
[2009/01/31 09:49:05 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/31 01:00:09 | 00,000,000 | R–D | C] – C:\Documents and Settings\user\Desktop\Games
[2009/01/30 20:32:31 | 00,000,000 | —D | C] – C:\Program Files\EsetOnlineScanner
[2009/01/30 20:22:22 | 00,000,319 | —- | C] () – C:\Documents and Settings\user\My Documents\My Documents.lnk
[2009/01/30 20:04:34 | 00,000,000 | —D | C] – C:\Rooter$
[2009/01/30 01:03:21 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2009/01/30 00:41:52 | 00,000,211 | —- | C] () – C:\Boot.bak
[2009/01/30 00:41:49 | 00,260,272 | —- | C] () – C:\cmldr
[2009/01/30 00:41:47 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/01/30 00:40:10 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/01/30 00:40:10 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/01/30 00:40:10 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/01/30 00:40:10 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/01/30 00:40:10 | 00,089,504 | —- | C] (Smallfrogs Studio) – C:\WINDOWS\fdsv.exe
[2009/01/30 00:40:10 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/01/30 00:40:10 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/01/30 00:40:10 | 00,049,152 | —- | C] () – C:\WINDOWS\VFIND.exe
[2009/01/30 00:40:10 | 00,029,696 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/01/30 00:40:05 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/01/30 00:40:05 | 00,000,000 | —D | C] – C:\Qoobox
[2009/01/30 00:38:15 | 03,048,418 | R— | C] () – C:\Documents and Settings\user\Desktop\ComboFix.exe
[2009/01/30 00:05:47 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\WinRAR
[2009/01/30 00:02:02 | 00,010,520 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/01/29 23:54:32 | 21,458,98496 | -HS- | C] () – C:\hiberfil.sys
[2009/01/29 23:22:06 | 00,578,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\user32.dll
[2009/01/29 23:15:48 | 00,000,000 | —D | C] – C:\WINDOWS\ERUNT
[2009/01/29 23:02:40 | 00,000,000 | —D | C] – C:\SDFix
[2009/01/29 17:29:39 | 00,401,720 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\user\Desktop\HiJackThis.exe
[2009/01/29 10:38:51 | 00,030,208 | —- | C] () – C:\Documents and Settings\user\My Documents\Cover Letter Volunteer and Event Coordinator.doc
[2009/01/29 10:09:11 | 00,014,227 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Volunteer and Event Coordinator.docx
[2009/01/28 16:52:46 | 00,225,122 | —- | C] () – C:\Documents and Settings\All Users\Documents\Awards1.jpg
[2009/01/28 12:44:08 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\EA
[2009/01/27 11:49:27 | 00,031,232 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Office Receptionist.doc
[2009/01/25 21:25:37 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\December 2008
[2009/01/25 21:23:13 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\January 2009
[2009/01/23 09:00:38 | 00,000,000 | —D | C] – C:\Program Files\Games
[2009/01/22 22:45:54 | 00,000,000 | —D | C] – C:\WINDOWS\Parking Dash
[2009/01/22 22:45:54 | 00,000,000 | —D | C] – C:\Program Files\Parking Dash
[2009/01/22 11:01:27 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\blg
[2009/01/22 11:01:27 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\blg
[2009/01/22 10:33:28 | 00,000,000 | —D | C] – C:\Program Files\LeeGTs Games
[2009/01/21 20:04:06 | 00,000,000 | —D | C] – C:\WINDOWS\Operation Mania
[2009/01/21 20:04:06 | 00,000,000 | —D | C] – C:\Program Files\Operation Mania
[2009/01/21 14:06:16 | 00,014,387 | —- | C] () – C:\Documents and Settings\user\My Documents\Cover Letter Human Resources Generalist.docx
[2009/01/21 13:58:33 | 00,014,471 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Human Resources Generalist.docx
[2009/01/21 13:42:59 | 00,014,493 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Project Administrator.docx
[2009/01/15 16:46:32 | 00,030,720 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Executive Assistant 2.doc
[2009/01/15 16:45:56 | 00,030,720 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Executive Assistant.doc
[2009/01/15 16:45:31 | 00,030,208 | —- | C] () – C:\Documents and Settings\user\My Documents\Cover Letter Executive Assistant 2.doc
[2009/01/15 14:33:55 | 00,014,280 | —- | C] () – C:\Documents and Settings\user\My Documents\Cover Letter Executive Assistant.docx
[2009/01/15 14:16:59 | 00,014,419 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Executive Assistant.docx
[2009/01/15 13:01:23 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\Home Sweet Home 2
[2009/01/15 10:07:46 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\PetShowCraze
[2009/01/15 10:07:29 | 00,000,000 | —D | C] – C:\WINDOWS\Home Sweet Home 2 Kitchens and Baths
[2009/01/15 10:07:29 | 00,000,000 | —D | C] – C:\Program Files\Home Sweet Home 2 Kitchens and Baths
[2009/01/15 10:07:02 | 00,000,000 | —D | C] – C:\WINDOWS\Restaurant Rush
[2009/01/15 10:07:02 | 00,000,000 | —D | C] – C:\Program Files\Restaurant Rush
[2009/01/15 10:05:36 | 00,000,000 | —D | C] – C:\WINDOWS\Pet Show Craze
[2009/01/14 23:20:25 | 00,000,000 | —D | C] – C:\WINDOWS\Beach Party Craze
[2009/01/14 23:20:25 | 00,000,000 | —D | C] – C:\Program Files\Beach Party Craze
[2009/01/14 17:18:24 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\FreshGames
[2009/01/14 17:17:22 | 00,000,000 | —D | C] – C:\WINDOWS\Ranch Rush
[2009/01/14 17:17:22 | 00,000,000 | —D | C] – C:\Program Files\Ranch Rush
[2009/01/14 15:42:42 | 00,000,000 | —D | C] – C:\Program Files\Mystic Inn
[2009/01/14 13:02:20 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
[2009/01/14 13:01:37 | 00,000,000 | —D | C] – C:\WINDOWS\Farm Frenzy 2
[2009/01/14 13:01:36 | 00,000,000 | —D | C] – C:\Program Files\Farm Frenzy 2
[2009/01/13 09:07:18 | 00,013,704 | —- | C] () – C:\Documents and Settings\user\My Documents\Cover Letter Regional Intake Officers Métis Nation.docx
[2009/01/13 08:45:17 | 00,014,343 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Regional Intake Officers.docx
[2009/01/11 10:14:59 | 00,000,000 | —D | C] – C:\WINDOWS\Wedding Dash 2 - Rings Around the World
[2009/01/11 10:14:59 | 00,000,000 | —D | C] – C:\Program Files\Wedding Dash 2 - Rings Around the World
[2009/01/09 23:44:31 | 00,000,000 | —D | C] – C:\Program Files\Wedding Dash
[2009/01/09 13:44:31 | 00,219,158 | —- | C] () – C:\Documents and Settings\user\Desktop\petey.jpg
[2009/01/09 12:02:01 | 00,014,375 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Pharmacy Technician.docx
[2009/01/09 11:58:33 | 00,014,402 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Office Coordinator.docx
[2009/01/09 10:39:29 | 00,014,436 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume PT Studies Coordinator.docx
[2009/01/09 10:38:44 | 00,013,986 | —- | C] () – C:\Documents and Settings\user\My Documents\Cover Letter PT Studies Coordinator.docx
[2009/01/05 13:26:51 | 00,014,395 | —- | C] () – C:\Documents and Settings\user\My Documents\Combo Style Resume Karri.docx

========== Files - Modified Within 30 Days ==========

[5 C:\WINDOWS\System32\*.tmp files]
[11 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\user\My Documents\*.tmp files]
[2009/01/31 12:38:05 | 00,000,032 | —- | M] () – C:\WINDOWS\buff-out.ogf
[2009/01/31 12:38:03 | 00,070,432 | —- | M] () – C:\WINDOWS\buff-in.r72
[2009/01/31 12:38:03 | 00,000,032 | —- | M] () – C:\WINDOWS\buff-out.r72
[2009/01/31 12:38:03 | 00,000,032 | —- | M] () – C:\WINDOWS\buff-in.ogf
[2009/01/31 12:37:32 | 00,000,208 | —- | M] () – C:\WINDOWS\jantje
[2009/01/31 10:24:20 | 00,422,912 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTViewIt.exe
[2009/01/31 09:55:03 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/01/31 09:53:21 | 00,020,712 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/01/31 09:53:11 | 04,932,286 | —- | M] () – C:\WINDOWS\{00000000-00000000-0000000B-00001102-00000004-20021102}.CDF
[2009/01/31 09:51:58 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/01/31 09:51:45 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/01/31 09:51:43 | 21,458,98496 | -HS- | M] () – C:\hiberfil.sys
[2009/01/31 09:50:45 | 00,003,048 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2009/01/31 09:50:45 | 00,003,048 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2009/01/31 09:50:45 | 00,000,384 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000000-00000000-0000000B-00001102-00000004-20021102}.dat
[2009/01/31 09:50:45 | 00,000,384 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000000-00000000-0000000B-00001102-00000004-20021102}.dat
[2009/01/31 09:50:44 | 00,031,056 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000000-00000000-0000000B-00001102-00000004-20021102}.rfx
[2009/01/31 09:50:44 | 00,031,056 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000000-00000000-0000000B-00001102-00000004-20021102}.rfx
[2009/01/31 09:50:44 | 00,030,528 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000000-00000000-0000000B-00001102-00000004-20021102}.rfx
[2009/01/31 09:50:44 | 00,030,528 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000000-00000000-0000000B-00001102-00000004-20021102}.rfx
[2009/01/30 20:22:22 | 00,000,319 | —- | M] () – C:\Documents and Settings\user\My Documents\My Documents.lnk
[2009/01/30 17:03:21 | 32,607,818 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/01/30 09:40:48 | 00,082,350 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/01/30 00:43:50 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/01/30 00:41:52 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/01/30 00:38:51 | 03,048,418 | R— | M] () – C:\Documents and Settings\user\Desktop\ComboFix.exe
[2009/01/30 00:02:02 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/01/30 00:02:02 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/01/30 00:02:02 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/01/29 23:23:36 | 00,000,686 | —- | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS
[2009/01/29 23:22:06 | 00,578,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\user32.dll
[2009/01/29 23:08:44 | 05,332,966 | -H– | M] () – C:\Documents and Settings\user\Local Settings\Application Data\IconCache.db
[2009/01/29 17:29:48 | 00,401,720 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\user\Desktop\HiJackThis.exe
[2009/01/29 12:33:58 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/29 12:20:33 | 00,000,125 | —- | M] () – C:\ioSpecial.ini
[2009/01/29 10:38:51 | 00,030,208 | —- | M] () – C:\Documents and Settings\user\My Documents\Cover Letter Volunteer and Event Coordinator.doc
[2009/01/29 10:09:11 | 00,014,227 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Volunteer and Event Coordinator.docx
[2009/01/28 16:52:46 | 00,225,122 | —- | M] () – C:\Documents and Settings\All Users\Documents\Awards1.jpg
[2009/01/27 11:49:28 | 00,031,232 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Office Receptionist.doc
[2009/01/27 09:02:04 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/01/21 14:06:16 | 00,014,387 | —- | M] () – C:\Documents and Settings\user\My Documents\Cover Letter Human Resources Generalist.docx
[2009/01/21 13:58:33 | 00,014,471 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Human Resources Generalist.docx
[2009/01/21 13:42:59 | 00,014,493 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Project Administrator.docx
[2009/01/15 16:46:33 | 00,030,720 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Executive Assistant 2.doc
[2009/01/15 16:45:57 | 00,030,720 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Executive Assistant.doc
[2009/01/15 16:45:32 | 00,030,208 | —- | M] () – C:\Documents and Settings\user\My Documents\Cover Letter Executive Assistant 2.doc
[2009/01/15 14:48:47 | 00,197,120 | -HS- | M] () – C:\Documents and Settings\user\My Documents\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\user\My Documents\Thumbs.db:encryptable
[2009/01/15 14:33:55 | 00,014,280 | —- | M] () – C:\Documents and Settings\user\My Documents\Cover Letter Executive Assistant.docx
[2009/01/15 14:16:59 | 00,014,419 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Executive Assistant.docx
[2009/01/14 16:11:32 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/14 16:11:28 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/13 09:07:18 | 00,013,704 | —- | M] () – C:\Documents and Settings\user\My Documents\Cover Letter Regional Intake Officers Métis Nation.docx
[2009/01/13 08:45:17 | 00,014,343 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Regional Intake Officers.docx
[2009/01/09 20:35:28 | 20,853,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/09 20:18:51 | 00,039,424 | —- | M] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/09 13:40:19 | 00,219,158 | —- | M] () – C:\Documents and Settings\user\Desktop\petey.jpg
[2009/01/09 12:02:02 | 00,014,375 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Pharmacy Technician.docx
[2009/01/09 11:58:33 | 00,014,402 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Office Coordinator.docx
[2009/01/09 10:39:29 | 00,014,436 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume PT Studies Coordinator.docx
[2009/01/09 10:38:45 | 00,013,986 | —- | M] () – C:\Documents and Settings\user\My Documents\Cover Letter PT Studies Coordinator.docx
[2009/01/08 21:22:43 | 00,014,395 | —- | M] () – C:\Documents and Settings\user\My Documents\Combo Style Resume Karri.docx
< End of report >

___________________________________________________

OTViewIt Extras logfile created on: 1/31/2009 12:44:32 PM - Run
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\user\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.24 Gb Available Physical Memory | 62.17% Memory free
3.35 Gb Paging File | 2.65 Gb Available in Paging File | 79.15% Paging File free
Paging file location(s): c:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.31 Gb Total Space | 82.02 Gb Free Space | 44.03% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TOUGAS3
Current User Name: user
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
"Use My Stylesheet"=
"User Stylesheet"=

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled"=1
"AntiVirusDisableNotify"=0
"FirewallDisableNotify"=0
"UpdatesDisableNotify"=0
"AntiVirusOverride"=0
"FirewallOverride"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall"=1
"DoNotAllowExceptions"=0
"DisableNotifications"=0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008/04/13 19:12:34 | 00,141,312 | —- | M] (Microsoft Corporation) – %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
File not found – C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)
[2008/04/13 13:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2007/01/19 13:54:56 | 05,674,352 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
[2007/01/04 17:10:02 | 00,297,752 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
[2008/11/01 12:15:46 | 00,067,128 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2008/04/13 19:12:34 | 00,141,312 | —- | M] (Microsoft Corporation) – %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation) – C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
File not found – C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
[2006/10/10 12:53:46 | 00,010,800 | —- | M] (AOL LLC) – C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader
[2006/05/09 19:24:16 | 00,050,760 | —- | M] (America Online, Inc.) – C:\Program Files\Common Files\AOL\1134336249\ee\aolsoftware.exe:*:Enabled:AOL Services
[2006/08/28 15:22:24 | 00,050,768 | —- | M] (America Online, Inc.) – C:\Program Files\Common Files\AOL\1134336249\ee\aim6.exe:*:Enabled:AIM
[2006/10/17 12:56:10 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\mshta.exe:*:Enabled:Microsoft ® HTML Application host
[2008/06/10 18:04:58 | 00,689,456 | —- | M] (Hewlett-Packard) – C:\Program Files\Hewlett-Packard\HP Software Update\HPWUCli.exe:*:Enabled:HP Software Update Client
File not found – C:\Program Files\Java\jre1.5.0_07\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary
[2006/07/28 15:11:12 | 02,109,440 | —- | M] (mIRC Co. Ltd.) – C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC
[2008/10/27 17:05:49 | 00,270,128 | —- | M] (BitTorrent, Inc.) – C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent
File not found – C:\Program Files\Java\jre1.5.0_09\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary
[2008/04/13 13:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008/12/19 14:16:34 | 00,307,704 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox
[2008/02/05 15:29:18 | 06,190,320 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Jukebox
[2008/05/22 21:14:46 | 00,214,560 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer
[2008/05/21 04:37:24 | 12,844,576 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook
[2007/08/29 00:23:36 | 00,340,856 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove
[2008/05/21 05:54:40 | 01,022,496 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote
[2009/01/29 23:07:05 | 01,032,984 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe
[2007/05/18 00:00:00 | 04,583,424 | —- | M] () – C:\Program Files\Winsim\ConnectionManager\MySqlBinary\5.0.38\mysql\mysqld-nt.exe:*:Enabled:mysqld-nt.exe 5.0.38
[2008/06/06 00:00:00 | 00,018,216 | —- | M] (Sage Software) – C:\Program Files\Winsim\ConnectionManager\SimplyConnectionManager.exe:*:Enabled:SimplyConnectionManager.exe
[2007/01/19 13:54:56 | 05,674,352 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
[2007/01/04 17:10:02 | 00,297,752 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
[2007/01/02 21:40:10 | 00,210,520 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe
[2006/12/10 21:51:08 | 00,271,960 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe
[2007/01/02 22:46:54 | 00,280,152 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe
[2007/01/02 22:46:54 | 00,053,248 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe
[2006/12/10 23:29:24 | 00,108,120 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe
[2007/01/02 17:27:40 | 00,221,184 | —- | M] () – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe
[2007/01/02 17:27:38 | 01,138,688 | —- | M] (Hewlett-Packard) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe
[2004/05/29 00:06:26 | 00,512,000 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcopy.exe:*:Enabled:hpqcopy.exe
[2007/01/02 22:46:54 | 00,472,664 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe
[2006/02/09 16:43:36 | 00,110,592 | R— | M] (Hewlett-Packard) – C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe
[2006/02/09 16:41:28 | 00,573,440 | —- | M] ( ) – C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe
[2006/12/10 23:29:24 | 00,075,352 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe
[2008/11/01 12:15:46 | 00,067,128 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger
[2008/11/20 14:20:48 | 14,294,824 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
[2008/11/07 14:31:38 | 21,633,320 | R— | M] (Skype Technologies S.A.) – C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype

========== (O18) Protocol Handlers ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/11/01 12:15:47 | 00,028,711 | —- | M] (Logitech Inc.) C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (bwfile-8876480:{9462A756-7B47-47BC-8C80-C34B9B80B32B} (HKLM) [BackWeb GA Pluggable Protocol])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/08/24 07:01:46 | 00,224,128 | —- | M] (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (grooveLocalGWS:{88FED34C-F0CA-4636-A375-3CB6248B04CD} (HKLM) [Local Groove Web Services Protocol])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/12/12 13:17:12 | 00,069,632 | —- | M] (Intuit Canada, a general partnership/une société en nom collectif.) C:\Program Files\QuickTax 2007\ic2007pp.dll (intu-qt2007:{026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} (HKLM) [qt2007 Pluggable Protocol Handler Class])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
ipp: [HKLM - No CLSID value]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2007/08/28 23:55:14 | 01,014,128 | —- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2009/01/30 00:02:00 | 00,079,128 | —- | M] (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG8\avgpp.dll (linkscanner:{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} (HKLM) [XPLPPFilter Class])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/01/19 12:53:24 | 00,063,344 | —- | M] (Microsoft Corporation) C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (livecall:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
msdaipp: [HKLM - No CLSID value]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2007/08/28 23:55:14 | 01,014,128 | —- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2007/08/28 23:55:14 | 01,014,128 | —- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2006/10/26 13:45:02 | 00,873,216 | —- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (ms-help:{314111c7-a502-11d2-bbca-00c04f8ec294} (HKLM) [HxProtocol Class])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/01/19 12:53:24 | 00,063,344 | —- | M] (Microsoft Corporation) C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (msnim:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/05/30 15:54:14 | 01,942,864 | R— | M] (Skype Technologies) C:\Program Files\Common Files\Skype\Skype4COM.dll (skype4com:{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} (HKLM) [IEProtocolHandler Class])

========== (O18) Protocol Filters ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters
[2006/10/26 21:41:48 | 00,044,344 | —- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL text/xml:{807563E5-5146-11D5-A672-00B0D022E945} (HKLM) [Microsoft Office InfoPath XML Mime Filter]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}"=Windows Installer Clean Up
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}"=Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}"=WebReg
"{1A15507A-8551-4626-915D-3D5FA095CC1B}"=Corel Paint Shop Pro X
"{22EC35BD-F8F2-45EB-8DCB-1C7FB65D0A71}"=QuickTax 2007
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}"=HPPhotoSmartExpress
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}"=Java™ 6 Update 11
"{2BBC9458-07CA-4843-848B-5C8146E5EFA8}"=CreativeProjects
"{2DBFBD32-00BB-4678-B77B-8F5F729842BC}"=PS7600
"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}"=Logitech SetPoint
"{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}"=ASUS Enhanced Display Driver
"{318AB667-3230-41B5-A617-CB3BF748D371}"=iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0150110}"=J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}"=Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}"=Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}"=Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}"=Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160060}"=Java™ 6 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160070}"=Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}"=PanoStandAlone
"{3666ABBE-F749-4747-BAAE-0B0712B130E4}"=Yahoo! Music Jukebox
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}"=HP Product Assistant
"{378299DC-4DA8-48B3-BD2C-4596EEDC0627}_is1"=Mystic Inn v1.0.8
"{3A1421C0-5610-46D4-8283-82F3CA755FDB}"=Roxio PhotoSuite 5
"{3AE681E0-4E8D-453F-950A-48534D3C0724}"=Copy
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}"=HPSystemDiagnostics
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}"=Google Earth
"{45B6180B-DCAB-4093-8EE8-6164457517F0}"=Photosmart 140,240,7200,7600,7700,7900 Series
"{4817189D-1785-4627-A33C-39FD90919300}"=The Sims 2 Pets
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}"=DocProc
"{4ADC0BF7-B965-11D8-AA51-00B0D0627A8E}"=Simply Accounting 2005 Basic
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}"=Adobe® Photoshop® Album Starter Edition 3.0
"{4FB600F5-C478-4DF7-A2BC-57D3807BAC91}"=BPDSoftware_Ini
"{5104B07C-6A3D-4E7E-8BBB-960B52554BDD}"=BPD_HPSU
"{517B8FB2-26EE-43B0-AE1B-07408860AA69}"=DigitImg
"{53337CA9-E9A4-4C59-9D1C-D980EF9BF0C2}"=QuickTax 2004
"{5421155F-B033-49DB-9B33-8F80F233D4D5}"=GdiplusUpgrade
"{5567F737-98A5-4CF3-8B4A-2F4E515966F7}"=Simply Accounting by Sage 2008
"{56F3E1FF-54FE-4384-A153-6CCABA097814}"=Creative MediaSource
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}"=Windows Live Messenger
"{590D4F8F-98FE-47FA-AC2B-3F22FDCF7C09}"=ShareIns
"{5A0C892E-FD1C-4203-941E-0956AED20A6A}"=APC PowerChute Personal Edition
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}"=Skype™ 3.8
"{60758250-C8CF-47EB-8CB6-E0C3B84D8207}"=PSShortcuts
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}"=Windows Genuine Advantage v1.3.0254.0
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}"=HPProductAssistant
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}"=PowerDVD
"{6909F917-5499-482e-9AA1-FAD06A99F231}"=Toolbox
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}"=Apple Software Update
"{6BDD9CE6-D0A6-478A-BAD3-BA6945E89EB0}"=The Sims 2 Family Fun Stuff
"{6DA9102E-199F-43A0-A36B-6EF48081A658}"=MobileMe Control Panel
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}"=HP Update
"{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}"=DesignPro 5.4 Limited Edition
"{7299052b-02a4-4627-81f2-1818da5d550d}"=Microsoft Visual C++ 2005 Redistributable
"{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}"=overland
"{7729A02E-D1AD-4830-8FC5-11853500D90D}"=HP Officejet Pro All-In-One Series
"{777CA290-7D14-77c5-C518-684DC520A777}_is1"=Puzzle Mania
"{78AD4938-7EE6-4DC0-A5BC-3AF82750A617}"=QuickTax Tracker
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}"=Fax
"{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}"=The Sims 2 Open For Business
"{806E137F-D829-463D-8635-01A55A734B29}_is1"=Musikapa
"{81DB3158-20CC-41B1-8281-D5422F6DEA12}"=ASUS ATI Driver
"{83EC8AE9-53A6-474D-95AF-8F5116CC9C4E}"=3D Home Architect Design Suite Deluxe 8
"{868EA922-5675-4E91-BDA6-BBD0F923C5EF}"=HP Officejet Pro All-In-One Series
"{8777AC6D-89F9-4793-8266-DE406F343E89}"=QFolder
"{8868D822-2CBA-46B2-A286-B400B6185769}"=7500_7600_7700_Help
"{8AB8D458-939E-403F-0097-9BA1C1F013D5}"=The Sims 2
"{8C5766F2-81D9-4B5A-8AD5-A8BD6361EF0A}"=Hoyle Card Games
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}"=Unload
"{8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}"=The Sims 2 University
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}"=Logitech Desktop Messenger
"{90120000-0010-0409-0000-0000000FF1CE}"=Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}"=Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0016-0409-0000-0000000FF1CE}"=Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}"=Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}"=Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}"=Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}"=Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}"=Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{3EC77D26-799B-4CD8-914F-C1565E796173}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}"=Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{430971B1-C31E-45DA-81E0-72C095BAB72C}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}"=Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}"=Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}"=Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0044-0409-0000-0000000FF1CE}"=Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-006E-0409-0000-0000000FF1CE}"=Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00A1-0409-0000-0000000FF1CE}"=Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00BA-0409-0000-0000000FF1CE}"=Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0114-0409-0000-0000000FF1CE}"=Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}"=Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0117-0409-0000-0000000FF1CE}"=Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{937B232D-9776-471E-92BD-D424E514EF14}"=Logitech QuickCam
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}"=MarketResearch
"{978C25EE-5777-46e4-8988-732C297CBDBD}"=Status
"{981FB376-8418-4EA8-BBED-9DE5AA63E7D5}"=SkinsHP1
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}"=Destinations
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}"=QuickProjects
"{9CDBC303-3EED-40b0-8E41-A7C65AA96C26}"=The Sims 2 Glamour Life Stuff
"{9E2514D9-DC24-4634-B348-61F3EF0F1628}"=Sound Blaster Audigy 2 ZS
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}"=PrintScreen
"{A06275F4-324B-4E85-95E6-87B2CD729401}"=Windows Defender
"{A1B7B9B3-E1D2-41CA-9B4A-F18DC2710704}"=Microsoft Works 6.0
"{A1DCC235-DACC-4E1F-8D11-D630634B4AEF}"=PhotoGallery
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}"=SolutionCenter
"{A495D4DC-4036-4914-9CB2-0FCF6A3166EF}"=L7500
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}"=Windows Defender Signatures
"{AC76BA86-7AD7-1033-7B44-A81300000003}"=Adobe Reader 8.1.3
"{B2E92CF8-8D2F-4203-B5C4-177174472C9A}"=The Typing of The Dead
"{B376402D-58EA-45EA-BD50-DD924EB67A70}"=HP Memories Disc
"{B45D9FEE-1AF4-46F3-9A83-2545F81547F5}"=CreativeProjectsTemplates
"{B508B3F1-A24A-32C0-B310-85786919EF28}"=Microsoft .NET Framework 2.0 Service Pack 1
"{B8D0BC3E-67DF-48A3-ACC9-EEAA8DBFBF29}"=QuickTax 2005
"{BCC992E5-5C81-4066-9B55-03DC10B24D21}"=InstantShare
"{BD3DCAB0-3FE5-44FB-90DA-EFB0A2CD1387}"=Works Synchronization
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}"=BufferChm
"{C1177B5C-6C8A-420B-84D3-287E456651F9}"=Airport Mania - First Flight
"{C3A439E4-7303-491F-A678-CEA36A87D517}"=Microsoft Works Suite Add-in for Microsoft Word
"{C4F1B9FE-F3AF-11D5-93D1-00C0CA18FDE6}"=Hotel Giant
"{C716522C-3731-4667-8579-40B098294500}"=Toolbox
"{C769A271-7E1C-48F9-B331-474600DD4C06}"=Microsoft Picture It! Photo 2002
"{C93A6CFE-2C74-428B-9CFE-6EAF1BE34BFA}"=ArcSoft Collage Creator
"{C9618743-1A5C-461E-91C4-E013A3D70F3C}"=Adobe® Photoshop® Album Starter Edition 3.0.1
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}"=Microsoft .NET Framework 1.1
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}"=Nikon Message Center
"{D361C406-ED11-4A88-AD42-4A749BBAE6F9}"=Hoyle Card Games 2007
"{D48AD533-BAD5-469B-A9AA-272C6D80E70B}"=MPM
"{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A}"=iPod for Windows 2005-10-12
"{DA83FEB1-B397-461D-B120-7B996E83ADEE}"=Simply Accounting by Sage 2008
"{DC19E750-988B-4005-A355-85EF66055EFE}"=Works Suite OS Pack
"{DE4997B5-55AD-4878-97A7-C9FA84FE23C7}"=PSUsage
"{DEB9AEF7-3ADA-40a9-9C98-546D54FE9CBD}"=ProductContext
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}"=Ad-Aware
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}"=UnloadSupport
"{EB21A812-671B-4D08-B974-2A347F0D8F70}"=HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}"=HPSSupply
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}"=Apple Mobile Device Support
"{ECAD4F6A-0BF3-4028-9C81-E5D9F9606CBA}"=BPDSoftware
"{EE7C3A14-1D20-49F6-B903-491561076F0F}"=ArcSoft Software Suite
"{F157460F-720E-482f-8625-AD7843891E5F}"=InstantShareDevicesMFC
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}"=32 Bit HP CIO Components Installer
"{F4476AF5-B402-4C62-BE7D-0182F2B15D0A}"=Simply Accounting by Sage 2008
"{F7529650-B9DB-481B-0089-A2AC3C2821C1}"=The Sims 2 Nightlife
"{F929096B-54A0-4C5C-B125-1E7EB1917412}"=MySQL Connector/ODBC 3.51
"{F958CA02-BB40-4007-894B-258729456EE4}"=QuickTime
"{FAFDA89B-1031-4BDB-8619-DE20CBDEDF32}"=QuickTax 2006
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}"=HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FF075778-6E50-47ed-991D-3B07FD4E3250}"=TrayApp
"{FF26F7EA-BCEE-478C-9A1B-6B4F88717D73}"=CueTour
"{FF3999BE-1A7B-4738-88AA-97BF14094A4A}"=PictureProject
"Adobe Flash Player Plugin"=Adobe Flash Player Plugin
"Adobe Shockwave Player"=Adobe Shockwave Player
"AIM_6.0"=AIM 6.0
"Arxon"=Arxon
"Avalon Deluxe_is1"=Avalon Deluxe v1.1.0
"AVG8Uninstall"=AVG Free 8.0
"Azangara_is1"=Azangara version 1.1
"Beach Party Craze1.0"=Beach Party Craze
"Bejeweled 2"=GameHouse Games Collection: Bejeweled 2
"BFGC"=Big Fish Games Client
"BFG-Home Sweet Home"=Home Sweet Home (remove only)
"Build-a-lot"=Build-a-lot
"Cake Mania"=Cake Mania
"Chameleon Gems"=Chameleon Gems
"Charm Tale"=GameHouse Games Collection: Charm Tale
"Chuzzle Deluxe"=GameHouse Games Collection: Chuzzle Deluxe
"Collapse! Crunch"=GameHouse Games Collection: Collapse! Crunch
"Combo Chaos!"=GameHouse Games Collection: Combo Chaos!
"Coupon Printer for Windows4.0"=Coupon Printer for Windows
"Crossing 3D_is1"=Crossing 3D 1.1
"Crystal Path"=GameHouse Games Collection: Crystal Path
"Cubis Gold 2"=GameHouse Games Collection: Cubis Gold 2
"Cursed Weel"=Cursed Weel 1.0
"Deep Sea Tycoon 2_is1"=Deep Sea Tycoon 2
"Delivery King"=Delivery King
"Diner Dash"=GameHouse Games Collection: Diner Dash
"E2BABA4F-C37B-4A6C-8F00-0D303441C2D3"=FATE from WildGames (remove only)
"Encore LaunchPad_is1"=Encore LaunchPad [removed]
"ENTERPRISE"=Microsoft Office Enterprise 2007
"EsetOnlineScanner"=ESET Online Scanner
"Farm Frenzy 21.0"=Farm Frenzy 2
"Feeding Frenzy"=GameHouse Games Collection: Feeding Frenzy
"Five Card Deluxe"=GameHouse Games Collection: Five Card Deluxe
"Flip Words"=GameHouse Games Collection: Flip Words
"Flying Leo"=GameHouse Games Collection: Flying Leo
"Fortune Tiles Gold"=GameHouse Games Collection: Fortune Tiles Gold
"Fresco Wizard"=GameHouse Games Collection: Fresco Wizard
"Gearz"=GameHouse Games Collection: Gearz
"Hamsterball"=GameHouse Games Collection: Hamsterball
"Hello!"=GameHouse Games Collection: Hello!
"HijackThis"=HijackThis 2.0.2
"Holiday Express"=GameHouse Games Collection: Holiday Express
"Home Sweet Home 2 Kitchens and Baths1.02"=Home Sweet Home 2 Kitchens and Baths
"HP Imaging Device Functions"=HP Imaging Device Functions 8.0
"HP Photo & Imaging"=HP Image Zone 4.0
"HP Solution Center & Imaging Support Tools"=HP Solution Center 8.0
"HPExtendedCapabilities"=HP Customer Participation Program 8.0
"HPOCR"=HP OCR Software 8.0
"Ice Age_is1"=Ice Age
"IDNMitigationAPIs"=Microsoft Internationalized Domain Names Mitigation APIs
"ie7"=Windows Internet Explorer 7
"Iggle Pop!"=GameHouse Games Collection: Iggle Pop!
"Incadia"=GameHouse Games Collection: Incadia
"Incredible Ink"=GameHouse Games Collection: Incredible Ink
"Insaniquarium Deluxe"=GameHouse Games Collection: Insaniquarium Deluxe
"Inspector Parker"=GameHouse Games Collection: Inspector Parker
"InstallShield_{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}"=DesignPro 5.4 Limited Edition
"InstallShield_{78AD4938-7EE6-4DC0-A5BC-3AF82750A617}"=QuickTax Tracker
"InstallShield_{83EC8AE9-53A6-474D-95AF-8F5116CC9C4E}"=3D Home Architect Design Suite Deluxe 8
"InstallShield_{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A}"=iPod for Windows 2005-10-12
"Invadazoid"=GameHouse Games Collection: Invadazoid
"Jewel Quest"=GameHouse Games Collection: Jewel Quest
"Kaspersky Online Scanner"=Kaspersky Online Scanner
"legacyqcam_11.10"=Logitech Legacy USB Camera Driver Package
"Lemonade Tycoon"=GameHouse Games Collection: Lemonade Tycoon
"Lemonade Tycoon 2_is1"=Lemonade Tycoon 2
"Logitech Print Service"=Logitech Print Service
"Luxor"=GameHouse Games Collection: Luxor
"lvdrivers_11.90"=Logitech QuickCam Driver Package
"Mad Caps"=GameHouse Games Collection: Mad Caps
"Magic Ball 2"=GameHouse Games Collection: Magic Ball 2
"Magic Ball 2 - New Worlds"=GameHouse Games Collection: Magic Ball 2 - New Worlds
"Magic Ball Deluxe"=GameHouse Games Collection: Magic Ball
"Magic Inlay"=GameHouse Games Collection: Magic Inlay
"Magic Tea"=Magic Tea
"Magic Vines"=GameHouse Games Collection: Magic Vines
"Mah Jong Adventures"=GameHouse Games Collection: Mah Jong Adventures
"Mah Jong Medley"=GameHouse Games Collection: Mah Jong Medley
"Malwarebytes' Anti-Malware_is1"=Malwarebytes' Anti-Malware
"Maui Wowee"=GameHouse Games Collection: Maui Wowee
"Microsoft .NET Framework 1.1 (1033)"=Microsoft .NET Framework 1.1
"Mindlink2005Underground"=Mindlink2005Underground (remove only)
"Mirage Driver_is1"=Mirage Driver 1.1
"mIRC"=mIRC
"Mozilla Firefox (3.0.5)"=Mozilla Firefox (3.0.5)
"MSCompPackV1"=Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST"=MSN
"Mysteries of Horus"=Mysteries of Horus
"Nero - Burning Rom!UninstallKey"=Nero OEM
"NeroVision!UninstallKey"=NeroVision Express 2
"NLSDownlevelMapping"=Microsoft National Language Support Downlevel APIs
"NMPUninstallKey"=Nero Media Player
"NVIDIA Drivers"=NVIDIA Drivers
"Operation Mania1.0.5"=Operation Mania
"Parking Dash1.0"=Parking Dash
"Phantasia 2"=Phantasia 2 1.02
"Phlinx To Go"=GameHouse Games Collection: Phlinx To Go
"Picasa2"=Picasa 2
"Pin High Country Club Golf"=GameHouse Games Collection: Pin High Country Club Golf
"Pizza Frenzy"=GameHouse Games Collection: Pizza Frenzy
"Platypus"=GameHouse Games Collection: Platypus
"Poker Superstars"=GameHouse Games Collection: Poker Superstars
"PopCap Browser Plugin"=PopCap Browser Plugin
"Puzzle Express"=GameHouse Games Collection: Puzzle Express
"Puzzle Inlay"=GameHouse Games Collection: Puzzle Inlay
"Puzzle Solitaire"=GameHouse Games Collection: Puzzle Solitaire
"QBz"=GameHouse Games Collection: QBz
"Ranch Rush1.0"=Ranch Rush
"Reader's Digest Super Word Power"=GameHouse Games Collection: Reader's Digest Super Word Power
"RealPlayer 6.0"=RealPlayer
"Ricochet"=GameHouse Games Collection: Ricochet
"Ricochet Lost Worlds"=GameHouse Games Collection: Ricochet Lost Worlds
"Ricochet Lost Worlds: Recharged"=GameHouse Games Collection: Ricochet Lost Worlds - Recharged
"Roboball"=Roboball
"Roller Rush"=GameHouse Games Collection: Roller Rush
"RotoBlox_is1"=RotoBlox version 2.2
"Saints & Sinners Bingo"=GameHouse Games Collection: Saints & Sinners Bingo
"Sandlot Games Client Services 1.2.2_is1"=Sandlot Games Client Services 1.2.2
"Sandlot Games Client Services_is1"=Sandlot Games Client Services
"SCRABBLE"=GameHouse Games Collection: SCRABBLE
"Sea Bounty"=Sea Bounty
"Shape Shifter"=GameHouse Games Collection: Shape Shifter
"ShockwaveFlash"=Adobe Flash Player 9 ActiveX
"Slingo Deluxe"=GameHouse Games Collection: Slingo Deluxe
"Spelvin"=GameHouse Games Collection: Spelvin
"Splash"=GameHouse Games Collection: Splash
"Spring Sprang Sprung"=GameHouse Games Collection: Spring Sprang Sprung
"Spybot - Search & Destroy_is1"=Spybot - Search & Destroy 1.4
"Super 5-Line Slots"=GameHouse Games Collection: Super 5-Line Slots
"Super Blackjack!"=GameHouse Games Collection: Super Blackjack!
"Super Bounce Out!"=GameHouse Games Collection: Super Bounce Out!
"Super Candy Cruncher"=GameHouse Games Collection: Super Candy Cruncher
"Super Collapse!"=GameHouse Games Collection: Super Collapse!
"Super Collapse! II"=GameHouse Games Collection: Super Collapse! II
"Super Collapse! II Platinum"=GameHouse Games Collection: Super Collapse! II Platinum
"Super Fruit Frolic"=GameHouse Games Collection: Super Fruit Frolic
"Super GameHouse Solitaire Vol. 1"=GameHouse Games Collection: Super GameHouse Solitaire Vol. 1
"Super GameHouse Solitaire Vol. 2"=GameHouse Games Collection: Super GameHouse Solitaire Vol. 2
"Super GameHouse Solitaire Vol. 3"=GameHouse Games Collection: Super GameHouse Solitaire Vol. 3
"Super Gem Drop"=GameHouse Games Collection: Super Gem Drop
"Super Glinx!"=GameHouse Games Collection: Super Glinx!
"Super Letter Linker"=GameHouse Games Collection: Super Letter Linker
"Super Mah Jong Solitaire"=GameHouse Games Collection: Super Mah Jong Solitaire
"Super Nisqually"=GameHouse Games Collection: Super Nisqually
"Super PileUp!"=GameHouse Games Collection: Super PileUp!
"Super Pool"=GameHouse Games Collection: Super Pool
"Super Pop & Drop!"=GameHouse Games Collection: Super Pop & Drop!
"Super Rumble Cube"=GameHouse Games Collection: Super Rumble Cube
"Super SpongeBob Collapse!"=GameHouse Games Collection: Super SpongeBob Collapse!
"Super TextTwist"=GameHouse Games Collection: Super TextTwist
"Super WHATword"=GameHouse Games Collection: Super WHATword
"Super Wild Wild Words"=GameHouse Games Collection: Super Wild Wild Words
"SysInfo"=Creative System Information
"Tap a Jam"=GameHouse Games Collection: Tap a Jam
"Ten Pin Championship Bowling Pro"=GameHouse Games Collection: Ten Pin Championship Bowling Pro
"Tennis Titans"=GameHouse Games Collection: Tennis Titans
"Tetpic 4000(v2.6 Full Version)"=Tetpic 4000(v2.6 Full Version)
"The Treasures Of Montezuma"=The Treasures Of Montezuma
"Tradewinds 2"=GameHouse Games Collection: Tradewinds 2
"Trivia Machine"=GameHouse Games Collection: Trivia Machine
"Tropical Swaps"=GameHouse Games Collection: Tropical Swaps
"TUGZip_is1"=TUGZip 3.4
"Tumblebugs"=GameHouse Games Collection: Tumblebugs
"Turtle Bay"=GameHouse Games Collection: Turtle Bay
"Twistingo"=GameHouse Games Collection: Twistingo
"Ultimate Dominoes"=GameHouse Games Collection: Ultimate Dominoes
"uTorrent"=µTorrent
"Vanilla and Chocolate FINAL 1.00"=Vanilla and Chocolate FINAL 1.00
"Varmintz Deluxe"=GameHouse Games Collection: Varmintz Deluxe
"Walls of Jericho, The"=GameHouse Games Collection: Walls of Jericho, The
"Wedding Dash 2 - Rings Around the World1.0"=Wedding Dash 2 - Rings Around the World
"Wheel of Fortune"=GameHouse Games Collection: Wheel of Fortune
"Windows Media Format Runtime"=Windows Media Format 11 runtime
"Windows Media Player"=Windows Media Player 11
"Windows XP Service Pack"=Windows XP Service Pack 3
"WMCSetup"=Windows Media Connect
"WMFDist11"=Windows Media Format 11 runtime
"wmp11"=Windows Media Player 11
"Wonderland Online_is1"=Wonderland Online 2.0.3
"Word Jolt"=GameHouse Games Collection: Word Jolt
"Word Slinger"=GameHouse Games Collection: Word Slinger
"WordJong To Go"=GameHouse Games Collection: WordJong To Go
"Works2002Setup"=Microsoft Works 2002 Setup Launcher
"Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0
"Zoo Tycoon 1.0"=Zoo Tycoon: Complete Collection
"Zuma Deluxe"=GameHouse Games Collection: Zuma Deluxe

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent"=µTorrent
"WeatherEye"=WeatherEye

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent"=µTorrent
"WeatherEye"=WeatherEye

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/28/2009 4:04:41 PM | Computer Name = TOUGAS3 | Source = Application Error | ID = 1000
Description = Faulting application pet show craze.exe, version 0.0.0.0, faulting
module pet show craze.exe, version 0.0.0.0, fault address 0x0007264a.

Error - 1/28/2009 4:11:28 PM | Computer Name = TOUGAS3 | Source = Application Error | ID = 1000
Description = Faulting application pet show craze.exe, version 0.0.0.0, faulting
module pet show craze.exe, version 0.0.0.0, fault address 0x0007264a.

Error - 1/29/2009 5:58:09 PM | Computer Name = TOUGAS3 | Source = Outlook | ID = 34
Description = Failed to get the Crawl Scope Manager with error=0x8001010d.

Error - 1/29/2009 5:58:09 PM | Computer Name = TOUGAS3 | Source = Outlook | ID = 35
Description = Failed to determine if the store is in the crawl scope (error=0x8001010d).

Error - 1/29/2009 5:58:09 PM | Computer Name = TOUGAS3 | Source = Outlook | ID = 35
Description = Failed to determine if the store is in the crawl scope (error=0x8001010d).

Error - 1/30/2009 1:53:42 PM | Computer Name = TOUGAS3 | Source = Outlook | ID = 34
Description = Failed to get the Crawl Scope Manager with error=0x8001010d.

Error - 1/30/2009 1:53:42 PM | Computer Name = TOUGAS3 | Source = Outlook | ID = 35
Description = Failed to determine if the store is in the crawl scope (error=0x8001010d).

Error - 1/30/2009 1:53:42 PM | Computer Name = TOUGAS3 | Source = Outlook | ID = 35
Description = Failed to determine if the store is in the crawl scope (error=0x8001010d).

Error - 1/30/2009 7:26:24 PM | Computer Name = TOUGAS3 | Source = Outlook | ID = 34
Description = Failed to get the Crawl Scope Manager with error=0x8001010d.

Error - 1/30/2009 7:26:24 PM | Computer Name = TOUGAS3 | Source = Outlook | ID = 35
Description = Failed to determine if the store is in the crawl scope (error=0x8001010d).

[ OSession Events ]
Error - 9/3/2008 10:31:00 AM | Computer Name = TOUGAS3 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 31
seconds with 0 seconds of active time. This session ended with a crash.

Error - 9/3/2008 10:31:39 AM | Computer Name = TOUGAS3 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 12
seconds with 0 seconds of active time. This session ended with a crash.

Error - 9/8/2008 5:23:27 PM | Computer Name = TOUGAS3 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 631
seconds with 240 seconds of active time. This session ended with a crash.

Error - 9/15/2008 10:02:22 AM | Computer Name = TOUGAS3 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 55389
seconds with 300 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 1/31/2009 1:55:53 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/31/2009 1:55:53 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/31/2009 1:55:54 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/31/2009 1:55:54 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/31/2009 1:55:54 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/31/2009 1:55:54 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/31/2009 1:55:54 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/31/2009 1:55:54 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/31/2009 10:53:15 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7000
Description = The Automatic LiveUpdate Scheduler service failed to start due to
the following error: %%3

Error - 1/31/2009 10:53:15 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7000
Description = The PfModNT service failed to start due to the following error: %%2


< End of report >
Hi FrejyaGoddess


There are a couple of things you can still do for optimal performance:

If you are still having issues with gmail try downloading ATF cleaner and clearing out all the clutter.

Then in Firefox go to Tools>ClearPrivateData . check everything and choose>Clear private data now.
(you will have to re-enter all saved passwords - but it's a good idea to clear everything out once in a while)

Please download ATF Cleaner by Atribune.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE:
Click Exit on the Main menu to close the program.
It's normal after running ATF cleaner that the PC will be slower to boot the first time.


Now please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select.
  • Then click Remove Older Versions.
  • Accept any prompts.

Next:

You still have traces or Norton on your system:
Norton has a tool that will remove all of its products from failed uninstalls or installs
Download the Norton Remover tool for your product and follow the instructions for removal.


Please advise how you got along with the above instructions and finally post a fresh HJT log.
I use the ATF cleaner quite frequently, also I clear out Firefox everytime I use it. I think it's a good habit. I will run the rest of the stuff you suggested. Will post soon! -Freyja
No problem with any of the other instructions.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:26:15 PM, on 1/31/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\ATKKBService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\dnetc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Winsim\ConnectionManager\SimplyConnectionManager.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\system32\hphmon05.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winsim\ConnectionManager\Simply.SystemTrayIcon.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\user\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE"
O4 - HKLM\..\Run: [SBDrvDet] "C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [WorksFUD] "C:\Program Files\Microsoft Works\wkfud.exe"
O4 - HKLM\..\Run: [Microsoft Works Portfolio] "C:\Program Files\Microsoft Works\WksSb.exe" /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ConnectionManager] C:\Program Files\Winsim\ConnectionManager\Simply.SystemTrayIcon.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [RemoteCenter] "C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [WeatherEye] C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_11.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_11.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/2…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120829558027
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1136849927000
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: distributed.net client (dnetc) - Distributed Computing Technologies, Inc. - C:\WINDOWS\dnetc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Simply Accounting Database Connection Manager - Sage Software - C:\Program Files\Winsim\ConnectionManager\SimplyConnectionManager.exe

–
End of file - 14567 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI