1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Run a DLL as an App

Discussion in 'Malware and Virus Removal Archive' started by yosef7000, 2010/08/06.

  1. 2010/08/06
    yosef7000

    yosef7000 Inactive Thread Starter

    Joined:
    2010/08/06
    Messages:
    24
    Likes Received:
    0
    [Resolved] Run a DLL as an App

    I downloaded some themes for my Windows XP this morning, as soon as I opened them all hell broke loose, the theme switched from the standard XP theme (Luna) to that "classic" depressing windows '95 theme. I can't switch it back, it's stuck, every time I try it gives me the same error (Run a DLL as an App has encountered a problem that needs to be closed) and it gives me 2 options, debug and close.
    please help :(


    DDS (Ver_10-03-17.01) - NTFSx86
    Run by Administrator at 20:31:43.53 on Fri 08/06/2010
    Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_12
    Microsoft Windows XP Professional 5.1.2600.3.1256.973.1033.18.254.45 [GMT 3:00]

    AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    C:\Program Files\D-Link\D-Link Wireless 108G DWA-120\AirPlusCFG.exe
    C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\uTorrent\uTorrent.exe
    C:\Program Files\Messenger\Msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\eMule\emule.exe
    C:\Program Files\Belkin\F5D8053\Belkinwcui.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    svchost.exe
    C:\Program Files\Hotspot Shield\bin\openvpnas.exe
    C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Hotspot Shield\bin\openvpntray.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Administrator\My Documents\Downloads\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.yahoo.com/
    uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
    uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    mDefault_Page_URL = hxxp://www.yahoo.com/
    mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
    mStart Page = hxxp://www.yahoo.com/
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    uInternet Settings,ProxyOverride = local
    uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
    mSearchAssistant = hxxp://www.google.com/ie
    uURLSearchHooks: Yahoo! ¤u¨م¦C: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
    uURLSearchHooks: toto gateway Toolbar: {b7f907ee-0a1b-43b8-a611-b429a184ad6b} - c:\program files\torrents.to\tbtor1.dll
    uURLSearchHooks: Hotspot Shield Toolbar: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - c:\program files\hotspot_shield\tbHot1.dll
    uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
    BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
    BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
    BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
    BHO: toto gateway Toolbar: {b7f907ee-0a1b-43b8-a611-b429a184ad6b} - c:\program files\torrents.to\tbtor1.dll
    BHO: Hotspot Shield Toolbar: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - c:\program files\hotspot_shield\tbHot1.dll
    BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll
    TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
    TB: Yahoo! ¤u¨م¦C: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
    TB: toto gateway Toolbar: {b7f907ee-0a1b-43b8-a611-b429a184ad6b} - c:\program files\torrents.to\tbtor1.dll
    TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
    TB: Hotspot Shield Toolbar: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - c:\program files\hotspot_shield\tbHot1.dll
    TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
    TB: {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No File
    uRun: [Yahoo! Pager] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
    uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe "
    uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
    uRun: [updateMgr] c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe AcRdB7_1_0
    uRun: [Free Download Manager] "c:\program files\free download manager\fdm.exe" -autorun
    uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe "
    uRun: [MSMSGS] "c:\program files\messenger\Msmsgs.exe" /background
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [RegTool] c:\program files\regtool\RegTool.exe -boot
    uRun: [eMuleAutoStart] c:\program files\emule\emule.exe -AutoStart
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [SoundMan] SOUNDMAN.EXE
    mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
    mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe "
    mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe "
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe "
    mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
    mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    mRun: [googletalk] c:\program files\google\google talk\googletalk.exe /autostart
    mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    mRun: [ANIWZCS2Service] c:\program files\ani\aniwzcs2 service\WZCSLDR2.exe
    mRun: [D-Link D-Link Wireless 108G DWA-120] c:\program files\d-link\d-link wireless 108g dwa-120\AirPlusCFG.exe
    mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
    dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\belkin~1.lnk - c:\program files\belkin\f5d8053\Belkinwcui.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\totalm~1.lnk - c:\program files\arcsoft\totalmedia backup\uBBMonitor.exe
    uPolicies-explorer: NoThumbnailCache = 0 (0x0)
    IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
    IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
    IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
    IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
    DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
    DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
    DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
    Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
    Notify: igfxcui - igfxsrvc.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\njex9ys9.default\
    FF - prefs.js: browser.search.selectedEngine - isoHunt â€؛ BT Search
    FF - component: c:\documents and settings\administrator\application data\mozilla\firefox\profiles\njex9ys9.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\FFExternalAlert.dll
    FF - component: c:\documents and settings\administrator\application data\mozilla\firefox\profiles\njex9ys9.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\RadioWMPCore.dll
    FF - component: c:\documents and settings\administrator\application data\mozilla\firefox\profiles\njex9ys9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
    FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
    FF - plugin: c:\documents and settings\administrator\application data\mozilla\firefox\profiles\njex9ys9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
    FF - plugin: c:\program files\microsoft\office live\npOLW.dll
    FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
    FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    c:\program files\mozilla firefox\greprefs\all.js - pref( "ui.use_native_colors ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "ui.use_native_popup_windows ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.enable_click_image_resizing ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "accessibility.browsewithcaret_shortcut.enabled ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "javascript.options.mem.high_water_mark ", 32);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "javascript.options.mem.gc_frequency ", 1600);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.lu ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.nu ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.nz ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgbaam7a8h ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgberp4a5d4ar ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--p1ai ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgbayh7gpa ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.tel ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.auth.force-generic-ntlm ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.proxy.type ", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.buffer.cache.count ", 24);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.buffer.cache.size ", 4096);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "dom.ipc.plugins.timeoutSecs ", 45);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "svg.smil.enabled ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "ui.trackpoint_hack.enabled ", -1);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.debug ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.agedWeight ", 2);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.bucketSize ", 1);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.maxTimeGroupings ", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.timeGroupingSize ", 604800);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.boundaryWeight ", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.prefixWeight ", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "accelerometer.enabled ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "html5.enable ", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref ", true);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.renego_unrestricted_hosts ", " ");
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.treat_unsafe_negotiation_as_broken ", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.require_safe_negotiation ", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl3.rsa_seed_sha ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref( "app.update.download.backgroundInterval ", 600);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref( "app.update.url.manual ", "http://www.firefox.com ");
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref( "browser.search.param.yahoo-fr-ja ", "mozff ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name ", "chrome://browser/locale/browser.properties ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description ", "chrome://browser/locale/browser.properties ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "xpinstall.whitelist.add ", "addons.mozilla.org ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "xpinstall.whitelist.add.36 ", "getpersonas.com ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "lightweightThemes.update.enabled ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.allTabs.previews ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "plugins.hide_infobar_for_outdated_plugin ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "plugins.update.notifyUser ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "toolbar.customization.usesheet ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.nptest.dll ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npswf32.dll ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npctrl.dll ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npqtplugin.dll ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.enable ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.max ", 20);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.cachetime ", 20);

    ============= SERVICES / DRIVERS ===============

    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2008-4-2 162640]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-4-2 19024]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-27 40384]
    R2 AWISp50;AWISp50 NDIS Protocol Driver;c:\windows\system32\drivers\AWISp50.sys [2006-3-15 17664]
    R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-4-3 54752]
    R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-7-31 93320]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-8-24 24652]
    R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-27 40384]
    R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-27 40384]
    R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [2009-5-22 57376]
    R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2007-7-28 517632]
    R3 slnt;Realtek RTL8139D Family Fast Ethernet NIC;c:\windows\system32\drivers\slnt.sys [2007-10-7 18004]
    S3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [2009-4-1 377920]
    S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
    S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\d-link\d-link wireless 108g dwa-120\jswutil\jswpsapi.exe [2009-9-3 352338]

    =============== Created Last 30 ================

    2010-08-06 17:03:49 54156 ---ha-w- c:\windows\QTFont.qfn
    2010-08-06 17:03:49 1409 ----a-w- c:\windows\QTFont.for
    2010-08-06 16:41:44 0 d-----w- c:\docume~1\alluse~1\applic~1\ParetoLogic
    2010-08-06 16:41:43 0 d-----w- c:\program files\common files\ParetoLogic
    2010-08-06 16:41:31 0 d-----w- c:\program files\ParetoLogic
    2010-08-06 12:18:10 0 d-----w- c:\docume~1\admini~1\applic~1\RegTool
    2010-08-06 12:16:22 0 d-----w- c:\program files\RegTool
    2010-08-06 12:12:08 0 d-----w- c:\program files\Downloaded Installers
    2010-08-06 10:49:13 0 d-----w- c:\docume~1\admini~1\applic~1\RegistryTool
    2010-08-06 10:47:53 0 d-----w- c:\program files\RegistryTool
    2010-08-06 10:21:54 0 d-----w- c:\windows\pss
    2010-08-06 04:27:13 2560 ----a-w- c:\windows\_MSRSTRT.EXE
    2010-07-14 10:29:02 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
    2010-07-10 09:01:47 0 d-----w- c:\windows\Logs
    2010-07-10 08:58:54 0 d-----w- c:\program files\PCSX2 0.9.7
    2010-07-09 08:46:37 0 d-----w- C:\New Folder

    ==================== Find3M ====================

    2007-10-08 13:05:41 56 --sh--r- c:\windows\system32\57B6654BED.sys
    2007-10-08 13:05:41 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys
    2008-10-22 13:27:25 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008102220081023\index.dat

    ============= FINISH: 20:34:31.93 ===============


    OK AND THE OTHER ONE ::::::::: :confused: :confused: :confused: :confused:


    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-03-17.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 10/7/2007 10:14:41 AM
    System Uptime: 8/6/2010 3:39:20 PM (5 hours ago)

    Motherboard: Intel Corporation | | D845GVSR
    Processor: Intel(R) Celeron(R) CPU 2.40GHz | X1 | 2399/100mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 29 GiB total, 6.154 GiB free.
    D: is FIXED (NTFS) - 39 GiB total, 0.105 GiB free.
    E: is FIXED (NTFS) - 43 GiB total, 1.052 GiB free.
    F: is CDROM ()
    H: is FIXED (FAT32) - 466 GiB total, 104.412 GiB free.

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP862: 8/6/2010 7:07:18 PM - System Checkpoint
    RP863: 8/6/2010 7:13:03 PM - restore

    ==== Installed Programs ======================

    µTorrent
    Adobe Anchor Service CS3
    Adobe Asset Services CS3
    Adobe Bridge CS3
    Adobe Bridge Start Meeting
    Adobe Camera Raw 4.0
    Adobe CMaps
    Adobe Color - Photoshop Specific
    Adobe Color Common Settings
    Adobe Color EU Extra Settings
    Adobe Color JA Extra Settings
    Adobe Color NA Recommended Settings
    Adobe Default Language CS3
    Adobe Device Central CS3
    Adobe ExtendScript Toolkit 2
    Adobe Flash Player 10 Plugin
    Adobe Flash Player ActiveX
    Adobe Fonts All
    Adobe Help Viewer CS3
    Adobe Linguistics CS3
    Adobe PDF Library Files
    Adobe Photoshop CS3
    Adobe Reader 7.1.0
    Adobe Setup
    Adobe Stock Photos CS3
    Adobe Type Support
    Adobe Update Manager CS3
    Adobe Version Cue CS3 Client
    Adobe WinSoft Linguistics Plugin
    Adobe XMP Panels CS3
    Advanced WindowsCare 2.57 Personal
    AdVantage
    ANIO Service
    ANIWZCS2 Service
    Any Video Converter 2.6.3
    Apple Software Update
    ArcSoft TotalMedia Backup
    avast! Free Antivirus
    Belkin F5D8053 N Wireless USB Adapter
    BufferChm
    Compact Wireless-G USB Adapter
    Compatibility Pack for the 2007 Office system
    CoreAAC Audio Decoder (remove only)
    CustomerResearchQFolder
    D-Link Wireless 108G DWA-120
    D1300
    D1300_Help
    DeviceManagementQFolder
    eMule
    eSupportQFolder
    Free Download Manager 2.5
    GOM Player
    Google Earth
    Google Talk (remove only)
    Google Toolbar for Internet Explorer
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954708)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    Hotfix for Windows XP (KB976098-v2)
    Hotfix for Windows XP (KB979306)
    Hotfix for Windows XP (KB981793)
    Hotspot Shield 1.22
    Hotspot_Shield Toolbar
    HP Customer Participation Program 7.0
    HP Imaging Device Functions 7.0
    HP Photosmart and Deskjet 7.0 Software
    HP Photosmart Essential
    HP Solution Center 7.0
    HP Update
    hph_ProductContext
    hph_readme
    hph_software
    hph_software_req
    HPPhotoSmartExpress
    HPProductAssistant
    Intel(R) Extreme Graphics Driver
    Java(TM) 6 Update 12
    Java(TM) 6 Update 3
    Junk Mail filter update
    MarketResearch
    MasterSplitter Program
    McAfee SiteAdvisor
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office 2003 Arabic User Interface Pack
    Microsoft Office Live Add-in 1.3
    Microsoft Office Outlook Connector
    Microsoft Office Professional Edition 2003
    Microsoft Search Enhancement Pack
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Sync Framework Runtime Native v1.0 (x86)
    Microsoft Sync Framework Services Native v1.0 (x86)
    Microsoft Text-to-Speech Engine 4.0 (English)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Mozilla Firefox (3.6.8)
    MSN
    MSVCRT
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    Nero 6 Enterprise Edition
    OGA Notifier 2.0.0048.0
    ParetoLogic PC Health Advisor
    PC CameraN
    PCSX2 - Playstation 2 Emulator
    PDF Settings
    PowerDVD
    QuickTime
    RealPlayer
    Realtek AC'97 Audio
    RegTool
    Rhapsody Player Engine
    RM to MP3 Converter 1.32
    Royale Remixed Theme
    Secure Copy 4
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB942615)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Internet Explorer 7 (KB969897)
    Security Update for Windows Internet Explorer 7 (KB972260)
    Security Update for Windows Internet Explorer 7 (KB974455)
    Security Update for Windows Internet Explorer 7 (KB976325)
    Security Update for Windows Internet Explorer 7 (KB978207)
    Security Update for Windows Internet Explorer 7 (KB982381)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player (KB978695)
    Security Update for Windows Media Player (KB979402)
    Security Update for Windows XP (KB2229593)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB971961)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975562)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB977165)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978251)
    Security Update for Windows XP (KB978262)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB978706)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979482)
    Security Update for Windows XP (KB979559)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB980195)
    Security Update for Windows XP (KB980218)
    Security Update for Windows XP (KB980232)
    Security Update for Windows XP (KB981349)
    Segoe UI
    Software Informer 1.0 BETA
    SolutionCenter
    Status
    Toolbox
    torrents.to Toolbar
    TrayApp
    Unload
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Windows Internet Explorer 7 (KB976749)
    Update for Windows Internet Explorer 7 (KB980182)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB961503)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    VideoLAN VLC media player 0.8.6h
    Viewpoint Media Player
    VobSub v2.23 (Remove Only)
    WebFldrs XP
    WebReg
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Family Safety
    Windows Live Mail
    Windows Live Messenger
    Windows Live Photo Gallery
    Windows Live Sign-in Assistant
    Windows Live Sync
    Windows Live Toolbar
    Windows Live Upload Tool
    Windows Live Writer
    Windows Media Format Runtime
    Windows Messenger 5.1
    Windows XP Service Pack 3
    WinRAR archiver
    WinZip
    Yahoo! Browser Services
    Yahoo! Install Manager
    Yahoo! Internet Mail
    Yahoo! Messenger
    Yahoo! ¤u¨م¦C

    ==== Event Viewer Messages From Past Week ========

    8/6/2010 7:36:06 AM, error: Service Control Manager [7000] - The HTTP SSL service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    8/6/2010 7:36:05 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the HTTP SSL service to connect.
    8/6/2010 12:51:25 PM, information: Windows File Protection [64018] - Windows File Protection file scan was cancelled by user interaction, user name is Administrator.
    8/6/2010 12:51:24 PM, information: Windows File Protection [64021] - The system file c:\windows\system32\iisreset.exe could not be copied into the DLL cache. The specific error code is 0x000004c7 [The operation was canceled by the user. ]. This file is necessary to maintain system stability.
    8/6/2010 12:37:22 PM, information: Windows File Protection [64021] - The system file c:\windows\system32\ftpsapi2.dll could not be copied into the DLL cache. The specific error code is 0x000004c7 [The operation was canceled by the user. ]. This file is necessary to maintain system stability.
    8/6/2010 12:36:57 PM, information: Windows File Protection [64021] - The system file c:\windows\system32\inetsrv\certmap.ocx could not be copied into the DLL cache. The specific error code is 0x000004c7 [The operation was canceled by the user. ]. This file is necessary to maintain system stability.
    8/6/2010 12:34:09 PM, information: Windows File Protection [64016] - Windows File Protection file scan was started.
    8/6/2010 12:00:01 AM, error: Dhcp [1002] - The IP address lease 192.168.1.101 for the Network Card with network address 0022750D0D16 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
    8/6/2010 10:19:27 AM, information: Windows File Protection [64005] - The protected system file uxtheme.dll was not restored to its original, valid version because the Windows File Protection restoration process was cancelled by user interaction, user name is Administrator. The file version of the bad file is 6.0.2600.0.
    8/5/2010 11:57:49 PM, error: Service Control Manager [7022] - The Automatic Updates service hung on starting.
    8/5/2010 11:47:29 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC000009A' while processing the file 'XPC.mfl' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
    8/4/2010 6:45:33 AM, error: Dhcp [1002] - The IP address lease 192.168.1.104 for the Network Card with network address 0022750D0D16 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
    8/1/2010 9:43:16 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the avast! Web Scanner service.
    8/1/2010 9:42:46 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the avast! Mail Scanner service.
    8/1/2010 9:42:17 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the avast! Antivirus service.
    8/1/2010 6:41:07 PM, error: Dhcp [1002] - The IP address lease 192.168.1.102 for the Network Card with network address 0022750D0D16 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).

    ==== End Of File ===========================


    :confused: I'm not sure if I should post all this here, please keep in mind that I'm new to this forum :) thanks in advance!
     
  2. 2010/08/06
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    You have posted in the right place :)

    I see you have P2P software ( Azures, Limewire, BitTorrent, uTorrent etc…) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information.

    Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares and their infections.

    References for the risk of these programs are here, and here.

    I would strongly recommend that you uninstall them, and read the links above for educational value!

    Note: Please be advised that continued use of these programs after being warned of the danger of infections from them, may result in the discontinued help of future cleaning of your system here at WindowsBBS Malware and Virus removal.

    A Malware expert will have a look at your log in due course.
     

  3. to hide this advert.

  4. 2010/08/06
    yosef7000

    yosef7000 Inactive Thread Starter

    Joined:
    2010/08/06
    Messages:
    24
    Likes Received:
    0
    Thank you PeteC, I really appreciate your help. I do have uTorrent installed on my PC. I'll be reading those links.
     
  5. 2010/08/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Where were those themes downloaded from?


    STEP 1. Download Malwarebytes' Anti-Malware (aka MBAM): http://www.malwarebytes.org/mbam.php to your desktop.
    (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform Quick Scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt


    STEP 2. Download GMER: http://www.gmer.net/files.php, by clicking on Download EXE button.
    Alternative downloads:
    - http://majorgeeks.com/GMER_d5198.html
    - http://www.softpedia.com/get/Interne...ers/GMER.shtml
    Double click on downloaded .exe file, select Rootkit tab and click the Scan button.
    Do NOT use the computer while GMER is running!
    When scan is completed, click Save button, and save the results as gmer.log
    Warning ! Please, do not select the "Show all" checkbox during the scan.
    Post the log to your next reply.

    IMPORTANT! If for some reason GMER refuses to run, try again.
    If it still fails, try to UN-check "Devices" in right pane.
    If still no joy, try to run it from Safe Mode.


    STEP 3. Download MBRCheck to your desktop

    Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
    It will show a black screen with some data on it.
    A report called MBRcheckxxxx.txt will be on your desktop
    Open this report and post its content in your next reply.



    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  6. 2010/08/07
    yosef7000

    yosef7000 Inactive Thread Starter

    Joined:
    2010/08/06
    Messages:
    24
    Likes Received:
    0
    I posted the same log twice, I don't know how to delete it so I'm overwriting it with this message. I apologize for the inconvenience. scroll down for the logs.
     
    Last edited: 2010/08/07
  7. 2010/08/07
    yosef7000

    yosef7000 Inactive Thread Starter

    Joined:
    2010/08/06
    Messages:
    24
    Likes Received:
    0
    I downloaded one from here http://www.guimods.com/category/windows-xp-themes/
    OK, I followed your instructions carefully, I downloaded, installed, scanned and saved the logs.
    I can't post them all at once since it's too long (more than 900000 characters I think) so I have to post one at a time.


    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4401

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 7.0.5730.13

    8/7/2010 10:29:13 AM
    mbam-log-2010-08-07 (10-29-13).txt

    Scan type: Quick scan
    Objects scanned: 149493
    Time elapsed: 18 minute(s), 18 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 5
    Registry Values Infected: 1
    Registry Data Items Infected: 3
    Folders Infected: 16
    Files Infected: 230

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\advantage (Adware.Vomba) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\regtool (Rogue.RegTool) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    C:\Documents and Settings\Administrator\Application Data\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\Logs (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380 (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-13-240 (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-18-040 (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-20-270 (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-22-500 (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-35-150 (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-37-340 (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-53-460 (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\Results (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Program Files\Advantage (Adware.Advantage) -> Quarantined and deleted successfully.
    C:\Program Files\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Program Files\VVSN (Adware.WhenU) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Start Menu\Programs\RegTool (Rogue.RegTool) -> Quarantined and deleted successfully.

    Files Infected:
    C:\Documents and Settings\Administrator\Desktop\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Desktop\U94.exe (HackTool.Proxy) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Desktop\RegTool v2.8.3415.454.exe (Rogue.Installer) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\database.tmp (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\resultsw.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\spy_ignore.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\UpdatesToInstall.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\Logs\2010-08-06 15-18-100.log (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\Logs\2010-08-06 15-40-250.log (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\Logs\2010-08-06 16-04-000.log (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\filelist.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-0.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-1.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-10.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-100.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-101.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-102.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-103.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-104.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-105.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-106.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-107.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-108.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-109.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-11.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-110.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-111.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-112.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-113.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-114.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-115.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-116.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-117.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-118.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-119.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-12.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-120.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-121.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-122.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-123.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-124.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-125.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-126.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-127.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-128.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-129.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-13.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-130.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-131.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-132.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-133.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-134.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-135.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-136.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-137.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-138.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-139.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-14.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-140.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-141.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-142.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-143.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-144.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-145.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-146.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-147.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-148.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-149.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-15.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-150.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-151.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-152.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-153.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-154.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-155.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-156.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-157.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-158.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-159.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-16.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-160.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-161.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-162.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-163.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-164.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-165.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-166.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-167.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-168.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-169.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-17.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-170.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-171.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-172.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-173.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-174.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-175.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-176.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-177.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-178.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-179.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-18.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-180.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-181.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-182.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-183.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-184.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-185.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-186.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-187.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-188.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-19.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-2.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-20.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-21.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-22.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-23.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-24.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-25.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-26.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-27.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-28.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-29.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-3.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-30.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-31.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-32.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-33.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-34.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-35.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-36.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-37.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-38.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-39.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-4.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-40.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-41.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-42.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-43.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-44.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-45.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-46.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-47.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-48.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-49.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-5.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-50.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-51.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-52.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-53.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-54.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-55.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-56.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-57.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-58.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-59.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-6.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-60.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-61.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-62.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-63.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-64.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-65.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-66.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-67.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-68.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-69.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-7.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-70.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-71.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-72.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-73.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-74.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-75.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-76.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-77.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-78.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-79.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-8.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-80.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-81.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-82.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-83.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-84.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-85.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-86.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-87.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-88.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-89.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-9.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-90.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-91.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-92.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-93.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-94.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-95.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-96.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-97.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-98.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 15-36-380\regb-99.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-13-240\filelist.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-13-240\regb-0.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-13-240\regb-1.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-13-240\regb-10.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-13-240\regb-11.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-13-240\regb-2.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-13-240\regb-3.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-13-240\regb-4.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-13-240\regb-5.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-13-240\regb-6.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-13-240\regb-7.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-13-240\regb-8.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-13-240\regb-9.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-18-040\filelist.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-20-270\filelist.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-22-500\filelist.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-35-150\filelist.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-37-340\filelist.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-53-460\filelist.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Administrator\Application Data\RegTool\QuarantineW\2010-08-06 16-53-460\regb-0.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Program Files\Advantage\AdVUninst.exe (Adware.Advantage) -> Quarantined and deleted successfully.
    C:\Program Files\Advantage\ffext.mod (Adware.Advantage) -> Quarantined and deleted successfully.
    C:\Program Files\RegTool\definitions.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Program Files\RegTool\privacy.db (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Program Files\RegTool\RegTool.exe (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Program Files\RegTool\RegTool.url (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Start Menu\Programs\RegTool\RegTool Help.lnk (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Start Menu\Programs\RegTool\RegTool on the Web.lnk (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Start Menu\Programs\RegTool\RegTool.lnk (Rogue.RegTool) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Desktop\RegTool.lnk (Rogue.RegTool) -> Quarantined and deleted successfully.
     
  8. 2010/08/07
    yosef7000

    yosef7000 Inactive Thread Starter

    Joined:
    2010/08/06
    Messages:
    24
    Likes Received:
    0
    GMER 1.0.15.15281 - http://www.gmer.net
    Rootkit scan 2010-08-07 12:47:39
    Windows 5.1.2600 Service Pack 3
    Running: 1djyhqql.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\awtyqpob.sys


    ---- System - GMER 1.0.15 ----

    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF06E0C56]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF06E0B12]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xF06E10C6]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF06E0FF0]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF06E06E8]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF06E0BEC]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF06E0628]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF06E068C]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF06E0D0C]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xF06E1194]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF06E0CCC]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF06E0E4C]

    Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xF06ED4FE]
    Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xF06ED322]
    Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xF06ED45C]
    Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
    Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
    Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject

    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntoskrnl.exe!_abnormal_termination + 15C 804E27C8 4 Bytes CALL 4C3E95D3
    PAGE ntoskrnl.exe!ObInsertObject 8056503A 5 Bytes JMP F06EA972 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
    PAGE ntoskrnl.exe!NtCreateSection 805652B3 7 Bytes JMP F06ED326 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
    PAGE ntoskrnl.exe!ZwCreateProcessEx 8057FE4C 7 Bytes JMP F06ED502 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
    PAGE ntoskrnl.exe!ObMakeTemporaryObject 8059F8CA 5 Bytes JMP F06E94BA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
    PAGE ntoskrnl.exe!ZwLoadDriver 805A3B73 7 Bytes JMP F06ED460 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
    ? lpciokk.sys The system cannot find the file specified. !

    ---- User code sections - GMER 1.0.15 ----

    .text C:\Program Files\Mozilla Firefox\firefox.exe[3892] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT C:\WINDOWS\system32\services.exe[1160] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 005D0002
    IAT C:\WINDOWS\system32\services.exe[1160] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 005D0000

    ---- Devices - GMER 1.0.15 ----

    Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)

    AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

    Device \FileSystem\Fastfat \FatCdrom aswSP.SYS (avast! self protection module/ALWIL Software)

    AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
    AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
    AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
    AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

    Device \FileSystem\Fastfat \Fat aswSP.SYS (avast! self protection module/ALWIL Software)

    AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
    AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\bb4abb330fd1
    Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\bb4abb330fd1 (not active ControlSet)

    ---- EOF - GMER 1.0.15 ----
     
  9. 2010/08/07
    yosef7000

    yosef7000 Inactive Thread Starter

    Joined:
    2010/08/06
    Messages:
    24
    Likes Received:
    0
    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Professional
    Windows Information: Service Pack 3 (build 2600)
    Logical Drives Mask: 0x000000bd

    Kernel Drivers (total 136):
    0x804D7000 \WINDOWS\system32\ntoskrnl.exe
    0x806EE000 \WINDOWS\system32\hal.dll
    0xF97C6000 \WINDOWS\system32\KDCOM.DLL
    0xF96D6000 \WINDOWS\system32\BOOTVID.dll
    0xF92C6000 lpciokk.sys
    0xF9277000 ACPI.sys
    0xF97C8000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
    0xF9266000 pci.sys
    0xF92D6000 isapnp.sys
    0xF9546000 \WINDOWS\System32\Drivers\PCIIDEX.SYS
    0xF97CA000 intelide.sys
    0xF92E6000 MountMgr.sys
    0xF9247000 ftdisk.sys
    0xF97CC000 dmload.sys
    0xF9221000 dmio.sys
    0xF954E000 PartMgr.sys
    0xF92F6000 VolSnap.sys
    0xF9209000 atapi.sys
    0xF9306000 disk.sys
    0xF9316000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    0xF91E9000 fltmgr.sys
    0xF91D7000 sr.sys
    0xF91C0000 KSecDD.sys
    0xF9133000 Ntfs.sys
    0xF9106000 NDIS.sys
    0xF90EC000 Mup.sys
    0xF9766000 \SystemRoot\system32\DRIVERS\tunmp.sys
    0xF9366000 \SystemRoot\system32\DRIVERS\intelppm.sys
    0xF908D000 \SystemRoot\system32\DRIVERS\ialmnt5.sys
    0xF9079000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
    0xF9586000 \SystemRoot\system32\DRIVERS\usbuhci.sys
    0xF9055000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0xF958E000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0xF959E000 \SystemRoot\system32\DRIVERS\slnt.sys
    0xF95AE000 \SystemRoot\system32\DRIVERS\fdc.sys
    0xF9376000 \SystemRoot\system32\DRIVERS\serial.sys
    0xF9772000 \SystemRoot\system32\DRIVERS\serenum.sys
    0xF9041000 \SystemRoot\system32\DRIVERS\parport.sys
    0xF9386000 \SystemRoot\system32\DRIVERS\i8042prt.sys
    0xF95BE000 \SystemRoot\system32\DRIVERS\kbdclass.sys
    0xF9396000 \SystemRoot\system32\DRIVERS\imapi.sys
    0xF9782000 \SystemRoot\system32\drivers\pfc.sys
    0xF93A6000 \SystemRoot\system32\DRIVERS\cdrom.sys
    0xF93B6000 \SystemRoot\system32\DRIVERS\redbook.sys
    0xF901E000 \SystemRoot\system32\DRIVERS\ks.sys
    0xF8C7D000 \SystemRoot\system32\drivers\ALCXWDM.SYS
    0xF8C59000 \SystemRoot\system32\drivers\portcls.sys
    0xF93C6000 \SystemRoot\system32\drivers\drmk.sys
    0xF93D6000 \SystemRoot\system32\DRIVERS\jswscimd.sys
    0xF9A08000 \SystemRoot\system32\DRIVERS\audstub.sys
    0xF93E6000 \SystemRoot\system32\DRIVERS\HssDrv.sys
    0xF95E6000 \SystemRoot\system32\DRIVERS\rasirda.sys
    0xF95F6000 \SystemRoot\system32\DRIVERS\TDI.SYS
    0xF93F6000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0xF97A2000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0xF8C1A000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0xF9406000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0xF9416000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0xF8C09000 \SystemRoot\system32\DRIVERS\psched.sys
    0xF9426000 \SystemRoot\system32\DRIVERS\msgpc.sys
    0xF9616000 \SystemRoot\system32\DRIVERS\ptilink.sys
    0xF9626000 \SystemRoot\system32\DRIVERS\raspti.sys
    0xF9436000 \SystemRoot\system32\DRIVERS\tapvpn.sys
    0xF9636000 \SystemRoot\system32\DRIVERS\tap0901.sys
    0xF8B39000 \SystemRoot\system32\DRIVERS\rdpdr.sys
    0xF9446000 \SystemRoot\system32\DRIVERS\termdd.sys
    0xF9646000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0xF97D2000 \SystemRoot\system32\DRIVERS\swenum.sys
    0xF8ADB000 \SystemRoot\system32\DRIVERS\update.sys
    0xF97BE000 \SystemRoot\system32\DRIVERS\mssmbios.sys
    0xF9456000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0xF0A1B000 \SystemRoot\system32\drivers\ialmkchw.sys
    0xF09FD000 \SystemRoot\system32\drivers\ialmsbw.sys
    0xF9476000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0xF97D8000 \SystemRoot\system32\DRIVERS\USBD.SYS
    0xF966E000 \SystemRoot\system32\DRIVERS\flpydisk.sys
    0xF97DC000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
    0xF98BD000 \SystemRoot\System32\Drivers\Null.SYS
    0xF97E0000 \SystemRoot\System32\Drivers\Beep.SYS
    0xF9686000 \SystemRoot\System32\drivers\vga.sys
    0xF97E4000 \SystemRoot\System32\Drivers\mnmdd.SYS
    0xF97E8000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0xF9696000 \SystemRoot\System32\Drivers\Msfs.SYS
    0xF96A6000 \SystemRoot\System32\Drivers\Npfs.SYS
    0xF8C4D000 \SystemRoot\system32\DRIVERS\rasacd.sys
    0xF093B000 \SystemRoot\system32\DRIVERS\ipsec.sys
    0xF08E2000 \SystemRoot\system32\DRIVERS\tcpip.sys
    0xF9496000 \SystemRoot\System32\Drivers\aswTdi.SYS
    0xF08BC000 \SystemRoot\system32\DRIVERS\ipnat.sys
    0xF94A6000 \SystemRoot\system32\DRIVERS\wanarp.sys
    0xF0894000 \SystemRoot\system32\DRIVERS\netbt.sys
    0xF085C000 \SystemRoot\system32\DRIVERS\tcpip6.sys
    0xF083A000 \SystemRoot\System32\drivers\afd.sys
    0xF94B6000 \SystemRoot\system32\drivers\ip6fw.sys
    0xF94C6000 \SystemRoot\system32\DRIVERS\netbios.sys
    0xF076F000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0xF06FF000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0xF94D6000 \SystemRoot\System32\Drivers\Fips.SYS
    0xF06D8000 \SystemRoot\System32\Drivers\aswSP.SYS
    0xF956E000 \SystemRoot\System32\Drivers\Aavmker4.SYS
    0xF957E000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
    0xF0631000 \SystemRoot\system32\DRIVERS\rt2870.sys
    0xF8BD9000 \SystemRoot\System32\Drivers\Cdfs.SYS
    0xF0A3B000 \SystemRoot\system32\DRIVERS\hidusb.sys
    0xF8BA9000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
    0xF95B6000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    0xF0A33000 \SystemRoot\system32\DRIVERS\mouhid.sys
    0xBF800000 \SystemRoot\System32\win32k.sys
    0xF098A000 \SystemRoot\System32\drivers\Dxapi.sys
    0xF95CE000 \SystemRoot\System32\watchdog.sys
    0xBF000000 \SystemRoot\System32\drivers\dxg.sys
    0xF99D7000 \SystemRoot\System32\drivers\dxgthk.sys
    0xBF020000 \SystemRoot\System32\ialmdnt5.dll
    0xBF012000 \SystemRoot\System32\ialmrnt5.dll
    0xBF042000 \SystemRoot\System32\ialmdev5.DLL
    0xBF073000 \SystemRoot\System32\ialmdd5.DLL
    0xF0532000 \SystemRoot\System32\Drivers\Fastfat.SYS
    0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
    0xF0992000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
    0xF960E000 \SystemRoot\system32\DRIVERS\AegisP.sys
    0xF962E000 \SystemRoot\System32\Drivers\AWISp50.sys
    0xF081A000 \SystemRoot\system32\DRIVERS\fssfltr_tdi.sys
    0xF02EC000 \SystemRoot\system32\DRIVERS\irda.sys
    0xF041E000 \SystemRoot\system32\DRIVERS\ndisuio.sys
    0xF0285000 \SystemRoot\System32\Drivers\aswMon2.SYS
    0xEFB00000 \SystemRoot\system32\DRIVERS\mrxdav.sys
    0xEFAEB000 \SystemRoot\system32\drivers\wdmaud.sys
    0xEFC9D000 \SystemRoot\system32\drivers\sysaudio.sys
    0xF9846000 \SystemRoot\System32\Drivers\ParVdm.SYS
    0xF96AE000 \??\C:\WINDOWS\system32\ANIO.SYS
    0xEF7B2000 \SystemRoot\System32\Drivers\HTTP.sys
    0xEF733000 \SystemRoot\system32\DRIVERS\srv.sys
    0xEF623000 \SystemRoot\System32\Drivers\aswRdr.SYS
    0xEEF1E000 \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\awtyqpob.sys
    0xEEEF3000 \SystemRoot\system32\drivers\kmixer.sys
    0x7C900000 \WINDOWS\system32\ntdll.dll

    Processes (total 55):
    0 System Idle Process
    4 System
    600 C:\WINDOWS\system32\smss.exe
    1080 csrss.exe
    1104 C:\WINDOWS\system32\winlogon.exe
    1160 C:\WINDOWS\system32\services.exe
    1172 C:\WINDOWS\system32\lsass.exe
    1324 C:\WINDOWS\system32\svchost.exe
    1392 svchost.exe
    1448 C:\WINDOWS\system32\svchost.exe
    1836 svchost.exe
    1864 svchost.exe
    372 C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    880 C:\WINDOWS\explorer.exe
    1600 C:\WINDOWS\system32\igfxtray.exe
    1612 C:\WINDOWS\system32\hkcmd.exe
    1620 C:\WINDOWS\SOUNDMAN.EXE
    1636 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    1656 C:\Program Files\HP\HP Software Update\hpwuschd2.exe
    1680 C:\Program Files\Java\jre6\bin\jusched.exe
    1720 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    1728 C:\WINDOWS\system32\rundll32.exe
    1756 C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    1788 C:\Program Files\D-Link\D-Link Wireless 108G DWA-120\AirPlusCFG.exe
    1800 C:\PROGRA~1\ALWILS~1\Avast5\AvastUI.exe
    1536 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    1984 C:\Program Files\uTorrent\uTorrent.exe
    1992 C:\Program Files\Messenger\Msmsgs.exe
    140 C:\WINDOWS\system32\ctfmon.exe
    148 C:\Program Files\eMule\emule.exe
    268 C:\Program Files\Belkin\F5D8053\Belkinwcui.exe
    292 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    768 C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
    1052 C:\WINDOWS\system32\spoolsv.exe
    1776 svchost.exe
    2148 alg.exe
    2176 C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    2188 C:\Program Files\Bonjour\mDNSResponder.exe
    2208 svchost.exe
    2256 C:\Program Files\Hotspot Shield\bin\openvpnas.exe
    2308 C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
    2380 C:\Program Files\Java\jre6\bin\jqs.exe
    2408 C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    2436 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    2460 C:\WINDOWS\system32\HPZipm12.exe
    2516 C:\WINDOWS\system32\rundll32.exe
    2552 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    2608 C:\WINDOWS\system32\svchost.exe
    2664 wdfmgr.exe
    2748 C:\Program Files\Viewpoint\Common\ViewpointService.exe
    3192 C:\Program Files\Hotspot Shield\bin\openvpntray.exe
    3220 C:\WINDOWS\system32\svchost.exe
    3892 C:\Program Files\Mozilla Firefox\firefox.exe
    2916 C:\Documents and Settings\Administrator\My Documents\Downloads\1djyhqql.exe
    1484 C:\Documents and Settings\Administrator\My Documents\Downloads\MBRCheck.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
    \\.\D: --> \\.\PhysicalDrive0 at offset 0x00000007`52c65e00 (NTFS)
    \\.\E: --> \\.\PhysicalDrive0 at offset 0x00000011`16a2b400 (NTFS)
    \\.\H: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (FAT32)

    PhysicalDrive0 Model Number: MDTMD1200JB-00GVA0, Rev: 08.02D08
    PhysicalDrive1 Model Number: SAMSUNGHM500LI, Rev: 2TF0

    Size Device Name MBR Status
    --------------------------------------------
    111 GB \\.\PhysicalDrive0 Windows XP MBR code detected
    SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
    465 GB \\.\PhysicalDrive1 RE: Windows XP MBR code detected
    SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


    Done!
     
  10. 2010/08/07
    yosef7000

    yosef7000 Inactive Thread Starter

    Joined:
    2010/08/06
    Messages:
    24
    Likes Received:
    0
    The above post is the MBRCheck, I posted all 3 but I guess long posts need approval from the admin. I'm going to wait for them to appear, if they don't, the I guess posting has failed and I'm going to try again.
    Thank you for your help and patience.

    ===UPDATE====
    OK all 3 are here.
     
    Last edited: 2010/08/07
  11. 2010/08/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You did just fine :)

    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    [color= "Blue"]**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**[/color]
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on [color= "Red"]this link[/color] to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • [color= "Red"]WARNING:[/color] Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  12. 2010/08/07
    yosef7000

    yosef7000 Inactive Thread Starter

    Joined:
    2010/08/06
    Messages:
    24
    Likes Received:
    0
    Is this it?


    ComboFix 10-08-06.03 - Administrator 08/07/2010 19:20:08.1.1 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1256.973.1033.18.254.8 [GMT 3:00]
    Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
    AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\program files\Downloaded Installers
    c:\program files\Downloaded Installers\{3488685E-6364-4327-81E1-CFFB8C60E451}\setup.msi

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_WinDHCPsvc


    ((((((((((((((((((((((((( Files Created from 2010-07-07 to 2010-08-07 )))))))))))))))))))))))))))))))
    .

    2010-08-07 06:53 . 2010-08-07 06:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
    2010-08-07 06:52 . 2010-04-29 12:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-08-07 06:52 . 2010-08-07 06:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-08-07 06:52 . 2010-04-29 12:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-08-07 06:52 . 2010-08-07 06:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-08-06 16:41 . 2010-08-06 16:41 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic
    2010-08-06 16:41 . 2010-08-06 16:41 -------- d-----w- c:\program files\Common Files\ParetoLogic
    2010-08-06 16:41 . 2010-08-06 16:41 -------- d-----w- c:\program files\ParetoLogic
    2010-08-06 10:49 . 2010-08-06 11:28 -------- d-----w- c:\documents and settings\Administrator\Application Data\RegistryTool
    2010-08-06 10:47 . 2010-08-06 12:08 -------- d-----w- c:\program files\RegistryTool
    2010-08-06 04:27 . 2010-08-06 04:27 2560 ----a-w- c:\windows\_MSRSTRT.EXE
    2010-07-14 10:29 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
    2010-07-10 10:54 . 2010-07-10 10:54 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\pcsx2
    2010-07-10 09:01 . 2010-07-10 10:43 -------- d-----w- c:\windows\Logs
    2010-07-10 08:58 . 2010-07-10 10:54 -------- d-----w- c:\program files\PCSX2 0.9.7
    2010-07-09 08:46 . 2010-07-09 15:14 -------- d-----w- C:\New Folder

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-08-07 16:43 . 2008-06-01 10:08 -------- d-----w- c:\documents and settings\Administrator\Application Data\Free Download Manager
    2010-08-07 16:37 . 2008-01-18 10:15 -------- d-----w- c:\documents and settings\Administrator\Application Data\uTorrent
    2010-08-06 07:31 . 2010-07-20 06:40 27630760 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUPDATER\msgup1000_1270_us_u1.exe
    2010-07-24 18:47 . 2009-07-19 04:30 188152 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\FlashGot.exe
    2010-06-18 06:45 . 2010-04-13 06:25 439816 ----a-w- c:\documents and settings\Administrator\Application Data\Real\Update\setup3.10\setup.exe
    2010-06-16 16:29 . 2008-03-12 21:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
    2010-06-15 00:23 . 2010-06-16 16:30 607472 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUPDATER\yupdater.exe
    2010-06-14 14:31 . 2007-10-07 07:09 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
    2010-06-14 09:08 . 2010-06-21 05:37 103424 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
    2010-06-14 09:08 . 2010-06-21 05:37 545280 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
    2010-06-14 09:08 . 2010-06-21 05:37 4687360 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com\libs\cooliris192.dll
    2010-06-14 09:08 . 2010-06-21 05:37 425984 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
    2010-06-14 09:08 . 2010-06-21 05:37 152064 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
    2010-06-14 09:08 . 2010-06-21 05:37 4687872 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com\libs\cooliris190.dll
    2010-06-14 09:08 . 2010-06-21 05:37 57856 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
    2010-06-07 08:34 . 2010-06-21 05:37 52224 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\FFExternalAlert.dll
    2010-06-07 08:34 . 2010-06-21 05:37 101376 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\RadioWMPCore.dll
    2010-05-28 06:36 . 2010-05-28 06:36 118784 ----a-w- c:\documents and settings\Administrator\Application Data\Real\Update\temp\~Upg0\install.dll
    2007-10-08 13:05 . 2007-10-08 13:05 56 --sh--r- c:\windows\system32\57B6654BED.sys
    2007-10-08 13:05 . 2007-10-08 13:05 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{b7f907ee-0a1b-43b8-a611-b429a184ad6b} "= "c:\program files\torrents.to\tbtor1.dll" [2010-08-06 2515552]
    "{c95a4e8e-816d-4655-8c79-d736da1adb6d} "= "c:\program files\Hotspot_Shield\tbHot1.dll" [2010-08-06 2515552]

    [HKEY_CLASSES_ROOT\clsid\{b7f907ee-0a1b-43b8-a611-b429a184ad6b}]

    [HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b7f907ee-0a1b-43b8-a611-b429a184ad6b}]
    2010-08-06 10:15 2515552 ----a-w- c:\program files\torrents.to\tbtor1.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
    2010-08-06 10:16 2515552 ----a-w- c:\program files\Hotspot_Shield\tbHot1.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
    2009-07-17 10:56 204248 ----a-w- c:\program files\Hotspot Shield\HssIE\HssIE.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{b7f907ee-0a1b-43b8-a611-b429a184ad6b} "= "c:\program files\torrents.to\tbtor1.dll" [2010-08-06 2515552]
    "{c95a4e8e-816d-4655-8c79-d736da1adb6d} "= "c:\program files\Hotspot_Shield\tbHot1.dll" [2010-08-06 2515552]

    [HKEY_CLASSES_ROOT\clsid\{b7f907ee-0a1b-43b8-a611-b429a184ad6b}]

    [HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{B7F907EE-0A1B-43B8-A611-B429A184AD6B} "= "c:\program files\torrents.to\tbtor1.dll" [2010-08-06 2515552]
    "{C95A4E8E-816D-4655-8C79-D736DA1ADB6D} "= "c:\program files\Hotspot_Shield\tbHot1.dll" [2010-08-06 2515552]

    [HKEY_CLASSES_ROOT\clsid\{b7f907ee-0a1b-43b8-a611-b429a184ad6b}]

    [HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Yahoo! Pager "= "c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
    "swg "= "c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-01 68856]
    "MsnMsgr "= "c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
    "updateMgr "= "c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
    "Free Download Manager "= "c:\program files\Free Download Manager\fdm.exe" [2008-05-20 2474031]
    "uTorrent "= "c:\program files\uTorrent\uTorrent.exe" [2010-02-22 320816]
    "eMuleAutoStart "= "c:\program files\eMule\emule.exe" [2010-04-07 5758976]
    "ctfmon.exe "= "c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray "= "c:\windows\system32\igfxtray.exe" [2003-07-09 155648]
    "HotKeysCmds "= "c:\windows\system32\hkcmd.exe" [2003-07-09 114688]
    "SoundMan "= "SOUNDMAN.EXE" [2005-11-11 90112]
    "NeroFilterCheck "= "c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
    "RemoteControl "= "c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
    "LanguageShortcut "= "c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]
    "HP Software Update "= "c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
    "QuickTime Task "= "c:\program files\QuickTime\qttask.exe" [2007-10-19 286720]
    "SunJavaUpdateSched "= "c:\program files\Java\jre6\bin\jusched.exe" [2009-01-31 148888]
    "TkBellExe "= "c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-04 185896]
    "BluetoothAuthenticationAgent "= "bthprops.cpl" [2008-04-14 110592]
    "googletalk "= "c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
    "ANIWZCS2Service "= "c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]
    "D-Link D-Link Wireless 108G DWA-120 "= "c:\program files\D-Link\D-Link Wireless 108G DWA-120\AirPlusCFG.exe" [2007-09-27 1671168]
    "avast5 "= "c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
    Belkin F5D8053 N Wireless USB Adapter Utility.lnk - c:\program files\Belkin\F5D8053\Belkinwcui.exe [2007-9-17 1732608]
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
    TotalMedia Backup Monitor.lnk - c:\program files\ArcSoft\TotalMedia Backup\uBBMonitor.exe [2009-3-26 315392]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoThumbnailCache "= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "c:\\Program Files\\eMule\\eMule.exe "=
    "c:\\Program Files\\uTorrent\\uTorrent.exe "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe "=
    "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe "=
    "c:\\Program Files\\Free Download Manager\\fdm.exe "=
    "c:\\Program Files\\Free Download Manager\\fdmwi.exe "=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe "=
    "c:\\Program Files\\Google\\Google Talk\\googletalk.exe "=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe "=
    "c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\English\\setup.exe "=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe "=
    "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe "=
    "c:\\Program Files\\Messenger\\Msmsgs.exe "=
    "c:\\WINDOWS\\system32\\rtcshare.exe "=
    "c:\\Program Files\\NetMeeting\\conf.exe "=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
    "AllowInboundEchoRequest "= 1 (0x1)

    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [4/2/2008 2:07 AM 162640]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/2/2008 2:07 AM 19024]
    R2 AWISp50;AWISp50 NDIS Protocol Driver;c:\windows\system32\drivers\AWISp50.sys [3/15/2006 4:35 PM 17664]
    R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [5/22/2009 11:03 AM 57376]
    R3 slnt;Realtek RTL8139D Family Fast Ethernet NIC;c:\windows\system32\drivers\slnt.sys [10/7/2007 2:57 PM 18004]
    S3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [4/1/2009 12:22 PM 377920]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-08-07 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 11:57]

    2010-08-07 c:\windows\Tasks\ParetoLogic Registration3.job
    - c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2009-10-12 05:01]

    2010-08-06 c:\windows\Tasks\ParetoLogic Update Version3.job
    - c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2009-10-12 05:01]

    2010-08-06 c:\windows\Tasks\PC Health Advisor Defrag.job
    - c:\program files\ParetoLogic\PCHA\PCHA.exe [2010-06-23 04:06]

    2010-08-07 c:\windows\Tasks\PC Health Advisor.job
    - c:\program files\ParetoLogic\PCHA\PCHA.exe [2010-06-23 04:06]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.yahoo.com/
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    mStart Page = hxxp://www.yahoo.com/
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    uInternet Settings,ProxyOverride = local
    uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
    IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
    IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
    IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
    IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
    FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\FFExternalAlert.dll
    FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\RadioWMPCore.dll
    FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
    FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
    FF - plugin: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "ui.use_native_colors ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.lu ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.nu ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.nz ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgbaam7a8h ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgberp4a5d4ar ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--p1ai ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgbayh7gpa ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.tel ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.auth.force-generic-ntlm ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.proxy.type ", 5);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.buffer.cache.count ", 24);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.buffer.cache.size ", 4096);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "dom.ipc.plugins.timeoutSecs ", 45);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "svg.smil.enabled ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "accelerometer.enabled ", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref ", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.renego_unrestricted_hosts ", " ");
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.treat_unsafe_negotiation_as_broken ", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.require_safe_negotiation ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name ", "chrome://browser/locale/browser.properties ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description ", "chrome://browser/locale/browser.properties ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "plugins.update.notifyUser ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.nptest.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npswf32.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npctrl.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npqtplugin.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled ", false);
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-08-07 19:40
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'explorer.exe'(1308)
    c:\windows\system32\WININET.dll
    c:\progra~1\mcafee\SITEAD~1\saHook.dll
    c:\windows\system32\ieframe.dll
    c:\program files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    c:\program files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
    c:\program files\Microsoft Office\OFFICE11\msohev.dll
    c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
    c:\windows\system32\DVobSub.ax
    c:\windows\system32\vobsub.dll
    c:\windows\system32\bsrmdec.ax
    c:\program files\Common Files\Ahead\DSFilter\NeVideo.ax
    c:\program files\Common Files\Ahead\Lib\AdvrCntr.dll
    c:\program files\CyberLink\PowerDVD\NavFilter\clm4splt.ax
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Alwil Software\Avast5\AvastSvc.exe
    c:\windows\SOUNDMAN.EXE
    c:\windows\system32\rundll32.exe
    c:\program files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Hotspot Shield\bin\openvpnas.exe
    c:\program files\Hotspot Shield\HssWPR\hsssrv.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\McAfee\SiteAdvisor\McSACore.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\windows\system32\HPZipm12.exe
    c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    c:\windows\system32\rundll32.exe
    c:\windows\system32\wdfmgr.exe
    c:\program files\Viewpoint\Common\ViewpointService.exe
    c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
    c:\program files\Hotspot Shield\bin\openvpntray.exe
    c:\program files\Internet Explorer\IEXPLORE.EXE
    c:\program files\Windows Live\Toolbar\wltuser.exe
    c:\windows\system32\NOTEPAD.EXE
    .
    **************************************************************************
    .
    Completion time: 2010-08-07 19:53:57 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-08-07 16:52

    Pre-Run: 7,273,725,952 bytes free
    Post-Run: 7,343,030,272 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT= "Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS= "Microsoft Windows XP Professional" /noexecute=optin /fastdetect

    - - End Of File - - 3293C811DAF6DAAE499CCBBCD8B2F2A0
     
  13. 2010/08/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I'm not familiar with RegistryTool, but registry tinkering programs are not recommended, so I strongly suggest, you uninstall it.
    Here is why: http://miekiemoes.blogspot.com/2008/02/registry-cleaners-and-system-tweaking_13.html

    ================================================================

    Unless you installed Viewpoint Manager knowledgeably...
    Go Start>Control Panel>Add\Remove (Programs and Features in Vista), and...
    Uninstall any of the following programs associated with Viewpoint:
    * Viewpoint Manager
    * Viewpoint Media Player
    * Viewpoint Toolbar
    This program does not do anything bad such as deliver ads or spy on you, but it is considered foistware ( "drive-by-install ") as it is installed without your consent through programs like AOL, AIM, Compuserve, etc.

    =============================================================

    1. Please open Notepad
    • Click Start , then Run
    • Type notepad .exe in the Run Box.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    File::
    c:\windows\system32\57B6654BED.sys
    

    3. Save the above as CFScript.txt

    4. Close/disable all anti virus and anti malware programs again, so they do not interfere with the running of ComboFix.

    5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [​IMG]


    6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
     
  14. 2010/08/08
    yosef7000

    yosef7000 Inactive Thread Starter

    Joined:
    2010/08/06
    Messages:
    24
    Likes Received:
    0
    I uninstalled registerytool, and I only had Viewpoint Media Player on my system, uninstalled it too.
    Here's the log...


    ComboFix 10-08-06.03 - Administrator 08/08/2010 9:24.2.1 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1256.973.1033.18.254.94 [GMT 3:00]
    Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
    AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

    FILE ::
    "c:\windows\system32\57B6654BED.sys "
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Administrator\.exe
    c:\windows\system32\57B6654BED.sys

    .
    ((((((((((((((((((((((((( Files Created from 2010-07-08 to 2010-08-08 )))))))))))))))))))))))))))))))
    .

    2010-08-07 06:53 . 2010-08-07 06:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
    2010-08-07 06:52 . 2010-04-29 12:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-08-07 06:52 . 2010-08-07 06:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-08-07 06:52 . 2010-04-29 12:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-08-07 06:52 . 2010-08-07 06:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-08-06 10:49 . 2010-08-06 11:28 -------- d-----w- c:\documents and settings\Administrator\Application Data\RegistryTool
    2010-08-06 10:47 . 2010-08-06 12:08 -------- d-----w- c:\program files\RegistryTool
    2010-08-06 04:27 . 2010-08-06 04:27 2560 ----a-w- c:\windows\_MSRSTRT.EXE
    2010-07-20 06:40 . 2010-08-06 07:31 27630760 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUPDATER\msgup1000_1270_us_u1.exe
    2010-07-14 10:29 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
    2010-07-10 10:54 . 2010-07-10 10:54 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\pcsx2
    2010-07-10 09:01 . 2010-07-10 10:43 -------- d-----w- c:\windows\Logs
    2010-07-10 08:58 . 2010-07-10 10:54 -------- d-----w- c:\program files\PCSX2 0.9.7
    2010-07-09 08:46 . 2010-07-09 15:14 -------- d-----w- C:\New Folder

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-08-08 06:37 . 2008-01-18 10:15 -------- d-----w- c:\documents and settings\Administrator\Application Data\uTorrent
    2010-08-08 06:16 . 2008-06-01 10:08 -------- d-----w- c:\documents and settings\Administrator\Application Data\Free Download Manager
    2010-08-08 06:06 . 2008-08-24 13:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
    2010-07-24 18:47 . 2009-07-19 04:30 188152 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\FlashGot.exe
    2010-06-18 06:45 . 2010-04-13 06:25 439816 ----a-w- c:\documents and settings\Administrator\Application Data\Real\Update\setup3.10\setup.exe
    2010-06-16 16:29 . 2008-03-12 21:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
    2010-06-15 00:23 . 2010-06-16 16:30 607472 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUPDATER\yupdater.exe
    2010-06-14 14:31 . 2007-10-07 07:09 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
    2010-06-14 09:08 . 2010-06-21 05:37 103424 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
    2010-06-14 09:08 . 2010-06-21 05:37 545280 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
    2010-06-14 09:08 . 2010-06-21 05:37 4687360 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com\libs\cooliris192.dll
    2010-06-14 09:08 . 2010-06-21 05:37 425984 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
    2010-06-14 09:08 . 2010-06-21 05:37 152064 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
    2010-06-14 09:08 . 2010-06-21 05:37 4687872 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com\libs\cooliris190.dll
    2010-06-14 09:08 . 2010-06-21 05:37 57856 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
    2010-06-07 08:34 . 2010-06-21 05:37 52224 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\FFExternalAlert.dll
    2010-06-07 08:34 . 2010-06-21 05:37 101376 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\RadioWMPCore.dll
    2010-05-28 06:36 . 2010-05-28 06:36 118784 ----a-w- c:\documents and settings\Administrator\Application Data\Real\Update\temp\~Upg0\install.dll
    2007-10-08 13:05 . 2007-10-08 13:05 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{b7f907ee-0a1b-43b8-a611-b429a184ad6b} "= "c:\program files\torrents.to\tbtor1.dll" [2010-08-06 2515552]
    "{c95a4e8e-816d-4655-8c79-d736da1adb6d} "= "c:\program files\Hotspot_Shield\tbHot1.dll" [2010-08-06 2515552]

    [HKEY_CLASSES_ROOT\clsid\{b7f907ee-0a1b-43b8-a611-b429a184ad6b}]

    [HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b7f907ee-0a1b-43b8-a611-b429a184ad6b}]
    2010-08-06 10:15 2515552 ----a-w- c:\program files\torrents.to\tbtor1.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
    2010-08-06 10:16 2515552 ----a-w- c:\program files\Hotspot_Shield\tbHot1.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
    2009-07-17 10:56 204248 ----a-w- c:\program files\Hotspot Shield\HssIE\HssIE.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{b7f907ee-0a1b-43b8-a611-b429a184ad6b} "= "c:\program files\torrents.to\tbtor1.dll" [2010-08-06 2515552]
    "{c95a4e8e-816d-4655-8c79-d736da1adb6d} "= "c:\program files\Hotspot_Shield\tbHot1.dll" [2010-08-06 2515552]

    [HKEY_CLASSES_ROOT\clsid\{b7f907ee-0a1b-43b8-a611-b429a184ad6b}]

    [HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{B7F907EE-0A1B-43B8-A611-B429A184AD6B} "= "c:\program files\torrents.to\tbtor1.dll" [2010-08-06 2515552]
    "{C95A4E8E-816D-4655-8C79-D736DA1ADB6D} "= "c:\program files\Hotspot_Shield\tbHot1.dll" [2010-08-06 2515552]

    [HKEY_CLASSES_ROOT\clsid\{b7f907ee-0a1b-43b8-a611-b429a184ad6b}]

    [HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Yahoo! Pager "= "c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
    "swg "= "c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-01 68856]
    "MsnMsgr "= "c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
    "updateMgr "= "c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
    "Free Download Manager "= "c:\program files\Free Download Manager\fdm.exe" [2008-05-20 2474031]
    "uTorrent "= "c:\program files\uTorrent\uTorrent.exe" [2010-02-22 320816]
    "eMuleAutoStart "= "c:\program files\eMule\emule.exe" [2010-04-07 5758976]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray "= "c:\windows\system32\igfxtray.exe" [2003-07-09 155648]
    "HotKeysCmds "= "c:\windows\system32\hkcmd.exe" [2003-07-09 114688]
    "SoundMan "= "SOUNDMAN.EXE" [2005-11-11 90112]
    "NeroFilterCheck "= "c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
    "RemoteControl "= "c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
    "LanguageShortcut "= "c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]
    "HP Software Update "= "c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
    "QuickTime Task "= "c:\program files\QuickTime\qttask.exe" [2007-10-19 286720]
    "SunJavaUpdateSched "= "c:\program files\Java\jre6\bin\jusched.exe" [2009-01-31 148888]
    "TkBellExe "= "c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-04 185896]
    "BluetoothAuthenticationAgent "= "bthprops.cpl" [2008-04-14 110592]
    "googletalk "= "c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
    "ANIWZCS2Service "= "c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]
    "D-Link D-Link Wireless 108G DWA-120 "= "c:\program files\D-Link\D-Link Wireless 108G DWA-120\AirPlusCFG.exe" [2007-09-27 1671168]
    "avast5 "= "c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
    Belkin F5D8053 N Wireless USB Adapter Utility.lnk - c:\program files\Belkin\F5D8053\Belkinwcui.exe [2007-9-17 1732608]
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
    TotalMedia Backup Monitor.lnk - c:\program files\ArcSoft\TotalMedia Backup\uBBMonitor.exe [2009-3-26 315392]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoThumbnailCache "= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "c:\\Program Files\\eMule\\eMule.exe "=
    "c:\\Program Files\\uTorrent\\uTorrent.exe "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe "=
    "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe "=
    "c:\\Program Files\\Free Download Manager\\fdm.exe "=
    "c:\\Program Files\\Free Download Manager\\fdmwi.exe "=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe "=
    "c:\\Program Files\\Google\\Google Talk\\googletalk.exe "=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe "=
    "c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\English\\setup.exe "=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe "=
    "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe "=
    "c:\\Program Files\\Messenger\\Msmsgs.exe "=
    "c:\\WINDOWS\\system32\\rtcshare.exe "=
    "c:\\Program Files\\NetMeeting\\conf.exe "=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
    "AllowInboundEchoRequest "= 1 (0x1)

    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [4/2/2008 2:07 AM 162640]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/2/2008 2:07 AM 19024]
    R2 AWISp50;AWISp50 NDIS Protocol Driver;c:\windows\system32\drivers\AWISp50.sys [3/15/2006 4:35 PM 17664]
    R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [7/31/2008 7:34 PM 93320]
    R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [5/22/2009 11:03 AM 57376]
    R3 slnt;Realtek RTL8139D Family Fast Ethernet NIC;c:\windows\system32\drivers\slnt.sys [10/7/2007 2:57 PM 18004]
    S3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [4/1/2009 12:22 PM 377920]
    S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\D-Link\D-Link Wireless 108G DWA-120\JSWUtil\jswpsapi.exe [9/3/2009 8:08 PM 352338]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-08-07 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 11:57]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.yahoo.com/
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    mStart Page = hxxp://www.yahoo.com/
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    uInternet Settings,ProxyOverride = local
    uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
    IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
    IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
    IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
    IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\
    FF - prefs.js: browser.search.selectedEngine - Facebook
    FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
    FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\FFExternalAlert.dll
    FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\RadioWMPCore.dll
    FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
    FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
    FF - plugin: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "ui.use_native_colors ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.lu ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.nu ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.nz ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgbaam7a8h ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgberp4a5d4ar ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--p1ai ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgbayh7gpa ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.tel ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.auth.force-generic-ntlm ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.proxy.type ", 5);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.buffer.cache.count ", 24);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.buffer.cache.size ", 4096);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "dom.ipc.plugins.timeoutSecs ", 45);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "svg.smil.enabled ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "accelerometer.enabled ", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref ", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.renego_unrestricted_hosts ", " ");
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.treat_unsafe_negotiation_as_broken ", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.require_safe_negotiation ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name ", "chrome://browser/locale/browser.properties ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description ", "chrome://browser/locale/browser.properties ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "plugins.update.notifyUser ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.nptest.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npswf32.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npctrl.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npqtplugin.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled ", false);
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-08-08 09:37
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2010-08-08 09:43:44
    ComboFix-quarantined-files.txt 2010-08-08 06:43
    ComboFix2.txt 2010-08-07 16:54

    Pre-Run: 6,902,235,136 bytes free
    Post-Run: 6,877,462,528 bytes free

    - - End Of File - - 29ADF13518E00149764F229E101260A8
     
  15. 2010/08/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Good :)

    How is computer doing at the moment?

    Uninstall Combofix:
    Go Start > Run [Vista users, go Start> "Start search"]
    Type in:
    Combofix /Uninstall
    Note the space between the "Combofix" and the "/Uninstall "
    Click OK (Vista users - press Enter).
    Restart computer.

    ===============================================================

    Download OTL to your Desktop.

    * Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    * Under the Custom Scan box paste this in:



    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\*. /mp /s
    /md5start
    /md5stop
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs



    * Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  16. 2010/08/08
    yosef7000

    yosef7000 Inactive Thread Starter

    Joined:
    2010/08/06
    Messages:
    24
    Likes Received:
    0
    It still stuck on Windows classic theme and won't let me change it. I uninstalled Combofix, downloaded OTL, ran it, copied and pasted that code, and clicked on the quick scan button, nothing happened ! so I clicked on it again at least 6 times! LOL then I realized that it's already scanning :)
    Here's the OTL.Txt log...

    OTL logfile created on: 8/8/2010 6:46:59 PM - Run 1
    OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Administrator\Desktop
    Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 7.0.5730.13)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    254.00 Mb Total Physical Memory | 54.00 Mb Available Physical Memory | 21.00% Memory free
    662.00 Mb Paging File | 199.00 Mb Available in Paging File | 30.00% Paging File free
    Paging file location(s): C:\pagefile.sys 384 768 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 29.29 Gb Total Space | 6.47 Gb Free Space | 22.08% Space Free | Partition Type: NTFS
    Drive D: | 39.06 Gb Total Space | 0.11 Gb Free Space | 0.27% Space Free | Partition Type: NTFS
    Drive E: | 43.43 Gb Total Space | 1.05 Gb Free Space | 2.42% Space Free | Partition Type: NTFS
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    Drive H: | 465.65 Gb Total Space | 103.72 Gb Free Space | 22.27% Space Free | Partition Type: FAT32
    I: Drive not present or media not loaded

    Computer Name: ALBAWASE-F56D6E
    Current User Name: Administrator
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: On
    Skip Microsoft Files: On
    File Age = 90 Days
    Output = Standard
    Quick Scan

    ========== Processes (SafeList) ==========

    PRC - [2010/08/08 18:30:39 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
    PRC - [2010/08/08 09:47:01 | 000,381,304 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exe
    PRC - [2010/05/20 17:19:16 | 000,088,176 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    PRC - [2010/04/07 16:00:04 | 005,758,976 | ---- | M] (http://www.emule-project.net) -- C:\Program Files\eMule\emule.exe
    PRC - [2010/03/09 14:24:10 | 002,769,336 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    PRC - [2010/03/09 14:24:08 | 000,040,384 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    PRC - [2009/08/11 02:19:14 | 000,094,256 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpntray.exe
    PRC - [2009/08/11 02:19:08 | 000,132,144 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe
    PRC - [2009/08/06 21:58:38 | 000,331,824 | ---- | M] (AnchorFree Inc.) -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
    PRC - [2009/05/19 11:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    PRC - [2008/08/01 17:28:11 | 000,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    PRC - [2008/04/14 03:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
    PRC - [2008/04/04 03:35:41 | 000,185,896 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    PRC - [2007/09/27 20:08:34 | 001,671,168 | ---- | M] (D-Link) -- C:\Program Files\D-Link\D-Link Wireless 108G DWA-120\AirPlusCFG.exe
    PRC - [2007/09/17 11:28:26 | 001,732,608 | ---- | M] (Belkin) -- C:\Program Files\Belkin\F5D8053\Belkinwcui.exe
    PRC - [2007/08/09 10:27:52 | 000,073,728 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
    PRC - [2007/01/19 11:49:26 | 000,049,152 | ---- | M] (Wireless Service) -- C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    PRC - [2007/01/19 11:49:04 | 000,049,152 | ---- | M] (Wireless Service) -- C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    PRC - [2005/11/11 09:07:40 | 000,090,112 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE


    ========== Modules (SafeList) ==========

    MOD - [2010/08/08 18:30:39 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
    MOD - [2010/07/14 13:30:14 | 000,018,688 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\sahook.dll
    MOD - [2008/04/14 03:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx


    ========== Win32 Services (SafeList) ==========

    SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
    SRV - [2010/05/20 17:19:16 | 000,088,176 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
    SRV - [2010/03/09 14:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
    SRV - [2010/03/09 14:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
    SRV - [2010/03/09 14:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
    SRV - [2009/08/11 02:19:16 | 000,057,640 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Hotspot Shield\bin\HssTrayService.exe -- (HssTrayService)
    SRV - [2009/08/11 02:19:08 | 000,132,144 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe -- (HotspotShieldService)
    SRV - [2009/08/06 21:58:38 | 000,331,824 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv)
    SRV - [2009/08/05 22:48:42 | 000,704,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
    SRV - [2009/05/19 11:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
    SRV - [2008/09/09 23:01:53 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
    SRV - [2007/09/21 00:23:40 | 000,352,338 | ---- | M] (Atheros Communications, Inc.) [On_Demand | Stopped] -- C:\Program Files\D-Link\D-Link Wireless 108G DWA-120\JSWUtil\jswpsapi.exe -- (jswpsapi)
    SRV - [2007/08/09 10:27:52 | 000,073,728 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
    SRV - [2007/01/19 11:49:26 | 000,049,152 | ---- | M] (Wireless Service) [Auto | Running] -- C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe -- (ANIWZCSdService)
    SRV - [2005/11/14 01:06:04 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys -- (catchme)
    DRV - [2010/03/09 14:12:54 | 000,046,672 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
    DRV - [2010/03/09 14:12:33 | 000,162,640 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
    DRV - [2010/03/09 14:09:08 | 000,023,376 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
    DRV - [2010/03/09 14:08:41 | 000,100,432 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
    DRV - [2010/03/09 14:08:30 | 000,019,024 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
    DRV - [2010/03/09 14:08:15 | 000,028,880 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
    DRV - [2010/02/11 15:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
    DRV - [2009/08/05 22:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
    DRV - [2009/07/22 22:13:20 | 000,028,592 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tap0901.sys -- (tap0901)
    DRV - [2009/07/02 05:34:30 | 000,033,840 | ---- | M] (AnchorFree Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hssdrv.sys -- (HssDrv)
    DRV - [2008/01/24 00:25:32 | 000,027,136 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tapvpn.sys -- (tapvpn)
    DRV - [2007/10/07 15:01:22 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
    DRV - [2007/07/28 14:50:36 | 000,517,632 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rt2870.sys -- (rt2870)
    DRV - [2007/07/06 17:30:54 | 000,057,376 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\jswscimd.sys -- (JSWSCIMD)
    DRV - [2007/06/06 22:40:50 | 000,377,920 | ---- | M] (D-Link Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\A5AGU.sys -- (A5AGU)
    DRV - [2006/11/30 14:58:42 | 000,090,800 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se44unic.sys -- (se44unic) Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (WDM)
    DRV - [2006/11/30 14:58:34 | 000,086,432 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se44obex.sys -- (se44obex)
    DRV - [2006/11/30 14:58:32 | 000,018,704 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se44nd5.sys -- (se44nd5) Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (NDIS)
    DRV - [2006/11/30 14:58:30 | 000,088,624 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se44mgmt.sys -- (se44mgmt) Sony Ericsson Device 068 USB WMC Device Management Drivers (WDM)
    DRV - [2006/11/30 14:58:26 | 000,097,088 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se44mdm.sys -- (se44mdm)
    DRV - [2006/11/30 14:58:24 | 000,009,360 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se44mdfl.sys -- (se44mdfl)
    DRV - [2006/11/30 14:58:18 | 000,061,536 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se44bus.sys -- (se44bus) Sony Ericsson Device 068 driver (WDM)
    DRV - [2006/03/15 16:35:06 | 000,017,664 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\AWISp50.sys -- (AWISp50)
    DRV - [2005/12/11 11:55:38 | 000,028,195 | ---- | M] (Alpha Networks Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\ANIO.sys -- (ANIO)
    DRV - [2005/11/22 09:44:22 | 003,804,416 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
    DRV - [2005/06/09 11:08:40 | 000,018,004 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\slnt.sys -- (slnt)
    DRV - [2004/06/17 10:05:46 | 000,136,832 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pfc027.sys -- (SoC PC-Camera Service)
    DRV - [2001/08/17 13:49:10 | 000,026,624 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\irstusb.sys -- (STIrUsb)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr8/*http://www.yahoo.com/ext/search/search.html

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    IE - HKCU\..\URLSearchHook: {b7f907ee-0a1b-43b8-a611-b429a184ad6b} - C:\Program Files\torrents.to\tbtor1.dll (Conduit Ltd.)
    IE - HKCU\..\URLSearchHook: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot1.dll (Conduit Ltd.)
    IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local

    ========== FireFox ==========

    FF - prefs.js..browser.search.selectedEngine: "Wikipedia (en) "
    FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/ "
    FF - prefs.js..extensions.enabledItems: piclens@cooliris.com:1.12.0.36949
    FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7.4
    FF - prefs.js..extensions.enabledItems: facepad@lazyrussian.com:0.7.3
    FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.1.26
    FF - prefs.js..extensions.enabledItems: {c95a4e8e-816d-4655-8c79-d736da1adb6d}:2.5.6.0
    FF - prefs.js..extensions.enabledItems: {c33c5b47-69c8-45a4-a5e0-af85bbe628dd}:1.6.1.3
    FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
    FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.2

    FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/04/04 03:36:45 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/08/08 12:12:36 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/26 18:52:48 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/24 21:45:43 | 000,000,000 | ---D | M]

    [2009/01/23 14:38:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
    [2010/08/07 18:47:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions
    [2010/06/21 08:38:05 | 000,000,000 | ---D | M] (FlashGot) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
    [2010/06/21 08:37:36 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    [2009/11/12 08:05:35 | 000,000,000 | ---D | M] (torrents.to Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{b7f907ee-0a1b-43b8-a611-b429a184ad6b}
    [2010/07/22 20:17:00 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
    [2010/06/21 08:37:57 | 000,000,000 | ---D | M] (Interclue) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{c33c5b47-69c8-45a4-a5e0-af85bbe628dd}
    [2010/06/21 08:37:39 | 000,000,000 | ---D | M] (Hotspot Shield Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}
    [2010/06/21 08:38:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\facepad@lazyrussian.com
    [2010/06/21 08:37:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com
    [2009/01/15 09:37:48 | 000,000,884 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\searchplugins\conduit.xml
    [2009/04/04 15:28:16 | 000,002,042 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\searchplugins\facebook.xml
    [2010/08/04 15:43:33 | 000,004,859 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\searchplugins\isohunt---bt-search.xml
    [2009/11/24 15:38:46 | 000,001,597 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\searchplugins\the-pirate-bay.xml
    [2009/08/25 10:27:55 | 000,000,945 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\searchplugins\youtube-video-search.xml
    [2010/08/07 17:18:12 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
    [2010/06/10 07:40:12 | 000,002,024 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\McSiteAdvisor.xml

    O1 HOSTS File: ([2010/08/08 09:36:52 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
    O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
    O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
    O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
    O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O2 - BHO: (toto gateway Toolbar) - {b7f907ee-0a1b-43b8-a611-b429a184ad6b} - C:\Program Files\torrents.to\tbtor1.dll (Conduit Ltd.)
    O2 - BHO: (Hotspot Shield Toolbar) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot1.dll (Conduit Ltd.)
    O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll ()
    O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
    O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (toto gateway Toolbar) - {b7f907ee-0a1b-43b8-a611-b429a184ad6b} - C:\Program Files\torrents.to\tbtor1.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (Hotspot Shield Toolbar) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot1.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (Yahoo! ¤u¨م¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O3 - HKCU\..\Toolbar\ShellBrowser: (toto gateway Toolbar) - {B7F907EE-0A1B-43B8-A611-B429A184AD6B} - C:\Program Files\torrents.to\tbtor1.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\ShellBrowser: (Hotspot Shield Toolbar) - {C95A4E8E-816D-4655-8C79-D736DA1ADB6D} - C:\Program Files\Hotspot_Shield\tbHot1.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (toto gateway Toolbar) - {B7F907EE-0A1B-43B8-A611-B429A184AD6B} - C:\Program Files\torrents.to\tbtor1.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Hotspot Shield Toolbar) - {C95A4E8E-816D-4655-8C79-D736DA1ADB6D} - C:\Program Files\Hotspot_Shield\tbHot1.dll (Conduit Ltd.)
    O4 - HKLM..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Wireless Service)
    O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
    O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
    O4 - HKLM..\Run: [D-Link D-Link Wireless 108G DWA-120] C:\Program Files\D-Link\D-Link Wireless 108G DWA-120\AirPlusCFG.exe (D-Link)
    O4 - HKLM..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe (Google)
    O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
    O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
    O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
    O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
    O4 - HKCU..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe (http://www.emule-project.net)
    O4 - HKCU..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe (FreeDownloadManager.ORG)
    O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
    O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
    O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
    O4 - HKCU..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Belkin F5D8053 N Wireless USB Adapter Utility.lnk = C:\Program Files\Belkin\F5D8053\Belkinwcui.exe (Belkin)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TotalMedia Backup Monitor.lnk = C:\Program Files\ArcSoft\TotalMedia Backup\uBBMonitor.exe (ArcSoft, Inc.)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
    O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
    O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
    O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
    O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
    O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab (Java Plug-in 1.6.0_12)
    O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
    O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab (Java Plug-in 1.6.0_12)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab (Java Plug-in 1.6.0_12)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
    O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.17.233.49 193.188.97.193
    O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
    O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
    O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2007/10/07 10:11:44 | 000,000,000 | -HS- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    ========== Files/Folders - Created Within 90 Days ==========

    [2010/08/08 18:27:01 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
    [2010/08/08 18:18:51 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator\Recent
    [2010/08/08 13:04:15 | 000,000,000 | -HSD | C] -- C:\RECYCLER
    [2010/08/07 19:17:37 | 000,000,000 | RHSD | C] -- C:\cmdcons
    [2010/08/07 19:07:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2010/08/07 09:53:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
    [2010/08/07 09:52:28 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/08/07 09:52:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    [2010/08/07 09:52:23 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2010/08/07 09:52:22 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2010/08/06 13:49:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\RegistryTool
    [2010/08/06 13:47:53 | 000,000,000 | ---D | C] -- C:\Program Files\RegistryTool
    [2010/08/06 13:21:54 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
    [2010/07/10 13:55:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\pcsx2
    [2010/07/10 13:54:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\pcsx2
    [2010/07/10 12:01:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\Logs
    [2010/07/10 11:58:54 | 000,000,000 | ---D | C] -- C:\Program Files\PCSX2 0.9.7
    [2010/07/09 11:46:37 | 000,000,000 | ---D | C] -- C:\New Folder
    [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

    ========== Files - Modified Within 90 Days ==========

    [2010/08/08 18:30:39 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
    [2010/08/08 18:22:39 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2010/08/08 18:21:41 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
    [2010/08/08 18:20:33 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2010/08/08 18:19:29 | 017,039,360 | -H-- | M] () -- C:\Documents and Settings\Administrator\NTUSER.DAT
    [2010/08/08 18:19:29 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Administrator\ntuser.ini
    [2010/08/08 18:19:02 | 007,527,166 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
    [2010/08/08 13:15:04 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
    [2010/08/08 13:14:59 | 000,062,464 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010/08/08 09:37:14 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
    [2010/08/08 09:36:52 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
    [2010/08/08 00:19:28 | 000,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
    [2010/08/08 00:19:27 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
    [2010/08/07 19:17:43 | 000,000,281 | RHS- | M] () -- C:\boot.ini
    [2010/08/07 11:05:44 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [2010/08/07 09:52:33 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/08/06 13:28:34 | 000,000,967 | ---- | M] () -- C:\WINDOWS\win.ini
    [2010/08/06 13:28:34 | 000,000,211 | ---- | M] () -- C:\Boot.bak
    [2010/08/06 11:57:51 | 000,001,891 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2010/08/06 07:57:26 | 000,849,315 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\nw_uxpatcher.zip
    [2010/08/06 07:27:13 | 000,002,560 | ---- | M] () -- C:\WINDOWS\_MSRSTRT.EXE
    [2010/07/17 23:32:42 | 160,794,916 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\RE-1.part5.rar
    [2010/07/16 13:04:37 | 033,554,432 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Crash Bandicoot 3 - Warped [SCUS_942.44] psx - psone - by Sedan75.7z.001
    [2010/07/11 14:29:39 | 000,000,007 | ---- | M] () -- C:\WINDOWS\System32\ANIWZCSUSERNAME
    [2010/07/10 09:04:48 | 000,000,517 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\ePSXe.lnk
    [2010/06/23 18:13:29 | 000,489,196 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
    [2010/06/23 18:13:29 | 000,432,806 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2010/06/23 18:13:29 | 000,067,762 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2010/06/11 23:00:20 | 001,633,944 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2010/05/22 07:44:14 | 000,000,630 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\µTorrent.lnk
    [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2010/08/08 00:19:28 | 000,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
    [2010/08/08 00:19:27 | 000,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
    [2010/08/07 19:17:43 | 000,000,211 | ---- | C] () -- C:\Boot.bak
    [2010/08/07 19:17:39 | 000,260,272 | ---- | C] () -- C:\cmldr
    [2010/08/07 09:52:33 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/08/06 07:56:29 | 000,849,315 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\nw_uxpatcher.zip
    [2010/08/06 07:27:13 | 000,002,560 | ---- | C] () -- C:\WINDOWS\_MSRSTRT.EXE
    [2010/07/17 18:09:59 | 160,794,916 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\RE-1.part5.rar
    [2010/07/16 11:50:33 | 033,554,432 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Crash Bandicoot 3 - Warped [SCUS_942.44] psx - psone - by Sedan75.7z.001
    [2010/07/09 18:13:56 | 000,000,517 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\ePSXe.lnk
    [2009/09/03 20:10:04 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\WlanApp.dll
    [2009/09/03 20:10:03 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\JJAKEn.dll
    [2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
    [2009/05/22 10:51:44 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll
    [2009/04/01 12:46:57 | 000,000,962 | ---- | C] () -- C:\WINDOWS\System32\WLAN.INI
    [2008/08/24 16:52:08 | 000,000,021 | ---- | C] () -- C:\WINDOWS\atid.ini
    [2008/06/20 21:30:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iSnooker.INI
    [2008/06/12 07:45:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\WB.ini
    [2008/04/06 02:16:03 | 000,000,507 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
    [2008/02/02 00:00:06 | 000,001,555 | ---- | C] () -- C:\WINDOWS\ata live update.ini
    [2008/01/12 11:00:17 | 000,000,109 | ---- | C] () -- C:\WINDOWS\SYMGAMES.INI
    [2007/11/05 20:30:54 | 000,000,047 | ---- | C] () -- C:\WINDOWS\entpack.ini
    [2007/11/05 15:41:19 | 000,000,070 | ---- | C] () -- C:\WINDOWS\GECKOS.INI
    [2007/10/08 16:05:39 | 000,001,682 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
    [2007/10/07 22:35:44 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
    [2007/10/07 15:19:18 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2007/10/07 14:57:05 | 000,018,004 | R--- | C] () -- C:\WINDOWS\System32\drivers\slnt.sys
    [2007/10/07 14:56:11 | 000,157,184 | R--- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
    [2007/10/07 14:55:20 | 000,002,778 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
    [2007/10/07 14:55:18 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
    [2006/07/13 06:36:36 | 001,167,360 | ---- | C] () -- C:\WINDOWS\System32\acAuth.dll
    [2006/05/16 09:25:43 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\hpzids01.dll
    [2004/06/17 10:05:46 | 000,136,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\pfc027.sys
    [2004/01/08 10:30:22 | 000,011,170 | ---- | C] () -- C:\WINDOWS\System32\PA207Usd.dll
    [2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
    [2002/10/16 01:54:04 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
    [2002/03/21 15:39:02 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\UNACEV2.DLL

    ========== LOP Check ==========

    [2007/10/08 15:49:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\ACD Systems
    [2009/01/10 00:32:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Any Video Converter
    [2007/12/30 08:44:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Azureus
    [2010/08/08 18:23:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Free Download Manager
    [2008/09/26 07:09:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\JCreator
    [2008/01/12 01:08:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\LimeWire
    [2010/08/06 14:28:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\RegistryTool
    [2008/06/01 13:09:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Software Informer
    [2009/03/26 20:29:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Teleca
    [2010/08/08 18:56:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\uTorrent
    [2008/08/24 16:51:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore
    [2010/03/27 17:09:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
    [2007/12/30 08:07:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
    [2008/06/01 13:08:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
    [2008/09/26 07:09:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\JCreator
    [2008/12/30 14:11:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
    [2010/08/08 09:06:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
    [2007/10/07 15:02:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.* >
    [2007/10/07 10:11:44 | 000,000,000 | -HS- | M] () -- C:\AUTOEXEC.BAT
    [2010/08/06 13:28:34 | 000,000,211 | ---- | M] () -- C:\Boot.bak
    [2010/08/07 19:17:43 | 000,000,281 | RHS- | M] () -- C:\boot.ini
    [2004/08/03 23:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr
    [2010/08/08 09:43:46 | 000,018,729 | ---- | M] () -- C:\ComboFix.txt
    [2007/10/07 10:11:44 | 000,000,000 | -HS- | M] () -- C:\CONFIG.SYS
    [2010/08/06 00:11:02 | 000,000,423 | ---- | M] () -- C:\INSTALL.LOG
    [2007/10/07 10:11:44 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
    [2008/08/24 16:58:21 | 000,000,761 | -H-- | M] () -- C:\IPH.PH
    [2007/10/07 10:11:44 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
    [2004/08/04 15:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
    [2008/10/22 16:00:14 | 000,250,048 | RHS- | M] () -- C:\ntldr
    [2010/08/08 18:51:49 | 666,525,696 | -HS- | M] () -- C:\pagefile.sys
    [2007/10/07 15:26:21 | 000,000,268 | -H-- | M] () -- C:\sqmdata00.sqm
    [2007/11/21 14:12:24 | 000,000,268 | -H-- | M] () -- C:\sqmdata01.sqm
    [2007/11/22 14:47:22 | 000,000,268 | -H-- | M] () -- C:\sqmdata02.sqm
    [2007/12/07 22:26:08 | 000,000,268 | -H-- | M] () -- C:\sqmdata03.sqm
    [2007/12/08 19:50:20 | 000,000,268 | -H-- | M] () -- C:\sqmdata04.sqm
    [2007/12/09 03:15:12 | 000,000,268 | -H-- | M] () -- C:\sqmdata05.sqm
    [2007/12/09 03:26:41 | 000,000,268 | -H-- | M] () -- C:\sqmdata06.sqm
    [2007/12/09 12:31:29 | 000,000,268 | -H-- | M] () -- C:\sqmdata07.sqm
    [2008/01/23 19:15:38 | 000,000,232 | -H-- | M] () -- C:\sqmdata08.sqm
    [2007/10/07 15:26:21 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
    [2007/11/21 14:12:24 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
    [2007/11/22 14:47:22 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
    [2007/12/07 22:26:08 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
    [2007/12/08 19:50:20 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
    [2007/12/09 03:15:12 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
    [2007/12/09 03:26:41 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
    [2007/12/09 12:31:29 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
    [2008/01/23 19:15:38 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
    [2008/05/08 06:40:19 | 000,304,182 | ---- | M] () -- C:\StiImg.dat
    [2008/03/18 02:07:44 | 000,000,146 | ---- | M] () -- C:\YServer.txt

    < %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
    [2008/07/06 15:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
    [2006/06/03 21:29:06 | 000,076,288 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp4pi.dll
    [2007/04/09 13:23:54 | 000,028,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll

    < %systemroot%\system32\*.wt >

    < %systemroot%\system32\*.ruy >

    < %systemroot%\Fonts\*.com >
    [2006/04/18 15:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
    [2006/06/29 14:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
    [2006/04/18 15:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
    [2006/06/29 14:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

    < %systemroot%\*. /mp /s >


    < %systemroot%\system32\*.dll /lockedfiles >

    < %systemroot%\Tasks\*.job /lockedfiles >

    < %systemroot%\System32\config\*.sav >
    [2007/10/07 13:00:32 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
    [2007/10/07 13:00:32 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
    [2007/10/07 13:00:32 | 000,872,448 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

    < %systemroot%\system32\user32.dll /md5 >
    [2008/04/14 03:12:08 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B -- C:\WINDOWS\system32\user32.dll

    < %systemroot%\system32\ws2_32.dll /md5 >
    [2008/04/14 03:12:10 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\system32\ws2_32.dll

    < %systemroot%\system32\ws2help.dll /md5 >
    [2008/04/14 03:12:10 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=9789E95E1D88EEB4B922BF3EA7779C28 -- C:\WINDOWS\system32\ws2help.dll

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >

    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:54D4173A
    < End of report >
     
  17. 2010/08/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Go on....
     
  18. 2010/08/08
    yosef7000

    yosef7000 Inactive Thread Starter

    Joined:
    2010/08/06
    Messages:
    24
    Likes Received:
    0
    And the Extras.Txt...


    OTL Extras logfile created on: 8/8/2010 6:46:59 PM - Run 1
    OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Administrator\Desktop
    Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 7.0.5730.13)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    254.00 Mb Total Physical Memory | 54.00 Mb Available Physical Memory | 21.00% Memory free
    662.00 Mb Paging File | 199.00 Mb Available in Paging File | 30.00% Paging File free
    Paging file location(s): C:\pagefile.sys 384 768 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 29.29 Gb Total Space | 6.47 Gb Free Space | 22.08% Space Free | Partition Type: NTFS
    Drive D: | 39.06 Gb Total Space | 0.11 Gb Free Space | 0.27% Space Free | Partition Type: NTFS
    Drive E: | 43.43 Gb Total Space | 1.05 Gb Free Space | 2.42% Space Free | Partition Type: NTFS
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    Drive H: | 465.65 Gb Total Space | 103.72 Gb Free Space | 22.27% Space Free | Partition Type: FAT32
    I: Drive not present or media not loaded

    Computer Name: ALBAWASE-F56D6E
    Current User Name: Administrator
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: On
    Skip Microsoft Files: On
    File Age = 90 Days
    Output = Standard
    Quick Scan

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

    [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1 "
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled" = 1
    "AntiVirusOverride" = 0
    "FirewallOverride" = 0
    "AntiVirusDisableNotify" = 0
    "FirewallDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DoNotAllowExceptions" = 0
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22008

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
    "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Program Files\eMule\eMule.exe" = C:\Program Files\eMule\eMule.exe:*:Enabled:eMule Plus -- (http://www.emule-project.net)
    "C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
    "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
    "C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server -- (Yahoo! Inc.)
    "C:\Program Files\Free Download Manager\fdm.exe" = C:\Program Files\Free Download Manager\fdm.exe:*:Enabled:Free Download Manager -- (FreeDownloadManager.ORG)
    "C:\Program Files\Free Download Manager\fdmwi.exe" = C:\Program Files\Free Download Manager\fdmwi.exe:*:Disabled:fdmwi -- ()
    "C:\Program Files\Google\Google Talk\googletalk.exe" = C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk -- (Google)
    "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
    "C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 7.0.1.325\English\setup.exe" = C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 7.0.1.325\English\setup.exe:*:Enabled:Kaspersky Anti-Virus 7.0 Setup -- (Kaspersky Lab)
    "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)
    "C:\WINDOWS\system32\rtcshare.exe" = C:\WINDOWS\system32\rtcshare.exe:*:Enabled:RTC App Sharing -- (Microsoft Corporation)
    "C:\Program Files\NetMeeting\conf.exe" = C:\Program Files\NetMeeting\conf.exe:*:Enabled:Windows® NetMeeting® -- (Microsoft Corporation)


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
    "{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
    "{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
    "{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
    "{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
    "{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
    "{20749F76-4228-43AD-8AB5-E7B20D8040C4}" = hph_readme
    "{20B9BC7F-BB40-4A4F-95D6-91E4D8FBE5AF}" = PC CameraN
    "{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
    "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
    "{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
    "{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java(TM) 6 Update 12
    "{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
    "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3
    "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
    "{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
    "{36DC3E2F-CD8C-4953-9E8F-9A1916D10AA1}" = hph_software
    "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
    "{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}" = Google Earth
    "{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
    "{4C590030-7469-453E-8589-D15DA9D03F52}" = ANIWZCS2 Service
    "{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
    "{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
    "{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
    "{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
    "{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
    "{5B09BD67-4C99-46A1-8161-B7208CE18121}" = QuickTime
    "{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
    "{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
    "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
    "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
    "{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
    "{6994491D-D491-48F1-AE1F-E179C1FFFC2F}" = HP Photosmart Essential
    "{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
    "{6B164A39-1201-4991-B39E-6D58DB5C8B33}" = D-Link Wireless 108G DWA-120
    "{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
    "{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
    "{7B5CE976-C7A9-4E38-A7F3-6C8EF025DD8E}" = ANIO Service
    "{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
    "{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
    "{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
    "{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
    "{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
    "{883D5A3A-74C2-4873-BE18-89F467DFA6C8}" = Secure Copy 4
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8A62A068-3FD6-495A-9F66-26FE94F32EC9}" = Rhapsody Player Engine
    "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Extreme Graphics Driver
    "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
    "{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
    "{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
    "{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
    "{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
    "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
    "{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
    "{901E0401-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Arabic User Interface Pack
    "{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
    "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
    "{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
    "{993A94A9-DCE3-4774-B35D-D8C74FC1E0BE}" = Royale Remixed Theme
    "{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
    "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
    "{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
    "{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
    "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
    "{A8019072-B760-47E2-9BDD-DF94B4FBFFBB}" = ArcSoft TotalMedia Backup
    "{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
    "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
    "{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
    "{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
    "{ACCCEE83-B49B-4964-8A4F-378B8FBC9F75}" = hph_ProductContext
    "{B19F9155-9337-4807-B5EF-ED471DDB2CCE}" = hph_software_req
    "{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
    "{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
    "{B63C1E49-2E0E-406B-BD8A-C703E4263E0A}" = AdVantage
    "{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
    "{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
    "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
    "{BE365801-FB4B-49D7-87D2-9477EE371F1C}" = D1300_Help
    "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
    "{C13F11D1-00BA-44DF-B626-35E1C03F85E5}" = D1300
    "{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
    "{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
    "{D1BB4446-AE9C-4256-9A7F-4D46604D2462}" = Adobe Setup
    "{D1E44702-21F5-4918-B8A3-6D126D5BD33C}" = Windows Messenger 5.1
    "{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
    "{D2A3C9D5-0B56-4656-8277-7EDC65D62B6E}" = HP Photosmart and Deskjet 7.0 Software
    "{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
    "{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
    "{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
    "{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
    "{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
    "{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
    "{E6607F5B-50E7-4B54-81B7-F0600E3C8CF4}" = Belkin F5D8053 N Wireless USB Adapter
    "{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
    "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
    "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
    "{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
    "{F855C3AE-992D-4B84-A09D-07103CDCDAC2}" = Compact Wireless-G USB Adapter
    "{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
    "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
    "Adobe_2ac78060bc5856b0c1cf873bb919b58" = Adobe Photoshop CS3
    "Advanced WindowsCare V2 Personal_is1" = Advanced WindowsCare 2.57 Personal
    "Any Video Converter_is1" = Any Video Converter 2.6.3
    "avast5" = avast! Free Antivirus
    "CoreAAC Audio Decoder" = CoreAAC Audio Decoder (remove only)
    "eMule" = eMule
    "Free Download Manager_is1" = Free Download Manager 2.5
    "GOM Player" = GOM Player
    "Hotspot_Shield Toolbar" = Hotspot_Shield Toolbar
    "HotspotShield" = Hotspot Shield 1.22
    "HP Imaging Device Functions" = HP Imaging Device Functions 7.0
    "HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
    "HPExtendedCapabilities" = HP Customer Participation Program 7.0
    "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
    "InstallShield_{20B9BC7F-BB40-4A4F-95D6-91E4D8FBE5AF}" = PC CameraN
    "InstallShield_{E6607F5B-50E7-4B54-81B7-F0600E3C8CF4}" = Belkin F5D8053 N Wireless USB Adapter
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
    "MasterSplitter" = MasterSplitter Program
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
    "MSNINST" = MSN
    "MSTTS" = Microsoft Text-to-Speech Engine 4.0 (English)
    "Nero - Burning Rom!UninstallKey" = Nero 6 Enterprise Edition
    "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
    "pcsx2-r3113" = PCSX2 - Playstation 2 Emulator
    "RealPlayer 6.0" = RealPlayer
    "RM to MP3 Converter_is1" = RM to MP3 Converter 1.32
    "Software Informer_is1" = Software Informer 1.0 BETA
    "torrents.to Toolbar" = torrents.to Toolbar
    "VLC media player" = VideoLAN VLC media player 0.8.6h
    "VobSub" = VobSub v2.23 (Remove Only)
    "Windows Media Format Runtime" = Windows Media Format Runtime
    "Windows XP Service Pack" = Windows XP Service Pack 3
    "WinLiveSuite_Wave3" = Windows Live Essentials
    "WinRAR archiver" = WinRAR archiver
    "WinZip" = WinZip
    "Yahoo! Companion" = Yahoo! ¤u¨م¦C
    "Yahoo! Extras" = Yahoo! Browser Services
    "Yahoo! Mail" = Yahoo! Internet Mail
    "Yahoo! Messenger" = Yahoo! Messenger
    "YInstHelper" = Yahoo! Install Manager

    ========== HKEY_CURRENT_USER Uninstall List ==========

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "uTorrent" = µTorrent

    ========== Last 10 Event Log Errors ==========

    [ Antivirus Events ]
    Error - 10/25/2009 11:55:22 AM | Computer Name = ALBAWASE-F56D6E | Source = avast! | ID = 33554522
    Description =

    Error - 10/27/2009 7:21:49 AM | Computer Name = ALBAWASE-F56D6E | Source = avast! | ID = 33554522
    Description =

    Error - 11/6/2009 12:30:03 AM | Computer Name = ALBAWASE-F56D6E | Source = avast! | ID = 33554522
    Description =

    Error - 11/9/2009 11:24:09 AM | Computer Name = ALBAWASE-F56D6E | Source = avast! | ID = 33554522
    Description =

    Error - 11/9/2009 11:43:59 AM | Computer Name = ALBAWASE-F56D6E | Source = avast! | ID = 33554522
    Description =

    Error - 11/10/2009 9:37:13 AM | Computer Name = ALBAWASE-F56D6E | Source = avast! | ID = 33554522
    Description =

    Error - 11/12/2009 5:34:10 AM | Computer Name = ALBAWASE-F56D6E | Source = avast! | ID = 33554522
    Description =

    Error - 12/11/2009 10:13:12 AM | Computer Name = ALBAWASE-F56D6E | Source = avast! | ID = 33554522
    Description =

    Error - 2/18/2010 7:58:44 AM | Computer Name = ALBAWASE-F56D6E | Source = avast! | ID = 33554522
    Description =

    Error - 2/18/2010 7:58:44 AM | Computer Name = ALBAWASE-F56D6E | Source = avast! | ID = 33554522
    Description =

    [ Application Events ]
    Error - 8/6/2010 1:10:35 PM | Computer Name = ALBAWASE-F56D6E | Source = crypt32 | ID = 131075
    Description = Failed auto update retrieval of third-party root list cab from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
    with error: The specified server cannot perform the requested operation.

    Error - 8/6/2010 1:10:55 PM | Computer Name = ALBAWASE-F56D6E | Source = crypt32 | ID = 131083
    Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
    with error: The data is invalid.

    Error - 8/6/2010 1:10:55 PM | Computer Name = ALBAWASE-F56D6E | Source = crypt32 | ID = 131075
    Description = Failed auto update retrieval of third-party root list cab from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
    with error: The specified server cannot perform the requested operation.

    Error - 8/6/2010 4:24:58 PM | Computer Name = ALBAWASE-F56D6E | Source = Application Error | ID = 1000
    Description = Faulting application rundll32.exe, version 5.1.2600.5512, faulting
    module unknown, version 0.0.0.0, fault address 0x000d2cc5.

    Error - 8/6/2010 6:30:58 PM | Computer Name = ALBAWASE-F56D6E | Source = crypt32 | ID = 131083
    Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
    with error: The data is invalid.

    Error - 8/7/2010 7:02:51 AM | Computer Name = ALBAWASE-F56D6E | Source = Application Error | ID = 1000
    Description = Faulting application rundll32.exe, version 5.1.2600.5512, faulting
    module unknown, version 0.0.0.0, fault address 0x000d486d.

    Error - 8/7/2010 3:57:19 PM | Computer Name = ALBAWASE-F56D6E | Source = Application Error | ID = 1000
    Description = Faulting application rundll32.exe, version 5.1.2600.5512, faulting
    module unknown, version 0.0.0.0, fault address 0x001625cd.

    Error - 8/8/2010 4:28:31 AM | Computer Name = ALBAWASE-F56D6E | Source = crypt32 | ID = 131083
    Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
    with error: A required certificate is not within its validity period when verifying
    against the current system clock or the timestamp in the signed file.

    Error - 8/8/2010 4:28:31 AM | Computer Name = ALBAWASE-F56D6E | Source = crypt32 | ID = 131083
    Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
    with error: A required certificate is not within its validity period when verifying
    against the current system clock or the timestamp in the signed file.

    Error - 8/8/2010 6:07:25 AM | Computer Name = ALBAWASE-F56D6E | Source = Application Error | ID = 1000
    Description = Faulting application rundll32.exe, version 5.1.2600.5512, faulting
    module unknown, version 0.0.0.0, fault address 0x000d4225.

    [ System Events ]
    Error - 8/6/2010 12:34:42 PM | Computer Name = ALBAWASE-F56D6E | Source = Service Control Manager | ID = 7011
    Description = Timeout (30000 milliseconds) waiting for a transaction response from
    the avast! Web Scanner service.

    Error - 8/6/2010 12:35:12 PM | Computer Name = ALBAWASE-F56D6E | Source = Service Control Manager | ID = 7011
    Description = Timeout (30000 milliseconds) waiting for a transaction response from
    the avast! Mail Scanner service.

    Error - 8/6/2010 1:05:03 PM | Computer Name = ALBAWASE-F56D6E | Source = DCOM | ID = 10010
    Description = The server {AE3A66BB-85FE-49B8-BF7B-4DB4E0005091} did not register
    with DCOM within the required timeout.

    Error - 8/7/2010 3:36:10 AM | Computer Name = ALBAWASE-F56D6E | Source = UPS | ID = 2481
    Description = The UPS service is not configured correctly.

    Error - 8/7/2010 3:36:39 AM | Computer Name = ALBAWASE-F56D6E | Source = Service Control Manager | ID = 7023
    Description = The Uninterruptible Power Supply service terminated with the following
    error: %%2481

    Error - 8/7/2010 3:36:39 AM | Computer Name = ALBAWASE-F56D6E | Source = Service Control Manager | ID = 7026
    Description = The following boot-start or system-start driver(s) failed to load:
    PCIIde

    Error - 8/7/2010 9:56:50 AM | Computer Name = ALBAWASE-F56D6E | Source = UPS | ID = 2481
    Description = The UPS service is not configured correctly.

    Error - 8/7/2010 9:57:12 AM | Computer Name = ALBAWASE-F56D6E | Source = Service Control Manager | ID = 7023
    Description = The Uninterruptible Power Supply service terminated with the following
    error: %%2481

    Error - 8/8/2010 1:48:45 AM | Computer Name = ALBAWASE-F56D6E | Source = Service Control Manager | ID = 7024
    Description = The Messenger service terminated with service-specific error 2137
    (0x859).

    Error - 8/8/2010 1:48:47 AM | Computer Name = ALBAWASE-F56D6E | Source = Dhcp | ID = 1002
    Description = The IP address lease 192.168.1.101 for the Network Card with network
    address 0022750D0D16 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
    sent a DHCPNACK message).


    < End of report >
     
  19. 2010/08/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You have very little of RAM:
    For XP, at least 512MB would be much, much better.

    =================================================================

    Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it to its own folder
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.

    ==============================================================

    Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following

      Code:
      :OTL
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
      O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
      O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
      O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
      O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
      [2010/08/06 13:47:53 | 000,000,000 | ---D | C] -- C:\Program Files\RegistryTool
      [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
      [2010/08/08 09:06:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
      @Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:54D4173A
      
      
      :Services
      
      :Reg
      
      :Files
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
      
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.
    • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
     
  20. 2010/08/08
    yosef7000

    yosef7000 Inactive Thread Starter

    Joined:
    2010/08/06
    Messages:
    24
    Likes Received:
    0
    I installed Java, and ran the scans, however when I performed the quick scan it produced 2 logs, both named OTL.Txt, I don't know if this is right or did I do something wrong; anyway, I'm going to post them both here just in case, please keep in mind that I will be posting the 3 logs in separately, since I can't post anything with more than 500000 characters or so, and long posts need approval from the admin before they become visible.

    Here's the results of the (Run Fix) scan:

    All processes killed
    ========== OTL ==========
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
    Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Infodelivery\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
    Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
    File oft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab not found.
    Starting removal of ActiveX control Microsoft XML Parser for Java
    Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF .
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found.
    C:\Program Files\RegistryTool\PW folder moved successfully.
    C:\Program Files\RegistryTool folder moved successfully.
    C:\WINDOWS\SET3.tmp deleted successfully.
    C:\WINDOWS\SET4.tmp deleted successfully.
    C:\WINDOWS\SET8.tmp deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint folder moved successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:54D4173A deleted successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 9610416 bytes
    ->Temporary Internet Files folder emptied: 10598969 bytes
    ->Java cache emptied: 80486764 bytes
    ->FireFox cache emptied: 40811137 bytes
    ->Google Chrome cache emptied: 7041282 bytes
    ->Flash cache emptied: 311608 bytes

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: LocalService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 49286 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 82054 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 33251 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
    RecycleBin emptied: 5705667 bytes

    Total Files Cleaned = 148.00 mb


    [EMPTYFLASH]

    User: Administrator
    ->Flash cache emptied: 0 bytes

    User: All Users

    User: Default User

    User: LocalService

    User: NetworkService

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.9.1 log created on 08082010_232443

    Files\Folders moved on Reboot...
    File\Folder C:\Documents and Settings\Administrator\Local Settings\Temp\Perflib_Perfdata_e20.dat not found!
    File move failed. C:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.

    Registry entries deleted on Reboot...
     
  21. 2010/08/08
    yosef7000

    yosef7000 Inactive Thread Starter

    Joined:
    2010/08/06
    Messages:
    24
    Likes Received:
    0
    OTL logfile created on: 8/8/2010 11:45:17 PM - Run 2
    OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Administrator\Desktop
    Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 7.0.5730.13)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    254.00 Mb Total Physical Memory | 12.00 Mb Available Physical Memory | 5.00% Memory free
    738.00 Mb Paging File | 154.00 Mb Available in Paging File | 21.00% Paging File free
    Paging file location(s): C:\pagefile.sys 384 768 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 29.29 Gb Total Space | 6.70 Gb Free Space | 22.87% Space Free | Partition Type: NTFS
    Drive D: | 39.06 Gb Total Space | 0.11 Gb Free Space | 0.27% Space Free | Partition Type: NTFS
    Drive E: | 43.43 Gb Total Space | 1.05 Gb Free Space | 2.42% Space Free | Partition Type: NTFS
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    Drive H: | 465.65 Gb Total Space | 103.37 Gb Free Space | 22.20% Space Free | Partition Type: FAT32
    I: Drive not present or media not loaded

    Computer Name: ALBAWASE-F56D6E
    Current User Name: Administrator
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: On
    Skip Microsoft Files: On
    File Age = 90 Days
    Output = Standard
    Quick Scan

    ========== Processes (SafeList) ==========

    PRC - [2010/08/08 18:30:39 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
    PRC - [2010/08/08 09:47:01 | 000,381,304 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exe
    PRC - [2010/05/20 17:19:16 | 000,088,176 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    PRC - [2010/04/07 16:00:04 | 005,758,976 | ---- | M] (http://www.emule-project.net) -- C:\Program Files\eMule\emule.exe
    PRC - [2010/03/09 14:24:10 | 002,769,336 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    PRC - [2010/03/09 14:24:08 | 000,040,384 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    PRC - [2009/08/11 02:19:14 | 000,094,256 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpntray.exe
    PRC - [2009/08/11 02:19:08 | 000,132,144 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe
    PRC - [2009/08/06 21:58:38 | 000,331,824 | ---- | M] (AnchorFree Inc.) -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
    PRC - [2009/05/19 11:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    PRC - [2008/08/01 17:28:11 | 000,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    PRC - [2008/04/14 03:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
    PRC - [2008/04/04 03:35:41 | 000,185,896 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    PRC - [2007/09/27 20:08:34 | 001,671,168 | ---- | M] (D-Link) -- C:\Program Files\D-Link\D-Link Wireless 108G DWA-120\AirPlusCFG.exe
    PRC - [2007/09/17 11:28:26 | 001,732,608 | ---- | M] (Belkin) -- C:\Program Files\Belkin\F5D8053\Belkinwcui.exe
    PRC - [2007/08/09 10:27:52 | 000,073,728 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
    PRC - [2007/01/19 11:49:04 | 000,049,152 | ---- | M] (Wireless Service) -- C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    PRC - [2005/11/11 09:07:40 | 000,090,112 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE


    ========== Modules (SafeList) ==========

    MOD - [2010/08/08 18:30:39 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
    MOD - [2010/07/14 13:30:14 | 000,018,688 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\sahook.dll
    MOD - [2008/04/14 03:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx


    ========== Win32 Services (SafeList) ==========

    SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
    SRV - [2010/05/20 17:19:16 | 000,088,176 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
    SRV - [2010/03/09 14:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
    SRV - [2010/03/09 14:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
    SRV - [2010/03/09 14:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
    SRV - [2009/08/11 02:19:16 | 000,057,640 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Hotspot Shield\bin\HssTrayService.exe -- (HssTrayService)
    SRV - [2009/08/11 02:19:08 | 000,132,144 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe -- (HotspotShieldService)
    SRV - [2009/08/06 21:58:38 | 000,331,824 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv)
    SRV - [2009/08/05 22:48:42 | 000,704,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
    SRV - [2009/05/19 11:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
    SRV - [2008/09/09 23:01:53 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
    SRV - [2007/09/21 00:23:40 | 000,352,338 | ---- | M] (Atheros Communications, Inc.) [On_Demand | Stopped] -- C:\Program Files\D-Link\D-Link Wireless 108G DWA-120\JSWUtil\jswpsapi.exe -- (jswpsapi)
    SRV - [2007/08/09 10:27:52 | 000,073,728 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
    SRV - [2007/01/19 11:49:26 | 000,049,152 | ---- | M] (Wireless Service) [Auto | Stopped] -- C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe -- (ANIWZCSdService)
    SRV - [2005/11/14 01:06:04 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys -- (catchme)
    DRV - [2010/03/09 14:12:54 | 000,046,672 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
    DRV - [2010/03/09 14:12:33 | 000,162,640 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
    DRV - [2010/03/09 14:09:08 | 000,023,376 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
    DRV - [2010/03/09 14:08:41 | 000,100,432 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
    DRV - [2010/03/09 14:08:30 | 000,019,024 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
    DRV - [2010/03/09 14:08:15 | 000,028,880 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
    DRV - [2010/02/11 15:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
    DRV - [2009/08/05 22:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
    DRV - [2009/07/22 22:13:20 | 000,028,592 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tap0901.sys -- (tap0901)
    DRV - [2009/07/02 05:34:30 | 000,033,840 | ---- | M] (AnchorFree Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hssdrv.sys -- (HssDrv)
    DRV - [2008/01/24 00:25:32 | 000,027,136 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tapvpn.sys -- (tapvpn)
    DRV - [2007/10/07 15:01:22 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
    DRV - [2007/07/28 14:50:36 | 000,517,632 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rt2870.sys -- (rt2870)
    DRV - [2007/07/06 17:30:54 | 000,057,376 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\jswscimd.sys -- (JSWSCIMD)
    DRV - [2007/06/06 22:40:50 | 000,377,920 | ---- | M] (D-Link Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\A5AGU.sys -- (A5AGU)
    DRV - [2006/11/30 14:58:42 | 000,090,800 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se44unic.sys -- (se44unic) Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (WDM)
    DRV - [2006/11/30 14:58:34 | 000,086,432 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se44obex.sys -- (se44obex)
    DRV - [2006/11/30 14:58:32 | 000,018,704 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se44nd5.sys -- (se44nd5) Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (NDIS)
    DRV - [2006/11/30 14:58:30 | 000,088,624 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se44mgmt.sys -- (se44mgmt) Sony Ericsson Device 068 USB WMC Device Management Drivers (WDM)
    DRV - [2006/11/30 14:58:26 | 000,097,088 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se44mdm.sys -- (se44mdm)
    DRV - [2006/11/30 14:58:24 | 000,009,360 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se44mdfl.sys -- (se44mdfl)
    DRV - [2006/11/30 14:58:18 | 000,061,536 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se44bus.sys -- (se44bus) Sony Ericsson Device 068 driver (WDM)
    DRV - [2006/03/15 16:35:06 | 000,017,664 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\AWISp50.sys -- (AWISp50)
    DRV - [2005/12/11 11:55:38 | 000,028,195 | ---- | M] (Alpha Networks Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\ANIO.sys -- (ANIO)
    DRV - [2005/11/22 09:44:22 | 003,804,416 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
    DRV - [2005/06/09 11:08:40 | 000,018,004 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\slnt.sys -- (slnt)
    DRV - [2004/06/17 10:05:46 | 000,136,832 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pfc027.sys -- (SoC PC-Camera Service)
    DRV - [2001/08/17 13:49:10 | 000,026,624 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\irstusb.sys -- (STIrUsb)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr8/*http://www.yahoo.com/ext/search/search.html

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    IE - HKCU\..\URLSearchHook: {b7f907ee-0a1b-43b8-a611-b429a184ad6b} - C:\Program Files\torrents.to\tbtor1.dll (Conduit Ltd.)
    IE - HKCU\..\URLSearchHook: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot1.dll (Conduit Ltd.)
    IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local

    ========== FireFox ==========

    FF - prefs.js..browser.search.selectedEngine: "Wikipedia (en) "
    FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/ "
    FF - prefs.js..extensions.enabledItems: piclens@cooliris.com:1.12.0.36949
    FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7.4
    FF - prefs.js..extensions.enabledItems: facepad@lazyrussian.com:0.7.3
    FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.1.26
    FF - prefs.js..extensions.enabledItems: {c95a4e8e-816d-4655-8c79-d736da1adb6d}:2.5.6.0
    FF - prefs.js..extensions.enabledItems: {c33c5b47-69c8-45a4-a5e0-af85bbe628dd}:1.6.1.3
    FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
    FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.2
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21

    FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/04/04 03:36:45 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/08/08 12:12:36 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/26 18:52:48 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/08 23:16:59 | 000,000,000 | ---D | M]

    [2009/01/23 14:38:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
    [2010/08/08 23:18:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions
    [2010/06/21 08:38:05 | 000,000,000 | ---D | M] (FlashGot) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
    [2010/06/21 08:37:36 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    [2009/11/12 08:05:35 | 000,000,000 | ---D | M] (torrents.to Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{b7f907ee-0a1b-43b8-a611-b429a184ad6b}
    [2010/07/22 20:17:00 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
    [2010/06/21 08:37:57 | 000,000,000 | ---D | M] (Interclue) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{c33c5b47-69c8-45a4-a5e0-af85bbe628dd}
    [2010/06/21 08:37:39 | 000,000,000 | ---D | M] (Hotspot Shield Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}
    [2010/06/21 08:38:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\facepad@lazyrussian.com
    [2010/06/21 08:37:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\extensions\piclens@cooliris.com
    [2009/01/15 09:37:48 | 000,000,884 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\searchplugins\conduit.xml
    [2009/04/04 15:28:16 | 000,002,042 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\searchplugins\facebook.xml
    [2010/08/04 15:43:33 | 000,004,859 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\searchplugins\isohunt---bt-search.xml
    [2009/11/24 15:38:46 | 000,001,597 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\searchplugins\the-pirate-bay.xml
    [2009/08/25 10:27:55 | 000,000,945 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\njex9ys9.default\searchplugins\youtube-video-search.xml
    [2010/08/08 23:19:00 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
    [2010/08/08 23:17:05 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
    [2010/08/08 23:16:34 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
    [2010/06/10 07:40:12 | 000,002,024 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\McSiteAdvisor.xml

    O1 HOSTS File: ([2010/08/08 09:36:52 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
    O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
    O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
    O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
    O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
    O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O2 - BHO: (toto gateway Toolbar) - {b7f907ee-0a1b-43b8-a611-b429a184ad6b} - C:\Program Files\torrents.to\tbtor1.dll (Conduit Ltd.)
    O2 - BHO: (Hotspot Shield Toolbar) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot1.dll (Conduit Ltd.)
    O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll ()
    O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
    O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (toto gateway Toolbar) - {b7f907ee-0a1b-43b8-a611-b429a184ad6b} - C:\Program Files\torrents.to\tbtor1.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (Hotspot Shield Toolbar) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot1.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (Yahoo! ¤u¨م¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O3 - HKCU\..\Toolbar\ShellBrowser: (toto gateway Toolbar) - {B7F907EE-0A1B-43B8-A611-B429A184AD6B} - C:\Program Files\torrents.to\tbtor1.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\ShellBrowser: (Hotspot Shield Toolbar) - {C95A4E8E-816D-4655-8C79-D736DA1ADB6D} - C:\Program Files\Hotspot_Shield\tbHot1.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (toto gateway Toolbar) - {B7F907EE-0A1B-43B8-A611-B429A184AD6B} - C:\Program Files\torrents.to\tbtor1.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Hotspot Shield Toolbar) - {C95A4E8E-816D-4655-8C79-D736DA1ADB6D} - C:\Program Files\Hotspot_Shield\tbHot1.dll (Conduit Ltd.)
    O4 - HKLM..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Wireless Service)
    O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
    O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
    O4 - HKLM..\Run: [D-Link D-Link Wireless 108G DWA-120] C:\Program Files\D-Link\D-Link Wireless 108G DWA-120\AirPlusCFG.exe (D-Link)
    O4 - HKLM..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe (Google)
    O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
    O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
    O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
    O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
    O4 - HKCU..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe (http://www.emule-project.net)
    O4 - HKCU..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe (FreeDownloadManager.ORG)
    O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
    O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
    O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
    O4 - HKCU..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Belkin F5D8053 N Wireless USB Adapter Utility.lnk = C:\Program Files\Belkin\F5D8053\Belkinwcui.exe (Belkin)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TotalMedia Backup Monitor.lnk = C:\Program Files\ArcSoft\TotalMedia Backup\uBBMonitor.exe (ArcSoft, Inc.)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
    O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
    O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
    O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
    O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
    O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
    O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.17.233.49 193.188.97.193
    O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
    O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
    O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2007/10/07 10:11:44 | 000,000,000 | -HS- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    ========== Files/Folders - Created Within 90 Days ==========

    [2010/08/08 23:24:43 | 000,000,000 | ---D | C] -- C:\_OTL
    [2010/08/08 23:22:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\New Folder
    [2010/08/08 23:17:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
    [2010/08/08 18:27:01 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
    [2010/08/08 18:18:51 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator\Recent
    [2010/08/08 13:04:15 | 000,000,000 | -HSD | C] -- C:\RECYCLER
    [2010/08/07 19:17:37 | 000,000,000 | RHSD | C] -- C:\cmdcons
    [2010/08/07 19:07:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2010/08/07 09:53:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
    [2010/08/07 09:52:28 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/08/07 09:52:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    [2010/08/07 09:52:23 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2010/08/07 09:52:22 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2010/08/06 13:49:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\RegistryTool
    [2010/08/06 13:21:54 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
    [2010/07/10 13:55:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\pcsx2
    [2010/07/10 13:54:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\pcsx2
    [2010/07/10 12:01:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\Logs
    [2010/07/10 11:58:54 | 000,000,000 | ---D | C] -- C:\Program Files\PCSX2 0.9.7
    [2010/07/09 11:46:37 | 000,000,000 | ---D | C] -- C:\New Folder

    ========== Files - Modified Within 90 Days ==========

    [2010/08/08 23:30:37 | 000,000,007 | ---- | M] () -- C:\WINDOWS\System32\ANIWZCSUSERNAME
    [2010/08/08 23:29:39 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2010/08/08 23:29:16 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
    [2010/08/08 23:28:47 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2010/08/08 23:27:52 | 017,039,360 | -H-- | M] () -- C:\Documents and Settings\Administrator\NTUSER.DAT
    [2010/08/08 23:27:52 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Administrator\ntuser.ini
    [2010/08/08 23:21:02 | 000,156,063 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\JavaRa.zip
    [2010/08/08 20:30:57 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
    [2010/08/08 20:30:17 | 000,062,464 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010/08/08 19:46:03 | 000,028,790 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\[isoHunt] Gossip Girl - Season 1.torrent
    [2010/08/08 18:30:39 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
    [2010/08/08 18:19:02 | 007,527,166 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
    [2010/08/08 09:37:14 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
    [2010/08/08 09:36:52 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
    [2010/08/08 00:19:28 | 000,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
    [2010/08/08 00:19:27 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
    [2010/08/07 19:17:43 | 000,000,281 | RHS- | M] () -- C:\boot.ini
    [2010/08/07 11:05:44 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [2010/08/07 09:52:33 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/08/06 13:28:34 | 000,000,967 | ---- | M] () -- C:\WINDOWS\win.ini
    [2010/08/06 13:28:34 | 000,000,211 | ---- | M] () -- C:\Boot.bak
    [2010/08/06 11:57:51 | 000,001,891 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2010/08/06 07:57:26 | 000,849,315 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\nw_uxpatcher.zip
    [2010/08/06 07:27:13 | 000,002,560 | ---- | M] () -- C:\WINDOWS\_MSRSTRT.EXE
    [2010/07/17 23:32:42 | 160,794,916 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\RE-1.part5.rar
    [2010/07/16 13:04:37 | 033,554,432 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Crash Bandicoot 3 - Warped [SCUS_942.44] psx - psone - by Sedan75.7z.001
    [2010/07/10 09:04:48 | 000,000,517 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\ePSXe.lnk
    [2010/06/23 18:13:29 | 000,489,196 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
    [2010/06/23 18:13:29 | 000,432,806 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2010/06/23 18:13:29 | 000,067,762 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2010/06/11 23:00:20 | 001,633,944 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2010/05/22 07:44:14 | 000,000,630 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\µTorrent.lnk

    ========== Files Created - No Company Name ==========

    [2010/08/08 23:20:51 | 000,156,063 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\JavaRa.zip
    [2010/08/08 19:45:41 | 000,028,790 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\[isoHunt] Gossip Girl - Season 1.torrent
    [2010/08/08 00:19:28 | 000,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
    [2010/08/08 00:19:27 | 000,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
    [2010/08/07 19:17:43 | 000,000,211 | ---- | C] () -- C:\Boot.bak
    [2010/08/07 19:17:39 | 000,260,272 | ---- | C] () -- C:\cmldr
    [2010/08/07 09:52:33 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/08/06 07:56:29 | 000,849,315 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\nw_uxpatcher.zip
    [2010/08/06 07:27:13 | 000,002,560 | ---- | C] () -- C:\WINDOWS\_MSRSTRT.EXE
    [2010/07/17 18:09:59 | 160,794,916 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\RE-1.part5.rar
    [2010/07/16 11:50:33 | 033,554,432 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Crash Bandicoot 3 - Warped [SCUS_942.44] psx - psone - by Sedan75.7z.001
    [2010/07/09 18:13:56 | 000,000,517 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\ePSXe.lnk
    [2009/09/03 20:10:04 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\WlanApp.dll
    [2009/09/03 20:10:03 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\JJAKEn.dll
    [2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
    [2009/05/22 10:51:44 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll
    [2009/04/01 12:46:57 | 000,000,962 | ---- | C] () -- C:\WINDOWS\System32\WLAN.INI
    [2008/08/24 16:52:08 | 000,000,021 | ---- | C] () -- C:\WINDOWS\atid.ini
    [2008/06/20 21:30:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iSnooker.INI
    [2008/06/12 07:45:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\WB.ini
    [2008/04/06 02:16:03 | 000,000,507 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
    [2008/02/02 00:00:06 | 000,001,555 | ---- | C] () -- C:\WINDOWS\ata live update.ini
    [2008/01/12 11:00:17 | 000,000,109 | ---- | C] () -- C:\WINDOWS\SYMGAMES.INI
    [2007/11/05 20:30:54 | 000,000,047 | ---- | C] () -- C:\WINDOWS\entpack.ini
    [2007/11/05 15:41:19 | 000,000,070 | ---- | C] () -- C:\WINDOWS\GECKOS.INI
    [2007/10/08 16:05:39 | 000,001,682 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
    [2007/10/07 22:35:44 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
    [2007/10/07 15:19:18 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2007/10/07 14:57:05 | 000,018,004 | R--- | C] () -- C:\WINDOWS\System32\drivers\slnt.sys
    [2007/10/07 14:56:11 | 000,157,184 | R--- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
    [2007/10/07 14:55:20 | 000,002,778 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
    [2007/10/07 14:55:18 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
    [2006/07/13 06:36:36 | 001,167,360 | ---- | C] () -- C:\WINDOWS\System32\acAuth.dll
    [2006/05/16 09:25:43 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\hpzids01.dll
    [2004/06/17 10:05:46 | 000,136,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\pfc027.sys
    [2004/01/08 10:30:22 | 000,011,170 | ---- | C] () -- C:\WINDOWS\System32\PA207Usd.dll
    [2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
    [2002/10/16 01:54:04 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
    [2002/03/21 15:39:02 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\UNACEV2.DLL

    ========== LOP Check ==========

    [2007/10/08 15:49:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\ACD Systems
    [2009/01/10 00:32:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Any Video Converter
    [2007/12/30 08:44:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Azureus
    [2010/08/08 23:33:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Free Download Manager
    [2008/09/26 07:09:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\JCreator
    [2008/01/12 01:08:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\LimeWire
    [2010/08/06 14:28:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\RegistryTool
    [2008/06/01 13:09:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Software Informer
    [2009/03/26 20:29:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Teleca
    [2010/08/09 00:01:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\uTorrent
    [2008/08/24 16:51:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore
    [2010/03/27 17:09:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
    [2007/12/30 08:07:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
    [2008/06/01 13:08:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
    [2008/09/26 07:09:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\JCreator
    [2008/12/30 14:11:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
    [2007/10/07 15:02:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip

    ========== Purity Check ==========


    < End of report >
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.