1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Machine has slowed to near a stop!

Discussion in 'Malware and Virus Removal Archive' started by Ski52, 2009/10/23.

  1. 2009/10/23
    Ski52

    Ski52 Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    176
    Likes Received:
    1
    [Resolved] Machine has slowed to near a stop!

    Normally I fix these kind of problems for neighbors & friends - I get a lot of my info from here, and have been doing so for a number of years.

    My turn

    System - main - 3.4 P4D 2G PC5300 667 Asus P5GC-MX/1333 single 160G SATA
    'Quasi-Server' - 2.5 P4 512M DDR Intel 865 - 1 X 100G; 2 X RAID1 arrays - 1=120G IDE; 2=80G SATA
    Both machines have XP Pro SP3
    Laptop - Toshiba - Win7 No Problems on the network

    Yesterday or so, everything slowed to almost a stop. To burn a DVD that normally takes 6 - 8 minutes - 93 minutes, but the DVD was OK. Start up of machine - seems normal til you log in with password - then it takes 2 - 3 minutes and long after the desktop is up, the splash tune plays. System tray sometimes shows all the appropriate icons - most times not. Missing any number - there are only 5. 2 Avast, 2 Volume & 1 USB (have 5 printers on a USB hub)
    The 'server' is slow, but it only has 512 memory.
    I have run numerous Avast virus scans; Trojan Remover; defrag all disks, and numerous registry cleaners - Advanced Uninstaller, Win ASO & System Cleaner 5 - all to no avail.....

    Am lost on this one, considering a full fdisk & format - last resort - any help greatly appreciated

    As I said - 'my turn in the bucket...' ;)

    TIA
     
  2. 2009/10/24
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Read this post, then post the requested log(s).
     

  3. to hide this advert.

  4. 2009/10/24
    Ski52

    Ski52 Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    176
    Likes Received:
    1
    Thanx Broni for the response. Sorry it's taken me so long to reply - weekend chores....

    Per request:

    DDS (Ver_09-10-24.03) - NTFSx86
    Run by Ski at 18:17:43.42 on Sat 10/24/2009
    Internet Explorer: 8.0.6001.18702

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://my.yahoo.com/
    BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
    TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    mRun: [RTHDCPL] RTHDCPL.EXE
    mRun: [SkyTel] SkyTel.EXE
    mRun: [Alcmtr] ALCMTR.EXE
    mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
    IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1245381457687
    TCP: {F1E2F992-2041-4A33-9CFD-C3AD2A6EAE1D} = 192.168.2.1,192.168.2.1
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe "

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\ski\applic~1\mozilla\firefox\profiles\4bz8esua.default\
    FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/|http://mrcs.phpbb3now.com/index.php...nfile.org/index.php|http://www.reflexive.com/
    FF - plugin: c:\documents and settings\ski\application data\mozilla\firefox\profiles\4bz8esua.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll
    FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

    ============= SERVICES / DRIVERS ===============


    =============== Created Last 30 ================

    2009-10-23 22:31:30 1116 ---ha-r- c:\windows\EPMBatch.ept
    2009-10-23 03:24:35 0 d-----w- c:\windows\system32\wbem\Repository
    2009-10-23 03:17:22 0 d-----w- C:\Tools
    2009-10-19 18:02:06 0 d-----w- c:\docume~1\ski\applic~1\Awem
    2009-10-17 22:38:09 453456 ----a-w- c:\windows\system32\d3dx10_41.dll
    2009-10-17 22:38:09 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
    2009-10-17 22:38:09 1846632 ----a-w- c:\windows\system32\D3DCompiler_41.dll
    2009-10-17 22:38:08 69448 ----a-w- c:\windows\system32\XAPOFX1_3.dll
    2009-10-17 22:38:08 517448 ----a-w- c:\windows\system32\XAudio2_4.dll
    2009-10-17 22:38:08 235352 ----a-w- c:\windows\system32\xactengine3_4.dll
    2009-10-17 22:38:07 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll
    2009-10-17 00:28:18 0 d-----w- c:\docume~1\ski\applic~1\VampireSaga
    2009-10-16 20:29:21 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
    2009-10-16 20:04:56 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
    2009-10-16 20:04:56 7396 ----a-w- c:\windows\system32\drivers\pctcore.cat
    2009-10-16 20:04:56 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
    2009-10-16 20:04:49 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
    2009-10-16 20:04:43 0 d-----w- c:\docume~1\ski\applic~1\PC Tools
    2009-10-16 20:04:43 0 d-----w- c:\docume~1\alluse~1\applic~1\PC Tools
    2009-10-16 19:48:57 0 d-----w- c:\program files\SpywareBlaster
    2009-10-16 19:30:42 0 d-----w- c:\program files\common files\PC Tools
    2009-10-16 19:30:36 0 d-----w- c:\program files\Spyware Doctor
    2009-10-16 19:24:56 0 d-----w- c:\program files\Trend Micro
    2009-10-16 17:59:13 0 d-----w- c:\docume~1\ski\applic~1\GTM_Bodie
    2009-10-16 15:44:05 0 d-----w- c:\docume~1\ski\applic~1\Pointstone
    2009-10-15 16:12:30 68608 --sha-r- c:\windows\system32\zgzwo.dll
    2009-10-14 20:52:07 0 d-----w- c:\program files\DVD Shrink
    2009-10-12 22:56:04 0 d-----w- c:\program files\DirPrn
    2009-10-12 22:55:55 249856 ------w- c:\windows\Setup1.exe
    2009-10-12 22:55:54 73216 ----a-w- c:\windows\ST6UNST.EXE
    2009-10-12 22:00:50 0 d-----w- c:\docume~1\ski\applic~1\GARMIN
    2009-10-12 22:00:41 0 d-----w- c:\program files\Garmin GPS Plugin
    2009-10-12 21:54:57 0 d-----w- c:\program files\Garmin
    2009-10-12 21:54:07 0 d-----w- C:\Garmin
    2009-10-11 14:53:25 0 d-----w- c:\docume~1\ski\applic~1\AMPSoft
    2009-10-11 14:53:09 0 d-----w- c:\program files\AMP Font Viewer
    2009-10-11 14:03:28 0 d-----w- c:\program files\SystemRequirementsLab
    2009-10-11 13:57:39 0 d-----w- c:\docume~1\ski\applic~1\Blitware
    2009-10-10 20:42:19 0 d-----w- c:\documents and settings\ski\EurekaLog
    2009-10-10 18:30:45 0 d-----w- c:\docume~1\alluse~1\applic~1\GameHouse
    2009-10-10 18:18:39 0 d-----w- c:\docume~1\alluse~1\applic~1\NVIDIA Corporation
    2009-10-10 18:18:31 0 d-----w- c:\program files\NVIDIA Corporation
    2009-10-09 00:39:43 0 d-----w- c:\docume~1\ski\applic~1\Movie Label
    2009-10-09 00:38:48 0 d-----w- c:\program files\Movie Label 2010
    2009-10-09 00:11:26 0 d-----w- c:\docume~1\ski\applic~1\Frostbow
    2009-10-09 00:11:13 0 d-----w- c:\program files\Frostbow
    2009-10-08 23:57:42 0 d-----w- c:\documents and settings\ski\WINDOWS
    2009-10-08 04:11:28 0 d-----w- c:\docume~1\ski\applic~1\Total Eclipse
    2009-10-08 03:31:29 0 d-----w- c:\docume~1\alluse~1\applic~1\AdventureChronicles1
    2009-10-04 01:55:45 0 d-----w- c:\docume~1\alluse~1\applic~1\NeptunesAdve
    2009-10-03 18:39:52 0 d-----w- c:\docume~1\ski\applic~1\HdO Adventure
    2009-10-02 15:05:42 0 d-----w- c:\program files\Pointstone
    2009-10-02 15:05:42 0 d-----w- c:\program files\common files\Pointstone
    2009-09-30 20:20:48 0 d-----w- c:\docume~1\ski\applic~1\Merscom
    2009-09-30 20:20:48 0 d-----w- c:\docume~1\alluse~1\applic~1\Merscom
    2009-09-29 07:24:42 0 d-----w- c:\program files\VideoLAN
    2009-09-28 20:10:42 902432 ----a-w- c:\windows\system32\drivers\tdrpm251.sys

    ==================== Find3M ====================

    2009-09-28 20:10:41 570016 ----a-w- c:\windows\system32\drivers\timntr.sys
    2009-09-27 20:12:22 490088 ----a-w- c:\windows\system32\nvudisp.exe
    2009-09-26 21:25:05 73312 ----a-w- c:\windows\system32\drivers\adfs.sys
    2009-09-24 13:24:18 490088 ----a-w- c:\windows\system32\NVUNINST.EXE
    2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
    2009-09-10 00:27:40 1880856 ----a-w- c:\windows\system32\AutoPartNt.exe
    2009-09-04 21:03:36 58880 ----a-w- c:\windows\system32\msasn1.dll
    2009-08-29 08:08:21 916480 ----a-w- c:\windows\system32\wininet.dll
    2009-08-26 08:00:21 247326 ----a-w- c:\windows\system32\strmdll.dll
    2009-08-20 03:50:31 22872 ----a-r- c:\windows\system32\AdobePDFUI.dll
    2009-08-20 03:50:11 46928 ----a-r- c:\windows\system32\AdobePDF.dll
    2009-08-18 15:31:41 6656 ----a-w- c:\windows\system32\lpcio.dll
    2009-08-18 03:33:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
    2009-08-06 23:23:46 274288 ----a-w- c:\windows\system32\mucltui.dll
    2009-08-06 23:23:46 215920 ----a-w- c:\windows\system32\muweb.dll
    2009-08-06 03:51:59 90112 ----a-w- c:\windows\system32\agsaami.dll
    2009-08-06 03:51:59 610304 ----a-w- c:\windows\system32\agsaamg.dll
    2009-08-06 03:51:59 372736 ----a-w- c:\windows\system32\agsaamc.dll
    2009-08-06 03:51:59 2535424 ----a-w- c:\windows\system32\agsaamj.dll
    2009-08-05 09:01:48 204800 ----a-w- c:\windows\system32\mswebdvd.dll
    2009-08-04 15:13:08 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe
    2009-08-04 14:20:09 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe

    ============= FINISH: 18:17:59.76 ===============
     
  5. 2009/10/24
    Ski52

    Ski52 Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    176
    Likes Received:
    1
    Second file:

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-10-24.03)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 6/18/2009 10:21:05 PM
    System Uptime: 10/23/2009 6:47:22 PM (24 hours ago)

    Motherboard: ASUSTeK Computer INC. | | P5GC-MX/1333
    Processor: Intel(R) Pentium(R) D CPU 3.40GHz | LGA 775 | 3570/211mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 52 GiB total, 24.596 GiB free.
    D: is FIXED (NTFS) - 45 GiB total, 24.948 GiB free.
    E: is FIXED (NTFS) - 21 GiB total, 13.634 GiB free.
    F: is FIXED (NTFS) - 21 GiB total, 10.744 GiB free.
    G: is FIXED (NTFS) - 12 GiB total, 11.653 GiB free.
    I: is Removable
    J: is Removable
    K: is Removable
    L: is Removable
    R: is CDROM ()
    W: is CDROM ()

    ==== Disabled Device Manager Items =============

    Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
    Description: Microsoft® Keyboard with Fingerprint Reader
    Device ID: USB\VID_045E&PID_00BB&MI_02\7&7F9206E&0&0002
    Manufacturer:
    Name: Microsoft® Keyboard with Fingerprint Reader
    PNP Device ID: USB\VID_045E&PID_00BB&MI_02\7&7F9206E&0&0002
    Service:

    Class GUID: {4D36E96B-E325-11CE-BFC1-08002BE10318}
    Description: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
    Device ID: ACPI\PNP0303\4&2C575ACB&0
    Manufacturer: (Standard keyboards)
    Name: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
    PNP Device ID: ACPI\PNP0303\4&2C575ACB&0
    Service: i8042prt

    Class GUID: {6BDD1FC6-810F-11D0-BEC7-08002BE2092F}
    Description: Officejet J6400 series
    Device ID: ROOT\IMAGE\0000
    Manufacturer: HP
    Name: HP Officejet J6400
    PNP Device ID: ROOT\IMAGE\0000
    Service: StillCam

    Class GUID: {4D36E971-E325-11CE-BFC1-08002BE10318}
    Description: Officejet J6400 series
    Device ID: ROOT\MULTIFUNCTION\0000
    Manufacturer: HP
    Name: Officejet J6400 series
    PNP Device ID: ROOT\MULTIFUNCTION\0000
    Service:

    Class GUID: {4D36E979-E325-11CE-BFC1-08002BE10318}
    Description: Officejet J6400 series
    Device ID: ROOT\PRINTER\0000
    Manufacturer: HP
    Name: Officejet J6400 series
    PNP Device ID: ROOT\PRINTER\0000
    Service:

    ==== System Restore Points ===================

    RP1: 10/16/2009 11:36:51 AM - System Checkpoint
    RP2: 10/17/2009 11:51:36 AM - System Checkpoint
    RP3: 10/17/2009 6:16:11 PM - Installed Wolfenstein
    RP4: 10/17/2009 7:05:09 PM - Removed Wolfenstein
    RP5: 10/18/2009 7:18:52 PM - System Checkpoint
    RP6: 10/19/2009 7:51:49 PM - System Checkpoint
    RP7: 10/20/2009 8:12:39 PM - System Checkpoint
    RP8: 10/21/2009 8:13:38 PM - System Checkpoint
    RP9: 10/22/2009 8:53:48 PM - System Checkpoint
    RP10: 10/22/2009 10:38:25 PM - Removed Acronis*True*Image*Home
    RP11: 10/22/2009 11:21:18 PM - Restore Operation
    RP12: 10/22/2009 11:43:07 PM - Removed Acronis*True*Image*Home
    RP13: 10/23/2009 11:55:21 PM - System Checkpoint

    ==== Installed Programs ======================

    µTorrent
    32 Bit HP CIO Components Installer
    6400_Help
    Acrobat.com
    Adobe Acrobat 9 Pro - English, Français, Deutsch
    Adobe After Effects CS4
    Adobe After Effects CS4 Presets
    Adobe After Effects CS4 Third Party Content
    Adobe AIR
    Adobe Anchor Service CS4
    Adobe Asset Services CS4
    Adobe Bridge CS4
    Adobe CMaps CS4
    Adobe Color - Photoshop Specific CS4
    Adobe Color EU Recommended Settings CS4
    Adobe Color JA Extra Settings CS4
    Adobe Color NA Extra Settings CS4
    Adobe Color Video Profiles AE CS4
    Adobe Color Video Profiles CS CS4
    Adobe Contribute CS4
    Adobe Creative Suite 4 Master Collection
    Adobe CS4 American English Speech Analysis Models
    Adobe CSI CS4
    Adobe Default Language CS4
    Adobe Device Central CS4
    Adobe Download Manager
    Adobe Dreamweaver CS4
    Adobe Drive CS4
    Adobe Dynamiclink Support
    Adobe Encore CS4
    Adobe Encore CS4 Codecs
    Adobe ExtendScript Toolkit CS4
    Adobe Extension Manager CS4
    Adobe Fireworks CS4
    Adobe Flash CS4
    Adobe Flash CS4 Extension - Flash Lite STI en
    Adobe Flash CS4 STI-en
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Fonts All
    Adobe Illustrator CS4
    Adobe InDesign CS4
    Adobe InDesign CS4 Application Feature Set Files (Roman)
    Adobe InDesign CS4 Common Base Files
    Adobe InDesign CS4 Icon Handler
    Adobe Linguistics CS4
    Adobe Media Encoder CS4
    Adobe Media Encoder CS4 Additional Exporter
    Adobe Media Encoder CS4 Dolby
    Adobe Media Encoder CS4 Exporter
    Adobe Media Encoder CS4 Importer
    Adobe Media Player
    Adobe MotionPicture Color Files CS4
    Adobe OnLocation CS4
    Adobe Output Module
    Adobe PDF Library Files CS4
    Adobe Photoshop CS4
    Adobe Photoshop CS4 Support
    Adobe Premiere Pro CS4
    Adobe Premiere Pro CS4 Functional Content
    Adobe Premiere Pro CS4 Third Party Content
    Adobe Reader 9.2
    Adobe Search for Help
    Adobe Service Manager Extension
    Adobe Setup
    Adobe SGM CS4
    Adobe SING CS4
    Adobe Soundbooth CS4
    Adobe Soundbooth CS4 Codecs
    Adobe Type Support CS4
    Adobe Update Manager CS4
    Adobe Version Cue CS4 Server
    Adobe WinSoft Linguistics Plugin
    Adobe XMP Panels CS4
    AdobeColorCommonSetCMYK
    AdobeColorCommonSetRGB
    Advanced Uninstaller PRO 2006 - version 7
    Adventure Chronicles
    AMP Font Viewer
    Ancient Mosaic
    Atheros Communications Inc.(R) L2 Fast Ethernet Driver
    Atheros Ethernet Utility
    avast! Antivirus
    Avery Wizard 3.1
    Big City Adventure San Francisco
    Big City Adventure Sydney Australia
    bpd_scan
    BPDSoftware
    BPDSoftware_Ini
    BufferChm
    Campfire Legends The Hookman
    Canon Camera Access Library
    Canon Camera Support Core Library
    Canon Camera WIA Driver
    Canon Camera WIA Driver 6.2.5
    Canon MOV Decoder
    Canon MOV Encoder
    Canon MovieEdit Task for ZoomBrowser EX
    Canon PhotoRecord
    Canon RAW Image Task for ZoomBrowser EX
    Canon Utilities CameraWindow
    Canon Utilities CameraWindow DC
    Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
    Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
    Canon Utilities MyCamera
    Canon Utilities MyCamera DC
    Canon Utilities PhotoStitch
    Canon Utilities RemoteCapture DC
    Canon Utilities RemoteCapture Task for ZoomBrowser EX
    Canon Utilities ZoomBrowser EX
    Canon ZoomBrowser EX Memory Card Utility
    Chuzzle Deluxe
    ClassicPro© v1.12
    Connect
    CPUID HWMonitor Pro 1.05
    Critical Update for Windows Media Player 11 (KB959772)
    CustomerResearchQFolder
    Department 42 The Mystery of the Nine
    Destination Component
    Detective Stories Hollywood
    DeviceDiscovery
    DeviceManagementQFolder
    DISC TITLE PRINTER
    DocMgr
    DocProc
    DocProcQFolder
    Dream Vacation Solitaire
    DVD Shrink 3.2
    EASEUS Partition Master 4.0 Home Edition
    eSupportQFolder
    Fax
    FLV Player 2.0 (build 25)
    Frostbow Home Inventory 5 Lite
    Garmin Communicator Plugin
    Garmin USB Drivers
    Garmin WebUpdater
    Gem Ball
    Ghost Town Mysteries - Bodie
    Google Earth
    Google Update Helper
    GPBaseService
    HdO Adventure Hollywood
    HdO Adventure Secrets of the Vatican
    Hidden Expedition Titanic
    Hidden Mysteries - White House
    High Definition Audio Driver Package - KB888111
    HijackThis 2.0.2
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    HP Customer Participation Program 10.0
    HP Document Manager 1.0
    HP Imaging Device Functions 10.0
    HP Officejet J6400 Series
    HP Photosmart Essential 2.5
    HP Smart Web Printing
    HP Solution Center 10.0
    HP Update
    HPProductAssistant
    HPSSupply
    HyperMediaCenter
    Insider Tales The Stolen Venus
    J6400
    Jewel Quest Mysteries 2 Trail of the Midnight Heart
    Karen's Directory Printer
    kuler
    KWorld TV Tuner Card Utilities
    KWorld TV713X BDA Driver
    LaserJet 1018
    Legend of Crystal Valley 1.00
    LightScribe Applications
    LightScribe Diagnostic Utility
    LightScribe System Software
    LightScribe Template Designs - Bonus Pack 1
    LightScribe Template Designs - Seasonal Pack 1
    LightScribe Template Labeler
    Little Shop - World Traveler
    Lost Realms Legacy of the Sun Princess
    Luxor
    Luxor Amun Rising
    MailWasher 2.0.19 beta
    MarketResearch
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB953297)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Access MUI (English) 2007
    Microsoft Office Access Setup Metadata MUI (English) 2007
    Microsoft Office Enterprise 2007
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Groove MUI (English) 2007
    Microsoft Office Groove Setup Metadata MUI (English) 2007
    Microsoft Office InfoPath MUI (English) 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office Outlook MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Publisher MUI (English) 2007
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Silverlight
    Microsoft Software Update for Web Folders (English) 12
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Mosaic Tomb of Mystery
    Movie Label 2010 v5.1.1
    Movie Label XML Import Utility v1.6.2
    Mozilla Firefox (3.5.3)
    MSXML 4.0 SP2 (KB954430)
    MSXML 6.0 Parser
    Mysterious City Vegas
    Mystery Age - The Imperial Staff
    Nat Geo Adventure Lost City of Z
    Neptunes Secret
    Nero 7 Premium
    neroxml
    NetDeviceManager
    NVIDIA Drivers
    NVIDIA PhysX
    OCR Software by I.R.I.S. 10.0
    OJOsoft MP4 Converter
    Paint Shop Pro 7
    Password Safe
    PC Probe II
    PDF Settings CS4
    Photoshop Camera Raw
    Pixel Bender Toolkit
    Popcap Game Collection
    Power AMR MP3 WAV WMA M4A AC3 Audio Converter 1.6
    Princess Isabella A Witch's Curse 1.00
    Private Eye Greatest Unsolved Mysteries
    ProductContext
    PSSWCORE
    RAW Image Task 1.1
    RealPlayer
    Realtek High Definition Audio Driver
    Righteous Kill Revenge of the Poet Killer
    Romance of Rome
    Router Screen Capture
    Scan
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB969679)
    Security Update for Microsoft Office Excel 2007 (KB969682)
    Security Update for Microsoft Office Outlook 2007 (KB972363)
    Security Update for Microsoft Office PowerPoint 2007 (KB957789)
    Security Update for Microsoft Office Publisher 2007 (KB969693)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB969613)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Security Update for Microsoft Office Word 2007 (KB969604)
    Security Update for Windows Internet Explorer 8 (KB969897)
    Security Update for Windows Internet Explorer 8 (KB971961)
    Security Update for Windows Internet Explorer 8 (KB972260)
    Security Update for Windows Internet Explorer 8 (KB974455)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Shattera2
    Shop for HP Supplies
    Simple Port Forwarding
    SIW version 2009-07-28
    Slingo Mystery Whos Gold
    SmartWebPrintingOC
    SolutionCenter
    Sony Noise Reduction Plug-In 2.0h
    Sound Forge Pro 10.0
    Spelling Dictionaries Support For Adobe Reader 9
    Spyware Doctor 6.1
    SpywareBlaster 4.2
    Status
    Suite Shared Configuration CS4
    System Cleaner 5
    System Requirements Lab
    The Clockwork Man
    The Magicians Handbook II BlackLore
    The Mystery of the Mary Celeste
    Toolbox
    Torrent Harvester
    TrayApp
    Trojan Remover 6.8.1
    Tweak UI
    UnloadSupport
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Outlook 2007 Junk Email Filter (KB974810)
    Update for Windows Internet Explorer 8 (KB971180)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB973815)
    VideoToolkit01
    VLC media player 1.0.2
    WebFldrs XP
    WebReg
    Winamp
    WinASO Registry Optimizer 4.5.1
    WinDirStat 1.1.2
    Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
    Windows Internet Explorer 8
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3
    WinImage
    WinRAR archiver

    ==== Event Viewer Messages From Past Week ========

    10/22/2009 10:55:08 PM, error: Service Control Manager [7000] - The Application Layer Gateway Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    10/22/2009 10:54:39 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Application Layer Gateway Service service to connect.
    10/22/2009 10:54:06 PM, error: DCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {D851F103-8C90-4321-AFF0-58BA5BD421C2} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18). This security permission can be modified using the Component Services administrative tool.
    10/21/2009 6:24:01 PM, error: Service Control Manager [7034] - The PC Tools Security Service service terminated unexpectedly. It has done this 1 time(s).
    10/21/2009 12:50:08 PM, error: atapi [11] - The driver detected a controller error on \Device\Ide\IdePort2.
    10/21/2009 12:47:13 PM, error: atapi [9] - The device, \Device\Ide\IdePort2, did not respond within the timeout period.
    10/19/2009 1:10:14 PM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery Service service hung on starting.
    10/19/2009 1:05:59 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments " " in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    10/19/2009 1:03:36 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD AsIO aswSP aswTdi Fips i8042prt intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip Tcpip6
    10/19/2009 1:03:36 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PC Tools Security Service service to connect.
    10/19/2009 1:03:36 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
    10/19/2009 1:03:36 PM, error: Service Control Manager [7001] - The IPv6 Helper Service service depends on the Microsoft IPv6 Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    10/19/2009 1:03:36 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
    10/19/2009 1:03:36 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    10/19/2009 1:03:36 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
    10/19/2009 1:03:36 PM, error: Service Control Manager [7000] - The PC Tools Security Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    10/18/2009 12:09:14 PM, error: Srv [2011] - The server's configuration parameter "irpstacksize" is too small for the server to use a local device. Please increase the value of this parameter.

    ==== End Of File ===========================
     
  6. 2009/10/24
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE. If Combofix asks you to install Recovery Console, please allow it.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!


    Download HijackThis:
    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
    by clicking on Download HijackThis Installer
    Install, and run it.
    Post HijackTHis log.
    Do NOT attempt to fix anything!

    NOTE. If you're using Vista, right click on HijackThis, and click Run as Administrator
     
  7. 2009/10/24
    Ski52

    Ski52 Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    176
    Likes Received:
    1
    As requested:

    ComboFix 09-10-24.01 - Ski 10/24/2009 20:51.1.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1502 [GMT -4:00]
    Running from: c:\documents and settings\Ski\Desktop\ComboFix.exe
    AV: avast! antivirus 4.8.1351 [VPS 091024-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\winitn.dll

    .
    ((((((((((((((((((((((((( Files Created from 2009-09-25 to 2009-10-25 )))))))))))))))))))))))))))))))
    .

    2009-10-23 03:24 . 2009-10-23 03:24 -------- d-----w- c:\windows\system32\wbem\Repository
    2009-10-23 03:17 . 2009-10-23 03:17 -------- d-----w- C:\Tools
    2009-10-19 18:02 . 2009-10-19 18:02 -------- d-----w- c:\documents and settings\Ski\Application Data\Awem
    2009-10-17 22:38 . 2009-03-09 19:27 453456 ----a-w- c:\windows\system32\d3dx10_41.dll
    2009-10-17 22:38 . 2009-03-09 19:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
    2009-10-17 22:38 . 2009-03-09 19:27 1846632 ----a-w- c:\windows\system32\D3DCompiler_41.dll
    2009-10-17 22:38 . 2009-03-16 18:18 69448 ----a-w- c:\windows\system32\XAPOFX1_3.dll
    2009-10-17 22:38 . 2009-03-16 18:18 517448 ----a-w- c:\windows\system32\XAudio2_4.dll
    2009-10-17 22:38 . 2009-03-16 18:18 235352 ----a-w- c:\windows\system32\xactengine3_4.dll
    2009-10-17 22:38 . 2009-03-16 18:18 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll
    2009-10-17 00:28 . 2009-10-17 00:28 -------- d-----w- c:\documents and settings\Ski\Application Data\VampireSaga
    2009-10-16 20:29 . 2009-10-16 20:29 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
    2009-10-16 20:04 . 2009-08-24 18:05 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
    2009-10-16 20:04 . 2009-08-19 15:01 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
    2009-10-16 20:04 . 2008-12-10 15:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
    2009-10-16 20:04 . 2009-10-16 20:04 -------- d-----w- c:\documents and settings\Ski\Application Data\PC Tools
    2009-10-16 20:04 . 2009-10-16 20:04 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
    2009-10-16 19:48 . 2009-10-21 23:12 -------- d-----w- c:\program files\SpywareBlaster
    2009-10-16 19:30 . 2009-10-16 20:28 -------- d-----w- c:\program files\Common Files\PC Tools
    2009-10-16 19:30 . 2009-10-16 20:30 -------- d-----w- c:\program files\Spyware Doctor
    2009-10-16 19:24 . 2009-10-16 19:24 -------- d-----w- c:\program files\Trend Micro
    2009-10-16 17:59 . 2009-10-16 17:59 -------- d-----w- c:\documents and settings\Ski\Application Data\GTM_Bodie
    2009-10-16 15:44 . 2009-10-16 15:44 -------- d-----w- c:\documents and settings\Ski\Application Data\Pointstone
    2009-10-15 16:12 . 2009-10-15 16:12 68608 --sha-r- c:\windows\system32\zgzwo.dll
    2009-10-14 20:52 . 2009-10-14 20:52 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
    2009-10-14 20:52 . 2009-10-14 20:52 -------- d-----w- c:\program files\DVD Shrink
    2009-10-13 03:39 . 2009-10-13 03:39 -------- d-----w- c:\documents and settings\Ski\Application Data\Games
    2009-10-12 22:56 . 2009-10-13 03:18 -------- d-----w- c:\program files\DirPrn
    2009-10-12 22:55 . 2009-10-12 22:55 249856 ------w- c:\windows\Setup1.exe
    2009-10-12 22:55 . 2009-10-12 22:55 73216 ----a-w- c:\windows\ST6UNST.EXE
    2009-10-12 22:00 . 2009-10-12 22:00 -------- d-----w- c:\documents and settings\Ski\Application Data\GARMIN
    2009-10-12 22:00 . 2009-10-12 22:00 -------- d-----w- c:\program files\Garmin GPS Plugin
    2009-10-12 21:54 . 2009-10-12 21:54 -------- d-----w- c:\program files\Garmin
    2009-10-12 21:54 . 2009-10-12 21:54 -------- d-----w- c:\program files\DIFX
    2009-10-12 21:54 . 2009-10-12 21:55 -------- d-----w- C:\Garmin
    2009-10-11 14:53 . 2009-10-11 14:53 -------- d-----w- c:\documents and settings\Ski\Application Data\AMPSoft
    2009-10-11 14:53 . 2009-10-11 14:53 -------- d-----w- c:\program files\AMP Font Viewer
    2009-10-11 14:03 . 2009-10-11 14:03 -------- d-----w- c:\program files\SystemRequirementsLab
    2009-10-11 13:57 . 2009-10-11 13:57 -------- d-----w- c:\documents and settings\Ski\Application Data\Blitware
    2009-10-11 13:37 . 2009-10-11 13:37 -------- d-----w- c:\documents and settings\Ski\Application Data\dvdcss
    2009-10-10 20:42 . 2009-10-10 20:42 -------- d-----w- c:\documents and settings\Ski\EurekaLog
    2009-10-10 18:30 . 2009-10-10 18:30 -------- d-----w- c:\documents and settings\All Users\Application Data\GameHouse
    2009-10-10 18:18 . 2009-10-10 18:18 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
    2009-10-10 18:18 . 2009-10-10 18:18 -------- d-----w- c:\program files\NVIDIA Corporation
    2009-10-09 00:39 . 2009-10-09 00:39 -------- d-----w- c:\documents and settings\Ski\Application Data\Movie Label
    2009-10-09 00:38 . 2009-10-09 17:39 -------- d-----w- c:\program files\Movie Label 2010
    2009-10-09 00:11 . 2009-10-09 00:11 -------- d-----w- c:\documents and settings\Ski\Application Data\Frostbow
    2009-10-09 00:11 . 2009-10-09 00:11 -------- d-----w- c:\program files\Frostbow
    2009-10-08 23:57 . 2009-10-08 23:57 -------- d-----w- c:\documents and settings\Ski\WINDOWS
    2009-10-08 04:11 . 2009-10-08 04:11 -------- d-----w- c:\documents and settings\Ski\Application Data\Total Eclipse
    2009-10-08 03:31 . 2009-10-08 03:31 -------- d-----w- c:\documents and settings\All Users\Application Data\AdventureChronicles1
    2009-10-04 01:55 . 2009-10-04 01:55 -------- d-----w- c:\documents and settings\All Users\Application Data\NeptunesAdve
    2009-10-03 18:39 . 2009-10-05 17:12 -------- d-----w- c:\documents and settings\Ski\Application Data\HdO Adventure
    2009-10-02 15:05 . 2009-10-02 15:05 -------- d-----w- c:\program files\Pointstone
    2009-10-02 15:05 . 2009-10-02 15:05 -------- d-----w- c:\program files\Common Files\Pointstone
    2009-09-30 20:20 . 2009-09-30 20:20 -------- d-----w- c:\documents and settings\Ski\Application Data\Merscom
    2009-09-30 20:20 . 2009-09-30 20:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Merscom
    2009-09-29 07:25 . 2009-10-23 20:09 -------- d-----w- c:\documents and settings\Ski\Application Data\vlc
    2009-09-29 07:24 . 2009-09-29 07:24 -------- d-----w- c:\program files\VideoLAN
    2009-09-28 20:10 . 2009-09-28 20:10 902432 ----a-w- c:\windows\system32\drivers\tdrpm251.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-10-24 16:56 . 2009-06-19 17:02 -------- d-----w- c:\documents and settings\Ski\Application Data\MailWasher
    2009-10-24 00:33 . 2009-06-22 21:28 -------- d-----w- c:\documents and settings\Ski\Application Data\uTorrent
    2009-10-23 03:44 . 2009-08-17 17:07 -------- d-----w- c:\program files\Common Files\Acronis
    2009-10-21 23:11 . 2009-09-02 21:12 -------- d-----w- c:\program files\Simple Port Forwarding
    2009-10-21 23:11 . 2009-06-27 14:00 -------- d-----w- c:\program files\Password Safe
    2009-10-21 23:11 . 2009-06-28 11:29 -------- d-----w- c:\documents and settings\Ski\Application Data\RobinsonCrusoeREF
    2009-10-21 22:25 . 2009-07-27 19:17 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2009-10-17 23:07 . 2009-06-19 02:45 -------- d--h--w- c:\program files\InstallShield Installation Information
    2009-10-15 17:47 . 2009-06-27 14:15 -------- d-----w- c:\program files\Common Files\Adobe
    2009-10-14 07:04 . 2009-06-20 21:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
    2009-10-11 17:21 . 2009-06-19 03:04 54784 ----a-w- c:\documents and settings\Ski\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-10-10 20:44 . 2009-09-04 18:06 -------- d-----w- c:\documents and settings\Ski\Application Data\ZoomBrowser EX
    2009-10-10 20:38 . 2009-09-04 17:59 -------- d-----w- c:\documents and settings\All Users\Application Data\ZoomBrowser
    2009-10-10 18:20 . 2009-06-19 03:01 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
    2009-09-28 20:10 . 2009-08-17 17:07 570016 ----a-w- c:\windows\system32\drivers\timntr.sys
    2009-09-27 20:12 . 2009-06-19 03:01 490088 ----a-w- c:\windows\system32\nvudisp.exe
    2009-09-26 21:25 . 2008-08-14 11:57 73312 ----a-w- c:\windows\system32\drivers\adfs.sys
    2009-09-25 17:15 . 2009-07-25 14:20 -------- d-----w- c:\documents and settings\Ski\Application Data\PlayFirst
    2009-09-25 17:15 . 2009-07-25 14:20 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
    2009-09-24 13:24 . 2009-06-19 03:01 490088 ----a-w- c:\windows\system32\NVUNINST.EXE
    2009-09-23 22:25 . 2009-09-23 22:25 -------- d-----w- c:\program files\Microsoft Silverlight
    2009-09-23 03:37 . 2009-09-07 13:14 -------- d-----w- c:\program files\Windows Home Server
    2009-09-19 18:15 . 2009-09-19 18:15 -------- d-----w- c:\documents and settings\Ski\Application Data\funkitron
    2009-09-18 23:08 . 2009-08-06 01:07 -------- d-----w- c:\documents and settings\Ski\Application Data\Sony
    2009-09-18 23:02 . 2009-09-18 23:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Sony
    2009-09-18 23:02 . 2009-09-18 23:02 -------- d-----w- c:\program files\Sony
    2009-09-18 19:00 . 2009-09-18 19:00 -------- d-----w- c:\program files\WinASO
    2009-09-15 17:35 . 2009-08-20 15:47 -------- d-----w- c:\documents and settings\Ski\Application Data\iWin
    2009-09-11 14:18 . 2004-08-04 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
    2009-09-10 00:27 . 2009-09-10 00:27 1880856 ----a-w- c:\windows\system32\AutoPartNt.exe
    2009-09-08 18:51 . 2009-09-07 13:12 -------- d-----w- c:\documents and settings\Ski\Application Data\Windows Home Server
    2009-09-04 21:03 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
    2009-09-04 19:15 . 2009-09-04 19:15 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
    2009-09-04 18:01 . 2009-06-22 18:39 -------- d-----w- c:\program files\Canon
    2009-09-04 17:58 . 2009-09-04 17:57 -------- d-----w- c:\program files\Common Files\Canon
    2009-08-31 21:13 . 2009-08-31 21:13 -------- d-----w- c:\program files\SIW
    2009-08-31 20:54 . 2009-06-19 17:25 -------- d-----w- c:\documents and settings\Ski\Application Data\Ahead
    2009-08-31 20:45 . 2009-07-25 20:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Sandlot Games
    2009-08-31 19:07 . 2009-08-31 18:09 -------- d-----w- c:\program files\Jasc Software Inc
    2009-08-31 19:03 . 2009-08-31 18:24 -------- d-----w- c:\program files\RegCleaner
    2009-08-30 21:45 . 2009-08-30 21:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Princess Isabella
    2009-08-30 07:02 . 2009-06-20 21:37 -------- d-----w- c:\program files\Microsoft Works
    2009-08-29 18:23 . 2009-08-29 18:23 -------- d-----w- c:\documents and settings\Ski\Application Data\Gold Casual Games
    2009-08-29 08:08 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
    2009-08-27 15:44 . 2009-08-27 15:44 -------- d-----w- c:\documents and settings\Ski\Application Data\blg
    2009-08-27 15:44 . 2009-08-27 15:44 -------- d-----w- c:\documents and settings\All Users\Application Data\blg
    2009-08-26 18:17 . 2009-08-26 18:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Intenium
    2009-08-26 08:00 . 2004-08-04 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
    2009-08-20 03:50 . 2009-07-31 23:04 22872 ----a-r- c:\windows\system32\AdobePDFUI.dll
    2009-08-20 03:50 . 2009-07-31 23:04 46928 ----a-r- c:\windows\system32\AdobePDF.dll
    2009-08-18 15:31 . 2004-08-04 12:00 6656 ----a-w- c:\windows\system32\lpcio.dll
    2009-08-18 03:33 . 2009-08-18 03:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
    2009-08-17 17:07 . 2009-08-17 17:07 44384 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
    2009-08-17 16:10 . 2009-07-19 03:27 1279456 ----a-w- c:\windows\system32\aswBoot.exe
    2009-08-17 16:06 . 2009-07-19 03:28 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
    2009-08-17 16:06 . 2009-07-19 03:28 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
    2009-08-17 16:05 . 2009-07-19 03:28 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2009-08-17 16:05 . 2009-07-19 03:28 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2009-08-17 16:04 . 2009-07-19 03:28 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2009-08-17 16:04 . 2009-07-19 03:28 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2009-08-17 16:03 . 2009-07-19 03:28 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
    2009-08-17 16:02 . 2009-07-19 03:28 97480 ----a-w- c:\windows\system32\AvastSS.scr
    2009-08-06 23:24 . 2009-06-19 02:17 327896 ----a-w- c:\windows\system32\wucltui.dll
    2009-08-06 23:24 . 2009-06-19 02:17 209632 ----a-w- c:\windows\system32\wuweb.dll
    2009-08-06 23:24 . 2009-06-19 03:18 44768 ----a-w- c:\windows\system32\wups2.dll
    2009-08-06 23:24 . 2009-06-19 02:17 35552 ----a-w- c:\windows\system32\wups.dll
    2009-08-06 23:24 . 2009-06-19 02:17 53472 ----a-w- c:\windows\system32\wuauclt.exe
    2009-08-06 23:24 . 2004-08-04 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
    2009-08-06 23:23 . 2009-06-19 02:17 575704 ----a-w- c:\windows\system32\wuapi.dll
    2009-08-06 23:23 . 2009-07-04 17:48 274288 ----a-w- c:\windows\system32\mucltui.dll
    2009-08-06 23:23 . 2009-07-04 17:48 215920 ----a-w- c:\windows\system32\muweb.dll
    2009-08-06 23:23 . 2009-06-19 02:17 1929952 ----a-w- c:\windows\system32\wuaueng.dll
    2009-08-06 03:51 . 2009-08-06 03:48 90112 ----a-w- c:\windows\system32\agsaami.dll
    2009-08-06 03:51 . 2009-08-06 03:48 610304 ----a-w- c:\windows\system32\agsaamg.dll
    2009-08-06 03:51 . 2009-08-06 03:48 372736 ----a-w- c:\windows\system32\agsaamc.dll
    2009-08-06 03:51 . 2009-08-06 03:48 2535424 ----a-w- c:\windows\system32\agsaamj.dll
    2009-08-05 09:01 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
    2009-08-04 15:13 . 2004-08-04 12:00 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe
    2009-08-04 14:20 . 2004-08-03 22:59 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2009-07-29 02:00 . 2009-07-17 21:41 159 ----a-w- c:\windows\popcinfo.dat
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "avast! "= "c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
    "RTHDCPL "= "RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-10-25 16855552]
    "SkyTel "= "SkyTel.EXE" - c:\windows\SkyTel.exe [2007-10-11 1826816]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
    @= "Service "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
    @=" "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
    @=" "

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
    backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Home Server.lnk]
    backup=c:\windows\pss\Windows Home Server.lnkCommon Startup
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall "= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe "=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe "=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe "=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe "=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe "=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe "=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe "=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe "=
    "c:\\Program Files\\uTorrent\\uTorrent.exe "=
    "c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe "=
    "c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe "=
    "c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe "=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "5353:TCP "= 5353:TCP:Adobe CSI CS4
    "3703:TCP "= 3703:TCP:Adobe Version Cue CS4 Server
    "3704:TCP "= 3704:TCP:Adobe Version Cue CS4 Server
    "51000:TCP "= 51000:TCP:Adobe Version Cue CS4 Server
    "51001:TCP "= 51001:TCP:Adobe Version Cue CS4 Server
    "58495:TCP "= 58495:TCP:SPF Port 58495 TCP
    "3587:TCP "= 3587:TCP:Windows Peer-to-Peer Grouping
    "3540:UDP "= 3540:UDP:peer Name Resolution Protocol (PNRP)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
    "AllowInboundEchoRequest "= 1 (0x1)

    R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [10/16/2009 4:04 PM 206256]
    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [7/18/2009 11:28 PM 114768]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7/18/2009 11:28 PM 20560]
    R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [6/22/2009 4:04 PM 674048]
    S2 gupdate1c9f4dcaae7aea4;Google Update Service (gupdate1c9f4dcaae7aea4);c:\program files\Google\Update\GoogleUpdate.exe [6/24/2009 11:01 AM 133104]
    S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [8/15/2008 5:46 AM 284016]
    S3 CGY013;CW-K85 Device;c:\windows\system32\drivers\CGY013.sys [6/22/2009 2:35 PM 24093]
    S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [8/6/2009 5:46 PM 8704]
    S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [8/6/2009 5:46 PM 3072]
    S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/16/2009 4:04 PM 348824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    HPService REG_MULTI_SZ HPSLPSVC
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "c:\program files\Common Files\LightScribe\LSRunOnce.exe "
    .
    Contents of the 'Scheduled Tasks' folder

    2009-10-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-24 15:01]

    2009-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-24 15:01]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://my.yahoo.com/
    IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    TCP: {F1E2F992-2041-4A33-9CFD-C3AD2A6EAE1D} = 192.168.2.1,192.168.2.1
    FF - ProfilePath - c:\documents and settings\Ski\Application Data\Mozilla\Firefox\Profiles\4bz8esua.default\
    FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/|http://mrcs.phpbb3now.com/index.php...nfile.org/index.php|http://www.reflexive.com/
    FF - plugin: c:\documents and settings\Ski\Application Data\Mozilla\Firefox\Profiles\4bz8esua.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-10-24 21:09
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2009-10-25 21:15
    ComboFix-quarantined-files.txt 2009-10-25 01:15

    Pre-Run: 26,448,429,056 bytes free
    Post-Run: 26,433,609,728 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT= "Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS= "Microsoft Windows XP Professional" /noexecute=optin /fastdetect

    - - End Of File - - 4D3DFA8E8291B30DEBC7B3A0BBDCE3FD


    HijackThis:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:21:43 PM, on 10/24/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    C:\WINDOWS\explorer.exe
    D:\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
    O15 - Trusted IP range: http://192.168.2.1
    O15 - ESC Trusted IP range: http://192.168.2.1
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1245381457687
    O17 - HKLM\System\CCS\Services\Tcpip\..\{F1E2F992-2041-4A33-9CFD-C3AD2A6EAE1D}: NameServer = 192.168.2.1,192.168.2.1
    O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
    O23 - Service: Google Update Service (gupdate1c9f4dcaae7aea4) (gupdate1c9f4dcaae7aea4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

    --
    End of file - 6035 bytes
     
  8. 2009/10/24
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    1. Please open Notepad
    • Click Start , then Run
    • Type notepad .exe in the Run Box.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    File::
    c:\windows\system32\zgzwo.dll
    c:\windows\system32\drivers\tdrpm251.sys
    
    
    Folder::
    
    Driver::
    
    Registry::
    
    RegLockDel::
    
    

    3. Save the above as CFScript.txt

    4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [​IMG]


    5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
    • A new HijackThis log.
     
  9. 2009/10/24
    Ski52

    Ski52 Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    176
    Likes Received:
    1
    Here they are:

    ComboFix 09-10-24.01 - Ski 10/24/2009 22:23.2.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1471 [GMT -4:00]
    Running from: c:\documents and settings\Ski\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Ski\Desktop\CFScript.txt
    AV: avast! antivirus 4.8.1351 [VPS 091024-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

    FILE ::
    "c:\windows\system32\drivers\tdrpm251.sys "
    "c:\windows\system32\zgzwo.dll "
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\drivers\tdrpm251.sys
    c:\windows\system32\zgzwo.dll

    .
    ((((((((((((((((((((((((( Files Created from 2009-09-25 to 2009-10-25 )))))))))))))))))))))))))))))))
    .

    2009-10-23 03:24 . 2009-10-23 03:24 -------- d-----w- c:\windows\system32\wbem\Repository
    2009-10-23 03:17 . 2009-10-23 03:17 -------- d-----w- C:\Tools
    2009-10-19 18:02 . 2009-10-19 18:02 -------- d-----w- c:\documents and settings\Ski\Application Data\Awem
    2009-10-17 22:38 . 2009-03-09 19:27 453456 ----a-w- c:\windows\system32\d3dx10_41.dll
    2009-10-17 22:38 . 2009-03-09 19:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
    2009-10-17 22:38 . 2009-03-09 19:27 1846632 ----a-w- c:\windows\system32\D3DCompiler_41.dll
    2009-10-17 22:38 . 2009-03-16 18:18 69448 ----a-w- c:\windows\system32\XAPOFX1_3.dll
    2009-10-17 22:38 . 2009-03-16 18:18 517448 ----a-w- c:\windows\system32\XAudio2_4.dll
    2009-10-17 22:38 . 2009-03-16 18:18 235352 ----a-w- c:\windows\system32\xactengine3_4.dll
    2009-10-17 22:38 . 2009-03-16 18:18 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll
    2009-10-17 00:28 . 2009-10-17 00:28 -------- d-----w- c:\documents and settings\Ski\Application Data\VampireSaga
    2009-10-16 20:29 . 2009-10-16 20:29 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
    2009-10-16 20:04 . 2009-08-24 18:05 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
    2009-10-16 20:04 . 2009-08-19 15:01 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
    2009-10-16 20:04 . 2008-12-10 15:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
    2009-10-16 20:04 . 2009-10-16 20:04 -------- d-----w- c:\documents and settings\Ski\Application Data\PC Tools
    2009-10-16 20:04 . 2009-10-16 20:04 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
    2009-10-16 19:48 . 2009-10-21 23:12 -------- d-----w- c:\program files\SpywareBlaster
    2009-10-16 19:30 . 2009-10-16 20:28 -------- d-----w- c:\program files\Common Files\PC Tools
    2009-10-16 19:30 . 2009-10-16 20:30 -------- d-----w- c:\program files\Spyware Doctor
    2009-10-16 17:59 . 2009-10-16 17:59 -------- d-----w- c:\documents and settings\Ski\Application Data\GTM_Bodie
    2009-10-16 15:44 . 2009-10-16 15:44 -------- d-----w- c:\documents and settings\Ski\Application Data\Pointstone
    2009-10-14 20:52 . 2009-10-14 20:52 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
    2009-10-14 20:52 . 2009-10-14 20:52 -------- d-----w- c:\program files\DVD Shrink
    2009-10-13 03:39 . 2009-10-13 03:39 -------- d-----w- c:\documents and settings\Ski\Application Data\Games
    2009-10-12 22:56 . 2009-10-13 03:18 -------- d-----w- c:\program files\DirPrn
    2009-10-12 22:55 . 2009-10-12 22:55 249856 ------w- c:\windows\Setup1.exe
    2009-10-12 22:55 . 2009-10-12 22:55 73216 ----a-w- c:\windows\ST6UNST.EXE
    2009-10-12 22:00 . 2009-10-12 22:00 -------- d-----w- c:\documents and settings\Ski\Application Data\GARMIN
    2009-10-12 22:00 . 2009-10-12 22:00 -------- d-----w- c:\program files\Garmin GPS Plugin
    2009-10-12 21:54 . 2009-10-12 21:54 -------- d-----w- c:\program files\Garmin
    2009-10-12 21:54 . 2009-10-12 21:54 -------- d-----w- c:\program files\DIFX
    2009-10-12 21:54 . 2009-10-12 21:55 -------- d-----w- C:\Garmin
    2009-10-11 14:53 . 2009-10-11 14:53 -------- d-----w- c:\documents and settings\Ski\Application Data\AMPSoft
    2009-10-11 14:53 . 2009-10-11 14:53 -------- d-----w- c:\program files\AMP Font Viewer
    2009-10-11 14:03 . 2009-10-11 14:03 -------- d-----w- c:\program files\SystemRequirementsLab
    2009-10-11 13:57 . 2009-10-11 13:57 -------- d-----w- c:\documents and settings\Ski\Application Data\Blitware
    2009-10-11 13:37 . 2009-10-11 13:37 -------- d-----w- c:\documents and settings\Ski\Application Data\dvdcss
    2009-10-10 20:42 . 2009-10-10 20:42 -------- d-----w- c:\documents and settings\Ski\EurekaLog
    2009-10-10 18:30 . 2009-10-10 18:30 -------- d-----w- c:\documents and settings\All Users\Application Data\GameHouse
    2009-10-10 18:18 . 2009-10-10 18:18 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
    2009-10-10 18:18 . 2009-10-10 18:18 -------- d-----w- c:\program files\NVIDIA Corporation
    2009-10-09 00:39 . 2009-10-09 00:39 -------- d-----w- c:\documents and settings\Ski\Application Data\Movie Label
    2009-10-09 00:38 . 2009-10-09 17:39 -------- d-----w- c:\program files\Movie Label 2010
    2009-10-09 00:11 . 2009-10-09 00:11 -------- d-----w- c:\documents and settings\Ski\Application Data\Frostbow
    2009-10-09 00:11 . 2009-10-09 00:11 -------- d-----w- c:\program files\Frostbow
    2009-10-08 23:57 . 2009-10-08 23:57 -------- d-----w- c:\documents and settings\Ski\WINDOWS
    2009-10-08 04:11 . 2009-10-08 04:11 -------- d-----w- c:\documents and settings\Ski\Application Data\Total Eclipse
    2009-10-08 03:31 . 2009-10-08 03:31 -------- d-----w- c:\documents and settings\All Users\Application Data\AdventureChronicles1
    2009-10-04 01:55 . 2009-10-04 01:55 -------- d-----w- c:\documents and settings\All Users\Application Data\NeptunesAdve
    2009-10-03 18:39 . 2009-10-05 17:12 -------- d-----w- c:\documents and settings\Ski\Application Data\HdO Adventure
    2009-10-02 15:05 . 2009-10-02 15:05 -------- d-----w- c:\program files\Pointstone
    2009-10-02 15:05 . 2009-10-02 15:05 -------- d-----w- c:\program files\Common Files\Pointstone
    2009-09-30 20:20 . 2009-09-30 20:20 -------- d-----w- c:\documents and settings\Ski\Application Data\Merscom
    2009-09-30 20:20 . 2009-09-30 20:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Merscom
    2009-09-29 07:25 . 2009-10-23 20:09 -------- d-----w- c:\documents and settings\Ski\Application Data\vlc
    2009-09-29 07:24 . 2009-09-29 07:24 -------- d-----w- c:\program files\VideoLAN

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-10-24 16:56 . 2009-06-19 17:02 -------- d-----w- c:\documents and settings\Ski\Application Data\MailWasher
    2009-10-24 00:33 . 2009-06-22 21:28 -------- d-----w- c:\documents and settings\Ski\Application Data\uTorrent
    2009-10-23 03:44 . 2009-08-17 17:07 -------- d-----w- c:\program files\Common Files\Acronis
    2009-10-21 23:11 . 2009-09-02 21:12 -------- d-----w- c:\program files\Simple Port Forwarding
    2009-10-21 23:11 . 2009-06-27 14:00 -------- d-----w- c:\program files\Password Safe
    2009-10-21 23:11 . 2009-06-28 11:29 -------- d-----w- c:\documents and settings\Ski\Application Data\RobinsonCrusoeREF
    2009-10-21 22:25 . 2009-07-27 19:17 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2009-10-17 23:07 . 2009-06-19 02:45 -------- d--h--w- c:\program files\InstallShield Installation Information
    2009-10-15 17:47 . 2009-06-27 14:15 -------- d-----w- c:\program files\Common Files\Adobe
    2009-10-14 07:04 . 2009-06-20 21:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
    2009-10-11 17:21 . 2009-06-19 03:04 54784 ----a-w- c:\documents and settings\Ski\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-10-10 20:44 . 2009-09-04 18:06 -------- d-----w- c:\documents and settings\Ski\Application Data\ZoomBrowser EX
    2009-10-10 20:38 . 2009-09-04 17:59 -------- d-----w- c:\documents and settings\All Users\Application Data\ZoomBrowser
    2009-10-10 18:20 . 2009-06-19 03:01 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
    2009-09-28 20:10 . 2009-08-17 17:07 570016 ----a-w- c:\windows\system32\drivers\timntr.sys
    2009-09-27 20:12 . 2009-06-19 03:01 490088 ----a-w- c:\windows\system32\nvudisp.exe
    2009-09-26 21:25 . 2008-08-14 11:57 73312 ----a-w- c:\windows\system32\drivers\adfs.sys
    2009-09-25 17:15 . 2009-07-25 14:20 -------- d-----w- c:\documents and settings\Ski\Application Data\PlayFirst
    2009-09-25 17:15 . 2009-07-25 14:20 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
    2009-09-24 13:24 . 2009-06-19 03:01 490088 ----a-w- c:\windows\system32\NVUNINST.EXE
    2009-09-23 22:25 . 2009-09-23 22:25 -------- d-----w- c:\program files\Microsoft Silverlight
    2009-09-23 03:37 . 2009-09-07 13:14 -------- d-----w- c:\program files\Windows Home Server
    2009-09-19 18:15 . 2009-09-19 18:15 -------- d-----w- c:\documents and settings\Ski\Application Data\funkitron
    2009-09-18 23:08 . 2009-08-06 01:07 -------- d-----w- c:\documents and settings\Ski\Application Data\Sony
    2009-09-18 23:02 . 2009-09-18 23:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Sony
    2009-09-18 23:02 . 2009-09-18 23:02 -------- d-----w- c:\program files\Sony
    2009-09-18 19:00 . 2009-09-18 19:00 -------- d-----w- c:\program files\WinASO
    2009-09-15 17:35 . 2009-08-20 15:47 -------- d-----w- c:\documents and settings\Ski\Application Data\iWin
    2009-09-11 14:18 . 2004-08-04 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
    2009-09-10 00:27 . 2009-09-10 00:27 1880856 ----a-w- c:\windows\system32\AutoPartNt.exe
    2009-09-08 18:51 . 2009-09-07 13:12 -------- d-----w- c:\documents and settings\Ski\Application Data\Windows Home Server
    2009-09-04 21:03 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
    2009-09-04 19:15 . 2009-09-04 19:15 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
    2009-09-04 18:01 . 2009-06-22 18:39 -------- d-----w- c:\program files\Canon
    2009-09-04 17:58 . 2009-09-04 17:57 -------- d-----w- c:\program files\Common Files\Canon
    2009-08-31 21:13 . 2009-08-31 21:13 -------- d-----w- c:\program files\SIW
    2009-08-31 20:54 . 2009-06-19 17:25 -------- d-----w- c:\documents and settings\Ski\Application Data\Ahead
    2009-08-31 20:45 . 2009-07-25 20:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Sandlot Games
    2009-08-31 19:07 . 2009-08-31 18:09 -------- d-----w- c:\program files\Jasc Software Inc
    2009-08-31 19:03 . 2009-08-31 18:24 -------- d-----w- c:\program files\RegCleaner
    2009-08-30 21:45 . 2009-08-30 21:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Princess Isabella
    2009-08-30 07:02 . 2009-06-20 21:37 -------- d-----w- c:\program files\Microsoft Works
    2009-08-29 18:23 . 2009-08-29 18:23 -------- d-----w- c:\documents and settings\Ski\Application Data\Gold Casual Games
    2009-08-29 08:08 . 2004-08-04 12:00 916480 ------w- c:\windows\system32\wininet.dll
    2009-08-27 15:44 . 2009-08-27 15:44 -------- d-----w- c:\documents and settings\Ski\Application Data\blg
    2009-08-27 15:44 . 2009-08-27 15:44 -------- d-----w- c:\documents and settings\All Users\Application Data\blg
    2009-08-26 18:17 . 2009-08-26 18:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Intenium
    2009-08-26 08:00 . 2004-08-04 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
    2009-08-20 03:50 . 2009-07-31 23:04 22872 ----a-r- c:\windows\system32\AdobePDFUI.dll
    2009-08-20 03:50 . 2009-07-31 23:04 46928 ----a-r- c:\windows\system32\AdobePDF.dll
    2009-08-18 15:31 . 2004-08-04 12:00 6656 ----a-w- c:\windows\system32\lpcio.dll
    2009-08-18 03:33 . 2009-08-18 03:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
    2009-08-17 17:07 . 2009-08-17 17:07 44384 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
    2009-08-17 16:10 . 2009-07-19 03:27 1279456 ----a-w- c:\windows\system32\aswBoot.exe
    2009-08-17 16:06 . 2009-07-19 03:28 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
    2009-08-17 16:06 . 2009-07-19 03:28 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
    2009-08-17 16:05 . 2009-07-19 03:28 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2009-08-17 16:05 . 2009-07-19 03:28 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2009-08-17 16:04 . 2009-07-19 03:28 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2009-08-17 16:04 . 2009-07-19 03:28 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2009-08-17 16:03 . 2009-07-19 03:28 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
    2009-08-17 16:02 . 2009-07-19 03:28 97480 ----a-w- c:\windows\system32\AvastSS.scr
    2009-08-06 23:24 . 2009-06-19 02:17 327896 ----a-w- c:\windows\system32\wucltui.dll
    2009-08-06 23:24 . 2009-06-19 02:17 209632 ----a-w- c:\windows\system32\wuweb.dll
    2009-08-06 23:24 . 2009-06-19 03:18 44768 ----a-w- c:\windows\system32\wups2.dll
    2009-08-06 23:24 . 2009-06-19 02:17 35552 ----a-w- c:\windows\system32\wups.dll
    2009-08-06 23:24 . 2009-06-19 02:17 53472 ------w- c:\windows\system32\wuauclt.exe
    2009-08-06 23:24 . 2004-08-04 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
    2009-08-06 23:23 . 2009-06-19 02:17 575704 ----a-w- c:\windows\system32\wuapi.dll
    2009-08-06 23:23 . 2009-07-04 17:48 274288 ----a-w- c:\windows\system32\mucltui.dll
    2009-08-06 23:23 . 2009-07-04 17:48 215920 ----a-w- c:\windows\system32\muweb.dll
    2009-08-06 23:23 . 2009-06-19 02:17 1929952 ----a-w- c:\windows\system32\wuaueng.dll
    2009-08-06 03:51 . 2009-08-06 03:48 90112 ----a-w- c:\windows\system32\agsaami.dll
    2009-08-06 03:51 . 2009-08-06 03:48 610304 ----a-w- c:\windows\system32\agsaamg.dll
    2009-08-06 03:51 . 2009-08-06 03:48 372736 ----a-w- c:\windows\system32\agsaamc.dll
    2009-08-06 03:51 . 2009-08-06 03:48 2535424 ----a-w- c:\windows\system32\agsaamj.dll
    2009-08-05 09:01 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
    2009-08-04 15:13 . 2004-08-04 12:00 2145280 ------w- c:\windows\system32\ntoskrnl.exe
    2009-08-04 14:20 . 2004-08-03 22:59 2023936 ------w- c:\windows\system32\ntkrnlpa.exe
    2009-07-29 02:00 . 2009-07-17 21:41 159 ----a-w- c:\windows\popcinfo.dat
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "avast! "= "c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
    "RTHDCPL "= "RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-10-25 16855552]
    "SkyTel "= "SkyTel.EXE" - c:\windows\SkyTel.exe [2007-10-11 1826816]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
    @= "Service "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
    @=" "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
    @=" "

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
    backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Home Server.lnk]
    backup=c:\windows\pss\Windows Home Server.lnkCommon Startup

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall "= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe "=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe "=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe "=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe "=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe "=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe "=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe "=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe "=
    "c:\\Program Files\\uTorrent\\uTorrent.exe "=
    "c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe "=
    "c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe "=
    "c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe "=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "5353:TCP "= 5353:TCP:Adobe CSI CS4
    "3703:TCP "= 3703:TCP:Adobe Version Cue CS4 Server
    "3704:TCP "= 3704:TCP:Adobe Version Cue CS4 Server
    "51000:TCP "= 51000:TCP:Adobe Version Cue CS4 Server
    "51001:TCP "= 51001:TCP:Adobe Version Cue CS4 Server
    "58495:TCP "= 58495:TCP:SPF Port 58495 TCP
    "3587:TCP "= 3587:TCP:Windows Peer-to-Peer Grouping
    "3540:UDP "= 3540:UDP:peer Name Resolution Protocol (PNRP)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
    "AllowInboundEchoRequest "= 1 (0x1)

    R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [10/16/2009 4:04 PM 206256]
    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [7/18/2009 11:28 PM 114768]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7/18/2009 11:28 PM 20560]
    R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [6/22/2009 4:04 PM 674048]
    S2 gupdate1c9f4dcaae7aea4;Google Update Service (gupdate1c9f4dcaae7aea4);c:\program files\Google\Update\GoogleUpdate.exe [6/24/2009 11:01 AM 133104]
    S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [8/15/2008 5:46 AM 284016]
    S3 CGY013;CW-K85 Device;c:\windows\system32\drivers\CGY013.sys [6/22/2009 2:35 PM 24093]
    S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [8/6/2009 5:46 PM 8704]
    S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [8/6/2009 5:46 PM 3072]
    S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/16/2009 4:04 PM 348824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    HPService REG_MULTI_SZ HPSLPSVC
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "c:\program files\Common Files\LightScribe\LSRunOnce.exe "
    .
    Contents of the 'Scheduled Tasks' folder

    2009-10-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-24 15:01]

    2009-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-24 15:01]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://my.yahoo.com/
    IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    TCP: {F1E2F992-2041-4A33-9CFD-C3AD2A6EAE1D} = 192.168.2.1,192.168.2.1
    FF - ProfilePath - c:\documents and settings\Ski\Application Data\Mozilla\Firefox\Profiles\4bz8esua.default\
    FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/|http://mrcs.phpbb3now.com/index.php...nfile.org/index.php|http://www.reflexive.com/
    FF - plugin: c:\documents and settings\Ski\Application Data\Mozilla\Firefox\Profiles\4bz8esua.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
    .
    - - - - ORPHANS REMOVED - - - -

    AddRemove-HijackThis - c:\program files\Trend Micro\HijackThis\HijackThis.exe



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-10-24 22:36
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2009-10-25 22:42
    ComboFix-quarantined-files.txt 2009-10-25 02:42

    Pre-Run: 26,444,046,336 bytes free
    Post-Run: 26,426,998,784 bytes free

    - - End Of File - - 13A93FB9F6F3CBA6FA16DF14FE082CEB


    HijackThis:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:44:56 PM, on 10/24/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    C:\WINDOWS\system32\notepad.exe
    C:\WINDOWS\explorer.exe
    D:\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
    O15 - Trusted IP range: http://192.168.2.1
    O15 - ESC Trusted IP range: http://192.168.2.1
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1245381457687
    O17 - HKLM\System\CCS\Services\Tcpip\..\{F1E2F992-2041-4A33-9CFD-C3AD2A6EAE1D}: NameServer = 192.168.2.1,192.168.2.1
    O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
    O23 - Service: Google Update Service (gupdate1c9f4dcaae7aea4) (gupdate1c9f4dcaae7aea4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

    --
    End of file - 6069 bytes
     
  10. 2009/10/24
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Print these instructions out.

    NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe

    ***VERY IMPORTANT! Make sure, you update Superantispyware, and Malwarebytes before running the scans.***

    STEP 1. Download SUPERAntiSpyware Free for Home Users:
    http://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes ". If not, update the definitions before scanning by selecting "Check for Updates ". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * Close SUPERAntiSpyware.

    PHYSICALLY DISCONNECT FROM THE INTERNET

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Click Scan your Computer... button.
    * Click Scanning Preferences/Control Center... button.
    * Under General and Startup tab, make sure, Start SUPERAntiSpyware when Windows starts option is UN-checked.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are checked (leave all others unchecked):
    - Close browsers before scanning.
    - Terminate memory threats before quarantining.

    * Click the Close button to leave the control center screen.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, choose Perform Complete Scan.
    * Click Next to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click OK.
    * Make sure everything has a checkmark next to it and click Next.
    * A notification will appear that Quarantine and Removal is Complete. Click OK and then click the Finish button to return to the main menu.
    * If asked if you want to reboot, click Yes.
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
    - Click Preferences, then click the Statistics/Logs tab.
    - Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    - If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    - Please copy and paste the Scan Log results in your next reply.

    * Click Close to exit the program.
    Post SUPERAntiSpyware log.

    RECONNECT TO THE INTERNET

    RESTART COMPUTER!

    STEP 2. Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php to your desktop.
    (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!


    STEP 3.
    Post fresh HijackThis log.
    NOTE. If you're using Vista, right click on HijackThis, and click Run as Administrator
    Do NOT attempt to "fix" anything!


    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  11. 2009/10/25
    Ski52

    Ski52 Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    176
    Likes Received:
    1
    Some 15 or 16 hours of scans, with little or no results, and I still have sporadic icons in the systray (anywhere from 1 to 5), and it took almost 2 full minutes from clicking on the Firefox icon before anything happened......

    Scan results....

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 10/25/2009 at 09:35 AM

    Application Version : 4.29.1004

    Core Rules Database Version : 4188
    Trace Rules Database Version: 2103

    Scan type : Complete Scan
    Total Scan Time : 10:25:51

    Memory items scanned : 207
    Memory threats detected : 0
    Registry items scanned : 6486
    Registry threats detected : 0
    File items scanned : 192867
    File threats detected : 4

    Trojan.Agent/Gen-Keygen
    F:\CD-DVD UTILITIES\CONVERTXTODVD-3.7.2.188.FF\KEYGEN.EXE

    Trojan.VXGame-Variant/D
    F:\GRAPHICS\PLUGINS FOR GRAPHICPROGRAMS\AUTOFX.MYSTICAL.LIGHTING.V1.05.GFX\AUTOFX.MYSTICAL.LIGHTING.V1.05\KEYGEN\KEYGEN.EXE

    Adware.GloboLook
    F:\ICONS\FREE\ARCADE_EX.ICO
    F:\ICONS\FREE\PILL2.ICO

    Next..

    Malwarebytes' Anti-Malware 1.41
    Database version: 3029
    Windows 5.1.2600 Service Pack 3

    10/25/2009 3:19:14 PM
    mbam-log-2009-10-25 (15-19-14).txt

    Scan type: Full Scan (C:\|D:\|E:\|F:\|G:\|)
    Objects scanned: 304000
    Time elapsed: 4 hour(s), 32 minute(s), 0 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    Thanx for your continuing help here!!

    I'm starting to look at how much more to backup, and how much to loose on a full fdisk & format...
     
  12. 2009/10/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    First of all, we're not done yet.

    Then...
    what do you mean by:
    Combofix cleaned some stuff, Super got another two trojans and couple of adwares, so...

    I still need fresh HJT log.
     
  13. 2009/10/25
    Ski52

    Ski52 Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    176
    Likes Received:
    1
    Sorry to be so pushy.... Usually by now, most of the ones I have worked with have gone away. guess this one is a stinker.... catchin' he!! from the 'boss', she needs her game 'fix', and the box is busy....

    Here's the HJT log fresh off the box....

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:34:23 PM, on 10/25/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    D:\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
    O15 - Trusted IP range: http://192.168.2.1
    O15 - ESC Trusted IP range: http://192.168.2.1
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1245381457687
    O17 - HKLM\System\CCS\Services\Tcpip\..\{F1E2F992-2041-4A33-9CFD-C3AD2A6EAE1D}: NameServer = 192.168.2.1,192.168.2.1
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
    O23 - Service: Google Update Service (gupdate1c9f4dcaae7aea4) (gupdate1c9f4dcaae7aea4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

    --
    End of file - 6211 bytes
     
  14. 2009/10/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Download Dr.Web CureIt to the desktop:
    ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
    • Doubleclick the drweb-cureit.exe file and click Scan to run express scan. Click OK in pop-up window to allow scan.
    • This will scan the files currently running in memory and when something is found, click the Yes button when it asks you if you want to cure it. This is only a short scan.
    • Once the short scan has finished, select Complete scan.
    • Click the green arrow [​IMG] at the right, and the scan will start.
    • Click Yes to all if it asks if you want to cure/move the file.
    • When the scan has finished, in the menu, click File and choose Save report list
    • Save the report to your desktop. The report will be called DrWeb.csv
    • Close Dr.Web Cureit.
    • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
    • Copy and paste that log in the next reply. You can use Notepad to open the DrWeb.cvs report.

    NOTE. During the scan, pop-up window will open asking for full version purchase. Simply close the window by clicking on X in upper right corner.


    Post fresh HijackThis log as well.
     
  15. 2009/10/25
    Ski52

    Ski52 Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    176
    Likes Received:
    1
    Broni - Drweb-cureit won't run. It seems to load, but after 10 seconds or so of the hour glass - nothing. I rebooted the machine twice, and renamed the executable to something other than the original name - still no-go.
    Just had 6 icons in the sys tray, but after rebooting another time, I'm back to 1.
     
  16. 2009/10/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Uninstall Combofix:
    Go Start > Run
    Type in:
    combofix /u
    Note the space between the "combofix" and the "/u "
    Restart computer.


    Download, and install AVP Tool.
    After installation, leave all settings as they're, and simply click on Scan button.
    When scan is done, and any objects are found, click on Neutralize all button.
    Next, click Reports... button, then Save to file....
    Save the file to know location as report.txt.
    Open report.txt in Notepad, copy all content, and post it in your next reply.

    Post fresh HijackThis log as well.
     
  17. 2009/10/25
    Ski52

    Ski52 Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    176
    Likes Received:
    1
    OK - uninstalled Combofix and ran AVP & HJT.

    Scan
    ----
    Scanned: 3579
    Detected: 0
    Untreated: 0
    Start time: 10/25/2009 10:43:05 PM
    Duration: 00:05:44
    Finish time: 10/25/2009 10:48:49 PM


    Detected
    --------
    Status Object
    ------ ------


    Events
    ------
    Time Name Status Reason
    ---- ---- ------ ------
    10/25/2009 10:43:14 PM Running module: smss.exe\smss.exe ok scanned


    Statistics
    ----------
    Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted
    ------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------


    Settings
    --------
    Parameter Value
    --------- -----
    Security Level Recommended
    Action Prompt for action when the scan is complete
    Run mode Manually
    File types Scan all files
    Scan only new and changed files No
    Scan archives All
    Scan embedded OLE objects All
    Skip if object is larger than No
    Skip if scan takes longer than No
    Parse email formats No
    Scan password-protected archives No
    Enable iChecker technology No
    Enable iSwift technology No
    Show detected threats on "Detected" tab Yes
    Rootkits search Yes
    Deep rootkits search No
    Use heuristic analyzer Yes


    Quarantine
    ----------
    Status Object Size Added
    ------ ------ ---- -----


    Backup
    ------
    Status Object Size
    ------ ------ ----

    HijackThis:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:50:40 PM, on 10/25/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\DOCUME~1\Ski\LOCALS~1\Temp\dc31284348\pbts6e.exe
    C:\DOCUME~1\Ski\LOCALS~1\Temp\dc31284348\pbts6e.exe
    C:\DOCUME~1\Ski\LOCALS~1\Temp\dc31284348\pbts6e.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    D:\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
    O15 - Trusted IP range: http://192.168.2.1
    O15 - ESC Trusted IP range: http://192.168.2.1
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1245381457687
    O17 - HKLM\System\CCS\Services\Tcpip\..\{F1E2F992-2041-4A33-9CFD-C3AD2A6EAE1D}: NameServer = 192.168.2.1,192.168.2.1
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
    O23 - Service: Google Update Service (gupdate1c9f4dcaae7aea4) (gupdate1c9f4dcaae7aea4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

    --
    End of file - 6292 bytes
     
  18. 2009/10/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I don't like something here...
    Re-run HJT and checkmark following entries:
    - R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    - R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    Click "Fix checked" button.

    Did you add these two entries into "Trusted zone ":
    O15 - Trusted IP range: http://192.168.2.1
    O15 - ESC Trusted IP range: http://192.168.2.1



    Download OTL to your Desktop.

    * Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    * Under the Custom Scan box paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.exe
    %systemroot%\system32\eventlog.dll
    %systemroot%\system32\scecli.dll
    %systemroot%\netlogon.dll
    %systemroot%\system32\cngaudit.dll
    %systemroot%\system32\sceclt.dll
    %systemroot%\ntelogon.dll
    %systemroot%\system32\logevent.dll


    * Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
      Since those are pretty big files, you can attach them, if you wish.
     
    Last edited: 2009/10/25
  19. 2009/10/25
    Ski52

    Ski52 Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    176
    Likes Received:
    1
    OK - Did as you said with the 'R0...' entries, and NO, I had nothing to do with my router IP - 192.168.2.1 Food for thought, I am behind 2 routers.... A standard Belkin wired/wireless, and a VoIP - Vonage. Cable from the wall to the Toshiba (RoadRunner) modem to the Vonage router (192.168.15.something) to the Belkin router, which is the address you questioned.
    Don't know how to attach files here so I'll just add them...

    OTL Extras logfile created on: 10/25/2009 11:43:35 PM - Run 1
    OTL by OldTimer - Version 3.0.22.1 Folder = D:\
    Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    2.00 Gb Total Physical Memory | 1.42 Gb Available Physical Memory | 71.24% Memory free
    3.85 Gb Paging File | 3.34 Gb Available in Paging File | 86.75% Paging File free
    Paging file location(s): C:\pagefile.sys 2046 2046 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 51.77 Gb Total Space | 25.33 Gb Free Space | 48.93% Space Free | Partition Type: NTFS
    Drive D: | 44.54 Gb Total Space | 25.16 Gb Free Space | 56.49% Space Free | Partition Type: NTFS
    Drive E: | 20.51 Gb Total Space | 13.63 Gb Free Space | 66.46% Space Free | Partition Type: NTFS
    Drive F: | 20.51 Gb Total Space | 10.85 Gb Free Space | 52.90% Space Free | Partition Type: NTFS
    Drive G: | 11.71 Gb Total Space | 11.65 Gb Free Space | 99.49% Space Free | Partition Type: NTFS
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: SKISINTEL
    Current User Name: Ski
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: On
    Skip Microsoft Files: On
    File Age = 14 Days
    Output = Standard
    Quick Scan

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
    .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

    [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %* File not found
    chm.file [open] -- "%SYSTEMROOT%\hh.exe" %1 (Microsoft Corporation)
    cmdfile [open] -- "%1" %* File not found
    comfile [open] -- "%1" %* File not found
    exefile [open] -- "%1" %* File not found
    htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
    htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
    htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
    http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
    https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
    piffile [open] -- "%1" %* File not found
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1" File not found
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
    scrfile [open] -- "%1" /S File not found
    txtfile [edit] -- Reg Error: Key error.
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
    Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
    Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
    CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled" = 1
    "AntiVirusDisableNotify" = 1
    "FirewallDisableNotify" = 1
    "UpdatesDisableNotify" = 1
    "AntiVirusOverride" = 0
    "FirewallOverride" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
    "139:TCP" = 139:TCP:*:Enabled:mad:xpsp2res.dll,-22004
    "445:TCP" = 445:TCP:*:Enabled:mad:xpsp2res.dll,-22005
    "137:UDP" = 137:UDP:*:Enabled:mad:xpsp2res.dll,-22001
    "138:UDP" = 138:UDP:*:Enabled:mad:xpsp2res.dll,-22002
    "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22008
    "3587:TCP" = 3587:TCP:*:Enabled:Windows Peer-to-Peer Grouping
    "3540:UDP" = 3540:UDP:*:Enabled:peer Name Resolution Protocol (PNRP)

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 0
    "DoNotAllowExceptions" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "139:TCP" = 139:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22004
    "445:TCP" = 445:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22005
    "137:UDP" = 137:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22001
    "138:UDP" = 138:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22002
    "5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4
    "3703:TCP" = 3703:TCP:*:Enabled:Adobe Version Cue CS4 Server
    "3704:TCP" = 3704:TCP:*:Enabled:Adobe Version Cue CS4 Server
    "51000:TCP" = 51000:TCP:*:Enabled:Adobe Version Cue CS4 Server
    "51001:TCP" = 51001:TCP:*:Enabled:Adobe Version Cue CS4 Server
    "58495:TCP" = 58495:TCP:*:Enabled:SPF Port 58495 TCP
    "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22008
    "3587:TCP" = 3587:TCP:*:Enabled:Windows Peer-to-Peer Grouping
    "3540:UDP" = 3540:UDP:*:Enabled:peer Name Resolution Protocol (PNRP)

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 -- (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 -- (Microsoft Corporation)
    "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe -- (Hewlett-Packard Co.)
    "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe -- (Hewlett-Packard Co.)
    "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe -- (Hewlett-Packard Co.)
    "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe -- (Hewlett-Packard Co.)
    "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Co.)
    "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe -- (Hewlett-Packard)
    "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe -- (Hewlett-Packard Co.)
    "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Co.)
    "C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
    "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 -- (Adobe Systems Incorporated)
    "C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe" = C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe:*:Enabled:Adobe Version Cue CS4 Server -- (Adobe Systems Incorporated)
    "C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe" = C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe:*:Enabled:Nero ShowTime -- (Nero AG)


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    "{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
    "{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
    "{06A1BE8A-4CA4-4A39-B9E4-E815AA8FE05C}" = Sony Noise Reduction Plug-In 2.0h
    "{0878E100-C0BB-41E8-B4C6-C486B61FDA7B}" = Canon PhotoRecord
    "{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
    "{098A2A49-7CF3-4F08-A38D-FB879117152A}" = Adobe Color NA Extra Settings CS4
    "{0A755762-EED8-47AB-A446-505766F93D43}" = Atheros Communications Inc.(R) L2 Fast Ethernet Driver
    "{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
    "{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}" = Adobe Color EU Recommended Settings CS4
    "{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
    "{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
    "{11B83AD3-7A46-4C2E-A568-9505981D4C6F}" = HP Update
    "{14F70205-1940-4000-88C7-BE799A6B2CAD}" = Adobe Soundbooth CS4
    "{15262012-213A-4f65-9019-C8A409EC0156}" = HP Officejet J6400 Series
    "{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4
    "{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
    "{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
    "{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
    "{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
    "{188C0E25-3D65-4DAC-9C00-7483FBA4C7EB}" = Status
    "{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
    "{1B7C06E1-4888-47A6-992A-0990B9683486}" = Adobe Version Cue CS4 Server
    "{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4
    "{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler
    "{1F698102-5739-441E-96F0-74F4EA540F06}" = Atheros Ethernet Utility
    "{2168245A-B5AD-40D8-A641-48E3E070B5B6}" = Adobe Flash CS4 STI-en
    "{279D3818-7287-4ab4-A927-542EBEA9E365}" = ProductContext
    "{297190A1-4B0D-4CD6-8B9F-3907F15C3FD8}" = Adobe CS4 American English Speech Analysis Models
    "{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application Feature Set Files (Roman)
    "{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
    "{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
    "{34D8A788-9397-4695-86BF-B6920284CC65}_is1" = Power AMR MP3 WAV WMA M4A AC3 Audio Converter 1.6
    "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
    "{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
    "{36FDBE6E-6684-462b-AE98-9A39A1B200CC}" = HPProductAssistant
    "{380CC749-8C28-4C74-BE01-45921D062302}" = BPDSoftware_Ini
    "{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
    "{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
    "{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
    "{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
    "{3F9170C9-A7C2-408F-A4D8-EC77250040BF}" = Sound Forge Pro 10.0
    "{41853D20-40CC-4266-978D-F128BB97CA96}" = 6400_Help
    "{428FDF9F-E010-4C4C-A8BB-156960AFCA1C}" = Adobe Fireworks CS4
    "{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
    "{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets
    "{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4
    "{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
    "{49F864F5-1A85-4E69-8764-C7E4EABD8BA0}" = KWorld TV Tuner Card Utilities
    "{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4
    "{4B66765B-8596-4698-A208-E23D11D84AA7}" = Canon Camera WIA Driver
    "{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC
    "{52232EF4-CC12-4C21-ABCF-ADB79618302D}" = Adobe Soundbooth CS4 Codecs
    "{52A69E11-7CEB-4a7d-9607-68BA4F39A89B}" = DeviceDiscovery
    "{535A4F3D-06C3-446C-A2AA-DBB71EC192B8}" = LightScribe Applications
    "{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
    "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
    "{5ACE69F0-A3E8-44eb-88C1-0A841E700180}" = TrayApp
    "{5BB4D7C1-52F2-4BFD-9E40-0D419E2E3021}" = bpd_scan
    "{5C5F82A1-F792-48F9-99BE-8AFE123A23D5}" = DISC TITLE PRINTER
    "{5D934326-165A-413b-B056-26BE1EC082AF}" = J6400
    "{5EAD5443-7194-46CC-A055-428E6ABB1BAF}" = Adobe Encore CS4
    "{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
    "{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C}" = Adobe Creative Suite 4 Master Collection
    "{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
    "{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
    "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
    "{676981B7-A2D9-49D0-9F4C-03018F131DA9}" = DocProc
    "{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
    "{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
    "{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
    "{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
    "{68E7E8BD-2233-49BE-81D6-1A1FAF1B5196}" = RAW Image Task 1.1
    "{69EA986B-B172-4FAA-B54D-853BD3A2B264}" = Popcap Game Collection
    "{6AE9A059-6372-435D-A5FE-0568A3B67F19}" = HyperMediaCenter
    "{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
    "{7406DF60-016D-476B-A2C7-55D997592047}" = Adobe OnLocation CS4
    "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    "{793D1D88-6141-43DE-BE58-59BCE31B4090}" = Adobe Flash CS4 Extension - Flash Lite STI en
    "{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base Files
    "{80533B67-C407-485D-8B5D-63BB8ED9D878}" = Scan
    "{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
    "{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111249233}" = Dream Vacation Solitaire
    "{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
    "{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
    "{84B01A13-F78F-4281-9224-C96FB3530A2C}" = LightScribe Template Designs - Seasonal Pack 1
    "{85C8D391-0EAE-4492-8A0A-2EE8B0B6DA03}" = BPDSoftware
    "{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
    "{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
    "{8B332722-DF02-480E-AC80-873F2462A4F3}" = LightScribe Diagnostic Utility
    "{8BA510D1-045B-4E1A-AF52-2282BBF69D5D}" = LightScribe System Software
    "{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
    "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
    "{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
    "{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
    "{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
    "{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
    "{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
    "{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
    "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
    "{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
    "{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
    "{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
    "{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
    "{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
    "{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
    "{98EFD8F0-08DE-48DB-B922-A2EBAB711033}" = Nero 7 Premium
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
    "{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}" = SolutionCenter
    "{A6EC82A0-1414-475D-8AFD-469089F3080D}" = Adobe Contribute CS4
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
    "{AB67580-257C-45FF-B8F4-C8C30682091A}_is1" = SIW version 2009-07-28
    "{ABA00898-9467-4689-9F40-DE7F58C8429C}" = Fax
    "{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
    "{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
    "{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
    "{ACDE260A-602B-4cfb-A650-D0DBA6FFAD85}" = NetDeviceManager
    "{AEB9948B-4FF2-47C9-990E-47014492A0FE}" = MSXML 6.0 Parser
    "{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
    "{B1102A25-3AA3-446B-AA0F-A699B07A02FD}" = Garmin USB Drivers
    "{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
    "{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}" = Adobe Premiere Pro CS4 Functional Content
    "{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
    "{B4E96960-5F6B-48B9-A5BD-6A5A9BB4F027}" = Avery Wizard 3.1
    "{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
    "{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
    "{B9F4561A-924D-4510-A85A-BB0960C338CB}" = Adobe Asset Services CS4
    "{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
    "{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
    "{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
    "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
    "{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
    "{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
    "{C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B}" = Acrobat.com
    "{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content
    "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
    "{CC016F21-3970-11DE-B878-005056806466}" = Google Earth
    "{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
    "{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
    "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{D142FE39-3386-4d82-9AD3-36D4A92AC3C2}" = DocMgr
    "{D1C70CF7-F2F3-4A15-ADE5-5DF1BA0739E1}" = LightScribe Template Designs - Bonus Pack 1
    "{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
    "{D499F8DE-3F31-4900-9157-61061613704B}" = Adobe Premiere Pro CS4
    "{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7
    "{D99A8E3A-AE5A-4692-8B19-6F16D454E240}" = Destination Component
    "{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
    "{E0783143-EAE2-4047-A8D6-E155523C594C}" = Garmin WebUpdater
    "{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
    "{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
    "{E8EE9410-8AC4-4F43-A626-DDECA75C79F3}" = Adobe Setup
    "{EE353798-E875-42E0-B58D-7E6696182EA8}" = Adobe Media Encoder CS4 Dolby
    "{EFF87108-C9D0-43F1-BEE1-28DA87778F1A}" = Garmin Communicator Plugin
    "{F0C8BC0A-B0E7-4F39-848C-C5B06021B702}" = Hidden Mysteries - White House
    "{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
    "{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4
    "{F7338FA3-DAB5-49B2-900D-0AFB5760C166}" = PC Probe II
    "{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
    "{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
    "{FB2A5FCC-B81B-48C2-A009-7804694D83E9}" = Adobe Encore CS4 Codecs
    "{FCBE0690-CBE1-4C60-87B0-4A70A6F5434E}" = LightScribe Template Labeler
    "{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
    "45A7283175C62FAC673F913C1F532C5361F97841" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
    "Adobe_b2d6abde968e6f277ddbfd501383e02" = Adobe Creative Suite 4 Master Collection
    "Adventure Chronicles_is1" = Adventure Chronicles
    "AMP Font Viewer" = AMP Font Viewer
    "Ancient Mosaic_is1" = Ancient Mosaic
    "AU7_is1" = Advanced Uninstaller PRO 2006 - version 7
    "avast!" = avast! Antivirus
    "Big City Adventure San Francisco_is1" = Big City Adventure San Francisco
    "Big City Adventure Sydney Australia_is1" = Big City Adventure Sydney Australia
    "ca_molimport_is1" = Movie Label XML Import Utility v1.6.2
    "ca_movielabel_is1" = Movie Label 2010 v5.1.1
    "CAL" = Canon Camera Access Library
    "CameraWindowDC" = Canon Utilities CameraWindow DC
    "CameraWindowDVC5" = Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
    "CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
    "CameraWindowLauncher" = Canon Utilities CameraWindow
    "Campfire Legends The Hookman_is1" = Campfire Legends The Hookman
    "Canon MOV Decoder" = Canon MOV Decoder
    "Canon MOV Encoder" = Canon MOV Encoder
    "Chuzzle Deluxe_is1" = Chuzzle Deluxe
    "ClassicPro" = ClassicPro© v1.12
    "com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
    "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
    "CPUID HWMonitor Pro_is1" = CPUID HWMonitor Pro 1.05
    "CSCLIB" = Canon Camera Support Core Library
    "Department 42 The Mystery of the Nine_is1" = Department 42 The Mystery of the Nine
    "Detective Stories Hollywood_is1" = Detective Stories Hollywood
    "DVD Shrink_is1" = DVD Shrink 3.2
    "EASEUS Partition Master Home Edition_is1" = EASEUS Partition Master 4.0 Home Edition
    "ENTERPRISE" = Microsoft Office Enterprise 2007
    "FLV Player" = FLV Player 2.0 (build 25)
    "Frostbow Home Inventory Lite_is1" = Frostbow Home Inventory 5 Lite
    "Gem Ball_is1" = Gem Ball
    "Ghost Town Mysteries - Bodie_is1" = Ghost Town Mysteries - Bodie
    "HdO Adventure Hollywood_is1" = HdO Adventure Hollywood
    "HdO Adventure Secrets of the Vatican_is1" = HdO Adventure Secrets of the Vatican
    "Hidden Expedition Titanic_is1" = Hidden Expedition Titanic
    "HijackThis" = HijackThis 2.0.2
    "HP Document Manager" = HP Document Manager 1.0
    "HP Imaging Device Functions" = HP Imaging Device Functions 10.0
    "HP Photosmart Essential" = HP Photosmart Essential 2.5
    "HP Smart Web Printing" = HP Smart Web Printing
    "HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0
    "HPExtendedCapabilities" = HP Customer Participation Program 10.0
    "HP-LaserJet 1018" = LaserJet 1018
    "HPOCR" = OCR Software by I.R.I.S. 10.0
    "ie8" = Windows Internet Explorer 8
    "Insider Tales The Stolen Venus_is1" = Insider Tales The Stolen Venus
    "InstallShield_{4B66765B-8596-4698-A208-E23D11D84AA7}" = Canon Camera WIA Driver 6.2.5
    "InstallShield_{68E7E8BD-2233-49BE-81D6-1A1FAF1B5196}" = Canon RAW Image Task for ZoomBrowser EX
    "Jewel Quest Mysteries 2 Trail of the Midnight Heart_is1" = Jewel Quest Mysteries 2 Trail of the Midnight Heart
    "Legend of Crystal Valley 1.00" = Legend of Crystal Valley 1.00
    "Little Shop - World Traveler_is1" = Little Shop - World Traveler
    "Lost Realms Legacy of the Sun Princess_is1" = Lost Realms Legacy of the Sun Princess
    "Luxor Amun Rising_is1" = Luxor Amun Rising
    "Luxor_is1" = Luxor
    "MailWasher_is1" = MailWasher 2.0.19 beta
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
    "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Mosaic Tomb of Mystery_is1" = Mosaic Tomb of Mystery
    "MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
    "Mozilla Firefox (3.5.3)" = Mozilla Firefox (3.5.3)
    "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
    "MyCamera" = Canon Utilities MyCamera
    "MyCameraDC" = Canon Utilities MyCamera DC
    "Mysterious City Vegas_is1" = Mysterious City Vegas
    "Mystery Age - The Imperial Staff1.0" = Mystery Age - The Imperial Staff
    "Nat Geo Adventure Lost City of Z_is1" = Nat Geo Adventure Lost City of Z
    "Neptunes Secret_is1" = Neptunes Secret
    "NVIDIA Drivers" = NVIDIA Drivers
    "OJOsoft MP4 Converter_is1" = OJOsoft MP4 Converter
    "Password Safe" = Password Safe
    "PhotoStitch" = Canon Utilities PhotoStitch
    "Princess Isabella A Witch's Curse 1.00" = Princess Isabella A Witch's Curse 1.00
    "Private Eye Greatest Unsolved Mysteries_is1" = Private Eye Greatest Unsolved Mysteries
    "RealPlayer 12.0" = RealPlayer
    "RemoteCaptureDC" = Canon Utilities RemoteCapture DC
    "RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
    "Righteous Kill Revenge of the Poet Killer_is1" = Righteous Kill Revenge of the Poet Killer
    "Romance of Rome_is1" = Romance of Rome
    "Router Screen Capture" = Router Screen Capture
    "Shattera2" = Shattera2
    "Shop for HP Supplies" = Shop for HP Supplies
    "Simple Port Forwarding" = Simple Port Forwarding
    "Slingo Mystery Whos Gold_is1" = Slingo Mystery Whos Gold
    "Spyware Doctor" = Spyware Doctor 6.1
    "SpywareBlaster_is1" = SpywareBlaster 4.2
    "ST6UNST #1" = Karen's Directory Printer
    "System Cleaner 5" = System Cleaner 5
    "SystemRequirementsLab" = System Requirements Lab
    "The Clockwork Man_is1" = The Clockwork Man
    "The Magicians Handbook II BlackLore_is1" = The Magicians Handbook II BlackLore
    "The Mystery of the Mary Celeste_is1" = The Mystery of the Mary Celeste
    "Torrent Harvester" = Torrent Harvester
    "Trojan Remover_is1" = Trojan Remover 6.8.1
    "TVP3XDrv" = KWorld TV713X BDA Driver
    "Tweak UI 2.10" = Tweak UI
    "VLC media player" = VLC media player 1.0.2
    "Winamp" = Winamp
    "WinASO Registry Optimizer 4.5.1_is1" = WinASO Registry Optimizer 4.5.1
    "Windows Media Format Runtime" = Windows Media Format 11 runtime
    "Windows Media Player" = Windows Media Player 11
    "Windows XP Service Pack" = Windows XP Service Pack 3
    "WinImage" = WinImage
    "WinRAR archiver" = WinRAR archiver
    "WMFDist11" = Windows Media Format 11 runtime
    "wmp11" = Windows Media Player 11
    "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
    "ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
    "ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

    ========== HKEY_CURRENT_USER Uninstall List ==========

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "uTorrent" = µTorrent
    "WinDirStat" = WinDirStat 1.1.2

    ========== Last 10 Event Log Errors ==========

    [ Antivirus Events ]
    Error - 10/21/2009 12:55:13 PM | Computer Name = SKISINTEL | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    C:\WINDOWS\SYSTEM32\ZGZWO.DLL failed, 00000005.

    Error - 10/21/2009 6:35:58 PM | Computer Name = SKISINTEL | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    C:\WINDOWS\system32\zgzwo.dll failed, 00000005.

    Error - 10/21/2009 6:44:13 PM | Computer Name = SKISINTEL | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    C:\WINDOWS\SYSTEM32\ZGZWO.DLL failed, 00000005.

    Error - 10/22/2009 10:50:43 PM | Computer Name = SKISINTEL | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    C:\WINDOWS\SYSTEM32\ZGZWO.DLL failed, 00000005.

    Error - 10/22/2009 11:10:20 PM | Computer Name = SKISINTEL | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    C:\WINDOWS\SYSTEM32\ZGZWO.DLL failed, 00000005.

    Error - 10/22/2009 11:30:33 PM | Computer Name = SKISINTEL | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    C:\WINDOWS\SYSTEM32\ZGZWO.DLL failed, 00000005.

    Error - 10/22/2009 11:54:26 PM | Computer Name = SKISINTEL | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    C:\WINDOWS\SYSTEM32\ZGZWO.DLL failed, 00000005.

    Error - 10/23/2009 12:04:50 PM | Computer Name = SKISINTEL | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    C:\WINDOWS\SYSTEM32\ZGZWO.DLL failed, 00000005.

    Error - 10/23/2009 6:40:39 PM | Computer Name = SKISINTEL | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    C:\WINDOWS\system32\zgzwo.dll failed, 00000005.

    Error - 10/23/2009 6:50:22 PM | Computer Name = SKISINTEL | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    C:\WINDOWS\SYSTEM32\ZGZWO.DLL failed, 00000005.

    [ Application Events ]
    Error - 10/13/2009 11:48:07 AM | Computer Name = SKISINTEL | Source = Application Error | ID = 1000
    Description = Faulting application casual.exe, version 0.0.0.0, faulting module
    casual.exe, version 0.0.0.0, fault address 0x000ae1da.

    Error - 10/16/2009 4:04:00 PM | Computer Name = SKISINTEL | Source = pctsSvc.exe | ID = 0
    Description =

    Error - 10/21/2009 4:36:03 PM | Computer Name = SKISINTEL | Source = Application Error | ID = 1000
    Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
    module unknown, version 0.0.0.0, fault address 0x044229c0.

    Error - 10/24/2009 8:33:58 AM | Computer Name = SKISINTEL | Source = Application Error | ID = 1000
    Description = Faulting application shattera.exe, version 0.0.0.0, faulting module
    shattera.exe, version 0.0.0.0, fault address 0x000f8717.

    Error - 10/24/2009 8:51:23 PM | Computer Name = SKISINTEL | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: A connection with the server could not be established

    Error - 10/24/2009 8:51:23 PM | Computer Name = SKISINTEL | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: This network connection does not exist.

    Error - 10/24/2009 8:51:30 PM | Computer Name = SKISINTEL | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: This network connection does not exist.

    Error - 10/24/2009 10:22:16 PM | Computer Name = SKISINTEL | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: A connection with the server could not be established

    Error - 10/24/2009 10:22:16 PM | Computer Name = SKISINTEL | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: This network connection does not exist.

    Error - 10/24/2009 10:22:17 PM | Computer Name = SKISINTEL | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: This network connection does not exist.

    [ System Events ]
    Error - 10/25/2009 10:11:48 AM | Computer Name = SKISINTEL | Source = DCOM | ID = 10005
    Description = DCOM got error "%1084" attempting to start the service EventSystem
    with arguments " " in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

    Error - 10/25/2009 10:19:40 AM | Computer Name = SKISINTEL | Source = Service Control Manager | ID = 7022
    Description = The HP CUE DeviceDiscovery Service service hung on starting.

    Error - 10/25/2009 10:35:42 AM | Computer Name = SKISINTEL | Source = Disk | ID = 262151
    Description = The device, \Device\Harddisk0\D, has a bad block.

    Error - 10/25/2009 10:35:44 AM | Computer Name = SKISINTEL | Source = Disk | ID = 262151
    Description = The device, \Device\Harddisk0\D, has a bad block.

    Error - 10/25/2009 10:35:47 AM | Computer Name = SKISINTEL | Source = Disk | ID = 262151
    Description = The device, \Device\Harddisk0\D, has a bad block.

    Error - 10/25/2009 11:41:57 AM | Computer Name = SKISINTEL | Source = Disk | ID = 262151
    Description = The device, \Device\Harddisk0\D, has a bad block.

    Error - 10/25/2009 11:42:00 AM | Computer Name = SKISINTEL | Source = Disk | ID = 262151
    Description = The device, \Device\Harddisk0\D, has a bad block.

    Error - 10/25/2009 11:42:03 AM | Computer Name = SKISINTEL | Source = Disk | ID = 262151
    Description = The device, \Device\Harddisk0\D, has a bad block.

    Error - 10/25/2009 3:37:23 PM | Computer Name = SKISINTEL | Source = Service Control Manager | ID = 7022
    Description = The HP CUE DeviceDiscovery Service service hung on starting.

    Error - 10/25/2009 9:13:15 PM | Computer Name = SKISINTEL | Source = Service Control Manager | ID = 7022
    Description = The HP CUE DeviceDiscovery Service service hung on starting.


    < End of report >
     
  20. 2009/10/25
    Ski52

    Ski52 Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    176
    Likes Received:
    1
    The OTL file:

    OTL logfile created on: 10/25/2009 11:43:35 PM - Run 1
    OTL by OldTimer - Version 3.0.22.1 Folder = D:\
    Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    2.00 Gb Total Physical Memory | 1.42 Gb Available Physical Memory | 71.24% Memory free
    3.85 Gb Paging File | 3.34 Gb Available in Paging File | 86.75% Paging File free
    Paging file location(s): C:\pagefile.sys 2046 2046 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 51.77 Gb Total Space | 25.33 Gb Free Space | 48.93% Space Free | Partition Type: NTFS
    Drive D: | 44.54 Gb Total Space | 25.16 Gb Free Space | 56.49% Space Free | Partition Type: NTFS
    Drive E: | 20.51 Gb Total Space | 13.63 Gb Free Space | 66.46% Space Free | Partition Type: NTFS
    Drive F: | 20.51 Gb Total Space | 10.85 Gb Free Space | 52.90% Space Free | Partition Type: NTFS
    Drive G: | 11.71 Gb Total Space | 11.65 Gb Free Space | 99.49% Space Free | Partition Type: NTFS
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: SKISINTEL
    Current User Name: Ski
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: On
    Skip Microsoft Files: On
    File Age = 14 Days
    Output = Standard
    Quick Scan

    ========== Processes (SafeList) ==========

    PRC - [2009/10/25 23:25:32 | 00,521,728 | ---- | M] (OldTimer Tools) -- D:\OTL.exe
    PRC - [2009/10/21 16:22:10 | 00,124,216 | ---- | M] (Doctor Web, Ltd.) -- C:\Documents and Settings\Ski\Local Settings\temp\dc31284348\pbts6e.exe
    PRC - [2009/09/12 20:31:54 | 00,908,280 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
    PRC - [2009/08/17 12:07:23 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
    PRC - [2009/08/17 12:07:17 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
    PRC - [2009/08/17 12:07:01 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    PRC - [2009/08/17 12:04:21 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    PRC - [2009/08/17 11:58:55 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    PRC - [2009/06/30 06:58:31 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
    PRC - [2009/06/10 08:28:50 | 00,168,004 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe
    PRC - [2009/02/25 11:21:56 | 00,073,728 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    PRC - [2008/04/13 20:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
    PRC - [2007/10/24 23:57:56 | 16,855,552 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.EXE
    PRC - [2007/01/31 14:55:42 | 00,096,370 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe

    ========== Win32 Services (SafeList) ==========

    SRV - [2009/10/16 16:29:22 | 00,348,824 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService [On_Demand | Stopped])
    SRV - [2009/08/17 12:07:17 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
    SRV - [2009/08/17 12:07:01 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
    SRV - [2009/08/17 12:04:21 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
    SRV - [2009/08/17 11:58:55 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
    SRV - [2009/07/31 18:41:26 | 00,655,624 | ---- | M] (Acresso Software Inc.) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service [On_Demand | Stopped])
    SRV - [2009/07/22 22:44:48 | 01,097,096 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService [On_Demand | Stopped])
    SRV - [2009/06/24 11:01:26 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1c9f4dcaae7aea4 [Auto | Stopped])
    SRV - [2009/06/10 08:28:50 | 00,168,004 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe -- (nvsvc [Auto | Running])
    SRV - [2009/06/04 10:53:02 | 00,066,048 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe -- (getPlus(R) Helper [On_Demand | Stopped])
    SRV - [2009/02/25 11:21:56 | 00,073,728 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running])
    SRV - [2008/11/04 01:06:28 | 00,441,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
    SRV - [2008/08/15 05:46:20 | 00,284,016 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe -- (Adobe Version Cue CS4 [On_Demand | Stopped])
    SRV - [2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
    SRV - [2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
    SRV - [2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
    SRV - [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
    SRV - [2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
    SRV - [2008/04/13 20:12:02 | 00,105,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\p2pgasvc.dll -- (p2pgasvc [On_Demand | Stopped])
    SRV - [2008/04/13 20:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
    SRV - [2008/04/13 20:11:48 | 00,100,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\6to4svc.dll -- (6to4 [Auto | Running])
    SRV - [2008/03/07 16:04:10 | 00,217,088 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll -- (hpqcxs08 [On_Demand | Running])
    SRV - [2008/01/22 11:13:26 | 00,275,752 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService [On_Demand | Stopped])
    SRV - [2007/11/06 21:16:54 | 00,139,264 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll -- (hpqddsvc [Auto | Running])
    SRV - [2007/10/14 21:15:52 | 00,663,552 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL -- (HPSLPSVC [Auto | Running])
    SRV - [2007/01/31 14:55:42 | 00,096,370 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8 [Auto | Running])
    SRV - [2006/11/08 16:35:38 | 00,053,248 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\System32\HPZipm12.dll -- (Pml Driver HPZ12 [Auto | Running])
    SRV - [2006/11/08 16:35:36 | 00,043,520 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\System32\HPZinw12.dll -- (Net Driver HPZ12 [Auto | Running])
    SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
    SRV - [2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])

    ========== Modules (SafeList) ==========

    MOD - [2009/10/25 23:25:32 | 00,521,728 | ---- | M] (OldTimer Tools) -- D:\OTL.exe
    MOD - [2008/05/13 10:13:36 | 00,077,824 | ---- | M] (SuperAdBlocker.com) -- C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
    MOD - [2008/04/13 20:12:51 | 01,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM32\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM32\blank.htm
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/|http://mrcs.phpbb3now.com/index.php?sid=4896f2a0295c726f403fe250e657741e|http://www.xtremepccentral.com/|http://www.windowsbbs.com/index.php|https://www.sodifferent.biz/|http://www.funfile.org/index.php|http://www.reflexive.com/ "
    FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
    FF - prefs.js..extensions.enabledItems: 6
    FF - prefs.js..extensions.enabledItems: 2
    FF - prefs.js..extensions.enabledItems: 29
    FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:3.3.17
    FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
    FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3

    FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/08/29 20:57:34 | 00,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/10/23 07:58:07 | 00,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/10/15 13:47:28 | 00,000,000 | ---D | M]

    [2009/06/21 14:05:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\mozilla\Extensions
    [2009/06/21 14:05:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
    [2009/10/25 21:39:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\mozilla\Firefox\Profiles\4bz8esua.default\extensions
    [2009/10/19 01:17:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\mozilla\Firefox\Profiles\4bz8esua.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
    [2009/08/30 13:03:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\mozilla\Firefox\Profiles\4bz8esua.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    [2009/06/27 10:05:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\mozilla\Firefox\Profiles\4bz8esua.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
    [2009/06/21 14:05:32 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
    [2009/09/12 20:31:57 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    [2009/09/12 20:31:53 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
    [2009/09/12 20:31:53 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
    [2009/09/12 20:31:55 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
    [2009/02/27 13:13:42 | 00,103,792 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
    [2009/07/14 09:21:03 | 00,136,768 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nppl3260.dll
    [2009/07/14 09:21:27 | 00,008,192 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprjplug.dll
    [2009/07/14 09:20:57 | 00,094,208 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
    [2009/06/04 10:53:02 | 00,031,944 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\mozilla firefox\plugins\np_gp.dll
    [2009/07/30 03:24:20 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
    [2009/07/30 03:24:20 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
    [2009/07/30 03:24:20 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
    [2009/07/30 03:24:20 | 00,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
    [2009/07/30 03:24:20 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
    [2009/07/30 03:24:20 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
    [2009/07/30 03:24:20 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

    O1 HOSTS File: (1300 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
    O1 - Hosts: 127.0.0.1 localhost
    O1 - Hosts: 127.0.0.1 activate.adobe.com
    O1 - Hosts: 127.0.0.1 practivate.adobe.com
    O1 - Hosts: 127.0.0.1 ereg.adobe.com
    O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
    O1 - Hosts: 127.0.0.1 wip3.adobe.com
    O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
    O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
    O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
    O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
    O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
    O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
    O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
    O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
    O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
    O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
    O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
    O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
    O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
    O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
    O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
    O4 - HKLM..\Run: [SkyTel] C:\WINDOWS\SkyTel.EXE (Realtek Semiconductor Corp.)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 01 00 00 00 [binary data]
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
    O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
    O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
    O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
    O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
    O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
    O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\System32\pnrpnsp.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\WINDOWS\System32\pnrpnsp.dll (Microsoft Corporation)
    O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
    O15 - HKCU\..Trusted Domains: 25 domain(s) and sub-domain(s) not assigned to a zone.
    O15 - HKCU\..Trusted Ranges: Range1979 ([http] in Trusted sites)
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1245381457687 (WUWebControl Class)
    O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\ipp - No CLSID value found
    O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp - No CLSID value found
    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
    O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
    O24 - Desktop Components:0 (My Current Home Page) - About:Home
    O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
    O31 - SafeBoot: AlternateShell - cmd.exe
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2009/06/18 22:19:19 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck) - File not found
    O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
    O34 - HKLM BootExecute: (*) - File not found
    O35 - comfile [open] -- "%1" %* File not found
    O35 - exefile [open] -- "%1" %* File not found

    NetSvcs: 6to4 - C:\WINDOWS\System32\6to4svc.dll (Microsoft Corporation)
    NetSvcs: Ias - Service key not found. File not found
    NetSvcs: Iprip - Service key not found. File not found
    NetSvcs: Irmon - Service key not found. File not found
    NetSvcs: NWCWorkstation - Service key not found. File not found
    NetSvcs: Nwsapagent - Service key not found. File not found
    NetSvcs: WmdmPmSp - Service key not found. File not found
    NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)

    ========== Files/Folders - Created Within 14 Days ==========

    [3 C:\WINDOWS\*.tmp files]
    [2009/10/14 16:52:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DVD Shrink
    [2009/10/25 10:34:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    [2009/10/16 16:04:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Tools
    [2009/10/24 22:57:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
    [2009/10/19 14:02:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ski\Application Data\Awem
    [2009/10/12 23:39:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ski\Application Data\Games
    [2009/10/12 18:00:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ski\Application Data\GARMIN
    [2009/10/16 13:59:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ski\Application Data\GTM_Bodie
    [2009/10/25 10:34:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ski\Application Data\Malwarebytes
    [2009/10/16 16:04:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ski\Application Data\PC Tools
    [2009/10/16 11:44:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ski\Application Data\Pointstone
    [2009/10/24 22:57:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ski\Application Data\SUPERAntiSpyware.com
    [2009/10/16 20:28:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ski\Application Data\VampireSaga
    [2009/10/16 15:30:42 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
    [2009/10/12 17:54:57 | 00,000,000 | ---D | C] -- C:\Program Files\DIFX
    [2009/10/12 18:56:04 | 00,000,000 | ---D | C] -- C:\Program Files\DirPrn
    [2009/10/14 16:52:07 | 00,000,000 | ---D | C] -- C:\Program Files\DVD Shrink
    [2009/10/12 17:54:57 | 00,000,000 | ---D | C] -- C:\Program Files\Garmin
    [2009/10/12 18:00:41 | 00,000,000 | ---D | C] -- C:\Program Files\Garmin GPS Plugin
    [2009/10/25 10:34:19 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2009/10/16 15:30:36 | 00,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor
    [2009/10/16 15:48:57 | 00,000,000 | ---D | C] -- C:\Program Files\SpywareBlaster
    [2009/10/24 22:57:08 | 00,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
    [2009/10/25 22:41:37 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood
    [2009/10/25 22:37:12 | 00,000,000 | --SD | C] -- C:\ComboFix
    [2009/10/25 21:05:44 | 19,515,960 | ---- | C] (Doctor Web, Ltd.) -- C:\Documents and Settings\Ski\Desktop\drweb-cureit.exe
    [2009/10/25 10:34:21 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2009/10/25 10:34:19 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2009/10/24 20:48:22 | 00,000,000 | RHSD | C] -- C:\cmdcons
    [2009/10/24 20:46:57 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2009/10/23 16:54:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ski\My Documents\Dziubinski 2202 Macedo_dbfiles
    [2009/10/22 23:17:22 | 00,000,000 | ---D | C] -- C:\Tools
    [2009/10/21 19:50:37 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Ski\My Documents\My Music
    [2009/10/21 19:46:58 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Ski\My Documents\My Pictures
    [2009/10/16 16:29:21 | 00,159,600 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys
    [2009/10/16 16:04:56 | 00,206,256 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys
    [2009/10/16 16:04:56 | 00,086,888 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTAppEvent.sys
    [2009/10/16 16:04:49 | 00,064,392 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplsg.sys
    [2009/10/14 14:27:40 | 00,000,000 | --SD | C] -- C:\Documents and Settings\Ski\My Documents\My Data Sources
    [2009/10/12 17:54:07 | 00,000,000 | ---D | C] -- C:\Garmin

    ========== Files - Modified Within 14 Days ==========

    [1 C:\WINDOWS\System32\*.tmp files]
    [3 C:\WINDOWS\*.tmp files]
    [2009/10/25 23:45:22 | 02,607,136 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.dat
    [2009/10/25 23:03:00 | 00,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
    [2009/10/25 22:42:04 | 00,000,032 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.idx
    [2009/10/25 21:15:43 | 00,441,454 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2009/10/25 21:15:43 | 00,071,264 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2009/10/25 21:15:42 | 00,521,942 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
    [2009/10/25 21:12:21 | 00,235,289 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
    [2009/10/25 21:11:54 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2009/10/25 21:11:27 | 00,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
    [2009/10/25 21:11:01 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
    [2009/10/25 21:10:23 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2009/10/25 21:05:08 | 19,515,960 | ---- | M] (Doctor Web, Ltd.) -- C:\Documents and Settings\Ski\Desktop\drweb-cureit.exe
    [2009/10/25 10:34:24 | 00,000,746 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2009/10/24 22:57:15 | 00,000,830 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2009/10/24 22:36:57 | 00,000,256 | ---- | M] () -- C:\WINDOWS\system.ini
    [2009/10/24 20:48:29 | 00,000,281 | RHS- | M] () -- C:\boot.ini
    [2009/10/24 18:13:19 | 00,524,288 | ---- | M] () -- C:\Documents and Settings\Ski\Desktop\dds.scr
    [2009/10/23 18:46:32 | 02,661,340 | -H-- | M] () -- C:\Documents and Settings\Ski\Local Settings\Application Data\IconCache.db
    [2009/10/23 18:38:08 | 00,001,116 | RH-- | M] () -- C:\WINDOWS\EPMBatch.ept
    [2009/10/23 16:56:31 | 00,006,630 | ---- | M] () -- C:\Documents and Settings\Ski\My Documents\Dziubinski 2202 Macedo.fshi
    [2009/10/23 16:53:41 | 00,012,149 | ---- | M] () -- C:\Documents and Settings\Ski\My Documents\Sample Inventory.fshi
    [2009/10/23 11:37:05 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
    [2009/10/21 18:39:48 | 00,000,537 | ---- | M] () -- C:\WINDOWS\win.ini
    [2009/10/21 18:39:48 | 00,000,211 | ---- | M] () -- C:\Boot.bak
    [2009/10/17 16:17:21 | 00,002,493 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Paint Shop Pro 7.lnk
    [2009/10/16 16:29:21 | 00,159,600 | ---- | M] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys
    [2009/10/15 21:35:52 | 00,000,507 | ---- | M] () -- C:\WINDOWS\WPB95.INI

    ========== Files - No Company Name ==========
    [2009/10/25 22:41:44 | 02,598,944 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox.dat
    [2009/10/25 22:41:44 | 00,000,032 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox.idx
    [2009/10/25 10:34:24 | 00,000,746 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2009/10/24 22:57:15 | 00,000,830 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2009/10/24 20:48:29 | 00,000,211 | ---- | C] () -- C:\Boot.bak
    [2009/10/24 20:48:25 | 00,260,272 | ---- | C] () -- C:\cmldr
    [2009/10/24 18:13:43 | 00,524,288 | ---- | C] () -- C:\Documents and Settings\Ski\Desktop\dds.scr
    [2009/10/23 18:31:30 | 00,001,116 | RH-- | C] () -- C:\WINDOWS\EPMBatch.ept
    [2009/10/23 16:54:22 | 00,006,630 | ---- | C] () -- C:\Documents and Settings\Ski\My Documents\Dziubinski 2202 Macedo.fshi
    [2009/10/16 16:04:56 | 00,007,396 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctcore.cat
    [2009/08/26 11:23:57 | 00,005,632 | ---- | C] () -- C:\Documents and Settings\Ski\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2009/08/14 11:48:43 | 00,000,000 | ---- | C] () -- C:\WINDOWS\acroread.ini
    [2009/08/12 16:18:41 | 00,162,304 | ---- | C] () -- C:\WINDOWS\System32\ztvunrar36.dll
    [2009/08/12 16:18:41 | 00,077,312 | ---- | C] () -- C:\WINDOWS\System32\ztvunace26.dll
    [2009/08/12 16:18:40 | 00,153,088 | ---- | C] () -- C:\WINDOWS\System32\UNRAR3.dll
    [2009/08/12 16:18:40 | 00,075,264 | ---- | C] () -- C:\WINDOWS\System32\unacev2.dll
    [2009/08/06 17:46:08 | 00,014,848 | ---- | C] () -- C:\WINDOWS\System32\EuEpmGdi.dll
    [2009/08/06 17:46:08 | 00,008,704 | ---- | C] () -- C:\WINDOWS\System32\epmntdrv.sys
    [2009/08/06 17:46:08 | 00,003,072 | ---- | C] () -- C:\WINDOWS\System32\EuGdiDrv.sys
    [2009/08/05 23:48:14 | 00,000,001 | ---- | C] () -- C:\WINDOWS\sslzdlt.dll
    [2009/08/05 23:48:12 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
    [2009/08/05 21:05:54 | 00,013,312 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
    [2009/07/26 18:28:04 | 02,661,340 | -H-- | C] () -- C:\Documents and Settings\Ski\Local Settings\Application Data\IconCache.db
    [2009/06/22 16:04:31 | 00,001,324 | ---- | C] () -- C:\WINDOWS\TVP3XDrv.ini
    [2009/06/22 16:04:22 | 00,003,072 | R--- | C] () -- C:\WINDOWS\System32\34CoInstaller.dll
    [2009/06/22 16:04:16 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll
    [2009/06/22 14:46:15 | 00,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
    [2009/06/19 13:44:00 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
    [2009/06/19 13:12:47 | 00,000,507 | ---- | C] () -- C:\WINDOWS\WPB95.INI
    [2009/06/19 10:18:13 | 00,106,496 | ---- | C] () -- C:\WINDOWS\System32\VSHP1018.DLL
    [2009/06/19 10:09:41 | 00,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
    [2009/06/19 10:03:18 | 00,002,228 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
    [2009/06/18 23:04:08 | 00,054,784 | ---- | C] () -- C:\Documents and Settings\Ski\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    [2009/06/18 22:56:54 | 00,024,576 | R--- | C] () -- C:\WINDOWS\System32\AsIO.dll
    [2009/06/18 22:56:54 | 00,012,664 | R--- | C] () -- C:\WINDOWS\System32\drivers\AsIO.sys
    [2009/06/18 22:56:52 | 00,012,096 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp64.sys
    [2009/06/18 22:56:52 | 00,010,304 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp32.sys
    [2009/06/18 22:42:18 | 00,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
    [2009/06/18 22:42:17 | 00,010,287 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
    [2009/06/18 22:42:11 | 00,012,536 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
    [2009/06/18 22:36:53 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Ski\Application Data\desktop.ini
    [2009/06/18 18:08:18 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini
    [2008/10/07 09:13:30 | 00,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
    [2008/10/07 09:13:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
    [2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
    [2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
    [2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
    [2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
    [2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
    [2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
    [2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
    [2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
    [2004/08/04 08:00:00 | 00,006,656 | ---- | C] () -- C:\WINDOWS\System32\lpcio.dll
    [2004/08/04 08:00:00 | 00,000,537 | ---- | C] () -- C:\WINDOWS\win.ini
    [2004/08/04 08:00:00 | 00,000,256 | ---- | C] () -- C:\WINDOWS\system.ini

    ========== LOP Check ==========

    [2009/10/25 10:34:19 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
    [2009/10/07 23:31:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AdventureChronicles1
    [2009/07/31 19:47:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ALM
    [2009/08/27 11:44:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\blg
    [2009/10/14 16:52:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DVD Shrink
    [2009/07/31 21:20:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
    [2009/10/10 14:30:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GameHouse
    [2009/07/10 11:05:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gamers Digital
    [2009/08/26 14:17:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intenium
    [2009/06/23 07:59:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\JollyBear
    [2009/06/30 14:50:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LightScribe
    [2009/09/30 16:20:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Merscom
    [2009/07/12 13:54:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MumboJumbo
    [2009/10/03 21:55:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NeptunesAdve
    [2009/09/25 13:15:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
    [2009/08/30 17:45:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Princess Isabella
    [2009/08/15 20:14:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Reflexive
    [2009/08/31 16:45:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games
    [2009/08/10 11:39:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Simply Super Software
    [2009/09/18 19:02:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sony
    [2009/08/19 16:00:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpinTop Games
    [2009/10/21 18:25:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
    [2009/10/10 16:38:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
    [2009/10/25 10:34:28 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Ski\Application Data
    [2009/09/28 16:14:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Acronis
    [2009/08/31 16:54:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Ahead
    [2009/07/24 00:20:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Aisle 5 Games, Inc
    [2009/06/19 09:34:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Alawar
    [2009/10/11 10:53:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\AMPSoft
    [2009/10/19 14:02:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Awem
    [2009/08/27 11:44:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\blg
    [2009/10/11 09:57:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Blitware
    [2009/08/08 11:31:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\cerasus.media
    [2009/10/11 09:37:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\dvdcss
    [2009/10/08 20:11:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Frostbow
    [2009/09/19 14:15:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\funkitron
    [2009/08/02 10:40:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\GameInvest
    [2009/07/10 11:05:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Gamers Digital
    [2009/10/12 23:39:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Games
    [2009/10/12 18:00:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\GARMIN
    [2009/08/29 14:23:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Gold Casual Games
    [2009/10/16 13:59:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\GTM_Bodie
    [2009/10/05 13:12:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\HdO Adventure
    [2009/07/05 23:18:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\IronCode
    [2009/09/15 13:35:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\iWin
    [2009/06/22 15:49:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\KWorld Multimedia
    [2009/08/21 11:10:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\MA
    [2009/06/25 18:12:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\MagicBall4
    [2009/10/25 18:26:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\MailWasher
    [2009/09/30 16:20:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Merscom
    [2009/10/08 20:39:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Movie Label
    [2009/07/02 16:17:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Opera
    [2009/09/25 13:15:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\PlayFirst
    [2009/10/16 11:44:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Pointstone
    [2009/07/17 21:15:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\PopCapv1005eni
    [2009/08/05 21:07:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Publish Providers
    [2009/08/17 15:10:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Reflexivev1001
    [2009/10/21 19:11:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\RobinsonCrusoeREF
    [2009/08/03 23:05:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\she_is_a_shadow
    [2009/08/12 16:18:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Simply Super Software
    [2009/09/18 19:08:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Sony
    [2009/08/05 20:56:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Sony Setup
    [2009/10/08 00:11:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Total Eclipse
    [2009/06/21 14:23:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Twintale Entertainment
    [2009/06/19 15:07:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\URSE Games
    [2009/10/23 20:33:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\uTorrent
    [2009/10/16 20:28:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\VampireSaga
    [2009/09/08 14:51:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\Windows Home Server
    [2009/07/31 22:09:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\YoudaGames
    [2009/10/10 16:44:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ski\Application Data\ZoomBrowser EX
    [2004/08/04 08:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
    [2009/10/25 21:11:27 | 00,000,882 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    [2009/10/25 23:03:00 | 00,000,886 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    [2009/10/25 21:11:01 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.exe >

    < %systemroot%\system32\eventlog.dll >
    [2008/04/13 20:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\eventlog.dll
    [1 C:\WINDOWS\system32\*.tmp files]

    < %systemroot%\system32\scecli.dll >
    [2008/04/13 20:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\scecli.dll
    [1 C:\WINDOWS\system32\*.tmp files]

    < %systemroot%\netlogon.dll >

    < %systemroot%\system32\cngaudit.dll >

    < %systemroot%\system32\sceclt.dll >

    < %systemroot%\ntelogon.dll >

    < %systemroot%\system32\logevent.dll >

    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
    @Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7FCB9D0D
    @Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5345C8F6
    @Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4FE42FFC
    @Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:40D8F125
    @Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
    @Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:870649A4
    @Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:81523426
    @Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E91ADC66
    @Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3D36932D
    < End of report >
     
  21. 2009/10/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following

      Code:
      :OTL
      PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
      PRC - [2009/10/21 16:22:10 | 00,124,216 | ---- | M] (Doctor Web, Ltd.) -- C:\Documents and Settings\Ski\Local Settings\temp\dc31284348\pbts6e.exe
      IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM32\blank.htm
      IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM32\blank.htm
      O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
      O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
      O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
      O15 - HKCU\..Trusted Domains: 25 domain(s) and sub-domain(s) not assigned to a zone.
      O15 - HKCU\..Trusted Ranges: Range1979 ([http] in Trusted sites)
      O18 - Protocol\Handler\msdaipp - No CLSID value found
      
      
      :Services
      
      :Reg
      
      :Files
      C:\Documents and Settings\Ski\Local Settings\temp\dc31284348\pbts6e.exe
      
      :Commands
      [purity]
      [emptytemp]
      [Reboot]
      [resethosts]
      
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.