and whenever i open a new window (like my computer etc ) i am getting a message from my avg8.0 free editon resident shield like
" Threat detected
file name c:\WINDOWS\system 32...."
and many more messages from my resident shield .i dont know how to remove this things
and i am having avg and malwarebytes and itried to remove it ,but nothing seems to work for me.
and my computer has been dramatically slowed down even at start ups.
and i had posted the scan results of deckard system scanner and hijack this log file along with it at the bottom
Deckard's System Scanner v20071014.68
Run by mars on 2008-08-07 06:41:25
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
8: 2008-08-07 01:11:30 UTC - RP8 - Deckard's System Scanner Restore Point
7: 2008-08-07 00:07:43 UTC - RP7 - System Checkpoint
6: 2008-08-05 23:37:44 UTC - RP6 - System Checkpoint
5: 2008-08-04 23:28:32 UTC - RP5 - Removed USBCV13
4: 2008-08-04 23:24:52 UTC - RP4 - Installed USBCV13
-- First Restore Point --
1: 2008-08-03 02:07:20 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as mars.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:43:32 AM, on 8/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI\WebPAM\jetty\extra\win32\Wrapper.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ATI\WebPAM\_jvm\bin\java.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\utorrent-1.8-rc6.upx.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\setup files\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\mars.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.in/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: 202.165.102.205 972.aksjd11.com
O1 - Hosts: 202.165.102.205 w3og.cn
O1 - Hosts: 203.208.35.100 qazc.fourtw.cn
O1 - Hosts: 203.208.35.100 www.aujoy.cn
O1 - Hosts: 203.208.35.101 www.hao601.cn
O1 - Hosts: 203.208.35.101 www.psp476.cn
O1 - Hosts: 72.14.235.99 222.1212l112.net
O1 - Hosts: 72.14.235.99 444.1212l112.netn
O1 - Hosts: 72.14.235.99 555.1212l112.net
O1 - Hosts: 72.14.235.99 111.1212l112.net
O1 - Hosts: 65.55.21.250 111.3243l24.com
O1 - Hosts: 65.55.21.250 222.3243l24.com
O1 - Hosts: 65.55.21.250 333.3243l24.com
O1 - Hosts: 125.64.8.112 kao2.gmwo03.com
O1 - Hosts: 125.64.8.112 kao.gmwo06.com
O1 - Hosts: 125.64.8.112 444.gmwo07.com
O1 - Hosts: 116.252.185.15 ru.update365.us
O1 - Hosts: 116.252.185.15 ad.update365.us
O1 - Hosts: 207.46.232.182 popmails.net
O1 - Hosts: 203.208.37.99 3.goodhh.com
O1 - Hosts: 220.181.37.55 down.rwixr.com
O1 - Hosts: 160.79.42.52 www.xdj2008.com
O1 - Hosts: 63.175.76.152 www.revtr.cn
O1 - Hosts: 219.133.40.91 qq.ljsll.com
O1 - Hosts: 203.208.35.102 www.aassccwe.cn
O1 - Hosts: 209.132.177.50 973.aksjd11.com
O1 - Hosts: 209.132.177.50 974.aksjd11.com
O1 - Hosts: 209.132.177.50 971.aksjd11.com
O1 - Hosts: 209.132.177.50 975.aksjd11.com
O1 - Hosts: 72.14.235.104 user1.12-39.net
O1 - Hosts: 72.14.235.147 www.infomt.net
O1 - Hosts: 192.150.18.101 ata1.sysions.net
O1 - Hosts: 192.150.18.101 ata2.sysions.net
O1 - Hosts: 192.150.18.101 ata3.sysions.net
O1 - Hosts: 192.150.18.101 ata4.sysions.net
O1 - Hosts: 193.120.42.226 8nnnnn99.cn
O1 - Hosts: 24.39.54.34 www.haoaoao.cn
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: detxbiua.dll - {20618412-C528-C784-C056-C164D1F7C502} - C:\WINDOWS\system32\detxbiua.dll (file missing)
O2 - BHO: ijdybpaw.dll - {2A698452-C5D8-C584-C256-C264C987C5A2} - C:\WINDOWS\system32\ijdybpaw.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: pqzfajke.dll - {60A345CD-ABCD-EFAB-CDEF-ABCD01020306} - C:\WINDOWS\system32\pqzfajke.dll (file missing)
O2 - BHO: zywmgime.dll - {7319A1F1-9410-9654-3201-345FFA349137} - C:\WINDOWS\system32\zywmgime.dll (file missing)
O2 - BHO: (no name) - {813DD04F-261A-428A-8309-3F541B2D2564} - c:\windows\system32\ziaashl.dll
O2 - BHO: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll (file missing)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [3PMmUpdate] rundll32 "C:\WINDOWS\Update.dll",Main
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1216438706155
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2C37B9D-5325-4248-9133-6C46B1F469C4}: NameServer = 218.248.255.146,218.248.240.46
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: tisqdtyu.dll,NTNJXSJTVC.dll,comremo.dll,myasemt.dll,googleons.dll,welycz.dll,jsnoer.dll,ezcron.dll,joliom.dll,fackwir.dll,caotxb.dll,ceshleo.dll,nhmxejkl.dll,woswelc.dll,avgrsstx.dll, mssetd.dll tiplict.dll businesn.dll esceps.dll keyiftp.dll baccops.dll aliens.dll offscrl.dll cmonos.dll wdhotem.dll xpsbos.dll manleu.dll squalle.dll therbrek.dll jolin0.dll
O20 - Winlogon Notify: obklooga - C:\WINDOWS\SYSTEM32\ziaashl.dll
O21 - SSODL: DesktopWin - {DA191DE0-AA86-4ED0-4B87-292A3D48BE99} - C:\WINDOWS\AppPatch\DesktopWin.dll
O21 - SSODL: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ATI WebPAM (ATIWebPAM) - Unknown owner - C:\Program Files\ATI\WebPAM\jetty\extra\win32\Wrapper.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
--
End of file - 10291 bytes
-- File Associations -----------------------------------------------------------
.reg - regfile - shell\open\command - regedit.exe "%1" %*
.scr - scrfile - shell\open\command - "%1" %*
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
All drivers whitelisted.
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {36FC9E60-C465-11CF-8056-444553540000}
Description: Universal Serial Bus (USB) Controller
Device ID: PCI\VEN_1002&DEV_4374&SUBSYS_2A31103C&REV_80\3&267A616A&0&98
Manufacturer: (Standard USB Host Controller)
Name: Universal Serial Bus (USB) Controller
PNP Device ID: PCI\VEN_1002&DEV_4374&SUBSYS_2A31103C&REV_80\3&267A616A&0&98
Service:
Class GUID: {36FC9E60-C465-11CF-8056-444553540000}
Description: Universal Serial Bus (USB) Controller
Device ID: PCI\VEN_1002&DEV_4375&SUBSYS_2A31103C&REV_80\3&267A616A&0&99
Manufacturer: (Standard USB Host Controller)
Name: Universal Serial Bus (USB) Controller
PNP Device ID: PCI\VEN_1002&DEV_4375&SUBSYS_2A31103C&REV_80\3&267A616A&0&99
Service:
Class GUID: {36FC9E60-C465-11CF-8056-444553540000}
Description: Universal Serial Bus (USB) Controller
Device ID: PCI\VEN_1002&DEV_4373&SUBSYS_2A31103C&REV_80\3&267A616A&0&9A
Manufacturer: (Standard USB Host Controller)
Name: Universal Serial Bus (USB) Controller
PNP Device ID: PCI\VEN_1002&DEV_4373&SUBSYS_2A31103C&REV_80\3&267A616A&0&9A
Service:
Class GUID:
Description: PCI Simple Communications Controller
Device ID: PCI\VEN_11C1&DEV_0620&SUBSYS_062011C1&REV_00\4&B4B0D3&0&18A4
Manufacturer:
Name: PCI Simple Communications Controller
PNP Device ID: PCI\VEN_11C1&DEV_0620&SUBSYS_062011C1&REV_00\4&B4B0D3&0&18A4
Service:
Class GUID: {4D36E96C-E325-11CE-BFC1-08002BE10318}
Description: Audio Codecs
Device ID: ROOT\MEDIA\MS_MMACM
Manufacturer: (Standard system devices)
Name: Audio Codecs
PNP Device ID: ROOT\MEDIA\MS_MMACM
Service:
Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Description: Nokia 6233
Device ID: ROOT\WPD\0000
Manufacturer: Nokia
Name: Nokia 6233
PNP Device ID: ROOT\WPD\0000
Service: WUDFRd
-- Files created between 2008-07-07 and 2008-08-07 -----------------------------
2008-08-07 06:43:11 0 d-------- C:\Program Files\Trend Micro
2008-08-07 02:48:28 0 d-------- C:\WINDOWS\LastGood
2008-08-06 18:40:27 0 d-------- C:\WINDOWS\pss
2008-08-05 04:13:10 0 d-------- C:\Documents and Settings\mars\Application Data\zweitgeist
2008-08-04 18:51:22 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-08-04 18:49:47 593920 -----n--- C:\WINDOWS\system32\ati2sgag.exe <Not Verified; ; ATI Smart>
2008-08-04 18:33:02 0 d-------- C:\Program Files\ATI
2008-08-04 18:28:52 0 d-------- C:\Program Files\Realtek
2008-08-04 18:28:36 315392 --a------ C:\WINDOWS\HideWin.exe <Not Verified; Realtek Semiconductor Corp.; HD Audio Hide windows program>
2008-08-04 18:26:17 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-08-04 18:25:29 0 d-------- C:\ATI
2008-08-03 14:04:07 0 d--h----- C:\$AVG8.VAULT$
2008-08-03 07:34:07 18048 --a------ C:\WINDOWS\system32\drivers\eth8023.sys
2008-08-03 07:33:49 15872 --a------ C:\WINDOWS\system32\drivers\cdralw.sys
2008-08-03 07:33:48 53248 --a------ C:\WINDOWS\linkinfo.dll
2008-08-03 07:33:40 266240 --a------ C:\WINDOWS\Update.dll
2008-08-03 07:33:07 24576 --a------ C:\WINDOWS\system32\squalle.dll
2008-08-03 07:33:00 24576 --a------ C:\WINDOWS\system32\xpsbos.dll
2008-08-03 07:32:17 28672 --a------ C:\WINDOWS\system32\aliens.dll
2008-08-03 07:32:13 24576 --a------ C:\WINDOWS\system32\baccops.dll
2008-08-03 07:31:56 28672 --a------ C:\WINDOWS\system32\keyiftp.dll
2008-08-03 07:31:35 272384 --ah----- C:\WINDOWS\system32\ddserh.dll
2008-08-03 07:31:19 265216 --ah----- C:\WINDOWS\system32\wzcfsw.dll
2008-08-03 07:31:05 14336 --a------ C:\WINDOWS\system32\mssetdk.exe
2008-08-02 07:39:13 0 d-------- C:\Program Files\DAEMON Tools Lite
2008-08-02 07:36:17 717296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-08-02 07:36:13 0 d-------- C:\Documents and Settings\mars\Application Data\DAEMON Tools
2008-08-02 06:40:06 0 d-------- C:\Documents and Settings\mars\Application Data\vlc
2008-08-02 06:38:26 0 d-------- C:\Program Files\VideoLAN
2008-07-29 02:25:13 0 d-------- C:\Program Files\uTorrent
2008-07-29 02:25:03 0 d-------- C:\Documents and Settings\mars\Application Data\uTorrent
2008-07-27 06:51:28 0 d-------- C:\Program Files\Microsoft Games
2008-07-26 07:53:19 0 dr-h----- C:\Documents and Settings\mars\Application Data\yahoo!
2008-07-26 06:44:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-07-26 06:39:39 0 dr------- C:\Program Files\Yahoo!
2008-07-25 05:06:31 0 d--h----- C:\WINDOWS\$hf_mig$
2008-07-23 04:46:13 20 --a------ C:\WINDOWS\system32\mhsha1.dat
2008-07-23 03:44:29 0 d-------- C:\Documents and Settings\All Users\Application Data\Trymedia
2008-07-22 07:36:23 0 d-------- C:\Program Files\directx
2008-07-22 06:49:56 50688 --a------ C:\Program Files\ATF-Cleaner.exe <Not Verified; Atribune.org; ATF Cleaner>
2008-07-22 04:11:48 0 dr------- C:\Program Files\SpeedBit Video Accelerator
2008-07-22 04:07:12 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-22 04:06:58 50688 --a------ C:\WINDOWS\system32\wbhelp2.dll <Not Verified; Stardock.Net, Inc; WindowBlinds for Win32 x86 machines>
2008-07-22 04:06:57 0 dr------- C:\Program Files\DAP
2008-07-21 06:45:37 0 d-------- C:\Documents and Settings\mars\Application Data\Malwarebytes
2008-07-21 06:45:34 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-21 06:45:33 0 dr------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-21 06:44:02 0 d-------- C:\Program Files\setup files
2008-07-20 08:59:39 0 d-------- C:\Program Files\avg and norton extracts
2008-07-20 08:47:43 0 d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-20 08:47:43 0 d-------- C:\Documents and Settings\mars\Application Data\AVGTOOLBAR
2008-07-20 08:47:39 0 dr------- C:\Program Files\AVG
2008-07-20 08:47:39 0 d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-07-19 17:15:01 0 d-------- C:\Documents and Settings\mars\My Document
2008-07-19 17:04:07 0 d-------- C:\Documents and Settings\All Users\Application Data\WinZip
2008-07-19 16:37:02 0 d-------- C:\WINDOWS\E80F62FF5D3C4A1984099721F2928206.TMP
2008-07-19 09:09:04 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-07-19 08:54:51 24 --a------ C:\WINDOWS\system32\wymxajkl.sys
2008-07-13 18:55:26 0 d-------- C:\Documents and Settings\mars\Application Data\Symantec
2008-07-13 18:55:25 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-07-13 14:49:26 38048 --a------ C:\WINDOWS\system32\drivers\HBKernel.sys
2008-07-13 10:35:14 0 d-------- C:\Documents and Settings\NetworkService\Application Data\Mozilla
2008-07-13 10:35:14 0 d-------- C:\Documents and Settings\NetworkService\Application Data\aomyqlxs
2008-07-12 15:27:26 0 d-------- C:\Documents and Settings\mars\Application Data\Mozilla
2008-07-12 15:27:26 0 d-------- C:\Documents and Settings\mars\Application Data\aomyqlxs
2008-07-12 09:27:45 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-07-12 09:27:45 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-07-12 09:27:45 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-07-12 09:27:45 0 d--h----- C:\Documents and Settings\Administrator\Recent
2008-07-12 09:27:45 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-07-12 09:27:45 499712 --a------ C:\Documents and Settings\Administrator\NTUSER.DAT
2008-07-12 09:27:45 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-07-12 09:27:45 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-07-12 09:27:45 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-07-12 09:27:45 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-07-12 09:27:45 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-07-12 09:27:45 0 d---s---- C:\Documents and Settings\Administrator\Cookies
2008-07-12 09:27:45 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-07-12 09:27:45 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-07-12 09:27:38 0 d--hs---- C:\WINDOWS\CSC
2008-07-11 21:52:42 8 --a------ C:\WINDOWS\system32\Update.dat
2008-07-11 07:04:51 24 --a------ C:\WINDOWS\system32\pzwlaime.sys
2008-07-11 07:03:31 36 --a------ C:\WINDOWS\system32\ijsgajba.sys
2008-07-10 09:43:48 17144 --a------ C:\Documents and Settings\mars\Application Data\GDIPFONTCACHEV1.DAT
2008-07-09 13:58:46 36 --a------ C:\WINDOWS\system32\qbhxaklo.sys
-- Find3M Report ---------------------------------------------------------------
2008-08-05 16:45:01 5545 --a------ C:\Documents and Settings\mars\Application Data\studio.xnf
2008-08-04 18:33:56 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-07-20 16:56:15 0 dr------- C:\Program Files\Common Files\Nokia
2008-07-20 16:55:35 0 dr------- C:\Program Files\Common Files\Real
2008-07-20 16:53:45 0 dr------- C:\Program Files\MSN Gaming Zone
2008-07-20 16:52:59 0 dr------- C:\Program Files\AvRack
2008-07-20 10:33:03 0 dr------- C:\Program Files\GRETECH
2008-07-20 10:31:18 0 dr------- C:\Program Files\Movie Maker
2008-07-20 10:27:09 0 dr------- C:\Program Files\Realtek Sound Manager
2008-07-20 10:26:12 0 dr------- C:\Program Files\Nero
2008-07-20 10:24:34 0 dr------- C:\Program Files\Winamp
2008-07-20 10:23:55 0 dr------- C:\Program Files\Real
2008-07-20 10:22:53 0 dr------- C:\Program Files\Nokia
2008-07-13 18:55:25 0 d-------- C:\Program Files\Common Files
2008-07-13 06:44:13 0 --a------ C:\WINDOWS\Sysvxd.exe
2008-07-12 06:54:55 24 --a------ C:\WINDOWS\system32\pzwmaime.sys
2008-07-12 06:54:54 36 --a------ C:\WINDOWS\system32\ijzhatde.sys
2008-07-05 12:39:01 24 --a------ C:\WINDOWS\system32\sqjsakaq.sys
2008-06-30 10:08:13 186 --a------ C:\MicroSoft.vbs
2008-06-30 10:08:11 30 --a------ C:\MicroSoft.bat
2008-06-27 08:59:59 0 d-------- C:\Documents and Settings\mars\Application Data\WinRAR
2008-06-25 11:43:01 0 d-------- C:\Program Files\Common Files\SWF Studio
2008-06-21 15:26:20 287 --a------ C:\WINDOWS\EReg072.dat
2008-06-21 01:11:36 0 d-------- C:\Documents and Settings\mars\Application Data\Adobe
2008-06-20 08:04:33 0 d-------- C:\Program Files\Common Files\Adobe
2008-06-17 16:45:43 38384 --a------ C:\Documents and Settings\mars\Application Data\NMM-MetaData.db
2008-06-17 14:10:10 0 d-------- C:\Documents and Settings\mars\Application Data\PC Suite
2008-06-17 11:49:00 0 d-------- C:\Program Files\Common Files\PCSuite
2008-06-17 11:48:50 0 d-------- C:\Program Files\DIFX
2008-06-17 11:48:33 0 d-------- C:\Program Files\PC Connectivity Solution
2008-06-15 23:04:48 0 d-------- C:\Documents and Settings\mars\Application Data\Google
2008-06-15 10:32:57 0 d-------- C:\Program Files\jvm
2008-06-15 10:32:40 5107041 --a------ C:\Program Files\jvm.zip
2008-06-14 07:33:47 0 d-------- C:\Program Files\Windows Media Connect 2
2008-06-12 15:59:18 0 d-------- C:\Documents and Settings\mars\Application Data\Macromedia
2008-06-07 09:22:01 0 d-------- C:\Documents and Settings\mars\Application Data\Ahead
2008-06-07 08:41:34 0 d-------- C:\Documents and Settings\mars\Application Data\CyberLink
2008-06-06 19:58:28 62 --ahs---- C:\Documents and Settings\mars\Application Data\desktop.ini
2008-06-06 14:40:00 0 -rahs---- C:\MSDOS.SYS
2008-06-06 14:40:00 0 -rahs---- C:\IO.SYS
2008-06-06 14:40:00 0 --a------ C:\CONFIG.SYS
2008-06-06 14:40:00 0 --a------ C:\AUTOEXEC.BAT
2008-06-06 14:36:50 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{20618412-C528-C784-C056-C164D1F7C502}]
C:\WINDOWS\system32\detxbiua.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2A698452-C5D8-C584-C256-C264C987C5A2}]
C:\WINDOWS\system32\ijdybpaw.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{60A345CD-ABCD-EFAB-CDEF-ABCD01020306}]
C:\WINDOWS\system32\pqzfajke.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7319A1F1-9410-9654-3201-345FFA349137}]
C:\WINDOWS\system32\zywmgime.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{813DD04F-261A-428A-8309-3F541B2D2564}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97421D0D-E07F-40DF-8F07-99597B9585AD}]
C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
07/20/2008 08:47 AM 2055960 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [07/20/2008 08:47 AM 2055960]
[-HKEY_CLASSES_ROOT\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [03/01/2007 03:57 PM]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [12/07/2005 10:57 PM]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [05/18/2006 11:29 AM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06/06/2008 03:52 PM]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [11/08/2006 01:27 PM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM]
"WindowsHive"="C:\WINDOWS\system32\rpcc.exe" []
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [07/20/2008 08:47 AM]
"3PMmUpdate"="C:\WINDOWS\Update.dll" [08/03/2008 07:33 AM]
"RTHDCPL"="RTHDCPL.EXE" [07/03/2008 04:51 PM C:\WINDOWS\RTHDCPL.exe]
"SoundMan"="SOUNDMAN.EXE" [06/18/2008 06:01 PM C:\WINDOWS\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [06/19/2008 04:42 PM C:\WINDOWS\alcwzrd.exe]
"Alcmtr"="ALCMTR.EXE" [06/19/2008 04:20 PM C:\WINDOWS\Alcmtr.exe]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [06/01/2007 10:21 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:26 AM]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [08/30/2007 05:43 PM]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [07/24/2008 08:32 PM]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"PcSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{2A698452-C5D8-C584-C256-C264C987C5A2}"= C:\WINDOWS\system32\ijdybpaw.dll [ ]
"{20618412-C528-C784-C056-C164D1F7C502}"= C:\WINDOWS\system32\detxbiua.dll [ ]
"{7319A1F1-9410-9654-3201-345FFA349137}"= C:\WINDOWS\system32\zywmgime.dll [ ]
"{8A041F13-A111-12A3-B0CF-F99818AA68A8}"= C:\WINDOWS\system32\zxmsewin.dll [ ]
"{87FD640A-158F-48AC-FD14-1597F14A9778}"= C:\WINDOWS\system32\mndshsrv.dll [ ]
"{6A908760-8000-4000-A000-9000322145A6}"= C:\WINDOWS\system32\akjsfkaq.dll [ ]
"{60A345CD-ABCD-EFAB-CDEF-ABCD01020306}"= C:\WINDOWS\system32\pqzfajke.dll [ ]
"{5A069845-2036-6084-9054-6087502480A5}"= C:\WINDOWS\system32\ozfyebyt.dll [ ]
"{3D698451-2015-6358-9871-2015987452D3}"= C:\WINDOWS\system32\apzhctde.dll [ ]
"{8C8D1401-A58D-A81C-CD24-A5915C4517C8}"= C:\WINDOWS\system32\mnmhhsrv.dll [ ]
"{45671234-7890-ABCD-CDEF-567801237654}"= C:\WINDOWS\system32\yxcsdhlp.dll [ ]
"{60940F85-F015-14F1-A05F-F69858AC6D06}"= C:\WINDOWS\system32\zptldsys.dll [ ]
"{37A924AF-1A5F-CF21-AB1D-1D5CF82A8A73}"= C:\WINDOWS\system32\zywlcime.dll [ ]
"{4D698451-2015-6358-9871-2015987452D4}"= C:\WINDOWS\system32\apzhdtde.dll [ ]
"{A1954FAC-1023-154F-895A-1458258AD81A}"= C:\WINDOWS\system32\ypdjhbmp.dll [ ]
"{40618412-C528-C784-C056-C164D1F7C504}"= C:\WINDOWS\system32\detxdiua.dll [ ]
"{97FD640A-158F-48AC-FD14-1597F14A9779}"= C:\WINDOWS\system32\mndsisrv.dll [ ]
"{49109876-7619-9101-7012-901938475194}"= C:\WINDOWS\system32\ietzdpaq.dll [ ]
"{6A069845-2036-6084-9054-6087502480A6}"= C:\WINDOWS\system32\ozfyfbyt.dll [ ]
"{8C954872-1230-6541-9548-6541025884C8}"= C:\WINDOWS\system32\fd233ds4f4.dll [ ]
"{9319A1F1-9410-9654-3201-345FFA349139}"= C:\WINDOWS\system32\zywmiime.dll [ ]
"{8FD45A54-9875-698F-E56E-65102358FDF8}"= C:\WINDOWS\system32\apsghjba.dll [ ]
"{50618412-C528-C784-C056-C164D1F7C505}"= C:\WINDOWS\system32\detxeiua.dll [ ]
"{47A924AF-1A5F-CF21-AB1D-1D5CF82A8A74}"= C:\WINDOWS\system32\zywldime.dll [ ]
"{C629FF4F-ACDB-5C90-A098-FACB3456A26C}"= C:\WINDOWS\system32\hdf453d1.dll [ ]
"{48093456-9012-4568-9076-908765467184}"= C:\WINDOWS\system32\tisqdtyu.dll [ ]
"{28766E1C-74B0-4417-8C75-F12AE309EF35}"= C:\WINDOWS\system32\wzcfsw.dll [08/03/2008 07:31 AM 265216]
"{A9895933-6636-4281-BC58-EE6DE2AF96E3}"= C:\WINDOWS\system32\ddserh.dll [08/03/2008 07:31 AM 272384]
"{0B846B26-BFE6-4E8E-A948-1DB17B77B483}"= C:\WINDOWS\system32\tdfhex.dll [ ]
"{73AE86E6-7F03-4C3B-8980-FB1DA157D3C7}"= C:\WINDOWS\system32\fmcvxy.dll [ ]
"{53D44DB6-E22B-4B17-97D3-572C96CCA6E1}"= C:\WINDOWS\system32\zsdgff.dll [ ]
"{6E6CA8A1-81BC-4707-A54C-F4903DD70BAD}"= C:\WINDOWS\system32\zgxfdx.dll [ ]
"{259BF3CF-194D-4FE6-9ADB-DE6544B098B6}"= C:\WINDOWS\system32\dndsaf.dll [ ]
"{EA5D4B0E-B8CE-4761-8C7E-5D26369F0EC6}"= C:\WINDOWS\system32\fsrgeb.dll [ ]
"{57AC9076-C898-B098-D098-A18319080975}"= C:\WINDOWS\system32\nhmxejkl.dll [ ]
"{7914E0AA-ECCB-4311-B584-C49538227824}"= C:\WINDOWS\system32\jhfrxz.dll [ ]
"{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}"= C:\WINDOWS\system32\hhrdxd.dll [ ]
"{8C41B7F7-3168-400D-A702-0E7EFE0BA304}"= C:\WINDOWS\system32\sgdewg.dll [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"DesktopWin"= {DA191DE0-AA86-4ED0-4B87-292A3D48BE99} - C:\WINDOWS\AppPatch\DesktopWin.dll [08/03/2008 07:28 AM 14336]
"ThunderAdvise"= {97421D0D-E07F-40DF-8F07-99597B9585AD} - C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\obklooga]
ziaashl.dll 08/23/2001 01:00 PM 104448 C:\WINDOWS\system32\ziaashl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=tisqdtyu.dll,NTNJXSJTVC.dll,comremo.dll,myasemt.dll,googleons.dll,welycz.dll,jsnoer.dll,ezcron.dll,joliom.dll,fackwir.dll,caotxb.dll,ceshleo.dll,nhmxejkl.dll,woswelc.dll,avgrsstx.dll, mssetd.dll tiplict.dll businesn.dll esceps.dll keyiftp.dll baccops.dll aliens.dll offscrl.dll cmonos.dll wdhotem.dll xpsbos.dll manleu.dll squalle.dll therbrek.dll jolin0.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winhd88.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winhx22.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winky58.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winlg64.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winqv60.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winss42.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winxt25.sys]
@="Driver"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ywdmwmbh
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
Auto\command- sxs.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sxs.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
Auto\command- sxs.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sxs.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
Auto\command- sxs.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sxs.exe
-- Hosts -----------------------------------------------------------------------
202.165.102.205 972.aksjd11.com
202.165.102.205 w3og.cn
203.208.35.100 qazc.fourtw.cn
203.208.35.100 www.aujoy.cn
203.208.35.101 www.hao601.cn
203.208.35.101 www.psp476.cn
72.14.235.99 222.1212l112.net
72.14.235.99 444.1212l112.netn
72.14.235.99 555.1212l112.net
72.14.235.99 111.1212l112.net
9279 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-08-07 06:45:44 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: Intel® Pentium® 4 CPU 3.06GHz
CPU 1: Intel® Pentium® 4 CPU 3.06GHz
Percentage of Memory in Use: 51%
Physical Memory (total/avail): 959.36 MiB / 466.26 MiB
Pagefile Memory (total/avail): 2313.93 MiB / 1885.5 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1925.32 MiB
C: is Fixed (NTFS) - 37.25 GiB total, 31.37 GiB free.
D: is Fixed (NTFS) - 37.25 GiB total, 31.36 GiB free.
E: is Fixed (NTFS) - 37.25 GiB total, 31.25 GiB free.
F: is Fixed (NTFS) - 37.28 GiB total, 33.93 GiB free.
G: is CDROM (No Media)
\\.\PHYSICALDRIVE0 - WDC WD1600JS-60NCB1 - 149.05 GiB - 4 partitions
\PARTITION0 (bootable) - Installable File System - 37.25 GiB - C:
\PARTITION1 - Extended w/Extended Int 13 - 111.79 GiB - D: - E: - F:
-- Security Center -------------------------------------------------------------
AUOptions is disabled.
Windows Internal Firewall is enabled.
FirstRunDisabled is set.
AntiVirusDisableNotify is set.
FirewallDisableNotify is set.
UpdatesDisableNotify is set.
AV: AVG Anti-Virus Free v8.0 (AVG Technologies)
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\WINDOWS\\system32\\drivers\\svchost.exe"="C:\\WINDOWS\\system32\\drivers\\svchost.exe:*:Disabled:svchost"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"
"C:\\Program Files\\DAP\\DAP.exe"="C:\\Program Files\\DAP\\DAP.exe:*:Disabled:Download Accelerator Plus (DAP)"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"E:\\age of mythology\\EMPIRES2.EXE"="E:\\age of mythology\\EMPIRES2.EXE:*:Disabled:Age of Empires II"
"C:\\Program Files\\utorrent-1.8-rc6.upx.exe"="C:\\Program Files\\utorrent-1.8-rc6.upx.exe:*:Enabled:µTorrent"
"C:\\Program Files\\SpeedBit Video Accelerator\\VideoAccelerator.exe"="C:\\Program Files\\SpeedBit Video Accelerator\\VideoAccelerator.exe:*:Enabled:VideoAccelerator"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\mars\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=MARS-C47DFC032A
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\mars
LOGONSERVER=\\MARS-C47DFC032A
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\Program Files\PC Connectivity Solution\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 9, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0409
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\mars\LOCALS~1\Temp
TMP=C:\DOCUME~1\mars\LOCALS~1\Temp
USERDOMAIN=MARS-C47DFC032A
USERNAME=mars
USERPROFILE=C:\Documents and Settings\mars
windir=C:\WINDOWS
__COMPAT_LAYER=EnableNXShowUI
-- User Profiles ---------------------------------------------------------------
mars (admin)
Administrator (admin)
-- Add/Remove Programs ---------------------------------------------------------
--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
--> C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
--> C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
--> C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
--> C:\WINDOWS\UNNeroVision.exe /UNINSTALL
--> C:\WINDOWS\UNRecode.exe /UNINSTALL
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
µTorrent --> "C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
ATI - Software Uninstall Utility --> C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
AVG Free 8.0 --> C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Download Accelerator Plus (DAP) --> C:\PROGRA~1\DAP\DAPREMOVE.EXE
GOM Player --> "C:\Program Files\GRETECH\GomPlayer\Uninstall.exe"
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
Grand Theft Auto Vice City --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4B35F00C-E63D-40DC-9839-DF15A33EAC46}\setup.exe" -l0x9
GTA2 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2987EE84-C4EE-4FF5-8160-32DE00D6ABC6}\Setup.exe" -l0x9
High Definition Audio Driver Package - KB888111 --> "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office XP Professional with FrontPage --> MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9}
Microsoft Office XP Web Components --> MsiExec.exe /I{90260409-6000-11D3-8CFE-0050048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.5 --> "C:\WINDOWS\$NtUninstallWudf01005$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Nero 7 Essentials --> MsiExec.exe /X{66EBD70F-A42C-475F-AEDF-277378151033}
neroxml --> MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
Nokia Connectivity Cable Driver --> MsiExec.exe /X{0FF1922C-B6C4-40BB-AF30-BEF75A482444}
Nokia PC Suite --> MsiExec.exe /I{7B9031F8-6464-4687-893C-472D8D87527B}
PC Connectivity Solution --> MsiExec.exe /I{D8E4A66D-DB68-481F-ABA8-AC622566D4CB}
PowerDVD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek AC'97 Audio --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
REALTEK Gigabit and Fast Ethernet NIC Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{94FB906A-CF42-4128-A509-D353026A607E}\setup.exe" -l0x9 REMOVE
Realtek High Definition Audio Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
RoadRash --> C:\WINDOWS\uninst.exe -fe:\roadrash\DeIsL1.isu
SpeedBit Video Accelerator --> C:\PROGRA~1\SPEEDB~1\UNWISE.EXE C:\PROGRA~1\SPEEDB~1\INSTALL.LOG
VideoLAN VLC media player 0.8.6d --> C:\Program Files\VideoLAN\VLC\uninstall.exe
WebPAM --> C:\Program Files\InstallShield Installation Information\{EDC5E937-F707-4241-BB2F-111C4B83FF2C}\setup.exe -runfromtemp -l0x0409
Winamp (remove only) --> "C:\Program Files\Winamp\UninstWA.exe"
Windows Driver Package - Nokia (WUDFRd) WPD (11/03/2006 6.82.26.2) --> C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccswpddri_6B630EE2E66584353C6CD8683D447072872F34D8\pccswpddriver.inf
Windows Driver Package - Nokia Modem (11/03/2006 6.82.0.1) --> C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_4EFFAAE27A08EDFDE145390033D8EF099DA65567\nokbtmdm.inf
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
WinZip 11.2 --> MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240B6}
XMLinst --> MsiExec.exe /I{EA23971F-2CEE-48FC-B64D-7F74A6EF90F0}
Yahoo! Browser Services --> C:\PROGRA~1\Yahoo!\Common\UNIN_Y~1.EXE /S
Yahoo! Install Manager --> C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
Yahoo! Internet Mail --> C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\YMMAPI.dll
Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
-- Application Event Log -------------------------------------------------------
Event Record #/Type3544 / Error
Event Submitted/Written: 08/06/2008 06:40:48 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.
Processing media-specific event for [drwtsn32.exe!ws!]
Event Record #/Type3543 / Error
Event Submitted/Written: 08/06/2008 06:40:30 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application msconfig.exe, version 5.1.2600.2180, faulting module advapi32.dll, version 5.1.2600.2180, fault address 0x00067b91.
Processing media-specific event for [msconfig.exe!ws!]
Event Record #/Type3388 / Error
Event Submitted/Written: 08/04/2008 05:43:29 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application rundll32.exe, version 5.1.2600.2180, faulting module advapi32.dll, version 5.1.2600.2180, fault address 0x00067eff.
Processing media-specific event for [rundll32.exe!ws!]
Event Record #/Type3369 / Error
Event Submitted/Written: 08/03/2008 02:53:22 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application gta2.exe, version 9.6.0.0, faulting module unknown, version 0.0.0.0, fault address 0x737816d4.
Processing media-specific event for [gta2.exe!ws!]
Event Record #/Type3366 / Error
Event Submitted/Written: 08/03/2008 11:21:40 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application gta2.exe, version 9.6.0.0, faulting module unknown, version 0.0.0.0, fault address 0x737816d4.
Processing media-specific event for [gta2.exe!ws!]
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type4773 / Warning
Event Submitted/Written: 08/07/2008 06:00:52 AM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Event Record #/Type4772 / Warning
Event Submitted/Written: 08/07/2008 04:11:37 AM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Event Record #/Type4771 / Warning
Event Submitted/Written: 08/07/2008 03:17:00 AM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Event Record #/Type4770 / Warning
Event Submitted/Written: 08/07/2008 02:49:40 AM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Event Record #/Type4764 / Warning
Event Submitted/Written: 08/07/2008 02:35:57 AM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
-- End of Deckard's System Scanner: finished at 2008-08-07 06:45:44 ------------
Directories/Files moved to C:\Deckard\System Scanner\backup
2008-08-04 18:43:25 114688 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\6614.rra
2008-08-04 18:26:53 114688 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\958.rra
2008-08-04 18:39:06 20991 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Arabic.bin
2008-08-05 17:21:14 21176 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\atisketch.bmp
2006-09-19 01:01:40 57656 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Catalyst.bmp
2008-08-04 18:39:06 24321 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Czech.bin
2008-08-04 18:39:06 22794 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Danish.bin
2008-08-04 18:39:06 25758 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Dutch.bin
2008-08-05 17:21:15 21176 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\easpore.bmp
2008-08-04 18:39:06 21944 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\English.bin
2008-08-04 18:31:17 114688 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\ff23.rra
2008-08-04 18:39:06 22868 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Finnish.bin
2008-08-04 18:39:06 27246 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\French.bin
2008-08-05 17:21:17 21176 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\gardasil2.bmp
2008-08-04 18:39:06 25764 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\German.bin
2008-08-05 17:21:17 21176 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\gorving.bmp
2008-08-04 18:39:06 25093 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Greek.bin
2008-08-04 18:39:07 19564 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Hebrew.bin
2008-08-04 18:39:07 26094 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Hungarian.bin
2008-08-06 18:28:01 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT12.xml
2008-08-06 18:28:02 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT13.xml
2008-08-06 18:28:02 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT14.xml
2008-08-06 18:28:07 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT15.xml
2008-08-06 18:28:07 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT16.xml
2008-08-06 18:28:07 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT17.xml
2008-08-06 18:28:22 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT18.xml
2008-08-06 18:28:22 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT19.xml
2008-08-06 18:28:22 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT1A.xml
2008-08-04 17:42:24 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT1D.xml
2008-08-05 17:22:04 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT1E.xml
2008-08-05 17:22:04 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT1F.xml
2008-08-05 17:22:04 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT20.xml
2008-08-04 17:42:55 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT21.xml
2008-08-04 17:42:55 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT22.xml
2008-08-04 18:18:21 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT23.xml
2008-08-04 18:18:21 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT24.xml
2008-08-04 17:42:58 1022 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT25.dtd
2008-08-04 18:18:21 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT25.xml
2008-08-04 18:18:32 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT26.xml
2008-08-04 18:18:32 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT27.xml
2008-08-04 18:18:33 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT28.xml
2008-08-05 03:51:49 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT29.xml
2008-08-05 03:51:49 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT2A.xml
2008-08-05 03:51:49 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT2B.xml
2008-08-04 18:18:39 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT2C.xml
2008-08-05 20:59:48 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT2D.xml
2008-08-05 20:59:48 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT2E.xml
2008-08-06 07:02:07 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT2F.xml
2008-08-06 07:02:07 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT30.xml
2008-08-06 07:02:07 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT31.xml
2008-08-05 03:57:32 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT32.xml
2008-08-05 17:28:43 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT33.xml
2008-08-05 17:28:43 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT34.xml
2008-08-05 17:28:43 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT35.xml
2008-08-05 03:57:36 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT36.xml
2008-08-05 03:57:36 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT37.xml
2008-08-05 21:00:06 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT3B.xml
2008-08-05 21:00:07 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT3C.xml
2008-08-05 21:00:07 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT3D.xml
2008-08-04 17:43:59 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT40.xml
2008-08-04 17:43:59 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT41.xml
2008-08-04 17:44:00 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT42.xml
2008-08-06 18:42:32 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT46.xml
2008-08-06 18:42:32 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT47.xml
2008-08-06 18:42:32 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT48.xml
2008-08-06 18:42:37 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT49.xml
2008-08-06 18:42:37 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT4A.xml
2008-08-06 18:42:37 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT4B.xml
2008-08-06 18:42:40 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT4C.xml
2008-08-06 18:42:40 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT4D.xml
2008-08-06 18:42:40 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT4E.xml
2008-08-06 18:42:43 2232826 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT4F.xml
2008-08-06 18:42:44 1022 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT50.dtd
2008-08-04 18:20:48 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT52.xml
2008-08-05 21:00:22 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT53.xml
2008-08-05 21:00:22 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT54.xml
2008-08-05 21:00:22 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT55.xml
2008-08-04 18:21:15 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT5A.xml
2008-08-04 18:21:15 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT5B.xml
2008-08-04 18:21:15 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT5C.xml
2008-08-04 18:21:32 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT66.xml
2008-08-04 18:21:32 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT67.xml
2008-08-04 18:21:33 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT68.xml
2008-08-04 18:21:38 2232826 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT69.xml
2008-08-04 18:21:38 1022 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT6A.dtd
2008-08-04 18:21:40 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT6B.xml
2008-08-04 18:21:40 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT6C.xml
2008-08-04 18:21:40 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT6D.xml
2008-08-04 18:21:52 2232826 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT6E.xml
2008-08-04 18:21:52 1022 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT6F.dtd
2008-08-04 18:22:05 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT70.xml
2008-08-04 18:22:05 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT71.xml
2008-08-04 18:22:05 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT72.xml
2008-08-04 18:22:10 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT73.xml
2008-08-04 18:22:10 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT74.xml
2008-08-04 18:22:10 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT75.xml
2008-08-06 18:49:54 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT78.xml
2008-08-06 18:49:55 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT79.xml
2008-08-06 18:49:55 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT7A.xml
2008-08-06 18:50:18 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT7C.xml
2008-08-06 18:50:18 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT7D.xml
2008-08-06 18:50:18 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT7E.xml
2008-08-06 18:50:21 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT7F.xml
2008-08-06 18:50:21 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT80.xml
2008-08-06 18:50:21 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT81.xml
2008-08-06 18:50:47 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT8D.xml
2008-08-06 18:50:47 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT8E.xml
2008-08-06 18:50:47 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT8F.xml
2008-08-06 18:51:09 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT91.xml
2008-08-06 18:51:09 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT92.xml
2008-08-06 18:51:09 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT93.xml
2008-08-05 06:09:41 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT94.xml
2008-08-05 06:09:41 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT95.xml
2008-08-05 06:09:41 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMT96.xml
2008-08-06 18:51:49 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMTA1.xml
2008-08-06 18:51:49 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMTA2.xml
2008-08-06 18:51:49 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMTA3.xml
2008-08-06 18:51:51 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMTA4.xml
2008-08-06 18:51:51 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMTA5.xml
2008-08-06 18:51:51 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMTA6.xml
2008-08-06 18:52:07 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMTA8.xml
2008-08-06 18:52:07 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMTA9.xml
2008-08-06 18:52:07 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMTAA.xml
2008-08-06 18:52:10 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMTAB.xml
2008-08-06 18:52:10 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMTAC.xml
2008-08-06 18:52:10 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMTAD.xml
2008-08-06 18:52:14 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMTAE.xml
2008-08-06 18:52:14 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMTAF.xml
2008-08-06 18:52:14 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMTB0.xml
2008-08-06 18:52:17 1994 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMTB1.xml
2008-08-06 18:52:17 426 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMTB2.xml
2008-08-06 18:52:17 707348 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\IMTB3.xml
2008-08-04 18:39:06 27421 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Italian.bin
2008-08-04 18:39:06 24340 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Japanese.bin
2008-08-05 17:21:15 21176 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\jcpenneybts.bmp
2008-08-04 18:39:06 20145 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Korean.bin
2008-08-04 18:39:07 21975 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Norwegian.bin
2008-08-06 06:53:14 0 d-------- C:\DOCUME~1\mars\LOCALS~1\Temp\pft26.tmp
2008-08-06 06:52:27 5310 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\plf24.tmp
2008-08-04 18:39:06 24232 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Polish.bin
2008-08-04 18:39:06 25082 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Portuguese(Brazil).bin
2008-08-04 18:39:06 26271 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Portuguese.bin
2008-08-04 18:39:06 26136 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Russian.bin
2008-08-04 18:39:06 16420 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\SimChin.bin
2008-08-04 18:39:06 27764 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Spanish.bin
2008-08-04 18:39:06 24093 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\SWEDISH.bin
2008-08-04 18:39:06 21987 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Thai.bin
2008-08-05 17:21:15 21176 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\thethread.bmp
2008-08-04 18:39:06 16962 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\TradChin.bin
2008-08-04 18:39:07 22263 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\Turkish.bin
2008-08-05 04:16:00 729651 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\U93ce34489786137829.zip
2008-08-07 06:28:52 5632 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\wmsetup.dll
2008-08-07 02:34:23 0 d-------- C:\DOCUME~1\mars\LOCALS~1\Temp\WPDNSE
2008-08-04 18:50:27 0 d-------- C:\DOCUME~1\mars\LOCALS~1\Temp\{9b94be6f-7ca3-4c40-a266-62667ff746cc}
2008-08-04 17:50:15 16384 --a------ C:\DOCUME~1\mars\LOCALS~1\Temp\~DF2B2B.tmp
2008-08-04 17:50:15 512 --a-----t C:\DOCUME~1\mars\LOCALS~1\Temp\~DF2B36.tmp
2008-08-05 17:23:23 0 --a------ C:\WINDOWS\temp\IMT25.tmp
2008-08-05 17:23:23 0 --a------ C:\WINDOWS\temp\IMT26.tmp
2008-07-20 08:47:14 616448 --ahs---- C:\WINDOWS\temp\jnfg9ysu.TMP
2008-08-03 07:34:01 45056 --a------ C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
-*- End of Logfile -*-
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:56:49 AM, on 8/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI\WebPAM\jetty\extra\win32\Wrapper.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\ATI\WebPAM\_jvm\bin\java.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\utorrent-1.8-rc6.upx.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.in/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: 202.165.102.205 972.aksjd11.com
O1 - Hosts: 202.165.102.205 w3og.cn
O1 - Hosts: 203.208.35.100 qazc.fourtw.cn
O1 - Hosts: 203.208.35.100 www.aujoy.cn
O1 - Hosts: 203.208.35.101 www.hao601.cn
O1 - Hosts: 203.208.35.101 www.psp476.cn
O1 - Hosts: 72.14.235.99 222.1212l112.net
O1 - Hosts: 72.14.235.99 444.1212l112.netn
O1 - Hosts: 72.14.235.99 555.1212l112.net
O1 - Hosts: 72.14.235.99 111.1212l112.net
O1 - Hosts: 65.55.21.250 111.3243l24.com
O1 - Hosts: 65.55.21.250 222.3243l24.com
O1 - Hosts: 65.55.21.250 333.3243l24.com
O1 - Hosts: 125.64.8.112 kao2.gmwo03.com
O1 - Hosts: 125.64.8.112 kao.gmwo06.com
O1 - Hosts: 125.64.8.112 444.gmwo07.com
O1 - Hosts: 116.252.185.15 ru.update365.us
O1 - Hosts: 116.252.185.15 ad.update365.us
O1 - Hosts: 207.46.232.182 popmails.net
O1 - Hosts: 203.208.37.99 3.goodhh.com
O1 - Hosts: 220.181.37.55 down.rwixr.com
O1 - Hosts: 160.79.42.52 www.xdj2008.com
O1 - Hosts: 63.175.76.152 www.revtr.cn
O1 - Hosts: 219.133.40.91 qq.ljsll.com
O1 - Hosts: 203.208.35.102 www.aassccwe.cn
O1 - Hosts: 209.132.177.50 973.aksjd11.com
O1 - Hosts: 209.132.177.50 974.aksjd11.com
O1 - Hosts: 209.132.177.50 971.aksjd11.com
O1 - Hosts: 209.132.177.50 975.aksjd11.com
O1 - Hosts: 72.14.235.104 user1.12-39.net
O1 - Hosts: 72.14.235.147 www.infomt.net
O1 - Hosts: 192.150.18.101 ata1.sysions.net
O1 - Hosts: 192.150.18.101 ata2.sysions.net
O1 - Hosts: 192.150.18.101 ata3.sysions.net
O1 - Hosts: 192.150.18.101 ata4.sysions.net
O1 - Hosts: 193.120.42.226 8nnnnn99.cn
O1 - Hosts: 24.39.54.34 www.haoaoao.cn
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: detxbiua.dll - {20618412-C528-C784-C056-C164D1F7C502} - C:\WINDOWS\system32\detxbiua.dll (file missing)
O2 - BHO: ijdybpaw.dll - {2A698452-C5D8-C584-C256-C264C987C5A2} - C:\WINDOWS\system32\ijdybpaw.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: pqzfajke.dll - {60A345CD-ABCD-EFAB-CDEF-ABCD01020306} - C:\WINDOWS\system32\pqzfajke.dll (file missing)
O2 - BHO: zywmgime.dll - {7319A1F1-9410-9654-3201-345FFA349137} - C:\WINDOWS\system32\zywmgime.dll (file missing)
O2 - BHO: (no name) - {813DD04F-261A-428A-8309-3F541B2D2564} - c:\windows\system32\ziaashl.dll
O2 - BHO: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll (file missing)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [3PMmUpdate] rundll32 "C:\WINDOWS\Update.dll",Main
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1216438706155
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2C37B9D-5325-4248-9133-6C46B1F469C4}: NameServer = 218.248.255.146,218.248.240.46
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: tisqdtyu.dll,NTNJXSJTVC.dll,comremo.dll,myasemt.dll,googleons.dll,welycz.dll,jsnoer.dll,ezcron.dll,joliom.dll,fackwir.dll,caotxb.dll,ceshleo.dll,nhmxejkl.dll,woswelc.dll,avgrsstx.dll, mssetd.dll tiplict.dll businesn.dll esceps.dll keyiftp.dll baccops.dll aliens.dll offscrl.dll cmonos.dll wdhotem.dll xpsbos.dll manleu.dll squalle.dll therbrek.dll jolin0.dll,
O20 - Winlogon Notify: obklooga - C:\WINDOWS\SYSTEM32\ziaashl.dll
O21 - SSODL: DesktopWin - {DA191DE0-AA86-4ED0-4B87-292A3D48BE99} - C:\WINDOWS\AppPatch\DesktopWin.dll (file missing)
O21 - SSODL: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ATI WebPAM (ATIWebPAM) - Unknown owner - C:\Program Files\ATI\WebPAM\jetty\extra\win32\Wrapper.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
--
End of file - 10334 bytes
please help me to fix this problem ,if you need any more informations tell me in your reply


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked
Back to top


















