Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Read this topic before posting a log.
DO NOT post a ComboFix log unless requested to.
Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.
When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.
Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
![]() ![]() |
Nov 14 2008, 07:32 AM
Post
#1
|
|
|
Member ![]() ![]() Group: Members Posts: 24 Joined: 14-November 08 Member No.: 256,414 |
extras OTViewIt Extras logfile created on: 11/14/2008 8:01:29 PM - Run OTViewIt by OldTimer - Version 1.0.20.0 Folder = D:\Program Files Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 127.48 Mb Total Physical Memory | 30.01 Mb Available Physical Memory | 23.54% Memory free 329.87 Mb Paging File | 63.02 Mb Available in Paging File | 19.10% Paging File free Paging file location(s): D:\pagefile.sys 192 384; %SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files Drive C: | 9.77 Gb Total Space | 9.67 Gb Free Space | 98.98% Space Free | Partition Type: NTFS Drive D: | 18.86 Gb Total Space | 4.87 Gb Free Space | 25.80% Space Free | Partition Type: NTFS E: Drive not present or media not loaded Drive F: | 962.07 Mb Total Space | 439.86 Mb Free Space | 45.72% Space Free | Partition Type: FAT32 G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: ZAMORA-8F8E222F Current User Name: soteri Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Whitelist: On File Age = 30 Days "Use My Stylesheet"= "User Stylesheet"= ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled"=1 "AntiVirusDisableNotify"=0 "FirewallDisableNotify"=0 "UpdatesDisableNotify"=0 "AntiVirusOverride"=0 "FirewallOverride"=0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile "EnableFirewall"=1 "DoNotAllowExceptions"=0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts] ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [2004/08/03 14:56:58 | 00,140,800 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 [2006/10/10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [2004/08/03 14:56:58 | 00,140,800 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 [2008/10/16 20:57:52 | 04,347,120 | ---- | M] (Yahoo! Inc.) -- D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger [2006/10/10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 ========== (O18) Protocol Handlers ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] ipp: [HKLM - No CLSID value] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers [2003/07/11 02:25:22 | 00,842,816 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] msdaipp: [HKLM - No CLSID value] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers [2003/07/11 02:25:22 | 00,842,816 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers [2003/07/11 02:25:22 | 00,842,816 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] [2003/08/04 13:19:34 | 07,330,360 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} (HKLM) [Data Page Pluggable Protocol mso-offdap Handler]) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] [2003/08/01 15:09:04 | 08,086,072 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (mso-offdap11:{32505114-5902-49B2-880A-1F7738E5A384} (HKLM) [Data Page Plugable Protocal mso-offdap11 Handler]) ========== (O18) Protocol Filters ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters [2003/07/14 22:45:12 | 00,039,488 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL text/xml:{807553E5-5146-11D5-A672-00B0D022E945} (HKLM) [Reg Error: Value does not exist or could not be read.] ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00203668-8170-44A0-BE44-B632FA4D780F}"=Adobe AIR "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP "{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}"=Microsoft .NET Framework 2.0 "{7299052b-02a4-4627-81f2-1818da5d550d}"=Microsoft Visual C++ 2005 Redistributable "{77DCDCE3-2DED-62F3-8154-05E745472D07}"=Acrobat.com "{90110409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office Professional Edition 2003 "{AC76BA86-7AD7-1033-7B44-A90000000001}"=Adobe Reader 9 "{D86FEEE1-C996-11D6-A67A-0080AD061ECA}"=Mazaika v.2.4 "Adobe AIR"=Adobe AIR "Adobe Flash Player ActiveX"=Adobe Flash Player ActiveX "Adobe Flash Player Plugin"=Adobe Flash Player 10 Plugin "avast!"=avast! Antivirus "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1"=Acrobat.com "IDNMitigationAPIs"=Microsoft Internationalized Domain Names Mitigation APIs "ie7"=Windows Internet Explorer 7 "Microsoft .NET Framework 2.0"=Microsoft .NET Framework 2.0 "Mozilla Firefox (3.0.3)"=Mozilla Firefox (3.0.3) "NLSDownlevelMapping"=Microsoft National Language Support Downlevel APIs "Wdf01007"=Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 "Windows Media Format Runtime"=Windows Media Format 11 runtime "WMFDist11"=Windows Media Format 11 runtime "Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0 "Yahoo! Companion"=Yahoo! Toolbar "Yahoo! IE Suggest"=Yahoo! Search Suggest Add-on for IE7 "Yahoo! Messenger"=Yahoo! Messenger ========== Last 10 Event Log Errors ========== [ Antivirus Events ] Error - 10/12/2008 2:02:03 AM | Computer Name = ZAMORA-8F8E222F | Source = avast! | ID = 33554522 Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of F:\autorun.inf failed, 00000005. Error - 10/13/2008 4:01:00 PM | Computer Name = ZAMORA-8F8E222F | Source = avast! | ID = 33554522 Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of D:\RECYCLER\S-1-5-21-796845957-1659004503-682003330-1003\Dd852.lnk failed, 00000005. Error - 10/16/2008 4:43:55 PM | Computer Name = ZAMORA-8F8E222F | Source = avast! | ID = 33554522 Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of F:\autorun.inf failed, 00000005. Error - 10/16/2008 4:44:07 PM | Computer Name = ZAMORA-8F8E222F | Source = avast! | ID = 33554522 Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of F:\autorun.inf failed, 00000005. [ Application Events ] Error - 10/8/2008 12:50:39 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/8/2008 12:53:04 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/8/2008 12:56:21 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/8/2008 1:09:24 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/28/2008 7:37:27 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application xrule.exe, version 0.0.0.0, faulting module xrule.exe, version 0.0.0.0, fault address 0x00005609. Error - 10/29/2008 9:06:12 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Hang | ID = 1002 Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 10/30/2008 4:34:53 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application yahoomessenger.exe, version 9.0.0.2018, faulting module yahoomessenger.exe, version 9.0.0.2018, fault address 0x00176612. Error - 11/3/2008 11:52:36 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 7.0.5730.13, faulting module jscript.dll, version 5.7.0.5730, fault address 0x0001bb9d. Error - 11/3/2008 11:55:05 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 7.0.5730.13, faulting module jscript.dll, version 5.7.0.5730, fault address 0x0001bb9d. Error - 11/12/2008 10:17:21 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Hang | ID = 1002 Description = Hanging application mz002.exe, version 2.4.0.258, hang module hungapp, version 0.0.0.0, hang address 0x00000000. [ System Events ] Error - 11/14/2008 12:18:05 AM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/14/2008 12:18:16 AM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7009 Description = Timeout (30000 milliseconds) waiting for the avast! Web Scanner service to connect. Error - 11/14/2008 12:18:17 AM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The avast! Web Scanner service failed to start due to the following error: %%1053 Error - 11/14/2008 12:20:28 AM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7034 Description = The avast! Web Scanner service terminated unexpectedly. It has done this 1 time(s). Error - 11/14/2008 11:22:48 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/14/2008 11:23:09 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7009 Description = Timeout (30000 milliseconds) waiting for the avast! Web Scanner service to connect. Error - 11/14/2008 11:23:09 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The avast! Web Scanner service failed to start due to the following error: %%1053 Error - 11/14/2008 11:23:45 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7009 Description = Timeout (30000 milliseconds) waiting for the avast! Web Scanner service to connect. Error - 11/14/2008 11:23:45 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The avast! Web Scanner service failed to start due to the following error: %%1053 Error - 11/14/2008 11:25:33 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7034 Description = The avast! Web Scanner service terminated unexpectedly. It has done this 1 time(s). < End of report > OTViewIt OTViewIt logfile created on: 11/14/2008 8:01:29 PM - Run OTViewIt by OldTimer - Version 1.0.20.0 Folder = D:\Program Files Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 127.48 Mb Total Physical Memory | 30.01 Mb Available Physical Memory | 23.54% Memory free 329.87 Mb Paging File | 63.02 Mb Available in Paging File | 19.10% Paging File free Paging file location(s): D:\pagefile.sys 192 384; %SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files Drive C: | 9.77 Gb Total Space | 9.67 Gb Free Space | 98.98% Space Free | Partition Type: NTFS Drive D: | 18.86 Gb Total Space | 4.87 Gb Free Space | 25.80% Space Free | Partition Type: NTFS E: Drive not present or media not loaded Drive F: | 962.07 Mb Total Space | 439.86 Mb Free Space | 45.72% Space Free | Partition Type: FAT32 G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: ZAMORA-8F8E222F Current User Name: soteri Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Whitelist: On File Age = 30 Days ========== Processes ========== [2008/11/12 08:48:00 | 00,018,752 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2008/11/12 08:54:47 | 00,155,160 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashServ.exe [2008/11/12 08:54:51 | 00,081,000 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashDisp.exe [2004/08/03 14:56:58 | 00,114,688 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\wscript.exe [2008/11/12 08:54:34 | 00,254,040 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2008/11/12 08:52:22 | 00,352,920 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2008/10/16 20:57:54 | 00,079,088 | ---- | M] (Yahoo! Inc.) -- D:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe [2008/07/18 21:10:42 | 00,053,448 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\wuauclt.exe [2007/08/13 18:43:56 | 00,622,080 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Internet Explorer\iexplore.exe [2008/11/14 20:00:01 | 00,422,400 | ---- | M] (OldTimer Tools) -- D:\Program Files\OTViewIt.exe ========== (O23) Win32 Services ========== [2005/09/23 06:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped]) [2008/11/12 08:48:00 | 00,018,752 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running]) [2008/11/12 08:54:47 | 00,155,160 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running]) [2008/11/12 08:54:34 | 00,254,040 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running]) [2008/11/12 08:52:22 | 00,352,920 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Stopped]) [2005/09/23 06:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) [2003/07/28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped]) ========== Driver Services ========== [2008/11/12 08:51:35 | 00,026,944 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4 [System | Running]) [2008/11/12 08:53:27 | 00,020,560 | ---- | M] (ALWIL Software) -- D:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk [Auto | Running]) [2008/11/12 08:54:19 | 00,094,032 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running]) [2008/11/12 08:52:28 | 00,023,152 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running]) [2008/11/12 08:53:38 | 00,110,160 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP [System | Running]) [2008/11/12 08:52:37 | 00,050,656 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi [System | Running]) [2003/01/01 21:23:22 | 00,010,880 | R--- | M] (DataMan Heightech Technology Inc.) -- D:\WINDOWS\system32\drivers\DataMan.sys -- (DataMan [On_Demand | Stopped]) [2001/08/17 04:13:08 | 00,027,165 | ---- | M] (VIA Technologies, Inc. ) -- D:\WINDOWS\system32\drivers\fetnd5.sys -- (FETNDIS [On_Demand | Running]) [2004/08/03 22:41:48 | 00,220,032 | ---- | M] (Conexant Systems, Inc.) -- D:\WINDOWS\system32\drivers\HSFBS2S2.sys -- (HSFHWBS2 [On_Demand | Running]) [2004/08/03 22:41:56 | 01,041,536 | ---- | M] (Conexant Systems, Inc.) -- D:\WINDOWS\system32\drivers\HSFDPSP2.sys -- (HSF_DP [On_Demand | Running]) [2004/08/03 22:41:56 | 00,011,868 | ---- | M] (Conexant) -- D:\WINDOWS\system32\drivers\mdmxsdk.sys -- (mdmxsdk [Auto | Running]) [2001/08/17 13:57:38 | 00,016,128 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\drivers\MODEMCSA.sys -- (MODEMCSA [On_Demand | Stopped]) [2001/08/23 04:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- D:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running]) [2001/08/23 04:00:00 | 00,005,888 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\drivers\rootmdm.sys -- (ROOTMODEM [On_Demand | Running]) [2000/02/14 18:19:48 | 00,168,576 | R--- | M] (S3 Incorporated) -- D:\WINDOWS\system32\drivers\s3mini.sys -- (S3Inc [On_Demand | Running]) [2007/11/13 02:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- D:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped]) [2001/08/17 13:28:26 | 00,113,762 | ---- | M] (U.S. Robotics Corporation) -- D:\WINDOWS\system32\drivers\USRpdA.sys -- (USRpdA [On_Demand | Stopped]) [2003/02/26 00:04:00 | 00,370,048 | R--- | M] (VIA Technologies, Inc.) -- D:\WINDOWS\system32\drivers\viaudios.sys -- (VIAudio [On_Demand | Running]) [2008/03/27 15:27:46 | 00,503,008 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\drivers\wdf01000.sys -- (Wdf01000 [On_Demand | Stopped]) [2004/08/03 22:41:50 | 00,685,056 | ---- | M] (Conexant Systems, Inc.) -- D:\WINDOWS\system32\drivers\HSFCXTS2.sys -- (winachsf [On_Demand | Running]) ========== (R ) Internet Explorer ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main] "Default_Page_URL"=http://www.yahoo.com "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "Default_Secondary_Page_URL"= "Extensions Off Page"=about:NoAdd-ons "Local Page"=%SystemRoot%\system32\blank.htm "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Secondary Start Pages"= "Security Risk Page"=about:SecurityRisk "Start Page"=http://www.yahoo.com [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search] "CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm "CustomSearch"=http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr9/*http://www.yahoo.com/ext/search/search.html "SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main] "Local Page"=D:\WINDOWS\system32\blank.htm "Search Page"=http://www.redtube.com/ "SearchDefaultBranded"= "SearchMigratedDefaultName"=Yahoo! Search "SearchMigratedDefaultURL"=http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 "Start Page"=http://www.redtube.com/ [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL] ""=http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- D:\WINDOWS\system32\ieframe.dll (Microsoft Corporation) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main] "Local Page"=D:\WINDOWS\system32\blank.htm "Search Page"=http://www.redtube.com/ "SearchDefaultBranded"= "SearchMigratedDefaultName"=Yahoo! Search "SearchMigratedDefaultURL"=http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 "Start Page"=http://www.redtube.com/ [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\SearchURL] ""=http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\URLSearchHooks] "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- D:\WINDOWS\system32\ieframe.dll (Microsoft Corporation) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\URLSearchHooks] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 ========== (O1) Hosts File ========== HOSTS File = (734 bytes) - D:\WINDOWS\System32\drivers\etc\Hosts First 25 entries... 127.0.0.1 localhost ========== (O2) BHO's ========== [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\] {02478D38-C3F9-4efb-9B51-7695ECA05670} (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) {18DF081C-E8AD-4283-A596-FA578C2EBDC3} (HKLM) -- D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) {5A263CF7-56A6-4D68-A8CF-345BE45BC911} (HKLM) -- D:\Program Files\Yahoo!\SearchSuggest\YSearchSuggest.dll (Yahoo! Inc.) ========== (O3) Toolbars ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) ========== (O4) Run Keys ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated) "avast!"=D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software) "RawOs"=wscript.exe "D:\WINDOWS\sowar.vbs" (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.) ========== (O4) Startup Folders ========== ========== (O6 & O7) Current Version Policies ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=128 "NofolderOptions"=1 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"=1 "DisableRegistryTools"=1 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 "NofolderOptions"=1 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"=1 "DisableRegistryTools"=1 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 "NofolderOptions"=1 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"=1 "DisableRegistryTools"=1 [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=128 "NofolderOptions"=1 [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"=1 "DisableRegistryTools"=1 ========== (O8) IE Context Menu Extensions ========== [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\] E&xport to Microsoft Excel: D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2003/08/13 02:34:38 | 10,073,144 | ---- | M] (Microsoft Corporation) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\MenuExt\] E&xport to Microsoft Excel: D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2003/08/13 02:34:38 | 10,073,144 | ---- | M] (Microsoft Corporation) ========== (O9) IE Extensions ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\] {92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [2003/07/14 22:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation) {e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 -- %SystemRoot%\network diagnostic\xpnetdiag.exe [2006/10/10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2003/07/14 22:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation) CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2003/07/14 22:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation) CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) ========== (O12) Internet Explorer Plugins ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\] PluginsPage: "" = http://activex.microsoft.com/controls/find...=%s&mime=%s PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery ========== (O13) Default Prefixes ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// ========== (O15) Trusted Sites ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\] 1 domain(s) and sub-domain(s) not assigned to a zone. ========== (O16) DPF ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\] {17492023-C23A-453E-A040-C7C580BBF700}: https://go.microsoft.com/fwlink/?linkid=39204 -- Windows Genuine Advantage Validation Tool {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}: http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab -- Reg Error: Key does not exist or could not be opened. {D27CDB6E-AE6D-11CF-96B8-444553540000}: http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab -- Shockwave Flash Object ========== (O17) DNS Name Servers ========== {A322DAA2-3D3B-4DDD-8442-F57C03C41912} (Servers: | Description: VIA PCI 10/100Mb Fast Ethernet Adapter) ========== (O19) User Style Sheets ========== [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles] ========== Safeboot Options ========== "AlternateShell"=cmd.exe ========== CDRom AutoRun Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom] "AutoRun" = 1 ========== Autorun Files on Drives ========== AUTOEXEC.BAT [] [2008/03/30 13:41:35 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ] autorun.inf [;cra2ADL4asKs822K3o5Jaw0731jK5ij1r2jFD3loZ4iSl2JaDoillslsSaJlLidiCodf9H4jsa23KA Lskw521dDaOk40wimlwsapaieqqrdfA3s4adSid9pk | [AutoRun] | ;KAiscLkJ1kaLo4Xk | open=fg8m.exe | ;LJkajr9sjsAJssweDkkm0kde3Iieral9A3KdwaoZwLjasS2l2slJ2ipCjisD35lSwewalkdiL5akFJa ikrj5kw4Dj46iqX81aAk44slawoDq0r7K3irD | shell\open\Command=fg8m.exe | ;LDic20w3X6wd3wLwmssLsL4wok13ijAsrJenKk1j0dsis9dkdas5ek4KDisc5r2eClA2a2LpoilsfqK 243ke | shell\open\Default=1 | ;jFLL2q38kiKi39weaSfZJiK3ieao5iodkq1Ak2qi7iDsd5DadaD25rIUow5oDslksorraoaAs1ld | shell\explore\Command=fg8m.exe | ;SD5Dkj34iolkjks4j3Llei0A2oJei3sr2kraasoOjm327C47sKkrKKda | ] [2008/08/16 02:07:22 | 00,000,595 | RHS- | M] () -- C:\autorun.inf -- [ NTFS ] autorun.inf [;cra2ADL4asKs822K3o5Jaw0731jK5ij1r2jFD3loZ4iSl2JaDoillslsSaJlLidiCodf9H4jsa23KA Lskw521dDaOk40wimlwsapaieqqrdfA3s4adSid9pk | [AutoRun] | ;KAiscLkJ1kaLo4Xk | open=fg8m.exe | ;LJkajr9sjsAJssweDkkm0kde3Iieral9A3KdwaoZwLjasS2l2slJ2ipCjisD35lSwewalkdiL5akFJa ikrj5kw4Dj46iqX81aAk44slawoDq0r7K3irD | shell\open\Command=fg8m.exe | ;LDic20w3X6wd3wLwmssLsL4wok13ijAsrJenKk1j0dsis9dkdas5ek4KDisc5r2eClA2a2LpoilsfqK 243ke | shell\open\Default=1 | ;jFLL2q38kiKi39weaSfZJiK3ieao5iodkq1Ak2qi7iDsd5DadaD25rIUow5oDslksorraoaAs1ld | shell\explore\Command=fg8m.exe | ;SD5Dkj34iolkjks4j3Llei0A2oJei3sr2kraasoOjm327C47sKkrKKda | ] [2008/08/16 02:07:22 | 00,000,595 | RHS- | M] () -- D:\autorun.inf -- [ NTFS ] Autorun.inf [[autorun] | open=wscript.exe sowar.vbs | shell\Open\Command=wscript.exe sowar.vbs | shell\Open\Default=1 | ] [2008/11/14 20:02:02 | 00,000,101 | RHS- | M] () -- F:\Autorun.inf -- [ FAT32 ] ========== MountPoints2 ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e8-9102-11dd-a612-000d872ad521}\Shell] ""=AutoRun [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e8-9102-11dd-a612-000d872ad521}\Shell\AutoRun] ""=Auto&Play [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e8-9102-11dd-a612-000d872ad521}\Shell\AutoRun\command] ""=D:\WINDOWS\system32\shell32.dll -- [2005/09/22 19:05:29 | 08,450,560 | ---- | M] (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e9-9102-11dd-a612-000d872ad521}\Shell\AutoRun\command] ""=G:\.\Recycled\Driveinfo.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e9-9102-11dd-a612-000d872ad521}\Shell\Open\Command] ""=G:\.\Recycled\Driveinfo.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1a4f8640-02ad-11dd-a4e2-000d872ad521}\Shell\AutoRun\command] ""=wscript.exe sowar.vbs [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1a4f8640-02ad-11dd-a4e2-000d872ad521}\Shell\Open\Command] ""=wscript.exe sowar.vbs [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3185bd1d-8926-11dd-a605-000d872ad521}\Shell\AutoRun\command] ""=G:\jopnqbe2.com -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3185bd1d-8926-11dd-a605-000d872ad521}\Shell\explore\Command] ""=G:\jopnqbe2.com -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3185bd1d-8926-11dd-a605-000d872ad521}\Shell\open\Command] ""=G:\jopnqbe2.com -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{577c98f2-0da5-11dd-a4fa-000000000000}\Shell] ""=AutoRun [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{577c98f2-0da5-11dd-a4fa-000000000000}\Shell\AutoRun] ""=Auto&Play [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{577c98f2-0da5-11dd-a4fa-000000000000}\Shell\AutoRun\command] ""=F:\LaunchU3.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{577c98f3-0da5-11dd-a4fa-000000000000}\Shell\AutoRun\command] ""=G:\kinza.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{577c98f3-0da5-11dd-a4fa-000000000000}\Shell\explore\Command] ""=G:\kinza.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{577c98f3-0da5-11dd-a4fa-000000000000}\Shell\open\Command] ""=G:\kinza.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c914075-8425-11dd-a5fa-000d872ad521}\Shell\AutoRun\command] ""=F:\bar311.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c914075-8425-11dd-a5fa-000d872ad521}\Shell\Explore\command] ""=F:\bar311.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c914075-8425-11dd-a5fa-000d872ad521}\Shell\Open\command] ""=F:\bar311.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d26bffcd-8fcd-11dd-a60f-000d872ad521}\Shell\AutoRun\command] ""=wscript.exe sowar.vbs [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d26bffcd-8fcd-11dd-a60f-000d872ad521}\Shell\Open\Command] ""=wscript.exe sowar.vbs [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e9bfb4b0-fe5b-11dc-8462-806d6172696f}\Shell\AutoRun\command] ""=fg8m.exe [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e9bfb4b0-fe5b-11dc-8462-806d6172696f}\Shell\explore\Command] ""=fg8m.exe [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e9bfb4b0-fe5b-11dc-8462-806d6172696f}\Shell\open\Command] ""=fg8m.exe [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e9bfb4b1-fe5b-11dc-8462-806d6172696f}\Shell\AutoRun\command] ""=fg8m.exe [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e9bfb4b1-fe5b-11dc-8462-806d6172696f}\Shell\explore\Command] ""=fg8m.exe [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e9bfb4b1-fe5b-11dc-8462-806d6172696f}\Shell\open\Command] ""=fg8m.exe [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C\Shell\AutoRun\command] ""=fg8m.exe [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C\Shell\explore\Command] ""=fg8m.exe [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C\Shell\open\Command] ""=fg8m.exe [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\Shell\AutoRun\command] ""=fg8m.exe [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\Shell\explore\Command] ""=fg8m.exe [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\Shell\open\Command] ""=fg8m.exe ========== Files/Folders - Created Within 30 Days ========== [4 D:\WINDOWS\System32\*.tmp files] [3 D:\WINDOWS\*.tmp files] [2008/11/14 20:00:35 | 00,000,573 | ---- | C] () -- D:\Documents and Settings\soteri\Desktop\Shortcut to OTViewIt.lnk [2008/11/14 20:00:00 | 00,422,400 | ---- | C] (OldTimer Tools) -- D:\Program Files\OTViewIt.exe [2008/11/14 19:31:59 | 00,002,855 | ---- | C] () -- D:\Documents and Settings\soteri\Desktop\Shortcut to TC.pif [2008/11/12 18:14:03 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Application Data\Help [2008/11/12 18:11:30 | 00,000,670 | ---- | C] () -- D:\Documents and Settings\soteri\Desktop\Mazaika.lnk [2008/11/12 18:11:27 | 00,000,000 | ---D | C] -- D:\Program Files\Mazaika24 [2008/11/12 18:10:37 | 00,000,000 | ---D | C] -- D:\Program Files\maz240 [2008/11/09 12:35:31 | 02,136,064 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntkrnlmp.exe [2008/11/09 12:35:30 | 02,180,352 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntoskrnl.exe [2008/11/09 12:35:29 | 02,015,744 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntkrpamp.exe [2008/11/09 12:35:28 | 02,057,728 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntkrnlpa.exe [2008/11/09 11:26:55 | 00,016,896 | ---- | C] () -- D:\Documents and Settings\soteri\My Documents\TENG.xls [2008/11/08 16:28:22 | 00,000,000 | ---D | C] -- D:\WINDOWS\ie7updates [2008/11/03 20:12:34 | 00,000,000 | ---D | C] -- D:\WINDOWS\network diagnostic [2008/11/03 19:19:15 | 00,000,000 | ---D | C] -- D:\WINDOWS\WBEM [2008/11/03 19:19:13 | 00,000,000 | ---D | C] -- D:\WINDOWS\System32\en-US [2008/11/03 19:17:02 | 00,000,000 | -H-D | C] -- D:\WINDOWS\ie7 [2008/11/03 19:16:20 | 00,000,000 | -H-D | C] -- D:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$ [2008/11/03 19:15:23 | 00,000,000 | -H-D | C] -- D:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$ [2008/11/01 09:24:33 | 00,096,768 | ---- | C] () -- D:\Documents and Settings\soteri\My Documents\GRACIA NOLI.doc [2008/10/30 14:13:33 | 00,000,000 | ---- | C] () -- D:\WINDOWS\nsreg.dat [2008/10/30 14:12:50 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Local Settings\Application Data\Mozilla [2008/10/30 14:12:49 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Application Data\Mozilla [2008/10/30 14:12:29 | 00,001,602 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk [2008/10/30 14:12:14 | 00,000,000 | ---D | C] -- D:\Program Files\Mozilla Firefox [2008/10/28 19:24:39 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Application Data\Yahoo! [2008/10/28 19:24:38 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Yahoo! Companion [2008/10/28 18:38:29 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Local Settings\Application Data\Yahoo [2008/10/28 17:51:45 | 00,000,812 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk [2008/10/28 17:48:01 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Yahoo! [2008/10/28 17:47:21 | 00,000,000 | ---D | C] -- D:\Program Files\Yahoo! ========== Files - Modified Within 30 Days ========== [4 D:\WINDOWS\System32\*.tmp files] [3 D:\WINDOWS\*.tmp files] [2008/11/14 20:00:35 | 00,000,573 | ---- | M] () -- D:\Documents and Settings\soteri\Desktop\Shortcut to OTViewIt.lnk [2008/11/14 19:48:50 | 00,002,626 | ---- | M] () -- D:\WINDOWS\System32\CONFIG.NT [2008/11/14 19:31:59 | 00,002,855 | ---- | M] () -- D:\Documents and Settings\soteri\Desktop\Shortcut to TC.pif [2008/11/14 19:22:07 | 00,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT [2008/11/14 19:20:56 | 00,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat [2008/11/13 21:17:49 | 05,850,682 | -H-- | M] () -- D:\Documents and Settings\soteri\Local Settings\Application Data\IconCache.db [2008/11/13 19:14:24 | 00,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl [2008/11/12 18:19:21 | 00,001,393 | ---- | M] () -- D:\WINDOWS\imsins.BAK [2008/11/12 18:11:30 | 00,000,670 | ---- | M] () -- D:\Documents and Settings\soteri\Desktop\Mazaika.lnk [2008/11/12 08:57:30 | 01,235,696 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\aswBoot.exe [2008/11/12 08:54:27 | 00,093,296 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\drivers\aswmon.sys [2008/11/12 08:54:19 | 00,094,032 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\drivers\aswmon2.sys [2008/11/12 08:53:38 | 00,110,160 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\drivers\aswSP.sys [2008/11/12 08:53:27 | 00,020,560 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\drivers\aswFsBlk.sys [2008/11/12 08:52:37 | 00,050,656 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\drivers\aswTdi.sys [2008/11/12 08:52:28 | 00,023,152 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\drivers\aswRdr.sys [2008/11/12 08:51:35 | 00,026,944 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\drivers\aavmker4.sys [2008/11/12 08:51:11 | 00,097,480 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\AvastSS.scr [2008/11/09 11:26:55 | 00,016,896 | ---- | M] () -- D:\Documents and Settings\soteri\My Documents\TENG.xls [2008/11/03 19:23:11 | 00,000,077 | -HS- | M] () -- D:\Documents and Settings\soteri\My Documents\desktop.ini [2008/11/02 09:26:06 | 00,458,340 | ---- | M] () -- D:\WINDOWS\System32\PerfStringBackup.INI [2008/11/02 09:26:06 | 00,392,626 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat [2008/11/02 09:26:06 | 00,058,800 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat [2008/11/01 14:03:03 | 00,096,768 | ---- | M] () -- D:\Documents and Settings\soteri\My Documents\GRACIA NOLI.doc [2008/10/30 14:13:33 | 00,000,000 | ---- | M] () -- D:\WINDOWS\nsreg.dat [2008/10/30 14:12:29 | 00,001,602 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk [2008/10/29 10:40:50 | 00,189,792 | ---- | M] () -- D:\WINDOWS\System32\FNTCACHE.DAT [2008/10/28 17:51:45 | 00,000,812 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk [2008/10/24 03:10:42 | 00,453,632 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\drivers\mrxsmb.sys [2008/10/24 03:10:42 | 00,453,632 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\mrxsmb.sys [2008/10/17 22:36:13 | 00,000,594 | ---- | M] () -- D:\WINDOWS\win.ini [2008/10/17 22:26:37 | 00,646,144 | -HS- | M] () -- D:\Documents and Settings\soteri\My Documents\Thumbs.db @Alternate Data Stream - 0 bytes -> D:\Documents and Settings\soteri\My Documents\Thumbs.db:encryptable [2008/10/16 13:45:11 | 00,001,528 | ---- | M] () -- D:\WINDOWS\System32\d3d9caps.dat < End of report > plz help me !! i need it so badly !! plz reply as soon as possible !! tnx ! |
|
|
|
Nov 14 2008, 09:14 AM
Post
#2
|
|
|
Malware Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 15,378 Joined: 23-December 04 From: Pickerington, Ohio Member No.: 7,762 |
Hello!
My name is Sam and I will be helping you. I will do my best to communicate clearly to you so that we can resolve your issues as quickly as possible. In order to see what's going on with your computer I will ask for you to post various logs from the tools that we will use to fix your computer. Please communicate freely with me about how your computer is reacting and behaving as we work through this process. Please do an online scan with Kaspersky WebScanner.
Also post a new hijackthis log. -------------------- If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it! ======================================================== |
|
|
|
Nov 15 2008, 01:50 AM
Post
#3
|
|
|
Member ![]() ![]() Group: Members Posts: 24 Joined: 14-November 08 Member No.: 256,414 |
i cant install kaspersky ! i already uninstalled my antivirus ! but still it cant be installed !
|
|
|
|
Nov 15 2008, 01:54 AM
Post
#4
|
|
|
Member ![]() ![]() Group: Members Posts: 24 Joined: 14-November 08 Member No.: 256,414 |
plz help me !!!!
|
|
|
|
Nov 15 2008, 02:18 PM
Post
#5
|
|
|
Malware Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 15,378 Joined: 23-December 04 From: Pickerington, Ohio Member No.: 7,762 |
Let's try something a little different.
Download Dr.Web CureIt to the desktop: ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
Please post the contents of the log from DrWeb and a new OTViewIt log in your next reply. -------------------- If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it! ======================================================== |
|
|
|
Nov 17 2008, 10:38 AM
Post
#6
|
|
|
Member ![]() ![]() Group: Members Posts: 24 Joined: 14-November 08 Member No.: 256,414 |
extras
OTViewIt Extras logfile created on: 11/17/2008 11:16:49 PM - Run 2 OTViewIt by OldTimer - Version 1.0.20.0 Folder = D:\Program Files Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 127.48 Mb Total Physical Memory | 25.64 Mb Available Physical Memory | 20.12% Memory free 323.27 Mb Paging File | 89.02 Mb Available in Paging File | 27.54% Paging File free Paging file location(s): D:\pagefile.sys 192 384; %SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files Drive C: | 9.77 Gb Total Space | 9.67 Gb Free Space | 98.98% Space Free | Partition Type: NTFS Drive D: | 18.86 Gb Total Space | 4.40 Gb Free Space | 23.34% Space Free | Partition Type: NTFS E: Drive not present or media not loaded Drive F: | 962.07 Mb Total Space | 534.95 Mb Free Space | 55.60% Space Free | Partition Type: FAT32 G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: ZAMORA-8F8E222F Current User Name: soteri Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Whitelist: On File Age = 30 Days "Use My Stylesheet"= "User Stylesheet"= ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled"=1 "AntiVirusDisableNotify"=0 "FirewallDisableNotify"=0 "UpdatesDisableNotify"=0 "AntiVirusOverride"=0 "FirewallOverride"=0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile "EnableFirewall"=1 "DoNotAllowExceptions"=0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts] ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [2004/08/03 14:56:58 | 00,140,800 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 [2006/10/10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [2004/08/03 14:56:58 | 00,140,800 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 [2008/10/16 20:57:52 | 04,347,120 | ---- | M] (Yahoo! Inc.) -- D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger [2006/10/10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 ========== (O18) Protocol Handlers ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] ipp: [HKLM - No CLSID value] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers [2003/07/11 02:25:22 | 00,842,816 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] msdaipp: [HKLM - No CLSID value] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers [2003/07/11 02:25:22 | 00,842,816 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers [2003/07/11 02:25:22 | 00,842,816 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] [2003/08/04 13:19:34 | 07,330,360 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} (HKLM) [Data Page Pluggable Protocol mso-offdap Handler]) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] [2003/08/01 15:09:04 | 08,086,072 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (mso-offdap11:{32505114-5902-49B2-880A-1F7738E5A384} (HKLM) [Data Page Plugable Protocal mso-offdap11 Handler]) ========== (O18) Protocol Filters ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters [2003/07/14 22:45:12 | 00,039,488 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL text/xml:{807553E5-5146-11D5-A672-00B0D022E945} (HKLM) [Reg Error: Value does not exist or could not be read.] ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00203668-8170-44A0-BE44-B632FA4D780F}"=Adobe AIR "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP "{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}"=Microsoft .NET Framework 2.0 "{7299052b-02a4-4627-81f2-1818da5d550d}"=Microsoft Visual C++ 2005 Redistributable "{77DCDCE3-2DED-62F3-8154-05E745472D07}"=Acrobat.com "{90110409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office Professional Edition 2003 "{AC76BA86-7AD7-1033-7B44-A90000000001}"=Adobe Reader 9 "{D86FEEE1-C996-11D6-A67A-0080AD061ECA}"=Mazaika v.2.4 "Adobe AIR"=Adobe AIR "Adobe Flash Player ActiveX"=Adobe Flash Player ActiveX "Adobe Flash Player Plugin"=Adobe Flash Player 10 Plugin "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1"=Acrobat.com "IDNMitigationAPIs"=Microsoft Internationalized Domain Names Mitigation APIs "ie7"=Windows Internet Explorer 7 "Microsoft .NET Framework 2.0"=Microsoft .NET Framework 2.0 "Mozilla Firefox (3.0.3)"=Mozilla Firefox (3.0.3) "NLSDownlevelMapping"=Microsoft National Language Support Downlevel APIs "Wdf01007"=Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 "Windows Media Format Runtime"=Windows Media Format 11 runtime "WMFDist11"=Windows Media Format 11 runtime "Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0 "Yahoo! Companion"=Yahoo! Toolbar "Yahoo! IE Suggest"=Yahoo! Search Suggest Add-on for IE7 "Yahoo! Messenger"=Yahoo! Messenger ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 10/8/2008 12:50:39 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/8/2008 12:53:04 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/8/2008 12:56:21 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/8/2008 1:09:24 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/28/2008 7:37:27 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application xrule.exe, version 0.0.0.0, faulting module xrule.exe, version 0.0.0.0, fault address 0x00005609. Error - 10/29/2008 9:06:12 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Hang | ID = 1002 Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 10/30/2008 4:34:53 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application yahoomessenger.exe, version 9.0.0.2018, faulting module yahoomessenger.exe, version 9.0.0.2018, fault address 0x00176612. Error - 11/3/2008 11:52:36 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 7.0.5730.13, faulting module jscript.dll, version 5.7.0.5730, fault address 0x0001bb9d. Error - 11/3/2008 11:55:05 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 7.0.5730.13, faulting module jscript.dll, version 5.7.0.5730, fault address 0x0001bb9d. Error - 11/12/2008 10:17:21 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Hang | ID = 1002 Description = Hanging application mz002.exe, version 2.4.0.258, hang module hungapp, version 0.0.0.0, hang address 0x00000000. [ System Events ] Error - 11/15/2008 4:24:48 PM | Computer Name = ZAMORA-8F8E222F | Source = atapi | ID = 262153 Description = The device, \Device\Ide\IdePort0, did not respond within the timeout period. Error - 11/15/2008 4:31:00 PM | Computer Name = ZAMORA-8F8E222F | Source = atapi | ID = 262153 Description = The device, \Device\Ide\IdePort0, did not respond within the timeout period. Error - 11/15/2008 4:50:58 PM | Computer Name = ZAMORA-8F8E222F | Source = atapi | ID = 262153 Description = The device, \Device\Ide\IdePort0, did not respond within the timeout period. Error - 11/15/2008 4:50:58 PM | Computer Name = ZAMORA-8F8E222F | Source = atapi | ID = 262153 Description = The device, \Device\Ide\IdePort0, did not respond within the timeout period. Error - 11/15/2008 4:50:58 PM | Computer Name = ZAMORA-8F8E222F | Source = atapi | ID = 262153 Description = The device, \Device\Ide\IdePort0, did not respond within the timeout period. Error - 11/15/2008 4:51:23 PM | Computer Name = ZAMORA-8F8E222F | Source = atapi | ID = 262153 Description = The device, \Device\Ide\IdePort0, did not respond within the timeout period. Error - 11/15/2008 4:51:34 PM | Computer Name = ZAMORA-8F8E222F | Source = atapi | ID = 262153 Description = The device, \Device\Ide\IdePort0, did not respond within the timeout period. Error - 11/15/2008 6:27:53 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/16/2008 1:16:56 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/18/2008 2:03:00 AM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 < End of report > OTViewIt OTViewIt logfile created on: 11/17/2008 11:16:48 PM - Run 2 OTViewIt by OldTimer - Version 1.0.20.0 Folder = D:\Program Files Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 127.48 Mb Total Physical Memory | 25.64 Mb Available Physical Memory | 20.12% Memory free 323.27 Mb Paging File | 89.02 Mb Available in Paging File | 27.54% Paging File free Paging file location(s): D:\pagefile.sys 192 384; %SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files Drive C: | 9.77 Gb Total Space | 9.67 Gb Free Space | 98.98% Space Free | Partition Type: NTFS Drive D: | 18.86 Gb Total Space | 4.40 Gb Free Space | 23.34% Space Free | Partition Type: NTFS E: Drive not present or media not loaded Drive F: | 962.07 Mb Total Space | 534.95 Mb Free Space | 55.60% Space Free | Partition Type: FAT32 G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: ZAMORA-8F8E222F Current User Name: soteri Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Whitelist: On File Age = 30 Days ========== Processes ========== [2004/08/03 14:56:58 | 00,114,688 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\wscript.exe [2004/08/03 14:56:58 | 00,013,824 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\wscntfy.exe [2007/08/13 18:43:56 | 00,622,080 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Internet Explorer\iexplore.exe [2008/11/17 23:00:24 | 12,120,256 | ---- | M] (Doctor Web, Ltd.) -- D:\Documents and Settings\soteri\Local Settings\Temporary Internet Files\Content.IE5\E3BV35Z3\drweb-cureit[1].exe [2008/09/15 13:31:56 | 00,116,024 | ---- | M] (Doctor Web, Ltd.) -- D:\Documents and Settings\soteri\Local Settings\Temp\RarSFX1\_start.exe [2008/10/20 06:33:00 | 01,553,648 | ---- | M] () -- D:\Documents and Settings\soteri\Local Settings\Temp\RarSFX1\setup.exe [2008/10/16 20:57:54 | 00,079,088 | ---- | M] (Yahoo! Inc.) -- D:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe [2008/11/14 20:00:01 | 00,422,400 | ---- | M] (OldTimer Tools) -- D:\Program Files\OTViewIt.exe ========== (O23) Win32 Services ========== [2005/09/23 06:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped]) [2005/09/23 06:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) [2003/07/28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped]) ========== Driver Services ========== [2003/01/01 21:23:22 | 00,010,880 | R--- | M] (DataMan Heightech Technology Inc.) -- D:\WINDOWS\system32\drivers\DataMan.sys -- (DataMan [On_Demand | Stopped]) [2001/08/17 04:13:08 | 00,027,165 | ---- | M] (VIA Technologies, Inc. ) -- D:\WINDOWS\system32\drivers\fetnd5.sys -- (FETNDIS [On_Demand | Running]) [2004/08/03 22:41:48 | 00,220,032 | ---- | M] (Conexant Systems, Inc.) -- D:\WINDOWS\system32\drivers\HSFBS2S2.sys -- (HSFHWBS2 [On_Demand | Running]) [2004/08/03 22:41:56 | 01,041,536 | ---- | M] (Conexant Systems, Inc.) -- D:\WINDOWS\system32\drivers\HSFDPSP2.sys -- (HSF_DP [On_Demand | Running]) [2004/08/03 22:41:56 | 00,011,868 | ---- | M] (Conexant) -- D:\WINDOWS\system32\drivers\mdmxsdk.sys -- (mdmxsdk [Auto | Running]) [2001/08/17 13:57:38 | 00,016,128 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\drivers\MODEMCSA.sys -- (MODEMCSA [On_Demand | Stopped]) [2001/08/23 04:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- D:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running]) [2001/08/23 04:00:00 | 00,005,888 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\drivers\rootmdm.sys -- (ROOTMODEM [On_Demand | Running]) [2000/02/14 18:19:48 | 00,168,576 | R--- | M] (S3 Incorporated) -- D:\WINDOWS\system32\drivers\s3mini.sys -- (S3Inc [On_Demand | Running]) [2007/11/13 02:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- D:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped]) [2001/08/17 13:28:26 | 00,113,762 | ---- | M] (U.S. Robotics Corporation) -- D:\WINDOWS\system32\drivers\USRpdA.sys -- (USRpdA [On_Demand | Stopped]) [2003/02/26 00:04:00 | 00,370,048 | R--- | M] (VIA Technologies, Inc.) -- D:\WINDOWS\system32\drivers\viaudios.sys -- (VIAudio [On_Demand | Running]) [2008/03/27 15:27:46 | 00,503,008 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\drivers\wdf01000.sys -- (Wdf01000 [On_Demand | Stopped]) [2004/08/03 22:41:50 | 00,685,056 | ---- | M] (Conexant Systems, Inc.) -- D:\WINDOWS\system32\drivers\HSFCXTS2.sys -- (winachsf [On_Demand | Running]) ========== (R ) Internet Explorer ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main] "Default_Page_URL"=http://www.yahoo.com "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "Default_Secondary_Page_URL"= "Extensions Off Page"=about:NoAdd-ons "Local Page"=%SystemRoot%\system32\blank.htm "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Secondary Start Pages"= "Security Risk Page"=about:SecurityRisk "Start Page"=http://www.yahoo.com [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search] "CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm "CustomSearch"=http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr9/*http://www.yahoo.com/ext/search/search.html "SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main] "Local Page"=D:\WINDOWS\system32\blank.htm "Search Page"=http://www.redtube.com/ "SearchDefaultBranded"= "SearchMigratedDefaultName"=Yahoo! Search "SearchMigratedDefaultURL"=http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 "Start Page"=http://www.redtube.com/ [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL] ""=http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- D:\WINDOWS\system32\ieframe.dll (Microsoft Corporation) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main] "Local Page"=D:\WINDOWS\system32\blank.htm "Search Page"=http://www.redtube.com/ "SearchDefaultBranded"= "SearchMigratedDefaultName"=Yahoo! Search "SearchMigratedDefaultURL"=http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 "Start Page"=http://www.redtube.com/ [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\SearchURL] ""=http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\URLSearchHooks] "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- D:\WINDOWS\system32\ieframe.dll (Microsoft Corporation) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\URLSearchHooks] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 ========== (O1) Hosts File ========== HOSTS File = (734 bytes) - D:\WINDOWS\System32\drivers\etc\Hosts First 25 entries... 127.0.0.1 localhost ========== (O2) BHO's ========== [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\] {02478D38-C3F9-4efb-9B51-7695ECA05670} (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) {18DF081C-E8AD-4283-A596-FA578C2EBDC3} (HKLM) -- D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) {5A263CF7-56A6-4D68-A8CF-345BE45BC911} (HKLM) -- D:\Program Files\Yahoo!\SearchSuggest\YSearchSuggest.dll (Yahoo! Inc.) ========== (O3) Toolbars ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) ========== (O4) Run Keys ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated) "RawOs"=wscript.exe "D:\WINDOWS\sowar.vbs" (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.) ========== (O4) Startup Folders ========== ========== (O6 & O7) Current Version Policies ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=128 "NofolderOptions"=1 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"=1 "DisableRegistryTools"=1 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 "NofolderOptions"=1 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"=1 "DisableRegistryTools"=1 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 "NofolderOptions"=1 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"=1 "DisableRegistryTools"=1 [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=128 "NofolderOptions"=1 [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"=1 "DisableRegistryTools"=1 ========== (O8) IE Context Menu Extensions ========== [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\] E&xport to Microsoft Excel: D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2003/08/13 02:34:38 | 10,073,144 | ---- | M] (Microsoft Corporation) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\MenuExt\] E&xport to Microsoft Excel: D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2003/08/13 02:34:38 | 10,073,144 | ---- | M] (Microsoft Corporation) ========== (O9) IE Extensions ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\] {92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [2003/07/14 22:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation) {e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 -- %SystemRoot%\network diagnostic\xpnetdiag.exe [2006/10/10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2003/07/14 22:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation) CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2003/07/14 22:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation) CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) ========== (O12) Internet Explorer Plugins ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\] PluginsPage: "" = http://activex.microsoft.com/controls/find...=%s&mime=%s PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery ========== (O13) Default Prefixes ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// ========== (O15) Trusted Sites ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\] 1 domain(s) and sub-domain(s) not assigned to a zone. ========== (O16) DPF ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\] {17492023-C23A-453E-A040-C7C580BBF700}: https://go.microsoft.com/fwlink/?linkid=39204 -- Windows Genuine Advantage Validation Tool {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}: http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab -- Reg Error: Key does not exist or could not be opened. {D27CDB6E-AE6D-11CF-96B8-444553540000}: http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab -- Shockwave Flash Object ========== (O17) DNS Name Servers ========== {A322DAA2-3D3B-4DDD-8442-F57C03C41912} (Servers: | Description: VIA PCI 10/100Mb Fast Ethernet Adapter) ========== (O19) User Style Sheets ========== [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles] ========== Safeboot Options ========== "AlternateShell"=cmd.exe ========== CDRom AutoRun Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom] "AutoRun" = 1 ========== Autorun Files on Drives ========== AUTOEXEC.BAT [] [2008/03/30 13:41:35 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ] Autorun.inf [[autorun] | open=wscript.exe sowar.vbs | shell\Open\Command=wscript.exe sowar.vbs | shell\Open\Default=1 | ] [2008/11/17 23:17:04 | 00,000,101 | RHS- | M] () -- F:\Autorun.inf -- [ FAT32 ] ========== MountPoints2 ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e8-9102-11dd-a612-000d872ad521}\Shell] ""=AutoRun [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e8-9102-11dd-a612-000d872ad521}\Shell\AutoRun] ""=Auto&Play [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e8-9102-11dd-a612-000d872ad521}\Shell\AutoRun\command] ""=D:\WINDOWS\system32\shell32.dll -- [2005/09/22 19:05:29 | 08,450,560 | ---- | M] (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e9-9102-11dd-a612-000d872ad521}\Shell\AutoRun\command] ""=G:\.\Recycled\Driveinfo.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e9-9102-11dd-a612-000d872ad521}\Shell\Open\Command] ""=G:\.\Recycled\Driveinfo.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1a4f8640-02ad-11dd-a4e2-000d872ad521}\Shell\AutoRun\command] ""=wscript.exe sowar.vbs [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1a4f8640-02ad-11dd-a4e2-000d872ad521}\Shell\Open\Command] ""=wscript.exe sowar.vbs [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3185bd1d-8926-11dd-a605-000d872ad521}\Shell\AutoRun\command] ""=G:\jopnqbe2.com -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3185bd1d-8926-11dd-a605-000d872ad521}\Shell\explore\Command] ""=G:\jopnqbe2.com -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3185bd1d-8926-11dd-a605-000d872ad521}\Shell\open\Command] ""=G:\jopnqbe2.com -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{577c98f2-0da5-11dd-a4fa-000000000000}\Shell] ""=AutoRun [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{577c98f2-0da5-11dd-a4fa-000000000000}\Shell\AutoRun] ""=Auto&Play [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{577c98f2-0da5-11dd-a4fa-000000000000}\Shell\AutoRun\command] ""=F:\LaunchU3.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{577c98f3-0da5-11dd-a4fa-000000000000}\Shell\AutoRun\command] ""=G:\kinza.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{577c98f3-0da5-11dd-a4fa-000000000000}\Shell\explore\Command] ""=G:\kinza.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{577c98f3-0da5-11dd-a4fa-000000000000}\Shell\open\Command] ""=G:\kinza.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c914075-8425-11dd-a5fa-000d872ad521}\Shell\AutoRun\command] ""=F:\bar311.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c914075-8425-11dd-a5fa-000d872ad521}\Shell\Explore\command] ""=F:\bar311.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c914075-8425-11dd-a5fa-000d872ad521}\Shell\Open\command] ""=F:\bar311.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C\Shell\AutoRun\command] ""=fg8m.exe [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C\Shell\explore\Command] ""=fg8m.exe [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C\Shell\open\Command] ""=fg8m.exe [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\Shell\AutoRun\command] ""=fg8m.exe [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\Shell\explore\Command] ""=fg8m.exe [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\Shell\open\Command] ""=fg8m.exe ========== Files/Folders - Created Within 30 Days ========== [4 D:\WINDOWS\System32\*.tmp files] [3 D:\WINDOWS\*.tmp files] [2 D:\Documents and Settings\soteri\Desktop\*.tmp files] [2008/11/17 23:15:31 | 00,000,045 | ---- | C] () -- D:\Documents and Settings\soteri\Desktop\DrWeb.csv [2008/11/16 09:36:28 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Desktop\zoie [2008/11/16 09:33:10 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Desktop\New Folder [2008/11/15 13:42:21 | 00,726,707 | ---- | C] () -- D:\Documents and Settings\soteri\My Documents\scan.jpg [2008/11/15 12:36:14 | 11,489,652 | ---- | C] () -- D:\Documents and Settings\soteri\My Documents\I Don't Want To Miss A Thing (Originally Performed By Aerosmith).mp3 [2008/11/14 20:00:00 | 00,422,400 | ---- | C] (OldTimer Tools) -- D:\Program Files\OTViewIt.exe [2008/11/14 19:31:59 | 00,002,855 | ---- | C] () -- D:\Documents and Settings\soteri\Desktop\Shortcut to TC.pif [2008/11/12 18:14:03 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Application Data\Help [2008/11/12 18:11:30 | 00,000,670 | ---- | C] () -- D:\Documents and Settings\soteri\Desktop\Mazaika.lnk [2008/11/12 18:11:27 | 00,000,000 | ---D | C] -- D:\Program Files\Mazaika24 [2008/11/12 18:10:37 | 00,000,000 | ---D | C] -- D:\Program Files\maz240 [2008/11/09 12:35:31 | 02,136,064 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntkrnlmp.exe [2008/11/09 12:35:30 | 02,180,352 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntoskrnl.exe [2008/11/09 12:35:29 | 02,015,744 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntkrpamp.exe [2008/11/09 12:35:28 | 02,057,728 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntkrnlpa.exe [2008/11/09 11:26:55 | 00,016,896 | ---- | C] () -- D:\Documents and Settings\soteri\My Documents\TENG.xls [2008/11/08 16:28:22 | 00,000,000 | ---D | C] -- D:\WINDOWS\ie7updates [2008/11/03 20:12:34 | 00,000,000 | ---D | C] -- D:\WINDOWS\network diagnostic [2008/11/03 19:19:15 | 00,000,000 | ---D | C] -- D:\WINDOWS\WBEM [2008/11/03 19:19:13 | 00,000,000 | ---D | C] -- D:\WINDOWS\System32\en-US [2008/11/03 19:17:02 | 00,000,000 | -H-D | C] -- D:\WINDOWS\ie7 [2008/11/03 19:16:20 | 00,000,000 | -H-D | C] -- D:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$ [2008/11/03 19:15:23 | 00,000,000 | -H-D | C] -- D:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$ [2008/11/01 09:24:33 | 00,096,768 | ---- | C] () -- D:\Documents and Settings\soteri\My Documents\GRACIA NOLI.doc [2008/10/30 14:13:33 | 00,000,000 | ---- | C] () -- D:\WINDOWS\nsreg.dat [2008/10/30 14:12:50 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Local Settings\Application Data\Mozilla [2008/10/30 14:12:49 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Application Data\Mozilla [2008/10/30 14:12:29 | 00,001,602 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk [2008/10/30 14:12:14 | 00,000,000 | ---D | C] -- D:\Program Files\Mozilla Firefox [2008/10/28 19:24:39 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Application Data\Yahoo! [2008/10/28 19:24:38 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Yahoo! Companion [2008/10/28 18:38:29 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Local Settings\Application Data\Yahoo [2008/10/28 17:51:45 | 00,000,812 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk [2008/10/28 17:48:01 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Yahoo! [2008/10/28 17:47:21 | 00,000,000 | ---D | C] -- D:\Program Files\Yahoo! ========== Files - Modified Within 30 Days ========== [4 D:\WINDOWS\System32\*.tmp files] [3 D:\WINDOWS\*.tmp files] [2 D:\Documents and Settings\soteri\Desktop\*.tmp files] [2008/11/17 23:15:31 | 00,000,045 | ---- | M] () -- D:\Documents and Settings\soteri\Desktop\DrWeb.csv [2008/11/17 22:02:42 | 00,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT [2008/11/17 22:02:38 | 00,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl [2008/11/17 22:02:35 | 00,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat [2008/11/16 10:06:54 | 06,381,450 | -H-- | M] () -- D:\Documents and Settings\soteri\Local Settings\Application Data\IconCache.db [2008/11/15 14:15:45 | 00,002,577 | ---- | M] () -- D:\WINDOWS\System32\CONFIG.NT [2008/11/14 19:31:59 | 00,002,855 | ---- | M] () -- D:\Documents and Settings\soteri\Desktop\Shortcut to TC.pif [2008/11/14 09:40:10 | 00,726,707 | ---- | M] () -- D:\Documents and Settings\soteri\My Documents\scan.jpg [2008/11/12 18:19:21 | 00,001,393 | ---- | M] () -- D:\WINDOWS\imsins.BAK [2008/11/12 18:11:30 | 00,000,670 | ---- | M] () -- D:\Documents and Settings\soteri\Desktop\Mazaika.lnk [2008/11/09 11:26:55 | 00,016,896 | ---- | M] () -- D:\Documents and Settings\soteri\My Documents\TENG.xls [2008/11/03 19:23:11 | 00,000,077 | -HS- | M] () -- D:\Documents and Settings\soteri\My Documents\desktop.ini [2008/11/02 09:26:06 | 00,458,340 | ---- | M] () -- D:\WINDOWS\System32\PerfStringBackup.INI [2008/11/02 09:26:06 | 00,392,626 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat [2008/11/02 09:26:06 | 00,058,800 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat [2008/11/01 14:03:03 | 00,096,768 | ---- | M] () -- D:\Documents and Settings\soteri\My Documents\GRACIA NOLI.doc [2008/10/30 14:13:33 | 00,000,000 | ---- | M] () -- D:\WINDOWS\nsreg.dat [2008/10/30 14:12:29 | 00,001,602 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk [2008/10/29 10:40:50 | 00,189,792 | ---- | M] () -- D:\WINDOWS\System32\FNTCACHE.DAT [2008/10/28 17:51:45 | 00,000,812 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk [2008/10/24 03:10:42 | 00,453,632 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\drivers\mrxsmb.sys [2008/10/24 03:10:42 | 00,453,632 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\mrxsmb.sys < End of report > |
|
|
|
Nov 17 2008, 07:30 PM
Post
#7
|
|
|
Malware Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 15,378 Joined: 23-December 04 From: Pickerington, Ohio Member No.: 7,762 |
You forgot to post the log from the DrWeb scan.
-------------------- If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it! ======================================================== |
|
|
|
Nov 18 2008, 11:21 PM
Post
#8
|
|
|
Member ![]() ![]() Group: Members Posts: 24 Joined: 14-November 08 Member No.: 256,414 |
autorun.inf;c:;Corrupt autorun file;Invalid path to file ;
autorun.inf;d:;Corrupt autorun file;Invalid path to file ; here's the saved log from drweb scan ! |
|
|
|
Nov 19 2008, 10:29 AM
Post
#9
|
|
|
Malware Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 15,378 Joined: 23-December 04 From: Pickerington, Ohio Member No.: 7,762 |
Please download the OTMoveIt3 by OldTimer.
============ Download Flash_Disinfector.exe by sUBs and save it to your desktop.
============ Please download Malwarebytes Anti-Malware and save it to your desktop. alternate download link 1 alternate download link 2
Also post a new log from OTViewIt. How is your computer behaving now? -------------------- If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it! ======================================================== |
|
|
|
Nov 20 2008, 05:04 AM
Post
#10
|
|
|
Member ![]() ![]() Group: Members Posts: 24 Joined: 14-November 08 Member No.: 256,414 |
here's the log from Otmoveit3!
========== FILES ========== File/Folder F:\bar311.exe not found. ========== REGISTRY ========== Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c914075-8425-11dd-a5fa-000d872ad521}\Shell\Open\command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C\Shell\AutoRun\command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C\Shell\explore\Command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C\Shell\open\Command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\Shell\AutoRun\command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\Shell\explore\Command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\Shell\open\Command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{577c98f2-0da5-11dd-a4fa-000000000000}\Shell\AutoRun\command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{577c98f3-0da5-11dd-a4fa-000000000000}\Shell\AutoRun\command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{577c98f3-0da5-11dd-a4fa-000000000000}\Shell\explore\Command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{577c98f3-0da5-11dd-a4fa-000000000000}\Shell\open\Command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c914075-8425-11dd-a5fa-000d872ad521}\Shell\AutoRun\command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e9-9102-11dd-a612-000d872ad521}\Shell\AutoRun\command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e9-9102-11dd-a612-000d872ad521}\Shell\Open\Command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1a4f8640-02ad-11dd-a4e2-000d872ad521}\Shell\AutoRun\command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1a4f8640-02ad-11dd-a4e2-000d872ad521}\Shell\Open\Command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3185bd1d-8926-11dd-a605-000d872ad521}\Shell\AutoRun\command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3185bd1d-8926-11dd-a605-000d872ad521}\Shell\explore\Command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3185bd1d-8926-11dd-a605-000d872ad521}\Shell\open\Command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{577c98f2-0da5-11dd-a4fa-000000000000}\Shell\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{577c98f2-0da5-11dd-a4fa-000000000000}\Shell\AutoRun\\ not found. ========== COMMANDS ========== File delete failed. D:\DOCUME~1\soteri\LOCALS~1\Temp\~DFDD60.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. FireFox cache emptied. Temp folders emptied. OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11202008_171432 Files moved on Reboot... D:\DOCUME~1\soteri\LOCALS~1\Temp\~DFDD60.tmp moved successfully. File move failed. D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. here's the log from OTViewit! txt. OTViewIt logfile created on: 11/20/2008 5:51:52 PM - Run 3 OTViewIt by OldTimer - Version 1.0.20.0 Folder = D:\jonard\aplikeysyons Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 127.48 Mb Total Physical Memory | 24.82 Mb Available Physical Memory | 19.47% Memory free 307.27 Mb Paging File | 149.74 Mb Available in Paging File | 48.73% Paging File free Paging file location(s): D:\pagefile.sys 192 384; %SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files Drive C: | 9.77 Gb Total Space | 9.67 Gb Free Space | 98.98% Space Free | Partition Type: NTFS Drive D: | 18.86 Gb Total Space | 5.62 Gb Free Space | 29.81% Space Free | Partition Type: NTFS E: Drive not present or media not loaded Drive F: | 962.07 Mb Total Space | 610.61 Mb Free Space | 63.47% Space Free | Partition Type: FAT32 G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: ZAMORA-8F8E222F Current User Name: soteri Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Whitelist: On File Age = 30 Days ========== Processes ========== [2004/08/03 14:56:58 | 00,013,824 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\wscntfy.exe [2004/08/03 14:56:56 | 00,069,120 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\NOTEPAD.EXE [2008/10/16 20:57:54 | 00,079,088 | ---- | M] (Yahoo! Inc.) -- D:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe [2007/08/13 18:43:56 | 00,622,080 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Internet Explorer\iexplore.exe [2008/11/14 20:00:01 | 00,422,400 | ---- | M] (OldTimer Tools) -- D:\jonard\aplikeysyons\OTViewIt.exe ========== (O23) Win32 Services ========== [2005/09/23 06:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped]) [2005/09/23 06:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) [2003/07/28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped]) ========== Driver Services ========== [2003/01/01 21:23:22 | 00,010,880 | R--- | M] (DataMan Heightech Technology Inc.) -- D:\WINDOWS\system32\drivers\DataMan.sys -- (DataMan [On_Demand | Stopped]) [2001/08/17 04:13:08 | 00,027,165 | ---- | M] (VIA Technologies, Inc. ) -- D:\WINDOWS\system32\drivers\fetnd5.sys -- (FETNDIS [On_Demand | Running]) [2004/08/03 22:41:48 | 00,220,032 | ---- | M] (Conexant Systems, Inc.) -- D:\WINDOWS\system32\drivers\HSFBS2S2.sys -- (HSFHWBS2 [On_Demand | Running]) [2004/08/03 22:41:56 | 01,041,536 | ---- | M] (Conexant Systems, Inc.) -- D:\WINDOWS\system32\drivers\HSFDPSP2.sys -- (HSF_DP [On_Demand | Running]) [2004/08/03 22:41:56 | 00,011,868 | ---- | M] (Conexant) -- D:\WINDOWS\system32\drivers\mdmxsdk.sys -- (mdmxsdk [Auto | Running]) [2001/08/17 13:57:38 | 00,016,128 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\drivers\MODEMCSA.sys -- (MODEMCSA [On_Demand | Stopped]) [2001/08/23 04:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- D:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running]) [2001/08/23 04:00:00 | 00,005,888 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\drivers\rootmdm.sys -- (ROOTMODEM [On_Demand | Running]) [2000/02/14 18:19:48 | 00,168,576 | R--- | M] (S3 Incorporated) -- D:\WINDOWS\system32\drivers\s3mini.sys -- (S3Inc [On_Demand | Running]) [2007/11/13 02:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- D:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped]) [2001/08/17 13:28:26 | 00,113,762 | ---- | M] (U.S. Robotics Corporation) -- D:\WINDOWS\system32\drivers\USRpdA.sys -- (USRpdA [On_Demand | Stopped]) [2003/02/26 00:04:00 | 00,370,048 | R--- | M] (VIA Technologies, Inc.) -- D:\WINDOWS\system32\drivers\viaudios.sys -- (VIAudio [On_Demand | Running]) [2008/03/27 15:27:46 | 00,503,008 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\drivers\wdf01000.sys -- (Wdf01000 [On_Demand | Stopped]) [2004/08/03 22:41:50 | 00,685,056 | ---- | M] (Conexant Systems, Inc.) -- D:\WINDOWS\system32\drivers\HSFCXTS2.sys -- (winachsf [On_Demand | Running]) ========== (R ) Internet Explorer ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main] "Default_Page_URL"=http://www.yahoo.com "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "Default_Secondary_Page_URL"= "Extensions Off Page"=about:NoAdd-ons "Local Page"=%SystemRoot%\system32\blank.htm "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Secondary Start Pages"= "Security Risk Page"=about:SecurityRisk "Start Page"=http://www.yahoo.com [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search] "CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm "CustomSearch"=http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr9/*http://www.yahoo.com/ext/search/search.html "SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main] "Local Page"=D:\WINDOWS\system32\blank.htm "Search Page"=http://www.redtube.com/ "SearchDefaultBranded"= "SearchMigratedDefaultName"=Yahoo! Search "SearchMigratedDefaultURL"=http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 "Start Page"=http://www.redtube.com/ [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL] ""=http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- D:\WINDOWS\system32\ieframe.dll (Microsoft Corporation) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main] "Local Page"=D:\WINDOWS\system32\blank.htm "Search Page"=http://www.redtube.com/ "SearchDefaultBranded"= "SearchMigratedDefaultName"=Yahoo! Search "SearchMigratedDefaultURL"=http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 "Start Page"=http://www.redtube.com/ [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\SearchURL] ""=http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\URLSearchHooks] "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- D:\WINDOWS\system32\ieframe.dll (Microsoft Corporation) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\URLSearchHooks] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 ========== (O1) Hosts File ========== HOSTS File = (734 bytes) - D:\WINDOWS\System32\drivers\etc\Hosts First 25 entries... 127.0.0.1 localhost ========== (O2) BHO's ========== [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\] {02478D38-C3F9-4efb-9B51-7695ECA05670} (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) {18DF081C-E8AD-4283-A596-FA578C2EBDC3} (HKLM) -- D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) {5A263CF7-56A6-4D68-A8CF-345BE45BC911} (HKLM) -- D:\Program Files\Yahoo!\SearchSuggest\YSearchSuggest.dll (Yahoo! Inc.) ========== (O3) Toolbars ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) ========== (O4) Run Keys ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated) "RawOs"=wscript.exe "D:\WINDOWS\sowar.vbs" (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.) ========== (O4) Startup Folders ========== ========== (O6 & O7) Current Version Policies ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=36 "NoDriveAutoRun"=FF FF FF FF [binary data] [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"=1 "DisableRegistryTools"=1 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"=1 "DisableRegistryTools"=1 [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=36 "NoDriveAutoRun"=FF FF FF FF [binary data] ========== (O8) IE Context Menu Extensions ========== [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\] E&xport to Microsoft Excel: D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2003/08/13 02:34:38 | 10,073,144 | ---- | M] (Microsoft Corporation) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\MenuExt\] E&xport to Microsoft Excel: D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2003/08/13 02:34:38 | 10,073,144 | ---- | M] (Microsoft Corporation) ========== (O9) IE Extensions ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\] {92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [2003/07/14 22:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation) {e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 -- %SystemRoot%\network diagnostic\xpnetdiag.exe [2006/10/10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2003/07/14 22:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation) CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2003/07/14 22:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation) CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) ========== (O12) Internet Explorer Plugins ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\] PluginsPage: "" = http://activex.microsoft.com/controls/find...=%s&mime=%s PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery ========== (O13) Default Prefixes ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// ========== (O15) Trusted Sites ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\] 1 domain(s) and sub-domain(s) not assigned to a zone. ========== (O16) DPF ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\] {17492023-C23A-453E-A040-C7C580BBF700}: https://go.microsoft.com/fwlink/?linkid=39204 -- Windows Genuine Advantage Validation Tool {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}: http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab -- Reg Error: Key does not exist or could not be opened. {D27CDB6E-AE6D-11CF-96B8-444553540000}: http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab -- Shockwave Flash Object ========== (O17) DNS Name Servers ========== {A322DAA2-3D3B-4DDD-8442-F57C03C41912} (Servers: | Description: VIA PCI 10/100Mb Fast Ethernet Adapter) ========== (O19) User Style Sheets ========== [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles] ========== Safeboot Options ========== "AlternateShell"=cmd.exe ========== CDRom AutoRun Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom] "AutoRun" = 1 ========== Autorun Files on Drives ========== AUTOEXEC.BAT [] [2008/03/30 13:41:35 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ] autorun.inf [] [2008/11/20 17:44:19 | 00,000,000 | RHSD | M] -- C:\autorun.inf -- [ NTFS ] autorun.inf [] [2008/11/20 17:44:19 | 00,000,000 | RHSD | M] -- D:\autorun.inf -- [ NTFS ] Autorun.inf [[autorun] | open=wscript.exe sowar.vbs | shell\Open\Command=wscript.exe sowar.vbs | shell\Open\Default=1 | ] [2008/11/20 17:44:06 | 00,000,101 | RHS- | M] () -- F:\Autorun.inf -- [ FAT32 ] ========== MountPoints2 ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e8-9102-11dd-a612-000d872ad521}\Shell] ""=AutoRun [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e8-9102-11dd-a612-000d872ad521}\Shell\AutoRun] ""=Auto&Play [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e8-9102-11dd-a612-000d872ad521}\Shell\AutoRun\command] ""=D:\WINDOWS\system32\shell32.dll -- [2005/09/22 19:05:29 | 08,450,560 | ---- | M] (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c914075-8425-11dd-a5fa-000d872ad521}\Shell\Explore\command] ""=F:\bar311.exe -- File not found ========== Files/Folders - Created Within 30 Days ========== [4 D:\WINDOWS\System32\*.tmp files] [3 D:\WINDOWS\*.tmp files] [2 D:\Documents and Settings\soteri\Desktop\*.tmp files] [2008/11/20 17:44:19 | 00,000,000 | RHSD | C] -- D:\autorun.inf [2008/11/20 17:33:04 | 02,372,472 | ---- | C] (Malwarebytes Corporation ) -- D:\Documents and Settings\soteri\Desktop\mbam-setup.exe [2008/11/20 17:18:26 | 00,132,597 | ---- | C] () -- D:\Documents and Settings\soteri\Desktop\Flash_Disinfector.exe [2008/11/20 17:14:32 | 00,000,000 | ---D | C] -- D:\_OTMoveIt [2008/11/20 17:12:18 | 00,349,696 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\soteri\Desktop\OTMoveIt3.exe [2008/11/19 12:10:11 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\My Documents\zoie [2008/11/16 09:33:10 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Desktop\New Folder [2008/11/15 13:42:21 | 00,726,707 | ---- | C] () -- D:\Documents and Settings\soteri\My Documents\scan.jpg [2008/11/15 12:36:14 | 11,489,652 | ---- | C] () -- D:\Documents and Settings\soteri\My Documents\I Don't Want To Miss A Thing (Originally Performed By Aerosmith).mp3 [2008/11/14 19:31:59 | 00,002,855 | ---- | C] () -- D:\Documents and Settings\soteri\Desktop\Shortcut to TC.pif [2008/11/12 18:14:03 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Application Data\Help [2008/11/12 18:11:30 | 00,000,670 | ---- | C] () -- D:\Documents and Settings\soteri\Desktop\Mazaika.lnk [2008/11/12 18:11:27 | 00,000,000 | ---D | C] -- D:\Program Files\Mazaika24 [2008/11/12 18:10:37 | 00,000,000 | ---D | C] -- D:\Program Files\maz240 [2008/11/09 12:35:31 | 02,136,064 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntkrnlmp.exe [2008/11/09 12:35:30 | 02,180,352 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntoskrnl.exe [2008/11/09 12:35:29 | 02,015,744 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntkrpamp.exe [2008/11/09 12:35:28 | 02,057,728 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntkrnlpa.exe [2008/11/09 11:26:55 | 00,016,896 | ---- | C] () -- D:\Documents and Settings\soteri\My Documents\TENG.xls [2008/11/08 16:28:22 | 00,000,000 | ---D | C] -- D:\WINDOWS\ie7updates [2008/11/03 20:12:34 | 00,000,000 | ---D | C] -- D:\WINDOWS\network diagnostic [2008/11/03 19:19:15 | 00,000,000 | ---D | C] -- D:\WINDOWS\WBEM [2008/11/03 19:19:13 | 00,000,000 | ---D | C] -- D:\WINDOWS\System32\en-US [2008/11/03 19:17:02 | 00,000,000 | -H-D | C] -- D:\WINDOWS\ie7 [2008/11/03 19:16:20 | 00,000,000 | -H-D | C] -- D:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$ [2008/11/03 19:15:23 | 00,000,000 | -H-D | C] -- D:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$ [2008/11/01 09:24:33 | 00,096,768 | ---- | C] () -- D:\Documents and Settings\soteri\My Documents\GRACIA NOLI.doc [2008/10/30 14:13:33 | 00,000,000 | ---- | C] () -- D:\WINDOWS\nsreg.dat [2008/10/30 14:12:50 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Local Settings\Application Data\Mozilla [2008/10/30 14:12:49 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Application Data\Mozilla [2008/10/30 14:12:29 | 00,001,602 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk [2008/10/30 14:12:14 | 00,000,000 | ---D | C] -- D:\Program Files\Mozilla Firefox [2008/10/28 19:24:39 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Application Data\Yahoo! [2008/10/28 19:24:38 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Yahoo! Companion [2008/10/28 18:38:29 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Local Settings\Application Data\Yahoo [2008/10/28 17:51:45 | 00,000,812 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk [2008/10/28 17:48:01 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Yahoo! [2008/10/28 17:47:21 | 00,000,000 | ---D | C] -- D:\Program Files\Yahoo! ========== Files - Modified Within 30 Days ========== [4 D:\WINDOWS\System32\*.tmp files] [3 D:\WINDOWS\*.tmp files] [2 D:\Documents and Settings\soteri\Desktop\*.tmp files] [2008/11/20 17:35:08 | 00,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT [2008/11/20 17:35:03 | 00,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat [2008/11/20 17:33:39 | 06,374,706 | -H-- | M] () -- D:\Documents and Settings\soteri\Local Settings\Application Data\IconCache.db [2008/11/20 17:33:04 | 02,372,472 | ---- | M] (Malwarebytes Corporation ) -- D:\Documents and Settings\soteri\Desktop\mbam-setup.exe [2008/11/20 17:18:26 | 00,132,597 | ---- | M] () -- D:\Documents and Settings\soteri\Desktop\Flash_Disinfector.exe [2008/11/20 17:12:18 | 00,349,696 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\soteri\Desktop\OTMoveIt3.exe [2008/11/20 16:43:26 | 00,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl [2008/11/19 15:47:24 | 00,649,728 | -HS- | M] () -- D:\Documents and Settings\soteri\My Documents\Thumbs.db @Alternate Data Stream - 0 bytes -> D:\Documents and Settings\soteri\My Documents\Thumbs.db:encryptable [2008/11/15 14:15:45 | 00,002,577 | ---- | M] () -- D:\WINDOWS\System32\CONFIG.NT [2008/11/14 19:31:59 | 00,002,855 | ---- | M] () -- D:\Documents and Settings\soteri\Desktop\Shortcut to TC.pif [2008/11/14 09:40:10 | 00,726,707 | ---- | M] () -- D:\Documents and Settings\soteri\My Documents\scan.jpg [2008/11/12 18:19:21 | 00,001,393 | ---- | M] () -- D:\WINDOWS\imsins.BAK [2008/11/12 18:11:30 | 00,000,670 | ---- | M] () -- D:\Documents and Settings\soteri\Desktop\Mazaika.lnk [2008/11/09 11:26:55 | 00,016,896 | ---- | M] () -- D:\Documents and Settings\soteri\My Documents\TENG.xls [2008/11/03 19:23:11 | 00,000,077 | -HS- | M] () -- D:\Documents and Settings\soteri\My Documents\desktop.ini [2008/11/02 09:26:06 | 00,458,340 | ---- | M] () -- D:\WINDOWS\System32\PerfStringBackup.INI [2008/11/02 09:26:06 | 00,392,626 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat [2008/11/02 09:26:06 | 00,058,800 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat [2008/11/01 14:03:03 | 00,096,768 | ---- | M] () -- D:\Documents and Settings\soteri\My Documents\GRACIA NOLI.doc [2008/10/30 14:13:33 | 00,000,000 | ---- | M] () -- D:\WINDOWS\nsreg.dat [2008/10/30 14:12:29 | 00,001,602 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk [2008/10/29 10:40:50 | 00,189,792 | ---- | M] () -- D:\WINDOWS\System32\FNTCACHE.DAT [2008/10/28 17:51:45 | 00,000,812 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk [2008/10/24 03:10:42 | 00,453,632 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\drivers\mrxsmb.sys [2008/10/24 03:10:42 | 00,453,632 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\mrxsmb.sys < End of report > extras ! OTViewIt Extras logfile created on: 11/20/2008 5:51:52 PM - Run 3 OTViewIt by OldTimer - Version 1.0.20.0 Folder = D:\jonard\aplikeysyons Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 127.48 Mb Total Physical Memory | 24.82 Mb Available Physical Memory | 19.47% Memory free 307.27 Mb Paging File | 149.74 Mb Available in Paging File | 48.73% Paging File free Paging file location(s): D:\pagefile.sys 192 384; %SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files Drive C: | 9.77 Gb Total Space | 9.67 Gb Free Space | 98.98% Space Free | Partition Type: NTFS Drive D: | 18.86 Gb Total Space | 5.62 Gb Free Space | 29.81% Space Free | Partition Type: NTFS E: Drive not present or media not loaded Drive F: | 962.07 Mb Total Space | 610.61 Mb Free Space | 63.47% Space Free | Partition Type: FAT32 G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: ZAMORA-8F8E222F Current User Name: soteri Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Whitelist: On File Age = 30 Days "Use My Stylesheet"= "User Stylesheet"= ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled"=1 "AntiVirusDisableNotify"=0 "FirewallDisableNotify"=0 "UpdatesDisableNotify"=0 "AntiVirusOverride"=0 "FirewallOverride"=0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile "EnableFirewall"=1 "DoNotAllowExceptions"=0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts] ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [2004/08/03 14:56:58 | 00,140,800 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 [2006/10/10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [2004/08/03 14:56:58 | 00,140,800 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 [2008/10/16 20:57:52 | 04,347,120 | ---- | M] (Yahoo! Inc.) -- D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger [2006/10/10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 ========== (O18) Protocol Handlers ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] ipp: [HKLM - No CLSID value] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers [2003/07/11 02:25:22 | 00,842,816 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] msdaipp: [HKLM - No CLSID value] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers [2003/07/11 02:25:22 | 00,842,816 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers [2003/07/11 02:25:22 | 00,842,816 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] [2003/08/04 13:19:34 | 07,330,360 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} (HKLM) [Data Page Pluggable Protocol mso-offdap Handler]) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] [2003/08/01 15:09:04 | 08,086,072 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (mso-offdap11:{32505114-5902-49B2-880A-1F7738E5A384} (HKLM) [Data Page Plugable Protocal mso-offdap11 Handler]) ========== (O18) Protocol Filters ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters [2003/07/14 22:45:12 | 00,039,488 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL text/xml:{807553E5-5146-11D5-A672-00B0D022E945} (HKLM) [Reg Error: Value does not exist or could not be read.] ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00203668-8170-44A0-BE44-B632FA4D780F}"=Adobe AIR "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP "{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}"=Microsoft .NET Framework 2.0 "{7299052b-02a4-4627-81f2-1818da5d550d}"=Microsoft Visual C++ 2005 Redistributable "{77DCDCE3-2DED-62F3-8154-05E745472D07}"=Acrobat.com "{90110409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office Professional Edition 2003 "{AC76BA86-7AD7-1033-7B44-A90000000001}"=Adobe Reader 9 "{D86FEEE1-C996-11D6-A67A-0080AD061ECA}"=Mazaika v.2.4 "Adobe AIR"=Adobe AIR "Adobe Flash Player ActiveX"=Adobe Flash Player ActiveX "Adobe Flash Player Plugin"=Adobe Flash Player 10 Plugin "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1"=Acrobat.com "IDNMitigationAPIs"=Microsoft Internationalized Domain Names Mitigation APIs "ie7"=Windows Internet Explorer 7 "Microsoft .NET Framework 2.0"=Microsoft .NET Framework 2.0 "Mozilla Firefox (3.0.3)"=Mozilla Firefox (3.0.3) "NLSDownlevelMapping"=Microsoft National Language Support Downlevel APIs "Wdf01007"=Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 "Windows Media Format Runtime"=Windows Media Format 11 runtime "WMFDist11"=Windows Media Format 11 runtime "Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0 "Yahoo! Companion"=Yahoo! Toolbar "Yahoo! IE Suggest"=Yahoo! Search Suggest Add-on for IE7 "Yahoo! Messenger"=Yahoo! Messenger ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 10/8/2008 12:50:39 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/8/2008 12:53:04 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/8/2008 12:56:21 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/8/2008 1:09:24 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/28/2008 7:37:27 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application xrule.exe, version 0.0.0.0, faulting module xrule.exe, version 0.0.0.0, fault address 0x00005609. Error - 10/29/2008 9:06:12 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Hang | ID = 1002 Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 10/30/2008 4:34:53 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application yahoomessenger.exe, version 9.0.0.2018, faulting module yahoomessenger.exe, version 9.0.0.2018, fault address 0x00176612. Error - 11/3/2008 11:52:36 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 7.0.5730.13, faulting module jscript.dll, version 5.7.0.5730, fault address 0x0001bb9d. Error - 11/3/2008 11:55:05 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 7.0.5730.13, faulting module jscript.dll, version 5.7.0.5730, fault address 0x0001bb9d. Error - 11/12/2008 10:17:21 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Hang | ID = 1002 Description = Hanging application mz002.exe, version 2.4.0.258, hang module hungapp, version 0.0.0.0, hang address 0x00000000. [ System Events ] Error - 11/15/2008 4:51:23 PM | Computer Name = ZAMORA-8F8E222F | Source = atapi | ID = 262153 Description = The device, \Device\Ide\IdePort0, did not respond within the timeout period. Error - 11/15/2008 4:51:34 PM | Computer Name = ZAMORA-8F8E222F | Source = atapi | ID = 262153 Description = The device, \Device\Ide\IdePort0, did not respond within the timeout period. Error - 11/15/2008 6:27:53 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/16/2008 1:16:56 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/18/2008 2:03:00 AM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/19/2008 4:09:35 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/19/2008 7:42:49 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/19/2008 7:46:41 PM | Computer Name = ZAMORA-8F8E222F | Source = W32Time | ID = 39452706 Description = The time service has detected that the system time needs to be changed by -57454 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com (ntp.m|0x1|210.1.98.177:123->207.46.197.32:123) is working properly. Error - 11/20/2008 8:43:50 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/20/2008 9:35:19 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 < End of report > my computer behave in a good manner ! it suddenly performs faster ! and the sowar browser was removed ,,the redtube.com homepage was also removed !!! praise to you !! thank you so much ! my internet browsing became faster, even though i only used 56kb modem !! thnak you so much sir/maam !!! but i think i have problems about virus in my pc ! help me to find the best anti-virus !but i'll try the one u suggested which is MBAM !! tnx again ! |
|
|
|
Nov 20 2008, 05:07 AM
Post
#11
|
|
|
Member ![]() ![]() Group: Members Posts: 24 Joined: 14-November 08 Member No.: 256,414 |
do you think i still have some irregularities in my pc that is needed to be fix ?? ! help me about it !! tnx !!
|
|
|
|
Nov 20 2008, 07:42 AM
Post
#12
|
|
|
Malware Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 15,378 Joined: 23-December 04 From: Pickerington, Ohio Member No.: 7,762 |
Sounds like things are coming together. You still need to run Malwarebuytes and post that log.
We still have some more to cleanup, but I need to see a log from OTViewIt after you run Malwarebytes. -------------------- If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it! ======================================================== |
|
|
|
Nov 22 2008, 08:48 AM
Post
#13
|
|
|
Member ![]() ![]() Group: Members Posts: 24 Joined: 14-November 08 Member No.: 256,414 |
log from malware
Malwarebytes' Anti-Malware 1.30 Database version: 1412 Windows 5.1.2600 Service Pack 2 11/20/2008 6:22:03 PM mbam-log-2008-11-20 (18-22-03).txt Scan type: Quick Scan Objects scanned: 44412 Time elapsed: 6 minute(s), 19 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\iehlprobj.iehlprobj.1 (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{ce7c3cf0-4b15-11d1-abed-709549c10000} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{ce7c3cf0-4b15-11d1-abed-709549c10000} (Trojan.BHO) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: D:\WINDOWS\system32\ActMon.ini (Spyware.ActMon) -> Quarantined and deleted successfully. from Otviewit txt OTViewIt logfile created on: 11/22/2008 9:35:40 PM - Run 4 OTViewIt by OldTimer - Version 1.0.20.0 Folder = D:\jonard\aplikeysyons Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 127.48 Mb Total Physical Memory | 16.60 Mb Available Physical Memory | 13.02% Memory free 339.27 Mb Paging File | 78.06 Mb Available in Paging File | 23.01% Paging File free Paging file location(s): D:\pagefile.sys 192 384; %SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files Drive C: | 9.77 Gb Total Space | 9.67 Gb Free Space | 98.98% Space Free | Partition Type: NTFS Drive D: | 18.86 Gb Total Space | 8.11 Gb Free Space | 42.99% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: ZAMORA-8F8E222F Current User Name: soteri Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Whitelist: On File Age = 30 Days ========== Processes ========== [2004/08/03 14:56:58 | 00,114,688 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\wscript.exe [2008/07/18 21:10:42 | 00,053,448 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\wuauclt.exe [2007/08/13 18:43:56 | 00,622,080 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Internet Explorer\iexplore.exe [2008/10/16 20:57:52 | 04,347,120 | ---- | M] (Yahoo! Inc.) -- D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2004/08/03 14:56:58 | 00,218,112 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\wbem\wmiprvse.exe [2008/09/25 05:51:54 | 00,307,712 | ---- | M] (Mozilla Corporation) -- D:\Program Files\Mozilla Firefox\firefox.exe [2008/10/22 16:10:20 | 01,261,200 | ---- | M] (Malwarebytes Corporation) -- D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2008/11/14 20:00:01 | 00,422,400 | ---- | M] (OldTimer Tools) -- D:\jonard\aplikeysyons\OTViewIt.exe ========== (O23) Win32 Services ========== [2005/09/23 06:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped]) [2005/09/23 06:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) [2003/07/28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped]) ========== Driver Services ========== [2003/01/01 21:23:22 | 00,010,880 | R--- | M] (DataMan Heightech Technology Inc.) -- D:\WINDOWS\system32\drivers\DataMan.sys -- (DataMan [On_Demand | Stopped]) [2001/08/17 04:13:08 | 00,027,165 | ---- | M] (VIA Technologies, Inc. ) -- D:\WINDOWS\system32\drivers\fetnd5.sys -- (FETNDIS [On_Demand | Running]) [2004/08/03 22:41:48 | 00,220,032 | ---- | M] (Conexant Systems, Inc.) -- D:\WINDOWS\system32\drivers\HSFBS2S2.sys -- (HSFHWBS2 [On_Demand | Running]) [2004/08/03 22:41:56 | 01,041,536 | ---- | M] (Conexant Systems, Inc.) -- D:\WINDOWS\system32\drivers\HSFDPSP2.sys -- (HSF_DP [On_Demand | Running]) [2004/08/03 22:41:56 | 00,011,868 | ---- | M] (Conexant) -- D:\WINDOWS\system32\drivers\mdmxsdk.sys -- (mdmxsdk [Auto | Running]) [2001/08/17 13:57:38 | 00,016,128 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\drivers\MODEMCSA.sys -- (MODEMCSA [On_Demand | Stopped]) [2001/08/23 04:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- D:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running]) [2001/08/23 04:00:00 | 00,005,888 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\drivers\rootmdm.sys -- (ROOTMODEM [On_Demand | Running]) [2000/02/14 18:19:48 | 00,168,576 | R--- | M] (S3 Incorporated) -- D:\WINDOWS\system32\drivers\s3mini.sys -- (S3Inc [On_Demand | Running]) [2007/11/13 02:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- D:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped]) [2001/08/17 13:28:26 | 00,113,762 | ---- | M] (U.S. Robotics Corporation) -- D:\WINDOWS\system32\drivers\USRpdA.sys -- (USRpdA [On_Demand | Stopped]) [2003/02/26 00:04:00 | 00,370,048 | R--- | M] (VIA Technologies, Inc.) -- D:\WINDOWS\system32\drivers\viaudios.sys -- (VIAudio [On_Demand | Running]) [2008/03/27 15:27:46 | 00,503,008 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\drivers\wdf01000.sys -- (Wdf01000 [On_Demand | Stopped]) [2004/08/03 22:41:50 | 00,685,056 | ---- | M] (Conexant Systems, Inc.) -- D:\WINDOWS\system32\drivers\HSFCXTS2.sys -- (winachsf [On_Demand | Running]) ========== (R ) Internet Explorer ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main] "Default_Page_URL"=http://www.yahoo.com "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "Default_Secondary_Page_URL"= "Extensions Off Page"=about:NoAdd-ons "Local Page"=%SystemRoot%\system32\blank.htm "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Secondary Start Pages"= "Security Risk Page"=about:SecurityRisk "Start Page"=http://www.yahoo.com [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search] "CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm "CustomSearch"=http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr9/*http://www.yahoo.com/ext/search/search.html "SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main] "Local Page"=D:\WINDOWS\system32\blank.htm "Search Page"=http://www.redtube.com/ "SearchDefaultBranded"= "SearchMigratedDefaultName"=Yahoo! Search "SearchMigratedDefaultURL"=http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 "Start Page"=http://www.redtube.com/ [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL] ""=http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- D:\WINDOWS\system32\ieframe.dll (Microsoft Corporation) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main] "Local Page"=D:\WINDOWS\system32\blank.htm "Search Page"=http://www.redtube.com/ "SearchDefaultBranded"= "SearchMigratedDefaultName"=Yahoo! Search "SearchMigratedDefaultURL"=http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 "Start Page"=http://www.redtube.com/ [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\SearchURL] ""=http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\URLSearchHooks] "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- D:\WINDOWS\system32\ieframe.dll (Microsoft Corporation) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\URLSearchHooks] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 ========== (O1) Hosts File ========== HOSTS File = (734 bytes) - D:\WINDOWS\System32\drivers\etc\Hosts First 25 entries... 127.0.0.1 localhost ========== (O2) BHO's ========== [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\] {02478D38-C3F9-4efb-9B51-7695ECA05670} (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) {18DF081C-E8AD-4283-A596-FA578C2EBDC3} (HKLM) -- D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) {5A263CF7-56A6-4D68-A8CF-345BE45BC911} (HKLM) -- D:\Program Files\Yahoo!\SearchSuggest\YSearchSuggest.dll (Yahoo! Inc.) ========== (O3) Toolbars ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) ========== (O4) Run Keys ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated) "RawOs"=wscript.exe "D:\WINDOWS\sowar.vbs" (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.) ========== (O4) Startup Folders ========== ========== (O6 & O7) Current Version Policies ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=128 "NoDriveAutoRun"=FF FF FF FF [binary data] "NoFolderOptions"=1 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableRegistryTools"=1 "DisableTaskMgr"=1 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"=1 "DisableRegistryTools"=1 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"=1 "DisableRegistryTools"=1 [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=128 "NoDriveAutoRun"=FF FF FF FF [binary data] "NoFolderOptions"=1 [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableRegistryTools"=1 "DisableTaskMgr"=1 ========== (O8) IE Context Menu Extensions ========== [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\] E&xport to Microsoft Excel: D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2003/08/13 02:34:38 | 10,073,144 | ---- | M] (Microsoft Corporation) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\MenuExt\] E&xport to Microsoft Excel: D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2003/08/13 02:34:38 | 10,073,144 | ---- | M] (Microsoft Corporation) ========== (O9) IE Extensions ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\] {92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [2003/07/14 22:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation) {e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 -- %SystemRoot%\network diagnostic\xpnetdiag.exe [2006/10/10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2003/07/14 22:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation) CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2003/07/14 22:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation) CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) ========== (O12) Internet Explorer Plugins ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\] PluginsPage: "" = http://activex.microsoft.com/controls/find...=%s&mime=%s PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery ========== (O13) Default Prefixes ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// ========== (O15) Trusted Sites ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\] 1 domain(s) and sub-domain(s) not assigned to a zone. ========== (O16) DPF ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\] {17492023-C23A-453E-A040-C7C580BBF700}: https://go.microsoft.com/fwlink/?linkid=39204 -- Windows Genuine Advantage Validation Tool {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}: http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab -- Reg Error: Key does not exist or could not be opened. {D27CDB6E-AE6D-11CF-96B8-444553540000}: http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab -- Shockwave Flash Object ========== (O17) DNS Name Servers ========== {A322DAA2-3D3B-4DDD-8442-F57C03C41912} (Servers: | Description: VIA PCI 10/100Mb Fast Ethernet Adapter) ========== (O19) User Style Sheets ========== [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles] ========== Safeboot Options ========== "AlternateShell"=cmd.exe ========== CDRom AutoRun Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom] "AutoRun" = 1 ========== Autorun Files on Drives ========== AUTOEXEC.BAT [] [2008/03/30 13:41:35 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ] autorun.inf [] [2008/11/20 17:44:19 | 00,000,000 | RHSD | M] -- C:\autorun.inf -- [ NTFS ] autorun.inf [] [2008/11/20 17:44:19 | 00,000,000 | RHSD | M] -- D:\autorun.inf -- [ NTFS ] ========== MountPoints2 ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e8-9102-11dd-a612-000d872ad521}\Shell] ""=AutoRun [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e8-9102-11dd-a612-000d872ad521}\Shell\AutoRun] ""=Auto&Play [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e8-9102-11dd-a612-000d872ad521}\Shell\AutoRun\command] ""=D:\WINDOWS\system32\shell32.dll -- [2005/09/22 19:05:29 | 08,450,560 | ---- | M] (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c914075-8425-11dd-a5fa-000d872ad521}\Shell\Explore\command] ""=F:\bar311.exe -- File not found ========== Files/Folders - Created Within 30 Days ========== [4 D:\WINDOWS\System32\*.tmp files] [3 D:\WINDOWS\*.tmp files] [2008/11/20 18:06:41 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Application Data\Malwarebytes [2008/11/20 18:06:35 | 00,000,696 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2008/11/20 18:06:34 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbam.sys [2008/11/20 18:06:32 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbamswissarmy.sys [2008/11/20 18:06:30 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Malwarebytes [2008/11/20 18:06:29 | 00,000,000 | ---D | C] -- D:\Program Files\Malwarebytes' Anti-Malware [2008/11/20 17:44:19 | 00,000,000 | RHSD | C] -- D:\autorun.inf [2008/11/14 19:31:59 | 00,002,855 | ---- | C] () -- D:\Documents and Settings\soteri\Desktop\Shortcut to TC.pif [2008/11/12 18:14:03 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Application Data\Help [2008/11/12 18:11:30 | 00,000,670 | ---- | C] () -- D:\Documents and Settings\soteri\Desktop\Mazaika.lnk [2008/11/12 18:11:27 | 00,000,000 | ---D | C] -- D:\Program Files\Mazaika24 [2008/11/12 18:10:37 | 00,000,000 | ---D | C] -- D:\Program Files\maz240 [2008/11/09 12:35:31 | 02,136,064 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntkrnlmp.exe [2008/11/09 12:35:30 | 02,180,352 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntoskrnl.exe [2008/11/09 12:35:29 | 02,015,744 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntkrpamp.exe [2008/11/09 12:35:28 | 02,057,728 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntkrnlpa.exe [2008/11/08 16:28:22 | 00,000,000 | ---D | C] -- D:\WINDOWS\ie7updates [2008/11/03 20:12:34 | 00,000,000 | ---D | C] -- D:\WINDOWS\network diagnostic [2008/11/03 19:19:15 | 00,000,000 | ---D | C] -- D:\WINDOWS\WBEM [2008/11/03 19:19:13 | 00,000,000 | ---D | C] -- D:\WINDOWS\System32\en-US [2008/11/03 19:17:02 | 00,000,000 | -H-D | C] -- D:\WINDOWS\ie7 [2008/11/03 19:16:20 | 00,000,000 | -H-D | C] -- D:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$ [2008/11/03 19:15:23 | 00,000,000 | -H-D | C] -- D:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$ [2008/10/30 14:13:33 | 00,000,000 | ---- | C] () -- D:\WINDOWS\nsreg.dat [2008/10/30 14:12:50 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Local Settings\Application Data\Mozilla [2008/10/30 14:12:49 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Application Data\Mozilla [2008/10/30 14:12:29 | 00,001,602 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk [2008/10/30 14:12:14 | 00,000,000 | ---D | C] -- D:\Program Files\Mozilla Firefox [2008/10/28 19:24:39 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Application Data\Yahoo! [2008/10/28 19:24:38 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Yahoo! Companion [2008/10/28 18:38:29 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Local Settings\Application Data\Yahoo [2008/10/28 17:51:45 | 00,000,812 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk [2008/10/28 17:48:01 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Yahoo! [2008/10/28 17:47:21 | 00,000,000 | ---D | C] -- D:\Program Files\Yahoo! ========== Files - Modified Within 30 Days ========== [4 D:\WINDOWS\System32\*.tmp files] [3 D:\WINDOWS\*.tmp files] [2008/11/22 21:17:53 | 00,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT [2008/11/22 21:17:50 | 00,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl [2008/11/22 21:17:48 | 00,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat [2008/11/21 18:53:21 | 06,906,760 | -H-- | M] () -- D:\Documents and Settings\soteri\Local Settings\Application Data\IconCache.db [2008/11/20 18:35:34 | 00,042,944 | ---- | M] () -- D:\Documents and Settings\soteri\Local Settings\Application Data\GDIPFONTCACHEV1.DAT [2008/11/20 18:34:45 | 00,189,792 | ---- | M] () -- D:\WINDOWS\System32\FNTCACHE.DAT [2008/11/20 18:06:35 | 00,000,696 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2008/11/19 15:47:24 | 00,649,728 | -HS- | M] () -- D:\Documents and Settings\soteri\My Documents\Thumbs.db @Alternate Data Stream - 0 bytes -> D:\Documents and Settings\soteri\My Documents\Thumbs.db:encryptable [2008/11/15 14:15:45 | 00,002,577 | ---- | M] () -- D:\WINDOWS\System32\CONFIG.NT [2008/11/14 19:31:59 | 00,002,855 | ---- | M] () -- D:\Documents and Settings\soteri\Desktop\Shortcut to TC.pif [2008/11/12 18:19:21 | 00,001,393 | ---- | M] () -- D:\WINDOWS\imsins.BAK [2008/11/12 18:11:30 | 00,000,670 | ---- | M] () -- D:\Documents and Settings\soteri\Desktop\Mazaika.lnk [2008/11/03 19:23:11 | 00,000,077 | -HS- | M] () -- D:\Documents and Settings\soteri\My Documents\desktop.ini [2008/11/02 09:26:06 | 00,458,340 | ---- | M] () -- D:\WINDOWS\System32\PerfStringBackup.INI [2008/11/02 09:26:06 | 00,392,626 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat [2008/11/02 09:26:06 | 00,058,800 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat [2008/10/30 14:13:33 | 00,000,000 | ---- | M] () -- D:\WINDOWS\nsreg.dat [2008/10/30 14:12:29 | 00,001,602 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk [2008/10/28 17:51:45 | 00,000,812 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk [2008/10/24 03:10:42 | 00,453,632 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\drivers\mrxsmb.sys [2008/10/24 03:10:42 | 00,453,632 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\mrxsmb.sys < End of report > extras OTViewIt Extras logfile created on: 11/22/2008 9:35:40 PM - Run 4 OTViewIt by OldTimer - Version 1.0.20.0 Folder = D:\jonard\aplikeysyons Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 127.48 Mb Total Physical Memory | 16.60 Mb Available Physical Memory | 13.02% Memory free 339.27 Mb Paging File | 78.06 Mb Available in Paging File | 23.01% Paging File free Paging file location(s): D:\pagefile.sys 192 384; %SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files Drive C: | 9.77 Gb Total Space | 9.67 Gb Free Space | 98.98% Space Free | Partition Type: NTFS Drive D: | 18.86 Gb Total Space | 8.11 Gb Free Space | 42.99% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: ZAMORA-8F8E222F Current User Name: soteri Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Whitelist: On File Age = 30 Days "Use My Stylesheet"= "User Stylesheet"= ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled"=1 "AntiVirusDisableNotify"=0 "FirewallDisableNotify"=0 "UpdatesDisableNotify"=0 "AntiVirusOverride"=1 "FirewallOverride"=0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile "EnableFirewall"=1 "DoNotAllowExceptions"=0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts] ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [2004/08/03 14:56:58 | 00,140,800 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 [2006/10/10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [2004/08/03 14:56:58 | 00,140,800 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 [2008/10/16 20:57:52 | 04,347,120 | ---- | M] (Yahoo! Inc.) -- D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger [2006/10/10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 ========== (O18) Protocol Handlers ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] ipp: [HKLM - No CLSID value] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers [2003/07/11 02:25:22 | 00,842,816 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] msdaipp: [HKLM - No CLSID value] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers [2003/07/11 02:25:22 | 00,842,816 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers [2003/07/11 02:25:22 | 00,842,816 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] [2003/08/04 13:19:34 | 07,330,360 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} (HKLM) [Data Page Pluggable Protocol mso-offdap Handler]) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] [2003/08/01 15:09:04 | 08,086,072 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (mso-offdap11:{32505114-5902-49B2-880A-1F7738E5A384} (HKLM) [Data Page Plugable Protocal mso-offdap11 Handler]) ========== (O18) Protocol Filters ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters [2003/07/14 22:45:12 | 00,039,488 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL text/xml:{807553E5-5146-11D5-A672-00B0D022E945} (HKLM) [Reg Error: Value does not exist or could not be read.] ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00203668-8170-44A0-BE44-B632FA4D780F}"=Adobe AIR "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP "{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}"=Microsoft .NET Framework 2.0 "{7299052b-02a4-4627-81f2-1818da5d550d}"=Microsoft Visual C++ 2005 Redistributable "{77DCDCE3-2DED-62F3-8154-05E745472D07}"=Acrobat.com "{90110409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office Professional Edition 2003 "{AC76BA86-7AD7-1033-7B44-A90000000001}"=Adobe Reader 9 "{D86FEEE1-C996-11D6-A67A-0080AD061ECA}"=Mazaika v.2.4 "Adobe AIR"=Adobe AIR "Adobe Flash Player ActiveX"=Adobe Flash Player ActiveX "Adobe Flash Player Plugin"=Adobe Flash Player 10 Plugin "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1"=Acrobat.com "IDNMitigationAPIs"=Microsoft Internationalized Domain Names Mitigation APIs "ie7"=Windows Internet Explorer 7 "Malwarebytes' Anti-Malware_is1"=Malwarebytes' Anti-Malware "Microsoft .NET Framework 2.0"=Microsoft .NET Framework 2.0 "Mozilla Firefox (3.0.3)"=Mozilla Firefox (3.0.3) "NLSDownlevelMapping"=Microsoft National Language Support Downlevel APIs "Wdf01007"=Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 "Windows Media Format Runtime"=Windows Media Format 11 runtime "WMFDist11"=Windows Media Format 11 runtime "Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0 "Yahoo! Companion"=Yahoo! Toolbar "Yahoo! IE Suggest"=Yahoo! Search Suggest Add-on for IE7 "Yahoo! Messenger"=Yahoo! Messenger ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 10/8/2008 12:50:39 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/8/2008 12:53:04 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/8/2008 12:56:21 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/8/2008 1:09:24 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/28/2008 7:37:27 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application xrule.exe, version 0.0.0.0, faulting module xrule.exe, version 0.0.0.0, fault address 0x00005609. Error - 10/29/2008 9:06:12 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Hang | ID = 1002 Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 10/30/2008 4:34:53 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application yahoomessenger.exe, version 9.0.0.2018, faulting module yahoomessenger.exe, version 9.0.0.2018, fault address 0x00176612. Error - 11/3/2008 11:52:36 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 7.0.5730.13, faulting module jscript.dll, version 5.7.0.5730, fault address 0x0001bb9d. Error - 11/3/2008 11:55:05 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 7.0.5730.13, faulting module jscript.dll, version 5.7.0.5730, fault address 0x0001bb9d. Error - 11/12/2008 10:17:21 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Hang | ID = 1002 Description = Hanging application mz002.exe, version 2.4.0.258, hang module hungapp, version 0.0.0.0, hang address 0x00000000. [ System Events ] Error - 11/18/2008 2:03:00 AM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/19/2008 4:09:35 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/19/2008 7:42:49 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/19/2008 7:46:41 PM | Computer Name = ZAMORA-8F8E222F | Source = W32Time | ID = 39452706 Description = The time service has detected that the system time needs to be changed by -57454 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com (ntp.m|0x1|210.1.98.177:123->207.46.197.32:123) is working properly. Error - 11/20/2008 8:43:50 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/20/2008 9:35:19 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/20/2008 10:35:14 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/21/2008 9:29:18 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/21/2008 10:19:31 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/23/2008 1:18:09 AM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 < End of report > ei, the sowar browser return again on the title bar of my windows and the redtube is still my homepage ! it was already fixed but after 1day it return again into that situation !! heres another log from full scan !! Malwarebytes' Anti-Malware 1.30 Database version: 1412 Windows 5.1.2600 Service Pack 2 11/21/2008 6:17:29 PM mbam-log-2008-11-21 (18-17-29).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 72166 Time elapsed: 30 minute(s), 18 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) huhuhuhu !! help me plz !it give me a damn !! thanks !! |
|
|
|
Nov 22 2008, 09:51 AM
Post
#14
|
|
|
Malware Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 15,378 Joined: 23-December 04 From: Pickerington, Ohio Member No.: 7,762 |
Copy this text into OTMoveIt3 just like you did before and click MoveIt.
CODE :files D:\WINDOWS\sowar.vbs :reg [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main] "Search Page"=- "Start Page"=- [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main] "Search Page"=- "Start Page"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RawOs"=- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableRegistryTools"=- "DisableTaskMgr"=- [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"=- "DisableRegistryTools"=- [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"=- "DisableRegistryTools"=- [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveAutoRun"=- "NoFolderOptions"=- [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableRegistryTools"=- "DisableTaskMgr"=- Please post the resulting log from OTMoveit as well as a new log from OTViewIt. -------------------- If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it! ======================================================== |
|
|
|
Nov 23 2008, 09:13 AM
Post
#15
|
|
|
Member ![]() ![]() Group: Members Posts: 24 Joined: 14-November 08 Member No.: 256,414 |
log from OTMoveIt3
========== FILES ========== D:\WINDOWS\sowar.vbs moved successfully. ========== REGISTRY ========== Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page deleted successfully. Registry value HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page not found. Registry value HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\RawOs deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableTaskMgr deleted successfully. Registry value HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableTaskMgr deleted successfully. Registry value HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully. Registry value HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableTaskMgr not found. Registry value HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools not found. Registry value HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun deleted successfully. Registry value HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoFolderOptions deleted successfully. Registry value HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools not found. Registry value HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableTaskMgr not found. OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11232008_220711 OTViewIt OTViewIt logfile created on: 11/23/2008 10:08:46 PM - Run 5 OTViewIt by OldTimer - Version 1.0.20.0 Folder = D:\jonard\aplikeysyons Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 127.48 Mb Total Physical Memory | 36.12 Mb Available Physical Memory | 28.33% Memory free 307.27 Mb Paging File | 142.95 Mb Available in Paging File | 46.52% Paging File free Paging file location(s): D:\pagefile.sys 192 384; %SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files Drive C: | 9.77 Gb Total Space | 9.67 Gb Free Space | 98.98% Space Free | Partition Type: NTFS Drive D: | 18.86 Gb Total Space | 8.12 Gb Free Space | 43.05% Space Free | Partition Type: NTFS E: Drive not present or media not loaded Drive F: | 962.07 Mb Total Space | 610.44 Mb Free Space | 63.45% Space Free | Partition Type: FAT32 Drive G: | 1010.22 Mb Total Space | 1009.23 Mb Free Space | 99.90% Space Free | Partition Type: FAT H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: ZAMORA-8F8E222F Current User Name: soteri Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Whitelist: On File Age = 30 Days ========== Processes ========== [2004/08/03 14:56:58 | 00,114,688 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\wscript.exe [2008/10/16 20:57:54 | 00,079,088 | ---- | M] (Yahoo! Inc.) -- D:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe [2008/07/18 21:10:42 | 00,053,448 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\wuauclt.exe [2007/08/13 18:43:56 | 00,622,080 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Internet Explorer\iexplore.exe [2008/11/14 20:00:01 | 00,422,400 | ---- | M] (OldTimer Tools) -- D:\jonard\aplikeysyons\OTViewIt.exe ========== (O23) Win32 Services ========== [2005/09/23 06:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped]) [2005/09/23 06:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) [2003/07/28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped]) ========== Driver Services ========== [2003/01/01 21:23:22 | 00,010,880 | R--- | M] (DataMan Heightech Technology Inc.) -- D:\WINDOWS\system32\drivers\DataMan.sys -- (DataMan [On_Demand | Stopped]) [2001/08/17 04:13:08 | 00,027,165 | ---- | M] (VIA Technologies, Inc. ) -- D:\WINDOWS\system32\drivers\fetnd5.sys -- (FETNDIS [On_Demand | Running]) [2004/08/03 22:41:48 | 00,220,032 | ---- | M] (Conexant Systems, Inc.) -- D:\WINDOWS\system32\drivers\HSFBS2S2.sys -- (HSFHWBS2 [On_Demand | Running]) [2004/08/03 22:41:56 | 01,041,536 | ---- | M] (Conexant Systems, Inc.) -- D:\WINDOWS\system32\drivers\HSFDPSP2.sys -- (HSF_DP [On_Demand | Running]) [2004/08/03 22:41:56 | 00,011,868 | ---- | M] (Conexant) -- D:\WINDOWS\system32\drivers\mdmxsdk.sys -- (mdmxsdk [Auto | Running]) [2001/08/17 13:57:38 | 00,016,128 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\drivers\MODEMCSA.sys -- (MODEMCSA [On_Demand | Stopped]) [2001/08/23 04:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- D:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running]) [2001/08/23 04:00:00 | 00,005,888 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\drivers\rootmdm.sys -- (ROOTMODEM [On_Demand | Running]) [2000/02/14 18:19:48 | 00,168,576 | R--- | M] (S3 Incorporated) -- D:\WINDOWS\system32\drivers\s3mini.sys -- (S3Inc [On_Demand | Running]) [2007/11/13 02:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- D:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped]) [2001/08/17 13:28:26 | 00,113,762 | ---- | M] (U.S. Robotics Corporation) -- D:\WINDOWS\system32\drivers\USRpdA.sys -- (USRpdA [On_Demand | Stopped]) [2003/02/26 00:04:00 | 00,370,048 | R--- | M] (VIA Technologies, Inc.) -- D:\WINDOWS\system32\drivers\viaudios.sys -- (VIAudio [On_Demand | Running]) [2008/03/27 15:27:46 | 00,503,008 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\drivers\wdf01000.sys -- (Wdf01000 [On_Demand | Stopped]) [2004/08/03 22:41:50 | 00,685,056 | ---- | M] (Conexant Systems, Inc.) -- D:\WINDOWS\system32\drivers\HSFCXTS2.sys -- (winachsf [On_Demand | Running]) ========== (R ) Internet Explorer ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main] "Default_Page_URL"=http://www.yahoo.com "Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896 "Default_Secondary_Page_URL"= "Extensions Off Page"=about:NoAdd-ons "Local Page"=%SystemRoot%\system32\blank.htm "Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896 "Secondary Start Pages"= "Security Risk Page"=about:SecurityRisk "Start Page"=http://www.yahoo.com [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search] "CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm "CustomSearch"=http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr9/*http://www.yahoo.com/ext/search/search.html "SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main] "Local Page"=D:\WINDOWS\system32\blank.htm "Search Page"=http://www.redtube.com/ "SearchDefaultBranded"= "SearchMigratedDefaultName"=Yahoo! Search "SearchMigratedDefaultURL"=http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 "Start Page"=http://www.redtube.com/ [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL] ""=http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- D:\WINDOWS\system32\ieframe.dll (Microsoft Corporation) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main] [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main] "Local Page"=D:\WINDOWS\system32\blank.htm "Search Page"=http://www.redtube.com/ "SearchDefaultBranded"= "SearchMigratedDefaultName"=Yahoo! Search "SearchMigratedDefaultURL"=http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 "Start Page"=http://www.redtube.com/ [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\SearchURL] ""=http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\URLSearchHooks] "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- D:\WINDOWS\system32\ieframe.dll (Microsoft Corporation) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\URLSearchHooks] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = 0 ========== (O1) Hosts File ========== HOSTS File = (734 bytes) - D:\WINDOWS\System32\drivers\etc\Hosts First 25 entries... 127.0.0.1 localhost ========== (O2) BHO's ========== [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\] {02478D38-C3F9-4efb-9B51-7695ECA05670} (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) {18DF081C-E8AD-4283-A596-FA578C2EBDC3} (HKLM) -- D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) {5A263CF7-56A6-4D68-A8CF-345BE45BC911} (HKLM) -- D:\Program Files\Yahoo!\SearchSuggest\YSearchSuggest.dll (Yahoo! Inc.) ========== (O3) Toolbars ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) ========== (O4) Run Keys ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated) "RawOs"=wscript.exe "D:\WINDOWS\sowar.vbs" (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.) ========== (O4) Startup Folders ========== ========== (O6 & O7) Current Version Policies ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=128 "NoFolderOptions"=1 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"=1 "DisableRegistryTools"=1 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=145 [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=128 "NoFolderOptions"=1 [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"=1 "DisableRegistryTools"=1 ========== (O8) IE Context Menu Extensions ========== [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\] E&xport to Microsoft Excel: D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2003/08/13 02:34:38 | 10,073,144 | ---- | M] (Microsoft Corporation) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\Software\Microsoft\Internet Explorer\MenuExt\] E&xport to Microsoft Excel: D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2003/08/13 02:34:38 | 10,073,144 | ---- | M] (Microsoft Corporation) ========== (O9) IE Extensions ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\] {92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [2003/07/14 22:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation) {e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 -- %SystemRoot%\network diagnostic\xpnetdiag.exe [2006/10/10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2003/07/14 22:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation) CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) [HKEY_USERS\S-1-5-21-796845957-1659004503-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Extensions\] CmdMapping\\{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2003/07/14 22:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation) CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 01:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation) ========== (O12) Internet Explorer Plugins ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\] PluginsPage: "" = http://activex.microsoft.com/controls/find...=%s&mime=%s PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery ========== (O13) Default Prefixes ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// ========== (O15) Trusted Sites ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\] 1 domain(s) and sub-domain(s) not assigned to a zone. ========== (O16) DPF ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\] {17492023-C23A-453E-A040-C7C580BBF700}: https://go.microsoft.com/fwlink/?linkid=39204 -- Windows Genuine Advantage Validation Tool {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}: http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab -- Reg Error: Key does not exist or could not be opened. {D27CDB6E-AE6D-11CF-96B8-444553540000}: http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab -- Shockwave Flash Object ========== (O17) DNS Name Servers ========== {A322DAA2-3D3B-4DDD-8442-F57C03C41912} (Servers: | Description: VIA PCI 10/100Mb Fast Ethernet Adapter) ========== (O19) User Style Sheets ========== [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles] ========== Safeboot Options ========== "AlternateShell"=cmd.exe ========== CDRom AutoRun Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom] "AutoRun" = 1 ========== Autorun Files on Drives ========== AUTOEXEC.BAT [] [2008/03/30 13:41:35 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ] autorun.inf [] [2008/11/20 17:44:19 | 00,000,000 | RHSD | M] -- C:\autorun.inf -- [ NTFS ] autorun.inf [] [2008/11/20 17:44:19 | 00,000,000 | RHSD | M] -- D:\autorun.inf -- [ NTFS ] Autorun.inf [[autorun] | open=wscript.exe sowar.vbs | shell\Open\Command=wscript.exe sowar.vbs | shell\Open\Default=1 | ] [2008/11/23 22:08:54 | 00,000,101 | RHS- | M] () -- F:\Autorun.inf -- [ FAT32 ] Autorun.inf [[autorun] | open=wscript.exe sowar.vbs | shell\Open\Command=wscript.exe sowar.vbs | shell\Open\Default=1 | ] [2008/11/23 22:08:54 | 00,000,101 | RHS- | M] () -- G:\Autorun.inf -- [ FAT ] ========== MountPoints2 ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e8-9102-11dd-a612-000d872ad521}\Shell] ""=AutoRun [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e8-9102-11dd-a612-000d872ad521}\Shell\AutoRun] ""=Auto&Play [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b9c02e8-9102-11dd-a612-000d872ad521}\Shell\AutoRun\command] ""=D:\WINDOWS\system32\shell32.dll -- [2005/09/22 19:05:29 | 08,450,560 | ---- | M] (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1a4f8640-02ad-11dd-a4e2-000d872ad521}\Shell\AutoRun\command] ""=wscript.exe sowar.vbs [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1a4f8640-02ad-11dd-a4e2-000d872ad521}\Shell\Open\Command] ""=wscript.exe sowar.vbs [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c914075-8425-11dd-a5fa-000d872ad521}\Shell\Explore\command] ""=F:\bar311.exe -- File not found [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{eee417a0-b834-11dd-a64e-000d872ad521}\Shell\AutoRun\command] ""=wscript.exe sowar.vbs [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{eee417a0-b834-11dd-a64e-000d872ad521}\Shell\Open\Command] ""=wscript.exe sowar.vbs ========== Files/Folders - Created Within 30 Days ========== [4 D:\WINDOWS\System32\*.tmp files] [3 D:\WINDOWS\*.tmp files] [2008/11/23 22:07:11 | 00,000,000 | ---D | C] -- D:\_OTMoveIt [2008/11/20 18:06:41 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Application Data\Malwarebytes [2008/11/20 18:06:35 | 00,000,696 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2008/11/20 18:06:34 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbam.sys [2008/11/20 18:06:32 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbamswissarmy.sys [2008/11/20 18:06:30 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Malwarebytes [2008/11/20 18:06:29 | 00,000,000 | ---D | C] -- D:\Program Files\Malwarebytes' Anti-Malware [2008/11/20 17:44:19 | 00,000,000 | RHSD | C] -- D:\autorun.inf [2008/11/14 19:31:59 | 00,002,855 | ---- | C] () -- D:\Documents and Settings\soteri\Desktop\Shortcut to TC.pif [2008/11/12 18:14:03 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Application Data\Help [2008/11/12 18:11:30 | 00,000,670 | ---- | C] () -- D:\Documents and Settings\soteri\Desktop\Mazaika.lnk [2008/11/12 18:11:27 | 00,000,000 | ---D | C] -- D:\Program Files\Mazaika24 [2008/11/12 18:10:37 | 00,000,000 | ---D | C] -- D:\Program Files\maz240 [2008/11/09 12:35:31 | 02,136,064 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntkrnlmp.exe [2008/11/09 12:35:30 | 02,180,352 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntoskrnl.exe [2008/11/09 12:35:29 | 02,015,744 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntkrpamp.exe [2008/11/09 12:35:28 | 02,057,728 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\ntkrnlpa.exe [2008/11/08 16:28:22 | 00,000,000 | ---D | C] -- D:\WINDOWS\ie7updates [2008/11/03 20:12:34 | 00,000,000 | ---D | C] -- D:\WINDOWS\network diagnostic [2008/11/03 19:19:15 | 00,000,000 | ---D | C] -- D:\WINDOWS\WBEM [2008/11/03 19:19:13 | 00,000,000 | ---D | C] -- D:\WINDOWS\System32\en-US [2008/11/03 19:17:02 | 00,000,000 | -H-D | C] -- D:\WINDOWS\ie7 [2008/11/03 19:16:20 | 00,000,000 | -H-D | C] -- D:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$ [2008/11/03 19:15:23 | 00,000,000 | -H-D | C] -- D:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$ [2008/10/30 14:13:33 | 00,000,000 | ---- | C] () -- D:\WINDOWS\nsreg.dat [2008/10/30 14:12:50 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Local Settings\Application Data\Mozilla [2008/10/30 14:12:49 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Application Data\Mozilla [2008/10/30 14:12:29 | 00,001,602 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk [2008/10/30 14:12:14 | 00,000,000 | ---D | C] -- D:\Program Files\Mozilla Firefox [2008/10/28 19:24:39 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Application Data\Yahoo! [2008/10/28 19:24:38 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Yahoo! Companion [2008/10/28 18:38:29 | 00,000,000 | ---D | C] -- D:\Documents and Settings\soteri\Local Settings\Application Data\Yahoo [2008/10/28 17:51:45 | 00,000,812 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk [2008/10/28 17:48:01 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Yahoo! [2008/10/28 17:47:21 | 00,000,000 | ---D | C] -- D:\Program Files\Yahoo! ========== Files - Modified Within 30 Days ========== [4 D:\WINDOWS\System32\*.tmp files] [3 D:\WINDOWS\*.tmp files] [2008/11/23 22:00:49 | 00,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT [2008/11/23 22:00:44 | 00,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat [2008/11/23 21:48:42 | 06,907,426 | -H-- | M] () -- D:\Documents and Settings\soteri\Local Settings\Application Data\IconCache.db [2008/11/23 21:44:40 | 00,028,160 | ---- | M] () -- D:\Documents and Settings\soteri\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008/11/23 21:23:16 | 00,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl [2008/11/20 18:35:34 | 00,042,944 | ---- | M] () -- D:\Documents and Settings\soteri\Local Settings\Application Data\GDIPFONTCACHEV1.DAT [2008/11/20 18:34:45 | 00,189,792 | ---- | M] () -- D:\WINDOWS\System32\FNTCACHE.DAT [2008/11/20 18:06:35 | 00,000,696 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2008/11/19 15:47:24 | 00,649,728 | -HS- | M] () -- D:\Documents and Settings\soteri\My Documents\Thumbs.db @Alternate Data Stream - 0 bytes -> D:\Documents and Settings\soteri\My Documents\Thumbs.db:encryptable [2008/11/15 14:15:45 | 00,002,577 | ---- | M] () -- D:\WINDOWS\System32\CONFIG.NT [2008/11/14 19:31:59 | 00,002,855 | ---- | M] () -- D:\Documents and Settings\soteri\Desktop\Shortcut to TC.pif [2008/11/12 18:19:21 | 00,001,393 | ---- | M] () -- D:\WINDOWS\imsins.BAK [2008/11/12 18:11:30 | 00,000,670 | ---- | M] () -- D:\Documents and Settings\soteri\Desktop\Mazaika.lnk [2008/11/03 19:23:11 | 00,000,077 | -HS- | M] () -- D:\Documents and Settings\soteri\My Documents\desktop.ini [2008/11/02 09:26:06 | 00,458,340 | ---- | M] () -- D:\WINDOWS\System32\PerfStringBackup.INI [2008/11/02 09:26:06 | 00,392,626 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat [2008/11/02 09:26:06 | 00,058,800 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat [2008/10/30 14:13:33 | 00,000,000 | ---- | M] () -- D:\WINDOWS\nsreg.dat [2008/10/30 14:12:29 | 00,001,602 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk [2008/10/28 17:51:45 | 00,000,812 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk < End of report > extras OTViewIt Extras logfile created on: 11/23/2008 10:08:47 PM - Run 5 OTViewIt by OldTimer - Version 1.0.20.0 Folder = D:\jonard\aplikeysyons Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 127.48 Mb Total Physical Memory | 36.12 Mb Available Physical Memory | 28.33% Memory free 307.27 Mb Paging File | 142.95 Mb Available in Paging File | 46.52% Paging File free Paging file location(s): D:\pagefile.sys 192 384; %SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files Drive C: | 9.77 Gb Total Space | 9.67 Gb Free Space | 98.98% Space Free | Partition Type: NTFS Drive D: | 18.86 Gb Total Space | 8.12 Gb Free Space | 43.05% Space Free | Partition Type: NTFS E: Drive not present or media not loaded Drive F: | 962.07 Mb Total Space | 610.44 Mb Free Space | 63.45% Space Free | Partition Type: FAT32 Drive G: | 1010.22 Mb Total Space | 1009.23 Mb Free Space | 99.90% Space Free | Partition Type: FAT H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: ZAMORA-8F8E222F Current User Name: soteri Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Whitelist: On File Age = 30 Days "Use My Stylesheet"= "User Stylesheet"= ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled"=1 "AntiVirusDisableNotify"=0 "FirewallDisableNotify"=0 "UpdatesDisableNotify"=0 "AntiVirusOverride"=1 "FirewallOverride"=0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile "EnableFirewall"=1 "DoNotAllowExceptions"=0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts] ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [2004/08/03 14:56:58 | 00,140,800 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 [2006/10/10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [2004/08/03 14:56:58 | 00,140,800 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 [2008/10/16 20:57:52 | 04,347,120 | ---- | M] (Yahoo! Inc.) -- D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger [2006/10/10 04:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 ========== (O18) Protocol Handlers ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] ipp: [HKLM - No CLSID value] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers [2003/07/11 02:25:22 | 00,842,816 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] msdaipp: [HKLM - No CLSID value] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers [2003/07/11 02:25:22 | 00,842,816 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers [2003/07/11 02:25:22 | 00,842,816 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] [2003/08/04 13:19:34 | 07,330,360 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} (HKLM) [Data Page Pluggable Protocol mso-offdap Handler]) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] [2003/08/01 15:09:04 | 08,086,072 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (mso-offdap11:{32505114-5902-49B2-880A-1F7738E5A384} (HKLM) [Data Page Plugable Protocal mso-offdap11 Handler]) ========== (O18) Protocol Filters ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters [2003/07/14 22:45:12 | 00,039,488 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL text/xml:{807553E5-5146-11D5-A672-00B0D022E945} (HKLM) [Reg Error: Value does not exist or could not be read.] ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00203668-8170-44A0-BE44-B632FA4D780F}"=Adobe AIR "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP "{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}"=Microsoft .NET Framework 2.0 "{7299052b-02a4-4627-81f2-1818da5d550d}"=Microsoft Visual C++ 2005 Redistributable "{77DCDCE3-2DED-62F3-8154-05E745472D07}"=Acrobat.com "{90110409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office Professional Edition 2003 "{AC76BA86-7AD7-1033-7B44-A90000000001}"=Adobe Reader 9 "{D86FEEE1-C996-11D6-A67A-0080AD061ECA}"=Mazaika v.2.4 "Adobe AIR"=Adobe AIR "Adobe Flash Player ActiveX"=Adobe Flash Player ActiveX "Adobe Flash Player Plugin"=Adobe Flash Player 10 Plugin "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1"=Acrobat.com "IDNMitigationAPIs"=Microsoft Internationalized Domain Names Mitigation APIs "ie7"=Windows Internet Explorer 7 "Malwarebytes' Anti-Malware_is1"=Malwarebytes' Anti-Malware "Microsoft .NET Framework 2.0"=Microsoft .NET Framework 2.0 "Mozilla Firefox (3.0.3)"=Mozilla Firefox (3.0.3) "NLSDownlevelMapping"=Microsoft National Language Support Downlevel APIs "Wdf01007"=Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 "Windows Media Format Runtime"=Windows Media Format 11 runtime "WMFDist11"=Windows Media Format 11 runtime "Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0 "Yahoo! Companion"=Yahoo! Toolbar "Yahoo! IE Suggest"=Yahoo! Search Suggest Add-on for IE7 "Yahoo! Messenger"=Yahoo! Messenger ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 10/8/2008 12:50:39 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/8/2008 12:53:04 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/8/2008 12:56:21 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/8/2008 1:09:24 PM | Computer Name = ZAMORA-8F8E222F | Source = ZuneDriver | ID = 80837 Description = Error - 10/28/2008 7:37:27 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application xrule.exe, version 0.0.0.0, faulting module xrule.exe, version 0.0.0.0, fault address 0x00005609. Error - 10/29/2008 9:06:12 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Hang | ID = 1002 Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 10/30/2008 4:34:53 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application yahoomessenger.exe, version 9.0.0.2018, faulting module yahoomessenger.exe, version 9.0.0.2018, fault address 0x00176612. Error - 11/3/2008 11:52:36 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 7.0.5730.13, faulting module jscript.dll, version 5.7.0.5730, fault address 0x0001bb9d. Error - 11/3/2008 11:55:05 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 7.0.5730.13, faulting module jscript.dll, version 5.7.0.5730, fault address 0x0001bb9d. Error - 11/12/2008 10:17:21 PM | Computer Name = ZAMORA-8F8E222F | Source = Application Hang | ID = 1002 Description = Hanging application mz002.exe, version 2.4.0.258, hang module hungapp, version 0.0.0.0, hang address 0x00000000. [ System Events ] Error - 11/19/2008 7:42:49 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/19/2008 7:46:41 PM | Computer Name = ZAMORA-8F8E222F | Source = W32Time | ID = 39452706 Description = The time service has detected that the system time needs to be changed by -57454 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com (ntp.m|0x1|210.1.98.177:123->207.46.197.32:123) is working properly. Error - 11/20/2008 8:43:50 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/20/2008 9:35:19 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/20/2008 10:35:14 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/21/2008 9:29:18 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/21/2008 10:19:31 PM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/23/2008 1:18:09 AM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/24/2008 1:23:35 AM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 Error - 11/24/2008 2:01:05 AM | Computer Name = ZAMORA-8F8E222F | Source = Service Control Manager | ID = 7000 Description = The Zune Bus Enumerator Driver service failed to start due to the following error: %%2 < End of report > |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 8th November 2009 - 04:59 AM |