Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Problems With Unknown Malware


  • This topic is locked This topic is locked
8 replies to this topic

#1 tranqiller

tranqiller

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:08:41 AM

Posted 03 October 2008 - 06:50 PM

Hi,im experiencing numerous problems on pc these days.IE wont terminate when im turning off the computer and in many situations it stops responding.When i try to open Registry editor i get a message that administrator disabled that option.I found a strange file called U.exe in my root folder.Also,primosearch.com site sometimes pops up and i cant use automatic updates settings.After scan with NOD32,Spybot and Stinger nothing comes up.Here is my log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:20:25, on 4.10.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\Program Files\ASUS\ASUS Remote\RemoteControlAppl.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_06\bin\jucheck.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sarajevo-x.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\System\Sony_Desk_Startup.exe"
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {89353243-3473-6884-6472-5599ca323026} - C:\Program Files\Common Files\System\vss z.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [RemoteControl] C:\Program Files\ASUS\ASUS Remote\RemoteControlAppl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: NVidia Desk Startup.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Skype Util Startup.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{94224FA4-CB9B-49E9-A02E-556ABB35FDB9}: NameServer = 195.222.32.10 195.222.32.20
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe

--
End of file - 7959 bytes

BC AdBot (Login to Remove)

 


#2 tranqiller

tranqiller
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:08:41 AM

Posted 05 October 2008 - 05:41 AM

I also did a scan today,with Trojan Hunter,but nothing could be found.What about this entry:
F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\System\Sony_Desk_Startup.exe"
Does it look suspicious?Any help would be appreciated...

#3 tranqiller

tranqiller
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:08:41 AM

Posted 07 October 2008 - 07:06 AM

After submitting Sony_Desk_Startup.exe file for further analysis to NOD32,and definition update,the file was detected as a "variant of Win32/TrojanDownloader.Delf.OHT trojan" and action taken:cleaned by deleting - quarantined.What more can i do,to get rid of this trojan?

#4 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:06:41 AM

Posted 09 October 2008 - 03:21 PM

Hello, tranqiller.
:thumbsup: to BleepingComputer.com

My name is Billy O'Neal and I will be helping you. (Billy or Bill is fine, if you like.)

I want to apologise that it has taken so long to get back to you. We on the HJT Team are working as fast as possible to get your log answered.

If you do not still need help, please let me know, so that I can move on to other users who still need help.

Please take note of the following:
  • While a HJT Team member is working with you, please refrain from making any changes to your computer.
  • Also, even if things appear to be running better, there is no guarantee that everything is finished. Please continue to check this forum post in order to ensure we get your system completely clean. We do not want to clean you part-way up, only to have the system re-infect itself. :)
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Please reply using the Posted Image button in the lower left hand corner of your screen.
  • Old topics are closed after 3 days with no reply, and working topics are closed after 5 days. If for any reason you cannot complete instructions within that time, that's fine, just put a post here so that I know you're still here. We get a lot of people who simply leave, and if there is no contact for that amount of time I will have to assume you have "vanished" :).
If you would still like help, please follow the instructions below:

We need to create an OTViewIt Report
  • Please download OTViewIt by OldTimer.
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Push the Posted Image button.
  • Two reports will open, copy and paste them in a reply here:
  • OTViewIt.txt <-- Will be opened
  • Extra.txt <-- Will be minimized
Please do an online scan with Kaspersky WebScanner.
  • Please visit the Kaspersky Online Scanner website.
    Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
In your next reply, please include the following:
  • OTViewIt.txt
  • Extra.txt
  • Kaspersky's Log


Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#5 tranqiller

tranqiller
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:08:41 AM

Posted 10 October 2008 - 09:28 AM

Thx for the reply,Billy :thumbsup: Before i paste log information,here are the things i did since my last post:Sony_Desk_Startup.exe,Skype Util Startup.exe and NVidia Desk Starup.exe are deleted by NOD32,i have reinstalled IE and removed the "C:\Program Files\Common Files\System\Sony_Desk_Startup.exe" part from the Shell value.
This is OTViewIt report:

OTViewIt logfile created on: 10.10.2008 11:30:43 - Run 2
OTViewIt by OldTimer - Version 1.0.10.1 Folder = C:\Documents and Settings\****\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 0000101A | Country: Bosnia and Herzegovina | Language: HRB | Date Format: d.M.yyyy

510,80 Mb Total Physical Memory | 73,31 Mb Available Physical Memory | 14,35% Memory free
1,22 Gb Paging File | 0,80 Gb Available in Paging File | 65,35% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 28,61 Gb Total Space | 5,97 Gb Free Space | 20,87% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 37,60 Gb Total Space | 10,66 Gb Free Space | 28,34% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ******
Current User Name: *****
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== Processes ==========

[2007.08.22 03:57:14 | 00,487,424 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\ati2evxx.exe
[2005.05.11 21:01:14 | 00,221,257 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
[2005.05.11 21:03:14 | 00,061,440 | ---- | M] (Cyberlink) -- C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
[2005.05.11 21:03:18 | 00,737,381 | ---- | M] (Cyberlink) -- C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
[2008.03.13 16:49:56 | 00,472,320 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
[2008.03.09 11:20:26 | 00,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
[2005.05.11 21:01:36 | 00,110,663 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
[2007.08.22 03:57:14 | 00,487,424 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\ati2evxx.exe
[2002.07.12 16:33:00 | 01,581,056 | ---- | M] (C-Media Electronic Inc. (www.cmedia.com.tw)) -- C:\WINDOWS\mixer.exe
[2005.12.05 17:04:00 | 00,065,536 | ---- | M] (ASUSTeK) -- C:\Program Files\ASUS\ASUS Remote\RemoteControlAppl.exe
[2005.05.11 20:58:12 | 00,127,118 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerCinema\PCMService.exe
[2008.03.25 04:28:02 | 00,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
[2008.03.13 16:48:30 | 01,443,072 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
[2007.07.17 11:13:56 | 00,049,152 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
[2007.08.24 07:00:48 | 00,033,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[2008.09.16 12:16:08 | 01,833,296 | RHS- | M] (Safer Networking Limited) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[2007.07.17 11:13:34 | 00,049,152 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
[2008.04.14 05:42:42 | 00,218,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\wmiprvse.exe
[2008.10.03 12:32:59 | 00,307,712 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
[2007.10.18 11:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[2008.03.25 04:28:02 | 00,329,104 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_06\bin\jucheck.exe
[2008.10.10 11:27:15 | 00,421,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Danko\Desktop\OTViewIt.exe

========== (O23) Win32 Services ==========

[2007.10.24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2007.08.22 03:57:14 | 00,487,424 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\ati2evxx.exe -- (Ati HotKey Poller [Auto | Running])
[2007.08.21 21:05:00 | 00,593,920 | ---- | M] () -- C:\WINDOWS\system32\ati2sgag.exe -- (ATI Smart [Auto | Stopped])
[2005.05.11 21:01:14 | 00,221,257 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe -- (CLCapSvc [Auto | Running])
[2007.10.24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[2005.05.11 21:01:36 | 00,110,663 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe -- (CLSched [Auto | Running])
[2005.05.11 21:03:14 | 00,061,440 | ---- | M] (Cyberlink) -- C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe -- (CyberLink Media Library Service [Auto | Running])
[2008.03.13 16:55:26 | 00,019,200 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv [On_Demand | Stopped])
[2008.03.13 16:49:56 | 00,472,320 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn [Auto | Running])
[2007.10.09 12:58:12 | 00,036,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
[2007.10.11 09:55:10 | 00,864,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
[2007.08.24 06:59:20 | 00,068,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])
[2007.10.11 09:55:14 | 00,122,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
[2008.03.09 11:20:26 | 00,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU [Auto | Running])
[2007.08.24 03:19:12 | 00,443,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
[2006.10.26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2007.10.18 11:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Stopped])

========== Driver Services ==========

[2005.12.26 10:08:52 | 02,815,744 | R--- | M] (ASUSTek) -- C:\WINDOWS\system32\drivers\3xHybrid.sys -- (3xHybrid [On_Demand | Running])
[2008.05.06 08:01:28 | 00,016,512 | ---- | M] (Adaptec) -- C:\WINDOWS\system32\drivers\ASPI32.SYS -- (Aspi32 [Auto | Running])
[2007.08.22 04:07:38 | 02,417,664 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag [On_Demand | Running])
[2002.07.16 10:58:00 | 00,379,726 | ---- | M] (C-Media Inc) -- C:\WINDOWS\system32\drivers\cmaudio.sys -- (cmpci [On_Demand | Running])
[2000.05.02 15:42:50 | 00,016,480 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\dmsmbios.sys -- (dmsmbios [Auto | Running])
[2008.03.13 16:43:42 | 00,040,456 | ---- | M] (ESET) -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon [Auto | Running])
[2008.03.13 16:44:36 | 00,029,704 | ---- | M] (ESET) -- C:\WINDOWS\system32\drivers\easdrv.sys -- (easdrv [System | Running])
[2008.03.13 16:52:18 | 00,033,800 | ---- | M] () -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir [System | Running])
[2008.04.14 00:15:30 | 00,010,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum [On_Demand | Running])
[2001.08.17 15:28:02 | 00,907,456 | ---- | M] (Conexant) -- C:\WINDOWS\system32\drivers\HCF_MSFT.sys -- (HCF_MSFT [On_Demand | Running])
[2008.04.14 00:16:24 | 00,015,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\MPE.sys -- (MPE [On_Demand | Stopped])
File not found -- E:\PCIDATA.sys -- (PCIDATA [On_Demand | Stopped])
[2004.02.24 19:25:06 | 00,010,368 | ---- | M] (Padus, Inc.) -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc [On_Demand | Running])
[2004.05.05 21:48:40 | 00,004,228 | ---- | M] (PowerQuest Corporation) -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv [System | Running])
[2001.08.23 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2008.06.11 02:07:16 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
[2004.08.04 00:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139 [On_Demand | Running])
[2008.04.13 22:09:16 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped])

========== (R ) Internet Explorer ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"First Home Page"=http://go.microsoft.com/fwlink/?LinkId=54843
"Local Page"=C:\WINDOWS\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-21-117609710-515967899-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main]
"First Home Page"=http://go.microsoft.com/fwlink/?LinkId=54843
"Local Page"=C:\WINDOWS\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896

[HKEY_USERS\S-1-5-21-117609710-515967899-839522115-1003\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-117609710-515967899-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

========== (O1) Hosts File ==========

HOSTS File = (265959 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 123topsearch.com
127.0.0.1 www.123topsearch.com
127.0.0.1 132.com
127.0.0.1 www.132.com
127.0.0.1 www.136136.net
127.0.0.1 136136.net
9215 more lines...

========== (O4) Run Keys ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"=Mixer.exe /startup (C-Media Electronic Inc. (www.cmedia.com.tw))
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice (ESET)
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" (Microsoft Corporation)
"PCMService"="C:\Program Files\CyberLink\PowerCinema\PCMService.exe" (CyberLink Corp.)
"RemoteControl"=C:\Program Files\ASUS\ASUS Remote\RemoteControlAppl.exe (ASUSTeK)
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" ()
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" (Sun Microsystems, Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)

[HKEY_USERS\S-1-5-21-117609710-515967899-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)

========== (O4) Startup Folders ==========

[2005.09.23 22:05:26 | 00,029,696 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

========== (O6 & O7) Current Version Policies ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoWindowsUpdate"=0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableRegistryTools"=0

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoWindowsUpdate"=0

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"DisableRegistryTools"=0

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-21-117609710-515967899-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoWindowsUpdate"=0

[HKEY_USERS\S-1-5-21-117609710-515967899-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"DisableRegistryTools"=0

========== (O9) IE Extensions ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console -- %ProgramFiles%\Java\jre1.6.0_06\bin\npjpi160_06.dll [2008.03.25 04:28:01 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
{2670000A-7350-4f3c-8081-5663EE0C6C49}: Button: Send to OneNote -- %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [2007.08.29 00:49:28 | 00,606,120 | ---- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}: Menu: S&end to OneNote -- %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [2007.08.29 00:49:28 | 00,606,120 | ---- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [2006.10.26 20:12:22 | 00,040,424 | ---- | M] (Microsoft Corporation)
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}: Menu: Spybot - Search & Destroy Configuration -- %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [2008.09.15 14:25:44 | 01,562,960 | RHS- | M] (Safer Networking Limited)
{e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 -- %SystemRoot%\network diagnostic\xpnetdiag.exe [2008.04.14 00:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008.04.14 05:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008.04.14 05:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [Research] -> [2006.10.26 20:12:22 | 00,040,424 | ---- | M] (Microsoft Corporation)
CmdMapping\\{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008.04.14 00:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008.04.14 05:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008.04.14 00:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008.04.14 05:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008.04.14 00:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008.04.14 05:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-117609710-515967899-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [Research] -> [2006.10.26 20:12:22 | 00,040,424 | ---- | M] (Microsoft Corporation)
CmdMapping\\{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008.04.14 00:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008.04.14 05:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation)

========== (O12) Internet Explorer Plugins ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = http://activex.microsoft.com/controls/find...=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery

========== (O13) Default Prefixes ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://

========== (O15) Trusted Sites ==========

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
45 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
45 domain(s) and sub-domain(s) not assigned to a zone.

========== (O16) DPF ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_06
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}: http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab -- Reg Error: Key does not exist or could not be opened.
{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_06
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_06

========== (O17) DNS Name Servers ==========

{95004D3B-42C2-4679-8CA1-6F9F0E9B99AB} (Servers: | Description: )
{C1263EA9-9B8E-40FA-926A-59FF708067FD} (Servers: | Description: Realtek RTL8139 Family PCI Fast Ethernet NIC)

========== (O20) Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
AtiExtEvent: "DllName" = Ati2evxx.dll -- C:\WINDOWS\system32\ati2evxx.dll (ATI Technologies Inc.)
WgaLogon: "DllName" = WgaLogon.dll -- File not found

========== Shell Execute Hooks ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" (HKLM) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

========== Safeboot Options ==========

"AlternateShell"=cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
[2008.05.26 16:55:10 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2008.10.10 11:26:48 | 00,421,376 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Danko\Desktop\OTViewIt.exe
[2008.10.09 12:50:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Danko\Application Data\Malwarebytes
[2008.10.09 12:49:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008.10.09 11:51:14 | 00,053,248 | ---- | C] (http://www.beyondlogic.org) -- C:\WINDOWS\System32\process.exe
[2008.10.09 11:51:14 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\swsc.exe
[2008.10.09 11:51:14 | 00,016,384 | ---- | C] (WareSoft Software) -- C:\WINDOWS\System32\restart.exe
[2008.10.09 11:51:14 | 00,004,096 | ---- | C] () -- C:\WINDOWS\System32\reboot.exe
[2008.10.09 11:51:13 | 00,090,112 | ---- | C] (Frank Heyne Software) -- C:\WINDOWS\System32\regdacl.exe
[2008.10.09 11:51:13 | 00,042,496 | ---- | C] () -- C:\WINDOWS\System32\swreg.exe
[2008.10.09 11:51:13 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\regdacl
[2008.10.07 20:00:10 | 00,008,180 | ---- | C] () -- C:\Documents and Settings\Danko\Desktop\vozac.o
[2008.10.07 19:06:43 | 00,003,595 | ---- | C] () -- C:\Documents and Settings\Danko\Desktop\vozilo.o
[2008.10.07 18:57:10 | 00,000,844 | ---- | C] () -- C:\Documents and Settings\Danko\Desktop\vozilo.cpp
[2008.10.07 18:53:16 | 00,000,314 | ---- | C] () -- C:\Documents and Settings\Danko\Desktop\vozilo.h
[2008.10.06 21:25:47 | 00,482,835 | ---- | C] () -- C:\Documents and Settings\Danko\Desktop\Project1.exe
[2008.10.06 20:56:53 | 00,002,516 | ---- | C] () -- C:\Documents and Settings\Danko\Desktop\main.o
[2008.10.06 20:25:34 | 00,000,424 | ---- | C] () -- C:\Documents and Settings\Danko\Desktop\Project1.layout
[2008.10.06 20:13:39 | 00,002,053 | ---- | C] () -- C:\Documents and Settings\Danko\Desktop\vozac.cpp
[2008.10.06 20:13:34 | 00,000,209 | ---- | C] () -- C:\Documents and Settings\Danko\Desktop\main.cpp
[2008.10.06 20:10:50 | 00,000,561 | ---- | C] () -- C:\Documents and Settings\Danko\Desktop\vozac.h
[2008.10.04 14:38:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Danko\Application Data\TrojanHunter
[2008.10.04 14:01:01 | 00,059,392 | R--- | C] () -- C:\WINDOWS\System32\streamhlp.dll
[2008.10.04 14:00:59 | 00,000,000 | ---D | C] -- C:\Program Files\TrojanHunter 5.0
[2008.10.04 13:17:42 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2008.10.04 13:17:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008.10.04 13:05:06 | 53,567,8976 | -HS- | C] () -- C:\hiberfil.sys
[2008.10.04 01:17:24 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2008.10.03 22:17:30 | 00,000,933 | ---- | C] () -- C:\Documents and Settings\Danko\Desktop\Spybot - Search & Destroy.lnk
[2008.10.03 22:17:18 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2008.10.03 22:17:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008.10.03 20:52:55 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie7updates
[2008.10.03 20:52:17 | 00,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2008.10.03 20:12:48 | 00,203,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rmcast.sys
[2008.10.03 20:12:35 | 00,331,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msadce.dll
[2008.10.03 20:12:30 | 00,459,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll
[2008.10.03 20:12:30 | 00,052,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2008.10.03 20:12:29 | 00,267,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll
[2008.10.03 20:12:26 | 00,383,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2008.10.03 20:12:26 | 00,063,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icardie.dll
[2008.10.03 20:12:26 | 00,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieudinit.exe
[2008.10.03 20:12:24 | 02,455,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieapfltr.dat
[2008.10.03 20:12:24 | 00,991,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll.mui
[2008.10.03 20:12:20 | 06,066,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
[2008.10.03 20:10:57 | 00,691,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetcomm.dll
[2008.10.03 15:57:30 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2008.10.03 11:05:15 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2008.09.30 17:22:55 | 00,001,346 | ---- | C] () -- C:\Documents and Settings\Danko\Desktop\Project1.dev
[2008.09.30 17:22:55 | 00,000,959 | ---- | C] () -- C:\Documents and Settings\Danko\Desktop\Makefile.win
[2008.09.29 13:26:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Danko\Local Settings\Application Data\ESET
[2008.09.28 21:55:17 | 00,585,048 | ---- | C] () -- C:\Documents and Settings\Danko\Desktop\Untitled1.exe
[2008.09.24 20:34:42 | 00,000,041 | ---- | C] () -- C:\WINDOWS\MinGW.INI
[2008.09.24 20:34:12 | 00,000,000 | ---D | C] -- C:\MinGW
[2008.09.16 20:59:09 | 00,303,104 | ---- | C] () -- C:\Documents and Settings\Danko\My Documents\test.accdb
[2008.09.16 12:54:16 | 00,486,762 | ---- | C] () -- C:\Documents and Settings\Danko\My Documents\UBP.Syllabus.2007.08.zip
[2008.09.15 20:00:51 | 00,032,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msonpmon.dll
[2008.09.15 19:57:46 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2008.09.15 19:56:42 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
[2008.09.15 19:56:42 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2008.09.15 19:55:28 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2008.09.15 19:51:17 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 8
[2008.09.15 19:50:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Danko\Local Settings\Application Data\Microsoft Help
[2008.09.15 19:50:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2008.09.15 19:48:47 | 00,000,000 | RH-D | C] -- C:\MSOCache

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2008.10.10 11:27:15 | 00,421,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Danko\Desktop\OTViewIt.exe
[2008.10.10 09:55:35 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2008.10.10 09:55:32 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2008.10.10 09:55:28 | 53,567,8976 | -HS- | M] () -- C:\hiberfil.sys
[2008.10.09 19:40:37 | 00,000,424 | ---- | M] () -- C:\Documents and Settings\Danko\Desktop\Project1.layout
[2008.10.09 19:35:10 | 00,000,959 | ---- | M] () -- C:\Documents and Settings\Danko\Desktop\Makefile.win
[2008.10.09 19:27:52 | 00,000,209 | ---- | M] () -- C:\Documents and Settings\Danko\Desktop\main.cpp
[2008.10.09 19:26:48 | 00,002,053 | ---- | M] () -- C:\Documents and Settings\Danko\Desktop\vozac.cpp
[2008.10.09 19:26:42 | 00,000,561 | ---- | M] () -- C:\Documents and Settings\Danko\Desktop\vozac.h
[2008.10.09 19:00:55 | 00,000,215 | ---- | M] () -- C:\Documents and Settings\Danko\Desktop\Untitled1.cpp
[2008.10.09 19:00:27 | 00,585,048 | ---- | M] () -- C:\Documents and Settings\Danko\Desktop\Untitled1.exe
[2008.10.09 17:22:46 | 00,046,080 | ---- | M] () -- C:\Documents and Settings\Danko\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.10.09 11:51:11 | 00,090,112 | ---- | M] (Frank Heyne Software) -- C:\WINDOWS\System32\regdacl.exe
[2008.10.09 11:51:11 | 00,053,248 | ---- | M] (http://www.beyondlogic.org) -- C:\WINDOWS\System32\process.exe
[2008.10.09 11:51:11 | 00,042,496 | ---- | M] () -- C:\WINDOWS\System32\swreg.exe
[2008.10.09 11:51:11 | 00,040,960 | ---- | M] () -- C:\WINDOWS\System32\swsc.exe
[2008.10.09 11:51:11 | 00,016,384 | ---- | M] (WareSoft Software) -- C:\WINDOWS\System32\restart.exe
[2008.10.09 11:51:11 | 00,004,096 | ---- | M] () -- C:\WINDOWS\System32\reboot.exe
[2008.10.07 20:00:11 | 00,482,835 | ---- | M] () -- C:\Documents and Settings\Danko\Desktop\Project1.exe
[2008.10.07 20:00:10 | 00,008,180 | ---- | M] () -- C:\Documents and Settings\Danko\Desktop\vozac.o
[2008.10.07 19:59:34 | 00,002,516 | ---- | M] () -- C:\Documents and Settings\Danko\Desktop\main.o
[2008.10.07 19:59:15 | 00,001,346 | ---- | M] () -- C:\Documents and Settings\Danko\Desktop\Project1.dev
[2008.10.07 19:06:43 | 00,003,595 | ---- | M] () -- C:\Documents and Settings\Danko\Desktop\vozilo.o
[2008.10.06 21:11:00 | 00,000,844 | ---- | M] () -- C:\Documents and Settings\Danko\Desktop\vozilo.cpp
[2008.10.06 21:10:42 | 00,000,314 | ---- | M] () -- C:\Documents and Settings\Danko\Desktop\vozilo.h
[2008.10.04 14:01:22 | 00,059,392 | R--- | M] () -- C:\WINDOWS\System32\streamhlp.dll
[2008.10.04 13:18:23 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2008.10.04 12:34:00 | 00,000,773 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.msn
[2008.10.04 12:30:27 | 00,265,959 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2008.10.03 22:27:11 | 00,265,912 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts1.bak
[2008.10.03 22:17:30 | 00,000,933 | ---- | M] () -- C:\Documents and Settings\Danko\Desktop\Spybot - Search & Destroy.lnk
[2008.10.03 20:55:21 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2008.10.01 18:15:27 | 00,436,090 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2008.10.01 18:15:27 | 00,068,608 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2008.10.01 18:15:26 | 00,510,888 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2008.09.24 20:34:42 | 00,000,041 | ---- | M] () -- C:\WINDOWS\MinGW.INI
[2008.09.17 14:10:54 | 00,303,104 | ---- | M] () -- C:\Documents and Settings\Danko\My Documents\test.accdb
[2008.09.16 12:54:21 | 00,486,762 | ---- | M] () -- C:\Documents and Settings\Danko\My Documents\UBP.Syllabus.2007.08.zip
[2008.09.15 20:17:22 | 00,069,232 | ---- | M] () -- C:\Documents and Settings\Danko\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008.09.15 20:15:43 | 00,267,800 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008.09.15 20:06:27 | 00,000,667 | ---- | M] () -- C:\WINDOWS\win.ini
< End of report >

Extras report:

OTViewIt Extras logfile created on: 10.10.2008 11:30:43 - Run 2
OTViewIt by OldTimer - Version 1.0.10.1 Folder = C:\Documents and Settings\****\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 0000101A | Country: Bosnia and Herzegovina | Language: HRB | Date Format: d.M.yyyy

510,80 Mb Total Physical Memory | 73,31 Mb Available Physical Memory | 14,35% Memory free
1,22 Gb Paging File | 0,80 Gb Available in Paging File | 65,35% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 28,61 Gb Total Space | 5,97 Gb Free Space | 20,87% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 37,60 Gb Total Space | 10,66 Gb Free Space | 28,34% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ****
Current User Name: *******
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled"=1
"AntiVirusDisableNotify"=1
"FirewallDisableNotify"=1
"UpdatesDisableNotify"=1
"AntiVirusOverride"=0
"FirewallOverride"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008.04.14 05:42:36 | 00,141,312 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2008.04.14 00:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2007.10.18 11:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
[2007.10.02 17:18:24 | 00,304,488 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2008.04.14 05:42:36 | 00,141,312 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2008.04.14 00:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008.04.14 05:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
[2007.10.18 11:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
[2007.10.02 17:18:24 | 00,304,488 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)
File not found -- C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus
[2005.05.11 20:58:08 | 00,045,056 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerCinema\PowerCinema.exe:*:Enabled:CyberLink PowerCinema Main Program
[2005.04.10 18:04:27 | 01,163,264 | ---- | M] () -- F:\DC++\DCPlusPlus.exe:*:Enabled:DC++
[2007.09.06 18:01:10 | 12,836,728 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook
[2007.08.29 00:23:36 | 00,340,856 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove
[2007.08.28 23:43:30 | 01,022,840 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote

========== (O18) Protocol Handlers ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007.08.24 07:01:46 | 00,224,128 | ---- | M] (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (grooveLocalGWS:{88FED34C-F0CA-4636-A375-3CB6248B04CD} (HKLM) [Local Groove Web Services Protocol])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
ipp: [HKLM - No CLSID value]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2007.08.28 23:55:14 | 01,014,128 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007.10.18 11:31:54 | 00,066,072 | ---- | M] (Microsoft Corporation) C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (livecall:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
msdaipp: [HKLM - No CLSID value]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2007.08.28 23:55:14 | 01,014,128 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2007.08.28 23:55:14 | 01,014,128 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2006.10.26 13:45:02 | 00,873,216 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (ms-help:{314111c7-a502-11d2-bbca-00c04f8ec294} (HKLM) [HxProtocol Class])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007.10.18 11:31:54 | 00,066,072 | ---- | M] (Microsoft Corporation) C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (msnim:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

========== (O18) Protocol Filters ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters
[2006.10.26 21:41:48 | 00,044,344 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL text/xml:{807563E5-5146-11D5-A672-00B0D022E945} (HKLM) [Microsoft Office InfoPath XML Mime Filter]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{001DC47F-B755-4024-7BBE-2B55F876F27A}"=CCC Help Hungarian
"{0148F26E-45F1-8E12-C007-BF101A24B53B}"=CCC Help Finnish
"{055EE59D-217B-43A7-ABFF-507B966405D8}"=ATI Catalyst Control Center
"{06A1BE8A-4CA4-4A39-B9E4-E815AA8FE05C}"=Sony Noise Reduction Plug-In 2.0h
"{092D5859-1DAC-E3AC-BE62-185D5F43C2D7}"=Catalyst Control Center Localization Thai
"{0B010EB2-2867-2C54-4250-301DE0EB200E}"=Catalyst Control Center Localization Chinese Traditional
"{0CD6EFF4-36AB-F7A2-3CDB-4C3DA8237A51}"=CCC Help Greek
"{18D10072035C4515918F7E37EAFAACFC}"=AutoUpdate
"{1F46AA6E-F1C4-005C-80E4-A0CA16260C03}"=Catalyst Control Center Graphics Light
"{1F76B418-A510-3E60-9115-8D3FAC044404}"=Catalyst Control Center Localization Russian
"{21DBBDD6-93A5-4326-9A04-C9A5C9148502}"=Norton PartitionMagic
"{22F7E7FC-E9F2-996C-E4F9-A7701FA6E15A}"=CCC Help Swedish
"{247643CE-54DC-74D1-D771-3FF0869F8DEF}"=Catalyst Control Center Localization German
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}"=PowerCinema 4.0
"{289C2FC2-6ED9-D19C-B450-BDB38DE067EF}"=Catalyst Control Center Localization Japanese
"{2BA00471-0328-3743-93BD-FA813353A783}"=Microsoft .NET Framework 3.0 Service Pack 1
"{2FC099BD-AC9B-33EB-809C-D332E1B27C40}"=Microsoft .NET Framework 3.5
"{30861CAD-1E28-79F4-5614-7944AF8318E9}"=CCC Help Portuguese
"{3248F0A8-6813-11D6-A77B-00B0D0160060}"=Java™ 6 Update 6
"{33348B14-87AE-A70D-08E6-DD79D9DD2CE9}"=CCC Help Chinese Traditional
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP
"{3651BA98-AB2C-6B8C-D4BD-A46271A57334}"=ccc-core-static
"{36CDA33B-909B-4719-97D1-C4B99309BDC7}"=ATI Parental Control & Encoder
"{3C26A967-F653-7B0E-4353-7E3A606E0947}"=Catalyst Control Center Localization Chinese Standard
"{3CDF65C9-C782-A1EA-AE77-452C2369D60A}"=CCC Help Danish
"{3D91E096-EDE8-A42A-31DB-3F1BA94A4EA2}"=CCC Help Japanese
"{4694FFFC-B97C-BCF2-397A-6251D702C35F}"=Catalyst Control Center Localization Polish
"{4AEA9A23-D627-4699-8A0F-FC474308C2E6}"=Sony Sound Forge 9.0
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}"=Windows Live Messenger
"{523E31CF-7240-5BB7-AD81-42DA680C2FF9}"=CCC Help Turkish
"{53B492B5-5446-0426-D254-245EBE461106}"=Catalyst Control Center Graphics Full New
"{53E2B15C-6663-EA6D-B1C1-D6A58C887F66}"=Catalyst Control Center Graphics Previews Common
"{54DB039D-1BA2-1F35-28D6-2FDB5D7DC390}"=CCC Help French
"{54F4CAE0-D0C8-CC2A-FBF4-D812DEDAABFB}"=Catalyst Control Center Localization Czech
"{58FE5799-7A89-185E-ACCB-0E247B3E8571}"=Catalyst Control Center Localization Turkish
"{5C4C7A64-9165-5AD4-A6E8-BDD2A138151C}"=Catalyst Control Center Localization Hungarian
"{653C869A-7602-682B-6C1B-CEDDC72C95CE}"=CCC Help English
"{6631DAE9-739E-BE8D-DDFE-8D6549860096}"=Catalyst Control Center Localization French
"{675E49B1-C3F0-2C15-331B-6F600241F344}"=Catalyst Control Center Localization Greek
"{70BB5CA2-18DF-3A1C-15B4-FD09FC0EC0CA}"=Catalyst Control Center Localization Norwegian
"{7299052b-02a4-4627-81f2-1818da5d550d}"=Microsoft Visual C++ 2005 Redistributable
"{729A8EEF-43AF-884B-2C50-05484FEF6DF5}"=Catalyst Control Center Localization Spanish
"{752AF1F3-BF6D-6682-1BE8-8DBA574F1327}"=CCC Help Dutch
"{7B63B2922B174135AFC0E1377DD81EC2}"=DivX Codec
"{7D73CC6B-33A8-4DE2-9539-2498A59C12C2}"=My Cinema
"{7DFD0504-9DDC-35A1-988F-9A6F53BA4B53}"=CCC Help Spanish
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1"=CDBurnerXP
"{7F5665A3-ABED-F92A-853E-A02154C0A1C4}"=CCC Help Italian
"{83CA8AF8-94BC-7A48-F4D5-027E1C67D5F7}"=Catalyst Control Center Localization Korean
"{84FE12A7-293B-4E90-CE43-38991D066D42}"=Catalyst Control Center Localization Italian
"{8531CB7D-3D1D-C4F7-16FD-1579360B48DE}"=Catalyst Control Center Localization Danish
"{86A6E235-C08F-4A14-B14C-793C7D8844A0}"=ESET NOD32 Antivirus
"{87DCDDBD-6589-1526-8B1C-E513ABB0BBBB}"=CCC Help Korean
"{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}"=ATI AVIVO Codecs
"{8ADFC4160D694100B5B8A22DE9DCABD9}"=DivX Player
"{8D67174A-6520-2434-F86B-67733EEFCF54}"=CCC Help Thai
"{90120000-0010-0409-0000-0000000FF1CE}"=Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}"=Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0016-0409-0000-0000000FF1CE}"=Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}"=Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}"=Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}"=Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}"=Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}"=Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{3EC77D26-799B-4CD8-914F-C1565E796173}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}"=Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{430971B1-C31E-45DA-81E0-72C095BAB72C}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}"=Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}"=Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}"=Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0044-0409-0000-0000000FF1CE}"=Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-006E-0409-0000-0000000FF1CE}"=Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00A1-0409-0000-0000000FF1CE}"=Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00BA-0409-0000-0000000FF1CE}"=Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0114-0409-0000-0000000FF1CE}"=Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}"=Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0117-0409-0000-0000000FF1CE}"=Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{998C8C87-603F-D794-2FCA-CF08A9521801}"=Catalyst Control Center Core Implementation
"{9FC605B4-1CA2-0D34-79A0-EF40593DE0E8}"=CCC Help Russian
"{A416C213-4295-B1C4-20B1-2A44050120D9}"=Skins
"{AC76BA86-7AD7-1033-7B44-A70500000002}"=Adobe Reader 7.0.5
"{B15366B1-CF2A-EE2B-A20A-F33B8DD86239}"=CCC Help Polish
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1"=Spybot - Search & Destroy
"{B508B3F1-A24A-32C0-B310-85786919EF28}"=Microsoft .NET Framework 2.0 Service Pack 1
"{B72B9ADE-4BE9-089A-3283-85DB51BE513F}"=Catalyst Control Center Localization Portuguese
"{B75CFA68-E161-024D-0C75-AF08AC434041}"=Catalyst Control Center Localization Finnish
"{BD1009A1-7E9A-A000-755D-E72B3C6D7F04}"=ccc-utility
"{BF6E9F41-C807-95FC-B88A-DD9007F76645}"=Catalyst Control Center Localization Swedish
"{C373D22F-9F9E-1020-98AF-799A7D9370BF}"=CCC Help Norwegian
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B6}"=WinZip 11.2
"{D0EA021E-15B2-AA74-9D7B-2D95C15AFB12}"=Catalyst Control Center Localization Dutch
"{D16F348B-4A43-1613-9A05-853A1520F810}"=CCC Help Czech
"{D439EC86-B927-7B2D-4606-87AE95EB3B3B}"=ccc-core-preinstall
"{DBFA98B2-1D1D-488C-B80D-26057DA9A492}"=OPNET IT Guru Academic Edition 9.1
"{EA7C8C83-77E1-E1AC-FC80-35368FE8A6B1}"=CCC Help German
"{EAA354BE-46EC-DD29-8A1C-DDFF55221BE7}"=Catalyst Control Center Graphics Full Existing
"{EDA67211-80E7-631E-3FED-44B5788997B6}"=CCC Help Chinese Standard
"24C8EE9E-CACE-4C60-8B1F-E2317BC2B510"=Crystal Maze (For Remote Control) from Dell Media Experience (remove only)
"25142B7C-EBFD-4E7B-8623-9C4B02892CAD"=Super Granny from Dell Media Experience (remove only)
"44D95F24-6CF9-4298-9756-F3CE97B55786"=Final Drive Nitro from Dell Media Experience (remove only)
"9FD89F55-16CB-49B8-BA2B-3EE3E7A023DF"=Blasterball 2 Remix from Dell Media Experience (remove only)
"AC3Filter"=AC3Filter (remove only)
"Adobe Flash Player ActiveX"=Adobe Flash Player ActiveX
"All ATI Software"=ATI - Software Uninstall Utility
"ATI Display Driver"=ATI Display Driver
"CCA8EE82-572D-47B1-AF81-17EEFBC4012A"=Phoenix Assault from Dell Media Experience (remove only)
"CDex"=CDex extraction audio
"D5E78171-FE0D-4D1A-97B2-632684E68105"=Polar Golfer from Dell Media Experience (remove only)
"DC++"=DC++ 0.674
"Dev-C++"=Dev-C++ 5 beta 9 release (4.9.9.2)
"DVD Decrypter"=DVD Decrypter (Remove Only)
"ENTERPRISE"=Microsoft Office Enterprise 2007
"ffdshow_is1"=ffdshow [rev 1999] [2008-06-12]
"FileZilla Client"=FileZilla Client 3.0.10
"Fraunhofer MP3 Codec Pro 1.263"=Fraunhofer MP3 Codec Pro 1.263
"HijackThis"=HijackThis 2.0.2
"IDNMitigationAPIs"=Microsoft Internationalized Domain Names Mitigation APIs
"ie7"=Windows Internet Explorer 7
"InstallShield_{21DBBDD6-93A5-4326-9A04-C9A5C9148502}"=Norton PartitionMagic 8.0
"InstallShield_{7D73CC6B-33A8-4DE2-9539-2498A59C12C2}"=My Cinema
"Microsoft .NET Framework 3.5"=Microsoft .NET Framework 3.5
"MinGW_is1"=MinGW 3.1.0
"Mozilla Firefox (3.0.3)"=Mozilla Firefox (3.0.3)
"NLSDownlevelMapping"=Microsoft National Language Support Downlevel APIs
"PCI Audio Driver"=PCI Audio Driver
"RealPlayer 6.0"=RealPlayer
"Windows XP Service Pack"=Windows XP Service Pack 3
"WinRAR archiver"=WinRAR archiver
"Xilisoft DVD Ripper Ultimate 5"=Xilisoft DVD Ripper Ultimate
"XpsEPSC"=XML Paper Specification Shared Components Pack 1.0
"Xvid_is1"=Xvid 1.1.3 final uninstall

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 17.7.2008 19:12:08 | Computer Name = BALL | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x04f21468.

Error - 17.7.2008 19:12:25 | Computer Name = BALL | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x04f21468.

Error - 18.7.2008 12:16:29 | Computer Name = BALL | Source = Application Error | ID = 1000
Description = Faulting application divx player.exe, version 6.8.0.153, faulting
module dmfplaybackmodule1.dll, version 0.0.0.0, fault address 0x0004885b.

Error - 18.7.2008 12:17:04 | Computer Name = BALL | Source = Application Error | ID = 1000
Description = Faulting application divx player.exe, version 6.8.0.153, faulting
module dmfplaybackmodule1.dll, version 0.0.0.0, fault address 0x0004885b.

Error - 18.7.2008 12:19:41 | Computer Name = BALL | Source = Application Error | ID = 1000
Description = Faulting application divx player.exe, version 6.8.0.153, faulting
module dmfplaybackmodule1.dll, version 0.0.0.0, fault address 0x0004885b.

Error - 18.7.2008 12:21:11 | Computer Name = BALL | Source = Application Error | ID = 1000
Description = Faulting application divx player.exe, version 6.8.0.153, faulting
module dmfplaybackmodule1.dll, version 0.0.0.0, fault address 0x0004885b.

Error - 18.7.2008 15:37:54 | Computer Name = BALL | Source = Application Error | ID = 1000
Description = Faulting application divx player.exe, version 6.8.0.153, faulting
module dmfplaybackmodule1.dll, version 0.0.0.0, fault address 0x0004885b.

Error - 18.7.2008 15:42:39 | Computer Name = BALL | Source = Application Hang | ID = 1002
Description = Hanging application wordpad.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 18.7.2008 16:21:07 | Computer Name = BALL | Source = Application Hang | ID = 1002
Description = Hanging application DivX Player.exe, version 6.8.0.153, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 18.7.2008 16:28:38 | Computer Name = BALL | Source = Application Error | ID = 1000
Description = Faulting application divx player.exe, version 6.8.0.153, faulting
module dmfplaybackmodule1.dll, version 0.0.0.0, fault address 0x0004885b.

[ System Events ]
Error - 10.10.2008 4:52:46 | Computer Name = BALL | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom1, has a bad block.

Error - 10.10.2008 4:52:46 | Computer Name = BALL | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom1, has a bad block.

Error - 10.10.2008 4:52:47 | Computer Name = BALL | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom1, has a bad block.

Error - 10.10.2008 4:52:47 | Computer Name = BALL | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom1, has a bad block.

Error - 10.10.2008 4:52:48 | Computer Name = BALL | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom1, has a bad block.

Error - 10.10.2008 4:52:48 | Computer Name = BALL | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom1, has a bad block.

Error - 10.10.2008 4:53:33 | Computer Name = BALL | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom1, has a bad block.

Error - 10.10.2008 4:53:40 | Computer Name = BALL | Source = Cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom1.

Error - 10.10.2008 4:53:40 | Computer Name = BALL | Source = Cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom1.

Error - 10.10.2008 4:53:41 | Computer Name = BALL | Source = Cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom1.


< End of report >

and Kasperskys log:

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Friday, October 10, 2008
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, October 10, 2008 12:00:14
Records in database: 1303170
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan statistics:
Files scanned: 53946
Threat name: 4
Infected objects: 4
Suspicious objects: 0
Duration of the scan: 01:12:54


File name / Threat name / Threats count
F:\My Shared Folder\Hack\brutus-aet2.zip Infected: not-a-virus:PSWTool.Win32.Brutus 1
F:\My Shared Folder\Hack\dgt.exe Infected: not-a-virus:AdTool.Win32.WhenU.a 1
F:\My Shared Folder\Hack\legionv21.zip Infected: not-a-virus:NetTool.Win32.Legion.21 1
F:\My Shared Folder\Hack\NetCat.zip Infected: not-a-virus:RemoteAdmin.Win32.NetCat 1

The selected area was scanned.

Edited by tranqiller, 10 October 2008 - 09:30 AM.


#6 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:06:41 AM

Posted 10 October 2008 - 06:47 PM

Hello :thumbsup:

I don't see any problems there. Are you still having problems? Your first HJT log shows stuff but at this point it looks as if you have cleaned things up :)

You know what these apps do right?

F:\My Shared Folder\Hack\brutus-aet2.zip Infected: not-a-virus:PSWTool.Win32.Brutus
F:\My Shared Folder\Hack\dgt.exe Infected: not-a-virus:AdTool.Win32.WhenU.a
F:\My Shared Folder\Hack\legionv21.zip Infected: not-a-virus:NetTool.Win32.Legion.21
F:\My Shared Folder\Hack\NetCat.zip Infected: not-a-virus:RemoteAdmin.Win32.NetCat

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#7 tranqiller

tranqiller
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:08:41 AM

Posted 10 October 2008 - 07:16 PM

After reinstalling IE and cleaning files with NOD,I did a little tweaking,so i can gain control of Registry Editor and Automatic Updates settings.That solved,pretty much,all the problems .But,i hope this is not some sort of rootkit.Dont worry about the apps,they are under control :thumbsup: .Thx for your time,Billy.

Edited by tranqiller, 10 October 2008 - 07:46 PM.


#8 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:06:41 AM

Posted 10 October 2008 - 08:02 PM

Hello, tranqiller.

You're welcome :)

Congratulations! You now appear clean! :thumbsup:

Are things running okay? Do you have any more questions?

System Still Slow?
You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.
If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware


We Need to Clean Up Our Mess
  • Please download OTCleanIt from one of the following mirrors and save it to your desktop:
  • Double click the Posted Image icon.
  • Push the large "Cleanup" button.
  • Allow your system to reboot.
Reset System Restore
Windows' "System Restore" feature can cause malware files to be cached and retained by your system. Resetting System Restore will clean these files from your system, and will allow you to use System Restore without fear of reinfection.
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
Note: You should only do this once, not on a regular basis!
You will not be able to restore computer to any earlier than today!

Recommendations
Below are some recommendations to lower your chances of (re)infection.
  • Install and maintain an outbound firewall
  • Install Spyware Blaster and update it regularly
    If you wish, the commercial version provides automatic updating.
  • Install the MVPs hosts file, and update it regularly
    You can use the HostMan host file manager to do this automaticly if you wish.
    For more information on the hosts file, and what it can do for you, you can view the Tutorial on the Hosts file
  • Install an Anti-Spyware program, and update it regularly
    Malware Byte's Anti Malware is an excellent Anti-Spyware scanner. It's scan times are usually under ten minutes, and has excellent detection and removal rates.
    SUPERAntiSpyware is another good scanner with high detection and removal rates.
    Both programs are free for non commercial home use but provide a resident and do not nag if you purchase the paid versions.
  • Keep Windows (and your other Microsoft software) up to date!
    I cannot stress how important this is enough. Often holes are found in Internet Explorer or Windows itself that require patching. Sometimes these holes will allow an attacker unrestricted access to your computer.

    If you are using Windows XP or earlier
    Visit the Microsoft Update Website and follow the on screen instructions to setup Microsoft Update. Also follow the instructions to update your system. Please REBOOT and repeat this process until there are no more updates to install!!

    If you are using Windows Vista
    • Click the "Start Menu" (or Windows Orb)
    • Click "All Programs"
    • Click "Windows Update"
    • On the left, choose "Change Settings"
    • Ensure that the checkbox "Use Microsoft Update" at the bottom of the window is checked.
    • Press OK and accept the UAC prompt.
      Note: You shouldn't need to check this checkbox every single time you update, only the first time.
    • Click "Check for Updates" in the upper left corner.
    • Follow the instructions to install the latest updates.
    • Reboot and repeat the "Check for Updates" until there are no more critical updates to install
  • Keep your other software up to date as well
    Software does not need to be made by Microsoft to be insecure. You can use the Secunia Online Software occasionally to help you check for out of date software on your machine.
  • Stay up to date!
    The MOST IMPORTANT part of any security setup is keeping the software up to date. Malware writers release new variants every single day. If your software updates don't keep up, then the malware will always be one step ahead. Not a good thing :).
Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#9 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:06:41 AM

Posted 11 October 2008 - 05:47 PM

Since this issue appears resolved, this topic is closed. Everyone else, please begin a new one. Thanks!!

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users