Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Virtumonde.dll,Vertudmonde infection


  • This topic is locked This topic is locked
20 replies to this topic

#1 LordSnoop

LordSnoop

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:08:53 PM

Posted 26 April 2009 - 04:36 PM

Hi there I was wondering if someone could please help me with this problem with malware: Anyhelp would be great!

Bididepu.dll as a ie addon re enables itself after a disable.
Automative Updates disables itself soon after enabling.
Spybot - Search & Destory - Found Win32.Sdbot.aad, Virtumonde.dll, Virtumonde after fixing it and scanning with spybot all 3 return.
After running msconfig startup programs pinafadi and batuviko would renable themselves after a disable
I'm getting a Windows - No Disk message which reads: "Exception Processing Message c0000013 Parameters 75b6bf7c..." when certion programs start up like spybot and even when the dds started up.
I went to system restore to restore a couple of days before this malware infected my computer, but after choosing which date I wanted and hitting next nothing would happen.

DDS (Ver_09-03-16.01) - NTFSx86
Run by LordSnoop at 15:24:35.88 on 26/04/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.468 [GMT -6:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
FW: Norton Internet Worm Protection *disabled*

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\arservice.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\LordSnoop\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=Q106&bd=pavilion&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=Q106&bd=pavilion&pf=desktop
uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=Q106&bd=pavilion&pf=desktop
mDefault_Page_URL = hxxp://ca.yahoo.com
mSearch Page =
mStart Page = hxxp://ca.yahoo.com
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=Q106&bd=pavilion&pf=desktop
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = 212.19.6.237:80
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {3271596b-9649-4705-abd1-7493c99a9fdc} - c:\windows\system32\budidepu.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: {6e0900a8-d69f-4204-a789-03f215707c53} - c:\windows\system32\qoMeCvss.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: hpWebHelper Class: {aaae832a-5fff-4661-9c8f-369692d1dcb9} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\WebHelper.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: {e7aa6d61-658f-29ab-f324-f6fc3de88c5c}: {c5c88ed3-cf6f-423f-ba92-f85616d6aa7e} - c:\windows\system32\sazroq.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219B3E1547538286.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: Veoh Video Compass: {52836eb0-631a-47b1-94a6-61f9d9112dae} - c:\program files\veoh networks\veoh video compass\SearchRecsPlugin.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [29fd146a] rundll32.exe "c:\windows\system32\pinafadi.dll",b
mRun: [vapumoluji] Rundll32.exe "c:\windows\system32\batuviko.dll",s
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000
IE: {073fe43a-def1-4955-96e2-f0a401b5b111} - c:\program files\youtube clip extractor\ClipExtractor.exe
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partygaming\partypoker\RunApp.exe
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: trymedia.com
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/SCRABBLE/Images/stg_drm.ocx
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} - hxxp://zone.msn.com/bingame/chnz/default/mjolauncher.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game08.zylom.com/activex/zylomgamesplayer.cab
DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://zone.msn.com/bingame/popcaploader_v10.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: wvUlJyVL - wvUlJyVL.dll
AppInit_DLLs: avgrsstx.dll sazroq.dll,c:\windows\system32\kohisiva.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\qoMeCvss
LSA: Notification Packages = scecli c:\windows\system32\kohisiva.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\lordsn~1\applic~1\mozilla\firefox\profiles\obhzcql1.default\
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com/?o=101760&l=dis
FF - prefs.js: network.proxy.ftp - 128.31.1.13
FF - prefs.js: network.proxy.ftp_port - 3128
FF - prefs.js: network.proxy.gopher - 128.31.1.13
FF - prefs.js: network.proxy.gopher_port - 3128
FF - prefs.js: network.proxy.http - 128.31.1.13
FF - prefs.js: network.proxy.http_port - 3128
FF - prefs.js: network.proxy.socks - 128.31.1.13
FF - prefs.js: network.proxy.socks_port - 3128
FF - prefs.js: network.proxy.ssl - 128.31.1.13
FF - prefs.js: network.proxy.ssl_port - 3128
FF - prefs.js: network.proxy.type - 1
FF - component: c:\documents and settings\lordsnoop\application data\mozilla\firefox\profiles\obhzcql1.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npracplug.dll
FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-1-23 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-12-25 325128]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-12-25 27656]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-12-25 298264]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-4-9 55152]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-1-14 226656]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 953168]
S3 ZD1211U(WirelessLAN);Wireless IEEE 802.11g Wireless LAN Driver (USB)(WirelessLAN);c:\windows\system32\drivers\ZD1211U.sys [2007-5-25 210944]
S4 fsssvc;Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2009-2-6 533360]
S4 gupdate1c95d4a8527714c;Google Update Service (gupdate1c95d4a8527714c);c:\program files\google\update\GoogleUpdate.exe [2008-12-13 133104]
S4 QuickBooksDB17;QuickBooksDB17;c:\progra~1\intuit\quickb~1\qbdbmgrn.exe -hvquickbooksdb17 --> c:\progra~1\intuit\quickb~1\QBDBMgrN.exe -hvQuickBooksDB17 [?]

=============== Created Last 30 ================

2009-04-26 12:00 <DIR> --d----- c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-04-26 12:00 <DIR> --d----- c:\program files\SDHelper (Spybot - Search & Destroy)
2009-04-26 12:00 <DIR> --d----- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-04-26 12:00 <DIR> --d----- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-04-26 02:52 <DIR> --d----- c:\program files\Trend Micro
2009-04-26 01:10 <DIR> --d----- c:\program files\WWShow
2009-04-26 01:09 1,398,493 ---sh--- c:\windows\system32\idafanip.ini
2009-04-26 01:04 <DIR> --d----- c:\program files\Jcore
2009-04-26 01:03 <DIR> --d----- c:\docume~1\lordsn~1\applic~1\pidle
2009-04-26 01:03 182,911 a------- c:\windows\system32\prnet.tmp
2009-04-26 00:56 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Azureus
2009-04-26 00:56 <DIR> --d----- c:\docume~1\lordsn~1\applic~1\Azureus
2009-04-26 00:55 <DIR> --d----- c:\program files\Vuze
2009-04-26 00:20 <DIR> --d----- c:\program files\Enterbrain
2009-04-18 01:02 <DIR> --d----- c:\docume~1\lordsn~1\applic~1\.freeciv
2009-04-15 22:40 284,160 -------- c:\windows\system32\dllcache\pdh.dll
2009-04-15 22:40 401,408 -------- c:\windows\system32\dllcache\rpcss.dll
2009-04-15 22:40 473,600 -------- c:\windows\system32\dllcache\fastprox.dll
2009-04-15 22:40 110,592 -------- c:\windows\system32\dllcache\services.exe
2009-04-15 22:40 729,088 -------- c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 22:40 453,120 -------- c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 22:40 227,840 -------- c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 22:40 714,752 -------- c:\windows\system32\dllcache\ntdll.dll
2009-04-15 22:40 617,472 -------- c:\windows\system32\dllcache\advapi32.dll
2009-04-15 22:37 1,203,922 -------- c:\windows\system32\dllcache\sysmain.sdb
2009-04-15 22:37 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-04-15 22:36 215,552 -------- c:\windows\system32\dllcache\wordpad.exe
2009-04-10 16:24 2,297,552 a------- c:\windows\system32\d3dx9_26.dll
2009-04-10 16:19 <DIR> --d-h--- c:\windows\msdownld.tmp
2009-04-10 16:19 <DIR> --d----- c:\windows\Logs
2009-04-10 03:01 <DIR> --d----- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-04-09 20:26 268,648 a------- c:\windows\system32\mucltui.dll
2009-04-09 20:26 208,744 a------- c:\windows\system32\muweb.dll
2009-04-09 20:26 27,496 a------- c:\windows\system32\mucltui.dll.mui
2009-04-09 09:50 <DIR> --d----- c:\documents and settings\lordsnoop\Tracing
2009-04-09 09:48 55,152 a------- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-04-09 09:47 3,426,072 a------- c:\windows\system32\d3dx9_32.dll
2009-04-09 09:47 <DIR> --d----- c:\program files\Microsoft SQL Server Compact Edition
2009-04-09 09:45 <DIR> --d----- c:\program files\Microsoft
2009-04-09 09:45 <DIR> --d----- c:\program files\Windows Live SkyDrive
2009-04-09 09:36 <DIR> --d----- c:\program files\common files\Windows Live
2009-04-07 03:13 215,465 a------- c:\windows\system32\nvapps.nvb
2009-04-07 03:01 <DIR> --d----- c:\program files\SystemRequirementsLab
2009-04-04 20:16 <DIR> --d----- c:\program files\UrbanTerror
2009-04-02 10:50 1,693,696 a------- c:\windows\system32\ltclr13n.dll
2009-04-02 10:50 155,648 a------- c:\windows\system32\lftif13n.dll
2009-04-02 10:50 98,304 a------- c:\windows\system32\lffax13n.dll
2009-03-31 04:04 <DIR> --d----- c:\docume~1\lordsn~1\applic~1\BitTorrent
2009-03-31 04:04 <DIR> --d----- c:\program files\DNA
2009-03-31 04:04 <DIR> --d----- c:\program files\BitTorrent
2009-03-31 04:04 <DIR> --d----- c:\docume~1\lordsn~1\applic~1\DNA

==================== Find3M ====================

2009-04-26 01:08 79,872 a--sh--- c:\windows\system32\pinafadi.dll
2009-04-26 01:08 87,552 a--sh--- c:\windows\system32\hulifeki.dll
2009-04-24 18:49 15,688 a------- c:\windows\system32\lsdelete.exe
2009-04-24 18:47 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-03-27 08:14 453,152 a------- c:\windows\system32\NVUNINST.EXE
2009-03-21 08:06 989,696 -------- c:\windows\system32\dllcache\kernel32.dll
2009-03-19 11:33 56,280 a------- c:\docume~1\lordsn~1\applic~1\GDIPFONTCACHEV1.DAT
2009-03-16 14:18 517,448 a------- c:\windows\system32\XAudio2_4.dll
2009-03-16 14:18 235,352 a------- c:\windows\system32\xactengine3_4.dll
2009-03-16 14:18 69,448 a------- c:\windows\system32\XAPOFX1_3.dll
2009-03-16 14:18 22,360 a------- c:\windows\system32\X3DAudio1_6.dll
2009-03-09 15:27 4,178,264 a------- c:\windows\system32\D3DX9_41.dll
2009-03-09 15:27 1,846,632 a------- c:\windows\system32\D3DCompiler_41.dll
2009-03-09 15:27 453,456 a------- c:\windows\system32\d3dx10_41.dll
2009-03-08 20:42 410,984 a------- c:\windows\system32\deploytk.dll
2009-03-06 08:22 284,160 -------- c:\windows\system32\pdh.dll
2009-03-02 18:18 826,368 a------- c:\windows\system32\wininet.dll
2009-03-02 18:18 826,368 a------- c:\windows\system32\dllcache\wininet.dll
2009-02-27 22:54 636,072 a------- c:\windows\system32\dllcache\iexplore.exe
2009-02-20 04:20 70,656 a------- c:\windows\system32\dllcache\ie4uinit.exe
2009-02-20 04:20 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2009-02-19 23:14 161,792 a------- c:\windows\system32\dllcache\ieakui.dll
2009-02-09 06:10 729,088 -------- c:\windows\system32\lsasrv.dll
2009-02-09 06:10 401,408 a------- c:\windows\system32\rpcss.dll
2009-02-09 06:10 714,752 -------- c:\windows\system32\ntdll.dll
2009-02-09 06:10 617,472 -------- c:\windows\system32\advapi32.dll
2009-02-09 05:13 1,846,784 a------- c:\windows\system32\win32k.sys
2009-02-09 05:13 1,846,784 -------- c:\windows\system32\dllcache\win32k.sys
2009-02-07 19:02 2,066,048 a------- c:\windows\system32\ntkrnlpa.exe
2009-02-07 19:02 2,066,048 -------- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-06 19:03 307,576 a------- c:\windows\WLXPGSS.SCR
2009-02-06 18:52 49,504 a------- c:\windows\system32\sirenacm.dll
2009-02-06 05:11 110,592 -------- c:\windows\system32\services.exe
2009-02-06 05:08 2,189,056 a------- c:\windows\system32\ntoskrnl.exe
2009-02-06 05:08 2,189,056 -------- c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-06 05:06 2,145,280 -------- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-06 04:39 35,328 -------- c:\windows\system32\sc.exe
2009-02-06 04:39 35,328 -------- c:\windows\system32\dllcache\sc.exe
2009-02-06 04:32 2,023,936 -------- c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-03 13:59 56,832 a------- c:\windows\system32\secur32.dll
2009-02-03 13:59 56,832 -------- c:\windows\system32\dllcache\secur32.dll
2009-02-01 09:31 10,520 a------- c:\windows\system32\avgrsstx.dll
2007-07-30 12:17 774,144 a------- c:\program files\RngInterstitial.dll
2009-01-22 09:12 58,905 a--sh--- c:\windows\system32\ssvCeMoq.ini2
2008-09-20 09:43 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092020080921\index.dat

============= FINISH: 15:25:30.56 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:09:53 AM

Posted 28 April 2009 - 03:26 AM

Hello, my name is fenzodahl512 and welcome to Bleeping Computer.. Please do the following....



Please download The Comedian.exe to your desktop
  • Double click the program to run it. It will only take around several minutes to run.
  • It will do a series of tasks and tell you when each one is finished.
  • You will be prompted to press any key after each step
  • When it is done it will close and exit itself automatically.
  • You can delete The_Comedian.exe once it is finished



NEXT


Please download Malwarebytes' Anti-Malware from HERE or HERE

Note: If you already have Malwarebytes' Anti-Malware, just run and update it.. Then do a "Perform Full Scan"

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.




NEXT


Please download RSIT by random/random and save it to your Desktop.
  • Double click on RSIT.exe to run RSIT
  • Before you click "Continue", make sure you change the List files/folders created or modified in the last 3 months
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt and info.txt in your next reply.



NEXT


Please download GMER and unzip it to your Desktop. <<mirror>>
If you see "random" name, just leave it.. If you see "GMER", please rename GMER into GAMERS
  • Open the renamed program and click on the Rootkit tab.
  • Make sure all the boxes on the right of the screen are checked, EXCEPT for ‘Show All’.
  • Click on Scan.
  • When the scan has run click Copy and paste the results into a Notepad >> save it and attach in this thread.
IMPORTANT: Do NOT run any program while you are doing these scans as it may interfere with the output results



Post me these logs in your next reply.. Post each log in separate post..

1. Malwarebytes'
2. RSIT log.txt
3. RSIT info.txt
4. Attach GMER result..

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#3 LordSnoop

LordSnoop
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:08:53 PM

Posted 28 April 2009 - 07:33 PM

Malwarebytes' Anti-Malware 1.36
Database version: 2056
Windows 5.1.2600 Service Pack 3

28/04/2009 6:21:49 PM
mbam-log-2009-04-28 (18-21-49).txt

Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 298740
Time elapsed: 1 hour(s), 9 minute(s), 53 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 3
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 13

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\Temp\msb.dll (Worm.Autorun) -> Delete on reboot.

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autochk (Worm.Autorun) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autochk (Worm.Autorun) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autochk (Worm.Autorun) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\Temp\msb.dll (Worm.Autorun) -> Delete on reboot.
C:\Documents and Settings\LordSnoop\protect.dll (Worm.Autorun) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\autochk.dll (Worm.Autorun) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\protect.dll (Worm.Autorun) -> Quarantined and deleted successfully.
C:\Documents and Settings\LordSnoop\Start Menu\Programs\Startup\ChkDisk.dll (Worm.Autorun) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lmppcsetup.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UNS18Z0T\lsp[1].exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\ChkDisk.dll (Worm.Autorun) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dllcache\userinit.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\protect.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\LordSnoop\Start Menu\Programs\Startup\ChkDisk.lnk (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\win32hlp.cnf (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\nsrbgxod.bak (Trojan.Agent) -> Delete on reboot.

Edited by LordSnoop, 28 April 2009 - 07:35 PM.


#4 LordSnoop

LordSnoop
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:08:53 PM

Posted 28 April 2009 - 07:36 PM

Logfile of random's system information tool 1.06 (written by random/random)
Run by LordSnoop at 2009-04-28 18:25:36
Microsoft Windows XP Professional Service Pack 3
System drive C: has 133 GB (73%) free of 182 GB
Total RAM: 958 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:25:42 PM, on 28/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\LordSnoop\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\LordSnoop.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ca.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 212.19.6.237:80
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: Download with YouTube Clip Extractor - {073fe43a-def1-4955-96e2-f0a401b5b111} - C:\Program Files\YouTube Clip Extractor\ClipExtractor.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (file missing)
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1...toUploader5.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/SCRABBLE/Images/stg_drm.ocx
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game08.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{031AECE2-CFA9-4C9D-8192-79C896617DF3}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{1F0282A5-D3BD-4560-A8C8-7731EC98D8A2}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{3822AE64-4077-4FF4-A42D-4A2D58FCEE32}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{892900FC-9814-4488-99C0-81491C1EE93D}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{ACAA9C68-C07E-4B5B-816E-12B0A8E6A891}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0FAE5AC-025C-46F2-8229-0E953B1135CE}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{D1EB76A5-63EF-4F10-925C-D517E92E7EEE}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{E70E84A3-13C3-4458-BFB6-29EC6D0B3107}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CS1\Services\Tcpip\..\{031AECE2-CFA9-4C9D-8192-79C896617DF3}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CS2\Services\Tcpip\..\{031AECE2-CFA9-4C9D-8192-79C896617DF3}: NameServer = 218.93.202.110,218.93.202.111
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: avgrsstx.dll sazroq.dll
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 8092 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\Google Software Updater.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{9F05BCD9-6060-4C10-90CE-5237A0979E0B}.job
C:\WINDOWS\tasks\{F897AA24-BDC3-11D1-B85B-00C04FB93981}_L33T_Betty Fiddler.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2009-02-01 1968920]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-04-27 259696]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-03-27 13684736]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\29fd146a]
C:\WINDOWS\system32\bozuhanu.dll,b []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Watch]
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2009-04-24 516440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-02-01 1601304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
C:\Program Files\DNA\btdna.exe [2009-03-31 321344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPM2ace27f6]
c:\windows\system32\mubayito.dll,a []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-02-19 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ImgTask]
C:\DOCUME~1\LORDSN~1\LOCALS~1\Temp\Imgtask.exe [2008-06-11 7680]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
C:\Program Files\Logitech\QuickCam\Quickcam.exe [2008-12-20 2656528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-02-06 3885408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui]
C:\Program Files\Eset\nod32kui.exe /WAITSERVICE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2009-03-27 13684736]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2009-03-27 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\prnet]
C:\WINDOWS\system32\prnet.tmp []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2006-10-25 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmileboxTray]
C:\Documents and Settings\Betty Fiddler\Application Data\Smilebox\SmileboxTray.exe [2009-01-29 254600]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
c:\steam\steam.exe [2009-03-06 1410296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-08 136600]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-06-16 68856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Synchronization Manager]
C:\WINDOWS\system32\mobsync.exe [2008-04-13 143360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Twain]
C:\Documents and Settings\LordSnoop\Application Data\Twain\Twain.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vapumoluji]
C:\WINDOWS\system32\batuviko.dll,s []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WeatherEye]
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2009-03-09 37888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe -quiet []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2006-02-19 288472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~4\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
C:\PROGRA~1\COMMON~1\Intuit\QUICKB~1\QBUpdate\qbupdate.exe [2007-11-23 967960]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WirelessLAN USB Utility.lnk]
C:\PROGRA~1\WIRELE~1.11G\Wlan.exe [2004-06-09 417792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NOD32krn"=2
"iPod Service"=3
"usnjsvc"=3
"WMPNetworkSvc"=3
"SeaPort"=2
"QuickBooksDB17"=2
"QBFCService"=3
"QBCFMonitorService"=2
"npkcmsvc"=2
"MDM"=2
"LVPrcSrv"=2
"LightScribeService"=2
"JavaQuickStarterService"=2
"IDriverT"=3
"gusvc"=2
"gupdate1c95d4a8527714c"=2
"fsssvc"=3
"CCALib8"=2
"Lavasoft Ad-Aware Service"=2
"avg8wd"=2

C:\Documents and Settings\LordSnoop\Start Menu\Programs\Startup
ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="avgrsstx.dll sazroq.dll "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\WINDOWS\system32\qoMeCvss

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoFolderOptions"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoSetActiveDesktop"=
"NoActiveDesktopChanges"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Grisoft\AVG Free\avgamsvr.exe"="C:\Program Files\Grisoft\AVG Free\avgamsvr.exe:*:Disabled:avgamsvr.exe"
"C:\Program Files\Grisoft\AVG Free\avgcc.exe"="C:\Program Files\Grisoft\AVG Free\avgcc.exe:*:Disabled:avgcc.exe"
"C:\Program Files\Grisoft\AVG Free\avginet.exe"="C:\Program Files\Grisoft\AVG Free\avginet.exe:*:Disabled:avginet.exe"
"C:\Program Files\DISC\DISCover.exe"="C:\Program Files\DISC\DISCover.exe:*:Disabled:DISCover Drop & Play System"
"C:\Program Files\DISC\myFTP.exe"="C:\Program Files\DISC\myFTP.exe:*:Disabled:DISCover FTP"
"C:\Program Files\DISC\DiscStreamHub.exe"="C:\Program Files\DISC\DiscStreamHub.exe:*:Disabled:DISCover Stream Hub"
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe"="C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Disabled:Earthlink"
"C:\WINDOWS\Network Diagnostic\xpnetdiag.exe"="C:\WINDOWS\Network Diagnostic\xpnetdiag.exe:*:Disabled:@xpsp3res.dll,-20000"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe"="C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Disabled:Updates from HP"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Disabled:Windows Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Disabled:Yahoo! FT Server"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Disabled:Yahoo! Messenger"
"C:\Program Files\Steam\steam.exe"="C:\Program Files\Steam\steam.exe:*:Enabled:Steam"
"C:\Program Files\PPMate\ppmnet.exe"="C:\Program Files\PPMate\ppmnet.exe:*:Disabled:PPMate"
"C:\Documents and Settings\HP_Administrator\Application Data\SopCast\adv\SopAdver.exe"="C:\Documents and Settings\HP_Administrator\Application Data\SopCast\adv\SopAdver.exe:*:Disabled:SopCast Adver"
"C:\Program Files\SopCast\SopCast.exe"="C:\Program Files\SopCast\SopCast.exe:*:Disabled:SopCast Main Application"
"C:\Program Files\TVUPlayer\TVUPlayer.exe"="C:\Program Files\TVUPlayer\TVUPlayer.exe:*:Disabled:TVU Player Component"
"C:\My Games\JEOPARDY!\JEOPARDY!.exe"="C:\My Games\JEOPARDY!\JEOPARDY!.exe:*:Disabled:JEOPARDY!"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Documents and Settings\LordSnoop\Desktop\Action_Quake2_Standalone~\nocheat.exe"="C:\Documents and Settings\LordSnoop\Desktop\Action_Quake2_Standalone~\nocheat.exe:*:Enabled:nocheat"
"C:\Quake2\aq2.exe"="C:\Quake2\aq2.exe:*:Disabled:aq2"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Disabled:avgupd.exe"
"C:\Program Files\Bos Wars\boswars.exe"="C:\Program Files\Bos Wars\boswars.exe:*:Disabled:boswars"
"C:\Documents and Settings\LordSnoop\Desktop\Freeciv-2.1.9-gtk2\civclient.exe"="C:\Documents and Settings\LordSnoop\Desktop\Freeciv-2.1.9-gtk2\civclient.exe:*:Disabled:civclient"
"C:\Documents and Settings\LordSnoop\Desktop\Freeciv-2.1.9-gtk2\civserver.exe"="C:\Documents and Settings\LordSnoop\Desktop\Freeciv-2.1.9-gtk2\civserver.exe:*:Disabled:civserver"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Disabled:DNA"
"C:\Steam\steamapps\coanza@hotmail.com\source sdk base\hl2.exe"="C:\Steam\steamapps\coanza@hotmail.com\source sdk base\hl2.exe:*:Disabled:hl2"
"C:\Steam\steamapps\coanza@hotmail.com\counter-strike source\hl2.exe"="C:\Steam\steamapps\coanza@hotmail.com\counter-strike source\hl2.exe:*:Disabled:hl2"
"C:\Program Files\Steam\steamapps\coanza@hotmail.com\source sdk base\hl2.exe"="C:\Program Files\Steam\steamapps\coanza@hotmail.com\source sdk base\hl2.exe:*:Disabled:hl2"
"C:\Program Files\Steam\steamapps\coanza@hotmail.com\half-life 2\hl2.exe"="C:\Program Files\Steam\steamapps\coanza@hotmail.com\half-life 2\hl2.exe:*:Disabled:hl2"
"C:\Program Files\Steam\steamapps\coanza@hotmail.com\half-life 2 deathmatch\hl2.exe"="C:\Program Files\Steam\steamapps\coanza@hotmail.com\half-life 2 deathmatch\hl2.exe:*:Disabled:hl2"
"C:\Program Files\Steam\steamapps\coanza@hotmail.com\counter-strike source\hl2.exe"="C:\Program Files\Steam\steamapps\coanza@hotmail.com\counter-strike source\hl2.exe:*:Disabled:hl2"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Disabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Disabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Disabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Disabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Disabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Disabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Disabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Disabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Disabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Disabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Disabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Disabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Disabled:hpzwiz01.exe"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Disabled:Internet Explorer"
"C:\Program Files\UrbanTerror\ioUrbanTerror.exe"="C:\Program Files\UrbanTerror\ioUrbanTerror.exe:*:Disabled:ioUrbanTerror"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Disabled:LimeWire"
"C:\StubInstaller.exe"="C:\StubInstaller.exe:*:Disabled:LimeWire swarmed installer"
"C:\Program Files\mIRC\mirc.exe"="C:\Program Files\mIRC\mirc.exe:*:Disabled:mIRC"
"C:\Quake2\nocheat.exe"="C:\Quake2\nocheat.exe:*:Disabled:nocheat"
"C:\Documents and Settings\LordSnoop\Desktop\Emulator\Action_Quake2_Standalone~\nocheat.exe"="C:\Documents and Settings\LordSnoop\Desktop\Emulator\Action_Quake2_Standalone~\nocheat.exe:*:Disabled:nocheat"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Disabled:Pando Media Booster"
"C:\Program Files\PPMate\ppmate.exe"="C:\Program Files\PPMate\ppmate.exe:*:Disabled:PPMate"
"C:\Program Files\Intuit\QuickBooks 2008\QBDBMgrN.exe"="C:\Program Files\Intuit\QuickBooks 2008\QBDBMgrN.exe:*:Disabled:QuickBooks 2008 Data Manager"
"C:\WINDOWS\system32\services.exe"="C:\WINDOWS\system32\services.exe:*:Disabled:services"
"C:\Program Files\SopCast\adv\SopAdver.exe"="C:\Program Files\SopCast\adv\SopAdver.exe:*:Disabled:SopCast Adver"
"C:\Program Files\Battle of Survival\stratagus.exe"="C:\Program Files\Battle of Survival\stratagus.exe:*:Disabled:stratagus"
"C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"="C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Disabled:Veoh Web Player "
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Disabled:VLC media player"
"C:\Program Files\Warcraft III\Warcraft III.exe"="C:\Program Files\Warcraft III\Warcraft III.exe:*:Disabled:Warcraft III"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Disabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Disabled:Windows Live Messenger"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Disabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Disabled:Windows Live Sync"
"C:\Program Files\World of Warcraft\Launcher.exe"="C:\Program Files\World of Warcraft\Launcher.exe:*:Disabled:World of Warcraft"
"C:\Program Files\The All-Seeing Eye\eye.exe"="C:\Program Files\The All-Seeing Eye\eye.exe:*:Disabled:Yahoo! All-Seeing Eye"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Disabled:Explorer"
"C:\WINDOWS\system32\winlogon.exe"="C:\WINDOWS\system32\winlogon.exe:*:Enabled:winlogon"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe"="C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e68b79f6-288d-11de-9a8f-0017310e91a5}]
shell\AutoRun\command - J:\DigitalPhotoViewer.exe


======List of files/folders created in the last 3 months======

2009-04-28 18:25:36 ----D---- C:\rsit
2009-04-28 17:07:12 ----D---- C:\WINDOWS\ERDNT
2009-04-28 17:06:32 ----D---- C:\Program Files\ERUNT
2009-04-28 13:14:00 ----A---- C:\WINDOWS\ntbtlog.txt
2009-04-28 00:22:09 ----A---- C:\WINDOWS\iconeasl.ini
2009-04-28 00:22:09 ----A---- C:\WINDOWS\easyicon.ini
2009-04-28 00:22:07 ----D---- C:\Program Files\EasyApps XP
2009-04-27 15:41:11 ----A---- C:\WINDOWS\system32\loader49.exe
2009-04-27 00:31:36 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Malwarebytes
2009-04-27 00:31:26 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-04-27 00:31:25 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-04-26 12:00:15 ----D---- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2009-04-26 12:00:14 ----D---- C:\Program Files\SDHelper (Spybot - Search & Destroy)
2009-04-26 12:00:14 ----D---- C:\Program Files\Misc. Support Library (Spybot - Search & Destroy)
2009-04-26 12:00:13 ----D---- C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
2009-04-26 02:52:34 ----D---- C:\Program Files\Trend Micro
2009-04-26 00:56:26 ----D---- C:\Documents and Settings\All Users\Application Data\Azureus
2009-04-26 00:56:24 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Azureus
2009-04-26 00:46:46 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Sun
2009-04-26 00:20:02 ----D---- C:\Program Files\Enterbrain
2009-04-19 20:21:01 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Sonic
2009-04-19 20:20:54 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Leadertech
2009-04-18 01:02:31 ----D---- C:\Documents and Settings\LordSnoop\Application Data\.freeciv
2009-04-16 03:11:33 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2009-04-16 03:11:19 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2009-04-16 03:04:22 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2009-04-16 03:03:43 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2009-04-16 03:03:05 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-04-16 03:02:37 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2009-04-15 22:37:00 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2009-04-10 16:25:32 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2009-04-10 16:25:32 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2009-04-10 16:25:31 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2009-04-10 16:25:30 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2009-04-10 16:25:30 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2009-04-10 16:25:30 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2009-04-10 16:25:29 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2009-04-10 16:25:28 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2009-04-10 16:25:28 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2009-04-10 16:25:27 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2009-04-10 16:25:27 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2009-04-10 16:25:27 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2009-04-10 16:25:26 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2009-04-10 16:25:26 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2009-04-10 16:25:25 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2009-04-10 16:25:25 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2009-04-10 16:25:25 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2009-04-10 16:25:24 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2009-04-10 16:25:24 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2009-04-10 16:25:23 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2009-04-10 16:25:22 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2009-04-10 16:25:22 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2009-04-10 16:25:22 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2009-04-10 16:25:21 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2009-04-10 16:25:21 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2009-04-10 16:25:21 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2009-04-10 16:25:20 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2009-04-10 16:25:20 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2009-04-10 16:25:19 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2009-04-10 16:25:19 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2009-04-10 16:25:18 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2009-04-10 16:25:18 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2009-04-10 16:25:17 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2009-04-10 16:25:17 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2009-04-10 16:25:16 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2009-04-10 16:25:16 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2009-04-10 16:25:15 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2009-04-10 16:25:14 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2009-04-10 16:25:13 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2009-04-10 16:25:13 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2009-04-10 16:25:12 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2009-04-10 16:25:12 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2009-04-10 16:25:12 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2009-04-10 16:25:11 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2009-04-10 16:25:11 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2009-04-10 16:25:11 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2009-04-10 16:25:10 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2009-04-10 16:25:08 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2009-04-10 16:25:06 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2009-04-10 16:25:06 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2009-04-10 16:25:04 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2009-04-10 16:25:04 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2009-04-10 16:25:03 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2009-04-10 16:25:03 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2009-04-10 16:25:03 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2009-04-10 16:25:02 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2009-04-10 16:25:02 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2009-04-10 16:25:02 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2009-04-10 16:25:02 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2009-04-10 16:25:01 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2009-04-10 16:25:00 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2009-04-10 16:24:57 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2009-04-10 16:24:57 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2009-04-10 16:24:57 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2009-04-10 16:24:56 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2009-04-10 16:24:56 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2009-04-10 16:24:56 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2009-04-10 16:24:55 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2009-04-10 16:24:55 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2009-04-10 16:24:54 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2009-04-10 16:24:52 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2009-04-10 16:19:20 ----HD---- C:\WINDOWS\msdownld.tmp
2009-04-10 16:19:13 ----D---- C:\WINDOWS\Logs
2009-04-10 03:01:14 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2009-04-09 20:26:31 ----A---- C:\WINDOWS\system32\muweb.dll
2009-04-09 20:26:31 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2009-04-09 20:26:31 ----A---- C:\WINDOWS\system32\mucltui.dll
2009-04-09 09:48:22 ----D---- C:\Program Files\Microsoft Sync Framework
2009-04-09 09:47:41 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2009-04-09 09:47:30 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2009-04-09 09:47:09 ----HDC---- C:\WINDOWS\$NtUninstallKB954708$
2009-04-09 09:45:25 ----D---- C:\Program Files\Microsoft
2009-04-09 09:45:07 ----D---- C:\Program Files\Windows Live SkyDrive
2009-04-09 09:44:37 ----D---- C:\Program Files\Windows Live
2009-04-09 09:36:01 ----D---- C:\Program Files\Common Files\Windows Live
2009-04-07 03:01:46 ----D---- C:\Program Files\SystemRequirementsLab
2009-04-04 20:16:40 ----D---- C:\Program Files\UrbanTerror
2009-04-02 10:50:53 ----A---- C:\WINDOWS\system32\ltclr13n.dll
2009-04-02 10:50:53 ----A---- C:\WINDOWS\system32\lftif13n.dll
2009-04-02 10:50:53 ----A---- C:\WINDOWS\system32\lffax13n.dll
2009-03-31 04:04:08 ----D---- C:\Program Files\DNA
2009-03-31 04:04:08 ----D---- C:\Program Files\BitTorrent
2009-03-31 04:04:08 ----D---- C:\Documents and Settings\LordSnoop\Application Data\DNA
2009-03-27 19:08:49 ----D---- C:\Documents and Settings\LordSnoop\Application Data\HP
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcuda.dll
2009-03-25 12:01:26 ----D---- C:\tmp
2009-03-23 19:56:07 ----D---- C:\Program Files\Python26
2009-03-23 12:18:53 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Yahoo!
2009-03-22 20:14:56 ----D---- C:\Program Files\Veoh Networks
2009-03-22 12:09:59 ----D---- C:\Documents and Settings\LordSnoop\Application Data\HPQ
2009-03-21 16:25:45 ----D---- C:\Documents and Settings\LordSnoop\Application Data\ZoomBrowser EX
2009-03-21 16:25:20 ----D---- C:\Documents and Settings\LordSnoop\Application Data\CameraWindowDC
2009-03-21 16:25:19 ----D---- C:\Documents and Settings\LordSnoop\Application Data\CANON INC
2009-03-20 03:03:33 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2009-03-20 03:03:06 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2009-03-20 03:02:34 ----HDC---- C:\WINDOWS\$NtUninstallKB959772_WM11$
2009-03-20 03:02:19 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2009-03-20 03:01:57 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
2009-03-19 20:33:39 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-03-19 20:33:38 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2009-03-19 20:32:59 ----D---- C:\Program Files\Windows Media Connect 2
2009-03-19 20:32:46 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2009-03-19 20:31:14 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2009-03-19 20:30:07 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2009-03-19 20:28:52 ----HDC---- C:\WINDOWS\$NtUninstallKB925766$
2009-03-18 19:59:38 ----D---- C:\Program Files\Microsoft Silverlight
2009-03-18 17:30:32 ----D---- C:\Documents and Settings\LordSnoop\Application Data\AdobeUM
2009-03-18 13:10:37 ----D---- C:\Documents and Settings\LordSnoop\Application Data\vlc
2009-03-18 13:08:29 ----D---- C:\Program Files\VideoLAN
2009-03-16 14:16:42 ----D---- C:\Documents and Settings\LordSnoop\Application Data\LimeWire
2009-03-16 13:52:27 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Media Player Classic
2009-03-16 13:51:56 ----A---- C:\WINDOWS\system32\unrar.dll
2009-03-16 12:55:30 ----A---- C:\Documents and Settings\LordSnoop\Application Data\ClipExtractor-UpdatePerformed.txt
2009-03-16 12:55:22 ----D---- C:\Program Files\YouTube Clip Extractor
2009-03-15 16:23:14 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Mozilla
2009-03-15 16:22:13 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Macromedia
2009-03-15 16:22:02 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Adobe
2009-03-15 16:21:32 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Google
2009-03-15 16:19:29 ----D---- C:\Documents and Settings\LordSnoop\Application Data\AVGTOOLBAR
2009-03-15 16:19:19 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Subversion
2009-03-15 16:18:32 ----ASH---- C:\Documents and Settings\LordSnoop\Application Data\desktop.ini
2009-03-15 16:18:29 ----SD---- C:\Documents and Settings\LordSnoop\Application Data\Microsoft
2009-03-15 16:18:29 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Real
2009-03-15 16:18:29 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Intuit
2009-03-15 16:18:29 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Identities
2009-03-14 20:15:27 ----A---- C:\WINDOWS\system32\lvci11901262.dll
2009-03-14 20:12:48 ----D---- C:\Program Files\Logitech
2009-03-11 00:51:52 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-03-11 00:51:47 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2009-03-11 00:51:34 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2009-03-08 20:42:23 ----A---- C:\WINDOWS\system32\javaws.exe
2009-03-08 20:42:23 ----A---- C:\WINDOWS\system32\javaw.exe
2009-03-08 20:42:23 ----A---- C:\WINDOWS\system32\java.exe
2009-03-08 20:42:23 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-03-08 03:50:31 ----D---- C:\zv
2009-03-06 21:25:42 ----D---- C:\Steam
2009-02-25 22:49:04 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-02-11 01:16:44 ----HDC---- C:\WINDOWS\$NtUninstallKB960715$
2009-02-06 18:52:40 ----A---- C:\WINDOWS\system32\sirenacm.dll

======List of files/folders modified in the last 3 months======

2009-04-28 18:24:37 ----D---- C:\WINDOWS\Temp
2009-04-28 18:24:37 ----D---- C:\WINDOWS\system32
2009-04-28 18:24:04 ----D---- C:\WINDOWS\Registration
2009-04-28 18:23:49 ----AD---- C:\WINDOWS
2009-04-28 18:23:07 ----D---- C:\WINDOWS\system32\drivers
2009-04-28 18:22:24 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-04-28 18:21:49 ----RSHD---- C:\WINDOWS\system32\dllcache
2009-04-28 18:18:51 ----D---- C:\Program Files\Mozilla Firefox
2009-04-28 17:55:00 ----D---- C:\WINDOWS\Prefetch
2009-04-28 17:47:37 ----D---- C:\WINDOWS\system32\CatRoot2
2009-04-28 17:15:19 ----RASH---- C:\boot.ini
2009-04-28 17:15:19 ----A---- C:\WINDOWS\win.ini
2009-04-28 17:15:19 ----A---- C:\WINDOWS\system.ini
2009-04-28 17:06:32 ----D---- C:\Program Files
2009-04-28 16:53:55 ----SD---- C:\WINDOWS\Tasks
2009-04-28 02:05:42 ----HD---- C:\$AVG8.VAULT$
2009-04-27 23:59:39 ----D---- C:\Program Files\mIRC
2009-04-27 22:52:25 ----D---- C:\WINDOWS\system32\Lang
2009-04-27 22:11:27 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-04-27 21:13:19 ----SHD---- C:\WINDOWS\Installer
2009-04-27 19:35:17 ----SHD---- C:\WINDOWS\CSC
2009-04-27 19:35:14 ----D---- C:\WINDOWS\Minidump
2009-04-27 19:06:02 ----D---- C:\WINDOWS\system32\FxsTmp
2009-04-27 18:02:28 ----A---- C:\WINDOWS\ModemLog_Agere Systems PCI-SV92PP Soft Modem.txt
2009-04-27 07:57:02 ----A---- C:\WINDOWS\system32\userinit.exe
2009-04-27 07:42:12 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
2009-04-26 21:06:45 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-04-26 15:23:59 ----D---- C:\Program Files\Common Files
2009-04-26 13:46:28 ----D---- C:\Documents and Settings\All Users\Application Data\Google Updater
2009-04-26 12:07:06 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-26 03:34:21 ----D---- C:\WINDOWS\SoftwareDistribution
2009-04-26 02:01:05 ----HD---- C:\Config.Msi
2009-04-26 01:54:57 ----D---- C:\Program Files\Yahoo!
2009-04-26 01:08:01 ----HD---- C:\WINDOWS\inf
2009-04-26 01:07:57 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-04-25 13:39:32 ----D---- C:\Program Files\PokerStars
2009-04-24 18:49:29 ----A---- C:\WINDOWS\system32\lsdelete.exe
2009-04-21 07:30:54 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-04-18 21:01:56 ----D---- C:\WINDOWS\pss
2009-04-16 03:47:17 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-04-16 03:39:39 ----D---- C:\Program Files\Internet Explorer
2009-04-16 03:39:38 ----D---- C:\WINDOWS\system32\wbem
2009-04-16 03:39:38 ----D---- C:\WINDOWS\AppPatch
2009-04-16 03:11:24 ----A---- C:\WINDOWS\imsins.BAK
2009-04-16 03:10:44 ----D---- C:\WINDOWS\system32\en-US
2009-04-16 03:10:15 ----D---- C:\WINDOWS\ie7updates
2009-04-16 03:04:13 ----HD---- C:\WINDOWS\$hf_mig$
2009-04-13 03:35:06 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-04-10 16:25:34 ----D---- C:\WINDOWS\system32\DirectX
2009-04-10 16:25:00 ----RSD---- C:\WINDOWS\assembly
2009-04-10 16:24:49 ----D---- C:\WINDOWS\Microsoft.NET
2009-04-09 23:46:53 ----D---- C:\Program Files\Common Files\InstallShield
2009-04-09 09:48:23 ----D---- C:\WINDOWS\WinSxS
2009-04-09 09:45:50 ----D---- C:\Program Files\MSN Messenger
2009-04-09 09:44:47 ----SD---- C:\WINDOWS\Fonts
2009-04-07 03:21:15 ----D---- C:\WINDOWS\nview
2009-04-07 03:13:41 ----D---- C:\WINDOWS\Help
2009-04-07 03:11:56 ----D---- C:\NVIDIA
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nwiz.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvwss.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvwimg.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvwdmcpl.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvwddi.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvvitvs.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvudisp.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvsvc32.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvshell.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvmobls.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvmctray.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvmccss.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvmccsrs.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvmccs.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nview.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvgames.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvdspsch.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvdisps.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcplui.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcpl.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcolor.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcodins.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcod.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvappbar.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvapi.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\keystone.exe
2009-03-27 08:14:42 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2009-03-23 12:42:25 ----D---- C:\Quake2
2009-03-21 15:35:33 ----D---- C:\Program Files\Winamp
2009-03-21 08:06:58 ----N---- C:\WINDOWS\system32\kernel32.dll
2009-03-20 03:04:28 ----D---- C:\WINDOWS\system32\CatRoot
2009-03-19 21:10:36 ----D---- C:\Program Files\Windows Media Player
2009-03-19 20:30:13 ----D---- C:\WINDOWS\system32\LogFiles
2009-03-19 20:28:59 ----AD---- C:\WINDOWS\ehome
2009-03-16 13:52:08 ----D---- C:\Program Files\K-Lite Codec Pack
2009-03-15 22:02:02 ----A---- C:\WINDOWS\ODBC.INI
2009-03-15 16:22:14 ----D---- C:\Program Files\Google
2009-03-15 16:21:40 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2009-03-15 16:19:21 ----SHD---- C:\RECYCLER
2009-03-15 16:18:45 ----A---- C:\WINDOWS\OEWABLog.txt
2009-03-15 16:18:28 ----D---- C:\Documents and Settings
2009-03-14 20:16:21 ----D---- C:\Program Files\Common Files\logishrd
2009-03-14 20:12:53 ----D---- C:\Documents and Settings\All Users\Application Data\Logishrd
2009-03-10 12:13:36 ----D---- C:\Program Files\MSN
2009-03-08 20:42:48 ----D---- C:\Program Files\LimeWire
2009-03-08 20:41:59 ----D---- C:\Program Files\Java
2009-03-08 14:46:13 ----D---- C:\Program Files\SopCast
2009-03-06 08:22:18 ----N---- C:\WINDOWS\system32\pdh.dll
2009-03-02 18:18:25 ----A---- C:\WINDOWS\system32\wininet.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\webcheck.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\urlmon.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\url.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\pngfilt.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\occache.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\mstime.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\msrating.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\mshtmled.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\ieencode.dll
2009-02-20 12:09:37 ----A---- C:\WINDOWS\system32\mshtml.dll
2009-02-20 12:09:37 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2009-02-20 12:09:37 ----A---- C:\WINDOWS\system32\msfeeds.dll
2009-02-20 12:09:37 ----A---- C:\WINDOWS\system32\jsproxy.dll
2009-02-20 12:09:37 ----A---- C:\WINDOWS\system32\iertutil.dll
2009-02-20 12:09:37 ----A---- C:\WINDOWS\system32\iernonce.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\ieframe.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\ieaksie.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\ieakeng.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\icardie.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\extmgr.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\dxtrans.dll
2009-02-20 12:09:35 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2009-02-20 12:09:35 ----A---- C:\WINDOWS\system32\advpack.dll
2009-02-20 04:20:49 ----A---- C:\WINDOWS\system32\ieudinit.exe
2009-02-20 04:20:49 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2009-02-19 23:14:12 ----A---- C:\WINDOWS\system32\ieakui.dll
2009-02-09 06:10:49 ----N---- C:\WINDOWS\system32\lsasrv.dll
2009-02-09 06:10:48 ----N---- C:\WINDOWS\system32\ntdll.dll
2009-02-09 06:10:48 ----N---- C:\WINDOWS\system32\advapi32.dll
2009-02-09 06:10:48 ----A---- C:\WINDOWS\system32\rpcss.dll
2009-02-07 19:02:58 ----A---- C:\WINDOWS\system32\ntkrnlpa.exe
2009-02-06 12:35:56 ----A---- C:\WINDOWS\system32\LegitCheckControl.DLL
2009-02-06 05:11:05 ----N---- C:\WINDOWS\system32\services.exe
2009-02-06 05:08:19 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2009-02-06 04:39:08 ----N---- C:\WINDOWS\system32\sc.exe
2009-02-03 13:59:07 ----A---- C:\WINDOWS\system32\secur32.dll
2009-02-01 09:31:14 ----A---- C:\WINDOWS\system32\avgrsstx.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-02-01 325128]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-02-01 27656]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-09 12032]
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2004-08-09 63232]
R2 NwlnkSpx;NWLink SPX/SPXII Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2004-08-09 55936]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2005-10-20 1095009]
R3 aracpi;aracpi; C:\WINDOWS\system32\DRIVERS\aracpi.sys [2005-08-02 22784]
R3 arhidfltr;MS Ar HID Filter Driver; C:\WINDOWS\system32\DRIVERS\arhidfltr.sys [2005-08-02 19200]
R3 arkbcfltr;Microsoft PS2 Keyboard Filter; C:\WINDOWS\system32\DRIVERS\arkbcfltr.sys [2005-08-02 5376]
R3 armoucfltr;Microsoft PS2 Mouse Filter; C:\WINDOWS\system32\DRIVERS\armoucfltr.sys [2005-08-02 4992]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ARPolicy;ARPolicy; C:\WINDOWS\system32\DRIVERS\arpolicy.sys [2005-08-02 10112]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-01-23 4145152]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-03-27 6280416]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-07-29 34048]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-07-29 12928]
R3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2005-12-12 19072]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S2 npkcrypt;npkcrypt; \??\C:\Nexon\Mabinogi\npkcrypt.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 LVPr2Mon;LVPr2Mon Driver; C:\WINDOWS\system32\Drivers\LVPr2Mon.sys [2008-12-16 25624]
S3 LVRS;Logitech RightSound Filter Driver; C:\WINDOWS\system32\DRIVERS\lvrs.sys [2008-12-17 768024]
S3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\LVUSBSta.sys [2008-12-17 41752]
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-09 11008]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 pepifilter;Volume Adapter; C:\WINDOWS\system32\DRIVERS\lv302af.sys [2008-12-16 13848]
S3 PID_PEPI;Logitech QuickCam IM(PID_PEPI); C:\WINDOWS\system32\DRIVERS\LV302V32.SYS [2008-12-16 2686104]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 ZD1211U(WirelessLAN);Wireless IEEE 802.11g Wireless LAN Driver (USB)(WirelessLAN); C:\WINDOWS\system32\DRIVERS\zd1211u.sys [2004-04-24 210944]
S3 ZDPNDIS5;ZDPNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\ZDPNDIS5.SYS []
S4 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ARSVC;ARSVC; C:\WINDOWS\arservice.exe [2005-08-02 58880]
R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2005-10-11 237568]
R2 ehSched;Media Center Scheduler Service; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 102912]
R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-03-27 163908]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]
S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 267776]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S4 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-02-01 298264]
S4 CCALib8;Canon Camera Access Library 8; C:\Program Files\Canon\CAL\CALMAIN.exe [2007-01-31 96370]
S4 fsssvc;Windows Live Family Safety; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S4 gupdate1c95d4a8527714c;Google Update Service (gupdate1c95d4a8527714c); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-15 133104]
S4 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-28 183280]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-03-08 152984]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-04-24 953168]
S4 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2005-12-18 73728]
S4 LVPrcSrv;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2008-12-16 150040]
S4 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
S4 npkcmsvc;npkcmsvc; C:\Nexon\Mabinogi\npkcmsvc.exe [2007-08-02 80528]
S4 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\C:\WINDOWS\system32\HPZipm12.exe []
S4 QBCFMonitorService;QuickBooks Database Manager Service; C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [2007-11-23 20480]
S4 QBFCService;Intuit QuickBooks FCS; C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [2006-10-09 71184]
S4 QuickBooksDB17;QuickBooksDB17; C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe [2007-11-23 128280]
S4 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S4 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]

-----------------EOF-----------------

Attached Files

  • Attached File  gmer.log   1.68KB   15 downloads

Edited by LordSnoop, 28 April 2009 - 07:40 PM.


#5 LordSnoop

LordSnoop
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:08:53 PM

Posted 28 April 2009 - 07:42 PM

info.txt logfile of random's system information tool 1.06 2009-04-28 18:25:46

======Uninstall list======

-->C:\PROGRA~1\TELUSE~1\Uninstall.exe TELUS
-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
-->c:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
-->c:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
-->c:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
-->c:\WINDOWS\system32\\MSIEXEC.EXE /x {F80239D8-7811-4D5E-B033-0D0BBFE32920}
-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
-->MsiExec.exe /I{71EEA108-09C9-4D81-8FA2-D48C70681242}
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
7-Zip 4.57-->"C:\Program Files\7-Zip\Uninstall.exe"
Ad-Aware SE Personal-->C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
Ad-Aware-->"C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE
Ad-Aware-->C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->MsiExec.exe /X{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}
Adobe Reader 7.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
Agere Systems PCI-SV92PP Soft Modem-->agrsmdel
AVG Free 8.0-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Blender (remove only)-->"C:\Documents and Settings\LordSnoop\Desktop\Emulator\Blender\uninstall.exe"
Bos Wars-->C:\Documents and Settings\LordSnoop\Desktop\Emulator\BOS Wars\Uninstall.exe
Canon Camera Access Library-->"C:\Program Files\Common Files\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\CAL\Uninst.ini"
Canon Camera Support Core Library-->"C:\Program Files\Common Files\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\CSCLIB\Uninst.ini"
Canon G.726 WMP-Decoder-->"C:\Program Files\Common Files\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\G726Decoder\G726DecUnInstall.ini"
Canon MovieEdit Task for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\MVWUninst.ini"
Canon RAW Image Task for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\RAW Image Task\Uninst.ini"
Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDVC\Uninst.ini"
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDVC6\Uninst.ini"
Canon Utilities CameraWindow DC-->"C:\Program Files\Common Files\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDC\Uninst.ini"
Canon Utilities CameraWindow-->"C:\Program Files\Common Files\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowLauncher\Uninst.ini"
Canon Utilities EOS Utility-->"C:\Program Files\Common Files\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\EOS Utility\Uninst.ini"
Canon Utilities MyCamera DC-->"C:\Program Files\Common Files\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\MyCameraDC\Uninst.ini"
Canon Utilities MyCamera-->"C:\Program Files\Common Files\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\MyCamera\Uninst.ini"
Canon Utilities PhotoStitch-->"C:\Program Files\Common Files\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\PhotoStitch\Uninst.ini"
Canon Utilities RemoteCapture Task for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\RemoteCaptureTask DC\Uninst.ini"
Canon Utilities ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\Uninst.ini"
Canon ZoomBrowser EX Memory Card Utility-->"C:\Program Files\Common Files\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX MCU\Uninst.ini"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Continuum-->"C:\Program Files\Continuum\unins000.exe"
Counter-Strike: Source-->"C:\Steam\steam.exe" steam://uninstall/240
Critical Update for Windows Media Player 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
DISCover-->"C:\Program Files\DISC\uninstall.exe"
Easy Internet Sign-up-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{8105684D-8CA6-440D-8F58-7E5FD67A499D} /l1033
EasyIcons XP / IconEasel XP-->"C:\Program Files\EasyApps XP\Apps\Remove.exe" /U:"C:\Program Files\EasyApps XP\Apps\Remove.log"
ebgcInfra-->MsiExec.exe /X{39B1BD87-561E-4762-AED9-7C5213B06C24}
ebgcRes-->MsiExec.exe /X{41F8316B-D73A-44CE-98A3-A43CDED14857}
ebgcSDK-->MsiExec.exe /X{28E7B64D-150F-4A9E-B7A3-5A6AC8C2F822}
Enhanced Multimedia Keyboard Solution-->C:\HP\KBD\Install.exe /u
ERUNT 1.1j-->"C:\Program Files\ERUNT\unins000.exe"
Freeciv 2.1.9 (GTK+ client)-->"C:\Documents and Settings\LordSnoop\Desktop\Freeciv-2.1.9-gtk2\uninstall.exe"
Google Chrome-->"C:\Program Files\Google\Chrome\Application\1.0.154.59\Installer\setup.exe" --uninstall --system-level
Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_BDA1448D3D255554.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Google Updater-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Half-Life 2-->"C:\Steam\steam.exe" steam://uninstall/220
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 10 (KB910393)-->"C:\WINDOWS\$NtUninstallKB910393$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB954708)-->"C:\WINDOWS\$NtUninstallKB954708$\spuninst\spuninst.exe"
HP Boot Optimizer-->C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe /uninstall
HP Customer Participation Program 7.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Deskjet Printer Preload-->MsiExec.exe /I{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}
HP DigitalMedia Archive-->MsiExec.exe /X{F80239D8-7811-4D5E-B033-0D0BBFE32920}
HP Document Viewer 5.3-->C:\Program Files\HP\Digital Imaging\DocumentViewer\hpzscr01.exe -datfile hpqbud04.dat
HP DVD Play 1.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
HP Game Console and games-->C:\Program Files\WildTangent\Apps\hpuninstall.exe
HP Imaging Device Functions 7.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart 330,380,420,470,7800,8000,8200 Series-->C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\setup\hpzscr01.exe -d MsiRollbackUninstaller -datfile hphscr08.dat
HP Photosmart and Deskjet 7.0 Software-->C:\Program Files\HP\Digital Imaging\{D2A3C9D5-0B56-4656-8277-7EDC65D62B6E}\setup\hpzscr01.exe -datfile hphscr12.dat -showdisconnect -forcereboot
HP Photosmart Cameras 5.0-->C:\Program Files\HP\Digital Imaging\{C83A12B9-B31B-461A-BBD4-CE9B988094F1}\setup\hpzscr01.exe -datfile hpiscr01.dat
HP Photosmart Essential-->MsiExec.exe /X{6994491D-D491-48F1-AE1F-E179C1FFFC2F}
HP Photosmart for Media Center PC-->c:\Program Files\HP\Digital Imaging\bin\mcpc\setupmcl.exe /u
HP Photosmart Premier Software 6.0-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP PSC & OfficeJet 5.3.A-->"C:\Program Files\HP\Digital Imaging\{3E386744-10FA-44b2-98C9-DF7A270DECB3}\setup\hpzscr01.exe" -datfile hposcr06.dat
HP PSC & OfficeJet 5.3.B-->"C:\Program Files\HP\Digital Imaging\{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}\setup\hpzscr01.exe" -datfile hposcr07.dat
HP Rhapsody-->C:\PROGRA~1\HPRHAP~1\Unwise32.exe /A C:\PROGRA~1\HPRHAP~1\install.log
HP Solution Center 7.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Update-->MsiExec.exe /X{8C6027FD-53DC-446D-BB75-CACD7028A134}
HP Web Helper-->regsvr32 /u /s "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll"
IEEE 802.11g Wireless LAN - USB-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{581CE7EA-A30D-0000-1211-088635773309}\Setup.exe" -l0x9
InterActual Player-->C:\Program Files\InterActual\InterActual Player\inuninst.exe
J2SE Runtime Environment 5.0 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150050}
J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
J2SE Runtime Environment 5.0 Update 9-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150090}
Java™ 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
K-Lite Codec Pack 4.7.0 (Standard)-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
LimeWire 5.1.1-->"C:\Program Files\LimeWire\uninstall.exe"
Logitech QuickCam Driver Package-->"C:\Program Files\Common Files\LogiShrd\LogiDriverStore\lvdrivers\11.90.1262\LgDrvInst.exe" -remove -instdir"C:\Program Files\Common Files\LogiShrd\LogiDriverStore\lvdrivers\" -enumdelay=200 -enabledifx -forcedelete -usbhubsfirst -forceremove -cumulativeremove -promptuninstall -arpregkey"lvdrivers_11.90" /clone_wait /hide_progress
Logitech QuickCam-->MsiExec.exe /I{937B232D-9776-471E-92BD-D424E514EF14}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Interactive Training-->C:\Program Files\MSPress\Training\lunins32_s.exe
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft Money 2006-->"C:\Program Files\Microsoft Money 2006\MNYCoreFiles\Setup\uninst.exe" /s:120
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
Microsoft Office XP Media Content-->MsiExec.exe /I{90300409-6000-11D3-8CFE-0050048383C9}
Microsoft Office XP Standard for Students and Teachers-->MsiExec.exe /I{913D0409-6000-11D3-8CFE-0050048383C9}
Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Express Edition - ENU-->C:\Program Files\Microsoft Visual Studio 8\Microsoft Visual C++ 2005 Express Edition - ENU\setup.exe
Microsoft Visual C++ 2005 Express Edition - ENU-->MsiExec.exe /X{AB6F4AB9-AC85-4002-9829-B6EEA55AE3A5}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
MINERVA: Metastasis 2-->C:\PROGRA~1\Steam\STEAMA~1\SOURCE~1\METAST~1\UNWISE.EXE C:\PROGRA~1\Steam\STEAMA~1\SOURCE~1\METAST~1\metastasis.log
mIRC-->"C:\Program Files\mIRC\mirc.exe" -uninstall
Mozilla Firefox (3.0.7)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
muvee autoProducer 4.5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E073D315-3C54-44BF-A1B2-B5583AEA618C}\setup.exe" -l0x9
muvee autoProducer unPlugged 1.2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{35DD9A1D-B340-4F41-A8B0-6EEBFB119280}\setup.exe" -l0x9
NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
Pando Media Booster-->C:\Program Files\Pando Networks\Media Booster\uninst.exe
PC-Doctor 5 for Windows-->C:\Program Files\PC-Doctor 5 for Windows\uninst.exe
PokerStars-->"C:\Program Files\PokerStars\PokerStarsUninstall.exe" /u:PokerStars
PPMate Network TV 2.0.0.38-->C:\Program Files\PPMate\uninst.exe
Project64 1.6-->MsiExec.exe /X{9559F7CA-5E34-4237-A2D9-D856464AD727}
Python 2.2 pywin32 extensions (build 203)-->"C:\Python22\Removepywin32.exe" -u "C:\Python22\pywin32-wininst.log"
Python 2.2.3-->C:\Python22\UNWISE.EXE C:\Python22\INSTALL.LOG
Python 2.6.1-->MsiExec.exe /I{9CC89170-000B-457D-91F1-53691F85B223}
QuickBooks Premier: Retail Edition 2008-->msiexec.exe /I {71EEA108-09C9-4D81-8FA2-D48C70681242} UNIQUE_NAME="retail" QBFULLNAME="QuickBooks Premier: Retail Edition 2008" ADDREMOVE=1
Quicken 2006-->MsiExec.exe /X{2818095F-FB6C-42C8-827E-0A406CC9AFF5}
QuickTime-->MsiExec.exe /I{50D8FFDD-90CD-4859-841F-AA1961C7767A}
RealArcade-->C:\Program Files\Real\RealArcade\Update\rnuninst.exe RealNetworks|RealArcade|1.2
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
Remove IntelliMover Demo-->c:\hp\bin\cloaker.exe c:\hp\bin\commands.exe /c "C:\Program Files\IntelliMoverDemo\clean.bat"
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Microsoft .NET Framework 2.0 (KB928365)-->C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {8056AC9E-49C5-4375-9ADE-B2F862C9DF51} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
Security Update for Step By Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Security Update for Step By Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
Sonic Express Labeler-->MsiExec.exe /X{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Sonic MyDVD Plus-->MsiExec.exe /X{21657574-BD54-48A2-9450-EB03B2C7FC29}
Sonic RecordNow Audio-->MsiExec.exe /X{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
Sonic RecordNow Copy-->MsiExec.exe /X{B12665F4-4E93-4AB4-B7FC-37053B524629}
Sonic RecordNow Data-->MsiExec.exe /X{075473F5-846A-448B-BCB3-104AA1760205}
Sonic Update Manager-->MsiExec.exe /X{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
SopCast 1.1.1-->C:\Program Files\SopCast\uninst.exe
Source SDK Base-->"C:\Steam\steam.exe" steam://uninstall/215
Spybot - Search & Destroy 1.4-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins001.exe"
Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
SupportSoft Assisted Service-->MsiExec.exe /I{5A3F6A80-7913-475E-8B96-477A952CFA43}
TELUS eCare-->C:\WINDOWS\Motive\TELUS\MCCUninst.exe
TortoiseSVN 1.4.4.9706 (32 bit)-->MsiExec.exe /X{182A59A6-1AAB-44AC-9C37-59A2A88F2D70}
Update for Windows Media Player 10 (KB913800)-->"C:\WINDOWS\$NtUninstallKB913800$\spuninst\spuninst.exe"
Update for Windows Media Player 10 (KB926251)-->"C:\WINDOWS\$NtUninstallKB926251$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB953356)-->"C:\WINDOWS\$NtUninstallKB953356$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Updates from HP (remove only)-->C:\WINDOWS\HPCPCUninstall-9972322\HPBWSetup.exe -appid 9972322 -uninstall
Urban Terror 4.1-->"C:\Program Files\UrbanTerror\unins000.exe"
Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Live Call-->MsiExec.exe /I{F6BD194C-4190-4D73-B1B1-C48C99921BFE}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Essentials-->C:\Program Files\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{C6CA8874-5F22-4AF0-9BE3-016BF299C536}
Windows Live Family Safety-->MsiExec.exe /X{76CD2979-09C0-493A-84B3-8FD97EF4BCEA}
Windows Live Mail-->MsiExec.exe /I{63C1109E-D977-49ED-BCE3-D00D0BF187D6}
Windows Live Messenger-->MsiExec.exe /X{0AAA9C97-74D4-47CE-B089-0B147EF3553C}
Windows Live Photo Gallery-->MsiExec.exe /X{3C52E7DA-C431-4239-B66B-1BF703D5B194}
Windows Live Sign-in Assistant-->MsiExec.exe /I{45338B07-A236-4270-9A77-EBB4115517B5}
Windows Live Sync-->MsiExec.exe /X{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}
Windows Live Toolbar-->MsiExec.exe /X{995F1E2E-F542-4310-8E1D-9926F5A279B3}
Windows Live Upload Tool-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Windows Live Writer-->MsiExec.exe /X{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
Windows XP Media Center Edition 2005 KB925766-->"C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
YouTube Clip Extractor-->"C:\Program Files\YouTube Clip Extractor\unins000.exe"

======Security center information======

AV: AVG Anti-Virus Free
FW: Norton Internet Worm Protection (disabled)

======System event log======

Computer Name: STEVE2
Event Code: 10005
Message: DCOM got error "%1058" attempting to start the service usnjsvc with arguments ""
in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}

Record Number: 33435
Source Name: DCOM
Time Written: 20090409093615.000000-360
Event Type: error
User: STEVE2\LordSnoop

Computer Name: STEVE2
Event Code: 10005
Message: DCOM got error "%1058" attempting to start the service usnjsvc with arguments ""
in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}

Record Number: 33432
Source Name: DCOM
Time Written: 20090409093604.000000-360
Event Type: error
User: STEVE2\LordSnoop

Computer Name: STEVE2
Event Code: 10005
Message: DCOM got error "%1058" attempting to start the service usnjsvc with arguments ""
in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}

Record Number: 33431
Source Name: DCOM
Time Written: 20090409093554.000000-360
Event Type: error
User: STEVE2\LordSnoop

Computer Name: STEVE2
Event Code: 10005
Message: DCOM got error "%1058" attempting to start the service usnjsvc with arguments ""
in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}

Record Number: 33430
Source Name: DCOM
Time Written: 20090409093542.000000-360
Event Type: error
User: STEVE2\LordSnoop

Computer Name: STEVE2
Event Code: 36
Message: The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Record Number: 33429
Source Name: W32Time
Time Written: 20090409071229.000000-360
Event Type: warning
User:

=====Application event log=====

Computer Name: STEVE2
Event Code: 11
Message: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: The data is invalid.


Record Number: 12445
Source Name: crypt32
Time Written: 20090203150511.000000-420
Event Type: error
User:

Computer Name: STEVE2
Event Code: 11
Message: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: The data is invalid.


Record Number: 12442
Source Name: crypt32
Time Written: 20090203150510.000000-420
Event Type: error
User:

Computer Name: STEVE2
Event Code: 11
Message: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: The data is invalid.


Record Number: 12441
Source Name: crypt32
Time Written: 20090203150510.000000-420
Event Type: error
User:

Computer Name: STEVE2
Event Code: 11
Message: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: The data is invalid.


Record Number: 12438
Source Name: crypt32
Time Written: 20090203150509.000000-420
Event Type: error
User:

Computer Name: STEVE2
Event Code: 11
Message: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: The data is invalid.


Record Number: 12437
Source Name: crypt32
Time Written: 20090203150509.000000-420
Event Type: error
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;c:\Python22;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 47 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=2f02
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"SonicCentral"=c:\Program Files\Common Files\Sonic Shared\Sonic Central\
"CLASSPATH"=.;C:\Program Files\Java\jre1.5.0_09\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.5.0_09\lib\ext\QTJava.zip
"VS80COMNTOOLS"=C:\Program Files\Microsoft Visual Studio 8\Common7\Tools\

-----------------EOF-----------------

#6 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:09:53 AM

Posted 29 April 2009 - 01:31 AM

IMPORTANT!! Please disable these programs (if present) before proceed with our fixes.. . Please visit HERE if you don't know how.. Please re-enable them back after performing all steps given..

1. SpySweeper
2. Spyware Doctor
3. Windows Defender
4. Trojan Hunter
5. WinPatrol
6. Spybot S&D
7. Lavasoft Ad-Aware
8. Zone Alarm
9. AVG8



Please download the OTMoveIt3 by OldTimer
  • Save it to your Desktop.
  • Please double-click OTMoveIt3.exe to run it. (Vista users, please right click on OTMoveit3.exe and select "Run as an Administrator")
  • Let the Unregister Dll's and Ocx's remain ticked and Zip Files After Moves remain unticked..
  • Copy the codebox contents and paste it to the "Paste List of Files/Folders to Move" window (under the light Yellow bar)

    :processes
    explorer.exe
    
    :services
    
    :files
    C:\WINDOWS\system32\bozuhanu.dll
    c:\windows\system32\mubayito.dll
    C:\WINDOWS\system32\prnet.tmp
    C:\Documents and Settings\LordSnoop\Application Data\Twain
    C:\WINDOWS\system32\batuviko.dll
    C:\WINDOWS\system32\loader49.exe
    
    :reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\29fd146a]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPM2ace27f6]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\prnet]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Twain]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vapumoluji]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLS"="avgrsstx.dll"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
    "Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00
    
    :commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt3
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.



Run RSIT again... Post these logs in your next reply..

1. OTMoveIt3
2. RSIT log.txt

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#7 LordSnoop

LordSnoop
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:08:53 PM

Posted 29 April 2009 - 02:47 AM

Ok fenzodahl512 I'll try that right now.

#8 LordSnoop

LordSnoop
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:08:53 PM

Posted 29 April 2009 - 03:00 AM

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== FILES ==========
File/Folder C:\WINDOWS\system32\bozuhanu.dll not found.
File/Folder c:\windows\system32\mubayito.dll not found.
File/Folder C:\WINDOWS\system32\prnet.tmp not found.
File/Folder C:\Documents and Settings\LordSnoop\Application Data\Twain not found.
File/Folder C:\WINDOWS\system32\batuviko.dll not found.
C:\WINDOWS\system32\loader49.exe moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\29fd146a\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPM2ace27f6\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\prnet\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Twain\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vapumoluji\\ deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\"AppInit_DLLS"|"avgrsstx.dll" /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\"Authentication Packages"|hex(7):6d,73,76,31,5f,30,00,00 /E : value set successfully!
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\LORDSN~1\LOCALS~1\Temp\~DF51EB.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\LORDSN~1\LOCALS~1\Temp\~DF51F0.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[10].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[3].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[4].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[5].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[6].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[7].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[8].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[9].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\topic114351[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\msb.dll scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\nsrbgxod.bak scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 04292009_015116

Files moved on Reboot...
File C:\DOCUME~1\LORDSN~1\LOCALS~1\Temp\~DF51EB.tmp not found!
File C:\DOCUME~1\LORDSN~1\LOCALS~1\Temp\~DF51F0.tmp not found!
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[10].htm moved successfully.
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[3].htm moved successfully.
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[4].htm moved successfully.
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[5].htm moved successfully.
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[6].htm moved successfully.
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[7].htm moved successfully.
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[8].htm moved successfully.
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[9].htm moved successfully.
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\topic114351[1].htm moved successfully.
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\temp\msb.dll
C:\WINDOWS\temp\msb.dll NOT unregistered.
C:\WINDOWS\temp\msb.dll moved successfully.
C:\WINDOWS\temp\nsrbgxod.bak moved successfully.


Logfile of random's system information tool 1.06 (written by random/random)
Run by LordSnoop at 2009-04-29 01:58:07
Microsoft Windows XP Professional Service Pack 3
System drive C: has 134 GB (73%) free of 182 GB
Total RAM: 958 MB (50% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:58:11 AM, on 29/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\LordSnoop\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\LordSnoop.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ca.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 212.19.6.237:80
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [autochk] rundll32.exe C:\WINDOWS\system32\autochk.dll,_IWMPEvents@16
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [autochk] rundll32.exe C:\DOCUME~1\LOCALS~1\protect.dll,_IWMPEvents@16 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [autochk] rundll32.exe C:\DOCUME~1\LOCALS~1\protect.dll,_IWMPEvents@16 (User 'Default user')
O4 - S-1-5-18 Startup: ChkDisk.dll (User 'SYSTEM')
O4 - S-1-5-18 Startup: ChkDisk.lnk = ? (User 'SYSTEM')
O4 - S-1-5-18 Startup: ChkDisk.lnk.disabled (User 'SYSTEM')
O4 - .DEFAULT Startup: ChkDisk.dll (User 'Default user')
O4 - .DEFAULT Startup: ChkDisk.lnk = ? (User 'Default user')
O4 - .DEFAULT Startup: ChkDisk.lnk.disabled (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: ChkDisk.dll
O4 - Startup: ChkDisk.lnk = ?
O4 - Startup: ChkDisk.lnk.disabled
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: Download with YouTube Clip Extractor - {073fe43a-def1-4955-96e2-f0a401b5b111} - C:\Program Files\YouTube Clip Extractor\ClipExtractor.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (file missing)
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1...toUploader5.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/SCRABBLE/Images/stg_drm.ocx
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game08.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{031AECE2-CFA9-4C9D-8192-79C896617DF3}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{1F0282A5-D3BD-4560-A8C8-7731EC98D8A2}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{3822AE64-4077-4FF4-A42D-4A2D58FCEE32}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{892900FC-9814-4488-99C0-81491C1EE93D}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{ACAA9C68-C07E-4B5B-816E-12B0A8E6A891}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0FAE5AC-025C-46F2-8229-0E953B1135CE}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{D1EB76A5-63EF-4F10-925C-D517E92E7EEE}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{E70E84A3-13C3-4458-BFB6-29EC6D0B3107}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CS1\Services\Tcpip\..\{031AECE2-CFA9-4C9D-8192-79C896617DF3}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CS2\Services\Tcpip\..\{031AECE2-CFA9-4C9D-8192-79C896617DF3}: NameServer = 218.93.202.110,218.93.202.111
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 9015 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\Google Software Updater.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{9F05BCD9-6060-4C10-90CE-5237A0979E0B}.job
C:\WINDOWS\tasks\{F897AA24-BDC3-11D1-B85B-00C04FB93981}_L33T_Betty Fiddler.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2009-02-01 1968920]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-04-27 259696]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-03-27 13684736]
"autochk"=C:\WINDOWS\system32\autochk.dll [2009-04-29 24064]
"MSConfig"=C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe [2008-04-13 169984]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\autochk]
C:\WINDOWS\system32\autochk.dll [2009-04-29 24064]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-02-01 1601304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
C:\Program Files\DNA\btdna.exe [2009-03-31 321344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-02-19 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ImgTask]
C:\DOCUME~1\LORDSN~1\LOCALS~1\Temp\Imgtask.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
C:\Program Files\Logitech\QuickCam\Quickcam.exe [2008-12-20 2656528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-02-06 3885408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui]
C:\Program Files\Eset\nod32kui.exe /WAITSERVICE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2009-03-27 13684736]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2009-03-27 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2006-10-25 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmileboxTray]
C:\Documents and Settings\Betty Fiddler\Application Data\Smilebox\SmileboxTray.exe [2009-01-29 254600]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
c:\steam\steam.exe [2009-03-06 1410296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-08 136600]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-06-16 68856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Synchronization Manager]
C:\WINDOWS\system32\mobsync.exe [2008-04-13 143360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WeatherEye]
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2009-03-09 37888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe -quiet []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2006-02-19 288472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~4\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
C:\PROGRA~1\COMMON~1\Intuit\QUICKB~1\QBUpdate\qbupdate.exe [2007-11-23 967960]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WirelessLAN USB Utility.lnk]
C:\PROGRA~1\WIRELE~1.11G\Wlan.exe [2004-06-09 417792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^LordSnoop^Start Menu^Programs^Startup^ChkDisk.dll]
C:\Documents and Settings\LordSnoop\Start Menu\Programs\Startup\ChkDisk.dll [2009-04-28 24064]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^LordSnoop^Start Menu^Programs^Startup^ChkDisk.lnk]
C:\DOCUME~1\LORDSN~1\STARTM~1\Programs\Startup\ChkDisk.dll,_IWMPEvents@16 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^LordSnoop^Start Menu^Programs^Startup^ERUNT AutoBackup.lnk]
C:\PROGRA~1\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NOD32krn"=2
"iPod Service"=3
"usnjsvc"=3
"WMPNetworkSvc"=3
"SeaPort"=2
"QuickBooksDB17"=2
"QBFCService"=3
"QBCFMonitorService"=2
"npkcmsvc"=2
"MDM"=2
"LVPrcSrv"=2
"LightScribeService"=2
"JavaQuickStarterService"=2
"IDriverT"=3
"gusvc"=2
"gupdate1c95d4a8527714c"=2
"fsssvc"=3
"CCALib8"=2
"Lavasoft Ad-Aware Service"=2
"avg8wd"=2

C:\Documents and Settings\LordSnoop\Start Menu\Programs\Startup
ChkDisk.dll
ChkDisk.lnk - C:\WINDOWS\system32\rundll32.exe
ChkDisk.lnk.disabled - C:\WINDOWS\system32\rundll32.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="avgrsstx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoFolderOptions"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoSetActiveDesktop"=
"NoActiveDesktopChanges"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Grisoft\AVG Free\avgamsvr.exe"="C:\Program Files\Grisoft\AVG Free\avgamsvr.exe:*:Disabled:avgamsvr.exe"
"C:\Program Files\Grisoft\AVG Free\avgcc.exe"="C:\Program Files\Grisoft\AVG Free\avgcc.exe:*:Disabled:avgcc.exe"
"C:\Program Files\Grisoft\AVG Free\avginet.exe"="C:\Program Files\Grisoft\AVG Free\avginet.exe:*:Disabled:avginet.exe"
"C:\Program Files\DISC\DISCover.exe"="C:\Program Files\DISC\DISCover.exe:*:Disabled:DISCover Drop & Play System"
"C:\Program Files\DISC\myFTP.exe"="C:\Program Files\DISC\myFTP.exe:*:Disabled:DISCover FTP"
"C:\Program Files\DISC\DiscStreamHub.exe"="C:\Program Files\DISC\DiscStreamHub.exe:*:Disabled:DISCover Stream Hub"
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe"="C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Disabled:Earthlink"
"C:\WINDOWS\Network Diagnostic\xpnetdiag.exe"="C:\WINDOWS\Network Diagnostic\xpnetdiag.exe:*:Disabled:@xpsp3res.dll,-20000"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe"="C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Disabled:Updates from HP"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Disabled:Windows Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Disabled:Yahoo! FT Server"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Disabled:Yahoo! Messenger"
"C:\Program Files\Steam\steam.exe"="C:\Program Files\Steam\steam.exe:*:Enabled:Steam"
"C:\Program Files\PPMate\ppmnet.exe"="C:\Program Files\PPMate\ppmnet.exe:*:Disabled:PPMate"
"C:\Documents and Settings\HP_Administrator\Application Data\SopCast\adv\SopAdver.exe"="C:\Documents and Settings\HP_Administrator\Application Data\SopCast\adv\SopAdver.exe:*:Disabled:SopCast Adver"
"C:\Program Files\SopCast\SopCast.exe"="C:\Program Files\SopCast\SopCast.exe:*:Disabled:SopCast Main Application"
"C:\Program Files\TVUPlayer\TVUPlayer.exe"="C:\Program Files\TVUPlayer\TVUPlayer.exe:*:Disabled:TVU Player Component"
"C:\My Games\JEOPARDY!\JEOPARDY!.exe"="C:\My Games\JEOPARDY!\JEOPARDY!.exe:*:Disabled:JEOPARDY!"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Documents and Settings\LordSnoop\Desktop\Action_Quake2_Standalone~\nocheat.exe"="C:\Documents and Settings\LordSnoop\Desktop\Action_Quake2_Standalone~\nocheat.exe:*:Enabled:nocheat"
"C:\Quake2\aq2.exe"="C:\Quake2\aq2.exe:*:Disabled:aq2"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Disabled:avgupd.exe"
"C:\Program Files\Bos Wars\boswars.exe"="C:\Program Files\Bos Wars\boswars.exe:*:Disabled:boswars"
"C:\Documents and Settings\LordSnoop\Desktop\Freeciv-2.1.9-gtk2\civclient.exe"="C:\Documents and Settings\LordSnoop\Desktop\Freeciv-2.1.9-gtk2\civclient.exe:*:Disabled:civclient"
"C:\Documents and Settings\LordSnoop\Desktop\Freeciv-2.1.9-gtk2\civserver.exe"="C:\Documents and Settings\LordSnoop\Desktop\Freeciv-2.1.9-gtk2\civserver.exe:*:Disabled:civserver"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Disabled:DNA"
"C:\Steam\steamapps\coanza@hotmail.com\source sdk base\hl2.exe"="C:\Steam\steamapps\coanza@hotmail.com\source sdk base\hl2.exe:*:Disabled:hl2"
"C:\Steam\steamapps\coanza@hotmail.com\counter-strike source\hl2.exe"="C:\Steam\steamapps\coanza@hotmail.com\counter-strike source\hl2.exe:*:Disabled:hl2"
"C:\Program Files\Steam\steamapps\coanza@hotmail.com\source sdk base\hl2.exe"="C:\Program Files\Steam\steamapps\coanza@hotmail.com\source sdk base\hl2.exe:*:Disabled:hl2"
"C:\Program Files\Steam\steamapps\coanza@hotmail.com\half-life 2\hl2.exe"="C:\Program Files\Steam\steamapps\coanza@hotmail.com\half-life 2\hl2.exe:*:Disabled:hl2"
"C:\Program Files\Steam\steamapps\coanza@hotmail.com\half-life 2 deathmatch\hl2.exe"="C:\Program Files\Steam\steamapps\coanza@hotmail.com\half-life 2 deathmatch\hl2.exe:*:Disabled:hl2"
"C:\Program Files\Steam\steamapps\coanza@hotmail.com\counter-strike source\hl2.exe"="C:\Program Files\Steam\steamapps\coanza@hotmail.com\counter-strike source\hl2.exe:*:Disabled:hl2"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Disabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Disabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Disabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Disabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Disabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Disabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Disabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Disabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Disabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Disabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Disabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Disabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Disabled:hpzwiz01.exe"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Disabled:Internet Explorer"
"C:\Program Files\UrbanTerror\ioUrbanTerror.exe"="C:\Program Files\UrbanTerror\ioUrbanTerror.exe:*:Disabled:ioUrbanTerror"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Disabled:LimeWire"
"C:\StubInstaller.exe"="C:\StubInstaller.exe:*:Disabled:LimeWire swarmed installer"
"C:\Program Files\mIRC\mirc.exe"="C:\Program Files\mIRC\mirc.exe:*:Disabled:mIRC"
"C:\Quake2\nocheat.exe"="C:\Quake2\nocheat.exe:*:Disabled:nocheat"
"C:\Documents and Settings\LordSnoop\Desktop\Emulator\Action_Quake2_Standalone~\nocheat.exe"="C:\Documents and Settings\LordSnoop\Desktop\Emulator\Action_Quake2_Standalone~\nocheat.exe:*:Disabled:nocheat"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Disabled:Pando Media Booster"
"C:\Program Files\PPMate\ppmate.exe"="C:\Program Files\PPMate\ppmate.exe:*:Disabled:PPMate"
"C:\Program Files\Intuit\QuickBooks 2008\QBDBMgrN.exe"="C:\Program Files\Intuit\QuickBooks 2008\QBDBMgrN.exe:*:Disabled:QuickBooks 2008 Data Manager"
"C:\WINDOWS\system32\services.exe"="C:\WINDOWS\system32\services.exe:*:Disabled:services"
"C:\Program Files\SopCast\adv\SopAdver.exe"="C:\Program Files\SopCast\adv\SopAdver.exe:*:Disabled:SopCast Adver"
"C:\Program Files\Battle of Survival\stratagus.exe"="C:\Program Files\Battle of Survival\stratagus.exe:*:Disabled:stratagus"
"C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"="C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Disabled:Veoh Web Player "
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Disabled:VLC media player"
"C:\Program Files\Warcraft III\Warcraft III.exe"="C:\Program Files\Warcraft III\Warcraft III.exe:*:Disabled:Warcraft III"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Disabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Disabled:Windows Live Messenger"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Disabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Disabled:Windows Live Sync"
"C:\Program Files\World of Warcraft\Launcher.exe"="C:\Program Files\World of Warcraft\Launcher.exe:*:Disabled:World of Warcraft"
"C:\Program Files\The All-Seeing Eye\eye.exe"="C:\Program Files\The All-Seeing Eye\eye.exe:*:Disabled:Yahoo! All-Seeing Eye"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Disabled:Explorer"
"C:\WINDOWS\system32\winlogon.exe"="C:\WINDOWS\system32\winlogon.exe:*:Enabled:winlogon"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe"="C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e68b79f6-288d-11de-9a8f-0017310e91a5}]
shell\AutoRun\command - J:\DigitalPhotoViewer.exe


======List of files/folders created in the last 3 months======

2009-04-29 01:51:16 ----D---- C:\_OTMoveIt
2009-04-28 22:42:30 ----ASH---- C:\WINDOWS\system32\autochk.dll
2009-04-28 22:42:28 ----A---- C:\WINDOWS\system32\lmppcsetup.exe
2009-04-28 18:25:36 ----D---- C:\rsit
2009-04-28 17:07:12 ----D---- C:\WINDOWS\ERDNT
2009-04-28 17:06:32 ----D---- C:\Program Files\ERUNT
2009-04-28 13:14:00 ----A---- C:\WINDOWS\ntbtlog.txt
2009-04-28 00:22:09 ----A---- C:\WINDOWS\iconeasl.ini
2009-04-28 00:22:09 ----A---- C:\WINDOWS\easyicon.ini
2009-04-28 00:22:07 ----D---- C:\Program Files\EasyApps XP
2009-04-27 00:31:36 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Malwarebytes
2009-04-27 00:31:26 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-04-27 00:31:25 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-04-26 12:00:15 ----D---- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2009-04-26 12:00:14 ----D---- C:\Program Files\SDHelper (Spybot - Search & Destroy)
2009-04-26 12:00:14 ----D---- C:\Program Files\Misc. Support Library (Spybot - Search & Destroy)
2009-04-26 12:00:13 ----D---- C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
2009-04-26 02:52:34 ----D---- C:\Program Files\Trend Micro
2009-04-26 00:56:26 ----D---- C:\Documents and Settings\All Users\Application Data\Azureus
2009-04-26 00:56:24 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Azureus
2009-04-26 00:46:46 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Sun
2009-04-26 00:20:02 ----D---- C:\Program Files\Enterbrain
2009-04-19 20:21:01 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Sonic
2009-04-19 20:20:54 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Leadertech
2009-04-18 01:02:31 ----D---- C:\Documents and Settings\LordSnoop\Application Data\.freeciv
2009-04-16 03:11:33 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2009-04-16 03:11:19 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2009-04-16 03:04:22 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2009-04-16 03:03:43 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2009-04-16 03:03:05 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-04-16 03:02:37 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2009-04-15 22:37:00 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2009-04-10 16:25:32 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2009-04-10 16:25:32 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2009-04-10 16:25:31 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2009-04-10 16:25:30 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2009-04-10 16:25:30 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2009-04-10 16:25:30 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2009-04-10 16:25:29 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2009-04-10 16:25:28 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2009-04-10 16:25:28 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2009-04-10 16:25:27 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2009-04-10 16:25:27 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2009-04-10 16:25:27 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2009-04-10 16:25:26 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2009-04-10 16:25:26 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2009-04-10 16:25:25 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2009-04-10 16:25:25 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2009-04-10 16:25:25 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2009-04-10 16:25:24 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2009-04-10 16:25:24 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2009-04-10 16:25:23 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2009-04-10 16:25:22 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2009-04-10 16:25:22 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2009-04-10 16:25:22 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2009-04-10 16:25:21 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2009-04-10 16:25:21 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2009-04-10 16:25:21 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2009-04-10 16:25:20 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2009-04-10 16:25:20 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2009-04-10 16:25:19 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2009-04-10 16:25:19 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2009-04-10 16:25:18 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2009-04-10 16:25:18 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2009-04-10 16:25:17 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2009-04-10 16:25:17 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2009-04-10 16:25:16 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2009-04-10 16:25:16 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2009-04-10 16:25:15 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2009-04-10 16:25:14 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2009-04-10 16:25:13 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2009-04-10 16:25:13 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2009-04-10 16:25:12 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2009-04-10 16:25:12 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2009-04-10 16:25:12 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2009-04-10 16:25:11 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2009-04-10 16:25:11 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2009-04-10 16:25:11 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2009-04-10 16:25:10 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2009-04-10 16:25:08 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2009-04-10 16:25:06 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2009-04-10 16:25:06 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2009-04-10 16:25:04 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2009-04-10 16:25:04 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2009-04-10 16:25:03 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2009-04-10 16:25:03 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2009-04-10 16:25:03 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2009-04-10 16:25:02 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2009-04-10 16:25:02 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2009-04-10 16:25:02 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2009-04-10 16:25:02 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2009-04-10 16:25:01 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2009-04-10 16:25:00 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2009-04-10 16:24:57 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2009-04-10 16:24:57 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2009-04-10 16:24:57 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2009-04-10 16:24:56 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2009-04-10 16:24:56 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2009-04-10 16:24:56 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2009-04-10 16:24:55 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2009-04-10 16:24:55 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2009-04-10 16:24:54 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2009-04-10 16:24:52 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2009-04-10 16:19:20 ----HD---- C:\WINDOWS\msdownld.tmp
2009-04-10 16:19:13 ----D---- C:\WINDOWS\Logs
2009-04-10 03:01:14 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2009-04-09 20:26:31 ----A---- C:\WINDOWS\system32\muweb.dll
2009-04-09 20:26:31 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2009-04-09 20:26:31 ----A---- C:\WINDOWS\system32\mucltui.dll
2009-04-09 09:48:22 ----D---- C:\Program Files\Microsoft Sync Framework
2009-04-09 09:47:41 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2009-04-09 09:47:30 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2009-04-09 09:47:09 ----HDC---- C:\WINDOWS\$NtUninstallKB954708$
2009-04-09 09:45:25 ----D---- C:\Program Files\Microsoft
2009-04-09 09:45:07 ----D---- C:\Program Files\Windows Live SkyDrive
2009-04-09 09:44:37 ----D---- C:\Program Files\Windows Live
2009-04-09 09:36:01 ----D---- C:\Program Files\Common Files\Windows Live
2009-04-07 03:01:46 ----D---- C:\Program Files\SystemRequirementsLab
2009-04-04 20:16:40 ----D---- C:\Program Files\UrbanTerror
2009-04-02 10:50:53 ----A---- C:\WINDOWS\system32\ltclr13n.dll
2009-04-02 10:50:53 ----A---- C:\WINDOWS\system32\lftif13n.dll
2009-04-02 10:50:53 ----A---- C:\WINDOWS\system32\lffax13n.dll
2009-03-31 04:04:08 ----D---- C:\Program Files\DNA
2009-03-31 04:04:08 ----D---- C:\Program Files\BitTorrent
2009-03-31 04:04:08 ----D---- C:\Documents and Settings\LordSnoop\Application Data\DNA
2009-03-27 19:08:49 ----D---- C:\Documents and Settings\LordSnoop\Application Data\HP
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcuda.dll
2009-03-25 12:01:26 ----D---- C:\tmp
2009-03-23 19:56:07 ----D---- C:\Program Files\Python26
2009-03-23 12:18:53 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Yahoo!
2009-03-22 20:14:56 ----D---- C:\Program Files\Veoh Networks
2009-03-22 12:09:59 ----D---- C:\Documents and Settings\LordSnoop\Application Data\HPQ
2009-03-21 16:25:45 ----D---- C:\Documents and Settings\LordSnoop\Application Data\ZoomBrowser EX
2009-03-21 16:25:20 ----D---- C:\Documents and Settings\LordSnoop\Application Data\CameraWindowDC
2009-03-21 16:25:19 ----D---- C:\Documents and Settings\LordSnoop\Application Data\CANON INC
2009-03-20 03:03:33 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2009-03-20 03:03:06 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2009-03-20 03:02:34 ----HDC---- C:\WINDOWS\$NtUninstallKB959772_WM11$
2009-03-20 03:02:19 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2009-03-20 03:01:57 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
2009-03-19 20:33:39 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-03-19 20:33:38 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2009-03-19 20:32:59 ----D---- C:\Program Files\Windows Media Connect 2
2009-03-19 20:32:46 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2009-03-19 20:31:14 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2009-03-19 20:30:07 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2009-03-19 20:28:52 ----HDC---- C:\WINDOWS\$NtUninstallKB925766$
2009-03-18 19:59:38 ----D---- C:\Program Files\Microsoft Silverlight
2009-03-18 17:30:32 ----D---- C:\Documents and Settings\LordSnoop\Application Data\AdobeUM
2009-03-18 13:10:37 ----D---- C:\Documents and Settings\LordSnoop\Application Data\vlc
2009-03-18 13:08:29 ----D---- C:\Program Files\VideoLAN
2009-03-16 14:16:42 ----D---- C:\Documents and Settings\LordSnoop\Application Data\LimeWire
2009-03-16 13:52:27 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Media Player Classic
2009-03-16 13:51:56 ----A---- C:\WINDOWS\system32\unrar.dll
2009-03-16 12:55:30 ----A---- C:\Documents and Settings\LordSnoop\Application Data\ClipExtractor-UpdatePerformed.txt
2009-03-16 12:55:22 ----D---- C:\Program Files\YouTube Clip Extractor
2009-03-15 16:23:14 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Mozilla
2009-03-15 16:22:13 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Macromedia
2009-03-15 16:22:02 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Adobe
2009-03-15 16:21:32 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Google
2009-03-15 16:19:29 ----D---- C:\Documents and Settings\LordSnoop\Application Data\AVGTOOLBAR
2009-03-15 16:19:19 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Subversion
2009-03-15 16:18:32 ----ASH---- C:\Documents and Settings\LordSnoop\Application Data\desktop.ini
2009-03-15 16:18:29 ----SD---- C:\Documents and Settings\LordSnoop\Application Data\Microsoft
2009-03-15 16:18:29 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Real
2009-03-15 16:18:29 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Intuit
2009-03-15 16:18:29 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Identities
2009-03-14 20:15:27 ----A---- C:\WINDOWS\system32\lvci11901262.dll
2009-03-14 20:12:48 ----D---- C:\Program Files\Logitech
2009-03-11 00:51:52 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-03-11 00:51:47 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2009-03-11 00:51:34 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2009-03-08 20:42:23 ----A---- C:\WINDOWS\system32\javaws.exe
2009-03-08 20:42:23 ----A---- C:\WINDOWS\system32\javaw.exe
2009-03-08 20:42:23 ----A---- C:\WINDOWS\system32\java.exe
2009-03-08 20:42:23 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-03-08 03:50:31 ----D---- C:\zv
2009-03-06 21:25:42 ----D---- C:\Steam
2009-02-25 22:49:04 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-02-11 01:16:44 ----HDC---- C:\WINDOWS\$NtUninstallKB960715$
2009-02-06 18:52:40 ----A---- C:\WINDOWS\system32\sirenacm.dll

======List of files/folders modified in the last 3 months======

2009-04-29 01:55:40 ----RASH---- C:\boot.ini
2009-04-29 01:55:40 ----A---- C:\WINDOWS\win.ini
2009-04-29 01:55:40 ----A---- C:\WINDOWS\system.ini
2009-04-29 01:54:54 ----D---- C:\WINDOWS\Temp
2009-04-29 01:54:54 ----D---- C:\WINDOWS\system32
2009-04-29 01:54:11 ----D---- C:\WINDOWS\Registration
2009-04-29 01:54:04 ----AD---- C:\WINDOWS
2009-04-29 01:52:46 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-04-28 23:52:33 ----D---- C:\WINDOWS\system32\CatRoot2
2009-04-28 22:28:20 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-28 22:27:24 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-04-28 22:27:02 ----D---- C:\WINDOWS\system32\drivers
2009-04-28 22:27:02 ----D---- C:\Program Files
2009-04-28 22:12:00 ----D---- C:\WINDOWS\Prefetch
2009-04-28 22:01:24 ----D---- C:\WINDOWS\pss
2009-04-28 21:36:46 ----D---- C:\WINDOWS\system32\Lang
2009-04-28 19:43:23 ----HD---- C:\WINDOWS\inf
2009-04-28 19:42:18 ----HD---- C:\WINDOWS\$hf_mig$
2009-04-28 18:21:49 ----RSHD---- C:\WINDOWS\system32\dllcache
2009-04-28 18:18:51 ----D---- C:\Program Files\Mozilla Firefox
2009-04-28 16:53:55 ----SD---- C:\WINDOWS\Tasks
2009-04-28 02:05:42 ----HD---- C:\$AVG8.VAULT$
2009-04-27 23:59:39 ----D---- C:\Program Files\mIRC
2009-04-27 21:13:19 ----SHD---- C:\WINDOWS\Installer
2009-04-27 19:35:17 ----SHD---- C:\WINDOWS\CSC
2009-04-27 19:35:14 ----D---- C:\WINDOWS\Minidump
2009-04-27 19:06:02 ----D---- C:\WINDOWS\system32\FxsTmp
2009-04-27 18:02:28 ----A---- C:\WINDOWS\ModemLog_Agere Systems PCI-SV92PP Soft Modem.txt
2009-04-27 07:57:02 ----A---- C:\WINDOWS\system32\userinit.exe
2009-04-27 07:42:12 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
2009-04-26 21:06:45 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-04-26 15:23:59 ----D---- C:\Program Files\Common Files
2009-04-26 13:46:28 ----D---- C:\Documents and Settings\All Users\Application Data\Google Updater
2009-04-26 03:34:21 ----D---- C:\WINDOWS\SoftwareDistribution
2009-04-26 02:01:05 ----HD---- C:\Config.Msi
2009-04-26 01:54:57 ----D---- C:\Program Files\Yahoo!
2009-04-26 01:07:57 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-04-25 13:39:32 ----D---- C:\Program Files\PokerStars
2009-04-24 18:49:29 ----A---- C:\WINDOWS\system32\lsdelete.exe
2009-04-21 07:30:54 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-04-16 03:47:17 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-04-16 03:39:39 ----D---- C:\Program Files\Internet Explorer
2009-04-16 03:39:38 ----D---- C:\WINDOWS\system32\wbem
2009-04-16 03:39:38 ----D---- C:\WINDOWS\AppPatch
2009-04-16 03:11:24 ----A---- C:\WINDOWS\imsins.BAK
2009-04-16 03:10:44 ----D---- C:\WINDOWS\system32\en-US
2009-04-16 03:10:15 ----D---- C:\WINDOWS\ie7updates
2009-04-13 03:35:06 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-04-10 16:25:34 ----D---- C:\WINDOWS\system32\DirectX
2009-04-10 16:25:00 ----RSD---- C:\WINDOWS\assembly
2009-04-10 16:24:49 ----D---- C:\WINDOWS\Microsoft.NET
2009-04-09 23:46:53 ----D---- C:\Program Files\Common Files\InstallShield
2009-04-09 09:48:23 ----D---- C:\WINDOWS\WinSxS
2009-04-09 09:45:50 ----D---- C:\Program Files\MSN Messenger
2009-04-09 09:44:47 ----SD---- C:\WINDOWS\Fonts
2009-04-07 03:21:15 ----D---- C:\WINDOWS\nview
2009-04-07 03:13:41 ----D---- C:\WINDOWS\Help
2009-04-07 03:11:56 ----D---- C:\NVIDIA
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nwiz.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvwss.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvwimg.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvwdmcpl.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvwddi.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvvitvs.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvudisp.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvsvc32.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvshell.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvmobls.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvmctray.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvmccss.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvmccsrs.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvmccs.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nview.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvgames.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvdspsch.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvdisps.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcplui.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcpl.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcolor.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcodins.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcod.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvappbar.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvapi.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\keystone.exe
2009-03-27 08:14:42 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2009-03-23 12:42:25 ----D---- C:\Quake2
2009-03-21 15:35:33 ----D---- C:\Program Files\Winamp
2009-03-21 08:06:58 ----N---- C:\WINDOWS\system32\kernel32.dll
2009-03-20 03:04:28 ----D---- C:\WINDOWS\system32\CatRoot
2009-03-19 21:10:36 ----D---- C:\Program Files\Windows Media Player
2009-03-19 20:30:13 ----D---- C:\WINDOWS\system32\LogFiles
2009-03-19 20:28:59 ----AD---- C:\WINDOWS\ehome
2009-03-16 13:52:08 ----D---- C:\Program Files\K-Lite Codec Pack
2009-03-15 22:02:02 ----A---- C:\WINDOWS\ODBC.INI
2009-03-15 16:22:14 ----D---- C:\Program Files\Google
2009-03-15 16:21:40 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2009-03-15 16:19:21 ----SHD---- C:\RECYCLER
2009-03-15 16:18:45 ----A---- C:\WINDOWS\OEWABLog.txt
2009-03-15 16:18:28 ----D---- C:\Documents and Settings
2009-03-14 20:16:21 ----D---- C:\Program Files\Common Files\logishrd
2009-03-14 20:12:53 ----D---- C:\Documents and Settings\All Users\Application Data\Logishrd
2009-03-10 12:13:36 ----D---- C:\Program Files\MSN
2009-03-08 20:42:48 ----D---- C:\Program Files\LimeWire
2009-03-08 20:41:59 ----D---- C:\Program Files\Java
2009-03-08 14:46:13 ----D---- C:\Program Files\SopCast
2009-03-06 08:22:18 ----N---- C:\WINDOWS\system32\pdh.dll
2009-03-02 18:18:25 ----A---- C:\WINDOWS\system32\wininet.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\webcheck.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\urlmon.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\url.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\pngfilt.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\occache.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\mstime.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\msrating.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\mshtmled.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\ieencode.dll
2009-02-20 12:09:37 ----A---- C:\WINDOWS\system32\mshtml.dll
2009-02-20 12:09:37 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2009-02-20 12:09:37 ----A---- C:\WINDOWS\system32\msfeeds.dll
2009-02-20 12:09:37 ----A---- C:\WINDOWS\system32\jsproxy.dll
2009-02-20 12:09:37 ----A---- C:\WINDOWS\system32\iertutil.dll
2009-02-20 12:09:37 ----A---- C:\WINDOWS\system32\iernonce.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\ieframe.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\ieaksie.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\ieakeng.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\icardie.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\extmgr.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\dxtrans.dll
2009-02-20 12:09:35 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2009-02-20 12:09:35 ----A---- C:\WINDOWS\system32\advpack.dll
2009-02-20 04:20:49 ----A---- C:\WINDOWS\system32\ieudinit.exe
2009-02-20 04:20:49 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2009-02-19 23:14:12 ----A---- C:\WINDOWS\system32\ieakui.dll
2009-02-09 06:10:49 ----N---- C:\WINDOWS\system32\lsasrv.dll
2009-02-09 06:10:48 ----N---- C:\WINDOWS\system32\ntdll.dll
2009-02-09 06:10:48 ----N---- C:\WINDOWS\system32\advapi32.dll
2009-02-09 06:10:48 ----A---- C:\WINDOWS\system32\rpcss.dll
2009-02-07 19:02:58 ----A---- C:\WINDOWS\system32\ntkrnlpa.exe
2009-02-06 12:35:56 ----A---- C:\WINDOWS\system32\LegitCheckControl.DLL
2009-02-06 05:11:05 ----N---- C:\WINDOWS\system32\services.exe
2009-02-06 05:08:19 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2009-02-06 04:39:08 ----N---- C:\WINDOWS\system32\sc.exe
2009-02-03 13:59:07 ----A---- C:\WINDOWS\system32\secur32.dll
2009-02-01 09:31:14 ----A---- C:\WINDOWS\system32\avgrsstx.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-02-01 325128]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-02-01 27656]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-09 12032]
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2004-08-09 63232]
R2 NwlnkSpx;NWLink SPX/SPXII Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2004-08-09 55936]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2005-10-20 1095009]
R3 aracpi;aracpi; C:\WINDOWS\system32\DRIVERS\aracpi.sys [2005-08-02 22784]
R3 arhidfltr;MS Ar HID Filter Driver; C:\WINDOWS\system32\DRIVERS\arhidfltr.sys [2005-08-02 19200]
R3 arkbcfltr;Microsoft PS2 Keyboard Filter; C:\WINDOWS\system32\DRIVERS\arkbcfltr.sys [2005-08-02 5376]
R3 armoucfltr;Microsoft PS2 Mouse Filter; C:\WINDOWS\system32\DRIVERS\armoucfltr.sys [2005-08-02 4992]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ARPolicy;ARPolicy; C:\WINDOWS\system32\DRIVERS\arpolicy.sys [2005-08-02 10112]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-01-23 4145152]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-03-27 6280416]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-07-29 34048]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-07-29 12928]
R3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2005-12-12 19072]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S2 npkcrypt;npkcrypt; \??\C:\Nexon\Mabinogi\npkcrypt.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 LVPr2Mon;LVPr2Mon Driver; C:\WINDOWS\system32\Drivers\LVPr2Mon.sys [2008-12-16 25624]
S3 LVRS;Logitech RightSound Filter Driver; C:\WINDOWS\system32\DRIVERS\lvrs.sys [2008-12-17 768024]
S3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\LVUSBSta.sys [2008-12-17 41752]
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-09 11008]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 pepifilter;Volume Adapter; C:\WINDOWS\system32\DRIVERS\lv302af.sys [2008-12-16 13848]
S3 PID_PEPI;Logitech QuickCam IM(PID_PEPI); C:\WINDOWS\system32\DRIVERS\LV302V32.SYS [2008-12-16 2686104]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 ZD1211U(WirelessLAN);Wireless IEEE 802.11g Wireless LAN Driver (USB)(WirelessLAN); C:\WINDOWS\system32\DRIVERS\zd1211u.sys [2004-04-24 210944]
S3 ZDPNDIS5;ZDPNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\ZDPNDIS5.SYS []
S4 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ARSVC;ARSVC; C:\WINDOWS\arservice.exe [2005-08-02 58880]
R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2005-10-11 237568]
R2 ehSched;Media Center Scheduler Service; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 102912]
R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-03-27 163908]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]
S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 267776]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S4 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-02-01 298264]
S4 CCALib8;Canon Camera Access Library 8; C:\Program Files\Canon\CAL\CALMAIN.exe [2007-01-31 96370]
S4 fsssvc;Windows Live Family Safety; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S4 gupdate1c95d4a8527714c;Google Update Service (gupdate1c95d4a8527714c); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-15 133104]
S4 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-28 183280]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-03-08 152984]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-04-24 953168]
S4 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2005-12-18 73728]
S4 LVPrcSrv;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2008-12-16 150040]
S4 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
S4 npkcmsvc;npkcmsvc; C:\Nexon\Mabinogi\npkcmsvc.exe [2007-08-02 80528]
S4 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\C:\WINDOWS\system32\HPZipm12.exe []
S4 QBCFMonitorService;QuickBooks Database Manager Service; C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [2007-11-23 20480]
S4 QBFCService;Intuit QuickBooks FCS; C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [2006-10-09 71184]
S4 QuickBooksDB17;QuickBooksDB17; C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe [2007-11-23 128280]
S4 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S4 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]

-----------------EOF-----------------

#9 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:09:53 AM

Posted 29 April 2009 - 03:08 AM

Please make sure you disable ALL of your Antivirus/Antispyware/Firewall before running ComboFix.. Please visit HERE if you don't know how.. Please re-enable them back after performing all steps given..

Please download ComboFix by sUBs from one of the locations below, and save it to your Desktop.Link 1
Link 2
Link 3
Double click combofix.exe and follow the prompts. Please, never rename Combofix unless instructed.

If ComboFix asked you to install Recovery Console, please do so.. It will be your best interest..

When finished, it shall produce a log for you. Post that log and a fresh HijackThis log in your next reply..

Note: DON'T do anything with your computer while ComboFix is running.. Let ComboFix finishes its job..

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#10 LordSnoop

LordSnoop
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:08:53 PM

Posted 29 April 2009 - 03:45 AM

I uncheck the Resident Shield box but avg still runs a process and the security center says I have a antivirus scanner on. Killing the process with the task manager doesn't work.

I'll keep on looking for a way to turn off this process, any ideas? I'll check that link you gave me earlier about turning off antivirus to see if anyone else has had that problem.

Edited by LordSnoop, 29 April 2009 - 03:48 AM.


#11 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:09:53 AM

Posted 29 April 2009 - 03:50 AM

That's the reason I never use AVG.. sigh.. Reboot into Safe Mode and run ComboFix from there..

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#12 LordSnoop

LordSnoop
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:08:53 PM

Posted 29 April 2009 - 04:01 AM

Even in safe mode it says AVG Free is active, yet I see no process for it.

Edit: This time in normal mode though there is no avgsrx.exe process perhaps I'll run combofix and see if it warns me about avg?
Edit2: But the Security Center still says that my antivirus is reporting thats its On.

Edited by LordSnoop, 29 April 2009 - 04:04 AM.


#13 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:09:53 AM

Posted 29 April 2009 - 04:07 AM

Just run ComboFix and post the log here..

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#14 LordSnoop

LordSnoop
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:08:53 PM

Posted 29 April 2009 - 04:39 AM

ComboFix 09-04-28.02 - LordSnoop 29/04/2009 3:18.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.568 [GMT -6:00]
Running from: c:\documents and settings\LordSnoop\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
FW: Norton Internet Worm Protection *disabled*
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\LocalService\protect.dll
c:\documents and settings\LordSnoop\Local Settings\Temporary Internet Files\bestwiner.stt
c:\documents and settings\LordSnoop\Local Settings\Temporary Internet Files\CPV.stt
c:\documents and settings\LordSnoop\Local Settings\Temporary Internet Files\fbk.sts
c:\documents and settings\LordSnoop\protect.dll
c:\documents and settings\LordSnoop\Start Menu\Programs\Startup\ChkDisk.dll
c:\documents and settings\LordSnoop\Start Menu\Programs\Startup\ChkDisk.lnk
C:\test.txt
c:\windows\IE4 Error Log.txt
c:\windows\system32\autochk.dll
c:\windows\system32\config\systemprofile\protect.dll
c:\windows\system32\drivers\ovfsthdwqbutiqdsthorajnfvoqxweexnqqhtp.sys
c:\windows\system32\nvnbdidd.ini
c:\windows\system32\ovfsthdhvtksiewfleawswowdbmyjrraeojqlp.dat
c:\windows\system32\ovfsthhffmcedmfbvvxvesibxkpfhmjolvamiu.dll
c:\windows\system32\ovfsthvmdltakdlbxnirnqgiylpvpadkdjpebe.dll
c:\windows\system32\ovfsthxdggttsngagtrfjtienpmpemqdifvxyp.dat
c:\windows\system32\ovfsthxnrcnvdtxyiqrncwxstcivligstyemxt.dll
c:\windows\system32\ssvCeMoq.ini
c:\windows\system32\ssvCeMoq.ini2
c:\windows\system32\uniq.tll
c:\windows\system32\win32hlp.cnf
D:\Autorun.inf

Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\userinit.exe


.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_ovfsthcvfvijglksmccdxrrxvbrmeixjuctfni


((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-29 )))))))))))))))))))))))))))))))
.

2009-04-29 08:55 . 2009-04-29 08:56 664 ----a-w c:\windows\system32\d3d9caps.dat
2009-04-29 07:51 . 2009-04-29 07:51 -------- d-----w C:\_OTMoveIt
2009-04-29 00:25 . 2009-04-29 00:25 -------- d-----w C:\rsit
2009-04-28 23:06 . 2009-04-28 23:06 -------- d-----w c:\program files\ERUNT
2009-04-28 06:22 . 2009-04-28 06:22 -------- d-----w c:\program files\EasyApps XP
2009-04-27 10:13 . 2009-04-27 10:13 -------- d-----w c:\windows\system32\config\systemprofile\Application Data\AVGTOOLBAR
2009-04-27 06:31 . 2009-04-27 06:31 -------- d-----w c:\documents and settings\LordSnoop\Application Data\Malwarebytes
2009-04-27 06:31 . 2009-04-06 21:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-27 06:31 . 2009-04-06 21:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-27 06:31 . 2009-04-27 06:31 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-27 06:31 . 2009-04-27 06:31 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-26 18:00 . 2009-04-26 18:00 -------- d-----w c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-04-26 18:00 . 2009-04-26 18:00 -------- d-----w c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-04-26 18:00 . 2009-04-26 18:00 -------- d-----w c:\program files\SDHelper (Spybot - Search & Destroy)
2009-04-26 18:00 . 2009-04-26 18:00 -------- d-----w c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-04-26 08:52 . 2009-04-26 08:52 -------- d-----w c:\program files\Trend Micro
2009-04-26 06:56 . 2009-04-26 06:56 -------- d-----w c:\documents and settings\All Users\Application Data\Azureus
2009-04-26 06:56 . 2009-04-26 06:56 -------- d-----w c:\documents and settings\LordSnoop\Application Data\Azureus
2009-04-26 06:20 . 2009-04-26 06:22 -------- d-----w c:\program files\Enterbrain
2009-04-21 15:58 . 2009-04-21 15:58 -------- d-----w c:\documents and settings\Betty Fiddler\Local Settings\Application Data\DNA
2009-04-21 15:58 . 2009-04-24 06:06 -------- d-----w c:\documents and settings\Betty Fiddler\Application Data\DNA
2009-04-20 02:21 . 2009-04-20 02:21 -------- d-----w c:\documents and settings\LordSnoop\Application Data\Sonic
2009-04-20 02:20 . 2009-04-20 02:20 -------- d-----w c:\documents and settings\LordSnoop\Application Data\Leadertech
2009-04-18 07:02 . 2009-04-25 01:43 -------- d-----w c:\documents and settings\LordSnoop\Application Data\.freeciv
2009-04-16 04:40 . 2009-03-06 14:22 284160 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-16 04:40 . 2009-02-09 12:10 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 04:40 . 2009-02-06 11:11 110592 ------w c:\windows\system32\dllcache\services.exe
2009-04-16 04:40 . 2009-02-09 12:10 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 04:40 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 04:40 . 2009-02-09 12:10 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 04:40 . 2009-02-09 12:10 729088 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 04:40 . 2009-02-09 12:10 617472 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 04:40 . 2009-02-09 12:10 714752 ------w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 04:37 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-16 04:36 . 2008-04-21 12:08 215552 ------w c:\windows\system32\dllcache\wordpad.exe
2009-04-13 13:51 . 2009-04-23 20:12 -------- d-----w c:\documents and settings\HP_Administrator\Tracing
2009-04-11 14:34 . 2009-04-11 14:34 -------- d-----w c:\documents and settings\LordSnoop\Local Settings\Application Data\Identities
2009-04-10 22:24 . 2005-05-26 21:34 2297552 ----a-w c:\windows\system32\d3dx9_26.dll
2009-04-10 22:19 . 2009-04-10 22:24 -------- d--h--w c:\windows\msdownld.tmp
2009-04-10 22:19 . 2009-04-10 22:19 -------- d-----w c:\windows\Logs
2009-04-10 09:01 . 2009-04-10 09:01 -------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
2009-04-10 02:26 . 2008-10-16 20:06 208744 ----a-w c:\windows\system32\muweb.dll
2009-04-10 02:26 . 2008-10-16 20:06 268648 ----a-w c:\windows\system32\mucltui.dll
2009-04-09 22:27 . 2009-04-27 01:58 -------- d-----w c:\documents and settings\Betty Fiddler\Tracing
2009-04-09 15:50 . 2009-04-28 19:04 -------- d-----w c:\documents and settings\LordSnoop\Tracing
2009-04-09 15:48 . 2009-02-07 00:08 55152 ----a-w c:\windows\system32\drivers\fssfltr_tdi.sys
2009-04-09 15:48 . 2009-04-09 15:48 -------- d-----w c:\program files\Microsoft Sync Framework
2009-04-09 15:47 . 2006-11-29 19:06 3426072 ----a-w c:\windows\system32\d3dx9_32.dll
2009-04-09 15:47 . 2009-04-09 15:47 -------- d-----w c:\program files\Microsoft SQL Server Compact Edition
2009-04-09 15:45 . 2009-04-09 15:49 -------- d-----w c:\program files\Microsoft
2009-04-09 15:45 . 2009-04-09 15:45 -------- d-----w c:\program files\Windows Live SkyDrive
2009-04-09 15:44 . 2009-04-09 15:48 -------- d-----w c:\program files\Windows Live
2009-04-09 15:36 . 2009-04-09 15:36 -------- d-----w c:\program files\Common Files\Windows Live
2009-04-07 09:01 . 2009-04-07 09:01 -------- d-----w c:\program files\SystemRequirementsLab
2009-04-06 09:00 . 2009-04-06 09:26 -------- d-----w c:\documents and settings\Betty Fiddler\Application Data\BitTorrent
2009-04-05 02:16 . 2009-04-05 02:49 -------- d-----w c:\program files\UrbanTerror
2009-04-02 16:50 . 2003-12-12 22:06 1693696 ----a-w c:\windows\system32\ltclr13n.dll
2009-04-02 16:50 . 2003-11-04 21:10 98304 ----a-w c:\windows\system32\lffax13n.dll
2009-04-02 16:50 . 2003-11-04 21:11 155648 ----a-w c:\windows\system32\lftif13n.dll
2009-04-01 12:41 . 2009-04-01 12:41 -------- d-----w c:\documents and settings\HP_Administrator\Application Data\Yahoo!
2009-03-31 10:04 . 2009-03-31 10:04 -------- d-----w c:\documents and settings\LordSnoop\Local Settings\Application Data\DNA
2009-03-31 10:04 . 2009-04-24 05:18 -------- d-----w c:\program files\DNA
2009-03-31 10:04 . 2009-04-16 09:41 -------- d-----w c:\documents and settings\LordSnoop\Application Data\DNA
2009-03-31 10:04 . 2009-04-27 23:13 -------- d-----w c:\program files\BitTorrent

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-29 08:19 . 2006-02-17 05:23 56864 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-29 04:27 . 2007-01-04 11:38 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-28 05:59 . 2007-01-04 10:51 -------- d-----w c:\program files\mIRC
2009-04-27 23:14 . 2009-03-23 02:14 -------- d-----w c:\program files\Veoh Networks
2009-04-27 03:19 . 2009-03-15 22:18 132 ----a-w c:\documents and settings\LordSnoop\Local Settings\Application Data\fusioncache.dat
2009-04-26 07:54 . 2006-08-28 05:42 -------- d-----w c:\program files\Yahoo!
2009-04-25 19:39 . 2009-01-05 05:20 -------- d-----w c:\program files\PokerStars
2009-04-25 00:49 . 2009-01-24 02:26 15688 ----a-w c:\windows\system32\lsdelete.exe
2009-04-25 00:47 . 2009-01-24 01:45 64160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-04-10 05:46 . 2006-02-17 05:25 -------- d-----w c:\program files\Common Files\InstallShield
2009-04-09 15:45 . 2007-02-09 15:47 -------- d-----w c:\program files\MSN Messenger
2009-03-27 14:14 . 2007-07-13 10:21 453152 ----a-w c:\windows\system32\NVUNINST.EXE
2009-03-24 01:56 . 2009-03-24 01:56 -------- d-----w c:\program files\Python26
2009-03-21 21:35 . 2007-02-02 04:21 -------- d-----w c:\program files\Winamp
2009-03-20 02:33 . 2009-03-20 02:32 -------- d-----w c:\program files\Windows Media Connect 2
2009-03-19 17:33 . 2009-03-19 17:33 56280 ----a-w c:\documents and settings\LordSnoop\Application Data\GDIPFONTCACHEV1.DAT
2009-03-19 01:59 . 2009-03-19 01:59 -------- d-----w c:\program files\Microsoft Silverlight
2009-03-18 19:08 . 2009-03-18 19:08 -------- d-----w c:\program files\VideoLAN
2009-03-16 20:18 . 2009-04-10 22:25 69448 ----a-w c:\windows\system32\XAPOFX1_3.dll
2009-03-16 20:18 . 2009-04-10 22:25 517448 ----a-w c:\windows\system32\XAudio2_4.dll
2009-03-16 20:18 . 2009-04-10 22:25 235352 ----a-w c:\windows\system32\xactengine3_4.dll
2009-03-16 20:18 . 2009-04-10 22:25 22360 ----a-w c:\windows\system32\X3DAudio1_6.dll
2009-03-16 19:52 . 2007-02-11 01:28 -------- d-----w c:\program files\K-Lite Codec Pack
2009-03-16 18:55 . 2009-03-16 18:55 -------- d-----w c:\program files\YouTube Clip Extractor
2009-03-15 22:22 . 2006-02-17 05:50 -------- d-----w c:\program files\Google
2009-03-15 02:16 . 2009-01-23 23:44 -------- d-----w c:\program files\Common Files\logishrd
2009-03-15 02:12 . 2009-03-15 02:12 -------- d-----w c:\program files\Logitech
2009-03-09 21:27 . 2009-04-10 22:25 453456 ----a-w c:\windows\system32\d3dx10_41.dll
2009-03-09 21:27 . 2009-04-10 22:25 1846632 ----a-w c:\windows\system32\D3DCompiler_41.dll
2009-03-09 21:27 . 2009-04-10 22:25 4178264 ----a-w c:\windows\system32\D3DX9_41.dll
2009-03-09 02:42 . 2008-12-25 19:02 -------- d-----w c:\program files\LimeWire
2009-03-09 02:42 . 2009-03-09 02:42 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-09 02:41 . 2006-02-17 04:54 -------- d-----w c:\program files\Java
2009-03-08 20:46 . 2007-02-11 01:23 -------- d-----w c:\program files\SopCast
2009-03-06 14:22 . 2004-08-09 21:00 284160 ------w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-08-09 21:00 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2004-08-09 21:00 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 12:10 . 2004-08-09 21:00 729088 ------w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-10 04:00 714752 ------w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-09 21:00 617472 ------w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2004-08-09 21:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 11:13 . 2004-08-09 21:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-08 01:02 . 2004-08-10 04:00 2066048 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-07 01:03 . 2009-02-07 01:03 307576 ----a-w c:\windows\WLXPGSS.SCR
2009-02-07 00:52 . 2009-02-07 00:52 49504 ----a-w c:\windows\system32\sirenacm.dll
2009-02-06 11:11 . 2004-08-09 21:00 110592 ------w c:\windows\system32\services.exe
2009-02-06 11:08 . 2004-08-10 04:00 2189056 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-08-09 21:00 35328 ------w c:\windows\system32\sc.exe
2009-02-04 19:22 . 2007-04-10 18:39 56280 ----a-w c:\documents and settings\Betty Fiddler\Application Data\GDIPFONTCACHEV1.DAT
2009-02-03 19:59 . 2004-08-09 21:00 56832 ----a-w c:\windows\system32\secur32.dll
2009-02-01 15:31 . 2008-12-25 17:39 325128 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-02-01 15:31 . 2008-12-25 17:39 10520 ----a-w c:\windows\system32\avgrsstx.dll
2007-07-30 18:17 . 2007-07-30 18:17 774144 ----a-w c:\program files\RngInterstitial.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@="{30351346-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2007-06-09 19:42 536576 ----a-w c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@="{30351347-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2007-06-09 19:42 536576 ----a-w c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@="{30351348-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2007-06-09 19:42 536576 ----a-w c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@="{3035134B-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2007-06-09 19:42 536576 ----a-w c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@="{3035134C-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2007-06-09 19:42 536576 ----a-w c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@="{3035134D-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2007-06-09 19:42 536576 ----a-w c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@="{3035134E-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2007-06-09 19:42 536576 ----a-w c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]

c:\documents and settings\LordSnoop\Start Menu\Programs\Startup\
ChkDisk.lnk.disabled [2009-4-28 655]

c:\documents and settings\QBDataServiceUser17\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-2-16 27136]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WirelessLAN USB Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WirelessLAN USB Utility.lnk
backup=c:\windows\pss\WirelessLAN USB Utility.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^LordSnoop^Start Menu^Programs^Startup^ChkDisk.dll]
path=c:\documents and settings\LordSnoop\Start Menu\Programs\Startup\ChkDisk.dll
backup=c:\windows\pss\ChkDisk.dllStartup

[HKLM\~\startupfolder\C:^Documents and Settings^LordSnoop^Start Menu^Programs^Startup^ChkDisk.lnk]
path=c:\documents and settings\LordSnoop\Start Menu\Programs\Startup\ChkDisk.lnk
backup=c:\windows\pss\ChkDisk.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^LordSnoop^Start Menu^Programs^Startup^ERUNT AutoBackup.lnk]
path=c:\documents and settings\LordSnoop\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
backup=c:\windows\pss\ERUNT AutoBackup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NOD32krn"=2 (0x2)
"iPod Service"=3 (0x3)
"usnjsvc"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"SeaPort"=2 (0x2)
"QuickBooksDB17"=2 (0x2)
"QBFCService"=3 (0x3)
"QBCFMonitorService"=2 (0x2)
"npkcmsvc"=2 (0x2)
"MDM"=2 (0x2)
"LVPrcSrv"=2 (0x2)
"LightScribeService"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"IDriverT"=3 (0x3)
"gusvc"=2 (0x2)
"gupdate1c95d4a8527714c"=2 (0x2)
"fsssvc"=3 (0x3)
"CCALib8"=2 (0x2)
"Lavasoft Ad-Aware Service"=2 (0x2)
"avg8wd"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\PPMate\\ppmnet.exe"=
"c:\\Documents and Settings\\HP_Administrator\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Quake2\\aq2.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Bos Wars\\boswars.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Steam\\steamapps\\coanza@hotmail.com\\source sdk base\\hl2.exe"=
"c:\\Steam\\steamapps\\coanza@hotmail.com\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\UrbanTerror\\ioUrbanTerror.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Quake2\\nocheat.exe"=
"c:\\Documents and Settings\\LordSnoop\\Desktop\\Emulator\\Action_Quake2_Standalone~\\nocheat.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\PPMate\\ppmate.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\Battle of Survival\\stratagus.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\The All-Seeing Eye\\eye.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:*:Disabled:blizz
"57857:TCP"= 57857:TCP:*:Disabled:Pando Media Booster
"57857:UDP"= 57857:UDP:*:Disabled:Pando Media Booster

R3 ZD1211U(WirelessLAN);Wireless IEEE 802.11g Wireless LAN Driver (USB)(WirelessLAN);c:\windows\system32\DRIVERS\zd1211u.sys [2004-04-24 210944]
R4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-01 298264]
R4 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-07 533360]
R4 gupdate1c95d4a8527714c;Google Update Service (gupdate1c95d4a8527714c);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-16 133104]
R4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-04-25 953168]
R4 QuickBooksDB17;QuickBooksDB17;c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe [2007-11-23 128280]
R4 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-04-25 64160]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-02-01 325128]
S2 fssfltr;fssfltr;c:\windows\system32\DRIVERS\fssfltr_tdi.sys [2009-02-07 55152]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e68b79f6-288d-11de-9a8f-0017310e91a5}]
\Shell\AutoRun\command - J:\DigitalPhotoViewer.exe
.
Contents of the 'Scheduled Tasks' folder

2009-04-28 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 00:46]

2009-04-28 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-31 02:21]

2009-04-29 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-12-13 04:28]

2009-04-29 c:\windows\Tasks\User_Feed_Synchronization-{9F05BCD9-6060-4C10-90CE-5237A0979E0B}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 18:58]

2009-04-29 c:\windows\Tasks\{F897AA24-BDC3-11D1-B85B-00C04FB93981}_L33T_Betty Fiddler.job
- c:\windows\system32\mobsync.exe [2004-08-09 00:12]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-autochk - c:\windows\system32\autochk.dll
HKU-Default-Run-autochk - c:\docume~1\LOCALS~1\protect.dll


.
------- Supplementary Scan -------
.
uStart Page = about:blank
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=Q106&bd=pavilion&pf=desktop
mStart Page = hxxp://ca.yahoo.com
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=Q106&bd=pavilion&pf=desktop
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = 212.19.6.237:80
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
IE: {{073fe43a-def1-4955-96e2-f0a401b5b111} - c:\program files\YouTube Clip Extractor\ClipExtractor.exe
Trusted Zone: trymedia.com
TCP: {031AECE2-CFA9-4C9D-8192-79C896617DF3} = 218.93.202.110,218.93.202.111
TCP: {1F0282A5-D3BD-4560-A8C8-7731EC98D8A2} = 218.93.202.110,218.93.202.111
TCP: {3822AE64-4077-4FF4-A42D-4A2D58FCEE32} = 218.93.202.110,218.93.202.111
TCP: {892900FC-9814-4488-99C0-81491C1EE93D} = 218.93.202.110,218.93.202.111
TCP: {ACAA9C68-C07E-4B5B-816E-12B0A8E6A891} = 218.93.202.110,218.93.202.111
TCP: {D0FAE5AC-025C-46F2-8229-0E953B1135CE} = 218.93.202.110,218.93.202.111
TCP: {D1EB76A5-63EF-4F10-925C-D517E92E7EEE} = 218.93.202.110,218.93.202.111
TCP: {E70E84A3-13C3-4458-BFB6-29EC6D0B3107} = 218.93.202.110,218.93.202.111
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game08.zylom.com/activex/zylomgamesplayer.cab
FF - ProfilePath - c:\documents and settings\LordSnoop\Application Data\Mozilla\Firefox\Profiles\obhzcql1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - component: c:\documents and settings\LordSnoop\Application Data\Mozilla\Firefox\Profiles\obhzcql1.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-29 03:29
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3476)
c:\program files\TortoiseSVN\bin\tortoisesvn.dll
c:\program files\TortoiseSVN\bin\intl3_svn.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\arservice.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\windows\system32\nvsvc32.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\TortoiseSVN\bin\TSVNCache.exe
c:\windows\system32\dllhost.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2009-04-29 3:36 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-29 09:36

Pre-Run: 140,015,869,952 bytes free
Post-Run: 143,343,882,240 bytes free

418 --- E O F --- 2009-04-16 09:11


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:38:24 AM, on 29/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 212.19.6.237:80
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: ChkDisk.lnk.disabled (User 'SYSTEM')
O4 - .DEFAULT Startup: ChkDisk.lnk.disabled (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: ChkDisk.lnk.disabled
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: Download with YouTube Clip Extractor - {073fe43a-def1-4955-96e2-f0a401b5b111} - C:\Program Files\YouTube Clip Extractor\ClipExtractor.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (file missing)
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1...toUploader5.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/SCRABBLE/Images/stg_drm.ocx
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game08.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{031AECE2-CFA9-4C9D-8192-79C896617DF3}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{1F0282A5-D3BD-4560-A8C8-7731EC98D8A2}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{3822AE64-4077-4FF4-A42D-4A2D58FCEE32}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{892900FC-9814-4488-99C0-81491C1EE93D}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{ACAA9C68-C07E-4B5B-816E-12B0A8E6A891}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0FAE5AC-025C-46F2-8229-0E953B1135CE}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{D1EB76A5-63EF-4F10-925C-D517E92E7EEE}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{E70E84A3-13C3-4458-BFB6-29EC6D0B3107}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CS1\Services\Tcpip\..\{031AECE2-CFA9-4C9D-8192-79C896617DF3}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CS2\Services\Tcpip\..\{031AECE2-CFA9-4C9D-8192-79C896617DF3}: NameServer = 218.93.202.110,218.93.202.111
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 8183 bytes

#15 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:09:53 AM

Posted 29 April 2009 - 04:59 AM

Please re-open HijackThis and click on Do a system scan only. Check the boxes next to all the entries listed below.

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O4 - S-1-5-18 Startup: ChkDisk.lnk.disabled (User 'SYSTEM')
O4 - .DEFAULT Startup: ChkDisk.lnk.disabled (User 'Default user')
O4 - Startup: ChkDisk.lnk.disabled


Now close all windows other than HijackThis, then click Fix checked. Close HijackThis.




Please download Norman Malware Cleaner and save it to your Desktop.
  • Reboot your computer into Safe Mode.
  • Double-click Norman Malware Cleaner >> click Accept >> click Start scan
  • Let it finish it scan. A log will be created on your Desktop. Post the log in your next reply


Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan.
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan
    Wait for the scan to finish
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic


Post these logs in your next reply...

1. Norman Malware Cleaner
2. ESET Online Scanner
3. How's the computer now? :thumbup2:

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users