Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Security Tool
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Security Tool  
Forum Quick Jump
 
New Topic Locked Topic Printable version of : Security Tool
[ << Previous Thread | Next Thread >> ]

disneyk
Junior Member


Date Joined Oct 2007
Total Posts : 73
 
   Posted 10-29-2009 6:45 (GMT +1)    Quote: Security ToolAlert an admin about: Security Tool
Once again Hi Guy's, hope this finds you well
I again find myself in a spot of trouble it would appear i have been invaded by some low life piece of work which goes by the name of Security Tool. the usual
 
Avast is going mental with alerts all of which have been moved to chest. the programme states i have numerious virus's and has disabled my wall paper also redirects my homepage all of which leads to purchasing a programme to remove the virus. I ran malwarebytes but this crashed before finishing.  Knowledge would be grately appreciated have run hi jack and the log is as follows
 
disney
Logfile of HijackThis v1.99.1
Scan saved at 17:35, on 2009-10-29
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\winupdate.exe
C:\DOCUME~1\ALLUSE~1\APPLIC~1\22706724\22706724.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\john\Desktop\hijack this\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\msgr.en-us.en-gb\msntb.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [calc] rundll32.exe C:\WINDOWS\system32\calc.dll,_IWMPEvents@0
O4 - HKLM\..\Run: [winupdate.exe] C:\WINDOWS\system32\winupdate.exe
O4 - HKLM\..\Run: [22706724] C:\DOCUME~1\ALLUSE~1\APPLIC~1\22706724\22706724.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PopRock] C:\DOCUME~1\john\LOCALS~1\Temp\b.exe
O4 - HKCU\..\Run: [NordBull] C:\WINDOWS\msa.exe
O4 - HKCU\..\Run: [calc] rundll32.exe C:\DOCUME~1\john\ntuser.dll,_IWMPEvents@0
O4 - HKCU\..\Run: [12CFG214-K641-24SF-N84P] C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1858\port88.exe
O4 - HKCU\..\Run: [12CFG214-K641-12SF-N85P] C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe
O4 - Startup: ..
O4 - Startup: ..
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O8 - Extra context menu item: Save YouTube Video as MP3 - res://C:\Program Files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.8.05.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} (TraderMediaImgX Control) - http://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {680285A8-96D3-43DA-9D3D-51DD987D0B77} (NeroVersionCheckerControl Control) - http://www.nero.com/doc/NeroVersionCheckerControl.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E8D58496-5721-4C51-9BAE-BD33F4343773}: NameServer = 192.168.2.1,194.168.4.100
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16745
 
   Posted 10-29-2009 6:59 (GMT +1)    Quote: Security ToolAlert an admin about: Security Tool
Hello disneyk smile
 
 
"the programme states i have numerious virus's"   That´s right, as you have a large number of infections, therefore ->
 
Please follow this guide:

 Follow the instructions and copy the logs here,
in this Topic.


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

disneyk
Junior Member


Date Joined Oct 2007
Total Posts : 73
 
   Posted 10-29-2009 8:44 (GMT +1)    Quote: Security ToolAlert an admin about: Security Tool
Hi Touch thanks for the reply
a few problems, ran CC Cleaner crashed comp before finishing. Same result when attempting to run MBAM??
Did manage DDS though logs as follows
 
DDS (Ver_09-10-26.01) - NTFSx86 
Run by john at 19:33:14.42 on 2009-10-29
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.959.470 [GMT 0:00]
AV: avast! antivirus 4.8.1356 [VPS 091029-0] *On-access scanning enabled* (Updated)   {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
svchost.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\winupdate.exe
C:\DOCUME~1\ALLUSE~1\APPLIC~1\22706724\22706724.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\john\Local Settings\Temporary Internet Files\Content.IE5\20SB6NKJ\dds[1].scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.co.uk/
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
mURLSearchHooks: H - No File
mWinlogon: Taskman=c:\recycler\s-1-5-21-9281726040-9661670027-273044406-1909\wnzip32.exe
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: MSN Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn toolbar\01.01.2607.0\msgr.en-us.en-gb\msntb.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
EB: Groove Folder Synchronization: {2a541ae1-5bf6-4665-a8a3-cfa9672e4291} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [PopRock] c:\docume~1\john\locals~1\temp\b.exe
uRun: [NordBull] c:\windows\msa.exe
uRun: [calc] rundll32.exe c:\docume~1\john\ntuser.dll,_IWMPEvents@0
uRun: [12CFG214-K641-24SF-N84P] c:\recycler\s-1-5-21-0243936033-3052116371-381863308-1858\port88.exe
uRun: [12CFG214-K641-12SF-N85P] c:\recycler\s-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [calc] rundll32.exe c:\windows\system32\calc.dll,_IWMPEvents@0
mRun: [winupdate.exe] c:\windows\system32\winupdate.exe
mRun: [22706724] c:\docume~1\alluse~1\applic~1\22706724\22706724.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
uPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
uPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
uPolicies-system: NoDispSettingPage = 1 (0x1)
uPolicies-system: DisableTaskMgr = 1 (0x1)
mPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
IE: &Download with &DAP
IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: Download &all with DAP
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\iespell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\iespell\wikipedia.HTM
IE: Save YouTube Video as MP3 - c:\program files\common files\dvdvideosoft\dll\IEContextMenuY.dll/scriptY2MP3.htm
IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {00000055-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/fhg.CAB
DPF: {00B71CFB-6864-4346-A978-C0A14556272C} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab
DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - hxxp://www.ipix.com/download/ipixx.cab
DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} - hxxp://www.bebo.com/files/BeboUploader.5.8.05.cab
DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} - hxxp://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper200711281.dll
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
DPF: {680285A8-96D3-43DA-9D3D-51DD987D0B77} - hxxp://www.nero.com/doc/NeroVersionCheckerControl.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - hxxp://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash5r42.cab
DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} - hxxp://download.microsoft.com/download/7/E/6/7E6A8567-DFE4-4624-87C3-163549BE2704/clearadj.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
TCP: {E8D58496-5721-4C51-9BAE-BD33F4343773} = 192.168.2.1,194.168.4.100
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: {FB87BE85-13F2-481F-80F1-63F21B26F021} - No File
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
============= SERVICES / DRIVERS ===============
R0 SI3112r;ATI-437A Serial ATA Controller;c:\windows\system32\drivers\SI3112r.sys [1979-12-31 97920]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-9-6 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2006-10-10 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2007-2-27 74480]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-9-6 20560]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-6-5 55152]
R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-6-5 233472]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-9-28 604488]
R2 wwEngineSvc;Window Washer Engine;c:\program files\webroot\washer\WasherSvc.exe [2008-3-29 598856]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2009-6-5 36608]
S3 BRGSp50;BRGSp50 NDIS Protocol Driver;c:\windows\system32\drivers\BRGSp50.sys [2006-12-29 20608]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2008-9-10 38224]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-9-3 7408]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w300mgmt.sys [2006-12-26 87824]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\drivers\w300obex.sys [2006-12-26 85696]
S4 ASKService;ASKService;c:\program files\askbardis\bar\bin\AskService.exe [2009-9-14 464264]
S4 ASKUpgrade;ASKUpgrade;c:\program files\askbardis\bar\bin\ASKUpgrade.exe [2009-9-14 234888]
S4 fsssvc;Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2009-2-6 533360]
=============== Created Last 30 ================
2009-10-29 16:25:16 0 ----a-w- c:\windows\system32\AVR09.exe
2009-10-29 16:25:07 0 d-----w- c:\docume~1\alluse~1\applic~1\22706724
2009-10-29 16:25:01 0 ----a-w- c:\windows\system32\winhelper.dll
2009-10-29 16:24:08 831 ----a-w- c:\windows\system32\critical_warning.html
2009-10-29 16:24:01 26624 ----a-w- c:\windows\system32\winupdate.exe
2009-10-29 16:23:43 91648 ----a-w- C:\brpv.exe
2009-10-29 16:23:43 26624 ----a-w- C:\lwmb.exe
2009-10-25 23:03:04 0 d-----w- c:\docume~1\john\applic~1\Desktopicon
2009-10-23 16:54:39 0 d-----w- c:\program files\NCH Software
2009-10-23 16:39:08 0 d-----w- c:\program files\NCH Swift Sound
2009-10-14 09:41:00 0 d-----w- c:\docume~1\alluse~1\applic~1\Messenger Plus!
2009-10-13 14:48:31 0 d-----w- c:\program files\Circle Developemen
2009-10-13 14:48:04 0 d-----w- c:\program files\Messenger Plus! Live
2009-10-11 21:02:43 0 d-----w- c:\docume~1\john\applic~1\Blitware
2009-10-11 20:19:52 266360 ----a-w- c:\windows\system32\TweakUI.exe
2009-10-11 20:19:52 160217 ----a-w- c:\windows\system32\PowerToysLicense.rtf
2009-10-10 21:11:26 0 d-----w- c:\docume~1\john\applic~1\GetRightToGo
2009-10-09 15:56:56 0 d-----w- c:\windows\Cache
2009-10-03 19:24:05 0 d-s---w- C:\ComboFix
2009-10-03 19:24:02 389120 ----a-w- c:\windows\system32\CF20816.exe
2009-10-03 19:22:54 389120 ----a-w- c:\windows\system32\CF5374.exe
2009-09-30 15:09:17 40960 ----a-w- c:\windows\system32\ssubtmr6.dll
2009-09-30 15:09:16 36864 ----a-w- c:\windows\system32\trayicon_handler.ocx
==================== Find3M  ====================
2009-09-28 20:31:03 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-09-28 20:30:59 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-09-26 16:07:03 76184 ---ha-w- c:\windows\system32\mlfcache.dat
2009-09-23 17:59:20 361600 ----a-w- c:\windows\system32\drivers\TCPIP.SYS
2009-09-23 17:59:20 361600 ----a-w- c:\windows\system32\dllcache\TCPIP.SYS
2009-09-23 17:59:19 361600 ----a-w- c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2009-09-14 01:12:36 229888 ----a-w- c:\windows\PEV.exe
2009-09-10 13:54:06 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 13:53:50 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-28 18:42:52 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-16 17:51:30 389120 ----a-w- c:\windows\system32\CF10463.exe
2009-08-15 20:35:31 389120 ----a-w- c:\windows\system32\CF22597.exe
2009-08-15 09:06:32 389120 ----a-w- c:\windows\system32\CF18674.exe
2009-08-14 21:20:15 98304 ----a-w- c:\windows\DUMP5246.tmp
2009-08-14 21:19:00 98304 ----a-w- c:\windows\DUMP5285.tmp
2009-08-14 21:17:45 98304 ----a-w- c:\windows\DUMP51c9.tmp
2009-08-14 21:16:30 98304 ----a-w- c:\windows\DUMP5350.tmp
2009-08-14 21:08:58 98304 ----a-w- c:\windows\DUMP5275.tmp
2009-08-14 21:07:44 98304 ----a-w- c:\windows\DUMP5459.tmp
2008-01-10 16:34:46 88 --sha-r- c:\windows\system32\570905537A.sys
2009-03-21 14:06:58 23552 --sha-w- c:\windows\system32\calc.dll
2008-09-22 20:57:09 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092220080923\index.dat
============= FINISH: 19:33:57.03 ===============
DDS (Ver_09-10-26.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 2006-10-02 22:03:01
System Uptime: 2009-10-29 19:26:18 (0 hours ago)
Motherboard: NEC COMPUTERS INTERNATIONAL |  | MS-7168
Processor: AMD Athlon(tm) 64 Processor 3400+ | CPU 1 | 2188/200mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 186 GiB total, 44.91 GiB free.
D: is CDROM ()
==== Disabled Device Manager Items =============
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Kaspersky Anti-Virus NDIS Miniport
Device ID: ROOT\KL_KLIM5MP\0002
Manufacturer: Kaspersky Lab
Name: Kaspersky Anti-Virus NDIS Miniport #3
PNP Device ID: ROOT\KL_KLIM5MP\0002
Service: klim5
Class GUID: {4D36E96C-E325-11CE-BFC1-08002BE10318}
Description: Microsoft Kernel DLS Synthesizer
Device ID: SW\{8C07DD50-7A8D-11D2-8F8C-00C04FBF8FEF}\DMUSIC
Manufacturer: Microsoft
Name: Microsoft Kernel DLS Synthesizer
PNP Device ID: SW\{8C07DD50-7A8D-11D2-8F8C-00C04FBF8FEF}\DMUSIC
Service: DMusic
==== System Restore Points ===================
RP80: 2009-10-13 21:30:15 - System Checkpoint
RP81: 2009-10-16 03:32:48 - System Checkpoint
RP82: 2009-10-17 10:29:39 - System Checkpoint
RP83: 2009-10-18 13:23:45 - System Checkpoint
RP84: 2009-10-19 18:22:49 - System Checkpoint
RP85: 2009-10-20 18:41:00 - System Checkpoint
RP86: 2009-10-21 18:49:16 - System Checkpoint
RP87: 2009-10-22 22:25:49 - System Checkpoint
==== Installed Programs ======================
2007 Microsoft Office Suite Service Pack 2 (SP2)
ABBYY FineReader 4.0 Sprint
Adobe Acrobat 4.0
Adobe Acrobat 5.0
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Flash Player 10 Plugin
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Reader 8.1.7
Adobe Shockwave Player
Adobe Stock Photos 1.0
Apple Mobile Device Support
Apple Software Update
AudibleManager
avast! Antivirus
CCleaner
Choice Guard
CloneDVD 4.0
CopySafe Plugin
Corel Paint Shop Pro Photo XI
Creative Software AutoUpdate
Creative System Information
Creative ZEN
Critical Update for Windows Media Player 11 (KB959772)
Disc2Phone
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Web Player
eBay Icon
EPSON PhotoQuicker3.2
EPSON Printer Software
exPressit S.E. 2.1
Free Video to iPod Converter version 3.2
Free YouTube to iPod Converter version 3.2
Free YouTube to Mp3 Converter version 3.2
FUJIFILM USB Driver
Google Chrome
HijackThis 1.99.1
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954708)
ieSpell
IncrediMail
IpkutilaVxb
IsoBuster 2.5.5
iTunes
Java(TM) 6 Update 15
Junk Mail filter update
LG PC Suite
LG USB Modem driver
Logitech Desktop Messenger
Logitech Print Service
Logitech QuickCam Software
Logitech® Camera Driver
Malwarebytes' Anti-Malware
Messenger Plus! Live
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Easy Assist
Microsoft Expression Web
Microsoft Expression Web MUI (English)
Microsoft Expression Web Service Pack 1 (SP1)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Project 2007 Service Pack 1 (SP1)
Microsoft Office Project MUI (English) 2007
Microsoft Office Project Professional 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Visio 2007 Service Pack 1 (SP1)
Microsoft Office Visio MUI (English) 2007
Microsoft Office Visio Professional 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders  (English) 12
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft XML Parser
MP3+G Toolz
MSVCRT
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6.0 Parser (KB933579)
Nero 7 Premium
neroxml
OpenDNS Updater 2.0
PC Connectivity Solution
Personal Address Book 4.0.2
Photodex Presenter
ProShow Gold
QuickTime
Realtek AC'97 Audio
SAMSUNG Mobile Composite Device Software
SAMSUNG Mobile Modem Driver Set
Samsung Mobile phone USB driver Software
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
Samsung New PC Studio
SamsungConnectivityCableDriver
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB969679)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office Excel 2007 (KB969682)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Project 2007 (KB949046)
Security Update for Microsoft Office Publisher 2007 (KB969693)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office Visio 2007 (KB957831)
Security Update for Microsoft Office Word 2007 (KB969604)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB973346)
Segoe UI
SmartSound Quicktracks Plugin
Sony Ericsson PC Suite
Spotify
SUPERAntiSpyware Free Edition
Trust 240TH Direct Webscan Gold v2.1
Trust 240TH Direct Webscan Gold v3.0
TuneUp Utilities 2009
Tweak UI
Uninstall 1.0.0.1
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office Outlook 2007 (KB969907)
Update for Outlook 2007 Junk Email Filter (kb971933)
Update for Windows Internet Explorer 8 (KB971930)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
V3105s Digital Camera Driver
VC80CRTRedist - 8.0.50727.762
VCRedistSetup
ViewSonic Monitor Drivers
Vodei Multimedia Processor 2.10
Vuze
Vuze Toolbar
VuzeStream Plugin
WavePad Sound Editor
WebFldrs XP
Window Washer
Windows Desktop Search 3.01
Windows Driver Package - MobileTop (sshpmdm) Modem  (02/23/2007 2.5.0.0)
Windows Driver Package - MobileTop (sshpusb) USB  (02/23/2007 2.5.0.0)
Windows Driver Package - Nokia pccsmcfd  (10/12/2007 6.85.4.0)
Windows Essentials Media Codec Pack 2.3d
Windows Genuine Advantage Notifications (KB905474)
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
Windows Media Format 11 runtime
Windows Media Player 11
Windows Resource Kit Tools - SubInAcl.exe
Windows XP Service Pack 3
WinRAR archiver
Yahoo! Messenger
ZEN Media Explorer
ZENcast Organizer
Zune Desktop Theme
==== End Of File ===========================
 
Back to Top
 

disneyk
Junior Member


Date Joined Oct 2007
Total Posts : 73
 
   Posted 10-29-2009 10:04 (GMT +1)    Quote: Security ToolAlert an admin about: Security Tool
Hi Again
tried the MBAM another few times and success in the end her's the log also HJT log


Malwarebytes' Anti-Malware 1.41
Database version: 3054
Windows 5.1.2600 Service Pack 3
2009-10-29 20:44:35
mbam-log-2009-10-29 (20-44-35).txt
Scan type: Full Scan (C:\|)
Objects scanned: 212241
Time elapsed: 46 minute(s), 37 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 1
Registry Keys Infected: 3
Registry Values Infected: 8
Registry Data Items Infected: 7
Folders Infected: 3
Files Infected: 23
Memory Processes Infected:
C:\Documents and Settings\All Users\Application Data\22706724\22706724.exe (Rogue.SecurityTool) -> Unloaded process successfully.
C:\WINDOWS\system32\winupdate.exe (Trojan.Downloader) -> Unloaded process successfully.
Memory Modules Infected:
C:\WINDOWS\system32\calc.dll (Trojan.Agent) -> Delete on reboot.
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\NordBull (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\poprock (Trojan.Downloader) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\22706724 (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\calc (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupdate.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\12cfg214-k641-24sf-n84p (Worm.AutoRun) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\12cfg214-k641-12sf-n85p (Worm.AutoRun) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\poprock (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\calc (Trojan.Agent) -> Delete on reboot.
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
C:\Documents and Settings\All Users\Application Data\22706724 (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811 (Trojan.Agent) -> Quarantined and deleted successfully.
C:\RECYCLER\s-1-5-21-0243936033-3052116371-381863308-1858 (Worm.Autorun) -> Quarantined and deleted successfully.
Files Infected:
C:\Documents and Settings\All Users\Application Data\22706724\22706724.exe (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\calc.dll (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\john\ntuser.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\john\Local Settings\temp\rundll32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\john\Local Settings\temp\065.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\john\Local Settings\temp\159.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\john\Local Settings\temp\202.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\john\Local Settings\temp\355.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\john\Local Settings\temp\755.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\john\Start Menu\Programs\Startup\scandisk.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-9281726040-9661670027-273044406-1909\wnzip32.exe (Worm.Autorun.B) -> Delete on reboot.
C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\Desktop.ini (Trojan.Agent) -> Quarantined and deleted successfully.
C:\RECYCLER\s-1-5-21-0243936033-3052116371-381863308-1858\Desktop.ini (Worm.Autorun) -> Quarantined and deleted successfully.
C:\Documents and Settings\john\Start Menu\Programs\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\Documents and Settings\john\Start Menu\Programs\Startup\scandisk.lnk (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\AVR09.exe (Rogue.AdvancedVirusRemover) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\critical_warning.html (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mscert.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winhelper.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winupdate.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\TEMP\_ex-68.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\john\Local Settings\temp\nsrbgxod.bak (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\kbdnet.dll (Trojan.Agent) -> Quarantined and deleted successfully.
 
HJT Log
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:02, on 2009-10-29
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\msgr.en-us.en-gb\msntb.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [calc] rundll32.exe C:\WINDOWS\system32\calc.dll,_IWMPEvents@0
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NordBull] C:\WINDOWS\msa.exe
O4 - HKCU\..\Run: [calc] rundll32.exe C:\DOCUME~1\john\ntuser.dll,_IWMPEvents@0
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O8 - Extra context menu item: Save YouTube Video as MP3 - res://C:\Program Files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.8.05.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} (TraderMediaImgX Control) - http://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {680285A8-96D3-43DA-9D3D-51DD987D0B77} (NeroVersionCheckerControl Control) - http://www.nero.com/doc/NeroVersionCheckerControl.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E8D58496-5721-4C51-9BAE-BD33F4343773}: NameServer = 192.168.2.1,194.168.4.100
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: MsmacrobPau - {FB87BE85-13F2-481F-80F1-63F21B26F021} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
--
End of file - 12072 bytes
Back to Top
 

disneyk
Junior Member


Date Joined Oct 2007
Total Posts : 73
 
   Posted 10-29-2009 10:16 (GMT +1)    Quote: Security ToolAlert an admin about: Security Tool
Just an update on how things are going
I ran the cc cleaner after MBAM and this time this also worked
It would appear that the pop up's telling me that i'm infected and the virus warnings have ceased and things are running ok the only thing which i have noticed is that i am unable to set desktop background


Disney
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16745
 
   Posted 10-30-2009 6:07 (GMT +1)    Quote: Security ToolAlert an admin about: Security Tool
Ok. Let´s see if combofix can remove the infections you still have ->
 
Please download Combofix from:
 
 And save to the desktop as alg.exe.

Close all other browser windows.
 
Double-click on the combofix icon found on your desktop.
 
Please note, that once you start combofix you should not click anywhere on the combofix window as it can cause the program to stall. In fact, when combofix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.

 When finished, it will produce a logfile located at C:\combofix.txt.
 

Post the contents of that log in your next reply
 
The logs will be reasonably large so you may have to divide them into sections and make several posts to post them.



Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

disneyk
Junior Member


Date Joined Oct 2007
Total Posts : 73
 
   Posted 10-30-2009 11:47 (GMT +1)    Quote: Security ToolAlert an admin about: Security Tool
Hi Touch,
Tried to run Combo fix on 2 seperate occassions both time the comp crashed around stage 50? The comp displayed message that windows had shut down to prevent damage? It also stated that this was caused by BAD_POOL_HEADER??  Decided to try to run combo fix in safe mode but when requested to run safe mode with networking comp crashed again
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16745
 
   Posted 11-1-2009 7:37 (GMT +1)    Quote: Security ToolAlert an admin about: Security Tool
Ok.
 
 
 and download File Lister.
Save it to your Desktop
Rightlick ->> Extract all ->> And extract it to your Desktop
Open the File Lister Folder.
Note: Leave the FileLister.vbe file in the folder and run it from there.
Rightclick FileLister.vbe ->>Select Open Then Open to confirm.
When the program is fnished it will produce a log for you C:\Files.txt
 
Copy and paste the contents of that log in your reply.
 
The log will be reasonably large so you may have to divide it into sections and make several posts to post it.


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

disneyk
Junior Member


Date Joined Oct 2007
Total Posts : 73
 
   Posted 11-1-2009 5:08 (GMT +1)    Quote: Security ToolAlert an admin about: Security Tool
log as requested





====== Running Processes ======
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\SoftwareDistribution\Download\Install\dotnetfx35_x86.exe
c:\52451da1422aff25d40def\dotnetfx35setup.exe
c:\2494f498e8397b9c3ac210bbe6\setup.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
c:\WINDOWS\system32\MsiExec.exe
C:\WINDOWS\System32\WScript.exe
====== BHO's ======
BHO: (NO NAME) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
BHO: (NO NAME) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
BHO: (NO NAME) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: (NO NAME) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: (NO NAME) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
====== HKLM\~\Run Keys ======
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
[avast!] = C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[GrooveMonitor] = "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
[QuickTime Task] = "C:\Program Files\QuickTime\qttask.exe" -atboottime
[Adobe ARM] = "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
[Adobe Reader Speed Launcher] = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[SunJavaUpdateSched] = "C:\Program Files\Java\jre6\bin\jusched.exe"
[Malwarebytes Anti-Malware (reboot)] = "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
[KernelFaultCheck] = %systemroot%\system32\dumprep 0 -k
====== HKCU\~\Run Keys ======
[msnmsgr] = "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
[ctfmon.exe] = C:\WINDOWS\system32\ctfmon.exe
====== DNS Info (List may be empty) ======
HKEY_LOCAL_MACHINE\CCS\~\{46960BA6-0D3F-4A9B-9EE2-FC9E29AF2AFC}\  NameServer=
HKEY_LOCAL_MACHINE\CCS\~\{87F2B810-4D9E-46EB-B6CA-D87700FED496}\  NameServer=
HKEY_LOCAL_MACHINE\CCS\~\{9852492A-867E-4252-A851-66ADF6C950C3}\  NameServer=
HKEY_LOCAL_MACHINE\CCS\~\{B4E58AF4-B3B5-4863-97F4-270185B390ED}\  NameServer=
HKEY_LOCAL_MACHINE\CCS\~\{C05155B2-F77D-4D40-8AF6-CA239D87EF89}\  NameServer=
HKEY_LOCAL_MACHINE\CCS\~\{E8D58496-5721-4C51-9BAE-BD33F4343773}\  NameServer= 192.168.2.1,194.168.4.100
HKEY_LOCAL_MACHINE\CS001\~\{46960BA6-0D3F-4A9B-9EE2-FC9E29AF2AFC}\  NameServer=
HKEY_LOCAL_MACHINE\CS001\~\{87F2B810-4D9E-46EB-B6CA-D87700FED496}\  NameServer=
HKEY_LOCAL_MACHINE\CS001\~\{9852492A-867E-4252-A851-66ADF6C950C3}\  NameServer=
HKEY_LOCAL_MACHINE\CS001\~\{B4E58AF4-B3B5-4863-97F4-270185B390ED}\  NameServer=
HKEY_LOCAL_MACHINE\CS001\~\{C05155B2-F77D-4D40-8AF6-CA239D87EF89}\  NameServer=
HKEY_LOCAL_MACHINE\CS001\~\{E8D58496-5721-4C51-9BAE-BD33F4343773}\  NameServer= 192.168.2.1,194.168.4.100
 
====== Folders and Files from "%\" and "%\Windows" Created Last 60 Days ======
2009-11-01 14:42:41    15826810    C:\2494f498e8397b9c3ac210bbe6
2009-11-01 14:42:17    59027604    C:\52451da1422aff25d40def
2009-11-01 14:42:18    24520704    C:\52451da1422aff25d40def\dotnetfx20
2009-11-01 14:42:28    23268176    C:\52451da1422aff25d40def\dotnetfx30
2009-11-01 14:42:34    1527296    C:\52451da1422aff25d40def\dotnetfx30\x86
2009-11-01 14:42:34    8164360    C:\52451da1422aff25d40def\dotnetfx35
2009-11-01 14:42:34    8164360    C:\52451da1422aff25d40def\dotnetfx35\x86
2009-11-01 14:42:38    114200    C:\52451da1422aff25d40def\tools
2009-10-31 20:21:57    25192370    C:\ComboFix
2009-10-31 20:21:58    16539    C:\ComboFix\N_
2009-11-01 14:50:09    5484    32    C:\Files.txt
2009-11-01 00:40:46    1230987    C:\WINDOWS\$NtUninstallKB954155_WM9$
2009-11-01 00:40:46    627339    C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst
2009-11-01 00:39:46    2717920    C:\WINDOWS\$NtUninstallKB956744$
2009-11-01 00:39:46    631520    C:\WINDOWS\$NtUninstallKB956744$\spuninst
2009-11-01 00:39:10    780778    C:\WINDOWS\$NtUninstallKB956844$
2009-11-01 00:39:10    627690    C:\WINDOWS\$NtUninstallKB956844$\spuninst
2009-11-01 00:45:50    627393    C:\WINDOWS\$NtUninstallKB958869$
2009-11-01 00:45:51    627393    C:\WINDOWS\$NtUninstallKB958869$\spuninst
2009-11-01 00:48:26    703884    C:\WINDOWS\$NtUninstallKB960859$
2009-11-01 00:48:26    628108    C:\WINDOWS\$NtUninstallKB960859$\spuninst
2009-10-31 10:36:24    2135370    C:\WINDOWS\$NtUninstallKB968389$
2009-10-31 10:36:24    630986    C:\WINDOWS\$NtUninstallKB968389$\spuninst
2009-11-01 00:42:00    3085665    C:\WINDOWS\$NtUninstallKB968816_WM9$
2009-11-01 00:42:00    627553    C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst
2009-11-01 00:42:12    2063433    C:\WINDOWS\$NtUninstallKB969059$
2009-11-01 00:42:12    627785    C:\WINDOWS\$NtUninstallKB969059$\spuninst
2009-10-31 09:58:55    838895    C:\WINDOWS\$NtUninstallKB970653-v3$
2009-10-31 09:58:55    640751    C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst
2009-10-31 10:05:52    9053027    C:\WINDOWS\$NtUninstallKB971486$
2009-10-31 10:05:53    628707    C:\WINDOWS\$NtUninstallKB971486$\spuninst
2009-11-01 00:40:59    712662    C:\WINDOWS\$NtUninstallKB971557$
2009-11-01 00:40:59    627670    C:\WINDOWS\$NtUninstallKB971557$\spuninst
2009-11-01 00:41:16    759817    C:\WINDOWS\$NtUninstallKB971657$
2009-11-01 00:41:16    627721    C:\WINDOWS\$NtUninstallKB971657$\spuninst
2009-10-31 10:22:00    1941927    C:\WINDOWS\$NtUninstallKB973354$
2009-10-31 10:22:00    627111    C:\WINDOWS\$NtUninstallKB973354$\spuninst
2009-11-01 00:37:48    686175    C:\WINDOWS\$NtUninstallKB973507$
2009-11-01 00:37:48    627295    C:\WINDOWS\$NtUninstallKB973507$\spuninst
2009-10-31 10:05:15    7768815    C:\WINDOWS\$NtUninstallKB973525$
2009-10-31 10:05:15    625391    C:\WINDOWS\$NtUninstallKB973525$\spuninst
2009-10-31 10:13:55    11780410    C:\WINDOWS\$NtUninstallKB973540_WM9$
2009-10-31 10:13:55    627514    C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst
2009-10-31 10:37:13    831417    C:\WINDOWS\$NtUninstallKB973815$
2009-10-31 10:37:13    627641    C:\WINDOWS\$NtUninstallKB973815$\spuninst
2009-11-01 00:38:27    756157    C:\WINDOWS\$NtUninstallKB973869$
2009-11-01 00:38:27    627645    C:\WINDOWS\$NtUninstallKB973869$\spuninst
2009-11-01 00:39:27    874915    C:\WINDOWS\$NtUninstallKB974112$
2009-11-01 00:39:27    627589    C:\WINDOWS\$NtUninstallKB974112$\spuninst
2009-11-01 00:38:07    684714    C:\WINDOWS\$NtUninstallKB974571$
2009-11-01 00:38:07    627370    C:\WINDOWS\$NtUninstallKB974571$\spuninst
2009-10-31 10:36:50    899737    C:\WINDOWS\$NtUninstallKB975467$
2009-10-31 10:36:50    627353    C:\WINDOWS\$NtUninstallKB975467$\spuninst
2009-10-09 15:56:56    2478793    C:\WINDOWS\Cache
2009-10-09 15:56:56    2478793    C:\WINDOWS\Cache\Adobe Reader 6.0
2009-10-09 15:56:56    2478793    C:\WINDOWS\Cache\Adobe Reader 6.0\CZEMIN
2009-10-30 09:27:36    0    32    C:\WINDOWS\0.log
2009-10-31 09:59:13    47420    32    C:\WINDOWS\comsetup.log
2009-10-31 09:59:09    142204    32    C:\WINDOWS\FaxSetup.log
2009-10-31 09:59:11    22601    32    C:\WINDOWS\iis6.log
2009-10-31 09:59:19    1374    32    C:\WINDOWS\imsins.BAK
2009-10-31 09:59:19    1374    32    C:\WINDOWS\imsins.log
2009-11-01 00:40:44    7621    32    C:\WINDOWS\KB954155.log
2009-11-01 00:39:42    9113    32    C:\WINDOWS\KB956744.log
2009-11-01 00:39:07    8772    32    C:\WINDOWS\KB956844.log
2009-11-01 00:45:48    5883    32    C:\WINDOWS\KB958869.log
2009-10-30 10:44:13    21841    32    C:\WINDOWS\KB960859.log
2009-10-30 10:09:37    25534    32    C:\WINDOWS\KB968389.log
2009-11-01 00:41:58    7947    32    C:\WINDOWS\KB968816.log
2009-10-30 10:43:30    17872    32    C:\WINDOWS\KB969059.log
2009-10-31 09:58:11    4106    32    C:\WINDOWS\KB970653-v3.log
2009-10-31 10:05:40    12283    32    C:\WINDOWS\KB971486.log
2009-10-30 10:43:06    17527    32    C:\WINDOWS\KB971557.log
2009-10-30 10:43:12    18034    32    C:\WINDOWS\KB971657.log
2009-10-31 10:05:26    9651    32    C:\WINDOWS\KB971961-IE8.log
2009-10-31 10:21:32    39445    32    C:\WINDOWS\KB973354.log
2009-10-30 10:41:17    17830    32    C:\WINDOWS\KB973507.log
2009-10-31 10:04:16    7417    32    C:\WINDOWS\KB973525.log
2009-10-31 10:13:52    37685    32    C:\WINDOWS\KB973540.log
2009-10-30 10:12:13    15898    32    C:\WINDOWS\KB973815.log
2009-11-01 00:38:23    8772    32    C:\WINDOWS\KB973869.log
2009-10-30 10:42:46    17553    32    C:\WINDOWS\KB974112.log
2009-11-01 00:46:06    24826    32    C:\WINDOWS\KB974455-IE8.log
2009-10-30 10:42:24    17818    32    C:\WINDOWS\KB974571.log
2009-10-30 10:10:53    16779    32    C:\WINDOWS\KB975467.log
2009-10-30 09:53:10    77312    32    C:\WINDOWS\MBR.exe
2009-10-31 09:59:21    7107    32    C:\WINDOWS\msgsocm.log
2009-10-03 19:24:18    31232    32    C:\WINDOWS\NIRCMD.exe
2009-10-31 09:59:16    28734    32    C:\WINDOWS\ntdtcsetup.log
2009-10-31 09:59:07    67988    32    C:\WINDOWS\ocgen.log
2009-10-31 09:59:26    7866    32    C:\WINDOWS\ocmsn.log
2009-10-30 09:27:09    7122    32    C:\WINDOWS\SchedLgU.Txt
2009-10-31 09:59:13    0    32    C:\WINDOWS\setupact.log
2009-10-31 09:59:31    30692    32    C:\WINDOWS\setupapi.log
2009-10-31 09:59:13    0    32    C:\WINDOWS\setuperr.log
2009-10-31 10:14:08    1084    32    C:\WINDOWS\spupdsvc.log
2009-09-01 17:30:02    0    0    C:\WINDOWS\Sti_Trace.log
2009-10-31 09:59:18    54257    32    C:\WINDOWS\tsoc.log
2009-10-31 10:05:34    5442    32    C:\WINDOWS\updspapi.log
2009-09-01 17:30:05    159    32    C:\WINDOWS\wiadebug.log
2009-09-29 12:02:14    50    32    C:\WINDOWS\wiaservc.log
2009-10-29 23:26:31    1339859    32    C:\WINDOWS\WindowsUpdate.log
2009-10-31 10:14:14    618    32    C:\WINDOWS\wmsetup.log
2009-09-06 11:21:54    380928    32    C:\WINDOWS\system32\actskin4.ocx
2009-09-06 11:21:54    1279968    32    C:\WINDOWS\system32\aswBoot.exe
2009-09-06 11:22:19    97480    32    C:\WINDOWS\system32\AvastSS.scr
2009-10-03 19:24:02    389120    32    C:\WINDOWS\system32\CF20816.exe
2009-10-03 19:22:54    389120    32    C:\WINDOWS\system32\CF5374.exe
2009-10-29 19:47:07    145184    32    C:\WINDOWS\system32\java.exe
2009-10-29 19:47:07    145184    32    C:\WINDOWS\system32\javaw.exe
2009-10-29 19:47:07    149280    32    C:\WINDOWS\system32\javaws.exe
2009-10-29 19:46:33    3032    32    C:\WINDOWS\system32\jupdate-1.6.0_16-b01.log
2009-10-11 20:19:52    160217    32    C:\WINDOWS\system32\PowerToysLicense.rtf
2009-09-30 15:09:17    40960    32    C:\WINDOWS\system32\ssubtmr6.dll
2009-09-30 15:09:16    36864    32    C:\WINDOWS\system32\trayicon_handler.ocx
2009-09-28 20:30:59    361288    32    C:\WINDOWS\system32\TuneUpDefragService.exe
2009-09-28 20:31:03    604488    32    C:\WINDOWS\system32\TUProgSt.exe
2009-10-11 20:19:52    266360    32    C:\WINDOWS\system32\TweakUI.exe
2009-09-28 20:31:00    29000    32    C:\WINDOWS\system32\uxtuneup.dll
====== Files under "\Administrator\Startup" Last 60 Days======

====== Files under "\All Users\Startup" Last 60 Days======

====== Files and Folders under "\Program Files" Last 60 Days======
2009-09-14 09:10:04    1591796    C:\Program Files\AskBarDis
2009-10-13 14:48:31    0    C:\Program Files\Circle Developemen
2009-09-10 19:01:29    70466344    C:\Program Files\DivX
2009-09-18 19:03:13    85906    C:\Program Files\MediaMonkey
2009-10-13 14:48:04    13325626    C:\Program Files\Messenger Plus! Live
2009-09-14 12:51:45    15461451    C:\Program Files\Microsoft Silverlight
2009-09-26 16:21:14    764    C:\Program Files\MSBuild
2009-10-23 16:54:39    110592    C:\Program Files\NCH Software
2009-10-23 16:39:08    3851578    C:\Program Files\NCH Swift Sound
2009-09-30 14:16:15    9343802    C:\Program Files\Smart Projects
2009-09-28 20:28:49    45409445    C:\Program Files\TuneUp Utilities 2009
====== Files under "\System32\Drivers" Last 60 Days======
2009-09-06 11:22:22    27408    32    C:\WINDOWS\system32\drivers\aavmker4.sys
2009-09-06 11:22:19    20560    32    C:\WINDOWS\system32\drivers\aswFsBlk.sys
2009-09-06 11:22:19    93424    32    C:\WINDOWS\system32\drivers\aswmon.sys
2009-09-06 11:22:19    94160    32    C:\WINDOWS\system32\drivers\aswmon2.sys
2009-09-06 11:22:25    23152    32    C:\WINDOWS\system32\drivers\aswRdr.sys
2009-09-06 11:22:19    114768    32    C:\WINDOWS\system32\drivers\aswSP.sys
2009-09-06 11:22:24    52368    32    C:\WINDOWS\system32\drivers\aswTdi.sys
2009-09-23 17:59:19    361600    32    C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
====== Files Deleted under "%Temp%" ======

5 Files deleted
====== Files and Folders under "All Users\Application Data" Last 60 Days======
2009-10-14 09:41:00    0    C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2009-10-23 16:39:37    0    C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2009-10-23 16:39:37    0    C:\Documents and Settings\All Users\Application Data\NCH Swift Sound\WavePad
2009-09-28 20:29:07    217517    C:\Documents and Settings\All Users\Application Data\TuneUp Software
2009-09-28 20:29:07    217517    C:\Documents and Settings\All Users\Application Data\TuneUp Software\TuneUp Utilities
2009-09-28 20:31:04    208896    C:\Documents and Settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\Program Statistics
2009-09-28 20:29:07    8621    C:\Documents and Settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\Web
2009-09-28 20:27:13    17515520    C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
====== Values under HKLM\Software\microsoft\shared tools\msconfig\startupreg ======
HKLM\Software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
HKLM\Software\microsoft\shared tools\msconfig\startupreg\ATIPTA
HKLM\Software\microsoft\shared tools\msconfig\startupreg\atiptaxx
HKLM\Software\microsoft\shared tools\msconfig\startupreg\AutoStartNPSAgent
HKLM\Software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}
HKLM\Software\microsoft\shared tools\msconfig\startupreg\CTCheck
HKLM\Software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe
HKLM\Software\microsoft\shared tools\msconfig\startupreg\CTSyncU.exe
HKLM\Software\microsoft\shared tools\msconfig\startupreg\GoogleToolbarNotifier
HKLM\Software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor
HKLM\Software\microsoft\shared tools\msconfig\startupreg\Gtwatch
HKLM\Software\microsoft\shared tools\msconfig\startupreg\IncrediMail
HKLM\Software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
HKLM\Software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck
HKLM\Software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate
HKLM\Software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair
HKLM\Software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray
HKLM\Software\microsoft\shared tools\msconfig\startupreg\MSMSGS
HKLM\Software\microsoft\shared tools\msconfig\startupreg\msnmsgr
HKLM\Software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck
HKLM\Software\microsoft\shared tools\msconfig\startupreg\NMBgMonitor
HKLM\Software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE
HKLM\Software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKLM\Software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite
HKLM\Software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
HKLM\Software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware
HKLM\Software\microsoft\shared tools\msconfig\startupreg\Window Washer
HKLM\Software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager
====== Services ( Services that are Whitelisted are not shown) ======
ASAPIW2K (ASAPIW2K)-  - Manual/Stopped
aswFsBlk (aswFsBlk)- C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys - Auto/Running
aswSP (avast! Self Protection)- C:\WINDOWS\system32\drivers\aswSP.sys - System/Running
BRGSp50 (BRGSp50 NDIS Protocol Driver)- C:\WINDOWS\system32\Drivers\BRGSp50.sys - Manual/Stopped
CSS DVP (CSS DVP)- C:\WINDOWS\system32\DRIVERS\css-dvp.sys - Auto/Stopped
fssfltr (FssFltr)- C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys - Auto/Running
GT680x (%GrandTechICNameNT%)- C:\WINDOWS\system32\DRIVERS\GT680x.SYS - Manual/Running
MarvinBus (Pinnacle Marvin Bus)- C:\WINDOWS\system32\DRIVERS\MarvinBus.sys - Manual/Running
Mtlmnt5 (Mtlmnt5)- C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys - Manual/Running
Mtlstrm (Mtlstrm)- C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys - Manual/Stopped
NdisIP (Microsoft TV/Video Connection)- C:\WINDOWS\system32\DRIVERS\NdisIP.sys - Manual/Stopped
NtMtlFax (NtMtlFax)- C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys - Manual/Stopped
PCASp50 (PCASp50 NDIS Protocol Driver)-  - Manual/Stopped
pccsmcfd (PCCS Mode Change Filter Driver)- C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys - Manual/Stopped
pcouffin (VSO Software pcouffin)- C:\WINDOWS\system32\Drivers\pcouffin.sys - Manual/Stopped
pgfilter (pgfilter)- \??\C:\Program Files\PeerGuardian2\pgfilter.sys - Manual/Stopped
PID_0928 (Logitech QuickCam Express(PID_0928))- C:\WINDOWS\system32\DRIVERS\LV561AV.SYS - Manual/Running
RecAgent (recagent)- \??\C:\WINDOWS\system32\DRIVERS\RecAgent.sys - Manual/Stopped
RTL8023xp (Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver)- C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys - Manual/Running
SABProcEnum (SABProcEnum)- \??\C:\Program Files\Internet Explorer\SABProcEnum.sys - Manual/Stopped
SASDIFSV (SASDIFSV)- \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS - System/Running
SASENUM (SASENUM)- \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS - Manual/Stopped
SASKUTIL (SASKUTIL)- \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys - System/Running
SE27bus (Sony Ericsson Device 039 Driver driver (WDM))- C:\WINDOWS\system32\DRIVERS\SE27bus.sys - Manual/Stopped
SE27mdfl (Sony Ericsson Device 039 USB WMC Modem Filter)- C:\WINDOWS\system32\DRIVERS\SE27mdfl.sys - Manual/Stopped
SE27mdm (Sony Ericsson Device 039 USB WMC Modem Driver)- C:\WINDOWS\system32\DRIVERS\SE27mdm.sys - Manual/Stopped
SE27mgmt (Sony Ericsson Device 039 USB WMC Device Management Drivers (WDM))- C:\WINDOWS\system32\DRIVERS\SE27mgmt.sys - Manual/Stopped
se27nd5 (Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (NDIS))- C:\WINDOWS\system32\DRIVERS\se27nd5.sys - Manual/Stopped
SE27obex (Sony Ericsson Device 039 USB WMC OBEX Interface)- C:\WINDOWS\system32\DRIVERS\SE27obex.sys - Manual/Stopped
se27unic (Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (WDM))- C:\WINDOWS\system32\DRIVERS\se27unic.sys - Manual/Stopped
SI3112r (ATI-437A Serial ATA Controller)- C:\WINDOWS\system32\DRIVERS\SI3112r.sys - Boot/Running
SiFilter (SATALink driver accelerator)- C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys - Boot/Running
SLIP (BDA Slip De-Framer)- C:\WINDOWS\system32\DRIVERS\SLIP.sys - Manual/Stopped
Slntamr (SmartLink AMR_PCI Driver)- C:\WINDOWS\system32\DRIVERS\slntamr.sys - Manual/Running
SlNtHal (SlNtHal)- C:\WINDOWS\system32\DRIVERS\Slnthal.sys - Manual/Stopped
SlWdmSup (SlWdmSup)- C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys - Manual/Running
USBAAPL (Apple Mobile USB Driver)- C:\WINDOWS\system32\Drivers\usbaapl.sys - Manual/Stopped
usbbus (LGE Mobile Composite USB Device)- C:\WINDOWS\system32\DRIVERS\lgusbbus.sys - Manual/Stopped
usbcm (USB Cable Modem 351000 NDIS Driver)- C:\WINDOWS\system32\DRIVERS\usbcm.sys - Manual/Stopped
UsbDiag (LGE Mobile USB Serial Port)- C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys - Manual/Stopped
USBModem (LGE Mobile USB Modem)- C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys - Manual/Stopped
w300bus (Sony Ericsson W300 Driver driver (WDM))- C:\WINDOWS\system32\DRIVERS\w300bus.sys - Manual/Stopped
w300mdfl (Sony Ericsson W300 USB WMC Modem Filter)- C:\WINDOWS\system32\DRIVERS\w300mdfl.sys - Manual/Stopped
w300mdm (Sony Ericsson W300 USB WMC Modem Driver)- C:\WINDOWS\system32\DRIVERS\w300mdm.sys - Manual/Stopped
w300mgmt (Sony Ericsson W300 USB WMC Device Management Drivers (WDM))- C:\WINDOWS\system32\DRIVERS\w300mgmt.sys - Manual/Stopped
w300obex (Sony Ericsson W300 USB WMC OBEX Interface)- C:\WINDOWS\system32\DRIVERS\w300obex.sys - Manual/Stopped
WpdUsb (WpdUsb)- C:\WINDOWS\system32\DRIVERS\wpdusb.sys - Manual/Stopped
ZD1211BU(ZyDAS) (ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS))- C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys - Manual/Stopped
ZDPSp50 (ZDPSp50 NDIS Protocol Driver)- C:\WINDOWS\system32\Drivers\ZDPSp50.sys - Manual/Stopped
FsUsbExDisk (FsUsbExDisk)- \??\C:\WINDOWS\system32\FsUsbExDisk.SYS - Manual/Running
====== Uninstall List ======
Windows Driver Package - Nokia pccsmcfd  (10/12/2007 6.85.4.0)
Windows Driver Package - MobileTop (sshpmdm) Modem  (02/23/2007 2.5.0.0)
Windows Driver Package - MobileTop (sshpusb) USB  (02/23/2007 2.5.0.0)
Vuze
ABBYY FineReader 4.0 Sprint
Adobe Acrobat 4.0
Adobe Acrobat 5.0
Adobe Flash Player 10 Plugin
Adobe Photoshop CS2
Adobe Shockwave Player
Vuze Toolbar
AudibleManager
avast! Antivirus
CCleaner
CopySafe Plugin
Creative Software AutoUpdate
DivX Plus DirectShow Filters
eBay Icon
Microsoft Office Enterprise 2007
EPSON Printer Software
exPressit S.E. 2.1
Free Video to iPod Converter version 3.2
Free YouTube to iPod Converter version 3.2
Free YouTube to Mp3 Converter version 3.2
HijackThis 2.0.2
Microsoft Internationalized Domain Names Mitigation APIs
Windows Internet Explorer 8
ieSpell
IncrediMail
SmartSound Quicktracks Plugin
Samsung New PC Studio
IsoBuster 2.5.5
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Windows Desktop Search 3.01
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB923561)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Hotfix for Windows Media Format 11 SDK (KB929399)
Security Update for CAPICOM (KB931906)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938464-v2)
Hotfix for Windows Media Player 11 (KB939683)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Update for Windows XP (KB951072-v2)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Update for Windows XP (KB951978)
Security Update for Windows XP (KB952004)
Security Update for Windows Media Player (KB952069)
Hotfix for Windows XP (KB952287)
Security Update for Windows XP (KB952954)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player (KB954155)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Hotfix for Windows XP (KB954708)
Security Update for Windows XP (KB955069)
Update for Windows XP (KB955839)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Critical Update for Windows Media Player 11 (KB959772)
Security Update for Windows XP (KB960225)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Update for Windows XP (KB961503)
Security Update for Windows Internet Explorer 7 (KB963027)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Security Update for Windows XP (KB968537)
Security Update for Windows Media Player (KB968816)
Security Update for Windows XP (KB969059)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Hotfix for Windows XP (KB970653-v3)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Update for Windows Internet Explorer 8 (KB971930)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows Media Player (KB973540)
Update for Windows XP (KB973815)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB974112)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975467)
Logitech Print Service
Microsoft .NET Framework 1.1 Security Update (KB953297)
CloneDVD 4.0
Malwarebytes' Anti-Malware
Messenger Plus! Live
Microsoft .NET Framework 1.1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft National Language Support Downlevel APIs
OpenDNS Updater 2.0
Personal Address Book 4.0.2
Photodex Presenter
Microsoft Office Project Professional 2007
Microsoft Office Professional Plus 2007
ProShow Gold
Logitech® Camera Driver
SAMSUNG Mobile Composite Device Software
SAMSUNG Mobile Modem Driver Set
Samsung Mobile phone USB driver Software
SAMSUNG Mobile USB Modem Software
SAMSUNG Mobile USB Modem 1.0 Software
Spotify
Creative System Information
Trust 240TH Direct Webscan Gold v2.1
Trust 240TH Direct Webscan Gold v3.0
Tweak UI
Uninstall 1.0.0.1
V3105s Digital Camera Driver
Microsoft Office Visio Professional 2007
Vodei Multimedia Processor 2.10
WavePad Sound Editor
Microsoft Expression Web
Windows Genuine Advantage Notifications (KB905474)
Window Washer
Windows Essentials Media Codec Pack 2.3d
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
Windows Live Essentials
WinRAR archiver
Windows Media Format 11 runtime
Windows Media Player 11
Microsoft User-Mode Driver Framework Feature Pack 1.0
Yahoo! Messenger
ZEN Media Explorer
ZENcast Organizer
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
MSXML 6.0 Parser (KB933579)
Windows Live Messenger
Security Update for CAPICOM (KB931906)
Creative ZEN
Windows Live Upload Tool
MSVCRT
Adobe Photoshop CS2
Java(TM) 6 Update 16
WebFldrs XP
VCRedistSetup
Windows Live Communications Platform
Windows Live Photo Gallery
SmartSound Quicktracks Plugin
Junk Mail filter update
Microsoft Easy Assist
FUJIFILM USB Driver
TuneUp Utilities 2009
neroxml
Windows Live Mail
Apple Software Update
Windows Live Writer
Microsoft Visual C++ 2005 Redistributable
VC80CRTRedist - 8.0.50727.762
Windows Live Family Safety
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Adobe Stock Photos 1.0
DivX Codec
Zune Desktop Theme
SamsungConnectivityCableDriver
MSXML 4.0 SP2 (KB954430)
Microsoft Silverlight
DivX Player
QuickTime
Adobe Common File Installer
Choice Guard
Logitech Desktop Messenger
Microsoft Software Update for Web Folders  (English) 12
Microsoft Office Professional Plus 2007
2007 Microsoft Office Suite Service Pack 2 (SP2)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office system 2007 (972581)
Security Update for 2007 Microsoft Office System (KB969559)
Update for Outlook 2007 Junk Email Filter (KB974810)
Security Update for Microsoft Office Word 2007 (KB969604)
Security Update for Microsoft Office system 2007 (KB974234)
Microsoft Office Access MUI (English) 2007
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
Microsoft Office PowerPoint MUI (English) 2007
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
Microsoft Office Outlook MUI (English) 2007
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
Microsoft Office Word MUI (English) 2007
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
Microsoft Office Proof (English) 2007
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
Microsoft Office Proof (French) 2007
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
Microsoft Office Proof (Spanish) 2007
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
Microsoft Expression Web
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB951944)
Microsoft Expression Web Service Pack 1 (SP1)
Security Update for 2007 Microsoft Office System (KB951550)
Update for 2007 Microsoft Office System (KB967642)
Security Update for Microsoft Office system 2007 (KB974234)
Microsoft Expression Web MUI (English)
Microsoft Expression Web Service Pack 1 (SP1)
Microsoft Office Proofing (English) 2007
Microsoft Office Enterprise 2007
2007 Microsoft Office Suite Service Pack 2 (SP2)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB969693)
Security Update for Microsoft Office Excel 2007 (KB969682)
Update for Outlook 2007 Junk Email Filter (KB974810)
Update for 2007 Microsoft Office System (KB967642)
Security Update for 2007 Microsoft Office System (KB969679)
Security Update for Microsoft Office Word 2007 (KB969604)
Security Update for Microsoft Office system 2007 (KB974234)
Microsoft Office Project Professional 2007
Security Update for Microsoft Office system 2007 (972581)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for Microsoft Office Project 2007 (KB949046)
Security Update for 2007 Microsoft Office System (KB951550)
Microsoft Office Project 2007 Service Pack 1 (SP1)
Update for 2007 Microsoft Office System (KB967642)
Security Update for Microsoft Office system 2007 (KB974234)
Microsoft Office InfoPath MUI (English) 2007
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
Microsoft Office Visio Professional 2007
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB951944)
Microsoft Office Visio 2007 Service Pack 1 (SP1)
Security Update for 2007 Microsoft Office System (KB951550)
Update for 2007 Microsoft Office System (KB967642)
Security Update for Microsoft Office Visio 2007 (KB957831)
Security Update for Microsoft Office system 2007 (KB974234)
Microsoft Office Visio MUI (English) 2007
Microsoft Office Visio 2007 Service Pack 1 (SP1)
Microsoft Office Shared MUI (English) 2007
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
Microsoft Office Project MUI (English) 2007
Microsoft Office Project 2007 Service Pack 1 (SP1)
Microsoft Office Shared Setup Metadata MUI (English) 2007
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
Microsoft Office Access Setup Metadata MUI (English) 2007
2007 Microsoft Office Suite Service Pack 2 (SP2)
2007 Microsoft Office Suite Service Pack 2 (SP2)
Corel Paint Shop Pro Photo XI
Windows Live Sign-in Assistant
Microsoft Application Error Reporting
Nero 7 Premium
LG PC Suite
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Windows Live Sync
Segoe UI
Apple Mobile Device Support
PC Connectivity Solution
Adobe Reader 8.1.7
DivX Converter
EPSON PhotoQuicker3.2
ViewSonic Monitor Drivers
Microsoft .NET Framework 2.0 Service Pack 1
DivX Web Player
Adobe Bridge 1.0
Adobe Stock Photos 1.0
MSXML 4.0 SP2 (KB936181)
LG USB Modem driver
Logitech QuickCam Software
Windows Live Essentials
Microsoft .NET Framework 1.1
SUPERAntiSpyware Free Edition
Windows Resource Kit Tools - SubInAcl.exe
Microsoft XML Parser
IpkutilaVxb
Adobe Help Center 1.0
iTunes
Microsoft SQL Server 2005 Compact Edition [ENU]
Samsung New PC Studio
MP3+G Toolz
Windows Live Call
Realtek AC'97 Audio
Sony Ericsson PC Suite
Disc2Phone
======== Other Info ========
TOTAL PHYSICAL RAM: 1006 MB
Boot Info
[boot loader]
timeout=3
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

OS Type:  Microsoft Windows XP Home Edition
Build:  5.1.2600
Service Pack:  3.0

====== Files with Hidden Attributes======
 
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16745
 
   Posted 11-2-2009 6:17 (GMT +1)    Quote: Security ToolAlert an admin about: Security Tool
Download http://eric.71.mespages.googlepages.com/LopSD.exe
by Eric_71 and save it to your desktop.

Double-click LopSD.exe
Choose the language by typing of the corresponding letter and press Enter
Click OK at the informative window
Type 2 to choose Option 2 (Fix + Hosts), then press Enter
Wait until the end of the scan have finished

A report will be generated, post the contents of it in your next reply.
 


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

disneyk
Junior Member


Date Joined Oct 2007
Total Posts : 73
 
   Posted 11-3-2009 12:14 (GMT +1)    Quote: Security ToolAlert an admin about: Security Tool
--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3400+ )
BIOS : BIOS Date: 07/20/05 11:46:51 Ver: 08.00.12
USER : john ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1356 [VPS 091102-0] 4.8.1356 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:186 Go (Free:42 Go)
D:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : ( 2009-11-02|23:04 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ FIX

Deleted! - C:\DOCUME~1\john\Cookies\john@adultfriendfinder.txt
-
[ Hosts file ] .. Restored!

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing folders in APPLIC~1

[2008-03-05|20:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[2004-08-10|16:04] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[2008-03-05|20:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[2009-06-18|09:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[2008-01-18|09:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\Propellerhead Software
[2006-10-02|20:53] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[2007-10-12|21:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\SUPERAntiSpyware.com
[2007-10-12|20:51] C:\DOCUME~1\ADMINI~1\APPLIC~1\Uniblue

[2008-09-10|14:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009-09-28|20:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{55A29068-F2CE-456C-9148-C869879E2357}
[2009-10-20|09:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[2008-10-06|15:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe Systems
[2007-10-21|11:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[2007-10-03|15:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[2006-11-04|13:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[2009-06-18|09:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg8
[2009-08-10|12:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[2009-03-07|18:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus
[2009-04-29|19:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BullGuard
[2008-01-10|16:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Corel
[2008-01-29|15:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
[2009-05-25|21:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[2007-02-12|20:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVDXStudio
[2008-01-24|16:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ExPLabs.com
[2007-09-28|09:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[2007-10-01|08:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[2009-02-09|15:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IM
[2009-02-09|15:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IncrediMail
[2009-04-29|19:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab Setup Files
[2008-09-10|09:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[2009-10-14|09:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[2009-06-05|13:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[2009-11-02|08:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
[2009-10-23|16:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NCH Swift Sound
[2009-08-16|22:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
[2009-03-26|15:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\OpenDNS Updater
[2008-09-29|19:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Drivers HeadQuarters
[2009-06-05|20:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[2007-09-20|13:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle
[2007-09-20|12:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle Studio
[2008-01-15|09:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Propellerhead Software
[2009-07-20|10:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\River Past G4
[2007-07-17|16:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\River Past G5
[2004-08-10|16:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[2008-02-08|22:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Seagate
[2007-02-19|16:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SlySoft
[2007-09-20|13:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SmartSound Software Inc
[2007-12-26|17:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Ericsson
[2008-02-08|14:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[2007-10-04|11:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
[2007-12-26|17:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Teleca
[2009-06-03|18:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[2009-09-28|20:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TuneUp Software
[2007-07-17|08:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[2008-03-25|15:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\vsosdk
[2008-03-29|16:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Webroot
[2006-10-03|11:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[2008-03-03|22:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[2007-03-08|10:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
[2009-08-25|20:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion

[2004-08-10|16:04] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[2004-08-10|15:46] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[2006-10-02|20:53] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Sun

[2009-07-27|10:49] C:\DOCUME~1\john\APPLIC~1\Adobe
[2006-12-26|22:01] C:\DOCUME~1\john\APPLIC~1\AdobeAUM
[2006-12-26|22:13] C:\DOCUME~1\john\APPLIC~1\AdobeUM
[2009-08-11|21:14] C:\DOCUME~1\john\APPLIC~1\Ahead
[2006-10-11|19:26] C:\DOCUME~1\john\APPLIC~1\aicon
[2007-07-11|13:19] C:\DOCUME~1\john\APPLIC~1\Alien Skin
[2009-09-26|16:06] C:\DOCUME~1\john\APPLIC~1\Apple Computer
[2009-07-19|19:31] C:\DOCUME~1\john\APPLIC~1\Avira
[2009-11-01|23:11] C:\DOCUME~1\john\APPLIC~1\Azureus
[2009-10-11|21:02] C:\DOCUME~1\john\APPLIC~1\Blitware
[2009-04-29|16:07] C:\DOCUME~1\john\APPLIC~1\BullGuard
[2008-10-28|15:57] C:\DOCUME~1\john\APPLIC~1\Corel
[2008-09-11|18:50] C:\DOCUME~1\john\APPLIC~1\Creative
[2009-10-25|23:03] C:\DOCUME~1\john\APPLIC~1\Desktopicon
[2009-08-16|13:41] C:\DOCUME~1\john\APPLIC~1\DivX
[2006-10-03|08:11] C:\DOCUME~1\john\APPLIC~1\FotoWire
[2007-08-02|20:31] C:\DOCUME~1\john\APPLIC~1\FUJIFILM
[2009-10-10|21:11] C:\DOCUME~1\john\APPLIC~1\GetRightToGo
[2007-06-02|10:18] C:\DOCUME~1\john\APPLIC~1\Google
[2006-10-02|21:14] C:\DOCUME~1\john\APPLIC~1\Help
[2004-08-10|16:04] C:\DOCUME~1\john\APPLIC~1\Identities
[2009-07-03|10:33] C:\DOCUME~1\john\APPLIC~1\ieSpell
[2009-07-31|11:07] C:\DOCUME~1\john\APPLIC~1\InfraRecorder
[2009-03-23|21:01] C:\DOCUME~1\john\APPLIC~1\InstallShield
[2006-10-03|11:10] C:\DOCUME~1\john\APPLIC~1\InterTrust
[2006-12-26|22:18] C:\DOCUME~1\john\APPLIC~1\Leadertech
[2007-02-13|21:32] C:\DOCUME~1\john\APPLIC~1\LG Electronics
[2007-09-10|13:37] C:\DOCUME~1\john\APPLIC~1\Macromedia
[2008-09-10|09:43] C:\DOCUME~1\john\APPLIC~1\Malwarebytes
[2007-02-15|11:23] C:\DOCUME~1\john\APPLIC~1\Media Player Classic
[2009-06-11|17:03] C:\DOCUME~1\john\APPLIC~1\Microsoft
[2006-10-03|09:02] C:\DOCUME~1\john\APPLIC~1\Microsoft Web Folders
[2009-09-14|09:36] C:\DOCUME~1\john\APPLIC~1\Mozilla
[2009-10-23|16:39] C:\DOCUME~1\john\APPLIC~1\NCH Swift Sound
[2008-01-12|13:20] C:\DOCUME~1\john\APPLIC~1\Nero
[2006-12-19|13:13] C:\DOCUME~1\john\APPLIC~1\Opera
[2007-02-18|17:20] C:\DOCUME~1\john\APPLIC~1\OTVREG
[2009-06-05|20:15] C:\DOCUME~1\john\APPLIC~1\PC Suite
[2008-01-15|10:14] C:\DOCUME~1\john\APPLIC~1\Propellerhead Software
[2007-07-22|15:14] C:\DOCUME~1\john\APPLIC~1\River Past G4
[2007-07-17|16:19] C:\DOCUME~1\john\APPLIC~1\River Past G5
[2009-06-05|20:07] C:\DOCUME~1\john\APPLIC~1\Samsung
[2007-04-02|19:56] C:\DOCUME~1\john\APPLIC~1\Screenshot Sender
[2009-05-30|20:26] C:\DOCUME~1\john\APPLIC~1\SecondLife
[2006-10-24|14:28] C:\DOCUME~1\john\APPLIC~1\Seven Zip
[2007-02-19|16:35] C:\DOCUME~1\john\APPLIC~1\SlySoft
[2006-10-24|14:04] C:\DOCUME~1\john\APPLIC~1\Softplicity
[2007-12-26|17:39] C:\DOCUME~1\john\APPLIC~1\Sony Ericsson
[2009-05-20|13:20] C:\DOCUME~1\john\APPLIC~1\Spotify
[2006-10-02|20:53] C:\DOCUME~1\john\APPLIC~1\Sun
[2008-09-10|09:01] C:\DOCUME~1\john\APPLIC~1\SUPERAntiSpyware.com
[2007-12-26|17:42] C:\DOCUME~1\john\APPLIC~1\Teleca
[2007-10-15|16:03] C:\DOCUME~1\john\APPLIC~1\TrojanHunter
[2009-09-28|20:30] C:\DOCUME~1\john\APPLIC~1\TuneUp Software
[2007-01-02|14:38] C:\DOCUME~1\john\APPLIC~1\Ulead Systems
[2007-10-12|14:26] C:\DOCUME~1\john\APPLIC~1\Uniblue
[2009-07-20|09:34] C:\DOCUME~1\john\APPLIC~1\Vso
[2009-09-14|13:24] C:\DOCUME~1\john\APPLIC~1\VuzeStream
[2008-03-29|16:09] C:\DOCUME~1\john\APPLIC~1\Webroot
[2007-05-21|21:54] C:\DOCUME~1\john\APPLIC~1\Windows Desktop Search
[2008-09-15|14:18] C:\DOCUME~1\john\APPLIC~1\Yahoo!

[2008-01-24|11:04] C:\DOCUME~1\LOCALS~1\APPLIC~1\Adobe
[2007-12-27|09:10] C:\DOCUME~1\LOCALS~1\APPLIC~1\Macromedia
[2009-06-18|09:08] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[2009-06-18|09:08] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

--------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[2009-10-22 23:00][--a------] C:\WINDOWS\tasks\1-Click Maintenance.job
[2009-10-22 23:30][--ah-----] C:\WINDOWS\tasks\User_Feed_Synchronization-{2D113D38-60E0-437E-8091-BCFEA8C45CAE}.job
[2009-10-22 23:12][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3319507284-1904020372-2158876734-1006UA.job
[2009-10-22 15:12][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3319507284-1904020372-2158876734-1006Core.job
[2009-07-15 08:08][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009-11-02 08:14][--ah-----] C:\WINDOWS\tasks\SA.DAT
[2004-08-04 13:00][--ah-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing Folders in C:\Program Files

[2009-08-14|21:26] C:\Program Files\ABBYY FineReader 4.0 Sprint
[2007-07-17|15:30] C:\Program Files\ACE-HIGH MP3 WAV WMA OGG Converter
[2009-02-10|16:48] C:\Program Files\Adobe
[2007-01-13|22:12] C:\Program Files\Alcohol Soft
[2007-03-13|10:02] C:\Program Files\All To All AudioConvert
[2006-10-03|08:43] C:\Program Files\Alwil Software
[2006-10-02|20:50] C:\Program Files\AMD
[2006-12-29|19:26] C:\Program Files\Apache Group
[2008-09-10|14:29] C:\Program Files\Apple Software Update
[2009-09-14|09:10] C:\Program Files\AskBarDis
[2008-01-29|17:09] C:\Program Files\Audible
[2006-10-24|13:46] C:\Program Files\Audio Converter
[2009-05-25|21:00] C:\Program Files\AVG
[2009-03-07|17:54] C:\Program Files\Azureus
[2009-01-29|12:11] C:\Program Files\CCleaner
[2009-10-13|14:48] C:\Program Files\Circle Developemen
[2007-02-12|20:01] C:\Program Files\CloneDVD
[2009-10-31|20:26] C:\Program Files\Common Files
[2009-09-06|11:06] C:\Program Files\Comodo
[2008-04-10|11:14] C:\Program Files\Conduit
[2008-11-15|23:02] C:\Program Files\Copysafe
[2008-01-10|16:34] C:\Program Files\Corel
[2008-03-11|11:32] C:\Program Files\Creative
[2008-01-29|15:11] C:\Program Files\Creative Installation Information
[2006-10-12|17:04] C:\Program Files\Cucusoft
[2007-07-11|11:33] C:\Program Files\!!!! NFO Viewer
[2008-03-05|20:54] C:\Program Files\DAP
[2006-12-29|19:24] C:\Program Files\Datel
[2009-06-05|20:11] C:\Program Files\DIFX
[2007-12-26|17:22] C:\Program Files\Disc2Phone
[2009-09-10|19:03] C:\Program Files\DivX
[2009-10-25|23:02] C:\Program Files\DVDVideoSoft
[2006-10-03|09:27] C:\Program Files\EPSON
[2009-08-16|13:56] C:\Program Files\Essentials Codec Pack
[2009-07-16|18:30] C:\Program Files\exPressit S.E. 2.1
[2007-08-02|20:32] C:\Program Files\FinePixViewer
[2007-09-28|09:01] C:\Program Files\Google
[2009-07-03|10:30] C:\Program Files\ieSpell
[2009-08-15|19:41] C:\Program Files\IncrediMail
[2009-07-19|17:53] C:\Program Files\InstallShield Installation Information
[2009-11-01|14:52] C:\Program Files\Internet Explorer
[2008-09-10|14:38] C:\Program Files\iPod
[2009-09-14|09:14] C:\Program Files\iTunes
[2009-10-29|19:47] C:\Program Files\Java
[2006-10-12|18:21] C:\Program Files\LEAD Technologies, Inc
[2009-03-23|21:08] C:\Program Files\LG Electronics
[2009-03-23|21:06] C:\Program Files\LG PC Suite 2
[2007-10-04|21:56] C:\Program Files\LizardTech
[2008-09-10|16:16] C:\Program Files\Logitech
[2009-10-03|21:52] C:\Program Files\Malwarebytes' Anti-Malware
[2009-06-05|20:06] C:\Program Files\MarkAny
[2009-09-18|20:51] C:\Program Files\MediaMonkey
[2008-11-15|23:02] C:\Program Files\Messenger
[2009-10-13|14:48] C:\Program Files\Messenger Plus! Live
[2009-06-05|13:52] C:\Program Files\Microsoft
[2007-05-21|22:03] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2008-09-22|18:01] C:\Program Files\Microsoft Easy Assist
[2007-05-21|20:52] C:\Program Files\Microsoft Expression
[2006-10-03|09:02] C:\Program Files\microsoft frontpage
[2009-09-30|21:23] C:\Program Files\Microsoft Office
[2009-10-31|10:27] C:\Program Files\Microsoft Silverlight
[2009-06-05|13:58] C:\Program Files\Microsoft SQL Server Compact Edition
[2006-10-03|09:05] C:\Program Files\Microsoft Visual Studio
[2009-09-30|21:25] C:\Program Files\Microsoft Visual Studio 8
[2009-09-30|21:37] C:\Program Files\Microsoft Works
[2007-05-21|20:52] C:\Program Files\Microsoft.NET
[2008-09-22|20:40] C:\Program Files\Movie Maker
[2008-02-20|23:42] C:\Program Files\MP3+G Toolz .NET 4
[2007-06-14|12:08] C:\Program Files\Mp3Doctor
[2006-10-24|14:34] C:\Program Files\mp3Tag 5
[2009-09-26|16:21] C:\Program Files\MSBuild
[2004-08-10|15:54] C:\Program Files\MSN
[2004-08-10|15:54] C:\Program Files\MSN Gaming Zone
[2009-07-21|10:24] C:\Program Files\MSN Messenger
[2006-11-15|18:21] C:\Program Files\MSN Toolbar
[2008-02-08|22:18] C:\Program Files\MSXML 6.0
[2009-10-23|16:54] C:\Program Files\NCH Software
[2009-10-23|16:39] C:\Program Files\NCH Swift Sound
[2008-01-27|17:55] C:\Program Files\Nero
[2008-09-22|20:37] C:\Program Files\NetMeeting
[2007-04-21|12:50] C:\Program Files\NewLive All Media To Mp3 Converter
[2006-10-02|21:21] C:\Program Files\Online Services
[2009-09-06|10:56] C:\Program Files\OpenDNS Updater
[2009-10-31|10:22] C:\Program Files\Outlook Express
[2007-12-16|17:42] C:\Program Files\PAB
[2009-06-05|20:10] C:\Program Files\PC Connectivity Solution
[2006-10-03|09:50] C:\Program Files\Photodex
[2006-10-03|09:50] C:\Program Files\Photodex Presenter
[2008-01-19|10:32] C:\Program Files\Propellerhead
[2007-07-11|11:31] C:\Program Files\PSCS2Updater
[2008-09-10|14:35] C:\Program Files\QuickTime
[2006-11-24|19:20] C:\Program Files\Real
[2009-11-01|16:18] C:\Program Files\Reference Assemblies
[2006-10-12|16:58] C:\Program Files\RM Converter
[2009-06-05|20:11] C:\Program Files\Samsung
[2009-09-30|14:16] C:\Program Files\Smart Projects
[2007-09-20|13:07] C:\Program Files\SmartSound Software
[2007-12-26|17:37] C:\Program Files\Sony Ericsson
[2009-05-27|15:14] C:\Program Files\Spotify
[2009-10-30|12:21] C:\Program Files\SUPERAntiSpyware
[2009-10-29|21:02] C:\Program Files\trend micro
[2009-05-26|12:34] C:\Program Files\TrojanHunter 5.0
[2006-10-03|08:58] C:\Program Files\Trust
[2009-10-09|09:00] C:\Program Files\TuneUp Utilities 2009
[2006-10-16|13:25] C:\Program Files\Ubisoft
[2004-08-10|16:04] C:\Program Files\Uninstall Information
[2007-03-04|21:37] C:\Program Files\V3105s Digital Camera
[2008-11-15|23:02] C:\Program Files\viewsonic
[2007-08-21|13:53] C:\Program Files\Vodei
[2009-07-20|09:35] C:\Program Files\VSO
[2009-10-20|13:17] C:\Program Files\Vuze
[2008-03-29|16:09] C:\Program Files\Webroot
[2007-05-21|21:53] C:\Program Files\Windows Desktop Search
[2009-06-05|14:01] C:\Program Files\Windows Live
[2009-06-05|13:52] C:\Program Files\Windows Live SkyDrive
[2008-11-15|23:02] C:\Program Files\Windows Media Connect 2
[2008-11-21|20:50] C:\Program Files\Windows Media Player
[2008-09-22|20:36] C:\Program Files\Windows NT
[2008-09-22|19:03] C:\Program Files\Windows Resource Kits
[2004-08-10|15:57] C:\Program Files\WindowsUpdate
[2007-03-14|16:50] C:\Program Files\WinRAR
[2004-08-10|15:59] C:\Program Files\xerox
[2009-08-25|20:32] C:\Program Files\Yahoo!

--------------------\\ Listing Folders in C:\Program Files\Common Files

[2009-10-19|17:40] C:\Program Files\Common Files\Adobe
[2008-10-06|15:35] C:\Program Files\Common Files\Adobe Systems Shared
[2009-08-16|22:39] C:\Program Files\Common Files\Ahead
[2008-09-10|14:35] C:\Program Files\Common Files\Apple
[2008-01-10|16:33] C:\Program Files\Common Files\Corel
[2008-01-29|14:06] C:\Program Files\Common Files\Creative
[2006-10-03|09:05] C:\Program Files\Common Files\Designer
[2009-09-10|19:01] C:\Program Files\Common Files\DivX Shared
[2009-10-25|23:02] C:\Program Files\Common Files\DVDVideoSoft
[2006-10-03|09:28] C:\Program Files\Common Files\EPSON
[2006-10-03|08:11] C:\Program Files\Common Files\FotoWire
[2006-12-25|10:58] C:\Program Files\Common Files\InstallShield
[2006-10-03|08:04] C:\Program Files\Common Files\Logitech
[2007-07-03|18:53] C:\Program Files\Common Files\Macrovision Shared
[2009-09-30|21:38] C:\Program Files\Common Files\Microsoft Shared
[2004-08-10|15:56] C:\Program Files\Common Files\MSSoap
[2008-01-25|16:44] C:\Program Files\Common Files\Nero
[2004-08-10|15:48] C:\Program Files\Common Files\ODBC
[2008-03-15|11:35] C:\Program Files\Common Files\Real
[2009-07-20|10:03] C:\Program Files\Common Files\River Past
[2004-08-10|15:56] C:\Program Files\Common Files\Services
[2007-12-26|17:38] C:\Program Files\Common Files\Sony Ericsson Shared
[2004-08-10|15:48] C:\Program Files\Common Files\SpeechEngines
[2009-09-30|21:45] C:\Program Files\Common Files\System
[2007-12-26|17:38] C:\Program Files\Common Files\Teleca Shared
[2008-03-29|16:09] C:\Program Files\Common Files\Webroot Shared
[2009-06-05|13:42] C:\Program Files\Common Files\Windows Live
[2008-03-03|22:00] C:\Program Files\Common Files\WindowsLiveInstaller
[2008-09-10|09:01] C:\Program Files\Common Files\Wise Installation Wizard

--------------------\\ Process

( 36 Processes )

... OK !

--------------------\\ Searching with S_Lop

No Lop folder found !

--------------------\\ Searching for Lop Files - Folders

No Lop folder found !

--------------------\\ Searching within the Registry

..... OK !

--------------------\\ Checking the Hosts file

Hosts file CLEAN


--------------------\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-02 23:06:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 4

--------------------\\ Searching for other infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\john\Desktop\Azureus Downloads\VSO ConvertXtoDVD 3.8.0.193k+keygen
C:\DOCUME~1\john\Desktop\Azureus Downloads\VSO ConvertXtoDVD 3.8.0.193k+keygen\Keygen
C:\DOCUME~1\john\Desktop\Dad's music\David Bowie - Complete Discography\--- Studio albums ---\1989 - Tin Machine\04 - Crack City.mp3
C:\DOCUME~1\john\Desktop\Dad's music\Eminem-Relapse-2009\18-Crack A Bottle (Feat. Dr. Dre & 50 Cent.mp3
C:\DOCUME~1\john\Desktop\Dad's music\Neil Diamond - Hot August Night II - 320 [stereo rat]\15 Cracklin' Rosie.mp3
C:\DOCUME~1\john\Local Settings\Application Data\Xenocode\XSandbox\1.0.0.0\2009.03.04T02.27\Virtual\MODIFIED\@PROGRAMFILES@\ImTOO\MPEG Encoder Ultimate\script\crack.js
C:\DOCUME~1\john\My Documents\Divx 7\DivX.Pro.v7.0.0.Incl.Keygen.PS
C:\DOCUME~1\john\My Documents\Divx 7\DivX.Pro.v7.0.0.Incl.Keygen.PS\DivX.Pro.v7.0.0.Incl.Keygen.FFF
C:\DOCUME~1\john\My Documents\Divx 7\DivX.Pro.v7.0.0.Incl.Keygen.PS\Thumbs.db
C:\DOCUME~1\john\My Documents\Divx 7\DivX.Pro.v7.0.0.Incl.Keygen.PS\DivX.Pro.v7.0.0.Incl.Keygen.FFF\DivXInstaller.exe
C:\DOCUME~1\john\My Documents\ImTOO Software Studio\MPEG Encoder Ultimate\crack.js
C:\DOCUME~1\john\My Documents\IsoBuster 2.5.5.1 Final Portable\Keygen ZWT
C:\DOCUME~1\john\My Documents\IsoBuster 2.5.5.1 Final Portable\Keygen ZWT\Keygen ZWT
C:\DOCUME~1\john\My Documents\IsoBuster 2.5.5.1 Final Portable\Keygen ZWT\Keygen ZWT\keygen.exe
C:\DOCUME~1\john\My Documents\My Pictures\beccas pictures\Music x\Now 69 with covers\Now 69 disk 2\14-mark_brown_feat._sarah_cracknell_-_the_journey_continues_(vocal_club_mix).mp3
C:\DOCUME~1\john\My Documents\My Pictures\beccas pictures\Music x\Random Songs\_NEW_ Crack A Bottle - Eminem Dr Dre 50 Cent.mp3
C:\DOCUME~1\john\My Documents\tune up key gen\TU2009Keygen.exe


[F:22][D:17]-> C:\DOCUME~1\john\LOCALS~1\Temp
[F:268][D:0]-> C:\DOCUME~1\john\Cookies
[F:11185][D:13]-> C:\DOCUME~1\john\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 2009-11-02|23:09 - Option :

--------------------\\ Scan completed at 23:09:53
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16745
 
   Posted 11-3-2009 6:02 (GMT +1)    Quote: Security ToolAlert an admin about: Security Tool
The log shows the existence of illegal software. As  Bullguard  does not assist when the presence or use of illegal software become known, I will be ending all assistance here at this time. The best I might suggest you do is to reformat and reinstall the operating system to remove all infection.


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 
New Topic Locked Topic Printable version of : Security Tool
 
Forum Information
Currently it is Monday, March 15, 2010 9:17 PM (GMT +1)
There are a total of 76.224 posts in 17.603 threads.
In the last 3 days there were 11 new threads and 75 reply posts. View Active Threads
Who's Online
This forum has 31141 registered members. Please welcome our newest member, bippedibopp.
32 Guest(s), 2 Registered Member(s) are currently online.  Details
LANEYM, markusg
5 Latest Threads
Myspace.com.exe msn virus (2)15-03-2010 19:59:00 (bippedibopp)
Not enough specific information on website about Game Mode (2)15-03-2010 18:46:01 (kerrykathy)
My computer is running slow (2)15-03-2010 18:05:53 (Dev1ce)
Can't perform a full system scan (0)15-03-2010 17:24:02 (booboo1)
Another Pesky Redirect Issue (7)15-03-2010 12:52:00 (markusg)