Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Win32/Rootkit.Agent.ODG.trojan [Closed]


  • This topic is locked This topic is locked

#1
graaf24

graaf24

    New Member

  • Member
  • Pip
  • 6 posts
After next message:
Operating memory - Win32/Rootkit.Agent.ODG.trojan - unable to clean (Real-time protection message from ESET Smart Sec.4.0.314 virus database 4025)

i find your site about this tread, start ComboFix ( ComboFix.txt attached)

WHAT NOW!

Thanks,

Graaf

Attached Files


  • 0

Advertisements


#2
handhfan

handhfan

    Trusted Helper

  • Expert
  • 13,659 posts
Hello, graaf24, and welcome to GeeksToGo!

First off, please don't use ComboFix without the direct supervision of a Malware Expert. This is a very powerful tool, and if used incorrectly, can't cause you computer to be unusable and unbootable.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

<http://www.geekstogo...n-t236409.html>

Collect::
c:\windows\system32\drivers\ovfsthxkvrvptqb.sys
c:\windows\system32\ovfsthxbcmtltoq.dll
c:\windows\system32\ovfsthxlrcrjlkt.dll
c:\windows\system32\ovfsthxnkrrnopu.dll
c:\windows\system32\ovfsthxoqxwgsfs.dat
c:\windows\system32\ovfsthxuiqhxtqy.dat

File::
I:\rtyb.cmd

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{670b94d7-8027-11dd-b2ed-4d6564696130}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{689d1d3a-21db-11de-b4ab-4d6564696130}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c827770d-ab22-11dd-b353-4d6564696130}]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ovfsthxbqvmpptn]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. Additonally, ComboFix will generate the following files on your desktop
  • A zipped file on your desktop called Submit [Date Time].zip
  • And another file named - CF-Submit.htm
6. ComboFix may need to reboot to finish its work. Let it.

7. When CF has finished running, it will generate the ComboFix.log which will appear on your screen.

8. If CF-Submit.htm is detected, ComboFix will generate this message box:

Posted Image

Clicking OK will cause the machine's browser to load CF-Submit.htm

Posted Image

9. Click the "Browse" button and locate the Submit [Date Time].zip file on your desktop.
  • Click on the file to Select it.
  • Submit the file by clicking "OK"
10. Once the file has been submitted, please DELETE both files on your desktop.

Post the ComboFix log in your next reply.

Please do not attach the log, but copy the contents of it and place it in the reply. It makes it much easier to read. :)
  • 0

#3
graaf24

graaf24

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi nice people at GeeksToGo!
Thanks for you speedy answer and help.

ComboFix.txt is below, NO Additonally genereted files on my desktop (No, ZIP & HTML)
ESET 4.0 did't find anything now!

BIG THANKS from Belgrade
Graaf
=======================================================

ComboFix 09-04-21.A7 - Cile 04/22/2009 9:26.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1495 [GMT 2:00]
Running from: c:\documents and settings\Cile\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Cile\Desktop\CFScript.txt
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated)
FW: ESET Personal firewall *enabled*

FILE ::
I:\rtyb.cmd
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\ovfsthxkvrvptqb.sys
c:\windows\system32\ovfsthxbcmtltoq.dll
c:\windows\system32\ovfsthxlrcrjlkt.dll
c:\windows\system32\ovfsthxnkrrnopu.dll
c:\windows\system32\ovfsthxoqxwgsfs.dat
c:\windows\system32\ovfsthxuiqhxtqy.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_ovfsthxbqvmpptn


((((((((((((((((((((((((( Files Created from 2009-03-22 to 2009-04-22 )))))))))))))))))))))))))))))))
.

2009-04-22 07:28 . 2009-04-22 07:33 1818 ----a-w c:\windows\system32\ovfsthxjllkvqmn.dat
2009-04-22 07:12 . 2009-04-22 07:12 -------- d-----w c:\documents and settings\Cile\Application Data\Malwarebytes
2009-04-22 07:12 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-22 07:12 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-22 07:12 . 2009-04-22 07:12 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-22 07:12 . 2009-04-22 07:12 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-20 14:03 . 2009-04-20 14:03 -------- d-----w c:\program files\iPod
2009-04-20 14:03 . 2009-04-20 14:03 -------- d-----w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-20 13:09 . 2009-04-20 13:09 663 ----a-w c:\windows\unins000.dat
2009-04-20 12:49 . 2009-04-20 12:49 -------- d-----w c:\program files\Adobe Media Player
2009-04-20 11:47 . 2009-04-20 11:47 0 ----a-w c:\windows\ativpsrm.bin
2009-04-20 11:35 . 2009-04-20 11:35 58293 ----a-w c:\windows\system32\IntelSdi.dll
2009-04-20 11:31 . 2009-04-22 07:34 3568 ----a-w c:\windows\system32\ativvaxx.cap
2009-04-20 11:31 . 2009-04-20 11:54 35328 ----a-w c:\windows\system32\atiadlxx.dll
2009-04-20 11:31 . 2009-04-20 11:54 48640 ----a-w c:\windows\system32\amdpcom32.dll
2009-04-20 11:16 . 2009-04-20 11:16 42 ----a-w c:\windows\system32\DriverChecker.lie
2009-04-20 11:16 . 2008-12-03 15:40 81408 ----a-w c:\windows\system32\devcon_x64.exe
2009-04-20 11:16 . 2002-11-14 20:32 55808 ----a-w c:\windows\system32\devcon.exe
2009-04-20 11:16 . 2009-04-20 13:43 -------- d-----w c:\program files\Driver Checker
2009-04-19 16:17 . 2009-04-19 16:31 -------- d-----w c:\program files\Common Files\DivX Shared
2009-04-15 20:24 . 2009-04-15 20:24 90112 ----a-w c:\windows\system32\dpl100.dll
2009-04-15 20:24 . 2009-04-15 20:24 823296 ----a-w c:\windows\system32\divx_xx0c.dll
2009-04-15 20:24 . 2009-04-15 20:24 823296 ----a-w c:\windows\system32\divx_xx07.dll
2009-04-15 20:24 . 2009-04-15 20:24 815104 ----a-w c:\windows\system32\divx_xx0a.dll
2009-04-15 20:24 . 2009-04-15 20:24 802816 ----a-w c:\windows\system32\divx_xx11.dll
2009-04-15 20:24 . 2009-04-15 20:24 684032 ----a-w c:\windows\system32\DivX.dll
2009-04-11 19:16 . 2009-02-27 10:55 111992 ----a-w c:\windows\system32\acaptuser32.dll
2009-04-09 08:27 . 2009-04-13 21:03 -------- d-----w c:\documents and settings\Cile\Local Settings\Application Data\FLVService
2009-04-09 08:27 . 2009-04-13 21:26 -------- d-----w c:\program files\Ask & Record Toolbar
2009-04-09 08:27 . 2009-04-09 08:27 -------- d-----w c:\windows\Ask & Record Toolbar
2009-04-07 18:05 . 2009-04-07 18:05 -------- d--h--w c:\windows\system32\GroupPolicy
2009-04-06 16:47 . 2009-04-06 16:47 134120 ----a-w c:\windows\ColorPic Uninstaller.exe
2009-04-06 16:47 . 2009-04-06 16:47 -------- d-----w c:\program files\ColorPic 4.1
2009-04-04 09:32 . 2009-04-04 09:32 -------- d-----w c:\documents and settings\Cile\Application Data\DAZ 3D
2009-04-02 16:55 . 2009-04-13 21:23 64 ---h--w c:\windows\system32\superpad8.lnf
2009-04-02 16:54 . 2009-04-02 16:54 64 ---h--w c:\windows\system32\superpad6.lnf
2009-04-02 16:54 . 2009-04-02 16:54 -------- d-----w c:\documents and settings\Cile\Application Data\Mootools
2009-04-02 16:54 . 2009-04-13 21:23 -------- d-----w c:\program files\3D Photo Browser
2009-03-31 17:08 . 2009-03-31 17:08 -------- d-----w c:\program files\MoI 1.0
2009-03-28 15:47 . 2006-08-28 16:12 13312 ----a-w c:\windows\system32\drivers\MTictwl.sys
2009-03-28 15:47 . 2009-03-28 15:47 -------- d-----w c:\program files\SEC
2009-03-27 14:29 . 2009-03-27 14:29 -------- d-----w c:\documents and settings\Cile\Local Settings\Application Data\licensecb
2009-03-27 14:29 . 2009-03-27 14:29 -------- d-----w c:\documents and settings\All Users\Application Data\licensecb
2009-03-27 14:28 . 2009-03-27 14:28 -------- d-----w c:\documents and settings\All Users\Application Data\CrazyBump
2009-03-27 14:27 . 2009-03-27 14:36 -------- d-----w c:\documents and settings\Cile\Local Settings\Application Data\CrazyBump
2009-03-25 21:52 . 2009-03-25 21:52 344494 ----a-w c:\windows\uninstall Zima.exe
2009-03-25 21:52 . 2009-03-25 21:52 4465697 ----a-w c:\windows\Zima.scr

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-21 17:15 . 2007-11-02 13:56 -------- d-----w c:\documents and settings\Cile\Application Data\MegauploadToolbar
2009-04-21 08:07 . 2008-03-19 19:31 115 ----a-w C:\VO.log
2009-04-21 08:05 . 2008-03-19 19:31 0 ----a-w C:\dxva.log
2009-04-20 14:03 . 2008-01-17 20:10 -------- d-----w c:\program files\iTunes
2009-04-20 14:03 . 2007-10-16 21:29 -------- d-----w c:\program files\Common Files\Apple
2009-04-20 13:09 . 2002-02-09 23:00 72748 ----a-w c:\windows\unins000.exe
2009-04-20 12:34 . 2008-12-07 20:42 -------- d-----w c:\program files\Common Files\Adobe AIR
2009-04-20 11:53 . 2008-09-23 18:30 -------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-04-20 11:35 . 2007-10-16 18:25 1903370 ----a-w c:\windows\system32\drivers\IntelS51.sys
2009-04-20 11:31 . 2007-08-22 01:58 143360 ----a-w c:\windows\system32\ati2evxx.dll
2009-04-19 20:49 . 2007-10-21 19:15 48497 ----a-w C:\moduleName.txt
2009-04-19 20:37 . 2007-10-16 18:34 261760 ----a-w c:\documents and settings\Cile\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-19 16:32 . 2007-10-16 18:10 -------- d-----w c:\program files\DivX
2009-04-19 09:12 . 2008-10-05 09:26 -------- d-----w c:\documents and settings\Cile\Application Data\Skype
2009-04-19 08:49 . 2008-10-05 09:33 -------- d-----w c:\documents and settings\Cile\Application Data\skypePM
2009-04-15 19:34 . 2008-08-23 10:54 -------- d-----w c:\documents and settings\Cile\Application Data\U3
2009-04-15 09:13 . 2008-01-25 08:17 106936 ---ha-w c:\windows\system32\mlfcache.dat
2009-04-13 09:58 . 2008-01-19 19:18 -------- d-----w c:\program files\Zoom Player
2009-04-12 11:48 . 2007-10-16 20:49 -------- d-----w c:\program files\Java
2009-04-11 18:06 . 2007-10-17 12:27 -------- d-----w c:\documents and settings\Cile\Application Data\VUPlayer
2009-04-09 13:21 . 2008-03-19 20:00 -------- d-----w c:\program files\DVDPean Pro 5.6.0
2009-04-07 17:16 . 2009-04-07 17:16 31 ----a-w c:\windows\system32\drivers\adidsl.cfg
2009-04-07 17:16 . 2007-10-16 18:30 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-07 17:16 . 2009-04-07 17:16 -------- d-----w c:\program files\SAGEM
2009-04-07 09:33 . 2008-02-23 15:29 -------- d-----w c:\documents and settings\Cile\Application Data\Offline Explorer
2009-04-05 12:52 . 2008-02-19 18:45 -------- d-----w c:\documents and settings\Cile\Application Data\BSplayer PRO
2009-04-04 21:22 . 2008-06-03 22:36 -------- d-----w c:\program files\Plato Video Converter
2009-04-04 09:23 . 2007-10-21 18:54 -------- d-----w c:\program files\DAZ
2009-04-02 16:54 . 2007-12-08 12:58 -------- d-----w c:\program files\Autodesk
2009-04-02 15:33 . 2009-04-02 15:33 4882 ----a-w C:\tasklist_svc.txt
2009-04-02 15:31 . 2009-04-02 15:31 65282 ----a-w C:\tasklist_m.txt
2009-03-31 17:08 . 2007-10-25 15:12 -------- d-----w c:\documents and settings\Cile\Application Data\Moi
2009-03-28 14:53 . 2008-07-24 14:48 2545 ----a-w C:\Relaxing Ocean V3Trace.txt
2009-03-25 20:39 . 2008-03-24 21:47 -------- d-----w c:\documents and settings\Cile\Application Data\Thinstall
2009-03-19 14:32 . 2008-01-29 10:01 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-17 19:11 . 2008-01-22 17:12 -------- d-----w c:\program files\Google
2009-03-14 18:52 . 2008-10-07 17:16 -------- d-----w c:\program files\Common Files\LogiShrd
2009-03-14 18:36 . 2008-10-07 17:14 -------- d-----w c:\documents and settings\All Users\Application Data\LogiShrd
2009-03-13 13:28 . 2009-03-13 13:28 -------- d-----w c:\program files\BlazeVideo
2009-03-13 13:28 . 2009-03-13 13:28 -------- d-----w c:\documents and settings\All Users\Application Data\BlazeVideo
2009-03-12 18:16 . 2009-03-12 18:15 -------- d-----w c:\documents and settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-03-12 18:11 . 2007-10-16 19:31 -------- d-----w c:\program files\QuickTime
2009-03-11 10:09 . 2009-03-11 10:09 -------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
2009-03-10 18:46 . 2009-03-10 18:46 -------- d-----w c:\program files\Microsoft Silverlight
2009-03-10 18:19 . 2008-10-07 17:19 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
2009-03-10 18:19 . 2008-10-07 18:59 0 ----a-w c:\windows\system32\drivers\logiflt.iad
2009-03-09 03:19 . 2009-01-19 18:15 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 20:51 . 2009-03-08 20:51 -------- d-----w c:\program files\:spam: Studio
2009-03-06 23:00 . 2008-08-04 19:12 -------- d-----w c:\documents and settings\Cile\Application Data\ESET
2009-03-06 22:59 . 2009-03-06 22:59 -------- d-----w c:\program files\ESET
2009-03-06 22:59 . 2008-01-07 19:00 -------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-03-06 14:17 . 2007-10-16 20:50 -------- d-----w c:\program files\Opera
2009-03-03 22:29 . 2009-03-02 13:29 2828 --sha-w c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2009-03-03 20:52 . 2008-02-01 19:56 -------- d-----w c:\program files\Moyea
2009-03-02 13:34 . 2007-12-19 17:13 -------- d-----w c:\documents and settings\Cile\Application Data\Corel
2009-03-02 13:31 . 2009-03-02 13:29 88 --sh--r c:\documents and settings\All Users\Application Data\64FC1614CF.sys
2009-03-02 13:28 . 2009-03-02 13:28 -------- d-----w c:\program files\Common Files\Protexis
2009-03-02 13:28 . 2009-03-02 13:28 -------- d-----w c:\documents and settings\All Users\Application Data\Corel
2009-03-02 13:27 . 2007-12-19 17:10 -------- d-----w c:\program files\Corel
2009-02-28 12:50 . 2007-10-17 12:34 -------- d-----w c:\documents and settings\Cile\Application Data\XnView
2009-02-28 12:44 . 2007-10-17 12:33 -------- d-----w c:\program files\XnView
2009-02-28 09:59 . 2008-02-01 20:11 -------- d-----w c:\program files\Neoretix
2009-02-27 22:15 . 2008-12-05 18:38 -------- d-----w c:\program files\Safari
2009-02-24 18:16 . 2008-01-20 12:13 -------- d-----w c:\program files\AlbumPlayer_4.9demo
2009-02-24 18:16 . 2008-01-20 09:25 -------- d-----w c:\documents and settings\Cile\Application Data\AlbumPlayer
2009-02-24 18:16 . 2008-01-20 09:25 -------- d-----w c:\documents and settings\All Users\Application Data\AlbumPlayer
2009-02-24 18:05 . 2009-02-09 20:44 -------- d-----w c:\program files\Morpheus Photo Animation Suite
2009-02-24 17:54 . 2008-01-29 19:40 -------- d-----w c:\program files\CCleaner
2009-02-24 17:42 . 2009-01-29 19:35 -------- d-----w c:\program files\Common Files\element5 Shared
2009-02-24 17:31 . 2008-01-15 14:31 -------- d-----w c:\program files\Plextor
2009-02-24 16:36 . 2009-02-24 16:36 -------- d-----w c:\documents and settings\Cile\Application Data\VSRevoGroup
2009-02-21 19:19 . 2008-01-26 19:42 -------- d-----w c:\program files\Real Desktop
2009-02-21 19:14 . 2008-01-28 19:34 -------- d-----w c:\program files\Ambient Design
2009-02-21 18:48 . 2007-10-21 12:59 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-21 18:45 . 2008-01-25 19:40 -------- d-----w c:\documents and settings\All Users\Application Data\Ashlar-Vellum
2009-02-21 18:43 . 2008-01-19 20:37 -------- d-----w c:\program files\Ashlar-Vellum
2009-02-21 18:34 . 2008-10-27 22:00 -------- d-----w c:\program files\Red Kawa
2009-02-21 18:07 . 2009-01-17 13:04 -------- d-----w c:\program files\WhereIsIt
2009-02-21 18:00 . 2008-07-25 18:02 -------- d-----w c:\program files\3D Object Converter 4.0
2009-02-21 17:55 . 2009-02-21 17:55 -------- d-----w c:\program files\VS Revo Group
2009-02-18 13:34 . 2007-10-16 18:10 129520 ------w c:\windows\system32\pxafs.dll
2009-02-18 13:34 . 2007-10-16 18:10 120568 ------w c:\windows\system32\pxcpyi64.exe
2009-02-18 13:34 . 2007-10-16 18:10 118256 ------w c:\windows\system32\pxinsi64.exe
2009-02-09 11:13 . 2004-08-04 12:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-07 13:32 . 2009-02-07 13:32 2353 ----a-w C:\audiodvd_burn.log
2009-01-29 19:35 . 2009-01-29 19:34 1696 ----a-w C:\PlexTools Professional XL.lnk
2008-01-25 20:25 . 2008-01-25 20:25 127 ----a-w c:\documents and settings\Cile\Local Settings\Application Data\fusioncache.dat
2007-10-16 18:12 . 2007-10-16 18:12 64200 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-04-15 20:2009-04-15 20:24 24:54 . c:\program files\opera\program\plugins\libdivx.dll
2009-04-15 20:2009-04-15 20:24 24:54 . c:\program files\opera\program\plugins\ssldivx.dll
2008-08-28 17:42 . 2008-08-28 17:42 32768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082820080829\index.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-04-21_15.42.12 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-22 07:34 . 2009-04-22 07:34 16384 c:\windows\Temp\Perflib_Perfdata_1fc.dat
+ 2007-10-16 17:57 . 2009-04-22 07:07 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-10-16 17:57 . 2009-04-21 13:27 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-10-16 17:57 . 2009-04-22 07:07 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-10-16 17:57 . 2009-04-21 13:27 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-10-16 17:57 . 2009-04-22 07:07 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2007-10-16 17:57 . 2009-04-21 13:27 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-23 39408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-05 177472]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2009-02-27 38768]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2009-02-27 640376]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-02-06 2021400]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"P17Helper"="P17.dll" - c:\windows\system32\P17.dll [2005-05-03 64512]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]

c:\documents and settings\Cile\Start Menu\Programs\Startup\
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2007-12-12 3746856]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-3-5 11000]
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2009-4-7 839680]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=acaptuser32.dll

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Next Limit\\Maxwell\\mxcl.exe"=
"c:\\Program Files\\Opera\\Opera.exe"=
"c:\\Program Files\\Adobe\\Adobe Photoshop CS3\\Photoshop.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
"50000:TCP"= 50000:TCP:Mezzmo Media Sharing Service

R2 EsetNod32Fix;Nod32 AV;c:\windows\Regedit.exe [2008-04-14 146432]
R2 gupdate1c99a69ac6ff312;Google Update Service (gupdate1c99a69ac6ff312);c:\program files\Google\Update\GoogleUpdate.exe [2009-03-01 133104]
R2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);c:\windows\system32\Drivers\e4ldr.sys [2006-03-02 63555]
R3 MEMSWEEP2;MEMSWEEP2; [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-02-06 727720]
S2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2007-11-21 572776]
S2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2007-11-21 572776]
S2 Stuffit Archive Name Service;Stuffit Archive Name Service;c:\program files\Smith Micro\StuffIt\ArcNameService.exe [2008-01-31 157016]
S3 e4usbaw;USB ADSL2 WAN Adapter;c:\windows\system32\DRIVERS\e4usbaw.sys [2006-05-04 114616]

.
Contents of the 'Scheduled Tasks' folder

2009-04-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2009-04-22 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-01 12:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.eunet.yu/
IE: + Offline &Explorer: Download the link - file://c:\program files\Offline Explorer Enterprise\Add_UrlO.htm
IE: + Offline E&xplorer: Download the current page - file://c:\program files\Offline Explorer Enterprise\Add_AllO.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append to existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert link target to existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Download Link Using Mega Manager... - c:\program files\Megaupload\Mega Manager\mm_file.htm
IE: Save Flash - c:\program files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/210
IE: Save YouTube Video - c:\program files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/217
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-22 09:36
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\361.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ovfsthxbqvmpptn]
"imagepath"="\systemroot\system32\drivers\ovfsthxkvrvptqb.sys"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ovfsthxbqvmpptn]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\ovfsthxkvrvptqb.sys"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1008)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2592)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\DCPFLICS\DCPFLICS.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\windows\system32\rundll32.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2009-04-22 9:43 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-22 07:43
ComboFix2.txt 2009-04-21 15:44

Pre-Run: 49,893,646,336 bytes free
Post-Run: 49,837,035,520 bytes free

322 --- E O F --- 2009-03-11 10:13
  • 0

#4
handhfan

handhfan

    Trusted Helper

  • Expert
  • 13,659 posts
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

RegLock::
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ovfsthxbqvmpptn]

Registry::
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ovfsthxbqvmpptn]

Restart::



3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


Please post the ComboFix log in your next reply.

Edited by handhfan, 23 April 2009 - 04:03 PM.

  • 0

#5
graaf24

graaf24

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts

1. Please open Notepad

  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

RegLock::
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ovfsthxbqvmpptn]

Registry::
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ovfsthxbqvmpptn]

Restart::



3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


Please post the ComboFix log in your next reply.



Hi handhfan,

ComboFix.txt is here, I'm waiting, Graaf

ComboFix 09-04-21.A7 - Cile 04/24/2009 12:55.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1527 [GMT 2:00]
Running from: c:\documents and settings\Cile\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Cile\Desktop\CFScript.txt
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated)
FW: ESET Personal firewall *enabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\ovfsthxjllkvqmn.dat

.
((((((((((((((((((((((((( Files Created from 2009-03-24 to 2009-04-24 )))))))))))))))))))))))))))))))
.

2009-04-22 10:48 . 2009-04-22 10:48 73728 ----a-w c:\windows\system32\javacpl.cpl
2009-04-22 10:48 . 2009-04-22 10:48 -------- d-----w c:\program files\Java
2009-04-22 10:29 . 2009-04-22 10:44 -------- d-----w c:\program files\MSECACHE
2009-04-22 07:12 . 2009-04-22 07:12 -------- d-----w c:\documents and settings\Cile\Application Data\Malwarebytes
2009-04-22 07:12 . 2009-04-22 07:12 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-20 14:03 . 2009-04-20 14:03 -------- d-----w c:\program files\iPod
2009-04-20 14:03 . 2009-04-20 14:03 -------- d-----w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-20 13:09 . 2009-04-20 13:09 663 ----a-w c:\windows\unins000.dat
2009-04-20 12:49 . 2009-04-20 12:49 -------- d-----w c:\program files\Adobe Media Player
2009-04-20 11:47 . 2009-04-20 11:47 0 ----a-w c:\windows\ativpsrm.bin
2009-04-20 11:35 . 2009-04-20 11:35 58293 ----a-w c:\windows\system32\IntelSdi.dll
2009-04-20 11:31 . 2009-04-24 11:04 3568 ----a-w c:\windows\system32\ativvaxx.cap
2009-04-20 11:31 . 2009-04-20 11:54 35328 ----a-w c:\windows\system32\atiadlxx.dll
2009-04-20 11:31 . 2009-04-20 11:54 48640 ----a-w c:\windows\system32\amdpcom32.dll
2009-04-20 11:16 . 2009-04-20 11:16 42 ----a-w c:\windows\system32\DriverChecker.lie
2009-04-20 11:16 . 2008-12-03 15:40 81408 ----a-w c:\windows\system32\devcon_x64.exe
2009-04-20 11:16 . 2002-11-14 20:32 55808 ----a-w c:\windows\system32\devcon.exe
2009-04-20 11:16 . 2009-04-20 13:43 -------- d-----w c:\program files\Driver Checker
2009-04-19 16:17 . 2009-04-19 16:31 -------- d-----w c:\program files\Common Files\DivX Shared
2009-04-15 20:24 . 2009-04-15 20:24 90112 ----a-w c:\windows\system32\dpl100.dll
2009-04-15 20:24 . 2009-04-15 20:24 823296 ----a-w c:\windows\system32\divx_xx0c.dll
2009-04-15 20:24 . 2009-04-15 20:24 823296 ----a-w c:\windows\system32\divx_xx07.dll
2009-04-15 20:24 . 2009-04-15 20:24 815104 ----a-w c:\windows\system32\divx_xx0a.dll
2009-04-15 20:24 . 2009-04-15 20:24 802816 ----a-w c:\windows\system32\divx_xx11.dll
2009-04-15 20:24 . 2009-04-15 20:24 684032 ----a-w c:\windows\system32\DivX.dll
2009-04-11 19:16 . 2009-02-27 10:55 111992 ----a-w c:\windows\system32\acaptuser32.dll
2009-04-09 08:27 . 2009-04-13 21:03 -------- d-----w c:\documents and settings\Cile\Local Settings\Application Data\FLVService
2009-04-09 08:27 . 2009-04-13 21:26 -------- d-----w c:\program files\Ask & Record Toolbar
2009-04-09 08:27 . 2009-04-09 08:27 -------- d-----w c:\windows\Ask & Record Toolbar
2009-04-07 18:05 . 2009-04-07 18:05 -------- d--h--w c:\windows\system32\GroupPolicy
2009-04-06 16:47 . 2009-04-06 16:47 134120 ----a-w c:\windows\ColorPic Uninstaller.exe
2009-04-06 16:47 . 2009-04-06 16:47 -------- d-----w c:\program files\ColorPic 4.1
2009-04-04 09:32 . 2009-04-04 09:32 -------- d-----w c:\documents and settings\Cile\Application Data\DAZ 3D
2009-04-02 16:55 . 2009-04-13 21:23 64 ---h--w c:\windows\system32\superpad8.lnf
2009-04-02 16:54 . 2009-04-02 16:54 64 ---h--w c:\windows\system32\superpad6.lnf
2009-04-02 16:54 . 2009-04-02 16:54 -------- d-----w c:\documents and settings\Cile\Application Data\Mootools
2009-04-02 16:54 . 2009-04-13 21:23 -------- d-----w c:\program files\3D Photo Browser
2009-03-31 17:08 . 2009-03-31 17:08 -------- d-----w c:\program files\MoI 1.0
2009-03-28 15:47 . 2006-08-28 16:12 13312 ----a-w c:\windows\system32\drivers\MTictwl.sys
2009-03-28 15:47 . 2009-03-28 15:47 -------- d-----w c:\program files\SEC
2009-03-27 14:29 . 2009-03-27 14:29 -------- d-----w c:\documents and settings\Cile\Local Settings\Application Data\licensecb
2009-03-27 14:29 . 2009-03-27 14:29 -------- d-----w c:\documents and settings\All Users\Application Data\licensecb
2009-03-27 14:28 . 2009-03-27 14:28 -------- d-----w c:\documents and settings\All Users\Application Data\CrazyBump
2009-03-27 14:27 . 2009-03-27 14:36 -------- d-----w c:\documents and settings\Cile\Local Settings\Application Data\CrazyBump
2009-03-25 21:52 . 2009-03-25 21:52 344494 ----a-w c:\windows\uninstall Zima.exe
2009-03-25 21:52 . 2009-03-25 21:52 4465697 ----a-w c:\windows\Zima.scr

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-23 17:40 . 2008-09-23 18:30 -------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-04-22 10:55 . 2007-11-02 13:56 -------- d-----w c:\documents and settings\Cile\Application Data\MegauploadToolbar
2009-04-22 10:48 . 2009-01-19 18:15 410984 ----a-w c:\windows\system32\deploytk.dll
2009-04-22 10:43 . 2009-04-22 10:03 1601 ----a-w C:\JavaRa.log
2009-04-21 08:07 . 2008-03-19 19:31 115 ----a-w C:\VO.log
2009-04-21 08:05 . 2008-03-19 19:31 0 ----a-w C:\dxva.log
2009-04-20 14:03 . 2008-01-17 20:10 -------- d-----w c:\program files\iTunes
2009-04-20 14:03 . 2007-10-16 21:29 -------- d-----w c:\program files\Common Files\Apple
2009-04-20 13:09 . 2002-02-09 23:00 72748 ----a-w c:\windows\unins000.exe
2009-04-20 12:34 . 2008-12-07 20:42 -------- d-----w c:\program files\Common Files\Adobe AIR
2009-04-20 11:35 . 2007-10-16 18:25 1903370 ----a-w c:\windows\system32\drivers\IntelS51.sys
2009-04-20 11:31 . 2007-08-22 01:58 143360 ----a-w c:\windows\system32\ati2evxx.dll
2009-04-19 20:49 . 2007-10-21 19:15 48497 ----a-w C:\moduleName.txt
2009-04-19 20:37 . 2007-10-16 18:34 261760 ----a-w c:\documents and settings\Cile\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-19 16:32 . 2007-10-16 18:10 -------- d-----w c:\program files\DivX
2009-04-19 09:12 . 2008-10-05 09:26 -------- d-----w c:\documents and settings\Cile\Application Data\Skype
2009-04-19 08:49 . 2008-10-05 09:33 -------- d-----w c:\documents and settings\Cile\Application Data\skypePM
2009-04-15 19:34 . 2008-08-23 10:54 -------- d-----w c:\documents and settings\Cile\Application Data\U3
2009-04-15 09:13 . 2008-01-25 08:17 106936 ---ha-w c:\windows\system32\mlfcache.dat
2009-04-11 18:06 . 2007-10-17 12:27 -------- d-----w c:\documents and settings\Cile\Application Data\VUPlayer
2009-04-09 13:21 . 2008-03-19 20:00 -------- d-----w c:\program files\DVDPean Pro 5.6.0
2009-04-07 17:16 . 2009-04-07 17:16 31 ----a-w c:\windows\system32\drivers\adidsl.cfg
2009-04-07 17:16 . 2007-10-16 18:30 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-07 17:16 . 2009-04-07 17:16 -------- d-----w c:\program files\SAGEM
2009-04-07 09:33 . 2008-02-23 15:29 -------- d-----w c:\documents and settings\Cile\Application Data\Offline Explorer
2009-04-05 12:52 . 2008-02-19 18:45 -------- d-----w c:\documents and settings\Cile\Application Data\BSplayer PRO
2009-04-04 21:22 . 2008-06-03 22:36 -------- d-----w c:\program files\Plato Video Converter
2009-04-04 09:23 . 2007-10-21 18:54 -------- d-----w c:\program files\DAZ
2009-04-02 16:54 . 2007-12-08 12:58 -------- d-----w c:\program files\Autodesk
2009-04-02 15:33 . 2009-04-02 15:33 4882 ----a-w C:\tasklist_svc.txt
2009-04-02 15:31 . 2009-04-02 15:31 65282 ----a-w C:\tasklist_m.txt
2009-03-31 17:08 . 2007-10-25 15:12 -------- d-----w c:\documents and settings\Cile\Application Data\Moi
2009-03-28 14:53 . 2008-07-24 14:48 2545 ----a-w C:\Relaxing Ocean V3Trace.txt
2009-03-25 20:39 . 2008-03-24 21:47 -------- d-----w c:\documents and settings\Cile\Application Data\Thinstall
2009-03-19 14:32 . 2008-01-29 10:01 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-17 19:11 . 2008-01-22 17:12 -------- d-----w c:\program files\Google
2009-03-14 18:52 . 2008-10-07 17:16 -------- d-----w c:\program files\Common Files\LogiShrd
2009-03-14 18:36 . 2008-10-07 17:14 -------- d-----w c:\documents and settings\All Users\Application Data\LogiShrd
2009-03-13 13:28 . 2009-03-13 13:28 -------- d-----w c:\program files\BlazeVideo
2009-03-13 13:28 . 2009-03-13 13:28 -------- d-----w c:\documents and settings\All Users\Application Data\BlazeVideo
2009-03-12 18:16 . 2009-03-12 18:15 -------- d-----w c:\documents and settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-03-12 18:11 . 2007-10-16 19:31 -------- d-----w c:\program files\QuickTime
2009-03-11 10:09 . 2009-03-11 10:09 -------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
2009-03-10 18:46 . 2009-03-10 18:46 -------- d-----w c:\program files\Microsoft Silverlight
2009-03-10 18:19 . 2008-10-07 17:19 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
2009-03-10 18:19 . 2008-10-07 18:59 0 ----a-w c:\windows\system32\drivers\logiflt.iad
2009-03-08 20:51 . 2009-03-08 20:51 -------- d-----w c:\program files\:spam: Studio
2009-03-06 23:00 . 2008-08-04 19:12 -------- d-----w c:\documents and settings\Cile\Application Data\ESET
2009-03-06 22:59 . 2009-03-06 22:59 -------- d-----w c:\program files\ESET
2009-03-06 22:59 . 2008-01-07 19:00 -------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-03-06 14:17 . 2007-10-16 20:50 -------- d-----w c:\program files\Opera
2009-03-03 22:29 . 2009-03-02 13:29 2828 --sha-w c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2009-03-03 20:52 . 2008-02-01 19:56 -------- d-----w c:\program files\Moyea
2009-03-02 13:34 . 2007-12-19 17:13 -------- d-----w c:\documents and settings\Cile\Application Data\Corel
2009-03-02 13:31 . 2009-03-02 13:29 88 --sh--r c:\documents and settings\All Users\Application Data\64FC1614CF.sys
2009-03-02 13:28 . 2009-03-02 13:28 -------- d-----w c:\program files\Common Files\Protexis
2009-03-02 13:28 . 2009-03-02 13:28 -------- d-----w c:\documents and settings\All Users\Application Data\Corel
2009-03-02 13:27 . 2007-12-19 17:10 -------- d-----w c:\program files\Corel
2009-02-28 12:50 . 2007-10-17 12:34 -------- d-----w c:\documents and settings\Cile\Application Data\XnView
2009-02-28 12:44 . 2007-10-17 12:33 -------- d-----w c:\program files\XnView
2009-02-28 09:59 . 2008-02-01 20:11 -------- d-----w c:\program files\Neoretix
2009-02-27 22:15 . 2008-12-05 18:38 -------- d-----w c:\program files\Safari
2009-02-24 18:16 . 2008-01-20 12:13 -------- d-----w c:\program files\AlbumPlayer_4.9demo
2009-02-24 18:16 . 2008-01-20 09:25 -------- d-----w c:\documents and settings\Cile\Application Data\AlbumPlayer
2009-02-24 18:16 . 2008-01-20 09:25 -------- d-----w c:\documents and settings\All Users\Application Data\AlbumPlayer
2009-02-24 18:05 . 2009-02-09 20:44 -------- d-----w c:\program files\Morpheus Photo Animation Suite
2009-02-24 17:54 . 2008-01-29 19:40 -------- d-----w c:\program files\CCleaner
2009-02-24 17:42 . 2009-01-29 19:35 -------- d-----w c:\program files\Common Files\element5 Shared
2009-02-24 17:31 . 2008-01-15 14:31 -------- d-----w c:\program files\Plextor
2009-02-24 16:36 . 2009-02-24 16:36 -------- d-----w c:\documents and settings\Cile\Application Data\VSRevoGroup
2009-02-18 13:34 . 2007-10-16 18:10 129520 ------w c:\windows\system32\pxafs.dll
2009-02-18 13:34 . 2007-10-16 18:10 120568 ------w c:\windows\system32\pxcpyi64.exe
2009-02-18 13:34 . 2007-10-16 18:10 118256 ------w c:\windows\system32\pxinsi64.exe
2009-02-09 11:13 . 2004-08-04 12:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-07 13:32 . 2009-02-07 13:32 2353 ----a-w C:\audiodvd_burn.log
2009-01-29 19:35 . 2009-01-29 19:34 1696 ----a-w C:\PlexTools Professional XL.lnk
2008-01-25 20:25 . 2008-01-25 20:25 127 ----a-w c:\documents and settings\Cile\Local Settings\Application Data\fusioncache.dat
2007-10-16 18:12 . 2007-10-16 18:12 64200 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-04-15 20:2009-04-15 20:24 24:54 . c:\program files\opera\program\plugins\libdivx.dll
2009-04-15 20:2009-04-15 20:24 24:54 . c:\program files\opera\program\plugins\ssldivx.dll
2008-08-28 17:42 . 2008-08-28 17:42 32768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082820080829\index.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-04-21_15.42.12 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-24 11:04 . 2009-04-24 11:04 16384 c:\windows\temp\Perflib_Perfdata_254.dat
+ 2007-10-16 17:57 . 2009-04-22 07:07 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-10-16 17:57 . 2009-04-21 13:27 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-10-16 17:57 . 2009-04-22 07:07 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-10-16 17:57 . 2009-04-21 13:27 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-10-16 17:57 . 2009-04-21 13:27 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2007-10-16 17:57 . 2009-04-22 07:07 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-04-22 10:48 . 2009-04-22 10:48 148888 c:\windows\system32\javaws.exe
- 2009-04-12 11:48 . 2009-03-09 03:19 148888 c:\windows\system32\javaws.exe
+ 2009-04-22 10:48 . 2009-04-22 10:48 144792 c:\windows\system32\javaw.exe
- 2009-04-12 11:48 . 2009-03-09 03:19 144792 c:\windows\system32\javaw.exe
+ 2009-04-22 10:48 . 2009-04-22 10:48 144792 c:\windows\system32\java.exe
- 2009-04-12 11:48 . 2009-03-09 03:19 144792 c:\windows\system32\java.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-23 39408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-05 177472]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2009-02-27 38768]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2009-02-27 640376]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-02-06 2021400]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-22 148888]
"P17Helper"="P17.dll" - c:\windows\system32\P17.dll [2005-05-03 64512]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]

c:\documents and settings\Cile\Start Menu\Programs\Startup\
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2007-12-12 3746856]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-3-5 11000]
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2009-4-7 839680]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=acaptuser32.dll

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Next Limit\\Maxwell\\mxcl.exe"=
"c:\\Program Files\\Opera\\Opera.exe"=
"c:\\Program Files\\Adobe\\Adobe Photoshop CS3\\Photoshop.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
"50000:TCP"= 50000:TCP:Mezzmo Media Sharing Service

R2 EsetNod32Fix;Nod32 AV;c:\windows\Regedit.exe [2008-04-14 146432]
R2 gupdate1c99a69ac6ff312;Google Update Service (gupdate1c99a69ac6ff312);c:\program files\Google\Update\GoogleUpdate.exe [2009-03-01 133104]
R2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);c:\windows\system32\Drivers\e4ldr.sys [2006-03-02 63555]
R3 MEMSWEEP2;MEMSWEEP2; [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-02-06 727720]
S2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2007-11-21 572776]
S2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2007-11-21 572776]
S2 Stuffit Archive Name Service;Stuffit Archive Name Service;c:\program files\Smith Micro\StuffIt\ArcNameService.exe [2008-01-31 157016]
S3 e4usbaw;USB ADSL2 WAN Adapter;c:\windows\system32\DRIVERS\e4usbaw.sys [2006-05-04 114616]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e1e88180-7101-11dd-b2c7-4d6564696130}]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2009-04-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2009-04-24 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-01 12:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.eunet.yu/
IE: + Offline &Explorer: Download the link - file://c:\program files\Offline Explorer Enterprise\Add_UrlO.htm
IE: + Offline E&xplorer: Download the current page - file://c:\program files\Offline Explorer Enterprise\Add_AllO.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append to existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert link target to existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Download Link Using Mega Manager... - c:\program files\Megaupload\Mega Manager\mm_file.htm
IE: Save Flash - c:\program files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/210
IE: Save YouTube Video - c:\program files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/217
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-24 13:04
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\windows\TEMP\NODA.tmp 287223 bytes
c:\windows\TEMP\NODB.tmp 0 bytes

scan completed successfully
hidden files: 2

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\361.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1008)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3316)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\DCPFLICS\DCPFLICS.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\windows\system32\rundll32.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2009-04-24 13:12 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-24 11:12
ComboFix2.txt 2009-04-22 07:43
ComboFix3.txt 2009-04-21 15:44

Pre-Run: 49,479,868,416 bytes free
Post-Run: 49,466,044,416 bytes free

303 --- E O F --- 2009-03-11 10:13
  • 0

#6
handhfan

handhfan

    Trusted Helper

  • Expert
  • 13,659 posts
  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

  • 0

#7
graaf24

graaf24

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi again,

here is reports:

OTListIt.Txt
----------------------------------------
OTListIt logfile created on: 4/25/2009 8:07:42 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Cile\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.47 Gb Available Physical Memory | 73.54% Memory free
3.85 Gb Paging File | 3.46 Gb Available in Paging File | 89.79% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 117.19 Gb Total Space | 45.98 Gb Free Space | 39.24% Space Free | Partition Type: NTFS
Drive D: | 255.41 Gb Total Space | 48.30 Gb Free Space | 18.91% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 372.61 Gb Total Space | 36.08 Gb Free Space | 9.68% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded

Computer Name: CILE-452CCE298C
Current User Name: Cile
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\DCPFLICS\DCPFLICS.exe ()
PRC - C:\Program Files\ESET\ESET Smart Security\ekrn.exe (ESET)
PRC - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
PRC - C:\Program Files\iolo\common\lib\ioloServiceManager.exe ()
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe ()
PRC - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Smith Micro\StuffIt\ArcNameService.exe (Smith Micro Software, Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE (Advanced Micro Devices Inc.)
PRC - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe ()
PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe (Yahoo! Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe (Yahoo! Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Documents and Settings\Cile\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe Version Cue CS3 [On_Demand | Stopped]) -- C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (Adobe Systems Incorporated)
SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) -- C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) -- C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (Autodesk Licensing Service [Auto | Running]) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DCPFLICS [Auto | Running]) -- C:\Program Files\DCPFLICS\DCPFLICS.exe ()
SRV - (EhttpSrv [On_Demand | Stopped]) -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe (ESET)
SRV - (ekrn [Auto | Running]) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe (ESET)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gupdate1c99a69ac6ff312 [Auto | Stopped]) -- C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [Auto | Running]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (ioloFileInfoList [Auto | Running]) -- C:\Program Files\iolo\common\lib\ioloServiceManager.exe ()
SRV - (ioloSystemService [Auto | Running]) -- C:\Program Files\iolo\common\lib\ioloServiceManager.exe ()
SRV - (iPod Service [On_Demand | Running]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (MDM [Auto | Running]) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (mi-raysat_3dsmax9_32 [Auto | Running]) -- C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe ()
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NMIndexingService [On_Demand | Stopped]) -- C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (Nero AG)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PSI_SVC_2 [Auto | Running]) -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (Stuffit Archive Name Service [Auto | Running]) -- C:\Program Files\Smith Micro\StuffIt\ArcNameService.exe (Smith Micro Software, Inc.)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (Aspi32 [System | Running]) -- C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)
DRV - (ati2mtag [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ctsfm2k [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys (Creative Technology Ltd)
DRV - (e4usbaw [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\e4usbaw.sys (Analog Devices Inc.)
DRV - (eamon [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\eamon.sys (ESET)
DRV - (ehdrv [System | Running]) -- C:\WINDOWS\system32\DRIVERS\ehdrv.sys (ESET)
DRV - (epfw [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\epfw.sys (ESET)
DRV - (Epfwndis [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\Epfwndis.sys (ESET)
DRV - (epfwtdi [System | Running]) -- C:\WINDOWS\system32\DRIVERS\epfwtdi.sys (ESET)
DRV - (FileDisk [System | Running]) -- C:\WINDOWS\System32\drivers\filedisk.sys (iolo technologies, LLC (based on original work by Bo Brantén))
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (IKANLOADER2 [Auto | Stopped]) -- C:\WINDOWS\System32\Drivers\e4ldr.sys (Analog Deivces)
DRV - (Intels51 [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\Intels51.sys (Intel Corporation)
DRV - (LVUVC [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\lvuvc.hs ()
DRV - (MagicTune [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\MTiCtwl.sys ()
DRV - (MODEMCSA [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (ossrv [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ctoss2k.sys (Creative Technology Ltd.)
DRV - (P17 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (Pcouffin [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\Pcouffin.sys (VSO Software)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sptd [Boot | Running]) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (usbaudio [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (yukonwxp [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\yukonwxp.sys (Marvell Semiconductor Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.eunet.yu/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/04/22 12:48:09 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\PROGRAM FILES\ESET\ESET SMART SECURITY\MOZILLA THUNDERBIRD


O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Megaupload Toolbar) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\Program Files\MegauploadToolbar\megauploadtoolbar.dll (MEGAUPLOAD )
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (Google Inc.)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - Reg Error: Key error. File not found
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (IEButton Class) - {F81D52BF-F2F1-4F49-BF5F-05664E803039} - C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll (UnH Solutions)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Megaupload Toolbar) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\Program Files\MegauploadToolbar\megauploadtoolbar.dll (MEGAUPLOAD )
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\Program Files\MegauploadToolbar\megauploadtoolbar.dll (MEGAUPLOAD )
O4 - HKLM..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent (Microsoft Corporation)
O4 - HKLM..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice (ESET)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [P17Helper] Rundll32 P17.dll,P17Helper ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" ()
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe (Autodesk, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe ()
O4 - Startup: C:\Documents and Settings\Cile\Start Menu\Programs\Startup\Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe (Yahoo! Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: + Offline &Explorer: Download the link - file://C:\Program Files\Offline Explorer Enterprise\Add_UrlO.htm File not found
O8 - Extra context menu item: + Offline E&xplorer: Download the current page - file://C:\Program Files\Offline Explorer Enterprise\Add_AllO.htm File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 (Google Inc.)
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm ()
O8 - Extra context menu item: Save Flash - res://C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/210 (UnH Solutions)
O8 - Extra context menu item: Save YouTube Video - res://C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/217 (UnH Solutions)
O9 - Extra Button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - Reg Error: Key error. File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [Bluetooth Namespace] - C:\WINDOWS\system32\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\dadb {82D6F09F-4AC2-11D3-8BD9-0080ADB8683C} - C:\Program Files\OrangeCD\dadb.dll (Firetongue Software)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (acaptuser32.dll) - C:\WINDOWS\system32\acaptuser32.dll (Adobe Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{e1e88180-7101-11dd-b2c7-4d6564696130}\Shell - "" = AutoRun
O33 - MountPoints2\{e1e88180-7101-11dd-b2c7-4d6564696130}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e1e88180-7101-11dd-b2c7-4d6564696130}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\*.tmp files]
[2009/04/25 20:05:24 | 00,540,135 | ---- | C] () -- C:\Documents and Settings\Cile\Desktop\Win32_Rootkit.Agent.ODG.trojan-3.mht
[2009/04/25 20:04:12 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Cile\Desktop\OTListIt2.exe
[2009/04/25 14:39:12 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe
[2009/04/24 13:35:48 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2009/04/24 13:01:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
[2009/04/24 10:39:13 | 01,079,808 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\Malica.pps
[2009/04/23 15:46:33 | 03,354,774 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\DrvoZibota1.obj
[2009/04/22 21:15:42 | 00,159,900 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\Pamela Wyn Shannon - Courting Autumn - 2007.jpg
[2009/04/22 12:48:04 | 00,000,000 | ---D | C] -- C:\Program Files\Java
[2009/04/22 12:29:05 | 00,000,000 | ---D | C] -- C:\Program Files\MSECACHE
[2009/04/22 09:12:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Cile\Application Data\Malwarebytes
[2009/04/22 09:12:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/21 17:35:57 | 00,000,211 | ---- | C] () -- C:\Boot.bak
[2009/04/21 17:35:53 | 00,260,272 | ---- | C] () -- C:\cmldr
[2009/04/21 17:35:52 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009/04/21 17:34:03 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/04/21 17:34:03 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/04/21 17:34:03 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/04/21 17:34:03 | 00,109,568 | ---- | C] () -- C:\WINDOWS\vFind.exe
[2009/04/21 17:34:03 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/04/21 17:34:03 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/04/21 17:34:03 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/04/21 17:34:03 | 00,029,696 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/04/21 17:33:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/04/21 17:33:16 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/04/21 17:30:41 | 02,998,641 | R--- | C] () -- C:\Documents and Settings\Cile\Desktop\ComboFix.exe
[2009/04/20 16:03:08 | 00,000,000 | ---D | C] -- C:\Program Files\iPod
[2009/04/20 16:03:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/04/20 15:16:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Cile\Desktop\Web Razno
[2009/04/20 15:14:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Cile\Desktop\Katalozi
[2009/04/20 15:09:55 | 00,000,663 | ---- | C] () -- C:\WINDOWS\unins000.dat
[2009/04/20 14:49:38 | 00,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Media Player.lnk
[2009/04/20 14:49:37 | 00,000,000 | ---D | C] -- C:\Program Files\Adobe Media Player
[2009/04/20 13:47:50 | 00,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2009/04/20 13:31:53 | 00,003,568 | ---- | C] () -- C:\WINDOWS\System32\ativvaxx.cap
[2009/04/20 13:16:54 | 00,000,042 | ---- | C] () -- C:\WINDOWS\System32\DriverChecker.lie
[2009/04/20 13:16:16 | 00,081,408 | ---- | C] (Windows ® Codename Longhorn DDK provider) -- C:\WINDOWS\System32\devcon_x64.exe
[2009/04/20 13:16:16 | 00,055,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\devcon.exe
[2009/04/20 13:16:16 | 00,000,685 | ---- | C] () -- C:\Documents and Settings\Cile\Desktop\Driver Checker.lnk
[2009/04/20 13:16:14 | 00,000,000 | ---D | C] -- C:\Program Files\Driver Checker
[2009/04/19 23:56:34 | 00,822,250 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\drvo zivota.3dm
[2009/04/19 23:53:16 | 00,111,647 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\drvo-zivota.jpg
[2009/04/19 18:38:37 | 00,000,795 | ---- | C] () -- C:\Documents and Settings\Cile\Desktop\DivX Player.lnk
[2009/04/19 18:17:34 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\DivX Shared
[2009/04/18 18:55:57 | 00,310,795 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\Srecan-Vaskrs---2009.jpg
[2009/04/18 18:41:02 | 01,122,119 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\Vasilija Radojcic - Na Uskrs Sam Se Rodila.mp3
[2009/04/17 19:54:53 | 00,060,396 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\band_detail.jpg
[2009/04/17 19:54:07 | 00,108,156 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\front_cover_small.jpg
[2009/04/16 17:45:40 | 00,141,529 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\Piletina-sa-bukovacama-i-pelatom.jpg
[2009/04/15 22:24:40 | 00,090,112 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\dpl100.dll
[2009/04/15 22:24:38 | 00,823,296 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\divx_xx0c.dll
[2009/04/15 22:24:38 | 00,823,296 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\divx_xx07.dll
[2009/04/15 22:24:38 | 00,815,104 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\divx_xx0a.dll
[2009/04/15 22:24:38 | 00,802,816 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\divx_xx11.dll
[2009/04/15 22:24:38 | 00,684,032 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\DivX.dll
[2009/04/15 22:05:56 | 00,031,267 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\Cile_Perish.jpg
[2009/04/15 21:26:09 | 00,015,360 | ---- | C] () -- C:\Documents and Settings\Cile\Desktop\CileEXEL.xls
[2009/04/15 11:58:14 | 00,030,182 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\collin14[1].jpg
[2009/04/11 21:16:49 | 00,111,992 | ---- | C] (Adobe Systems, Inc.) -- C:\WINDOWS\System32\acaptuser32.dll
[2009/04/11 20:54:49 | 00,000,500 | ---- | C] () -- C:\Documents and Settings\Cile\Desktop\Cathy - SVE.lnk
[2009/04/11 15:18:45 | 00,019,968 | ---- | C] () -- C:\Documents and Settings\Cile\Desktop\Pele-excel.xls
[2009/04/11 14:00:58 | 00,025,600 | ---- | C] () -- C:\Documents and Settings\Cile\Desktop\Neda informatika.xls
[2009/04/11 00:12:00 | 00,020,645 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\PrayerForCompassionOverleaf_lg.jpg
[2009/04/11 00:11:58 | 00,032,320 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\PrayerForCompassionBack_lg.jpg
[2009/04/11 00:11:54 | 00,023,848 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\PrayerForCompassion_lg.jpg
[2009/04/09 16:57:08 | 00,085,074 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\adsl.cilegraaf_uplata_03_2009.jpg
[2009/04/09 10:27:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Cile\Application Data\Mozilla
[2009/04/09 10:27:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Cile\My Documents\Ask and Record Toolbar
[2009/04/09 10:27:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Cile\Local Settings\Application Data\FLVService
[2009/04/09 10:27:00 | 00,000,000 | ---D | C] -- C:\WINDOWS\Ask & Record Toolbar
[2009/04/09 10:27:00 | 00,000,000 | ---D | C] -- C:\Program Files\Ask & Record Toolbar
[2009/04/07 20:05:30 | 00,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
[2009/04/07 19:16:38 | 00,000,560 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Internet ADSL.lnk
[2009/04/07 19:16:37 | 00,000,169 | ---- | C] () -- C:\WINDOWS\adidsl.ini
[2009/04/07 19:16:37 | 00,000,021 | ---- | C] () -- C:\WINDOWS\Fast800.ini
[2009/04/07 19:16:30 | 00,143,360 | ---- | C] () -- C:\WINDOWS\adiras.exe
[2009/04/07 19:16:29 | 00,126,489 | ---- | C] (Analog Devices Inc.) -- C:\WINDOWS\System32\drivers\adiusbaw.sys
[2009/04/07 19:16:29 | 00,114,616 | ---- | C] (Analog Devices Inc.) -- C:\WINDOWS\System32\drivers\e4usbaw.sys
[2009/04/07 19:16:29 | 00,012,169 | ---- | C] () -- C:\WINDOWS\System32\drivers\adiusbaw.cat
[2009/04/07 19:16:29 | 00,010,442 | ---- | C] () -- C:\WINDOWS\System32\drivers\e4usbaw.cat
[2009/04/07 19:16:28 | 00,155,648 | ---- | C] (Analog Devices Inc.) -- C:\WINDOWS\System32\adadix32.dll
[2009/04/07 19:16:28 | 00,127,456 | ---- | C] () -- C:\WINDOWS\System32\IPDETECT.EXE
[2009/04/07 19:16:27 | 00,024,576 | ---- | C] () -- C:\WINDOWS\enddisk32.exe
[2009/04/07 19:16:27 | 00,000,655 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DSLMON.lnk
[2009/04/07 19:16:26 | 00,152,126 | ---- | C] () -- C:\WINDOWS\System32\drivers\L1E9P2.BIN
[2009/04/07 19:16:26 | 00,152,126 | ---- | C] () -- C:\WINDOWS\System32\drivers\L1E9I2.BIN
[2009/04/07 19:16:26 | 00,135,168 | ---- | C] (Analog Devices.) -- C:\WINDOWS\System32\unaddrv.exe
[2009/04/07 19:16:26 | 00,126,976 | ---- | C] () -- C:\WINDOWS\System32\coclassfast.dll
[2009/04/07 19:16:26 | 00,063,555 | ---- | C] (Analog Deivces) -- C:\WINDOWS\System32\drivers\e4ldr.sys
[2009/04/07 19:16:26 | 00,050,007 | ---- | C] (Analog Deivces) -- C:\WINDOWS\System32\drivers\adildr.sys
[2009/04/07 19:16:26 | 00,046,892 | ---- | C] () -- C:\WINDOWS\System32\ADADIX16.DLL
[2009/04/07 19:16:26 | 00,008,412 | ---- | C] () -- C:\WINDOWS\System32\drivers\adildr.cat
[2009/04/07 19:16:26 | 00,007,924 | ---- | C] () -- C:\WINDOWS\System32\drivers\e4ldr.cat
[2009/04/07 19:16:26 | 00,004,981 | ---- | C] (SITECSOFT Co., LTD.) -- C:\WINDOWS\System32\ADADIX2K.DLL
[2009/04/07 19:16:25 | 00,261,964 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbldep3.bnm
[2009/04/07 19:16:25 | 00,261,964 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld9i1.bnm
[2009/04/07 19:16:25 | 00,261,962 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld9p3.bnm
[2009/04/07 19:16:25 | 00,261,960 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbldep1.bnm
[2009/04/07 19:16:25 | 00,261,960 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld9i0.bnm
[2009/04/07 19:16:25 | 00,261,952 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld9p1.bnm
[2009/04/07 19:16:25 | 00,261,952 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld3.bnm
[2009/04/07 19:16:25 | 00,261,932 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld0.bnm
[2009/04/07 19:16:25 | 00,261,930 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld9p0.bnm
[2009/04/07 19:16:25 | 00,261,926 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbldei1.bnm
[2009/04/07 19:16:25 | 00,261,926 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld9p2.bnm
[2009/04/07 19:16:25 | 00,261,926 | ---- | C] () -- C:\WINDOWS\System32\drivers\RTBLD3p0.BNM
[2009/04/07 19:16:25 | 00,261,920 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld2.bnm
[2009/04/07 19:16:25 | 00,261,918 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld9i2.bnm
[2009/04/07 19:16:25 | 00,261,918 | ---- | C] () -- C:\WINDOWS\System32\drivers\RTBLD3p3.BNM
[2009/04/07 19:16:25 | 00,261,918 | ---- | C] () -- C:\WINDOWS\System32\drivers\RTBLD3p1.BNM
[2009/04/07 19:16:25 | 00,261,916 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbldep0.bnm
[2009/04/07 19:16:25 | 00,261,916 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbldei0.bnm
[2009/04/07 19:16:25 | 00,261,914 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbldei2.bnm
[2009/04/07 19:16:25 | 00,261,908 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbldei3.bnm
[2009/04/07 19:16:25 | 00,261,900 | ---- | C] () -- C:\WINDOWS\System32\drivers\RTBLD3p2.BNM
[2009/04/07 19:16:25 | 00,261,894 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld1.bnm
[2009/04/07 19:16:25 | 00,261,892 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbldep2.bnm
[2009/04/07 19:16:25 | 00,152,308 | ---- | C] () -- C:\WINDOWS\System32\drivers\L1E4I2.BIN
[2009/04/07 19:16:25 | 00,152,306 | ---- | C] () -- C:\WINDOWS\System32\drivers\L1E4I1.BIN
[2009/04/07 19:16:25 | 00,152,306 | ---- | C] () -- C:\WINDOWS\System32\drivers\L1E4I0.BIN
[2009/04/07 19:16:25 | 00,152,146 | ---- | C] () -- C:\WINDOWS\System32\drivers\L1E4P2.BIN
[2009/04/07 19:16:25 | 00,152,145 | ---- | C] () -- C:\WINDOWS\System32\drivers\L1E4P1.BIN
[2009/04/07 19:16:25 | 00,152,145 | ---- | C] () -- C:\WINDOWS\System32\drivers\L1E4P0.BIN
[2009/04/07 19:16:25 | 00,152,126 | ---- | C] () -- C:\WINDOWS\System32\drivers\L1E9P1.BIN
[2009/04/07 19:16:25 | 00,152,126 | ---- | C] () -- C:\WINDOWS\System32\drivers\L1E9P0.BIN
[2009/04/07 19:16:25 | 00,152,126 | ---- | C] () -- C:\WINDOWS\System32\drivers\L1E9I1.BIN
[2009/04/07 19:16:25 | 00,152,126 | ---- | C] () -- C:\WINDOWS\System32\drivers\L1E9I0.BIN
[2009/04/07 19:16:25 | 00,152,036 | ---- | C] () -- C:\WINDOWS\System32\drivers\L1E4D2.BIN
[2009/04/07 19:16:25 | 00,152,034 | ---- | C] () -- C:\WINDOWS\System32\drivers\L1E4D1.BIN
[2009/04/07 19:16:25 | 00,152,034 | ---- | C] () -- C:\WINDOWS\System32\drivers\L1E4D0.BIN
[2009/04/07 19:16:25 | 00,081,088 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbldep4.bnm
[2009/04/07 19:16:25 | 00,078,040 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbldei4.bnm
[2009/04/07 19:16:25 | 00,055,228 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld4.bnm
[2009/04/07 19:16:25 | 00,053,590 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld9i4.bnm
[2009/04/07 19:16:25 | 00,041,620 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld9p4.bnm
[2009/04/07 19:16:25 | 00,022,395 | ---- | C] () -- C:\WINDOWS\System32\drivers\fpga.bin
[2009/04/07 19:16:25 | 00,022,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\RTBLD3p4.BNM
[2009/04/07 19:16:25 | 00,000,031 | ---- | C] () -- C:\WINDOWS\System32\drivers\adidsl.cfg
[2009/04/07 19:16:24 | 00,176,128 | ---- | C] () -- C:\WINDOWS\autoclk.exe
[2009/04/07 19:16:00 | 00,000,000 | ---D | C] -- C:\Program Files\SAGEM
[2009/04/06 22:18:52 | 06,313,787 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\Catedral de La Seo en Zaragoza v7.skp
[2009/04/06 22:13:52 | 06,312,374 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\Catedral de La Seo en Zaragoza.skp
[2009/04/06 22:12:24 | 01,389,154 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\El Pilar de Zaragoza_google_4.skp
[2009/04/06 18:47:39 | 00,134,120 | ---- | C] () -- C:\WINDOWS\ColorPic Uninstaller.exe
[2009/04/06 18:47:39 | 00,000,712 | ---- | C] () -- C:\Documents and Settings\Cile\Desktop\ColorPic.lnk
[2009/04/06 18:47:36 | 00,000,000 | ---D | C] -- C:\Program Files\ColorPic 4.1
[2009/04/05 10:12:42 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Cile\Desktop\Sindik privremeno
[2009/04/04 11:32:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Cile\My Documents\DAZ 3D
[2009/04/04 11:32:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Cile\Application Data\DAZ 3D
[2009/04/03 08:48:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Cile\Desktop\CD-RW privremeno
[2009/04/02 18:55:10 | 00,000,064 | -H-- | C] () -- C:\WINDOWS\System32\superpad8.lnf
[2009/04/02 18:54:47 | 00,000,064 | -H-- | C] () -- C:\WINDOWS\System32\superpad6.lnf
[2009/04/02 18:54:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Cile\Application Data\Mootools
[2009/04/02 18:54:00 | 00,000,000 | ---D | C] -- C:\Program Files\3D Photo Browser
[2009/04/02 18:42:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Cile\My Documents\Neda PPS neiskoriceno
[2009/04/01 22:04:33 | 00,116,224 | -HS- | C] () -- C:\Documents and Settings\Cile\My Documents\Thumbs.db
[2009/04/01 21:50:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Cile\My Documents\Neda PPS
[2009/03/31 20:14:16 | 00,142,465 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\Vase.3dm
[2009/03/31 20:13:46 | 00,672,583 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\Vase.3ds
[2009/03/31 20:00:02 | 00,398,418 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\HandbookOfOrnament-(slika-305).jpg
[2009/03/31 19:56:48 | 00,073,958 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\HandbookOfOrnament (slika 305).pdf
[2009/03/31 19:09:48 | 00,013,085 | ---- | C] () -- C:\Documents and Settings\Cile\My Documents\proba MOI.3dm
[2009/03/31 19:08:33 | 00,000,000 | ---D | C] -- C:\Program Files\MoI 1.0
[2009/03/28 17:47:49 | 00,013,312 | ---- | C] () -- C:\WINDOWS\System32\drivers\MTictwl.sys
[2009/03/28 17:47:37 | 00,000,000 | ---D | C] -- C:\Program Files\SEC
[2009/03/27 16:29:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Cile\Local Settings\Application Data\licensecb
[2009/03/27 16:29:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\licensecb
[2009/03/27 16:28:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\CrazyBump
[2009/03/27 16:27:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Cile\Local Settings\Application Data\CrazyBump
[2009/03/27 13:51:58 | 00,001,834 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Lightroom 2.3.lnk
[2009/03/16 18:00:18 | 00,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
[2009/03/08 22:51:46 | 00,135,168 | ---- | C] () -- C:\WINDOWS\System32\DVDIFOFilter.dll
[2009/02/21 18:56:42 | 00,001,084 | ---- | C] () -- C:\WINDOWS\System32\ASPRTMM8.DLL
[2009/02/14 20:36:48 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009/02/07 15:15:28 | 00,000,221 | ---- | C] () -- C:\WINDOWS\AudioDVD.INI
[2008/11/21 23:47:52 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/11/21 23:45:16 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2008/09/11 21:23:06 | 00,000,116 | ---- | C] () -- C:\WINDOWS\ppdrv.ini
[2008/08/05 21:43:23 | 00,000,400 | ---- | C] () -- C:\WINDOWS\g_iclink319.ini
[2008/06/19 18:14:08 | 06,131,712 | ---- | C] () -- C:\WINDOWS\System32\daz-qt-mt.dll
[2008/06/19 18:14:08 | 02,076,672 | ---- | C] () -- C:\WINDOWS\System32\dz3delight.dll
[2008/06/19 18:14:08 | 01,785,856 | ---- | C] () -- C:\WINDOWS\System32\daz-qsa.dll
[2008/06/04 21:31:15 | 00,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2008/03/20 20:31:13 | 00,000,363 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2008/03/09 14:20:54 | 00,000,067 | ---- | C] () -- C:\WINDOWS\#1 DVD Ripper.INI
[2008/03/09 13:48:29 | 00,000,042 | ---- | C] () -- C:\WINDOWS\AlchemyMindworksUpdateList.INI
[2008/02/29 22:36:21 | 00,000,040 | ---- | C] () -- C:\WINDOWS\System32\hrwd8.dll
[2008/02/09 17:15:31 | 00,074,703 | ---- | C] () -- C:\WINDOWS\System32\mfc45.dll
[2008/01/28 21:25:13 | 00,000,014 | ---- | C] () -- C:\WINDOWS\System32\SystemInfo32.sys
[2008/01/23 17:57:21 | 00,000,081 | ---- | C] () -- C:\WINDOWS\GetFLV.ini
[2008/01/17 22:32:06 | 00,000,000 | ---- | C] () -- C:\WINDOWS\AoADVDRipper.INI
[2007/10/17 14:30:10 | 00,019,405 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2007/10/16 22:43:18 | 00,000,202 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007/10/16 21:48:06 | 00,009,728 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2007/10/16 21:27:54 | 02,463,976 | ---- | C] () -- C:\WINDOWS\System32\NPSWF32.dll
[2007/10/16 21:03:20 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/10/16 20:52:14 | 00,000,990 | ---- | C] () -- C:\WINDOWS\adiras.ini
[2007/10/16 20:31:44 | 00,005,627 | R--- | C] () -- C:\WINDOWS\System32\Ludap17.ini
[2007/10/16 20:31:44 | 00,000,039 | R--- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2007/10/16 20:16:37 | 00,003,230 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2007/10/16 20:16:36 | 00,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007/10/16 20:08:11 | 00,002,822 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2007/06/19 19:21:39 | 00,001,132 | ---- | C] () -- C:\WINDOWS\System32\ASPRTMM5.DLL
[2007/04/17 08:01:11 | 00,003,509 | ---- | C] () -- C:\WINDOWS\System32\ASPRTMM4.DLL
[2006/10/01 08:42:59 | 00,270,336 | ---- | C] () -- C:\WINDOWS\System32\QtNetwork4.dll
[2006/09/28 15:10:06 | 00,212,992 | ---- | C] () -- C:\WINDOWS\System32\QtXml4.dll
[2006/09/15 13:28:19 | 01,753,088 | ---- | C] () -- C:\WINDOWS\System32\QtCore4.dll
[2006/09/14 13:55:25 | 04,112,384 | ---- | C] () -- C:\WINDOWS\System32\QtGui4.dll
[2005/12/30 22:18:26 | 00,159,744 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2005/12/30 22:10:30 | 00,561,152 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2005/10/25 10:07:12 | 00,004,417 | ---- | C] () -- C:\WINDOWS\System32\ASPRTMM0.DLL
[2005/05/03 13:38:42 | 00,064,512 | R--- | C] () -- C:\WINDOWS\System32\P17.dll
[2005/04/13 14:41:02 | 00,749,568 | ---- | C] () -- C:\WINDOWS\System32\SWFGen.dll
[2004/08/04 14:00:00 | 00,001,024 | ---- | C] () -- C:\WINDOWS\System32\q1gr2wf.dll
[2004/08/04 14:00:00 | 00,001,024 | ---- | C] () -- C:\WINDOWS\System32\grcauth2.dll
[2004/08/04 14:00:00 | 00,001,024 | ---- | C] () -- C:\WINDOWS\System32\grcauth1.dll
[2004/08/04 14:00:00 | 00,001,024 | ---- | C] () -- C:\WINDOWS\System32\clauth2.dll
[2004/08/04 14:00:00 | 00,001,024 | ---- | C] () -- C:\WINDOWS\System32\clauth1.dll
[2004/08/04 14:00:00 | 00,000,579 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/04 14:00:00 | 00,000,341 | ---- | C] () -- C:\WINDOWS\System32\htbgybv.dll
[2004/08/04 14:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2004/08/04 14:00:00 | 00,000,100 | ---- | C] () -- C:\WINDOWS\System32\prsgrc.dll
[2004/08/04 14:00:00 | 00,000,072 | ---- | C] () -- C:\WINDOWS\System32\ssprs.dll
[2004/08/04 14:00:00 | 00,000,016 | -H-- | C] () -- C:\WINDOWS\System32\rzcbaso.dll
[2003/10/02 12:48:18 | 00,053,248 | R--- | C] () -- C:\WINDOWS\System32\P17CPI.dll
[2002/10/06 20:42:57 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2002/04/10 19:41:06 | 00,065,536 | R--- | C] ( ) -- C:\WINDOWS\System32\A3d.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\*.tmp files]
[2009/04/25 20:05:24 | 00,540,135 | ---- | M] () -- C:\Documents and Settings\Cile\Desktop\Win32_Rootkit.Agent.ODG.trojan-3.mht
[2009/04/25 20:04:22 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Cile\Desktop\OTListIt2.exe
[2009/04/25 16:15:07 | 00,164,844 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/04/25 14:42:20 | 00,000,878 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
[2009/04/25 14:42:18 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/04/25 14:42:13 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/04/25 14:42:12 | 00,003,568 | ---- | M] () -- C:\WINDOWS\System32\ativvaxx.cap
[2009/04/25 13:46:27 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/04/24 23:06:11 | 00,233,984 | ---- | M] () -- C:\Documents and Settings\Cile\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/24 23:04:01 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/04/24 13:04:46 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/04/24 13:04:25 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/04/24 10:39:13 | 01,079,808 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\Malica.pps
[2009/04/24 09:54:02 | 00,000,202 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/04/23 15:46:37 | 00,822,250 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\drvo zivota.3dm
[2009/04/23 15:46:34 | 03,354,774 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\DrvoZibota1.obj
[2009/04/22 21:15:42 | 00,159,900 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\Pamela Wyn Shannon - Courting Autumn - 2007.jpg
[2009/04/21 19:14:30 | 00,002,822 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2009/04/21 17:35:57 | 00,000,281 | RHS- | M] () -- C:\boot.ini
[2009/04/21 17:31:16 | 02,998,641 | R--- | M] () -- C:\Documents and Settings\Cile\Desktop\ComboFix.exe
[2009/04/21 16:33:31 | 00,000,579 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/04/21 09:58:08 | 00,109,568 | ---- | M] () -- C:\WINDOWS\vFind.exe
[2009/04/20 19:58:41 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2009/04/20 17:32:18 | 04,783,070 | -H-- | M] () -- C:\Documents and Settings\Cile\Local Settings\Application Data\IconCache.db
[2009/04/20 15:09:55 | 00,072,748 | ---- | M] (Jordan Russell) -- C:\WINDOWS\unins000.exe
[2009/04/20 15:09:55 | 00,000,663 | ---- | M] () -- C:\WINDOWS\unins000.dat
[2009/04/20 14:49:38 | 00,000,730 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Media Player.lnk
[2009/04/20 14:38:09 | 00,002,587 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ACDSee 10 Photo Manager.lnk
[2009/04/20 13:54:51 | 03,107,788 | ---- | M] () -- C:\WINDOWS\System32\ativvaxx.dat
[2009/04/20 13:54:51 | 03,107,788 | ---- | M] () -- C:\WINDOWS\System32\ativva5x.dat
[2009/04/20 13:54:51 | 00,887,724 | ---- | M] () -- C:\WINDOWS\System32\ativva6x.dat
[2009/04/20 13:54:51 | 00,184,320 | ---- | M] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\atipdlxx.dll
[2009/04/20 13:54:51 | 00,143,360 | ---- | M] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\Oemdspif.dll
[2009/04/20 13:54:51 | 00,024,064 | ---- | M] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\ativcoxx.dll
[2009/04/20 13:54:50 | 00,174,820 | ---- | M] () -- C:\WINDOWS\System32\atiicdxx.dat
[2009/04/20 13:54:50 | 00,014,505 | ---- | M] () -- C:\WINDOWS\atiogl.xml
[2009/04/20 13:54:50 | 00,007,167 | ---- | M] () -- C:\WINDOWS\System32\atifglpf.xml
[2009/04/20 13:54:49 | 00,043,520 | ---- | M] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\ati2edxx.dll
[2009/04/20 13:54:49 | 00,026,112 | ---- | M] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\Ati2mdxx.exe
[2009/04/20 13:47:50 | 00,000,000 | ---- | M] () -- C:\WINDOWS\ativpsrm.bin
[2009/04/20 13:37:01 | 00,515,688 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/20 13:37:01 | 00,435,920 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/04/20 13:37:01 | 00,070,066 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/04/20 13:16:54 | 00,000,042 | ---- | M] () -- C:\WINDOWS\System32\DriverChecker.lie
[2009/04/20 13:16:16 | 00,000,685 | ---- | M] () -- C:\Documents and Settings\Cile\Desktop\Driver Checker.lnk
[2009/04/20 11:48:00 | 00,000,363 | ---- | M] () -- C:\WINDOWS\wcx_ftp.ini
[2009/04/19 23:53:17 | 00,111,647 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\drvo-zivota.jpg
[2009/04/19 22:37:58 | 00,261,760 | ---- | M] () -- C:\Documents and Settings\Cile\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/04/19 18:38:37 | 00,000,795 | ---- | M] () -- C:\Documents and Settings\Cile\Desktop\DivX Player.lnk
[2009/04/19 18:28:53 | 03,377,064 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/19 10:49:53 | 00,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2009/04/18 18:55:57 | 00,310,795 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\Srecan-Vaskrs---2009.jpg
[2009/04/18 18:41:02 | 01,122,119 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\Vasilija Radojcic - Na Uskrs Sam Se Rodila.mp3
[2009/04/17 19:54:53 | 00,060,396 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\band_detail.jpg
[2009/04/17 19:54:07 | 00,108,156 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\front_cover_small.jpg
[2009/04/16 17:45:40 | 00,141,529 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\Piletina-sa-bukovacama-i-pelatom.jpg
[2009/04/16 13:07:49 | 00,025,600 | ---- | M] () -- C:\Documents and Settings\Cile\Desktop\Neda informatika.xls
[2009/04/15 22:24:40 | 00,090,112 | ---- | M] (DivX, Inc.) -- C:\WINDOWS\System32\dpl100.dll
[2009/04/15 22:24:38 | 00,823,296 | ---- | M] (DivX, Inc.) -- C:\WINDOWS\System32\divx_xx0c.dll
[2009/04/15 22:24:38 | 00,823,296 | ---- | M] (DivX, Inc.) -- C:\WINDOWS\System32\divx_xx07.dll
[2009/04/15 22:24:38 | 00,815,104 | ---- | M] (DivX, Inc.) -- C:\WINDOWS\System32\divx_xx0a.dll
[2009/04/15 22:24:38 | 00,802,816 | ---- | M] (DivX, Inc.) -- C:\WINDOWS\System32\divx_xx11.dll
[2009/04/15 22:24:38 | 00,684,032 | ---- | M] (DivX, Inc.) -- C:\WINDOWS\System32\DivX.dll
[2009/04/15 22:05:58 | 00,031,267 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\Cile_Perish.jpg
[2009/04/15 21:25:50 | 00,015,360 | ---- | M] () -- C:\Documents and Settings\Cile\Desktop\CileEXEL.xls
[2009/04/15 11:58:14 | 00,030,182 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\collin14[1].jpg
[2009/04/13 23:23:19 | 00,000,064 | -H-- | M] () -- C:\WINDOWS\System32\superpad8.lnf
[2009/04/11 21:21:57 | 00,001,742 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Acrobat 9.1 Pro Extended.lnk
[2009/04/11 20:54:49 | 00,000,500 | ---- | M] () -- C:\Documents and Settings\Cile\Desktop\Cathy - SVE.lnk
[2009/04/11 20:06:39 | 00,019,405 | ---- | M] () -- C:\WINDOWS\cdplayer.ini
[2009/04/11 15:18:45 | 00,019,968 | ---- | M] () -- C:\Documents and Settings\Cile\Desktop\Pele-excel.xls
[2009/04/11 00:12:00 | 00,020,645 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\PrayerForCompassionOverleaf_lg.jpg
[2009/04/11 00:11:58 | 00,032,320 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\PrayerForCompassionBack_lg.jpg
[2009/04/11 00:11:54 | 00,023,848 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\PrayerForCompassion_lg.jpg
[2009/04/09 16:57:08 | 00,085,074 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\adsl.cilegraaf_uplata_03_2009.jpg
[2009/04/08 21:02:52 | 00,000,038 | ---- | M] () -- C:\WINDOWS\AviSplitter.INI
[2009/04/07 19:18:03 | 00,000,169 | ---- | M] () -- C:\WINDOWS\adidsl.ini
[2009/04/07 19:16:38 | 00,000,560 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Internet ADSL.lnk
[2009/04/07 19:16:37 | 00,000,990 | ---- | M] () -- C:\WINDOWS\adiras.ini
[2009/04/07 19:16:37 | 00,000,031 | ---- | M] () -- C:\WINDOWS\System32\drivers\adidsl.cfg
[2009/04/07 19:16:37 | 00,000,021 | ---- | M] () -- C:\WINDOWS\Fast800.ini
[2009/04/07 19:16:27 | 00,000,655 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DSLMON.lnk
[2009/04/06 22:19:14 | 06,313,787 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\Catedral de La Seo en Zaragoza v7.skp
[2009/04/06 22:13:53 | 06,312,374 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\Catedral de La Seo en Zaragoza.skp
[2009/04/06 22:12:35 | 01,389,154 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\El Pilar de Zaragoza_google_4.skp
[2009/04/06 18:47:39 | 00,134,120 | ---- | M] () -- C:\WINDOWS\ColorPic Uninstaller.exe
[2009/04/06 18:47:39 | 00,000,712 | ---- | M] () -- C:\Documents and Settings\Cile\Desktop\ColorPic.lnk
[2009/04/02 18:54:47 | 00,000,064 | -H-- | M] () -- C:\WINDOWS\System32\superpad6.lnf
[2009/04/01 22:04:35 | 00,116,224 | -HS- | M] () -- C:\Documents and Settings\Cile\My Documents\Thumbs.db
[2009/03/31 20:14:16 | 00,142,465 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\Vase.3dm
[2009/03/31 20:14:00 | 00,672,583 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\Vase.3ds
[2009/03/31 20:00:03 | 00,398,418 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\HandbookOfOrnament-(slika-305).jpg
[2009/03/31 19:56:48 | 00,073,958 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\HandbookOfOrnament (slika 305).pdf
[2009/03/31 19:09:48 | 00,013,085 | ---- | M] () -- C:\Documents and Settings\Cile\My Documents\proba MOI.3dm
[2009/03/27 13:51:58 | 00,001,834 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Lightroom 2.3.lnk
< End of report >

Extras.Txt
-----------------------------------
OTListIt Extras logfile created on: 4/25/2009 8:07:42 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Cile\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.47 Gb Available Physical Memory | 73.54% Memory free
3.85 Gb Paging File | 3.46 Gb Available in Paging File | 89.79% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 117.19 Gb Total Space | 45.98 Gb Free Space | 39.24% Space Free | Partition Type: NTFS
Drive D: | 255.41 Gb Total Space | 48.30 Gb Free Space | 18.91% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 372.61 Gb Total Space | 36.08 Gb Free Space | 9.68% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded

Computer Name: CILE-452CCE298C
Current User Name: Cile
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"3703:TCP" = 3703:TCP:*:Enabled:Adobe Version Cue CS3 Server
"3704:TCP" = 3704:TCP:*:Enabled:Adobe Version Cue CS3 Server
"50900:TCP" = 50900:TCP:*:Enabled:Adobe Version Cue CS3 Server
"50901:TCP" = 50901:TCP:*:Enabled:Adobe Version Cue CS3 Server
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"50000:TCP" = 50000:TCP:*:Enabled:Mezzmo Media Sharing Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Messenger\msmsgs.exe:*:Disabled:Windows Messenger (Microsoft Corporation)
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:*:Enabled:Adobe Version Cue CS3 Server (Adobe Systems Incorporated)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Autodesk\3ds Max 9\3dsmax.exe:*:Enabled:Autodesk 3ds Max 9 32-bit (Autodesk, Inc.)
C:\Program Files\Autodesk\Backburner\monitor.exe:*:Enabled:backburner 2.3 monitor (Autodesk, Inc.)
C:\Program Files\Autodesk\Backburner\manager.exe:*:Enabled:backburner 2.3 manager (Autodesk, Inc.)
C:\Program Files\Autodesk\Backburner\server.exe:*:Enabled:backburner 2.3 server (Autodesk, Inc.)
C:\Program Files\Next Limit\Maxwell\mxcl.exe:*:Enabled:mxcl ()
C:\Program Files\Opera\Opera.exe:*:Disabled:Opera Internet Browser (Opera Software)
C:\Program Files\Adobe\Adobe Photoshop CS3\Photoshop.exe:*:Disabled:Adobe Photoshop CS3 (Adobe Systems, Incorporated)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype (Skype Technologies S.A.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"#1 DVD Ripper" = #1 DVD Ripper 7.1
"_{5B51BB5F-4E7C-4275-A653-E98534E9C1D2}" = Corel Painter 11
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{01386D1F-ADE7-43B4-A4E9-312FC5BC726F}_is1" = SWF Opener
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{063FC154-D3DD-4B21-99FE-BD7D437CE173}" = vcd
"{06A1BE8A-4CA4-4A39-B9E4-E815AA8FE05C}" = Sony Noise Reduction Plug-In 2.0h
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{09E2111C-16B1-4DDF-BF0D-F994C9A12350}" = Adobe Setup
"{09F6D244-DFA2-41DD-A0F0-63CA5AD2A36B}" = TubeHunter Media Center
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{1047B3FE-E1EB-4E03-97DE-C5037C2CE9CF}" = TubeHunter
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1AED4ABF-0852-4B3F-9F87-00CF88F25CE0}" = IconHandler 32 bit
"{1B1DDAD2-C704-49F8-8FC2-18DAAD9A87C5}" = Sound Blaster Audigy
"{1D58229F-C505-45CA-8223-F35F3A34B963}" = Adobe Version Cue CS3 Server
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{28F8F8F0-C278-454A-9507-46B344AAD188}" = Corel Painter 11
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2A15F264-10BA-47FB-98F2-856A80F35E41}" = Duplicate File Detective 2
"{2C272396-11B1-79BD-2BB3-40B9BEE9BCE5}" = Catalyst Control Center Core Implementation
"{2EFFFC71-1E66-454E-A6E6-CEEC800B96D2}" = Adobe Flash Video Encoder
"{342F5437-C87D-4BB5-89B9-B23E16C6A395}" = Microsoft Visual C++ 8.0 Support DLLs
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}" = Mega Manager
"{3D347E6D-5A03-4342-B5BA-6A771885F379}" = Backburner
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{4062364A-1290-43E5-8250-6A0C8C74CABC}" = ccc-core-preinstall
"{4231395F-C55C-FBAD-E4A5-C0E7D67F32E4}" = Catalyst Control Center Graphics Full New
"{447FB54F-EEE7-4F18-9B5A-77EBA7079FBC}" = Photo Slide Show Application
"{44A91B04-3D0C-47F9-B644-7F682869AFF3}" = MobileMe Control Panel
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F}" = SAGEM F@st 800-840
"{4AEA9A23-D627-4699-8A0F-FC474308C2E6}" = Sony Sound Forge 9.0
"{4AFF784E-C233-47DD-8AB9-5A12F2C6AC6C}" = Sony Preset Manager 2.0e
"{4F93ABBE-5A1D-4D56-94CB-022F109FDE4D}" = Adobe Presenter 7
"{505AFDC0-5E72-4928-8368-5DEA385E3647}" = CorelDRAW Graphics Suite 12
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{53735ECE-E461-4FD0-B742-23A352436D3A}" = Logitech Updater
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{548EAC70-EE00-11DD-908C-005056806466}" = Google Earth
"{55718B4B90B54F7EADC5621C750A14E6}" = DivX Author 1.5
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{572527DD-05F1-E9EA-5B4F-055ECDD720EB}" = ccc-utility
"{5783F2D7-4001-0409-0002-0060B0CE6BBA}" = AutoCAD 2006 - English
"{5783F2D7-5001-0409-0002-0060B0CE6BBA}" = AutoCAD 2007 - English
"{5AD4A795-3BDC-4667-A881-8FBC56F407D1}" = iTunesFolderWatch
"{5B51BB5F-4E7C-4275-A653-E98534E9C1D2}" = Corel Painter 11 - ICA
"{5B5B1BD4-1450-355C-92AF-2DA0C9DF1A7F}" = PicLens for Internet Explorer
"{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}" = iTunes
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6B52140A-F189-4945-BFFC-DB3F00B8C589}" = Adobe Flash CS3
"{6B708481-748A-4EB4-97C1-CD386244FF77}" = Adobe MotionPicture Color Files
"{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}" = AHV content for Acrobat and Flash
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{746EC26B-9A80-4FD5-9861-545E0CD2A795}" = Mega Manager
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{7912CF00-F16C-44BF-A2B1-B54669E0142F}" = mp3
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7C10F5C7-F00F-4BD3-A110-C7D240D2DD25}" = Adobe Dreamweaver CS3
"{7C8B5E63-821A-4DFB-BDFA-19854D88EC5C}" = 3dsmax ancillary install
"{7CBD8A89-45F4-4203-9923-673F72603747}" = Adobe Photoshop Lightroom 2.3
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{7E37FE5D-833D-8CEC-68DE-665DDDDA06B5}" = Catalyst Control Center Graphics Light
"{7EC69F77-5494-4E1F-8BC6-956DAA5A91F2}" = Corel Painter 11 - IPM
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{840BF2FE-033D-437C-89D1-AAA206BA13B6}" = Langauge
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90170409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{9455959E-D588-EFAE-329C-F66CC797F32A}" = Adobe Media Player
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{9A346205-EA92-4406-B1AB-50379DA3F057}" = Autodesk DWF Viewer 7
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9ED3C484-D002-4D4D-9BF3-C3DF9048EE7D}" = StuffIt 12
"{A2A60894-E3ED-46FE-9A6A-7CF7A87572A0}" = Opera 9.64
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A4C9E6C5-A082-4DF3-A12E-A176929E41E6}" = flv
"{A73C3B76-C889-29FF-811E-14AF82CCEBEE}" = ccc-core-static
"{A8B2C826-3627-52AA-D5B5-D89F178F4A8B}" = Catalyst Control Center Graphics Full Existing
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{ABC0976C-723E-CDA4-7F09-378FAF2C2890}" = Skins
"{AC138218-5F23-DCC0-357D-143EF8451483}" = CCC Help English
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
"{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AC76BA86-7AD7-5760-0000-900000000003}" = Japanese Fonts Support For Adobe Reader 9
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{AF10D7E4-D29A-45DA-8050-B116097B69B5}" = Safari
"{AFA20D47-69C3-4030-8DF8-D37466E70F13}" = Apple Mobile Device Support
"{B1166CA2-9264-C562-AEDE-7C1965CBAAF8}" = Catalyst Control Center Graphics Previews Common
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B369483E-0728-405C-8F8C-3427B263B01F}" = Content
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B671CBFD-4109-4D35-9252-3062D3CCB7B2}" = Adobe SING CS3
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B7F560B3-6EFF-4026-A982-843895A41149}" = Adobe BridgeTalk Plugin CS3
"{B944FA21-81AF-4A77-8328-CE4F4CC51033}" = Nero 8
"{B96D2269-568B-4CBF-9332-12FAE8B158F7}" = Medieval CUE Splitter
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BE24AB71-85E9-45D8-8F5D-661430182197}" = DirectShow .SHN FIlter
"{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C3A3B7AA-DBB8-45CD-A221-1A9A91C20FC5}" = SizeFixer XL
"{C5BD220A-EFE8-48A5-B70E-9503D535FACE}" = Adobe WAS CS3
"{C8F4800F-52F4-4115-BE64-FF1C23604E86}_is1" = Sothink SWF Easy
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB3F8375-B600-4B9F-83C9-238ED1E583FD}" = Adobe InDesign CS3
"{CE4B4C3F-1C0A-4933-B321-0CD036AF1127}" = iTunesAlbumBrowser
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D1C18EDD-571A-4BDD-BE7B-1DD86027D7FF}" = Adobe Creative Suite 3 Design Premium
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{D7960C39-E3FD-4B46-8E97-A1E9D128F913}" = Rhinoceros 4.0 Evaluation
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DBB61A16-A0E0-4EAB-9E59-D0F3B0299429}" = Maxwell Render
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DF31E97B-81AD-4F60-B7C4-266ABF228FEE}" = RhinoART 1.0 Demo For Rhino 4.0
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E96D4088-AAC5-437F-9E39-EC0E387897B4}" = Autodesk 3ds Max 9 32-bit
"{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}" = Adobe InDesign CS3 Icon Handler
"{ECB5F4EA-D7DD-4423-B1E5-CD14A30A3732}" = RealFlow
"{F08E8D2E-F132-4742-9C87-D5FF223A016A}" = Adobe Illustrator CS3
"{F3E2505F-AA57-476B-9F67-F8C5E3938080}" = ESET Smart Security
"{F8B98EB6-FC06-45BF-87D4-9784E0408611}" = ACDSee 10 Photo Manager
"{FA0BC743-0C8D-40C1-A074-BD4825A75A77}" = TubeHunter Ultra
"{FC7BACF0-1FFA-4605-B3B4-A66AB382752D}" = XML Notepad 2007
"3D Object Converter for Windows 4.0" = 3D Object Converter for Windows 4.0
"3D Photo Browser" = 3D Photo Browser 10.03
"7-Zip" = 7-Zip 4.57
"Acme CAD Converter v7.87_is1" = Acme CAD Converter v7.87
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Presenter 7" = Adobe Presenter 7
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_c14ac4070fd9614ffe63f4bb533db2c" = Add or Remove Adobe Creative Suite 3 Design Premium
"Advanced Flash Player1.1" = Advanced Flash Player
"All ATI Software" = ATI - Software Uninstall Utility
"Alligator Flash Designer 7" = Alligator Flash Designer 7 (7.1.0.1) Trial
"AlphaPlugins RedEyes for Adobe Photoshop_is1" = AlphaPlugins RedEyes
"Anfy" = Anfy
"AoA DVD Ripper_is1" = AoA DVD Ripper
"ATI Display Driver" = ATI Display Driver
"Audio Catalog_is1" = Audio Catalog 3.7
"Audio DVD Creator_is1" = Audio DVD Creator 1.9.1.0
"AutoRun Architect" = AutoRun Architect
"AutoRun Design Specialty_is1" = AutoRun Design Specialty 8.0.1.1
"AviSynth" = AviSynth 2.5
"Blow Up" = Alien Skin Blow Up
"Bryce" = Bryce 6.1
"BSPlayer1" = BSPlayer
"BSPlayerp" = BS.Player PRO
"ca_musiclabel_is1" = Music Label 2008 v14.0.3
"Carrara Pro 7.0.0" = Carrara Pro
"CCleaner" = CCleaner (remove only)
"CD Art Display_is1" = CD Art Display 1.0
"CD Catalog Expert_is1" = CD Catalog Expert 9.30.807.11
"Collectorz.com Music Collector" = Collectorz.com Music Collector
"ColorPic" = ColorPic
"Crystal Player" = Crystal Player Professional 1.8
"DAZ Studio 2.2" = DAZ Studio
"DiagramStudio 4.3" = DiagramStudio 4.3
"Directory Lister_is1" = Directory Lister v0.9.1
"DirectVobSub" = DirectVobSub (remove only)
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DreamAqua" = Dream Aquarium
"Driver Checker_is1" = Driver Checker v2.7.3
"DScaler 5 Mpeg Decoders_is1" = DScaler 5 Mpeg Decoders
"Duplicate File Detective 2" = Duplicate File Detective 2
"DVD Identifier_is1" = DVD Identifier
"DVD X Player 4.1 Professional_is1" = DVD X Player 4.1 Professional
"DVDCreator.exe_is1" = Music DVD Creator 2.0
"DVDPean Pro 5.6.0_is1" = DVDPean Pro 5.6.0
"DzSoftPPSlideShowConv_is1" = PowerPoint Slide Show Converter 3.1
"Easy Button & Menu Maker_is1" = Easy Button & Menu Maker 1.2
"Easy Website Pro 4" = Easy Website Pro 4
"Exact Audio Copy" = Exact Audio Copy 0.99pb4
"EZ Mask v1 for Adobe Photoshop & Photoshop Elements" = EZ Mask v1 for Adobe Photoshop & Photoshop Elements
"FBX Plugin 2006.08 for Max 9.0" = FBX Plugin 2006.08 for Max 9.0
"Flash Saving Plugin" = Flash Saving Plugin
"FLV Player" = FLV Player 2.0 (build 25)
"FLV Player2.0 " = FLV Player
"FocalBlade_is1" = FocalBlade 1.05
"Google Updater" = Google Updater
"Icon Restore_is1" = Icon Restore 1.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Intel® 536EP Modem" = Intel® 536EP Modem
"KC Softwares AudioGrail_is1" = KC Softwares AudioGrail
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 3.9.5
"LightZone 3.4" = LightZone 3.4
"Matroska Pack" = Matroska Pack (remove only)
"Maxwell" = Maxwell
"MaxwellMax" = Maxwell Plugin for 3D Studio Max
"MegauploadToolbar" = Megaupload Toolbar
"MetaProducts Offline Explorer Enterprise" = MetaProducts Offline Explorer Enterprise
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"MoI_v1_is1" = Moment of Inspiration 1.0
"Monkey's Audio_is1" = Monkey's Audio
"MP3-Check_is1" = MP3-Check (v1.0.26.0)
"Mp3Doctor PRO_is1" = Mp3Doctor PRO
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"Natura Sound Therapy" = Natura Sound Therapy
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OggDS" = Direct Show Ogg Vorbis Filter (remove only)
"OrangeCD Suite_is1" = OrangeCD Suite version 6.2.1
"Picasa 3" = Picasa 3
"Plato Video Converter_is1" = Plato Video Converter 7.85
"Plato Video To FLV Converter_is1" = Plato Video To FLV Converter 4.78
"Player" = Player
"Presentation Wizard" = Presentation Wizard
"Registry Mechanic_is1" = Registry Mechanic 7.0
"Relaxing Ocean V3" = Relaxing Ocean V3 Screen Saver
"Revo Uninstaller" = Revo Uninstaller 1.80
"Search and Recover 4_is1" = iolo technologies' Search and Recover 4
"SereneScreen Marine Aquarium 2.6_is1" = SereneScreen Marine Aquarium 2.6
"Silver Efex Pro" = Silver Efex Pro
"Snowflakes (plug-in)" = Snowflakes (plug-in)
"Solar System - Earth 3D Screensaver_is1" = Solar System - Earth 3D Screensaver v1.1
"Solar System - Moon 3D Screensaver_is1" = Solar System - Moon 3D Screensaver v1.0
"Switch" = Switch
"SysInfo" = Creative System Information
"The KMPlayer" = The KMPlayer (remove only)
":spam: All Music Converter_is1" = :spam: All Music Converter
"Total Audio Converter_is1" = TotalAudioConverter
"Totalcmd" = Total Commander (Remove or Repair)
"Tweak UI 2.10" = Tweak UI
"VertusFluidMask3" = Vertus Fluid Mask 3 3.0.8
"Victoria 4.2 Base ps_pe069_Victoria4" = Victoria 4.2 Base
"Video to Audio Converter 3" = Video to Audio Converter 3
"VLC media player" = VideoLAN VLC media player 0.8.6d
"VUPlayer" = VUPlayer
"WavePad" = WavePad Uninstall
"Web Button Menu Maker_is1" = Web Button Menu Maker 3.2
"whereisit-wii_is1" = WhereIsIt? 3.90
"WIC" = Windows Imaging Component
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wondershare DVD Slideshow Builder_is1" = Wondershare DVD Slideshow Builder 4.3.0 Trial Version
"Wondershare Flash Gallery Factory_is1" = Wondershare Flash Gallery Factory 4.7.1
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"X-Fonter_is1" = X-Fonter 6.4
"Xilisoft Audio Maker" = Xilisoft Audio Maker
"Xilisoft FLV Converter" = Xilisoft FLV Converter
"Xilisoft Video Converter Ultimate" = Xilisoft Video Converter Ultimate
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Xvid_is1" = Xvid 1.1.3 final uninstall
"Yahoo! Widget Engine" = Yahoo! Widgets
"YInstHelper" = Yahoo! Install Manager
"Zima" = Zima

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"File Renamer Deluxe" = File Renamer Deluxe
"Flash Music Studio 1.0" = Flash Music Studio 1.0(remove only)

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/22/2009 6:26:47 AM | Computer Name = CILE-452CCE298C | Source = MsiInstaller | ID = 10005
Description = Product: Java™ 6 Update 11 -- Internal Error 2753. regutils.dll

Error - 4/22/2009 6:36:10 AM | Computer Name = CILE-452CCE298C | Source = MsiInstaller | ID = 10005
Description = Product: Java™ 6 Update 10 -- Internal Error 2753. regutils.dll

Error - 4/22/2009 5:22:20 PM | Computer Name = CILE-452CCE298C | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x057dc550.

Error - 4/23/2009 3:09:11 AM | Computer Name = CILE-452CCE298C | Source = Google Update | ID = 20
Description =

Error - 4/24/2009 3:09:49 AM | Computer Name = CILE-452CCE298C | Source = Google Update | ID = 20
Description =

Error - 4/24/2009 4:09:49 AM | Computer Name = CILE-452CCE298C | Source = Google Update | ID = 20
Description =

Error - 4/24/2009 9:23:16 AM | Computer Name = CILE-452CCE298C | Source = Application Hang | ID = 1002
Description = Hanging application KMPlayer.exe, version 2.9.3.1431, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/25/2009 7:58:11 AM | Computer Name = CILE-452CCE298C | Source = Google Update | ID = 20
Description =

Error - 4/25/2009 8:56:54 AM | Computer Name = CILE-452CCE298C | Source = Google Update | ID = 20
Description =

Error - 4/25/2009 12:34:37 PM | Computer Name = CILE-452CCE298C | Source = Application Error | ID = 1000
Description = Faulting application opera.exe, version 9.64.10487.0, faulting module
msvcrt.dll, version 7.0.2600.5512, fault address 0x00037c89.

[ System Events ]
Error - 4/24/2009 6:55:08 AM | Computer Name = CILE-452CCE298C | Source = Service Control Manager | ID = 7034
Description = The iPod Service service terminated unexpectedly. It has done this
1 time(s).

Error - 4/24/2009 7:04:18 AM | Computer Name = CILE-452CCE298C | Source = Service Control Manager | ID = 7000
Description = The General Purpose USB Driver (e4ldr.sys) service failed to start
due to the following error: %%1058

Error - 4/24/2009 7:04:18 AM | Computer Name = CILE-452CCE298C | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Nod32 AV service to connect.

Error - 4/24/2009 7:04:18 AM | Computer Name = CILE-452CCE298C | Source = Service Control Manager | ID = 7000
Description = The Nod32 AV service failed to start due to the following error: %%1053

Error - 4/25/2009 7:46:34 AM | Computer Name = CILE-452CCE298C | Source = Service Control Manager | ID = 7000
Description = The General Purpose USB Driver (e4ldr.sys) service failed to start
due to the following error: %%1058

Error - 4/25/2009 7:46:34 AM | Computer Name = CILE-452CCE298C | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Nod32 AV service to connect.

Error - 4/25/2009 7:46:34 AM | Computer Name = CILE-452CCE298C | Source = Service Control Manager | ID = 7000
Description = The Nod32 AV service failed to start due to the following error: %%1053

Error - 4/25/2009 8:42:27 AM | Computer Name = CILE-452CCE298C | Source = Service Control Manager | ID = 7000
Description = The General Purpose USB Driver (e4ldr.sys) service failed to start
due to the following error: %%1058

Error - 4/25/2009 8:42:27 AM | Computer Name = CILE-452CCE298C | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Nod32 AV service to connect.

Error - 4/25/2009 8:42:27 AM | Computer Name = CILE-452CCE298C | Source = Service Control Manager | ID = 7000
Description = The Nod32 AV service failed to start due to the following error: %%1053


< End of report >
-----------------------------------
atb, Graaf
  • 0

#8
handhfan

handhfan

    Trusted Helper

  • Expert
  • 13,659 posts
Please do an online scan with Kaspersky WebScanner

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure the following is checked.
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

  • 0

#9
graaf24

graaf24

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
OK, few days ago (before you contact me, after my problem with this Trojan) I begin online-scan Kaspersky WebScanner. After 3 1/2 hours it's scanned 8%, because I have large HD and lot of files to scan. I need ~ 35-40 hours to scan My Computer. Please take me time to do this scan (few days?). I must finish my job on my PC now (with or without Trojan on it).

Please tell me next: when KWScaner download update and begin scan NO NEED to stay ON LINE instead?

Thanks, Graaf
  • 0

#10
handhfan

handhfan

    Trusted Helper

  • Expert
  • 13,659 posts
You can take your time, I'm pretty patient. :)

However, 35-40 hours for a single scan seems rather extreme here. If you'd rather, let's try the following tool, it hopefully will be done sooner. Perhaps you can just leave it run overnight or something, so it's not when you need to use it.

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder.Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


After that click on Security level then choose Customize then click on the tab that says Heuristic Analyzer then choose Enable Deep rootkit search then choose ok.
Then choose OK again then you are back to the main screen.

  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left un-neutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.


  • 0

#11
graaf24

graaf24

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
OK, I just downloading this tool and I scan my PC tonight (houp so!)

atb, Graaf
  • 0

#12
handhfan

handhfan

    Trusted Helper

  • Expert
  • 13,659 posts
Okay. :)
  • 0

#13
handhfan

handhfan

    Trusted Helper

  • Expert
  • 13,659 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP